Skip to main content

md-insights-client-api

API client for MetaDefender InSights threat intelligence feeds.

Installation

The app has been tested on Python 3.

It's best to install the program into a Python virtual environment. The recommended way to install it is using pipx:

pipx install md-insights-client

It can also be installed using pip into a target virtualenv.

/path/to/environment/bin/python3 -m pip install md-insights-client

Configuration

A configuration file must be populated with an API key. If only querying the API to perform lookups, this configuration setting is all that is required. If retrieving snapshots, a list of feed names to retrieve must also be specified.

A sample configuration file can be copied from config/dot.md-insights.yml and installed at $HOME/.md-insights.yml. Update the configuration file to make the following changes:

  1. Set your API key.
  2. Uncomment feed names for the MetaDefender InSights feeds you will access (if applicable).

Don't forget to set a restrictive mode on the file:

chmod 0600 ~/.md-insights.yml

Usage

When installed, two commands are available.

md-insights-query-client

The md-insights-query-client command can be used to query the MD InSights API to look up artifacts against one or more threat intelligence collections.

See -h/--help output for help.

To use this command, provide multiple positional arguments to the script.

  • The first argument is the query type, such as c2-dns, c2-ip, reputation or all. The special all type autodetects the artifact format(s) to query all relevant collections.
  • The second and subsequent arguments are the artifacts for which to query. One or more artifacts such as IP addresses or domain names may be specified.

For example:

md-insights-query-client all appleprocesshub.com apimonger.com

By default, response data is output in tabular format, one indicator per row that is found in MD InSights collections. If you prefer to see the raw JSON response format from the API, use the -j/--json option.

md-insights-snapshot-client

The md-insights-snapshot-client command can be used to download feed snapshots. To retrieve feed snapshots, your API key must be provisioned with access to the selected feeds.

See -h/--help output for help.

When the command is called, the client script downloads feed snapshots from the API service. As the compressed snapshots are downloaded, they are decompressed and the feeds are written to disk.

Documentation

For information about MetaDefender InSights threat intelligence feeds, see the documentation site:

https://www.opswat.com/docs/mdinsights

Metadata

Release files for md-insights-client 0.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for md-insights-client 0.3.1
File Size Uploaded
md_insights_client-0.3.1.tar.gz 9.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for md-insights-client 0.3.1
File Interpreter ABI Platform
md_insights_client-0.3.1-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 20.4 kB

Release files / md_insights_client-0.3.1.tar.gz

Download URL md_insights_client-0.3.1.tar.gz
Size 9.8 kB
Tags Source
SHA-256 checksum
How to use checksums
3de0721af5fd6b1de5510a152bc1d81a0dee5a8ccd4892ab54dcd42e3334a132
BLAKE2b-256 checksum
How to use checksums
756857dd7b40a9192dc112585c5dfba2a168bb95ddc66b0fa7efc193fe1c5213
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release files / md_insights_client-0.3.1-py2.py3-none-any.whl

Download URL md_insights_client-0.3.1-py2.py3-none-any.whl
Size 10.6 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
59449bec65d8a2e15b9b61ec3f065e667b5b423b89c2d671e8d25310411746fd
BLAKE2b-256 checksum
How to use checksums
d62f5ee7a195edcbba92207ab9be80beacd4a039d1572770927744ac91c5b9c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.3.1 This release

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page