Skip to main content
Real-time threat intelligence

Threat intelligence for your SIEM
and security products

Investigate indicators with source evidence, add STIX/TAXII feeds to your tools, or check links and content from an AI assistant. Start with a lookup below, then connect the access method your team needs.

Find your integration path
IPDomainURLEmailPhoneWalletHashCVE
Multi-source
Evidence
Request-time
Lookups
As published
Events
Trusted by SOC teams worldwide
From indicator to evidenceIllustrative example
203.0.113.42IPv4
ReputationBlocklists
ActivityObservations
NetworkASN · ports
Cross-reference
203.0.113.42IP
Example
Score92

Example verdict

Malicious
Reputation
Malicious
Source: Blocklists
Activity
Command & control
Source: Observations
Network
Ports 443 · 8443
Source: ASN · ports
Reserved IP address and fictional findings. Your report uses the available source data.

Put the data to work

Start with the way your team works

Choose a first step you can evaluate in your own workflow.

Enrich your security product

Test reputation checks on your indicators. Inspect the response and source evidence before building an integration.

A free API key includes a monthly allowance for reputation checks.

Test the APIExplore lookup tools

Bring threat feeds into your tools

Prepare a STIX/TAXII evaluation for OpenCTI, a SIEM, or a firewall. Define the collections and import workflow you need.

STIX/TAXII access requires Pro or Enterprise. Feed polling is outside the monthly lookup quota.

Evaluate a feed in my toolRead the OpenCTI guide

Check from your AI assistant

Connect the MCP server to look up indicators, check links, and scan untrusted content within an agent workflow.

Connect with a free API key. Reputation checks and prompt-injection scans have separate allowances.

Install the MCP serverTry the content scanner
Trusted by security teams worldwide
HKCERT
Houston University
ICS
Kimoshiro
National Grid
Tehtris
Xfinit
By the numbers

Indexed

Threat Records

Malicious IPs, domains, URLs, and file hashes tracked across the globe — refreshed continuously.

463

Intelligence Sources

Configured feeds are reliability-weighted so SOC teams can see why a verdict was produced.

Active

New Threats (24h)

Indicators indexed in the last day. Continuous monitoring means you always query the latest intelligence.

Multiple

Source Evidence

Assessments show contributing sources so analysts can review agreement and conflicts.

Capabilities

What Powers the Platform

Inspect the sources behind each result, then bring the data into your product, your security tools, or your AI assistant.

The evidence

Multi-Source Verdicts

Cross-reference threat feeds and enrichment data. Each result exposes contributing sources and detected categories so you can examine the verdict.

Threat IntelSource AgreementIOC Feeds

The context

Full Enrichment Profiles

WHOIS, DNS history, SSL certificates, ASN, geolocation, abuse contacts, and tech stack — resolved in one pass so analysts stop juggling five tabs.

domain.recordEXAMPLE
Domain
example.com
DNS A
192.0.2.1
WHOIS
Sample record

Sample record · DNS and WHOIS

01 / API

One Request, Full Verdict

A REST API designed for developers: reputation, sources, categories, and history in a single JSON response. SDKs, OpenAPI spec, and copy-paste examples included.

REST APISDKsOpenAPI

02 / STIX · TAXII

Feeds in your security tools

Bring indicators into OpenCTI or your SIEM through STIX/TAXII. Choose the collections that match your environment.

03 / MCP

Checks for your AI agents

Look up indicators, check links, and scan suspicious content from your AI assistant with the MCP server.

Model Context Protocol

Bring threat intelligence to your AI agents.

Connect Claude, Cursor or Codex to indicator reputation, CVE intelligence and prompt injection detection with the isMalicious MCP server.

Explore the MCP server and setup guide
check_indicator · get_cve · recent_cves
Investigate IPs, domains and file hashes, look up a CVE, or review newly published vulnerabilities.
scan_before_use
Scan text from web pages, documents, or tool responses for prompt injection before your agent uses it.
check_url
Look up a URL's threat reputation before your agent follows the link.
How it works

See It in Action

terminal
$ curl -H "X-API-Key: $KEY" https://api.ismalicious.com/v1/check/192.168.1.1
Snippet showing IP/domain check response
Data Sources

573+ Verified Intelligence Sources

Real-time threat intelligence aggregated from industry-leading providers, community feeds, and proprietary detection engines.

573/647
domain262
ip236
mixed24
hash12
SourceTypeReliabilityTier
AbuseIPDBipA
URLhausurlA
Community IOC feedsmixedB
IsMaliciousmultiA
+569More Sources
Free account

You Just Ran a Check. Here's What You're Missing.

Anonymous checks show the verdict. A free account includes the analysis, the history, and the API behind it — in under a minute.

AI-generated assessmentFree API KeySaved Reports & HistoryMonitoring & AlertsExports

No credit card required · 500 free checks/month · Free API key

FAQ

Frequently Asked Questions

Anything else? Reach out to us.

What data does the API return?
Security score, threat reputation, WHOIS, geolocation, TLS certificates, vulnerabilities, identifier lists, and similar suspicious entities — all from a single query.
How often is data refreshed?
All data is refreshed once per day to ensure daily accuracy across all indexed records.
What are the API usage limits?
Anonymous visitors can run 10 checks per hour from the website. A free account or free API key raises that to 60 requests per minute and 500 checks per month. Paid plans scale from there: Pro includes 10,000 checks per month at 60 requests per minute, and Enterprise goes up to 1M checks per month.
Can I try before buying?
Yes. Create a free account for higher dashboard limits, or request an API key for programmatic access. Paid plans unlock higher throughput and commercial use.
Who is isMalicious for?
SOC teams, MSSPs, developers building security products, and anyone who needs fast IP, domain, URL, and hash reputation checks.