Panther has partnered with IPinfo, a trusted source for IP address data, to provide integrated IP related enrichment to Panther customers. The IPinfo data sets are available to all Panther accounts at no additional cost and are disabled by default.
IPinfo datasets are stored as Panther-managed Lookup Tables in bulk, so there is no need to make API calls to leverage this enrichment in your detection logic or alerts. Alert events are automatically enriched with IPinfo data within the p_enrichment field in JSON events.
IPinfo data can be accessed in detections with pre-built Python helpers.
Panther’s IPinfo enrichment integration helps users to:
All Panther customers are given access to IPinfo data sets at no additional cost. The IPinfo enrichment data is disabled by default, and can be enabled easily in the console following these steps.
You can check out our product documentation for more information.