An Update to the DomainTools App for Splunk
ID: e59e76fb-674c-5800-b8cd-457351496014
STIX ID: report--e59e76fb-674c-5800-b8cd-457351496014
Feed Name: DomainTools
The post announces DomainTools App for Splunk 4.2, highlighting enhancements that streamline SOC workflows and performance: auto-refreshing Threat Profile/Monitoring panels, simplified triage from Enterprise Security, allowlist/monitoring actions from Enrichment Explorer, a new regex-based extraction macro, multivalue URL enrichment, and disabled-by-default logging. It also adds informational urgency tags, expanded allowlist configurations, replaces “Active Domains” with “Risky Observed Domains,” shifts timelines to event counts, preserves search time frames, supports defanged domains, removes confusing sparklines, and provides improved in-app documentation and a forthcoming webinar.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
