WhoisXML API Intelligence Is Now Available on Malfors

WhoisXML API Intelligence Is Now Available on Malfors

WhoisXML API is proud to announce its integration with Malfors, an investigation platform built for threat intelligence, OSINT, and security research teams, adding WhoisXML API as an enrichment source for entities across Malfors’ platform. The integration is live and widely used, and is one of the most popular among Malfors users.

WhoisXML API integration

Once Malfors users connect their own WhoisXML API key, they can start enriching domains with current and historical registration details, DNS intelligence, and IP geolocation details using these WhoisXML API products:

  • WHOIS API
  • WHOIS History API
  • IP Geolocation API
  • Reverse DNS API
  • Reverse IP API
  • Reverse MX API
  • Reverse NS API
  • Reverse WHOIS API
  • Domains & Subdomains Discovery API

The integration is built for threat intelligence analysts and threat hunters, security operations specialists, and incident response teams who collect intelligence on threat actors, discover more infrastructure through pivots on DNS records and WHOIS data, and make attribution.

The new data source gives Malfors users several advantages as they build out cases, including:

  • Enrichment across investigations: WhoisXML API intelligence acts as an enrichment source for entities in Malfors. Users can enrich domains with historical WHOIS data, IP geolocation, or DNS resolution. They can also search by string or by specific DNS record, all within their existing workflow.
  • Faster infrastructure mapping: With Reverse DNS, Reverse IP, Reverse MX, and Reverse NS all built into the platform, analysts can trace connections between domains, IPs, name servers, and mail servers in a few clicks, helping investigators map out a threat actor’s infrastructure faster.
  • Deeper attribution through historical data: WHOIS History lets users see how domain registration details have changed over time. That kind of record can reveal patterns or connections that current records would miss, which is important for attribution work.
  • Broader investigative context: Users can pull WHOIS, DNS, reverse DNS, IP intelligence, and reputation data into their case graph, connecting domains, IPs, registrants, and related infrastructure alongside data from Malfors’ other integrated sources.

We’ve used WhoisXML API’s data in our own investigations, and it is one of the most popular integrations among Malfors users. It is the best source we’ve found for WHOIS data, including WHOIS history and Reverse WHOIS. Analysts can pivot on DNS records or WHOIS text to uncover more infrastructure and support threat actor attribution. Our users, from SOC teams to incident responders, can access that data in just a few clicks.

—Artem Tamoian, CEO at Malfors

The Malfors integration is part of WhoisXML API’s ongoing work supporting the professionals and organizations on the front lines of cybercrime and fraud, alongside initiatives such as the Internet Abuse Signal Collective (IASC), Research and Media Collaborations, and Integration Partnerships.

To learn more about the integration, please visit Malfors’ integration page.

About Malfors

Malfors is an investigation platform for threat intelligence, OSINT, and security research, built around graph-based analysis, integrated enrichment, and real-time collaboration. 

The platform lets intelligence teams enrich entities with data from leading providers directly from the graph, connect their own internal intelligence through a simple API, and automatically discover shared data points between entities as cases develop, all within a secure investigation workspace.

Related posts

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.