Skip to content

Products · Data Feeds & API

The signal, without the console.

The same proprietary collection that powers Mythic is available as data: detailed malicious domain intelligence, delivered as feeds your defenses can act on and an API your engineers can build with.

Data Feeds & API datasheet (PDF)
01Data feeds

Malicious domains, from the source.

Most domain intelligence is scraped, aggregated, and resold, which is why so many feeds agree with each other and lag the adversary together. Vigilocity's feeds come from our own proprietary gathering capabilities: the same tradecraft that watches threat actors acquire and stage infrastructure for Mythic.

The result is detailed, high-confidence malicious domain intelligence, identified as adversaries register and arm it, with the infrastructure context that separates a parked look-alike from a campaign about to launch.

02The API

Fully functional, built to be built on.

The API is not a companion utility; it is a first-class way to consume the intelligence. Query domains and infrastructure programmatically, integrate the collection into your own systems, and automate the decisions the data supports, at whatever scale your architecture requires.

Look up any domain and pivot through its registration to every domain the same registrant controls. Resolve an IP to the threats behind it. Pull DNS and data logs by date range, and stand up watchlists over the entities and network ranges you care about, with notifications when new matches appear.

API reference · docs.vigilocity.com
03Integration

Built to land in what you already run.

The feeds are plain, structured data, so they drop into the control points you already operate: firewalls and DNS filtering for blocking, your SIEM for enrichment, your threat intelligence platform for correlation, and your SOAR for the automation that follows. Consume them as scheduled pulls or query the API in real time; both speak the same records.

A representative record
domain
the domain, as registered
first_observed
timestamp of first observation in collection
registration
registrar, dates, and registration detail
registrant
pivotable registrant identity and related domains
infrastructure
hosting, IP, and related infrastructure context
attribution
actor, campaign, and tooling linkage where established
threats
associated threat classifications

Field names and full schemas are in the API reference. Evaluations run against your own telemetry, so you judge the feeds on your traffic, not ours.

04In practice

Three ways teams put the data to work.

01

Block before the campaign launches

Feed newly observed malicious domains directly into firewalls, DNS filtering, and secure gateways, so infrastructure is blocked in the window between registration and use.

02

Enrich what you already see

Resolve the alerts in your SIEM and the indicators in your threat intelligence platform against domains with actor, campaign, and infrastructure context attached.

03

Build on the signal

Security vendors and internal platform teams use the API to build the intelligence into their own products, scoring engines, and automated workflows.

Evaluate the feeds against your own telemetry.