Securitytrails
security & identity tools 12 tools availableSecurityTrails is a cybersecurity platform providing comprehensive domain, IP, DNS, and WHOIS intelligence data. It offers historical DNS records, subdomain discovery, WHOIS history, associated domains, passive DNS datasets, and website technology detection to support threat hunting, brand protection, cyber forensics, and attack surface management.
About this integration
Connect Securitytrails to Definable to automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas call Securitytrails's 12 tools directly from chat or scheduled flows. You can wire it into any persona to read, write, and react when an event fires.
Connect Securitytrails to Definable and it becomes a set of typed tools your agents plan with — triggered by events, run on schedules, or invoked mid-conversation. Every write is checked by the verifier before it lands.
Securitytrails · in workflows
What teams actually run.
Three patterns teams run with Securitytrails on day one. Each one is a plain-English prompt — no canvas, no glue code — and you can remix them into anything.
Daily summary
Cross-tool sync
12 tools available
The Securitytrails toolbox.
Every Securitytrails capability your agents can call, each with a typed schema the planner reads. The router picks the right tool per step; the verifier checks the result.
Bulk Static Asset Rules Bulk add or remove static asset rules for a SecurityTrails ASI project. Static asset rules define which domains/IPs are included or excluded from the project's monitoring scope. This operation processes up to 1000 rules (combined add + remove) per request. The API processes rules asynchronously, waiting up to 2 seconds for completion. If processing takes longer, task_ids are returned for status polling. Note: Requires a valid project_id from the List Projects endpoint. Use the Get Static Assets endpoint to verify changes after bulk operations complete.
Get Company Associated IPs Tool to retrieve IPs associated with a company domain. Use when you need to find all IP addresses linked to an organization's domain name.
Get Domain Details Retrieves comprehensive domain information from SecurityTrails including current DNS records, infrastructure details, and statistics. This tool fetches detailed DNS data (A, AAAA, MX, NS, SOA, TXT records) along with metadata about when records were first seen, which organizations own the infrastructure, and how many other domains share the same servers. Useful for domain reconnaissance, infrastructure mapping, security analysis, and understanding domain configurations. Returns structured data with typed fields for easy programmatic access by AI agents.
Get Domain SSL Tool to fetch current and historical SSL certificate details for a hostname. Use when you need to retrieve SSL data after identifying the domain. Coverage limited to certificates indexed by SecurityTrails; private, internally-issued, or very recently issued certificates may be absent.
IP Search Statistics Fetch aggregated statistics for IP addresses matching a DSL query. Returns top open ports by frequency, common reverse DNS patterns, and total count. Useful for analyzing IP infrastructure patterns, port distributions, and PTR records across specific IP ranges or reverse DNS domains.
List ASI Projects Tool to list ASI projects available to the account. Use when you need project IDs for subsequent ASI operations.
Ping Tool to test authentication and connectivity with the SecurityTrails API. Use after configuring API key.
Scroll Results Tool to continue scrolling through DSL search results. Use after receiving a scroll_id from SECURITYTRAILS_SEARCH_IPS or SECURITYTRAILS_SQL_API_EXECUTE_QUERY to fetch the next batch of data. Call iteratively until no scroll_id is returned to retrieve all pages.
Search IPs Tool to search IP addresses via SecurityTrails DSL. Use when you need to filter IPs with custom DSL queries. Results are paginated; use SecurityTrails scroll mechanisms for large result sets to avoid missing assets.
SQL API Execute Query Execute SQL-like queries against SecurityTrails data. Query the 'hosts' table for domain/DNS information or the 'ips' table for IP address/ASN/port data. Returns up to 100 records per request with a scroll ID for pagination. Supports standard SQL syntax (SELECT, WHERE, AND, OR, IN, IS NULL) but does NOT support LIMIT clause.
SQL API Scroll Results Tool to fetch next page of SQL query results. Use after obtaining scroll_id from initial SQL API response.
Temp Scrape Securitytrails Usage Retrieve account usage information from the SecurityTrails API. This action fetches the current monthly usage and allowed monthly usage limits for your SecurityTrails API account. Use this to monitor your API quota consumption. Returns: On success (200): - current_monthly_usage: Your current API usage for the month - allowed_monthly_usage: Your total allowed monthly API quota On error: - status_code: HTTP status code - response_text: Error message from API
See it run
One prompt, start to finish.
A real prompt, the Securitytrails tools it calls, and what comes back. This is the whole interface — describe the outcome, agents handle the rest.
Run a real Securitytrails task end-to-end — plan it, execute across the API, and hand back a verified result.
securitytrails.bulk_static_asset_rules Bulk add or remove static asset rules for a SecurityTrails ASI project. Static asset rules securitytrails.get_company_associated_ips Tool to retrieve IPs associated with a company domain. Use when you need to find all IP ad securitytrails.get_domain_details Retrieves comprehensive domain information from SecurityTrails including current DNS recor · verified Done. Securitytrails responded across 3 calls, the verifier signed off, and the result is logged with every payload.
FAQ · Securitytrails
Questions, answered.
What teams ask before connecting Securitytrails.
01 What can I automate with Securitytrails on Definable?
Anything Securitytrails exposes through its API. Common security & identity tools workflows on Definable include automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas can call any of the 12 Securitytrails tools directly, then chain the result into another integration without you writing code.
02 How does Securitytrails authentication work?
Securitytrails uses API_KEY on Definable. You connect once from the integrations page, scoped to the permissions you choose, and from then on any persona that has the integration enabled can act on your behalf. Tokens are encrypted at rest and rotated automatically.
03 Is the Securitytrails integration included in my Definable plan?
Yes — every Definable plan, including Starter, includes access to all 12 Securitytrails tools. You only need a separate Securitytrails subscription if Securitytrails itself charges per seat or per API call.
04 Is using Securitytrails through Definable secure?
Every call from a persona to Securitytrails is logged with the user, persona, prompt, and response. Tokens never leave Definable's secrets vault, scopes are configurable per persona, and you can revoke access at any time from the integration page.
05 How do I get started with Securitytrails on Definable?
Sign up for Definable, open the integrations page, find Securitytrails, and connect via OAuth or API key. You can immediately attach Securitytrails to any persona and start running workflows. The free Starter plan includes 5,000 credits/month.
06 What Securitytrails actions does Definable expose?
Definable exposes all 12 Securitytrails actions as callable tools — including `Bulk Static Asset Rules`, `Get Company Associated IPs`, `Get Domain Details`, plus 9 more. Each tool gets a typed parameter schema so personas know exactly how to call it.
Put Securitytrails to work tonight.
Connect in two clicks, describe an outcome, and your first workflow is live in minutes. Free plan included — no card required.