> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# v2025-09-23 - Search Page

> Search any IPv4 address for threat intelligence data, activity history, and MITRE ATT&CK-mapped events.

## IPv4 Threat Intelligence Search

Search any IPv4 address to retrieve threat intelligence data associated with it.

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/search_1.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=79ad616987ef285892c11dba8d1677ce" width="1726" height="1384" data-path="images/search_1.webp" />

### Summary view

* **Risk level** with Crime Score visualization.
* **IP details**: ASN, domain, reverse DNS, country of origin.
* **Timeline**: first seen date, latest attack timestamp, time span of malicious activity.
* **Community intelligence**: number of reports and distinct contributing organizations.
* **Historical crime level graph**: malicious activity trends over time.

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/search_2.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=74e3cbf85e6d23a1d23de93f6d3512dc" width="1746" height="1396" data-path="images/search_2.webp" />

### Activity feed

Each entry includes:

* Human-readable description of the activity (e.g., brute-force attempts, malware distribution, reconnaissance).
* Mapped MITRE ATT\&CK techniques.
* Honeypot engagement logs from OneFirewall DeceptionGrid.
* External references (e.g., Blocklist.de reports).

### Notes

* Explanations shown when a classification is unavailable (confidential, obfuscated, or withheld).
* Reported activity represents a subset of broader cybercrime attempts identified by the Alliance community.
