# com.threadlinqs/intelthreadlinqs-mcp (npm · intelthreadlinqs-mcp)

Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs

- Trust score: 20/100 (low)
- Change this week: −4
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `intelthreadlinqs-mcp`: 20/100 (this document), [markdown](https://verifymcp.io/servers/com-threadlinqs-intelthreadlinqs-mcp/intelthreadlinqs-mcp.md), [page](https://verifymcp.io/servers/com-threadlinqs-intelthreadlinqs-mcp/intelthreadlinqs-mcp)

## Channel facts

- Registry: `npm`
- Package: `intelthreadlinqs-mcp`
- Version: `8.1.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 37/100
  - Malware scan not yet available for this package.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 0 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 0/100
  - Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.
- **Capabilities**: 0/100
  - Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.

**Unverified: 4 categories.** Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you.

## Install

### Claude

```bash
claude mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
```

### Codex

```bash
codex mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-threadlinqs-intelthreadlinqs-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "intelthreadlinqs-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-threadlinqs-intelthreadlinqs-mcp --command npx --arg -y --arg intelthreadlinqs-mcp
```

### Hermes

```yaml
mcp_servers:
  com-threadlinqs-intelthreadlinqs-mcp:
    command: "npx"
    args: ["-y", "intelthreadlinqs-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "com-threadlinqs-intelthreadlinqs-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "intelthreadlinqs-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 20, −15)

- [security regression] Malware scan: pass → unverified
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional] Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.
- [functional] Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional] Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.
- [functional] Package version: 7.1.4 → 8.1.1

### 2026-08-02 (score 35, +15)

- [security regression] Provenance: unverified → fail
- [security regression] Malware scan: pass → unverified
- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security] Stability: Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] License: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional] Capabilities: Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake.
- [functional] Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess.
- [functional] Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess.
- [functional] Licence: MIT

### 2026-08-01 (score 20, +14)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-31 (score 6, −18)

- [security regression] Malware scan: pass → unverified

### 2026-07-27 (score 24)

First indexed and scored.

## MCP tools (73)

### `get_started` (~40 tokens)

Get Started

Start here. Returns the Threadlinqs Intelligence tool catalog, categories, tiering, and usage guidance. No API call — read this before using other tools.

Output parameters:

- `categories` (object)
- `exports` (string)
- `instructions` (string)
- `resources` (object)
- `server` (object)
- `tiering` (object)
- `tools` (array)

### `search_vulnerabilities` (~354 tokens)

Search Vulnerabilities

Query the real-time CVE feed — validated against CVE.org and enriched from open sources (CVSS, EPSS exploitation probability, CISA KEV, public PoCs/exploits, nuclei detection templates, affected products/packages, plus platform-native trending/priority). Sort by trending|latest|priority|cvss|epss; filter by severity, kev (KEV-only), has_poc, nuclei, epss_min, window (days), vendor, cwe, or free-text query. Returns COMPACT cards {cve_id, severity, cvss, epss_percentile, is_kev, has_poc/exploit/nuclei, priority, trending, vendors, age} — call get_cve(id) for full detail.

Input parameters:

- `cwe` (string): Weakness id, e.g. CWE-79
- `epss_min` (number): Minimum EPSS exploitation probability, 0-1
- `has_poc` (boolean): Only CVEs with a public proof-of-concept
- `kev` (boolean): Only CISA KEV (known-exploited) CVEs
- `limit` (number): default 30, max 100
- `nuclei` (boolean): Only CVEs with a nuclei detection template
- `query` (string): Free-text: a CVE id or keyword (matches id + description)
- `severity` (string): CRITICAL | HIGH | MEDIUM | LOW
- `sort` (string): trending (default) | latest | priority | cvss | epss
- `vendor` (string): Affected vendor/product substring
- `window` (number): Only CVEs published within the last N days

Output parameters:

- `facets` (object)
- `pagination` (object)
- `sort` (string)
- `total` (integer)
- `vulnerabilities` (array)

### `search_threats` (~681 tokens)

Search Threats

The deterministic threat-catalog query tool. Returns LEAN summary rows {id, title, severity, category, status, threat_actor, nation_state, affected_products, cves, cvss_score, summary, created} — call get_threat for full detail on a specific id. Combine a free-text `query` with any structured filters; ALL filters AND-combine and apply together (e.g. query="supply chain" + threat_actor="TeamPCP" + category="SUPPLY_CHAIN" returns only matching rows, with affected_products inline). Paginated: limit (default 20, max 100) + offset/cursor; result carries total, has_more, and next_cursor.

Input parameters:

- `affected_product` (string): Filter by affected product/vendor (e.g. "npm", "Microsoft", "VS Code")
- `campaign` (string): Filter to threats in a named campaign/operation (e.g. "Snowflake campaign")
- `category` (string): e.g. SUPPLY_CHAIN, MALWARE, RANSOMWARE, VULNERABILITY, APT, PHISHING, ZERO_DAY (call list_threat_categories for the full vocabulary)
- `created_after` (string): ISO date — only threats created on/after (e.g. 2026-05-01)
- `created_before` (string): ISO date — only threats created on/before
- `cursor` (string): Opaque pagination cursor (next_cursor from a prior result); ignored when offset is given.
- `cve` (string): Filter by CVE id (e.g. CVE-2026-45321)
- `limit` (number): Max results (default 20, max 100)
- `malware` (string): Filter to threats deploying a malware family (e.g. "LockBit", "Vidar")
- `mitre_technique` (string): Filter by MITRE technique id (e.g. T1059)
- `motivation` (string): Filter by motivation (e.g. financial, espionage)
- `nation_state` (string): Filter by nation-state (e.g. Russia, China, Iran)
- `offset` (number): Row offset for pagination (default 0).
- `os` (string): Filter to threats affecting an operating system (e.g. "Windows", "Linux", "VMware ESXi")
- `query` (string): Free-text term across title/summary/description/CVE/actor (optional; AND-combined with filters)
- `sector` (string): Filter by grounded industry sector (e.g. "Healthcare", "Government")
- `severity` (string): critical | high | medium | low
- `status` (string): Threat status filter (e.g. active)
- `tag` (string): Filter by exact tag (e.g. "supply-chain-compromise")
- `target_region` (string): Filter by targeted region (e.g. APAC, Europe)
- `target_sector` (string): Filter by targeted sector (e.g. Healthcare, Finance)
- `threat_actor` (string): Filter by attributed actor name/alias (e.g. "TeamPCP", "APT29")
- `tool` (string): Filter to threats using a tool (e.g. "Cobalt Strike", "Mimikatz")

Output parameters:

- `data` (array)
- `has_more` (boolean): True when another page may exist.
