Enter a CVE ID, IP address, Domain, Email, Phone Number, File Hash, URL to scan/analyze threat intelligence data
Nothing searched yet

IP Address lookup

An address out of a firewall log, a SIEM alert or an extracted IOC. The lookup answers what the address is, who it belongs to, and what has been seen using it.

What you can paste

These are format examples. Clicking one puts it in the search box — it does not run a search, so you choose when to spend a lookup.

How to run one
  1. 1Paste the IP address into the box above. The type is already set to IP Address on this page.
  2. 2Press Analyze. If the indicator is new to the platform it is queued for enrichment, and the page holds a progress view while that runs rather than telling you to come back later.
  3. 3Read the report top-down. The verdict is the headline; the sections below it are the evidence, and the evidence is the part worth your time.
  4. 4Pivot. Almost every value in the report is itself searchable, which is how one indicator becomes an investigation.
Where to go next
  • Search the domains resolving to the address
  • Cross-reference to find malware that communicated with it
  • Check whether neighbouring infrastructure shows the same behaviour
What comes back, and how to read it

These are the sections of the report, in the order you will meet them.

  1. 01Detection Consensus

    How many sources consider the address malicious, and how strongly. Shared hosting means a bad neighbour can drag an address down -- check what else is on it before you block.

  2. 02Multi-Source Intelligence

    The same address as several providers see it. Agreement across independent sources is worth far more than a high score from one.

  3. 03Geographic Location

    Where the address geolocates, plotted. Treat it as context rather than attribution -- hosting location says little about who is operating it.

  4. 04Identity & Infrastructure

    The owning network and ASN, plus the domains resolving here. A hosting provider and a corporate netblock warrant very different responses.

  5. 05Security Analysis

    The specific abuse reported against the address -- scanning, brute force, malware hosting, command-and-control -- rather than a single undifferentiated score.

  6. 06Analysis Timeline

    When the address was first and last seen doing something worth reporting. An address clean for two years is a different proposition to one reported this morning.