category: Data Enrichment & Threat Intelligence provider: Microsoft commonfields: id: PassiveTotal v2 version: -1 configuration: - defaultvalue: https://api.passivetotal.org display: API URL name: url required: true type: 0 - display: Username name: credentials required: false type: 9 displaypassword: API Secret - display: Username name: username required: false hidden: true type: 0 - display: API Secret name: secret required: false hidden: true type: 4 - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false - additionalinfo: All the PassiveTotal API calls would timeout if the response is not returned within the configured time interval. Default is 20. defaultvalue: '20' display: HTTP(S) Request Timeout (in seconds) name: request_timeout type: 0 required: false - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: B - Usually reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged type: 15 required: false - defaultvalue: indicatorType name: feedExpirationPolicy display: '' options: - never - interval - indicatorType - suddenDeath type: 17 required: false - defaultvalue: '20160' name: feedExpirationInterval display: '' type: 1 required: false description: Analyze and understand threat infrastructure from a variety of sources-passive DNS, active DNS, WHOIS, SSL certificates and more-without devoting resources to time-intensive manual threat research and analysis. display: PassiveTotal v2 name: PassiveTotal v2 script: commands: - arguments: - description: Query value to use in your request. name: query required: true - auto: PREDEFINED description: 'WHOIS field to execute the search on: domain, email, name, organization, address, phone, nameserver.' name: field predefined: - domain - email - name - organization - address - phone - nameserver required: true description: Gets WHOIS information records based on field matching queries. name: pt-whois-search outputs: - contextPath: Domain.Name description: 'The domain name, for example: ''google.com''.' type: String - contextPath: Domain.WHOIS.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.WHOIS.UpdatedDate description: The date that the domain was last updated. type: Date - contextPath: Domain.WHOIS.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.WHOIS.NameServers description: Name servers of the domain. type: String - contextPath: Domain.Organization description: The organization of the domain. type: String - contextPath: Domain.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.Admin.Country description: The country of the domain administrator. type: String - contextPath: Domain.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.Registrant.Phone description: The phone number for receiving abuse reports. type: String - contextPath: Domain.Registrant.Country description: The country of the registrant. type: String - contextPath: Domain.WHOIS.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Country description: The country of the domain administrator. type: String - contextPath: Domain.WHOIS.Registrar.Name description: 'The name of the registrar, for example: ''GoDaddy''.' type: String - contextPath: Domain.WHOIS.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Phone description: The phone number for receiving abuse reports. type: String - contextPath: Domain.WHOIS.Registrant.Country description: The country of the registrant. type: String - contextPath: PassiveTotal.WHOIS.domain description: 'The domain name, for example: ''google.com''.' type: String - contextPath: PassiveTotal.WHOIS.registrar description: The name of the registrar of the domain. type: String - contextPath: PassiveTotal.WHOIS.whoisServer description: WHOIS server name where the details of domain registrations belong. type: String - contextPath: PassiveTotal.WHOIS.registered description: The date that the domain was registered. type: Date - contextPath: PassiveTotal.WHOIS.expiresAt description: The expiration date of the domain. type: Date - contextPath: PassiveTotal.WHOIS.registryUpdatedAt description: The date when registry was last updated. type: Date - contextPath: PassiveTotal.WHOIS.lastLoadedAt description: Last loaded date of WHOIS database. type: Date - contextPath: PassiveTotal.WHOIS.nameServers description: Name servers of the domain. type: String - contextPath: PassiveTotal.WHOIS.organization description: The organization of the domain. type: String - contextPath: PassiveTotal.WHOIS.name description: Name of the domain. type: String - contextPath: PassiveTotal.WHOIS.telephone description: Telephone number fetched from whois details of the domain. type: String - contextPath: PassiveTotal.WHOIS.contactEmail description: Contact Email address of the domain owner. type: String - contextPath: PassiveTotal.WHOIS.registrantEmail description: The name of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantFax description: The fax number of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantName description: The name of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantOrganization description: The organizations of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantStreet description: The street of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantCity description: The city of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantState description: The state of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantPostalCode description: The postal code of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantCountry description: The country of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantTelephone description: The telephone number of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.adminEmail description: The email address of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminFax description: The fax number of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminName description: The name of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminOrganization description: The organizations of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminStreet description: The street of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminCity description: The city of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminState description: The state of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminPostalCode description: The postal code of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminCountry description: The country of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminTelephone description: The telephone number of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.billingEmail description: The email address of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingFax description: The fax number of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingName description: The name of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingOrganization description: The organizations of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingStreet description: The street of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingCity description: The city of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingState description: The state of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingPostalCode description: The postal code of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingCountry description: The country of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingTelephone description: The telephone number of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.techEmail description: The email address of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techFax description: The fax number of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techName description: The name of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techOrganization description: The organizations of domain tech. type: String - contextPath: PassiveTotal.WHOIS.techStreet description: The street of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techCity description: The city of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techState description: The state of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techPostalCode description: The postal code of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techCountry description: The country of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techTelephone description: The telephone number of the domain tech. type: String - arguments: - description: 'Query value to use in the request. For example: riskiq.com, 1.1.1.1.' name: query required: true - auto: PREDEFINED defaultValue: 'false' description: |- Whether to return historical results. Valid values: true, false. name: history predefined: - 'true' - 'false' description: Gets WHOIS information records based on queries. name: pt-get-whois outputs: - contextPath: PassiveTotal.WHOIS.domain description: 'The domain name. For example: ''google.com''.' type: String - contextPath: PassiveTotal.WHOIS.registrar description: The name of the registrar of the domain. type: String - contextPath: PassiveTotal.WHOIS.whoisServer description: WHOIS server name where the details of domain registrations belong. type: String - contextPath: PassiveTotal.WHOIS.registered description: The date that the domain was registered. type: Date - contextPath: PassiveTotal.WHOIS.expiresAt description: The expiration date of the domain. type: Date - contextPath: PassiveTotal.WHOIS.registryUpdatedAt description: The date when the registry was last updated. type: Date - contextPath: PassiveTotal.WHOIS.lastLoadedAt description: Last loaded date of WHOIS database. type: Date - contextPath: PassiveTotal.WHOIS.nameServers description: Name servers of the domain. type: String - contextPath: PassiveTotal.WHOIS.organization description: The organization of the domain. type: String - contextPath: PassiveTotal.WHOIS.name description: Name of the domain. type: String - contextPath: PassiveTotal.WHOIS.telephone description: Telephone number fetched from whois details of the domain. type: String - contextPath: PassiveTotal.WHOIS.contactEmail description: Contact Email address of the domain owner. type: String - contextPath: PassiveTotal.WHOIS.registrantEmail description: The email address of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantFax description: The fax number of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantName description: The name of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantOrganization description: The organizations of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantStreet description: The street of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantCity description: The city of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantState description: The state of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantPostalCode description: The postal code of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantCountry description: The country of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.registrantTelephone description: The telephone number of the domain registrant. type: String - contextPath: PassiveTotal.WHOIS.adminEmail description: The email address of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminFax description: The fax number of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminName description: The name of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminOrganization description: The organizations of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminStreet description: The street of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminCity description: The city of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminState description: The state of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminPostalCode description: The postal code of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminCountry description: The country of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.adminTelephone description: The telephone number of the domain administrator. type: String - contextPath: PassiveTotal.WHOIS.billingEmail description: The email address of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingFax description: The fax number of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingName description: The name of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingOrganization description: The organizations of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingStreet description: The street of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingCity description: The city of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingState description: The state of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingPostalCode description: The postal code of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingCountry description: The country of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.billingTelephone description: The telephone number of the domain billing. type: String - contextPath: PassiveTotal.WHOIS.techEmail description: The email address of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techFax description: The fax number of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techName description: The name of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techOrganization description: The organizations of domain tech. type: String - contextPath: PassiveTotal.WHOIS.techStreet description: The street of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techCity description: The city of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techState description: The state of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techPostalCode description: The postal code of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techCountry description: The country of the domain tech. type: String - contextPath: PassiveTotal.WHOIS.techTelephone description: The telephone number of the domain tech. type: String - arguments: - default: true description: Domain or IP address you want to search components for. name: query required: true - description: Filter for records whose last seen is after this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: start - description: Filter for records whose first seen is before this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: end description: Retrieves the host attribute components for a domain or IP address. Maximum 2000 records are fetched. name: pt-get-components outputs: - contextPath: Domain.Name description: 'The domain name, for example: "google.com".' type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: IP.Address description: The IP Address of the component. type: String - contextPath: PassiveTotal.Component.firstSeen description: The date and time when the component was first observed. type: Date - contextPath: PassiveTotal.Component.lastSeen description: The date and time when the component was most recently observed. type: Date - contextPath: PassiveTotal.Component.version description: The current version of component. type: String - contextPath: PassiveTotal.Component.category description: The category under which the component falls. type: String - contextPath: PassiveTotal.Component.label description: The value of the component. type: String - contextPath: PassiveTotal.Component.hostname description: The hostname of the component. type: String - contextPath: PassiveTotal.Component.address description: The IP address of the component. type: String - arguments: - default: true description: Domain or IP address you want to search trackers for. name: query required: true - description: Filter for records whose last seen is after this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: start - description: Filter for records whose first seen is before this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: end description: Retrieves the host attribute trackers for a domain or IP address. Maximum 2000 records are fetched. name: pt-get-trackers outputs: - contextPath: Domain.Name description: 'The domain name, for example: "google.com".' type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: IP.Address description: The IP Address of the component. type: String - contextPath: PassiveTotal.Tracker.firstSeen description: The date and time when the tracker was first observed. type: Date - contextPath: PassiveTotal.Tracker.lastSeen description: The date and time when the tracker was most recently observed. type: Date - contextPath: PassiveTotal.Tracker.attributeValue description: The value of the tracker. type: String - contextPath: PassiveTotal.Tracker.attributeType description: The type under which the tracker falls. type: String - contextPath: PassiveTotal.Tracker.hostname description: The hostname of the tracker. type: String - contextPath: PassiveTotal.Tracker.address description: The IP address of the tracker. type: String - arguments: - default: true description: The domain or IP being queried. name: query required: true - description: Filter for records whose last seen is after this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: start - description: Filter for records whose first seen is before this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: end description: Retrieves the passive DNS results from active account sources. name: pt-get-pdns-details outputs: - contextPath: PassiveTotal.PDNS.resolve description: The host or ip address that indicates resolve in Passive DNS record. type: String - contextPath: PassiveTotal.PDNS.resolveType description: The type of the resolve. I.e domain, ip, host, etc. type: String - contextPath: PassiveTotal.PDNS.value description: The value of the Passive DNS record. type: String - contextPath: PassiveTotal.PDNS.source description: Source of the passive DNS records. type: String - contextPath: PassiveTotal.PDNS.firstSeen description: First seen timestamp of the passive DNS record. type: String - contextPath: PassiveTotal.PDNS.lastSeen description: Last seen timestamp of the passive DNS record. type: String - contextPath: PassiveTotal.PDNS.collected description: The date when a passive DNS record is collected. type: String - contextPath: PassiveTotal.PDNS.recordType description: The type of the passive DNS record. I.e CNAME, SOA, A, etc. type: String - contextPath: PassiveTotal.PDNS.recordHash description: The hash value of the passive DNS record. type: String - contextPath: Domain.Name description: 'The domain name, for example: ''google.com''.' type: String - contextPath: IP.Address description: The IP Address of the component. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - arguments: - auto: PREDEFINED description: "Field by which to search. \n\nAllowed values: issuerSurname, subjectOrganizationName, issuerCountry, issuerOrganizationUnitName, fingerprint, subjectOrganizationUnitName, serialNumber, subjectEmailAddress, subjectCountry, issuerGivenName, subjectCommonName, issuerCommonName, issuerStateOrProvinceName, issuerProvince, subjectStateOrProvinceName, sha1, subjectStreetAddress, subjectSerialNumber, issuerOrganizationName, subjectSurname, subjectLocalityName, issuerStreetAddress, issuerLocalityName, subjectGivenName, subjectProvince, issuerSerialNumber, issuerEmailAddress." name: field predefined: - issuerSurname - subjectOrganizationName - issuerCountry - issuerOrganizationUnitName - fingerprint - subjectOrganizationUnitName - serialNumber - subjectEmailAddress - subjectCountry - issuerGivenName - subjectCommonName - issuerCommonName - issuerStateOrProvinceName - issuerProvince - subjectStateOrProvinceName - sha1 - subjectStreetAddress - subjectSerialNumber - issuerOrganizationName - subjectSurname - subjectLocalityName - issuerStreetAddress - issuerLocalityName - subjectGivenName - subjectProvince - issuerSerialNumber - issuerEmailAddress required: true - description: Field value for which to search. name: query required: true description: Retrieves SSL certificates for a given field value. name: pt-ssl-cert-search outputs: - contextPath: PassiveTotal.SSL.firstSeen description: Epoch timestamp when SSL certificate identified by the system. type: Number - contextPath: PassiveTotal.SSL.lastSeen description: The last seen epoch timestamp of the SSL certificates. type: Number - contextPath: PassiveTotal.SSL.fingerprint description: 'A fingerprint detail from the SSL certificates. ' type: String - contextPath: PassiveTotal.SSL.sslVersion description: A version of the certificate. type: Number - contextPath: PassiveTotal.SSL.expirationDate description: The expiry date of the certificate. type: String - contextPath: PassiveTotal.SSL.issueDate description: Issue date of the certificate. type: String - contextPath: PassiveTotal.SSL.sha1 description: Sha1 of the certificate. type: String - contextPath: PassiveTotal.SSL.serialNumber description: A serial number of the certificate. type: String - contextPath: PassiveTotal.SSL.issuerCountry description: The country name of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerStateOrProvinceName description: The state or province name of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerCommonName description: The common name of the issuer. type: String - contextPath: PassiveTotal.SSL.issuerEmailAddress description: A contact email address of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerProvince description: A province of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerOrganizationUnitName description: An organization unit name of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerSurname description: The surname of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerStreetAddress description: Street address of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerLocalityName description: The locality of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerSerialNumber description: The serial number of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerOrganizationName description: An organization name of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.issuerGivenName description: A given name of the certificate issuer. type: String - contextPath: PassiveTotal.SSL.subjectCommonName description: The common name of the subject. type: String - contextPath: PassiveTotal.SSL.subjectOrganizationName description: An organization name of the subject of the certificate. type: String - contextPath: PassiveTotal.SSL.subjectOrganizationUnitName description: An organization unit name of the subject of the certificate. type: String - contextPath: PassiveTotal.SSL.subjectGivenName description: The given name of the subject of the certificate. type: String - contextPath: PassiveTotal.SSL.subjectSurname description: The surname of the subject of the certificate. type: String - contextPath: PassiveTotal.SSL.subjectLocalityName description: The locality of the subject. type: String - contextPath: PassiveTotal.SSL.subjectEmailAddress description: A contact email address of the subject. type: String - contextPath: PassiveTotal.SSL.subjectProvince description: The province of the subject. type: String - contextPath: PassiveTotal.SSL.subjectStateOrProvinceName description: The state or province name of the subject. type: String - contextPath: PassiveTotal.SSL.subjectSerialNumber description: A serial number of the subject. type: String - contextPath: PassiveTotal.SSL.subjectStreetAddress description: The street address of the subject. type: String - contextPath: PassiveTotal.SSL.subjectCountry description: The country name of the subject from the certificate. type: String - contextPath: PassiveTotal.SSL.subjectAlternativeNames description: Alternative names of the subject from the certificate details. type: String - arguments: - description: Domain or IP address you want to search host-pairs for. name: query required: true - auto: PREDEFINED description: 'The direction of searching pair records for a given domain. Valid values: children, parents.' name: direction predefined: - children - parents required: true - description: Filter for records whose last seen is after this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: start - description: Filter for records whose first seen is before this datetime. It accepts "yyyy-mm-dd hh:mm:ss" or "yyyy-mm-dd" format. name: end description: Retrieves the host attribute pairs related to a domain or IP address. Maximum 2000 records are fetched. name: pt-get-host-pairs outputs: - contextPath: PassiveTotal.HostPair.firstSeen description: The date and time when the host pair was first observed. type: Date - contextPath: PassiveTotal.HostPair.lastSeen description: The date and time when the host pair was most recently observed. type: Date - contextPath: PassiveTotal.HostPair.cause description: The cause of relation between parent and child. type: String - contextPath: PassiveTotal.HostPair.parent description: The hostname of the parent of the host pair. type: String - contextPath: PassiveTotal.HostPair.child description: The hostname of the child of the host pair. type: String - arguments: - default: true description: The domain to enrich. isArray: true name: domain description: Provides data enrichment for domains. name: domain outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: Unknown - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: Unknown - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: Domain.Name description: 'The domain name, for example: ''google.com''.' type: String - contextPath: Domain.WHOIS.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.WHOIS.UpdatedDate description: The date that the domain was last updated. type: Date - contextPath: Domain.WHOIS.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.WHOIS.NameServers description: Name servers of the domain. type: String - contextPath: Domain.Organization description: The organization of the domain. type: String - contextPath: Domain.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.Admin.Country description: The country of the domain administrator. type: String - contextPath: Domain.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.Registrant.Phone description: The phone number for receiving abuse reports. type: String - contextPath: Domain.Registrant.Country description: The country of the registrant. type: String - contextPath: Domain.WHOIS.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Country description: The country of the domain administrator. type: String - contextPath: Domain.WHOIS.Registrar.Name description: 'The name of the registrar, for example: ''GoDaddy''.' type: String - contextPath: Domain.WHOIS.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Phone description: The phone number for receiving abuse reports. type: String - contextPath: Domain.WHOIS.Registrant.Country description: The country of the registrant. type: String - contextPath: PassiveTotal.Domain.domain description: 'The domain name, for example: ''google.com''.' type: String - contextPath: PassiveTotal.Domain.registrar description: The name of the registrar of the domain. type: String - contextPath: PassiveTotal.Domain.whoisServer description: WHOIS server name where the details of domain registrations belong. type: String - contextPath: PassiveTotal.Domain.registered description: The date that the domain was registered. type: Date - contextPath: PassiveTotal.Domain.expiresAt description: The expiration date of the domain. type: Date - contextPath: PassiveTotal.Domain.registryUpdatedAt description: The date when registry was last updated. type: Date - contextPath: PassiveTotal.Domain.lastLoadedAt description: Last loaded date of WHOIS database. type: Date - contextPath: PassiveTotal.Domain.nameServers description: Name servers of the domain. type: String - contextPath: PassiveTotal.Domain.organization description: The organization of the domain. type: String - contextPath: PassiveTotal.Domain.name description: Name of the domain. type: String - contextPath: PassiveTotal.Domain.telephone description: Telephone number fetched from whois details of the domain. type: String - contextPath: PassiveTotal.Domain.contactEmail description: Contact Email address of the domain owner. type: String - contextPath: PassiveTotal.Domain.registrantEmail description: The name of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantFax description: The fax number of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantName description: The name of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantOrganization description: The organizations of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantStreet description: The street of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantCity description: The city of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantState description: The state of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantPostalCode description: The postal code of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantCountry description: The country of the domain registrant. type: String - contextPath: PassiveTotal.Domain.registrantTelephone description: The telephone number of the domain registrant. type: String - contextPath: PassiveTotal.Domain.adminEmail description: The email address of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminFax description: The fax number of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminName description: The name of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminOrganization description: The organizations of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminStreet description: The street of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminCity description: The city of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminState description: The state of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminPostalCode description: The postal code of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminCountry description: The country of the domain administrator. type: String - contextPath: PassiveTotal.Domain.adminTelephone description: The telephone number of the domain administrator. type: String - contextPath: PassiveTotal.Domain.billingEmail description: The email address of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingFax description: The fax number of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingName description: The name of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingOrganization description: The organizations of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingStreet description: The street of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingCity description: The city of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingState description: The state of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingPostalCode description: The postal code of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingCountry description: The country of the domain billing. type: String - contextPath: PassiveTotal.Domain.billingTelephone description: The telephone number of the domain billing. type: String - contextPath: PassiveTotal.Domain.techEmail description: The email address of the domain tech. type: String - contextPath: PassiveTotal.Domain.techFax description: The fax number of the domain tech. type: String - contextPath: PassiveTotal.Domain.techName description: The name of the domain tech. type: String - contextPath: PassiveTotal.Domain.techOrganization description: The organizations of domain tech. type: String - contextPath: PassiveTotal.Domain.techStreet description: The street of the domain tech. type: String - contextPath: PassiveTotal.Domain.techCity description: The city of the domain tech. type: String - contextPath: PassiveTotal.Domain.techState description: The state of the domain tech. type: String - contextPath: PassiveTotal.Domain.techPostalCode description: The postal code of the domain tech. type: String - contextPath: PassiveTotal.Domain.techCountry description: The country of the domain tech. type: String - contextPath: PassiveTotal.Domain.techTelephone description: The telephone number of the domain tech. type: String - contextPath: PassiveTotal.Domain.score description: Reputation score of the indicator. type: Number - contextPath: PassiveTotal.Domain.classification description: Reputation classification of the indicator. (Can be GOOD, SUSPICIOUS, MALICIOUS, or UNKNOWN). type: String - contextPath: PassiveTotal.Domain.rules.name description: Name of the rule that informed the reputation score of the indicator. type: String - contextPath: PassiveTotal.Domain.rules.description description: Description of the rule. type: String - contextPath: PassiveTotal.Domain.rules.severity description: Severity of the rule. type: Number - contextPath: PassiveTotal.Domain.rules.link description: Link to the rule. type: String - arguments: - description: 'Indicator value to search for in articles. For example: riskiq.com, 1.1.1.1.' name: query required: true - description: 'Type of the indicator. For example: domain, ip, url.' name: type description: Retrieves information related to articles for a specific indicator. name: pt-get-articles outputs: - contextPath: PassiveTotal.Article.guid description: The global unique ID of the article. type: String - contextPath: PassiveTotal.Article.title description: The title of the article. type: String - contextPath: PassiveTotal.Article.summary description: The summary of the article. type: String - contextPath: PassiveTotal.Article.type description: The type of an article. type: String - contextPath: PassiveTotal.Article.publishedDate description: The date and time on which the article was published. type: Date - contextPath: PassiveTotal.Article.link description: The link of the article for getting more details. type: String - contextPath: PassiveTotal.Article.categories description: An array of categories of the article. type: Unknown - contextPath: PassiveTotal.Article.tags description: An array of tags for the article. type: Unknown - contextPath: PassiveTotal.Article.indicators.type description: The type of the indicator. type: String - contextPath: PassiveTotal.Article.indicators.count description: Total number of indicators of a particular type. type: Number - contextPath: PassiveTotal.Article.indicators.values description: An array of values related to indicators. type: Unknown - contextPath: PassiveTotal.Article.indicators.source description: The source of the indicator. type: String - arguments: - default: true description: IP address for which the user wants to search services for. name: ip required: true description: Retrieves exposed services on the recently open ports for an IP address. name: pt-get-services outputs: - contextPath: PassiveTotal.Service.ip description: IP address of the service. type: String - contextPath: PassiveTotal.Service.portNumber description: Port number on which recent services were running or current services are running. type: Number - contextPath: PassiveTotal.Service.firstSeen description: The date and time when the service was started for the first time on the port. type: Date - contextPath: PassiveTotal.Service.lastSeen description: The date and time when the service was most recently used on the port. type: Date - contextPath: PassiveTotal.Service.lastScan description: The date and time when the system performed the last scan to check whether any service is running on the port or not. type: Date - contextPath: PassiveTotal.Service.count description: The total number of times service was used on the port. type: Number - contextPath: PassiveTotal.Service.status description: The status of the service. type: String - contextPath: PassiveTotal.Service.protocol description: The protocol used by the service. type: String - contextPath: PassiveTotal.Service.banners.banner description: The description of the banner generated as a result of scanning. Can be in HTML format. type: String - contextPath: PassiveTotal.Service.banners.scanType description: The type of scan when the banner was generated. type: String - contextPath: PassiveTotal.Service.banners.firstSeen description: The date and time when the scan started. type: Date - contextPath: PassiveTotal.Service.banners.lastSeen description: The date and time when the scan ended. type: Date - contextPath: PassiveTotal.Service.banners.count description: The total number of times the same label was generated while scanning. type: Number - contextPath: PassiveTotal.Service.currentServices.firstSeen description: The date and time when the current service started. type: Date - contextPath: PassiveTotal.Service.currentServices.lastSeen description: The date and time when the current service was most recently used. type: Date - contextPath: PassiveTotal.Service.currentServices.version description: The version of the current service. type: String - contextPath: PassiveTotal.Service.currentServices.category description: The category of the current service. type: String - contextPath: PassiveTotal.Service.currentServices.label description: The label of the current service. type: String - contextPath: PassiveTotal.Service.recentServices.firstSeen description: The date and time when the recent service started. type: Date - contextPath: PassiveTotal.Service.recentServices.lastSeen description: The date and time when the recent service was most recently used. type: Date - contextPath: PassiveTotal.Service.recentServices.version description: The version of the recent service. type: String - contextPath: PassiveTotal.Service.recentServices.category description: The category of the recent service. type: String - contextPath: PassiveTotal.Service.recentServices.label description: The label of the recent service. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.firstSeen description: The timestamp in epoch when the most recent SSL certificate was identified by the system. type: Date - contextPath: PassiveTotal.Service.mostRecentSslCert.lastSeen description: The timestamp in epoch when the most recent SSL certificate was last used. type: Date - contextPath: PassiveTotal.Service.mostRecentSslCert.fingerprint description: A fingerprint detail from the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.sslVersion description: The version of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.expirationDate description: The expiry date and time of the most recent SSL certificate in GMT. type: Date - contextPath: PassiveTotal.Service.mostRecentSslCert.issueDate description: The date and time in GMT when the most recent SSL certificate was issued. type: Date - contextPath: PassiveTotal.Service.mostRecentSslCert.sha1 description: Sha1 of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.serialNumber description: The serial Number of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectCountry description: The name of the Country of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerCommonName description: The common name of the issuer of most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerProvince description: The province of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectStateOrProvinceName description: The state or province name of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectStreetAddress description: The street address of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerStateOrProvinceName description: The state or province name of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectSurname description: The surname of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerCountry description: The country of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectLocalityName description: The subject locality name of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectAlternativeNames description: List of alternative names of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerOrganizationUnitName description: The name organization unit of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerOrganizationName description: The organization name of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectEmailAddress description: Email Address of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectOrganizationName description: The organization name of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerLocalityName description: The name of the locality of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectCommonName description: Common name of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectProvince description: The province of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerGivenName description: The given name of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectOrganizationUnitName description: Subject organization unit name of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerEmailAddress description: The email address of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectGivenName description: Given name of the subject of the the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.subjectSerialNumber description: The serial number of the subject of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerStreetAddress description: The street Address of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerSerialNumber description: The serial number of the issuer of the most recent SSL certificate. type: String - contextPath: PassiveTotal.Service.mostRecentSslCert.issuerSurname description: The surname of the issuer of the most recent SSL certificate. type: String - arguments: - auto: PREDEFINED description: |- Search cookies information by name or domain. Valid values: 1. get addresses by cookie domain 2. get addresses by cookie name 3. get hosts by cookie domain 4. get hosts by cookie name. name: search_by predefined: - get addresses by cookie domain - get addresses by cookie name - get hosts by cookie domain - get hosts by cookie name required: true - description: Name or domain of cookie the user wants to search for. name: query required: true - defaultValue: '0' description: Page number for paging through results. Each page contains 2000 values. name: page - auto: PREDEFINED defaultValue: last seen description: 'Field to sort the results on. Valid values: last seen, first seen.' name: sort predefined: - last seen - first seen - auto: PREDEFINED defaultValue: desc description: 'Order to return the results in. Valid values: asc, desc.' name: order predefined: - desc - asc description: Retrieves cookies addresses or hostname information based on cookie name or domain. name: pt-get-cookies outputs: - contextPath: PassiveTotal.Cookie.hostname description: The hostname/IP of the machine on which the cookie was found. type: String - contextPath: PassiveTotal.Cookie.cookieName description: The name of the cookie that was found on the host. type: String - contextPath: PassiveTotal.Cookie.cookieDomain description: The domain from which the cookie originated from. type: String - contextPath: PassiveTotal.Cookie.firstSeen description: The date and time when the cookie was first observed. type: Date - contextPath: PassiveTotal.Cookie.lastSeen description: The date and time when the cookie was most recently observed. type: Date - arguments: - description: 'The domain, host or IP address to be queried. For example: riskiq.com, 1.1.1.1.' name: query required: true description: Retrieves a summary data card associated with the given query. name: pt-get-data-card outputs: - contextPath: PassiveTotal.DataCard.type description: Type of the indicator. type: String - contextPath: PassiveTotal.DataCard.name description: Name of the indicator. type: String - contextPath: PassiveTotal.DataCard.link description: Link to the indicator. type: String - contextPath: PassiveTotal.DataCard.netblock description: Netblock associated with the indicator. type: String - contextPath: PassiveTotal.DataCard.os description: Operating system associated with the indicator. type: String - contextPath: PassiveTotal.DataCard.organization description: The organization of the indicator. type: String - contextPath: PassiveTotal.DataCard.asn description: Autonomous system number assigned to the indicator. type: String - contextPath: PassiveTotal.DataCard.hosting_provider description: Host provider of the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.resolutions.count description: Number of resolutions attached to the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.resolutions.link description: Link of the resolutions attached to the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.services.count description: Number of service records for the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.services.link description: Link to the service records of the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.certificates.count description: Number of certificates for the given indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.certificates.link description: Link to the certificates associated with the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.hashes.count description: Number of hashes associated with the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.hashes.link description: Link to the hashes associated with the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.projects.count description: Number of projects containing the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.projects.link description: Number of projects containing the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.articles.count description: Number of articles referencing the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.articles.link description: Link to the articles referencing the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.trackers.count description: Number of trackers associated with the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.trackers.link description: Link to the trackers associated with the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.components.count description: Number of components associated with the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.components.link description: Link to the components associated with the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.host_pairs.count description: Number of host pairs associated with the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.host_pairs.link description: Link to the host pairs associated with the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.reverse_dns.count description: Number of DNS records for the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.reverse_dns.link description: Link to the DNS records of the indicator. type: String - contextPath: PassiveTotal.DataCard.data_summary.cookies.count description: Number of available cookie records for the indicator. type: Number - contextPath: PassiveTotal.DataCard.data_summary.cookies.link description: Link to the cookie records for the indicator. type: String - arguments: - description: 'The domain, host or IP address to be queried. For example: riskiq.com, 1.1.1.1.' name: query required: true description: Gets reputation for a given domain, host or IP. name: pt-get-reputation outputs: - contextPath: PassiveTotal.Reputation.query description: The value of the indicator. type: String - contextPath: PassiveTotal.Reputation.score description: Reputation score of the indicator. type: Number - contextPath: PassiveTotal.Reputation.classification description: Reputation classification of the indicator. (Can be GOOD, SUSPICIOUS, MALICIOUS, or UNKNOWN). type: String - contextPath: PassiveTotal.Reputation.rules.name description: Name of the rule that informed the reputation score of the indicator. type: String - contextPath: PassiveTotal.Reputation.rules.description description: Description of the rule. type: String - contextPath: PassiveTotal.Reputation.rules.severity description: Severity of the rule. type: Number - contextPath: PassiveTotal.Reputation.rules.link description: Link to the rule. type: String - arguments: - default: true description: The IP address to check. isArray: true name: ip description: Checks the reputation of an IP address. name: ip outputs: - contextPath: PassiveTotal.IP.query description: The value of the indicator. type: String - contextPath: PassiveTotal.IP.score description: Reputation score of the indicator. type: Number - contextPath: PassiveTotal.IP.classification description: Reputation classification of the indicator. (Can be GOOD, SUSPICIOUS, MALICIOUS, or UNKNOWN). type: String - contextPath: PassiveTotal.IP.rules.name description: Name of the rule that informed the reputation score of the indicator. type: String - contextPath: PassiveTotal.IP.rules.description description: Description of the rule. type: String - contextPath: PassiveTotal.IP.rules.severity description: Severity of the rule. type: Number - contextPath: PassiveTotal.IP.rules.link description: Link to the rule. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: IP.Address description: The IP Address. type: String - arguments: - description: |- Specify the ID of the profile to retrieve the specific profile. Note: If 'id' argument is provided, all other arguments will be neglected. name: id - description: 'Filter the result based on title or aliases. ' name: query - auto: PREDEFINED description: "Filter the results based on the profile type. \n\nPossible values: actor, tool, backdoor." name: type predefined: - actor - tool - backdoor - description: "Specify the indicator value to retrieve the profiles containing the given indicator.\n\nNote: To retrieve the list of indicators, execute the \"pt-list-intel-profile-indicators\" command. \nWhen both indicator_value and query are provided, higher priority will be given to indicator_value." name: indicator_value - auto: PREDEFINED description: "Filter the result based on the indicator source. \n\nPossible values: osint, riskiq.\n\nNote: Requires 'indicator_value' argument." name: source predefined: - osint - riskiq - auto: PREDEFINED description: "Filter the result based on the indicator category. \n\nPossible values: host, network.\n\nNote: Requires 'indicator_value' argument." name: category predefined: - host - network - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is 1000. name: page_size description: Retrieves the list of all profiles. name: pt-list-intel-profiles outputs: - contextPath: PassiveTotal.IntelProfile.id description: ID of the intel profile. type: String - contextPath: PassiveTotal.IntelProfile.title description: Title of the intel profile. type: String - contextPath: PassiveTotal.IntelProfile.link description: Link to the intel profile. type: String - contextPath: PassiveTotal.IntelProfile.osintIndicatorsCount description: Count of the open source intelligence indicators referencing the intel profile. type: Number - contextPath: PassiveTotal.IntelProfile.riskIqIndicatorsCount description: Count of the riskiq indicators referencing the intel profile. type: Number - contextPath: PassiveTotal.IntelProfile.indicators description: Link to the indicators referencing the intel profile. type: String - contextPath: PassiveTotal.IntelProfile.aliases description: Aliases of the intel profile. type: String - contextPath: PassiveTotal.IntelProfile.tags.label description: Labels associated with the intel profile. type: String - contextPath: PassiveTotal.IntelProfile.tags.countryCode description: Country code of the tags associated with the intel profile. type: String - arguments: - description: |- Specify the ID of the profile to retrieve indicators for the specific profile. Note: To retrieve the list of profile IDs, execute the "pt-list-intel-profile" command. name: id required: true - auto: PREDEFINED description: "Filter the results based on the indicator type. \n\nPossible values: certificate_sha1, domain, email, hash_md5, hash_sha256, ip, pdb_path, soa_email, url, whois_email." name: type predefined: - certificate_sha1 - domain - email - hash_md5 - hash_sha256 - ip - pdb_path - soa_email - url - whois_email - description: Specify the indicator value to retrieve the specific indicator. name: indicator_value - auto: PREDEFINED description: "Filter the result based on the indicator source. \n\nPossible values: osint, riskiq." name: source predefined: - osint - riskiq - auto: PREDEFINED description: "Filter the result based on the indicator category. \n\nPossible values: host, network." name: category predefined: - host - network - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the indicators for the given profile. name: pt-list-intel-profile-indicators outputs: - contextPath: PassiveTotal.IntelProfile.id description: Profile ID containing the indicator. type: String - contextPath: PassiveTotal.IntelProfile.indicator.id description: ID of the indicator. type: String - contextPath: PassiveTotal.IntelProfile.indicator.type description: Type of the indicator. type: String - contextPath: PassiveTotal.IntelProfile.indicator.value description: Value of the indicator. type: String - contextPath: PassiveTotal.IntelProfile.indicator.category description: Category of the indicator. type: String - contextPath: PassiveTotal.IntelProfile.indicator.firstSeen description: Date & time the record was first seen. type: String - contextPath: PassiveTotal.IntelProfile.indicator.lastSeen description: Date & time the record was most recently observed. type: String - contextPath: PassiveTotal.IntelProfile.indicator.osint description: Whether the indicator was published in open source intelligence articles. type: String - contextPath: PassiveTotal.IntelProfile.indicator.osintUrl description: Link to the osint source of the indicator. type: String - contextPath: PassiveTotal.IntelProfile.indicator.articleGuids description: List of RiskIQ OSINT article GUIDs associated with the indicator. type: String - arguments: - auto: PREDEFINED description: |- Filter the results based on the priority level specified. Possible values: high, medium, low. name: priority predefined: - high - medium - low required: true - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is 1000. name: page_size description: Retrieves the attack surface insight information of the individual's account. name: pt-list-my-attack-surface-insights outputs: - contextPath: PassiveTotal.Summary.Insight.name description: The command name. type: String - contextPath: PassiveTotal.Summary.Insight.activeInsightCount description: Total number of active insights. type: Number - contextPath: PassiveTotal.Summary.Insight.totalInsightCount description: Total number of insights. type: Number - contextPath: PassiveTotal.Summary.Insight.totalObservations description: Total number of observations. type: Number - contextPath: PassiveTotal.Insight.priorityLevel description: Priority level of insights. type: String - contextPath: