ThreatFox
liveSecurityabuse.ch IOC feed — IPs, domains, URLs, hashes tied to malware families and campaigns.
4tools
0msauth
free tier50 calls/day
Tools
search_iocrequired: indicatorLook up a specific indicator.
Parameters
NameTypeDescription
indicatorreqstringIP/domain/URL/hashexact_matchoptbooleanDefault trueTry it
Response
recent_iocsIOCs from the last N days.
Parameters
NameTypeDescription
daysoptnumber1-7Try it
Response
search_hashrequired: hashIOCs associated with a file hash.
Parameters
NameTypeDescription
hashreqstringmd5/sha1/sha256Try it
Response
search_malwarerequired: malwareIOCs tagged to a malware family.
Parameters
NameTypeDescription
malwarereqstringFamily namelimitoptnumberMax recordsTry it
Response
Test with curl
The gateway speaks JSON-RPC 2.0 over HTTP POST. You can test any pack directly from the terminal.
List available tools
bash
curl -X POST https://gateway.pipeworx.io/threatfox/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'Call a tool
bash
curl -X POST https://gateway.pipeworx.io/threatfox/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"search_ioc","arguments":{"indicator": "example"}}}'Use with the SDK
Install @pipeworx/sdk to call tools from any TypeScript/Node project.
TypeScript
import { Pipeworx } from '@pipeworx/sdk';
const px = new Pipeworx();
const result = await px.call("search_ioc", {"indicator":"example"});ask_pipeworx
// Or ask in plain English:
const answer = await px.ask("abuse");