Overview
RST Cloud Threat Intelligence API is a cloud-based threat intelligence pay-as-you-go service that you can use for various tasks. You can lookup file hashes, domains, URLs, and IPv4 addresses to check if these are malicious (RST IoC Lookup) or are "known-good" values (RST Noise Control). Also, it allows to lookup WHOIS registration data for domains (RST Whois API).
Key Features:
- Actionable Insights
Receive detailed indicators with comprehensive metadata, such as threat categories, severity levels (via scoring), related indicators, CVE, malware family names, attack tools and frameworks, threat actor information and additional contextual data. Empower your security teams to respond effectively to threats and take appropriate actions.
- Reduce False Positives
Check alerts from other systems before raising a ticket in JIRA, ServiceNow or other platforms. This is done via a query to RST Noise Control service which comes as a part of this offering. Simply lookup if a value is a known good. Avoid alerting on known DNS servers, CDN IP, well-known domains, common hashes of Windows or its components like calc.exe or notepad.exe.
- Comprehensive Threat Intelligence
Leverage our extensive threat intelligence database, continuously updated with the latest indicators of compromise (IOCs) from reputable sources, security vendors, individual threat intel researches worldwide, and research communities.
- Simple Integration
Seamlessly integrate our API into your existing security infrastructure such as TIP, SIEM, SOAR systems or other applications with minimal effort. We provide comprehensive documentation and sample code to ensure a smooth integration process.
- Cost-Effective
Pay only for the resources you consume with our flexible pricing model. Our cloud-based approach eliminates the need for on-premises infrastructure, reducing your operational costs and enabling you to focus on core security tasks.
- Fast and Accurate Results
Obtain real-time threat intelligence with lightning-fast response times. Our advanced algorithms and infrastructure enable rapid identification, attribution, and categorisation of known threats, empowering you to make informed security decisions.
- Multiple Query Options
Query our API using various indicators, including malware file hashes, domains, URLs, and IPv4 addresses. Gain a holistic view of potential threats associated with specific IOCs and take proactive measures to mitigate risks.
- Scalable and Reliable
Built on the robust AWS infrastructure, our service offers high scalability, availability, and reliability. Handle peak loads effortlessly, ensuring uninterrupted threat intelligence services for your organisation.
- Secure and Private
We prioritise data privacy and security. Your queries and sensitive information are handled with the utmost confidentiality and protected through industry-standard security practices and protocols.
Highlights
- Quickly identify known threats via direct access to the latest threat intelligence, query using suspect malware file hashes, domains, URLs, IPv4 addresses
- Ensure that false positive alerts do not create tickets in your case management systems by checking if they are driven by known-good IP, URLs, domains, or hashes.
- Verify WHOIS registration for domains to fight with potential phishing scenarios.
Details
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/request |
---|---|
RST Cloud Lookup Request | $0.002 |
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.