Searching for Defanged Observable Values
The ThreatStream observables search supports defanged domain, email address, IP address, and URL observable queries. When you enter a defanged value, ThreatStream queries and returns non-defanged observable values.
The following types of defanged values are supported for both basic and advanced searches:
-
[.]or [:]Examples:
-
analyst@security[.]comreturnsanalyst@security.com https[:]//test[.]comreturnshttps://test.com1[.]1[.]1[.]1returns1.1.1.1
-
-
{.}Examples:
1{.}1{.}1{.}1returns1.1.1.1https{:}//test{.}comreturnshttps://test.com
-
hxxp://Examples:
hxxp://test.comreturnshttp://test.comhxxp[:]//test[.]comreturnshttp://test.com
-
hxxps://Examples:
hxxps://test.comreturnshttps://test.comhxxps{:}//test{.}comreturnshttps://test.com
-
meow://Example:
meow://test.comreturnshttp://test.com -
meows://Example:
meows://test.comreturnshttps://test.com
The following is supported for basic search only:
(.)
Example: test(.)com returns test.com.