Multi-Source Aggregation
Aggregate data from Shodan, GreyNoise, AbuseIPDB, community threat feeds, and other configured providers. One lookup returns source-attributed results.
Access 29M+ indicators — malicious IPs, domains and more — from 591 sources with at least one entry in the corpus
Aggregate data from Shodan, GreyNoise, AbuseIPDB, community threat feeds, and other configured providers. One lookup returns source-attributed results.
The same corpus served three ways: lookups through the REST API, downloadable IP and domain blocklists regenerated every 12 hours, and STIX 2.1 collections over TAXII 2.1 rebuilt every night.
Automatically map IOCs to MITRE ATT&CK techniques based on threat tags and enrichment findings. Accelerate triage and build structured threat models.
Distinct sources with at least one indicator in the corpus at the last nightly rebuild, and some of the providers behind them.
Counted when the corpus is rebuilt each night. The verdict for an indicator lists the sources that actually returned it.
| Source | Type |
|---|---|
| AbuseIPDB | ip |
| URLhaus | url |
| Community IOC feeds | mixed |
| IsMalicious | multi |
IsMalicious provides a threat intelligence database for cybersecurity professionals. It aggregates commercial, open-source and community feeds, rebuilds the corpus every night and keeps the sources behind every listing.
Use it as a lookup database, a blocklist source, or a SOC enrichment layer for IP reputation, domain reputation, URL scanning, CVE context, and ransomware intelligence.
Free tier available - No credit card required