An interactive cybersecurity analyst workspace that supports single-IP and batch-IP investigation, lightweight risk scoring, analyst tagging, and persistent case history. Designed to simulate real-world SOC and GRC workflows with data visualization and export capabilities.
- Single IP investigation
- Batch CSV investigation
- Public/private IP classification
- Lightweight risk scoring and flags
- Analyst tagging (
benign,needs_review,suspicious,malicious) - Analyst notes and local case history
- Exportable CSV results
- Streamlit-ready dark theme
- Portfolio/demo friendly structure
IP-Intel-Analyst-Workspace/
├─ app.py
├─ requirements.txt
├─ README.md
├─ .gitignore
├─ assets/
│ └─ banner.png
├─ data/
│ └─ investigations.csv
├─ ip_intel/
│ ├─ __init__.py
│ ├─ service.py
│ └─ storage.py
└─ .streamlit/
└─ config.toml
- Create and activate a virtual environment.
- Install dependencies:
pip install -r requirements.txt
- Create a
.envfile in the repo root:IPINFO_TOKEN=your_ipinfo_token_here MAXMIND_CITY_DB=
- Run the app:
python -m streamlit run app.py
Your input CSV must contain a column named ip.
Example:
ip
8.8.8.8
1.1.1.1
208.67.222.222- Push this repository to GitHub.
- In Streamlit Community Cloud, create a new app from the repository.
- Set the main file path to:
app.py - Add your
IPINFO_TOKENas a Streamlit secret or environment variable before deployment.
- Input IP(s)
- Enrich with intelligence data
- Evaluate risk score
- Review indicators
- Tag (benign / suspicious / malicious)
- Add notes
- Save to workspace
- Export results
- Threat intelligence API integration (AbuseIPDB / VirusTotal)
- Case-based investigation tracking
- Timeline analytics for recurring IPs
- Automated reporting (PDF generation)
- Multi-user collaboration support
- API responses may vary depending on rate limits or availability
- Risk scoring is heuristic-based and intended for demonstration purposes
- Batch processing performance depends on API response time
- Geolocation accuracy may vary by IP source
If you encounter any issues or bugs, please open an issue in this repository.
data/investigations.csvis intended for local demo data only- Risk scoring is heuristic-based and for demonstration purposes only
- Not intended for production threat attribution
- Do not store sensitive or classified investigation data
This project is part of a professional cybersecurity portfolio. Reuse is permitted under license, but attribution is required. This project is for educational and demonstration purposes only.
© 2026 Eliza Ochoa - TANO Research
