Integrations
Direct Security Integrations
Connect isMalicious to your existing security stack
Native connectors for OpenCTI and Cortex, STIX/TAXII feeds for Sentinel and MISP, dashboard destinations for Splunk, Elastic, Slack, and Teams, plus firewall blocklists, a ChatGPT GPT, and an n8n community node.
- Listed integrations
- 27
- Standard feed
- TAXII 2.1
- Enrichment
- Real-time
- Tier available
- Free
isMalicious
api.ismalicious.com
Blocklists over HTTPS
13- FortiGate
- Palo Alto Networks
- pfSense
- OPNsense
- MikroTik
- Linux nftables
- Pi-hole
- AdGuard Home
- Splunk lookups and ES
- Elastic Security
- Wazuh
- Suricata
- IBM QRadar
TAXII 2.1 collections
5- Elastic Security
- IBM QRadar
Lookups through the API
6Push to your tools
6
On this page09
Firewalls and network
Setup guides for the firewall or router you run, sized to its limits.
FortiGate
IP and domain threat feeds that FortiOS downloads with basic authentication
- External connector, no relay
- Lists sized to FortiOS limits
- Firewall policies and DNS filter
- Full list on paid plans
Blocklists6 stepsEvery paid planPalo Alto Networks
External Dynamic Lists of malicious IPs and domains, sized to PAN-OS limits
- Client authentication with a certificate profile
- 50,000 riskiest critical IPs
- DNS sinkhole for domains
- Full list on paid plans
Blocklists6 stepsEvery paid planpfSense
IP and domain lists for URL Table aliases and pfBlockerNG, through a relay
- Relay with a netrc file
- URL Table alias or pfBlockerNG
- DNSBL for the domain lists
- Full list on paid plans
BlocklistsRelay6 stepsEvery paid planOPNsense
IP lists as URL Table aliases with Basic authorization, domains through a relay
- Authorized URL Table alias (25.1+)
- Certificate check turned on
- Unbound blocklists via a relay
- Full list on paid plans
BlocklistsOptional relay7 stepsEvery paid planMikroTik
Threat domains as a RouterOS DNS adlist, fetched with your API key
- RouterOS 7.15 and later
- Fetch with HTTP Basic
- Scheduled refresh script
- Full list on paid plans
Blocklists6 stepsEvery paid planLinux nftables
Threat IPs as nftables sets on any Linux host, refreshed by a systemd timer
- curl with a root-only netrc file
- IPv4 and IPv6 sets, one transaction
- Hourly check, lists rebuilt every 12 h
- Full list on paid plans
Blocklists5 stepsEvery paid plan
DNS resolvers
Setup guides that block threat domains at the resolver.
Pi-hole
Threat domains as an authenticated Pi-hole adlist
- Plain or adblock syntax
- API key in the list address
- Gravity every 12 hours
- Full list on paid plans
BlocklistsOptional relay6 stepsEvery paid planAdGuard Home
Threat domains as an authenticated AdGuard Home DNS blocklist
- Adblock syntax, subdomains included
- API key in the list URL
- 12-hour update interval
- Full list on paid plans
BlocklistsOptional relay6 stepsEvery paid plan
SIEM and detection
Setup guides that match logs and network traffic against isMalicious indicators.
Splunk lookups and ES
Threat lists as Splunk lookups and Enterprise Security sources
- Lookups rebuilt every 12 hours
- Enterprise Security threat lists
- HEC push from the dashboard
- Full list on paid plans
BlocklistsPush8 stepsEvery paid planPro and EnterpriseElastic Security
TAXII 2.1 collections for the Custom Threat Intelligence integration and indicator match rules
- Custom Threat Intelligence 1.8.2+
- Indicator match rules
- Value lists without TAXII
- TAXII on Pro and Enterprise
TAXII 2.1BlocklistsPush7 stepsEvery paid planPro and EnterpriseWazuh
Threat IPs and domains as Wazuh CDB lists, refreshed by a cron script
- CDB lists from a cron script
- IPv6 keys quoted
- Hot reload from 4.13
- Full list on paid plans
Blocklists7 stepsEvery paid planSuricata
Threat IPs and domains as Suricata datasets, reloaded with the rules
- Datasets of type ip and string
- DNS and HTTP host rules
- Rule reload, no restart
- Full list on paid plans
Blocklists6 stepsEvery paid planIBM QRadar
Threat IPs and domains as QRadar reference sets, refilled through the REST API
- Reference sets of type IP and ALNIC
- Asynchronous bulk update
- Python 3, standard library only
- Full list on paid plans
BlocklistsTAXII 2.18 stepsEvery paid planPro and Enterprise
TIP and incident response
Install isMalicious where analysts already enrich observables.
Native enrichment connector for the OpenCTI threat intelligence platform
- IPv4, IPv6, and Domain enrichment
- Risk score with threat labels
- Listed on Filigran Hub
- Docker deployment ready
Cortex / TheHive
OfficialOfficial analyzer for Cortex SOAR and TheHive incident response
- IP, domain, and FQDN analysis
- Risk scoring with taxonomies
- TheHive case enrichment
- Official Cortex-Analyzers repo
Observable analyzer that adds isMalicious scores to IntelOwl playbooks
- IPv4, IPv6, domain, and URL analysis
- Drop-in analyzer module
- Playbook compatible
- Same /check API as Cortex
Feeds
STIX/TAXII 2.1 collections. Sentinel and MISP consume the feed — they do not need a custom IsMalicious app.
Standard TAXII collections for TIPs, SIEMs, and custom clients
- Discovery at api.ismalicious.com/taxii2/
- IPs, domains, URLs, hashes, C2
- Basic Auth or X-API-KEY
- Works with any TAXII 2.1 client
Ingest isMalicious indicators through Sentinel’s built-in TAXII connector
- Content Hub Threat Intelligence solution
- TAXII 2.1 API root and collection IDs
- Score-filter before auto-block
- Optional Log Analytics destination
Pull TAXII collections into MISP now; native expansion module for live lookups
- TAXII 2.1 server ingest
- Expansion and hover module
- IP, domain, hostname, URL
- Score, categories, sources
SIEM and chat destinations
Configure from the dashboard. These are outbound destinations, not Splunkbase or Elastic Fleet apps.
Push IOCs and SOC events to Splunk through HTTP Event Collector
- Configure in the dashboard
- IOC sync plus event delivery
- Pro plan
- Not a Splunkbase app
Index IOCs and SOC events with the Elastic Bulk API
- Configure in the dashboard
- NDJSON bulk ingest
- Pro plan
- Custom index and pipeline
Push normalized telemetry to a Log Analytics table for Sentinel hunts
- Configure in the dashboard
- Workspace ID and shared key
- Pro plan
- Use TAXII for indicator ingest
Post threat, monitor, and CVE alerts to a Slack channel
- Incoming webhook
- Event-only (no bulk IOC sync)
- Paid plans
- Configure in the dashboard
Post SOC alerts as Adaptive Cards to a Teams channel
- Workflow webhook
- Event-only (no bulk IOC sync)
- Paid plans
- Configure in the dashboard
AI and automation
Lookups in ChatGPT, an n8n community node, and HTTPS webhooks.
Look up IPs, domains, hashes, and emails from ChatGPT without leaving chat
- Live /check lookups
- Free API key for IP, domain and hash checks
- Email & ransomware lookups without a key, 5 per conversation a day
- Ransomware search
Community node that looks up an IP, domain, or URL from an n8n workflow
- Check IOC node
- n8n-nodes-ismalicious
- No extra runtime deps
- Same /check API as Cortex
Receive eight platform events on an HTTPS endpoint you control
- threat.detected, monitor.alert, report.created
- CVE findings, cases, dataset freshness
- Signed deliveries (whsec_*)
- Paid plans
Build Your Own Integration
Use the REST API and the official TypeScript SDK (@ismalicious/sdk). Python, Go, and Rust clients are not published yet — call /check with X-API-KEY, or generate a client from OpenAPI.
Integration Use Cases
How security teams use isMalicious integrations
SOC Alert Enrichment
Automatically enrich security alerts with threat context and risk scores for faster triage.
Automated Threat Hunting
Integrate threat intelligence into hunting workflows for proactive threat detection.
Incident Response
Accelerate investigations with instant IOC enrichment during incident response.
Custom Integrations
Build custom integrations using the REST API and the TypeScript SDK.
Questions
Do I need a paid plan to use integrations?
The free plan includes an API key for individual reputation checks. STIX/TAXII feeds, including feed imports into OpenCTI or a SIEM, require Pro or Enterprise. Feed polling is outside the monthly lookup quota on those plans. Check each integration guide for its access requirements.
How do I get an API key?
Sign up for a free account at ismalicious.com, navigate to your dashboard, and generate an API key. It takes less than a minute.
Is the Cortex analyzer officially supported?
Yes! Our Cortex analyzer is included in the official Cortex-Analyzers repository (v3.6.8+) maintained by TheHive Project. It is production-ready and maintained by the isMalicious team.
How do I deploy the OpenCTI connector?
The OpenCTI connector can be deployed via Docker using docker-compose or manually with Python. Full deployment instructions are available on the OpenCTI integration page.
Can I request a new integration?
Yes. Contact us with the platform and the workflow you need. Native catalog submissions (IntelOwl, MISP modules, n8n) are in progress; Splunk, Elastic, and Sentinel already work as dashboard destinations or TAXII consumers.
What data types are supported?
We support IPv4 addresses, IPv6 addresses, domain names, FQDNs, and URLs across all integrations. Each integration may have specific supported types documented on its detail page.
How fresh is the threat intelligence data?
Our threat intelligence is updated in real-time from configured sources. When you query an IOC through any integration, you get the latest available threat data.
Integrations
Ready to Integrate?
Get started with isMalicious integrations in minutes. Free tier available for development and testing.
No credit card required · Free API key
Model Context Protocol
Bring threat intelligence to your AI agents.
Connect Claude, Cursor or Codex to indicator reputation, CVE intelligence and prompt injection detection with the isMalicious MCP server.
Explore the MCP server and setup guide- check_indicator · get_cve · recent_cves · check_password_exposure
- Investigate IPs, domains and file hashes, look up a CVE, review newly published vulnerabilities, or check whether a password has leaked.
- scan_before_use
- Scan text from web pages, documents, or tool responses for prompt injection before your agent uses it.
- check_url
- Look up a URL's threat reputation before your agent follows the link.