Daily malicious IP threat brief for your security team

By General Input

Every weekday morning, get a short brief of the internet's most-reported malicious IPs, double-checked against a second source and posted straight to your security Slack channel.

Integrations

  • AbuseIPDB
  • VirusTotal
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering
  • Operations

Every weekday at 8:00am, produce a short, plain-language threat brief on the internet's most-reported malicious IP addresses for our security team, with every standout corroborated across two independent reputation sources. Run this on a cron schedule (Monday through Friday at 8am), because AbuseIPDB is an on-demand lookup source rather than a webhook or poll feed.

Start by calling AbuseIPDB's Download Blacklist operation to pull the current list of highest-confidence malicious IPs. Each entry carries an abuseConfidenceScore from 0 to 100 where higher means more likely malicious, so sort by that score and keep only the worst offenders. To respect both services' daily quotas, cap the deeper analysis at roughly the top 10 to 15 IPs rather than the entire blacklist.

For each of those top offenders, call VirusTotal's Get an IP Address Report operation and read the engine verdicts (the malicious and suspicious counts under last_analysis_stats). Treat an IP as corroborated when AbuseIPDB rates it high-confidence AND VirusTotal's engines also flag it as malicious. Record how many VirusTotal engines flagged each one so the brief can convey the strength of the agreement.

AbuseIPDB reports abuse categories as integer IDs, so translate them into words in the brief (for example 18 = Brute-Force, 22 = SSH, 14 = Port Scan, 4 = DDoS, 10 = Email Spam). Group the standouts by abuse category and by country so the team can see the dominant attack types and origins at a glance, and explicitly call out the IPs where both AbuseIPDB and VirusTotal agree.

Post the finished brief to our security Slack channel using Slack Bot's Send a Message operation. Keep it short and skimmable: lead with the handful of worst IPs, each with its confidence score, its abuse categories in plain words, its country, and the corroboration verdict (both sources agree, or AbuseIPDB only). Follow with a quick by-category and by-country roll-up. Do not paste the raw blacklist or a dump of every IP; this is an analyst brief, not a data export.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them