ZaunDocs

Threat Intelligence

Integration setup guides for threat intelligence and vulnerability management platforms.

Connect your threat intelligence feeds and vulnerability scanners to Zaun for IOC enrichment, attack surface monitoring, and vulnerability tracking.

AlienVault OTX

Category: Open Threat Exchange | Auth: API Key (Free)

Required Credentials

FieldDescription
API KeyFrom OTX account settings

Auth: X-OTX-API-KEY: <key>. Rate: 10,000 req/hr. Free tier.

Capabilities

FeatureDescription
Pulse SubscriptionsList threat pulses you're subscribed to, with modified_since filtering
IOC LookupsQuery indicators by type: IPv4, IPv6, domain, hostname, file hash, URL, CVE
Pulse SearchSearch and retrieve pulse details, indicators, and related pulses

Setup Steps

  1. Create a free account at otx.alienvault.com.
  2. Subscribe to relevant threat pulses for your industry/region.
  3. Username > Settings > copy API Key. Paste into Zaun.

Shodan

Category: Internet Intelligence & Attack Surface | Auth: API Key

Required Credentials

FieldDescription
API KeyFrom Shodan account

Capabilities

FeatureDescription
Host SearchSearch internet-facing hosts with Shodan query syntax, facets, and filters
DNSResolve hostnames, reverse lookups, domain information
ScanningList scans, check auto-targets, view scan results
AlertsMonitor network alerts, triggers, and notifiers
Bulk DataAccess bulk datasets and open port listings

Small Business plan ($359/mo) recommended for MDR use (vuln filter requires paid plan).

Setup Steps

  1. Create account at account.shodan.io, select a plan (Small Business recommended).
  2. Account > Profile Overview > copy API key. Paste into Zaun.

Free tier allows basic host lookups. Paid plans unlock vulnerability data, network monitoring, and higher rate limits.


Tenable

Category: Vulnerability Management | Auth: API Key

Required Credentials

FieldDescription
Access KeyFirst part of API key pair
Secret KeySecond part (shown once at generation)

Auth: X-ApiKeys: accessKey=...;secretKey=...

Capabilities

FeatureDescription
Asset InventoryList and query assets, attributes, and asset imports
VulnerabilitiesExport and query vulnerability findings with plugin details
ScansView scan progress, history, and plugin output
ComplianceExport compliance status and audit results
ReportsGenerate and download vulnerability reports

Setup Steps

  1. In cloud.tenable.com > user icon > My Account > API Keys.
  2. Click Generate. Copy both Access Key and Secret Key immediately (Secret Key is only shown once).
  3. Paste both keys into Zaun.

Zaun connects to over 125 Tenable API endpoints covering assets, vulnerabilities, scans, compliance, and reporting.


VirusTotal

Category: Threat Intelligence & Malware Analysis | Auth: API Key

Required Credentials

FieldDescription
API KeyFrom VirusTotal account

Capabilities

FeatureDescription
URL AnalysisSubmit URLs for scanning and retrieve analysis results
File AnalysisUpload files, retrieve reports, and request rescans
IP & DomainAnalyze IP addresses and domains for reputation data
SearchGeneral search across all indicator types

Rate Limits

TierLimit
Free4 req/min, 500 req/day
PremiumPer contract (typically 1,000+ req/min)

Auth: x-apikey: <key>. Submissions are form-encoded; lookups return JSON.

Setup Steps

  1. Create an account at virustotal.com.
  2. Profile > API key page. Copy the key.
  3. Paste into Zaun.

Free tier is heavily rate-limited. For production MDR use, a Premium or Enterprise plan is recommended.