API Configuration

Set enrichment API keys here — no need to edit config.php. Menu keys take priority over config constants. Leave a field blank to keep its current value; keys are shown masked. Get free keys from the linked signup pages.

Enrichment API Keys

ProviderStatusKeyFree TierGet Key
VirusTotal
Files, URLs, domains, IPs
NONE 4 req/min free ↗ signup
AbuseIPDB
IP reputation
NONE 1000/day free ↗ signup
Shodan
Exposed services
NONE 100/mo free ↗ signup
GreyNoise
Scanner classification
NONE Community free ↗ signup
IPInfo
Geo / ASN / org
NONE 50k/mo free ↗ signup
WhoisXML
WHOIS / DNS
NONE Free tier ↗ signup
AlienVault OTX
Threat pulses
NONE Unlimited ↗ signup
URLScan
URL scanning
NONE Public search keyless ↗ signup
abuse.ch Auth-Key
URLhaus / ThreatFox / MalwareBazaar
NONE Free — one key ↗ signup
Pulsedive
IoC risk & threats
NONE Free tier ↗ signup
Team Cymru Scout
IP dossiers: PDNS, ports, x509, JA3/JARM, comms
NONE Paid / trial ↗ signup

Rate Limits & Throttling

Enrichment respects these — it sleeps between calls and stops at the daily cap so you never exceed provider limits.

Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php