IP threat lookup
Look up an IP address, domain or URL and see a malicious score, the sources that flagged it and MITRE ATT&CK mapping. This is IOC context for analysts, not a check of whether your mail server is listed.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is Threat Lookup?
Threat Lookup is an indicator investigation tool that gives analysts instant context on any IP address, domain, URL or file hash. Enter an indicator and see a malicious score, the sources that flagged it and a full MITRE ATT&CK mapping, aggregated from more than 2,500 intelligence sources. The scoring combines every source into one clear verdict.
Instead of pivoting between tools, your SOC gets one view that explains why an indicator is malicious and how it fits the wider attack, cutting triage time and speeding decisions.
Threat Lookup is part of the Q-Feeds Threat Intelligence Portal and fits neatly into existing SOC and incident-response workflows.
Context that speeds up every investigation
Malicious score
High-risk indicators are flagged with a malicious score based on multiple feeds and recent activity.
MITRE ATT&CK mapping
Every indicator is mapped to tactics and techniques so you understand how it fits your investigation.
Multiple feeds
Curated from 2,500+ sources, so a single lookup reflects the full picture.
Built for SOC workflows
Feeds tell you that something is bad; Threat Lookup explains why and how it fits in your investigation.
More from the Threat Intelligence Portal
Frequently asked questions about Threat Lookup
What is Threat Lookup?
Threat Lookup is a tool to investigate indicators of compromise. You enter an IP, domain, URL or hash and instantly get context, a malicious score and MITRE ATT&CK mapping.
Which indicators can I look up?
You can look up IP addresses, domains, URLs and file hashes and see which feeds and sources flagged them as malicious.
What is the malicious score?
The malicious score summarises how many independent sources consider an indicator harmful, helping you prioritise real threats quickly.
Does it map to MITRE ATT&CK?
Yes. Every indicator is mapped to the relevant MITRE ATT&CK tactics and techniques, so you understand how it fits the broader attack.
How do I get started?
Start for free on the Q-Feeds Threat Intelligence Portal, then upgrade to Plus or Premium for deeper access and faster intelligence.
How do I check an IP reputation?
Enter any IP address, domain or URL in Threat Lookup to see its reputation, a malicious score and MITRE ATT&CK context drawn from our multi-source IOC database.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access