• Last Updated
    Jul 7, 2026
  • Version
    1.0.0
  • Compatibility
    ThreatQ Versions >= 5.12.1
  • AbuseIPDB Action

    ThreatQuotient

    Overview

    The AbuseIPDB Action for ThreatQ enables users to automate reputation lookups for IP address indicators against AbuseIPDB’s community-driven threat intelligence database. The action retrieves abuse reporting, categorization, and geolocation context for each IP address and ingests the results into ThreatQ to support enrichment and investigation workflows.

    The integration provides the following action:

    • AbuseIPDB - Check IPs - queries AbuseIPDB for supported IP addresses and returns reputation data, abuse reports, and related contextual information to enrich ThreatQ indicators.

    The integration is compatible with IP Address type indicators

    The integration returns the following enriched indicator types:

    • FQDN
    • IP Address

    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

    Copyright © 2026, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy