Criminal IP by AI Spera is a threat intelligence platform that aggregates and analyzes infrastructure-focused data across approximately 4.2 billion IP addresses and 300 million domains. The platform collects real-time data from multiple sources—including geolocation, WHOIS records, blacklists, honeypot activity, IDS hits, malware and phishing indicators, network banners, screenshots, and SSL certificates—and processes it through AI-based scoring and machine-learning models. Risk is classified into five categories (SAFE, LOW, MODERATE, DANGEROUS, CRITICAL) with infrastructure classifications for VPN, TOR, proxy, hosting, and scanner IPs. Core data types include indicators of compromise (IOCs), indicators of attack (IOAs), tactics/techniques/procedures (TTPs), MITRE ATT&CK mappings, command-and-control servers, CVEs, and threat actor profiles. The platform provides a searchable threat intelligence engine with historical data access up to one year, supporting filtering, tagging, pivoting, and historical trend analysis.
The suite comprises specialized modules: Criminal IP ASM for attack surface management with asset discovery and risk correlation; Criminal IP Brand for detecting fraudulent sites and tracking domain re-registrations; and Criminal IP FDS for fraud detection and credential-stuffing protection through device intelligence and behavioral analytics. Primary search functions include Asset Search for IP-based information with port and service identification; Domain Search with AI-driven URL scanning at multiple levels (Quick, Lite, Full, and Phishing); Exploit Search for CVE data and associated exploit code; and Image Search for visual identification of vulnerable assets. The platform exposes a RESTful API with endpoints for asset discovery, IP reports, VPN status, hosting details, privacy threats, banner data, domain scans, exploit searches, and statistical queries, delivering data via synchronous and asynchronous calls with continuously updated feeds and an on-premise database option. Criminal IP integrates with SIEM, SOAR, XDR, and other security operations tools through API and pre-built connectors, including Palo Alto Networks Cortex XSOAR, Logpresso, VirusTotal, Cisco, Tenable, Fortinet, IBM, and Splunk, enabling automated indicator analysis, real-time threat scoring, and automated blocking in IDS, EDR, spam filters, and firewalls. Access is structured through tiered subscription plans with allocated search credits, and the platform has achieved PCI DSS v4.0.1 Level 1 certification.