Skip to main content

Integrations

Direct Security Integrations

Connect isMalicious to your existing security stack

Native connectors for OpenCTI and Cortex, STIX/TAXII feeds for Sentinel and MISP, dashboard destinations for Splunk, Elastic, Slack, and Teams, plus firewall blocklists, a ChatGPT GPT, and an n8n community node.

Listed integrations
27
Standard feed
TAXII 2.1
Enrichment
Real-time
Tier available
Free
How the data reaches your tools

isMalicious

api.ismalicious.com

  • Blocklists over HTTPS

    13
    • FortiGate
    • Palo Alto Networks
    • pfSense
    • OPNsense
    • MikroTik
    • Linux nftables
    • Pi-hole
    • AdGuard Home
    • Splunk lookups and ES
    • Elastic Security
    • Wazuh
    • Suricata
    • IBM QRadar
  • TAXII 2.1 collections

    5
    • STIX/TAXII 2.1
    • Microsoft Sentinel
    • MISP
    • Elastic Security
    • IBM QRadar
  • Lookups through the API

    6
    • OpenCTI
    • Cortex / TheHive
    • IntelOwl
    • MISP
    • ChatGPT GPT
    • n8n
  • Push to your tools

    6
    • Splunk HEC
    • Elastic
    • Sentinel Log Analytics
    • Slack
    • Microsoft Teams
    • Webhooks
On this page09

Firewalls and network

Setup guides for the firewall or router you run, sized to its limits.

  • FortiGate

    IP and domain threat feeds that FortiOS downloads with basic authentication

    • External connector, no relay
    • Lists sized to FortiOS limits
    • Firewall policies and DNS filter
    • Full list on paid plans
    Blocklists
    6 stepsEvery paid plan
  • Palo Alto Networks

    External Dynamic Lists of malicious IPs and domains, sized to PAN-OS limits

    • Client authentication with a certificate profile
    • 50,000 riskiest critical IPs
    • DNS sinkhole for domains
    • Full list on paid plans
    Blocklists
    6 stepsEvery paid plan
  • pfSense

    IP and domain lists for URL Table aliases and pfBlockerNG, through a relay

    • Relay with a netrc file
    • URL Table alias or pfBlockerNG
    • DNSBL for the domain lists
    • Full list on paid plans
    BlocklistsRelay
    6 stepsEvery paid plan
  • OPNsense

    IP lists as URL Table aliases with Basic authorization, domains through a relay

    • Authorized URL Table alias (25.1+)
    • Certificate check turned on
    • Unbound blocklists via a relay
    • Full list on paid plans
    BlocklistsOptional relay
    7 stepsEvery paid plan
  • MikroTik

    Threat domains as a RouterOS DNS adlist, fetched with your API key

    • RouterOS 7.15 and later
    • Fetch with HTTP Basic
    • Scheduled refresh script
    • Full list on paid plans
    Blocklists
    6 stepsEvery paid plan
  • Linux nftables

    Threat IPs as nftables sets on any Linux host, refreshed by a systemd timer

    • curl with a root-only netrc file
    • IPv4 and IPv6 sets, one transaction
    • Hourly check, lists rebuilt every 12 h
    • Full list on paid plans
    Blocklists
    5 stepsEvery paid plan

DNS resolvers

Setup guides that block threat domains at the resolver.

  • Pi-hole

    Threat domains as an authenticated Pi-hole adlist

    • Plain or adblock syntax
    • API key in the list address
    • Gravity every 12 hours
    • Full list on paid plans
    BlocklistsOptional relay
    6 stepsEvery paid plan
  • AdGuard Home

    Threat domains as an authenticated AdGuard Home DNS blocklist

    • Adblock syntax, subdomains included
    • API key in the list URL
    • 12-hour update interval
    • Full list on paid plans
    BlocklistsOptional relay
    6 stepsEvery paid plan

SIEM and detection

Setup guides that match logs and network traffic against isMalicious indicators.

