Skip to main content
Real-time threat intelligence

Threat Intel API
for Security Teams

Check any IP, domain, URL, email, phone, crypto wallet, file hash, or CVE against the industry's largest live indicator dataset — through a REST API, dashboard, or real-time stream. Free API key, no credit card required.

IPDomainURLEmailPhoneWalletHashCVE
Multi-source
Evidence
Request-time
Lookups
As published
Events
+1 719 620 threats indexed today
check185.220.101.47⌘K
92
185.220.101.47MaliciousTor exit
AS205100 · DE Frankfurt · 14/89 engines · 412 ms
FieldValueConf.
reputationmalicious0.86
abuse_confidence100 %0.98
classificationanonymizer, scanner0.79
tor_exittrue (since 2019)1.00
ports.open22, 80, 443, 90010.80
engines.gsb
streamingstreaming 7/987 rowsTTFP 412 mscache MISS
Trusted by security teams worldwide
HKCERT
Houston University
ICS
Kimoshiro
National Grid
Tehtris
Xfinit
By the numbers

0M+

Threat Records

Malicious IPs, domains, URLs, and file hashes tracked across the globe — refreshed continuously.

524

Intelligence Sources

Configured feeds are reliability-weighted so SOC teams can see why a verdict was produced.

0M+

New Threats (24h)

Indicators indexed in the last day. Continuous monitoring means you always query the latest intelligence.

0%

Source Evidence

Assessments show contributing sources so analysts can review agreement and conflicts.

Current dataUpdated continuously

What's Happening Right Now

A sample from our live feed. Registered users see the full picture.

Current data

What's Happening Right Now

Updated continuously
Ransomware Activity
high severityAyuntamiento de Velilla de San Antoniokairos · Government & DefenseAug 20
high severityCyrus******shinyhunters · TechnologyAug 20
high severityNetExamemperador · TechnologyAug 20
high severityBe Mediaplay · TechnologyAug 20
Recent CVEs
medium severityCVE-2026-76990A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unCVSS 7.3
medium severityCVE-2026-76833@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute aCVSS 7.8
medium severityCVE-2026-76635baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticateCVSS 7.2
Logged-in users see the full record set, full IOC context, and real-time alertsFull feed
Capabilities

What Powers the Platform

Every check fans out across hundreds of intelligence sources, correlates the evidence, and returns one explainable verdict — in a single API call.

Multi-Source Verdicts

Aggregate Shodan, GreyNoise, AbuseIPDB, community feeds, and hundreds more vetted providers. Every verdict shows which sources agreed, how reliable they are, and why the score was produced — evidence a SOC can act on.

Threat IntelSource AgreementIOC Feeds

Full Enrichment Profiles

WHOIS, DNS history, SSL certificates, ASN, geolocation, abuse contacts, and tech stack — resolved in one pass so analysts stop juggling five tabs.

AI-generated Analysis

LLM summaries turn raw enrichment into a threat narrative with recommended next steps, tailored to the indicator in front of you.

MITRE ATT&CK Mapping

IOCs map automatically to ATT&CK techniques from threat tags and findings — triage faster with structured threat models.

One Request, Full Verdict

A REST API designed for developers: reputation, sources, categories, and history in a single JSON response. SDKs, OpenAPI spec, and copy-paste examples included.

REST APISDKsOpenAPI

Monitoring & Alerts

Watch critical IPs and domains 24/7. Get notified the moment a watched asset turns suspicious or its threat status changes.

Bulk & Streaming Checks

Thousands of indicators per request over the bulk API, or progressive results streamed over SSE for long-running lookups.

Blocklist Exports

Firewall-ready blocklists by threat family, refreshed continuously and exportable straight into your perimeter.

Similarity Search

Fuzzy matching surfaces look-alike domains and related infrastructure, exposing coordinated campaigns behind a single IOC.

How it works

See It in Action

terminal
$ curl -H "X-API-Key: $KEY" https://api.ismalicious.com/v1/check/192.168.1.1
Snippet showing IP/domain check response
Data Sources

594+ Verified Intelligence Sources

Real-time threat intelligence aggregated from industry-leading providers, community feeds, and proprietary detection engines.

594/643
domain281
ip240
mixed26
hash13
SourceTypeReliabilityTier
AbuseIPDBipA
URLhausurlA
Community IOC feedsmixedB
IsMaliciousmultiA
+590More Sources
Free account

You Just Ran a Check. Here's What You're Missing.

Anonymous checks show the verdict. A free account includes the analysis, the history, and the API behind it — in under a minute.

AI-generated assessmentFree API KeySaved Reports & HistoryMonitoring & AlertsExports

No credit card required · 30 free checks/month · Free API key

FAQ

Frequently Asked Questions

Anything else? Reach out to us.

What data does the API return?
Security score, threat reputation, WHOIS, geolocation, TLS certificates, vulnerabilities, identifier lists, and similar suspicious entities — all from a single query.
How often is data refreshed?
All data is refreshed once per day to ensure daily accuracy across all indexed records.
What are the API usage limits?
Website / Dashboard: Anonymous 10 request / 60 min (30/month); Free Account 10 request / minute (30/month). API Access: Free API Key 10 request / 60 min (30/month); Basic 1 requests / min (2,000/month); Pro 60 requests / min (10,000/month).
Can I try before buying?
Yes. Create a free account for higher dashboard limits, or request an API key for programmatic access. Paid plans unlock higher throughput and commercial use.
Who is isMalicious for?
SOC teams, MSSPs, developers building security products, and anyone who needs fast IP, domain, URL, and hash reputation checks.