Enriching Data with AbuseIPDB
AbuseIPDB provides a central list for web administrators, system administrators, and other stakeholders to report and reference IP addresses associated with malicious activity.
When activated, the AbuseIPDB enrichment enables you to leverage AbuseIPDB data on IP observables from observable details pages in ThreatStream.
ThreatStream consumes and displays the following information from AbuseIPDB:
- Summary Information (Abuse Confidence Score, Is in Exclude List, Total Reports in Last 365 Days, Last Reported)
- Individual Reports
- Geo Information
You must have an API Key from AbuseIPDB in order to activate this enrichment.
To activate the AbuseIPDB enrichment:
-
Navigate to ThreatStream > APP STORE > APP Store.
- Click Get Access on the AbuseIPDB tile.
- Click I have credentials.
- Enter your AbuseIPDB API Key.
- Click Activate.
The AbuseIPDB enrichment is now active.
-
To learn more about the AbuseIPDB public API, visit https://docs.abuseipdb.com/#introduction
-
The AbuseIPDB public API imposes the following daily quotas: 1,000 IP checks and reports, 100 IP block checks, and 100 exclude list checks.