TAXII ingest and live enrichment
Pull STIX 2.1 collections on a schedule, then enrich individual attributes with the isMalicious expansion module.
Everything you need to protect your infrastructure and users
Add isMalicious under Sync Actions → Servers and select collections to fetch.
Live /check lookups for IPs, domains, hostnames, and URLs without leaving the event.
Malicious flag, 0–100 risk score, threat categories, and detection source count.
X-API-KEY / Basic Auth password is the dashboard Base64 API credential.
How security teams use this tool
Import malicious-ips and malicious-domains into events, then correlate with your own attributes.
Hover an IP on an event to see the isMalicious score before expanding.
Keep org-reported collections separate from the global malicious-* feeds.
https://api.ismalicious.com/taxii2/api, password = dashboard API credential.malicious-domains and malicious-ips. Filter on score before using a collection as a blocklist.Join thousands of security teams using isMalicious to protect their infrastructure.