Skip to main content

Infoblox Threat Defense with DDI

This Integration is part of the Infoblox Threat Defense with DDI Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.5.0 and later) and Cortex XSIAM.

Infoblox Threat Defense with DDI integration leverages DNS as the first line of defense to detect and block cyber threats, while also using threat intelligence to manage IQ for TD Insight incident response and enrich indicators. This integration was integrated and tested with version 1.0.0 of Infoblox Threat Defense with DDI.

Configure Infoblox Threat Defense with DDI in Cortex#

ParameterDescriptionRequired
Service API KeyTrue
Source ReliabilityReliability of the source providing the intelligence data.False
Create relationshipsCreate relationships between indicators as part of Enrichment.False
Fetch incidentsFalse
Incident typeFalse
Ingestion TypeSelect the ingestion type to fetch as Cortex XSOAR incident. Default is IQ for TD Insight. 'SOC Insight' is deprecated.False
IQ for TD Insight StatusRetrieve the IQ for TD Insights matching the specified workflow status.False
IQ for TD Insight SeverityRetrieve the IQ for TD Insights matching the specified severity.False
IQ for TD Insight Threat PropertiesRetrieve the IQ for TD Insights matching the specified threat properties (free text), e.g. malware, phishing, ransomware.False
Deprecated - SOC Insight StatusRetrieve the SOC Insights as specified status.False
Deprecated - SOC Insight Threat TypeRetrieve the SOC Insights as specified threat type.False
Deprecated - SOC Insight Priority LevelRetrieve the SOC Insights as specified priority level.False
DNS Security Event Feed NameRetrieve the DNS Security Events as specified feed name or custom list name.False
DNS Security Event NetworkRetrieve the DNS Security Events as specified network name.False
DNS Security Event Policy ActionRetrieve the DNS Security Events as specified policy action.False
DNS Security Event Policy NameRetrieve the DNS Security Events as specified policy name.False
DNS Security Event Queried NameRetrieve the DNS Security Events as specified queried name.False
DNS Security Event Threat ClassRetrieve the DNS Security Events as specified threat class.False
DNS Security Event Threat FamilyRetrieve the DNS Security Events as specified threat family.False
DNS Security Event Threat IndicatorRetrieve the DNS Security Events as specified threat indicator.False
DNS Security Event Threat LevelRetrieve the DNS Security Events as specified threat level.False
Max FetchThe maximum number of SOC Insights, DNS Security Events, or IQ for TD Insights to fetch each time. If the value is greater than 200, it will be considered as 200. The maximum is 200. Default is 50.False
First fetch timestampThe date or relative timestamp from which to begin fetching incidents.

Note: This parameter is only applicable for DNS Security Events and IQ for TD Insights. Default is '24 hours'.

Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

For example: 01 May 2025, 01 May 2025 04:45:33, 2025-05-17T14:05:44Z.
False
Incidents Fetch IntervalFalse
Trust any certificate (not secure)False
Use system proxy settingsFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

bloxone-td-dossier-lookup-get#


The Dossier Lookup API returns detailed information on the specified indicator from the requested sources.

Base Command#

bloxone-td-dossier-lookup-get

Input#

Argument NameDescriptionRequired
indicator_typeThe type of indicator to search by. Possible values are: host, ip, url, hash, email.Required
valueThe indicator to search on.Required
sourcesThe sources to query. Multiple sources can be specified. If no source is specified, the call will search on all available sources. (You can see the list of the available sources by running bloxone-td-dossier-source-list).Optional
interval_in_secondsThe interval in seconds between each poll. Default is 10.Optional
timeoutThe timeout in seconds until polling ends. Default is 600.Optional
job_idused for polling.Optional

Context Output#

PathTypeDescription
BloxOneTD.DossierLookup.sourceStringThe Dossier source.
BloxOneTD.DossierLookup.targetStringThe targeted indicator.
BloxOneTD.DossierLookup.task_idStringThe Dossier task ID.
BloxOneTD.DossierLookup.typeStringThe indicator type.

Command example#

!bloxone-td-dossier-lookup-get indicator_type="ip" value="11.22.33.44" sources="activity,threatfox,ccb"

Context Example#

{
"BloxOneTD": {
"DossierLookup": [
{
"params": {
"source": "ccb",
"target": "11.22.33.44",
"type": "ip"
},
"status": "success",
"task_id": "97bdeca2-b66d-47b1-b1ef-9e4833654df2",
"time": 6401,
"v": "3.0.0"
},
{
"data": {
"impacted_devices": [],
"requests_by_day": []
},
"params": {
"source": "activity",
"target": "11.22.33.44",
"type": "ip"
},
"status": "success",
"task_id": "4074cb34-2bec-485d-8d6d-9e9cc88d5229",
"time": 1708,
"v": "3.0.0"
},
{
"data": {
"matches": []
},
"params": {
"source": "threatfox",
"target": "11.22.33.44",
"type": "ip"
},
"status": "success",
"task_id": "73892ea3-1e22-433f-bc74-f59133b914d0",
"time": 8,
"v": "3.0.0"
}
]
}
}

Human Readable Output#

Lookalike Domain List#

Task IdTypeTargetSource
d418b8d6-831c-4f6f-a31a-6d48995d2267ip11.22.33.44threatfox
91945be3-0cef-4d03-afd7-e4f25864553dip11.22.33.44ccb
7145a1ca-40a9-43df-b0a3-c4281e5abd7eip11.22.33.44activity

bloxone-td-dossier-source-list#


Get available Dossier sources.

Base Command#

bloxone-td-dossier-source-list

Input#

There are no input arguments for this command.

Context Output#

PathTypeDescription
BloxOneTD.DossierSourceStringAvailable Dossier sources.

Command example#

!bloxone-td-dossier-source-list

Context Example#

{
"BloxOneTD": {
"DossierSource": [
"ccb",
"activity",
"geo",
"threatfox"
]
}
}

Human Readable Output#

Results#

DossierSource
activity
ccb
geo
threatfox

bloxone-td-lookalike-domain-list#


Get lookalike domain lists.

Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.

Base Command#

bloxone-td-lookalike-domain-list

Input#

Argument NameDescriptionRequired
filterThe free query filter argument.Optional
target_domainFilter by target domain.Optional
detected_atFilter by values that are greater than or equal to the given value. You can use ISO format (e.g. '2023-02-14T00:11:22Z') or use a relative time (e.g. "3 days").Optional
limitMaximum number of results to return from the query. Default is 50.Optional
offsetReturn results starting at this offset. Should be an integer. Default is 0.Optional

Context Output#

PathTypeDescription
BloxOneTD.LookalikeDomain.detected_atDateThe date of the lookalike detection.
BloxOneTD.LookalikeDomain.lookalike_domainStringThe lookalike domain.
BloxOneTD.LookalikeDomain.lookalike_hostStringThe lookalike host.
BloxOneTD.LookalikeDomain.reasonStringThe reason for the detection.
BloxOneTD.LookalikeDomain.target_domainStringThe domain that was targeted by the lookalike domain.

Command example#

!bloxone-td-lookalike-domain-list detected_at="1y"

Context Example#

{
"BloxOneTD": {
"LookalikeDomain": [
{
"detected_at": "2023-01-27T18:43:01Z",
"lookalike_domain": "test.a.com",
"lookalike_host": "test.a.com",
"reason": "Domain is a lookalike to test.com. The creation date is 2023-01-22.",
"target_domain": "test.com"
},
{
"detected_at": "2023-01-28T18:36:27Z",
"lookalike_domain": "test.b.com",
"lookalike_host": "test.b.com",
"reason": "Domain is a lookalike to test.com and has suspicious registration, behavior, or associations with known threats. The creation date is 2022-11-30.",
"suspicious": true,
"target_domain": "test.com"
},
{
"detected_at": "2023-01-28T18:37:03Z",
"lookalike_domain": "test.c.com",
"lookalike_host": "test.c.com",
"reason": "Domain is a lookalike to test.com. The creation date is 2022-09-18.",
"target_domain": "test.com"
}
]
}
}

Human Readable Output#

Results#

Detected AtLookalike DomainLookalike HostReasonTarget Domain
2023-01-27T18:43:01Ztest.a.comtest.a.comDomain is a lookalike to test.com. The creation date is 2023-01-22.test.com
2023-01-28T18:36:27Ztest.b.comtest.b.comDomain is a lookalike to test.com and has suspicious registration, behavior, or associations with known threats. The creation date is 2022-11-30.test.com
2023-01-28T18:37:03Ztest.c.comtest.c.comDomain is a lookalike to test.com. The creation date is 2022-09-18.test.com

infobloxcloud-block-ip#


The given IP addresses will be added to the provided block list.

Base Command#

infobloxcloud-block-ip

Input#

Argument NameDescriptionRequired
ipSpecify the IP addresses to block. Supports comma-separated values.Required
custom_list_nameSpecify the name of the custom list to add the given IP addresses to. Default is Default Block.Optional
custom_list_typeSpecify the type of the custom list to add the given IP addresses to. Possible values are: default_block, custom_list, threat_insight, dga, dnsm, zero_day_dns, threat_insight_nde. Default is default_block.Optional

Context Output#

PathTypeDescription
InfobloxCloud.CustomList.idStringThe ID of the custom list.
InfobloxCloud.CustomList.nameStringThe name of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.itemsStringThe items in the custom list.
InfobloxCloud.CustomList.items_describedArrayThe items described in the custom list.
InfobloxCloud.CustomList.item_countNumberThe number of items in the custom list.
InfobloxCloud.CustomList.confidence_levelStringThe confidence level of the custom list.
InfobloxCloud.CustomList.created_timeStringThe time the custom list was created.
InfobloxCloud.CustomList.last_updated_timeStringThe time the custom list was last updated.
InfobloxCloud.CustomList.descriptionStringThe description of the custom list.
InfobloxCloud.CustomList.policiesStringThe policies of the custom list.
InfobloxCloud.CustomList.tagsStringThe tags of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.threat_levelStringThe threat level of the custom list.

Command example#

!infobloxcloud-block-ip ip=0.0.0.0

Context Example#

{
"InfobloxCloud": {
"CustomList": {
"confidence_level": "HIGH",
"created_time": "2024-04-01T18:24:37Z",
"description": "Auto-generated",
"id": 456789,
"item_count": 2,
"items": [
"0.0.0.0/32",
"0.0.0.1/32"
],
"items_described": [
{
"description": "",
"item": "0.0.0.0/32",
"status": "ACTIVE",
"status_details": ""
},
{
"description": "",
"item": "0.0.0.1/32",
"status": "ACTIVE",
"status_details": ""
}
],
"name": "Test Block",
"policies": [
"Test Policy"
],
"tags": {
"test_key": "test_value"
},
"threat_level": "MEDIUM",
"type": "test_block",
"updated_time": "2025-07-29T08:47:54Z"
}
}
}

Human Readable Output#

'0.0.0.0' indicators added to the 'Test Block' list#

IDNameTypeDescriptionItemsConfidence LevelThreat LevelTagsCreated TimeUpdated Time
792594Test Blocktest_blockAuto-generated0.0.0.0/32,
0.0.0.1/32
HIGHMEDIUMtest_key: test_value2024-04-01T18:24:37Z2025-07-29T08:47:54Z

infobloxcloud-unblock-ip#


The given IP addresses will be added to the provided allow list.

Base Command#

infobloxcloud-unblock-ip

Input#

Argument NameDescriptionRequired
ipSpecify the IP addresses to unblock. Supports comma-separated values.Required
custom_list_nameSpecify the name of the custom list to add the given IP addresses to. Default is Default Allow.Optional
custom_list_typeSpecify the type of the custom list to add the given IP addresses to. Possible values are: default_allow, custom_list, threat_insight, threat_insight_nde. Default is default_allow.Optional

Context Output#

PathTypeDescription
InfobloxCloud.CustomList.idStringThe ID of the custom list.
InfobloxCloud.CustomList.nameStringThe name of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.itemsStringThe items in the custom list.
InfobloxCloud.CustomList.items_describedArrayThe items described in the custom list.
InfobloxCloud.CustomList.item_countNumberThe number of items in the custom list.
InfobloxCloud.CustomList.confidence_levelStringThe confidence level of the custom list.
InfobloxCloud.CustomList.created_timeStringThe time the custom list was created.
InfobloxCloud.CustomList.last_updated_timeStringThe time the custom list was last updated.
InfobloxCloud.CustomList.descriptionStringThe description of the custom list.
InfobloxCloud.CustomList.policiesStringThe policies of the custom list.
InfobloxCloud.CustomList.tagsStringThe tags of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.threat_levelStringThe threat level of the custom list.

Command example#

!infobloxcloud-unblock-ip ip=0.0.0.0

Context Example#

{
"InfobloxCloud": {
"CustomList": {
"confidence_level": "HIGH",
"created_time": "2024-04-01T18:24:37Z",
"description": "Auto-generated",
"id": 123456,
"item_count": 2,
"items": [
"0.0.0.0/32",
"0.0.0.1/32"
],
"items_described": [
{
"description": "",
"item": "0.0.0.0/32",
"status": "ACTIVE",
"status_details": ""
},
{
"description": "",
"item": "0.0.0.1/32",
"status": "ACTIVE",
"status_details": ""
}
],
"name": "Test Allow",
"policies": [
"Test Policy"
],
"tags": {
"test_key": "test_value"
},
"threat_level": "MEDIUM",
"type": "test_allow",
"updated_time": "2025-07-29T08:48:02Z"
}
}
}

Human Readable Output#

'0.0.0.0' indicators added to the 'Test Allow' list#

IDNameTypeDescriptionItemsConfidence LevelThreat LevelTagsCreated TimeUpdated Time
123456Test Allowtest_allowAuto-generated0.0.0.0/32,
0.0.0.1/32
HIGHMEDIUMtest_key: test_value2024-04-01T18:24:37Z2025-07-29T08:48:02Z

infobloxcloud-block-domain#


The given domains will be added to the provided block list.

Base Command#

infobloxcloud-block-domain

Input#

Argument NameDescriptionRequired
domainSpecify the Domains to block. Supports comma-separated values.Required
custom_list_nameSpecify the name of the custom list to add the given domains to. Default is Default Block.Optional
custom_list_typeSpecify the type of the custom list to add the given domains to. Possible values are: default_block, custom_list, threat_insight, dga, dnsm, zero_day_dns, threat_insight_nde. Default is default_block.Optional

Context Output#

PathTypeDescription
InfobloxCloud.CustomList.idStringThe ID of the custom list.
InfobloxCloud.CustomList.nameStringThe name of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.itemsStringThe items in the custom list.
InfobloxCloud.CustomList.items_describedArrayThe items described in the custom list.
InfobloxCloud.CustomList.item_countNumberThe number of items in the custom list.
InfobloxCloud.CustomList.confidence_levelStringThe confidence level of the custom list.
InfobloxCloud.CustomList.created_timeStringThe time the custom list was created.
InfobloxCloud.CustomList.last_updated_timeStringThe time the custom list was last updated.
InfobloxCloud.CustomList.descriptionStringThe description of the custom list.
InfobloxCloud.CustomList.policiesStringThe policies of the custom list.
InfobloxCloud.CustomList.tagsStringThe tags of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.threat_levelStringThe threat level of the custom list.

