Skip to content

Palo Alto XSOAR: DomainTools app

Use the DomainTools Iris app to bring Domain Name System (DNS) intelligence into Palo Alto XSOAR. You can enrich malicious domain observables in incidents and automate response workflows.

For more information about XSOAR, see the official Palo Alto XSOAR documentation. For playbooks, see the DomainTools GitHub repository.

Use the Iris Investigate API in Palo Alto XSOAR to enrich domain observables and investigate them in incident context.

The app enables:

  • Ad hoc investigations of domain Indicators of Compromise (IOCs) inside Palo Alto XSOAR incidents
  • Triage with DomainTools Risk Score, Threat Profile Scores, and other actionable analytics
  • Persistent DomainTools intelligence inside Palo Alto XSOAR
  • Discovery of connected infrastructure for a malicious domain
  • Automated triaging of DomainTools Iris tags inside Palo Alto XSOAR
  • Automated enrichment process using DomainTools playbooks
  • Targeted threat hunting at key aspects of a domain name’s registration profile

You need:

  • Palo Alto XSOAR Server 6.6.0 or later
  • Palo Alto XSOAR Content version 1.32.44 (6877054) or later
  • Active DomainTools Iris Investigate API credentials (username and key)

DomainTools offers two integrations: DomainTools Iris Investigate (as DomainTools Iris), and the DomainTools Real-time Threat Feeds (as FeedDomainTools). This guide provides instructions for both integrations, which you configure independently.

  1. Select Settings > Integrations > Servers & Services
  2. Search for “DomainTools” to find the DomainTools Iris (Partner Contribution) integration
  3. Select Add Instance to configure the DomainTools instance
  4. Enter the configuration parameters described in the following table:
Parameter nameRequiredDescription
API UsernameYesUsername used to authenticate DomainTools API calls.
API KeyYesAPI key used to authenticate DomainTools API calls.
High-Risk ThresholdYesA configurable threshold for DomainTools Risk Score that flags risky domains within your Palo Alto XSOAR instance. Default is 70.
Young Domain TimeframeYesA configurable threshold (in days) used to calculate if a domain is considered a ‘young domain’ within Palo Alto XSOAR.
Guided Pivot ThresholdYesGuided pivots are data points where 500 or fewer domains (by default) have that exact same value for the data point. You can configure the exact threshold number as desired.
Fetch IncidentsYesDetermines if the system enables the fetching of incidents (monitoring of Iris hash and Iris tag).
ClassifierNoDetermines the classifier to use when incidents are fetched or created. Classifies the incident type. You can choose DomainTools_Iris_Classifier. Required if Fetch Incidents is enabled.
Incident TypeNoDetermines what type of incident to create. Should default to “N/A” because there are two types of incidents. The classifiers handle this.
MapperNoDetermines the mapper to use when incidents are fetched or created. Maps the result with a given key to the created incident. Currently maps the domain key from Iris result to Additional Indicators incident field. You can choose DomainTools_Iris_Mapper. Required if Fetch Incidents is enabled.
Enabled on Monitoring Domains by Iris HashNoDetermines what method to use. Options are Import Indicators Only and Create Incident and Import Indicators. Default is Import Indicators Only. Required if Fetch Incidents is enabled.
DomainTools Iris Investigate Search HashNoRequired if Fetch Incidents is enabled.
Enabled on Monitoring Domains by Iris TagsNoDetermines what method to use. Options are Import Indicators Only and Create Incident and Import Indicators. Default is Import Indicators Only. Required if Fetch Incidents is enabled.
DomainTools Iris TagsNoContains the Iris tags to monitor. Creates incident or creates an indicator for each new domain found based on the tags. Required if Fetch Incidents is enabled.
Maximum Incidents to FetchNoDetermines the maximum incidents to fetch. Default is 2 (one for each possible feed type: iris search hash and iris tags).
Incidents Fetch IntervalNoDetermines the interval to fetch incidents (fetch results from Iris Investigate API with the given iris hash and iris tags). Required if Fetch Incidents is enabled.
  1. Test connectivity with DomainTools by clicking Test and look for the Success! indicator

To enable DomainTools to contribute to domain verdicts in XSOAR, you need to configure the domain-type indicator to use the DomainTools Iris domain command as part of its enrichment process.

Set the DomainTools domain command as the auto-enrichment or reputation command for domain indicators:

  1. Navigate to Settings > Objects Setup
  2. Select the Indicators tab
  3. Locate and select the Domain indicator type
  4. Click Edit
  5. Under the Reputation Command section, add the DomainTools domain command
  6. Save your changes

After you configure this setting, every time a domain indicator is encountered, XSOAR automatically runs the DomainTools command to enrich the indicator and contribute to the overall verdict (for example, via DBotScore and Domain.Malicious context fields).

