🚨 ipcriminal-python
A Python wrapper for the Criminal IP Cyber Threat Intelligence (CTI) API
Key Features • Installation • Quick Start • API Reference • Error Handling • Contributing
📖 Overview
ipcriminal-python is an easy-to-use, feature-packed Python SDK for interacting with the Criminal IP Threat Intelligence search engine. It empowers security analysts, red teamers, and threat intelligence practitioners to automate asset discovery, IP reputation scoring, domain threat scanning, exploit lookup, and banner searching directly within their Python workflows.
✨ Key Features
- 🌐 IP & Asset Intelligence: Query comprehensive reports, open ports, VPN detection, hosting status, malicious histories, and privacy threats.
- 🔍 Domain Security Analysis: Perform Full and Lite domain scans, retrieve scan progress, check malicious vs. trusted domain hashes, and list historical scan reports.
- 🛡️ Exploit & Banner Search: Search exposed services across global network banners and look up CVE vulnerability data.
- 🔄 Automated Pagination: Built-in offset management for endpoints like
assest_search,banner_search,domain_reports, andexploit_search. - 🔑 Clean Authentication: Seamless API key management with header-based request handling.
🚀 Installation
Install directly from GitHub via pip:
pip install git+https://github.com/Xeroxxhah/ipcriminal-python.git
Or clone the repository locally and install the dependencies:
git clone https://github.com/Xeroxxhah/ipcriminal-python.git
cd ipcriminal-python
pip install .
🛠️ Quick Start
1. Obtain Your API Key
Sign up or log into your account at Criminal IP and grab your API Key from the developer dashboard.
2. Initialize the Client
from criminalip.criminalip import CriminalIP
# Initialize the API client with your token
client = CriminalIP(api_token="YOUR_CRIMINAL_IP_API_KEY")
3. Usage Examples
# Check credit balance and subscription tier
account_data = client.account_info()
print(account_data)
# Get a comprehensive report on a target IP
ip_report = client.ip_asset_report(ip_address="1.1.1.1", full=True)
# Fetch summarized security issues, open ports, and risk score
summary = client.ip_assest_report_summary(ip_address="1.1.1.1")
# Check if an IP is a known VPN, hosting server, or privacy threat
is_vpn = client.ip_vpn(ip_address="1.1.1.1")
privacy_threat = client.ip_privacy_threats(ip_address="1.1.1.1")
print(f"VPN Status: {is_vpn}")
# Initiate a private domain scan
scan_response = client.domain_scan(domain="example.com")
# Request a fast 2-5 second Lite Scan
lite_scan = client.domain_lite_scan(domain="example.com")
# Check if a domain is connected to a malicious website
quick_mal_check = client.domain_quick_mal_view(domain="example.com")
print(quick_mal_check)
# Search banners with automatic pagination (fetches up to offset count)
banners = client.banner_search(query="port: 22", offset=20)
# Search CVE exploit details
exploits = client.exploit_search(query="CVE-2023-23397", offset=10)
print(exploits)
📚 API Reference
👤 Account Management
| Method | Description | Endpoint |
|---|---|---|
account_info() |
Retrieves account details, tier, and remaining search credits. | POST /v1/user/me |
🌐 IP & Asset Intelligence
| Method | Parameters | Description | Endpoint |
|---|---|---|---|
ip_asset_report() |
ip_address (str), full (bool) |
Comprehensive IP report (VPN, ports, vulnerabilities). | GET /v1/asset/ip/report |
ip_assest_report_summary() |
ip_address (str) |
Summary of issues, risks, open ports, and detections. | GET /v1/asset/ip/report/summary |
ip_assest_summary() |
ip_address (str) |
Location, ISP, owner, and ASN metadata. | GET /v1/asset/ip/summary |
assest_search() |
query (str), offset (int) |
Searches assets using Criminal IP filter syntax with pagination. | GET /v1/asset/search |
ip_vpn() |
ip_address (str) |
Inquires if an IP is associated with a VPN provider. | GET /v1/ip/vpn |
ip_hosting() |
ip_address (str), full (bool) |
Checks if an IP is hosted in a cloud/hosting datacenter. | GET /v1/ip/hosting |
ip_mal_info() |
ip_address (str) |
Inquires whether an IP address is flagged as malicious. | GET /v2/feature/ip/malicious-info |
