Skip to main content
Source we aggregate

isMalicious + ThreatFox

abuse.ch IOC sharing platform. isMalicious consumes this source and correlates it with others — this page explains what that adds, and when to go to the source directly.

Run a free reportView pricingFree tier · no credit card

ThreatFox is one of the sources isMalicious aggregates

We are not a replacement for ThreatFox, and the table below is not a scoreboard. isMalicious ingests or queries ThreatFox alongside other sources and returns a single weighted verdict. Rows where isMalicious shows a capability ThreatFox does not are usually capabilities of the aggregation layer, not evidence that our data on ThreatFox's own specialty is better. For ThreatFox's primary use case, go to ThreatFox.

Quick verdict

Choose ThreatFox for free community IOC exports and campaign tags. Choose isMalicious for production API automation, multi-source correlation, STIX/TAXII feeds, and CVE/ransomware intelligence layered on top of community IOCs.

isMalicious

Real-time threat intelligence API with multi-source correlation, CVE intelligence, and ransomware leak-site tracking.

Best for: Automated threat intelligence at scale

ThreatFox

ThreatFox is abuse.ch's platform for sharing indicators of compromise — IPs, domains, URLs, and hashes linked to active malware campaigns. It is excellent for community IOC discovery but lacks the enterprise API scale, enrichment depth, and feed automation of dedicated threat platforms.

Best for: Community IOC sharing and malware campaign tracking

Feature Comparison

FeatureisMaliciousThreatFox
IOC feed (IP/domain/URL/hash)
Multi-source confidence scoring
Bulk API (1K+ indicators)Limited
STIX/TAXII export
Ransomware leak-site tracking
CVE intelligence (CVSS, EPSS, KEV)
Streaming threat feed
Analyst report pagePartial
Free tier available

Every row above is backed by live data — see it on your own indicators.

Run a free report

ThreatFox — Strengths & Limitations

Strengths
  • Free IOC submissions and exports
  • Malware campaign context
  • JSON/CSV export API
  • Active community
Limitations
  • Community-driven — variable data quality
  • No multi-source confidence scoring
  • No CVE or ransomware dashboards
  • No STIX/TAXII at enterprise scale
  • Limited bulk enrichment API
  • No NRD or dark web monitoring

Pricing

isMalicious

Free up to 30 calls/month. Pro from €99/month. Enterprise custom pricing.

View pricing →

ThreatFox

Free

Frequently Asked Questions

Does isMalicious include ThreatFox IOCs?

Yes. ThreatFox and related abuse.ch feeds contribute to isMalicious malware IOC coverage with reliability weighting alongside professional threat feeds.

ThreatFox vs isMalicious for MISP workflows?

ThreatFox feeds MISP well for community IOCs. isMalicious adds API enrichment, STIX/TAXII delivery, blocklist exports, and confidence-scored verdicts for production blocking and SOAR automation.

Which has better API limits for automation?

isMalicious is designed for high-volume API and TAXII consumption with enterprise tiers. ThreatFox is tuned for community sharing rather than million-scale automated enrichment.

Other Comparisons

Decide with your own data

Don't take our word over ThreatFox's. Check something real.

Paste any IP, domain, or URL and get a full multi-source report — reputation, WHOIS, DNS, ransomware signals, and an AI verdict. Free, no signup.

  • 30 free API calls/month
  • No credit card required
  • API key in under 2 minutes