Command example#

!infobloxcloud-block-domain domain="test.com"

Context Example#

{
"InfobloxCloud": {
"CustomList": {
"confidence_level": "HIGH",
"created_time": "2024-04-01T18:24:37Z",
"description": "Auto-generated",
"id": 456789,
"item_count": 2,
"items": [
"test.com",
"test.org"
],
"items_described": [
{
"description": "",
"item": "test.com",
"status": "ACTIVE",
"status_details": ""
},
{
"description": "",
"item": "test.org",
"status": "ACTIVE",
"status_details": ""
}
],
"name": "Test Block",
"policies": [
"Test Policy"
],
"tags": null,
"threat_level": "MEDIUM",
"type": "test_block",
"updated_time": "2025-07-29T10:27:49Z"
}
}
}

Human Readable Output#

'test.com' indicator added to the 'Test Block' list#

IDNameTypeDescriptionItemsConfidence LevelThreat LevelCreated TimeUpdated Time
456789Test Blocktest_blockAuto-generatedtest.com,
test.org
HIGHMEDIUM2024-04-01T18:24:37Z2025-07-29T10:27:49Z

infobloxcloud-unblock-domain#


The given domains will be added to the provided allow list.

Base Command#

infobloxcloud-unblock-domain

Input#

Argument NameDescriptionRequired
domainSpecify the Domains to unblock. Supports comma-separated values.Required
custom_list_nameSpecify the name of the custom list to add the given domains to. Default is Default Allow.Optional
custom_list_typeSpecify the type of the custom list to add the given domains to. Possible values are: default_allow, custom_list, threat_insight, threat_insight_nde. Default is default_allow.Optional

Context Output#

PathTypeDescription
InfobloxCloud.CustomList.idStringThe ID of the custom list.
InfobloxCloud.CustomList.nameStringThe name of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.itemsStringThe items in the custom list.
InfobloxCloud.CustomList.items_describedArrayThe items described in the custom list.
InfobloxCloud.CustomList.item_countNumberThe number of items in the custom list.
InfobloxCloud.CustomList.confidence_levelStringThe confidence level of the custom list.
InfobloxCloud.CustomList.created_timeStringThe time the custom list was created.
InfobloxCloud.CustomList.last_updated_timeStringThe time the custom list was last updated.
InfobloxCloud.CustomList.descriptionStringThe description of the custom list.
InfobloxCloud.CustomList.policiesStringThe policies of the custom list.
InfobloxCloud.CustomList.tagsStringThe tags of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.threat_levelStringThe threat level of the custom list.

Command example#

!infobloxcloud-unblock-domain domain="test.com"

Context Example#

{
"InfobloxCloud": {
"CustomList": {
"confidence_level": "HIGH",
"created_time": "2024-04-01T18:24:37Z",
"description": "Auto-generated",
"id": 123456,
"item_count": 2,
"items": [
"test.com",
"test.org"
],
"items_described": [
{
"description": "",
"item": "test.com",
"status": "ACTIVE",
"status_details": ""
},
{
"description": "",
"item": "test.org",
"status": "ACTIVE",
"status_details": ""
}
],
"name": "Test Allow",
"policies": [
"Test Policy"
],
"tags": {
"test_key": "test_value"
},
"threat_level": "MEDIUM",
"type": "test_allow",
"updated_time": "2025-07-29T10:27:56Z"
}
}
}

Human Readable Output#

'test.com' indicator added to the 'Test Allow' list#

IDNameTypeDescriptionItemsConfidence LevelThreat LevelTagsCreated TimeUpdated Time
123456Test Allowtest_allowAuto-generatedtest.com,
test.org
HIGHMEDIUMtest_key: test_value2024-04-01T18:24:37Z2025-07-29T10:27:56Z

infobloxcloud-customlist-indicator-remove#


The given indicators will be removed from the provided custom list.

Base Command#

infobloxcloud-customlist-indicator-remove

Input#

Argument NameDescriptionRequired
indicatorsSpecify the indicators to remove from the custom list. Format accepted is: "0.0.0.0, example.com".Required
custom_list_nameSpecify the name of the custom list to remove the given indicators from.Required
custom_list_typeSpecify the type of the custom list to remove the given indicators from. Possible values are: default_allow, default_block, custom_list, threat_insight, dga, dnsm, zero_day_dns, threat_insight_nde.Required

Context Output#

PathTypeDescription
InfobloxCloud.CustomList.idStringThe ID of the custom list.
InfobloxCloud.CustomList.nameStringThe name of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.itemsStringThe items in the custom list.
InfobloxCloud.CustomList.items_describedArrayThe items described in the custom list.
InfobloxCloud.CustomList.item_countNumberThe number of items in the custom list.
InfobloxCloud.CustomList.confidence_levelStringThe confidence level of the custom list.
InfobloxCloud.CustomList.created_timeStringThe time the custom list was created.
InfobloxCloud.CustomList.last_updated_timeStringThe time the custom list was last updated.
InfobloxCloud.CustomList.descriptionStringThe description of the custom list.
InfobloxCloud.CustomList.policiesStringThe policies of the custom list.
InfobloxCloud.CustomList.tagsStringThe tags of the custom list.
InfobloxCloud.CustomList.typeStringThe type of the custom list.
InfobloxCloud.CustomList.threat_levelStringThe threat level of the custom list.

Command example#

!infobloxcloud-customlist-indicator-remove indicators="0.0.0.0" custom_list_name="Test Allow" custom_list_type="test_allow"

Context Example#

{
"InfobloxCloud": {
"CustomList": {
"confidence_level": "HIGH",
"created_time": "2024-04-01T18:24:37Z",
"description": "Auto-generated",
"id": 123456,
"item_count": 1,
"items": [
"example.com"
],
"items_described": [
{
"description": "",
"item": "example.com",
"status": "ACTIVE",
"status_details": ""
}
],
"name": "Test Allow",
"policies": [
"Test Policy",
],
"tags": {
"test_key": "test_value"
},
"threat_level": "MEDIUM",
"type": "test_allow",
"updated_time": "2025-07-31T11:07:41Z"
}
}
}

Human Readable Output#

'0.0.0.0' indicators removed from the 'Test Allow' list#

IDNameTypeDescriptionItemsConfidence LevelThreat LevelTagsCreated TimeUpdated Time
123456Test Allowtest_allowAuto-generatedexample.comHIGHMEDIUMtest_key: test_value2024-04-01T18:24:37Z2025-07-31T11:07:41Z

ip#


Gets the comprehensive IP reputation and threat intelligence from Infoblox Threat Defense, including threat indicators, IPAM address information, and standard IP reputation data.

Base Command#

ip

Input#

Argument NameDescriptionRequired
ipIP(s) for which to retrieve reputation and threat intelligence. Supports comma-separated values.Required

Context Output#

PathTypeDescription
InfobloxCloud.IP.ipStringThe requested IP address.
IP.AddressStringIP address.
IP.Relationships.EntityAStringThe source of the relationship.
IP.Relationships.EntityBStringThe destination of the relationship.
IP.Relationships.RelationshipStringThe name of the relationship.
IP.Relationships.EntityATypeStringThe type of the source of the relationship.
IP.Relationships.EntityBTypeStringThe type of the destination of the relationship.
IP.ASNStringThe autonomous system name for the IP address, for example: "AS8948".
IP.HostnameStringThe hostname that is mapped to this IP address.
IP.Geo.LocationStringThe geolocation where the IP address is located, in the format: latitude:longitude.
IP.Geo.CountryStringThe country in which the IP address is located.
IP.Geo.DescriptionStringAdditional information about the location.
IP.DetectionEnginesNumberThe total number of engines that checked the indicator.
IP.PositiveDetectionsNumberThe number of engines that positively detected the indicator as malicious.
IP.Malicious.VendorStringThe vendor reporting the IP address as malicious.
IP.Malicious.DescriptionStringA description explaining why the IP address was reported as malicious.
IP.TagsUnknown(List) Tags of the IP address.
IP.FeedRelatedIndicators.valueStringIndicators that are associated with the IP address.
IP.FeedRelatedIndicators.typeStringThe type of the indicators that are associated with the IP address.
IP.FeedRelatedIndicators.descriptionStringThe description of the indicators that are associated with the IP address.
IP.MalwareFamilyStringThe malware family associated with the IP address.
IP.Organization.NameStringThe organization of the IP address.
IP.Organization.TypeStringThe organization type of the IP address.
IP.ASOwnerStringThe autonomous system owner of the IP address.
IP.RegionStringThe region in which the IP address is located.
IP.PortStringPorts that are associated with the IP address.
IP.InternalBooleanWhether the IP address is internal or external.
IP.UpdatedDateDateThe date that the IP address was last updated.
IP.Registrar.Abuse.NameStringThe name of the contact for reporting abuse.
IP.Registrar.Abuse.AddressStringThe address of the contact for reporting abuse.
IP.Registrar.Abuse.CountryStringThe country of the contact for reporting abuse.
IP.Registrar.Abuse.NetworkStringThe network of the contact for reporting abuse.
IP.Registrar.Abuse.PhoneStringThe phone number of the contact for reporting abuse.
IP.Registrar.Abuse.EmailStringThe email address of the contact for reporting abuse.
IP.CampaignStringThe campaign associated with the IP address.
IP.TrafficLightProtocolStringThe Traffic Light Protocol (TLP) color that is suitable for the IP address.
IP.CommunityNotes.noteStringNotes on the IP address that were given by the community.
IP.CommunityNotes.timestampDateThe time in which the note was published.
IP.Publications.sourceStringThe source in which the article was published.
IP.Publications.titleStringThe name of the article.
IP.Publications.linkStringA link to the original article.
IP.Publications.timestampDateThe time in which the article was published.
IP.ThreatTypes.threatcategoryStringThe threat category associated to this indicator by the source vendor. For example, Phishing, Control, TOR, etc.
IP.ThreatTypes.threatcategoryconfidenceStringThe confidence level provided by the vendor for the threat type category For example, a confidence of 90 for the threat type category 'malware' means that the vendor rates that this is 90% confidence of being a malware.
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
DBotScore.ScoreNumberThe actual score.
DBotScore.ReliabilityStringReliability of the source providing the intelligence data.
InfobloxCloud.IP.Threat.idStringThe unique identifier for the threat indicator.
InfobloxCloud.IP.Threat.typeStringThe type of threat indicator.
InfobloxCloud.IP.Threat.ipStringThe IP address identified as a threat indicator.
InfobloxCloud.IP.Threat.profileStringThe threat profile or classification source.
InfobloxCloud.IP.Threat.propertyStringThe specific property or category of the threat.
InfobloxCloud.IP.Threat.classStringThe classification of the threat.
InfobloxCloud.IP.Threat.threat_levelNumberThe numeric threat level score.
InfobloxCloud.IP.Threat.threat_labelStringThe textual threat level label.
InfobloxCloud.IP.Threat.expirationDateThe timestamp when the threat indicator will expire.
InfobloxCloud.IP.Threat.detectedDateThe timestamp when the threat activity was first detected.
InfobloxCloud.IP.Threat.receivedDateThe timestamp when the threat indicator was received by the system.
InfobloxCloud.IP.Threat.importedDateThe timestamp when the threat indicator was imported into the system.
InfobloxCloud.IP.Threat.upStringThe boolean status flag indicating whether the threat indicator is currently active.
InfobloxCloud.IP.Threat.batch_idStringThe batch ID of the threat indicator.
InfobloxCloud.IP.Threat.confidenceNumberThe numeric confidence score representing the reliability of the threat indicator.
InfobloxCloud.IP.Threat.extended.notesStringThe additional notes or information about the threat indicator.
InfobloxCloud.IP.Threat.threat_scoreNumberThe numeric score representing the calculated threat severity.
InfobloxCloud.IP.Threat.threat_score_ratingStringThe textual rating of the threat score.
InfobloxCloud.IP.Threat.threat_score_vectorStringThe vector string representing threat scoring details.
InfobloxCloud.IP.Threat.risk_scoreNumberThe numeric risk score assigned to the threat indicator.
InfobloxCloud.IP.Threat.risk_score_ratingStringThe textual rating of the risk score.
InfobloxCloud.IP.Threat.risk_score_vectorStringThe vector string representing risk scoring details.
InfobloxCloud.IP.Threat.confidence_scoreNumberThe numeric confidence score for the threat assessment.
InfobloxCloud.IP.Threat.confidence_score_ratingStringThe textual rating of the confidence score.
InfobloxCloud.IP.Threat.confidence_score_vectorStringThe vector string representing confidence scoring details.
InfobloxCloud.IP.Threat.extended.cyberint_guidStringThe unique identifier for the threat indicator.
InfobloxCloud.IP.Threat.extended.attack_chainStringThe attack chain associated with the threat indicator.
InfobloxCloud.IP.Threat.extended.extendedStringThe additional information or metadata associated with the threat indicator.
InfobloxCloud.IP.Threat.extended.protocolStringThe protocol associated with the threat indicator.
InfobloxCloud.IP.Threat.extended.referencesStringThe references associated with the threat indicator.
InfobloxCloud.IP.Threat.extended.threat_actorStringThe threat actor associated with the threat indicator.
InfobloxCloud.IP.Threat.extended.threat_actor_vectorStringThe vector string representing threat actor details.
InfobloxCloud.IP.Threat.extended.risk_scoreStringThe numeric risk score assigned to the threat indicator.
InfobloxCloud.IP.Threat.extended.threat_scoreStringThe numeric threat score assigned to the threat indicator.
InfobloxCloud.IP.Threat.extended.sample_sha256StringThe SHA-256 hash of the sample associated with the threat.
InfobloxCloud.IP.Threat.extended.original_profileStringThe original profile or classification source of the threat.
InfobloxCloud.IP.Address.addressStringThe IP address assigned to the resource.
InfobloxCloud.IP.Address.commentStringA user-provided comment or annotation for the address record.
InfobloxCloud.IP.Address.compartment_idStringThe compartment ID of the IP address.
InfobloxCloud.IP.Address.created_atDateThe timestamp when the IP address was created.
InfobloxCloud.IP.Address.dhcp_infoUnknownThe DHCP information associated with the IP address.
InfobloxCloud.IP.Address.disable_dhcpBooleanA boolean flag indicating whether DHCP is disabled for the IP address.
InfobloxCloud.IP.Address.discovery_attrsUnknownThe discovery attributes associated with the IP address.
InfobloxCloud.IP.Address.discovery_metadataUnknownThe discovery metadata associated with the IP address.
InfobloxCloud.IP.Address.external_keysUnknownExternal keys associated with the IP address.
InfobloxCloud.IP.Address.hostUnknownThe host name of the IP address.
InfobloxCloud.IP.Address.hwaddrStringThe hardware address of the IP address.
InfobloxCloud.IP.Address.idStringThe unique identifier of the IP address.
InfobloxCloud.IP.Address.interfaceStringThe interface of the IP address.
InfobloxCloud.IP.Address.namesUnknownThe names associated with the IP address.
InfobloxCloud.IP.Address.parentStringThe parent of the IP address.
InfobloxCloud.IP.Address.protocolStringThe protocol of the IP address.
InfobloxCloud.IP.Address.rangeStringThe range of the IP address.
InfobloxCloud.IP.Address.spaceStringThe space of the IP address.
InfobloxCloud.IP.Address.stateStringThe state of the IP address.
InfobloxCloud.IP.Address.tagsUnknownThe tags associated with the IP address.
InfobloxCloud.IP.Address.updated_atDateThe timestamp when the IP address was last updated.
InfobloxCloud.IP.Address.usageStringThe usage of the IP address.
InfobloxCloud.IP.Address.names.nameStringThe name of the IP address.
InfobloxCloud.IP.Address.names.typeUnknownThe type of the IP address.

