Cortex / TheHive Analyzer
Official threat intelligence analyzer for Cortex SOAR
Included in the official Cortex-Analyzers repository. Analyze IPs, domains, and FQDNs with real-time threat intelligence from configured sources.
Analyzer Features
Comprehensive threat intelligence analysis for your security workflows
IP Address Analysis
Analyze IPv4 and IPv6 addresses for malicious activity and threat indicators.
Domain & FQDN Check
Check domains and fully qualified domain names against threat intelligence feeds.
Risk Scoring
Get a 0-100 risk score based on multi-source threat analysis with confidence weighting.
Threat Taxonomies
Automatic threat classification: Status, Risk Score, Category, and Source count.
TheHive Integration
Directly enrich cases and alerts in TheHive incident response platform.
Official Support
Included in official Cortex-Analyzers repository with ongoing maintenance.
Configuration
Simple setup with just two parameters
api_key
RequiredYour isMalicious API key. Get one for free at ismalicious.com
api_url
OptionalAPI endpoint URL. Defaults to https://ismalicious.com
Returned Taxonomies
Structured threat intelligence data for your workflows
StatusMalicious/Clean status based on threat analysis
Risk ScoreNumeric risk score (0-100) with confidence weighting
CategoryPrimary threat category (phishing, malware, C2, etc.)
SourcesNumber of detection sources that flagged the indicator
Frequently Asked Questions
Is the isMalicious analyzer officially supported?
What data types can I analyze?
How do I configure the analyzer?
Does it integrate with TheHive?
What taxonomies are returned?
Ready to Get Started?
Get your free API key and start analyzing threats with the official Cortex analyzer.