Virus Total | APIv3 | Domain enricher#

The Domain enricher provides additional intelligence connected to domain observables.

Observable types#

This Enricher only enriches domain observables.

Endpoints & Outputs#

Endpoint

Reponse

Output type

Communicating files

Files known to communicate with the enriched domain.

hash-sha256

Downloaded files

Files that have been downloaded from the enriched domain.

hash-sha256

Historical SSL certificates

Hashes of SSL certificates associated with the enriched domain at some point in time.

hash-sha256, hash-sha1

URLs

Known URLs under the enriched domain.

uri

Resolutions

Past and current IPv4 addresses that the enriched domain resolves to.

ipv4

MX records

All MX records associated with the enriched domain.

domain

NS records

All NS records associated with the enriched domain.

domain

Referrer files

Files that contain a string representation of the enriched domain.

hash-sha256

SOA records

All SOA records associated with the enriched domain.

domain

Subdomains

All direct subdomains for the enriched domain.

domain

Configure#

Make sure you’ve configured your VT APIv3 key.

Required fields

Fields on the Enricher pane marked with an asterisk (“*”) are required to fill in, but may come pre-filled.

  1. Go to Data configuration Data configuration icon > Enrichers.

  2. Filter the list by searching for VirusTotal APIv3 Domain enricher.

  3. In the row of the URL enricher, select More More > Edit.

  4. For Source reliability, select the source reliability rating that will be applied to the Entities and Observables this enricher will produce if you haven’t configured it yet.

  5. Under API key, enter your VirusTotal API key if you haven’t configured it yet.

  6. Under Include Endpoints, select the Endpoints you’d like the enricher to hit.

  7. (Optional) Change the Description.

  8. (Optional) Change the Cache validity, Rate limit, or Monthly execution cap.

  9. (Optional) Select Create Parent Report or SSL verification and supply a Path to SSL certificate file.

  10. Check the Enabled box to enable the enricher when you’re done configuring it.

  11. Select Save.