IPinfo provides accurate IP address data (geolocation, ASN, carrier/company, hosting/proxy/VPN/Tor flags, and more) to enrich investigations in Qevlar.
Overview
IPinfo is a widely used IP data platform that turns IP addresses into rich context for investigations. Typical attributes include:
- Geolocation: country, region, city, and coordinates
- Network: ASN, ISP/carrier, domain, and routing info
- Ownership: company or organization using the IP range
- Privacy signals: hosting provider, VPN/proxy, Tor exit node, and similar indicators
When connected to Qevlar, IPinfo automatically enriches indicators in cases, timelines, and graph views so analysts can quickly determine where an IP comes from, who owns it, and whether it’s likely to be anonymized.
How to integrate IPinfo with Qevlar
Step 1: Navigate to Integrations
- In Qevlar, open the left navigation and select Integrations.
- In Add new data sources, search for "IPinfo".
- Click the + button on the IPinfo tile to start the setup.

Step 2: Add credentials
You can either use Qevlar’s shared account (quick start) or enter your own IPinfo API token.

Option 1: Use Qevlar’s account (fastest)
- Check "I want to use Qevlar’s account."
- Click Test & Save.
infoThis is ideal for a quick evaluation. For higher throughput, dedicated quota, or stricter isolation, use your own API token.
- Option 2: Use your own IPinfo API token
- Paste your API key into the API key field.
- Click Test & Save. If you don’t have a token yet, follow the steps below.
Get your IPinfo API token
- Log in to your IPinfo account and open the Dashboard.

- In the dashboard’s left panel, click API token.

- Copy your Token.

- Return to Qevlar and paste the token into the API key field, then Test & Save.
Your secret is encrypted and stored securely in Qevlar; it’s never visible to other users or Qevlar staff.
What the integration enables
- Automatic enrichment of IP indicators in investigations
- Immediate context on geolocation, ASN/ISP, organization, and privacy indicators (e.g., VPN/proxy/Tor/hosting)
- Faster triage and more confident scoping during incident response and threat hunting