DNS
dns (domain name system) is a protocol that translates domain names into ip addresses, enabling communication across the internet the domain name system (dns) is a foundational internet service that translates domain names into ip addresses and provides critical network telemetry the dns connector for swimlane turbine enables automated retrieval of dns records for any domain and reverse resolution of ip addresses to domain names, all without manual queries or scripting by integrating dns data directly into turbine playbooks, security teams can enrich investigations, accelerate threat detection, and enhance incident response workflows with real time dns intelligence this seamless automation empowers users to quickly identify suspicious domains, map network relationships, and validate indicators of compromise within their security operations capabilities get records resolve domain from ip the swimlane dns connector allows you to retrieve dns records for the following record type txt cname soa ns mx cert dname ptr a aaaa spf srv url considerations as part of the action, you can specify the default nameserver from which to retrieve dns records by default, it uses the default nameservers specified on your turbine instance actions get records obtain dns records for a specified domain by providing the required domain name as input input argument name type required description domain string required parameter for get records records string optional parameter for get records default nameservers string optional name of the resource input example {"domain" "swimlane com","records" "txt,a","default nameservers" "8 8 8 8,8 8 4 4"} output parameter type description txt array output field txt cname array name of the resource soa array output field soa ns array output field ns mx array output field mx cert array output field cert dname array name of the resource ptr array output field ptr rp array output field rp a array output field a aaaa array output field aaaa spf array output field spf srv array output field srv uri array output field uri headers array http headers for the request headers file name string http headers for the request headers file string http headers for the request reason string response reason phrase status code number http status code of the response output example {"txt" \[],"cname" \[],"soa" \[],"ns" \[],"mx" \[],"cert" \[],"dname" \[],"ptr" \[],"rp" \[],"a" \[],"aaaa" \[],"spf" \[],"srv" \[],"uri" \[],"headers" \[]} resolve domain from ip retrieve the domain name linked to a specified ip address using dns resolution endpoint method get input argument name type required description ip address string required ipv4 or ipv6 address to resolve timeout number optional timeout in seconds for the dns lookup (default is 3 seconds) input example {"ip address" "31 13 80 36","timeout" 3} output parameter type description primary hostname string name of the resource output example {"primary hostname" "edge star mini shv 01 yyz1 facebook com"} response headers header description example content type the media type of the resource application/json date the date and time at which the message was originated thu, 01 jan 2024 00 00 00 gmt