com.threadlinqs/intelthreadlinqs-mcp
NPM · INTELTHREADLINQS-MCP · SCANNED AUG 3
Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security37
- Malware scan not yet available for this package.Unverified
- Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.Partial
- No install/post-install scripts declared.Pass
- Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 0 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability0
- Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Stability & Change Management0
- Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Tool Coverage0
- Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.Unverified
Capabilities0
- Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.Unverified
Unverified: 4 categories
Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · intelthreadlinqs-mcp
claude mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
codex mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-threadlinqs-intelthreadlinqs-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"intelthreadlinqs-mcp"
],
"enabled": true
}
}
} openclaw mcp add com-threadlinqs-intelthreadlinqs-mcp --command npx --arg -y --arg intelthreadlinqs-mcp
mcp_servers:
com-threadlinqs-intelthreadlinqs-mcp:
command: "npx"
args: ["-y", "intelthreadlinqs-mcp"] {
"mcpServers": {
"com-threadlinqs-intelthreadlinqs-mcp": {
"command": "npx",
"args": [
"-y",
"intelthreadlinqs-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 −15
- Malware scan: pass → unverified ▼ security
- Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
- Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
- Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
- Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
- Package version: 7.1.4 → 8.1.1 functional
- 2 Aug 26 +15
- Provenance: unverified → fail ▼ security
- Malware scan: pass → unverified ▼ security
- Install scripts: unverified → pass ▲ security
- Known CVEs: unverified → partial ▲ security
- Stability: Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare. security
- Maintenance: unverified → pass ▲ functional
- License: unverified → pass ▲ functional
- Dependency health: unverified → partial ▲ functional
- Capabilities: Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake. functional
- Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess. functional
- Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess. functional
- Licence: MIT functional
- 1 Aug 26 +14
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 −18
- Malware scan: pass → unverified ▼ security
- 27 Jul 26 24
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Analysed npm/[email protected]
Provenance none
Ecosystem: npm · Outcome: none
Dependencies 95 packages
95 packages in the resolved dependency tree · 95 deprecated · 29 stale.
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
get_technique_rules Technique Co-occurrence Rules ~80
MITRE ATT&CK technique PAIRS mined from the corpus with support, confidence and lift — which techniques travel together far above chance. Complements predict_mitre_transitions exactly: that answers sequence (what follows what), this answers co-occurrence (what appears alongside what).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Default 50, max 200. |
| Name | Type | Req | Description |
|---|---|---|---|
| rules | array | yes | — |
| summary | object | — | — |
No examples provided.
get_threat Get Threat ~95
Get the full detail for a single threat by its ID (e.g. TL-2026-0042): overview, MITRE techniques, IOCs, detections, timeline, and tags. For that threat's malware families, tools, targeted sectors/regions, affected OS and campaigns, call get_threat_enrichment.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| attribution | object | — | — |
| category | string | — | — |
| created_at | string | — | — |
| description | string | — | — |
| detections | array | — | — |
| id | string | yes | Threat ID (TL-YYYY-NNNN). |
| identifiers | object | — | — |
| iocs | object | — | — |
| mitre_attack | array | — | — |
| osint | object|null | — | Community-OSINT summary; null below Red tier or when unscanned. |
| references | array | — | — |
| severity | object | — | — |
| status | string | — | — |
| summary | string | — | — |
| tags | array | — | — |
| title | string | — | — |
| updated_at | string | — | — |
No examples provided.
get_threat_bundle Get Threat Bundle ~107
One-shot dossier for a threat: the full threat detail plus its simulations and analysis transcripts (include="summary" returns just the threat). Fewer round-trips than calling get_threat + get_threat_simulations + get_threat_transcripts separately.
| Name | Type | Req | Description |
|---|---|---|---|
| include | string | — | "full" (default) bundles simulations + transcripts; "summary" returns just the threat |
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| simulations | object|null | — | — |
| threat | object | yes | — |
| transcripts | object|null | — | Omitted entirely when include='summary'. |
No examples provided.
