Overview
This guide covers IP Intelligence and explains how to get started using the product via both the web portal and the API.
IP Intelligence provides high-confidence feeds of malicious IP addresses across multiple threat vectors. These feeds are derived from real-life attacks mitigated by Mastercard Threat Protection1, as well as insights collected from our global sensor network. Updated hourly, the threat feeds are continuously evaluated to ensure the highest possible accuracy. Additionally, the criteria used to determine whether an IP address is malicious are rigorous and specific, resulting in low false-positive rates.
IP Intelligence is natively integrated into the Threat Protection products to help identify and thwart malicious activity before it ever reaches business-critical systems or applications.
Benefits of IP Intelligence
Optimize your defense across multiple threat vectors:
-
Credential stuffing and brute force attacks — Prevent traffic from known IPs involved in automated login attempts and credential stuffing from compromised or bot-controlled networks.
-
Malware uploads — Block known IPs observed to upload malicious files that could compromise your applications and data.
-
Port scanning — Identify and block unauthorized scanning activity, preventing attackers from probing your network infrastructure.
-
Layer 7 application-level web attacks — Protect against sophisticated web attacks, including high-rate application DDoS attacks and bot-driven traffic floods.
-
Anonymous proxies and malicious VPNs — Proactively block traffic from known malicious VPN providers and other masked sources.
Use cases
Utilize the threat feeds for various purposes:
-
Dynamic Blocklisting — Deploy the IP Intelligence feed as a dynamic blocklist within your existing network defense stack, including routers, VPN edge devices, WAF appliances, and cloud-based protection platforms. It can be applied at both Layer 3 (for edge devices and firewalls) and Layer 7 (for risk scoring and mitigating malicious activity on web applications).
-
Forensic Analysis — Cross-reference events in your SIEM, IPS, or event log repositories to uncover intrusions, identify malicious activity, and detect early-stage patterns—such as reconnaissance—that may indicate future threats.
-
Cyber Threat Reporting — Initiate proactive threat hunting and track evolving cybercrime trends across the broader threat landscape by analyzing malicious IP feeds.