Quick Threat Scan

Your everyday first check. Drop in any indicator and get a fast, honest read: is this known-bad, how bad, and who says so. You see the reputation call, the abuse lists that name it, and what the target actually is — so a well-known service reads as recognised rather than just unlisted, and 'nothing found' never gets mistaken for 'safe.' Built for the check you run dozens of times a day before deciding whether anything deserves a deeper look.

How it uses the graph

Traverses the threat-intel layer of the graph, in 7 steps:

How it walks the graph7 steps
01Threat Assessment

Computing the threat verdict…

threat-intel
02Abuse feeds naming this indicator

Abuse feeds naming this indicator…

threat-intel
03IP threat category flags

IP threat category flags…

threat-intel
04ASN network reputation

ASN network reputation…

threat-intel
05Host vendor identity

Host vendor identity…

threat-intel
06Coverage-qualified verdict

Coverage-qualified verdict…

threat-intel
07Structural context (nearest vendors + siblings)

Structural context (nearest vendors + siblings)…

threat-intel

Why each step runs

  1. 01Threat Assessment. Returns a single composite threat assessment with its scoring rationale.
  2. 02Abuse feeds naming this indicator. Lists exactly which abuse/threat feeds name this domain or IP (excluding benign popularity lists), so the verdict is traceable to real sources.
  3. 03IP threat category flags. For an IP input, shows every threat category it is flagged for at a glance (Tor, C2, malware, phishing, anonymizer, spam, bruteforce, scanner).
  4. 04ASN network reputation. For an ASN input, summarizes the network's reputation derived from its hosted address space (max/avg score, overall level, whether it announces threatening prefixes).
  5. 05Host vendor identity. Identifies what a host actually is — its vendor, canonical name, category, and roles — for fast attribution; 0 rows means no atlas match, not an error.
  6. 06Coverage-qualified verdict. Returns a coverage-qualified suspicion band and label (malicious / benign-allowlisted / etc.) plus the signals behind it — the anti-false-positive primitive that distinguishes known-clean from no-data.
  7. 07Structural context (nearest vendors + siblings). When identify has no direct match, gives structural context — nearest known vendors and sibling hosts — so a novel host is not misread as clean.