- `next_cursor` (string|null): Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
- `total` (integer): Total matching rows, when the handler reports one.

### `get_threat` (~95 tokens)

Get Threat

Get the full detail for a single threat by its ID (e.g. TL-2026-0042): overview, MITRE techniques, IOCs, detections, timeline, and tags. For that threat's malware families, tools, targeted sectors/regions, affected OS and campaigns, call get_threat_enrichment.

Input parameters:

- `id` (string, required): Threat ID (e.g. TL-2026-0042)

Output parameters:

- `attribution` (object)
- `category` (string)
- `created_at` (string)
- `description` (string)
- `detections` (array)
- `id` (string): Threat ID (TL-YYYY-NNNN).
- `identifiers` (object)
- `iocs` (object)
- `mitre_attack` (array)
- `osint` (object|null): Community-OSINT summary; null below Red tier or when unscanned.
- `references` (array)
- `severity` (object)
- `status` (string)
- `summary` (string)
- `tags` (array)
- `title` (string)
- `updated_at` (string)

### `get_recent_threats` (~128 tokens)

Recent Threats

List the most recently published threats. Paginated: pass limit (default 15, max 100) and offset to page through older threats; the result includes has_more and an opaque next_cursor (reusable as offset/cursor).

Input parameters:

- `cursor` (string): Opaque pagination cursor (next_cursor from a prior result). Decoded to an offset; ignored when offset is given.
- `limit` (number): Max results (default 15, max 100)
- `offset` (number): Row offset for pagination (default 0). Or pass cursor from a prior result.

Output parameters:

- `data` (array)
- `has_more` (boolean): True when another page may exist.
- `next_cursor` (string|null): Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
- `total` (integer): Total matching rows, when the handler reports one.

### `get_detections` (~174 tokens)

Get Detections

List detection logic (Splunk SPL, Microsoft KQL, Sigma). Optionally filter by threat_id or detection type. Paginated: pass limit (default 15, max 100) and offset to page; the result includes has_more and an opaque next_cursor (reusable as offset/cursor).

Input parameters:

- `cursor` (string): Opaque pagination cursor (next_cursor from a prior result). Decoded to an offset; ignored when offset is given.
- `limit` (number): Max results (default 15, max 100)
- `offset` (number): Row offset for pagination (default 0). Or pass cursor from a prior result.
- `threat_id` (string): Filter detections for a specific threat ID
- `type` (string): Detection type: spl, kql, or sigma

Output parameters:

- `data` (array)
- `has_more` (boolean): True when another page may exist.
- `next_cursor` (string|null): Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
- `total` (integer): Total matching rows, when the handler reports one.

### `search_iocs` (~131 tokens)

Search IOCs

Search indicators of compromise (IPs, domains, hashes, URLs). Filter by value substring and/or category. Pass limit (default 25, max 100); the result includes has_more (true when the page is full, so more may exist). NOTE: the indicator endpoint does not yet honor offset — narrow with a more specific value/type substring rather than paging.

Input parameters:

- `limit` (number): Max results (default 25, max 100)
- `type` (string): IOC category (e.g. network, file, behavioral)
- `value` (string): Substring to match against IOC values

Output parameters:

- `data` (array)
- `has_more` (boolean): True when another page may exist.
- `next_cursor` (string|null): Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
- `total` (integer): Total matching rows, when the handler reports one.

### `get_mitre_coverage` (~48 tokens)

MITRE Coverage

Get MITRE ATT&CK coverage across the platform. Optionally filter by tactic.

Input parameters:

- `tactic` (string): Filter by ATT&CK tactic (e.g. "initial-access")

Output parameters:

- `tactics` (array)
- `top_techniques` (array)
- `total_techniques` (integer)

### `get_mitre_technique` (~62 tokens)

MITRE Technique

Get details for a specific MITRE ATT&CK technique by ID (e.g. T1059 or T1059.001).

Input parameters:

- `technique_id` (string, required): Technique ID (e.g. T1059 or T1059.001)

Output parameters:

- `data_sources` (array)
- `mitigations` (array)
- `tactic` (string|null)
- `technique` (string|null)
- `technique_id` (string)
- `threats` (array)

### `get_threat_enrichment` (~115 tokens)

Threat Enrichment

Reference-grounded enrichment for one threat by ID: the malware families and tools used, targeted sectors/regions, affected operating systems, named campaigns, AI/ML (ATLAS) techniques, and per-technique mitigations + detection data sources. Complements get_threat (overview/MITRE/IOCs/detections) — call this for the "what malware/tools were used and who was targeted" view.

Input parameters:

- `id` (string, required): Threat ID (e.g. TL-2026-0042)

Output parameters:

- `atlas` (array)
- `campaigns` (array)
- `id` (string)
- `malware` (array)
- `operating_systems` (array)
- `regions` (array)
- `sectors` (array)
- `tools` (array)

### `get_malware_intelligence` (~127 tokens)

Malware Intelligence

Pivot on a malware FAMILY by name (e.g. "LockBit", "Vidar", "Emotet"). Returns the canonical family + type, prevalence (threat/actor counts, first/last seen), the threats deploying it, the actors using it, and its most-common ATT&CK techniques. For an offensive TOOL (Cobalt Strike, Mimikatz) use get_tool_intelligence instead. Call resolve_entity first if unsure of the canonical name.

Input parameters:

- `name` (string, required): Malware family name (e.g. "LockBit", "Vidar")

Output parameters:

- `actors` (array)
- `canonical` (string)
- `entity_type` (string)
- `matched` (boolean)
- `prevalence` (object)
- `query` (string)
- `threats` (array)
- `top_techniques` (array)

### `get_tool_intelligence` (~94 tokens)

Tool Intelligence

Pivot on an offensive tool / utility / RMM / LOLBin by name (e.g. "Cobalt Strike", "Mimikatz", "AnyDesk", "PsExec"). Returns the canonical tool + class, prevalence, the threats and actors using it, and its most-common ATT&CK techniques.

