An ASN is a unique identifier assigned by the Internet Assigned Numbers Authority (IANA) to a network operator that controls a block of IP addresses.
Threat actors often use multiple IP addresses and domains to carry out their attacks. ASN information allows security analysts to group these disparate elements into larger networks or organizations, helping to identify patterns of behavior and to more accurately attribute attacks to specific threat actors or groups.
Incorporating ASN information into threat intelligence management allows security teams to better understand the nature and scope of threats facing their organization and take more effective measures to defend against them.
-
Navigate to
Advanced Query Builder > IPv4 Queries > history information - bulk
-
Specify a list of
IPs
anddates
one line at a time -
Click
Search
-
Data is outputted in the box to the right, in descending order, corresponding to each line
-
Click
Save
to save your query
Saving queries
Organizational users are able to save individual queries ran from Advanced Query Builder
, and store them in the Private Queries
menu for future analysis, or to share with their organization.
-
Specify the query parameters
-
Click
Save Query
-
Give your query a
Name
-
Specify a
Description
to add more context -
Click
Save