Cisco Umbrella Investigate Operation
The web format of this guide reflects the most current release. Guides for older iterations are available in PDF format.
Integration Details
ThreatQuotient provides the following details for this integration:
| Current Integration Version | 3.0.0 |
| Compatible with ThreatQ Versions | >= 4.57.0 |
| Support Tier | ThreatQ Supported |
Introduction
The Cisco Umbrella Investigate Operation for ThreatQuotient enables a user to enrich indicators in ThreatQ with context from Cisco Umbrella.
The operation provides the following actions:
- Enrich - enriches a domain with contextual or historical metadata.
- Get Samples - retrieves Cisco Threat Grid samples that are related to a given domain, IP, or URL.
- Reverse WHOIS - retrieves domains related to a given email address.
- Get Associated Names - retrieves domains related to a given IP Address.
The operation is compatible with the following indicator types:
- Email Address
- FQDN
- IP Address
- URL
Prerequisites
The following is required to run the integration:
- A Cisco Umbrella API Client ID.
- A Cisco Umbrella API Client Secret.
Installation
Perform the following steps to install the integration:
The same steps can be used to upgrade the integration to a new version.
- Log into https://marketplace.threatq.com/.
- Locate and download the integration file.
- Navigate to the integrations management page on your ThreatQ instance.
- Click on the Add New Integration button.
- Upload the integration file using one of the following methods:
- Drag and drop the file into the dialog box
- Select Click to Browse to locate the integration file on your local machine
ThreatQ will inform you if the operation already exists on the platform and will require user confirmation before proceeding. ThreatQ will also inform you if the new version of the operation contains changes to the user configuration. The new user configurations will overwrite the existing ones for the operation and will require user confirmation before proceeding.
The operation is now installed and will be displayed in the ThreatQ UI. You will still need to configure and then enable the operation.
Configuration
ThreatQuotient does not issue API keys for third-party vendors. Contact the specific vendor to obtain API keys and other integration-related credentials.
To configure the integration:
- Navigate to your integrations management page in ThreatQ.
- Select the Operation option from the Type dropdown (optional).
- Click on the integration entry to open its details page.
- Enter the following parameter under the Configuration tab:
Parameter Description Client ID Enter your Cisco Umbrella API Client ID to authenticate. Client Secret Enter your Cisco Umbrella API Client Secret to authenticate. - Review any additional settings, make any changes if needed, and click on Save.
- Click on the toggle switch, located above the Additional Information section, to enable it.
Actions
The operation provides the following actions:
| Action | Description | Object Type | Object Subtype |
|---|---|---|---|
| Enrich | Enriches a domain with contextual or historical metadata. | Indicator | FQDN |
| Get Samples | Retrieves Cisco Threat Grid samples that are related to a given domain, IP, or URL. | Indicator | FQDN, IP Address, URL |
| Reverse WHOIS | Retrieves domains related to a given email address. | Indicator | Email Address |
| Get Associated Names | Retrieves domains related to a given IP Address. | Indicator | IP Address |
Enrich
The Enrich action retrieves one or more enrichment datasets for a domain from Cisco Umbrella Investigate v2.
