ip-investigation

Aggregate threat intel from multiple sources to assess IP risk.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill ip-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ip-investigation
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/ip-investigation
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill ip-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Aggregates data from VirusTotal, Shodan, AbuseIPDB, GreyNoise, OTX, and optional Censys to deliver a unified risk assessment for an IP address.

Core Features & Use Cases

  • Parallel, multi-source lookups to quickly assemble evidence about an IP's reputation and infrastructure.
  • Consolidated verdict with prioritized follow-up IOCs and actionable next steps for incident response.
  • Composable within larger CTI workflows; can be invoked by other skills to enrich indicators.

Quick Start

Ask Claude Code to investigate an IP address and generate a consolidated risk report.

Frequently Asked Questions about ip-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate a suspicious IP address for threat intelligence?

IP investigation handles both IPv4 and IPv6 addresses, aggregating data from multiple threat intel sources to assess risk and deliver a structured verdict with actionable next steps for incident response.

Does this IP investigation skill support IPv6 alongside IPv4?

Yes, the IP investigation skill fully supports both IPv4 and IPv6 addresses, orchestrating parallel lookups across multiple threat intel sources to handle benign and malicious indicators alike.

What data sources are used for IP enrichment and incident response?

IP enrichment aggregates data from VirusTotal, Shodan, AbuseIPDB, GreyNoise, OTX, and optional Censys to deliver a unified risk assessment and consolidate evidence about an IP's reputation and infrastructure.

Can other skills invoke this IP lookup tool for OSINT enrichment?

Other skills can invoke this IP investigation tool to enrich indicators within larger CTI workflows, receiving a prioritized list of follow-up IOCs and a structured risk verdict for incident response.

How do I prioritize follow-up IOCs when triaging a malicious IP address?

When triaging a malicious IP address, the skill consolidates multi-source lookup results and prioritizes follow-up IOCs into a structured risk verdict, providing actionable next steps for incident response.

What is the best way to assess an IP's reputation and infrastructure exposure?

The best way to assess an IP's reputation and infrastructure exposure is through parallel multi-source lookups, which quickly assemble evidence across threat intel platforms to generate a consolidated risk profile.