Check any indicator
Paste an IP, domain, URL, email, phone, wallet, or file hash — same lookup as the homepage, streamed into a full threat report.
Free to try · No credit card · Automate via API
What you get
One paste. Full context.
The report stream layers verdict, enrichment, and evidence as it arrives — built for triage, not a dashboard wall.
Multi-source verdict
Reputation, confidence, and source attribution in one stream.
Infrastructure context
WHOIS, DNS, geo, ASN, and SSL when the indicator supports it.
Hashes & scam vectors
File hashes, emails, phones, and wallets on the same report flow.
Analyst-ready output
HTML report in the browser, or JSON from the API check path.
Learn more
- isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.
- Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages
External dynamic lists can block malware and phishing at the edge — or break payroll, CDN traffic, and vendor portals. This guide covers staged rollout, allowlists, fail-open vs fail-closed, and measuring hit rates for IP and domain blocklists.
- STIX/TAXII Threat Feeds: Operational Guide for OpenCTI, MISP, and SIEM Pipelines
How to wire STIX 2.1 and TAXII 2.1 collections into OpenCTI, MISP, or your SIEM — what to poll, how to handle confidence and aging indicators, and where enrichment APIs fit alongside feed ingestion.