{"uid":"cap_erHeXgVcxeTDv3WJvYH9f","slug":"agenttoll-mcp-iocs-indicators-of-compromise-lookup-103d010f","name":"AgentToll MCP IOCs — Indicators of Compromise Lookup","description":"108+ receipt-backed x402 work products for AI agents. Clear prices, spend caps, buyer metadata, and structured results over Base USDC.","url":"https://agenttoll.dev/paid/security/mcp-iocs","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"properties":{"host":{"type":"string","maxLength":200},"package":{"type":"string","maxLength":200}}},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"iocs":[],"malicious":false}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_b2BUo3W9G_7euyPYheHOr","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a given input (IP, domain, hash, or URL) against threat intelligence data to identify indicators of compromise (IOCs) and determine if it is malicious.","exampleAgentPrompt":"Check if the domain evil-phishing-site.com is a known indicator of compromise — is it flagged as malicious in threat intelligence feeds?","exampleUseCases":[{"title":"Malware hash verification in IR","prompt":"We found a suspicious file on a compromised host with SHA256 hash d41d8cd98f00b204e9800998ecf8427e — can you check if this is a known malware indicator?"},{"title":"Suspicious IP reputation check","prompt":"Our firewall logs show repeated connection attempts from 185.220.101.47 — look it up in threat intelligence and tell me if it's flagged as malicious or associated with any known IOCs."},{"title":"Phishing domain OSINT lookup","prompt":"I got a suspicious email containing a link to secure-login-update.net — can you check if that domain is a known indicator of compromise or tied to any phishing campaigns?"}],"resultDescription":"Returns a JSON object with an 'iocs' array listing any matched threat indicators associated with the queried entity, and a 'malicious' boolean indicating whether the indicator is known to be malicious based on threat intelligence data.","failureModes":["Unknown or unrecognized indicator type returns empty iocs array with malicious: false","Rate limiting or payment failure via x402 results in request rejection","Newly registered malicious domains may not yet appear in threat feeds, producing false negatives","Malformed input (invalid IP format, bad hash length) may return an error or empty result","Threat intelligence coverage gaps may yield false negatives for less-tracked IOC categories"],"whenToPreferThis":"Use this endpoint when an AI agent needs to quickly assess whether a specific network indicator — IP, domain, hash, or URL — is associated with known malicious activity, without spinning up a full security platform. It is ideal for inline triage during incident response, log enrichment pipelines, or automated phishing/malware detection workflows where per-call micropayments in USDC are acceptable and a lightweight JSON verdict is sufficient.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:32:01.867Z","isFirstParty":false}