Supported observables for RISKIQ and RISKIQ WHOISIQ

  • リリースバージョン: Australia
  • 更新日 2026年03月12日
  • 所要時間:4分
  • The RISKIQ API supports automatic SSL certificate lookups on IP address, file hash, Certificate Serial Number, domain, and URL observables. URL and domain observables are enriched automatically with the WHOISIQ API. For observable enrichment on other types of observables with the WHOISIQ API, create observables and run lookups manually from the Observables table.

    Supported observables

    The following table lists the type of APIs used in this integration, and the observables each API supports. The table also indicates whether a lookup occurs automatically when security incidents are created, or if the lookup is run manually from the Observables table.

    表 : 1. Supported observables and lookup
    API Supported observables Lookup (automated or manual)
    RISKIQ SSL certificate API
    • IP address
    • File hash (certificate thumb print). See the following figure for an example of a file hash.
    • Certificate Serial Number, or Serial Number. This string is a unique ID for the entity. See the following figure for an example of a certificate serial number.
    • Domain (www.site.com, or site.com)
    • URL
      注:
      automatic scans are run for the URL format using the https:// protocol, for example, https://example.com/index.html
    Automated lookup when incidents are created.

    Results are displayed on the SSL Certificates tab of the security incident record.

    RISKIQ WHOISIQ API
    • Domain
    • URL
    Automated lookup when incidents are created.

    Results are displayed on the Observable Enrichment Results tab on the security incident record.

    RISKIQ WHOISIQ API
    • Email address
    • Organization name
    • Phone number
    • Mailing address
    Manual lookup is run from the Observables table.

    Results are displayed on the Observable Enrichment Results tab on the Observable record.

    Example of a file hash and certificate serial number

    This figure shows an example of the file hash and certificate serial number observables used for the SSL certificate lookups for this integration. The file hash refers to a SHA-1fingerprint. This value is displayed in your ServiceNow AI Platform instance without the colon separators. For example, 646D4B7A0C59A66656E94DDADD6C798027EFC10F.

    The certificate serial number observable refers to the unique ID or serial number for the entity. This value is also displayed without the colon separators. For example, 00EA0F74B56D44BBBE0000000050DE1DFD.

    図 : 1. File hash and certificate serial number
    SHA1 and certificate serial number examples