PassiveTotal v2
Analyze and understand threat infrastructure from a variety of sources-passive DNS, active DNS, WHOIS, SSL certificates and more-without devoting resources to time-intensive manual threat research and analysis.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- PassiveTotal
Configuration parameters
- url — API URL (required)
- credentials — Username
- username — Username
- secret — API Secret
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- request_timeout — HTTP(S) Request Timeout (in seconds)
- integrationReliability — Source Reliability
- feedExpirationPolicy —
- feedExpirationInterval —
Commands (28)
- domain — Provides data enrichment for domains.
- ip — Checks the reputation of an IP address.
- pt-get-articles — Retrieves information related to articles for a specific indicator.
- pt-get-components — Retrieves the host attribute components for a domain or IP address. Maximum 2000 records are fetched.
- pt-get-cookies — Retrieves cookies addresses or hostname information based on cookie name or domain.
- pt-get-data-card — Retrieves a summary data card associated with the given query.
- pt-get-host-pairs — Retrieves the host attribute pairs related to a domain or IP address. Maximum 2000 records are fetched.
- pt-get-pdns-details — Retrieves the passive DNS results from active account sources.
- pt-get-reputation — Gets reputation for a given domain, host or IP.
- pt-get-services — Retrieves exposed services on the recently open ports for an IP address.
- pt-get-trackers — Retrieves the host attribute trackers for a domain or IP address. Maximum 2000 records are fetched.
- pt-get-whois — Gets WHOIS information records based on queries.
- pt-list-intel-profile-indicators — Retrieves the indicators for the given profile.
- pt-list-intel-profiles — Retrieves the list of all profiles.
- pt-list-my-attack-surface-assets — Retrieves the attack surface asset information of the individual's account.
- pt-list-my-attack-surface-insights — Retrieves the attack surface insight information of the individual's account.
- pt-list-my-attack-surface-observations — Retrieves the attack surface vulnerability observation information of the individual's account.
- pt-list-my-attack-surface-vulnerabilities — Retrieves the attack surface vulnerability information of the individual's account.
- pt-list-my-attack-surface-vulnerable-components — Retrieves the attack surface vulnerable component information of the individual's account.
- pt-list-my-attack-surfaces — Retrieves the attack surface information of the individual's account.
- pt-list-third-party-attack-surface — Retrieves the attack surface observations by severity level for the given third-party account.
- pt-list-third-party-attack-surface-assets — Retrieves the attack surface asset information of the given third-party account.
- pt-list-third-party-attack-surface-insights — Retrieves the attack surface insight information of the given third-party account.
- pt-list-third-party-attack-surface-observations — Retrieves the attack surface vulnerability observation information of the given third-party account.
- pt-list-third-party-attack-surface-vulnerabilities — Retrieves the attack surface vulnerability information of the given third-party account.
- pt-list-third-party-attack-surface-vulnerable-components — Retrieves the attack surface vulnerable component information of the given third-party account.
- pt-ssl-cert-search — Retrieves SSL certificates for a given field value.
- pt-whois-search — Gets WHOIS information records based on field matching queries.