SilentPush_v2
The Silent Push Platform uses first-party data and a proprietary scanning engine to enrich global DNS data with risk and reputation scoring, giving security teams the ability to join the dots across the entire IPv4 and IPv6 range, and identify adversary infrastructure before an attack is launched. The content pack integrates with the Silent Push system to gain insights into domain/IP information, reputations, enrichment, and infratag-related details. It also provides functionality to live-scan URLs and take screenshots of them. Additionally, it allows fetching future attack feeds from the Silent Push system.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- SilentPush
Configuration parameters
- url — Base URL (required)
- credentials —
- threat-check-key —
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
Commands (30)
- silentpush-add-feed — Add the new feed.
- silentpush-add-feed-tags — Add indicators to the feed.
- silentpush-add-indicator-tags — Updates tags to the indicators.
- silentpush-add-indicators — Add indicators to the feed.
- silentpush-bulk-enrich — Enriches IPs or Domains in a bulk.
- silentpush-density-lookup — Queries granular DNS/IP parameters (e.g., NS servers, MX servers, IPaddresses, ASNs) for density information.
- silentpush-domain-risk-score — Scores a list of Domain addresses.
- silentpush-forward-padns-lookup — Performs a forward PADNS lookup using various filtering parameters.
- silentpush-get-asn-reputation — This command retrieve the reputation information for an IPv4.
- silentpush-get-asn-takedown-reputation — This command retrieve the takedown reputation information for an Autonomous System Number (ASN).
- silentpush-get-asns-for-domain — Retrieves Autonomous System Numbers (ASNs) associated with a domain.
- silentpush-get-data-exports — Runs the threat check on the specified export type.
- silentpush-get-domain-certificates — Get certificate data collected from domain scanning.
- silentpush-get-enrichment-data — Retrieves comprehensive enrichment information for a given resource (domain, IPv4, or IPv6).
- silentpush-get-ipv4-reputation — Retrieves the reputation information for an IPv4.
- silentpush-get-nameserver-reputation — Retrieves historical reputation data for a specified nameserver, including reputation scores and optional detailed calculation information.
- silentpush-get-subnet-reputation — Retrieves the reputation history for a specific subnet.
- silentpush-ip-diversity-lookup — Get IP diversity (number of IP addresses pointed to over time) for the query to qtype.
- silentpush-ip-diversity-patterns — Search for IP Diversity patterns, with optional name server and domain name pattern matching.
- silentpush-ipv4-risk-score — Scores a list of IPv4 addresses.
- silentpush-ipv6-risk-score — Scores a list of IPv6 addresses.
- silentpush-live-url-scan — Scan a URL to retrieve hosting metadata.
- silentpush-multi-conditional-padns-lookup — Searches passive DNS data for records matching both query and answer.
- silentpush-retry-job — Retry another command which returned a Job ID.
- silentpush-reverse-padns-lookup — Retrieve reverse Passive DNS data for specific DNS record types.
- silentpush-run-threat-check — Runs the threat check on the specified resource.
- silentpush-search-domains — Search for domains with optional filters.
- silentpush-search-scan-data — Search Silent Push scan data repositories using SPQL queries.
- silentpush-tlp-reports — List all the TLP Reports.
- silentpush-whois — Get Whois information.