Check threat signals for IPs in Slack incident reports
Get a focused threat check when an incident message includes an IP, without switching tools to start triage.
Trigger
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Action
IPData Threat for IP
Tool to return threat intelligence data for a specific IP. Use when you need to determine if an IP is a Tor node, VPN, proxy, datacenter, threat actor, or listed on blocklists.
Why this helps
During an incident, opening another tool to assess an IP can interrupt the responder's train of thought.
- See threat indicators close to the incident discussion.
- Reduce manual copy and paste during initial triage.
- Keep the response focused on the IP mentioned in the message.
Setup
Build it in a few focused steps.
- 1Connect Slack and Ipdata co to Notis once through the portal.
- 2Create an automation in the portal, or ask Notis conversationally to check incident IPs from Slack.
- 3Use one plain-language instruction: when an incident message contains an IP address, check its threat data and report the result in my chosen channel.
- 4Select Slack Channel Message Received as the trigger and choose a channel for run reports.
- 5Test with a real incident-style Slack message containing a test IP.
Questions about this workflow
Does this inspect every Slack message?
The automation runs on the selected Slack channel message trigger. Its instruction should limit the lookup to messages that report an incident and contain an IP address.
What does the threat lookup return?
Ipdata co can return threat indicators such as Tor, VPN, proxy, datacenter, threat actor, and blocklist signals.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Slack to Ipdata co. A trigger fires from one place; an action lands in another.
Slack triggers
Ipdata co actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Advanced ASN Lookup
Tool to perform advanced ASN lookup returning prefixes, peers, and registry details. Use after confirming ASN number when detailed ASN info is required.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get Carrier Data for an IP
Tool to return mobile carrier data for a specific IP. Use when you need carrier name, MCC, and MNC for an IP address.
New Channel Created Trigger
Triggered when a new channel is created in Slack.
EU-specific IP lookup
Tool to lookup a specific IP address via the EU-only data residency endpoint. Use when you need IP lookup processed and stored within the EU.
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
IPData: Calling Code
Tool to fetch the international calling_code for an IP's country. Use when you need only the calling code field from ipdata_co.
Direct Message Received
Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.
IPDATA Field Carrier
Tool to return only the carrier object for the calling IP. Use when you need mobile carrier details of a specific IP.
Message Reaction Added
Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.
Get City from IP
Tool to return only city for an IP. Use when only the city name is required.
Message Reaction Removed
Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.
IPData: Continent Code
Tool to return only continent_code for an IP. Use when only the continent code is required.
Reaction Added Trigger
DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.
Get Continent Name from IP
Tool to return only continent name for an IP. Use when only the continent name is required.
Connect any two apps with Notis in the middle.
Slack and Ipdata co, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ipdata co.