This playbook enables ArcSight SOAR to perform a Reverse IP Lookup via DomainTools, allowing analysts to discover all known domains hosted on a particular IP address. This is valuable in threat-hunting, phishing campaigns, and infrastructure mapping where attackers may reuse infrastructure across multiple malicious domains.
The playbook includes an analyst decision point to confirm whether reverse lookup is necessary before performing the enrichment. If approved, the playbook fetches both gTLD and known ccTLD domains hosted on the IP.
This playbook enables ArcSight SOAR to perform a Reverse IP Lookup via DomainTools, allowing analysts to discover all known domains hosted on a particular IP address. This is valuable in threat-hunting, phishing campaigns, and infrastructure mapping where attackers may reuse infrastructure across multiple malicious domains.
The playbook includes an analyst decision point to confirm whether reverse lookup is necessary before performing the enrichment. If approved, the playbook fetches both gTLD and known ccTLD domains hosted on the IP.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox