MCP server exposing 4 tools for threatfox.
This URL is a JSON-RPC 2.0 endpoint over HTTP. Issue POST requests with a JSON-RPC body. Browsers and search crawlers land here on GET.
POST https://gateway.pipeworx.io/threatfox/mcp
Content-Type: application/json
{"jsonrpc":"2.0","id":1,"method":"tools/list"}
search_ioc — Look up a specific indicator of compromise (IP, domain, URL, hash, etc.). Returns matching IOCs with malware family, confidence, threat-type, first/last seen, tags, references.recent_iocs — IOCs added to ThreatFox in the last N days. Useful for daily threat-intel ingestion.search_hash — Everything ThreatFox knows about one file hash (md5 / sha1 / sha256), across BOTH relations it stores hashes in — they are different facts and a caller with a hash in hand rarely knows which one they have. (1) sample_to_c2: the hash is a malware SAMPLE, and ThreatFox returns the botnet C&C servers that sample talks to (this is what abuse.ch's own `search_hash` query answers, and only this). (2) hash_listed_as_ioc: the hash is itself published as an indicator — threat_type "payload" — in which case the row IS the answer. `matched_relation` says which one fired, or is null when neither did. AN EMPTY RESULT IS A REAL ANSWER HERE, not a failure: ThreatFox is a C&C-tracking feed, not a sample database — most hashes on any malware site are in neither relation. It also expires every IOC older than six months, so a hash from an old report can legitimately return nothing today. For sample metadata (file type, size, signature, YARA) use the malwarebazaar pack, which is the same vendor and indexes every sample.search_malware — IOCs tagged to a malware family (e.g., "Cobalt Strike", "Emotet", "QakBot").Code samples (curl / TypeScript / one-click client install), schemas, and the live playground are on the pack page:
https://pipeworx.io/packs/threatfox/
Pipeworx is an open MCP gateway connecting AI agents to live data. pipeworx.io