observables

AQL Search supports the out-of-the box observables lookup table that contains ThreatStream observable data from the last 30 days.

To view or search for these ThreatStream observables, enter the following lookup table name into the AQL Search box: observables.

You can also access the observables table on the Lookup Tables page. See Using Lookup Tables for more information.

Observable data is refreshed once daily.

Field Value Type Description Example
asn number The Autonomous System Number for the IP associated with the observable. 37,963
confidence number Indicates the ThreatStream-Assigned confidence of an observable being malicious. See Observable Confidence in ThreatStream for more information. 75
country string Two-letter ISO country code for the IP associated with the observable.
  • US

  • CN

  • DE

created_by string Email address of the user who submitted the import job containing the observable.  
created_ts date UTC time stamp of when the observable was first created in ThreatStream.  
expiration_ts date Time stamp of when intelligence will expire on ThreatStream, in UTC format. 2017-01-26T00:00:00.
extended_source      
feed_id numeric ID of the threat feed that created the observable on ThreatStream.  
id   Unique ID of a registered link. 17
ip string IP associated with the observable. 52.233.72.222
is_public   Specific nation or geographical region to which data, materials, or information is being directed or delivered. us
import_session_id numeric ID of the import session that created the observable on ThreatStream API.  
import_source string Original source of the observable. Values are only displayed for observables manually imported through the ThreatStream API user interface by your organization. Import source for observables owned by other organizations is not visible.  
ioc_type string Type of the observable.
  • ip

  • domain

  • email

  • string

  • md5

  • ipv6

  • url

  • phone_num

ioc_type_v2 string Unified hash label for all hash-based observables. hash
ip_network_start      
ip_network_end      
itype string ThreatStream indicator type.
  • c2_ip

  • compromised_email

  • apt_md5

  • mal_md5

itype_v2 string Unified hash label for ThreatStream indicator types. mal_hash
latitude numeric Latitude associated with the Geo location of the IP. 12.975
longitude numeric Longitude associated with the Geo location of the IP.
  • -80.193

  • 77.591

meta      
modified_ts date UTC time stamp of when the observable was last updated in ThreatStream. 2014-10-02T20:44:35.
org string ThreatStream organization that owns the observable. T-Mobile USA
owner_organization_id numeric ID of the organization owner. 2
rdns string Domain name (obtained through reverse domain name lookup) associated with the IP address that is associated with the observable.  
retina_confidence numeric

Confidence score calculated using ThreatStream’s machine learning-based scoring engine. This score is only calculated for IP-, domain-, and URL-based observables.

When reetina score is –1, it implies that a valid score could not be calculated or the source reported confidence was exclusively used.

67
source_created date Time stamp of when the entity was created by its original source.  
source_modified date Time stamp of when the entity was last updated by its original source.  
source_reported_confidence numeric Indicates the source reported confidence of an observable being malicious. See Observable Confidence in ThreatStream for more information. 82
status string Current state of the observable in ThreatStream.
  • active

  • inactive

  • falsepos

subtype string For hash observables—those with type=md5—subtype provides additional metadata on the type of hash associated with the observable.
  • md5

  • sha1

  • sha256

  • sha512

tags string Additional comments and context associated with the observable when it was imported from its original threat feed.  
threat_type string Summarized threat type of the observable.
  • malware

  • compromised

  • apt

  • c2

trusted_circle_ids numeric ID of the trusted circle with which the observable is shared.  
type string Data type of the observable.
  • ip

  • domain

  • email

  • md5

  • url

updated_id   Event message available when the "store raw logs" option has been configured. 1.0 2017-12-13T08:16:02.130Z Z123412341234 example.com A NOERROR UDP Region 192.168.1.1 -