Know the risk.
See the evidence.

Make better decisions about the traffic you trust. ACE v2 brings FraudGuard’s own threat observations, risk guidance, and IP context into one API response.

ACE v2 intelligence Example lookup
8.216.12.173 Critical risk

Alibaba Cloud Tokyo, Japan

Recommended actionBlock
85/100Confidence score
3Attack events
2Honeypots reached
2Target services

Observed in the prior 7 days

Jenkins probing2 events
HTTP / WAF probing1 event
See the evidence in the response
First-party threat evidence AI/ML intent verification Single + bulk IP lookups

Intelligence we collect ourselves

An IP is a clue.
Behavior is the evidence.

ACE stands for Attack Correlation Engine. Our honeypot network observes hostile activity firsthand. ACE connects those observations so you can see what an IP has actually done.

Explore a real IP
  1. 01

    Observe the behavior

    See attacks, targeted services, and recent activity captured across FraudGuard’s own proprietary threat network.

  2. 02

    Connect the signals

    Correlate repeat activity and honeypot reach. AI/ML layers help assess attack intent.

  3. 03

    Explain the recommendation

    Get a recommended action, risk level, confidence factors, and the evidence behind them.

The single IP lookup

One IP.
A decision you can explain.

Actionable guidance for your application.
Clear evidence for the people behind it.

ACE v2 single-ip.json

The complete example, from recommendation to network context.

{
  "ip": "8.216.12.173",
  "recommendation": {
    "action": "block",
    "evidence_summary": "This IP was observed performing 3 total attack events across 2 FraudGuard honeypots in the last 7 days, including 2 Jenkins probing events and 1 HTTP/WAF probing event, most recently on May 26, 2026 at 19:31 UTC.",
    "cache_ttl_seconds": 14400
  },
  "classification": {
    "primary": "web_scanner",
    "secondary": [
      "multi_service_scanner",
      "honeypot_attacker",
      "ai_automation",
      "hosting_provider"
    ]
  },
  "risk": {
    "level": 5,
    "label": "critical",
    "confidence": 85,
    "confidence_factors": [
      "recent_activity",
      "repeated_activity",
      "multi_honeypot_reach",
      "specific_attack_signature",
      "multiple_attack_types",
      "multiple_target_services"
    ]
  },
  "observed_activity": {
    "observed": true,
    "attack_families": [
      "web_probe"
    ],
    "activity": {
      "pattern": "burst",
      "trend": "burst",
      "attack_events_24h": 3,
      "attack_events_7d": 3,
      "attack_events_30d": 3,
      "distinct_attack_types_30d": 2,
      "distinct_target_services_30d": 2,
      "distinct_target_ports_30d": 2,
      "first_seen": "2026-05-26T15:45:54+00:00",
      "last_seen": "2026-05-26T19:31:59+00:00"
    },
    "attacks": [
      {
        "type": "jenkins_login_page_probe",
        "service": "jenkins",
        "protocol": "http",
        "destination_port": 8080,
        "attack_events_24h": 2,
        "attack_events_7d": 2,
        "attack_events_30d": 2,
        "honeypots_reached_24h": 1,
        "honeypots_reached_7d": 1,
        "honeypots_reached_30d": 1,
        "first_seen": "2026-05-26T15:45:54+00:00",
        "last_seen": "2026-05-26T15:45:57+00:00"
      },
      {
        "type": "waf_attack",
        "service": "http",
        "protocol": "http",
        "destination_port": 80,
        "attack_events_24h": 1,
        "attack_events_7d": 1,
        "attack_events_30d": 1,
        "honeypots_reached_24h": 1,
        "honeypots_reached_7d": 1,
        "honeypots_reached_30d": 1,
        "first_seen": "2026-05-26T19:31:59+00:00",
        "last_seen": "2026-05-26T19:31:59+00:00"
      }
    ],
    "last_observed_attack": {
      "event_type": "waf_attack",
      "service": "http",
      "protocol": "http",
      "destination_port": 80,
      "observed_at": "2026-05-26T19:31:59+00:00"
    }
  },
  "attributes": {
    "ai_automation_suspected": {
      "detected": true
    }
  },
  "reasons": [
    {
      "code": "abusive_activity_observed",
      "message": "Abusive activity observed by FraudGuard ACE",
      "severity": "high"
    },
    {
      "code": "scanner_activity_observed",
      "message": "Scanner or probing activity observed",
      "severity": "medium"
    },
    {
      "code": "honeypot_interaction_observed",
      "message": "Interaction observed across FraudGuard honeypot infrastructure",
      "severity": "high"
    },
    {
      "code": "waf_attack_activity_observed",
      "message": "HTTP/WAF attack activity observed",
      "severity": "high"
    },
    {
      "code": "activity_within_7_days",
      "message": "Activity observed within the last 7 days",
      "severity": "high"
    }
  ],
  "customer": {
    "ip_in_whitelist": false,
    "ip_in_blacklist": false,
    "ip_in_geoblock": false
  },
  "infrastructure": {
    "type": "hosting_provider",
    "provider": "Alibaba Cloud",
    "is_tor_exit": false,
    "is_public_proxy": false,
    "is_vpn": false,
    "is_hosting_provider": true,
    "is_residential_proxy": false,
    "is_mobile_network": false,
    "is_satellite_network": false,
    "is_shared_exit": false,
    "is_ai_agent": false,
    "first_seen": "2026-05-18T02:44:12+00:00",
    "last_seen": "2026-05-18T15:07:09+00:00",
    "updated_at": "2026-05-18T15:07:09+00:00"
  },
  "network": {
    "asn": 45102,
    "asn_org": "Alibaba US Technology Co., Ltd.",
    "isp": "Alibaba",
    "organization": "Alibaba",
    "prefix": "8.216.12.0/24",
    "connection_type": "Corporate"
  },
  "geography": {
    "country": "Japan",
    "isocode": "JP",
    "state": "Tokyo",
    "city": "Tokyo",
    "postal_code": "102-0082",
    "timezone": "Asia/Tokyo",
    "latitude": 35.6893,
    "longitude": 139.6899
  },
  "metadata": {
    "request_id": "acev2_example_single_lookup",
    "generated_at": "2026-05-27T00:47:35+00:00",
    "schema_version": "2.0.0",
    "api_version": "2.0.0",
    "engine": "ace_v2"
  }
}

