Skip to main content
API & IntegrationUpdated September 3, 2026

IP Enrichment

IP enrichment is the process of attaching context to a bare IP address: who announces it (ASN and operator), where it is (geolocation), what it is (datacenter, residential, VPN, proxy, Tor), what name it carries (reverse DNS), and what it has done (reputation across abuse sources, with dates). It turns a number in a log into something an analyst can act on.

An IP address on its own says nothing. 203.0.113.42 could be a home connection, a scanner rented by the hour, a corporate proxy behind which a thousand employees sit, or a Tor exit node. Enrichment is the set of lookups that answers those questions at once, so the analyst does not run six queries per alert.

The facts come from different places. Routing data gives the ASN and the prefix. Geolocation databases give a country and often a city. Classification services say whether the block belongs to a hosting provider, a mobile carrier or an anonymising service. Reverse DNS gives the operator’s naming. Abuse sources give the history. Good enrichment reports each fact with its source and its age.

The value shows in bulk. Enriching one address by hand takes a minute; enriching ten thousand addresses from a day of firewall logs and sorting by “hostile ASN, datacenter, listed in the last week” turns a log into a shortlist.

Example

A day of denied connections holds 9 400 distinct source addresses. Enriched, 8 100 are residential and unlisted (background noise), 900 belong to two scanning services (expected), and 400 sit on hosting ASNs with recent abuse listings. Those 400 are the ones worth reading.

In isMalicious

An IP report on isMalicious is the enrichment in one page: ASN and operator, geolocation, reverse DNS, hosting classification and every source that lists the address with its last-seen date. The bulk API documented at /api-docs/bulk applies the same enrichment to a file of addresses in one request.

Frequently Asked Questions

What is IP Enrichment?

IP enrichment is the process of attaching context to a bare IP address: who announces it (ASN and operator), where it is (geolocation), what it is (datacenter, residential, VPN, proxy, Tor), what name it carries (reverse DNS), and what it has done (reputation across abuse sources, with dates). It turns a number in a log into something an analyst can act on.

How is IP Enrichment related to IOC Enrichment?

IP Enrichment and IOC Enrichment are both key concepts in threat intelligence. IOC enrichment augments a bare indicator — an IP, domain, or hash — with context such as risk score, confidence, categories, WHOIS, DNS, geolocation, and related infrastructure. Enrichment turns block/allow decisions into informed analyst and automation workflows.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary