egressview

Manual threat investigation

EgressView can query AbuseIPDB, VirusTotal, and AlienVault OTX for additional context about a public destination IP.

Open Settings > Threat Detection > Manual external investigation, enter the API keys for the services you use, and configure the cache and minimum request interval. An empty key field preserves the saved key; select Delete saved key to remove it.

Provider quotas and terms remain the administrator’s responsibility. EgressView caches successful results and applies a server-side per-provider cooldown, but provider-side limits may be stricter.