Skip to main content

IsMalicious

This Integration is part of the IsMalicious Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.10.0 and later).

Enrich IP, domain, URL and file-hash indicators with IsMalicious reputation, evidence and data-trust context. This integration uses the public IsMalicious REST API contract. Local validation uses synthetic provider responses and the real CommonServerPython framework; no production Cortex XSOAR deployment is claimed.

API checks consume the applicable account quota. Unknown hashes, delisted indicators and absent supported verdicts remain DBotScore 0; risk and confidence are separate fields. See the pack README for evidence interpretation and limits.

Configure IsMalicious in Cortex#

Create an API key and API secret at https://ismalicious.com/app/account. Configure the password field with Base64 of the exact apiKey:apiSecret pair. Keep this complete credential secret. TLS verification is mandatory, redirects and retries are disabled. Test connection performs an example.com lookup to validate authentication, not safety.

URL strings are preserved, including commas. Pass URL batches as arrays. URLs containing user information or passwords are rejected before any request.

ParameterDescriptionRequired
X-API-KEY credential (Base64 of apiKey:apiSecret)Use the complete encoded credential, not the raw API key. Keep it secret.True
Use system proxy settingsRoute requests through the proxy configured in the Cortex system settings.False
Source ReliabilityChoose the reliability assessed by your team; this is not the provider's risk or confidence score.False

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

The examples below illustrate command syntax only; they are not recorded production executions or verdicts.

ip#


Enrich ip indicators with IsMalicious evidence. At most 50 values per command.

Base Command#

ip

Input#

Argument NameDescriptionRequired
ipIndicators to check; comma-separated list or array.Required

Context Output#

PathTypeDescription
IsMalicious.Check.IndicatorStringThe indicator queried, unchanged.
IsMalicious.Check.TypeStringIndicator type.
IsMalicious.Check.VerdictStringServer-evidence-derived verdict; unknown remains unknown.
IsMalicious.Check.RiskScoreNumberRisk score from 0 to 100, higher is riskier. Missing remains unknown.
IsMalicious.Check.ConfidenceNumberConfidence from 0 to 100, separate from risk. Missing remains unknown.
IsMalicious.Check.BlocklistHitsNumberNumber of explicit blocklist matches as provided by API.
IsMalicious.Check.EvidenceUnknownServer evidence, reasons, contradictions, source summary and recommended action.
IsMalicious.Check.DataTrustUnknownProvider data quality and freshness profile.
IsMalicious.Check.SourcesUnknownRaw source context. Do not interpret all rows as malicious detections.
IsMalicious.Check.LookupStatusStringKnown or unknown hash lookup state.
IsMalicious.Check.KnownGoodBooleanKnown-good hash flag when provided.
IsMalicious.Check.DelistedBooleanReviewed delisting flag when provided.
IsMalicious.Check.ReportURLStringIsMalicious report URL.
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
DBotScore.ScoreNumberThe actual score.
IP.AddressStringIP address.

Command Example#

!ip ip=198.51.100.1

domain#


Enrich domain indicators with IsMalicious evidence. At most 50 values per command.

Base Command#

domain

Input#

Argument NameDescriptionRequired
domainIndicators to check; comma-separated list or array.Required

Context Output#

PathTypeDescription
IsMalicious.Check.IndicatorStringThe indicator queried, unchanged.
IsMalicious.Check.TypeStringIndicator type.
IsMalicious.Check.VerdictStringServer-evidence-derived verdict; unknown remains unknown.
IsMalicious.Check.RiskScoreNumberRisk score from 0 to 100, higher is riskier. Missing remains unknown.
IsMalicious.Check.ConfidenceNumberConfidence from 0 to 100, separate from risk. Missing remains unknown.
IsMalicious.Check.BlocklistHitsNumberNumber of explicit blocklist matches as provided by API.
IsMalicious.Check.EvidenceUnknownServer evidence, reasons, contradictions, source summary and recommended action.
IsMalicious.Check.DataTrustUnknownProvider data quality and freshness profile.
IsMalicious.Check.SourcesUnknownRaw source context. Do not interpret all rows as malicious detections.
IsMalicious.Check.LookupStatusStringKnown or unknown hash lookup state.
IsMalicious.Check.KnownGoodBooleanKnown-good hash flag when provided.
IsMalicious.Check.DelistedBooleanReviewed delisting flag when provided.
IsMalicious.Check.ReportURLStringIsMalicious report URL.
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
DBotScore.ScoreNumberThe actual score.
Domain.NameStringDomain name.