Put the intelligence to work

Better context.
Where every decision counts.

One source of IP intelligence.
Across your fraud and security workflows.

Protect account access

Spot risky sources at signup and login. Add IP evidence to your defenses against credential stuffing, account takeover, and automated abuse.

Signups · Logins · Account recovery

Assess checkout risk

Bring observed abuse, proxy and VPN signals, and location into payment reviews. Decide when a transaction deserves another check.

Payments · Promo abuse · Fraud review

Sharpen security decisions

Enrich WAF events, API traffic, and analyst queues with attacker history. Give your team the context to investigate and act.

WAF · SIEM / SOAR · API security

A few useful details

Before you build.

Read the integration docs
Can I try ACE v2 before integrating it?

Yes. Use the public IP lookup to explore the recommendation, evidence, and infrastructure context for an IP you know. When you’re ready to test ACE v2 in your application, start a free trial.

Where does your threat intelligence come from?

FraudGuard’s own honeypot network observes attacker behavior directly. ACE v2 correlates those observations and uses AI/ML layers to help assess intent, so you can review the activity behind a recommendation.

Does ACE v2 block traffic for me?

ACE v2 recommends allow, challenge, or block. Your application or security integration decides how to act. Your whitelist, blacklist, and geoblock matches are returned separately so you can apply your own policy.

Is a VPN or hosting IP automatically a threat?

No. Infrastructure is context. Consider VPN, proxy, Tor, and hosting signals alongside observed behavior, the ACE recommendation, and your own traffic before taking action.

Does a low risk score mean I should allow an IP?

Start with ACE v2’s recommended action, then apply your own policy. A low score can still carry a challenge recommendation. Combine the IP evidence with your own login, payment, and application signals to decide what to trust.

Can I look up one IP or enrich a whole dataset?

Both. Single IP intelligence is available on Professional and above. Bulk IP intelligence is available on Business and above for logs, queues, and larger datasets. Compare plans for allowances and pricing.

See it for yourself

Start with an IP you know.

Explore the evidence in a public lookup.
Then put ACE v2 behind your next decision.