Azure-Sentinel/Solutions/Farsight DNSDB/Playbooks/DNSDB_Co_Located_Hosts
Rambatla Venkat Rao 4bcef8a872
Removed locale from the links
2021-11-18 11:25:12 +05:30
..
Graphics Farsight DNSDB Playbook Templates - Initial Commit 2021-10-08 14:56:23 +05:30
azuredeploy.json Removed locale from the links 2021-11-18 11:25:12 +05:30
readme.md Update readme.md 2021-10-08 15:09:04 +05:30

readme.md

DNSDB_Co_Located_Hosts

author: Henry Stern, Farsight Security, Inc.

This playbook uses the Farsight DNSDB connector to automatically enrich Domain's found in the Sentinel incidents. This use case describes the desire to easily identify Hosts that are co-located (based on Address) based on the input of a Host and a given point in time. The response would be a set of domains that also shared the same IP address as the originating domain name at the given point in time. Learn more about the integration via the https://docs.microsoft.com/connectors/farsightdnsdb/ or visit https://www.farsightsecurity.com/about-farsight-security/contacts/ to request a trial key.

Screenshots

Incident Comments

Deploy to Azure

Deploy to Azure Gov