IP Enrichment
IP enrichment is the process of attaching context to a bare IP address: who announces it (ASN and operator), where it is (geolocation), what it is (datacenter, residential, VPN, proxy, Tor), what name it carries (reverse DNS), and what it has done (reputation across abuse sources, with dates). It turns a number in a log into something an analyst can act on.
An IP address on its own says nothing. 203.0.113.42 could be a home connection, a scanner rented by the hour, a corporate proxy behind which a thousand employees sit, or a Tor exit node. Enrichment is the set of lookups that answers those questions at once, so the analyst does not run six queries per alert.
The facts come from different places. Routing data gives the ASN and the prefix. Geolocation databases give a country and often a city. Classification services say whether the block belongs to a hosting provider, a mobile carrier or an anonymising service. Reverse DNS gives the operator’s naming. Abuse sources give the history. Good enrichment reports each fact with its source and its age.
The value shows in bulk. Enriching one address by hand takes a minute; enriching ten thousand addresses from a day of firewall logs and sorting by “hostile ASN, datacenter, listed in the last week” turns a log into a shortlist.
Example
A day of denied connections holds 9 400 distinct source addresses. Enriched, 8 100 are residential and unlisted (background noise), 900 belong to two scanning services (expected), and 400 sit on hosting ASNs with recent abuse listings. Those 400 are the ones worth reading.
In isMalicious
An IP report on isMalicious is the enrichment in one page: ASN and operator, geolocation, reverse DNS, hosting classification and every source that lists the address with its last-seen date. The bulk API documented at /api-docs/bulk applies the same enrichment to a file of addresses in one request.
Frequently Asked Questions
What is IP Enrichment?
IP enrichment is the process of attaching context to a bare IP address: who announces it (ASN and operator), where it is (geolocation), what it is (datacenter, residential, VPN, proxy, Tor), what name it carries (reverse DNS), and what it has done (reputation across abuse sources, with dates). It turns a number in a log into something an analyst can act on.
How is IP Enrichment related to IOC Enrichment?
IP Enrichment and IOC Enrichment are both key concepts in threat intelligence. IOC enrichment augments a bare indicator — an IP, domain, or hash — with context such as risk score, confidence, categories, WHOIS, DNS, geolocation, and related infrastructure. Enrichment turns block/allow decisions into informed analyst and automation workflows.
Related Terms
IOC Enrichment
IOC enrichment augments a bare indicator — an IP, domain, or hash — with context such as risk score, confidence, categories, WHOIS, DNS, geolocation, and related infrastructure. Enrichment turns block/allow decisions into informed analyst and automation workflows.
IP Reputation
IP reputation is a score or classification indicating whether an IP address has been associated with malicious activity. Factors include appearance on blocklists, volume of spam sent, history of port scanning, C2 hosting, and abuse reports.
ASN (Autonomous System Number)
An Autonomous System Number identifies a collection of IP address ranges under the control of a single organization (an Internet Service Provider, cloud provider, or enterprise). ASNs are used in threat intelligence to identify hosting providers commonly used by attackers.
Bulk API
A bulk API endpoint accepts multiple indicators in a single request, enabling high-throughput threat intelligence lookups without the latency overhead of individual calls. isMalicious supports batches of up to 10,000 mixed IP, domain, and URL indicators per request.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.