Skip to main content

How to find is a domain is suspicious or not

  • April 4, 2025
  • 3 replies
  • 35 views

MikelSA
Forum|alt.badge.img+8

Hi there, how u doing!

So, im with this block where im trying to find if a domain is suspicious or not. 

I receive an domain as input, create the entity, do a whois, and then is there any posibility with siemplify or google chronicle to check if the domain is suspicious or not?

I mean, i dunno if im doing right or not, but i tried the enrich domain from chronicle and it doesnt work. Probably im doing it wrong.

Any ideaas? Thanks!

3 replies

f3rz
Staff
Forum|alt.badge.img+10
  • Staff
  • April 4, 2025

Enrich Domain from Chronicle integration will only return the data if that domain is created as IOC in SIEM (Chronicle). 

I recommend you to review this article regarding IOCs in SIEM: https://medium.com/@thatsiemguy/ioc-matching-in-chronicle-siem-45a97c0b91a8


MikelSA
Forum|alt.badge.img+8
  • Author
  • Bronze 2
  • April 4, 2025

Oh thanks, so if it doesnt return data, is not suspicious. Thank you!


SoarAndy
Staff
Forum|alt.badge.img+12
  • Staff
  • April 4, 2025

Whois wont tell you if it's malicious

For a verdict you should use Threat Intel (VirusTotal, Mandiant, GTI, or any other vendor).  If you use a marketplace Action for a TI provider, in addition to the JSON output, the Entity should change colour to red, and [entity.isSuspicious] will be true.  From this you can do Flow conditions: 
If [entity.isSuspicious] contains True >> this is a catch all 'something in this Alert is bad'
Or you can do more fine controlled testing depending on your usecase