Quick Threat Scan
Your everyday first check. Drop in any indicator and get a fast, honest read: is this known-bad, how bad, and who says so. You see the reputation call, the abuse lists that name it, and what the target actually is — so a well-known service reads as recognised rather than just unlisted, and 'nothing found' never gets mistaken for 'safe.' Built for the check you run dozens of times a day before deciding whether anything deserves a deeper look.
How it uses the graph
Traverses the threat-intel layer of the graph, in 7 steps:
How it walks the graph7 steps
01Threat Assessment
Computing the threat verdict…
threat-intel
02Abuse feeds naming this indicator
Abuse feeds naming this indicator…
threat-intel
03IP threat category flags
IP threat category flags…
threat-intel
04ASN network reputation
ASN network reputation…
threat-intel
05Host vendor identity
Host vendor identity…
threat-intel
06Coverage-qualified verdict
Coverage-qualified verdict…
threat-intel
07Structural context (nearest vendors + siblings)
Structural context (nearest vendors + siblings)…
threat-intel
Why each step runs
- 01Threat Assessment. Returns a single composite threat assessment with its scoring rationale.
- 02Abuse feeds naming this indicator. Lists exactly which abuse/threat feeds name this domain or IP (excluding benign popularity lists), so the verdict is traceable to real sources.
- 03IP threat category flags. For an IP input, shows every threat category it is flagged for at a glance (Tor, C2, malware, phishing, anonymizer, spam, bruteforce, scanner).
- 04ASN network reputation. For an ASN input, summarizes the network's reputation derived from its hosted address space (max/avg score, overall level, whether it announces threatening prefixes).
- 05Host vendor identity. Identifies what a host actually is — its vendor, canonical name, category, and roles — for fast attribution; 0 rows means no atlas match, not an error.
- 06Coverage-qualified verdict. Returns a coverage-qualified suspicion band and label (malicious / benign-allowlisted / etc.) plus the signals behind it — the anti-false-positive primitive that distinguishes known-clean from no-data.
- 07Structural context (nearest vendors + siblings). When identify has no direct match, gives structural context — nearest known vendors and sibling hosts — so a novel host is not misread as clean.