Enricher - PassiveTotal Whois

This article describes the specific configuration options to set up the enricher.
To configure the general options for the enricher, see Configure the general options.


Enricher name

PassiveTotal Whois


Domain, host, and IP addresses (ipv4 and ipv6).


Enriches supported observable types with whois information.

API endpoint



The PassiveTotal Whois enricher provides information about individuals or entities associated with an IP address or a domain name, as well as geolocation details.
Analysts can retrieve registrar, organization, country, city, street, telephone, and email details.
They can then use these details to run further queries to obtain, for example, more domain names associated with the same individual or the same company.


Users need an API key for their own configuration. Sign up and subscribe to the service to obtain the required API key credentials to access the API endpoint exposing the service.

Configure the enricher parameters

  1. Edit the enricher.

  2. From the Observable types drop-down menu, select one or more observable types you want to enrich with data retrieved through the PassiveTotal Whois enricher.

  3. The API URL field is automatically filled in with the default domain for the endpoint.
    You can add a proxy or set up ports according to your needs.
    Default value: https://api.passivetotal.org/v2.

  4. In the API key field, enter your API key.

  5. In the Email field, enter the email address associated with the PassiveTotal Whois account to access and consume the PassiveTotal Whois API service.

  6. To store your changes, click Save; to discard them, click Cancel.

See also