Command Example#

!domain domain=example.com

url#


Enrich url indicators with IsMalicious evidence. At most 50 values per command.

Base Command#

url

Input#

Argument NameDescriptionRequired
urlOne complete HTTP(S) URL or an array of complete URLs. Commas inside a URL are preserved.Required

Context Output#

PathTypeDescription
IsMalicious.Check.IndicatorStringThe indicator queried, unchanged.
IsMalicious.Check.TypeStringIndicator type.
IsMalicious.Check.VerdictStringServer-evidence-derived verdict; unknown remains unknown.
IsMalicious.Check.RiskScoreNumberRisk score from 0 to 100, higher is riskier. Missing remains unknown.
IsMalicious.Check.ConfidenceNumberConfidence from 0 to 100, separate from risk. Missing remains unknown.
IsMalicious.Check.BlocklistHitsNumberNumber of explicit blocklist matches as provided by API.
IsMalicious.Check.EvidenceUnknownServer evidence, reasons, contradictions, source summary and recommended action.
IsMalicious.Check.DataTrustUnknownProvider data quality and freshness profile.
IsMalicious.Check.SourcesUnknownRaw source context. Do not interpret all rows as malicious detections.
IsMalicious.Check.LookupStatusStringKnown or unknown hash lookup state.
IsMalicious.Check.KnownGoodBooleanKnown-good hash flag when provided.
IsMalicious.Check.DelistedBooleanReviewed delisting flag when provided.
IsMalicious.Check.ReportURLStringIsMalicious report URL.
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
DBotScore.ScoreNumberThe actual score.
URL.DataStringFull URL.

Command Example#

!url url="https://example.com/path?a=1&b=2"

file#


Enrich MD5, SHA1 or SHA256 hashes with IsMalicious evidence. At most 50 values per command.

Base Command#

file

Input#

Argument NameDescriptionRequired
fileMD5, SHA1 or SHA256 hashes; comma-separated list or array. No file upload.Required

Context Output#

PathTypeDescription
IsMalicious.Check.IndicatorStringThe indicator queried, unchanged.
IsMalicious.Check.TypeStringIndicator type.
IsMalicious.Check.VerdictStringServer-evidence-derived verdict; unknown remains unknown.
IsMalicious.Check.RiskScoreNumberRisk score from 0 to 100, higher is riskier. Missing remains unknown.
IsMalicious.Check.ConfidenceNumberConfidence from 0 to 100, separate from risk. Missing remains unknown.
IsMalicious.Check.BlocklistHitsNumberNumber of explicit blocklist matches as provided by API.
IsMalicious.Check.EvidenceUnknownServer evidence, reasons, contradictions, source summary and recommended action.
IsMalicious.Check.DataTrustUnknownProvider data quality and freshness profile.
IsMalicious.Check.SourcesUnknownRaw source context. Do not interpret all rows as malicious detections.
IsMalicious.Check.LookupStatusStringKnown or unknown hash lookup state.
IsMalicious.Check.KnownGoodBooleanKnown-good hash flag when provided.
IsMalicious.Check.DelistedBooleanReviewed delisting flag when provided.
IsMalicious.Check.ReportURLStringIsMalicious report URL.
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
DBotScore.ScoreNumberThe actual score.
File.MD5StringMD5 hash.
File.SHA1StringSHA1 hash.
File.SHA256StringSHA256 hash.

Command Example#

!file file=d41d8cd98f00b204e9800998ecf8427e