Skip to content

Microsoft Sentinel: DomainTools Apps

Microsoft Sentinel is Microsoft’s Security Information and Event Management (SIEM) product. It includes integrated playbooks to help you develop your Security Orchestration, Automation and Response (SOAR) applications.

DomainTools offers three Logic Apps for Microsoft Sentinel that are designed to work independently or together to provide comprehensive domain intelligence and threat detection capabilities.

IntegrationPurposeKey FeaturesRate Limit
Iris InvestigateDeep investigation of indicatorsWhois, DNS, SSL, related infrastructure, guided pivots20 requests/min
Iris EnrichHigh-volume enrichmentFast domain enrichment with risk context60 requests/min
Farsight DNSDBPassive DNS lookupsHistorical DNS infrastructure dataPer quota

All DomainTools integrations for Microsoft Sentinel require:

  • A Microsoft Power Apps or Power Automate plan with custom connector feature
  • An Azure subscription
  • Active DomainTools API credentials (specific to each product) — see Authentication
  1. Choose your integration: Review the table above to determine which integration(s) meet your needs
  2. Verify prerequisites: Ensure you have the required Azure subscriptions and API credentials
  3. Follow the installation guide: Each integration has detailed installation instructions
  4. Configure playbooks: Install and configure reference playbooks for automated enrichment
  5. Set permissions: Grant Logic Apps the necessary permissions to interact with Sentinel

All integrations follow a similar installation pattern:

  1. Install from Azure Marketplace or Sentinel Content Hub
  2. Configure API connections with your DomainTools credentials
  3. Install reference playbooks
  4. Grant Microsoft Sentinel Responder permissions to Logic Apps
  5. Configure automation rules to trigger playbooks

For detailed installation instructions, see the individual integration guides.