CriminalIP
Criminal IP is a comprehensive cyber threat intelligence solution that provides actionable insights into IP addresses, domains, and connected assets across the internet. It enables organizations to detect malicious indicators, assess asset reputation, and enhance threat detection by integrating enriched threat data directly into security operations via the XSOAR interface.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- CriminalIP
Configuration parameters
- credentials —
- url — Server URL (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- request_timeout — Request timeout (seconds)
Commands (12)
- criminal-ip-check-last-scan-date — Checks if the domain has been scanned within the last 7 days.
- criminal-ip-check-malicious-ip — Determines whether an IP is malicious or safe through CriminalIP Asset Search.
- criminal-ip-domain-full-scan — Initiates a Domain Full Scan and returns a scan_id.
- criminal-ip-domain-full-scan-make-email-body — Builds an email body summarizing notable findings from a completed Full Scan.
- criminal-ip-domain-full-scan-result — Returns the Full Scan results for the given scan_id.
- criminal-ip-domain-full-scan-status — Checks the progress of the Full Scan.
- criminal-ip-domain-lite-scan — Initiates a Domain Lite Scan and returns a scan_id.
- criminal-ip-domain-lite-scan-result — Returns the Lite Scan results for the given scan_id.
- criminal-ip-domain-lite-scan-status — Checks the progress of the Lite Scan.
- criminal-ip-domain-quick-scan — Performs a Domain Quick Scan using CriminalIP's API.
- criminal-ip-ip-report — Provides detailed information about an IP address using Criminal IP's API.
- criminal-ip-micro-asm — Performs a micro ASM-style summary for a domain with a completed Full Scan.