Skip to main content

IP Enrichment - Generic v2

This Playbook is part of the Common Playbooks Pack.#

Enriches IP addresses using one or more integrations.

  • Resolve IP addresses to hostnames (DNS)
  • Provide threat information
  • Separate internal and external IP addresses
  • For internal IP addresses, get host information


This playbook uses the following sub-playbooks, integrations, and scripts.


  • IP Enrichment - Internal - Generic v2
  • IP Enrichment - External - Generic v2


This playbook does not use any integrations.


This playbook does not use any scripts.


This playbook does not use any commands.

Playbook Inputs#

NameDescriptionDefault ValueSourceRequired
IPThe IP address to enrich.AddressIPOptional
InternalRangeA list of internal IP address ranges to check IP addresses against. The list should be provided in CIDR notation, separated by commas. An example of a list of ranges would be: ",," (without quotation marks). If a list is not provided, the default list provided in the IsIPInRanges script (the known IPv4 private address ranges).Noneinputs.InternalRangeOptional
ResolveIPDetermines whether to convert the IP address to a hostname using a DNS query (True/False).Noneinputs.ResolveIPRequired

Playbook Outputs#

IPThe IP objects.unknown
DBotScoreThe Indicator, Score, Type, and Vendor.unknown
EndpointThe Endpoint's object.unknown
Endpoint.HostnameThe hostname to enrich.string
Endpoint.OSThe Endpoint OS.string
Endpoint.IPThe list of Endpoint IP addresses.unknown
Endpoint.MACThe list of Endpoint MAC addresses.unknown
Endpoint.DomainThe Endpoint domain name.string

Playbook Image#