Private/ASD/Invoke-APIOnypheASDWebSubdomainDomain.ps1
|
Function Invoke-APIOnypheASDWebSubdomainDomain { <# .SYNOPSIS create input for Invoke-OnypheAPIV2 function and then call it to query the ASD Web Subdomain Domain APIv1 .DESCRIPTION create input for Invoke-OnypheAPIV2 function and then call it to query the ASD Web Subdomain Domain APIv1 - discovers subdomain(s)/hostname(s) for the given domain(s) from web crawl data, returning a mix of {"hostname":"..."} entries and a trailing {"domain":"..."} echo of the query itself. BETA endpoint, requires a Griffin View or Griffin View ASM Edition subscription with a non-commercial use licence (see Get-OnypheUserInfo's asd.stdapis property). Live-tested 2026-09-19: "onyphe.io" returned 5 results (blog.onyphe.io, www.onyphe.io, search.onyphe.io, onyphe.io, plus the domain echo); "sovcloud-core.fr" returned 8 real internal-looking hostnames (e.g. cspv2.sovcloud-core.fr); "sovcloud-api.fr" returned 38; "neocase-sov.fr" returned 3. Unlike the ASD "*Exist" endpoints, -IncludePattern/-ExcludePattern/-Untrusted genuinely filter server-side here (verified live: -ExcludePattern "blog" against "onyphe.io" dropped "blog.onyphe.io" from the result set, going from 5 to 3 results). A domain with a large enough footprint ("microsoft.com" in testing) can time out server-side (HTTP error 2 "request timed out") rather than fail outright, the same characteristic already seen on Invoke-APIOnypheASDIpInventory - not an "astask"/task-mode situation like Invoke-APIOnypheASDOrgInventory/Invoke-APIOnypheASDDomainExist, just a computation-time limit. A genuinely non-existent domain returns HTTP error 1006 "search failed: no result found". .PARAMETER Domain -Domain string[] one or more domains to query .PARAMETER IncludePattern -IncludePattern string[] patterns to grep and keep matching results .PARAMETER ExcludePattern -ExcludePattern string[] patterns to grep and exclude from results .PARAMETER Untrusted -Untrusted switch disable Onyphe's backend false-positive filtering (server default is enabled/trusted) .PARAMETER AsLines -AsLines switch render results as one JSON object per line instead of with context (server default is with context) .PARAMETER APIKEY -APIKey string{APIKEY} Set APIKEY as global variable .PARAMETER FuncInput -FuncInput hashtable original bound parameters of the calling wrapper, threaded through to the result object's cli-func_input property .OUTPUTS TypeName: PSOnyphe .EXAMPLE C:\PS> Invoke-APIOnypheASDWebSubdomainDomain -Domain example.com #> [cmdletbinding()] Param ( [parameter(Mandatory=$true)] [ValidateNotNullOrEmpty()] [string[]]$Domain, [parameter(Mandatory=$false)] [ValidateNotNullOrEmpty()] [string[]]$IncludePattern, [parameter(Mandatory=$false)] [ValidateNotNullOrEmpty()] [string[]]$ExcludePattern, [parameter(Mandatory=$false)] [switch]$Untrusted, [parameter(Mandatory=$false)] [switch]$AsLines, [parameter(Mandatory=$false)] [ValidateLength(40,40)] [string]$APIKey, [parameter(Mandatory=$false)] [ValidateNotNullOrEmpty()] [hashtable]$FuncInput ) Process { if ($APIKey) {Set-OnypheAPIKey -APIKey $APIKey | out-null} $Body = [ordered]@{ domain = $Domain } if ($IncludePattern) { $Body.includep = $IncludePattern } if ($ExcludePattern) { $Body.excludep = $ExcludePattern } if ($Untrusted) { $Body.trusted = $false } if ($AsLines) { $Body.aslines = $true } $params = @{ request = "v1/asd/web/subdomain/domain" APIInfo = "asd/web/subdomain/domain" APIInput = @($Domain) APIKeyrequired = $true APIVersion = "1" Data = $Body | ConvertTo-Json } if ($FuncInput) { $params.add("FuncInput", $FuncInput) } Write-Verbose -message "URL Info : $($params.request)" Write-Verbose -message "POST JSON Data : $($Body | ConvertTo-Json)" Invoke-OnypheAPIV2 @params } } |