IP Intelligence
IP intelligence is the evidence available about an IP address: the network that announces it, its geography, its classification (datacenter, residential, mobile, VPN, proxy, Tor), the names that have pointed at it, and its record across abuse and threat sources with dates. It describes where something is hosted right now, which is exactly what a firewall or a rate limiter needs to know.
An address is the unit that network controls act on. Firewalls, WAFs, rate limiters and fraud systems all see an IP before they see anything else, so the intelligence that helps them has to be about the IP: is it a hosting provider’s, is it an anonymiser, has it scanned or attacked anyone recently, is it one of the addresses a known C2 has used.
The weakness of the address as an indicator is that it is shared and reused. A single cloud address serves many tenants over a month; a residential address is one subscriber today and another next week; a CDN edge fronts thousands of sites. IP intelligence therefore has to be dated and qualified, and a listing from last year on a datacenter address is close to worthless.
Domain intelligence versus IP intelligence: the domain describes what an actor built and carries across hosting moves; the address describes the current hosting and is what a network control can block. Investigations pivot between the two, and a verdict that rests on one alone is usually incomplete.
Example
A login endpoint sees 12 000 attempts from one address in an hour. IP intelligence says it belongs to a hosting ASN, is classified as a datacenter, carries no reverse DNS, and was listed by two sources for credential stuffing in the last 72 hours. The block is applied at the edge before the logs are read.
In isMalicious
The IP lookup at /threat-intel/ip and every IP report on isMalicious return the ASN and operator, geolocation, classification, reverse DNS and each source listing with its last-seen date; the same data is available per address through the API and in bulk.
Frequently Asked Questions
What is IP Intelligence?
IP intelligence is the evidence available about an IP address: the network that announces it, its geography, its classification (datacenter, residential, mobile, VPN, proxy, Tor), the names that have pointed at it, and its record across abuse and threat sources with dates. It describes where something is hosted right now, which is exactly what a firewall or a rate limiter needs to know.
How is IP Intelligence related to IP Reputation?
IP Intelligence and IP Reputation are both key concepts in threat intelligence. IP reputation is a score or classification indicating whether an IP address has been associated with malicious activity. Factors include appearance on blocklists, volume of spam sent, history of port scanning, C2 hosting, and abuse reports.
Related Terms
IP Reputation
IP reputation is a score or classification indicating whether an IP address has been associated with malicious activity. Factors include appearance on blocklists, volume of spam sent, history of port scanning, C2 hosting, and abuse reports.
ASN Reputation
ASN reputation assesses whether an Autonomous System Number — the network block announcing an IP range — has a history of hosting abuse, bulletproof providers, or residential versus datacenter traffic. It contextualizes IP verdicts when the same IP moves between benign and hostile ASNs.
Domain Intelligence
Domain intelligence is the body of evidence about a domain name: when and where it was registered, who operates its nameservers, what it has resolved to over time, what certificates it has carried, which sources list it and for what activity. It is the domain-side counterpart of IP intelligence and the more durable of the two, because names persist while addresses rotate.
ISP (Internet Service Provider)
An ISP provides internet connectivity to consumers and businesses. In threat intelligence, ISP context for an IP address indicates whether it is a residential, commercial, or hosting IP — a key factor in risk scoring, since hosting IPs are far more likely to be malicious.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.