Skip to content
ThreatSTOP for AWS Blog

Not sure about a domain or IP? Check it here.

Paste in any domain, IP address, or indicator of compromise and we'll tell you whether ThreatSTOP flags it as malicious, what category it falls into, and why. It's the very same intelligence behind DNS Defense and IP Defense.

Check an indicator.

Enter any domain, IP address, or indicator of compromise below. This is the live Check IoC application, querying current ThreatSTOP intelligence.

Prefer a full window? Open Check IoC in a new tab.

Here's what happens when you check.

Whatever you enter gets checked against the same curated threat intelligence that powers DNS Defense and IP Defense.

It runs on a small sample set so you can try it without a live query. The full tool checks our complete intelligence database, updated around the clock.

YOUR INPUT DOMAIN OR IP CURATED INTELLIGENCE 900+ FEEDS 25M+ INDICATORS LISTED CLEAN
Whatever you enter is checked against the same curated intelligence that powers DNS Defense and IP Defense.

Three quick steps, that's it.

01
Drop in what you want to check
Type a domain, an IP address, or any indicator of compromise into the console above.
02
We match it against our intelligence
It runs against the same curated intelligence that powers DNS Defense and IP Defense.
03
You get a clear answer
You'll see whether it's listed, which threat category it falls under, and a short note on why.

Seeing a threat is step one. Blocking it is next.

Check IoC shows you what ThreatSTOP sees. With a free trial, you can turn that into automatic blocking on the gear you already run.