Skip to main content
Real-time threat intelligence+287 389 threats indexed today

Threat intelligence. Evidence first.

Investigate an IP, domain or suspicious link. See the sources behind the verdict. Bring the intelligence into your SIEM, product or AI assistant. Start with 500 free API checks per month. The IsMalicious Free subscription plan costs €0 per month.

Start an investigation
Examples
Output
Find your integration path
From indicator to evidenceIllustrative example
203.0.113.42IPv4
ReputationBlocklists
ActivityObservations
NetworkASN · ports
Cross-reference
203.0.113.42IP
Example
Score92

Example verdict

Malicious
ReputationMaliciousSource: Blocklists
ActivityCommand & controlSource: Observations
NetworkPorts 443 · 8443Source: ASN · ports
Reserved IP address and fictional findings. Your report uses the available source data.
Evidence
Multi-source
Lookups
Request-time
Events
As published

Meet the founder

Why we built IsMalicious

Understand why something was flagged, see the evidence behind it, and make informed decisions in the tools you already use.

Jean-Vincent · Founder of IsMalicious

English audio · English and French captions

Read the transcript

My name is John, and I’m the founder of IsMalicious. We help you investigate threats, connect AI through MCP, and feed your SIEM with STIX and TAXII feeds or our API. We’re doing this so you can understand why something was flagged, see the evidence behind it, and make informed decisions in the tools you already use.

Trusted by security teams worldwide
HKCERTHouston UniversityICSKimoshiroNational GridTehtrisXfinit

Put the data to work

Start with the way your team works

Choose from 3 access methods and evaluate a first step in your own workflow.

API

Enrich your security product

Test reputation checks on your indicators. Inspect the response and source evidence before building an integration. The IsMalicious Free subscription plan costs €0 per month. Call the HTTP GET /api/check endpoint with an API key to use the monthly allowance.

A free API key includes 500 reputation checks per month.

Test the APIExplore lookup tools
STIX / TAXII

Bring threat feeds into your tools

Prepare a STIX 2.1/TAXII 2.1 evaluation for OpenCTI, a SIEM, or a firewall. Define the collections and import workflow you need. The IsMalicious Pro monthly subscription plan includes STIX/TAXII access for €99 per month. Feed polling is outside the monthly API lookup quota.

STIX/TAXII access requires Pro or Enterprise. Feed polling is outside the monthly lookup quota.

Evaluate a feed in my toolRead the OpenCTI guide
MCP

Check from your AI assistant

Connect the MCP server to look up indicators, check links, and scan untrusted content. Use 9 tools with an API key. The IsMalicious server supports MCP protocol version 2025-06-18. It communicates with the connected MCP client over the stdio transport.

Connect with a free API key. Reputation checks and scans (prompt injection and email) have separate allowances.

Install the MCP serverTry the content scanner

Comparing before you choose? See the data products: blocklists, malware hashes and STIX/TAXII feeds, or how isMalicious compares with VirusTotal, AbuseIPDB and urlscan.io.

By the numbers

28M+

Threat Records

Malicious IPs, domains, URLs, and file hashes tracked across the globe — refreshed continuously.

725

Intelligence Sources

Configured feeds are reliability-weighted so SOC teams can see why a verdict was produced.

287K+

New Threats (24h)

Indicators indexed in the last day. Continuous monitoring means you always query the latest intelligence.

60%

Source Evidence

Assessments show contributing sources so analysts can review agreement and conflicts.

Current dataUpdated continuously

What's Happening Right Now

A sample from our live feed. Registered users see the full picture.

Current data

What's Happening Right Now

Updated continuously
Ransomware Activity
high severityGenesis Credit Managementqilin · Financial ServicesOct 3
high severityPrecon Marine Incnetrunner · TransportationOct 3
high severitySkaff Grouprhysida · OtherOct 3
high severitySt. Francis Healthcare Systems of HawaiiWallstreet · HealthcareOct 3
Recent CVEs
medium severityCVE-2026-82044UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attacke…CVSS 7.7
high severityCVE-2026-82042UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain f…CVSS 9.8
high severityCVE-2026-82041UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processC…CVSS 9.9
Logged-in users see the full record set, full IOC context, and real-time alertsFull feed →
Capabilities

What Powers the Platform

Inspect the sources behind each result. Use 3 access methods to bring the data into your product, your security tools, or your AI assistant.