Command example#

!ip ip="0.0.0.1"

Context Example#

{
"DBotScore": {
"Indicator": "0.0.0.1",
"Reliability": "A - Completely reliable",
"Score": 3,
"Type": "ip",
"Vendor": "InfobloxThreatDefensewithDDI"
},
"IP": {
"Address": "0.0.0.1",
"Description": "Malware Download associated with the APT group",
"ThreatTypes": [
{
"threatcategory": "IP",
"threatcategoryconfidence": "100"
}
],
"Hostname": "name",
"DetectionEngines": 1,
"Tags": [
"cyberint_guid: simple_cyberint_guid",
"notes: Malware Download associated with the APT group",
"Protocol: ip4",
"State: used",
"temp: true"
],
"MalwareFamily": "APT",
"Malicious": {
"Vendor": "InfobloxThreatDefensewithDDI",
"Description": "Malware Download associated with the APT group"
}
},
"InfobloxCloud": {
"IP": {
"ip": "0.0.0.1",
"Threat": {
"id": "00000000-0000-0000-0000-000000000000",
"type": "IP",
"ip": "0.0.0.1",
"profile": "IID",
"property": "APT_Malware",
"class": "APT",
"threat_level": 100,
"expiration": "2042-11-01T09:29:18.721Z",
"detected": "2025-07-29T09:29:18.721Z",
"received": "2025-07-29T09:31:39.329Z",
"imported": "2025-07-29T09:31:39.329Z",
"up": "true",
"confidence": 100,
"batch_id": "00000000-0000-0000-0000-000000000000",
"threat_score": 10,
"threat_score_rating": "Critical",
"threat_score_vector": "simple_threat_vector",
"risk_score": 9.9,
"risk_score_rating": "Critical",
"risk_score_vector": "simple_risk_vector",
"confidence_score": 0.1,
"confidence_score_rating": "Unconfirmed",
"confidence_score_vector": "simple_confidence_vector",
"extended": {
"cyberint_guid": "simple_cyberint_guid",
"notes": "Malware Download associated with the APT group"
}
},
"Address": {
"address": "0.0.0.1",
"comment": "comment",
"compartment_id": "00000000-0000-0000-0000-000000000000",
"created_at": "2025-06-27T13:07:21.476126Z",
"disable_dhcp": false,
"external_keys": {
"e3": "3e3"
},
"host": "ipam/host/00000000-0000-0000-0000-000000000000",
"hwaddr": "00:00:00:00:00:00",
"id": "ipam/address/00000000-0000-0000-0000-000000000000",
"interface": "interface",
"names": [
{
"name": "name",
"type": "user"
}
],
"parent": "ipam/subnet/00000000-0000-0000-0000-000000000000",
"protocol": "ip4",
"range": "ipam/range/00000000-0000-0000-0000-000000000000",
"space": "ipam/ip_space/00000000-0000-0000-0000-000000000000",
"state": "used",
"tags": {
"temp": "true"
},
"updated_at": "2025-06-27T13:07:21.429056Z",
"usage": [
"IPAM RESERVED"
]
}
}
}
}

Human Readable Output#

Information for the given Bad IP: 0.0.0.1#

Threat Intelligence Summary#

Batch IdClassConfidenceConfidence ScoreConfidence Score RatingConfidence Score VectorDetectedExpirationExtendedIdImportedIPProfilePropertyReceivedRisk ScoreRisk Score RatingRisk Score VectorThreat LevelThreat ScoreThreat Score RatingThreat Score VectorTypeUp
00000000-0000-0000-0000-000000000000APT1000.1Unconfirmedsimple_confidence_vector2025-07-29T09:29:18.721Z2042-11-01T09:29:18.721Zcyberint_guid: simple_cyberint_guid
notes: Malware Download associated with the APT group
00000000-0000-0000-0000-0000000000002025-07-29T09:31:39.329Z0.0.0.1IIDAPT_Malware2025-07-29T09:31:39.329Z9.9Criticalsimple_risk_vector10010Criticalsimple_threat_vectorIPtrue

Address Information#

AddressCommentCompartment IdCreated AtDisable DhcpExternal KeysHostHwaddrIdInterfaceNamesParentProtocolRangeSpaceStateTagsUpdated AtUsage
0.0.0.1comment00000000-0000-0000-0000-0000000000002025-06-27T13:07:21.476126ZFalsee3: 3e3ipam/host/00000000-0000-0000-0000-00000000000000:00:00:00:00:00ipam/address/00000000-0000-0000-0000-000000000000interface- name: name
type: user
ipam/subnet/00000000-0000-0000-0000-000000000000ip4ipam/range/00000000-0000-0000-0000-000000000000ipam/ip_space/00000000-0000-0000-0000-000000000000usedtemp: true2025-06-27T13:07:21.429056Zvalues: IPAM RESERVED

domain#


Gets the comprehensive domain/host reputation and threat intelligence from Infoblox Threat Defense, including threat indicators, IPAM address information and standard domain reputation data.

Base Command#

domain

Input#

Argument NameDescriptionRequired
domainDomain(s) or Hosts(s) for which to retrieve reputation and threat intelligence. Supports comma-separated values.Required

Context Output#

PathTypeDescription
InfobloxCloud.Domain.domainStringThe requested domain.
Domain.NameStringThe domain name, for example: "google.com".
Domain.Relationships.EntityAstringThe source of the relationship.
Domain.Relationships.EntityBstringThe destination of the relationship.
Domain.Relationships.RelationshipstringThe name of the relationship.
Domain.Relationships.EntityATypestringThe type of the source of the relationship.
Domain.Relationships.EntityBTypestringThe type of the destination of the relationship.
Domain.DNSStringA list of IP objects resolved by DNS.
Domain.DetectionEnginesNumberThe total number of engines that checked the indicator.
Domain.PositiveDetectionsNumberThe number of engines that positively detected the indicator as malicious.
Domain.CreationDateDateThe date that the domain was created.
Domain.UpdatedDateStringThe date that the domain was last updated.
Domain.ExpirationDateDateThe expiration date of the domain.
Domain.DomainStatusDatteThe status of the domain.
Domain.NameServersUnknown(List<String>) Name servers of the domain.
Domain.OrganizationStringThe organization of the domain.
Domain.SubdomainsUnknown(List<String>) Subdomains of the domain.
Domain.Admin.CountryStringThe country of the domain administrator.
Domain.Admin.EmailStringThe email address of the domain administrator.
Domain.Admin.NameStringThe name of the domain administrator.
Domain.Admin.PhoneStringThe phone number of the domain administrator.
Domain.Registrant.CountryStringThe country of the registrant.
Domain.Registrant.EmailStringThe email address of the registrant.
Domain.Registrant.NameStringThe name of the registrant.
Domain.Registrant.PhoneStringThe phone number for receiving abuse reports.
Domain.TagsUnknown(List) Tags of the domain.
Domain.FeedRelatedIndicators.valueStringIndicators that are associated with the domain.
Domain.FeedRelatedIndicators.typeStringThe type of the indicators that are associated with the domain.
Domain.FeedRelatedIndicators.descriptionStringThe description of the indicators that are associated with the domain.
Domain.MalwareFamilyStringThe malware family associated with the domain.
Domain.WHOIS.DomainStatusStringThe status of the domain.
Domain.WHOIS.NameServersString(List<String>) Name servers of the domain.
Domain.WHOIS.CreationDateDateThe date that the domain was created.
Domain.WHOIS.UpdatedDateDateThe date that the domain was last updated.
Domain.WHOIS.ExpirationDateDateThe expiration date of the domain.
Domain.WHOIS.Registrant.NameStringThe name of the registrant.
Domain.WHOIS.Registrant.EmailStringThe email address of the registrant.
Domain.WHOIS.Registrant.PhoneStringThe phone number of the registrant.
Domain.WHOIS.Registrar.NameStringThe name of the registrar.
Domain.WHOIS.Registrar.AbuseEmailStringThe email address of the contact for reporting abuse.
Domain.WHOIS.Registrar.AbusePhoneStringThe phone number of contact for reporting abuse.
Domain.WHOIS.Admin.NameStringThe name of the domain administrator.
Domain.WHOIS.Admin.EmailStringThe email address of the domain administrator.
Domain.WHOIS.Admin.PhoneStringThe phone number of the domain administrator.
Domain.WHOIS/HistoryStringList of Whois objects.
Domain.Malicious.VendorStringThe vendor reporting the domain as malicious.
Domain.Malicious.DescriptionStringA description explaining why the domain was reported as malicious.
Domain.DomainIDNNameStringThe internationalized domain name (IDN) of the domain.
Domain.PortStringPorts that are associated with the domain.
Domain.InternalBoolWhether or not the domain is internal or external.
Domain.CategoryStringThe category associated with the indicator.
Domain.CampaignStringThe campaign associated with the domain.
Domain.TrafficLightProtocolStringThe Traffic Light Protocol (TLP) color that is suitable for the domain.
Domain.ThreatTypes.threatcategoryStringThe threat category associated to this indicator by the source vendor. For example, Phishing, Control, TOR, etc.
Domain.ThreatTypes.threatcategoryconfidenceStringThreat Category Confidence is the confidence level provided by the vendor for the threat type category For example a confidence of 90 for threat type category 'malware' means that the vendor rates that this is 90% confidence of being a malware.
Domain.Geo.LocationStringThe geolocation where the domain address is located, in the format: latitude:longitude.
Domain.Geo.CountryStringThe country in which the domain address is located.
Domain.Geo.DescriptionStringAdditional information about the location.
Domain.Tech.CountryStringThe country of the domain technical contact.
Domain.Tech.NameStringThe name of the domain technical contact.
Domain.Tech.OrganizationStringThe organization of the domain technical contact.
Domain.Tech.EmailStringThe email address of the domain technical contact.
Domain.CommunityNotes.noteStringNotes on the domain that were given by the community.
Domain.CommunityNotes.timestampDateThe time in which the note was published.
Domain.Publications.sourceStringThe source in which the article was published.
Domain.Publications.titleStringThe name of the article.
Domain.Publications.linkStringA link to the original article.
Domain.Publications.timestampDateThe time in which the article was published.
Domain.BillingStringThe billing address of the domain.
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
DBotScore.ScoreNumberThe actual score.
DBotScore.ReliabilityStringReliability of the source providing the intelligence data.
InfobloxCloud.Domain.Threat.idStringThe unique identifier for the threat indicator.
InfobloxCloud.Domain.Threat.typeStringThe type of threat indicator.
InfobloxCloud.Domain.Threat.domainStringThe domain identified as a threat indicator.
InfobloxCloud.Domain.Threat.profileStringThe threat profile or classification source.
InfobloxCloud.Domain.Threat.propertyStringThe specific property or category of the threat.
InfobloxCloud.Domain.Threat.classStringThe classification of the threat.
InfobloxCloud.Domain.Threat.threat_levelNumberThe numeric threat level score.
InfobloxCloud.Domain.Threat.threat_labelStringThe textual threat level label.
InfobloxCloud.Domain.Threat.expirationDateThe timestamp when the threat indicator will expire.
InfobloxCloud.Domain.Threat.detectedDateThe timestamp when the threat activity was first detected.
InfobloxCloud.Domain.Threat.receivedDateThe timestamp when the threat indicator was received by the system.
InfobloxCloud.Domain.Threat.importedDateThe timestamp when the threat indicator was imported into the system.
InfobloxCloud.Domain.Threat.upStringThe boolean status flag indicating whether the threat indicator is currently active.
InfobloxCloud.Domain.Threat.batch_idStringThe batch ID of the threat indicator.
InfobloxCloud.Domain.Threat.confidenceNumberThe numeric confidence score representing the reliability of the threat indicator.
InfobloxCloud.Domain.Threat.extended.notesStringThe additional notes or information about the threat indicator.
InfobloxCloud.Domain.Threat.threat_scoreNumberThe numeric score representing the calculated threat severity.
InfobloxCloud.Domain.Threat.threat_score_ratingStringThe textual rating of the threat score.
InfobloxCloud.Domain.Threat.threat_score_vectorStringThe vector string representing threat scoring details.
InfobloxCloud.Domain.Threat.risk_scoreNumberThe numeric risk score assigned to the threat indicator.
InfobloxCloud.Domain.Threat.risk_score_ratingStringThe textual rating of the risk score.
InfobloxCloud.Domain.Threat.risk_score_vectorStringThe vector string representing risk scoring details.
InfobloxCloud.Domain.Threat.confidence_scoreNumberThe numeric confidence score for the threat assessment.
InfobloxCloud.Domain.Threat.confidence_score_ratingStringThe textual rating of the confidence score.
InfobloxCloud.Domain.Threat.confidence_score_vectorStringThe vector string representing confidence scoring details.
InfobloxCloud.Domain.Threat.extended.cyberint_guidStringThe unique identifier for the threat indicator.
InfobloxCloud.Domain.Threat.extended.attack_chainStringThe attack chain associated with the threat indicator.
InfobloxCloud.Domain.Threat.extended.extendedStringThe additional information or metadata associated with the threat indicator.
InfobloxCloud.Domain.Threat.extended.protocolStringThe protocol associated with the threat indicator.
InfobloxCloud.Domain.Threat.extended.referencesStringThe references associated with the threat indicator.
InfobloxCloud.Domain.Threat.extended.threat_actorStringThe threat actor associated with the threat indicator.
InfobloxCloud.Domain.Threat.extended.threat_actor_vectorStringThe vector string representing threat actor details.
InfobloxCloud.Domain.Threat.extended.risk_scoreStringThe numeric risk score assigned to the threat indicator.
InfobloxCloud.Domain.Threat.extended.threat_scoreStringThe numeric threat score assigned to the threat indicator.
InfobloxCloud.Domain.Threat.extended.sample_sha256StringThe SHA-256 hash of the sample associated with the threat.
InfobloxCloud.Domain.Threat.extended.original_profileStringThe original profile or classification source of the threat.
InfobloxCloud.Domain.Threat.dgaStringThe domain name generated by a DGA (Domain Generation Algorithm).
InfobloxCloud.Domain.Threat.hostStringThe host name of the domain.
InfobloxCloud.Domain.Threat.tldStringThe top-level domain (TLD) of the threat.
InfobloxCloud.Domain.Address.addresses.addressStringThe address of the IP address.
InfobloxCloud.Domain.Address.addresses.refStringThe reference of the IP address.
InfobloxCloud.Domain.Address.addresses.spaceStringThe space of the IP address.
InfobloxCloud.Domain.Address.auto_generate_recordsBooleanA boolean flag indicating whether auto generate records is enabled for the IP address.
InfobloxCloud.Domain.Address.commentStringThe description for the IPAM host.
InfobloxCloud.Domain.Address.created_atDateTime when the object has been created.
InfobloxCloud.Domain.Address.host_namesUnknownThe name records to be generated for the host.
InfobloxCloud.Domain.Address.idStringThe resource identifier.
InfobloxCloud.Domain.Address.nameStringThe name of the IPAM host.
InfobloxCloud.Domain.Address.host_names.aliasBooleanA boolean flag indicating whether the name record is an alias.
InfobloxCloud.Domain.Address.host_names.nameStringThe name of the host.
InfobloxCloud.Domain.Address.host_names.primary_nameBooleanA boolean flag indicating whether the name record is the primary name.
InfobloxCloud.Domain.Address.host_names.zoneStringThe zone of the host.
InfobloxCloud.Domain.Address.tagsUnknownThe tags associated with the IP address.
InfobloxCloud.Domain.Address.addressesUnknownThe IP address assigned to the resource.

