"Domain": {
"Name": "STRING, The domain name, for example: 'google.com'.",
"EntityA": "STRING, The source of the relationship.",
"EntityB": "STRING, The destination of the relationship.",
"Relationship": "STRING, The name of the relationship.",
"EntityAType": "STRING, The type of the source of the relationship.",
"EntityBType": "STRING, The type of the destination of the relationship.",
"DNS": "STRING, A list of IP objects resolved by DNS.",
"DetectionEngines": "NUMBER, The total number of engines that checked the indicator.",
"PositiveDetections": "NUMBER, The number of engines that positively detected the indicator as malicious.",
"CreationDate": "DATE, The date that the domain was created.",
"UpdatedDate": "DATE, The date that the domain was last updated.",
"ExpirationDate": "DATE, The expiration date of the domain.",
"DomainStatus": "STRING, The status of the domain.",
"NameServers": "STRING, Name servers of the domain.",
"Organization": "STRING, The organization of the domain.",
"Subdomains": "STRING, Subdomains of the domain.",
"Admin": {
"Country": "STRING, The country of the domain administrator.",
"Email": "STRING, The email address of the domain administrator.",
"Name": "STRING, The name of the domain administrator.",
"Phone": "STRING, The phone number of the domain administrator."
},
"Registrant": {
"Country": "STRING, The country of the registrant.",
"Email": "STRING, The email address of the registrant.",
"Name": "STRING, The name of the registrant.",
"Phone": "STRING, The phone number for receiving abuse reports."
},
"Tags": "STRING, Tags of the domain.",
"FeedRelatedIndicators": {
"value": "STRING, Indicators that are associated with the domain.",
"type": "STRING, The type of the indicators that are associated with the domin",
"description": "STRING, The description of the indicators that are associated with the domain."
},
"MalwareFamily": "STRING, The malware family associated with the domain.",
"WHOIS": {
"DomainStatus": "STRING, The status of the domain.",
"NameServers": "STRING, A list of name servers, for example: 'ns1.bla.com, ns2.bla.com'.",
"CreationDate": "DATE, The date that the domain was created.",
"UpdatedDate": "DATE, The date that the domain was last updated.",
"ExpirationDate": "DATE, The date that the domain expires.",
"Registrant": {
"Name": "STRING, The name of the registrant.",
"Email": "STRING, The email address of the registrant.",
"Phone": "STRING, The phone number of the registrant."
},
"Registrar": {
"Name": "STRING, The name of the registrar, for example: 'GoDaddy'.",
"AbuseEmail": "STRING, The email address of the contact for reporting abuse.",
"AbusePhone": "STRING, The phone number of contact for reporting abuse."
},
"Admin": {
"Name": "STRING, The name of the domain administrator.",
"Email": "STRING, The email address of the domain administrator.",
"Phone": "STRING, The phone number of the domain administrator."
}
},
"WHOIS/History": "List of Whois objects",
"Malicious":{
"Vendor": "STRING, The vendor reporting the domain as malicious.",
"Description": "STRING, A description explaining why the domain was reported as malicious."
},
"DomainIDNName": "STRING, The internationalized domain name (IDN) of the domain.",
"Port": "STRING, Ports that are associated with the domain.",
"Internal": "BOOL, Whether or not the domain is internal or external.",
"Category": "STRING, The category associated with the indicator.",
"Campaign": "STRING, The campaign associated with the domain.",
"TrafficLightProtocol": "STRING, The Traffic Light Protocol (TLP) color that is suitable for the domain.",
"ThreatTypes": {
"threatcategory": "STRING, The threat category associated to this indicator by the source vendor. For example, Phishing, Control, TOR, etc.",
"threatcategoryconfidence": "STRING, Threat Category Confidence is the confidence level provided by the vendor for the threat type category For example a confidence of 90 for threat type category 'malware' means that the vendor rates that this is 90% confidence of being a malware."
},
"Geo":{
"Location": "STRING, The geolocation where the domain address is located, in the format: latitude:longitude.",
"Country": "STRING, The country in which the domain address is located.",
"Description": "STRING, Additional information about the location."
},
"Tech": {
"Country": "STRING, The country of the domain technical contact.",
"Name": "STRING, The name of the domain technical contact.",
"Organization": "STRING, The organization of the domain technical contact.",
"Email": "STRING, The email address of the domain technical contact."
},
"CommunityNotes": {
"note": "STRING, Notes on the domain that were given by the community.",
"timestamp": "DATE, The time in which the note was published."
},
"Publications": {
"source": "STRING, The source in which the article was published.",
"title": "STRING, The name of the article.",
"link": "STRING, A link to the original article.",
"timestamp": "DATE, The time in which the article was published."
},
"Billing": "STRING, The billing address of the domain.",
}