IP Threat Intelligence

Insights from threat intelligence platforms about IP Addresses

Attributes

CaptionNameTypeDescription
ASN asn Integer The 2- or 4-byte Autonomous System Number (ASN)
AS Owner asn_owner String The Autonomous System (AS) owner
Details details String Details about the IP address.
Findings findings Finding[] The findings from threat intelligence platforms
IP Address ip IP Address The IP address, in either IPv4 or IPv6 format.
Labels labels String[] The labels or tags in the intelligence.
Geo Location location Geo Location[] The detailed geographical location usually associated with an IP address.
Raw Data raw_data JSON The event data as received from the event source.
Record ID record_id String Unique identifier for the object
Additional references for more information. references String[] A list of reference URLs supporting the finding/detection.
Reputations reputations Reputation[] Reputation score as reported by provider
Subnet subnet Subnet The subnet mask.
Unmapped Data unmapped Unmapped[] The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source.
Vendor Name vendor_name String The vendor that provided the intelligence.

Relationships

IP Threat Intelligence shown in context

Inbound Relationships

These objects and events reference IP Threat Intelligence in their attributes:

Outbound Relationships

IP Threat Intelligence references the following objects and events in its attributes:

This page describes qdm-1.3.2+ocsf-1.3.0