EmergingThreats

logo

EmergingThreats_DomainInfo

Details

Author

Davide Arcuri and Andrea Garavaglia, LDO-CERT

Version

1.0

License

AGPL-V3

Website

https://github.com/dadokkio/Cortex-Analyzers

Requires Registration

Yes

Requires Subscription

Yes

Free Subscription Available

No

DataType Supported

domain, fqdn

Service Homepage

EmergingThreats_DomainInfo

Description

Retrieve ET reputation, related malware, and IDS requests for a given domain.

Configuration

Name

Description

key

API key

EmergingThreats_IPInfo

Details

Author

Davide Arcuri and Andrea Garavaglia, LDO-CERT

Version

1.0

License

AGPL-V3

Website

https://github.com/dadokkio/Cortex-Analyzers

Requires Registration

Yes

Requires Subscription

Yes

Free Subscription Available

No

DataType Supported

ip

Service Homepage

EmergingThreats_IPInfo

Description

Retrieve ET reputation, related malware, and IDS requests for a given IP address.

Configuration

Name

Description

key

API key

EmergingThreats_MalwareInfo

Details

Author

Davide Arcuri and Andrea Garavaglia, LDO-CERT

Version

1.0

License

AGPL-V3

Website

https://github.com/dadokkio/Cortex-Analyzers

Requires Registration

Yes

Requires Subscription

Yes

Free Subscription Available

No

DataType Supported

file, hash

Service Homepage

EmergingThreats_MalwareInfo

Description

Retrieve ET details and info related to a malware hash.

Configuration

Name

Description

key

API key

Additional details from the README file:

EmergingThreats

EmergingThreats intelligence helps prevent attacks and reduce risk by helping you understand the historical context of where these threats originated, who is behind them, when have they attacked, what methods they used, and what they’re after.

The analyzer is available in 3 flavors:

  • EmergingThreats_DomainInfo: retrieve ET reputation, related malware, and IDS requests for a given domain.

  • EmergingThreats_IPInfo: retrieve ET reputation, related malware, and IDS requests for a given IP address.

  • EmergingThreats_MalwareInfo: retrieve ET details and info related to a malware hash.

Requirements

You need a valid EmergingThreats API subscription to use the analyzer:

  • Provide your API key as a value for the key parameter.