Aller au contenu principal
Integration

IntelOwl Analyzer Observable enrichment for IntelOwl playbooks

Call isMalicious from IntelOwl the same way Cortex does: GET /check with X-API-KEY. The analyzer PR is open against intelowlproject/IntelOwl develop.

No credit card required · Free API key

Capabilities

Key features. Everything you need to protect your infrastructure and users.

IP, domain, URL

Observable types match IntelOwl ip, domain, and url.

Same /check API

Malicious flag, risk score, categories, sources.

Playbook ready

Register via plugin.json; add to FREE_TO_USE_ANALYZERS if the free tier applies.

Drop-in module

Single Python file plus plugin.json for the upstream PR.

Applications

Use cases. How security teams use this tool.

Multi-analyzer jobs

Run isMalicious next to AbuseIPDB, GreyNoise, and VirusTotal in one IntelOwl job.

SOC playbooks

Include the analyzer in an existing playbook instead of a custom script.

Support

Frequently asked questions.

Is the analyzer in IntelOwl core yet?

The analyzer is proposed upstream in intelowlproject/IntelOwl#3936. Until that merges, copy packages/intelowl-analyzer/ismalicious.py into observable_analyzers and load the dumpplugin migration.

What observable types are supported?

ip, domain, and url. File hashes are not in the first analyzer revision.

How is it authenticated?

Secret api_key_name maps to ISMALICIOUS_API_KEY — the same Base64 credential used as X-API-KEY on api.ismalicious.com.
Get started

Ready to get started?

Rejoignez des milliers d'équipes de sécurité qui utilisent isMalicious pour protéger leur infrastructure.

No credit card required · Free API key