Document toolboxDocument toolbox

threatintel.domaintools

Introduction

The tags beginning with threatintel.domaintools identify events generated by DomainTools Iris platform belonging to DomainTools.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as threatintel.domaintools and the third identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

DomainTools Iris platform

threatintel.domaintools.whois

threatintel.domaintools.whois

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

threatintel.domaintools.whois

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

rawMessage

str

 

✓

host

str

vhost

 

serverdate

str

 

 

search_name

str

 

 

search_now

timestamp

 

 

info_min_time

timestamp

 

 

info_max_time

timestamp

 

 

info_search_time

timestamp

 

 

admin_country

str

 

 

admin_email

str

 

 

domain

str

 

 

nameservers

str

 

 

registrant

str

 

 

registrant_country

str

 

 

registrant_email

str

 

 

registrant_org

str

 

 

registrar

str

 

 

risk_score

float8

 

 

technical_country

str

 

 

technical_email

str

 

 

created

timestamp

 

 

expires

timestamp

 

 

updated

timestamp

 

 

retrieved

timestamp

 

 

message

str

rawMessage

 

hostchain

str

 

✓

tag

str

 

✓