Providers

AlienVault OTX

The URL list of the Open Threat Exchange. No key. Paged JSON up to 20 pages. Rate limits under parallel use.
IDalienvault01 / 7otx.alienvault.com
Source

AlienVault OTX

  • provider: "alienvault"
  • otx.alienvault.com

Threat intel URL lists. Keyless, but the public endpoint gets grumpy under load.

Format
JSON pages
Paging
page by page, at most 20
Dates
none, from and to skip nothing
Key
none

Access

Loadawait create("alienvault")
CLIurls discover example.com -p alienvault
Keynothing, no key and no account
Endpointhttps://otx.alienvault.com/api/v1/indicators/domain/{domain}/url_list

What it knows

Keyless and generous, right up until it isn't. OTX collects indicators its community shares. For a domain it keeps a list of URLs seen with it, often the odd ones: webhook endpoints, redirect targets, paths somebody flagged. No dates come back, so firstSeen stays empty.

How it asks

GET /api/v1/indicators/domain/{domain}/url_list?page=N, page after page while has_next is true. It stops after 20 pages even when OTX still says there's more, and then the agent tools report the page as truncated.

Traps

  • It's the default pick when no key is configured. Expect RateLimitError when you hit it in parallel, and the automatic pick moves on to the next source when that happens.
  • The public endpoint can be slow. A timeout isn't an access failure, so the automatic pick throws it instead of moving on. Name another source or use provider: "all".