Skip to main content

API Playground

API console

Build a request. Inspect the response.

API reference
ismalicious / playground
Without API key
GET/api/check?query=8.8.8.8

Full analysis

Threat intelligence and enrichment for an indicator.

Try an example
AuthenticationOptional

X-API-KEY · Base64(apiKey:apiSecret)

Requests use your API quota or the anonymous allowance.

cURL
curl 'https://ismalicious.com/api/check?query=8.8.8.8'

Response

Your response appears here

Send a request to inspect its body, headers and timing.

idle

API reference

Explore all endpoints and code examples.

Spec merges Rust (api.ismalicious.com) with Next.js scam routes on ismalicious.com/api (/analyze, phone, crypto, email). Pick the matching server in Scalar before “Try it”. Written examples also in API docs.
Reference

Every endpoint you can call from this playground

63 operations across 20 groups, generated from isMalicious - Threat Intelligence API v1.2.0 — the same OpenAPI document the interactive reference above loads.

Production server
https://api.ismalicious.com
Next.js web API (analyze / phone / crypto / email)
https://ismalicious.com/api
Auth header
X-API-KEY
MethodEndpointPurpose
monitoring— Watch ownership and authenticated monitoring
POST/monitoring/claim-pendingVerified pending watches transferred, possibly partially
check— Threat intelligence check endpoints for IPs, domains, URLs, and file hashes
GET/bulk/checkBulk check limits and usage
POST/bulk/checkBulk entity check
GET/checkFull Threat Analysis
GET/check/certificatesCheck Certificates
GET/check/locationCheck Geolocation
POST/check/passwordBreach exposure of a password, checked as an indicator.
GET/check/reputationCheck Reputation
GET/check/streamReport stream (SSE)
GET/check/tenantMicrosoft 365 tenant
GET/check/vulnerabilitiesCheck Vulnerabilities
GET/check/whoisCheck WHOIS
POST/indicator-contextExisting evidence with optional, separately metered context qualification
GET/pwned-passwords/range/{prefix}k-anonymity lookup in Have I Been Pwned's Pwned Passwords corpus.
search— Search for similar malicious domains
POST/searchSearch Keywords
blocklist— Download blocklists and read their generation stats
GET/blocklist/download/{filename}Download Blocklist
GET/blocklist/statsGet Blocklist Stats
submit— Submit new threat intelligence sources
POST/submitSubmit Sources
gate— isinjected gate: prompt-injection scanning and link reputation for AI agents (own scan meter)
GET/gate/quotaGET /gate/quota
POST/gate/scanPOST /gate/scan
GET/gate/urlGET /gate/url?u=
mail— Inbound-message scan: what a mail's structure and the dataset say about it (gate scan meter, one unit per message)
POST/mail/scanPOST /mail/scan
platform— Dataset freshness and data-ops pipeline status
GET/platform/data-freshnessDataset freshness, version, and SLA status
GET/platform/data-ops/pipelineData operations pipeline phases and last recorded run
cases— SOC case workspace: cases and their evidence timeline
GET/casesCase workspace list, wrapped as `{"cases": […]}`
POST/casesCreated case
PATCH/cases/{id}Updated case
POST/cases/{id}/evidenceUpdated case with appended evidence
action-center— Prioritized SOC action queue
GET/action-center/overviewPrioritized SOC action center overview
alerts— Alerting trends and metrics
GET/alerts/trendsOpened/resolved per day plus MTTR percentiles for the signed-in scope
webhooks— Webhook event catalog
GET/user/webhooks/eventsSupported webhook events, signature scheme, and management path
briefs— Executive risk briefs
GET/risk-brief/latestLatest organization risk brief summary
trust— Trust assessment contract
GET/trust/assessment/schemaCanonical trust assessment field contract
taxii— TAXII 2.1 / STIX 2.1 threat-intelligence feed (Pro and Enterprise). Never decrements the monthly request quota
GET/taxiiTAXII discovery
GET/taxii/api-rootTAXII API root
GET/taxii/api-root/collectionsList TAXII collections
GET/taxii/api-root/collections/{collectionId}Get a TAXII collection
GET/taxii/api-root/collections/{collectionId}/manifestGet object manifests
GET/taxii/api-root/collections/{collectionId}/objectsGet collection objects
POST/taxii/api-root/collections/{collectionId}/objectsAdd objects (refused)
GET/taxii/api-root/collections/{collectionId}/objects/{objectId}Get an object
GET/taxii/api-root/collections/{collectionId}/objects/{objectId}/versionsGet object versions
GET/taxii/api-root/status/{statusId}Get status
stats— Public dataset statistics — no authentication, not metered
GET/statsPublic dataset statistics
cve— CVE catalog: lookup by id, search and recent list (authenticated, one request each) and public statistics (EPSS, exploitation signals, time series — no authentication, not metered)
GET/cveCVE lookup, search and recent list
GET/cve/{id}CVE by id (path form)
GET/cve/recentRecent CVEs (bare array)
GET/cve/stats/epssCVE EPSS statistics
GET/cve/stats/timeseriesCVE time series
ransomware— Ransomware intelligence from the cached ransomware.live datasets: victims, groups, sectors, press. Authenticated, one request each except `/ransomware/live-quota`
GET/ransomware/feedRecent ransomware victims
GET/ransomware/group-profileRansomware group profile
GET/ransomware/groupsRansomware groups
GET/ransomware/live-quotaransomware.live call budget
GET/ransomware/pressRansomware press
GET/ransomware/sector-riskSector risk
GET/ransomware/sector-risk/historySector risk history
GET/ransomware/sector-victimsSector victims
GET/ransomware/statsRansomware statistics
Scam Intelligence— Next.js routes for analyze / email / phone / crypto (ismalicious.com/api).
POSTismalicious.com/api/analyzeUnified analyze (auto-detect type)
GETismalicious.com/api/check/cryptoCheck crypto wallet address
GETismalicious.com/api/check/emailCheck email address
GETismalicious.com/api/check/phoneCheck phone number risk
Account
POSTismalicious.com/api/keys/instantGet an API key instantly (email only)

Calling one without the playground

# X-API-KEY carries Base64(apiKey:apiSecret)
curl -H "X-API-KEY: $ISMALICIOUS_KEY" \
  "https://api.ismalicious.com/check?query=example.com"