Combines geolocation, ASN, open ports, known CVEs, and hostnames from Shodan and ipapi.co.
Pulls from Shodan InternetDB and ipapi.co.
Queries IP geolocation and network data for any IPv4 or IPv6 address: country, region, city, ISP, ASN, organization, and whether the address belongs to a hosting provider, VPN service, or Tor exit node. Combines data from ipapi.co and Shodan InternetDB.
Shodan InternetDB data includes open ports and known CVEs associated with the IP, providing a quick view of the exposed attack surface for hosts you are investigating.
During incident response, IP data helps you quickly characterize an unknown source: is it a residential ISP, a cloud provider, a VPN exit node, or a known hosting range? An IP in a Ukrainian ASN connecting to your VPN at 3am is a different signal than one from your corporate ISP range.
In penetration testing scoping, IP lookup helps validate which assets are in scope and understand the hosting relationships behind target domains.