AlienVault OTX

liveSecurity

Open Threat Exchange — community threat-intel pulses + per-indicator context (IPv4 / domain / URL / file hash).

3tools
0msauth
free tier50 calls/day

Tools

search_pulsesrequired: query

Keyword search across community threat-intel pulses.

Parameters
NameTypeDescription
queryreqstringSearch term
limitoptnumber1-50 (default 20)
pageoptnumber1-based page
Try it
get_pulserequired: pulse_id

Full pulse with indicators.

Parameters
NameTypeDescription
pulse_idreqstringOTX pulse ID
Try it
lookup_indicatorrequired: indicator

Pulses referencing an IOC. Type auto-detected when omitted.

Parameters
NameTypeDescription
indicatorreqstringIPv4 / domain / URL / hash
typeoptstringForce type
Try it

Test with curl

The gateway speaks JSON-RPC 2.0 over HTTP POST. You can test any pack directly from the terminal.

List available tools
bash
curl -X POST https://gateway.pipeworx.io/alienvault-otx/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
Call a tool
bash
curl -X POST https://gateway.pipeworx.io/alienvault-otx/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"search_pulses","arguments":{"query": "hello"}}}'

Use with the SDK

Install @pipeworx/sdk to call tools from any TypeScript/Node project.

TypeScript
import { Pipeworx } from '@pipeworx/sdk';
const px = new Pipeworx();
const result = await px.call("search_pulses", {"query":"example"});
ask_pipeworx
// Or ask in plain English:
const answer = await px.ask("open threat exchange — community threat-intel pulses + per-indicator context (ipv4 / domain / url / file hash)");