---
title: "Summary"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/271975496/Summary"
format: markdown
---
The *Dossier Summary Report* provides a comprehensive overview of threat indicator information, including DNS records, domain/subdomain count, URL count, and IP count. The report includes:

- A representative screenshot of queried domains.
- The Infoblox Intelligence section, which includes Web Category, TLD Score, and Nameserver Reputation.
- Additional features such as Categorizations and Lookalike Detection.
- Links to summary detail reports generated from a Dossier search.
- Sensative content is blurred for some categories (e.g., Terrorism and Pornography).

## Reported Threat Classes and Properties

For information on the threat classes and properties reported, see the *Infoblox Threat Classification Guide *located at **Security** > **Research** > **Resources** > **Classification Guide**. 

![image](media://63439836-1585-485d-91d5-cc9e6baa5aad)

![call-out A](media://633cbcb2-607b-420a-93fb-e896c9aab19a)

<span style="color: #000000">**Summary Detail Reports**</span><span style="color: #000000">: The links to the generated summary detail reports resulting from conducting a Dossier search are displayed here. Do note that not every Dossier search results in generating all summary setails reports. Only the summary detail reports applicalbe to the Dossier search are returned; these are indicated by a light-blue colored hyperlink. Unavailable reports are indicated in light gray. The following detail reports are available (the quantity and types of available reports are dependent on the threat indicator being searched). </span>

- <span style="color: #000000">Impacted Devices</span>
- <span style="color: #000000">Current DNS</span>
- <span style="color: #000000">Related Domains</span>
- <span style="color: #000000">Related URLs</span>
- <span style="color: #000000">Related IPs</span>
- <span style="color: #000000">Related File Samples</span>
- <span style="color: #000000">Related Contacts</span>
- <span style="color: #000000">Reports</span>
- <span style="color: #000000">Timeline</span>
- <span style="color: #000000">Threat Actor</span>
- MITRE ATT&CK
- WHOIS Record
- <span style="color: #000000">Raw Whois</span>

![call-out B](media://37031ed0-608b-4547-8c2b-e2d530e0c449)

<span style="color: #000000">**Dossier Summary**</span><span style="color: #000000">: The Summary report displays a representative screenshot of queried domains. Although a screenshot is a cropped version of a website's index page, clicking the </span><span style="color: #000000">**Full Image**</span><span style="color: #000000"> link (located below the screenshot) will call up a screenshot of the entire index page, including the date on which the screenshot was captured and the page's title. Because a screenshot is a cached version of a website's index page, the current index page might or might not reflect what is currently published on the live website's index page.</span>

Domain information included in the summary report identifies whether a domain is benign or malicious. For malicious domains, the summary provides the reasons it is classified as harmful. If the domain is associated with a known threat actor, the summary also includes details about that actor, such as its objectives and the techniques it uses to defraud or harm users. Additionally, a timeline shows the domain’s recorded activity and status over the reported historical period.  


> ℹ️ **Disclaimer**
> ℹ️ 
> ℹ️ The images and screenshots that we provide to you as part of the threads or that you build for use with our products are operated and owned by third parties. We have no control over, are not responsible for, and do not endorse any of these third parties’ websites, materials, or content. We provide these items and access to them “as is” and “as applicable”, and we neither warrant nor take any responsibility for them.

In cases where sensitive content is not displayed on the **Summary** page, a blurred image of the page will be displayed along with a disclaimer requesting that viewers acknowledge that they are choosing to view sensitive content. We blur the following categories of domains that we know to contain sensitive content:

- Abortion
- Abortion Pro Choice
- Child Inappropriate
- Gambling
- Gay, Lesbian, or Bisexual
- Lingerie, Suggestive and Pinup
- Nudity
- Pornography
- Profanity
- R-Rated
- Sex and Erotic
- Sex Education
- Child Abuse images
- Terrorism
- Unknown

<span style="color: #000000">The following information also be viewed in the summary section:</span>

- <span style="color: #000000">**DNS Record Count**</span><span style="color: #000000">: The number of DNS records associated with the queried threat indicator. </span>
- <span style="color: #000000">**Domain/Subdomain Count**</span><span style="color: #000000">: The number of doamins and/or subdomains associated with the queried threat indicator. </span>
- <span style="color: #000000">**URL Count**</span><span style="color: #000000">: The number of URLs associated with the queried threat indicator. </span>
- <span style="color: #000000">**IP Count**</span><span style="color: #000000">: The number of IP addresses associated with the queried threat indicator. </span>

![call-out C](media://33ab5164-8e5b-4e93-b0bb-b89c0595e05e)

<span style="color: #000000">**Infoblox Intelligence**</span><span style="color: #000000">: </span>The Infoblox intelligence section of the report includes information acquired by Infoblox during the course of investigation of the threat indicator. For additional information, the individual information panes of the intelligence section can be expanded by clicking the down-pointing arrow icon. Similarly, the individual information panes for each section can be minimized by clickingthe up-pointing arrow icon.

Information reported in the *Infoblox* *Intelligence* section includes the following:

- **Web Category**: The web category the indicator is a member.
- **Info**: Information about the threat indicator.
- **TLD Score**: The risk score for the TLD calculated from the TLD's confidence, rarity, and popularity scores.
- **Nameserver Reputation**: Displays information on the domains associated with the nameserver, along with information on the nameserver's confidence, rarity, and popularity. The reputation of the nameserver is established based on the nameserver's confidence, rarity, and popularity scores.
- **DNS Ranking**: The DNS ranking as determined by Infoblox. Information on its query rank is also provided.
- **Threat Property**: The threat property associated with the indicator. Information on its query rank is also provided.
- **Industry DNS Rank**: A consensus rank determined by the aggragate of rankings provided by industry sources. Information on its query rank is also provided.
- **Dangling Domain**: A domain or subdomain is considered "dangling" when it points to a domain that no longer exists or is no longer controlled by its original owner. The term "dangling" suggests a DNS entry left unsupported or unconnected. Dossier reports the dangling CNAME (<span style="color: #001d35">canonical name</span>) and the level which is compromised.

<span style="color: #000000">**Dossier Search**</span><span style="color: #000000">:  Copy or paste your indicator search parameters into the search field followed by clicking Search to initiate an indicator search. The Dossier search feature accomodates searches for domains, IP addresses, hostnames, URLs, email, or hash value.</span>

![call-out D](media://a672361a-4290-4554-9595-28d0f7f8c5d5)

<span style="color: #000000">**Task Navigation Menu**</span><span style="color: #000000">: Click on one of the icons to perform a task.</span>  
  
> Macro (inline-media-image)

  
<span style="color: #000000">The task navigation menu. </span>

<span style="color: #000000">You can do the following, by clicking on the appropriate icon:</span>

## <span style="color: #000000">Reload Page</span>  


Click the reolad icon<span style="color: #000000">** **</span><span style="color: #000000">to reload the </span><span style="color: #000000">*Timeline Report*</span><span style="color: #000000"> page. </span>

## <span style="color: #000000">Add to Custom List</span><span style="color: #000000">** **</span>

To add a domain or IP address, complete the following:

1. On the Dossier **Timeline **report page, click the add to custom list icon** **located at the top, right-hand side of the Action bar.
2. <span style="color: #000000">On the </span><span style="color: #000000">*Add to Custom List*</span><span style="color: #000000"> page, select what custom list or lists from among the list of available custom lists to add the domain or IP address by clicking the blue arrow</span>> Macro (inline-media-image)

<span style="color: #000000">associated with the custom list. If you cannot locate the custom list you want to add the domain or IP address to, you can use the search feature to search for the custom list. Alternatively, you can click</span>> Macro (inline-media-image)

<span style="color: #000000">to add the domain or IP address to all custom lists. If you inadvertently add the domain or IP address, in the </span><span style="color: #000000">*Selected *</span><span style="color: #000000">column of custom lists, you can click the blue arrow associated with the custom list to remove the domain or IP address from it.</span>
3. Once you have added the domain or IP address to your custom list or lists, you can save your configuration by clicking **Add**.
  
4. You should now see the name of the custom list or lists where the domain or IP address has been added populating the *Custom Lists* section of the **Timeline** report page.

For informatioon on custom lists, see *[Creating Custom Lists](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469424)*. 

## <span style="color: #000000">Generate API Request</span>

Click the API Genrate icon to generate an API request. A pop-up window populated with the API information will be displayed.

> Macro (inline-media-image)

  
The *Generate API Request* window. 

  
Copy the information from the pop-up window. Click **Full API Guide** to view the Swagger Dossier API documentation. Click **Close** to close the window.

## <span style="color: #000000">Feedback on Results</span>

<span style="color: #000000">Click the load webform icon to load a webform where you can provide comments and feedback on results you obtained from Dossier. For details, see </span><span style="color: #000000">*[Dossier Threat Research Feedback](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/230493737)*</span><span style="color: #000000">.</span>  
  
> Macro (inline-media-image)

  
<span style="color: #000000">The </span><span style="color: #000000">*Feedback on Results*</span><span style="color: #000000"> pane. </span>

## <span style="color: #000000">Export</span>

<span style="color: #000000">Click the downloas Dossier report icon to export the Dossier Report file. You can choose to include any or all of the report sections by placing a check in the box associated with a specific section of the report. You can choose from among the following sections:</span>

- <span style="color: #000000">Summary</span>
- <span style="color: #000000">Impacted Devices</span>
- <span style="color: #000000">Current DNS</span>
- <span style="color: #000000">Related Domains</span>
- <span style="color: #000000">Related URLs</span>
- <span style="color: #000000">Related IPs</span>
- <span style="color: #000000">Related File Samples</span>
- <span style="color: #000000">Related Contacts</span>
- <span style="color: #000000">Reports</span>
- <span style="color: #000000">Timeline</span>
- <span style="color: #000000">Threat Actor</span>
- MITRE ATT&CK
- WHOIS Record
- <span style="color: #000000">Raw Whois</span>

> Macro (inline-media-image)

