AbuseIPDB 1.2.3
  • 03 Apr 2025
  • 3 Minutes to read
  • Dark
    Light
  • PDF

AbuseIPDB 1.2.3

  • Dark
    Light
  • PDF

Article summary

AbuseIPDB - 1.2.3

tags: python | Enrichment | IP Reputation | IP GeoLocation Maps | Adaptive Cards


Table of Contents


Description

Integration with AbuseIPDB is created to support CDC users by providing enrichments for specific IP addresses. This is done to determine if it is identified to be engaged in any malicious activities such as abusive usage, hacking, spam, etc. - which enable CDC users to make informed decisions regarding incident response.

AbuseIPDB helps make the web safer by providing a central repository for webmasters, system administrators, and other interested parties to identify IP addresses that have been associated with malicious activity online.

CyberProof uses custom adaptive cards to display large amounts of threat data in a meaningful and intuitive GUI, to facilitate easy understanding of complex enriched data about a particular IP.

Integration Type:Threat Intelligence Enrichment
Information read:IP Address reputation
API Supported:API V2
Input:IP Address to be enriched
Output:Details enriched information about IP provided in Input
Classification:Public

CDC Command Lines

enrich_ip_cli - Get information from AbuseIPDB about certain IPs.

OptionTypeDescriptionRequired
metadataobjectcommand metadataTrue
ipstringThe IP address should be v4 or v6.True

enrich_range_ips_cli - Get information from AbuseIPDB about a certain network.

OptionTypeDescriptionRequired
metadataobjectcommand metadataTrue
networkstringThe IP address to enrich as CIDR format.True

report_ip_cli - Report an IP in AbuseIPDB.

OptionTypeDescriptionRequired
metadataobjectcommand metadataTrue
ipstringThe IP address should be v4 or v6.True
categorystringA string of comma separated malware categories.True
commentstringThe reason to report this IP in free text.True

Workflows

post_enrich_ip - Post enrich-ip in CDC by ID of incident/message/chanel.

OptionTypeDescriptionRequired
cdc_instance_namestringThe configuration key name of the CDC environment.True
incident_idstringThe incident ID in CDC.False
channel_idstringThe channel ID in CDC.False
message_idstringThe message ID in CDC.False
default_error_messagestringThe message that will be posted when the action failed.False
instance_namestringThe configuration key name of the pack.False
ipstringThe IP address should be v4 or v6.True
max_age_in_daysintegerParameter to only return reports within the last x amount of days. !@Deprecated will be removed in v2.0.0@!.False

post_enrich_range_ips - Post enrich-range-ips in CDC by ID of incident/message/chanel.

OptionTypeDescriptionRequired
cdc_instance_namestringThe configuration key name of the CDC environment.True
incident_idstringThe incident ID in CDC.False
channel_idstringThe channel ID in CDC.False
message_idstringThe message ID in CDC.False
default_error_messagestringThe message that will be posted when the action failed.False
instance_namestringThe configuration key name of the pack.False
networkstringThe IP address to enrich as CIDR format.True
max_age_in_daysintegerParameter to only return reports within the last x amount of days.False

post_report_ip - Post report-ip in CDC by ID of incident/message/chanel.

OptionTypeDescriptionRequired
cdc_instance_namestringThe configuration key name of the CDC environment.True
incident_idstringThe incident ID in CDC.False
channel_idstringThe channel ID in CDC.False
message_idstringThe message ID in CDC.False
default_error_messagestringThe message that will be posted when the action failed.False
instance_namestringThe configuration key name of the pack.False
ipstringThe IP address should be v4 or v6.True
categorystringA string of comma separated malware categories.True
commentstringThe reason to report this IP in free text.True

Rules

No rules


Sensors

No sensors


Triggers

No triggers


Known Issues

No issues


Was this article helpful?

What's Next