• Last Updated
    Nov 5, 2024
  • Version
    1.0.1
  • Compatibility
    ThreatQ versions >= 4.56.0
  • Spur Operation

    ThreatQuotient

    Overview

    Spur tracks anonymization services so that you can identify when anonymization services are touching your website, application, or network.

    The Spur Operation allows analysts to perform quick context lookups for a given IP Address, bringing back anonymization information that can be used to determine if the IOC is a possible threat.

    The Get Context action enables the automatic enrichment of IP Addresses in ThreatQ, using Spur’s Context API. The API will tell you if the selected IOCs are used by anonymization services, as well as if the tunnels are used by a specific region, or used by a specific threat.

    The operation provides the following action:

    • Get Context - returns the context information collected by Spur about the selected IP.

    The operation is compatible with the following indicator types:

    • IP Address
    • IPv6 Address

    Copyright © 2025, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy