/alienvault_otx/indicators

POST /api/alienvault_otx/indicators

Price: 5 credits

Get an AlienVault OTX threat-intelligence indicator with its enrichment and related pulses

How to use it

Look up an AlienVault OTX (Open Threat Exchange) indicator of compromise by type and value — an IP (IPv4/IPv6), domain, hostname, URL, file hash (use type `file` for MD5/SHA1/SHA256) or CVE id. Returns the indicator's enrichment: geolocation and ASN (for IPs), a WHOIS reference (domains), reputation, false-positive and validation/whitelist assessments. For a CVE it returns the full vulnerability record — description, CVSS base score / severity / vector, CWE weakness id, EPSS exploit-prediction score, whether it is exploited in the wild, affected products (CPEs), known public exploits, advisory references, and the MITRE/NVD links. And — most importantly — the community pulses (threat reports) that reference this indicator with their tags, adversary, malware families and MITRE ATT&CK ids, plus the related adversaries, malware families and targeted industries.

Parameters

Request body

Response

Errors

Response headers