Team T5 Threat Vision TI
The Team T5 Threat Vision TI connector enables seamless access to a rich set of threat intelligence data, enhancing cybersecurity operations and threat analysis.
Team T5 Threat Vision TI offers a comprehensive threat intelligence platform, providing in-depth analysis and insights into cyber threats. This connector enables Swimlane Turbine users to integrate real-time threat intelligence directly into their security workflows. By leveraging Team T5's extensive data on domains, IPs, and malware samples, security teams can automate threat detection, enhance incident response, and improve overall security posture. The integration facilitates proactive defense strategies by providing actionable intelligence and automating analysis tasks.
Prerequisites
Before integrating Team T5 Threat Vision TI with Swimlane Turbine, ensure you have the following prerequisites:
- OAuth2 client credentials authentication with the following parameters:
- URL: Endpoint for the Team T5 Threat Vision TI API
- Client ID: Unique identifier for OAuth2 authentication
- Client Secret: Confidential key for OAuth2 authentication
Capabilities
This TeamT5 Threat Vision TI Connector has following capabilities:
- Domain
- Analysis Status for Domain
- DNS Records of Domain
- Get Domain Information
- Get Whois for Domain
- OSINT Posts Domain
- Reports Related to Domain
- Samples Related to Domain
- Search Domains
- Intelligence Reports
- Intelligence List Reports
- IoC Bundles
- Download IoC Bundles
- List IoC Bundles
- IP
- Analysis Status for IP
- DNS Records of IP
- Get IP Information
- Get Whois for IP
- OSINT Posts IP
- Reports Related to IP
- Samples Related to IP
- Search IPs
- Patch Management Report(PMR)
- Get PMR
- List PMR
- Sample (File)
- Reports of Sample
- Sandbox
- Search Samples
- Upload Sample File
Configurations
TeamT5 ThreatVision TI Oauth2 Client Credentials
Authenticates using oauth2 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
client_id | The client ID. | string | Required |
client_secret | The client secret. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Analysis Status for Domain
Check the completion status of a domain analysis in Team T5 Threat Vision TI using the provided domain name.
Endpoint
- URL: api/v2/network/domains/{{domain_name}}/analysis_status
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_name | string | Required | Domain Name. |
Input Example
{"path_parameters":{"domain_name":"login.spiritismireland.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
analysis_status | boolean | Status value |
message | string | Response message |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"analysis_status":true,"message":"Analysis Finished"}}
Analysis Status for IP
Check the completion status of an IP analysis in Team T5 Threat Vision TI using the specified address.
Endpoint
- URL: api/v2/network/ips/{{address}}/analysis_status
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.address | string | Required | The IP address. |
Input Example
{"path_parameters":{"address":"88.214.27.53"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
analysis_status | boolean | Status value |
message | string | Response message |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"analysis_status":true,"message":"Analysis Finished"}}
DNS Records of Domain
Retrieve passive DNS records associated with a specified domain name from Team T5 Threat Vision TI.
Endpoint
- URL: api/v2/network/domains/{{domain_name}}/dns_records
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_name | string | Required | Domain Name. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"domain_name":"lomeptos.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
records | array | Output field: records |
records.date | string | Date value |
records.type | string | Type of the resource |
records.value | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"lomeptos.com","analysis_status":true,"records":[{}]}}
DNS Records of IP
Retrieve passive DNS records for a given IP from Team T5 Threat Vision TI, requiring the 'address' path parameter.
Endpoint
- URL: api/v2/network/ips/{{address}}/dns_records
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.address | string | Required | The IP address. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"address":"167.179.85.233"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
records | array | Output field: records |
records.date | string | Date value |
records.type | string | Type of the resource |
records.value | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"88.214.27.53","analysis_status":true,"records":[{}]}}
Download IoC Bundles
Enables the downloading of authorized Indicator of Compromise (IoC) bundles in specified formats using 'ioc_bundle_id' and 'format'.
Endpoint
- URL: api/v2/ioc_bundles/{{ioc_bundle_id}}.{{format}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ioc_bundle_id | string | Required | The identity of IoC bundle. |
path_parameters.format | string | Required | Format of IoC bundle. |
Input Example
{"path_parameters":{"ioc_bundle_id":"Q2FzZUZpbGUvMTE3MDU="}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
file | object | Attachment |
file.file | string | Output field: file.file |
file.file_name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","file":{}}
Get Domain Information
Retrieve domain metadata such as risk level, registrar, and services from Team T5 Threat Vision TI using the 'domain_name' parameter.
Endpoint
- URL: api/v2/network/domains/{{domain_name}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_name | string | Required | Domain Name. |
Input Example
{"path_parameters":{"domain_name":"lomeptos.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
risk_level | string | Output field: risk_level |
risk_score | number | Score value |
adversaries | array | Output field: adversaries |
adversaries.file_name | string | Name of the resource |
adversaries.file | string | Output field: adversaries.file |
attributes | array | Output field: attributes |
attributes.file_name | string | Name of the resource |
attributes.file | string | Output field: attributes.file |
services | array | Output field: services |
services.file_name | string | Name of the resource |
services.file | string | Output field: services.file |
registrar | string | Output field: registrar |
last_update_at | string | Output field: last_update_at |
summary | object | Output field: summary |
summary.whois | boolean | Output field: summary.whois |
summary.related_adversaries | number | Output field: summary.related_adversaries |
summary.related_reports | number | Output field: summary.related_reports |
summary.related_samples | number | Output field: summary.related_samples |
summary.dns_records | number | Output field: summary.dns_records |
summary.osint | number | Output field: summary.osint |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"lomeptos.com","analysis_status":true,"risk_level":"high","risk_score":75,"adversaries":[],"attributes":[],"services":[],"registrar":"OwnRegistrar, Inc.","last_update_at":"2023-12-27T11:19:27.727Z","summary":{"whois":true,"related_adversaries":0,"related_reports":0,"related_samples":0,"dns_records":41,"osint":1}}}
Get IP Information
Retrieve IP address metadata, such as risk level, region, and city, from Team T5 Threat Vision TI.
Endpoint
- URL: api/v2/network/ips/{{address}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.address | string | Required | The IP address. |
Input Example
{"path_parameters":{"address":"167.179.85.233"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
risk_level | string | Output field: risk_level |
risk_score | number | Score value |
risk_types | array | Type of the resource |
adversaries | array | Output field: adversaries |
adversaries.file_name | string | Name of the resource |
adversaries.file | string | Output field: adversaries.file |
attributes | array | Output field: attributes |
attributes.name | string | Name of the resource |
attributes.first_seen | string | Output field: attributes.first_seen |
attributes.last_seen | string | Output field: attributes.last_seen |
ip_sharing | array | Output field: ip_sharing |
ip_sharing.name | string | Name of the resource |
ip_sharing.first_seen | string | Output field: ip_sharing.first_seen |
ip_sharing.last_seen | string | Output field: ip_sharing.last_seen |
services | array | Output field: services |
services.file_name | string | Name of the resource |
services.file | string | Output field: services.file |
country | string | Output field: country |
city | string | Output field: city |
region | string | Output field: region |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"167.179.85.233","analysis_status":true,"risk_level":"medium","risk_score":70,"risk_types":["ce"],"adversaries":[],"attributes":[{}],"ip_sharing":[{}],"services":[],"country":"Japan","city":"\u014ci","region":"Saitama","last_update_at":"2023-12-27T11:13:54.578Z","summary":{"whois":true,"related_adversaries":0,"related_reports":6,"related_samples":1,"dns_records":7,"osint":0}}}
Get PMR
Retrieves detailed vulnerability information from a specified report in Team T5 Threat Vision TI using the report name.
Endpoint
- URL: api/v2/vulnerability/advisory_lists/{{name}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.name | string | Required | Title of the report |
Input Example
{"path_parameters":{"name":"2023-Sep-2"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
advisories | array | Output field: advisories |
advisories.identification | string | Unique identifier |
advisories.report_urls | object | URL endpoint for the request |
advisories.vendor | string | Output field: advisories.vendor |
advisories.product | string | Output field: advisories.product |
advisories.product_list | array | Output field: advisories.product_list |
advisories.product_list.file_name | string | Name of the resource |
advisories.product_list.file | string | Output field: advisories.product_list.file |
advisories.cvss | number | Output field: advisories.cvss |
advisories.cvss_vector | string | Output field: advisories.cvss_vector |
advisories.description | object | Output field: advisories.description |
advisories.description.title | string | Output field: advisories.description.title |
advisories.description.detail | string | Output field: advisories.description.detail |
advisories.threat_level | string | Output field: advisories.threat_level |
advisories.poc | object | Output field: advisories.poc |
advisories.publicly_disclosed | boolean | Output field: advisories.publicly_disclosed |
advisories.updated_at | number | Output field: advisories.updated_at |
advisories.patch | string | Output field: advisories.patch |
advisories.references | array | Output field: advisories.references |
advisories.references.file_name | string | Name of the resource |
advisories.references.file | string | Output field: advisories.references.file |
advisories.malicious_files | object | Output field: advisories.malicious_files |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"advisories":[{}]}}
Get Whois for Domain
Retrieve Whois information for a specified domain name from Team T5 Threat Vision TI, requiring the domain_name parameter.
