Analyst resources

Useful tools for IP, URL and infrastructure context.

IPContext is designed to complement the wider security research ecosystem. These services are useful starting points when investigating infrastructure, files, domains, URLs and public internet activity.

VT

VirusTotal

Useful for file, domain, URL and IP enrichment, especially when historical detections and vendor context are needed.

US

urlscan.io

Useful for analysing how a URL behaves in a browser, including redirects, contacted domains, screenshots and page metadata.

SH

Shodan

Useful for understanding exposed services, banners and internet-wide scanning results for public infrastructure.

AB

AbuseIPDB

Useful for community reports around abuse activity, especially when compared carefully against freshness and evidence quality.

C

Censys

Useful for internet asset discovery, certificate context and exposed service research.

RIPE

RIPEstat and registry data

Useful for ASN, routing, allocation and registration context when trying to understand network ownership and changes.

Suggest a resource

Help improve the list.

If you know a useful dataset, research project, public feed, measurement platform or methodology reference that would improve IP context, please suggest it for inclusion.

Future product areas

  • Country and industry-focused breakdowns for observed activity.
  • Feeds that distinguish benign internet measurement from more concerning behaviour.
  • Subnet alarm grouping to show whether neighbouring IPs are behaving similarly.
  • Expanded API and firehose access for teams building their own tools.
  • Historical domain and URL context alongside fresh IP observations.