Skip to main content
Search any IPv4 address to retrieve threat intelligence data associated with it.

Summary view

  • Risk level with Crime Score visualization.
  • IP details: ASN, domain, reverse DNS, country of origin.
  • Timeline: first seen date, latest attack timestamp, time span of malicious activity.
  • Community intelligence: number of reports and distinct contributing organizations.
  • Historical crime level graph: malicious activity trends over time.

Activity feed

Each entry includes:
  • Human-readable description of the activity (e.g., brute-force attempts, malware distribution, reconnaissance).
  • Mapped MITRE ATT&CK techniques.
  • Honeypot engagement logs from OneFirewall DeceptionGrid.
  • External references (e.g., Blocklist.de reports).

Notes

  • Explanations shown when a classification is unavailable (confidential, obfuscated, or withheld).
  • Reported activity represents a subset of broader cybercrime attempts identified by the Alliance community.