ipinfo Deprecated

Deprecated. Use IPinfo v2 instead. Use the ipinfo.io API to get data about an IP address

Data Enrichment & Threat Intelligence · Ipinfo

Details

IDipinfo
ProviderIPinfo
CategoryData Enrichment & Threat Intelligence
From Version5.0.0
Supported ModulesAgentix XSIAM

README

Use the ipinfo.io API to get data about an IP address

IPinfo v2 is now available

It’s recommended to use IPinfo v2, rather than IPinfo:

  • IPinfo v2 allows setting source reliability.
  • IPinfo v2 enriches data with IP-hostname relationships.
  • On IPinfo v2, the ip-field command has been removed: all outputs are available by running ip.

Configure IPinfo in Cortex

Parameter Description Required
proxy Use system proxy settings False
token API Token (optional) False
insecure Trust any certificate (not secure) False
use_https Use HTTPS connections False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

ip


Check IP reputation (when information is available, returns a JSON with details). Uses all configured Threat Intelligence feeds

Base Command

ip

Input

Argument Name Description Required
ip IP address to query. E.g. !ip 1.1.1.1 Required

Context Output

Path Type Description
IP.Address String The IP address
IP.Hostname String The IP hostname
IP.ASN String The IP ASN
IP.Geo.Location String The IP geographic location in coordinates
IP.Geo.Country String The IP country
IP.Geo.Description String The IP location as <City, Region, Postal Code, Country>
IP.ASOwner string The IP AS owner
IP.FeedRelatedIndicators.value string Indicators that are associated with the IP
IP.FeedRelatedIndicators.type string The type of the indicators that are associated with the IP
IP.Tags string Tags that are associated with the IP
IP.Registrar.Abuse.Address string The IP registrar abuse address
IP.Registrar.Abuse.Country string The IP registrar abuse country
IP.Registrar.Abuse.Name string The IP registrar abuse name
IP.Registrar.Abuse.Network string The IP registrar abuse network
IP.Registrar.Abuse.Phone string The IP registrar abuse phone
IP.Registrar.Abuse.Email string The IP registrar abuse email
IP.Organization.Name string The IP organization name
IP.Organization.Type string The IP organization type
DBotScore.Indicator string The indicator that was tested.
DBotScore.Type string The indicator type.
DBotScore.Vendor string The vendor used to calculate the score.
DBotScore.Score Number The actual score.

Command Example

!ip ip=1.1.1.1

Human Readable Output

Key Value
city Miami
country US
hostname one.one.one.one
ip 1.1.1.1
loc 25.7867,-80.1800
org AS13335 Cloudflare, Inc.
postal 33132
readme https://ipinfo.io/missingauth
region Florida
timezone America/New_York

ipinfo_field


Retrieve value for a specific field from the IP address information

Base Command

ipinfo_field

Input

Argument Name Description Required
ip IP address to query. E.g. !ip 1.1.1.1 Required
field Name of the field to retrieve. Can be org, city, geo, etc. Required

Context Output

There is no context output for this command.

Command Example

!ipinfo_field ip=1.1.1.1 field=city

Human Readable Output

Miami

Configuration parameters

  • proxy — Use system proxy settings
  • token — API Token (optional)
  • insecure — Trust any certificate (not secure)
  • use_https — Use HTTPS connections

Commands (2)

  • ip

    Check IP reputation (when information is available, returns a JSON with details). Uses all configured Threat Intelligence feeds

  • ipinfo_field

    Retrieve value for a specific field from the IP address information

commonfields:
  id: ipinfo
  version: -1
deprecated: true
name: ipinfo
display: ipinfo (Deprecated)
category: Data Enrichment & Threat Intelligence
provider: IPinfo
image: data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAHgAAAAyCAYAAACXpx/YAAAABGdBTUEAALGPC/xhBQAACf9JREFUeAHtWwtQVdcVXU++AhIUEQER0agv0XxE1AgaBOIHtVVm/E1IUu2Uxta242hIx2gSO6adNGhJ29QkTuiozadJplY0NmoSf4mJ37FBQmNQEX8RUaOIEB7I6dr3vlfv+yFTg3mXeXtmvXv+95y979lnn33OA/zUoTlg6dCjA7pyfJOI+4l4O0L5/Jo4SxwjNhFHCD+ZhAPy0c4ithFNhNJgsSiEBuoI7KSnOfKAL1lmKXEH4Scf5kAW+3aA0AUY2KkFQ3oqxIQpjOqtMO1uhbREhdn3K4QHKaTGKUSFGoV9gXXnE8GEn3yIA53YlxcIXVix4QpLHlRYP0shMVKhIE3hwE/1tCkD9fDb0xSiOyu8OEHhlckUdrxR0HvYVpwPje//7oowxuzUhQPYQBQggGr4F8OBdTOBqVbgVU7mjD7AzMHuY+zXjZ/EWOC5XYC1Oyhk4E85QII0hxHEfmKoRMxMZhdwAJm/jpikqdpXJluofoGQQODf54CDtKXmpnqXz309+QEkUbj8EITSEoE1uRSrNnkTmPIB0V+yzEpmF3ARGf8QornGrplqwRCDVn2jFMhPAQ2r1mUjH8Cmr4A6m14uikb2X2h4Z/aRuFjhGwnTGl9mFvA0Mv6XCA5QWDHOgoRIRu10oZ4KlrugCXc6Urw/u3amQu4FvF9xo0wg2bIsCxgQLWkDiVU3Ms0VMquAg8jm5zVWLxxpweAezlzfeUJXvZ2lWBtoErXwtkrngjLz/zBeNIAYXzOIB5wLmCNmVgHPJXv7oR81aO5d7pzedwYYLktoGymVPpCy80Bjs3OFnhHAo/c6nEFipZuObrJA+ex4ZK/KeTUIOHXFvZMi4JnMq7rsnHeRqlvWWtd0KdWLKv7D43DTBmP6AH8vU7hqG81SYlUfJExDjq/TNB1mR+8hSjXjqUe4e79bqFHPXtUF5porwpVZGh3mmgNcagCCqNC6hHjO042wZcx8xr2A76aYcQZP1dg5kevmUzKpXEi2Ry/uAVbrxZxy19MjebgaeDrDKVmLvE6r+1wd8ESae55ohJ+LyxrSqKkEbMY1eKQmAdmzeqKvvcxeT2WNaaKipa4nSuH2Sze2RHt4UBueKvlGmhlnMC0iUrzmcXLn4rUmIKLtruQgSwBSw5KQcE8f2M7G42hoHMq/pYPESLJtigmz4FStpMr7DXsqY0HfC5tXwDEe1lHhbz0F3Pnmw+oeGIHFsTl4tNsInKw9j/O2agROHYk+va0ABVpYvRXFF3ejGS261GI4cf0Cvi1fsO7RCPcyS23XeRYkHkzvNIwzdl3yXJRXHcWY8ekoKz3sVPjhHz+GJSt+ixldh2J65Spcuk7r+4ZWMJVXy4xrMDesJLF6PZHM3gaX/ayhXP+4JLzXdx5WrXwZ460jNOHGxsZi4sSJGDVqFMLDw/HmX9diWC8rLlecxfq+P0Mw1bjhfbTSzENmFDB9kCRxR3qisCBdTXvKY9pr857Dlk+2Y9nCJYiKisKaNWtw5swZbNiwATt27EB1dTXmz5+P+vp6zErLQaQtEAt7jAVqrjla1N/viPn404wCPqnx9Nglz6yVfezlbz3mZSYPQWxkNB7/wcOwWCyaUPPy8pzKhoaGYvny5Vi8eDGamprw5Ox5WBCTjZArzeKy5AIP7sPMQ2YU8FaNvbuqPHO5N5dIT94tlp5iTce2bdvQ0NCAOXPmIC3Nw57X3qoIOCkpCVs3bUbFyUpkjskUp9AOQoRsGrq5uel7Q9nILrXg01MWbDlqcTOoxMg6Sffl9kq3nluz47D+wA4tPSsryy3fmBAUFIT09HRUVVXhROkRWK1WbN68eb2xjBnCZhSwGDm70dQyGsWHAJmxriT71re/MFq+WokuWcG48s03WjguznB27FrfHo+P17fcjVfrVWRkpOyXSrwU9dlkMwpYmPkb4kMaPgqv/dCCSBf/8fOfgHexgLx7nRh/LrgBSf2StbTS0lJkZHhwWRpqSBkhGmOWkJCQ3QzSZ2kuMuMaLBz+iNjCEx4Lij