Integration

MISP

TAXII ingest and live enrichment

Pull STIX 2.1 collections on a schedule, then enrich individual attributes with the isMalicious expansion module.

Capabilities

Key Features

Everything you need to protect your infrastructure and users

TAXII 2.1 server

Add isMalicious under Sync Actions → Servers and select collections to fetch.

Expansion + hover

Live /check lookups for IPs, domains, hostnames, and URLs without leaving the event.

Score and categories

Malicious flag, 0–100 risk score, threat categories, and detection source count.

Same credential

X-API-KEY / Basic Auth password is the dashboard Base64 API credential.

Applications

Use Cases

How security teams use this tool

Scheduled feed

Import malicious-ips and malicious-domains into events, then correlate with your own attributes.

Analyst hover

Hover an IP on an event to see the isMalicious score before expanding.

Sharing communities

Keep org-reported collections separate from the global malicious-* feeds.

TAXII server in MISP

  1. Sync Actions → Servers → New TAXII server.
  2. Discovery URL: https://api.ismalicious.com/taxii2/
  3. Username api, password = dashboard API credential.
  4. Start with malicious-domains and malicious-ips. Filter on score before using a collection as a blocklist.
Support

Frequently Asked Questions

Do I need a custom MISP plugin to ingest the feed?

No. Add isMalicious as a TAXII 2.1 server (Sync Actions → Servers) and pull collections. The expansion module is for live attribute lookups, not bulk ingest.

What is the discovery URL?

https://api.ismalicious.com/taxii2/ with Basic Auth username api and password equal to your API credential.

Where is the expansion module?

The module is proposed upstream in MISP/misp-modules#798. Until that merges, drop ismalicious.py into misp_modules/modules/expansion/ (auto-discovered).

Which attributes does the module enrich?

ip-src, ip-dst, hostname, domain, url, and domain|ip. Hover and expansion both return malicious flag, risk score, categories, and source count.
Get Started

Ready to Get Started?

Join thousands of security teams using isMalicious to protect their infrastructure.