Skip to main content

RiskIQ PassiveTotal Python Library

Build Status

build status doc status pypi downloads pypi version license

Introduction

This Python library provides an interface to the RiskIQ PassiveTotal Internet intelligence database and the RiskIQ Illuminate Reputation Score.

Security researchers and network defenders use RiskIQ PassiveTotal to map threat actor infrastructure, profile hostnames & IP addresses, discover web technologies on Internet hosts.

Capabilites of this library include:

  • Credential management - protect API keys from accidental disclosure
  • Object analyzer - analyze hosts without knowing which API endpoints to use
  • CLI for quick queries and package configuration
  • Low-level wrappers for all PassiveTotal API endpoints

To learn more about RiskIQ and start a free trial, visit https://community.riskiq.com

Getting Started

Install the PassiveTotal Library

The PassiveTotal Python library is available in pip under the package name passivetotal. Consider setting up a virtual environment, then run:

pip install passivetotal

Obtain API Keys

Queries to the API must be authenticated with a PassiveTotal API key.

  1. Log in (or sign up) at community.riskiq.com
  2. Access your profile by clicking the person icon in the upper-right corner of the page.
  3. Click on "Account Settings"
  4. Under "API Access", click "Show" to reveal your API credentials.

The identifier for your API account is alternatively called a "username", a "user", or an "API key". Look for an email address and use that value when prompted for your "API username".

The "API Secret" is a long string of characters that should be kept secure. It is the primary authentication method for your API account.

Your PassiveTotal account may have a separate "API Secret" for your organization - when available, always use your organization key unless you have a specific reason not to.

Build a Config File

The optimal way to store your API credentials is inside a config file managed by this library's command line tools.

The library references the config file by default when creating new API connections, setting up the analyzer module, or running command line tools.

Run the command setup command with your username to get started:

pt-config setup user@example.com

Enter the API secret key when prompted, then press enter. The complete configuration will then print out so you can confirm the values.

To see other configuration options, including options for an HTTP proxy, enter:

pt-config setup -h

Choose an Interface

This library enables interaction with the PassiveTotal API through several distinct interfaces. Choose the one that best fits your use case.

If you're not sure where to start, use the Object Analyzer.

Object Analyzer

>>> from passivetotal import analyzer
>>> analyzer.init()
>>> age = analyzer.Hostname('riskiq.com').whois.age
>>> print('Domain is {} days old'.format(age))
Domain is 5548 days old
>>> analyzer.set_date_range(days_back=30)
>>> pdns = analyzer.Hostname('api.passivetotal.org').ip.resolutions
>>> for record in pdns.sorted_by('lastseen'):
        print(record)
A "staging-api.passivetotal.org" [ 465 days] (2019-12-11 to 2021-03-21)
A "api.passivetotal.org" [ 459 days] (2019-12-18 to 2021-03-22)

Benefits

  • Ideal starting point for new scripts and product integrations.
  • Works well in interactive Python environments such as Jupyter.
  • Does not require familiarity with specific API endpoints.
  • Stores results within object instances to faciliate declarative interactions and offer an intuitive syntax.

Caveats

  • May not have complete coverage for every API endpoint.
  • Opinionated: default values are optimized for efficient queries and common investigative pathways.
  • API queries run automatically when properties are first accessed, which may result in excessive API query usage.

Command Line

Access the CLI with the pt-client command. Run the command without options to see a list of available commands.

Most CLI commands only output JSON; if you need more robust output options, consider writing a script with the analyzer module.

Request Wrappers

Use these low-level interfaces when you know exactly which API endpoints you need to query and what parameters they require. These are still preferred over making API requests directly with requests or urllib because they benefit from the credential management and config file mechanism described above.

Wrappers should exist for every PassiveTotal API endpoint, but availability may lag behind when new features are implemented. If you cannot locate a wrapper for your preferred endpoint, use an instance of the passivetotal.GenericRequest class.

Additional Resources

Library docs: https://passivetotal.readthedocs.io/

RiskIQ Product Support: https://info.riskiq.net/

Metadata

Release files for passivetotal 2.5.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for passivetotal 2.5.9
File Size Uploaded
passivetotal-2.5.9.tar.gz 129.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for passivetotal 2.5.9
File Interpreter ABI Platform
passivetotal-2.5.9-py3-none-any.whl Python 3 none any Details

Total release size: 243.9 kB

Release files / passivetotal-2.5.9.tar.gz

Download URL passivetotal-2.5.9.tar.gz
Size 129.8 kB
Tags Source
SHA-256 checksum
How to use checksums
f5f1b7843257bc1ed5ae951c48902eb809a4a632947a57d6f8ad199428b13251
BLAKE2b-256 checksum
How to use checksums
96d1c38b3b94a4ea1d0339848296095c13dab10857aebc88d201278123efbc4c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.3.0 pkginfo/1.7.0 requests/2.25.1 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.59.0 CPython/3.7.3

Release files / passivetotal-2.5.9-py3-none-any.whl

Download URL passivetotal-2.5.9-py3-none-any.whl
Size 114.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
070c408181bf294f1cf4d49bd7184a00c9419b2bac7a3405f247f786db45ed8f
BLAKE2b-256 checksum
How to use checksums
3fde8ef45c1231ae3ee2c39546432117e74bd36a9ef4e960d6b07592fded16ee
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.3.0 pkginfo/1.7.0 requests/2.25.1 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.59.0 CPython/3.7.3

Release history Release notifications | RSS feed

This release

2.5.9 This release

2 release files

2.5.8

2 release files

2.5.7

2 release files

2.5.6

2 release files

2.5.5

2 release files

2.5.4

2 release files

2.5.3

2 release files

2.5.2

2 release files

2.5.1

2 release files

2.5.0

2 release files

2.4.2

2 release files

2.4.1

2 release files

2.4.0

2 release files

2.3.0

2 release files

2.2.0

2 release files

2.1.0

2 release files

1.0.31

3 release files

1.0.30

1 release file

1.0.29

1 release file

1.0.28

1 release file

1.0.27

1 release file

1.0.26

1 release file

1.0.25

1 release file

1.0.23

1 release file

1.0.22

1 release file

1.0.21

1 release file

1.0.20

1 release file

1.0.19

1 release file

1.0.18

1 release file

1.0.17

1 release file

1.0.16

1 release file

1.0.15

1 release file

1.0.14

1 release file

1.0.13

1 release file

1.0.12

1 release file

1.0.11

1 release file

1.0.10

1 release file

1.0.9

1 release file

1.0.8

1 release file

1.0.7

1 release file

1.0.6

1 release file

1.0.5

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page