PassiveTotal Response Integration via API

Purpose

This guide explains how to configure the PassiveTotal (RiskIQ) Response integration in Logsign USO, so that an analyst (or an action rule) can pull general, malware-related, and OSINT enrichment data, plus WHOIS lookups, for a domain or IP directly from a Logsign Incident. This is a read-only threat-intelligence lookup integration; it does not block or change state anywhere.

Prerequisites

  • A PassiveTotal (RiskIQ / Microsoft Defender Threat Intelligence) account with API access, and an API key.

Step 1: Obtain Your PassiveTotal Credentials

  1. Log in to your PassiveTotal account.
  2. Open your account/API settings page and note your account Username and generate/copy your API Key.

Step 2: Configure the Integration in Logsign USO

In Logsign USO, go to Settings > Integrations > Responses, search for PassiveTotal, click Configure then +Device, and fill in:

FieldRequiredDescription
Device NameYesFree-text label identifying this PassiveTotal device in Logsign.
UsernameYesYour PassiveTotal account username/email.
KeyYesYour PassiveTotal API key from Step 1. Stored encrypted at rest.

Click Create to save the device.

Available Methods

  • enrichment_data — general enrichment data for a domain/IP. Arg: query (required).
  • enrichment_malware — malware-related enrichment for a domain/IP. Arg: query (required).
  • enrichment_osint — OSINT-sourced enrichment for a domain/IP. Arg: query (required).
  • whois — WHOIS lookup. Args: query, field (both required).

Troubleshooting

SymptomLikely causeWhat to check
401 UnauthorizedWrong Username or Key.Re-enter both fields exactly as shown in your PassiveTotal account settings.
429 Too Many RequestsPassiveTotal enforces API rate/quota limits per subscription tier.Reduce the frequency of automated lookups, or check your plan's quota.

Notes and Limits

  • This integration is read-only threat intelligence; it never blocks or changes state anywhere.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.