How Criminal IP Turns OpenCTI Indicators Into Actual Intelligence

Threat indicators are cheap. Context is what costs.

Criminal IP’s integration with OpenCTI aims to bridge that gap. Instead of just tagging an IP as “bad” and moving on, it enriches indicators with real intelligence — risk scoring, infrastructure data, vulnerability correlation, behavioral signals, and phishing analysis.

Here’s how it works. Indicators come into OpenCTI — IPs, domains, URLs. The Criminal IP connector automatically enriches each one. The result is structured as entities and relationships inside OpenCTI’s knowledge graph.

That matters because analysts need to pivot. An IP isn’t just an IP. It lives in an Autonomous System. It’s hosted somewhere. It may have known CVEs associated with its exposed services. Criminal IP maps all of that.

The risk scoring is dual-perspective — inbound and outbound. That gives you a better signal than a single number. An IP that’s being scanned heavily is different from one that’s actively attacking others.

Domain analysis goes further. Full URL scanning for phishing, credential harvesting, suspicious files, impersonation. Confidence scores tied directly to phishing probability. Quantifiable, not guesswork.

For security teams drowning in alerts, this kind of enrichment isn’t nice to have. It’s how you figure out what actually needs your attention.