get_threat_enrichment Threat Enrichment ~115
Reference-grounded enrichment for one threat by ID: the malware families and tools used, targeted sectors/regions, affected operating systems, named campaigns, AI/ML (ATLAS) techniques, and per-technique mitigations + detection data sources. Complements get_threat (overview/MITRE/IOCs/detections) — call this for the "what malware/tools were used and who was targeted" view.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| atlas | array | — | — |
| campaigns | array | — | — |
| id | string | yes | — |
| malware | array | — | — |
| operating_systems | array | — | — |
| regions | array | — | — |
| sectors | array | — | — |
| tools | array | — | — |
No examples provided.
get_threat_hunting_bundle Threat Hunting Bundle ~70
Flagship one-call hunting dossier for a threat: full detail + similar threats + simulations + infrastructure pivots, composed server-side. Best single tool to scope a hunt around one threat.
| Name | Type | Req | Description |
|---|---|---|---|
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| infrastructure_pivots | object|null | — | — |
| similar_threats | object|null | — | — |
| simulations | object|null | — | — |
| threat | object | yes | — |
No examples provided.
get_threat_level Threat Level ~29
Get the computed current threat-landscape level (a 0–25 rating of overall posture).
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| criteria | array | — | — |
| level | string | yes | — |
| max | number | — | — |
| score | number | yes | — |
| threats_observed | integer | — | — |
No examples provided.
get_threat_simulations Threat Simulations ~74
Get the adversary-emulation / simulation playbooks attached to a threat — step-by-step commands by platform for safely reproducing the behavior in a lab. Use to operationalize detection testing for a specific threat.
| Name | Type | Req | Description |
|---|---|---|---|
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| platforms | object | — | — |
| simulations | array | — | — |
| threat_id | string | yes | — |
No examples provided.
get_threat_transcripts Get Threat Transcripts ~55
Get the AI agent analysis transcripts for a threat — the step-by-step reasoning the research agents produced while profiling it.
| Name | Type | Req | Description |
|---|---|---|---|
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | — | — |
| threat_id | string | yes | — |
| transcripts | array | — | — |
No examples provided.
get_tool_intelligence Tool Intelligence ~94
Pivot on an offensive tool / utility / RMM / LOLBin by name (e.g. "Cobalt Strike", "Mimikatz", "AnyDesk", "PsExec"). Returns the canonical tool + class, prevalence, the threats and actors using it, and its most-common ATT&CK techniques.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Tool name (e.g. "Cobalt Strike", "Mimikatz") |
| Name | Type | Req | Description |
|---|---|---|---|
| actors | array | — | — |
| canonical | string | — | — |
| entity_type | string | — | — |
| matched | boolean | yes | — |
| prevalence | object | — | — |
| query | string | — | — |
| threats | array | — | — |
| top_techniques | array | — | — |
No examples provided.
health Health Check ~34
Lightweight liveness probe: confirms the API is reachable and your key is valid, and returns platform counts + the latest debrief date.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| api_reachable | boolean | — | — |
| latest_debrief_date | string|null | — | — |
| platform_stats | object|null | — | — |
| server_version | string | — | — |
| status | string | yes | 'ok' | 'degraded' |
No examples provided.
hunt Hunt (TLQL) ~183
Run a deterministic SIEM-style query over the pre-joined observation index (~106k rows across tool, malware, ioc, mitre, cve, attribution, dns and infra observations). Use this INSTEAD of chaining many search_threats calls when the question is an aggregate ("how many X grouped by Y") or crosses observation types ("threats using tool A that also have IOC type B"). Append "| stats count by <field>" to aggregate; without it you get matching rows. Call hunt_schema first if you do not know the field names.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Row cap for non-stats queries (default 50, max 150). Ignored in stats mode. |
| query | string | yes | TLQL, e.g. `tool = "cobalt strike" AND sector = "healthcare" | stats count by nation` |
| Name | Type | Req | Description |
|---|---|---|---|
| by | array | — | — |
| columns | array | — | — |
| count | integer | — | — |
| func | string | — | — |
| groups | array | — | — |
| mode | string | yes | 'stats' when the query has a | stats pipe, otherwise rows. |
| query | string | yes | — |
| rows | array | — | — |
| tier_gated_included | boolean | — | True when the caller's tier allows the c2_beacon/dns/infra observation types. |
No examples provided.
