Skip to content

Commit 6fb78d3

Browse files
committed
add ipdex in CTI getting started
1 parent 79a87ce commit 6fb78d3

File tree

1 file changed

+65
-0
lines changed

1 file changed

+65
-0
lines changed

crowdsec-docs/unversioned/cti_api/getting_started.mdx

Lines changed: 65 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,8 @@ On the next page you can create an API key by clicking the `+ New Key` button.
4848

4949
## Accessing the API
5050

51+
### cURL
52+
5153
You can test your newly created API key by running the following command in your terminal:
5254

5355
:::info
@@ -216,6 +218,69 @@ And the default output looks something like this:
216218

217219
</details>
218220

221+
### ipdex
222+
223+
You can interact with the CrowdSec CTI API with the [`ipdex`](https://github.com/crowdsecurity/ipdex) tool.
224+
225+
First, initiliaze the tool with your API key:
226+
227+
```console
228+
ipdex init
229+
```
230+
231+
And then analyze an IP or a file of IPs:
232+
233+
```console
234+
ipdex 193.105.134.155
235+
```
236+
237+
<details>
238+
239+
<summary>Command Output</summary>
240+
241+
```console
242+
IP Information
243+
244+
IP 193.105.134.155
245+
Reputation malicious
246+
Confidence high
247+
Country SE 🇸🇪
248+
Autonomous System w1n ltd
249+
Reverse DNS N/A
250+
Range 193.105.134.0/24
251+
First Seen 2023-06-23T01:15:00
252+
Last Seen 2025-05-11T11:15:00
253+
Console URL https://app.crowdsec.net/cti/193.105.134.155
254+
Last Local Refresh 2025-05-12 16:44:21
255+
256+
Threat Information
257+
258+
Behaviors
259+
HTTP Scan
260+
HTTP Bruteforce
261+
SSH Bruteforce
262+
... and 2 more
263+
264+
265+
Classifications
266+
Spoofed User Agent
267+
TOR exit node
268+
VPN or Proxy
269+
... and 1 more
270+
271+
272+
Blocklists
273+
Extended AI-Detected VPN/Proxy
274+
CrowdSec Intelligence Blocklist
275+
276+
Target countries
277+
🇺🇸 US 29%
278+
🇩🇪 DE 15%
279+
🇵🇱 PL 12%
280+
... and 2 more
281+
```
282+
</details>
283+
219284
<AcademyPromo
220285
image="crowdsec_threat_intelligence.svg"
221286
description="Watch a short series of videos on how to get the most out of CrowdSec’s Cyber Threat Intelligence database"

0 commit comments

Comments
 (0)