Skip to content
← UserSearch.comLog in ↗

Threat intelligence search: overview

The Threat Intelligence search type lets you check an IP address, email, domain or URL for threat indicators — infostealer compromise, reputation and blocklist status, and malware associations — and pull back what the underlying data source holds for it. Pick it from the search composer when your starting identifier is a network or web indicator you want to screen for risk, rather than a username, phone number, or other identity identifier.

The UserSearch composer with the Threat Intelligence search type active and the Computer/IP Threat Module selected, showing the IP address input, a Compromised Since year field, and a "Cost per search: Free" line
The UserSearch composer with the Threat Intelligence search type active and the Computer/IP Threat Module selected, showing the IP address input, a Compromised Since year field, and a "Cost per search: Free" line

Use the Threat Intelligence search type when you hold a network or web indicator and want to:

  • Check whether a machine tied to an IP address has been compromised by infostealer malware (via the Computer/IP Threat Module, the default, on HudsonRock infostealer data).
  • Screen an email or domain for infostealer exposure (via the Email Threat and Domain Threat Modules, also on HudsonRock).
  • Look up the reputation or blocklist status of an IP address or domain (via the IP Reputation and Domain Reputation Modules, on SpamHaus reputation data).
  • Check a URL against a malware-URL database (via the Malware URLs Module, on SpamHaus).

This search type exposes six Modules across two data sources — HudsonRock infostealer data and SpamHaus reputation data. For the full breakdown of each Module, its input, its cost, and what it returns, see Threat intelligence modules & options.

The Threat Intelligence search type follows the same search composer flow as every other search in UserSearch — see How UserSearch works for the general model.

  1. In the composer header, open the Search type selector and choose Threat Intelligence.
  2. Pick a Module from the grid — Computer/IP Threat (selected by default) or one of the other five. The Module grid is single-select: selecting one deselects the others. The selected tile is drawn with a coral-orange highlighted border, and it loads its description, its Cost per search value, and its query form below.
  3. Enter the identifier the Module expects. For Computer/IP Threat this is an IP address, and the Module also exposes a Compromised Since year field. The other Modules take an email, domain, or URL instead (see the modules page).
  4. Confirm the Cost per search line beneath the input before you run. With Computer/IP Threat selected it reads “Cost per search: Free” — the Module consumes no Credits per search.
  5. Select Search Now (the coral-orange button at the right of the input row) to run the query.

Selecting a Module and running a search returns what its data source holds for your identifier — for Computer/IP Threat, an indication of whether a machine tied to the IP has been compromised by infostealer malware, drawn from HudsonRock infostealer data. Results populate the Search Results panel on the right, which carries the standard Found / Enriched / Connections counters and Details / Graph tabs.

For how to read and verify those results — the counters, the results table columns, and the Details panel — see Reading Threat intelligence results.

Verified against UserSearch v2.0.20