When I use this
You have IP address and want to check it through safe, legal, source-based research.
IP / ASN workflow
A workflow for reading IP, ASN, hosting, and reputation signals without assigning blame.
Passive and safe research workflow
When I use this
You have IP address and want to check it through safe, legal, source-based research.
What you get
IP/ASN context note, reputation signals, uncertainty, and safe recommendation.
What I would be careful with here
The order I follow
Check ASN, organization field, hosting provider, and country.
Provider and owner are not confused.
Compare abuse, scanning, threat, and passive visibility sources.
The date of each signal is recorded.
Consider CDN, VPN, cloud, hosting, and shared IP context.
A shared IP is not tied to one actor.
Use visible network trace language.
The note avoids personal or organizational accusation.
Sources I open
What I can and cannot say
The IP/ASN has visible reputation and hosting context; this does not identify an actor by itself.
Move to evidence notesSources
AlienVault OTX
Threat intelligence
Open threat exchange for pulses, indicators, and community threat intelligence.
Open sourceAwesome Threat Intelligence
Threat intelligence
A broad GitHub list of threat-intelligence datasets, tools, platforms, and learning resources.
Open sourceGreyNoise Visualizer
IP and ASN intelligence
Noise and internet scanning context for IP addresses.
Open sourceHurricane Electric BGP Toolkit
IP and ASN intelligence
BGP and ASN lookup portal with peer, prefix, and DNS information.
Open sourceIntelOwl
Threat intelligence
Enriches IP, domain, URL, hash, and file indicators across multiple analyzers and threat-intelligence sources.
Open sourceIPinfo
IP and ASN intelligence
IP intelligence platform with geolocation, ASN, privacy, and company fields.
Open source