What does an IP address in a threat-intelligence or reputation report prove?¶
It proves that the reporting source applied a label to the address using its own observations, feeds or scoring rules. It does not automatically prove that the address, current user or event was malicious.
The short version¶
A reputation report is dated intelligence about infrastructure, not identity evidence.
Read the basis¶
Find out:
- when the address was observed;
- what behaviour triggered the label;
- whether the source saw packets, completed sessions or third-party reports;
- the confidence and update date; and
- whether other products repeat the same underlying feed.
Addresses can be shared, reassigned, compromised or used by VPN and hosting customers. A reputation created by one user may later attach to another.
Use it proportionately¶
Use the report to prioritise enquiries and seek underlying observations where it matters. Describe who classified the address, the category, date and basis.
The service classified this address as associated with scanning activity on the date shown. The report does not by itself establish that the present event or user was responsible.
The point to remember
Reputation is a line of enquiry about past infrastructure behaviour. It is not proof of intent, identity or responsibility for the event under investigation.