Skip to main content

Threat intelligence. Evidence first.

Investigate an IP, domain or suspicious link. See the sources behind the verdict. Bring the intelligence into your SIEM, product or AI assistant. Start with 50 free API checks per month. The IsMalicious Free subscription plan costs €0 per month.

Start an investigation
Examples
Output
Find your integration path
From indicator to evidenceIllustrative example
203.0.113.42IPv4
ReputationBlocklists
ActivityObservations
NetworkASN · ports
Cross-reference
203.0.113.42IP
Example
Score92

Example verdict

Malicious
ReputationMaliciousSource: Blocklists
ActivityCommand & controlSource: Observations
NetworkPorts 443 · 8443Source: ASN · ports
Reserved IP address and fictional findings. Your report uses the available source data.
When available
Sources
Lookups
Request-time
Freshness
Per source

Why we built IsMalicious

Understand why something was flagged, see the evidence behind it, and make informed decisions in the tools you already use.

Jean-Vincent · Founder of IsMalicious

English audio · English and French captions

Read the transcript

Hi, I'm Jean, founder of IsMalicious. We help you investigate suspicious IPs, domains and URLs, and understand the evidence behind the signals. You can use that intelligence in your AI tools through MCP, in your SIEM with STIX and TAXII, or in your own applications through our API. We built this because a threat label alone isn't enough. You need sources and context to make a decision you can explain.

Start with the way your team works

External threat intelligence to compare with the tools your team already uses. Start with the workflow you can evaluate.

STIX / TAXII

Evaluate feeds in your existing tools

For SOC, MDR, MSSP and network teams using OpenCTI, MISP, a SIEM or a firewall. Compare indicators, import behavior and maintenance effort with your existing sources.

Collection rebuilds and your polling schedule are separate. Verify freshness and false positives before using indicators in blocking rules.

Pro: €99/month. Enterprise: quotation. TAXII polling is outside the lookup quota.

Evaluate a feed in my toolRead the OpenCTI guide
REST API

Test enrichment for your product

For developers and security product vendors. Run a reputation lookup, inspect the JSON and compare the available source evidence with what your product already knows.

Fields depend on the indicator, plan and available sources. Missing data requires further investigation. Redistribution and OEM rights require an agreement.

The free API key includes 50 lookups/month. Scans have a separate allowance.

Test the API with a free keyRead the API documentation
MCP

Evaluate a check in your AI assistant

For analysts already using a compatible AI assistant. Install the MCP server, run an actual indicator check and compare the context with your existing investigation tools.

Your workflow must call the tool and interpret its result. An unknown indicator or an allow decision is not proof of safety.

Use an API key. Reputation checks and prompt-injection scans have separate quotas.

Install and run a first checkTry the content scanner

Comparing before you choose? See the data products: blocklists, malware hashes and STIX/TAXII feeds, or how isMalicious compares with VirusTotal, AbuseIPDB and urlscan.io.

What Powers the Platform

Inspect the sources behind each result. Use 3 access methods to bring the data into your product, your security tools, or your AI assistant.

Multi-Source Verdicts

Cross-reference threat feeds and enrichment data. Each result exposes contributing sources and detected categories so you can examine the verdict. Risk scores run from 0 to 100.

  • Threat Intel
  • Source Agreement
  • IOC Feeds

Full Enrichment Profiles

7 types of context: WHOIS, DNS history, SSL certificates, ASN, geolocation, abuse contacts, and tech stack. Resolved in one pass so analysts stop juggling five tabs.

domain.recordEXAMPLE
Domain
example.com
DNS A
192.0.2.1
WHOIS
Sample record

Sample record · DNS and WHOIS

One Request, Full Verdict

A REST API designed for developers. Get reputation, sources, categories, and history in a single JSON response. Start with 50 free checks per month. SDKs, OpenAPI spec, and copy-paste examples included. The IsMalicious Free subscription plan costs €0 per month. Use an API key with the HTTP GET /api/check endpoint.

