Pricing

Paid plans start at $50k/year.

Free

Use the feed for research, to block confirmed malware, and create detections.

Create free account

Core

Enhance the free feed with advanced API access, built for pipeline integration.

Contact us

Enterprise

Build an advanced research program with threat actor attribution, IOCs, and more.

Contact us

Compare tiers

FeatureFreeCoreEnterprise
Threat feedIncludedIncludedIncluded
Integrate via API2k/day25k/day25k/day
Custom alerts2520
Check if an asset is maliciousIncludedIncludedIncluded
See unconfirmed, pending reportsIncludedIncluded
STIX, custom TIP integrations (e.g. Anomali)IncludedIncluded
Structured IOCsIncluded
Trace threats to a specific publisher or actorIncluded
On-demand scanning queueIncluded
Intel libraryIncluded
Campaign grouping/mappingIncluded
Bulk API for retroactive sweepsIncluded
Custom research (RFI)Included

FAQ

Can individual researchers purchase OpenSourceMalware?

At this time, licenses are limited to organizations.

Can I use OpenSourceMalware in my product (e.g. as a data source for blocking malware for customers)?

Commercial usage requires an OEM license. Contact us to discuss how you'd like to use the feed, and review our Terms of Use to understand what's permitted with a Free account.

How do I create a free account?

You can create an account using your GitHub. If you'd rather have the account linked to your email, fill out the contact form and be detailed in your request.

How do I get an API key?

After you sign up for an account, navigate to the API token page in your profile.

How do I set up a threat alert?

After you sign up for an account, navigate to the threat alerts in your profile.