Looking for the threat feed? It now lives at threatcluster.io/threats.

20,000 sources collapsed into one scored record per incident, queryable from your code.

The only threat intelligence API that puts clustered incident reporting, validated IOCs, vulnerability intelligence and first-party dark-web collection behind one free key.

Read the docs

Free key on every account: 100 credits a day, the last 7 days, no card.

The API, in numbers

Incident records21,172+408 this week
Validated indicators13,813+930 this week
Leak-site victims20,587+247 this week
Entities104,835+3,818 this week
Articles214,105+4,159 this week
Lead over the trade press5.1 daysHow we measure it

What the API returns

45+ endpoints over incidents, IOCs, entities, vulnerabilities and the dark web. Pick an endpoint and a language, and see the real response.

Incident records, deduplicated from every source that covered them

GET /threats?time_filter=24h
{
  "threats": [
    {
      "cluster_id": "5f578c75-abf8-4fbd-915b-d4037386092f",
      "title": "Iranian cyber spies target aviation, fintech developers with new malware",
      "ai_title": "Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware",
      "ai_summary": "The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across…",
      "timeline": [
        {
          "date": "2026-09-01",
          "event": "New malware families identified",
          "detail": "Kaspersky reported on the discovery of NodeRabbit and PollCat used by Mirage Kitten to ta…",
          "source": "Securelist"
        }
      ],
      "article_count": 3,
      "threat_score": 78.5,
      "severity_score": 80.0,
      "urgency_level": "medium",
      "keywords": [
        "malware",
        "iranian"
      ],
      "sources": [
        "Thehackernews",
        "Therecord.Media"
      ],
      "date_range_latest": "2026-09-01T13:08:58+00:00",
      "articles": [
        {
          "title": "Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new m…",
          "source": "Securelist",
          "pub_date": "2026-09-01T07:00:26+00:00",
          "url": "https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/"
        }
      ],
      "entities": {
        "apt_group": [
          "Iranian Dream Job",
          "Lazarus Group"
        ],
        "attack_type": [
          "Malware",
          "Phishing"
        ]
      },
      "slug": "mirage-kitten-targets-aviation-and-fintech-with-new-cross-pl-7386092f",
      "ioc_count": 12
    },
    {
      "cluster_id": "afb356a7-d498-4c89-920a-44025c9b39fa",
      "title": "CPAI-2026-10671 - Check Point Software",
      "ai_title": "Multiple Remote Code Execution Vulnerabilities Identified in Check Point Software",
      "ai_summary": "Check Point Software has issued advisories for two critical remote code execution vulnerabilities. The first, CVE-2026-53576, was published on June 2…",
      "timeline": [
        {
          "date": "2026-06-11",
          "event": "CVE-2026-44495 published",
          "detail": "Check Point disclosed a remote code execution vulnerability affecting its Security Gatewa…",
          "source": "Advisories.Checkpoint"
        }
      ],
      "article_count": 2,
      "threat_score": 74.0,
      "severity_score": 80.0,
      "urgency_level": "medium",
      "keywords": [
        "protection",
        "update"
      ],
      "sources": [
        "Advisories.Checkpoint"
      ],
      "date_range_latest": "2026-08-31T18:52:57+00:00",
      "articles": [
        {
          "title": "CPAI-2026-10476 - Check Point Software",
          "source": "Advisories.Checkpoint",
          "pub_date": "2026-08-30T19:04:16+00:00",
          "url": "https://advisories.checkpoint.com/defense/advisories/public/2026/cpai-2026-10476.html"
        }
      ],
      "entities": {
        "attack_type": [
          "Zero-Day Exploit"
        ],
        "cve": [
          "CVE-2026-44495",
  …

Explore

From your existing workflow

The API speaks the formats your tools already read. Each link is a short setup guide.

Terminal

pipx install threatcluster-cli, or plain curl. Drop-in for cron, CI and shell pipelines.

BashcurlWindows TerminalVS Code

SIEM, firewall, TIP

Point the ingestor at the IOC feed, or import STIX bundles and the MISP manifest.

Microsoft SentinelSplunkElastic

Agents

Per-session agent keys with scoped budgets, tool definitions from the OpenAPI spec, and cost headers the model can read to pace itself.

ClaudeOpenAICursor

Who it's for

Security teams

A morning board, a KEV watch, a blocklist and an "are we on a leak site" check, on an expense card.

Builders and agents

License the corpus instead of building a collection pipeline, callable from your code or an agent.

MSSPs and vCISOs

Per-client feeds, alerts and branded digests from one data layer. For service providers →

Analysts

One deduplicated record instead of 40 articles, a median 5.1 days ahead of the trade press.

Where we sit

Threat intelligence is not one market. Each kind of tool answers a different question well, and most teams end up running several. This is what each is for, and what it leaves for you to do.

VirusTotalShodanAbuseIPDB

Indicator lookup

VirusTotal, Shodan, AbuseIPDB

Answers
Is this file, IP or domain known bad, and what is exposed on it
Leaves you
One indicator at a time. Not built to say what happened this week, or who reported it
abuse.chAlienVault OTX

Community feeds

abuse.ch, AlienVault OTX, CISA advisories

Answers
Fresh indicators and advisories, free, in bulk
Leaves you
Indicators without the story around them. Deduplicating 40 articles into one incident is still your job
RansomLookransomware.live

Leak-site trackers

RansomLook, ransomware.live

Answers
Which victims a ransomware group has posted
Leaves you
Victims only. No link to the reporting that followed, and no other threat activity
Feedly Threat Intelligence

Reader tools

Feedly Threat Intelligence

Answers
An AI-assisted reading experience over open sources
Leaves you
Priced per seat and quote-only. The data access is the upsell rather than the product
FlashpointIntel 471

Enterprise platforms

Recorded Future, Flashpoint, Intel 471

Answers
Analyst-produced intelligence over open and dark web sources
Leaves you
Procurement-gated and quote-only. Machine consumption is usually metered as the expensive part
ThreatCluster

ThreatCluster

The layer between them

Answers
What happened this week, deduplicated into one scored record per incident, with the entities, indicators and leak-site victims attached. Read it over the API or in the platform, same records either way
Leaves you
The judgement. We do not run your SOC, detonate your samples or scan your perimeter, and the tools above stay better at those

Facts about other tools come from their own documentation, checked on 2 September 2026. We use several of them ourselves. See what the API returns

Pricing

Every account gets a free key: 100 credits a day over the last 7 days, no card. That is about 100 record lookups or 20 searches, every day.

PlanPriceAPI allowanceRateIncludes
Free$0100 credits a day, last 7 days, trimmed records30 a minuteEvery read endpoint: incidents, IOCs, entities, vulnerabilities and dark web. The public feeds and IOC blocklist need no key at all.
Researcher$19.99 a month1,000 credits a day, full records, all history120 a minuteEverything in Free, plus custom feeds and alert rules over the API.
Business$399 a monthNo daily budget, per-key overrides600 a minuteEverything in Researcher, plus managed customers (on request; per-client feeds, alerts and branded digests) and org sharing.

Credit packs, for anything past the daily allowance

PackPriceCreditsRoughly
Starter$102,0002,000 record lookups, 400 searches or 200 dark-web enrichments
Bulk$5012,00012,000 record lookups, 2,400 searches or 1,200 dark-web enrichments

One-off, never expire, spent only after the day's allowance, on any plan. Past about 4,000 credits a month, Researcher is the better buy.

What a request costs

CreditsRequests
1Records and lists: incidents, entities, vulnerabilities, dark-web lists, stats
3Bulk and fan-out: the IOC feed and export, STIX bundles, dark-web keyword hits and trends
5Search, one query across the whole corpus
10A dark-web victim enrichment record: screenshots, extracted data, negotiation state

A request that finds nothing costs nothing: empty searches and 404 lookups refund their credits. Every response carries X-Request-Cost and your remaining balance. Monthly plans cancel anytime. All plans.

Security and reliability

Availability
99.8% of the 1.7 million requests served in the last 30 days succeeded, median response 48 ms, measured from our edge logs, not a status-page promise.
Freshness
Incidents form within minutes of the first credible report. Indicators are validated on ingest and a false-positive list is applied on every export path.
Data handling
The public feeds are TLP:CLEAR. Keyed responses are for your own tooling, and we do not resell your queries or your watchlists.
Dark-web collection
Passive observation of leak sites, markets and postings over Tor. We record what criminals publish; we do not intrude, purchase or engage.
Certification
SOC 2 is on the roadmap. Until it lands, our security summary is available on request for procurement reviews.

Instead of building it yourself

The alternative to this API is not another vendor. It is free feeds plus labour.

The analyst hour
Twenty sources cover the same incident with twenty headlines. Someone reads them all to learn there is one story. Clustering does that before you open the feed.
The pipeline team
Collectors for 20,000 sources, deduplication, entity extraction, scoring, and the on-call to keep it all running. That is an engineering project with a payroll, not a weekend script.
The Tor operation
Leak sites move, mirrors die and boards change layout weekly. We run the collection, the screenshots and the re-crawls so you consume a record, not an onion address.

FAQ

What does the free key include?

Every read scope over the last 7 days with 100 credits a day: incidents, IOCs, entities, vulnerabilities and dark web. Records are trimmed to the short summary, 3 timeline events and 25 rows per list.

Most calls cost 1 credit. The heavier ones cost more: unified search is 5, STIX bundles and bulk indicator pulls are 3, and a fully enriched leak-site victim record is 10. The budget resets daily.

How fresh is it?

Incidents form within minutes of the first credible report and indicators are validated on ingest.

The lead-time number is measured, not estimated: for every incident that later appeared in the trade press, we compare the timestamp our record was created with the earliest matching trade-press article, and take the median across the matched pairs over the last 90 days. Right now that is 5.1 days, from 82 matched incidents.

How does an incident record get made?

Articles from 20,000+ sources are deduplicated into one cluster per incident as reports arrive. Each record carries a rewritten title and summary, the extracted entities (actors, malware, CVEs, victims), a sourced timeline and a threat score, and it keeps updating as coverage grows. One id to follow instead of twenty headlines.

Where does the dark-web data come from?

Our own Tor collection of leak sites, markets and underground postings, with screenshots, extracted data sizes and negotiation state. Not resold from a broker.

What formats can I pull?

JSON everywhere, STIX 2.1 bundles per incident, MISP feeds, and CSV or plain-text blocklists from the indicator feeds. The public feeds are also available as RSS, and incident pages exist as .md and .json for LLM context windows.

Are there code examples?

Yes. The GitHub repository has a daily-refreshed OpenAPI snapshot, a small Python client and real request/response pairs for every major endpoint, and the live spec is browsable as Swagger UI.

Can I redistribute the data?

The free feeds are TLP:CLEAR, redistribute with attribution. Keyed responses are for your own tooling. Embedding them in a product you sell needs a Business agreement.

Can I cancel?

Plans are monthly with no minimum term. Cancel from settings and the key keeps working until the end of the period. The free key never expires.

Get started

The whole surface is in the spec: 45+ endpoints over incidents, IOCs, entities, vulnerabilities and the dark web. Mint a free key and make the first call in a minute.

Open the OpenAPI spec