Skip to content
Playbook All on Content Hub

Set alert severity from AbuseIPDB score

Checks an alert's source IP against AbuseIPDB and raises severity when the abuse score is high.

@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Sep 5, 2026
Download JSON · 15 KB

abuseipdb-severity.json

sha256:962814f3585c76634388129e8ab204aed6463245a009fc677e384fa3ec7e706b

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

Runs against the selected alert, looks up its source IP on AbuseIPDB and sets severity to Critical when the abuse confidence score is 50 or more, otherwise Low.

Tune the threshold in the decision step to match your tolerance.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000