Skip to main content

Threat Intelligence Database

Access 29M+ indicators — malicious IPs, domains and more — from 591 sources with at least one entry in the corpus

Capabilities

What Powers
the Platform

01

Multi-Source Aggregation

Aggregate data from Shodan, GreyNoise, AbuseIPDB, community threat feeds, and other configured providers. One lookup returns source-attributed results.

Threat IntelData EnrichmentIOC Feeds
02

Feeds and Blocklists

The same corpus served three ways: lookups through the REST API, downloadable IP and domain blocklists regenerated every 12 hours, and STIX 2.1 collections over TAXII 2.1 rebuilt every night.

REST APIBlocklistsSTIX/TAXII 2.1
03

MITRE ATT&CK Mapping

Automatically map IOCs to MITRE ATT&CK techniques based on threat tags and enrichment findings. Accelerate triage and build structured threat models.

MITRE ATT&CKTTPsThreat Modeling

591 sources in the corpus

Distinct sources with at least one indicator in the corpus at the last nightly rebuild, and some of the providers behind them.

591

Counted when the corpus is rebuilt each night. The verdict for an indicator lists the sources that actually returned it.

SourceType
AbuseIPDBip
URLhausurl
Community IOC feedsmixed
IsMaliciousmulti

Comprehensive Threat Intelligence & Cybersecurity Database

IsMalicious provides a threat intelligence database for cybersecurity professionals. It aggregates commercial, open-source and community feeds, rebuilds the corpus every night and keeps the sources behind every listing.

Use it as a lookup database, a blocklist source, or a SOC enrichment layer for IP reputation, domain reputation, URL scanning, CVE context, and ransomware intelligence.

CategoryCoverage
Malicious IP DatabaseOur comprehensive malicious IP database identifies and tracks IP addresses involved in cyberattacks, malware distribution, phishing campaigns, and network abuse. Each IP is enriched with geolocation data, ASN information, threat categories, and confidence scores. Use our IP blocklist API to automatically block malicious traffic before it reaches your infrastructure.9M+ listed IPsMalwarePhishingBotnet C2DDoSBrute forceSpam & abuse
Malicious Domain DatabaseTrack malicious domains across the entire web. Our domain blocklist includes phishing sites, malware hosting domains, scam websites, adware networks, and tracking domains. Every domain is analyzed with WHOIS data, SSL certificates, and threat intelligence from multiple sources, with newly registered domains added as their feeds report them.19M+ listed domainsPhishingMalware hostingScamsAdwareTrackingC2
Phishing Database - Stop Credential TheftOur specialized phishing database tracks credential harvesting sites, fake login pages, and brand impersonation domains. Check a domain or URL through the API, with lookalike-domain detection and SSL certificate context.6M+ phishing indicatorsBrand impersonationNewly registered domainsLookalike domainsEmail link scanning
Malware & Adware IntelligenceComprehensive malware database covering ransomware, trojans, viruses, spyware, and more. Our adware blocklist protects users from invasive advertising, unwanted software, and aggressive marketing tactics. Includes vulnerability information and IOC data for incident response.23M+ malware indicatorsRansomwareTrojansAdwareSpyware
Tracking Domain Database - Protect User PrivacyBlock invasive surveillance with our tracking domain database. Identify analytics scripts, tracking pixels, fingerprinting services, and data brokers. Ensure GDPR compliance and protect user privacy by blocking unwanted tracking at the DNS or application level.301K+ tracking indicatorsGDPRPrivacyAd blocking
Vulnerability Database - Proactive SecurityBeyond blocklists, our vulnerability database provides deep intelligence on security weaknesses, exposed services, weak SSL certificates, open ports, and CVE mappings. Perfect for security audits, penetration testing, and continuous vulnerability management.SSL/TLS certificatesOpen portsCVE mappingEmail posture (DMARC, SPF)

Continuously updated intelligence & Developer Tools

Continuously Ingested Intelligence

  • Nightly rebuild - Feeds ingested on their own schedules, corpus rebuilt every night
  • 591 sources - Distinct sources with at least one indicator in the corpus
  • Multi-category - Malware, phishing, adware, tracking, spam
  • Confidence scoring - Reduce false positives

Blocklist API for Developers

  • RESTful API with comprehensive documentation
  • Sub-100ms response times for continuous monitoring
  • Flexible rate limits scaling with your needs
  • JSON responses with detailed threat metadata

Database Coverage & Statistics

29M+
Threat Records
591
Sources in the Corpus
313K+
New Threats (24h)

Use Cases for Our Threat Intelligence Database

  • Firewall and IDS/IPS - Block malicious IPs at the network perimeter
  • SIEM integration - Enrich security events with threat intelligence
  • Email security - Detect phishing domains and malicious links
  • Web application firewalls - Real-time request validation
  • Threat hunting - Proactive security investigations
  • Incident response - Fast IOC validation and enrichment
FAQ

Frequently Asked Questions

What types of threats does the database include?

The database covers malicious IPs, domains, and URLs across every major threat category: phishing sites, malware hosts, botnet command-and-control infrastructure, ransomware indicators, adware networks, tracking domains, and vulnerability intelligence with CVE mappings.

How often is the database updated?

The database is refreshed daily, with continuous ingestion from our source network around the clock. Newly registered domains, fresh phishing sites, and emerging threat infrastructure are added as sources report them, so blocklists and API responses always reflect current threat data.

Is there a free tier?

Yes. The free plan includes 50 checks per month and a free API key — no credit card required. It is a full-featured way to evaluate the database before upgrading to a paid plan for higher volume.

Can I export blocklists?

Yes. Blocklist exports are available on paid plans in formats ready for firewalls, DNS resolvers, and SIEM ingestion. PDF report exports are available for free.

Where does the data come from?

Threat data is aggregated from configured commercial, open-source, and community sources. Each source is reliability-weighted, and results expose source agreement and conflicts so analysts can review confidence.

Start Using Our Threat Intelligence Database

Free tier available - No credit card required