↳ Source GitHubSolution

DomainTools CCF

Description

The [Domaintools Threat Intelligence Feeds](https://www.domaintools.com/products/threat-intelligence-feeds/) solution for Microsoft Sentinel contains CCF-based data connector that ingests domain-related threat intelligence from Domain tools including Newly Observed Domains (NOD), Newly Observed Hostnames (NOH), Newly Active Domains (NAD), and Domain Discovery. The solution also provides an analytic rule that automatically creates incidents when new domains are ingested, enabling security teams to quickly detect and investigate potentially malicious domains. In addition, a workbook is included to visualize domain activity, ingestion trends, and correlations with security telemetry, helping SOC analysts improve threat detection and response.
Version
3.0.0
Auteur / éditeur déclaré
DomainTools - memberservices@domaintools.com
Niveau de support
Partner

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
azure-sentinel-solution-domaintools-threatintel
Autres fichiers source 2Solutions/DomainTools CCF/Data/Solution_DomainTools.jsonsolution-manifest ↗Solutions/DomainTools CCF/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.