Partner Tool
Share:

ThreatBook X

Free threat-intelligence community — look up an IP, domain or hash, and pipe the same verdicts through a Cloud API

Opens at x.threatbook.com — external site, RECATOOLS doesn't host this tool.
Free daily queries No install APAC-based vendor
ThreatBook X logo
Free
Daily query allowance
IP · Domain · Hash
Lookup types
OpenAPI
Automated enrichment
APT-aware
Actor attribution context
What it does

The community front door to ThreatBook intelligence

Most investigations start with a single indicator and two questions: is this malicious, and what else is it connected to? ThreatBook X is built to answer them without a procurement cycle.

Indicator lookup

Paste an IP, domain or file hash and get a verdict with the evidence behind it.

Infrastructure context

You can trace an indicator's connections through its DNS history, associated certificates, and any related samples.

Actor attribution

Where the infrastructure is attributable, you get a named actor rather than a generic "malicious".

Cloud API

Pull the same verdicts through an OpenAPI to automate alert enrichment instead of doing it by hand.

Free tier for analysts

A daily query allowance covers ad-hoc investigation without a commercial agreement.

Shared research

As a community portal, it publishes intelligence from the vendor openly, rather than reserving it for licence-holders.

Advertisement
After features · AD-W1 Responsive · Post-feature engagement
Detection Pipeline

How an indicator becomes a decision

STAGE 1
Paste the indicator
An IP, domain or file hash from an alert or log line
STAGE 2
Reputation check
Current verdict plus how it has changed over time
STAGE 3
Pull context
DNS history, certificates, hosting and related samples
STAGE 4
Attribute
Link infrastructure to a tracked actor where possible
STAGE 5
Decide
Block, monitor, or dismiss with the evidence recorded
STAGE 6
Automate
Move the same lookup into your SIEM/SOAR via the API
Deployment

Three ways to get it running

Tier 02

Cloud API

Automate enrichment so every inbound alert arrives with a verdict attached.

  • OpenAPI access
  • SIEM / SOAR enrichment
  • Higher quotas
Tier 03

Enterprise intelligence

For volume use, move to the full ATI platform rather than the community tier.

  • Full intelligence platform
  • Detection rule feeds
  • Pricing on request
Advertisement
After deployment · AD-W2 Responsive
Regional presence

APAC offices & coverage

Same-jurisdiction threat-intel for ASEAN and East Asian compliance frameworks.

🇸🇬 Singapore 🇭🇰 Hong Kong 🇨🇳 China 🇦🇪 United Arab Emirates
FAQ

Common questions

What can I look up for free?

IP addresses, domains and file hashes, within a daily query allowance. That is aimed at an analyst checking indicators during an investigation, not at bulk enrichment — for volume you want the Cloud API or the full platform.

Is this the same as ThreatBook CTI?

The underlying intelligence is the same, but the delivery is different. ThreatBook X is the free community portal. CTI (branded ATI internationally, NGTIP domestically) is the commercial platform, with much higher quotas and features like detection-rule feeds and integrations. X is the starting point; you can move up to other products if you need higher volume.

Can I automate lookups?

Yes. The Cloud API exposes the same verdicts, allowing you to enrich alerts in a SIEM or SOAR automatically. Quotas depend on your plan, so ask us what tier fits your alert volume.

Does the portal see what I search for?

Assume yes, as with any hosted lookup service. Submitting an indicator tells the provider you are interested in it, which matters during a sensitive investigation. If that is a concern, discuss on-premises intelligence options with us.

Does RECATOOLS get paid to list ThreatBook X (X 情报社区)?

We earn no per-click fee for this listing and our editorial coverage is independent. For full disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor, so it earns revenue if you buy a commercial licence through us — the same relationship disclosed on our other ThreatBook listings.

Independently reviewed by RECATOOLS editorial on 16 Aug 2026. Listings are based on the vendor's public documentation; we don't accept payment for inclusion.
Disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor. We may earn revenue if you buy a commercial licence through us. This does not affect the editorial assessment above, and any free tier stays free regardless of how you reach it.
Authorized reseller

Need pricing, a demo, or the full brochure?

Tell us about your environment and our team will get back to you with ThreatBook licensing, a guided demo, or the product brochure — usually within one business day.

Handled by RECASYS, an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor for the region. Enquiries are copied to their sales desk. No obligation — your details are used only to answer you.

Prefer email? Write to [email protected]
Spam-protected · no account needed · see our Privacy Policy for how enquiries are handled.

Look up an indicator now

The community portal is free within a daily allowance.

Open ThreatBook X
Related on RECATOOLS

Explore related tools & intelligence

Hand-picked RECATOOLS pages relevant to indicator lookup and triage.

Related News

You may be interested in these recent stories from our newsroom.

View all news →
Related

More Cybersecurity Tools