Skip to main content

CTI API: IPv4 Intelligence Endpoint

GET /api/v1/intel/<IPv4>

Returns consolidated threat intelligence for a single IPv4 address — crime score and score history, geolocation and ASN ownership, reporting sectors and countries, MITRE ATT&CK technique mappings, and STIX 2.1 observables — in one response. Use it to determine whether an IP is malicious and why, without querying multiple feeds separately, and to feed dashboards, SIEM enrichment, or automated response workflows. This endpoint is additive: existing IPv4 feed, geolocation, and scoring APIs are unchanged.

Response Structure

The API returns a JSON object with the following fields:

Sample Response