PassiveTotal.Insight.insight.name description: Name of the insight. type: String - contextPath: PassiveTotal.Insight.insight.description description: Description of the insight. type: String - contextPath: PassiveTotal.Insight.insight.observationCount description: Number of observations for the given insight. type: Number - contextPath: PassiveTotal.Insight.insight.link description: Link to the insight. type: String - contextPath: PassiveTotal.Insight.insight.insightId description: ID of the third party insight. type: String - contextPath: PassiveTotal.Insight.insight.segmentBy description: Segment by of the insight. type: String - arguments: - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is 1000. name: page_size description: Retrieves the attack surface information of the individual's account. name: pt-list-my-attack-surfaces outputs: - contextPath: PassiveTotal.AttackSurface.id description: ID of the attack surface. type: Number - contextPath: PassiveTotal.AttackSurface.name description: Name of the attack surface. type: String - contextPath: PassiveTotal.AttackSurface.priority.high.observationCount description: Total observations of high priority attack surface. type: Number - contextPath: PassiveTotal.AttackSurface.priority.high.link description: Link to the high priority attack surface. type: String - contextPath: PassiveTotal.AttackSurface.priority.medium.observationCount description: Total observations of medium priority attack surface. type: Number - contextPath: PassiveTotal.AttackSurface.priority.medium.link description: Link to the medium priority attack surface. type: String - contextPath: PassiveTotal.AttackSurface.priority.low.observationCount description: Total observations of low priority attack surface. type: Number - contextPath: PassiveTotal.AttackSurface.priority.low.link description: Link to the low priority attack surface. type: String - arguments: - description: Specify the vendor ID to retrieve the attack surface third party information. name: id - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface observations by severity level for the given third-party account. name: pt-list-third-party-attack-surface outputs: - contextPath: PassiveTotal.ThirdParty.id description: ID of the vendor. type: Number - contextPath: PassiveTotal.ThirdParty.name description: Name of the vendor. type: String - contextPath: PassiveTotal.ThirdParty.priority.high.observationCount description: Total observations of high priority attack surface. type: Number - contextPath: PassiveTotal.ThirdParty.priority.high.link description: Link to the high priority attack surface. type: String - contextPath: PassiveTotal.ThirdParty.priority.medium.observationCount description: Total observations of medium priority attack surface. type: Number - contextPath: PassiveTotal.ThirdParty.priority.medium.link description: Link to the medium priority attack surface. type: String - contextPath: PassiveTotal.ThirdParty.priority.low.observationCount description: Total observations of low priority attack surface. type: Number - contextPath: PassiveTotal.ThirdParty.priority.low.link description: Link to the low priority attack surface. type: String - contextPath: PassiveTotal.Summary.ThirdPartyASI.name description: The command name. type: String - contextPath: PassiveTotal.Summary.ThirdPartyASI.totalCount description: Total number of attack surfaces. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyASI.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyASI.nextPage description: Link to the next page. type: String - arguments: - description: |- Specify the vendor ID to retrieve the third-party insights information. Note: To retrieve the list of vendor IDs, execute the "pt-list-third-party-attack-surface" command. name: id required: true - auto: PREDEFINED description: |- Filter the results based on the priority level specified. Possible values: high, medium, low. name: priority predefined: - high - medium - low required: true - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is 1000. name: page_size description: Retrieves the attack surface insight information of the given third-party account. name: pt-list-third-party-attack-surface-insights outputs: - contextPath: PassiveTotal.Summary.ThirdPartyInsight.activeInsightCount description: Total number of active third party insights. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyInsight.totalInsightCount description: Total number of third party insights. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyInsight.totalObservations description: Total number of third party observations. type: Number - contextPath: PassiveTotal.ThirdParty.id description: Vendor ID associated with the third party insights. type: Number - contextPath: PassiveTotal.ThirdParty.priorityLevel description: Priority level of third party insights. type: String - contextPath: PassiveTotal.ThirdParty.Insight.insight.name description: Name of the third party insight. type: String - contextPath: PassiveTotal.ThirdParty.Insight.insight.description description: Description of the third party insight. type: String - contextPath: PassiveTotal.ThirdParty.Insight.insight.observationCount description: Number of observations for the given third party insight. type: Number - contextPath: PassiveTotal.ThirdParty.Insight.insight.link description: Link to the third party insight. type: String - contextPath: PassiveTotal.ThirdParty.Insight.insight.insightId description: ID of the third party insight. type: String - contextPath: PassiveTotal.ThirdParty.Insight.insight.segmentBy description: Segment by of the third party insight. type: String - contextPath: PassiveTotal.Summary.ThirdPartyInsight.name description: The command name. type: String - arguments: - description: |- Specify the insight ID to retrieve the assets. Note: To retrieve the list of insight IDs, execute the "pt-list-my-attack-surface-insights" command. name: id required: true - description: |- Specify the segment_by to retrieve the assets. Note: To retrieve the list of segment by, execute the "pt-list-my-attack-surface-insights" command. name: segment_by required: true - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface asset information of the individual's account. name: pt-list-my-attack-surface-assets outputs: - contextPath: PassiveTotal.Summary.Asset.totalCount description: Total number of available assets. type: Number - contextPath: PassiveTotal.Summary.Asset.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.Asset.nextPage description: Link to the next page. type: String - contextPath: PassiveTotal.Asset.insightId description: Insight ID for which assets are retrieved. type: String - contextPath: PassiveTotal.Asset.segmentBy description: Segment by for which assets are retrieved. type: String - contextPath: PassiveTotal.Asset.asset.type description: Type of the asset. type: String - contextPath: PassiveTotal.Asset.asset.name description: Name of the asset. type: String - contextPath: PassiveTotal.Asset.asset.firstSeen description: Date & time the record was first seen. type: Date - contextPath: PassiveTotal.Asset.asset.lastSeen description: Date & time the record was most recently observed. type: Date - contextPath: PassiveTotal.Summary.Asset.name description: The command name. type: String - arguments: - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface vulnerable component information of the individual's account. name: pt-list-my-attack-surface-vulnerable-components outputs: - contextPath: PassiveTotal.Summary.VulnerableComponent.name description: The command name. type: String - contextPath: PassiveTotal.Summary.VulnerableComponent.totalCount description: Total number of available vulnerable components. type: Number - contextPath: PassiveTotal.Summary.VulnerableComponent.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.VulnerableComponent.nextPage description: Link to the next page. type: String - contextPath: PassiveTotal.VulnerableComponent.name description: Name of the vulnerable component. type: String - contextPath: PassiveTotal.VulnerableComponent.type description: Type of the vulnerable component. type: String - contextPath: PassiveTotal.VulnerableComponent.severity description: Severity of the vulnerable component. type: String - contextPath: PassiveTotal.VulnerableComponent.count description: Number of assets affected. type: Number - arguments: - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface vulnerability information of the individual's account. name: pt-list-my-attack-surface-vulnerabilities outputs: - contextPath: PassiveTotal.Vulnerability.cveId description: ID of the CVE. type: String - contextPath: PassiveTotal.Vulnerability.cwes.cweId description: CWE ID associated with the CVE. type: String - contextPath: PassiveTotal.Vulnerability.priorityScore description: Priority score of the CVE. type: Number - contextPath: PassiveTotal.Vulnerability.observationCount description: Number of observations of CVE. type: Number - contextPath: PassiveTotal.Vulnerability.cveLink description: Link to the CVE. type: String - contextPath: PassiveTotal.Summary.Vulnerability.name description: The command name. type: String - contextPath: PassiveTotal.Summary.Vulnerability.totalCount description: Total number of vulnerabilities. type: Number - contextPath: PassiveTotal.Summary.Vulnerability.