Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Potent New Tool in Fight Against Cybercrime
Articles

Potent New Tool in Fight Against Cybercrime

ISBuzz TeamBy ISBuzz TeamSeptember 24, 2015Updated:September 28, 20154 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Over 50k Premium WordPress Gift Card Plugin Hit By Hackers.
Over 50k Premium WordPress Gift Card Plugin Hit By Hackers.
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Internet can be a great place to hide. There are over 300 million domain names, over 4 billion IP addresses and many more nameservers, hostnames and email addresses within the infrastructure of DNS. Criminals make use of all of these resources to attack their targets, moving often and hiding in plain sight behind Whois privacy and shared hosting environments.

Within this context, threat intelligence analysts and incident response professionals must make critical decisions about proper defenses or countermoves. They need reliable information quickly, and must arm themselves with the best tools and data in order to expose threat infrastructure and defeat criminal networks. As of September 15, they have a potent new tool in the fight—DomainTools Iris.

Iris is a proprietary threat intelligence and investigation platform that combines enterprise-grade domain and DNS-based intelligence with an intuitive web interface designed to security teams quickly and efficiently investigate potential cybercrime and cyberespionage.

DomainTools emphasizes several specifics on how Iris delivers on its customer promise :

  • Better Data Yields Better Answers—Over the course of 15+ years, DomainTools has amassed the world’s largest database of domain profile information help teams avoid the blind spots that often stymie investigations relying on inferior data sources.
  • Designed By Investigators, For Investigators—DomainTools’ development team, many of them seasoned investigators in their own right, worked with some of the best security teams in the world to build a tool that reflects their best practices and methodologies.
  • Changes the Economics of Attribution—The expense of hiring external expertise or assigning internal resources to adversary analysis has always been prohibitive. DomainTools Iris seeks to change the equation, enabling high-confidence profiling and attribution at costs far below traditional means.
  • Provides Visibility Beyond the Firewall—Simply identifying malicious domains and IP addresses doesn’t protect organizations against the extended networks operated by threat actors. Iris gives organizations the ability to create forensic maps of criminal activity to triage threat indicators, assess risk, and prevent future attacks.

Inside the SOC :

There are specific ways in which security teams use DNS profile data in their moment-to-moment operations. Fundamentally, they continually seek the answers to two key questions: who is attacking me? and what is the extent of their infrastructure? The answers to those questions help teams align their defenses with the threats they face.

The starting point often is a single IOC (indicator of compromise). Using Iris, the investigator then surfaces a larger network of connected infrastructure.

In the context of a “continuous security” model, they can use the intel data across tenses of time :

  • Present: with a map of infrastructure connected to the original IOC, teams can immediately lock down against the extended list of assets, e.g. in firewall/IPS/UTM rules
  • Past: analysts can query archived logs and alerts for the now-expanded list of infrastructure, to see if threat actors were previously operating on their network
  • Future: DomainTools offers monitoring tools (separate from Iris) that allow the tracking of new registrations, hosting changes, and more, which can help defenders stay ahead of attackers’ moves

Who Uses Domain Profile Threat Intelligence Data?

Many of the largest organizations in the world, across all major verticals, are already power-users of DomainTools. Not surprisingly, these tend to be sophisticated shops that often consume threat intelligence data at large scale via APIs. With Iris, DomainTools intends to democratize threat intelligence by bringing this power to a much broader spectrum of organizations.[su_box title=”About DomainTools” style=”noise” box_color=”#336588″]DomianToolsDomainTools is the leader in domain name and DNS-based cyber threat intelligence. With over 14 years of ‘cyber fingerprint’ data across the global Internet, DomainTools helps companies assess security threats, profile attackers, investigate online fraud and crimes, and map cyber activity in order to stop attacks. Fortune 1000 companies, global government agencies, and many security solution vendors use the DomainTools platform as a critical ingredient in their threat investigation and mitigation work.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}