Enricher - CentralOps Domain Dossier


This article describes the specific configuration options to set up the enricher.
To configure the general options for the enricher, see Configure the general options.


Specifications

Enricher name

CentralOps Domain Dossier

Input

Domain.

Output

Details on geolocation, ASN, registrar, whois and DNS records, open ports and protocols (when available).

API endpoint

https://hexillion.com/rf/xml/1.0/whois/

Description

The CentralOps Domain Dossier enricher augments input observables with a wide range of contextual information such as geolocation, ASN, whois, registrar, domain name, file hash, and so on.

The default Source reliability value for this enricher is C – Fairly reliable.
You can change it to a different reliability value, as needed.

Requirements

Users need a Username and Password. Sign up and subscribe to the service to obtain the required credentials.

Configure the enricher parameters

  1. Edit the enricher.

  2. From the Observable types drop-down menu, select one or more observable types you want to enrich with data retrieved through the CentralOps Domain Dossier enricher.

  3. The API URL field is automatically filled in with the default domain for the endpoint.
    You can add a proxy or set up ports according to your needs.
    Default value: https://hexillion.com/rf/xml/1.0/.

  4. In the Username field, enter your user name.
    Sign up and subscribe to the service to obtain the required authorization user name and password credentials to access the API endpoint exposing the service, and then enter your user name in this field.

  5. In the Password field, enter the password you received after signing up for a user account at Hexillion.

  6. To store your changes, click Save; to discard them, click Cancel.

See also