IPv4 Threat Intelligence Search
Search any IPv4 address to retrieve threat intelligence data associated with it.
Summary view
- Risk level with Crime Score visualization.
- IP details: ASN, domain, reverse DNS, country of origin.
- Timeline: first seen date, latest attack timestamp, time span of malicious activity.
- Community intelligence: number of reports and distinct contributing organizations.
- Historical crime level graph: malicious activity trends over time.

Activity feed
Each entry includes:- Human-readable description of the activity (e.g., brute-force attempts, malware distribution, reconnaissance).
- Mapped MITRE ATT&CK techniques.
- Honeypot engagement logs from OneFirewall DeceptionGrid.
- External references (e.g., Blocklist.de reports).
Notes
- Explanations shown when a classification is unavailable (confidential, obfuscated, or withheld).
- Reported activity represents a subset of broader cybercrime attempts identified by the Alliance community.

