Aller au contenu principal
Integration

MISP TAXII ingest and live enrichment

Pull STIX 2.1 collections on a schedule, then enrich individual attributes with the isMalicious expansion module.

No credit card required · Free API key

Capabilities

Key features. Everything you need to protect your infrastructure and users.

TAXII 2.1 server

Add isMalicious under Sync Actions → Servers and select collections to fetch.

Expansion + hover

Live /check lookups for IPs, domains, hostnames, and URLs without leaving the event.

Score and categories

Malicious flag, 0–100 risk score, threat categories, and detection source count.

Same credential

X-API-KEY, or Basic Auth with apiKey:apiSecret (legacy: password = the Base64 credential).

Applications

Use cases. How security teams use this tool.

Scheduled feed

Import malicious-ips and malicious-domains into events, then correlate with your own attributes.

Analyst hover

Hover an IP on an event to see the isMalicious score before expanding.

Sharing communities

Keep org-reported collections separate from the global malicious-* feeds.

TAXII server in MISP

  1. Sync Actions → Servers → New TAXII server.
  2. Discovery URL: https://api.ismalicious.com/taxii2/
  3. Username api, password = dashboard API credential.
  4. Start with malicious-domains and malicious-ips. Filter on score before using a collection as a blocklist.
Support

Frequently asked questions.

Do I need a custom MISP plugin to ingest the feed?

No. Add isMalicious as a TAXII 2.1 server (Sync Actions → Servers) and pull collections. The expansion module is for live attribute lookups, not bulk ingest.

What is the discovery URL?

https://api.ismalicious.com/taxii2/ with Basic Auth. Prefer username = API key and password = API secret. Username api with password = the Base64 credential still works.

Where is the expansion module?

The module is proposed upstream in MISP/misp-modules#798. Until that merges, drop ismalicious.py into misp_modules/modules/expansion/ (auto-discovered).

Which attributes does the module enrich?

ip-src, ip-dst, hostname, domain, url, and domain|ip. Hover and expansion both return malicious flag, risk score, categories, and source count.
Get started

Ready to get started?

Rejoignez des milliers d'équipes de sécurité qui utilisent isMalicious pour protéger leur infrastructure.

No credit card required · Free API key