AbuseIPDB Connector
The AbuseIPDB connector lets you check whether an IP address has been associated with malicious activity using AbuseIPDB in your PingOne DaVinci flow.
The connector takes an IP address as an input value and runs it against the AbuseIPDB API to determine whether it’s from a bad actor. It outputs the abuse confidence score and related data points, such as whether the IP address is public, allow listed, or has been reported, that you can use to make decisions in your flow.
Setup
Resources
You can find more information and setup help in the following:
-
AbuseIPDB documentation:
-
PingOne DaVinci documentation:
Configuring the AbuseIPDB connector
Add the connector in PingOne DaVinci as shown in Adding a connector, then configure it as follows.
Using the connector in a flow
Checking an IP address for malicious activity
The capability returns a dataset around a single IP address, such as whether the IP address is public, allow listed, its abuse confidence score, and more.
At a high level:
-
The node sends a check request to AbuseIPDB for the IP address and maximum lookback period, in days, you specify in the node.
-
The connector outputs the abuse confidence score and related data points, such as whether the IP address is public, allow listed, or has been reported, that you can use to branch your flow.
| The connector verifies a single IP address at a time. |
Test the flow by clicking Save, Deploy, and Try Flow.
Capabilities
Returns a dataset around a single IP such as if the IP Address is public, allow listed, an Abuse Confidence Score, and more.
Returns datapoints around a single IP Address
Show details
-
Properties
-
Input Schema
-
Output Schema
- Max Days textField
-
Maximum amount of days to look back to
- IP Address textField
-
IP Address
-
default object
-
properties object
-
maxDays string required
Maximum amount of days to look back to
-
ipAddress string required
IP Address of end user
-
-
Input Example
{
"properties": {
"maxDays": "90",
"ipAddress": "118.25.6.39"
}
}
-
output object
-
rawResponse object
-
statusCode number
-
headers object
-
ipAddress number
-
isPublic object
-
ipVersion number
-
isWhitelisted object
-
abuseConfidenceScore number
-
countryCode object
-
usageType object
-
isp object
-
domain object
-
countryName object
-
totalReports number
-
numDistinctUsers number
-
lastReportedAt object
-