GeoThreat adds a geographic-neighborhood view to IP investigation. Given a query IP and radius, the API returns FraudGuard-observed threat records near the geolocated source with network, provider, risk, and distance context.

The result is an investigative lead—not evidence that nearby addresses are controlled by the same actor. Geographic proximity is most useful when it aligns with ASN, ISP, prefix, timing, or observed behavior.

What GeoThreat returns

A response can include:

  • query-IP city, region, country, coordinates, and timezone;
  • ASN, network organization, ISP, and connection type;
  • configurable radius and pagination context;
  • nearby FraudGuard-observed threat records;
  • threat classification, risk, provider, location, and distance for each result.

Review the GeoThreat API documentation for the current schema and request parameters.

Useful investigation questions

GeoThreat can help an analyst ask:

  • Does suspicious activity cluster within the same metropolitan area and provider?
  • Are multiple sources associated with the same ASN or ISP?
  • Does a source sit near other recently observed addresses with the same attack family?
  • Is an apparent geographic pattern still present after accounting for shared infrastructure?
  • Which nearby results deserve a single-IP ACE v2 lookup or an internal-log pivot?

The API should not be used to conclude that a city, neighborhood, or customer is malicious.

A responsible workflow

  1. Start from a suspicious event in your own logs.
  2. Run a single-IP lookup to establish observed behavior, recency, and network context.
  3. Use GeoThreat with the smallest radius appropriate to the question.
  4. Compare results by ASN, ISP, prefix, attack family, and time—not distance alone.
  5. Validate likely matches against your own account, session, route, or payload evidence.
  6. Take action on supported addresses or patterns, not on a map boundary.

How to read a large nearby count

A dense result does not necessarily indicate one coordinated campaign. Cities contain large ISPs, mobile gateways, cloud regions, carrier-grade NAT, VPN exits, and shared enterprise networks. Geolocation also has uncertainty; coordinates often represent an ISP service area or database centroid rather than a physical device.

A large count is a reason to narrow the query:

  • compare one provider with others in the same radius;
  • separate residential, cellular, corporate, hosting, and proxy infrastructure;
  • filter by recent activity or threat family;
  • look for repeated behavior across your own targets;
  • inspect a smaller set with ACE v2.

When geographic context is valuable

GeoThreat is most useful for threat research, abuse clustering, provider analysis, incident visualization, and hypothesis generation. It can also support a customer investigation when many sources rotate within one geographic and network footprint.

It is less suitable as a live block rule. For request-path decisions, use ACE v2 and combine its evidence with your account and session context. For explicit country policy, follow Country-Based Traffic Filtering Without Overblocking.

Availability

GeoThreat availability and limits depend on the current plan. Review FraudGuard pricing and the API documentation, or contact hello@fraudguard.io for a research workflow that needs a larger or custom delivery.