Input parameters:

- `name` (string, required): Tool name (e.g. "Cobalt Strike", "Mimikatz")

Output parameters:

- `actors` (array)
- `canonical` (string)
- `entity_type` (string)
- `matched` (boolean)
- `prevalence` (object)
- `query` (string)
- `threats` (array)
- `top_techniques` (array)

### `get_campaign_intelligence` (~63 tokens)

Campaign Intelligence

Pivot on a named campaign / operation by name (e.g. "Snowflake campaign", "ClickFix"). Returns the threats in the campaign, the actors involved, prevalence, and common ATT&CK techniques.

Input parameters:

- `name` (string, required): Campaign / operation name

Output parameters:

- `actors` (array)
- `canonical` (string)
- `entity_type` (string)
- `matched` (boolean)
- `prevalence` (object)
- `query` (string)
- `threats` (array)
- `top_techniques` (array)

### `resolve_entity` (~122 tokens)

Resolve Canonical Name

Normalize an actor / malware / tool / sector / region / technique name or alias to its canonical reference form + stable UUID (e.g. "fancy bear" → "APT28"). Call this BEFORE pivoting (get_actor / get_malware_intelligence / get_tool_intelligence / search_threats) when unsure of the canonical name. Optional type narrows the lookup.

Input parameters:

- `name` (string, required): Name or alias to resolve
- `type` (string): Optional: actor|malware|tool|sector|region|technique|campaign

Output parameters:

- `canonical` (string): Canonical name — feed to get_actor / get_malware_intelligence / get_tool_intelligence.
- `entity_type` (string)
- `matched` (boolean)
- `matched_via` (string)
- `query` (string)
- `uuid` (string)

### `get_actor` (~130 tokens)

Get Actor Profile

Get a lean threat-actor profile by name or alias: actor metadata, attribution counts, attributed-threat summary rows, MITRE tactic rollup + technique ids, IOC category counts (no raw values), CVE/CWE/tool summaries, and relationships. For heavy detail use the follow-up tools: get_threat(id) for a full threat, search_detections / get_detection_detail for detection bodies, search_iocs for IOC values, get_infrastructure_pivots for shared infrastructure.

Input parameters:

- `name` (string, required): Actor name or alias (e.g. 'APT29', 'Lazarus Group')

Output parameters:

- `actor` (object)
- `counts` (object)
- `cves` (array)
- `mitre` (object)
- `relationships` (object)
- `targets` (object)
- `threats` (array)
- `tools` (array)

### `search_actors` (~155 tokens)

List Actors

List attributed threat actors with aggregate stats (threat_count, severity levels, categories, nation_state). Returns the full roster in one call, or narrow it with the optional tool / malware / sector filters (e.g. tool="Cobalt Strike" → only actors that used it). Use get_actor for a single actor's full profile. Not paginated; the response carries a total count.

Input parameters:

- `malware` (string): Only actors with a threat deploying this malware family (e.g. "LockBit")
- `sector` (string): Only actors with a threat targeting this sector (e.g. "Healthcare")
- `tool` (string): Only actors with a threat using this tool (e.g. "Cobalt Strike")

Output parameters:

- `actors` (array)
- `has_more` (boolean): True when another page may exist.
- `next_cursor` (string|null): Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
- `total` (integer): Total matching rows, when the handler reports one.

### `get_cve` (~67 tokens)

Get CVE

Look up a CVE by identifier (e.g. CVE-2024-3400): description, CVSS, affected products, references, and linked threats.

Input parameters:

- `cve_id` (string, required): CVE identifier (e.g. CVE-2024-3400)

Output parameters:

- `affected_products` (array)
- `cve_id` (string)
- `cvss_v3` (object)
- `description` (string)
- `enriched` (boolean): False when the CVE is unknown — then only cve_id/valid/reason are present.
- `epss` (object)
- `exploitation` (object)
- `kev` (object)
- `published_date` (string)
- `threat_ids` (array)
- `weaknesses` (array)

### `get_cwe` (~56 tokens)

Get CWE

Look up a CWE by identifier (e.g. CWE-79): weakness name, description, severity, related CVEs, and mitigation guidance.

Input parameters:

- `cwe_id` (string, required): CWE identifier (e.g. CWE-79)

Output parameters:

- `cwe_id` (string)
- `description` (string)
- `enriched` (boolean): False when not found — then only cwe_id is present.
- `mitigations` (array)
- `name` (string)
- `related_cwes` (array)
- `threat_ids` (array)

### `get_platform_stats` (~28 tokens)

Platform Stats

Get aggregate platform statistics: threat, detection, IOC, MITRE technique, and actor counts.

Output parameters:

- `by_category` (array)
- `by_severity` (array)
- `top_actors` (array)
- `top_techniques` (array)
- `total_actors` (integer)
- `total_correlations` (integer)
- `total_detections` (integer)
- `total_iocs` (integer)
- `total_threats` (integer)
- `total_ttps` (integer)

### `get_similar_threats` (~113 tokens)

Similar Threats

Threats similar to a given threat, with the EVIDENCE behind each link: per-channel score breakdown, which signal dominates, the concrete shared techniques / IOCs / CVEs, and quality flags for stale or high-confidence-low-evidence links. Use explain_correlation for a full decomposition of one specific pair.

Input parameters:

- `id` (string, required): Source threat ID (e.g. TL-2026-0042)
- `limit` (number): Max results (default 10, max 50)

Output parameters:

- `count` (integer)
- `data` (array)
- `similar` (array)
- `source_threat_id` (string)

### `get_landscape_briefing` (~29 tokens)

Landscape Briefing

Get the latest threat-landscape briefing — a synthesized posture summary of recent threat activity.

Output parameters:

- `briefings` (array)
- `latest` (object|null)
- `top_viewed` (array)

### `get_daily_theme` (~19 tokens)

Daily Theme

Get the day's landscape theme and top threat tags.

Output parameters:

- `themes` (array)
- `yesterday` (object|null)

### `get_threat_level` (~29 tokens)

Threat Level

Get the computed current threat-landscape level (a 0–25 rating of overall posture).