5z57gcFe4+5Za++1QZhqXrx7pr165Fc7P37VRFRQV27dqltZGSktIyYMCAJW4NmiDBrAIW1i4grmHjV8Bbzo4KpNNPfeSCm2/5nbLtyEx7ENkTxuLQoUNYtGgRWlrsniqDsGpra5Gfn4/GxkYUFhaKxX1m+vTpHxuKmCZoZgGXk8s/IhSK9ihsPnqD6XLpbvIA4B2uwwY6XVuDle+/iRfWrkRAQACKioogxlZJSQlOnz6N8vJyFBcXawbV3r17oZTC8ePHrycmJj5iaMYfvM0cENUpe1SFObzQvj9fv/f8rzyFO0IUSng3Wu5E2+9FB+Tepd679Ln69PQXavjIB/R6jvqGZ05OjgoODpbprcLCwlbe5jF9Z69r3Wn7nb2mXRuShVLcl+N5VbYT5Ow2mVd5+hKduHVd/TmQcycQQGX15QWo6jq8e99FDI5KROFPfo3+1oEICg1BI/fGCb0SkJubq5YuXWopKCiw1dXVvbR///5Um802gkKOpeNDOxRu19H4G/fKgUzmyDmfPitH91b4XbZCdrKChD96zPmfDQtGqkEPpqoV+95Vhyr/o2pqalqoptXOnTtbVq9e/QHVM78QjSZSnYtzw9Qz2T4W0z94Sw7PEnJyrws6wNKCuAjFrZTCoBiF5CiF3vw7S3f+bSUy2FVF/4P1BhKu9D8hR0REvOSa6Y/ffg704CvnE9uJZsJVkMY4zXDtf01D+WyNRMgN48aNK2itkK/lcZHq8NSNI5SrNuK6EtdUKCGqXE6FjhEG85ux1imG2TWtF/Hn+jng54CfA34OtD8Hgtr/Ff43ODgQzIBYt7KeCjnikkaXFaIl0QuNYrqcGoz2ku+aLOs0L1Zrt+02umb64+3DgUFsVizfhfbmHXGjNXyEeQ/Z842PDEbEZynPtlAhC0m7+URKWyr4y9w6BxwCdRXw79n0YCKPOEFcIcRKvhX6Jyt7uQ90K81+P3XNfNggHBMXZRnxBvEywUNg3E0YKYsR4wyWj6KYeJzgf1lwmJhBCD1NZBPSjtQZTgiPniSOExeJt4iehCnI7AI2MnmoPSL7WyPJXyBE6PIU6kXMJuYQIugw4s+E0GfESULu5L5KSFtPEPJR7CP+SOQQG4mO4MfnMHyDvKnog+yezKhKQtZNEYorTWGC5E22Z8hsl2uXYqgJPUVIvlUipA1EtRbSf0TI5Ya4zHIpn2FI89mg2Wewo/8l5LAIcm4bOS0CstnLOoQZ5aGu+LbFAyaz10F77YGBjgRffvJk3NT0Onu/oh1HwP+TQm7piQZxkBh1QlX6w7d/HTPAt3v5/fbub3y9bJeeJaYTvyJOEB8TPk9mn8G3g8GyRsvZ8DOETAixrh8h6gk/dSAOONbjDjQk/1D8HPBzwLc58F+idNLX3x3NNQAAAABJRU5ErkJggg==
description: Deprecated. Use IPinfo v2 instead. Use the ipinfo.io API to get data about an IP address
configuration:
- display: Use system proxy settings
  name: proxy
  defaultvalue: "false"
  type: 8
  required: false
- display: API Token (optional)
  name: token
  type: 4
  required: false
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
- display: Use HTTPS connections
  name: use_https
  type: 8
  required: false
script:
  script: |-
    var sendRequest = function(url, json) {
        var res = http(
                url,
                {
                    Method: 'GET',
                },
                false,
                params.insecure,
                params.proxy
            );
        if (res.StatusCode < 200 || res.StatusCode >= 300) {
            throw 'Failed to query ipinfo, request status code: ' + res.StatusCode + ' and Body: ' + res.Body + '.';
        }
        return json && res.Body ? JSON.parse(res.Body) : res.Body;
    }


