Skip to main content

Infoblox Threat Defense with DDI

Download With Dependencies

Utilize the Infoblox Threat Defense with DDI integration to manage IQ for TD Insight incident response, indicator enrichment, and block cyber threats.

Note: Support for this Pack was moved to Partner starting August 25, 2025. In case of any issues arise, please contact the Partner directly at support@infoblox.com or https://support.infoblox.com/.

What does this pack do?

The Infoblox Threat Defense with DDI integration leverages DNS as a security control point to detect and block cyber threats. This integration enables threat intelligence sharing, automated IQ for TD Insight incident response, automated indicator enrichment, and DNS-based security controls within your Cortex XSOAR environment.

DNS Security

  • Protects the network at the DNS level, which is often the very first point of contact for cyberattacks, ensuring that threats are intercepted and mitigated before they can progress deeper into the infrastructure.
  • Blocks and unblocks malicious domains and IP addresses by preventing access to harmful destinations while allowing administrators to manage and maintain control over legitimate network usage.

Threat Intelligence

  • Provides SOC teams with actionable IQ for TD Insights with detailed information about indicators, events, and assets, to detect, investigate, and respond to threats more effectively.
  • Provides visibility into indicators of compromise (IoCs) and enriches them with context for faster investigation.

DDI

  • Tightly integrates security with DNS, DHCP, and IPAM, turning these core network services into enforcement points where malicious activity can be detected and blocked in real time.

Pack Use-cases

  • Retrieve comprehensive threat intelligence about domains, hosts, and IP addresses.
  • Detect and block malicious domains and IP addresses using the Threat Defense platform.
  • Identify lookalike domains that may indicate potential phishing attempts.
  • Manage custom security lists for blocking or allowing specific domains and IP addresses.
  • Automate threat response by integrating with existing security workflows.
  • Enrich indicators with DNS-based threat intelligence data for better security decisions.
  • Unblock previously blocked indicators when they are no longer considered malicious.

Support

  • For technical support or troubleshooting, please contact Infoblox Support at https://www.infoblox.com/support/
  • For documentation and resources, visit https://docs.infoblox.com/
  • For issues related to Cortex XSIAM (parsing/modeling rules, timestamp behavior, event collection), please open a support case with Palo Alto Networks Support, as these are owned and maintained solely by the Cortex content team.

Contact

Note: Support for this Pack was moved to Partner starting August 25, 2025. In case of any issues arise, please contact the Partner directly at support@infoblox.com or https://support.infoblox.com/.

What does this pack do?

The Infoblox Threat Defense with DDI integration leverages DNS as a security control point to detect and block cyber threats. This integration enables threat intelligence sharing, automated IQ for TD Insight incident response, automated indicator enrichment, and DNS-based security controls within your Cortex environment.

DNS Security

  • Protects the network at the DNS level, which is often the very first point of contact for cyberattacks, ensuring that threats are intercepted and mitigated before they can progress deeper into the infrastructure.
  • Blocks and unblocks malicious domains and IP addresses by preventing access to harmful destinations while allowing administrators to manage and maintain control over legitimate network usage.

Threat Intelligence

  • Provides SOC teams with actionable IQ for TD Insights with detailed information about indicators, events, and assets, to detect, investigate, and respond to threats more effectively.
  • Provides visibility into indicators of compromise (IoCs) and enriches them with context for faster investigation.

DDI

  • Tightly integrates security with DNS, DHCP, and IPAM, turning these core network services into enforcement points where malicious activity can be detected and blocked in real time.

Pack Use-cases

  • Retrieve comprehensive threat intelligence about domains, hosts, and IP addresses.
  • Detect and block malicious domains and IP addresses using the Threat Defense platform.
  • Identify lookalike domains that may indicate potential phishing attempts.
  • Manage custom security lists for blocking or allowing specific domains and IP addresses.
  • Automate threat response by integrating with existing security workflows.
  • Enrich indicators with DNS-based threat intelligence data for better security decisions.
  • Unblock previously blocked indicators when they are no longer considered malicious.

Support

  • For technical support or troubleshooting, please contact Infoblox Support at https://www.infoblox.com/support/
  • For documentation and resources, visit https://docs.infoblox.com/
  • For issues related to Cortex XSIAM (parsing/modeling rules, timestamp behavior, event collection), please open a support case with Palo Alto Networks Support, as these are owned and maintained solely by the Cortex content team.

Contact

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByPartner
CreatedMarch 1, 2023
Last ReleaseSeptember 14, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
By downloading or using Marketplace content, you agree to the applicable Terms of Use and End User License Agreement. Third-party content is provided by its publisher, and Palo Alto Networks does not warrant, endorse, support, or assume responsibility for content not expressly identified as owned by Palo Alto Networks.