Skip to main content
Threat IntelligenceUpdated September 3, 2026

IP Intelligence

IP intelligence is the evidence available about an IP address: the network that announces it, its geography, its classification (datacenter, residential, mobile, VPN, proxy, Tor), the names that have pointed at it, and its record across abuse and threat sources with dates. It describes where something is hosted right now, which is exactly what a firewall or a rate limiter needs to know.

An address is the unit that network controls act on. Firewalls, WAFs, rate limiters and fraud systems all see an IP before they see anything else, so the intelligence that helps them has to be about the IP: is it a hosting provider’s, is it an anonymiser, has it scanned or attacked anyone recently, is it one of the addresses a known C2 has used.

The weakness of the address as an indicator is that it is shared and reused. A single cloud address serves many tenants over a month; a residential address is one subscriber today and another next week; a CDN edge fronts thousands of sites. IP intelligence therefore has to be dated and qualified, and a listing from last year on a datacenter address is close to worthless.

Domain intelligence versus IP intelligence: the domain describes what an actor built and carries across hosting moves; the address describes the current hosting and is what a network control can block. Investigations pivot between the two, and a verdict that rests on one alone is usually incomplete.

Example

A login endpoint sees 12 000 attempts from one address in an hour. IP intelligence says it belongs to a hosting ASN, is classified as a datacenter, carries no reverse DNS, and was listed by two sources for credential stuffing in the last 72 hours. The block is applied at the edge before the logs are read.

In isMalicious

The IP lookup at /threat-intel/ip and every IP report on isMalicious return the ASN and operator, geolocation, classification, reverse DNS and each source listing with its last-seen date; the same data is available per address through the API and in bulk.

Frequently Asked Questions

What is IP Intelligence?

IP intelligence is the evidence available about an IP address: the network that announces it, its geography, its classification (datacenter, residential, mobile, VPN, proxy, Tor), the names that have pointed at it, and its record across abuse and threat sources with dates. It describes where something is hosted right now, which is exactly what a firewall or a rate limiter needs to know.

How is IP Intelligence related to IP Reputation?

IP Intelligence and IP Reputation are both key concepts in threat intelligence. IP reputation is a score or classification indicating whether an IP address has been associated with malicious activity. Factors include appearance on blocklists, volume of spam sent, history of port scanning, C2 hosting, and abuse reports.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary