This workflow enriches an IP address without converting incomplete evidence into a binary verdict.

Requirements

  • Nexus and Data Intelligence access
  • Python 3.10 or later with requests
  • A validated IPv4 or IPv6 indicator

Run the enrichment

enrich_ip.py
192.0.2.0/24 is reserved for documentation. Replace it with the actual indicator when running the script.

Interpretation

Keep these observations separate: Send the normalized object to your Security Information and Event Management (SIEM) system, then add event-specific context such as time, destination, authentication outcome, and observed behavior. Preserve raw FullHunt responses for investigation, but redact unnecessary personal data before wider distribution.