IntelOwl Analyzer Observable enrichment for IntelOwl playbooks
Call isMalicious from IntelOwl the same way Cortex does: GET /check with X-API-KEY. The analyzer PR is open against intelowlproject/IntelOwl develop.
No credit card required · Free API key
Key features.
Available signals and integration options.
IP, domain, URL
Observable types match IntelOwl ip, domain, and url.
Same /check API
Malicious flag, risk score, categories, sources.
Playbook ready
Register via plugin.json; add to FREE_TO_USE_ANALYZERS if the free tier applies.
Drop-in module
Single Python file plus plugin.json for the upstream PR.
Use cases.
Workflows to evaluate with your existing tools.
Multi-analyzer jobs
Run isMalicious next to AbuseIPDB, GreyNoise, and VirusTotal in one IntelOwl job.
SOC playbooks
Include the analyzer in an existing playbook instead of a custom script.
Frequently asked questions.
Is the analyzer in IntelOwl core yet?
What observable types are supported?
How is it authenticated?
Related tools.
Ready to get started?
Test the available signals in your workflow. Review the sources and limits before integrating.
No credit card required · Free API key