Get Categorizations
GET https://api.umbrella.com/investigate/v2/domains/categorization/{domain}
Sample Response:
{
"facebook.com": {
"status": 1,
"security_categories": ["150"],
"content_categories": ["Social Networking"]
}
}
ThreatQ provides the following default mapping for this dataset:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.*.security_categories[] |
Indicator.Attribute |
Security Category |
N/A |
150 |
Same mapping as the previous implementation |
.*.content_categories[] |
Indicator.Attribute |
Content Category |
N/A |
Social Networking |
Same mapping as the previous implementation |
Get Risk Scores
GET https://api.umbrella.com/investigate/v2/domains/risk-score/{domain}
Sample Response:
{
"risk_score": 6,
"indicators": [
{
"indicator": "Geo Popularity Score",
"indicator_id": "Geo Popularity Score",
"normalized_score": 2,
"score": -3.6108782
}
]
}
ThreatQ provides the following default mapping for this dataset:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
risk_score |
Indicator.Attribute |
Risk Score |
N/A |
6 |
Main risk score value |
.indicators[].indicator |
Indicator.Attribute |
Scoring Indicator |
N/A |
Geo Popularity Score |
Used as the attribute name shown in the scoring breakdown table |
.indicators[].normalized_score |
Indicator.Attribute |
Normalized Score |
N/A |
2 |
Displayed in the scoring breakdown table |
.indicators[].score |
Indicator.Attribute |
Raw Score |
N/A |
-3.6108782 |
Displayed in the scoring breakdown table |
Get Security Context
GET https://api.umbrella.com/investigate/v2/security/name/{domain}
Sample Response:
{
"perplexity": 0.18786756104373362,
"entropy": 1.9182958340544896,
"dga_score": 38.301771886101335,
"securerank2": -1.3135141095601992,
"pagerank": 4.072185,
"threat_type": "",
"geodiversity_normalized": [
["BM", 0.18798495007664884]
]
}
ThreatQ provides the following default mapping for this dataset:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.dga_score |
Indicator.Attribute |
DGA Score |
N/A |
38.301771886101335 |
N/A |
.perplexity |
Indicator.Attribute |
Perplexity |
N/A |
0.18786756104373362 |
N/A |
.entropy |
Indicator.Attribute |
Entropy |
N/A |
1.9182958340544896 |
N/A |
.securerank2 |
Indicator.Attribute |
Securerank |
N/A |
-1.3135141095601992 |
N/A |
.pagerank |
Indicator.Attribute |
Page Rank |
N/A |
4.072185 |
N/A |
.asn_score |
Indicator.Attribute |
ASN Score |
N/A |
-29.75810625887133 |
N/A |
.prefix_score |
Indicator.Attribute |
Prefix Score |
N/A |
-64.9070502788884 |
N/A |
.rip_score |
Indicator.Attribute |
RIP Score |
N/A |
-75.64720536038982 |
N/A |
.popularity |
Indicator.Attribute |
Popularity |
N/A |
25.335450495507196 |
N/A |
.fastflux |
Indicator.Attribute |
Fastflux |
N/A |
false |
N/A |
.attack |
Indicator.Attribute |
Attack |
N/A |
false |
N/A |
.threat_type |
Indicator.Attribute |
Threat Type |
N/A |
benign |
Empty values are not added |
.geoscore |
Indicator.Attribute |
Geodiversity Score |
N/A |
N/A |
N/A |
.ks_test |
Indicator.Attribute |
Kolmogorov–Smirnov Geodiversity Score |
N/A |
N/A |
N/A |
.geodiversity_normalized[] |
Indicator.Attribute |
Country Code / Geodiversity Score |
N/A |
['BM', 0.18798495007664884] |
Rendered in the geodiversity breakdown table |
Get WHOIS
GET https://api.umbrella.com/investigate/v2/whois/{domain}
Sample Response:
{
"registrarName": "MarkMonitor, Inc.",
"nameServers": ["a28-64.akam.net", "a3-64.akam.net"],
"emails": ["dns-admin@google.com"],
"created": "1987-05-14",
"status": ["clientDeleteProhibited clientTransferProhibited"]
}
ThreatQ provides the following default mapping for this dataset:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.registrarName |
Indicator.Attribute |
Registrar Name |
N/A |
MarkMonitor, Inc. |
N/A |
.nameServers[] |
Related Indicator.Value |
FQDN |
N/A |
a28-64.akam.net |
Added as related indicators |
.emails[] |
Related Indicator.Value |
Email Address |
N/A |
dns-admin@google.com |
Added as related indicators |
.created |
Indicator.Attribute |
Created At |
N/A |
1987-05-14 |
N/A |
.updated |
Indicator.Attribute |
Updated At |
N/A |
2025-09-09 |
N/A |
.expires |
Indicator.Attribute |
Expires At |
N/A |
2028-05-15 |
N/A |
.whoisServers |
Indicator.Attribute |
WHOIS Server |
N/A |
whois.markmonitor.com |
N/A |
.status[] |
Indicator.Attribute |
Status |
N/A |
clientDeleteProhibited |
N/A |
Get Related Domains
GET https://api.umbrella.com/investigate/v2/links/name/{domain}