Endpoint
- URL: api/v2/network/domains/{{domain_name}}/whois
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_name | string | Required | Domain Name. |
Input Example
{"path_parameters":{"domain_name":"lomeptos.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
whois | string | Output field: whois |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"lomeptos.com","analysis_status":true,"whois":" Domain Name: LOMEPTOS.COM\r\n Registry Domain ID: 2840749178_DOMAIN_COM-VRSN\r..."}}
Get Whois for IP
Retrieve WHOIS registry information for a specified IP address from Team T5 Threat Vision TI.
Endpoint
- URL: api/v2/network/ips/{{address}}/whois
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.address | string | Required | The IP address. |
Input Example
{"path_parameters":{"address":"167.179.85.233"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
whois | string | Output field: whois |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"167.179.85.233","analysis_status":true,"whois":"{\n \"ip\": \"167.179.85.233\",\n \"asn\": {\n \"asn\": \"AS20473\",\n \"name\": \"The Co..."}}
Intelligence List Reports
Retrieve the top 10 recent reports matching criteria in Team T5 Threat Vision TI, sorted by publish date.
Endpoint
- URL: api/v2/reports
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query | string | Optional | Keywords to filter reports. |
parameters.types[] | array | Optional | Available report types are Campaign Tracking Report - advanced, Cyber Affairs Report - bi_weekly, Monthly Report - monthly, Flash Report - flash, Vulnerability Insights Report - vulnerability_insights, Miscellaneous - on_demand |
parameters.date[from] | number | Optional | Only match reports published after this date, in unix timestamp. |
parameters.date[to] | number | Optional | Only match reports published before this date, in unix timestamp. |
parameters.tags[] | array | Optional | Only match reports with these tags. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"query":"Flash Report 20230929","types[]":["advanced","bi_weekly"],"date[from]":1622505600,"date[to]":1625097600,"tags[]":["tag1","tag2"],"offset":10}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
reports | array | Output field: reports |
reports.title | string | Output field: reports.title |
reports.date | number | Date value |
reports.type | string | Type of the resource |
reports.adversaries | array | Output field: reports.adversaries |
reports.malwares | array | Output field: reports.malwares |
reports.targeted_countries | array | Output field: reports.targeted_countries |
reports.targeted_industries | array | Output field: reports.targeted_industries |
reports.digest | string | Output field: reports.digest |
reports.pdf_url | string | URL endpoint for the request |
reports.stix_url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"reports":[{}]}}
List IoC Bundles
Retrieve authorized IOC bundles, including names, types, creation dates, and download URLs.
Endpoint
- URL: api/v2/ioc_bundles
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
ioc_bundles | array | Output field: ioc_bundles |
ioc_bundles.id | string | Unique identifier |
ioc_bundles.name | string | Name of the resource |
ioc_bundles.type | string | Type of the resource |
ioc_bundles.created_at | number | Output field: ioc_bundles.created_at |
ioc_bundles.stix_url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"ioc_bundles":[{}]}}
List PMR
Retrieve the most recent PMR reports from Team T5 Threat Vision TI, sorted by publish date.
Endpoint
- URL: api/v2/vulnerability/advisory_lists
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
advisory_lists | array | Output field: advisory_lists |
advisory_lists.name | string | Name of the resource |
advisory_lists.release_date | number | Date value |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"advisory_lists":[{}]}}
OSINT Posts Domain
Retrieve OSINT posts, such as Twitter mentions, linked to a given domain name, requiring the 'domain_name' parameter.
Endpoint
- URL: api/v2/network/domains/{{domain_name}}/intel_posts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_name | string | Required | Domain Name. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"domain_name":"lomeptos.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
posts | array | Output field: posts |
posts.posted_date | string | Date value |
posts.content | string | Response content |
posts.url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"lomeptos.com","analysis_status":true,"posts":[{}]}}
OSINT Posts IP
Retrieve OSINT mentions, like Twitter posts, linked to a specific IP address using Team T5 Threat Vision TI.
