
Jul 7, 2026
1.0.0
ThreatQ Versions >= 5.12.1
AbuseIPDB Action
Overview
The AbuseIPDB Action for ThreatQ enables users to automate reputation lookups for IP address indicators against AbuseIPDB’s community-driven threat intelligence database. The action retrieves abuse reporting, categorization, and geolocation context for each IP address and ingests the results into ThreatQ to support enrichment and investigation workflows.
The integration provides the following action:
- AbuseIPDB - Check IPs - queries AbuseIPDB for supported IP addresses and returns reputation data, abuse reports, and related contextual information to enrich ThreatQ indicators.
The integration is compatible with IP Address type indicators
The integration returns the following enriched indicator types:
- FQDN
- IP Address
Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.