ThreatBook intelligence API relies on the powerful data collection capabilities of the ThreatBook Security Cloud, combined with independently developed core intelligence production systems, including dozens of different extraction methods, to quickly and automatically produce high-coverage, high-fidelity, and context-rich intelligence data.
ThreatBook intelligence API relies on the powerful data collection capabilities of the ThreatBook Security Cloud, combined with independently developed core intelligence production systems, including dozens of different extraction methods, to quickly and automatically produce high-coverage, high-fidelity, and context-rich intelligence data.
Currently, ThreatBook Security Cloud has accumulated many kinds of data, including:
Basic data for hundreds of billions of domain names, including millions of new domain names added daily.
Billions of malicious samples, including millions of new malicious samples are added daily.
Real-time detection and analysis of all IPv4 and IPv6 addresses on the Internet.
Globally active hacker C&C (command and control) intelligence tracked, etc.
We also track over 200 APT (advanced persistent threat) organizations, as well as large-scale black market organizations, monitored for the latest attack activities related to them.
ThreatBook Intelligence APIs can provide the following unique value for various types of businesses:
Compromise Detection
Accurately detecting the threats of office terminals and servers in production network or DMZ that may have been compromised due to coin mining, ransomware, backdoor, and APT attacks,etc. ThreatBook intelligence can help enterprises to quickly respond to threats.
Security Alert Noise Reduction
Reducing false alerts and discovering real security incidents by extracting domains or IP addresses from logs collected by SOC or SIEM, etc., to detect or investigate them. One of the main benefits of threat intelligence is its ability to help organizations prioritize their security efforts. With so many potential threats to monitor, it can be difficult for SOC teams to know where to focus their attention. By providing insight into the most pressing threats and up to 99.9% high-fidelity intelligence, it enables organizations to allocate their resources more efficiently, and respond more quickly and effectively to security incidents. This can help minimize the impact of a security breach and reduce the risk of data loss or other damage.
IP Reputation Identification
Not only providing the capability to accurately identify whether the suspicious IP is a risk of scanning, vulnerability exploitation, botnet, etc. but also provides further attributes such as gateway, IDC, CDN, etc., which better conform to your business needs to respond to external threats.
Highlights
Basic data for hundreds of billions of domain names, including millions of new domain names added daily.
Billions of malicious samples, including millions of new malicious samples are added daily.
Real-time detection and analysis of all IPv4 and IPv6 addresses on the Internet. Globally active hacker C&C (command and control) intelligence tracked, etc.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You choose a contract tier based on your daily API call volume. All three tiers give you the same three intelligence services: IP lookups, URL lookups, and Compromise Detection. The tiers differ only in the daily call allowance for each service. The 10K tier allows 10,000 calls per service each day. The 20K tier raises that to 20,000 calls per service daily. The 50K tier allows 50,000 calls per service daily. Pricing scales with the daily call volume you expect to use across these three APIs.
Top-of-mind questions for buyers
What counts as one API call for each of the three services?
Each call is a single query against one intelligence service. An IP call analyzes one IP for a malicious verdict and attribution. A URL call checks one URL or domain. A Compromise Detection call cross-references DNS log data against known command-and-control infrastructure to flag internal hosts.
How do the three per-service call allowances combine within a single tier?
The allowances are independent, not pooled. Your tier grants a separate daily quota for IP calls, URL calls, and Compromise Detection calls. For example, the 10K tier gives 10,000 calls for each service per day. Using one service does not reduce the allowance for the others.
What happens if I reach my daily call allowance for a service?
Each service has a daily call limit set by your tier. Once you reach that limit for one service, further calls to it are constrained until the daily counter resets. To raise a service's daily allowance, move to a tier with a larger quota.
threatbook.io
Helpful?
Vendor refund policy
refunds as per our license terms
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Cloud-based DNS Secure Web Gateway powered by threat intelligence. Blocks ransomware, phishing, C2, and malicious mining at the DNS layer for office networks, branches, and roaming endpoints.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.