Skip to main content

Getting started with IP Intelligence

To activate your account and start using the product, follow these steps.

Creating an account

Once you receive an invitation to join a tenant, follow the instructions in the email to create your account. Upon verifying your email address, you will be prompted to set up a two-factor authentication (2FA) method.

Account verification email

Verify your email address to activate your account.

During your first login, you will be asked to review and sign the End User License Agreement (EULA). Afterwards, you will be redirected to the landing page, where you can customize your threat feed options and file formats.

Using the web interface

To download IP Intelligence threat feeds through the web interface, navigate to the Feeds section in the top-left corner and follow the outlined steps. You can modify the file format and configuration options each time you download a feed.

IP Intelligence feed download options

Choose a feed, file format, and download options.

IP Intelligence threat feeds can be downloaded in either CSV or JSON format. By default, the exported fields include the IP address, source country, and type or types of associated malicious activity. If preferred, you can modify the download configuration to include only the source IP field.

Choosing a feed

Select a threat feed to download from the drop-down menu.

  • Ingress Feed: Our standard threat feed for observations on malicious IP addresses. Easily block high-risk traffic at your endpoints or integrate the feed into your SIEM to automatically enrich logs and tag threat activity.

  • IP Attacked Countries: Enhances our core Ingress Feed by mapping malicious IP activity to specific target countries. Ideal for risk modeling and tracking regional attack trends across your global applications and teams.

Downloading historical data

The feeds include access to historical observation logs, allowing you to query specific dates and retroactively analyze threat activity. This can be used for reporting, incident investigation, and auditing SIEM logs to uncover previously undetected activity.

Using the API

Links to the API documentation and your account settings can be found in the top-right corner under your account name. You can also access the IP Intelligence API documentation directly.