IOC Intelligence
get_ioc_intelligenceAnalyze any IOC (IP, domain, hash, URL) to get a complete threat dossier with actor attribution, DNS enrichment, infrastructure pivots, and consensus confidence score from 7 external feeds.
Instructions
Given an IOC (IP, domain, hash, URL), return a complete dossier: all threats touching it + actor attribution + DNS enrichment trail + infrastructure pivots (cross-IOC links) + corr_ioc_consensus confidence score from 7 external feeds (Pulsedive, GreyNoise, Yaraify, MalwareBazaar, URLScan, VxVault, OpenPhish). Powers 'I found this in a log — tell me everything' workflows. Requires Purple tier ($11.99/mo).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ioc_value | Yes | IOC value (IP, domain, hash, URL) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||