Reversinglabs
ReversingLabs is a leading cybersecurity and threat intelligence platform that specializes in file reputation analysis, malware detection, and software security. The platform provides comprehensive threat intelligence through advanced static analysis of files, executables, binaries, and software components to identify malicious code, vulnerabilities, and security risks.
| Category | Threat intelligence |
| Direction | Query source |
| Sign-in | Username and Password |
| Query languages | STIX |
| Website | reversinglabs.com |
Before you start
Huntbase signs in to Reversinglabs with Username and Password. Create the credential in Reversinglabs first, then keep it to hand for the Connect step.
- Each lookup checks one indicator, such as an IP address, domain, URL or file hash. Queries that combine indicators with AND or OR only use the first one.
- To check your API entitlements and quota limits, contact ReversingLabs support at
[email protected].
For the vendor's own instructions, see ReversingLabs Spectra Intelligence API.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Reversinglabs
- Go to Connections and click New connection, or click New connection on the Reversinglabs product page.
- On Product, pick Reversinglabs and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Reversinglabs lives:
| Field | Required | Notes |
|---|---|---|
| Namespace | Yes | Any UUID. It's used to generate deterministic IDs for enrichment results. Defaults to 9d4bedaf-d351-4f50-930f-f8eb121e5bae. |
| Server Address | Yes | data.reversinglabs.com, the Spectra Intelligence API server. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 443. |
Advanced settings
These settings are under Advanced. You can usually leave them alone.
| Field | Required | Notes |
|---|---|---|
| Concurrent Searches | No | Number of concurrent searches to run (1-100). Defaults to 4. |
| Query Timeout (seconds) | No | Per-request timeout in seconds (1-60). Defaults to 30. |
Credentials
The only Method is Username and Password. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Username | Yes | ReversingLabs Username. Secret — not shown again after you save it. |
| Password | Yes | ReversingLabs Password. Secret — not shown again after you save it. |
Query it
Once connected, Reversinglabs can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog