Using the portal

Using Q-Feeds Threat Lookup

Threat Lookup tells you whether an IP address, domain, URL or file hash is known to be malicious, and why. Use it to check something suspicious before you trust it.

Look up a single indicator

  1. Open the Threat Intelligence Portal and go to Threat Lookup in the menu.
  2. Enter what you want to check: an IP address, a domain, a URL or a file hash.
  3. Select Search.

Read the result

The result shows whether the indicator is known to Q-Feeds and gives context so you can decide what to do:

  • A verdict and a threat score that show how risky the indicator is.
  • The categories it matches, for example malware or phishing.
  • Extra context where available, such as geographic location and DNS or name server records.

The amount of detail depends on your license. The free Community package covers the essentials, while Plus and Premium show richer context.

Check many indicators at once

If you have a list to review, use the bulk option to check multiple indicators in one go instead of typing them one by one. This is handy when you are triaging log entries or an email of suspicious addresses.

View your history

Your recent lookups are kept so you can reopen an earlier result without searching again.

What next

Found something malicious? Add Q-Feeds to your firewall or SIEM so traffic like this is blocked automatically.

Get your threat feeds

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access