Endpoint
- URL: api/v2/network/ips/{{address}}/intel_posts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.address | string | Required | The IP address. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"address":"167.179.85.233"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
posts | array | Output field: posts |
posts.posted_date | string | Date value |
posts.content | string | Response content |
posts.url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"88.214.27.53","analysis_status":true,"posts":[{}]}}
Reports of Sample
Retrieve related reports authored by Team T5 analysts using a specified sample ID as input.
Endpoint
- URL: api/v2/samples/{{sample_id}}/reports
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sample_id | string | Required | Sample ID. The sha256 for sample. |
parameters.offset | number | Optional | Parameters for the Reports of Sample action |
Input Example
{"parameters":{"offset":5},"path_parameters":{"sample_id":"364f38b48565814b576f482c1e0eb4c8d58effcd033fd45136ee00640a2b5321"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
reports | array | Output field: reports |
reports.title | string | Output field: reports.title |
reports.date | number | Date value |
reports.type | string | Type of the resource |
reports.adversaries | array | Output field: reports.adversaries |
reports.malwares | array | Output field: reports.malwares |
reports.targeted_countries | array | Output field: reports.targeted_countries |
reports.targeted_industries | array | Output field: reports.targeted_industries |
reports.capability | array | Output field: reports.capability |
reports.digest | string | Output field: reports.digest |
reports.pdf_url | string | URL endpoint for the request |
reports.stix_url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"364f38b48565814b576f482c1e0eb4c8d58effcd033fd45136ee00640a2b5321","reports":[{}]}}
Reports Related to Domain
Retrieve related reports from Team T5 Threat Vision TI for a specified domain, offering insights into associated campaigns.
Endpoint
- URL: api/v2/network/domains/{{domain_name}}/reports
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_name | string | Required | Domain Name. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"domain_name":"login.spiritismireland.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
reports | array | Output field: reports |
reports.title | string | Output field: reports.title |
reports.date | number | Date value |
reports.type | string | Type of the resource |
reports.adversaries | array | Output field: reports.adversaries |
reports.malwares | array | Output field: reports.malwares |
reports.targeted_countries | array | Output field: reports.targeted_countries |
reports.targeted_industries | array | Output field: reports.targeted_industries |
reports.capability | array | Output field: reports.capability |
reports.capability.file_name | string | Name of the resource |
reports.capability.file | string | Output field: reports.capability.file |
reports.digest | string | Output field: reports.digest |
reports.pdf_url | string | URL endpoint for the request |
reports.stix_url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"login.spiritismireland.com","analysis_status":true,"reports":[{}]}}
Reports Related to IP
Retrieve detailed reports from Team T5 Threat Vision TI analysts for a specified IP address, offering insights into related threat campaigns.
Endpoint
- URL: api/v2/network/ips/{{address}}/reports
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.address | string | Required | The IP address. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"address":"167.179.85.233"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
reports | array | Output field: reports |
reports.title | string | Output field: reports.title |
reports.date | number | Date value |
reports.type | string | Type of the resource |
reports.adversaries | array | Output field: reports.adversaries |
reports.malwares | array | Output field: reports.malwares |
reports.targeted_countries | array | Output field: reports.targeted_countries |
reports.targeted_industries | array | Output field: reports.targeted_industries |
reports.capability | array | Output field: reports.capability |
reports.digest | string | Output field: reports.digest |
reports.pdf_url | string | URL endpoint for the request |
reports.stix_url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"167.179.85.233","analysis_status":true,"reports":[{}]}}
Samples Related to Domain
Retrieve associated malware samples for a given domain name from Team T5 Threat Vision TI, requiring the 'domain_name' parameter.
Endpoint
- URL: api/v2/network/domains/{{domain_name}}/samples
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_name | string | Required | Domain Name. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"domain_name":"login.spiritismireland.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
samples | array | Output field: samples |
samples.main_value | string | Value for the parameter |
samples.sha256 | string | Output field: samples.sha256 |
samples.md5 | string | Output field: samples.md5 |
samples.size | number | Output field: samples.size |
samples.first_seen | number | Output field: samples.first_seen |
samples.adversaries | array | Output field: samples.adversaries |
samples.adversaries.file_name | string | Name of the resource |
samples.adversaries.file | string | Output field: samples.adversaries.file |
samples.malwares | array | Output field: samples.malwares |
samples.malwares.file_name | string | Name of the resource |
samples.malwares.file | string | Output field: samples.malwares.file |
samples.filename | object | Name of the resource |
samples.risk_level | string | Output field: samples.risk_level |
samples.has_network_activity | boolean | Output field: samples.has_network_activity |
samples.url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"login.spiritismireland.com","analysis_status":true,"samples":[{}]}}
Samples Related to IP
Retrieve associated malware samples for a given IP address from Team T5 Threat Vision TI, requiring an 'address' path parameter.
