Back to workflows

IP / ASN workflow

Check IP and ASN reputation carefully.

A workflow for reading IP, ASN, hosting, and reputation signals without assigning blame.

Passive and safe research workflow

When to use it

You have IP address and want to check it through safe, legal, source-based research.

What you get

IP/ASN context note, reputation signals, uncertainty, and safe recommendation.

Safety boundary

This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.

Simple order

Work through the steps in order.

  1. Identify the network context

    Check ASN, organization field, hosting provider, and country.

    Check: Provider and owner are not confused.

  2. Read reputation sources

    Compare abuse, scanning, threat, and passive visibility sources.

    Check: The date of each signal is recorded.

  3. Look for shared infrastructure

    Consider CDN, VPN, cloud, hosting, and shared IP context.

    Check: A shared IP is not tied to one actor.

  4. Write with caution

    Use visible network trace language.

    Check: The note avoids personal or organizational accusation.

Report language

The IP/ASN has visible reputation and hosting context; this does not identify an actor by itself.

Move to evidence notes

Sources

Start with these sources.

Open resource archive
  • AlienVault OTX logo

    AlienVault OTX

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source
  • GreyNoise Visualizer logo

    GreyNoise Visualizer

    IP and ASN intelligence

    Use for infrastructure context, hosting traces, and network ownership checks.

    Open source
  • Hurricane Electric BGP Toolkit logo

    Hurricane Electric BGP Toolkit

    IP and ASN intelligence

    Use for infrastructure context, hosting traces, and network ownership checks.

    Open source
  • IPinfo logo

    IPinfo

    IP and ASN intelligence

    Use for infrastructure context, hosting traces, and network ownership checks.

    Open source
  • MISP Project logo

    MISP Project

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source
  • MITRE ATT&CK logo

    MITRE ATT&CK

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source