• Last Updated
    Dec 9, 2025
  • Version
    1.0.0
  • Compatibility
    ThreatQ Versions >= 5.12.1
  • URLScan.io Action

    ThreatQuotient

    Overview

    The URLScan.io Action for ThreatQ enables security teams to leverage URLScan.io’s web sandboxing and analysis capabilities directly within the platform to identify phishing pages, malicious redirects, and other web-based threats. The integration enhances investigations by delivering deeper visibility into web activity and enriching indicators with actionable context. As a result, organizations can more effectively detect, assess, and respond to suspicious or malicious online behavior.

    The integration provides the following action:

    • URLScan.io - Enrich IOCs - enriches FQDNs, IPs, and URLs type indicators with context from URLScan.io.

    The integration is compatible with the following indicator types:

    • FQDN
    • IP Address
    • URL

    The integration returns the following enriched indicator types:

    • ASN
    • FQDN
    • IP Address
    • SHA-256
    • URL

    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

    Copyright © 2026, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy