threatfox_search_family
Retrieve all ThreatFox indicators of compromise for a given malware family, including C2 IPs, domains, and payload hashes, to support threat hunting and detection engineering.
Instructions
Get all IOCs in ThreatFox for a specific malware family (e.g. "Cobalt Strike", "Sliver", "AgentTesla"). Returns C2 IPs, domains, and payload hashes.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| family | Yes | Malware family name (e.g. "Cobalt Strike") |