Skip to main content
Glama
pipeworx-io

mcp-threatfox

by pipeworx-io

@pipeworx/threatfox

ThreatFox (abuse.ch) MCP — community IOC feed.

Part of Pipeworx — an MCP gateway connecting AI agents to 1394+ live data sources.

Tools

  • search_ioc(indicator, exact_match?)

  • recent_iocs(days?)

  • search_hash(hash)

  • search_malware(malware, limit?)

Related MCP server: Ioc Search MCP Server

Auth

  • Platform key: gateway env PLATFORM_ABUSECH_KEY (shared with malwarebazaar).

  • BYO: ?_apiKey=<key> after registering at https://auth.abuse.ch.

Data source

https://threatfox-api.abuse.ch/api/v1/ — header Auth-Key, POST with JSON body.

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

{
  "mcpServers": {
    "threatfox": {
      "url": "https://gateway.pipeworx.io/threatfox/mcp"
    }
  }
}

Or connect to the full Pipeworx gateway for access to all 1394+ data sources:

{
  "mcpServers": {
    "pipeworx": {
      "url": "https://gateway.pipeworx.io/mcp"
    }
  }
}

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English:

ask_pipeworx({ question: "your question about Threatfox data" })

The gateway picks the right tool and fills the arguments automatically.

More

License

MIT

A
license - permissive license
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    Enables querying threat intelligence data about files, URLs, IPs, and domains from multiple abuse.ch platforms (MalwareBazaar, URLhaus, and ThreatFox) through a unified API. Provides comprehensive security reports and threat analysis data for cybersecurity investigations.
    3
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables comprehensive threat analysis for Indicators of Compromise (IoCs) including IP addresses, file hashes, domains, and URLs. It provides detailed reputation scores, security vendor evaluations, and network metadata to facilitate security assessments and risk detection.
    4
    MIT
  • F
    license
    -
    quality
    D
    maintenance
    Provides real-time threat intelligence and malware metadata by integrating with MalwareBazaar and VirusTotal APIs. Users can search for IOCs, analyze local file hashes, and access data transformation tools for defensive security research.

View all related MCP servers

Related MCP Connectors

  • VirusTotal MCP — file / URL / domain / IP reputation (BYO key)

  • Query and retrieve information about various adversarial tactics and techniques used in cyber atta…

  • URLhaus MCP — wraps abuse.ch URLhaus malware URL database (free, no auth)

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/pipeworx-io/mcp-threatfox'

If you have feedback or need assistance with the MCP directory API, please join our Discord server