GET
https://darkwick.netlify.app/api/enrich?ip=<ip>
Free
No auth
Query any IP address (also ?url=, ?domain=, or ?q=) and get the full enrichment record.
A miss returns {"found": false} with HTTP 200 โ a miss is an answer, not an error. TLP:GREEN public data only.
Response fields
| Field | Type | Description |
| found | bool | Whether DarkWick has a record for this indicator |
| matched_by | string | exact (IP match) or cidr (inside a hostile netblock) |
| indicator | object | Full indicator record โ type, score, confidence, sources, geo, ASN, tags, provenance |
| dossier | object|null | Behavioral profile if observed by honeypot โ sessions, creds tried, commands, SSH clients, skill assessment |
| related_detections | array | Sigma detection rules matched to this attacker, with MITRE technique IDs |
| provenance_note | string | Explains the provenance classes (observed / inferred / feed) |
| generated | ISO 8601 | When the underlying data was last generated by the pipeline |
Provenance classes
| Class | Meaning |
| observed | Witnessed first-hand by a DarkWick honeypot sensor |
| inferred | Derived from witnessed evidence (e.g. C2 carved from a captured sample) |
| feed | Aggregated from a named open source feed (secondhand) |
Examples
curl
curl "https://darkwick.netlify.app/api/enrich?ip=91.92.42.168"
curl "https://darkwick.netlify.app/api/enrich?ip=45.9.148.100"
curl "https://darkwick.netlify.app/api/enrich?ip=8.8.8.8"
Python (SOAR playbook)
import requests
def enrich_ip(ip):
r = requests.get(f"https://darkwick.netlify.app/api/enrich?ip={ip}")
data = r.json()
if data["found"]:
return {
"score": data["indicator"]["score"],
"provenance": data["indicator"]["provenance"]["class"],
"dossier": data["dossier"],
}
return None
Splunk (scheduled lookup)
Microsoft Sentinel (KQL)
SigninLogs
| join kind=inner (
_GetWatchlist('darkwick')
) on $left.IPAddress == $right.indicator
| where score_d >= 70
Rate limits & cost
Free tier: 125,000 invocations/month (Netlify Functions). No API key, no signup, no billing.
The data refreshes every 6 hours via the DarkWick pipeline. Responses are cached for 5 minutes at the CDN edge.
Bulk feeds (static files)
For SIEM ingestion at scale, use the static enrichment feeds instead of polling the API per-indicator: