HYAS Insight
Use the HYAS Insight integration to interactively lookup PassiveDNS, DynamicDNS, WHOIS, Sample Malware Records, C2 Attribution, Passive Hash, SSL Certificate, Open Source Indicators, Device Geo, Sinkhole, Malware Sample Information – either as playbook tasks or through API calls in the War Room.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- HYASInsight
Configuration parameters
- X-API-Key — HYAS Insight Api Key (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (14)
- hyas-get-associated-domains-by-hash — Returns associated Domain's for the provided hash value.
- hyas-get-associated-ips-by-hash — Returns associated IP's for the provided hash value.
- hyas-get-c2attribution-records-by-indicator — Return C2 Attribution records for the provided indicator value.
- hyas-get-device-geo-records-by-ip-address — Returns a list of mobile geolocation information.
- hyas-get-dynamic-dns-records-by-indicator — Returns DynamicDNS records for the provided indicator value.
- hyas-get-malware-sample-information-by-hash — Returns malware information.
- hyas-get-malware-samples-records-by-indicator — Returns Malware Sample records for the provided indicator value.
- hyas-get-opensource-indicator-records-by-indicator — Return Open Source intel records for the provided indicator value.
- hyas-get-passive-dns-records-by-indicator — Returns PassiveDNS records for the provided indicator value.
- hyas-get-passive-hash-records-by-indicator — Return passive hash records for the provided indicator value.
- hyas-get-sinkhole-records-by-ipv4-address — Returns sinkhole information.
- hyas-get-ssl-certificate-records-by-indicator — Return SSL certificate records for the provided indicator value.
- hyas-get-whois-current-records-by-domain — Returns WHOIS Current records for the provided indicator value.
- hyas-get-whois-records-by-indicator — Returns WHOIS records for the provided indicator value.