The Threat Enrichment API by Hunt Intelligence provides structured threat intelligence and infrastructure-level context for IPv4 addresses. The service utilizes data from live internet-wide scanning and ongoing monitoring to deliver metadata such as malware associations, TLS fingerprints, and JARM insights. It is designed for security operations, incident response, and threat hunting, enabling teams to enrich security alerts and investigate how an IP address fits into an attacker's infrastructure.
Built for programmatic access, the API integrates into detection workflows, custom dashboards, and alerting systems to automate alert enrichment. It is accessed via standard REST requests and provides responses with consistent schemas, timestamps, and structured fields to support automated processes. Supported data formats include JSON and GZ.