TAXII 2.1 threat intelligence ingest
Use Sentinel’s built-in Threat Intelligence TAXII connector. No custom Content Hub solution is required — isMalicious already speaks STIX 2.1.
Everything you need to protect your infrastructure and users
Install the Threat Intelligence solution, then add a TAXII server with the isMalicious API root.
malicious-ips, malicious-domains, malicious-urls, c2-indicators, phishing-indicators, and more.
Filter on x_opencti_score. ≥ 60 for auto-block, 40–59 for analyst review.
SOC events can also land in Log Analytics via the dashboard Sentinel destination (Pro).
How security teams use this tool
Match Sentinel logs against isMalicious IPs and domains ingested over TAXII.
Use C2 and phishing collections as hunting seeds, not as a raw firewall dump.
High-score IPs from malicious-ips can feed EDL or blocklist workflows after review.
isMalicioushttps://api.ismalicious.com/taxii2/api-rootmalicious-ips or malicious-domainsapi, password = your dashboard API credential (Base64 of apiKey:apiSecret).Join thousands of security teams using isMalicious to protect their infrastructure.