XTM Hub by Filigran
DNSlytics logo

DNSlytics

Déploiement automatique
Supporté par la communauté
Infrastructure & Attack Surface Visibility
FIMI & Disinformation

Aperçu

Run DNSlytics domain searches stored as Indicators and ingest the matching domains with their IPs, AS and hosting provider.

Run DNSlytics domain searches from OpenCTI. A hunting rule is stored as an Indicator with pattern type dnslytics and the search query as its pattern, for example (name:*daily* OR name:*news*) AND (name:*armenia*). Enriching the Indicator makes one DNSlytics dataset/domains call (10 credits, first page, up to 1,000 domains) and creates one Domain-Name per hit, linked by Indicator based-on Domain-Name and labelled dnslytics:active or dnslytics:dropped. For active domains, the connector resolves the IPs (DNS), looks up the announcing Autonomous System (DNSlytics IP2ASN, free) and adds a provider:<AS name> label, so a widget or filter shows which hosting providers a campaign uses. The connector registers the dnslytics pattern type in OpenCTI at start-up and works in playbooks.

Informations de base

DNSlytics
Contact vendeur
Connecteurs
7.261002.0
0

    Nous utilisons des cookies pour assurer le fonctionnement de XTM Hub. Les cookies nécessaires sont toujours activés ; les cookies facultatifs (fonctionnels, d'analyse, de marketing) ne sont utilisés qu'avec votre consentement. Vous pouvez accepter tous les cookies, les refuser tous ou gérer vos préférences à tout moment dans la rubrique « Paramètres des cookies ».