HostIo
This Integration is part of the HostIo Pack.#
Supported versions
Available on Cortex XSOAR and Cortex XSIAM.
Use the HostIo integration to enrich domains using the Host.io API. This integration was integrated and tested with version 1.0 of HostIo
Configure HostIo in Cortex#
| Parameter | Required |
|---|---|
| Server URL (e.g. https://host.io) | True |
| API Key | True |
| Trust any certificate (not secure) | False |
| Use system proxy settings | False |
Commands#
You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
hostio-domain-search#
Returns a list of domains associated with a specific field, and the total number of these domains.
Base Command#
hostio-domain-search
Input#
| Argument Name | Description | Required |
|---|---|---|
| field | Field name by which to search for a domain. Possible values are: ip, ns, mx, asn, backlinks, redirects, adsense, facebook, twitter, instagram, gtm, googleanalytics, email. | Required |
| value | The value of the given field. | Required |
| limit | The maximum number of domains to display. Possible values are 0, 1, 5, 10, 25, 100, 250, or 1000. Default is 25. | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| HostIo.Search.Field | String | The field to look up. |
| HostIo.Search.Value | String | The value of the given field. |
| HostIo.Search.Domains | Unknown | List of domains associated with the given field. |
| HostIo.Search.Total | Number | The total number of domains associated with the given field. |
Command Example#
!hostio-domain-search field="twitter" value="elonmusk"
Context Example#
Human Readable Output#
Domains associated with twitter: elonmusk#
domains total dogedoor.net,
ridesharehouston.org,
a2ch.ru,
elon-airdrop.org,
selenianboondocks.com356 elonmusk
domain#
Returns Domain information.
Base Command#
domain
Input#
| Argument Name | Description | Required |
|---|---|---|
| domain | List of domains. | Required |
Context Output#
| Path | Type | Description |
|---|---|---|
| HostIo.Domain.web.rank | Number | A rank that's based on popularity. |
| HostIo.Domain.web.server | String | Name of the server where the domain exists. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| Domain.Name | String | The domain name. |
| Domain.Registrant.Name | String | The name of the registrant. |
| Domain.Registrant.Country | String | The country of the registrant. |
| Domain.UpdatedDate | Date | The date when the domain was last updated in ISO8601 format (i.e. '2020-04-30T10:35:00.000Z'). |
| Domain.NameServers | String | Name of the server where the domain exist. |
Command Example#
!domain domain="twitter.com"
Context Example#
Human Readable Output#
Domain#
dns domain ipinfo related updated_date web domain: twitter.com
a: 104.244.42.1,
104.244.42.193
mx: 10 aspmx.l.google.com.,
20 alt1.aspmx.l.google.com.,
20 alt2.aspmx.l.google.com.,
30 aspmx2.googlemail.com.,
30 aspmx3.googlemail.com.
ns: a.r06.twtrdns.net.,
b.r06.twtrdns.net.,
c.r06.twtrdns.net.,
d.r06.twtrdns.net.,
d01-01.ns.twtrdns.net.,
d01-02.ns.twtrdns.net.,
ns1.p34.dynect.net.,
ns2.p34.dynect.net.,
ns3.p34.dynect.net.,
ns4.p34.dynect.net.twitter.com 104.244.42.6: {"city": "San Francisco", "region": "California", "country": "US", "loc": "37.7749,-122.4194", "postal": "94103", "timezone": "America/Los_Angeles", "asn": {"asn": "AS13414", "name": "Twitter Inc.", "domain": "twitter.com", "route": "104.244.42.0/24", "type": "business"}}
104.244.42.1: {"city": "San Francisco", "region": "California", "country": "US", "loc": "37.7749,-122.4194", "postal": "94103", "timezone": "America/Los_Angeles", "asn": {"asn": "AS13414", "name": "Twitter Inc.", "domain": "twitter.com", "route": "104.244.42.0/24", "type": "business"}}
104.244.42.193: {"city": "San Francisco", "region": "California", "country": "US", "loc": "37.7749,-122.4194", "postal": "94103", "timezone": "America/Los_Angeles", "asn": {"asn": "AS13414", "name": "Twitter Inc.", "domain": "twitter.com", "route": "104.244.42.0/24", "type": "business"}}ip: {'value': '104.244.42.6', 'count': 92624},
{'value': '104.244.42.1', 'count': 51},
{'value': '104.244.42.193', 'count': 52}
asn: {'value': 'AS13414', 'count': 392693}
ns: {'value': 'twtrdns.net', 'count': 118},
{'value': 'dynect.net', 'count': 181297}
mx: {'value': 'google.com', 'count': 13977803},
{'value': 'googlemail.com', 'count': 5288687}
backlinks: {'value': 'twitter.com', 'count': 18707958}
redirects: {'value': 'twitter.com', 'count': 389612}2020-11-25T20:10:08Z domain: twitter.com
rank: 5
url: https://mobile.twitter.com/signup
ip: 104.244.42.6
date: 2020-11-25T20:10:08.708Z
length: 4170
server: tsa_a
encoding: utf8
twitter: signup
title: Twitter
links: