Hunt.io
Enrich IP addresses with threat intelligence, signatures, and infrastructure details.

Overview
Hunt.io provides threat intelligence for internet infrastructure, including IP details, signatures, and C2-related context.
Malfors uses Hunt.io to enrich IP addresses in your graph with returned intelligence and infrastructure details.
This gives you more context on suspicious IPs and helps decide whether to pivot into related services, signatures, or activity.
Configure
- Create a Hunt.io account and generate your API key.
- In Malfors, open Enrichments → Hunt.io → Add Token.
- Paste your token into the field and save.
- Hunt.io enrichments are now available.