  • Splunk lookups and ES

    Threat lists as Splunk lookups and Enterprise Security sources

    • Lookups rebuilt every 12 hours
    • Enterprise Security threat lists
    • HEC push from the dashboard
    • Full list on paid plans
    BlocklistsPush
    8 stepsEvery paid planPro and Enterprise
  • Elastic Security

    TAXII 2.1 collections for the Custom Threat Intelligence integration and indicator match rules

    • Custom Threat Intelligence 1.8.2+
    • Indicator match rules
    • Value lists without TAXII
    • TAXII on Pro and Enterprise
    TAXII 2.1BlocklistsPush
    7 stepsEvery paid planPro and Enterprise
  • Wazuh

    Threat IPs and domains as Wazuh CDB lists, refreshed by a cron script

    • CDB lists from a cron script
    • IPv6 keys quoted
    • Hot reload from 4.13
    • Full list on paid plans
    Blocklists
    7 stepsEvery paid plan
  • Suricata

    Threat IPs and domains as Suricata datasets, reloaded with the rules

    • Datasets of type ip and string
    • DNS and HTTP host rules
    • Rule reload, no restart
    • Full list on paid plans
    Blocklists
    6 stepsEvery paid plan
  • IBM QRadar

    Threat IPs and domains as QRadar reference sets, refilled through the REST API

    • Reference sets of type IP and ALNIC
    • Asynchronous bulk update
    • Python 3, standard library only
    • Full list on paid plans
    BlocklistsTAXII 2.1
    8 stepsEvery paid planPro and Enterprise

TIP and incident response

Install isMalicious where analysts already enrich observables.

  • Native enrichment connector for the OpenCTI threat intelligence platform

    • IPv4, IPv6, and Domain enrichment
    • Risk score with threat labels
    • Listed on Filigran Hub
    • Docker deployment ready
  • Official analyzer for Cortex SOAR and TheHive incident response

    • IP, domain, and FQDN analysis
    • Risk scoring with taxonomies
    • TheHive case enrichment
    • Official Cortex-Analyzers repo
  • Observable analyzer that adds isMalicious scores to IntelOwl playbooks

    • IPv4, IPv6, domain, and URL analysis
    • Drop-in analyzer module
    • Playbook compatible
    • Same /check API as Cortex

Feeds

STIX/TAXII 2.1 collections. Sentinel and MISP consume the feed — they do not need a custom IsMalicious app.

  • Standard TAXII collections for TIPs, SIEMs, and custom clients

    • Discovery at api.ismalicious.com/taxii2/
    • IPs, domains, URLs, hashes, C2
    • Basic Auth or X-API-KEY
    • Works with any TAXII 2.1 client
  • Ingest isMalicious indicators through Sentinel’s built-in TAXII connector

    • Content Hub Threat Intelligence solution
    • TAXII 2.1 API root and collection IDs
    • Score-filter before auto-block
    • Optional Log Analytics destination
  • Pull TAXII collections into MISP now; native expansion module for live lookups

    • TAXII 2.1 server ingest
    • Expansion and hover module
    • IP, domain, hostname, URL
    • Score, categories, sources

SIEM and chat destinations

Configure from the dashboard. These are outbound destinations, not Splunkbase or Elastic Fleet apps.

  • Push IOCs and SOC events to Splunk through HTTP Event Collector

    • Configure in the dashboard
    • IOC sync plus event delivery
    • Pro plan
    • Not a Splunkbase app
  • Index IOCs and SOC events with the Elastic Bulk API

    • Configure in the dashboard
    • NDJSON bulk ingest
    • Pro plan
    • Custom index and pipeline
  • Push normalized telemetry to a Log Analytics table for Sentinel hunts

    • Configure in the dashboard
    • Workspace ID and shared key
    • Pro plan
    • Use TAXII for indicator ingest
  • Post threat, monitor, and CVE alerts to a Slack channel

    • Incoming webhook
    • Event-only (no bulk IOC sync)
    • Paid plans
    • Configure in the dashboard
  • Post SOC alerts as Adaptive Cards to a Teams channel

    • Workflow webhook
    • Event-only (no bulk IOC sync)
    • Paid plans
    • Configure in the dashboard

AI and automation

Lookups in ChatGPT, an n8n community node, and HTTPS webhooks.

