isMalicious + ThreatFox
abuse.ch IOC sharing platform. isMalicious consumes this source and correlates it with others — this page explains what that adds, and when to go to the source directly.
ThreatFox is one of the sources isMalicious aggregates
We are not a replacement for ThreatFox, and the table below is not a scoreboard. isMalicious ingests or queries ThreatFox alongside other sources and returns a single weighted verdict. Rows where isMalicious shows a capability ThreatFox does not are usually capabilities of the aggregation layer, not evidence that our data on ThreatFox's own specialty is better. For ThreatFox's primary use case, go to ThreatFox.
Quick verdict
Choose ThreatFox for free community IOC exports and campaign tags. Choose isMalicious for production API automation, multi-source correlation, STIX/TAXII feeds, and CVE/ransomware intelligence layered on top of community IOCs.
isMalicious
Real-time threat intelligence API with multi-source correlation, CVE intelligence, and ransomware leak-site tracking.
Best for: Automated threat intelligence at scale
ThreatFox
ThreatFox is abuse.ch's platform for sharing indicators of compromise — IPs, domains, URLs, and hashes linked to active malware campaigns. It is excellent for community IOC discovery but lacks the enterprise API scale, enrichment depth, and feed automation of dedicated threat platforms.
Best for: Community IOC sharing and malware campaign tracking
Feature Comparison
| Feature | isMalicious | ThreatFox |
|---|---|---|
| IOC feed (IP/domain/URL/hash) | ||
| Multi-source confidence scoring | ||
| Bulk API (1K+ indicators) | Limited | |
| STIX/TAXII export | ||
| Ransomware leak-site tracking | ||
| CVE intelligence (CVSS, EPSS, KEV) | ||
| Streaming threat feed | ||
| Analyst report page | Partial | |
| Free tier available |
Every row above is backed by live data — see it on your own indicators.
Run a free reportThreatFox — Strengths & Limitations
- Free IOC submissions and exports
- Malware campaign context
- JSON/CSV export API
- Active community
- Community-driven — variable data quality
- No multi-source confidence scoring
- No CVE or ransomware dashboards
- No STIX/TAXII at enterprise scale
- Limited bulk enrichment API
- No NRD or dark web monitoring
Pricing
ThreatFox
Free
Frequently Asked Questions
Does isMalicious include ThreatFox IOCs?
Yes. ThreatFox and related abuse.ch feeds contribute to isMalicious malware IOC coverage with reliability weighting alongside professional threat feeds.
ThreatFox vs isMalicious for MISP workflows?
ThreatFox feeds MISP well for community IOCs. isMalicious adds API enrichment, STIX/TAXII delivery, blocklist exports, and confidence-scored verdicts for production blocking and SOAR automation.
Which has better API limits for automation?
isMalicious is designed for high-volume API and TAXII consumption with enterprise tiers. ThreatFox is tuned for community sharing rather than million-scale automated enrichment.
Other Comparisons
Decide with your own data
Don't take our word over ThreatFox's. Check something real.
Paste any IP, domain, or URL and get a full multi-source report — reputation, WHOIS, DNS, ransomware signals, and an AI verdict. Free, no signup.
- 30 free API calls/month
- No credit card required
- API key in under 2 minutes