Thanks to visit codestin.com
Credit goes to www.spamhaus.com

Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About

Intelligence API
Developer License

Increase your data coverage and insight with a 6-month Developer Licence for the Intelligence API, giving you access to context-rich metadata on IP and domain reputation. This expansive signal supports security teams with risk detection, incident response, and proactive threat research.

Adapt the data to suit your needs and assess its value with no commitment or expectation – experiment freely in your test environments and start solving real problems!

Context-rich metadata

Quickly understand the “what” and "why" behind threats, to pinpoint areas of interest and rapidly respond.

Targeted data access

Query only what’s relevant to your use case, without the need to download large files.

Seamless integration

Easily access and integrate the REST API (using JSON format) across multiple applications.

Spamhaus Intelligence API

Access to the Developer License is provided by Spamhaus Intelligence API (SIA). It provides a wide range of metadata signals, that contribute to the reputation of IPs and domains.

Derived from continuous, 24/7 analysis of billions of data points, this comprehensive data is available from a single source, and supports a variety of applications.

Integrate the API into your existing infrastructure and experiment with the data to tackle your security challenges.

Why are there two different names for the data?

Our datasets have been supporting users for a very long time. With new users requesting our support, the dataset names are being updated for clearer understanding. We’re documenting two names, for now, to best support all users.

Datasets Included

Botnet C2 IPs

(Botnet Controller List - BCL)

Botnet command and controller (C2) servers. The status of these single IPv4 addresses is re-evaluated several times a day to identify active botnet controllers only. Utilize for protection or threat intelligence requirements.

Compromised IPs

(Exploits Blocklist - XBL)

Domain Intel

(Domain Dataset)

Email Spam IPs

(Combined Spam Sources - CSS)

Zero reputation domains

(Zero Reputation Domains - ZRD)

transition

Use cases for Intelligence API Developer License

Gain a clearer understanding of the context and any associated risk associated with individual IPs, and domains with Spamhaus’ context-rich metadata — enrich existing data sources or query the data directly.

Threat Hunting
Threat Intelligence Enrichment
Email Compliance
Threat Hunting
Transition

For Threat Hunting

Seamlessly pivot through context-rich metadata including active botnet C2 IPs, to exploited and exploiting IPs, malicious and suspicious email traffic, and all domains observed by Spamhaus.

Strengthen domain context

Access metadata including senders data, nameserver reputation, A Record reputation, correlated related domains, listed Hostnames, and malware.

Tracked active Botnet C2 IPs

Dataset contains approximately 800 – 1,500 entries, with live updates every minute and up to 50 new detections every 24 hours.

Getting started

  • How to set up Developer License access

    To get started, simply sign up for an account and create an API user profile. This will give you 6-months free access for up to 5,000 queries per month.

    What happens next?

    After your API user profile is set up, you can generate a token through the authentication API.

    Need help?

    If you have any questions, please add them to the comments box on the form.

  • System requirements

    Access to the API via the Developer License is through a convenient HTTP REST interface. There are no strict system requirements, other than you'll need an environment that supports HTTPS and JSON.

  • Technical documentation

    To gain a better understanding of how to get set up and the data available, please see here. For a detailed breakdown on the anatomy of the data and the REST API, see our technical documentation.

    PLEASE NOTE: We are unable to provide technical support for any of our free services.

  • Pricing

    Use of the Developer License is free of charge, however the number of queries are limited to 5,000 per month. Should you wish to access the data at volume and/or for commercial purposes, access is based on the number of queries per month and per second. Prices start at $5,000 per year. To learn more contact our sales team, or fill out the form to start a free trial.

Ready to
get started?

Get immediate access for 6 months to the Spamhaus API – Explore. Build. Test. Solve. No credit card details required.

Sign up

Frequently Asked Questions

  • Where does Intelligence API obtain its data?

    The data comes from intelligence gathered through a global network of probes, honeypots, and spam traps, as well as trusted data shared by hosting providers, ISPs, internet governing bodies, and other industry partners.

    Using a combination of machine learning, heuristics, and manual investigations, Spamhaus’ dedicated team of researchers analyze this data, to identify malicious behavior to deliver high-confidence signal through the API.

    This data is deduped and false positives are removed before assembling production data.

  • Who can use the Intelligence API Developer License?

    Designed for individual developers, security researchers or anyone who wants to experiment with Spamhaus’ intelligence via API.

    The license is intended for development or evaluation of use, it does not cover commercial or high-volume use. If you intend to integrate the data into a production system, you’ll need to upgrade to a commercial subscription.

  • How can I purchase the data?

    At the end of the 6 months, you can request a quote in the Customer Portal to get the subscription cost based on your setup.

    You can also enable trials of additional datasets via the Customer Portal.

Data Access

abuse.ch API

High-impact data, dedicated to malware indicators, from a globally diverse, knowledge-rich community. Access enterprise-grade intelligence, with reliability and scale, to enrich, hunt and track with clarity and confidence.

Learn More

Data Access

Passive DNS API

A simple API supporting a variety of query types to discover historical, and up-to-the-moment, DNS infrastructure connections from Spamhaus’ Passive DNS database with up to one year of historical data.

Learn More

Data Access

Rsync

Incremental synchronization of binary and contextual datasets to local servers, including access to our entire binary DNS blocklist data. Efficiently transfer data by only copying changes between the source and destination.

Learn More