hunt_schema Hunt Schema ~58
The hunt query grammar: every filterable field and alias, which fields are scoped observables vs denormalized, the operators, the stats-pipe form, worked examples, and how fresh the index is. Call once before writing a hunt query.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| by_type_json | string | — | JSON string of per-observation-type row counts. |
| duration_ms | integer | — | — |
| grammar | object | yes | — |
| rebuilt_at | string|null | — | — |
| row_count | integer | — | — |
No examples provided.
list_debriefs List Debriefs ~140
List recent daily intelligence debriefs (newest first) with their per-day rollups: new/updated threats, themes, MITRE techniques, IOC breakdown, actors, and severity counts. Use to scan recent days; use get_debrief for the full detail of one date. Pass limit (default 30, max 100); the result includes has_more (true when the page is full, so older debriefs may exist). NOTE: the debriefs endpoint does not yet honor offset — it serves the most recent window.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Max debriefs to return (default 30, max 100) |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | — |
| has_more | boolean | — | True when another page may exist. |
| next_cursor | string|null | — | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | — | Total matching rows, when the handler reports one. |
No examples provided.
list_simulations List Simulations ~55
List adversary-emulation simulation scenarios across the platform (atomic test commands grouped by threat). Pass limit (default 50, max 200).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Max results (default 50, max 200) |
| Name | Type | Req | Description |
|---|---|---|---|
| correlation | object | — | — |
| filter_meta | object | — | — |
| threats | array | — | — |
| total | integer | — | — |
| total_simulations | integer | — | — |
No examples provided.
list_threat_categories List Threat Categories ~35
List every threat category with its threat count across the whole corpus. Use to discover valid category filters for search_threats.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | — |
| total_categories | integer | — | — |
No examples provided.
predict_mitre_transitions Predict MITRE Transitions ~142
Predict the MITRE ATT&CK techniques most likely to follow (or precede) a given technique, with observed probabilities and example threats. Use forward to anticipate the next step in a kill chain; reverse to infer what came before. Pair with get_mitre_technique for the technique definition.
| Name | Type | Req | Description |
|---|---|---|---|
| direction | string | — | 'forward' = techniques that typically follow (default); 'reverse' = techniques that typically precede |
| technique_id | string | — | Source technique ID (e.g. T1059 or T1059.001) |
| top_n | number | — | Max transitions to return (default 5, max 20) |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | — | — |
| direction | string | — | — |
| technique_id | string | yes | — |
| total | integer | — | — |
| transitions | array | — | — |
No examples provided.
resolve_entity Resolve Canonical Name ~122
Normalize an actor / malware / tool / sector / region / technique name or alias to its canonical reference form + stable UUID (e.g. "fancy bear" → "APT28"). Call this BEFORE pivoting (get_actor / get_malware_intelligence / get_tool_intelligence / search_threats) when unsure of the canonical name. Optional type narrows the lookup.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Name or alias to resolve |
| type | string | — | Optional: actor|malware|tool|sector|region|technique|campaign |
| Name | Type | Req | Description |
|---|---|---|---|
| canonical | string | — | Canonical name — feed to get_actor / get_malware_intelligence / get_tool_intelligence. |
| entity_type | string | — | — |
| matched | boolean | yes | — |
| matched_via | string | — | — |
| query | string | yes | — |
| uuid | string | — | — |
No examples provided.
search_actors List Actors ~155
List attributed threat actors with aggregate stats (threat_count, severity levels, categories, nation_state). Returns the full roster in one call, or narrow it with the optional tool / malware / sector filters (e.g. tool="Cobalt Strike" → only actors that used it). Use get_actor for a single actor's full profile. Not paginated; the response carries a total count.
