RDAP#
README
RDAP#
RDAP (Registration Data Access Protocol) is the IETF successor to WHOIS, standardised in RFC 7480 through RFC 7484. It returns registration data as structured JSON over HTTPS instead of the unstructured text WHOIS returns over port 43, and it is now the protocol registries are required to support.
The analyzer takes a domain or an IP address and returns its registration record: registrar, registration and expiry events, registry status codes, and nameservers. Nameservers are extracted as observables.
Queries go through https://rdap.org/, which resolves the authoritative RDAP server for the object and redirects to it, so a single endpoint covers every TLD and regional internet registry.
Requirements#
None. RDAP is an open protocol and requires no account, key or subscription.
The only configuration item is an optional HTTP timeout in seconds, which defaults
to 15.
RDAP#
Author: yatuk
License: AGPL-V3
Version: 1.0
Supported observables types:
- domain
- ip
Registration required: False
Subscription required: False
Free subscription: True
Third party service: https://rdap.org/
Description#
Look up domain and IP registration data over RDAP, the IETF successor to WHOIS. No API key required.
Configuration#
| timeout | HTTP timeout in seconds |
|---|---|
| Default value if not configured | 15 |
| Type of the configuration item | number |
| The configuration item can contain multiple values | False |
| Is required | False |
Templates samples for TheHive#
No template samples to display.