Investigate an entity and the ring around it
investigate_entityPivot from a single suspicious signup to connected fraud accounts by enriching email, IP, or device with cross-operator reputation and recent events.
Instructions
One call for what a fraud analyst actually wants. Returns enrichment for the entity, its reputation across the CROSS-OPERATOR abuse network (whether this email, IP or device has already burned other businesses, not just yours), and every recent event it appears in — which is how you get from one suspicious signup to the whole ring of accounts sharing its device, IP or inbox. Supply exactly one of email, ip or device_id. Enrichment consumes one row of monthly quota (device_id lookups are free).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ip | No | ||
| No | |||
| limit | No | How many recent events to scan. Default 100 | |
| device_id | No |