Overview
ThreatBook intelligence API relies on the powerful data collection capabilities of the ThreatBook Security Cloud, combined with independently developed core intelligence production systems, including dozens of different extraction methods, to quickly and automatically produce high-coverage, high-fidelity, and context-rich intelligence data.
Currently, ThreatBook Security Cloud has accumulated many kinds of data, including: Basic data for hundreds of billions of domain names, including millions of new domain names added daily. Billions of malicious samples, including millions of new malicious samples are added daily. Real-time detection and analysis of all IPv4 and IPv6 addresses on the Internet. Globally active hacker C&C (command and control) intelligence tracked, etc. We also track over 200 APT (advanced persistent threat) organizations, as well as large-scale black market organizations, monitored for the latest attack activities related to them.
ThreatBook Intelligence APIs can provide the following unique value for various types of businesses: Compromise Detection
Accurately detecting the threats of office terminals and servers in production network or DMZ that may have been compromised due to coin mining, ransomware, backdoor, and APT attacks,etc. ThreatBook intelligence can help enterprises to quickly respond to threats.
Security Alert Noise Reduction
Reducing false alerts and discovering real security incidents by extracting domains or IP addresses from logs collected by SOC or SIEM, etc., to detect or investigate them. One of the main benefits of threat intelligence is its ability to help organizations prioritize their security efforts. With so many potential threats to monitor, it can be difficult for SOC teams to know where to focus their attention. By providing insight into the most pressing threats and up to 99.9% high-fidelity intelligence, it enables organizations to allocate their resources more efficiently, and respond more quickly and effectively to security incidents. This can help minimize the impact of a security breach and reduce the risk of data loss or other damage.
IP Reputation Identification
Not only providing the capability to accurately identify whether the suspicious IP is a risk of scanning, vulnerability exploitation, botnet, etc. but also provides further attributes such as gateway, IDC, CDN, etc., which better conform to your business needs to respond to external threats.
Highlights
- Basic data for hundreds of billions of domain names, including millions of new domain names added daily.
- Billions of malicious samples, including millions of new malicious samples are added daily.
- Real-time detection and analysis of all IPv4 and IPv6 addresses on the Internet. Globally active hacker C&C (command and control) intelligence tracked, etc.
Details
Unlock automation with AI agent solutions

Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
---|---|---|
ThreatBook Intelligence API-10K | 20000 IP API calls/day; 10000 URL API calls/day; 10000 Compromise Detection API calls/day; | $90,000.00 |
ThreatBook Intelligence API-20K | 50000 IP API calls/day; 20000 URL API calls/day; 20000 Compromise Detection API calls/day; | $180,000.00 |
ThreatBook Intelligence API-50K | 100000 IP API calls/day; 50000 URL API calls/day; 50000 Compromise Detection API calls/day; | $360,000.00 |
Vendor refund policy
refunds as per our license terms
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Threatbook API Support Information https://threatbook.io/apiÂ
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.