Integration
IntelOwl Analyzer Observable enrichment for IntelOwl playbooks
Call isMalicious from IntelOwl the same way Cortex does: GET /check with X-API-KEY. The analyzer PR is open against intelowlproject/IntelOwl develop.
No credit card required · Free API key
Capabilities
Key features. Everything you need to protect your infrastructure and users.
IP, domain, URL
Observable types match IntelOwl ip, domain, and url.
Same /check API
Malicious flag, risk score, categories, sources.
Playbook ready
Register via plugin.json; add to FREE_TO_USE_ANALYZERS if the free tier applies.
Drop-in module
Single Python file plus plugin.json for the upstream PR.
Applications
Use cases. How security teams use this tool.
Multi-analyzer jobs
Run isMalicious next to AbuseIPDB, GreyNoise, and VirusTotal in one IntelOwl job.
SOC playbooks
Include the analyzer in an existing playbook instead of a custom script.
Support
Frequently asked questions.
Is the analyzer in IntelOwl core yet?
The analyzer is proposed upstream in intelowlproject/IntelOwl#3936. Until that merges, copy packages/intelowl-analyzer/ismalicious.py into observable_analyzers and load the dumpplugin migration.
What observable types are supported?
ip, domain, and url. File hashes are not in the first analyzer revision.
How is it authenticated?
Secret api_key_name maps to ISMALICIOUS_API_KEY — the same Base64 credential used as X-API-KEY on api.ismalicious.com.
Explore
Related tools.
Get started
Ready to get started?
Rejoignez des milliers d'équipes de sécurité qui utilisent isMalicious pour protéger leur infrastructure.
No credit card required · Free API key