Getting started with IP Intelligence
To activate your account and start using the product, follow these steps.
Creating an account
Once you receive an invitation to join a tenant, follow the instructions in the email to create your account. Upon verifying your email address, you will be prompted to set up a two-factor authentication (2FA) method.
During your first login, you will be asked to review and sign the End User License Agreement (EULA). Afterwards, you will be redirected to the landing page, where you can customize your threat feed options and file formats.
Using the web interface
To download IP Intelligence threat feeds through the web interface, navigate to the Feeds section in the top-left corner and follow the outlined steps. You can modify the file format and configuration options each time you download a feed.
IP Intelligence threat feeds can be downloaded in either CSV or JSON format. By default, the exported fields include the IP address, source country, and type or types of associated malicious activity. If preferred, you can modify the download configuration to include only the source IP field.
Choosing a feed
Select a threat feed to download from the drop-down menu.
-
Ingress Feed: Our standard threat feed for observations on malicious IP addresses. Easily block high-risk traffic at your endpoints or integrate the feed into your SIEM to automatically enrich logs and tag threat activity.
-
IP Attacked Countries: Enhances our core Ingress Feed by mapping malicious IP activity to specific target countries. Ideal for risk modeling and tracking regional attack trends across your global applications and teams.
Downloading historical data
The feeds include access to historical observation logs, allowing you to query specific dates and retroactively analyze threat activity. This can be used for reporting, incident investigation, and auditing SIEM logs to uncover previously undetected activity.
Using the API
Links to the API documentation and your account settings can be found in the top-right corner under your account name. You can also access the IP Intelligence API documentation directly.