Command example#

!domain domain=test.com

Context Example#

{
"DBotScore": {
"Indicator": "test.com",
"Reliability": "A - Completely reliable",
"Score": 3,
"Type": "domain",
"Vendor": "InfobloxBloxOneThreatDefense"
},
"Domain": {
"Description": "cyber actors, possibly associated with the APT group Agent Serpens, created a fake website mimicking a modeling agency to collect detailed visitor.",
"DetectionEngines": 1,
"Malicious": {
"Description": "cyber actors, possibly associated with the APT group Agent Serpens, created a fake website mimicking a modeling agency to collect detailed visitor.",
"Vendor": "InfobloxThreatDefensewithDDI"
},
"MalwareFamily": "Phishing",
"Name": "test.com",
"Relationships": [
{
"EntityA": "test.com",
"EntityAType": "Domain",
"EntityB": "0.0.0.1",
"EntityBType": "IP",
"Relationship": "resolves-to"
}
],
"Tags": [
"cyberint_guid: simple_cyberint_guid",
"notes: cyber actors, possibly associated with the APT group Agent Serpens, created a fake website mimicking a modeling agency to collect detailed visitor."
],
"ThreatTypes": [
{
"threatcategory": "HOST",
"threatcategoryconfidence": "100"
}
]
},
"InfobloxCloud": {
"Domain": {
"Address": {
"addresses": [
{
"address": "0.0.0.1",
"ref": "ipam/address/00000000-0000-0000-0000-000000000000",
"space": "ipam/ip_space/00000000-0000-0000-0000-000000000000"
}
],
"auto_generate_records": true,
"comment": "comment",
"created_at": "2025-07-22T05:26:46.834693Z",
"host_names": [
{
"alias": false,
"name": "test.com",
"primary_name": true,
"zone": "dns/auth_zone/8ce66502-8d4b-439e-8690-0c59d3122b9f"
}
],
"id": "ipam/host/00000000-0000-0000-0000-000000000000",
"name": "test.com",
"updated_at": "2025-07-22T05:26:57.219235Z"
},
"domain": "test.com",
"Threat": {
"batch_id": "00000000-0000-0000-0000-000000000001",
"class": "Phishing",
"confidence": 100,
"detected": "2025-05-08T16:39:38.959Z",
"dga": "false",
"domain": "test.com",
"expiration": "2025-09-05T16:39:38.959Z",
"extended": {
"cyberint_guid": "simple_cyberint_guid",
"notes": "cyber actors, possibly associated with the APT group Agent Serpens, created a fake website mimicking a modeling agency to collect detailed visitor."
},
"host": "test.com",
"id": "00000000-0000-0000-0000-000000000001",
"imported": "2025-05-08T16:41:37.894Z",
"profile": "IID",
"property": "Phishing_Lookalike",
"received": "2025-05-08T16:41:37.894Z",
"threat_level": 100,
"tld": "com",
"type": "HOST",
"up": "true"
}
}
}
}

Human Readable Output#

Information for the given Bad Domain: test.com#

Threat Intelligence Summary#

Batch IdClassConfidenceDetectedDgaDomainExpirationExtendedHostIdImportedProfilePropertyReceivedThreat LevelTldTypeUp
00000000-0000-0000-0000-000000000001Phishing1002025-05-08T16:39:38.959Zfalsetest.com2025-09-05T16:39:38.959Zcyberint_guid: simple_cyberint_guid
notes: cyber actors, possibly associated with the APT group Agent Serpens, created a fake website mimicking a modeling agency to collect detailed visitor.
test.com00000000-0000-0000-0000-0000000000012025-05-08T16:41:37.894ZIIDPhishing_Lookalike2025-05-08T16:41:37.894Z100comHOSTtrue

Address Information#

AddressesAuto Generate RecordsCommentCreated AtHost NamesIdNameUpdated At
- address: 0.0.0.1
ref: ipam/address/00000000-0000-0000-0000-000000000000
space: ipam/ip_space/00000000-0000-0000-0000-000000000000
Truecomment2025-07-22T05:26:46.834693Z- alias: False
name: test.com
primary_name: True
zone: dns/auth_zone/8ce66502-8d4b-439e-8690-0c59d3122b9f
ipam/host/00000000-0000-0000-0000-000000000000test.com2025-07-22T05:26:57.219235Z

url#


Gets the comprehensive URL reputation and threat intelligence from Infoblox Threat Defense, including threat indicators, and standard URL reputation data.

Base Command#

url

Input#

Argument NameDescriptionRequired
urlURL(s) for which to retrieve reputation and threat intelligence. Supports comma-separated values.Required

Context Output#

PathTypeDescription
InfobloxCloud.URL.urlStringThe requested URL.
URL.DataStringThe URL.
URL.Relationships.EntityAstringThe source of the relationship.
URL.Relationships.EntityBstringThe destination of the relationship.
URL.Relationships.RelationshipstringThe name of the relationship.
URL.Relationships.EntityATypestringThe type of the source of the relationship.
URL.Relationships.EntityBTypestringThe type of the destination of the relationship.
URL.DetectionEnginesStringThe total number of engines that checked the indicator.
URL.PositiveDetectionsStringThe number of engines that positively detected the indicator as malicious.
URL.CategoryStringThe category associated with the indicator.
URL.Malicious.VendorStringThe vendor reporting the URL as malicious.
URL.Malicious.DescriptionStringA description of the malicious URL.
URL.TagsUnknown(List) Tags of the URL.
URL.FeedRelatedIndicators.valueStringIndicators that are associated with the URL.
URL.FeedRelatedIndicators.typeStringThe type of the indicators that are associated with the URL.
URL.FeedRelatedIndicators.descriptionStringThe description of the indicators that are associated with the URL.
URL.MalwareFamilyStringThe malware family associated with the URL.
URL.PortStringPorts that are associated with the URL.
URL.InternalBoolWhether or not the URL is internal or external.
URL.CampaignStringThe campaign associated with the URL.
URL.TrafficLightProtocolStringThe Traffic Light Protocol (TLP) color that is suitable for the URL.
URL.ThreatTypes.threatcategoryStringThe threat category associated to this indicator by the source vendor. For example, Phishing, Control, TOR, etc.
URL.ThreatTypes.threatcategoryconfidenceStringThreat Category Confidence is the confidence level provided by the vendor for the threat type category For example a confidence of 90 for threat type category 'malware' means that the vendor rates that this is 90% confidence of being a malware.
URL.ASNStringThe autonomous system name for the URL, for example: 'AS8948'.
URL.ASOwnerStringThe autonomous system owner of the URL.
URL.GeoCountryStringThe country in which the URL is located.
URL.OrganizationStringThe organization of the URL.
URL.CommunityNotes.noteStringNotes on the URL that were given by the community.
URL.CommunityNotes.timestampDateThe time in which the note was published.
URL.Publications.sourceStringThe source in which the article was published.
URL.Publications.titleStringThe name of the article.
URL.Publications.linkStringA link to the original article.
URL.Publications.timestampDateThe time in which the article was published.
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
DBotScore.ScoreNumberThe actual score.
DBotScore.ReliabilityStringReliability of the source providing the intelligence data.
InfobloxCloud.URL.Threat.idStringThe unique identifier for the threat indicator.
InfobloxCloud.URL.Threat.typeStringThe type of threat indicator.
InfobloxCloud.URL.Threat.urlStringThe URL identified as a threat indicator.
InfobloxCloud.URL.Threat.profileStringThe threat profile or classification source.
InfobloxCloud.URL.Threat.propertyStringThe specific property or category of the threat.
InfobloxCloud.URL.Threat.classStringThe classification of the threat.
InfobloxCloud.URL.Threat.threat_levelNumberThe numeric threat level score.
InfobloxCloud.URL.Threat.threat_labelStringThe textual threat level label.
InfobloxCloud.URL.Threat.expirationDateThe timestamp when the threat indicator will expire.
InfobloxCloud.URL.Threat.detectedDateThe timestamp when the threat activity was first detected.
InfobloxCloud.URL.Threat.receivedDateThe timestamp when the threat indicator was received by the system.
InfobloxCloud.URL.Threat.importedDateThe timestamp when the threat indicator was imported into the system.
InfobloxCloud.URL.Threat.upStringThe boolean status flag indicating whether the threat indicator is currently active.
InfobloxCloud.URL.Threat.batch_idStringThe batch ID of the threat indicator.
InfobloxCloud.URL.Threat.confidenceNumberThe numeric confidence score representing the reliability of the threat indicator.
InfobloxCloud.URL.Threat.extended.notesStringThe additional notes or information about the threat indicator.
InfobloxCloud.URL.Threat.threat_scoreNumberThe numeric score representing the calculated threat severity.
InfobloxCloud.URL.Threat.threat_score_ratingStringThe textual rating of the threat score.
InfobloxCloud.URL.Threat.threat_score_vectorStringThe vector string representing threat scoring details.
InfobloxCloud.URL.Threat.risk_scoreNumberThe numeric risk score assigned to the threat indicator.
InfobloxCloud.URL.Threat.risk_score_ratingStringThe textual rating of the risk score.
InfobloxCloud.URL.Threat.risk_score_vectorStringThe vector string representing risk scoring details.
InfobloxCloud.URL.Threat.confidence_scoreNumberThe numeric confidence score for the threat assessment.
InfobloxCloud.URL.Threat.confidence_score_ratingStringThe textual rating of the confidence score.
InfobloxCloud.URL.Threat.confidence_score_vectorStringThe vector string representing confidence scoring details.
InfobloxCloud.URL.Threat.extended.cyberint_guidStringThe unique identifier for the threat indicator.
InfobloxCloud.URL.Threat.extended.attack_chainStringThe attack chain associated with the threat indicator.
InfobloxCloud.URL.Threat.extended.extendedStringThe additional information or metadata associated with the threat indicator.
InfobloxCloud.URL.Threat.extended.protocolStringThe protocol associated with the threat indicator.
InfobloxCloud.URL.Threat.extended.referencesStringThe references associated with the threat indicator.
InfobloxCloud.URL.Threat.extended.threat_actorStringThe threat actor associated with the threat indicator.
InfobloxCloud.URL.Threat.extended.threat_actor_vectorStringThe vector string representing threat actor details.
InfobloxCloud.URL.Threat.extended.risk_scoreStringThe numeric risk score assigned to the threat indicator.
InfobloxCloud.URL.Threat.extended.threat_scoreStringThe numeric threat score assigned to the threat indicator.
InfobloxCloud.URL.Threat.extended.sample_sha256StringThe SHA-256 hash of the sample associated with the threat.
InfobloxCloud.URL.Threat.extended.original_profileStringThe original profile or classification source of the threat.

Command example#

!url url=https://test.com

Context Example#

{
"DBotScore": {
"Indicator": "https://test.com",
"Reliability": "A - Completely reliable",
"Score": 3,
"Type": "url",
"Vendor": "InfobloxBloxOneThreatDefense"
},
"InfobloxCloud": {
"URL": {
"Threat": {
"id": "00000000-0000-0000-0000-000000000001",
"type": "URL",
"host": "test.com",
"url": "https://test.com",
"domain": "test.com",
"tld": "com",
"profile": "IID",
"property": "Scam_Generic",
"class": "Scam",
"threat_level": 100,
"expiration": "2025-10-05T12:12:00.22Z",
"detected": "2025-06-07T12:12:00.22Z",
"received": "2025-06-07T12:16:32.337Z",
"imported": "2025-06-07T12:16:32.337Z",
"up": "true",
"confidence": 100,
"batch_id": "00000000-0000-0000-0000-000000000000",
"extended": {
"cyberint_guid": "simple_cyberint_guid",
"notes": "Scam advertised. Lures victims to put their money into fake investments.",
"protocol": "https",
"references": "https://test.com"
}
},
"url": "https://test.com"
}
},
"URL": {
"Data": "https://test.com",
"Description": "Scam advertised. Lures victims to put their money into fake investments.",
"DetectionEngines": 1,
"Malicious": {
"Description": "Scam advertised. Lures victims to put their money into fake investments.",
"Vendor": "InfobloxThreatDefensewithDDI"
},
"MalwareFamily": "Scam",
"Tags": [
"cyberint_guid: simple_cyberint_guid",
"notes: Scam advertised. Lures victims to put their money into fake investments.",
"protocol: https",
"references: https://test.com"
],
"ThreatTypes": [
{
"threatcategory": "URL",
"threatcategoryconfidence": "100"
}
]
}
}

Human Readable Output#

Information for the given Bad URL: https://test.com#

Threat Intelligence Summary#

Batch IdClassConfidenceDetectedDomainExpirationExtendedHostIdImportedProfilePropertyReceivedThreat LevelTldTypeUpURL
00000000-0000-0000-0000-000000000000Scam1002025-06-07T12:12:00.22Ztest.com2025-10-05T12:12:00.22Zcyberint_guid: simple_cyberint_guid
notes: Scam advertised. Lures victims to put their money into fake investments.
protocol: https
references: https://test.com
test.com00000000-0000-0000-0000-0000000000012025-06-07T12:16:32.337ZIIDScam_Generic2025-06-07T12:16:32.337Z100comURLtruehttps://test.com

infobloxcloud-mac-enrich#


Enrich a MAC address with DHCP lease information.