Output parameters:

- `criteria` (array)
- `level` (string)
- `max` (number)
- `score` (number)
- `threats_observed` (integer)

### `get_ioc_blast_radius` (~143 tokens)

IOC Blast Radius

Map the blast radius of one indicator: the threats that contain it, the MITRE techniques those threats use, and the actors + sibling IOCs in the same campaigns. Use this to scope impact of a single IOC; for a richer multi-source dossier on one indicator use get_ioc_intelligence instead.

Input parameters:

- `depth` (number): Traversal rings to expand (1–3, default 3): 1=threats, 2=+techniques, 3=+actors & sibling IOCs
- `value` (string, required): Indicator value (IP, domain, hash, URL, or CVE-XXXX-NNNN)

Output parameters:

- `center` (string)
- `edge_scores` (array)
- `rings` (array)
- `stats` (object)

### `get_ioc_intelligence` (~77 tokens)

IOC Intelligence Dossier

Get the composite intelligence dossier for one indicator: linked threats, actor attribution, related IOCs, and enrichment context in a single call. Prefer this over search_iocs when you already have an exact indicator value and want its full story.

Input parameters:

- `value` (string, required): Exact indicator value (IP, domain, hash, or URL)

Output parameters:

- `consensus_score` (object|null): Multi-feed consensus; null when no feed has seen it.
- `dns_records` (array)
- `infrastructure_pivots` (array)
- `ioc_value` (string)
- `osint` (object|null)
- `threat_count` (integer)
- `threats` (array)
- `truncated` (boolean)

### `get_ioc_dns` (~79 tokens)

IOC DNS Enrichment

Return stored DNS enrichment for an IP or domain indicator (reverse-IP and subdomain records previously resolved and cached in the platform dataset). This reads stored data — it is NOT a live lookup at call time. Use get_ioc_intelligence for the full stored dossier.

Input parameters:

- `value` (string, required): IP address or domain (stored DNS enrichment lookup)

Output parameters:

- `cross_links` (array)
- `domains` (array)
- `query_value` (string)
- `total` (integer)

### `get_infrastructure_pivots` (~88 tokens)

Infrastructure Pivots

For a given threat, surface cross-threat infrastructure links — shared IPs/domains and DNS-derived overlaps that tie it to other campaigns. Use to widen from a single threat to its infrastructure neighborhood; use get_similar_threats for TTP/actor-based similarity instead.

Input parameters:

- `threat_id` (string, required): Threat ID (e.g. TL-2026-0042)

Output parameters:

- `dns_record_count` (integer)
- `dns_trail` (array)
- `infrastructure_pivots` (array)
- `pivot_count` (integer)
- `threat_id` (string)

### `get_osint` (~168 tokens)

Get OSINT Corroboration

Community corroboration for a threat or an indicator from the TL_OSINT_Scan layer (tweetfeed.live, CC0). Given threat_id, returns the matched community tags, the corroborated indicator count, and whether the community saw an indicator BEFORE our report. Given ioc_value, returns sightings, reporters, tags and every linked threat. Community-sourced and heavily concentrated (~73% of recent submissions come from a single reporter) — treat as corroborating evidence, never as authoritative attribution.

Input parameters:

- `ioc_value` (string): Exact indicator (IP, domain, URL, MD5 or SHA256). Returns the community lookup + our linked threats.
- `threat_id` (string): Threat ID (e.g. TL-2026-1531). Returns the per-threat corroboration block.

Output parameters:

- `community_seen_before_report` (boolean)
- `corroborated` (integer)
- `indicator_count` (integer)
- `lead_days` (number|null): Days the community saw an indicator before our report.
- `matched_tags` (array)
- `reporters` (array)
- `scanned` (boolean)
- `threat_id` (string): Present on the per-threat shape.
- `threat_ids` (array)
- `value` (string): Present on the per-IOC shape (ioc_value input).

### `search_xscan_indicators` (~265 tokens)

Search Community Indicators

Search the canonical community-indicator set (TL_OSINT_Scan / tweetfeed.live, CC0) — indicators the community reported that were also matched against our corpus. Filter by tag, type, ASN, country, minimum linked-threat count, or a value substring. There is deliberately NO family filter: the upstream AI family field is populated on under 1% of rows, so a family argument would return nothing. Use tag instead (community tags carry the family signal). Community-sourced and heavily concentrated (~73% of recent submissions come from a single reporter) — corroborating, not authoritative.

Input parameters:

- `asn` (string): Autonomous system, e.g. AS14061
- `country` (string): Two-letter country code, e.g. RU
- `limit` (number): Max rows (default 25, max 100)
- `min_threats` (number): Only indicators linked to at least this many of our threats
- `offset` (number): Row offset for paging
- `q` (string): Substring match on the indicator value
- `tag` (string): Community tag substring, case-insensitive and normalized (e.g. phishing, asyncrat, c2)
- `type` (string): Indicator type

Output parameters:

- `data` (array)
- `has_more` (boolean): True when another page may exist.
- `next_cursor` (string|null): Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
- `total` (integer): Total matching rows, when the handler reports one.

### `get_c2` (~151 tokens)

C2 Intelligence

Query the live C2 (command-and-control) intelligence center. Pick a view: 'beacons' (active C2 beacon snapshots — default), 'configs' (full extracted C2 configs), 'operators' (operator clusters), 'watermarks' (Cobalt Strike watermark index), 'correlations' (cross-C2 correlations), 'timeline' (activity over time), 'stats' (aggregate counts). Use generate_c2_blocklist when you want firewall-ready output rather than raw records.

Input parameters:

- `limit` (number): Max records for paginated views like beacons (default 50, max 100)
- `view` (string): Which C2 dataset to return (default 'beacons')

Output parameters:

- `aggregates` (object)
- `asns` (integer)
- `beacons` (integer)
- `clusters` (array)
- `configs` (array)
- `correlations` (array)
- `countries` (integer)
- `data` (object)
- `items` (array)
- `months` (array)
- `total` (integer)
- `versions` (array)
- `watermarks` (object)

### `generate_c2_blocklist` (~67 tokens)

Generate C2 Blocklist

Compile a firewall-ready C2 blocklist of active command-and-control IPs observed recently. Returns deduplicated network indicators ready to drop into a denylist. Use this for actionable blocking; use get_c2 with view="beacons" when you need the underlying beacon detail.

