Prepare a clear follow-up for a suspicious IP
When a teammate flags an IP, make the relevant abuse contact easier to find before deciding what to do next.
Trigger
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Action
Get Abuse Contact
Tool to retrieve abuse contact information for a specific IP address. Use when you need organizational abuse details of an IP.
Why this helps
Finding the right abuse contact can turn a focused security task into a string of manual searches and interruptions.
- Retrieve organizational abuse contact details for a reported IP.
- Reduce time spent searching for a contact.
- Keep the next-step context near the Slack report.
Setup
Build it in a few focused steps.
- 1Connect Slack and Ipinfo io to Notis once in the portal.
- 2Create an automation in the portal or tell Notis what to do in plain language.
- 3In one instruction, ask Notis to retrieve abuse contact information when a channel message flags an IP as suspicious.
- 4Select Channel Message Received and choose a channel for run reports.
- 5Test with one real message containing a suspicious IP.
Questions about this workflow
Does the workflow contact the abuse address?
No. It retrieves contact information; the team can decide whether to follow up.
What should the Slack message include?
Include the IP address and enough context for Notis to recognize that it has been flagged as suspicious.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Slack to Ipinfo io. A trigger fires from one place; an action lands in another.
Slack triggers
Ipinfo io actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Batch Lite Lookup
Tool to perform bulk Lite IP lookups. Use when you need to group up to 1000 IP or URL pattern lookups into a single request.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Batch IP Lookup
Tool to perform batch IP lookups. Use when grouping up to 1,000 IPs or URL patterns into a single POST request.
New Channel Created Trigger
Triggered when a new channel is created in Slack.
Get Abuse Contact
Tool to retrieve abuse contact information for a specific IP address. Use when you need organizational abuse details of an IP.
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Get IP Carrier Info
Tool to get carrier information for a given IP address. Use when you need mobile carrier details.
Direct Message Received
Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.
Get Company Info for an IP
Tool to retrieve company info for a specific IP. Use when you need organization details behind an IP.
Message Reaction Added
Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.
Get IP Information
Tool to retrieve detailed information about an IP address. Use when you need geolocation, ASN, and network flags for a specific IP or 'me'.
Message Reaction Removed
Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.
Get IP Privacy Details
Tool to retrieve privacy-related flags (VPN, proxy, Tor, relay, hosting) for an IP address. Use when you need to detect anonymizing usage after confirming an IP.
Reaction Added Trigger
DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.
Connect any two apps with Notis in the middle.
Slack and Ipinfo io, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ipinfo io.