Base Command#

infobloxcloud-mac-enrich

Input#

Argument NameDescriptionRequired
macSpecify the MAC Address to enrich.Required

Context Output#

PathTypeDescription
InfobloxCloud.DHCPLease.addressStringThe IP address assigned in the DHCP lease.
InfobloxCloud.DHCPLease.client_idStringThe identifier of the DHCP client.
InfobloxCloud.DHCPLease.endsStringThe timestamp indicating when the DHCP lease ends.
InfobloxCloud.DHCPLease.fingerprintStringThe DHCP client fingerprint, indicating device type or OS.
InfobloxCloud.DHCPLease.fingerprint_processedStringThe processed fingerprint result, if available.
InfobloxCloud.DHCPLease.ha_groupUnknownThe high-availability group associated with the lease, if any.
InfobloxCloud.DHCPLease.hardwareStringThe hardware (MAC) address of the DHCP client.
InfobloxCloud.DHCPLease.hostStringThe reference or identifier for the host associated with this lease.
InfobloxCloud.DHCPLease.hostnameStringThe hostname provided by the DHCP client.
InfobloxCloud.DHCPLease.iaidNumberThe Identity Association Identifier (IAID) for the DHCP lease.
InfobloxCloud.DHCPLease.last_updatedStringThe timestamp when the lease was last updated.
InfobloxCloud.DHCPLease.optionsStringThe encoded DHCP options provided with the lease.
InfobloxCloud.DHCPLease.preferred_lifetimeStringThe preferred lifetime of the lease.
InfobloxCloud.DHCPLease.protocolStringThe protocol used for the lease.
InfobloxCloud.DHCPLease.spaceStringThe identifier for the IP space to which this lease belongs.
InfobloxCloud.DHCPLease.startsStringThe timestamp indicating when the DHCP lease started.
InfobloxCloud.DHCPLease.stateStringThe current state of the lease.
InfobloxCloud.DHCPLease.typeStringThe type of DHCP lease.

Command example#

!infobloxcloud-mac-enrich mac="00:00:00:00:00:01"

Context Example#

{
"InfobloxCloud": {
"DHCPLease": {
"address": "0.0.0.1",
"client_id": "01:00:00:00:00:00:01",
"ends": "2025-07-01T19:25:24Z",
"fingerprint": "VMware:Virtual Machine:Windows:",
"fingerprint_processed": "processed",
"hardware": "00:00:00:00:00:01",
"host": "dhcp/host/123456",
"hostname": "test-host01",
"iaid": 0,
"last_updated": "2025-07-01T18:25:24.792Z",
"options": "{\"Options\":[{\"Code\":\"57\",\"Value\":\"test\"},{\"Code\":\"61\",\"Value\":\"sample\"},{\"Code\":\"53\",\"Value\":\"world\"},{\"Code\":\"55\",\"Value\":\"bar\"}]}",
"preferred_lifetime": "2025-07-01T18:25:24Z",
"protocol": "",
"space": "ipam/ip_space/12345678-1234-1234-1234-123456789012",
"starts": "2025-07-01T18:25:24Z",
"state": "used",
"type": "DHCPv4"
}
}
}

Human Readable Output#

DHCP Lease Information for MAC: 00:00:00:00:00:01#

AddressClient IdEndsFingerprintFingerprint ProcessedHardwareHostHostnameIaidLast UpdatedOptionsPreferred LifetimeSpaceStartsStateType
0.0.0.101:00:00:00:00:00:012025-07-01T19:25:24ZVMware:Virtual Machine:Windows:processed00:00:00:00:00:01dhcp/host/123456test-host0102025-07-01T18:25:24.792Z- Code: 57
Value: test
- Code: 61
Value: sample
- Code: 53
Value: world
- Code: 55
Value: bar
2025-07-01T18:25:24Zipam/ip_space/12345678-1234-1234-1234-1234567890122025-07-01T18:25:24ZusedDHCPv4

infobloxcloud-soc-insight-list#


Deprecated. Use 'infobloxcloud-iq-for-td-insight-list' instead. List SOC Insights from Infoblox Cloud.

Base Command#

infobloxcloud-soc-insight-list

Input#

Argument NameDescriptionRequired
statusSpecify the status of SOC Insights to fetch. Possible values are: Active, Closed.Optional
threat_typeSpecify the threat type of SOC Insights to fetch. Possible values are: DGA, Undefined, Malicious, Open Resolver, Phishing, DNS Tunneling, MalwareDownload, Sinkhole, Zero Day DNS, Notional Data Exfiltration, MalwareC2DGA, MalwareC2, Restricted Country Communications, Suspicious, CompromisedHost, CompromisedDomain, Lookalike Threat, Sanctioned Feed Disabled, DNSTunnel.Optional
prioritySpecify the priority level of SOC Insights to fetch. Possible values are: INFO, MEDIUM, HIGH, CRITICAL.Optional

Context Output#

PathTypeDescription
InfobloxCloud.SOCInsight.insightIdStringThe ID of the SOC Insight.
InfobloxCloud.SOCInsight.priorityTextStringThe priority level of the SOC Insight.
InfobloxCloud.SOCInsight.tClassStringThe threat class of the SOC Insight.
InfobloxCloud.SOCInsight.tFamilyStringThe threat family of the SOC Insight.
InfobloxCloud.SOCInsight.startedAtStringThe start time of the SOC Insight.
InfobloxCloud.SOCInsight.statusStringThe status of the SOC Insight.
InfobloxCloud.SOCInsight.persistentDateStringTimestamp when the threat was first observed as persistent.
InfobloxCloud.SOCInsight.spreadingDateStringTimestamp when the threat was first observed as spreading.
InfobloxCloud.SOCInsight.dateChangedStringTimestamp when the SOC Insight was last updated.
InfobloxCloud.SOCInsight.changerStringThe user or process that last changed the SOC Insight status or data.
InfobloxCloud.SOCInsight.feedSourceStringThe source feed or provider of the SOC Insight.
InfobloxCloud.SOCInsight.threatTypeStringThe threat type of the SOC Insight.
InfobloxCloud.SOCInsight.numEventsStringThe number of events associated with the SOC Insight.
InfobloxCloud.SOCInsight.eventsNotBlockedCountStringThe number of events not blocked by the SOC Insight.
InfobloxCloud.SOCInsight.mostRecentAtStringThe most recent time the SOC Insight was updated.

Command example#

!infobloxcloud-soc-insight-list

Context Example#

{
"InfobloxCloud": {
"SOCInsight": [
{
"changer": "abc@xyz.com",
"dateChanged": "2025-05-21T00:54:49.407214Z",
"eventsBlockedCount": "3",
"feedSource": "Insight Detection Framework",
"insightId": "00000000-0000-0000-0000-000000000000",
"mostRecentAt": "2025-07-19T19:25:11.723397Z",
"numEvents": "3",
"persistentDate": "2025-04-14T07:00:00Z",
"priorityText": "HIGH",
"spreadingDate": "2025-05-10T19:00:00Z",
"startedAt": "2025-04-14T07:00:00Z",
"status": "Active",
"tClass": "Suspicious",
"tFamily": "EmergentDomain",
"threatType": "Suspicious"
},
{
"tClass": "TI-RESTRICTED",
"tFamily": "OFAC",
"insightId": "00000000-0000-0000-0000-000000000001",
"feedSource": "Insight Detection Framework",
"startedAt": "2025-04-12T18:00:00Z",
"threatType": "Sanctioned Feed Disabled",
"status": "Active",
"persistentDate": "2025-04-12T15:00:00Z",
"numEvents": "246",
"mostRecentAt": "2025-08-07T23:59:19Z",
"eventsNotBlockedCount": "246",
"changer": "abc@xyz.com",
"dateChanged": "2025-08-06T13:58:01.050800Z",
"priorityText": "INFO"
}
]
}
}

Human Readable Output#

SOC Insights#

IDPriorityClassThreat TypeStatusThreat FamilyFeed SourceMost Recent At
00000000-0000-0000-0000-000000000000HIGHSuspiciousSuspiciousActiveEmergentDomainInsight Detection Framework2025-07-19T19:25:11.723397Z
00000000-0000-0000-0000-000000000001INFOTI-RESTRICTEDSanctioned Feed DisabledActiveOFACInsight Detection Framework2025-08-07T23:59:19Z

infobloxcloud-soc-insight-event-list#


Deprecated. Use 'infobloxcloud-iq-for-td-insight-event-list' instead. List events for a specific SOC Insight.

Base Command#

infobloxcloud-soc-insight-event-list

Input#

Argument NameDescriptionRequired
soc_insight_idSpecify the SOC Insight ID to fetch events for.Required
limitSpecify the maximum number of events to fetch. Default is 50.Optional
start_timeSpecify the start time for the events.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
end_timeSpecify the end time for the events.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
threat_levelSpecify the threat level of the events. Possible values are: High, Medium, Low, Info.Optional
confidence_levelSpecify the confidence level of the events. Possible values are: High, Medium, Low, Info.Optional
querySpecify the query to search for events.Optional
query_typeSpecify the query type to search for events. Possible values are: A, AAAA, ANY, TXT, RRSIG, CNAME, MX, NS, PTR, SOA, SRV.Optional
sourceSpecify the source of the events.Optional
device_ipSpecify the device IP of the events.Optional
indicatorSpecify the indicator of the events.Optional

Context Output#

PathTypeDescription
InfobloxCloud.Event.confidenceLevelStringThe confidence level of the threat detection.
InfobloxCloud.Event.deviceCountryStringThe country where the device is located.
InfobloxCloud.Event.deviceNameStringThe name or identifier of the device.
InfobloxCloud.Event.deviceRegionStringThe region where the device is located.
InfobloxCloud.Event.dnsViewStringThe DNS view used for the query.
InfobloxCloud.Event.feedStringThe feed that identified the threat.
InfobloxCloud.Event.sourceStringThe source of the threat detection.
InfobloxCloud.Event.actionStringThe action taken on the detected threat.
InfobloxCloud.Event.policyStringThe policy applied to the detection.
InfobloxCloud.Event.deviceIpStringThe IP address of the device.
InfobloxCloud.Event.queryStringThe DNS query that triggered the detection.
InfobloxCloud.Event.queryTypeStringThe type of DNS query.
InfobloxCloud.Event.responseStringThe DNS response for the query.
InfobloxCloud.Event.classStringThe classification of the threat.
InfobloxCloud.Event.threatFamilyStringThe family of the threat.
InfobloxCloud.Event.threatIndicatorStringThe indicator of the threat.
InfobloxCloud.Event.detectedStringThe timestamp when the event was detected.
InfobloxCloud.Event.propertyStringThe property of the event.
InfobloxCloud.Event.userStringThe user associated with the detection.
InfobloxCloud.Event.threatLevelStringThe severity level of the event.

Command example#

!infobloxcloud-soc-insight-event-list soc_insight_id="00000000-0000-0000-0000-000000000000"

Context Example#

{
"InfobloxCloud": {
"Event": [
{
"action": "Allow - No Log",
"class": "TI-CONFIGURATIONISSUE",
"confidenceLevel": "High",
"detected": "2025-08-11 23:42:04 +0000 UTC",
"deviceIp": "0.0.0.0",
"deviceName": "0.0.0.0",
"policy": "DoH",
"property": "example.com",
"query": "example.com",
"queryType": "A",
"source": "unknown",
"threatFamily": "OPENRESOLVER",
"threatLevel": "Low",
"user": "unknown"
},
{
"action": "Block",
"class": "Suspicious",
"confidenceLevel": "High",
"detected": "2025-07-16 07:37:29 +0000 UTC",
"deviceIp": "0.0.0.1",
"deviceName": "0.0.0.1",
"policy": "Default Policy",
"property": "EmergentDomain",
"query": "example.org",
"queryType": "RRSIG",
"source": "Endpoint",
"threatFamily": "EmergentDomain",
"threatLevel": "High",
"user": "unknown"
}
]
}
}

Human Readable Output#

Events for the given SOC Insight: 00000000-0000-0000-0000-000000000000#

Confidence LevelThreat LevelThreat FamilyActionClassDetected
HighLowOPENRESOLVERAllow - No LogTI-CONFIGURATIONISSUE2025-08-11 23:42:04 +0000 UTC
HighHighEmergentDomainBlockSuspicious2025-07-16 07:37:29 +0000 UTC

infobloxcloud-soc-insight-indicator-list#


Deprecated. Use 'infobloxcloud-iq-for-td-insight-indicator-list' instead. List indicators for a specific SOC Insight.

Base Command#

infobloxcloud-soc-insight-indicator-list

Input#

Argument NameDescriptionRequired
soc_insight_idSpecify the SOC Insight ID to fetch indicators for.Required
limitSpecify the maximum number of indicators to fetch. Default is 50.Optional
start_timeSpecify the start time for the indicators.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
end_timeSpecify the end time for the indicators.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
confidenceSpecify the confidence of the indicators. Possible values are: 1, 2, 3.Optional
indicatorSpecify the indicator of the indicators.Optional
actionSpecify the action of the indicators. Possible values are: Blocked, Not Blocked.Optional
actorSpecify the actor of the indicators.Optional

Context Output#

PathTypeDescription
InfobloxCloud.Indicator.actionStringThe action taken for the indicator.
InfobloxCloud.Indicator.confidenceStringThe confidence level of the indicator.
InfobloxCloud.Indicator.countNumberThe number of occurrences of the indicator.
InfobloxCloud.Indicator.feedNameStringThe feed name that identified the indicator.
InfobloxCloud.Indicator.threatLevelMaxStringThe maximum threat level associated with the indicator.
InfobloxCloud.Indicator.indicatorStringThe value of the indicator.
InfobloxCloud.Indicator.timeMaxDateThe latest time the indicator was observed.
InfobloxCloud.Indicator.timeMinDateThe earliest time the indicator was observed.

Command example#

!infobloxcloud-soc-insight-indicator-list soc_insight_id="00000000-0000-0000-0000-000000000000"

Context Example#

{
"InfobloxCloud": {
"Indicator": [
{
"action": "Not Blocked",
"confidence": "3",
"count": 189,
"indicator": "example.org",
"threatLevelMax": "1",
"timeMax": "2025-08-11T23:00:00.000",
"timeMin": "2025-07-13T15:00:00.000"
},
{
"action": "Blocked",
"confidence": "1",
"count": 5,
"indicator": "example.com",
"threatLevelMax": "3",
"timeMax": "2025-08-11T12:00:00.000",
"timeMin": "2025-07-14T10:00:00.000"
}
]
}
}

Human Readable Output#

Indicators for the given SOC Insight: 00000000-0000-0000-0000-000000000000#

ActionConfidenceMax Threat LevelIndicatorCountMax TimeMin Time
Not Blocked31example.org1892025-08-11T23:00:00.0002025-07-13T15:00:00.000
Blocked13example.com52025-08-11T12:00:00.0002025-07-14T10:00:00.000

infobloxcloud-soc-insight-asset-list#


Deprecated. Use 'infobloxcloud-iq-for-td-insight-asset-list' instead. List assets for a specific SOC Insight.

Base Command#

infobloxcloud-soc-insight-asset-list

Input#

Argument NameDescriptionRequired
soc_insight_idSpecify the SOC Insight ID to fetch assets for.Required
limitSpecify the maximum number of assets to fetch. Default is 50.Optional
start_timeSpecify the start time for the assets.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
end_timeSpecify the end time for the assets.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
qipSpecify the IP address of the assets.Optional
cmacSpecify the MAC address of the assets.Optional
os_versionSpecify the OS version of the assets.Optional
userSpecify the user of the assets.Optional

Context Output#

PathTypeDescription
InfobloxCloud.Asset.countNumberThe number of occurrences associated with the asset.
InfobloxCloud.Asset.qipStringThe IP address of the asset.
InfobloxCloud.Asset.locationStringThe geographical location of the asset.
InfobloxCloud.Asset.threatLevelMaxStringThe maximum threat level associated with the asset.
InfobloxCloud.Asset.threatIndicatorDistinctCountStringThe number of distinct threat indicators associated with the asset.
InfobloxCloud.Asset.timeMaxDateThe latest time the asset was observed.
InfobloxCloud.Asset.timeMinDateThe earliest time the asset was observed.
InfobloxCloud.Asset.mostRecentActionStringThe most recent action taken for the asset.

Command example#

!infobloxcloud-soc-insight-asset-list soc_insight_id="00000000-0000-0000-0000-000000000000"

Context Example#

{
"InfobloxCloud": {
"Asset": [
{
"count": 5,
"location": "Leidschendam,Netherlands",
"mostRecentAction": "Not Blocked",
"qip": "0.0.0.0",
"threatIndicatorDistinctCount": "1",
"threatLevelMax": "1",
"timeMax": "2025-08-11T12:00:00.000",
"timeMin": "2025-07-14T10:00:00.000"
},
{
"count": 1,
"location": "Minneapolis,United States",
"mostRecentAction": "Not Blocked",
"qip": "0.0.0.1",
"threatIndicatorDistinctCount": "1",
"threatLevelMax": "1",
"timeMax": "2025-08-07T12:00:00.000",
"timeMin": "2025-08-07T12:00:00.000"
}
]
}
}

Human Readable Output#

Assets for the given SOC Insight: 00000000-0000-0000-0000-000000000000#

CountQIPMax Threat LevelLocationThreat Indicator Distinct CountTime MaxTime MinMost Recent Action
50.0.0.01Leidschendam,Netherlands12025-08-11T12:00:00.0002025-07-14T10:00:00.000Not Blocked
10.0.0.11Minneapolis,United States12025-08-07T12:00:00.0002025-08-07T12:00:00.000Not Blocked

infobloxcloud-soc-insight-comment-list#


Deprecated. No available replacement. List comments for a specific SOC Insight.

Base Command#

infobloxcloud-soc-insight-comment-list

Input#

Argument NameDescriptionRequired
soc_insight_idSpecify the SOC Insight ID to fetch comments for.Required
start_timeSpecify the start time for the comments.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
end_timeSpecify the end time for the comments.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
limitSpecify the maximum number of comments to fetch. Default is 50.Optional

Context Output#

PathTypeDescription
InfobloxCloud.Comment.commentsChangerStringThe user who created or changed the comment.
InfobloxCloud.Comment.dateChangedDateThe timestamp when the comment was created or modified.
InfobloxCloud.Comment.statusStringThe status associated with the comment.
InfobloxCloud.Comment.newCommentStringThe comment text.

Command example#

!infobloxcloud-soc-insight-comment-list soc_insight_id="00000000-0000-0000-0000-000000000000"

Context Example#

{
"InfobloxCloud": {
"Comment": [
{
"commentsChanger": "abc.zyx.com",
"dateChanged": "2025-08-02T08:39:43.675",
"newComment": "\nAsset IP: 0.0.0.0\nScan ID: None\nReference ID: None\nQualys Scan Report URL: https://example.com/fo/report/report_view.php?&id=None\n",
"status": "Active"
},
{
"commentsChanger": "abc.zyx.com",
"dateChanged": "2025-07-15T05:24:29.803",
"newComment": "\nAsset IP: 0.0.0.0\nScan ID: None\nReference ID: None\nQualys Scan Report URL: https://example.com/fo/report/report_view.php?&id=None\n",
"status": "Active"
}
]
}
}

Human Readable Output#

Comments for the given SOC Insight: 00000000-0000-0000-0000-000000000000#

Comment ChangerDate ChangedStatusComment
abc.zyx.com2025-08-02T08:39:43.675Active
Asset IP: 0.0.0.0
Scan ID: None
Reference ID: None
Qualys Scan Report URL: https://example.com/fo/report/report_view.php?&id=None
abc.zyx.com2025-07-15T05:24:29.803Active
Asset IP: 0.0.0.0
Scan ID: None
Reference ID: None
Qualys Scan Report URL: https://example.com/fo/report/report_view.php?&id=None

infobloxcloud-iq-for-td-insight-list#


List IQ for TD Insights from Infoblox Cloud.

Base Command#

infobloxcloud-iq-for-td-insight-list

Input#

Argument NameDescriptionRequired
statusFilter by the insight's current workflow status. Possible values are: Needs Review, In Progress, Resolved, Reopened, Accepted Risk, False Positive.Optional
nameFilter by the user-facing insight name (case-insensitive partial match).Optional
severityFilter by severity level (case-insensitive match). Possible values are: Critical, High, Medium, Low.Optional
threat_propertiesThreat Property(ies) to search for. Multiple properties queried by specifying comma-separated values.

Example: malware,phishing,ransomware.
Optional
date_createdFilter by the insight creation timestamp. Provide an RFC 3339 date-time value.

Example: 2025-12-19T07:01:56Z. Only insights created on or after this date are returned.
Optional
indicatorsThreat indicator(s) to filter by. Multiple indicators queried by specifying comma-separated values.Optional
assetsAsset(s) to filter by. Multiple assets queried by specifying comma-separated values.Optional
userUser(s) to filter by. Multiple users queried by specifying comma-separated values.Optional

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsight.insight_idStringUnique display identifier for the insight.
InfobloxCloud.IQForTDInsight.nameStringHuman-readable name summarizing the threat or attack pattern.
InfobloxCloud.IQForTDInsight.descriptionStringDetailed description of what the insight represents.
InfobloxCloud.IQForTDInsight.severityStringSeverity level: Critical, High, Medium, or Low.
InfobloxCloud.IQForTDInsight.statusStringCurrent workflow status of the insight.
InfobloxCloud.IQForTDInsight.date_createdDateTimestamp when the insight was first created, e.g. 2026-08-19T07:01:56Z.
InfobloxCloud.IQForTDInsight.evaluation_start_dateDateStart of the time window evaluated to generate this insight.
InfobloxCloud.IQForTDInsight.evaluation_end_dateDateEnd of the time window evaluated to generate this insight.
InfobloxCloud.IQForTDInsight.total_eventsNumberTotal number of DNS security events correlated into this insight.
InfobloxCloud.IQForTDInsight.total_indicatorsNumberTotal number of distinct threat indicators associated with this insight.
InfobloxCloud.IQForTDInsight.total_assetsNumberTotal number of affected assets linked to this insight.
InfobloxCloud.IQForTDInsight.total_usersNumberTotal number of unique users whose queries triggered events in this insight.
InfobloxCloud.IQForTDInsight.expiring_in_daysNumberNumber of days until this insight expires and is automatically archived.
InfobloxCloud.IQForTDInsight.threat_propertiesStringList of threat property labels associated with this insight.
InfobloxCloud.IQForTDInsight.time_saved_secondsNumberTotal time saved in seconds by automated analysis for this insight.

Command example#

!infobloxcloud-iq-for-td-insight-list severity="High"

Context Example#

{
"InfobloxCloud": {
"IQForTDInsight": [
{
"total_events": 10,
"total_assets": 1,
"insight_id": "insight-v2-001",
"name": "Sample Malvertising Connection from dummy-host-01",
"description": "This insight is raised on observed domains that are generated by specific threat actor based patterns.",
"severity": "High",
"date_created": "2026-12-01T10:00:00Z",
"evaluation_start_date": "2026-11-30T00:00:00Z",
"evaluation_end_date": "2026-12-01T00:00:00Z",
"total_indicators": 2,
"total_users": 1,
"status": "In Progress",
"expiring_in_days": 2,
"threat_properties": [
"Malicious_TDS",
"Suspicious_Generic"
],
"time_saved_seconds": 3600
},
{
"total_events": 20,
"total_assets": 1,
"insight_id": "insight-v2-002",
"name": "Sample Beaconing Activity from dummy-host-02",
"description": "This insight is raised when an asset contacts a domain consistently across many hours with low volume, suggesting beaconing.",
"severity": "Critical",
"date_created": "2026-12-01T11:00:00Z",
"evaluation_start_date": "2026-11-30T11:00:00Z",
"evaluation_end_date": "2026-12-01T11:00:00Z",
"total_indicators": 3,
"total_users": 1,
"status": "Needs Review",
"expiring_in_days": 2,
"threat_properties": [
"Malicious_Generic"
],
"time_saved_seconds": 1800
}
]
}
}

Human Readable Output#

IQ for TD Insights#

Insight IDNameDescriptionSeverityStatusDate CreatedEvaluation Start DateEvaluation End DateTotal EventsTotal IndicatorsTotal AssetsTotal UsersExpiring In DaysThreat PropertiesTime Saved Seconds
insight-v2-001Sample Malvertising Connection from dummy-host-01This insight is raised on observed domains that are generated by specific threat actor based patterns.HighIn Progress2026-12-01T10:00:00Z2026-11-30T00:00:00Z2026-12-01T00:00:00Z102112Malicious_TDS,
Suspicious_Generic
3600
insight-v2-002Sample Beaconing Activity from dummy-host-02This insight is raised when an asset contacts a domain consistently across many hours with low volume, suggesting beaconing.CriticalNeeds Review2026-12-01T11:00:00Z2026-11-30T11:00:00Z2026-12-01T11:00:00Z203112Malicious_Generic1800

infobloxcloud-iq-for-td-insight-get#


Get the full detail view for a single IQ for TD Insight from Infoblox Cloud.

Base Command#

infobloxcloud-iq-for-td-insight-get

Input#

Argument NameDescriptionRequired
insight_idThe unique display identifier of the insight to retrieve. The insight_id can be fetched from the output context path (InfobloxCloud.IQForTDInsight.insight_id) of the 'infobloxcloud-iq-for-td-insight-list command'.Required

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsight.insight_idStringUnique display identifier for the insight.
InfobloxCloud.IQForTDInsight.nameStringHuman-readable name summarizing the threat or attack pattern.
InfobloxCloud.IQForTDInsight.descriptionStringDetailed description of what the insight represents.
InfobloxCloud.IQForTDInsight.severityStringSeverity level: Critical, High, Medium, or Low.
InfobloxCloud.IQForTDInsight.statusStringCurrent workflow status of the insight.
InfobloxCloud.IQForTDInsight.date_createdDateTimestamp when the insight was first created.
InfobloxCloud.IQForTDInsight.evaluation_start_dateDateStart of the time window evaluated to generate this insight.
InfobloxCloud.IQForTDInsight.evaluation_end_dateDateEnd of the time window evaluated to generate this insight.
InfobloxCloud.IQForTDInsight.total_eventsNumberTotal number of DNS security events correlated into this insight.
InfobloxCloud.IQForTDInsight.total_indicatorsNumberTotal number of distinct threat indicators associated with this insight.
InfobloxCloud.IQForTDInsight.total_assetsNumberTotal number of affected assets linked to this insight.
InfobloxCloud.IQForTDInsight.total_verified_assetsNumberNumber of assets that have been verified by an analyst.
InfobloxCloud.IQForTDInsight.total_unverified_assetsNumberNumber of assets that have not yet been verified.
InfobloxCloud.IQForTDInsight.total_usersNumberTotal number of unique users whose queries triggered events in this insight.
InfobloxCloud.IQForTDInsight.expiring_in_daysNumberNumber of days until this insight expires and is automatically archived.
InfobloxCloud.IQForTDInsight.threat_propertiesStringList of threat property labels associated with this insight.
InfobloxCloud.IQForTDInsight.top_indicators.indicatorStringThe threat indicator value (e.g., domain, IP, URL).
InfobloxCloud.IQForTDInsight.top_indicators.descriptionStringHuman-readable explanation of why this indicator is significant.
InfobloxCloud.IQForTDInsight.top_indicators.threat_actors.idStringUnique identifier for the threat actor.
InfobloxCloud.IQForTDInsight.top_indicators.threat_actors.nameStringName of the threat actor or group.
InfobloxCloud.IQForTDInsight.top_assets.assetStringDevice name or identifier of the affected asset.
InfobloxCloud.IQForTDInsight.top_assets.descriptionStringSummary of the asset's involvement in the insight.
InfobloxCloud.IQForTDInsight.threat_actors.actor_nameStringName of the threat actor or group.
InfobloxCloud.IQForTDInsight.threat_actors.actor_descriptionStringDescription of the threat actor's known tactics, techniques, and objectives.
InfobloxCloud.IQForTDInsight.overviewStringAI-generated overview summarizing notable patterns in the insight data.
InfobloxCloud.IQForTDInsight.key_recommendations.idStringIdentifier of the underlying recommendation action row that this displayed recommendation corresponds to.
InfobloxCloud.IQForTDInsight.key_recommendations.recommendationStringHuman-readable recommendation text.
InfobloxCloud.IQForTDInsight.key_recommendations.typeStringRecommendation category: indicator, asset, policy, or empty.
InfobloxCloud.IQForTDInsight.key_recommendations.action_takenStringWhether the recommended action has already been taken.
InfobloxCloud.IQForTDInsight.time_saved_secondsNumberTotal time saved in seconds by automated analysis for this insight.

