What is DomainTools?
DomainTools's flagship Iris Intelligence Platform is an Internet intelligence solution designed to help users find out if a domain name is risky, who's behind it, and what other cyber-assets are associated with it.
The platform includes:
The platform includes:
- Iris Investigate - A combination of enterprise-grade domain intelligence and risk scoring with passive DNS data. A web interface and corresponding APIs query these data sources to help security teams investigate potential cybercrime and cyberespionage.
- Iris Detect - An Internet infrastructure detection, monitoring, and enforcement tool (UI and API) built on DomainTools' domain discovery engine and databases of domain data. Capturing key data on new domains and risk-scoring them within minutes of discovery, Detect supports brand managers, digital risk and fraud prevention teams, and network defenders.
- Iris Enrich - The DomainTools Iris data set helps analysts, detection engineering teams, threat hunters, and other practitioners obtain critical situational awareness on domains or IP addresses observed in the protected environment. Whois, DNS, SSL certificate, and risk scoring elements help build out the needed context for the appropriate disposition of indicators. Iris Enrich APIs are REST-based and OpenAPI compatible, making it easy to incorporate into internal tools.
DomainTools acquired Farsight Security in 2021. The company's DNSDB is a Passive DNS historical database that provides a fact-based, multifaceted view of the configuration of the global Internet infrastructure. DNSDB leverages Farsight’s Security Information Exchange (SIE) data-sharing platform and is engineered and operated by DNS experts. And with the search function introduced in DNSDB 2.0, analysts can apply regular expressions, making this resource more versatile and powerful.
Categories & Use Cases
Technical Details
| Mobile Application | No |
|---|
FAQs
What is Iris Intelligence Platform?
DomainTools offers the Iris Intelligence Platform, an Internet intelligence solution designed to help users find out if a domain name is risky, who's behind it, and what other cyber-assets are associated with it.