  • Look up IPs, domains, hashes, and emails from ChatGPT without leaving chat

    • Live /check lookups
    • Free API key for IP, domain and hash checks
    • Email & ransomware lookups without a key, 5 per conversation a day
    • Ransomware search
  • Community node that looks up an IP, domain, or URL from an n8n workflow

    • Check IOC node
    • n8n-nodes-ismalicious
    • No extra runtime deps
    • Same /check API as Cortex
  • Receive eight platform events on an HTTPS endpoint you control

    • threat.detected, monitor.alert, report.created
    • CVE findings, cases, dataset freshness
    • Signed deliveries (whsec_*)
    • Paid plans

Build Your Own Integration

Use the REST API and the official TypeScript SDK (@ismalicious/sdk). Python, Go, and Rust clients are not published yet — call /check with X-API-KEY, or generate a client from OpenAPI.

Integration Use Cases

How security teams use isMalicious integrations

  • SOC Alert Enrichment

    Automatically enrich security alerts with threat context and risk scores for faster triage.

  • Automated Threat Hunting

    Integrate threat intelligence into hunting workflows for proactive threat detection.

  • Incident Response

    Accelerate investigations with instant IOC enrichment during incident response.

  • Custom Integrations

    Build custom integrations using the REST API and the TypeScript SDK.

Questions

Do I need a paid plan to use integrations?

The free plan includes an API key for individual reputation checks. STIX/TAXII feeds, including feed imports into OpenCTI or a SIEM, require Pro or Enterprise. Feed polling is outside the monthly lookup quota on those plans. Check each integration guide for its access requirements.

How do I get an API key?

Sign up for a free account at ismalicious.com, navigate to your dashboard, and generate an API key. It takes less than a minute.

Is the Cortex analyzer officially supported?

Yes! Our Cortex analyzer is included in the official Cortex-Analyzers repository (v3.6.8+) maintained by TheHive Project. It is production-ready and maintained by the isMalicious team.

How do I deploy the OpenCTI connector?

The OpenCTI connector can be deployed via Docker using docker-compose or manually with Python. Full deployment instructions are available on the OpenCTI integration page.

Can I request a new integration?

Yes. Contact us with the platform and the workflow you need. Native catalog submissions (IntelOwl, MISP modules, n8n) are in progress; Splunk, Elastic, and Sentinel already work as dashboard destinations or TAXII consumers.

What data types are supported?

We support IPv4 addresses, IPv6 addresses, domain names, FQDNs, and URLs across all integrations. Each integration may have specific supported types documented on its detail page.

How fresh is the threat intelligence data?

Our threat intelligence is updated in real-time from configured sources. When you query an IOC through any integration, you get the latest available threat data.

Integrations

Ready to Integrate?

Get started with isMalicious integrations in minutes. Free tier available for development and testing.

No credit card required · Free API key

Model Context Protocol

Bring threat intelligence to your AI agents.

Connect Claude, Cursor or Codex to indicator reputation, CVE intelligence and prompt injection detection with the isMalicious MCP server.

Explore the MCP server and setup guide
check_indicator · get_cve · recent_cves · check_password_exposure
Investigate IPs, domains and file hashes, look up a CVE, review newly published vulnerabilities, or check whether a password has leaked.
scan_before_use
Scan text from web pages, documents, or tool responses for prompt injection before your agent uses it.
check_url
Look up a URL's threat reputation before your agent follows the link.