Command example#

!infobloxcloud-iq-for-td-insight-get insight_id="insight-v2-001"

Context Example#

{
"InfobloxCloud": {
"IQForTDInsight": {
"insight_id": "insight-v2-001",
"name": "Sample Malvertising Connection from dummy-host-01",
"description": "This insight is raised on observed domains that are generated by specific threat actor based patterns.",
"severity": "High",
"date_created": "2026-12-01T10:00:00Z",
"evaluation_start_date": "2026-11-30T00:00:00Z",
"evaluation_end_date": "2026-12-01T00:00:00Z",
"total_events": 10,
"total_indicators": 2,
"total_assets": 1,
"total_verified_assets": 1,
"total_unverified_assets": 0,
"total_users": 1,
"status": "In Progress",
"expiring_in_days": 2,
"threat_properties": [
"Malicious_TDS",
"Suspicious_Generic"
],
"top_indicators": [
{
"indicator": "dummy-malicious-domain.example",
"description": "Domain associated with known malvertising campaign infrastructure.",
"threat_actors": [
{
"id": "actor-001",
"name": "Dummy Threat Group"
}
]
}
],
"top_assets": [
{
"asset": "dummy-host-01",
"description": "Repeatedly contacted the malicious domain over the evaluation window."
}
],
"threat_actors": [
{
"actor_name": "Dummy Threat Group",
"actor_description": "Known for operating malvertising redirection chains."
}
],
"overview": [
"dummy-host-01 contacted 1 malicious domain 10 times during the evaluation window.",
"The activity pattern matches known Dummy Threat Group infrastructure."
],
"key_recommendations": [
{
"id": "rec-001",
"recommendation": "Block the unblocked threat indicator: dummy-malicious-domain.example",
"type": "indicator",
"action_taken": "false"
}
],
"time_saved_seconds": 3600
}
}
}

Human Readable Output#

IQ for TD Insight Details#

Insight IDNameDescriptionSeverityStatusDate CreatedEvaluation Start DateEvaluation End DateTotal EventsTotal IndicatorsTotal AssetsTotal Verified AssetsTotal Unverified AssetsTotal UsersExpiring In DaysThreat PropertiesTime Saved Seconds
insight-v2-001Sample Malvertising Connection from dummy-host-01This insight is raised on observed domains that are generated by specific threat actor based patterns.HighIn Progress2026-12-01T10:00:00Z2026-11-30T00:00:00Z2026-12-01T00:00:00Z10211012Malicious_TDS,
Suspicious_Generic
3600

Overview#

Observation
dummy-host-01 contacted 1 malicious domain 10 times during the evaluation window.
The activity pattern matches known Dummy Threat Group infrastructure.

Top Indicators#

DescriptionIndicatorThreat Actors
Domain associated with known malvertising campaign infrastructure.dummy-malicious-domain.exampleDummy Threat Group (actor-001)

Top Assets#

AssetDescription
dummy-host-01Repeatedly contacted the malicious domain over the evaluation window.

Threat Actors#

Actor DescriptionActor Name
Known for operating malvertising redirection chains.Dummy Threat Group

Key Recommendations#

Action TakenIDRecommendationType
falserec-001Block the unblocked threat indicator: dummy-malicious-domain.exampleindicator

infobloxcloud-iq-for-td-insight-status-update#


Update the workflow status of an IQ for TD Insight from Infoblox Cloud, with an optional analyst comment.

Base Command#

infobloxcloud-iq-for-td-insight-status-update

Input#

Argument NameDescriptionRequired
insight_idThe unique display identifier of the insight whose status should be updated. The insight_id can be fetched from the output context path (InfobloxCloud.IQForTDInsight.insight_id) of the 'infobloxcloud-iq-for-td-insight-list command'.Required
statusNew workflow status to assign to the insight. Possible values are: Needs Review, In Progress, Resolved, Reopened, Accepted Risk, False Positive.Required
commentOptional analyst comment explaining the status change. Persisted in the insight's audit trail.Optional

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsight.insight_idStringUnique display identifier for the insight.
InfobloxCloud.IQForTDInsight.statusStringThe workflow status that was assigned to the insight.
InfobloxCloud.IQForTDInsight.commentStringThe analyst comment recorded with the status change, if provided.

Command example#

!infobloxcloud-iq-for-td-insight-status-update insight_id="insight-v2-001" status="Resolved" comment="Remediated the affected asset."

Context Example#

{
"InfobloxCloud": {
"IQForTDInsight": {
"insight_id": "insight-v2-001",
"status": "Resolved",
"comment": "Remediated the affected asset."
}
}
}

Human Readable Output#

Successfully updated the status of IQ for TD Insight 'insight-v2-001' to 'Resolved'.

infobloxcloud-iq-for-td-insight-asset-list#


List assets associated with a specific IQ for TD Insight from Infoblox Cloud.

Base Command#

infobloxcloud-iq-for-td-insight-asset-list

Input#

Argument NameDescriptionRequired
insight_idThe unique display identifier of the insight whose assets to list. The insight_id can be fetched from the output context path (InfobloxCloud.IQForTDInsight.insight_id) of the 'infobloxcloud-iq-for-td-insight-list command'.Required
device_nameFilter assets by device or host name (case-insensitive partial match).Optional
indicatorsIndicator(s) to filter by. Multiple indicators queried by specifying comma-separated values.

Example: dummy-indicator-1.com,dummy-indicator-2.com.
Optional
usersUser(s) to filter by. Multiple users queried by specifying comma-separated values.

Example: dummy-user-1,dummy-user-2.
Optional
ip_addressIP address(es) to filter by. Multiple IP addresses queried by specifying comma-separated values.

Example: 0.0.0.0,0.0.0.1.
Optional
is_verifiedFilter by asset verification state. Set to True to return only verified assets, or False for unverified assets only. Omit to return both. Possible values are: True, False.Optional
limitMaximum number of asset records to return per request. Must be a positive integer. Default is 50.Optional

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsightAsset.insight_idStringThe unique display identifier of the insight this asset belongs to.
InfobloxCloud.IQForTDInsightAsset.device_nameStringHostname or device name of the asset, when known.
InfobloxCloud.IQForTDInsightAsset.ip_addressStringIP addresses observed for this asset during the insight evaluation window.
InfobloxCloud.IQForTDInsightAsset.mac_addressStringMAC addresses observed for this asset, when available from DHCP or device telemetry.
InfobloxCloud.IQForTDInsightAsset.is_verifiedBooleanTrue when the asset has been matched to an inventory record; false when only an unverified IP/MAC observation is available.
InfobloxCloud.IQForTDInsightAsset.is_riskyBooleanTrue when an analyst has flagged this asset as risky for the insight; false otherwise.
InfobloxCloud.IQForTDInsightAsset.total_eventsNumberNumber of DNS security events from this asset that contributed to the insight.
InfobloxCloud.IQForTDInsightAsset.indicatorsStringThreat indicators (e.g., malicious domains, IPs, URLs) this asset interacted with.
InfobloxCloud.IQForTDInsightAsset.usersStringUsers whose activity on this asset triggered events in the insight.
InfobloxCloud.IQForTDInsightAsset.locationsStringGeographic locations (city, region, or country) associated with the asset.
InfobloxCloud.IQForTDInsightAsset.first_detectedDateTimestamp of the earliest event involving this asset within the insight.
InfobloxCloud.IQForTDInsightAsset.last_detectedDateTimestamp of the most recent event involving this asset within the insight.
InfobloxCloud.IQForTDInsightAsset.descriptionStringHuman-readable summary describing the asset's role or involvement in the insight.
InfobloxCloud.IQForTDInsightAsset.asset_keyStringInternal composite key used to merge duplicate assets in context across command runs.

Command example#

!infobloxcloud-iq-for-td-insight-asset-list insight_id="insight-v2-001"

Context Example#

{
"InfobloxCloud": {
"IQForTDInsightAsset": [
{
"device_name": "dummy-host-01",
"ip_address": [
"0.0.0.0"
],
"mac_address": [
"00:11:22:33:44:55"
],
"is_verified": true,
"is_risky": false,
"total_events": 10,
"indicators": [
"dummy-indicator-1.com"
],
"users": [
"dummy-user-1"
],
"locations": [
"Amsterdam, Netherlands"
],
"first_detected": "2026-11-30T00:00:00Z",
"last_detected": "2026-12-01T00:00:00Z",
"description": "Sample asset flagged for repeated contact with a malicious domain.",
"insight_id": "insight-v2-001",
"asset_key": "insight-v2-001|dummy-host-01"
},
{
"device_name": "dummy-host-02",
"ip_address": [
"0.0.0.1"
],
"mac_address": [
"66:77:88:99:AA:BB"
],
"is_verified": false,
"is_risky": true,
"total_events": 5,
"indicators": [
"dummy-indicator-2.com"
],
"users": [
"dummy-user-2"
],
"locations": [
"Minneapolis, United States"
],
"first_detected": "2026-11-30T11:00:00Z",
"last_detected": "2026-12-01T11:00:00Z",
"description": "Sample unverified asset observed beaconing to a threat indicator.",
"insight_id": "insight-v2-001",
"asset_key": "insight-v2-001|dummy-host-02"
}
]
}
}

Human Readable Output#

Assets for the given IQ for TD Insight: insight-v2-001#

Device NameIP AddressMac AddressIs VerifiedIs RiskyTotal EventsIndicatorsUsersLocationsFirst DetectedLast DetectedDescription
dummy-host-010.0.0.000:11:22:33:44:55TrueFalse10dummy-indicator-1.comdummy-user-1Amsterdam, Netherlands2026-11-30T00:00:00Z2026-12-01T00:00:00ZSample asset flagged for repeated contact with a malicious domain.
dummy-host-020.0.0.166:77:88:99:AA:BBFalseTrue5dummy-indicator-2.comdummy-user-2Minneapolis, United States2026-11-30T11:00:00Z2026-12-01T11:00:00ZSample unverified asset observed beaconing to a threat indicator.

infobloxcloud-iq-for-td-insight-event-list#


List events for a specific IQ for TD Insight from Infoblox Cloud.

Base Command#

infobloxcloud-iq-for-td-insight-event-list

Input#

Argument NameDescriptionRequired
insight_idSpecify the IQ for TD Insight ID to fetch events for. The insight_id can be fetched from the output context path (InfobloxCloud.IQForTDInsight.insight_id) of the 'infobloxcloud-iq-for-td-insight-list command'.Required
threat_levelFilter events by numeric threat level.

Possible values are: "1" (Low), "2" (Medium), "3" (High).
Optional
threat_confidenceFilter events by detection confidence level. Possible values are: Low, Medium, High.Optional
indicatorsIndicator(s) to filter by. Multiple indicators queried by specifying comma-separated values.

Example: dummy-indicator-1.com,dummy-indicator-2.com.
Optional
detected_fromStart of the detection time range (inclusive).

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
detected_toEnd of the detection time range (inclusive).

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
tclassFilter by threat class category (e.g. Malware, Phishing, C2, Data Exfiltration).Optional
queryFilter by the DNS query name.Optional
query_typeFilter by DNS query type. Possible values are: A, AAAA, CNAME, TXT, MX.Optional
usersUser(s) to filter by. Multiple users queried by specifying comma-separated values.

Example: dummy-user-1,dummy-user-2.
Optional
device_ipsDevice IP address(es) to filter by. Multiple IP addresses queried by specifying comma-separated values.

Example: 0.0.0.0,0.0.0.1.
Optional
device_nameFilter by the name of the device that generated the event.Optional
policyFilter by the security policy name applied to the event.Optional
sourceFilter by the network source identifier where the DNS query originated.Optional
responseFilter by the DNS response returned (e.g. NXDOMAIN, a resolved IP).Optional
dns_viewFilter by the DNS view configuration under which the query was resolved.Optional
feedFilter by the threat intelligence feed name that flagged the indicator.Optional
mac_addressesMAC address(es) to filter by. Multiple MAC addresses queried by specifying comma-separated values.

Example: 00:11:22:33:44:55,AA:BB:CC:DD:EE:FF.
Optional
os_versionFilter by the operating system version of the device.Optional
dhcp_fingerprintFilter by the DHCP fingerprint of the device.Optional
response_regionFilter by the geographic region of the DNS response destination.Optional
response_countryFilter by the country of the DNS response destination.Optional
device_regionFilter by the geographic region where the source device is located.Optional
device_countryFilter by the country where the source device is located.Optional
limitMaximum number of event records to return per request. Default is 50.Optional

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsightEvent.threat_levelStringNumeric threat severity assigned to the event.
InfobloxCloud.IQForTDInsightEvent.threat_confidenceStringDetection confidence score for the event.
InfobloxCloud.IQForTDInsightEvent.detected_atDateTimestamp when the event was detected.
InfobloxCloud.IQForTDInsightEvent.queryStringDNS query name that was looked up.
InfobloxCloud.IQForTDInsightEvent.tclassStringThreat class category for the event.
InfobloxCloud.IQForTDInsightEvent.actor_nameStringThreat actor or group attributed to the activity.
InfobloxCloud.IQForTDInsightEvent.query_typeStringDNS record type queried.
InfobloxCloud.IQForTDInsightEvent.userStringUser identity associated with the DNS query.
InfobloxCloud.IQForTDInsightEvent.device_nameStringHostname of the source device.
InfobloxCloud.IQForTDInsightEvent.device_ipStringIP address of the source device.
InfobloxCloud.IQForTDInsightEvent.tfamilyStringThreat family classification.
InfobloxCloud.IQForTDInsightEvent.tpropertyStringThreat property label associated with the event.
InfobloxCloud.IQForTDInsightEvent.policyStringSecurity policy that matched the event.
InfobloxCloud.IQForTDInsightEvent.actionStringEnforcement action taken by the policy.
InfobloxCloud.IQForTDInsightEvent.sourceStringNetwork source identifier where the query originated.
InfobloxCloud.IQForTDInsightEvent.indicatorStringThreat indicator that flagged the event.
InfobloxCloud.IQForTDInsightEvent.responseStringDNS response returned to the client.
InfobloxCloud.IQForTDInsightEvent.dns_viewStringDNS view configuration under which the query resolved.
InfobloxCloud.IQForTDInsightEvent.feedStringThreat intelligence feed that contributed the indicator match.
InfobloxCloud.IQForTDInsightEvent.mac_addressStringMAC address of the source device, when available.
InfobloxCloud.IQForTDInsightEvent.os_versionStringOperating system and version reported for the source device.
InfobloxCloud.IQForTDInsightEvent.dhcp_fingerprintStringDHCP fingerprint used to identify the source device type.
InfobloxCloud.IQForTDInsightEvent.response_regionStringGeographic region of the DNS response destination.
InfobloxCloud.IQForTDInsightEvent.response_countryStringCountry of the DNS response destination.
InfobloxCloud.IQForTDInsightEvent.device_regionStringGeographic region where the source device is located.
InfobloxCloud.IQForTDInsightEvent.device_countryStringCountry where the source device is located.
InfobloxCloud.IQForTDInsightEvent.event_countNumberNumber of duplicate events collapsed into this entry.
InfobloxCloud.IQForTDInsightEvent.event_keyStringInternal composite key used to merge duplicate events in context across command runs.

