Microsoft Sentinel TAXII 2.1 threat intelligence ingest
Use Sentinel’s built-in Threat Intelligence TAXII connector. No custom Content Hub solution is required — isMalicious already speaks STIX 2.1.
No credit card required · Free API key
Key features. Everything you need to protect your infrastructure and users.
Content Hub TAXII connector
Install the Threat Intelligence solution, then add a TAXII server with the isMalicious API root.
Collection IDs
malicious-ips, malicious-domains, malicious-urls, c2-indicators, phishing-indicators, and more.
Score before you block
Filter on x_opencti_score. ≥ 60 for auto-block, 40–59 for analyst review.
Optional event push
SOC events can also land in Log Analytics via the dashboard Sentinel destination (Pro).
Use cases. How security teams use this tool.
Indicator matching
Match Sentinel logs against isMalicious IPs and domains ingested over TAXII.
Hunting
Use C2 and phishing collections as hunting seeds, not as a raw firewall dump.
Firewall follow-through
High-score IPs from malicious-ips can feed EDL or blocklist workflows after review.
Connect in Sentinel
- Content management → Content hub → install Threat Intelligence.
- Data connectors → Threat Intelligence - TAXII → Open connector page → Add.
- Friendly name:
isMalicious - API root URL:
https://api.ismalicious.com/taxii2/api-root - Collection ID:
malicious-ipsormalicious-domains - Username
api, password = your dashboard API credential (Base64 of apiKey:apiSecret). - Polling frequency: hourly is enough for most SOCs.
Frequently asked questions.
Is there a custom isMalicious app in the Sentinel Content Hub?
What URL do I enter as the API root?
How do I authenticate?
Which collection should I start with?
Related tools.
Ready to get started?
Join thousands of security teams using isMalicious to protect their infrastructure.
No credit card required · Free API key