NETWORK INVESTIGATION
RIPE ASN lookup & IP WHOIS
Analyse the administrative allocation and public routing of an IPv4 or IPv6 address using RIPEstat and Internet registry data.
How to find the ASN of an IP address
Enter a public IPv4 or IPv6 address in the tool above. The report looks up the containing network prefix and its announcing autonomous system numbers (ASNs) using RIPEstat. An ASN identifies a network involved in Internet routing; it does not identify the person using an address.
IP WHOIS and BGP answer different questions
WHOIS records describe the registered allocation and organisation. BGP observations describe how the prefix is announced and which origin ASNs are visible to the collectors. Compare both when investigating an unexpected connection: the registered holder and the network announcing a route need not be the same organisation.
Read RPKI results in context
A valid RPKI result means the observed origin and prefix are covered by a matching route origin authorisation. Invalid indicates a mismatch; unknown means there is no covering authorisation. None of these results establishes whether a website is safe or an IP address is malicious. An unavailable source is shown separately from a routing result.
Use the report in an incident investigation
Keep the relevant log timestamps and timezone, then compare the prefix, origin ASN and published abuse contact with the connection you observed. Copy the report as JSON to retain the returned evidence. Shared hosting, VPNs, proxies and compromised devices make attribution uncertain: a network holder is not necessarily the actor behind an incident.
IP lookup: common questions
Can I look up a private IP address?
No. This tool accepts public IP addresses. Local, private and reserved ranges do not identify a publicly routed allocation for this investigation.
Does an IP WHOIS lookup reveal an exact location?
No. Registry country information is administrative. It cannot establish the precise location or identity of a person.
Why can an ASN or prefix be missing?
The collectors may not observe a route, or a source may be unavailable. Read the source-status section before drawing conclusions; missing data does not prove that an address is harmless.
Technical references: RIPEstat Network Info · RIPEstat RPKI Validation
Bring SecurCheck network investigation into your SOC workflows
During an intrusion investigation, a port scan or abnormal traffic in connection logs, contextualising the observed infrastructure helps your team decide what to investigate next. Manually collecting registry and routing data for each network indicator of compromise (IoC) takes time that analysts could spend correlating evidence.
Give your SOC and IT teams a centralised IP address and ASN analyser to support incident response. SecurCheck helps analysts analyse a suspicious IP address by bringing together administrative WHOIS allocation, publicly observed BGP routing and RPKI validation when sources are available. These findings support triage and documentation of technical decisions before any filtering or escalation is approved under your procedures.
Registry ownership does not identify an attacker. RPKI validates route origin against published authorisations, not whether traffic is malicious. Correlate findings with your logs and other indicators: SecurCheck does not automatically block traffic or certify compliance. Timing and coverage depend on the queried sources.
Explore the Business offer