Command example#

!infobloxcloud-iq-for-td-insight-event-list insight_id="insight-v2-001"

Context Example#

{
"InfobloxCloud": {
"IQForTDInsightEvent": [
{
"threat_level": "3",
"threat_confidence": "90",
"detected_at": "2026-12-01T02:55:00Z",
"query": "dummy-indicator-1.com",
"tclass": "Malware",
"actor_name": "DUMMY_ACTOR",
"query_type": "A",
"user": "dummy-user-1",
"device_name": "dummy-host-01",
"device_ip": "0.0.0.0",
"tfamily": "DUMMY_ACTOR",
"tproperty": "dga",
"policy": "Default",
"action": "Block",
"source": "unknown",
"indicator": "dummy-indicator-1.com",
"response": "NXDOMAIN",
"dns_view": "default",
"feed": "AntiMalware",
"mac_address": "00:11:22:33:44:55",
"os_version": "Windows 11",
"dhcp_fingerprint": "MSFT 5.0",
"response_region": "North Holland",
"response_country": "Netherlands",
"device_region": "North Holland",
"device_country": "Netherlands",
"event_count": 1,
"event_key": "3|90|2026-12-01T02:55:00Z|dummy-indicator-1.com|Malware|DUMMY_ACTOR|A|dummy-user-1|dummy-host-01|0.0.0.0|DUMMY_ACTOR|dga|Default|Block|unknown|dummy-indicator-1.com|NXDOMAIN|default|AntiMalware|00:11:22:33:44:55|Windows 11|MSFT 5.0|North Holland|Netherlands|North Holland|Netherlands|insight-v2-001"
},
{
"threat_level": "1",
"threat_confidence": "40",
"detected_at": "2026-12-01T11:00:00Z",
"query": "dummy-indicator-2.com",
"tclass": "Phishing",
"actor_name": "DUMMY_ACTOR_2",
"query_type": "AAAA",
"user": "dummy-user-2",
"device_name": "dummy-host-02",
"device_ip": "0.0.0.1",
"tfamily": "DUMMY_ACTOR_2",
"tproperty": "phishing",
"policy": "Default",
"action": "Log",
"source": "unknown",
"indicator": "dummy-indicator-2.com",
"response": "0.0.0.2",
"dns_view": "default",
"feed": "PhishFeed",
"mac_address": "66:77:88:99:AA:BB",
"os_version": "macOS 15",
"dhcp_fingerprint": "Apple",
"response_region": "Minnesota",
"response_country": "United States",
"device_region": "Minnesota",
"device_country": "United States",
"event_count": 1,
"event_key": "1|40|2026-12-01T11:00:00Z|dummy-indicator-2.com|Phishing|DUMMY_ACTOR_2|AAAA|dummy-user-2|dummy-host-02|0.0.0.1|DUMMY_ACTOR_2|phishing|Default|Log|unknown|dummy-indicator-2.com|0.0.0.2|default|PhishFeed|66:77:88:99:AA:BB|macOS 15|Apple|Minnesota|United States|Minnesota|United States|insight-v2-001"
}
]
}
}

Human Readable Output#

Events for the given IQ for TD Insight: insight-v2-001#

Event CountThreat LevelThreat ConfidenceDetected AtQueryTclassActor NameQuery TypeUserDevice NameDevice IPTfamilyTpropertyPolicyActionSourceIndicatorResponseDns ViewFeedMac AddressOs VersionDhcp FingerprintResponse RegionResponse CountryDevice RegionDevice Country
13902026-12-01T02:55:00Zdummy-indicator-1.comMalwareDUMMY_ACTORAdummy-user-1dummy-host-010.0.0.0DUMMY_ACTORdgaDefaultBlockunknowndummy-indicator-1.comNXDOMAINdefaultAntiMalware00:11:22:33:44:55Windows 11MSFT 5.0North HollandNetherlandsNorth HollandNetherlands
11402026-12-01T11:00:00Zdummy-indicator-2.comPhishingDUMMY_ACTOR_2AAAAdummy-user-2dummy-host-020.0.0.1DUMMY_ACTOR_2phishingDefaultLogunknowndummy-indicator-2.com0.0.0.2defaultPhishFeed66:77:88:99:AA:BBmacOS 15AppleMinnesotaUnited StatesMinnesotaUnited States

infobloxcloud-iq-for-td-insight-indicator-list#


List threat indicators associated with a specific IQ for TD Insight from Infoblox Cloud.

Base Command#

infobloxcloud-iq-for-td-insight-indicator-list

Input#

Argument NameDescriptionRequired
insight_idThe unique display identifier of the insight whose indicators to list. The insight_id can be fetched from the output context path (InfobloxCloud.IQForTDInsight.insight_id) of the 'infobloxcloud-iq-for-td-insight-list command'.Required
indicatorsIndicator(s) to filter by. Multiple indicators queried by specifying comma-separated values.

Example: dummy-indicator-1.com,dummy-indicator-2.com.
Optional
threat_levelFilter indicators by numeric threat level.

Possible values are: "1" (Low), "2" (Medium), "3" (High).
Optional
statusesBlocking/enforcement status value(s) to filter by. Multiple statuses specified as comma-separated values. Possible values are: Blocked, Not Blocked.Optional
usersUser(s) to filter by. Multiple users queried by specifying comma-separated values.

Example: dummy-user-1,dummy-user-2.
Optional
detected_atFilter indicators by detection timestamp. Returns only indicators detected on this specified date.

Format: YYYY-MM-DDTHH:MM:SSZ, YYYY-MM-DD, N days, N hours.

Example: 2025-04-25T00:00:00Z, 2025-04-25, 2 days, 5 hours, 01 Mar 2025, 01 Feb 2025 04:45:33, 15 Jun.
Optional
limitMaximum number of indicator records to return per request. Default is 50.Optional

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsightIndicator.insight_idStringThe unique display identifier of the insight this indicator belongs to.
InfobloxCloud.IQForTDInsightIndicator.threat_indicatorStringThe indicator value (e.g., malicious domain, IP, or URL).
InfobloxCloud.IQForTDInsightIndicator.threat_levelNumberNumeric threat severity assigned to the indicator.
InfobloxCloud.IQForTDInsightIndicator.confidence_levelNumberNumeric confidence rating for the detection.
InfobloxCloud.IQForTDInsightIndicator.statusStringBlocking/enforcement status values for the indicator (e.g., "Blocked", "Not Blocked").
InfobloxCloud.IQForTDInsightIndicator.total_eventsNumberNumber of DNS security events involving this indicator within the insight.
InfobloxCloud.IQForTDInsightIndicator.verified_assetsStringVerified assets (matched to inventory) that interacted with this indicator.
InfobloxCloud.IQForTDInsightIndicator.unverified_assetsStringUnverified assets (observed only by IP/MAC, not matched to inventory) that interacted with this indicator.
InfobloxCloud.IQForTDInsightIndicator.usersStringUsers whose queries involved this indicator.
InfobloxCloud.IQForTDInsightIndicator.threat_actorsStringThreat actors or groups attributed to this indicator.
InfobloxCloud.IQForTDInsightIndicator.first_detectedDateTimestamp of the first detection of this indicator within the insight.
InfobloxCloud.IQForTDInsightIndicator.last_detectedDateTimestamp of the most recent detection of this indicator within the insight.
InfobloxCloud.IQForTDInsightIndicator.detected_atDateTimestamp of the most recent detection of this indicator within the insight.
InfobloxCloud.IQForTDInsightIndicator.descriptionStringHuman-readable description of why the indicator is significant.
InfobloxCloud.IQForTDInsightIndicator.indicator_keyStringInternal composite key (insight_id and threat_indicator) used to merge context across command runs.

Command example#

!infobloxcloud-iq-for-td-insight-indicator-list insight_id="insight-v2-001"

Context Example#

{
"InfobloxCloud": {
"IQForTDInsightIndicator": [
{
"threat_indicator": "dummy-indicator-1.com",
"threat_level": 3,
"confidence_level": 90,
"status": [
"Blocked"
],
"total_events": 12,
"verified_assets": [
"dummy-host-01"
],
"unverified_assets": [],
"users": [
"dummy-user-1"
],
"threat_actors": [
"DUMMY_ACTOR"
],
"first_detected": "2026-11-28T02:55:00Z",
"last_detected": "2026-12-01T02:55:00Z",
"detected_at": "2026-12-01T02:55:00Z",
"description": "Malicious domain associated with malware distribution.",
"insight_id": "insight-v2-001",
"indicator_key": "insight-v2-001|dummy-indicator-1.com"
},
{
"threat_indicator": "dummy-indicator-2.com",
"threat_level": 1,
"confidence_level": 40,
"status": [
"Not Blocked"
],
"total_events": 3,
"verified_assets": [],
"unverified_assets": [
"0.0.0.1"
],
"users": [
"dummy-user-2"
],
"threat_actors": [
"DUMMY_ACTOR_2"
],
"first_detected": "2026-11-30T11:00:00Z",
"last_detected": "2026-12-01T11:00:00Z",
"detected_at": "2026-12-01T11:00:00Z",
"description": "Suspicious domain flagged by phishing feed.",
"insight_id": "insight-v2-001",
"indicator_key": "insight-v2-001|dummy-indicator-2.com"
}
]
}
}

Human Readable Output#

Indicators for the given IQ for TD Insight: insight-v2-001#

Threat IndicatorThreat LevelConfidence LevelStatusTotal EventsVerified AssetsUnverified AssetsUsersThreat ActorsFirst DetectedLast DetectedDetected AtDescription
dummy-indicator-1.com390Blocked12dummy-host-01dummy-user-1DUMMY_ACTOR2026-11-28T02:55:00Z2026-12-01T02:55:00Z2026-12-01T02:55:00ZMalicious domain associated with malware distribution.
dummy-indicator-2.com140Not Blocked30.0.0.1dummy-user-2DUMMY_ACTOR_22026-11-30T11:00:00Z2026-12-01T11:00:00Z2026-12-01T11:00:00ZSuspicious domain flagged by phishing feed.

infobloxcloud-iq-for-td-insight-action-execute#


Execute a recommendation action on a specific IQ for TD Insight from Infoblox Cloud.

Base Command#

infobloxcloud-iq-for-td-insight-action-execute

Input#

Argument NameDescriptionRequired
insight_idThe unique display identifier of the insight whose recommendations are being actioned. The insight_id can be fetched from the output context path (InfobloxCloud.IQForTDInsight.insight_id) of the 'infobloxcloud-iq-for-td-insight-list command'.Required
recommendation_idUUID of the recommendation to action. The recommendation_id can be fetched from the output context path (InfobloxCloud.IQForTDInsight.key_recommendations.id) of the 'infobloxcloud-iq-for-td-insight-get command'.

Example: dummy-recommendation-id-1.
Required
actionAction verb to execute, overriding the server's default. If not specified, the server selects the canonical verb for the recommendation type: 'block' for indicator, 'mark_risky' for asset, or 'update_policy' for policy.Optional

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsightAction.insight_idStringThe unique display identifier of the insight whose recommendations were actioned.
InfobloxCloud.IQForTDInsightAction.recommendation_idStringUUID of the recommendation that was actioned.
InfobloxCloud.IQForTDInsightAction.actionStringThe action verb that was executed (e.g., block, mark_risky, update_policy).
InfobloxCloud.IQForTDInsightAction.statusStringOutcome status of the action (succeeded or failed).
InfobloxCloud.IQForTDInsightAction.audit_entry_idStringID of the audit log entry; can be used to reverse this action. Empty on failure.
InfobloxCloud.IQForTDInsightAction.reasonStringClassification of the outcome (e.g., applied, already_applied, action_failed, resource_not_found, invalid_request, not_eligible).
InfobloxCloud.IQForTDInsightAction.messageStringHuman-readable detail for failed items. Empty on success.

Command example#

!infobloxcloud-iq-for-td-insight-action-execute insight_id="insight-v2-001" recommendation_id="dummy-recommendation-id-1"

Context Example#

{
"InfobloxCloud": {
"IQForTDInsightAction": {
"action": "block",
"status": "succeeded",
"audit_entry_id": "dummy-audit-entry-1",
"reason": "applied",
"message": "",
"insight_id": "insight-v2-001",
"recommendation_id": "dummy-recommendation-id-1"
}
}
}

Human Readable Output#

Action execution result for the given IQ for TD Insight: insight-v2-001#

Recommendation IdActionStatusAudit Entry IdReason
dummy-recommendation-id-1blocksucceededdummy-audit-entry-1applied

infobloxcloud-iq-for-td-insight-action-undo#


Undo a previously executed recommendation action on a specific IQ for TD Insight from Infoblox Cloud.

Base Command#

infobloxcloud-iq-for-td-insight-action-undo

Input#

Argument NameDescriptionRequired
audit_entry_idID of the audit log entry to undo. The audit_entry_id can be fetched from the output context path (InfobloxCloud.IQForTDInsightAction.audit_entry_id) of the 'infobloxcloud-iq-for-td-insight-action-execute command'.

Example: dummy-audit-entry-1.
Required

Context Output#

PathTypeDescription
InfobloxCloud.IQForTDInsightAction.audit_entry_idStringID of the audit log entry that was undone.
InfobloxCloud.IQForTDInsightAction.actionStringThe undo action that was performed (e.g., allow, undo_risky, revert_policy).
InfobloxCloud.IQForTDInsightAction.statusStringOutcome status of the undo operation (succeeded or failed).

Command example#

!infobloxcloud-iq-for-td-insight-action-undo audit_entry_id="dummy-audit-entry-1"

Context Example#

{
"InfobloxCloud": {
"IQForTDInsightAction": {
"action": "allow",
"status": "succeeded",
"audit_entry_id": "dummy-audit-entry-1"
}
}
}

Human Readable Output#

Action undo result for the given audit entry: dummy-audit-entry-1#

Audit Entry IdActionStatus
dummy-audit-entry-1allowsucceeded

Migration Guide#

If the Ingestion Type parameter was configured as SOC Insight, update it to IQ for TD Insight. Once updated, configure the relevant IQ for TD Insight Status, IQ for TD Insight Severity, and IQ for TD Insight Threat Properties filter parameters to match the fetch behavior previously configured via the SOC Insight filter parameters (SOC Insight Status, SOC Insight Threat Type, SOC Insight Priority Level).

Migrated Commands#

Some of the previous integration's commands have been migrated to new commands. Below is the table showing the commands that have been migrated to the new ones.

SOC Insight CommandMigrated IQ for TD Insight Command
infobloxcloud-soc-insight-listinfobloxcloud-iq-for-td-insight-list
infobloxcloud-soc-insight-event-listinfobloxcloud-iq-for-td-insight-event-list
infobloxcloud-soc-insight-indicator-listinfobloxcloud-iq-for-td-insight-indicator-list
infobloxcloud-soc-insight-asset-listinfobloxcloud-iq-for-td-insight-asset-list

Deprecated Commands#

Some of the previous integration's commands have been deprecated, for which there is no replacement available.

Deprecated Command
infobloxcloud-soc-insight-comment-list