Skip to main content
Glama
401,371 tools. Last updated 2026-08-06 11:58

"abuse.ch" matching MCP tools:

Matching MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    Enables querying threat intelligence data about files, URLs, IPs, and domains from multiple abuse.ch platforms (MalwareBazaar, URLhaus, and ThreatFox) through a unified API. Provides comprehensive security reports and threat analysis data for cybersecurity investigations.
    Last updated
    3
    MIT

Matching MCP Connectors

  • Swiss merchant ARVI SA: 27,000+ fine & rare wine labels, 300,000+ bottles ready to ship. No auth.

  • whentofly: flight search for AI agents — cheapest flexible-date round-trips + buy/wait verdict

  • Retrieve recent indicators of compromise from ThreatFox (abuse.ch) for threat intelligence and security analysis. Specify the number of days to look back.
    MIT
  • Check a domain against abuse.ch URLhaus to identify known malware-distributing URLs and assess domain-level threat status.
    MIT
  • Auto-detect the type of any IOC (IP, domain, URL, or hash), query abuse.ch feeds (ThreatFox, Feodo Tracker, URLhaus), and return a threat verdict and source summary.
    MIT
  • Query multiple malware intelligence sources for a file hash to retrieve prior analysis summaries and metadata without detonating the sample.
    MIT
  • Enrich up to 50 indicators per request by auto-detecting their type and querying abuse.ch threat feeds, returning per-indicator verdicts to triage SOC alerts efficiently.
    MIT
  • Check if an IP or domain is a known botnet command-and-control server by cross-referencing C2 blocklists like Feodo Tracker, ThreatFox, and URLhaus.
    MIT
  • Check a domain against free threat intelligence feeds (Spamhaus DBL, SURBL, URLhaus) to identify malicious listings and receive threat categories.
    MIT
  • Enrich Indicator of Compromise (IP/domain/URL/hash) by auto-detecting type and querying abuse.ch feeds. Per-type source coverage: hash → ThreatFox only (Feodo and URLhaus do not index hashes); IP → ThreatFox + Feodo Tracker + URLhaus; domain / URL → ThreatFox + URLhaus. verdict.sources_queried lists what actually ran; verdict.sources_unavailable lists what failed (timeout / upstream error). Use as primary IOC triage tool when type unknown; use threat_intel for domain-only, hash_lookup for richer MalwareBazaar hash data. Free: 30/hr, Pro: 500/hr. Returns {indicator, type, threat_level, sources, summary, verdict}.
    Connector
  • Batch query multiple IOCs (IP/domain/URL/hash, up to 50 per call, same for Free and Pro) in 1 request: auto-detects type + queries abuse.ch feeds per-indicator. Per-type source coverage matches ioc_lookup: hash → ThreatFox only; IP → ThreatFox + Feodo + URLhaus; domain / URL → ThreatFox + URLhaus. Each result item carries its own verdict.sources_queried / sources_unavailable so partial failures are visible per indicator. Use for SOC alert triage or batch enrichment; use ioc_lookup for single indicator. Free: 30/hr (1 per item), Pro: 500/hr. Returns {results, total, successful, failed, timed_out, partial, summary}.
    Connector
  • Check domain against abuse.ch URLhaus for known malware-distribution URLs (single source — for multi-feed correlation use ioc_lookup which adds ThreatFox and, for IPs, Feodo Tracker). Use for fast domain-level threat assessment; use phishing_check for specific URLs. Free: 30/hr, Pro: 500/hr. Returns {malware_urls, threat_tags, threat_status, summary}.
    Connector
  • Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the indicator set; it is not a clean verdict on the artifact.
    Connector
  • Risk profile for an IP address: geolocation and network (ASN/ISP/org) plus two abuse signals - whether it is a known Tor exit node, and whether it appears on the abuse.ch Feodo botnet command-and-control blocklist. For fraud, abuse, and security screening. Keyless.
    Connector