Explore our library of thought leadership articles and insights.
Podcasts
Stream informative and exclusive episodes of DomainTools “Breaking Badness” podcast.
Research
Read the latest from DomainTools Investigations.
Webinars
Watch live and on-demand cybersecurity training from the DomainTools team.
White Papers
Discover the real-world impact of DomainTools DNS intelligence.
Client Resources
Technical Documentation
Navigate DomainTools features effortlessly with our comprehensive guides.
API Documentation
Access everything you need, including endpoint, response formats, sample queries, and product service levels.
Webinars
Through close partnerships with leading security vendors, DomainTools embeds our best-in-class domain profiles and predictive Risk Score directly within your preferred SIEM, SOAR, and TIP solutions.
Watch Now
Company
About
Meet our exceptional executive team of experts and industry leaders.
Careers
Join Our Team
Pressroom
Access the latest DomainTools news and press coverage.
Contact
We’re here to help with product info, pricing, and current and future account services.
The DomainTools® App within Splunk SOAR enables you to block domain names based on Domain Risk Score, identify malicious connected infrastructure, and pivot within playbooks.
Learn More about
Splunk SOAR
Precisely Target Alerts and Hunt Threats Across Your Enterprise
Enhance Your Playbooks
Use Domain Risk Score to predict how likely a domain is to be malicious and take automated actions informed by the severity and classification of the threat
Leverage domain name and IP address Whois lookups in ad-hoc actions on events
Make automated decisions in playbooks to enrich a Splunk event with connected domains and even block them proactively
Add domain name profiles, ownership history and hosting history automatically in any Splunk playbook
Discover how many domains share an identity, a name server, or a hosting IP
Find recently registered domains that match a keyword
Automate Your Playbooks
Speed incident handling by ensuring analysts have everything they need to triage an event
Avoid context switching and preserve important artifacts in an event context
Efficiently execute the best analyst workflows with no manual interventions
Take targeted action on risky domains informed by machine learning classifiers