Data Points

🌐 IP Address

Internet Protocol address identifying a device or server on a network.
Network

Sources

6
4 no-auth

Disciplines

7
that use it

Mission domains

5
reach

Workbench

native tool

🔌 Sources that yield IP Address (6)

SourceCategoryAuthFormat
abuse.ch ThreatFox
Family-labelled IoC exchange.
Threat AnalysisNONEjsonhome↗ api↗
CISA Automated Indicator Sharing
US-CERT indicator sharing / advisories.
Threat AnalysisNONExmlhome↗
FireHOL IP Blocklists
Aggregated abusive-IP blocklists.
Operational SecurityNONEtexthome↗ api↗
Tor Bulk Exit List
Authoritative Tor exit-node list.
Dark WebNONEtexthome↗ api↗
AlienVault OTX Pulses
Community threat-intel pulses (free key).
Threat AnalysisKEYjsonhome↗ api↗
Shodan ICS/SCADA
Exposed ICS/SCADA device discovery.
Critical InfrastructureKEYjsonhome↗ api↗

🔍 Lookup

📜 Playbook — IP Address exploitation

  1. Direction — frame the requirement for IP Address: what decision does this support, by when?
  2. Collection — pull the 6 mapped sources (4 free) and the native workbench (open); capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 IP Address

An IP address is a numeric identifier (IPv4 or IPv6) assigned to a host or interface on a network, marking where traffic originates or terminates. In investigations it geolocates and attributes infrastructure, links hosts across campaigns via shared hosting, and drives blocking, netflow correlation, and scanning telemetry.

Format: IPv4 dotted quad (0-255)x4; IPv6 eight hextets with :: compression. Validate RFC 1918/RFC 4193 private, CGNAT 100.64/10, bogon and reserved ranges.

📡 How it is collected

  • DNS A/AAAA resolution of domains
  • Firewall / proxy / netflow logs
  • Passive DNS reverse records
  • Honeypot and scanner telemetry
  • Malware C2 beacon captures
  • Email Received headers

🧩 Analysis & hunting techniques

  • ASN / netblock ownership mapping
  • Reverse (PTR) and passive DNS pivoting
  • Port/banner fingerprinting
  • Scanner vs. targeted-traffic classification (GreyNoise)
  • Geolocation and hosting-type analysis
  • Co-hosting / virtual-host clustering
  • Netflow peer correlation
  • Reputation and blocklist aggregation

🔧 Tools

  • Shodan
  • Censys
  • nmap
  • masscan
  • MaxMind
  • whois/cymru
  • Zeek
  • MISP

⚡ Workbench actions

  • Resolve reverse DNS (PTR)
  • Query passive DNS
  • Look up ASN / CIDR owner
  • Scan open ports & banners
  • Check GreyNoise / AbuseIPDB reputation
  • Screen against sanctions & blocklists
  • Cluster by ASN
  • Pivot to netflow peers

📊 Dashboard KPIs

Abuse confidence score (AbuseIPDB)Open port countGreyNoise classification (benign/malicious/unknown)Distinct domains resolving hereFirst/last-seen span
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php