Infoblox
Infoblox is a network infrastructure and DNS security platform that provides comprehensive DNS (Domain Name System), DHCP (Dynamic Host Configuration Protocol), and IPAM (IP Address Management) services, collectively known as DDI. The platform serves as a critical network control point for managing IP addresses, DNS records, and network identity across enterprise environments.
| Category | Threat intelligence, Network security |
| Direction | Query source |
| Sign-in | API Key |
| Query languages | STIX |
| Website | infoblox.com |
Before you start
Huntbase signs in to Infoblox with API Key. Create the credential in Infoblox first, then keep it to hand for the Connect step.
- In the Infoblox Portal, click your user name at the top right and select Profile › User API Keys.
- Click Create, enter a name that identifies the purpose of the key, and select an expiry date.
- Click Save & Close, then click Copy in the confirmation dialog. The key is shown only once.
- Infoblox notifies you daily from 14 days before the key expires. Replace the key in Huntbase before it expires, or queries stop working.
- You can also create service account users and API keys that belong to them, so the connection does not depend on one person.
For the vendor's own instructions, see Infoblox user API key documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Infoblox
- Go to Connections and click New connection, or click New connection on the Infoblox product page.
- On Product, pick Infoblox and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Infoblox lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The Infoblox Portal API host, csp.infoblox.com. For a non-US realm use the regional host, such as csp.eu.infoblox.com. |
| Port | Yes | 443. Defaults to 443. |
| Certificate (PEM) | No | |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is API Key. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| API Token | Yes | The user API key itself. Do not add a Token prefix. Secret — not shown again after you save it. |
Query it
Once connected, Infoblox can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog