Providers
AlienVault OTX
The URL list of the Open Threat Exchange. No key. Paged JSON up to 20 pages. Rate limits under parallel use.
Source
AlienVault OTX
- provider: "alienvault"
- otx.alienvault.com
Threat intel URL lists. Keyless, but the public endpoint gets grumpy under load.
- Format
- JSON pages
- Paging
- page by page, at most 20
- Dates
- none, from and to skip nothing
- Key
- none
Access
- Load
await create("alienvault") - CLI
urls discover example.com -p alienvault - Key
nothing, no key and no account - Endpoint
https://otx.alienvault.com/api/v1/indicators/domain/{domain}/url_list
What it knows
Keyless and generous, right up until it isn't. OTX collects indicators its community shares. For a domain it keeps a list of URLs seen with it, often the odd ones: webhook endpoints, redirect targets, paths somebody flagged. No dates come back, so firstSeen stays empty.
How it asks
GET /api/v1/indicators/domain/{domain}/url_list?page=N, page after page while has_next is true. It stops after 20 pages even when OTX still says there's more, and then the agent tools report the page as truncated.
Traps
- It's the default pick when no key is configured. Expect
RateLimitErrorwhen you hit it in parallel, and the automatic pick moves on to the next source when that happens. - The public endpoint can be slow. A timeout isn't an access failure, so the automatic pick throws it instead of moving on. Name another source or use
provider: "all".