Tool profile
ThreatFox
Search community-shared malware indicators
Claims and corrections are reviewed before public profile changes.
Trust / disclosure
How to read this profile
Editorial line
Editorial judgment and commercial context are kept separate on OSINT4ALL.
Review status
This profile has an editorial review date. Source checking does not mean the tool was hands-on tested.
Claims / submissions
Corrections and claim requests are reviewed before any public change is made.
Commercial context
No commercial relationship is disclosed on this profile.
Editorial verdict
Use case and fit
This is editorial guidance, not vendor copy.
Checking whether a scoped domain, IP or hash appears in reported malware-related indicator data.
Check current authentication and usage policy before API automation; no guaranteed unrestricted bulk access.
Best for checking whether a scoped domain, IP or hash appears in reported malware-related indicator data.
Operational snapshot
Workflow, access, and coverage
Threat indicator reputation and enrichment, Threat intelligence correlation and sharing
Domain, IP Address, URL, File Hash, Email
Reputation Signal, Community Report, Linked Indicator, Dated Observation, Correlated Event
Triage, Enrichment, Verification, Analysis, Reporting
Search the exact indicator; inspect first/last-seen context and source; compare with independent data; note shared hosting; record the result as a lead until corroborated.
English-first editorial profile. Verify current interface languages and source-language coverage; multilingual input does not guarantee equal analytical quality.
Limits
Strengths, caveats, and risk
Structured, time-stamped indicator records support fast triage and cross-checking.
Community submissions can be incomplete, stale or misclassified.
An indicator association is not proof that a currently shared IP or domain is wholly malicious.
An indicator association is not proof that a currently shared IP or domain is wholly malicious.
Review external-submission privacy; do not execute malware or use exposed credentials in a general research workflow.
Separate vendor or community labels from verified observations and record freshness. Official-source desk research only; not hands-on tested. Tool-specific caution: An indicator association is not proof that a currently shared IP or domain is wholly malicious.
Maintenance
Source status & suggest an update
Help keep this profile accurate. Update requests are reviewed and logged before publication.
Source checked: 2026-09-19
If something is outdated, please submit a correction or ownership update request. Claim requests are reviewed and do not grant editorial control.
Commercial or sponsorship requests use the separate partner workflow.