urlscan io.md
For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.
Urlscan.io
urlscan.io is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
The Dropzone AI Platform integrates with urlscan.io, a URL scanning tool. urlscan browses URLs like a regular user and records the activity that this page navigation creates such as domains and IPs contacted, resources (JavaScript, CSS, etc) requested from those domains, etc.
Create an API Key
urlscan.io requires an API key to enable.
To obtain an API Key, do the following:
- Create a free account here, if you do not have one already
- In the banner on the left hand side of the urlscan.io homepage, navigate to Settings & API
Navigate to Settings & API
- Click "Create API Key"
Create API Key
- Under "Description", write something memorable, such as "Dropzone AI Integration"
Create API Key
- Click "Create API Key"
- Copy the API Key shown for use later in the Dropzone UI where it will be called API Key
Create API Key
Enable urlscan.io
To enable the Data Source integration, do the following:
- Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
- In the bottom left hand corner, click Settings > Integrations
Integrations Dropdown
- Click "Available"
Click Available
- In the Search bar, search urlscan.io, then click "Configure"
The urlscan.io Data Tile
- Input the API key
- Under "Visibility", select "Unlisted" or "Private"
- View urlscan's FAQ for more information about the options
The urlscan.io Data Source Configuration
- Click "Test & Save" to finish
If you have any errors engage your Dropzone AI support representative.