Output parameters:

- `cidrs` (array)
- `count` (integer)
- `detail` (array)
- `generated_at` (string)
- `since_days` (integer)

### `get_correlations` (~106 tokens)

Correlation Engine

Read precomputed cross-dataset correlations. Choose an engine: 'overview' (rollup of all engines — default), 'mitre-heatmap', 'adversary-infra', 'ioc-consensus', 'cve-velocity', 'attribution', 'detection-debt', or 'enrichment'. Use 'overview' first to see what's available, then drill into a specific engine.

Input parameters:

- `engine` (string): Which correlation engine to read (default 'overview')

Output parameters:

- `cves` (array)
- `engines` (object)
- `infrastructure` (array)
- `iocs` (array)
- `shared_entities` (array)
- `sources` (array)
- `summary` (object)
- `sync_log` (object)
- `techniques` (array)

### `predict_mitre_transitions` (~142 tokens)

Predict MITRE Transitions

Predict the MITRE ATT&CK techniques most likely to follow (or precede) a given technique, with observed probabilities and example threats. Use forward to anticipate the next step in a kill chain; reverse to infer what came before. Pair with get_mitre_technique for the technique definition.

Input parameters:

- `direction` (string): 'forward' = techniques that typically follow (default); 'reverse' = techniques that typically precede
- `technique_id` (string): Source technique ID (e.g. T1059 or T1059.001)
- `top_n` (number): Max transitions to return (default 5, max 20)

Output parameters:

- `data` (array)
- `direction` (string)
- `technique_id` (string)
- `total` (integer)
- `transitions` (array)

### `get_threat_simulations` (~74 tokens)

Threat Simulations

Get the adversary-emulation / simulation playbooks attached to a threat — step-by-step commands by platform for safely reproducing the behavior in a lab. Use to operationalize detection testing for a specific threat.

Input parameters:

- `threat_id` (string, required): Threat ID (e.g. TL-2026-0042)

Output parameters:

- `platforms` (object)
- `simulations` (array)
- `threat_id` (string)

### `list_debriefs` (~140 tokens)

List Debriefs

List recent daily intelligence debriefs (newest first) with their per-day rollups: new/updated threats, themes, MITRE techniques, IOC breakdown, actors, and severity counts. Use to scan recent days; use get_debrief for the full detail of one date. Pass limit (default 30, max 100); the result includes has_more (true when the page is full, so older debriefs may exist). NOTE: the debriefs endpoint does not yet honor offset — it serves the most recent window.

Input parameters:

- `limit` (number): Max debriefs to return (default 30, max 100)

Output parameters:

- `data` (array)
- `has_more` (boolean): True when another page may exist.
- `next_cursor` (string|null): Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
- `total` (integer): Total matching rows, when the handler reports one.

### `get_debrief` (~87 tokens)

Get Debrief

Get the full daily intelligence debrief for a specific calendar date (YYYY-MM-DD): posture summary, themes, threats grouped by severity, MITRE coverage, IOC distribution, actor attribution, and detection status. Find available dates first with list_debriefs.

Input parameters:

- `date` (string, required): Debrief date in YYYY-MM-DD format (e.g. 2026-05-30)

Output parameters:

- `date` (string)
- `highlights` (array)
- `new_detections` (integer)
- `new_threats` (integer)
- `stats` (object)
- `summary` (string)
- `themes` (array)
- `threats` (object)
- `title` (string)

### `export_stix` (~267 tokens)

Export STIX 2.1 Bundle

Export a threat, actor, or CVE as a STIX 2.1 bundle for ingestion into a TIP/SIEM. Provide at least one of threat_id, actor, or cve_id. Returns a {type:"bundle", objects:[...]} with indicator (per IOC), attack-pattern (per MITRE technique), intrusion-set (actor), vulnerability (CVE), malware/threat-actor, and relationship objects. Set include_osint=true to add `sighting` SROs for indicators the community independently reported (TL_OSINT_Scan / tweetfeed.live, CC0) — community-sourced and heavily concentrated, so they carry x_threadlinqs_trust="community-unverified". The bundle is capped (≤200 objects / ≤80KB); a note object is appended if truncated.

Input parameters:

- `actor` (string): Threat-actor name or alias to export (e.g. "APT29")
- `cve_id` (string): CVE identifier to export (e.g. CVE-2024-3400)
- `include_osint` (boolean): Add community `sighting` objects for corroborated indicators (default false)
- `threat_id` (string): Threat ID to export (e.g. TL-2026-0042)

Output parameters:

- `id` (string)
- `objects` (array)
- `type` (string): Always 'bundle'.

### `export_attack_navigator` (~125 tokens)

Export ATT&CK Navigator Layer

Export a MITRE ATT&CK Navigator layer (enterprise-attack) for visualization. Pass actor=<name> to score techniques attributed to one actor, or all=true for platform-wide coverage. Returns {name, versions, domain, techniques:[{techniqueID, score, color, comment}]}, capped at 600 techniques.

Input parameters:

- `actor` (string): Threat-actor name or alias whose techniques to score (e.g. "APT29")
- `all` (boolean): If true, build a platform-wide coverage layer from MITRE coverage instead of a single actor

Output parameters:

- `domain` (string)
- `gradient` (object)
- `name` (string)
- `techniques` (array)
- `versions` (object)

### `list_threat_categories` (~35 tokens)

List Threat Categories

List every threat category with its threat count across the whole corpus. Use to discover valid category filters for search_threats.

Output parameters:

- `data` (array)
- `total_categories` (integer)

### `search_detections` (~150 tokens)

Search Detections

Keyword search across detection logic (SPL/KQL/Sigma) by rule text, technique, or threat. Optionally filter by type (spl|kql|sigma) or severity. Paginated via limit (default 25, max 200) + offset.

Input parameters:

- `limit` (number): Max results (default 25, max 200)
- `offset` (number): Row offset for pagination (default 0)
- `query` (string, required): Search term (rule text, CVE, technique, etc.)
- `severity` (string): Filter by severity: critical, high, medium, low
- `type` (string): Detection type: spl, kql, or sigma

Output parameters:

- `data` (array)

### `get_detection_detail` (~53 tokens)

Get Detection Detail

Get the full detail for one detection rule by its ID, including the complete query text (SPL/KQL/Sigma), metadata, and the threat it maps to.

