The Investigation Insights – ThreatMiner integration searches ThreatMiner for whois information on domains and IPs as well as sample information related to file hashes. Enabling analysts to have quick insights into public whois information and vulnerability context around file hashes.
Examples
ThreatMiner Data Overview
- Summary Tags: When an analyst looks up indicators in ThreatMiner, they can quickly tell the number of associated results related to that indicator.
- Additional Context: Drilling into the details of the ThreatMiner integration, the analysts will be able to see additional details related to the indicator. In this case looking up an IP will result in whois information about the indicator.
