RIOT, also known as Business Services Intelligence, is a dataset that provides context for IP addresses associated with common business services. These services include content delivery networks (CDNs), update servers, public DNS and NTP services, SaaS APIs, and cloud security products. By tracking both published and unpublished or dynamic IPs used by these services, the dataset enables security teams to distinguish non-threat activity and harmless network behavior from potential threats. It functions as a context enrichment tool designed to accelerate security event triage.
The dataset is utilized to filter known benign IPs from logs, identify outbound connections to unidentified services, and validate IP addresses prior to their inclusion in blocklists to prevent the restriction of critical business infrastructure. To inform analysis, the data is separated into two Trust Levels (Level 1 and Level 2) that indicate the trustworthiness of an IP address. The data is accessible via Enterprise and Community APIs and through native integrations with various SIEM and SOAR platforms, and it is regularly refreshed to maintain accurate tracking of service provider IPs.