THREAT INTELLIGENCE WORKSPACE
Investigate an indicator.
One lookup. A clearer view across your intelligence sources.
Investigation results
SAMPLE REPORTIllustrative dataThis sample uses a reserved IP and fictional findings. Run a lookup for actual provider results.
IP address
203.0.113.42Review the flagged evidence and its source context.
ASSESSMENTRisk signals detected3 of 6 applicable sources flagged
Detection summary
BY SOURCEProvider scores describe different signals and are not combined into a probability.
Infrastructure context
- NetworkVirusTotal
- 203.0.113.0/24 (documentation)
- Network ownerVirusTotal
- Example Network · fictional
- Usage typeAbuseIPDB
- Data center · fictional
- Distinct reportersAbuseIPDB
- 38 · sample
- Reports in last 90 daysAbuseIPDB
- 247 · sample
Intelligence sources
5/6 applicable sources completedVT
CompletedSELECTED SOURCE
VirusTotal report
Multiple engines flagged this sample indicator as malicious.
Context & metadata
- Network
- 203.0.113.0/24 (documentation)
- Network owner
- Example Network · fictional
Detection evidence 2
Findings reported by intelligence sources
2 malicious
| Engine / signal | Finding | Observed |
|---|---|---|
| Example engine A | Malicious · command and control | Sample data |
| Example engine B | Malicious · malware | Sample data |