Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About

Intelligence
API

Spamhaus’ intelligence contains context-rich metadata relating to IP and domain reputation. Integrate this data via API with your applications to enhance existing data, or consume as an independent data source.

Breadth of insight

Access to numerous API calls returning actionable data to expose different types of reputation signals.

Dynamic threat intelligence

Ability to query only what’s relevant to your use case, without the need to download large files.

Reliable and trusted

Investigate with world-class intelligence, providing rich, reliable and timely contextual insight.

Spamhaus Intelligence via API

Easily access numerous signals that contribute to the reputation of IPs and domains, including botnet command and controllers (C2s). Derived from the 24/7 analysis of billions of datapoints, this data has multiple applications.

In this easy-to-consume format, the API can be used for threat hunting and investigation, risk scoring, customer vetting, validation and much more.

Why are there two different names for the data?

Our datasets have been supporting users for a very long time. With new users requesting our support, the dataset names are being updated for clearer understanding. We’re documenting two names, for now, to best support all users.

Datasets Included

Botnet C2 IPs

(Botnet Controller List - BCL)

Botnet command and controller (C2) servers. The status of these single IPv4 addresses is re-evaluated several times a day to identify active botnet controllers only. Utilize for protection or threat intelligence requirements.

Compromised IPs

(Exploits Blocklist - XBL)

Domain Intel

(Domain Dataset)

Email Spam IPs

(Combined Spam Sources - CSS)

Zero reputation domains

(Zero Reputation Domains - ZRD)

transition

Use cases for Intelligence API

Gain a clearer understanding of the context and risk associated with individual IPs, and domains with Spamhaus’ context-rich metadata — enrich existing data sources or query the data directly.

Threat Hunting
Threat Intelligence Enrichment
Email Compliance
Threat Hunting
Transition

For Threat Hunting

Seamlessly pivot through context-rich metadata including active botnet C2 IPs, exploited and exploiting IPs, malicious and suspicious email traffic, and all domains observed by Spamhaus.

Strengthen domain context

Access metadata including senders data, nameserver reputation, A Record reputation, correlated related domains, listed Hostnames, and malware.

Tracked active Botnet C2 IPs

Dataset contains approximately 800 – 1,500 entries, with live updates every minute, and up to 50 new detections every 24 hours.

Getting started

  • How to start a free 30-day trial

    Getting started is simple, complete this form and submit. There’s no requirement for credit card or payment details for the trial.

    What happens next?

    First, you’ll sign up for an account, then create an API user profile. After your API user profile is set up, you can generate a token through the authentication API.

    Need help?

    If you have any questions, please add them to the comments box on the sign up form. Once you gain access to the data, technical support is available via our Customer Portal.

    How can I purchase the data?

    During your free trial, you can request a quote in the Customer Portal to get the subscription cost based on your setup. You can also enable trials of additional datasets via the Customer Portal.

  • System requirements

    Access to the API is through a convenient HTTP REST interface. There are no strict system requirements, other than you'll need an environment that supports HTTPS and JSON.

  • Technical documentation

    To gain a better understanding of how to get set up and the data available, please see here. For a detailed breakdown on the anatomy of the data and the REST API, see our technical documentation.

  • Pricing

    Access is based on the number of queries per month and per second. To learn more contact our sales team, or fill out the form to start a free trial.

    You can also get limited access to the data for free for six months with a Developer License. This extended trial gives you the flexibility to test the data over a longer time period, to see what challenges it can help you solve.

Ready to start
your free trial?

Get a free 30-day trial of Spamhaus Intelligence via API. No credit card details required.

Sign up
Transition

Integrations

Intelligence API

Maltego Integration

With Maltego, streamline complex analysis by utilizing the Spamhaus-abuse.ch Alliance’s expansive malware, IP and domain reputation intelligence. Quickly understand whether entities should be considered high risk, why, and whether it is still perpetuating malicious behavior to confidently define and prioritise next steps.

Learn More

Frequently Asked Questions

  • Who can use the Intelligence API?

    The API has multiple applications across many specialist areas. Here are some examples of how different users can benefit:

    Threat analysts – increase your understanding of security events and alerts relating to IPs and domains to more effectively prioritize and report.

    Product Managers – enhance existing data pools to provide additional validation points to increase customer confidence in vulnerabilities and threats.

    Email Service Providers – keep your network clean by using this data to perform in-depth vetting of potential customers. Build a comprehensive picture with a vast number of domain and IP signals.

    A free six-month Developer License is also available, giving you limited access to the data to explore its potential.

  • Where does Intelligence API obtain its data?

    The data comes from intelligence gathered through a global network of probes, honeypots, and spam traps, as well as trusted data shared by hosting providers, ISPs, internet governing bodies, and other industry partners.

    Using a combination of machine learning, heuristics, and manual investigations, Spamhaus’ dedicated team of researchers analyze this data, to identify malicious behavior to deliver high-confidence signal through the API.

    This data is deduped and false positives are removed before assembling production data.

Explore more

Data Access

abuse.ch API

High-impact data, dedicated to malware indicators, from a globally diverse, knowledge-rich community. Access enterprise-grade intelligence, with reliability and scale, to enrich, hunt and track with clarity and confidence.

Learn More

Data Access

Passive DNS API

A simple API supporting a variety of query types to discover historical, and up-to-the-moment, DNS infrastructure connections from Spamhaus’ Passive DNS database with up to one year of historical data.

Learn More

Data Access

Rsync

Incremental synchronization of binary and contextual datasets to local servers, including access to our entire binary DNS blocklist data. Efficiently transfer data by only copying changes between the source and destination.

Learn More