  • REST API
  • SDKs
  • OpenAPI

Feeds in your security tools

Bring indicators into OpenCTI or your SIEM through STIX 2.1/TAXII 2.1. Choose the collections that match your environment. The IsMalicious Pro monthly subscription plan includes STIX/TAXII access for €99 per month. Feed polling is outside the monthly API lookup quota.

Checks for your AI agents

Look up indicators, check links, and scan suspicious content from your AI assistant with the MCP server. Use 9 tools with an API key. The IsMalicious server supports MCP protocol version 2025-06-18. It communicates with the connected MCP client over the stdio transport.

No Card Required

An OpenCTI import you can inspect.

A captured TAXII sample, imported and read back in a local OpenCTI instance. Check what transferred, what changed and what still needs validation in your tool.

Local OpenCTI import

OpenCTI 6.9.13

An internal TAXII sample was imported into a disposable local OpenCTI instance and read back through GraphQL. This is a local validation, not a customer deployment.

Collection: malicious-ips

Indicators read back
18
Observables created
0
Indicators rejected
0
valid_until changed
18

TAXII capture:

Readback verified:

TAXII capture: 2 pages. More pages remained; the collection was not fully captured.

Validity dates changed during import. The cause is not established; verify expiration behavior in the workflow you evaluate.

No customer deployment or automated polling was validated.

Compare with your own workflow

Validate pagination, expiration and import effort in your own tool. This internal sample establishes neither a customer deployment nor a measured gain.

Evaluate a feed in my toolInspect the dated evidence JSON
Method and limits

Local OpenCTI import

An internal TAXII sample was imported into a disposable local OpenCTI instance and read back through GraphQL. This is a local validation, not a customer deployment.

No Observable or firewall export was established. Indicator enrichment and an export that requires Observables are different workflows.

No automated TAXII polling, customer production deployment, MISP/SIEM import or detection accuracy was validated.

834 catalogued Feed entries

The public catalogue lists feed entries and their configured status. These entries are different from contributing sources in the current corpus or live enrichment providers.

834/1009
domain282
ip408
mixed40
hash30
SourceType
AbuseIPDBip
URLhausurl
Community IOC feedsmixed
IsMaliciousmulti

Simple Pricing for
All Security Needs

MonthlyAnnual (Save 17%)
Free
€0forever

Get started with basic threat intelligence. Perfect for individuals and small projects.

  • 50 reputation checks/month
  • 60 checks/minute burst limit
  • Monitor up to 5 domains or IPs
  • Threat reports
  • Dashboard and API access
  • 1,000 scans/month (prompt injection and email)
Create free account
ProMost Popular
€99/month

Live STIX/TAXII feeds for MISP, OpenCTI and your SIEM, plus 10,000 API checks/month.

  • STIX/TAXII feeds — polling outside your monthly checks
  • 10,000 reputation checks/month
  • 60 checks/minute burst limit
  • Monitor up to 100 domains or IPs
  • Real-time email notifications
  • Detailed threat reports
  • Advanced API & bulk (up to 100 entities/request)
  • Up to 10 webhooks
  • Priority support
  • 250,000 scans/month (prompt injection and email)
Subscribe
Enterprise
Contact us

For organizations that need higher volumes and help integrating threat intelligence into their tools.

  • STIX/TAXII feeds — no page limit, polling outside your monthly checks
  • 1,000,000 IP/domain checks/month, 5,000 requests/minute burst limit
  • Monitor up to 10,000 domains and IPs
  • Custom notification systems
  • Advanced threat intelligence
  • Onboarding help wiring the feed into your tools
  • Custom API rate limits
  • On-premise deployment on request
  • Dedicated support
  • 1,000,000 scans/month (prompt injection and email)
Contact us

What's Happening Right Now

A sample from our live feed. Registered users see the full picture.

