connectors
connectors copied to clipboard
[virustotal-enrichment] Add reverse DNS resolutions
Use case
When enriching an IP, I would expect to get the latest known domain for that IP. When enriching an IP, retrieve the “passive dns replication” field and create observables for the last three resolved domains (and the date of resolution should be saved in the created relationship within OpenCTI).
Current Workaround
This information is very important to retrieve, and currently SOC analysts have to go onto VirusTotal themselves for this piece of information.
Proposed Solution
Have the ability to retrieve the domain from the IP - reverse DNS
Besides reverse DNS, can additional information, such as Whois information, registration data, HTTPS certificates, be added to Notes?