Unified cyber intelligence API

20+ sources. One call.

ThreatMap aggregates Shodan, Censys, VirusTotal, AbuseIPDB, GreyNoise, and dozens more into one normalised API with a unified score. One auth. One data model. One MCP endpoint.

drag to rotate
20+
Intel sources
<500ms
p95 latency
99.9%
Uptime SLA
0
Agents to deploy
ShodanCensysVirusTotalAbuseIPDBGreyNoiseSecurityTrailsRecorded FutureMandiantCISA KEVEPSSNVDVulnCheckOTXURLhausMalwareBazaarFarsight DNSDBDomainToolsurlscan.ioShodanCensysVirusTotalAbuseIPDBGreyNoiseSecurityTrailsRecorded FutureMandiantCISA KEVEPSSNVDVulnCheckOTXURLhausMalwareBazaarFarsight DNSDBDomainToolsurlscan.io
How it works

Your AI agent is now a threat intelligence analyst.

Copy the config. Paste into Claude. Ask a question. ThreatMap handles the rest.

1
Copy config
2
Paste into Claude
3
Ask away
Step 1 — MCP Config
{
  "mcpServers": {
    "threatmap": {
      "command": "npx",
      "args": ["-y", "@threatmap/mcp"],
      "env": {
        "THREATMAP_API_KEY": "tm_live_..."
      }
    }
  }
}
paste into Claude Desktop
Claude + ThreatMap MCPconnected
What threats are emerging today?
querying 8 sources...
criticalCVE-2026-9999 — actively exploited
EPSS 94% · CISA KEV · ransomware campaigns using this
via NVD + VulnCheck + AbuseIPDB
high203.0.113.50 — known C2 node
AbuseIPDB score 87 · GreyNoise malicious · 14 sightings
via AbuseIPDB + GreyNoise + OTX
mediumpaypa1-verify.com — homoglyph attack
Registered 2h ago · targeting financial sector
via CertSh + passive DNS
3 emerging threats across 8 sources. 1 critical CVE needs patching tonight.
Your AI agent just did the work of a full SOC shift — in 2 seconds.
Why ThreatMap

Wiring it yourself vs ThreatMap

Yes, you could call Shodan + VT + GreyNoise directly. Here's what that actually costs.

DIY (10+ vendor APIs)ThreatMap
Time to first API call2+ weeks60 seconds
Procurement cycle6-12 months (per vendor)None — self-serve
Schema normalisationMonths of engineeringBuilt-in, one schema
MCP server for AI agentsBuild it yourselfNative, day one
Vendor API maintenanceForever — your problemZero — we handle it
Monthly bills10+ separate invoicesOne bill
Failed call costYou still pay upstream0 credits
Use cases

What people build on ThreatMap

If you'd otherwise wire up 10+ vendor APIs, use ThreatMap instead.

AI security agents

Give Claude, Cursor, or Copilot a tool that enriches any IOC, looks up any CVE, scans any asset. Native MCP.

Phishing pipelines

Auto-enrich every URL, domain, attachment hash, and sender IP in one batch call.

Infrastructure pivots

Chain /v1/ioc to /v1/dns to /v1/certificates to /v1/trackers — map an attacker's footprint in 4 calls.

CI/CD security checks

Scan assets before deploy, check dependencies against KEV + EPSS, block on critical exposure.

Pricing

Free for individuals.
Pay when you're a team.

The Free tier is a real product — not a trial. Stay on it forever if that's all you need.

For individuals
Always Free
$0forever
1,000 credits every month. All endpoints. No card, no timer, no cap on how long you stay.
Best for: Solo analysts, researchers, OSS, CI/CD, AI agent prototypes
  • 1,000 credits / month — resets every month, forever
  • All endpoints — nothing locked behind a paywall
  • MCP server (public + authed with your key)
  • All OSS feeds included
  • BYOK: bring your own Shodan / VT / GreyNoise keys (0 credits)
  • No credit card required — ever
Start free
For scale
Enterprise
$50K+/year
When you need scale — multi-tenant OEM, on-prem, premium feeds, compliance.
Best for: MSSPs, regulated industries, enterprise SOCs, government
  • Unlimited pooled credits
  • Multi-tenant OEM (MSSP-ready)
  • Premium feed partnerships
  • SIEM / SOAR connectors
  • On-prem / air-gapped
  • SSO / SAML / SCIM + RBAC
  • 24x7 named TAM, 1-hour SLA
Contact sales

You'll never be charged on Free. No card on file. No trial timer. No "upgrade to continue" popups. 1,000 credits land on the 1st of every month — use them or lose them, no catch.

Integrations

We integrate, we don't compete

These capabilities are served by partners — we feed intelligence into their workflows.

Cloud security
Cy5, Wiz, Orca, Prisma
SIEM
Splunk, Sentinel, Elastic, Chronicle
SOAR
Tines, Splunk SOAR, XSOAR
EDR
CrowdStrike, SentinelOne, Defender
Compliance
Vanta, Drata, OneTrust
Training
KnowBe4, Proofpoint
Red team
Mandiant, Bishop Fox, Pentera
Dark web
Searchlight, Flashpoint, Intel 471
5,000
FREE CREDITS+ 1,000 every month after

Stop wiring feeds. Start shipping features.

No credit card. No trial timer. Failed calls are free. Sign up and make your first API call in 60 seconds.

Get API key