Skip to main content
Criminal IP TI Feed app icon

Criminal IP TI Feed

Match Criminal IP's threat intelligence feed against your firewall logs, with rolled-up Slack alerts carrying per-asset detail and SOC triage dashboards.Built by AI Spera Inc
splunk product badge

Default Version 1.0.1

August 28, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Criminal IP TI Feed matches Criminal IP's threat intelligence feed against your firewall traffic logs and shows which of your assets actually communicated with malicious IPs. šŸ”Ž The app: - Downloads the feed every 3 hours - Correlates it with FortiGate traffic logs (Palo Alto Networks PAN-OS and Cisco ASA/FTD via field-mapping macros) - Writes findings to a summary index - Sends rolled-up Slack alerts (a section per malicious IP and direction, with per-asset detail) - Ships SOC dashboards for triage: Overview, Investigate, All detections, IP lookup, Trends, Alerts and Health 🚨 Severity is grounded in what actually happened on the wire: contacts that never completed a session cannot exceed the watch tier, so critical means a session really opened. ā˜‘ļø Requires a Criminal IP TI Feed License (API Key) and self-managed Splunk Enterprise on Linux. šŸ”” A Slack incoming webhook is optional for alerting.