Sample Response:
{
"tb1": [
["app.hightoucherp.com.", 247]
],
"found": true
}
ThreatQ provides the following default mapping for this dataset:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.tb1[][0] |
Related Indicator.Value |
FQDN |
N/A |
app.hightoucherp.com. |
Same mapping as the previous implementation |
.tb1[][1] |
Indicator.Attribute |
Score (resolutions/minute) |
N/A |
247 |
Displayed in the related domains table |
Get Domain History
GET https://api.umbrella.com/investigate/v2/pdns/name/{domain}
Sample Response:
{
"records": [
{
"minTtl": 1,
"maxTtl": 86400,
"firstSeenISO": "2014-06-23T19:03Z",
"lastSeenISO": "2026-08-25T12:14Z",
"name": "cisco.com",
"type": "MX",
"rr": "rcdn-mx-01.cisco.com.",
"securityCategories": [],
"contentCategories": ["Software/Technology", "Computers and Internet"]
}
]
}
ThreatQ provides the following default mapping for this dataset:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.records[].rr |
Related Indicator.Value |
Indicator type depends on .records[].type |
.records[].lastSeenISO |
72.163.4.185 |
Added as a related indicator in the passive DNS history table |
.records[].type |
Indicator.Attribute |
Type |
N/A |
A, AAAA, MX, NS |
Displayed in the passive DNS history table |
.records[].minTtl |
Indicator.Attribute |
Min TTL |
N/A |
1 |
Displayed in the passive DNS history table |
.records[].maxTtl |
Indicator.Attribute |
Max TTL |
N/A |
86400 |
Displayed in the passive DNS history table |
.records[].firstSeenISO |
Indicator.Attribute |
First Seen |
N/A |
2014-06-23T19:03Z |
Displayed in the passive DNS history table |
.records[].lastSeenISO |
Indicator.Attribute |
Last Seen |
N/A |
2026-08-25T12:14Z |
Displayed in the passive DNS history table |
.records[].securityCategories[] |
Indicator.Attribute |
Security Categories |
N/A |
Malware |
Displayed in the passive DNS history table |
.records[].contentCategories[] |
Indicator.Attribute |
Content Categories |
N/A |
Software/Technology |
Displayed in the passive DNS history table |
Run Configuration Options
These configuration options are set after selecting the action to run against an object and are not set from the operation's configuration screen.
The following configuration option is provided when using the action on an object:
| Parameter | Description |
|---|---|
| Select Enrichment Options | Select one or more enrichment options (API Endpoints) to use to fetch metadata. Options include:
|
Get Samples
The Get Samples action fetches Cisco Threat Grid samples that are related to a given domain, IP, or URL.
GET https://api.umbrella.com/investigate/v2/samples/{indicator}
Sample Response:
{
"query": "example.com",
"totalResults": 1,
"moreDataAvailable": false,
"samples": [
{
"sha256": "0d477ed687d9f7424d2d28b66717bad4c0d21db8433752c9c51b032d04066af1",
"sha1": "5a299e5bcf4b947e9e3aee9925ed068dd8809f9f",
"md5": "d22dc224cc7f11bf35137ed753078d62",
"magicType": "PE32 executable (GUI) Intel 80386, for MS Windows",
"threatScore": 95,
"size": 10752,
"firstSeen": 1785802695000,
"lastSeen": 1786677026000,
"avresults": [
{
"signature": "Gen:Variant.Worm.Phorpiex.153",
"product": "ALYac"
}
]
}
]
}
ThreatQ provides the following default mapping for this operation action:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.samples[].sha256 |
Related Indicator.Value |
SHA-256 |
N/A |
0d477ed687d9f7424d2d28b66717bad4c0d21db8433752c9c51b032d04066af1 |
N/A |
.samples[].sha1 |
Related Indicator.Value |
SHA-1 |
N/A |
5a299e5bcf4b947e9e3aee9925ed068dd8809f9f |
N/A |
.samples[].md5 |
Related Indicator.Value |
MD5 |
N/A |
d22dc224cc7f11bf35137ed753078d62 |
N/A |
.samples[].magicType |
Indicator.Attribute |
File Type |
N/A |
PE32 executable (GUI) Intel 80386, for MS Windows |
N/A |
.samples[].threatScore |
Indicator.Attribute |
Threat Score |
N/A |
95 |
N/A |
.samples[].size |
Indicator.Attribute |
File Size |
N/A |
10752 |
N/A |
.samples[].firstSeen |
Indicator.Attribute |
First Seen |
N/A |
1785802695000 |
Converted from epoch milliseconds |
.samples[].lastSeen |
Indicator.Attribute |
Last Seen |
N/A |
1786677026000 |
Converted from epoch milliseconds |
.samples[].avresults[].signature |
Indicator.Attribute |
Signature Detection |
N/A |
Gen:Variant.Worm.Phorpiex.153 |
product is displayed in the table but not stored as a separate attribute |
Reverse WHOIS
The Reverse WHOIS action fetches domains related to a given email address.
