IP Address Investigation.
/ip-investigation
IP address investigation is the everyday job of working out whether an address is hostile, noisy or benign, and what it connects to. This free, open-source skill runs inside your AI coding agent and enriches any IPv4 or IPv6 address by querying several threat-intel sources at once. It is built for SOC analysts and CTI practitioners who want one consolidated answer instead of ten browser tabs.
What it does.
It queries VirusTotal, Shodan, AbuseIPDB, GreyNoise and OTX in parallel, with Censys as an optional source, then consolidates the findings into a single readable summary. It also classifies scanner noise so you can tell mass-internet scanning apart from targeted activity.
When to use it.
Reach for it during SOC triage when an IP turns up in an alert, a firewall log or a phishing header and you need a verdict quickly. It is equally useful for CTI work when you are expanding an investigation and want to know whether an address is already known to the community.
What you get back.
You get a reputation verdict, open ports and running services, abuse-report history, a scanner-noise classification, and a prioritised list of pivot candidates such as resolving domains or related infrastructure to follow next.
How it fits your workflow.
Run it from Claude Code, Cursor, Codex or Windsurf with a single command. Free API tiers are enough to get started, and the skill degrades gracefully when a key is missing, so you still get results from whatever sources you have configured.
Keep going.
- Domain investigation, the same workflow for domains→
- Shodan lookup for ports, services and exposure→
- How IOC enrichment and decay scoring work→
- Source reliability and confidence scoring→
- Browse all 75 open-source CTI Skills →
- How Liberty91 speeds up analyst work →
- Start for Free, the free tier is coming →
Frequently Asked Questions.
Want to see this on your own organisation?
Request a demo or start your free trial today, and get straight to AI-powered threat intelligence built around your organisation.