Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Observable Enrichment

The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.

Note: The Threat Intelligence Security Center supports Observable Enrichment only for the WHOIS Integration.

  • Run Have I Been Pwned enrichment integration
    Run the Have I Been Pwned (HIBP) enrichment on an email address or domain name observable to determine whether it has been involved in a known data breach.
  • Whois integration
    Submit Whois lookups on domain names and URLs to gather threat intelligence and assess potential security risks. Use this integration to obtain registration details, ownership information, and other contextual data for suspicious domains.
  • Shodan integration
    Configure Shodan integration to enable automated discovery and analysis of internet-connected devices in your network infrastructure.

Parent Topic:Run Enrichment operations in TISC