Skip to content

IP Reputation

The IP Reputation module provides reputation scoring and intelligence for IP addresses associated with your external infrastructure. It checks your IPs against multiple threat intelligence sources to identify addresses that may be blacklisted, flagged for abuse, or associated with malicious activity.

Overview

IP Reputation

The page displays IP reputation findings in a scrollable table with column headers for IP Address, Port, Flagged By, Country Code, and Bot Name. The table supports progressive loading as you scroll, with dynamic search filters at the top.

Table Columns

ColumnDescription
IP AddressThe IP address that was flagged by one or more threat intelligence sources
PortThe specific port associated with the flagged activity, if applicable
Flagged ByThe threat intelligence source(s) that reported the IP. Shown as badges indicating which databases or blacklists contain the IP
Country CodeGeographic location of the IP address
Bot NameIf the IP was flagged as part of a botnet, the associated bot or malware family name
ActionsComment on findings and mark as false positive

Connection to IP Addresses Module

IP Reputation findings are linked to your IP Addresses inventory. When an IP in your asset inventory appears on a threat intelligence blacklist, it surfaces here as a reputation finding. This connection helps you:

  • Identify which of YOUR IPs have been flagged (not just random IPs on the internet)
  • Correlate reputation issues with specific services and ports you are running
  • Track remediation progress as you resolve the underlying issues causing blacklisting

The dynamic search filter panel supports filtering by:

  • IP Address -- Search for a specific IP
  • Port -- Filter by port number
  • Flagged By -- Filter by threat intelligence source
  • Country Code -- Filter by geographic location
  • Risk -- Filter by severity level
  • SLA status -- Filter by SLA violation state

Filters use AND logic. An export function is available to download all matching results.

Available Actions

ActionDescription
CommentAdd internal notes to a finding for team coordination
Mark as False PositiveFlag a finding as a false positive to remove it from the active view
Remove from False PositiveRestore a previously marked false positive (available in the false positive view)
ExportDownload matching findings for reporting

Common Causes of IP Reputation Issues

  • Compromised servers sending spam or participating in DDoS attacks
  • Open relays or proxies being abused by third parties
  • Shared hosting where another tenant's malicious activity taints the IP
  • Historical activity from a previous IP owner that was not cleaned up
  • Misconfigured services generating traffic patterns that resemble malicious behavior
  1. Review flagged IPs to determine if the reputation issue is legitimate or a false positive
  2. Check which services are running on flagged ports and whether they are properly secured
  3. Cross-reference with your IP Addresses inventory to understand the asset's importance
  4. Remediate the underlying issue (patch, reconfigure, or decommission the service)
  5. Request delisting from the relevant blacklists after remediation
  6. Mark false positives for shared hosting or historical issues outside your control

ShadowMap by Security Brigade