| Name | Type | Req | Description |
|---|---|---|---|
| malware | string | — | Only actors with a threat deploying this malware family (e.g. "LockBit") |
| sector | string | — | Only actors with a threat targeting this sector (e.g. "Healthcare") |
| tool | string | — | Only actors with a threat using this tool (e.g. "Cobalt Strike") |
| Name | Type | Req | Description |
|---|---|---|---|
| actors | array | — | — |
| has_more | boolean | — | True when another page may exist. |
| next_cursor | string|null | — | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | — | Total matching rows, when the handler reports one. |
No examples provided.
search_corpus_semantic Semantic Corpus Search ~104
Vector + rerank retrieval over the whole corpus, returning ranked source cards. Use when keyword search fails — conceptual or paraphrased questions where the exact terms do not appear in the text. Complements search_threats, which is boolean/exact over structured filters. Depends on the AI Search binding and is rate-limited; a 503 means the index is unavailable, not that nothing matched.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | A natural-language question or concept. |
| Name | Type | Req | Description |
|---|---|---|---|
| chunks | array | — | — |
| query | string | — | — |
| results | array | — | — |
No examples provided.
search_detections Search Detections ~150
Keyword search across detection logic (SPL/KQL/Sigma) by rule text, technique, or threat. Optionally filter by type (spl|kql|sigma) or severity. Paginated via limit (default 25, max 200) + offset.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Max results (default 25, max 200) |
| offset | number | — | Row offset for pagination (default 0) |
| query | string | yes | Search term (rule text, CVE, technique, etc.) |
| severity | string | — | Filter by severity: critical, high, medium, low |
| type | string | — | Detection type: spl, kql, or sigma |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | — |
No examples provided.
search_iocs Search IOCs ~131
Search indicators of compromise (IPs, domains, hashes, URLs). Filter by value substring and/or category. Pass limit (default 25, max 100); the result includes has_more (true when the page is full, so more may exist). NOTE: the indicator endpoint does not yet honor offset — narrow with a more specific value/type substring rather than paging.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Max results (default 25, max 100) |
| type | string | — | IOC category (e.g. network, file, behavioral) |
| value | string | — | Substring to match against IOC values |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | — |
| has_more | boolean | — | True when another page may exist. |
| next_cursor | string|null | — | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | — | Total matching rows, when the handler reports one. |
No examples provided.
search_threats Search Threats ~681
The deterministic threat-catalog query tool. Returns LEAN summary rows {id, title, severity, category, status, threat_actor, nation_state, affected_products, cves, cvss_score, summary, created} — call get_threat for full detail on a specific id. Combine a free-text `query` with any structured filters; ALL filters AND-combine and apply together (e.g. query="supply chain" + threat_actor="TeamPCP" + category="SUPPLY_CHAIN" returns only matching rows, with affected_products inline). Paginated: limit (default 20, max 100) + offset/cursor; result carries total, has_more, and next_cursor.
| Name | Type | Req | Description |
|---|---|---|---|
| affected_product | string | — | Filter by affected product/vendor (e.g. "npm", "Microsoft", "VS Code") |
| campaign | string | — | Filter to threats in a named campaign/operation (e.g. "Snowflake campaign") |
| category | string | — | e.g. SUPPLY_CHAIN, MALWARE, RANSOMWARE, VULNERABILITY, APT, PHISHING, ZERO_DAY (call list_threat_categories for the full vocabulary) |
| created_after | string | — | ISO date — only threats created on/after (e.g. 2026-05-01) |
| created_before | string | — | ISO date — only threats created on/before |
| cursor | string | — | Opaque pagination cursor (next_cursor from a prior result); ignored when offset is given. |
| cve | string | — | Filter by CVE id (e.g. CVE-2026-45321) |
| limit | number | — | Max results (default 20, max 100) |
| malware | string | — | Filter to threats deploying a malware family (e.g. "LockBit", "Vidar") |
| mitre_technique | string | — | Filter by MITRE technique id (e.g. T1059) |
| motivation | string | — | Filter by motivation (e.g. financial, espionage) |
| nation_state | string | — | Filter by nation-state (e.g. Russia, China, Iran) |
| offset | number | — | Row offset for pagination (default 0). |
| os | string | — | Filter to threats affecting an operating system (e.g. "Windows", "Linux", "VMware ESXi") |
| query | string | — | Free-text term across title/summary/description/CVE/actor (optional; AND-combined with filters) |
| sector | string | — | Filter by grounded industry sector (e.g. "Healthcare", "Government") |
| severity | string | — | critical | high | medium | low |
| status | string | — | Threat status filter (e.g. active) |
| tag | string | — | Filter by exact tag (e.g. "supply-chain-compromise") |
| target_region | string | — | Filter by targeted region (e.g. APAC, Europe) |
| target_sector | string | — | Filter by targeted sector (e.g. Healthcare, Finance) |
| threat_actor | string | — | Filter by attributed actor name/alias (e.g. "TeamPCP", "APT29") |
| tool | string | — | Filter to threats using a tool (e.g. "Cobalt Strike", "Mimikatz") |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | — |
| has_more | boolean | — | True when another page may exist. |
| next_cursor | string|null | — | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | — | Total matching rows, when the handler reports one. |
No examples provided.
