Integration

Microsoft Sentinel

TAXII 2.1 threat intelligence ingest

Use Sentinel’s built-in Threat Intelligence TAXII connector. No custom Content Hub solution is required — isMalicious already speaks STIX 2.1.

Capabilities

Key Features

Everything you need to protect your infrastructure and users

Content Hub TAXII connector

Install the Threat Intelligence solution, then add a TAXII server with the isMalicious API root.

Collection IDs

malicious-ips, malicious-domains, malicious-urls, c2-indicators, phishing-indicators, and more.

Score before you block

Filter on x_opencti_score. ≥ 60 for auto-block, 40–59 for analyst review.

Optional event push

SOC events can also land in Log Analytics via the dashboard Sentinel destination (Pro).

Applications

Use Cases

How security teams use this tool

Indicator matching

Match Sentinel logs against isMalicious IPs and domains ingested over TAXII.

Hunting

Use C2 and phishing collections as hunting seeds, not as a raw firewall dump.

Firewall follow-through

High-score IPs from malicious-ips can feed EDL or blocklist workflows after review.

Connect in Sentinel

  1. Content management → Content hub → install Threat Intelligence.
  2. Data connectors → Threat Intelligence - TAXII → Open connector page → Add.
  3. Friendly name: isMalicious
  4. API root URL: https://api.ismalicious.com/taxii2/api-root
  5. Collection ID: malicious-ips or malicious-domains
  6. Username api, password = your dashboard API credential (Base64 of apiKey:apiSecret).
  7. Polling frequency: hourly is enough for most SOCs.
Support

Frequently Asked Questions

Is there a custom isMalicious app in the Sentinel Content Hub?

No. Sentinel already ships a Threat Intelligence TAXII connector. Point it at the isMalicious TAXII 2.1 API root and a collection ID. The dashboard Log Analytics destination is a separate outbound path for SOC events, not indicator ingest.

What URL do I enter as the API root?

https://api.ismalicious.com/taxii2/api-root — not the discovery URL. Discovery is https://api.ismalicious.com/taxii2/.

How do I authenticate?

Use Basic Auth: username api and password equal to the Base64 API credential shown in Dashboard → Account → Team Management (the same value as the X-API-KEY header). Bearer token with that same value also works on the TAXII server.

Which collection should I start with?

malicious-ips or malicious-domains. Filter on x_opencti_score after ingest: ≥ 60 for auto-block, 40–59 for review. The malicious-ips collection is a broad intelligence set, not a confirmed-only blocklist.
Get Started

Ready to Get Started?

Join thousands of security teams using isMalicious to protect their infrastructure.