Azure-Sentinel/Solutions/Farsight DNSDB/Playbooks/DNSDB_Co_Located_IP_Address
Rambatla Venkat Rao f6ad7bb56f
Removed locals from the links
2021-11-18 11:25:55 +05:30
..
Graphics Farsight DNSDB Playbook Templates - Initial Commit 2021-10-08 14:56:23 +05:30
azuredeploy.json Removed locals from the links 2021-11-18 11:25:55 +05:30
readme.md Update readme.md 2021-10-08 15:13:52 +05:30

readme.md

DNSDB_Co_Located_IP_Address

author: Henry Stern, Farsight Security, Inc.

This playbook uses the Farsight DNSDB connector to automatically enrich IP Addresses found in the Sentinel incidents. This lookup will identify all the IPs that are co-located (based on Domain) based on the on the input of a IP Address. This would be set of IPs that also shared the same Domain as the originating IP address. Learn more about the integration via the https://docs.microsoft.com/connectors/farsightdnsdb/ or visit https://www.farsightsecurity.com/about-farsight-security/contacts/ to request a trial key.

Screenshots

Incident Comments

Deploy to Azure

Deploy to Azure Gov