{"slug":"api-agentstools-dev-threat-ioc-efd81f","title":"Type-agnostic threat-intelligence enrichment for a SOC or DFIR agent","host":"api.agentstools.dev","method":"GET","resource":"https://api.agentstools.dev/threat/ioc","category":"other","description":"Type-agnostic threat-intelligence enrichment for a SOC or DFIR agent. Give one indicator of compromise of any kind — a file hash, IP, domain, URL or CVE id — and get one normalized, cited verdict. Auto-detects the type, dispatches to the right grain, fuses the sources and returns a verdict, an is_ma","price_listed":0.01,"price_asked":0.01,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":989,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"indicator":"8.8.8.8"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"indicator":{"description":"The indicator of compromise: a file hash (md5/sha1/sha256), IP, domain, URL or CVE id","type":"string"},"type":{"description":"Optional type override; auto-detected if omitted","enum":["md5","sha1","sha256","hash","ip","ipv4","ipv6","domain","url","cve"],"type":"string"}},"required":["indicator"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.01,"price_match":true,"latency_ms":989,"error":null}],"description_full":"Type-agnostic threat-intelligence enrichment for a SOC or DFIR agent. Give one indicator of compromise of any kind — a file hash, IP, domain, URL or CVE id — and get one normalized, cited verdict. Auto-detects the type, dispatches to the right grain, fuses the sources and returns a verdict, an is_malicious flag, a confidence, malware family when known, per-source citations and reasons. Not a guarantee.","last_updated":"2026-09-19T15:57:42.334Z","schemes":["exact"]}