Thanks to visit codestin.com
Credit goes to github.com

Skip to content
Mike Goffin edited this page Jun 4, 2014 · 1 revision

The IPs collection is a way to track IP addresses that are of interest. In most cases these will be IPs that:

  • are related to Domains you are tracking.
  • were obtained through Analysis of a binary.
  • were found in a PCAP containing malicious activity.
  • were derived from Emails.
  • were teased out of Raw Data.
  • were added as Indicators.

You can also assign what type of IP address it is.

Using relationships you can see what these IPs were related to over time. It allows you to discover domains that might have used the same IP at different times which could relate two different Domains to each other.

Clone this wiki locally