Features

Everything you need tofight threats at scale

One platform. One API. From real-time reputation checks to CVE monitoring, ransomware intel, and STIX/TAXII feeds.

No credit card required · 30 free checks/month
0M+
Threat indicators

IPs, domains, URLs, file hashes — refreshed continuously

570
Data sources

NVD, CISA KEV, EPSS, GHSA, CERT-FR, OTX, and many more

~100ms
Median API latency

Globally distributed edge for sub-second responses

24/7
Real-time updates

Stream API and webhooks for instant propagation

The full capability set

Twelve capabilities, one platform. Available on every paid plan unless noted.

Real-time reputation checks

Look up an IP, domain, URL, or file hash across configured feeds and review the contributing sources.

IPs, domains, URLs, MD5/SHA1/SHA256 hashesAggregated from NVD, OTX, AbuseIPDB, Shodan, GreyNoise + 500 moreSub-100ms median response

CVE Watch

Monitor your stack for new vulnerabilities with CPE-based perimeters and exploit-likelihood scoring.

CISA KEV, EPSS, CERT-FR, GHSA, Exploit-DB, Nuclei templatesMulti-perimeter support — group assets by environmentFilter by severity, exploitability, vendor advisory

Ransomware intelligence

Search victim databases, map group TTPs, and track sector-level risk in real time.

Active groups, recent victims, country/sector breakdownIOC matching against ransomware-linked infrastructureGroup profiles with known techniques

AI-generated assessment

LLM-generated narratives with automatic MITRE ATT&CK mapping for any check result.

Streaming responses for low-latency triageTTPs mapped to MITRE techniques and tacticsContext-aware, not generic threat copy

Real-time stream API

Server-Sent Events for sub-second threat propagation — no polling, no missed updates.

Subscribe to new-threat, reputation-change, and monitoring-alert eventsFilter by severity and categoryBacked by webhooks for durable delivery

Monitoring & alerts

Watch domains, IPs, and certificates 24/7. Get notified the moment something changes.

Email, webhook, or stream-based alertsReputation flips, new IOCs, certificate expirationPer-asset notification rules

Bulk operations

Process up to 100 entities per request with bulk APIs designed for SIEM and SOAR pipelines.

Bulk reputation, WHOIS, certificate, and CVE lookupsStreaming progressive results for long jobsPlan-based concurrency limits

STIX / TAXII 2.1

Enterprise threat intel standard support — drop into any SOC stack that speaks TAXII.

Discoverable collections of structured indicatorsCompatible with OpenCTI, MISP, and most SIEMsAPI key auth, no broker required

Email risk analysis

Evaluate any email address for breach exposure, disposable domains, and DNS hygiene.

Breach corpus matchingDisposable / temp email detectionSPF, DKIM, DMARC, MX inspection

Phone scam checks

Score phone numbers for robocall and social-engineering risk with local and provider signals.

VOIP and fraud heuristicsOptional IPQS enrichment when configuredWorks via /api/check/phone and /report

Crypto wallet blacklist

Match BTC and ETH addresses against ScamSniffer and related scam indexes.

Local Redis index from open scam feedsCritical escalation on blacklist hitsPOST /api/analyze auto-detects wallets

Unified analyze API

One endpoint that auto-detects type and routes to the right check — links, emails, phones, wallets.

POST /api/analyze with optional input_typeSDK analyze() helper with webBaseUrlSame auth as other web API routes

Certificate monitoring

Track SSL/TLS certificates across your infrastructure and surface expirations before they bite.

Expiration, issuer change, and fingerprint mismatch alertsPer-domain certificate historyAdds certificate changes to monitoring alerts

Downloadable blocklists

Generated IP and domain blocklists you can drop straight into firewalls and DNS resolvers.

Multiple formats — plain text, CSV, hostsRefreshed continuouslyStable URLs for cron-based pulls

Webhooks & integrations

Custom webhooks for threat events, monitor alerts, and quota warnings — wire it to anything.

threat.detected, monitor.alert, report.created, usage.warningSigned payloads, retry with exponential backoffJS/TS SDK with typed event handlers

From zero to first call in 60 seconds

Register, copy your API key from the dashboard, and run any of these. Free tier works for all of them.

curlreputation-check.sh
curl -H "X-API-Key: $ISMALICIOUS_KEY" \
  "https://api.ismalicious.com/check/reputation?query=8.8.8.8"
Pythonreputation_check.py
import os, requests

r = requests.get(
    "https://api.ismalicious.com/check/reputation",
    params={"query": "8.8.8.8"},
    headers={"X-API-Key": os.environ["ISMALICIOUS_KEY"]},
)
print(r.json())
JavaScriptreputation-check.ts
import { IsMalicious } from "@ismalicious/sdk-js"

const client = new IsMalicious({ apiKey: process.env.ISMALICIOUS_KEY })
const result = await client.check("8.8.8.8")
console.log(result)

Drops into your existing stack

Talks to the tools your team already runs. Standards-first via STIX/TAXII, plus typed SDKs and signed webhooks.

SIEM & SOAR

  • Splunk
  • Elastic Security
  • Microsoft Sentinel
  • Wazuh
  • IBM QRadar
  • Cortex XSOAR
  • Tines
  • Torq

Threat intel platforms

  • OpenCTI
  • MISP
  • ThreatConnect
  • Anomali
  • Recorded Future
  • STIX 2.1
  • TAXII 2.1

Languages & SDKs

  • JavaScript / TypeScript SDK
  • Python (requests/httpx)
  • Go (net/http)
  • Rust (reqwest)
  • curl / bash
  • OpenAPI 3.1 spec

Output formats

  • JSON
  • CSV
  • Plain text blocklists
  • Hosts file
  • STIX 2.1 bundles
  • Webhook signed payloads

Looking for a specific connector? Browse all integrations →

What's included on each plan

CapabilityFreeProEnterprise
Reputation checks (all entity types)30/month10K/monthCustom
API accessRate-limited
Monitoring & email alerts5 assets100 assetsCustom
CVE Watch50 CPEsCustom
Bulk lookups10/request100/requestCustom
WebhooksUp to 10Custom
Stream API (SSE)
STIX / TAXII
AI-generated assessment
Ransomware intelligence
Email risk analysis
Phone & crypto scam checks
Unified analyze API
Downloadable blocklists

Need unlimited / on-prem / custom rate limits? See Enterprise →

See these features in action

Hands-on playbooks with copy-paste curl, Python, YARA, and SIEM examples — wired to the same API documented above.

Browse all playbooks

Frequently asked questions

Quick answers about features, plans, and integrations.

What can I do with the free tier?

The Free tier includes 30 reputation checks/month with rate-limited API access (no credit card). You can use the dashboard, generate an API key, monitor up to 5 assets, run reputation lookups for IPs/domains/URLs/hashes/emails/phones/wallets, query CVEs (50 CPEs in CVE Watch), and access ransomware intelligence and email risk endpoints. Paid features such as bulk batches up to 100, webhooks, the stream API, and STIX/TAXII require Pro (€99/mo) or Enterprise.

Which threat intelligence sources are aggregated?

isMalicious aggregates from configured sources including NVD, CISA KEV, EPSS, GHSA, CERT-FR, AlienVault OTX, AbuseIPDB, Shodan, GreyNoise, ThreatFox, URLhaus, Spamhaus, PhishTank, and many community feeds. Reputation results include source counts and per-source attribution so you can verify provenance.

How does CVE Watch differ from a CVE database lookup?

CVE Watch lets you define perimeters of CPE strings (the products and versions you actually run) and then continuously matches new CVEs to those perimeters with EPSS exploit-likelihood scores, CISA KEV flags, vendor advisories, and exploit availability. It is designed for ongoing monitoring rather than ad-hoc lookups; lookups remain available via /api/cve.

Do you support STIX and TAXII?

Yes. The Pro plan includes a TAXII 2.1 server with discoverable collections of STIX 2.1 objects. It is compatible with OpenCTI, MISP, and most modern SIEMs that speak TAXII. API key authentication only — no broker setup required.

How fresh is the data?

Most sources are ingested continuously and propagated through the stream API and webhooks within seconds. Aggregated reputation snapshots are refreshed multiple times per hour; CVE catalog entries (CVSS, EPSS, KEV flags) are updated as upstream feeds publish.

How does authentication work?

Send an X-API-Key header (or Authorization: Bearer) on every request. API keys are issued from the dashboard after registration; the Free tier includes API access at a rate-limited 30 requests/month, while Pro raises the quota and includes bulk, webhooks, and stream endpoints.

Is there an SDK?

Yes. The official JavaScript/TypeScript SDK (@ismalicious/sdk-js) ships typed methods for reputation checks, monitoring, CVE search, ransomware intel, AI-generated assessment, the SSE stream, reports, webhooks, and TAXII. Other languages are supported via the documented OpenAPI spec.

Can I deploy on-premise?

Yes — the Enterprise plan includes an on-premise deployment option with full feature parity, custom SLAs, and dedicated support. Contact sales for sizing and pricing.

How do bulk lookups work?

POST a JSON array of mixed IPs, domains, URLs, and hashes (up to 10 on Free, 100 on Pro per request) to /bulk/check. Each entity is processed in parallel and the response includes per-entity verdicts, source counts, and optional enrichment. For very large lists, pair bulk with the SSE stream to receive progressive results.

Are webhooks signed?

Yes. Webhook payloads are HMAC-signed with a per-webhook secret you set in the dashboard, and the platform retries with exponential backoff on 5xx and timeouts. Supported events include threat.detected, monitor.alert, report.created, and usage.warning.

Get a free API key

No credit card required. 30 checks/month, every feature you can run on the free plan.