• Last Updated
    May 26, 2026
  • Version
    1.1.0
  • Compatibility
    ThreatQ Versions >= 5.6.0
  • Criminal IP Action Bundle

    ThreatQuotient

    Overview

    The Criminal IP Action integration enables analysts to enrich IP Address and FQDN indicators with contextual intelligence from the Criminal IP platform. By leveraging Criminal IP’s intelligence data, including malicious activity assessments, open ports, vulnerabilities, WHOIS information, and domain reporting context, the integration helps analysts gain additional visibility into potentially malicious infrastructure and supports more informed threat analysis and investigation workflows.

    The integration provides the following actions:

    • Criminal IP - Get Malicious Info - queries the Criminal IP API to enrich an IP Address with intelligence indicating whether the indicator is malicious, along with additional contextual data used to support the assessment of the IOC.
    • Criminal IP - Get Domain Reports - utilizes the Criminal IP API to enrich an FQDN with domain report context.

    The integration is compatible with and returns enriched IP Address and FQDN type indicators.

    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

    Copyright © 2026, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy