Skip to content

MSRiskIQPassiveTotal#

PassiveTotal_Ssl_Certificate_Details#

Author: CERT-BDF
License: AGPL-V3
Version: 2.0
Supported observables types:
- hash
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal SSL Certificate Details Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Passive_Dns#

Author: CERT-BDF
License: AGPL-V3
Version: 2.1
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Passive DNS Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Trackers#

Author: Brandon Dixon (9bplus)
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Trackers Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Unique_Resolutions#

Author: CERT-BDF
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Unique Resolutions Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Malware#

Author: CERT-BDF
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Malware Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Ssl_Certificate_History#

Author: CERT-BDF
License: AGPL-V3
Version: 2.0
Supported observables types:
- hash
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal SSL Certificate History Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Host_Pairs#

Author: Brandon Dixon (9bplus)
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Host Pairs Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Whois_Details#

Author: CERT-BDF
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Whois Details Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Components#

Author: Brandon Dixon (9bplus)
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Components Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Osint#

Author: CERT-BDF
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal OSINT Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.

PassiveTotal_Enrichment#

Author: CERT-BDF
License: AGPL-V3
Version: 2.0
Supported observables types:
- domain
- fqdn
- ip
Registration required: N/A
Subscription required: N/A
Free subscription: N/A
Third party service: https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-threat-intelligence

Description#

PassiveTotal Enrichment Lookup.

Configuration#

username Define the username of the account used to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
key Define the API key to use to connect the service
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

No template samples to display.