Products · Data Feeds & API
The signal, without the console.
The same proprietary collection that powers Mythic is available as data: detailed malicious domain intelligence, delivered as feeds your defenses can act on and an API your engineers can build with.
Data Feeds & API datasheet (PDF)Malicious domains, from the source.
Most domain intelligence is scraped, aggregated, and resold, which is why so many feeds agree with each other and lag the adversary together. Vigilocity's feeds come from our own proprietary gathering capabilities: the same tradecraft that watches threat actors acquire and stage infrastructure for Mythic.
The result is detailed, high-confidence malicious domain intelligence, identified as adversaries register and arm it, with the infrastructure context that separates a parked look-alike from a campaign about to launch.
Fully functional, built to be built on.
The API is not a companion utility; it is a first-class way to consume the intelligence. Query domains and infrastructure programmatically, integrate the collection into your own systems, and automate the decisions the data supports, at whatever scale your architecture requires.
Look up any domain and pivot through its registration to every domain the same registrant controls. Resolve an IP to the threats behind it. Pull DNS and data logs by date range, and stand up watchlists over the entities and network ranges you care about, with notifications when new matches appear.
API reference · docs.vigilocity.comBuilt to land in what you already run.
The feeds are plain, structured data, so they drop into the control points you already operate: firewalls and DNS filtering for blocking, your SIEM for enrichment, your threat intelligence platform for correlation, and your SOAR for the automation that follows. Consume them as scheduled pulls or query the API in real time; both speak the same records.
- domain
- the domain, as registered
- first_observed
- timestamp of first observation in collection
- registration
- registrar, dates, and registration detail
- registrant
- pivotable registrant identity and related domains
- infrastructure
- hosting, IP, and related infrastructure context
- attribution
- actor, campaign, and tooling linkage where established
- threats
- associated threat classifications
Field names and full schemas are in the API reference. Evaluations run against your own telemetry, so you judge the feeds on your traffic, not ours.
Three ways teams put the data to work.
Block before the campaign launches
Feed newly observed malicious domains directly into firewalls, DNS filtering, and secure gateways, so infrastructure is blocked in the window between registration and use.
Enrich what you already see
Resolve the alerts in your SIEM and the indicators in your threat intelligence platform against domains with actor, campaign, and infrastructure context attached.
Build on the signal
Security vendors and internal platform teams use the API to build the intelligence into their own products, scoring engines, and automated workflows.
