
Jun 3, 2025
1.0.2
ThreatQ Versions >= 5.14.1
abuse.ch ThreatFox Action
Overview
The action can perform the following function:
- abuse.ch ThreatFox - enriches supported objects with attributes and related objects describing the IOC.
The action is compatible with the following indicator types:
- MD5
- SHA-1
- SHA-256
- FQDN
- IP
- URL
- SHA-256
- SHA-1
- MD5
- Email Address
The action returns the following enriched system objects:
- Indicators
- Malware
Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.