Skip to main content
External threat intelligence

Threat intelligence. Evidence first.

Investigate an IP, domain or suspicious link. See the sources behind the verdict. Bring the intelligence into your SIEM, product or AI assistant. Start with 50 free API checks per month. The IsMalicious Free subscription plan costs €0 per month.

Start an investigation
Examples
Output
Find your integration path
From indicator to evidenceIllustrative example
203.0.113.42IPv4
ReputationBlocklists
ActivityObservations
NetworkASN · ports
Cross-reference
203.0.113.42IP
Example
Score92

Example verdict

Malicious
ReputationMaliciousSource: Blocklists
ActivityCommand & controlSource: Observations
NetworkPorts 443 · 8443Source: ASN · ports
Reserved IP address and fictional findings. Your report uses the available source data.
When available
Sources
Lookups
Request-time
Freshness
Per source

Meet the founder

Why we built IsMalicious

Understand why something was flagged, see the evidence behind it, and make informed decisions in the tools you already use.

Jean-Vincent · Founder of IsMalicious

English audio · English and French captions

Read the transcript

Hi, I'm Jean, founder of IsMalicious. We help you investigate suspicious IPs, domains and URLs, and understand the evidence behind the signals. You can use that intelligence in your AI tools through MCP, in your SIEM with STIX and TAXII, or in your own applications through our API. We built this because a threat label alone isn't enough. You need sources and context to make a decision you can explain.

Put the data to work

Start with the way your team works

External threat intelligence to compare with the tools your team already uses. Start with the workflow you can evaluate.

STIX / TAXII

Evaluate feeds in your existing tools

For SOC, MDR, MSSP and network teams using OpenCTI, MISP, a SIEM or a firewall. Compare indicators, import behavior and maintenance effort with your existing sources.

Collection rebuilds and your polling schedule are separate. Verify freshness and false positives before using indicators in blocking rules.

Pro: €99/month. Enterprise: quotation. TAXII polling is outside the lookup quota.

Evaluate a feed in my toolRead the OpenCTI guide
REST API

Test enrichment for your product

For developers and security product vendors. Run a reputation lookup, inspect the JSON and compare the available source evidence with what your product already knows.

Fields depend on the indicator, plan and available sources. Missing data requires further investigation. Redistribution and OEM rights require an agreement.

The free API key includes 50 lookups/month. Scans have a separate allowance.

Test the API with a free keyRead the API documentation
MCP

Evaluate a check in your AI assistant

For analysts already using a compatible AI assistant. Install the MCP server, run an actual indicator check and compare the context with your existing investigation tools.

Your workflow must call the tool and interpret its result. An unknown indicator or an allow decision is not proof of safety.

Use an API key. Reputation checks and prompt-injection scans have separate quotas.

Install and run a first checkTry the content scanner

Comparing before you choose? See the data products: blocklists, malware hashes and STIX/TAXII feeds, or how isMalicious compares with VirusTotal, AbuseIPDB and urlscan.io.

By the numbers

725

Configured registry sources

Active entries in the configured source registry; not a contribution count

Counters unavailable. No estimated volumes are displayed.

Current dataUpdated continuously

What's Happening Right Now

A sample from our live feed. Registered users see the full picture.

Current data

What's Happening Right Now

Updated continuously
Ransomware Activity
high severityMCM Telecomqilin · TechnologyOct 8
high severityBaker McKenzieSilentRansomGroup · Professional ServicesOct 8
high severityManipal Academy of Higher EduUmBra · EducationOct 8
high severityIIT RoorkeeUmBra · EducationOct 8
Recent CVEs
high severityCVE-2026-76268In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patr…CVSS 9.8
medium severityCVE-2026-76266In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run com…CVSS 7.7
medium severityCVE-2026-107352Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenti…CVSS 7.7
Logged-in users see the full record set, full IOC context, and real-time alertsFull feed →
Capabilities

What Powers the Platform

Inspect the sources behind each result. Use 3 access methods to bring the data into your product, your security tools, or your AI assistant.

The evidence

Multi-Source Verdicts

Cross-reference threat feeds and enrichment data. Each result exposes contributing sources and detected categories so you can examine the verdict. Risk scores run from 0 to 100.

