CHAPTER 11Iris by DomainTools
If I had to pick a single tool that was most useful while investigating The Dark Overlord, it would be Iris.
DomainTools Iris is easily the most comprehensive and impressive historical domain registration search tool on the market. It is a full threat intelligence and investigation platform focused on providing context on threats with domain registration and Passive DNS data.
Iris is a paid proprietary tool. I do my best to include tools that are open source, but the truth is I have not found any other tool that even comes close to the capabilities I will demonstrate.
DomainTools not only has the most comprehensive database of historical domain registration data I have ever seen, but the tool itself is pretty amazing. (No, they are not paying me to write this—but now that I think about it, I probably should have asked.)
The Basics of Iris
This section will only cover the basics of Iris as we explore my personal website. We will dive deeper into Iris in subsequent sections as we start to combine it with other techniques. Iris is a great tool by itself, so combining it with other tools and techniques will make it that much more powerful, especially once we start pulling all of the discovered information together in our tracking matrix (which we will begin constructing in Part IV of this book).
We can start using Iris by searching for any number of fields, including domain names, personal names, email addresses, physical addresses, IP addresses, ...
Get Hunting Cyber Criminals now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.