ThreatSTOP
The ThreatSTOP connector includes the Check IOC feature, allowing users to lookup IP addresses and domains against their extensive database of malware-related IOCs.
Prerequisites
The ThreatSTOP asset requires an URL and an API Key to interact with the API.
Capabilities
This connector provides the following capabilities:
- Check IOC (Multiple)
- Get Check IOC (Single)
Notes
For more information on ThreatSTOP: ThreatSTOP API Documentation
Configurations
HTTP Bearer Authentication
Authenticates using bearer token such as a JWT, etc.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The API key. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Check IOC Multiple
The POST version of the check_ioc service can check for up to 10 IOCs in the same HTTP request.
Endpoint
- URL: /v4.0/check_ioc
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
iocs | array | Optional | Parameter for Check IOC Multiple |
iocs.ioc | string | Optional | IP address or domain name. |
Input Example
{"json_body":{"iocs":[{"ioc":"www.example.com"},{"ioc":"www.example.net"}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
_data | array | Response data |
_data.info | object | Response data |
_data.info.active | array | Response data |
_data.info.active.last_used | number | Response data |
_data.info.active.blocker | object | Response data |
_data.info.active.blocker.last_update | number | Response data |
_data.info.active.blocker.description | string | Response data |
_data.info.active.blocker.short_description | string | Response data |
_data.info.active.blocker.name | string | Response data |
_data.info.active.blocker.danger_level | number | Response data |
_data.info.active.blocker.public_description | string | Response data |
_data.info.active.blocker.match_type | string | Response data |
_data.info.active.first_identified | number | Response data |
_data.info.active.ioc | string | Response data |
_data.info.active.domain | string | Response data |
_data.info.active.address | string | Response data |
_data.info.history | array | Response data |
_data.info.history.last_used | number | Response data |
_data.info.history.blocker | object | Response data |
_data.info.history.blocker.public_description | string | Response data |
_data.info.history.blocker.last_update | number | Response data |
_data.info.history.blocker.description | string | Response data |
_data.info.history.blocker.short_description | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 08 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"_data":[{}],"_links":{"self":{}},"_meta":{"disclaimer":"string","request_id":"string"}}}
Get Check IOC (Single)
This operation retrieve the Threat Intelligence from ThreatSTOP's database for the IOC passed as argument - IP address or DNS Record.
Endpoint
- URL: /v4.0/check_ioc
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ioc | string | Required | IP address or domain name. |
parameters.include_related | boolean | Optional | Include targetas associated with A Records resolved from the DNS record, if any. |
parameters.include_subdomains | boolean | Optional | Include records for subdomains of the requested IOC (domain IOC only). |
Input Example
{"parameters":{"ioc":"bad.threatstop.com","include_related":false,"include_subdomains":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | object | Value for the parameter |
value._links | object | Value for the parameter |
value._links.self | object | Value for the parameter |
value._links.self.href | string | Value for the parameter |
value._data | array | Response data |
value._data.ioc | string | Response data |
value._data.info | object | Response data |
value._data.info.active | array | Response data |
value._data.info.active.blocker | object | Response data |
value._data.info.active.first_identified | number | Response data |
value._data.info.active.ioc | string | Response data |
value._data.info.active.last_used | number | Response data |
value._data.info.active.domain | string | Response data |
value._data.info.active.expired | boolean | Response data |
value._data.info.history | array | Response data |
value._data.info.history.blocker | object | Response data |
value._data.info.history.first_identified | number | Response data |
value._data.info.history.ioc | string | Response data |
value._data.info.history.last_used | number | Response data |
value._data.info.history.domain | string | Response data |
value._data.info.history.expired | boolean | Response data |
value._data.info.related_records | array | Response data |
value._data.info.related_records.bad.threatstop.com | array | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 08 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"value":{"_links":{},"_data":[],"_metadata":{}}}}
Response Headers
Header | Description | Example |
|---|---|---|
content-length | The length of the response body in bytes | 140 |
content-type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 08 Dec 2023 20:37:23 GMT |