- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-15-2024 07:09 AM
Hello @tlmarques, I would first check out the free feeds and free enrichers content packs in the XSOAR marketplace. These provide a large list of free feeds and enrichment integrations that can be used to help determine whether a domain is malicious or not. You can also leverage the Unit42 ATOMs feed as well. Overall I would not rely on a single feed or enrichment source to determine if an indicator is malicious or not. Try to enrich the URLs and domains against a few different enrichment sources to see what the verdict is. Some good enrichment sources for domains: VirusTotal, whois, Ipinfo. Combine those enrichment sources with feeds such as Unit42 ATOMs, SpamHaus, OpenPhish and this can help you to determine if an URL or Domain is malicious or not.