Pivot map
Pivot from here
Outputs from Domain/IP lookup can become inputs for the next tool. These are the most relevant follow-on pivots in the library.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
Algo VPN automates deployment of a personal WireGuard or IKEv2 VPN server in the cloud for private, secure OPSEC browsing.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Investigator Use
InfoByIP Bulk IP Lookup (infobyip.com/ipbulklookup.php) is an online tool that performs simultaneous lookups for multiple IP addresses in a single submission, returning geolocation data, ASN information, hostname, and organization details for each IP. This bulk processing capability makes it efficient for investigations involving large volumes of IP addresses.
For OSINT investigators, bulk IP lookup tools address a practical efficiency problem: investigations frequently surface dozens or hundreds of IP addresses from log files, network captures, threat intelligence feeds, or WHOIS records. Processing these individually through single-IP tools is time-consuming. Bulk lookup tools process the entire list simultaneously and return structured results that can be analyzed as a set.
The geolocation data returned for each IP — country, region, city, and ISP — enables geographic distribution analysis of IP datasets. When investigating a fraud campaign, botnet, or attack infrastructure, understanding the geographic distribution of IP addresses reveals operational patterns, hosting preferences, and potential attribution indicators.
ASN information connects individual IPs to their network operators and enables organization-level clustering. Multiple IPs belonging to the same ASN are hosted by the same network operator, which may indicate centralized infrastructure. Conversely, IPs distributed across many diverse ASNs and countries suggest a distributed or compromised-host infrastructure.
Hostname resolution converts IP addresses to their PTR (reverse DNS) records, which often contain descriptive hostnames that reveal the purpose or operator of a server. Hostnames like mail.company.com or vpn.organization.net provide immediate organizational context.
For network log analysis in incident response, bulk IP lookup allows rapid geolocation and organization enrichment of all external IPs in a log file — a standard initial step in understanding the scope and nature of a security incident.
Limitations: Bulk lookup services rely on GeoIP databases that have accuracy limitations, particularly at city level. IP-to-organization mappings may lag when networks are transferred or reallocated.
Document the full list of IPs submitted, the service queried, and all results returned with query timestamp for investigative records.
Before You Pivot
Capture the target, search terms, and why this source is relevant before you leave the page.
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Treat one tool as a lead source. Confirm important findings with independent sources.
Related tools
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
Internet-wide search interface for hosts and certificates with large-scale host, service, and virtual host coverage plus API access.
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
Criminal IP delivers AI-powered IP threat intelligence, attack surface data, and fraud detection for cyber threat investigations.
Free domain research tool to discover hosts related to a domain. Find visible hosts from the attackers perspective for Red and Blue Teams.