get_threat_intelligence
Query threat intelligence data to retrieve indicators of compromise, threat actors, and campaigns by IP, domain, hash, or actor name.
Instructions
Query threat intelligence data — IOCs, threat actors, and campaigns
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| type | No | Filter by IOC type: ip_address, domain, file_hash, url, email | |
| limit | No | Max records to return (default 25) | |
| query | Yes | Search term (IP, domain, hash, actor name) |