observables
AQL Search supports the out-of-the box observables lookup table that contains ThreatStream observable data from the last 30 days.
To view or search for these ThreatStream observables, enter the following lookup table name into the AQL Search box: observables.
You can also access the observables table on the Lookup Tables page. See Using Lookup Tables for more information.
Observable data is refreshed once daily.
| Field | Value Type | Description | Example |
|---|---|---|---|
| asn | number | The Autonomous System Number for the IP associated with the observable. | 37,963 |
| confidence | number | Indicates the ThreatStream-Assigned confidence of an observable being malicious. See Observable Confidence in ThreatStream for more information. | 75 |
| country | string | Two-letter ISO country code for the IP associated with the observable. |
|
| created_by | string | Email address of the user who submitted the import job containing the observable. | |
| created_ts | date | UTC time stamp of when the observable was first created in ThreatStream. | |
| expiration_ts | date | Time stamp of when intelligence will expire on ThreatStream, in UTC format. | 2017-01-26T00:00:00. |
| extended_source | |||
| feed_id | numeric | ID of the threat feed that created the observable on ThreatStream. | |
| id | Unique ID of a registered link. | 17 | |
| ip | string | IP associated with the observable. | 52.233.72.222 |
| is_public | Specific nation or geographical region to which data, materials, or information is being directed or delivered. | us | |
| import_session_id | numeric | ID of the import session that created the observable on ThreatStream API. | |
| import_source | string | Original source of the observable. Values are only displayed for observables manually imported through the ThreatStream API user interface by your organization. Import source for observables owned by other organizations is not visible. | |
| ioc_type | string | Type of the observable. |
|
| ioc_type_v2 | string | Unified hash label for all hash-based observables. | hash |
| ip_network_start | |||
| ip_network_end | |||
| itype | string | ThreatStream indicator type. |
|
| itype_v2 | string | Unified hash label for ThreatStream indicator types. | mal_hash |
| latitude | numeric | Latitude associated with the Geo location of the IP. | 12.975 |
| longitude | numeric | Longitude associated with the Geo location of the IP. |
|
| meta | |||
| modified_ts | date | UTC time stamp of when the observable was last updated in ThreatStream. | 2014-10-02T20:44:35. |
| org | string | ThreatStream organization that owns the observable. | T-Mobile USA |
| owner_organization_id | numeric | ID of the organization owner. | 2 |
| rdns | string | Domain name (obtained through reverse domain name lookup) associated with the IP address that is associated with the observable. | |
| retina_confidence | numeric |
Confidence score calculated using ThreatStream’s machine learning-based scoring engine. This score is only calculated for IP-, domain-, and URL-based observables. When reetina score is –1, it implies that a valid score could not be calculated or the source reported confidence was exclusively used. |
67 |
| source_created | date | Time stamp of when the entity was created by its original source. | |
| source_modified | date | Time stamp of when the entity was last updated by its original source. | |
| source_reported_confidence | numeric | Indicates the source reported confidence of an observable being malicious. See Observable Confidence in ThreatStream for more information. | 82 |
| status | string | Current state of the observable in ThreatStream. |
|
| subtype | string | For hash observables—those with type=md5—subtype provides additional metadata on the type of hash associated with the observable. |
|
| tags | string | Additional comments and context associated with the observable when it was imported from its original threat feed. | |
| threat_type | string | Summarized threat type of the observable. |
|
| trusted_circle_ids | numeric | ID of the trusted circle with which the observable is shared. | |
| type | string | Data type of the observable. |
|
| updated_id | Event message available when the "store raw logs" option has been configured. | 1.0 2017-12-13T08:16:02.130Z Z123412341234 example.com A NOERROR UDP Region 192.168.1.1 - |