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.Vulnerability.nextPage description: Link to the next page. type: String - arguments: - description: |- Specify the CVE ID to retrieve observations of that CVE. Note: To retrieve the list of CVE IDs, execute the "pt-list-my-attack-surface-vulnerabilities" command. name: cve_id required: true - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface vulnerability observation information of the individual's account. name: pt-list-my-attack-surface-observations outputs: - contextPath: PassiveTotal.Observation.asset.type description: Type of the asset. type: String - contextPath: PassiveTotal.Observation.asset.name description: Name of the asset. type: String - contextPath: PassiveTotal.Observation.asset.firstSeen description: Date & time the record was first seen. type: Date - contextPath: PassiveTotal.Observation.asset.lastSeen description: Date & time the record was most recently observed. type: Date - contextPath: PassiveTotal.Observation.cveId description: ID of the CVE. type: String - contextPath: PassiveTotal.Observation.cwe.cweId description: CWE ID associated with the CVE. type: String - contextPath: PassiveTotal.Summary.Observation.name description: The command name. type: String - contextPath: PassiveTotal.Summary.Observation.totalCount description: Total number of vulnerabilities. type: Number - contextPath: PassiveTotal.Summary.Observation.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.Observation.nextPage description: Link to the next page. type: String - arguments: - description: |- Specify the insight ID to retrieve the assets. Note: To retrieve the list of insight IDs, execute the "pt-list-third-party-attack-surface-insights" command. name: id required: true - description: |- Specify the vendor ID to retrieve the assets of a specific vendor. Note: To retrieve the list of vendor IDs, execute the "pt-list-third-party-attack-surface" command. name: vendor_id required: true - description: |- Specify the segment_by to retrieve the assets. Note: To retrieve the list of segment by, execute the "pt-list-third-party-attack-surface-insights" command. name: segment_by required: true - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface asset information of the given third-party account. name: pt-list-third-party-attack-surface-assets outputs: - contextPath: PassiveTotal.ThirdParty.id description: ID of the vendor. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyInsightAsset.name description: The command name. type: String - contextPath: PassiveTotal.Summary.ThirdPartyInsightAsset.totalCount description: Total number of available assets. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyInsightAsset.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyInsightAsset.nextPage description: Link to the next page. type: String - contextPath: PassiveTotal.ThirdParty.InsightAsset.insightId description: Insight ID for which assets are retrieved. type: Number - contextPath: PassiveTotal.ThirdParty.InsightAsset.segmentBy description: Segment by for which assets are retrieved. type: String - contextPath: PassiveTotal.ThirdParty.InsightAsset.asset.type description: Type of the asset. type: String - contextPath: PassiveTotal.ThirdParty.InsightAsset.asset.name description: Name of the asset. type: String - contextPath: PassiveTotal.ThirdParty.InsightAsset.asset.firstSeen description: Date & time the record was first seen. type: Date - contextPath: PassiveTotal.ThirdParty.InsightAsset.asset.lastSeen description: Date & time the record was most recently observed. type: Date - arguments: - description: |- Specify the vendor ID to retrieve the vulnerable components for a particular vendor. Note: To retrieve the list of vendor IDs, execute the "pt-list-third-party-attack-surface" command. name: id required: true - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface vulnerable component information of the given third-party account. name: pt-list-third-party-attack-surface-vulnerable-components outputs: - contextPath: PassiveTotal.ThirdParty.id description: ID of the vendor. type: String - contextPath: PassiveTotal.Summary.ThirdPartyVulnerableComponent.name description: The command name. type: String - contextPath: PassiveTotal.Summary.ThirdPartyVulnerableComponent.totalCount description: Total number of available vulnerable components. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyVulnerableComponent.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyVulnerableComponent.nextPage description: Link to the next page. type: String - contextPath: PassiveTotal.ThirdParty.VulnerableComponent.name description: Name of the vulnerable component. type: String - contextPath: PassiveTotal.ThirdParty.VulnerableComponent.type description: Type of the vulnerable component. type: String - contextPath: PassiveTotal.ThirdParty.VulnerableComponent.severity description: Severity of the vulnerable component. type: String - contextPath: PassiveTotal.ThirdParty.VulnerableComponent.count description: Number of assets affected. type: Number - arguments: - description: |- Specify the vendor ID to retrieve the vulnerabilities for a particular vendor. Note: To retrieve the list of vendor IDs, execute the "pt-list-third-party-attack-surface" command. name: id required: true - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface vulnerability information of the given third-party account. name: pt-list-third-party-attack-surface-vulnerabilities outputs: - contextPath: PassiveTotal.ThirdParty.id description: ID of the vendor. type: Number - contextPath: PassiveTotal.ThirdParty.Vulnerability.cveId description: ID of the CVE. type: String - contextPath: PassiveTotal.ThirdParty.Vulnerability.cwes.cweId description: CWE ID associated with the CVE. type: String - contextPath: PassiveTotal.ThirdParty.Vulnerability.priorityScore description: Priority score of the CVE. type: Number - contextPath: PassiveTotal.ThirdParty.Vulnerability.observationCount description: Number of observations of CVE. type: Number - contextPath: PassiveTotal.ThirdParty.Vulnerability.cveLink description: Link to the CVE. type: String - contextPath: PassiveTotal.Summary.ThirdPartyVulnerability.name description: The command name. type: String - contextPath: PassiveTotal.Summary.ThirdPartyVulnerability.totalCount description: Total number of vulnerabilities. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyVulnerability.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyVulnerability.nextPage description: Link to the next page. type: String - arguments: - description: |- Specify the vendor ID to retrieve the vulnerability observations for a particular vendor. Note: To retrieve the list of vendor IDs, execute the "pt-list-third-party-attack-surface" command. name: id required: true - description: |- Specify the CVE ID to retrieve observations of the CVE. Note: To retrieve the list of CVE IDs, execute the "pt-list-third-party-attack-surface-vulnerabilities" command. name: cve_id required: true - defaultValue: '0' description: |- Page number for paging through results. Note: The minimum value supported is 0 and maximum value supported is int32. name: page_number - defaultValue: '50' description: |- Maximum number of results to return per page. Note: The minimum value supported is 1 and maximum value supported is int32. name: page_size description: Retrieves the attack surface vulnerability observation information of the given third-party account. name: pt-list-third-party-attack-surface-observations outputs: - contextPath: PassiveTotal.ThirdParty.id description: ID of the vendor. type: Number - contextPath: PassiveTotal.ThirdParty.Observation.asset.type description: Type of the asset. type: String - contextPath: PassiveTotal.ThirdParty.Observation.asset.name description: Name of the asset. type: String - contextPath: PassiveTotal.ThirdParty.Observation.asset.firstSeen description: Date & time the record was first seen. type: Date - contextPath: PassiveTotal.ThirdParty.Observation.asset.lastSeen description: Date & time the record was most recently observed. type: Date - contextPath: PassiveTotal.ThirdParty.Observation.cveId description: ID of the CVE. type: String - contextPath: PassiveTotal.ThirdParty.Observation.cwe.cweId description: CWE ID associated with the CVE. type: String - contextPath: PassiveTotal.Summary.ThirdPartyObservation.name description: The command name. type: String - contextPath: PassiveTotal.Summary.ThirdPartyObservation.totalCount description: Total number of observations. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyObservation.totalPages description: Number of pages. type: Number - contextPath: PassiveTotal.Summary.ThirdPartyObservation.nextPage description: Link to the next page. type: String dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python tests: - No Tests- non-certified partner, test was moved to non circle folder. fromversion: 5.0.0