  • Threat Intel
  • Source Agreement
  • IOC Feeds

The context

Full Enrichment Profiles

7 types of context: WHOIS, DNS history, SSL certificates, ASN, geolocation, abuse contacts, and tech stack. Resolved in one pass so analysts stop juggling five tabs.

domain.recordEXAMPLE
Domain
example.com
DNS A
192.0.2.1
WHOIS
Sample record

Sample record · DNS and WHOIS

01 / API

One Request, Full Verdict

A REST API designed for developers. Get reputation, sources, categories, and history in a single JSON response. Start with 50 free checks per month. SDKs, OpenAPI spec, and copy-paste examples included. The IsMalicious Free subscription plan costs €0 per month. Use an API key with the HTTP GET /api/check endpoint.

  • REST API
  • SDKs
  • OpenAPI

02 / STIX · TAXII

Feeds in your security tools

Bring indicators into OpenCTI or your SIEM through STIX 2.1/TAXII 2.1. Choose the collections that match your environment. The IsMalicious Pro monthly subscription plan includes STIX/TAXII access for €99 per month. Feed polling is outside the monthly API lookup quota.

03 / MCP

Checks for your AI agents

Look up indicators, check links, and scan suspicious content from your AI assistant with the MCP server. Use 9 tools with an API key. The IsMalicious server supports MCP protocol version 2025-06-18. It communicates with the connected MCP client over the stdio transport.

No Card Required

Data Sources

834 catalogued Feed entries

The public catalogue lists feed entries and their configured status. These entries are different from contributing sources in the current corpus or live enrichment providers.

834/1009
domain282
ip408
mixed40
hash30
SourceTypeReliabilityTier
AbuseIPDBipA
URLhausurlA
Community IOC feedsmixedB
IsMaliciousmultiA
+830More Sources
Pricing

Simple Pricing for
All Security Needs

MonthlyAnnual (Save 17%)
Free
€0forever

Get started with basic threat intelligence. Perfect for individuals and small projects.

  • 50 reputation checks/month
  • 60 checks/minute burst limit
  • Monitor up to 5 domains or IPs
  • Threat reports
  • Dashboard and API access
  • 1,000 scans/month (prompt injection and email)
Create free account
ProMost Popular
€99/month

Live STIX/TAXII feeds for MISP, OpenCTI and your SIEM, plus 10,000 API checks/month.

  • STIX/TAXII feeds — polling outside your monthly checks
  • 10,000 reputation checks/month
  • 60 checks/minute burst limit
  • Monitor up to 100 domains or IPs
  • Real-time email notifications
  • Detailed threat reports
  • Advanced API & bulk (up to 100 entities/request)
  • Up to 10 webhooks
  • Priority support
  • 250,000 scans/month (prompt injection and email)
Subscribe
Enterprise
Contact us

For organizations that need higher volumes and help integrating threat intelligence into their tools.

  • STIX/TAXII feeds — no page limit, polling outside your monthly checks
  • 1,000,000 IP/domain checks/month, 5,000 requests/minute burst limit
  • Monitor up to 10,000 domains and IPs
  • Custom notification systems
  • Advanced threat intelligence
  • Onboarding help wiring the feed into your tools
  • Custom API rate limits
  • On-premise deployment on request
  • Dedicated support
  • 1,000,000 scans/month (prompt injection and email)
Contact us
FAQ

Frequently Asked Questions

Anything else? Reach out to us.

What data does the API return?
The available response depends on the indicator type and upstream data. It can include reputation, sources, observation dates, WHOIS, geolocation, certificates or DNS. Missing fields and contradictory signals require analyst review.
How often is data refreshed?
Freshness varies by source, ingestion schedule and cache state. Review the dates returned for each indicator. A client polling interval does not establish the age or accuracy of every record.
What are the API usage limits?
Anonymous visitors can run 10 checks per hour from the website. A free account or API key allows 60 requests per minute and 50 checks per month. Pro includes 10,000 checks per month at 60 requests per minute. Enterprise includes up to 1,000,000 checks per month.
Can I try before buying?
Use a free account or API key to evaluate individual reputation lookups within the Free quota. Feed access requires Pro or Enterprise. Agree any redistribution or OEM use separately.
Who is isMalicious for?
SOC teams, MSSPs, developers building security products, and anyone who needs fast IP, domain, URL, and hash reputation checks.
Blog

6 Stories from the Security Community

View all posts →