IP Addresses & Networks¶
78 investigator questions.
Use the list below or search the complete library.
- I’ve been told the offender came from an IP address. What do I do now?
- What is an IP address?
- What is the difference between a static and dynamic IP address?
- Where did this IP address come from?
- Do you have the original record?
- What could the recording system actually see?
- What event did the system actually record?
- What can DHCP, router and Wi-Fi records show about a local device?
- Can a source IP address be spoofed?
- What information should come with an IP address?
- What does a successful login record actually prove?
- What does a failed login or login attempt actually prove?
- What does a connection or session record actually prove?
- What is the difference between TCP and UDP?
- Does the same IP across several events mean the events are connected?
- What is a source port and when do I need it?
- Why can’t a provider identify one customer from some public IP addresses?
- What does an ISP subscriber result actually establish?
- What date, time and time zone does this timestamp represent?
- Can I trust the timestamp and the system clock?
- The record contains several IP addresses—which one matters?
- Is this actually a valid and complete IP address?
- What can an ordinary IP lookup actually tell me?
- What is DNS?
- What happens when a device looks up a domain name?
- What is the difference between a DNS resolver and an authoritative DNS server?
- What do DNS A and AAAA records show?
- Why can one domain name resolve to several IP addresses?
- Can several domain names use the same IP address?
- What is DNS caching, and why can an old answer remain visible?
- What can reverse DNS tell me about an IP address?
- I have a destination IP address. Can I tell which website was visited?
- Does a DNS query prove that somebody visited a website?
- What can DNS query logs actually show?
- What does NAT do to the address a service sees?
- What does a VPN do to the IP address a service sees?
- The IP belongs to a VPN provider—what do I do next?
- Does an IP address identify a particular device?
- The IP belongs to a home or business ISP—what does that mean?
- The IP belongs to a mobile network—what changes?
- The IP belongs to a workplace, school or other organisation—what changes?
- The IP belongs to a hotel, café or public Wi-Fi service—what changes?
- What does a proxy do to the IP address a service sees?
- What does Tor do to the IP address a service sees?
- The IP belongs to cloud hosting, a VPS or a data centre—what does that mean?
- What can WHOIS and RDAP tell me about an IP address?
- How accurate is IP geolocation?
- Who operates or announces this IP address?
- Does the current operator necessarily control the address at the event time?
- How reliable are VPN, proxy, hosting and Tor classifications?
- Who is likely to hold the useful records?
- What records might exist for this type of infrastructure?
- What should be preserved before relevant records disappear?
- What information must accompany an ISP subscriber request?
- What information is needed for a mobile or CGNAT request?
- What does an account-holder result actually establish?
- How do I move from a connection to a device, user and responsible person?
- Is this a system record, an alert, an intelligence report or somebody’s summary?
- What is a port?
- What is a firewall and what does it actually do?
- What does a firewall log actually show?
- What does “allowed” mean in a firewall log?
- What do “blocked”, “denied” and “dropped” mean in a firewall log?
- Does the record identify one event or a sequence of related events?
- Why might a CDN, reverse proxy or load balancer appear instead of the original source?
- What does an IP address in a threat-intelligence or reputation report prove?
- Can the IP link this event to earlier intelligence or other cases?
- What should I request from a hotel or public Wi-Fi operator?
- What changes when there is an immediate safeguarding risk?
- Is the proposed enquiry necessary and proportionate?
- What can an IP address in an email header actually represent?
- What are loopback, link-local and other special-purpose addresses?
- What can traceroute show about the path to an IP address?
- What does /24 or /64 after an IP address mean?
- What does pinging an IP address actually prove?
- What is a MAC address, and how is it different from an IP address?
- What is an ASN, and what does it identify?
- Why might one IPv6 device use several different addresses?