SilentPush
The Silent Push Platform uses first-party data and a proprietary scanning engine to enrich global DNS data with risk and reputation scoring, giving security teams the ability to join the dots across the entire IPv4 and IPv6 range, and identify adversary infrastructure before an attack is launched. The content pack integrates with the Silent Push system to gain insights into domain/IP information, reputations, enrichment, and infratag-related details. It also provides functionality to live-scan URLs and take screenshots of them. Additionally, it allows fetching future attack feeds from the Silent Push system.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- SilentPush
Configuration parameters
- url — Base URL (required)
- credentials — API Key (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (26)
- silentpush-add-feed — This command add the new feed
- silentpush-add-feed-tags — This command add indicators to the feed
- silentpush-add-indicator-tags — This command updates tags to the indicators
- silentpush-add-indicators — This command add indicators to the feed
- silentpush-density-lookup — This command queries granular DNS/IP parameters (e.g., NS servers, MX servers, IPaddresses, ASNs) for density information.
- silentpush-forward-padns-lookup — This command performs a forward PADNS lookup using various filtering parameters.
- silentpush-get-asn-reputation — This command retrieve the reputation information for an IPv4.
- silentpush-get-asn-takedown-reputation — This command retrieve the takedown reputation information for an Autonomous System Number (ASN).
- silentpush-get-asns-for-domain — This command retrieves Autonomous System Numbers (ASNs) associated with a domain.
- silentpush-get-data-exports — This command runs the threat check on the specified
- silentpush-get-domain-certificates — This command get certificate data collected from domain scanning.
- silentpush-get-enrichment-data — This command retrieves comprehensive enrichment information for a given resource (domain, IPv4, or IPv6).
- silentpush-get-future-attack-indicators — This command fetch indicators of potential future attacks using a feed UUID.
- silentpush-get-ipv4-reputation — This command retrieves the reputation information for an IPv4.
- silentpush-get-job-status — This command retrieve status of running job or results from completed job.
- silentpush-get-nameserver-reputation — This command retrieves historical reputation data for a specified nameserver,including reputation scores and optional detailed calculation information.
- silentpush-get-subnet-reputation — This command retrieves the reputation history for a specific subnet.
- silentpush-list-domain-information — This command get domain information along with Silent Push risk score and live whois information for multiple domains.
- silentpush-list-domain-infratags — This command get infratags for multiple domains with optional clustering.
- silentpush-list-ip-information — This command get IP information for multiple IPv4s and IPv6s.
- silentpush-live-url-scan — This command scan a URL to retrieve hosting metadata.
- silentpush-reverse-padns-lookup — This command retrieve reverse Passive DNS data for specific DNS record types.
- silentpush-run-threat-check — This command runs the threat check on the specified
- silentpush-screenshot-url — This commandGenerate screenshot of a URL.
- silentpush-search-domains — This command search for domains with optional filters.
- silentpush-search-scan-data — This command search Silent Push scan data repositories using SPQL queries.