Endpoint
- URL: api/v2/network/ips/{{address}}/samples
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.address | string | Required | The IP address. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"offset":5},"path_parameters":{"address":"167.179.85.233"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
analysis_status | boolean | Status value |
samples | array | Output field: samples |
samples.main_value | string | Value for the parameter |
samples.sha256 | string | Output field: samples.sha256 |
samples.md5 | string | Output field: samples.md5 |
samples.size | number | Output field: samples.size |
samples.first_seen | number | Output field: samples.first_seen |
samples.adversaries | array | Output field: samples.adversaries |
samples.malwares | array | Output field: samples.malwares |
samples.filename | object | Name of the resource |
samples.risk_level | string | Output field: samples.risk_level |
samples.has_network_activity | boolean | Output field: samples.has_network_activity |
samples.url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"167.179.85.233","analysis_status":true,"samples":[{}]}}
Sandbox
Retrieve dynamic analysis results for a given sample by using its unique sample_id in Team T5 Threat Vision TI.
Endpoint
- URL: api/v2/samples/{{sample_id}}/sandbox
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sample_id | string | Required | Sample ID. The sha256 for sample. |
Input Example
{"path_parameters":{"sample_id":"248c8bcccf439195f7e1656dfd2542ff34b4f79015575ef79195c8b233c5f48b"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
id | string | Unique identifier |
data | object | Response data |
data.registry | array | Response data |
data.mutex | array | Response data |
data.mutex.value | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"id":"248c8bcccf439195f7e1656dfd2542ff34b4f79015575ef79195c8b233c5f48b","data":{"registry":[],"mutex":[]}}}
Search Domains
Enables users to search for domains using a query, delivering up to 10 results per request with an offset for refined searches.
Endpoint
- URL: api/v2/network/domains/search
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query | string | Required | Keywords to filter domains. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"query":"teamt5","offset":5}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
domains | array | Output field: domains |
domains.fqdn | string | Output field: domains.fqdn |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"domains":[{}]}}
Search IPs
Search for specific IPs within Team T5 Threat Vision TI, delivering a maximum of 10 results per query with an offset for advanced filtering.
Endpoint
- URL: api/v2/network/ips/search
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query | string | Required | Keywords to filter ips. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"query":"flash_report-20240112023054","offset":5}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
ips | array | Output field: ips |
ips.address | string | Output field: ips.address |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"ips":[{}]}}
Search Samples
Enables users to search for samples in Team T5 Threat Vision TI, delivering up to 10 results per query with advanced offset filtering.
Endpoint
- URL: api/v2/samples/search
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query | string | Required | Keywords to filter samples. |
parameters.offset | number | Optional | Number of results to skip. Allows you to paginate over the results. |
Input Example
{"parameters":{"query":"huapi","offset":5}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
samples | array | Output field: samples |
samples.sha256 | string | Output field: samples.sha256 |
samples.md5 | string | Output field: samples.md5 |
samples.size | number | Output field: samples.size |
samples.first_seen | number | Output field: samples.first_seen |
samples.adversaries | array | Output field: samples.adversaries |
samples.malwares | array | Output field: samples.malwares |
samples.filename | string | Name of the resource |
samples.risk_level | string | Output field: samples.risk_level |
samples.has_network_activity | boolean | Output field: samples.has_network_activity |
samples.url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"samples":[{}]}}
Upload Sample File
Upload files to Team T5 Threat Vision TI for automated malware analysis; consumes 1 AAP per file.
Endpoint
- URL: api/v2/samples
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
files | object | Required | File to be analysed |
files.file | string | Optional | Parameter for Upload Sample File |
files.file_name | string | Optional | Name of the resource |
Input Example
{"files":{"file":"string","file_name":"Example Name"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
url | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"url":"https://api.threatvision.org/api/v2/samples/UPLOADED_SAMPLE_HASH"}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |