Home / IP & Network / IOC Enrichment
// IOC Enrichment · IP Threat Intelligence

Everything about one IP, on one page.

Paste an IPv4 or IPv6 address. We orchestrate our own existing tools — infrastructure / risk classification (ASN analysis), Tor exit detection, curated DNSBLs, and reverse DNS — concurrently, with per-source attribution. Each section degrades gracefully if any one source is slow or unavailable.

Please enter a valid IPv4 or IPv6 address.
[ 01 ] — What you get

Five signals, one screen.

Reputation & risk
An infrastructure / risk classification from our own ASN analysis (datacenter/hosting/CDN/VPN) plus current Tor-exit status — a plain-language verdict, not a third-party “abuse score”.
Network & geo
Country, region, city (GeoLite2), the announcing ASN + organisation, our datacenter/hosting/CDN/VPN classification, and current Tor-exit status.
Blacklist summary
A curated DNSBL summary for the headline verdict — a few commercial-OK lists (IPv4 addresses). The full run lives at /blacklist/.
Reverse DNS
PTR record via Cloudflare DoH — what the address calls itself.
Honest attribution
Every signal is labelled with its source. No opaque composite “risk score” — when something is unavailable, the section says so and the rest of the report still renders.