Skip to content

Undderstanding Intelowl #756

Answered by eshaan7
fear-the-reaper asked this question in Q&A
Discussion options

You must be logged in to vote

IntelOwl is for aggregating maximum amount of threat intelligence data about a particular observable (IP, domain, hash, URL) or file. This data is collected from external sources or tools that are available as analyzers inside of IntelOwl. You can query an observable/file against 100s of these analyzers and all the data is returned to you in a unified manner. Automation and ease-of-use is key here so all this is possible in just 2 HTTP calls to IntelOwl's REST API.

IntelOwl is composed of two sets of plugins - Analyzers and Connectors.

  • Analyzers:
    • Used to retrieve data from external sources (e.g. VirusTotal, AbuseIPDB) or to generate intel from internal analyzers (e.g. Yara, Oletools)
    • Li…

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@fear-the-reaper
Comment options

@mlodic
Comment options

@fear-the-reaper
Comment options

@eshaan7
Comment options

Answer selected by fear-the-reaper
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #755 on November 08, 2021 08:30.