Liberty91

AbuseIPDB module.

Last updated 10 Aug 20264 min read

AbuseIPDB enriches your organization's IP IOCs with community abuse reports and confidence scores. Where a vendor feed tells you what one company has seen, AbuseIPDB tells you how many separate operators have reported an address and how strongly, which is a useful second opinion on an address you are already suspicious of. It is a bring-your-own-key integration: create an AbuseIPDB account, generate an API key, and paste it into the module once for the whole billing account. Every new IP indicator that arrives after that is looked up automatically.

Before you start

You need an AbuseIPDB account and an API key generated from it. The key is the only thing this module asks for.

How to connect AbuseIPDB

  1. Sign in to AbuseIPDB, or create an account if you do not have one, and generate an API key.
  2. In Liberty91, go to Modules, open the Analysis Modules section, and click the AbuseIPDB tile.
  3. Paste the key into the API key field.
  4. Turn on Active and click update.

Checking the connection

There is no separate Test button, because saving is the health check. When you save, Liberty91 calls AbuseIPDB with the key you pasted and reports what came back. A green Connected banner means the credential works, and a red banner means it does not. If you leave the page and return later, a blue Status banner shows the result of the last save rather than re-testing.

MessageWhat it means
API key validatedThe key works and the module is ready to enrich
Invalid API keyAbuseIPDB rejected the key. Generate a new one and paste it again
AbuseIPDB rate limit reached, try again laterYour AbuseIPDB plan is out of requests for the moment. Nothing is wrong with the key
Could not reach AbuseIPDBLiberty91 got no response at all, usually a transient network problem
AbuseIPDB returned HTTP <code>AbuseIPDB answered with something unexpected, and the code says what
Note

Leave the API key field blank when you save and the stored key is kept. That is how you turn Active off and on again without retyping it. Keys are encrypted at rest and never sent back to the browser, so the field looks empty even when a key is stored.

The module also shows IOCs enriched as a running total, which is the quickest way to confirm that indicators really are being processed.

What you get from AbuseIPDB enrichment

Every IP indicator that arrives after the key is saved is looked up, and the abuse confidence AbuseIPDB reports becomes one of the four verdicts used across the platform, together with a score from 0 to 100.

Abuse confidenceVerdict
75% or aboveMalicious
15% or above, but below 75%Suspicious
Below 15%Unknown
Note

A low abuse confidence produces Unknown, never Benign, and that is deliberate. Too few reports to say anything about an address is a different claim from the address being known good. Do not build allow-listing on Unknown. The same rule applies to Censys, and both are covered on IOC enrichment and decay scoring.

In the platform you see an AbuseIPDB chip on the indicator's row and in its panel, showing the confidence percentage and then the number of reports behind it, so you can tell a single complaint apart from a sustained pattern. In an IOC CSV export, ABUSEIPDB appears in the enrichment_providers column, and over the API the same value comes back in the enrichment_providers and enrichments fields on the IOC endpoints, where you can also filter for it with ?enrichment_provider=ABUSEIPDB.

Permissions and limits

Any member of the billing account can configure this module. There is no Owner or Admin gate on it, unlike the ransomware domain alerts, which are restricted.

  • One key per billing account, shared by everyone on it.
  • Saving is rate-limited to 12 attempts a minute per user, so repeated retries pause briefly.
  • Enrichment runs in batches of up to 100 indicators.

Frequently asked questions

Which indicators does AbuseIPDB enrich?

IP addresses only. Domains, URLs, and hashes are left alone: AbuseIPDB adds no chip and no verdict to them.

Why does a low abuse confidence come back as Unknown rather than Benign?

Because a low confidence means there are too few reports to say anything about the address, not that the address is known to be good. Those are different claims, and only one of them is safe to build an allow-list on.

Do I have to retype the key to turn the module off and on?

No. Leave the API key field blank when you save and the stored key is kept, so you can flip Active off or on without it.

Was this page helpful?