The ThreatBook CTI Research module provides a platform for querying and analyzing IP and domain intelligence. Users can retrieve information such as verdicts, threat labels, historical activity, and various metadata related to an address.
Each queried IP or domain receives a verdict indicating its security status:
Malicious – Associated with known threats or attacks.
Suspicious – Exhibits behavior that may indicate risk.
Benign – No detected malicious activity.
Unknown – Insufficient data available.
The verdict is determined based on rule-based detection.Also, ThreatBook CTI integrates well-known external intelligence providers to enhance accuracy like VirusTotal, Greynoise and urlscan, etc. Users can configure third-party API keys in the Integration settings to unlock additional verdicts and enrich their analysis with external intelligence sources.
Currently, ThreatBook CTI Research is accessible through:
Web Interface – Users can perform manual searches via the platform.
API Integration – Support for automated queries.
Feeds (Coming Soon) – Continuous intelligence updates for external integration.
These options provide flexibility in how intelligence is accessed and utilized.Get Started with ThreatBook CTI Research
Start searching now at https://threatbook.io/research .For additional details, please contact us.