๐Ÿ”ฅ

DarkWick โ€” Enrichment API

Look up any IP and get back everything DarkWick knows โ€” indicator, dossier, detections, provenance.
โ† Back to globe
GET https://darkwick.netlify.app/api/enrich?ip=<ip> Free No auth

Query any IP address (also ?url=, ?domain=, or ?q=) and get the full enrichment record. A miss returns {"found": false} with HTTP 200 โ€” a miss is an answer, not an error. TLP:GREEN public data only.

Response fields

FieldTypeDescription
foundboolWhether DarkWick has a record for this indicator
matched_bystringexact (IP match) or cidr (inside a hostile netblock)
indicatorobjectFull indicator record โ€” type, score, confidence, sources, geo, ASN, tags, provenance
dossierobject|nullBehavioral profile if observed by honeypot โ€” sessions, creds tried, commands, SSH clients, skill assessment
related_detectionsarraySigma detection rules matched to this attacker, with MITRE technique IDs
provenance_notestringExplains the provenance classes (observed / inferred / feed)
generatedISO 8601When the underlying data was last generated by the pipeline

Provenance classes

ClassMeaning
observedWitnessed first-hand by a DarkWick honeypot sensor
inferredDerived from witnessed evidence (e.g. C2 carved from a captured sample)
feedAggregated from a named open source feed (secondhand)

Examples

curl

# Look up a known attacker
curl "https://darkwick.netlify.app/api/enrich?ip=91.92.42.168"

# Check a netblock (CIDR matching)
curl "https://darkwick.netlify.app/api/enrich?ip=45.9.148.100"

# Miss โ€” not in dataset
curl "https://darkwick.netlify.app/api/enrich?ip=8.8.8.8"
# โ†’ {"found": false, "queried": "8.8.8.8", ...}

Python (SOAR playbook)

import requests

def enrich_ip(ip):
    r = requests.get(f"https://darkwick.netlify.app/api/enrich?ip={ip}")
    data = r.json()
    if data["found"]:
        return {
            "score": data["indicator"]["score"],
            "provenance": data["indicator"]["provenance"]["class"],
            "dossier": data["dossier"],
        }
    return None

Splunk (scheduled lookup)

| inputlookup darkwick_alerts.csv
| lookup darkwick_enrichment ip AS src_ip OUTPUT score, provenance_class
| where score >= 70

Microsoft Sentinel (KQL)

// Join sign-in logs against DarkWick watchlist
SigninLogs
| join kind=inner (
    _GetWatchlist('darkwick')
) on $left.IPAddress == $right.indicator
| where score_d >= 70

Rate limits & cost

Free tier: 125,000 invocations/month (Netlify Functions). No API key, no signup, no billing. The data refreshes every 6 hours via the DarkWick pipeline. Responses are cached for 5 minutes at the CDN edge.

Bulk feeds (static files)

For SIEM ingestion at scale, use the static enrichment feeds instead of polling the API per-indicator:

FormatURLFor
STIX 2.1darkwick.stix2.jsonOpenCTI, MISP, Sentinel, ThreatConnect
Splunk CSVdarkwick-splunk.csvSplunk automatic lookups
Sentinel CSVdarkwick-sentinel.csvSentinel watchlists
Elastic ECSdarkwick-elastic.ndjsonElastic Security indicator-match
Blocklistblocklist.txtFirewall rules (plain IP/CIDR)
Manifestindex.jsonMachine-readable feed discovery
โ† Back to DarkWick Globe