ip_suspicious_info() |
ip_address (str) |
Inquires data suspected to be malicious. | GET /v2/feature/ip/suspicious-info |
ip_privacy_threats() |
ip_address (str) |
Detects exposed webcams or IoT devices on the IP. | GET /v1/feature/ip/privacy-threat |
is_safe_dns_server() |
ip_address (str) |
Verifies whether the DNS service on an IP is secure. | GET /v1/feature/ip/is_safe_dns_server |
🌐 Domain Intelligence
| Method | Parameters | Description | Endpoint |
|---|---|---|---|
domain_scan() |
domain (str) |
Initiates a confidential private domain threat scan. | POST /v1/domain/scan/private |
domain_reports() |
query (str), offset (int) |
Retrieves fully scanned domain reports matching a query. | GET /v1/domain/reports |
get_domain_reports_by_id() |
id (str) |
Fetches detailed domain scan findings for a specific scan_id. |
GET /v1/domain/reports/{id} |
get_domain_status_by_id() |
id (str) |
Checks scan status/history for a given domain ID. | GET /1/domain/status/{id} |
domain_lite_scan() |
domain (str) |
Triggers a fast (2–5s) OSINT Lite Scan for a domain. | POST /v1/domain/lite/scan |
domain_lite_progress() |
scan_id (str) |
Checks progress state (-1, -2, 0 to 100) of a Lite Scan. | GET /v1/domain/lite/progress |
domain_lite_report_by_id() |
scan_id (str) |
Fetches Lite Scan results by scan_id. |
GET /v1/domain/lite/report/{scan_id} |
domain_lite_report() |
query (str), offset (int) |
Searches Lite Scan domain reports with pagination. | GET /v1/domain/lite/reports |
domain_quick_view() |
domain (str) |
Classifies if a URL is connected to a malicious or legitimate site. | GET /v1/domain/quick/hash/view |
domain_quick_mal_view() |
domain (str) |
Specifically verifies if a URL is connected to a malicious site. | GET /v1/domain/quick/malicious/view |
domain_quick_trusted_view() |
domain (str) |
Specifically verifies if a URL is connected to a legitimate site. | GET /v1/domain/quick/trusted/view |
💥 Exploits, Banners & Threat Intelligence
| Method | Parameters | Description | Endpoint |
|---|---|---|---|
banner_search() |
query (str), offset (int) |
Searches banner data across open ports with auto-pagination. | GET /v1/banner/search |
banner_stats() |
query (str) |
Retrieves statistical aggregations for a banner query. | GET /v1/banner/stats |
exploit_search() |
query (str), offset (int) |
Searches CVE vulnerability details and exploit references. | GET /v1/exploit/search |
feed_status() |
key (str) |
Queries status, staleness, and count for Threat Intel feeds. | GET /ti/v1/feed/status |
🛡️ Error Handling
If an API call is made without providing an API key, the SDK raises a custom ApiKeyError:
from criminalip import CriminalIP
from criminalip.exceptions import ApiKeyError
try:
client = CriminalIP() # No token passed
client.account_info()
except ApiKeyError as e:
print(f"Authentication Error: {e}")
🤝 Contributing
Contributions, bug reports, and feature requests are very welcome!
- Fork the repository
- Create your feature branch (
git checkout -b feature/NewEndpoint) - Commit your changes (
git commit -m 'Add support for missing endpoint') - Push to the branch (
git push origin feature/NewEndpoint) - Open a Pull Request
📄 License
This project is licensed under the MIT License - see the LICENSE file for details.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ipcriminal_python-0.1.0.tar.gz.
File metadata
- Download URL: ipcriminal_python-0.1.0.tar.gz
- Upload date:
- Size: 7.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
856bb3cdf9aa2a50753bcc030cc7bb4cc78da869f5a767c134edb12d8f1d3ff0
|
|
| MD5 |
2343031fd592e23bf10e2f0584717e81
|
|
| BLAKE2b-256 |
b1fa8e54d99a720b8e04960d92e162303bc98e0dec9af280438abc263c3fce5f
|
File details
Details for the file ipcriminal_python-0.1.0-py3-none-any.whl.
File metadata
- Download URL: ipcriminal_python-0.1.0-py3-none-any.whl
- Upload date:
- Size: 7.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5bfddd638f2aa64cf18efcc7f8d0d87d9c98451b495cd80f405b819166ad9d82
|
|
| MD5 |
39cc4db34c97966489fa9604fe6c2a62
|
|
| BLAKE2b-256 |
8fead27a587aa5c5a86e49ee6f1227d8246515d18f1554f2f4ee9c764a68ef7e
|