ThreatMap Docs

ThreatMap is Unified cyber intelligence API. One API that fans out across Shodan, Censys, VirusTotal, AbuseIPDB, GreyNoise, and dozens more — and returns one normalised JSON with a unified score.

New here? Start with the Quickstart — you'll have a working IOC enrichment call in under 60 seconds.

Guides

Quickstart

Get an API key, make your first call, connect Claude via MCP.

API Reference

Every endpoint, every parameter, every response field.

Pricing & Credits

Credit system, BYOK, billing, usage benchmarks.

Partners

SIEM, SOAR, EDR, CSPM — we integrate, we don't compete.

What ThreatMap is

ThreatMap is the aggregator and access layer for cyber intelligence. We don't collect data — we aggregate, normalise, and orchestrate across the world's threat intel sources.

Bring your own API keys (BYOK) for feeds you've already licensed — those calls cost 0 credits. Or buy credits through us at wholesale + a normalisation margin.

One auth. One data model. One pricing model. One MCP endpoint.

What ThreatMap isn't

We don't replace your SIEM, EDR, CSPM, or training platform. We make them smarter by feeding aggregated intelligence into their workflows. We don't enter your network, don't read your data, don't authenticate into your systems.

See the full partner list →

The one-sentence pitch

One call to /v1/ioc fans out to Shodan, Censys, VirusTotal, AbuseIPDB, GreyNoise, and dozens more — simultaneously — and returns one normalised JSON with a unified score. That's the whole product.