Input parameters:

- `detection_id` (string, required): Detection ID

Output parameters:

- `detection_type` (string)
- `false_positives` (array)
- `id` (string)
- `kql_query` (string|null)
- `mitre_mapping` (array)
- `name` (string)
- `query` (string|null)
- `severity` (string)
- `sigma_rule` (string|null)
- `threat_id` (string): Pass to get_threat.
- `threat_title` (string)

### `list_simulations` (~55 tokens)

List Simulations

List adversary-emulation simulation scenarios across the platform (atomic test commands grouped by threat). Pass limit (default 50, max 200).

Input parameters:

- `limit` (number): Max results (default 50, max 200)

Output parameters:

- `correlation` (object)
- `filter_meta` (object)
- `threats` (array)
- `total` (integer)
- `total_simulations` (integer)

### `get_threat_transcripts` (~55 tokens)

Get Threat Transcripts

Get the AI agent analysis transcripts for a threat — the step-by-step reasoning the research agents produced while profiling it.

Input parameters:

- `threat_id` (string, required): Threat ID (e.g. TL-2026-0042)

Output parameters:

- `count` (integer)
- `threat_id` (string)
- `transcripts` (array)

### `get_mitre_gap_analysis` (~85 tokens)

MITRE Gap Analysis

Prioritized list of MITRE ATT&CK techniques with the weakest detection coverage (detection debt), so you can target where to build detections next. Optionally filter by tactic.

Input parameters:

- `limit` (number): Max techniques (default 20, max 100)
- `tactic` (string): Filter to one ATT&CK tactic (e.g. "execution")

Output parameters:

- `summary` (object)
- `techniques` (array)

### `get_enrichment_overview` (~40 tokens)

Enrichment Overview

Health and coverage overview of the enrichment sources (CVE/EPSS/KEV, IOC reputation, DNS, etc.) feeding the platform.

Output parameters:

- `sources` (array)
- `summary` (object)

### `get_roadmap` (~28 tokens)

Get Roadmap

Get the Threadlinqs Intelligence platform roadmap — shipped, in-progress, and planned capabilities.

Output parameters:

- `completed` (array)
- `ideas` (array)

### `get_changelog` (~52 tokens)

Get Changelog

Get the recent platform changelog (new threats, detections, features). Pass limit (default 20, max 100).

Input parameters:

- `limit` (number): Max entries (default 20, max 100)

Output parameters:

- `result` (array)

### `export_detection` (~68 tokens)

Export Detection

Export one detection rule in a specific format. format=spl|kql|sigma returns the raw query text for that flavor; format=json returns the full detection object.

Input parameters:

- `detection_id` (string, required): Detection ID
- `format` (string, required): spl, kql, sigma, or json

Output parameters:

- `available` (boolean)
- `content` (string|null): Rule text for spl/kql/sigma. For format=json the detection object is returned directly instead.
- `detection_id` (string)
- `format` (string)

### `get_latest_debrief` (~30 tokens)

Get Latest Debrief

Get the most recent daily intelligence debrief in full detail (resolves the latest date for you).

Output parameters:

- `date` (string)
- `latest` (object|null)
- `summary` (string)
- `title` (string)

### `get_threat_bundle` (~107 tokens)

Get Threat Bundle

One-shot dossier for a threat: the full threat detail plus its simulations and analysis transcripts (include="summary" returns just the threat). Fewer round-trips than calling get_threat + get_threat_simulations + get_threat_transcripts separately.

Input parameters:

- `include` (string): "full" (default) bundles simulations + transcripts; "summary" returns just the threat
- `threat_id` (string, required): Threat ID (e.g. TL-2026-0042)

Output parameters:

- `simulations` (object|null)
- `threat` (object)
- `transcripts` (object|null): Omitted entirely when include='summary'.

### `get_threat_hunting_bundle` (~70 tokens)

Threat Hunting Bundle

Flagship one-call hunting dossier for a threat: full detail + similar threats + simulations + infrastructure pivots, composed server-side. Best single tool to scope a hunt around one threat.

Input parameters:

- `threat_id` (string, required): Threat ID (e.g. TL-2026-0042)

Output parameters:

- `infrastructure_pivots` (object|null)
- `similar_threats` (object|null)
- `simulations` (object|null)
- `threat` (object)

### `get_daily_intel_bundle` (~86 tokens)

Daily Intel Bundle

One-shot "what happened" bundle: the day's debrief (latest by default, or pass date) plus platform stats, the top recent threats, and the correlations overview.

Input parameters:

- `date` (string): Debrief date YYYY-MM-DD (default: latest)
- `top_n` (number): How many top threats to include (default 5, max 10)

Output parameters:

- `correlations_overview` (object|null)
- `debrief` (object|null)
- `platform_stats` (object|null)
- `top_threats` (object|null)

### `bulk_get_threats` (~58 tokens)

Bulk Get Threats

Fetch up to 20 threats by ID in one call. Returns {threats, missing, count}. Use when you already have a list of threat IDs.

Input parameters:

- `threat_ids` (array, required): Threat IDs (max 20)

Output parameters:

- `count` (integer)
- `missing` (array)
- `threats` (array)

### `bulk_get_cves` (~49 tokens)

Bulk Get CVEs

Fetch up to 20 enriched CVEs by ID in one call. Returns {cves, missing, count}.

Input parameters:

- `cve_ids` (array, required): CVE IDs (max 20)

Output parameters:

- `count` (integer)
- `cves` (array)
- `missing` (array)

### `get_actor_intelligence` (~52 tokens)

Actor Intelligence

Composite intelligence picture for a threat actor: the full actor profile plus cross-actor attribution correlations in one call.

Input parameters:

- `name` (string, required): Threat-actor name or alias (e.g. "APT29")

Output parameters:

- `actor` (object)
- `cross_actor_attribution` (object|null): Shared entities across actors, or null when the attribution engine has nothing.
- `cves` (array)
- `mitre` (object)
- `threats` (array)
- `tools` (array)

### `get_cve_intelligence` (~62 tokens)

CVE Intelligence

Composite CVE dossier: the enriched CVE detail plus exploitation-velocity context and any detections that reference it, in one call.