search_vulnerabilities Search Vulnerabilities ~354
Query the real-time CVE feed — validated against CVE.org and enriched from open sources (CVSS, EPSS exploitation probability, CISA KEV, public PoCs/exploits, nuclei detection templates, affected products/packages, plus platform-native trending/priority). Sort by trending|latest|priority|cvss|epss; filter by severity, kev (KEV-only), has_poc, nuclei, epss_min, window (days), vendor, cwe, or free-text query. Returns COMPACT cards {cve_id, severity, cvss, epss_percentile, is_kev, has_poc/exploit/nuclei, priority, trending, vendors, age} — call get_cve(id) for full detail.
| Name | Type | Req | Description |
|---|---|---|---|
| cwe | string | — | Weakness id, e.g. CWE-79 |
| epss_min | number | — | Minimum EPSS exploitation probability, 0-1 |
| has_poc | boolean | — | Only CVEs with a public proof-of-concept |
| kev | boolean | — | Only CISA KEV (known-exploited) CVEs |
| limit | number | — | default 30, max 100 |
| nuclei | boolean | — | Only CVEs with a nuclei detection template |
| query | string | — | Free-text: a CVE id or keyword (matches id + description) |
| severity | string | — | CRITICAL | HIGH | MEDIUM | LOW |
| sort | string | — | trending (default) | latest | priority | cvss | epss |
| vendor | string | — | Affected vendor/product substring |
| window | number | — | Only CVEs published within the last N days |
| Name | Type | Req | Description |
|---|---|---|---|
| facets | object | — | — |
| pagination | object | — | — |
| sort | string | — | — |
| total | integer | — | — |
| vulnerabilities | array | yes | — |
No examples provided.
search_xscan_indicators Search Community Indicators ~265
Search the canonical community-indicator set (TL_OSINT_Scan / tweetfeed.live, CC0) — indicators the community reported that were also matched against our corpus. Filter by tag, type, ASN, country, minimum linked-threat count, or a value substring. There is deliberately NO family filter: the upstream AI family field is populated on under 1% of rows, so a family argument would return nothing. Use tag instead (community tags carry the family signal). Community-sourced and heavily concentrated (~73% of recent submissions come from a single reporter) — corroborating, not authoritative.
| Name | Type | Req | Description |
|---|---|---|---|
| asn | string | — | Autonomous system, e.g. AS14061 |
| country | string | — | Two-letter country code, e.g. RU |
| limit | number | — | Max rows (default 25, max 100) |
| min_threats | number | — | Only indicators linked to at least this many of our threats |
| offset | number | — | Row offset for paging |
| q | string | — | Substring match on the indicator value |
| tag | string | — | Community tag substring, case-insensitive and normalized (e.g. phishing, asyncrat, c2) |
| type | string | — | Indicator type |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | — | — |
| has_more | boolean | — | True when another page may exist. |
| next_cursor | string|null | — | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | — | Total matching rows, when the handler reports one. |
No examples provided.