Skip to content

Splunk Enterprise app Iris Detect

Use the Iris Detect page to triage new and changed domains that match your Iris Detect monitored terms, and to keep the Iris Detect Watch List in sync with your Splunk Monitoring List.

The following filters and actions are available to modify the results available in the table:

  • Time range
    • Choose between minutes, hours, or days to gather historical results from
  • Monitored Term
    • Select from a list of your monitors to display results from
  • Type
    • Choose between New domains, Watched domains from the Iris Detect Watch List, or Ignored domains
  • Automatic Sync
    • Choose between Enabled or Disabled to change whether actions affect the Iris Detect Watch List
  • Sync Splunk Monitoring List and Iris Detect Watch List
    • Manually sync the two lists
  • Refresh Iris Detect Results
    • Manually refresh the Iris Detect results visible in the table

Selecting the option for Automatic Sync adds and removes watched domains on an automatic schedule based on the Sync Iris Detect Watchlist saved search. The default schedule is every day. Sync Splunk Monitoring List and Iris Detect Watch List performs the sync on a one-time basis.

When new domains are discovered for the Enabled Monitors Terms, they are added in the results table with these fields. Click a field heading to sort.

DomainActMonitored TermTLDCountry CodeISPRisk ScoreRisk Score StatusFirst SeenLast UpdatedRegistrar NameIP AddressName ServerMail Server

The columns describe each discovered domain:

  • Domain: The full domain name including TLD.
  • TLD: The top-level domain for the domain.
  • Country Code: The country code where the domain is registered.
  • ISP: The Internet Service Provider associated with the IP address used by the domain.
  • Risk Score: The DomainTools Risk Score.
  • Risk Score Status: Whether the scoring is provisional or full. Newly discovered domains have initial proximity or phishing scores within a few minutes, and the score is provisional. Full risk scoring (across all four algorithms, including malware and spam) is typically available within 15-20 minutes of discovery. Risk scores are also updated when significant changes are detected to a domain’s DNS records or other attributes. All active domains continue to be scored daily.
  • First Seen (Lifecycle First Seen): The date and time that DomainTools learned a domain is likely active, or reactivated after going inactive.
  • Last Updated: The date Iris Detect last observed any changes to the DNS or WHOIS attributes associated with the domain.
  • IP Address: The numerical address that the domain name resolves to.
  • Name Server: The server that translates a domain name into its numerical IP address.
  • Mail Server: The server that handles emails sent to the domain.

The Act column helps triage discovered domains with the following actions:

  • Add to the Iris Detect Watchlist: Adds the listed domain to the Iris Detect Watchlist, which provides alerts on changes to these domains if hosting infrastructure or webpage changes are seen. The Iris Detect Watchlist can optionally be synchronized with the Splunk Monitoring list.
  • Add to the Detect Blocklist API: Marks the domain for blocking. The blocking designation is transmitted through the Iris Detect APIs.
  • Escalate to Google Phishing Protection: Domains can be sent to Google’s Phishing Protection team. If Google agrees the domain is malicious, it is blocked in Chrome browsers globally. This list is also picked up by Safari and Firefox.
  • Add to the Splunk Monitoring List: Adds the listed domain to the Monitored Domains List within the DomainTools Splunk App. This can enable detection and alerting if the domain is seen within your monitored log sources.
  • Ignore This Domain: If a domain is a false positive, ignoring the domain removes it from the “new” list on the next refresh. Watched domains can be ignored if they are no longer of interest for change tracking.
  • View Domain Profile: Load the Domain Profile page within Splunk, pulling up the Iris Investigate results for the listed domain.
  • Farsight pDNS Search: Run a Farsight pDNS Standard Search (if provisioned) in DNSDB for RRNames containing the listed domain. This is useful for finding any active subdomains as well as seeing the dates when a domain has been active based on DNS traffic observed on Farsight SIE.

This page shows all of the Iris Detect monitored terms on your account. You can configure this list of terms on the Iris Detect webpage. Make sure that the DomainTools - Import Iris Detect Monitors and DomainTools - Import Iris Detect Results saved searches are enabled (DT Settings > Configure Saved Searches).

Refresh the list of monitored terms in one of three ways:

  1. Set the Refresh Monitored Terms value to be either daily, weekly, or never and choose submit.
  2. Select the Refresh Now button on the Iris Detect Monitored Terms page to import any new terms.
  3. In DT Settings > Configured Saved Searches assign an update frequency on the DomainTools - Import Iris Detect Monitors saved search to sync daily or weekly.

Iris Detect Monitored Terms:

TermMonitor Creation DateCreated ByMonitor Last Updated In SplunkIngest Daily Detections in Splunk
  • Import Daily Detections in Splunk: Select the terms to import Iris Detect-monitored domains into Splunk so they show up on the Monitoring → Iris Detect Dashboard page.

Note that the DomainTools Iris Detect API is limited to an hourly refresh frequency.

  • Iris Enrich — monitor detected domains alongside your other enrichment data
  • Iris Investigate — pull a full Iris Investigate profile for a detected domain
  • DT Settings — enable the Iris Detect saved searches and sync the Watch List