Skip to main content

List of keyless (zero-auth) public CTI and infostealer API endpoints for rapid triage + open-source Python script to query them

0
Medium
Published: 09/27/2026 (09/27/2026, 16:01:56 UTC)
Source: Reddit ThreatIntel

Description

This content is a curated list of publicly accessible, keyless (zero-authentication) cyber threat intelligence (CTI) and infostealer API endpoints useful for rapid triage and investigation. It includes various free APIs for credential exposure, infrastructure reconnaissance, vulnerability scoring, and botnet command-and-control feeds. Additionally, an open-source Python script is provided to query these endpoints concurrently, facilitating efficient threat analysis workflows.

Reddit Discussion

r/threatintel·posted by u/Traditional_Bear5492
00

Hey r/threatintel,

When doing quick domain exposure checks or IOC triage on a clean workstation without my usual commercial API keys configured, I rely heavily on public CTI endpoints that don't require registration or bearer tokens.

I compiled my go-to list of keyless REST/socket sources below in case it helps other analysts, along with a small MIT-licensed Python stdlib script I wrote to query them concurrently:

### 1. Infostealer & Credential Exposure (Keyless)

- **Hudson Rock Cavalier (`cavalier.hudsonrock.com/api/json/v2/osint-tools/search-by-domain`):** Great for separating corporate credential leaks caused by client-side infostealers (RedLine, Lumma, Vidar, Raccoon) vs third-party database breaches. Returns infected employee/user counts and stolen login URLs without an API key.

- **HaveIBeenPwned v3 (`haveibeenpwned.com/api/v3/breaches` & `api.pwnedpasswords.com/range/`):** The general breaches list and k-Anonymity SHA-1 password range endpoints are completely free and keyless.

### 2. Infrastructure, BGP & Passive Recon

- **Shodan InternetDB (`internetdb.shodan.io/{ip}`):** Free, instant JSON lookup for open ports, CPEs, hostnames, tags, and known CVEs on any IP.

- **RIPE Stat Data API (`stat.ripe.net/data/prefix-overview/data.json`):** Keyless ASN, holder name, and BGP CIDR prefix lookups.

- **crt.sh (`crt.sh/?q={domain}&output=json`):** Certificate Transparency logs for passive subdomain discovery.

- **Cloudflare DoH (`cloudflare-dns.com/dns-query`):** RFC 8484 DNS-over-HTTPS for checking MX, TXT, SPF, and `_dmarc` spoofing policies.

### 3. Vulnerability & Botnet C2 Feeds

- **FIRST.org EPSS (`api.first.org/data/v1/epss`):** 30-day exploitation probability score and percentile for any CVE.

- **CISA KEV JSON (`cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json`):** Active exploitation confirmation.

- **Abuse.ch ThreatFox & Feodo Tracker:** Free JSON/CSV feeds for active C2 IPs and malware SHA-256 hashes.

To avoid querying these manually across 10 tabs, I bundled them into a zero-dependency Python CLI script (pure standard library, no commercial product/company, just MIT open-source):

https://github.com/prox0959/CyberCodex

What other keyless/free CTI endpoints are you all using in your daily triage workflows? I'd love to add more community-recommended sources to the list.

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 11:18:22 UTC

Technical Analysis

The post compiles multiple public CTI and infostealer API endpoints that do not require API keys or authentication, enabling quick domain exposure checks and indicator of compromise (IOC) triage without commercial API dependencies. The listed sources cover credential leaks from infostealers, breach data, infrastructure and BGP information, certificate transparency logs, DNS-over-HTTPS queries, vulnerability exploitation probabilities, known exploited vulnerabilities, and active malware/botnet C2 feeds. An accompanying MIT-licensed Python script automates querying these endpoints concurrently, enhancing analyst efficiency.

Potential Impact

This is informational content providing resources for threat intelligence analysts. It does not describe a vulnerability or active exploit but facilitates faster and broader threat data collection. There is no direct security impact or exploitation described.

Defensive Guidance

No remediation or patching is applicable as this is not a vulnerability or exploit. Analysts can leverage the provided resources and script to improve their triage processes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ThreatIntelligence+threatintel+websecurityresearch
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":41,"reasons":["external_link","newsworthy_keywords:rce,infostealer","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce","infostealer"]}
Has External Source
false
Trusted Domain
false

Threat ID: 6aba4cfaf7a7c54106950eeb

Added to database: 09/28/2026, 11:18:18 UTC

Last enriched: 09/28/2026, 11:18:22 UTC

Last updated: 09/29/2026, 03:47:55 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses