Free REST API powered by a global honeypot sensor network and community reports. Look up any IP for behavioral attack patterns, credential targeting, and a transparent confidence score. Protect your infrastructure with SikkerGuard firewall automation and Sikker-CLI — 1,000 free lookups per day.
IPv4, IPv6, or CIDR notation
Our distributed honeypot network runs high-interaction sensors across 17 protocols including SSH, HTTP, MySQL, PostgreSQL, FTP, SMTP, and Redis. Attackers interact with realistic environments while we capture IP threat intelligence — post-authentication behavior, command patterns, and tooling. Explore the full threat landscape.
Honeypot data is combined with community IP reports from Fail2Ban, CSF integrations, and security practitioners worldwide. Every IP reputation score is calculated from observable events — not opaque algorithms. See how scoring works.
Every IP lookup includes classified attack patterns — not just a score. See GPU reconnaissance campaigns, SSH key persistence, IoT botnet staging, and more, decomposed into named primitives and composed into behaviors with severity levels and match counts. Browse the detection catalog.
Automate IP blocking with iptables/ipset, Nginx, Fail2Ban, or CSF. Generate dynamic IP blacklists for your firewall, or report suspicious IPs to contribute back to the community threat intelligence database.