{"uid":"cap_iMXXVEsVXWcVWYla0E-dw","slug":"ioc-threat-intelligence-enrichment-23260dc3","name":"IOC Threat Intelligence Enrichment","description":"Type-agnostic threat-intelligence enrichment for a SOC or DFIR agent. Give one indicator of compromise of any kind — a file hash, IP, domain, URL or CVE id — and get one normalized, cited verdict. Auto-detects the type, dispatches to the right grain, fuses the sources and returns a verdict, an is_malicious flag, a confidence, malware family when known, per-source citations and reasons. Not a guarantee.","url":"https://api.agentstools.dev/threat/ioc","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["indicator"],"properties":{"type":{"enum":["md5","sha1","sha256","hash","ip","ipv4","ipv6","domain","url","cve"],"type":"string","description":"Optional type override; auto-detected if omitted"},"indicator":{"type":"string","description":"The indicator of compromise: a file hash (md5/sha1/sha256), IP, domain, URL or CVE id"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_QKRFVPcfYSQHNZ6Gal1t_","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Auto-detects and enriches any indicator of compromise (hash, IP, domain, URL, or CVE) with a normalized threat verdict, malicious flag, confidence score, malware family, and per-source citations.","exampleAgentPrompt":"Can you check if the SHA256 hash 3395856ce81f2b7382dee72602f798b642f14d8f92f16c997e4a5eea65e2b9e9 is malicious — I need a verdict, confidence score, and any associated malware family?","exampleUseCases":[{"title":"Automated malware incident triage","prompt":"I've got a suspicious file from an email attachment with MD5 hash d41d8cd98f00b204e9800998ecf8427e — can you quickly tell me if it's actually malicious, how confident you are, and what malware family it belongs to if known?"},{"title":"Real-time C2 infrastructure investigation","prompt":"Our network team flagged this IP address 192.0.2.42 in connection logs from a potential breach — I need a threat verdict, citations from your sources, and any confidence score on whether it's genuinely malicious."},{"title":"DFIR domain enrichment workflow","prompt":"I'm investigating a phishing campaign and need to enrich these indicators: the domain evil.example.com, the CVE-2024-1234 mentioned in the phishing email, and this URL pointing to a payload. Can you give me a normalized verdict with malware family and source citations for each?"}],"resultDescription":"Returns a normalized JSON object containing: a human-readable verdict, an is_malicious boolean flag, a confidence score, the malware family name when known, and per-source citations with reasons explaining why the indicator was or was not flagged as malicious.","failureModes":["Missing required 'indicator' query parameter — returns 400 error","Indicator type cannot be auto-detected and is ambiguous — returns error or low-confidence result","Unknown or unseen indicator with no threat intel coverage — returns is_malicious false with low confidence","Rate limit or payment failure via x402 — returns 402 Payment Required","Malformed hash or invalid IP/domain format — returns validation error","CVE ID not found in any upstream source — returns empty or inconclusive verdict"],"whenToPreferThis":"Choose this endpoint when you need a unified, type-agnostic threat verdict for a single IOC without maintaining separate integrations for hashes, IPs, domains, URLs, and CVEs. It is ideal for SOC triage, DFIR workflows, or agent-driven security automation where you want one normalized response with source attribution rather than querying multiple threat intel APIs separately.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:07:52.023Z","isFirstParty":false}