Ransomware Activity
high severityVadeto Groupqilin · Not FoundOct 9
high severityAnne Arundel Countyrhysida · Government & DefenseOct 9
high severityfleetworksinc.comthreeam · TransportationOct 9
high severityDW McMillan Memorial Hospitalthegentlemen · HealthcareOct 9
Recent CVEs
high severityCVE-2026-79842An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713CVSS 9.1
high severityCVE-2026-78406IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allo…CVSS 9.8
high severityCVE-2026-78401IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allo…CVSS 9.8
Logged-in users see the full record set, full IOC context, and real-time alertsFull feed →

CVE context, when you need it.

Vulnerability enrichment adds severity, known exploitation and a dated estimate. Inspect this captured API example alongside the primary sources.

API enrichment snapshot

CVE / API

CVE-2024-3400

Palo Alto Networks PAN-OS / GlobalProtect

CVSS severity
10.0
CISA KEV since
Apr 12, 2024
EPSS estimate
99.999%

API capture:

EPSS is a model estimate for the next 30 days. FIRST score date: Oct 08, 2026, checked separately.

This API example does not validate a feed import or protection of an asset.

Open the current CVE record

Compare with your own workflow

Check provenance, overlaps, useful additions, dates and import effort against your internal tools and CERT sources. No customer comparison or measured gain is established by these snapshots.

Inspect the dated evidence JSON
Method and limits

API enrichment snapshot

CVSS severity
10.0
CISA KEV since
Apr 12, 2024
EPSS estimate
99.999%
Product context
Palo Alto Networks PAN-OS / GlobalProtect
FIRST EPSS date (separate check)
Oct 08, 2026
CVE publication
Apr 12, 2024
Corroborating sources:
NVD · CISA KEV · FIRST / Empirical Security
EPSS date returned by this API
Not supplied in this capture

CVSS describes severity. EPSS estimates exploitation probability over the next 30 days; it is not certainty. These signals do not measure IsMalicious detection accuracy.

The EPSS date was checked separately with FIRST. The captured IsMalicious response does not return that score date. CISA KEV dates are historical catalogue dates.

Product context does not verify an installed version or an affected-package match.

The captured CVSS vector is absent and lastModified is empty. This is a selected response excerpt, not a coverage benchmark.

Reproduce the API lookup:

GET https://api.ismalicious.com/cve/CVE-2024-3400

Use authorized account credentials. This capture used an internal paid account; Free-tier access was not demonstrated.

Read the captured JSON excerpt

{
  "id": "CVE-2024-3400",
  "severity": "CRITICAL",
  "cvssScore": 10,
  "cvssVector": null,
  "published": "2024-04-12T08:15:06.230+00:00",
  "lastModified": "",
  "epssScore": 0.99999,
  "isKev": true,
  "kev": {
    "listed": true,
    "dateAdded": "2024-04-12T00:00:00+00:00",
    "dueDate": "2024-04-19T00:00:00+00:00"
  }
}

Frequently Asked Questions

Anything else? Reach out to us.

What data does the API return?
The available response depends on the indicator type and upstream data. It can include reputation, sources, observation dates, WHOIS, geolocation, certificates or DNS. Missing fields and contradictory signals require analyst review.
How often is data refreshed?
Freshness varies by source, ingestion schedule and cache state. Review the dates returned for each indicator. A client polling interval does not establish the age or accuracy of every record.
What are the API usage limits?
Anonymous visitors can run 10 checks per hour from the website. A free account or API key allows 60 requests per minute and 50 checks per month. Pro includes 10,000 checks per month at 60 requests per minute. Enterprise includes up to 1,000,000 checks per month.
Can I try before buying?
Use a free account or API key to evaluate individual reputation lookups within the Free quota. Feed access requires Pro or Enterprise. Agree any redistribution or OEM use separately.
Who is isMalicious for?
SOC teams, MSSPs, developers building security products, and anyone who needs fast IP, domain, URL, and hash reputation checks.

6 Stories from the Security Community

View all posts →