IP Threat Intelligence
Insights from threat intelligence platforms about IP Addresses
Attributes
Caption | Name | Type | Description |
---|---|---|---|
ASN | asn |
Integer | The 2- or 4-byte Autonomous System Number (ASN) |
AS Owner | asn_owner |
String | The Autonomous System (AS) owner |
Details | details |
String | Details about the IP address. |
Findings | findings |
Finding[] | The findings from threat intelligence platforms |
IP Address | ip |
IP Address | The IP address, in either IPv4 or IPv6 format. |
Labels | labels |
String[] | The labels or tags in the intelligence. |
Geo Location | location |
Geo Location[] | The detailed geographical location usually associated with an IP address. |
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
Additional references for more information. | references |
String[] | A list of reference URLs supporting the finding/detection. |
Reputations | reputations |
Reputation[] | Reputation score as reported by provider |
Subnet | subnet |
Subnet | The subnet mask. |
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Vendor Name | vendor_name |
String | The vendor that provided the intelligence. |
Relationships
Inbound Relationships
These objects and events reference IP Threat Intelligence in their attributes:
Outbound Relationships
IP Threat Intelligence references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated about 1 month ago