Automated Data Services Overview
  • 08 Feb 2024
  • 1 Minute to read
  • Dark
    Light

Automated Data Services Overview

  • Dark
    Light

Article summary

ThreatConnect® leverages several automated data services to enable automated correlation and discovery of threat intelligence. These services allow analysts to efficiently investigate and analyze Domain Name System (DNS) relationships, registrants for Internet resources (using the WHOIS protocol), IP address geographic information, and location and count information for computers that attempted to access suspicious domains captured by Quad9® infrastructure within the last 90 days.

The following data services are currently available from the relevant Indicators’ Details screen:

Before You Start

Minimum Role(s)
  • Organization role of Read Only User (for viewing information provided by automated data services)
  • Organization role of Standard User (for activating and deactivating automated data services)
Prerequisites
  • An Address Indicator created in one of your ThreatConnect owners (to view IP geolocation data and Address DNS resolutions)
  • A Host Indicator created in one of your ThreatConnect owners (to view Host DNS resolutions, IP geolocation data for Addresses that have resolved to the Host, and WHOIS information)

ThreatConnect® is a registered trademark of ThreatConnect, Inc.
Quad9® is a registered trademark of Quad9 Foundation.

20030-01 v.12.A


Was this article helpful?


What's Next