Threat intelligence search: overview
The Threat Intelligence search type lets you check an IP address, email, domain or URL for threat indicators — infostealer compromise, reputation and blocklist status, and malware associations — and pull back what the underlying data source holds for it. Pick it from the search composer when your starting identifier is a network or web indicator you want to screen for risk, rather than a username, phone number, or other identity identifier.

When to use it
Section titled “When to use it”Use the Threat Intelligence search type when you hold a network or web indicator and want to:
- Check whether a machine tied to an IP address has been compromised by infostealer malware (via the Computer/IP Threat Module, the default, on HudsonRock infostealer data).
- Screen an email or domain for infostealer exposure (via the Email Threat and Domain Threat Modules, also on HudsonRock).
- Look up the reputation or blocklist status of an IP address or domain (via the IP Reputation and Domain Reputation Modules, on SpamHaus reputation data).
- Check a URL against a malware-URL database (via the Malware URLs Module, on SpamHaus).
This search type exposes six Modules across two data sources — HudsonRock infostealer data and SpamHaus reputation data. For the full breakdown of each Module, its input, its cost, and what it returns, see Threat intelligence modules & options.
The end-to-end flow
Section titled “The end-to-end flow”The Threat Intelligence search type follows the same search composer flow as every other search in UserSearch — see How UserSearch works for the general model.
- In the composer header, open the Search type selector and choose Threat Intelligence.
- Pick a Module from the grid — Computer/IP Threat (selected by default) or one of the other five. The Module grid is single-select: selecting one deselects the others. The selected tile is drawn with a coral-orange highlighted border, and it loads its description, its Cost per search value, and its query form below.
- Enter the identifier the Module expects. For Computer/IP Threat this is an IP address, and the Module also exposes a Compromised Since year field. The other Modules take an email, domain, or URL instead (see the modules page).
- Confirm the Cost per search line beneath the input before you run. With Computer/IP Threat selected it reads “Cost per search: Free” — the Module consumes no Credits per search.
- Select Search Now (the coral-orange button at the right of the input row) to run the query.
What you get back
Section titled “What you get back”Selecting a Module and running a search returns what its data source holds for your identifier — for Computer/IP Threat, an indication of whether a machine tied to the IP has been compromised by infostealer malware, drawn from HudsonRock infostealer data. Results populate the Search Results panel on the right, which carries the standard Found / Enriched / Connections counters and Details / Graph tabs.
For how to read and verify those results — the counters, the results table columns, and the Details panel — see Reading Threat intelligence results.
Verified against UserSearch v2.0.20