IOC Lookup
Check IPs, domains, URLs, and file hashes against 40+ threat intelligence feeds. Get a verdict with MITRE context in seconds.
- Queries 40+ feeds including Abuse.ch, Spamhaus, OTX, and VirusTotal
- ManySignal Global TI feed updated every 15 minutes
- Confidence score from 0–100 with feed-level detail
- MITRE ATT&CK technique mapping for each verdict
MITRE ATT&CK
T1090.003 — Proxy: Multi-hop Proxy
T1071.001 — Application Layer Protocol: HTTP
How this tool works
Enter an IP, domain, or file hash
Paste a single indicator or a comma-separated list of up to 10 IOCs per lookup. Supports IPv4, IPv6, domain names, URLs, MD5, SHA1, and SHA256 hashes.
Select your threat intelligence feeds
Choose from public feeds (Abuse.ch, Spamhaus, OTX, VirusTotal) and the ManySignal Global Threat Intelligence feed updated every 15 minutes.
Review the verdict and context
The result shows a confidence score, all matching feeds, associated malware families, MITRE techniques, and last-seen timestamp for each feed.
What to do with the result
Pivot into your SIEM
Take a confirmed malicious IP or domain and search it across your log sources for historical contact.
Add to your blocklist
Export confirmed IOCs in STIX 2.1, CSV, or plain text format for import into your firewall, proxy, or EDR blocklist.
Create a detection rule
Use the IOC as the basis for a detection rule — the converter can generate a Sigma-format rule from a list of IPs or domains.
IOC lookup: frequently asked questions
Which threat intelligence feeds does the lookup use?
The free tool queries public feeds including Abuse.ch (Feodotracker, URLhaus, MalwareBazaar), Spamhaus DROP/EDROP, AlienVault OTX, and the ManySignal Global Threat Intelligence feed — a curated, deduplicated feed from 40+ sources updated every 15 minutes.
Is VirusTotal included?
VirusTotal file and URL lookups are included via the public API (limited to 4 lookups per minute). Hash lookups use the VirusTotal file report endpoint and show detection ratios across 70+ antivirus engines.
How fresh is the threat intelligence data?
The ManySignal Global TI feed is updated every 15 minutes. Public feed data varies by source — Abuse.ch updates hourly, Spamhaus updates daily, OTX updates in near real time for contributed IOCs.
Can I look up private IP addresses?
RFC 1918 private addresses and loopback ranges return a 'Private / Non-routable' verdict rather than querying public feeds. These are not sent to external services.
What does a 'confidence' score of 94 mean?
Confidence reflects the number of independent feeds reporting the indicator, the recency of the reports, and the reputation score of each feed. 90+ indicates broad consensus across multiple high-reliability feeds. 60-89 indicates corroboration but warrants manual review.
Can I bulk-check a list of IOCs from an incident report?
The free tool supports up to 10 IOCs per lookup. For bulk lookups of 100+ IOCs from a threat report or incident, the ManySignal platform API supports batch enrichment with results returned in under 2 seconds. Contact us to access the API.
Are my lookups stored or shared?
Individual lookups in the free tool are not stored or attributed. Aggregate, anonymised IOC query statistics are used to improve feed prioritisation. No PII or customer-identifiable data is collected.
What should I do if I get a false positive verdict?
If you believe an indicator has been incorrectly flagged, you can submit a false positive report directly from the result page. ManySignal's TI team reviews submissions within 24 hours and propagates corrections to all subscribers.
Enrich every alert with threat intelligence automatically
ManySignal enriches every alert with IOC lookups, entity graph context, and threat intel — before the triage agent even starts.