The evidence

Multi-Source Verdicts

Cross-reference threat feeds and enrichment data. Each result exposes contributing sources and detected categories so you can examine the verdict. Risk scores run from 0 to 100.

  • Threat Intel
  • Source Agreement
  • IOC Feeds

The context

Full Enrichment Profiles

7 types of context: WHOIS, DNS history, SSL certificates, ASN, geolocation, abuse contacts, and tech stack. Resolved in one pass so analysts stop juggling five tabs.

domain.recordEXAMPLE
Domain
example.com
DNS A
192.0.2.1
WHOIS
Sample record

Sample record · DNS and WHOIS

01 / API

One Request, Full Verdict

A REST API designed for developers. Get reputation, sources, categories, and history in a single JSON response. Start with 500 free checks per month. SDKs, OpenAPI spec, and copy-paste examples included. The IsMalicious Free subscription plan costs €0 per month. Use an API key with the HTTP GET /api/check endpoint.

  • REST API
  • SDKs
  • OpenAPI

02 / STIX · TAXII

Feeds in your security tools

Bring indicators into OpenCTI or your SIEM through STIX 2.1/TAXII 2.1. Choose the collections that match your environment. The IsMalicious Pro monthly subscription plan includes STIX/TAXII access for €99 per month. Feed polling is outside the monthly API lookup quota.

03 / MCP

Checks for your AI agents

Look up indicators, check links, and scan suspicious content from your AI assistant with the MCP server. Use 9 tools with an API key. The IsMalicious server supports MCP protocol version 2025-06-18. It communicates with the connected MCP client over the stdio transport.

No Card Required

Data Sources

834+ Verified Intelligence Sources

Real-time threat intelligence aggregated from industry-leading providers, community feeds, and proprietary detection engines. The source registry marks 82.7% of its 1,009 entries as verified. Counts group verified sources by indicator type. The table shows example sources and their reliability tiers.

834/1009
domain282
ip408
mixed40
hash30
SourceTypeReliabilityTier
AbuseIPDBipA
URLhausurlA
Community IOC feedsmixedB
IsMaliciousmultiA
+830More Sources
Pricing

Simple Pricing for
All Security Needs

MonthlyAnnually
Free
€0/mo

Get started with basic threat intelligence. Perfect for individuals and small projects.

  • 500 reputation checks/month
  • 60 checks/minute burst limit
  • Monitor up to 5 domains or IPs
  • Basic threat reports
  • Dashboard and API access
  • 1,000 scans/month (prompt injection and email)
Create free account
ProMost popular
€99/mo

Live STIX/TAXII feeds for MISP, OpenCTI and your SIEM, plus 10,000 API checks/month.

  • STIX/TAXII feeds — polling outside your monthly checks
  • 10,000 reputation checks/month
  • 60 checks/minute burst limit
  • Monitor up to 100 domains or IPs
  • Real-time email notifications
  • Detailed threat reports
  • Advanced API & bulk (up to 100 entities/request)
  • Up to 10 webhooks
  • Priority support
  • 250,000 scans/month (prompt injection and email)
Subscribe
Enterprise
Contact us

For organizations that need higher volumes and help integrating threat intelligence into their tools.

  • STIX/TAXII feeds — no page limit, polling outside your monthly checks
  • 1,000,000 IP/domain checks/month
  • Monitor up to 10,000 domains and IPs
  • Custom notification systems
  • Advanced threat intelligence
  • Real-time database updates
  • Custom API rate limits
  • On-premise solution
  • Dedicated support
  • 1,000,000 scans/month (prompt injection and email)
Contact us
FAQ

Frequently Asked Questions

Anything else? Reach out to us.

What data does the API return?
Security score, threat reputation, WHOIS, geolocation, TLS certificates, vulnerabilities, identifier lists, and similar suspicious entities — all from a single query.
How often is data refreshed?
All data is refreshed once per day to ensure daily accuracy across all indexed records.
What are the API usage limits?
Anonymous visitors can run 10 checks per hour from the website. A free account or API key allows 60 requests per minute and 500 checks per month. Pro includes 10,000 checks per month at 60 requests per minute. Enterprise includes up to 1,000,000 checks per month.
Can I try before buying?
Yes. Create a free account for higher dashboard limits, or request an API key for programmatic access. Paid plans add higher throughput and commercial use.
Who is isMalicious for?
SOC teams, MSSPs, developers building security products, and anyone who needs fast IP, domain, URL, and hash reputation checks.
Blog

6 Stories from the Security Community

View all posts →