Input parameters:

- `cve_id` (string, required): CVE identifier (e.g. CVE-2024-3400)

Output parameters:

- `cve` (object)
- `related_detections` (object|null)
- `velocity_data` (object|null)

### `health` (~34 tokens)

Health Check

Lightweight liveness probe: confirms the API is reachable and your key is valid, and returns platform counts + the latest debrief date.

Output parameters:

- `api_reachable` (boolean)
- `latest_debrief_date` (string|null)
- `platform_stats` (object|null)
- `server_version` (string)
- `status` (string): 'ok' | 'degraded'

### `hunt` (~183 tokens)

Hunt (TLQL)

Run a deterministic SIEM-style query over the pre-joined observation index (~106k rows across tool, malware, ioc, mitre, cve, attribution, dns and infra observations). Use this INSTEAD of chaining many search_threats calls when the question is an aggregate ("how many X grouped by Y") or crosses observation types ("threats using tool A that also have IOC type B"). Append "| stats count by <field>" to aggregate; without it you get matching rows. Call hunt_schema first if you do not know the field names.

Input parameters:

- `limit` (integer): Row cap for non-stats queries (default 50, max 150). Ignored in stats mode.
- `query` (string, required): TLQL, e.g. `tool = "cobalt strike" AND sector = "healthcare" | stats count by nation`

Output parameters:

- `by` (array)
- `columns` (array)
- `count` (integer)
- `func` (string)
- `groups` (array)
- `mode` (string): 'stats' when the query has a | stats pipe, otherwise rows.
- `query` (string)
- `rows` (array)
- `tier_gated_included` (boolean): True when the caller's tier allows the c2_beacon/dns/infra observation types.

### `hunt_schema` (~58 tokens)

Hunt Schema

The hunt query grammar: every filterable field and alias, which fields are scoped observables vs denormalized, the operators, the stats-pipe form, worked examples, and how fresh the index is. Call once before writing a hunt query.

Output parameters:

- `by_type_json` (string): JSON string of per-observation-type row counts.
- `duration_ms` (integer)
- `grammar` (object)
- `rebuilt_at` (string|null)
- `row_count` (integer)

### `get_attribution_evidence` (~100 tokens)

Attribution Evidence

Why a threat is attributed to an actor: the verdict, canonical actor, confidence, scope, the cited evidence chain, which signals fired, suspected alternatives and the analyst reasoning. Crucially it also reports `state` — whether this is a researched assessment or an unresearched intake stub — which threats.threat_actor alone cannot tell you.

Input parameters:

- `threat_id` (string, required): Threat ID (e.g. TL-2026-0989).

Output parameters:

- `actor` (string)
- `actor_canonical` (string)
- `actor_uuid` (string)
- `attributed_at` (string)
- `confidence` (string)
- `current_actor` (string)
- `evidence` (array)
- `method` (string)
- `queued_at` (string)
- `reason_code` (string|null)
- `reasoning` (string)
- `scope` (string)
- `signals` (array)
- `state` (string): 'assessed' vs 'pending_research' — whether this is a real assessment or an unresearched intake stub. Do not present a stub as an assessment.
- `suspected` (array)
- `threat_id` (string)
- `title` (string)
- `verdict` (string)

### `get_attribution_coverage` (~82 tokens)

Attribution Coverage

Corpus-level attribution honesty: how many threats are genuinely assessed vs merely actor-labelled at ingest vs uncovered, broken down by confidence, scope and reason code, plus the research backlog, contradictions, top actors and the research clock (last real assessment, not last nightly intake).

Input parameters:

- `actor` (string): Optional — scope the `recent` list to one actor.

Output parameters:

- `by_confidence` (object)
- `by_reason` (object)
- `by_scope` (object)
- `corpus` (object)
- `engine` (object)
- `recent` (array)
- `top_actors` (array)

### `explain_correlation` (~128 tokens)

Explain Correlation

Why two threats are linked: the per-channel similarity decomposition (techniques, IOCs, CVEs, products, CWEs, context), which channel dominates and by how much, the concrete shared artifacts, the signal count, and quality flags for high-confidence/low-evidence and stale links. Use when get_similar_threats gives a score and you need the evidence behind it. Pass the pair in either order. Returns 404 when the engine has no edge between them.

Input parameters:

- `threat_a` (string, required): First threat ID.
- `threat_b` (string, required): Second threat ID.

Output parameters:

- `dominance`
- `error` (string): Present with HTTP 404 when the engine has no edge between the pair.
- `is_high_conf_low_signal` (boolean)
- `is_stale` (boolean)
- `score_breakdown` (object)
- `shared_cves` (array)
- `shared_iocs` (array)
- `shared_techniques` (array)
- `signal_count` (integer)

### `get_correlation_path` (~119 tokens)

Correlation Path

Shortest evidence path between two threats across the similarity graph: the intermediate threats, each hop's dominant linking signal and shared artifacts, and the weakest-link strength of the whole path. Answers "is this incident connected to that campaign, and through what". Returns found:false with a reason (no edges vs different components) rather than an empty array.

Input parameters:

- `from` (string, required): Starting threat ID.
- `max_hops` (integer): Search depth, 1-8 (default 6).
- `to` (string, required): Target threat ID.

Output parameters:

- `found` (boolean)
- `from` (string)
- `hops` (array)
- `path_strength` (number)
- `reason` (string): Why no path exists (no similarity edges vs different components) when found is false.
- `to` (string)

### `get_entity_profile` (~129 tokens)

Entity Profile

One-call dossier for any node in the intelligence graph — threat, technique, actor, IOC or CVE. Returns its centrality/pivot rank, top graph neighbours with edge fidelity, and type-specific rollups (linked threats, techniques with risk scores, IOCs with consensus and rarity, campaigns, related CVEs). Best token-per-call ratio in the graph family: replaces five or six separate lookups.

Input parameters:

- `node_id` (string, required): The entity id/value (TL- id, T-number, actor name, IOC value, or CVE id).
- `node_type` (string, required)

Output parameters:

- `campaigns` (array)
- `cves` (array)
- `iocs` (array)
- `node` (object)
- `techniques` (array)
- `threats` (array)
- `top_neighbors` (array)

### `get_pivotal_entities` (~95 tokens)

Pivotal Entities

The hubs and bridges of the intelligence graph ranked by weighted degree and approximate betweenness — where a single detection buys the most coverage. NOTE: betweenness is an ego-bridge heuristic, not exact Brandes; the response says so in `note`. Do not present it as exact betweenness.

