Threat intelligence API / build
What you can build with the API
Runnable scripts against the live API. A free key covers every one of them, one key covers the whole API, and most recipes are under 30 lines.
Each page shows the full script, the output from a real run, and what a run costs in credits. Every page is also available as Markdown or JSON: append .md or .json to the URL.
Alerting
-
Brand and domain dark-web monitor
Are my brands or domains showing up on the dark web?
-
Sector ransomware watch for Slack
New dark-web ransomware victims for a sector/country, as a Slack message.
-
Vendor in the news
Which of my vendors/products are in incident reporting this week?
Triage
-
CVE triage: KEV and EPSS filter
From a list of CVE ids, keep only the ones that matter right now.
-
Exploited this week
CVEs from the last 7 days that are in KEV or have a public exploit.
Enrichment
-
IOC blocklist export
Validated malicious domains and IPs as plain blocklists.
-
SIEM indicator enrichment
What does ThreatCluster know about this indicator?
Reporting
-
Trending threat actors
Which threat actors, ransomware crews and malware families are rising this week?
-
Weekly executive brief
The week's top 10 threat clusters as a Markdown brief.
Agents
-
A lookup tool for LLM agents
A tool-calling function `threatcluster_lookup(query)` for LLM agents.
Integrations · Quickstart and plans · Output formats · OpenAPI reference