Skip to content

new: [expansion] OTI Labs Domain Intelligence module - #913

Merged
adulau merged 1 commit into
MISP:mainfrom
OsirisTechnicalInstitute:otilabs-expansion
Oct 6, 2026
Merged

adulau merged 1 commit into
MISP:mainfrom
OsirisTechnicalInstitute:otilabs-expansion

Conversation

@OsirisTechnicalInstitute

Copy link
Copy Markdown
Contributor

Adds otilabs, an expansion and hover module for the OTI Labs Domain Intelligence API. Disclosure: I run this API.

Input: domain or hostname. Config: apikey (a RapidAPI key subscribed to the API; the free plan is 1,000 requests a month) and an optional subdomain_limit (default 50).

One request to /lookup/{domain} is mapped to:

  • a whois object: registrar, creation/modification/expiration dates and nameservers (RDAP first, with a port-43 WHOIS fallback for TLDs RDAP doesn't cover). Free-text dates that some ccTLD registries return are skipped rather than stored in a datetime field.
  • an x509 object for the certificate the domain serves: issuer, subject, serial number, signature algorithm, validity dates and SANs (wildcards skipped, capped at 50).
  • a dns-record object: MX, NS, SOA and TXT records, with CAA as text.
  • a domain-ip object for the domain: its A/AAAA addresses plus the SPF, DMARC and DKIM results as text attributes with correlation disabled, the same way email_security_check reports them.
  • one domain-ip object per live subdomain (hostname plus its current IP, or its CNAME target as text), up to subdomain_limit, and a text attribute summarising how many subdomains were found and how many resolve now.

A section the API couldn't fetch (for example a WHOIS timeout) is skipped and the rest is still returned. Rejected keys (401/403), quota errors (429), network errors and responses with no usable data return an error message.

Tests: tests/test_otilabs.py (13 tests) mocks requests.get with a trimmed copy of a real /lookup response for stripe.com, so it runs offline without a key. I also ran the handler against full live responses for stripe.com and bbc.co.uk. black --check (project settings), isort --check-only and flake8 pass.

I haven't touched the generated documentation; moduleinfo is filled in, so it should come through the usual docs generation.

AI use disclosure

Written collaboratively with Claude (Anthropic, Claude Opus 5.5), modelled on the existing whoisfreaks, lamis_network and email_security_check modules, then reviewed and tested before submitting.

Enriches a domain or hostname with WHOIS/RDAP, DNS, the TLS certificate, live subdomains and SPF/DMARC/DKIM from the OTI Labs Domain Intelligence API.
@adulau
adulau merged commit a58d092 into MISP:main Oct 6, 2026
2 of 7 checks passed
@adulau

adulau commented Oct 6, 2026

Copy link
Copy Markdown
Member

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants