MISP TAXII ingest and live enrichment
Pull STIX 2.1 collections on a schedule, then enrich individual attributes with the isMalicious expansion module.
No credit card required · Free API key
Key features. Everything you need to protect your infrastructure and users.
TAXII 2.1 server
Add isMalicious under Sync Actions → Servers and select collections to fetch.
Expansion + hover
Live /check lookups for IPs, domains, hostnames, and URLs without leaving the event.
Score and categories
Malicious flag, 0–100 risk score, threat categories, and detection source count.
Same credential
X-API-KEY, or Basic Auth with apiKey:apiSecret (legacy: password = the Base64 credential).
Use cases. How security teams use this tool.
Scheduled feed
Import malicious-ips and malicious-domains into events, then correlate with your own attributes.
Analyst hover
Hover an IP on an event to see the isMalicious score before expanding.
Sharing communities
Keep org-reported collections separate from the global malicious-* feeds.
TAXII server in MISP
- Sync Actions → Servers → New TAXII server.
- Discovery URL:
https://api.ismalicious.com/taxii2/ - Username
api, password = dashboard API credential. - Start with
malicious-domainsandmalicious-ips. Filter on score before using a collection as a blocklist.
Frequently asked questions.
Do I need a custom MISP plugin to ingest the feed?
What is the discovery URL?
Where is the expansion module?
Which attributes does the module enrich?
Ready to get started?
Rejoignez des milliers d'équipes de sécurité qui utilisent isMalicious pour protéger leur infrastructure.
No credit card required · Free API key