π
AssemblyLine
Seamlessly integrates with the AssemblyLine malware analysis platform. Automatically correlates indicators
(IPs, domains, hashes) against past analysis results, providing immediate visibility into previously
analyzed threats and their verdicts.
π
Certificate Transparency (crt.sh)
Leverages the crt.sh database to uncover SSL/TLS certificate history for domains. Helps analysts track
certificate issuance, identify potential phishing infrastructure, and map related domains through
Certificate Transparency logs.
π
Example Plugin
A comprehensive reference implementation for developers. Demonstrates the complete plugin lifecycle,
including enrichment logic, custom actions, and data formatting, serving as a perfect starting point for
building custom internal integrations.
π¨
Howler
Connects directly with the Howler alert triage platform. Instantly verifies if an indicator has been seen
in previous security alerts or hits, and provides one-click pivoting features to seamlessly transition
from analysis to investigation within the Howler UI.
π¦
MalwareBazaar
Taps into the MalwareBazaar community-driven intelligence. Enriches file hashes (MD5, SHA1, SHA256) with
attribution data, malware family signatures, and vendor detection statistics to quickly identify known
malicious payloads.
πͺ
Port Lookup
Provides instant context for network ports and services. Automatically maps port numbers from raw inputs
or URLs to their IANA service definitions and common usages, enhanced with visual service icons (e.g.,
SSH, HTTP, FTP) for faster recognition.
π‘οΈ
VirusTotal
Unlocks global threat context via the VirusTotal API. Enriches IPs, domains, URLs, and file hashes with
reputation scores, geographic ownership data (ASN/Country), and detailed threat intelligence attributes
to accelerate decision-making.