---
title: Criminal IP Reviews
meta_title: 'Criminal IP Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 11 reviews by the users' company size, role or industry to
  find out how Criminal IP works for a business like yours.
aggregate_rating:
  rating_value: 4.5
  review_count: 11
  scale: '5'
date_modified: '2026-07-17'
parent_category:
  name: System Security
  url: https://www.g2.com/categories/system-security
---

# Criminal IP Reviews
**Vendor:** Criminal IP  
**Category:** [Threat Intelligence Software](https://www.g2.com/categories/threat-intelligence)  
**Average Rating:** 4.5/5.0  
**Total Reviews:** 11
## About Criminal IP
Criminal IP is a cyber threat intelligence solution that provides decision-ready threat intelligence, and attack surface management solutions to security teams worldwide. By continuously scanning the global internet, Criminal IP aggregates and contextualizes threat signals across IPs, domains, URLs, and attack infrastructure, covering malicious indicators, known vulnerabilities, exposed assets, and attacker behavior. Criminal IP&#39;s mission is to give organizations real visibility into their cyber landscape and accelerate threat detection and response by delivering the intelligence needed to outsmart attackers.



## Criminal IP Pros & Cons
**What users like:**

- Users appreciate the **automation capabilities** of Criminal IP, enabling efficient navigation and real-time threat data visualization. (1 reviews)
- Users appreciate the **ease of use** of Criminal IP, finding it accessible and intuitive for navigating complex security data. (1 reviews)
- Users appreciate the **user-friendly interface and powerful toolkit** of Criminal IP, enabling seamless navigation and real-time threat visualization. (1 reviews)
- Users commend the **quick response time** of Criminal IP, enabling effective action on security threats in real-time. (1 reviews)
- Users find the **setup ease** of Criminal IP to be impressive, allowing quick integration without complexity. (1 reviews)

**What users dislike:**

- Users face a **difficult learning curve** with advanced search filters, impacting their overall experience with Criminal IP. (1 reviews)
- Users find the **insufficient training** on advanced search filters creates a learning curve and hinders effective usage. (1 reviews)
- Users experience **slow loading** issues with Criminal IP&#39;s interface, which can hinder timely access to live data. (1 reviews)

## Criminal IP Reviews
  ### 1. Seamless OSINT with Outstanding Results

**Rating:** 5.0/5.0 stars

**Reviewed by:** Julio D. | CTO, Small-Business (50 or fewer emp.)

**Reviewed Date:** April 08, 2026

**What do you like best about Criminal IP?**

I like Criminal IP TI for its ease of use and the rich information it provides for searches. The drill-down capability is excellent, allowing me to start from a domain search and then drill down to each associated asset for an in-depth view. The domain and asset search is straightforward, with optional filters that save time and money. Having all results in one single view increases productivity. I also appreciate that the initial setup was very easy, just requiring account creation and login. Additionally, I find the results better and pricing more favorable compared to Shodan.io.

**What do you dislike about Criminal IP?**

Sometimes the time it takes to do a full scan on demand is too long and fails. Also, creating a PDF report of all vulnerabilities for all assets is difficult.

**What problems is Criminal IP solving and how is that benefiting you?**

I use Criminal IP TI to perform vulnerability scans that our customers can't do themselves. It saves time and money with ease of use and rich information, allowing us to be more productive. The drill-down capability provides an in-depth view of all assets.

  ### 2. Comprehensive IP Intelligence in One Place

**Rating:** 4.0/5.0 stars

**Reviewed by:** Jiin J. | Cybersecurity Consultant, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 18, 2026

**What do you like best about Criminal IP?**

The best part for me is the convenience. Instead of gathering information from several different sources, Criminal IP gives me a broad view of an IP or domain in seconds. It's fast, intuitive, and helps streamline security investigations.

**What do you dislike about Criminal IP?**

I don't have any major complaints, but I think the user onboarding experience could be improved a bit. Since the platform provides a wide range of security data, a few more guided explanations for beginners would be helpful.

**What problems is Criminal IP solving and how is that benefiting you?**

Criminal IP helps solve the problem of fragmented threat intelligence by bringing together IP and domain reputation, open port information, vulnerability data, and other security insights in one place. This saves me time during investigations and allows me to identify potential risks more quickly without relying on multiple tools. As a result, my workflow becomes more efficient and I can make security-related decisions with greater confidence.

  ### 3. Milestone rules and ways

**Rating:** 3.5/5.0 stars

**Reviewed by:** Said B. | Work Group Home, Entertainment, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 17, 2026

**What do you like best about Criminal IP?**

Criminal IP is a security analysis tool designed to help professionals detect and investigate online threats, often used in the context of threat intelligence.

**What do you dislike about Criminal IP?**

it must be used ethically and in compliance with the applicable laws.

**What problems is Criminal IP solving and how is that benefiting you?**

It allows to:
→ Identify infrastructures linked to criminal activities
→ Search for traces of information leaks (e.g., passwords, exposed servers)
→ Corroborate digital investigations with reliable data

  ### 4. Effortless Threat Detection with Stellar API Integration

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jieun P. | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 20, 2026

**What do you like best about Criminal IP?**

I mainly use Criminal IP TI as a preemptive defense tool to keep track of our global assets and verify the reputation of IPs accessing our services. I appreciate the 'asset search' feature because it's like a search engine for all our internet-facing assets, making it faster than running manual scans. I can see exactly what ports are open and what banners are being exposed in just a few clicks. The ability to pull real-time threat intelligence directly into our code is a game-changer, making it easy to automate the blocking of suspicious IPs based on their risk score. The API is clean and straightforward to set up, which allowed us to pull live threat data within the first hour of setting it up.

**What do you dislike about Criminal IP?**

If I had to pick something, I'd say the sheer volume of data can be a bit overwhelming sometimes. Since Criminal IP picks up everything, it occasionally flags IPs that are just harmless scanners or benign bots, which creates a bit of 'alert fatigue' for us. I wish there were more fine-tuned pre-filtering options to automatically weed out the 'noisy' but harmless data. Also the dashboard customization could be a bit more flexible. As a developer, I love building my own views, so having a more 'drag-and-drop' style dashboard to monitor our specific assets would be a huge plus.

**What problems is Criminal IP solving and how is that benefiting you?**

I use Criminal IP TI to automate identifying and blocking malicious IPs, saving time and effort by eliminating manual log reviews. Its asset search offers a quick view of our attack surface, while real-time threat intelligence helps us proactively defend against potential threats.

  ### 5. A practical platform for external asset investigation and threat intelligence

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 16, 2026

**What do you like best about Criminal IP?**

The feature I use most is the search for IP addresses and domains. I like that I can quickly see exposed services, open ports, SSL certificate information, reputation data, and known vulnerabilities without having to switch between multiple websites.

Before using Criminal IP, I usually had several browser tabs open to collect this information. Now I can review everything from one interface, which makes investigations much faster. The layout is clean, the searches are responsive, and the threat intelligence helps me decide which findings deserve a closer look. I also like the AI-powered insights because they provide additional context that would otherwise take longer to gather manually.

**What do you dislike about Criminal IP?**

The biggest challenge is the learning curve. Since the platform includes many search filters and investigation features, it takes some time to understand how to get the most out of everything it offers.

I think the experience would improve with more interactive onboarding, real-world investigation examples, and guided walkthroughs for new users. I would also welcome more native integrations with SIEM and SOAR platforms so investigation results can be shared more easily with the rest of the security workflow.

**What problems is Criminal IP solving and how is that benefiting you?**

Before using Criminal IP, we gathered information about external assets from several different sources. Looking up exposed ports, IP reputation, certificates, and vulnerability data meant repeating the same process across multiple tools.

Now we can perform most of that investigation from a single platform, which has noticeably reduced the time needed to analyze internet-facing assets. For routine investigations, we save around 20–30% of the time compared to our previous workflow. That means we can review more assets, respond to potential risks faster, and get better value from the security tools we already use instead of adding another specialized solution.

  ### 6. Rich IP Context That Speeds Up Daily Threat Investigations

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 13, 2026

**What do you like best about Criminal IP?**

One of the things I appreciate most about Criminal IP TI is how much context it provides for an IP address. When investigating alerts from firewalls, IDS, or SIEM systems, I often need to quickly determine whether an IP is suspicious or simply part of normal internet traffic, significantly reducing the time spent manually searching across multiple OSINT sources.

It's useful for daily security investigations: from an IT operations perspective, having quick access to threat intelligence speeds up incident triage. If a monitoring system flags an external connection, I can quickly search the IP in Criminal IP TI and immediately see whether it has been associated with malicious activity or suspicious infrastructure.


Implementation is fairly easy because the platform is web-based and provides an API. IT teams can start using the platform immediately through the web interface, and integration with monitoring tools can be done later through the API. It has strong API and automation options.

**What do you dislike about Criminal IP?**

While the platform is powerful, the amount of data available can initially feel overwhelming. New users may need some time to understand all the data points, filters, and risk indicators presented in the interface.

For smaller organizations or IT/Software Dev departments with limited budgets, access to full threat intelligence features and large API quotas could potentially be expensive.

**What problems is Criminal IP solving and how is that benefiting you?**

Faster Investigation of Suspicious IPs: one of the most common problems IT teams face is investigating alerts triggered by unknown IP addresses. This tool helps solve this by providing quick visibility into the reputation and activity of an IP, allowing teams to decide whether to block it or ignore it.

Reducing Manual OSINT Research: without a tool like Criminal IP TI, IT teams often need to check multiple platforms to gather information about suspicious infrastructure. Criminal IP centralizes this data, which significantly reduces investigation time.

Improving Security Decision-Making: by providing threat scoring, infrastructure details, and attack history, Criminal IP TI helps IT teams make more informed decisions when responding to alerts.

  ### 7. Streamlines Threat Intelligence and Boosts Efficiency

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 20, 2026

**What do you like best about Criminal IP?**

I love how Criminal IP TI brings multiple layers of threat intelligence into a single, easy-to-use platform. The real-time IP reputation and risk scoring are especially useful, as they quickly highlight suspicious or malicious infrastructure. I also appreciate the detailed visibility into open ports and services, which makes reconnaissance much faster. The OSINT aggregation saves a lot of time by eliminating the need to switch between tools. The speed, accuracy, and all-in-one approach make it a very efficient solution for security research and penetration testing. The initial setup was quite straightforward and user-friendly, and I liked that you can begin with the web interface for quick access and gradually integrate it into workflows.

**What do you dislike about Criminal IP?**

One area that could be improved is the depth of contextual insights for some IPs, as occasionally the data feels a bit limited for deeper analysis. The interface, while functional, could be more intuitive and streamlined for faster navigation during active testing. It would also be helpful to have more advanced filtering and customization options when working with large datasets. Additionally, clearer explanations of certain risk scores or flags would make it easier to interpret results.

**What problems is Criminal IP solving and how is that benefiting you?**

I use Criminal IP TI to centralize threat intelligence, quickly analyze IPs, domains, exposed services, and streamline reconnaissance. It helps identify attack surfaces, improve situational awareness, and reduces false positives by providing real-time data, making penetration testing faster and more efficient.

  ### 8. Precise Threat Data with Easy Setup

**Rating:** 5.0/5.0 stars

**Reviewed by:** Nandhu S. | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 12, 2026

**What do you like best about Criminal IP?**

I really appreciate how the UI/UX of Criminal IP TI is on point, making it a great experience to work with. The data collected by Criminal IP TI is really precise and it provides the technicals we need to enrich the data we already have. The initial setup was really easy, which made getting started a breeze.

**What do you dislike about Criminal IP?**

In the search engine there are hacking groups. The list of hacking groups is not that precise since some of them are just tools used by threat actors.

**What problems is Criminal IP solving and how is that benefiting you?**

I use Criminal IP TI for enriching our data. It correlates threat actors and hacking groups, gathering technicals and source references precisely, enhancing our data.

  ### 9. Complex Security Data Made Simple with a Powerful, Uncluttered Platform

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Design | Small-Business (50 or fewer emp.)

**Reviewed Date:** February 26, 2026

**What do you like best about Criminal IP?**

The platform does an incredible job of turning complex security data into a digestible format that’s easy to navigate even for a designer. It packs a massive toolkit without feeling cluttered, and our devs were impressed by how the well-structured API allowed for a quick, painless setup within our system. This seamless connectivity has made it much simpler for us to visualize and act on threat data in real-time.

**What do you dislike about Criminal IP?**

With so much data available, there’s a bit of a learning curve when you first try to master the advanced search filters. While I check the dashboard daily, I’ve noticed the web interface can occasionally lag slightly behind the live data we receive through our backend. It’s a minor friction point, but adding more intuitive onboarding for non-security specialists would definitely help bridge the gap.

**What problems is Criminal IP solving and how is that benefiting you?**

It has effectively solved the friction between security and user experience by allowing us to filter out malicious bots without bothering legitimate shoppers. We can now offer a frictionless checkout for honest customers while pinpointing high-risk traffic, which has directly boosted our conversion rates. Whenever we needed guidance on fine-tuning our fraud logic, their team was incredibly quick to jump in with the right solutions.

  ### 10. Exceptional UX in Security with Criminal IP TI

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 07, 2026

**What do you like best about Criminal IP?**

I use Criminal IP TI for checking all unauthorized IPs in our company. It keeps our company safe, compliant, and on-record. I really like the UX, which is something that most security apps don't get right. The user experience is crucial, especially in highlighting the issues and actions I need to take. The initial setup was very easy and straightforward.

**What do you dislike about Criminal IP?**

Nothing. I believe the app offers everything I need.

**What problems is Criminal IP solving and how is that benefiting you?**

I use Criminal IP TI to check unauthorized IPs, keeping our company safe, compliant, and on-record.

  ### 11. Clear, Detailed IP/URL Safety Insights I Can Trust

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 08, 2026

**What do you like best about Criminal IP?**

It helps me decide whether an IP or URL is safe or dangerous. Also, it gives lots of contents why.

**What do you dislike about Criminal IP?**

I don't find anything wrong or uncomfortable about TI yet.

**What problems is Criminal IP solving and how is that benefiting you?**

Criminal IP TI helps me find if the url or domain I go into is a scam or not. Also, I study cyber security that I use this platform to study.



- [View Criminal IP pricing details and edition comparison](https://www.g2.com/products/criminal-ip-criminal-ip/reviews?section=pricing&secure%5Bexpires_at%5D=2026-07-21+00%3A49%3A06+-0500&secure%5Bsession_id%5D=a7fa79a4-265b-48d5-8adf-ecc5e5458d0f&secure%5Btoken%5D=9e00f6b2f98a75b6085680642449982c02458a6b3266213cab3bde825adb0f11&format=llm_user)
## Criminal IP Integrations
  - [Cisco XDR](https://www.g2.com/products/cisco-xdr-cisco-xdr/reviews)
  - [FortiSOAR](https://www.g2.com/products/fortisoar/reviews)
  - [Hybrid Analysis](https://www.g2.com/products/hybrid-analysis/reviews)
  - [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews)
  - [IBM QRadar SOAR](https://www.g2.com/products/ibm-qradar-soar/reviews)
  - [Maltego](https://www.g2.com/products/maltego/reviews)
  - [NMAP Online](https://www.g2.com/products/nmap-online/reviews)
  - [OpenCTI by Filigran](https://www.g2.com/products/opencti-by-filigran/reviews)
  - [Palo Alto Cortex XSIAM](https://www.g2.com/products/palo-alto-cortex-xsiam/reviews)
  - [Palo Alto Networks Cortex XSOAR](https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews)
  - [Polarity](https://www.g2.com/products/polarity/reviews)
  - [Snowflake Data Exchange](https://www.g2.com/products/snowflake-data-exchange/reviews)
  - [Splunk](https://www.g2.com/products/splunk-2025-01-30/reviews)
  - [Splunk Cloud Platform](https://www.g2.com/products/splunk-cloud-platform/reviews)
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)
  - [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)
  - [Swimlane](https://www.g2.com/products/swimlane/reviews)
  - [Tenable Vulnerability Management](https://www.g2.com/products/tenable-vulnerability-management/reviews)
  - [ThreatQ](https://www.g2.com/products/threatq/reviews)
  - [Tines](https://www.g2.com/products/tines/reviews)
  - [Wazuh](https://www.g2.com/products/wazuh/reviews)

## Criminal IP Features
**Detection**
- Payment Verification
- Bot Mitigation
- Real-Time Monitoring
- Alerts

**Identification**
- Reseller Database
- Monitoring
- Violations

**Functionality**
- Monitoring - Deep Web
- Monitoring - Dark Web
- Analysis
- Ticketing
- Simple Search
- Leak Source
- Centralized Dashboard
- Real-Time Alerts

**Asset Management**
- Asset Discovery
- Shadow IT Detection
- Change Management

**Orchestration**
- Asset Management
- Security Workflow Automation

**Analysis **
- ID Analytics
- Intelligence Reporting
- Incident Reports

**Enforcement**
- Communication
- Plans
- Track

**Monitoring**
- Gap Analysis
- Vulnerability Intelligence
- Compliance Monitoring
- Continuous Monitoring

**Information**
- Proactive Alerts
- Intelligence Reports

**Administration**
- Fraud Markers
- Transaction Scoring
- Blacklisting

**Risk Management**
- Risk-Prioritization
- Reconnaissance
- At-Risk Analysis
- Threat Intelligence

**Personalization**
- Security Validation

**Generative AI**
- AI Text Summarization

**Agentic AI - Fraud Detection**
- Cross-system Integration
- Adaptive Learning
- Decision Making

**Generative AI**
- AI Text Summarization
- Generate Threat Detection Rules
- Generate Threat Summaries

## Top Criminal IP Alternatives
  - [LastPass](https://www.g2.com/products/lastpass/reviews) - 4.5/5.0 (2,040 reviews)
  - [1Password](https://www.g2.com/products/1password/reviews) - 4.6/5.0 (1,788 reviews)
  - [Scrut Automation](https://www.g2.com/products/scrut-automation/reviews) - 4.9/5.0 (1,311 reviews)

