
Oct 1, 2024
1.0.0
ThreatQ versions >= 4.35.0
MaxMind Geolocate Operation
Overview
The MaxMind Geolocate Operation for ThreatQ enables analysts to fetch geolocation information from a MaxMind database or the web API.
The operation provides the following actions:
- Lookup - performs a Geolocation lookup for the given IP Address.
- Lookup All Related IPS - performs a look up of related IPs and adds the results to the description.
The operation is compatible with the following system objects:
- Files (Attachments)
- Indicators:
- IP Address
- IPv6 Address