    var base = params.use_https ? 'https://ipinfo.io/' : 'http://ipinfo.io/';

    var token = params.token ? '?token=' + params.token : '';

    var jsonSuffix = '/json' + token;

    switch (command) {
        case 'test-module':
            if (sendRequest(base+'8.8.8.8'+jsonSuffix, true)) {
                return 'ok';
            }
            return 'not cool';
        case 'ip':
            var o = sendRequest(base + args.ip + jsonSuffix, true);
            var asn = '';
            var asn_owner = '';
            var organization = o.company? {Name:  o.company.name, Type:  o.company.type}: '';
            var abuse = o.Abuse? {Address: o.abuse.address, Country: o.abuse.country, Name: o.abuse.name, Network: o.abuse.network, Phone: o.abuse.phone, Email: o.abuse.email}: '';
            var feed_related_indicators = [{value: o.hostname, type: 'URL'}];
            if(o.asn){
                if(o.asn.asn){
                    asn = o.asn.asn
                }
                if(o.asn.name){
                    asn_owner = o.asn.name
                }
                if(o.asn.domain){
                    feed_related_indicators.push({value: o.asn.domain, type: 'Domain'});
            }}
            else if(o.org){
                var index = o.org.indexOf(' ');
                asn = o.org.slice(0, index);
                asn_owner = o.org.slice(index + 1);
            }
            if(o.company){
                if(o.company.domain){
                    feed_related_indicators.push({value: o.company.domain, type: 'Domain'});
            }}
            var tags = [];
            if(o.privacy){
                if (o.privacy.hosting){
                    tags.push('hosting');
                }
                if (o.privacy.proxy){
                    tags.push('proxy');
                }
                if (o.privacy.tor){
                    tags.push('tor');
                }
                if (o.privacy.vpn){
                    tags.push('vpn');
                }
            }
            var ec = {IP: {Address: o.ip, Hostname: o.hostname, ASN: asn, ASOwner: asn_owner, Tags: tags, Organization: organization, Geo: {
                Location: o.loc, Country: o.country, Description: o.city + ', ' + o.region + ', ' + o.postal + ', ' + o.country}, Registrar: {Abuse: abuse},
                FeedRelatedIndicators: feed_related_indicators}};
            ec.DBotScore = {Indicator: args.ip, Type: 'ip', Vendor: 'ipinfo', Score: 0};

            var reply = [{Type: entryTypes.note, Contents: o, ContentsFormat: formats.json, HumanReadable: objToMd(o), EntryContext: ec}];
            if (o.loc) {
                var parts = o.loc.split(',');
                reply.push({Type: entryTypes.map, Contents: {lat: parseFloat(parts[0]), lng: parseFloat(parts[1])}, ContentsFormat: formats.json});
            }
            return reply;
        case 'ipinfo_field':
            return sendRequest(base + args.ip + '/' + args.field + token, false);
    }
  type: javascript
  commands:
  - name: ip
    arguments:
    - name: ip
      required: true
      default: true
      description: IP address to query. E.g. !ip 1.1.1.1
    outputs:
    - contextPath: IP.Address
      description: The IP address
      type: string
    - contextPath: IP.Hostname
      description: The IP hostname
      type: string
    - contextPath: IP.ASN
      description: The IP ASN
      type: string
    - contextPath: IP.Geo.Location
      description: The IP geographic location in coordinates
      type: string
    - contextPath: IP.Geo.Country
      description: The IP country
      type: string
    - contextPath: IP.Geo.Description
      description: The IP location as <City, Region, Postal Code, Country>
      type: string
    - contextPath: IP.ASOwner
      description: The IP AS owner
      type: string
    - contextPath: IP.FeedRelatedIndicators.value
      description: Indicators that are associated with the IP
      type: string
    - contextPath: IP.FeedRelatedIndicators.type
      description: The type of the indicators that are associated with the IP
      type: string
    - contextPath: IP.Tags
      description: Tags that are associated with the IP
      type: string
    - contextPath: IP.Registrar.Abuse.Address
      description: The IP registrar abuse address
      type: string
    - contextPath: IP.Registrar.Abuse.Country
      description: The IP registrar abuse country
      type: string
    - contextPath: IP.Registrar.Abuse.Name
      description: The IP registrar abuse name
      type: string
    - contextPath: IP.Registrar.Abuse.Network
      description: The IP registrar abuse network
      type: string
    - contextPath: IP.Registrar.Abuse.Phone
      description: The IP registrar abuse phone
      type: string
    - contextPath: IP.Registrar.Abuse.Email
      description: The IP registrar abuse email
      type: string
    - contextPath: IP.Organization.Name
      description: The IP organization name
      type: string
    - contextPath: IP.Organization.Type
      description: The IP organization type
      type: string
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    description: Check IP reputation (when information is available, returns a JSON with details).  Uses all configured Threat Intelligence feeds
  - name: ipinfo_field
    arguments:
    - name: ip
      required: true
      default: true
      description: IP address to query. E.g. !ip 1.1.1.1
    - name: field
      required: true
      auto: PREDEFINED
      predefined:
      - geo
      - loc
      - city
      - region
      - country
      - org
      - hostname
      - phone
      description: Name of the field to retrieve. Can be org, city, geo, etc.
    description: Retrieve value for a specific field from the IP address information
tests:
- IPInfoTest
fromversion: 5.0.0