↳ GitHub sourceSolution

DomainTools CCF

Description

The [Domaintools Threat Intelligence Feeds](https://www.domaintools.com/products/threat-intelligence-feeds/) solution for Microsoft Sentinel contains CCF-based data connector that ingests domain-related threat intelligence from Domain tools including Newly Observed Domains (NOD), Newly Observed Hostnames (NOH), Newly Active Domains (NAD), and Domain Discovery. The solution also provides an analytic rule that automatically creates incidents when new domains are ingested, enabling security teams to quickly detect and investigate potentially malicious domains. In addition, a workbook is included to visualize domain activity, ingestion trends, and correlations with security telemetry, helping SOC analysts improve threat detection and response.
Version
3.0.0
Declared author / publisher
DomainTools - memberservices@domaintools.com
Support tier
Partner

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-domaintools-threatintel
Additional source files 2Solutions/DomainTools CCF/Data/Solution_DomainTools.jsonsolution-manifest ↗Solutions/DomainTools CCF/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.