Set up the Real-time Threat Feeds integration

Section titled “Set up the Real-time Threat Feeds integration”
  1. Select Settings > Integrations > Servers & Services
  2. Search for FeedDomainTools to find the Real-time Threat Feeds integration
  3. Select Add Instance to configure the DomainTools instance
  4. Enter the configuration parameters described in the following table

For more information on these parameters, see the Real-time Threat Feeds user guide.

ParameterDescriptionRequired
API UsernameThe DomainTools API usernameYes
API KeyThe DomainTools API keyYes
Session IDA string that serves as a unique identifier for the session, used for resuming data retrieval from the last point. Default is dt-cortex-feeds.No
AfterThe start of the query window in seconds, relative to the current time, inclusive. Default is -3600.No
TopLimits the number of results in the response payload. Especially useful for testing. Default is 5000.No
Feed TypeThe DomainTools feed type to fetch. Default is ALL.No
Indicator ReputationIndicators from this integration instance are marked with this reputation.No
Source ReliabilityReliability of the source providing the intelligence data.Yes
Feed Fetch IntervalThe feed fetching interval to use.No
Bypass exclusion listWhen selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.No
Use system proxy settingsNo
TagsSupports comma-separated values (CSV).No
Traffic Light Protocol ColorApplied to indicators fetched from the feed.No

For more information about the DomainTools Iris suite, see the Iris documentation.

CommandDescription
domainProvides data enrichment for domains.
domaintools-hosting-historyLists Internet Protocol (IP) address, name server, and registrar history.
domaintools-reverse-whoisLists domain names that share registrant information. Enter a domain-owner attribute, such as an email address or company name, to find matching registration records.
domaintools-whoisProvides parsed information from a raw WHOIS record for searching, indexing, and cross-referencing registration records.
domaintools-whois-historyReturns up to 100 historical WHOIS records for a domain name.
domaintoolsiris-analyticsDisplays DomainTools analytic data in a markdown format table.
domaintoolsiris-enrichReturns a complete profile of the domain (second-level domain and top-level domain) using Iris Enrich. If parsing of URLs or fully qualified domain names (FQDNs) is desired, see domainExtractAndEnrich.
domaintoolsiris-investigateReturns a complete profile of the domain (second-level domain and top-level domain) using Iris Investigate. If parsing of FQDNs is desired, see domainExtractAndInvestigate.
domaintoolsiris-pivotPivot on connected infrastructure (IP, email, Secure Sockets Layer (SSL)), or import domains from Iris Investigate using a search hash. Retrieves up to 5000 domains at a time. Optionally exclude results from context with include_context=false.
domaintoolsiris-threat-profileDisplays DomainTools Threat Profile data in a markdown format table.

Use DomainTools Real-time Threat Feeds commands

Section titled “Use DomainTools Real-time Threat Feeds commands”

The dtfeeds-get-indicators command returns feed indicators and displays them in the war room. It accepts the following arguments:

Argument nameDescriptionRequired
feed_typeThe DomainTools integration feed type to fetch. Default is nod.No
session_idSession unique identifier.No
domainFilter results for a top-level domain.No
afterThe start of the query window in seconds, relative to the current time, inclusive. Default is -3600 (3600 seconds or 1 hour).No
beforeThe end of the query window in seconds, relative to the current time, inclusive.No
topLimits the number of results in the response payload. Default is 50.No
AutomationDescription
AddDomainRiskScoreToContextSets average risk score to context for pivot result.
AssociateIndicatorsToIncidentAssociates indicators to an incident.
CheckLastEnrichmentChecks if DomainTools data needs enrichment.
CheckPivotableDomainsChecks for guided pivots for a given domain.
CheckTagsChecks DomainTools domain tags and if a tag is found, marks incident as high severity.
DomainExtractAndEnrichResolves a URL or fully qualified domain name (FQDN) and looks up a complete profile of the domain on the DomainTools Iris Enrich API.
DomainExtractAndInvestigateResolves a URL or fully qualified domain name (FQDN) and looks up a complete profile of the domain on the DomainTools Iris Investigate API.
SetIndicatorTableDataSets data for a domain in the indicator table.

In addition to the automation available within Palo Alto XSOAR, you can download automation scripts from the DomainTools Palo Alto XSOAR repository in GitHub.

XSOAR playbooks halt on errors by default. Some DomainTools playbooks may generate errors, such as when they receive unregistered domains, that you want to skip.

You can modify a playbook’s error handling via its On Error tab in Task Details in several ways:

  • Specify a permitted number of retries and the time between retries
  • Set the task to continue through an error
  • Set the task to take an error path

For more information about customized error handling, see this YouTube video from Palo Alto.

Before you upload these custom playbooks, review the Prerequisites section for each. It identifies any additional configurations and dependencies associated with these playbooks.

View on GitHub

This playbook fetches the Iris Investigate profile of a domain and uses DomainTools Guided Pivot values to identify related infrastructure.

Playbook: DomainTools Check Domain Risk Score By Iris Tags

Section titled “Playbook: DomainTools Check Domain Risk Score By Iris Tags”

View on GitHub

This playbook periodically checks domains for risk based on Iris Investigate tags. You can define a list of tags to monitor, and the playbook adds new high-risk domains as indicators on associated incidents.

Playbook: DomainTools Check New Domains by Iris Hash

Section titled “Playbook: DomainTools Check New Domains by Iris Hash”

View on GitHub

This playbook monitors new domains that match predefined infrastructure criteria, such as registrar, DNS, or SSL certificate data. It uses Iris Investigate data to identify newly registered domains.

Playbook: DomainTools Domain Auto Enrichment

Section titled “Playbook: DomainTools Domain Auto Enrichment”

View on GitHub

This playbook can reduce duplicate enrichment and store selected results in the XSOAR indicator table:

  • Checks if enrichment data is recent; if so, skips redundant enrichment of the domain
  • Performs domain enrichment
  • Stores key enrichment intelligence in Palo Alto XSOAR indicator table

Automation scripts: The playbook uses the following automation scripts to deliver these functionalities. Both of these are available for download in the scripts folder of the same repository:

  • DomainToolsCheckLastEnrichment
  • DomainToolsSetIndicatorTable

Custom indicator fields: The playbook uses the following custom fields in the indicator table to store DomainTools intelligence in Palo Alto XSOAR. Create these fields before you execute the playbook:

  1. Select Settings > Advanced > Fields
  2. Select Indicator from the dropdown list
  3. Add new fields per the following table:
Field nameField typeMandatory
additionalWhoisEmailsShort textNo
domainAgeShort textNo
emailDomainsShort textNo
ipAddressesShort textNo
mailServersShort textNo
nameServersShort textNo
soaEmailShort textNo
spfRecordShort textNo
sslCertificateShort textNo
  1. The same fields appear in an indicator table after you create them successfully

View on GitHub

The DomainTools_Iris_Tags playbook checks domains against a list of Iris tags and can raise an incident’s severity when a tag matches. It:

  • Lets you configure a list of Iris tags to monitor in Palo Alto XSOAR
  • Automates checking for any indicators that match one of the tags
  • Escalates the incident severity to ‘High’

Create tags in DomainTools Iris: To use this feature, create tags in DomainTools Iris. After you tag a domain in Iris, the tags become available in Palo Alto XSOAR. For more information, see “Tagging domains” in the Iris Investigate user guide.

Automation scripts: The playbook uses the DomainToolsCheckTags script, which is available for download in the scripts folder of the same repository.

Custom tag list: Palo Alto XSOAR users can store the list of tags inside Palo Alto XSOAR by following these steps:

  1. Select Settings > Advanced > Lists > New List
  2. Set values:
    • Name: tags
    • Data: Your comma-delimited list of tags

Enriches domain-related data from the Iris dataset, including domain risk scores, WHOIS, IP, active DNS, website, and SSL data. Enables rapid enrichment of proxy and DNS logs, enhancing the ability to detect and respond to threats in real-time. You can identify malicious domains and assess their risk levels efficiently.

Query DomainTools for DNS intelligence for a specific indicator:

!domain domain="example.com"
!domaintoolsiris-analytics domain="example.com"

Risk scores, threat profiles, and evidence

Section titled “Risk scores, threat profiles, and evidence”
!domaintoolsiris-threat-profile domain=example.com

Pivot on any of the following DomainTools attributes to discover potentially malicious infrastructure associated with the DNS artifact:

  • IP
  • Email
  • Mailserver_Host
  • Nameserver_Host
  • Nameserver_IP
  • SSL Hash

For example, a pivot on the hosting IP address:

!domaintoolsiris-pivot ip="199.79.62.18"

Retrieve latest results for Newly Observed Domains (NOD) Threat Feed

Section titled “Retrieve latest results for Newly Observed Domains (NOD) Threat Feed”
!dtfeeds-get-indicators session_id=mysession feed_type=nod