ioc_lookup_tool
Look up IP or domain reputation in honeypot dataset. Returns total events, first/last seen, country, ASN, targeted ports, user agents, URL paths, and fingerprints.
Instructions
Look up any IP address or domain in the honeypot dataset. Use this FIRST whenever the user asks: 'is this IP malicious?', 'is this a known scanner?', 'have you seen this IP?', 'what does this IP do?', 'when was it last seen?', 'is this IP in your data?'. Returns: total_events (0 = never observed), first_seen, last_seen, country, ASN, all ports targeted, top user agents, top URL paths, TLS/HTTP/SSH fingerprints. Covers both IPv4 and domains.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ioc | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||