Skip to main content

Reversinglabs

ReversingLabs is a leading cybersecurity and threat intelligence platform that specializes in file reputation analysis, malware detection, and software security. The platform provides comprehensive threat intelligence through advanced static analysis of files, executables, binaries, and software components to identify malicious code, vulnerabilities, and security risks.

CategoryThreat intelligence
DirectionQuery source
Sign-inUsername and Password
Query languagesSTIX
Websitereversinglabs.com

Before you start​

Huntbase signs in to Reversinglabs with Username and Password. Create the credential in Reversinglabs first, then keep it to hand for the Connect step.

Watch out for
  • Each lookup checks one indicator, such as an IP address, domain, URL or file hash. Queries that combine indicators with AND or OR only use the first one.
  • To check your API entitlements and quota limits, contact ReversingLabs support at [email protected].

For the vendor's own instructions, see ReversingLabs Spectra Intelligence API.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Reversinglabs​

  1. Go to Connections and click New connection, or click New connection on the Reversinglabs product page.
  2. On Product, pick Reversinglabs and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Reversinglabs lives:

FieldRequiredNotes
NamespaceYesAny UUID. It's used to generate deterministic IDs for enrichment results. Defaults to 9d4bedaf-d351-4f50-930f-f8eb121e5bae.
Server AddressYesdata.reversinglabs.com, the Spectra Intelligence API server.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.

Advanced settings​

These settings are under Advanced. You can usually leave them alone.

FieldRequiredNotes
Concurrent SearchesNoNumber of concurrent searches to run (1-100). Defaults to 4.
Query Timeout (seconds)NoPer-request timeout in seconds (1-60). Defaults to 30.

Credentials​

The only Method is Username and Password. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
UsernameYesReversingLabs Username. Secret — not shown again after you save it.
PasswordYesReversingLabs Password. Secret — not shown again after you save it.

Query it​

Once connected, Reversinglabs can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​