GET https://api.umbrella.com/investigate/v2/whois/emails/{email}
Sample Response:
{
"admin@example.net": {
"domains": [
{
"domain": "0emm.com",
"current": true
}
],
"totalResults": 1,
"offset": 0,
"moreDataAvailable": false,
"limit": 500,
"sortField": "domain"
}
}
ThreatQ provides the following default mapping for this operation action:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.*.domains[].domain |
Related Indicator.Value |
FQDN |
N/A |
0emm.com |
Added as related indicators |
.*.domains[].current |
Indicator.Attribute |
Is Current |
N/A |
true |
Displayed in the domain history table |
Get Associated Names
The Get Associated Names action fetches domains related to a given IP Address.
GET https://api.umbrella.com/investigate/v2/pdns/ip/{ip}
Sample Response:
{
"records": [
{
"minTtl": 0,
"maxTtl": 0,
"firstSeenISO": "2022-05-11T13:07Z",
"lastSeenISO": "2022-10-25T12:27Z",
"name": "04.pong.sasci.net.",
"type": "A",
"rr": "208.67.222.222",
"securityCategories": ["Malware"],
"contentCategories": ["Software/Technology"]
}
]
}
ThreatQ provides the following default mapping for this operation action:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.records[].name |
Related Indicator.Value |
FQDN |
N/A |
04.pong.sasci.net. |
Added as related indicators in the domain resolutions table |
.records[].type |
Indicator.Attribute |
Type |
N/A |
A |
Displayed in the domain resolutions table |
.records[].minTtl |
Indicator.Attribute |
Min TTL |
N/A |
0 |
Displayed in the domain resolutions table |
.records[].maxTtl |
Indicator.Attribute |
Max TTL |
N/A |
0 |
Displayed in the domain resolutions table |
.records[].firstSeenISO |
Indicator.Attribute |
First Seen |
N/A |
2022-05-11T13:07Z |
Displayed in the domain resolutions table |
.records[].lastSeenISO |
Indicator.Attribute |
Last Seen |
N/A |
2022-10-25T12:27Z |
Displayed in the domain resolutions table |
.records[].securityCategories[] |
Indicator.Attribute |
Security Categories |
N/A |
Malware |
Displayed in the domain resolutions table |
.records[].contentCategories[] |
Indicator.Attribute |
Content Categories |
N/A |
Software/Technology |
Displayed in the domain resolutions table |
Known Issues / Limitations
- Passive DNS Metadata: Passive DNS metadata displayed in the Get Associated Names and Domain History tables is intended for display purposes only. Related indicators are added without creating ThreatQ attributes from empty or unavailable metadata values.
Change Log
- Version 3.0.0
- Migrated authentication to use Cisco Umbrella Investigate v2 client credentials.
- Updated supported API endpoints to use the Cisco Umbrella Investigate v2 base URL.
- Enhanced passive DNS processing for associated names and domain history.
- Removed the Latest Malicious Domains action as Cisco Umbrella Investigate v2 does not provide a direct replacement.
- Version 2.0.0
- Initial release
PDF Guides
| Document | ThreatQ Version |
|---|---|
| Cisco Umbrella Investigate Operation Guide v3.0.0 | 4.57.0 or Greater |
| Cisco Umbrella Investigate Operation Guide v2.0.0 | 4.57.0 or Greater |