Bulk Analyze

Learn how to bulk upload a list of defanged indicators and extract information from the results.

Bulk Analyze lets you check multiple indicators simultaneously: perfect for triaging large IP or domain lists, assessing suspicious infrastructure, or analyzing indicators from alerts, logs, and threat feeds.

🚧

The New Bulk Experience is in Beta Mode

We are actively soliciting feedback from enterprise customers for the new Bulk Analysis experience. The new experience introduces a more complex workflow with additional data sources.

Prerequisites

You need:

  • A Validin Enterprise account (the new experience will be released to Professional Tier Individual accounts soon)
  • A list of indicators (domains, IPs, hashes) in defanged or raw format
📘

Limits and cost

A single bulk search accepts up to 100 indicators (Community) or 1,000 indicators (Enterprise). Each indicator searched costs 3 API queries, drawn from your daily/monthly quota. Community accounts can't start a search that would exceed their remaining quota.

Run a bulk search

  1. In the Validin dashboard, click Bulk Analyze.
  2. Add your indicators, separated by spaces. Press enter for new lines.
📘

Defanged indicators

Defanged indicators have malicious characters replaced with safe alternatives (e.g., hxxp:// instead of http://). Validin automatically parses defanged indicators from your input, including from complete threat reports.

  1. Select Next to review extracted indicators.

Review and configure

Extracted indicators appear in a tabulated view with Indicator and Type columns, plus a per‑indicator data source selector.

  1. Select an indicator to open a slide-out panel containing additional information, including:
    1. Reputation
    2. Usage
    3. Geolocation
  2. Click any available link to pivot across other sources of information.

Slide-out panel for a malicious IP address

  1. Edit an indicator with the pencil icon, or remove one with the trash icon (it's crossed out first, then confirm to delete). Use Add Another or Add Bulk to add more.
  2. Choose which data sources to run for each indicator: Resolutions, Extra DNS, Host Responses, and Registration. Toggle a whole column from its header checkbox, or use Select all / Clear all.
  3. (Optional) Under Search Criteria, set a date range with First seen after and Last seen before.
  4. The Summary shows counts by type and the cost to run (total API queries) before you commit.

Run the search

  1. Select Run Search.
  2. Give the search a name and optional description, and optionally enable Email me when the search completes.
  3. Confirm to start. You're taken to the job page.

Track and view results

  1. The job page shows a status badge (Queued / Running / Complete / Killed), a progress bar with indicators completed and API queries used, and a Kill button to stop a running search.
  2. Results are organized into tabs: Indicators, Resolutions, DNS Records, Host Connections, Host Responses, and Registration.
  3. Select a Host Connection row to open a slide-out with the host responses behind it.
  4. Use the icons on top of a results table to:
    1. Export rows as a CSV
    2. Add selected indicators to an existing or new Project
  5. Find all your past searches under Bulk Jobs.


Did this page help you?