Quickly identify known threats via direct access to the latest threat intelligence, query using suspect malware file hashes, domains, URLs, IPv4 addresses. Also, check if the suspected values are "known-good" values and request WHOIS data for domains.
RST Cloud Threat Intelligence API is a cloud-based threat intelligence pay-as-you-go service that you can use for various tasks. You can lookup file hashes, domains, URLs, and IPv4 addresses to check if these are malicious (RST IoC Lookup) or are "known-good" values (RST Noise Control). Also, it allows to lookup WHOIS registration data for domains (RST Whois API).
Key Features:
Actionable Insights
Receive detailed indicators with comprehensive metadata, such as threat categories, severity levels (via scoring), related indicators, CVE, malware family names, attack tools and frameworks, threat actor information and additional contextual data. Empower your security teams to respond effectively to threats and take appropriate actions.
Reduce False Positives
Check alerts from other systems before raising a ticket in JIRA, ServiceNow or other platforms. This is done via a query to RST Noise Control service which comes as a part of this offering. Simply lookup if a value is a known good. Avoid alerting on known DNS servers, CDN IP, well-known domains, common hashes of Windows or its components like calc.exe or notepad.exe.
Comprehensive Threat Intelligence
Leverage our extensive threat intelligence database, continuously updated with the latest indicators of compromise (IOCs) from reputable sources, security vendors, individual threat intel researches worldwide, and research communities.
Simple Integration
Seamlessly integrate our API into your existing security infrastructure such as TIP, SIEM, SOAR systems or other applications with minimal effort. We provide comprehensive documentation and sample code to ensure a smooth integration process.
Cost-Effective
Pay only for the resources you consume with our flexible pricing model. Our cloud-based approach eliminates the need for on-premises infrastructure, reducing your operational costs and enabling you to focus on core security tasks.
Fast and Accurate Results
Obtain real-time threat intelligence with lightning-fast response times. Our advanced algorithms and infrastructure enable rapid identification, attribution, and categorisation of known threats, empowering you to make informed security decisions.
Multiple Query Options
Query our API using various indicators, including malware file hashes, domains, URLs, and IPv4 addresses. Gain a holistic view of potential threats associated with specific IOCs and take proactive measures to mitigate risks.
Scalable and Reliable
Built on the robust AWS infrastructure, our service offers high scalability, availability, and reliability. Handle peak loads effortlessly, ensuring uninterrupted threat intelligence services for your organisation.
Secure and Private
We prioritise data privacy and security. Your queries and sensitive information are handled with the utmost confidentiality and protected through industry-standard security practices and protocols.
Highlights
Quickly identify known threats via direct access to the latest threat intelligence, query using suspect malware file hashes, domains, URLs, IPv4 addresses
Ensure that false positive alerts do not create tickets in your case management systems by checking if they are driven by known-good IP, URLs, domains, or hashes.
Verify WHOIS registration for domains to fight with potential phishing scenarios.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay per lookup request under a single usage-based dimension. Each request queries one indicator — an IP, domain, URL, or file hash — and returns its threat score plus supporting context. Pricing scales directly with how many lookups you make, so your cost tracks actual query volume with no fixed tiers or instance sizes to choose. There are no separate charges by indicator type; every request counts the same way toward your usage. This suits integrating on-demand enrichment into your security tools, where you query one indicator at a time as needed.
Top-of-mind questions for buyers
What counts as one lookup request for billing purposes?
One lookup request is a single call that queries one indicator — an IP address, domain, URL, or file hash. Each indicator you check counts as one request. The indicator type does not change the count; a hash lookup and a domain lookup each register as one request.
Does querying a historical or dormant indicator cost the same as an active one?
Yes. Every lookup counts as one request regardless of the indicator's current state. A dormant indicator scoring zero today still returns its stored history, including scores preserved at first-seen and last-seen dates. Whether the indicator is active in the current feed or historical, it registers as one billable request.
How does my cost behave as query volume rises or falls?
Cost tracks the number of lookup requests you make. There are no fixed tiers or instance sizes to select. If you query fewer indicators, you pay for fewer requests. If volume grows, charges scale directly with the added requests. Each request meters the same way.
www.rstcloud.com
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
A next generation platform that builds process flow diagram-based threat models for cloud with just one click. ThreatModeler enables you to design applications/ infrastructure securely and supports established regulatory standards such as NIST, GDPR & PCI, enabling DevOps to ensure compliance is met
RelayShield delivers threat intelligence and identity security via REST API - 4.5M+ IOC corpus, breach detection, SIM swap monitoring, infostealer exposure, ransomware victim tracking, and session hijack detection. Built for MSPs, MSSPs, and security-forward development teams.
ThreatBook intelligence API relies on the powerful data collection capabilities of the ThreatBook Security Cloud, combined with independently developed core intelligence production systems, including dozens of different extraction methods, to quickly and automatically produce high-coverage, high-fidelity, and context-rich intelligence data.
Threat Prevention API: Integrate Check Point's ThreatCloud AI services to detect various malware types, including advanced malware in email attachments and web downloads, through a simple API.
Reputation API: Utilize Check Point's ThreatCloud AI intelligence to enhance your Security Operations, securing applications and websites with RESTful APIs. The Reputation API allows users to check the reputation of URLs, file hashes, and IP addresses.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.