Skip to main content
Real-time threat intelligence

Threat Intel API
for Security Teams

Check any IP, domain, URL, email, phone, crypto wallet, file hash, or CVE against the industry's largest live indicator dataset — through a REST API, dashboard, or real-time stream. Free API key, no credit card required.

IPDomainURLEmailPhoneWalletHashCVE
Multi-source
Evidence
Request-time
Lookups
As published
Events
Trusted by SOC teams worldwide
check185.220.101.47⌘K
92
185.220.101.47MaliciousTor exit
AS205100 · DE Frankfurt · 14/89 engines · 412 ms
FieldValueConf.
reputationmalicious0.86
abuse_confidence100 %0.98
classificationanonymizer, scanner0.79
tor_exittrue (since 2019)1.00
ports.open22, 80, 443, 90010.80
engines.gsb
streamingstreaming 7/987 rowsTTFP 412 mscache MISS
Trusted by security teams worldwide
HKCERT
Houston University
ICS
Kimoshiro
National Grid
Tehtris
Xfinit
By the numbers

Indexed

Threat Records

Malicious IPs, domains, URLs, and file hashes tracked across the globe — refreshed continuously.

485

Intelligence Sources

Configured feeds are reliability-weighted so SOC teams can see why a verdict was produced.

Active

New Threats (24h)

Indicators indexed in the last day. Continuous monitoring means you always query the latest intelligence.

Multiple

Source Evidence

Assessments show contributing sources so analysts can review agreement and conflicts.

Capabilities

What Powers the Platform

Every check fans out across hundreds of intelligence sources, correlates the evidence, and returns one explainable verdict — in a single API call.

Multi-Source Verdicts

Aggregate Shodan, GreyNoise, AbuseIPDB, community feeds, and hundreds more vetted providers. Every verdict shows which sources agreed, how reliable they are, and why the score was produced — evidence a SOC can act on.

Threat IntelSource AgreementIOC Feeds

Full Enrichment Profiles

WHOIS, DNS history, SSL certificates, ASN, geolocation, abuse contacts, and tech stack — resolved in one pass so analysts stop juggling five tabs.

AI-generated Analysis

LLM summaries turn raw enrichment into a threat narrative with recommended next steps, tailored to the indicator in front of you.

MITRE ATT&CK Mapping

IOCs map automatically to ATT&CK techniques from threat tags and findings — triage faster with structured threat models.

One Request, Full Verdict

A REST API designed for developers: reputation, sources, categories, and history in a single JSON response. SDKs, OpenAPI spec, and copy-paste examples included.

REST APISDKsOpenAPI

Monitoring & Alerts

Watch critical IPs and domains 24/7. Get notified the moment a watched asset turns suspicious or its threat status changes.

Bulk & Streaming Checks

Thousands of indicators per request over the bulk API, or progressive results streamed over SSE for long-running lookups.

Blocklist Exports

Firewall-ready blocklists by threat family, refreshed continuously and exportable straight into your perimeter.

Similarity Search

Fuzzy matching surfaces look-alike domains and related infrastructure, exposing coordinated campaigns behind a single IOC.

How it works

See It in Action

terminal
$ curl -H "X-API-Key: $KEY" https://api.ismalicious.com/v1/check/192.168.1.1
Snippet showing IP/domain check response
Data Sources

594+ Verified Intelligence Sources

Real-time threat intelligence aggregated from industry-leading providers, community feeds, and proprietary detection engines.

594/643
domain281
ip240
mixed26
hash13
SourceTypeReliabilityTier
AbuseIPDBipA
URLhausurlA
Community IOC feedsmixedB
IsMaliciousmultiA
+590More Sources
Free account

You Just Ran a Check. Here's What You're Missing.

Anonymous checks show the verdict. A free account includes the analysis, the history, and the API behind it — in under a minute.

AI-generated assessmentFree API KeySaved Reports & HistoryMonitoring & AlertsExports

No credit card required · 30 free checks/month · Free API key

FAQ

Frequently Asked Questions

Anything else? Reach out to us.

What data does the API return?
Security score, threat reputation, WHOIS, geolocation, TLS certificates, vulnerabilities, identifier lists, and similar suspicious entities — all from a single query.
How often is data refreshed?
All data is refreshed once per day to ensure daily accuracy across all indexed records.
What are the API usage limits?
Website / Dashboard: Anonymous 10 request / 60 min (30/month); Free Account 10 request / minute (30/month). API Access: Free API Key 10 request / 60 min (30/month); Basic 1 requests / min (2,000/month); Pro 60 requests / min (10,000/month).
Can I try before buying?
Yes. Create a free account for higher dashboard limits, or request an API key for programmatic access. Paid plans unlock higher throughput and commercial use.
Who is isMalicious for?
SOC teams, MSSPs, developers building security products, and anyone who needs fast IP, domain, URL, and hash reputation checks.