Input parameters:

- `limit` (integer): Default 25, max 100.
- `node_type` (string)

Output parameters:

- `data` (array)
- `note` (string): States that betweenness is an ego-bridge approximation, not exact Brandes.

### `get_graph_campaigns` (~94 tokens)

Graph Campaigns

Campaign clusters the engine assembled from the similarity graph (connected components + label propagation): label, member count, cohesion, member threat IDs, top actors, top techniques, shared IOCs and nation-states. Distinct from get_campaign_intelligence, which looks up a NAMED campaign mentioned in threat text — this one reports clusters the engine derived itself.

Input parameters:

- `limit` (integer): Default 15, max 50.

Output parameters:

- `data` (array)
- `summary` (object)

### `get_technique_rules` (~80 tokens)

Technique Co-occurrence Rules

MITRE ATT&CK technique PAIRS mined from the corpus with support, confidence and lift — which techniques travel together far above chance. Complements predict_mitre_transitions exactly: that answers sequence (what follows what), this answers co-occurrence (what appears alongside what).

Input parameters:

- `limit` (integer): Default 50, max 200.

Output parameters:

- `rules` (array)
- `summary` (object)

### `get_engine_status` (~72 tokens)

Intelligence Engine Status

Is the intelligence pipeline healthy? Per-engine row counts, last-compute times and derived ok/stale/empty status; the nightly graph pipeline's staged progress, current stage and degraded flag; recent failures; and the latest held-out accuracy eval (AUC). Check this before reasoning over correlation output if freshness matters.

Output parameters:

- `engines` (array)
- `eval` (object)
- `failures` (array)
- `generated_at` (string)
- `graph_pipeline` (object)

### `get_osint_trends` (~116 tokens)

Community OSINT Trends

What the security community is surging on right now (tweetfeed.live, CC0), joined against our own corpus coverage: trending tags with movement, TLD distribution, novelty, top producers, daily volume — plus `corpus` (how much of our corpus the community corroborates) and `early_warning` (the lead-time distribution). The coverage-gap and lead-time read; the corpus join exists nowhere else. Keyed on community TAGS, not malware family (populated on <1% of upstream rows).

Output parameters:

- `caveat` (object)
- `corpus` (object)
- `daily` (object)
- `early_warning` (object)
- `generated_at` (string)
- `movers` (object)
- `novelty` (object)
- `producers` (object)
- `tlds` (object)
- `totals` (object)

### `get_community_campaigns` (~111 tokens)

Community Campaigns

Campaign clusters from the community OSINT layer (tweetfeed.live, CC0): cluster name, confidence, targeted brand, first/last seen, indicator count and types, tags and reporters. Cluster labels are UPSTREAM AI output, not Threadlinqs attribution — do not present them as our assessment. On an upstream proxy failure the response carries community_error rather than erroring; report "community feed unavailable", not "no campaigns".

Input parameters:

- `limit` (integer): Default 15, max 50.

Output parameters:

- `campaigns` (array)
- `community_error` (string|null): Set to 'upstream_unavailable' on a proxy failure — report the feed as unavailable, NOT as zero campaigns.
- `generated_at` (string)
- `window` (string)

### `get_c2_dns_intel` (~111 tokens)

C2 DNS Unmasking

Reverse-DNS unmasking of C2 beacon infrastructure: which domains ride on each beacon IP, infrastructure fidelity (dedicated / mixed / shared), compromised-host flags and sample domains. Answers "what else lives on this C2 infrastructure". Filter by fidelity to separate adversary-owned infrastructure from shared hosting.

Input parameters:

- `compromised` (boolean): Only hosts flagged as compromised rather than adversary-owned.
- `fidelity` (string)
- `limit` (integer): Default 40, max 100.

Output parameters:

- `offset` (integer)
- `rows` (array)
- `stats` (object)
- `total` (integer)

### `get_correlation_subgraph` (~191 tokens)

Correlation Subgraph

The N-hop neighbourhood around any graph node — nodes, edges, and each edge's fidelity — for incremental exploration of the correlation graph. Start at depth 1 and expand: a whole-corpus graph exceeds every response budget. For a pre-aggregated single-entity view prefer get_entity_profile, which is cheaper and usually what you want; use this when you need the actual edge topology.

Input parameters:

- `depth` (integer): Hops, 1-3 (default 1). Each hop multiplies the node count.
- `limit_edges` (integer): Default 80, max 120 over MCP.
- `limit_nodes` (integer): Default 40, max 60 over MCP.
- `min_fidelity` (number): Drop edges below this fidelity (0-1).
- `seed_id` (string, required): The entity id/value to expand from.
- `seed_type` (string, required)

Output parameters:

- `edges` (array)
- `nodes` (array)
- `params` (object)
- `seed` (object)

### `search_corpus_semantic` (~104 tokens)

Semantic Corpus Search

Vector + rerank retrieval over the whole corpus, returning ranked source cards. Use when keyword search fails — conceptual or paraphrased questions where the exact terms do not appear in the text. Complements search_threats, which is boolean/exact over structured filters. Depends on the AI Search binding and is rate-limited; a 503 means the index is unavailable, not that nothing matched.

Input parameters:

- `query` (string, required): A natural-language question or concept.

Output parameters:

- `chunks` (array)
- `query` (string)
- `results` (array)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/com-threadlinqs-intelthreadlinqs-mcp/intelthreadlinqs-mcp#diagnostics

## Score history

- 2026-08-03: 20
- 2026-08-02: 35
- 2026-08-01: 20
- 2026-07-31: 6
- 2026-07-30: 24
- 2026-07-28: 24
- 2026-07-27: 24

## Links

- npm package: https://www.npmjs.com/package/intelthreadlinqs-mcp
- Socket report: https://socket.dev/npm/package/intelthreadlinqs-mcp
- Repository: https://github.com/threadlinqs-cmd/intelthreadlinqs-mcp
- Changelog RSS feed: https://verifymcp.io/servers/com-threadlinqs-intelthreadlinqs-mcp/intelthreadlinqs-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-threadlinqs-intelthreadlinqs-mcp/intelthreadlinqs-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/com-threadlinqs-intelthreadlinqs-mcp/intelthreadlinqs-mcp