  
<span style="color: #000000">The </span><span style="color: #000000">*Export Dossier Report*</span><span style="color: #000000"> pane. </span>

<span style="color: #000000">When you have finished selecting what sections of the report to export, click</span><span style="color: #000000">** Export**</span><span style="color: #000000"> in the bottom right-hand corner of the dialogue box. Your report will be exported in PDF format.</span>


<span style="color: #000000">When available, the top navigation bar also displays a clickable link where you can find additional information on the indicator.  </span>

![call-out E](media://5e8034a2-2391-4a31-9c6b-9ce511a62ec2)

<span style="color: #000000">**Dossier Search**</span><span style="color: #000000">:  Copy or paste your indicator search parameters into the search field followed by clicking Search to initiate an indicator search. The Dossier search feature accomodates searches for domains, IP addresses, hostnames, URLs, email, or hash value. </span>

![call-out F](media://27834a17-acc3-49f4-b743-4dfaa6c48e6d)

<span style="color: #000000">**Resources: **</span><span style="color: #000000">Click Resources and select an option from the drop-down menu to view a Dossier resource. </span>

<span style="color: #000000">The available resources include the following: </span>

- **Dossier & TIDE Quick Start Guide**
- **Dossier API Calls Reference**
- **Dossier Source Descriptions**
- **Dossier User Guide**
- **Threat Classification Guide**

![call-out G](media://94409c7f-e337-4002-823f-4e3e982dd7d8)

<span style="color: #000000">**Registered Owner**</span><span style="color: #000000"> (WHOIS):  </span>The Registered Owner (WHOIS) record for the indicator contains information about the domain:

- **Created**: the date (month/day/year) on which the domain was created
- **Updated**: the date (month/day/year) on which the domain was updated most recently
- **Expires**: the date (month/day/year) on which the current domain’s registration expires
- **Registrant Name**: the name of the person or entity who registered the domain
- **Registrant Organization**: the name of the organization associated with the domain’s registration
- **Registrant Country**: the country where the domain registrant resides
- **Registrar Name**: the name of the domain’s registrar where the domain was registered

![call-out H](media://30e470a3-2183-49f3-aac3-c13d98f786fa)

<span style="color: #000000">**DNS Threat Actor**</span><span style="color: #000000">: This section provides information about threat actors associated with the threat indicator. </span>

![call-out I](media://f0f0ad9b-f64b-4a25-88de-ecaa8e022841)

<span style="color: #000000">**SSL Certificate**</span><span style="color: #000000">: The SSL Certificate section displays the data pulled from the SSL certificate associated with the queried domain name. The section contains information about the SSL certificate itself and about its issuer and domain. As in the Raw WHOIS section, the Details dropdown displays the raw data from the SSL certificate.</span>

![call-out J](media://002b7e8f-a19c-41e4-96d5-690768bdc18d)

<span style="color: #000000">**Detection History Timeline**</span><span style="color: #000000">: This is the timeline of events associated with an indicator. Timeline events are updated with the most current information.</span>

The detection history time line displays information on current (active) threat classifications and past threat classifications for the indicator. The information reported in each timeline includes the following: 

- **Indicator name**: The name of the threat indicator.
- **Feed name**: The name of the threat feed where the indicator was detected along with its risk level score.
- **Detection history date**: The date the detection information was obtained/documented.
- **Threat level**: The indicator's threat level classification as of the current date. This is a numerical score which can be translated into a threat classification (**High**, **Medium**, **Low**, or **Info**).
- **Risk level**: The indicator's risk level. This is a numerical score which can be translated into a threat risk level (**High**, **Medium**, **Low**, or **Info**).
- **Threat Confidence**: The indicator's threat confidence score.
- **Infoblox Threat intelligence Group Research Notes**: Threat notes acquired by inflblox through investigationh of the threat.

Do note that the historical record is documented based on the date the threat was accessed. 

Click **View Full Timeline** to view the *[Timeline report](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/230428633)*. 

> ⚠️ **Note**
> ⚠️ 
> ⚠️ Data from Mandiant and Emerging Trends Proofpoint will be displayed (in the timeline and elsewhere) only for organizations that possess separate, paid licenses from data vendors. Infoblox does not support free licenses.

## Custom List

The custom list section displays information about the custom listswhere the indicator appears. 

> Macro (inline-media-image)

  
The *Add to Custom List* pane. 

<span style="color: #000000">You can also do the following on the page: </span>

- <span style="color: #000000">**Background Tasks**</span><span style="color: #000000">: Click the hourglass icon to open the side panel to view a list of all running background tasks. </span>
- **Global Search**: Click the search icon in the Search text box, then enter your search criterion. Alternatively, select the criterion if it appears under Recent Searches, which shows tool information, console messages, and other information used in recent searches. The <span style="color: #172b4d">Infoblox</span> Portal will show all records that match the search criterion.<span style="color: #000000"> </span>

<span style="color: #000000">Click </span><span style="color: #000000">*[here](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/230493467)*</span><span style="color: #000000"> to return to the main </span><span style="color: #000000">*Dossier Threat indicator Report.*</span>