List of keyless (zero-auth) public CTI and infostealer API endpoints for rapid triage + open-source Python script to query them
This content is a curated list of publicly accessible, keyless (zero-authentication) cyber threat intelligence (CTI) and infostealer API endpoints useful for rapid triage and investigation. It includes various free APIs for credential exposure, infrastructure reconnaissance, vulnerability scoring, and botnet command-and-control feeds. Additionally, an open-source Python script is provided to query these endpoints concurrently, facilitating efficient threat analysis workflows.
AI Analysis
Technical Summary
The post compiles multiple public CTI and infostealer API endpoints that do not require API keys or authentication, enabling quick domain exposure checks and indicator of compromise (IOC) triage without commercial API dependencies. The listed sources cover credential leaks from infostealers, breach data, infrastructure and BGP information, certificate transparency logs, DNS-over-HTTPS queries, vulnerability exploitation probabilities, known exploited vulnerabilities, and active malware/botnet C2 feeds. An accompanying MIT-licensed Python script automates querying these endpoints concurrently, enhancing analyst efficiency.
Potential Impact
This is informational content providing resources for threat intelligence analysts. It does not describe a vulnerability or active exploit but facilitates faster and broader threat data collection. There is no direct security impact or exploitation described.
Mitigation Recommendations
No remediation or patching is applicable as this is not a vulnerability or exploit. Analysts can leverage the provided resources and script to improve their triage processes.
List of keyless (zero-auth) public CTI and infostealer API endpoints for rapid triage + open-source Python script to query them
Description
This content is a curated list of publicly accessible, keyless (zero-authentication) cyber threat intelligence (CTI) and infostealer API endpoints useful for rapid triage and investigation. It includes various free APIs for credential exposure, infrastructure reconnaissance, vulnerability scoring, and botnet command-and-control feeds. Additionally, an open-source Python script is provided to query these endpoints concurrently, facilitating efficient threat analysis workflows.
Reddit Discussion
Hey r/threatintel,
When doing quick domain exposure checks or IOC triage on a clean workstation without my usual commercial API keys configured, I rely heavily on public CTI endpoints that don't require registration or bearer tokens.
I compiled my go-to list of keyless REST/socket sources below in case it helps other analysts, along with a small MIT-licensed Python stdlib script I wrote to query them concurrently:
### 1. Infostealer & Credential Exposure (Keyless)
- **Hudson Rock Cavalier (`cavalier.hudsonrock.com/api/json/v2/osint-tools/search-by-domain`):** Great for separating corporate credential leaks caused by client-side infostealers (RedLine, Lumma, Vidar, Raccoon) vs third-party database breaches. Returns infected employee/user counts and stolen login URLs without an API key.
- **HaveIBeenPwned v3 (`haveibeenpwned.com/api/v3/breaches` & `api.pwnedpasswords.com/range/`):** The general breaches list and k-Anonymity SHA-1 password range endpoints are completely free and keyless.
### 2. Infrastructure, BGP & Passive Recon
- **Shodan InternetDB (`internetdb.shodan.io/{ip}`):** Free, instant JSON lookup for open ports, CPEs, hostnames, tags, and known CVEs on any IP.
- **RIPE Stat Data API (`stat.ripe.net/data/prefix-overview/data.json`):** Keyless ASN, holder name, and BGP CIDR prefix lookups.
- **crt.sh (`crt.sh/?q={domain}&output=json`):** Certificate Transparency logs for passive subdomain discovery.
- **Cloudflare DoH (`cloudflare-dns.com/dns-query`):** RFC 8484 DNS-over-HTTPS for checking MX, TXT, SPF, and `_dmarc` spoofing policies.
### 3. Vulnerability & Botnet C2 Feeds
- **FIRST.org EPSS (`api.first.org/data/v1/epss`):** 30-day exploitation probability score and percentile for any CVE.
- **CISA KEV JSON (`cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json`):** Active exploitation confirmation.
- **Abuse.ch ThreatFox & Feodo Tracker:** Free JSON/CSV feeds for active C2 IPs and malware SHA-256 hashes.
To avoid querying these manually across 10 tabs, I bundled them into a zero-dependency Python CLI script (pure standard library, no commercial product/company, just MIT open-source):
https://github.com/prox0959/CyberCodex
What other keyless/free CTI endpoints are you all using in your daily triage workflows? I'd love to add more community-recommended sources to the list.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The post compiles multiple public CTI and infostealer API endpoints that do not require API keys or authentication, enabling quick domain exposure checks and indicator of compromise (IOC) triage without commercial API dependencies. The listed sources cover credential leaks from infostealers, breach data, infrastructure and BGP information, certificate transparency logs, DNS-over-HTTPS queries, vulnerability exploitation probabilities, known exploited vulnerabilities, and active malware/botnet C2 feeds. An accompanying MIT-licensed Python script automates querying these endpoints concurrently, enhancing analyst efficiency.
Potential Impact
This is informational content providing resources for threat intelligence analysts. It does not describe a vulnerability or active exploit but facilitates faster and broader threat data collection. There is no direct security impact or exploitation described.
Defensive Guidance
No remediation or patching is applicable as this is not a vulnerability or exploit. Analysts can leverage the provided resources and script to improve their triage processes.
Technical Details
- Source Type
- Subreddit
- ThreatIntelligence+threatintel+websecurityresearch
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":41,"reasons":["external_link","newsworthy_keywords:rce,infostealer","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce","infostealer"]}
- Has External Source
- false
- Trusted Domain
- false
Threat ID: 6aba4cfaf7a7c54106950eeb
Added to database: 09/28/2026, 11:18:18 UTC
Last enriched: 09/28/2026, 11:18:22 UTC
Last updated: 09/29/2026, 03:47:55 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.