Enrich your security product
Test reputation checks on your indicators. Inspect the response and source evidence before building an integration.
A free API key includes a monthly allowance for reputation checks.
Test the APIExplore lookup toolsInvestigate an IP, domain or suspicious link. See the sources behind the verdict, then bring the intelligence into your SIEM, product or AI assistant.
Example verdict
Malicious| Reputation | Malicious Source: Blocklists |
|---|---|
| Activity | Command & control Source: Observations |
| Network | Ports 443 · 8443 Source: ASN · ports |
| Evidence | Finding | Source |
|---|---|---|
| Reputation | Malicious | Blocklists |
| Activity | Command & control | Observations |
| Network | Ports 443 · 8443 | ASN · ports |
Put the data to work
Choose a first step you can evaluate in your own workflow.
Test reputation checks on your indicators. Inspect the response and source evidence before building an integration.
A free API key includes a monthly allowance for reputation checks.
Test the APIExplore lookup toolsPrepare a STIX/TAXII evaluation for OpenCTI, a SIEM, or a firewall. Define the collections and import workflow you need.
STIX/TAXII access requires Pro or Enterprise. Feed polling is outside the monthly lookup quota.
Evaluate a feed in my toolRead the OpenCTI guideConnect the MCP server to look up indicators, check links, and scan untrusted content within an agent workflow.
Connect with a free API key. Reputation checks and scans (prompt injection and email) have separate allowances.
Install the MCP serverTry the content scannerComparing before you choose? See the data products: blocklists, malware hashes and STIX/TAXII feeds, or how isMalicious compares with VirusTotal, AbuseIPDB and urlscan.io.
28M+
Threat Records
Malicious IPs, domains, URLs, and file hashes tracked across the globe — refreshed continuously.
726
Intelligence Sources
Configured feeds are reliability-weighted so SOC teams can see why a verdict was produced.
317K+
New Threats (24h)
Indicators indexed in the last day. Continuous monitoring means you always query the latest intelligence.
60%
Source Evidence
Assessments show contributing sources so analysts can review agreement and conflicts.
A sample from our live feed. Registered users see the full picture.
| Ransomware Activity | ||||
| high severitySlate Valley Unified School District | kairos · Education | — | Oct 1 | — |
| high severitysteelco | AuditTeam · Manufacturing | — | Oct 1 | — |
| high severityProMind IT | AuditTeam · Technology | — | Oct 1 | — |
| high severityDISK PRECISION GROUP - diskprecision.com | krybit · Manufacturing | — | Oct 1 | — |
| Recent CVEs | ||||
| medium severityCVE-2026-62060 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivat… | CVSS 7.6 | — | — |
| medium severityCVE-2026-62059 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate… | CVSS 7.6 | — | — |
| medium severityCVE-2026-103338 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimite… | CVSS 8.5 | — | — |
Inspect the sources behind each result, then bring the data into your product, your security tools, or your AI assistant.
No Card Required
Real-time threat intelligence aggregated from industry-leading providers, community feeds, and proprietary detection engines.
| Source | Type | Reliability | Tier |
|---|---|---|---|
| AbuseIPDB | ip | A | |
| URLhaus | url | A | |
| Community IOC feeds | mixed | B | |
| IsMalicious | multi | A |
Twelve free lookups, no account needed. Every tool runs against the same current dataset as the API.
Fire real requests against the live API from your browser — no key, no setup, instant JSON.
Reputation, geolocation, and abuse history for any IPv4/IPv6.
Threat verdicts and enrichment for any domain.
Scan links for phishing, malware, and redirects.
MD5, SHA-1, SHA-256 against malware corpora.
Registration records with risk signals parsed out.
Historical resolutions to trace infrastructure.
Spot newly-registered domains — a top phishing signal.
Every domain hosted behind an IP address.
Map the attack surface of any domain.
Ownership and reputation of network blocks.
Paste a list of indicators, triage them in one pass.
curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant500 free requests/month · instant API key · no signup form
Get started with basic threat intelligence. Perfect for individuals and small projects.
Live STIX/TAXII feeds for MISP, OpenCTI and your SIEM, plus 10,000 API checks/month.
For organizations that need higher volumes and help integrating threat intelligence into their tools.
A 550 5.7.1 rejection can involve recipient policy, authentication, or reputation. Use the full diagnostic and delivery traces to find the cause.
Identify trusted servers, interpret Authentication-Results, and investigate a suspicious email without confusing authentication with safe content.
Specify a public-sector threat intelligence service with clear evidence, data-handling rules, acceptance tests and an exit plan for UK and European teams.
Build a council network security plan around public services, clear ownership, tested segmentation and useful logs, with practical actions across 90 days.
Deploy protective DNS across public-sector sites and remote staff. Test coverage, handle exceptions and keep essential services available during failures.
Control supplier remote access with named identities, agreed work windows, bounded paths and verified revocation, using a practical public sector example.