search_hash
Pack: threatfox · Connect: https://pipeworx.io/mcp (see Connect below for a single-pack URL)
No MCP client? Call it directly: GET https://gateway.pipeworx.io/v1/tools/search_hash for the schema, then POST the same URL with its arguments for the data.
Everything ThreatFox knows about one file hash (md5 / sha1 / sha256), across BOTH relations it stores hashes in —
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
hash | string | yes | md5 (32 hex), sha1 (40 hex) or sha256 (64 hex). Anything else is rejected upstream as illegl_hash [sic] rather than answered empty. |
Example call
Arguments
{
"hash": "2a85f2e5876b278a7af9393483de455b"
}
curl
curl -X POST https://gateway.pipeworx.io/threatfox/mcp \
-H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_hash","arguments":{"hash":"2a85f2e5876b278a7af9393483de455b"}}}'
TypeScript (@pipeworx/sdk)
import { Pipeworx } from '@pipeworx/sdk';
const pipeworx = new Pipeworx();
const result = await pipeworx.call('search_hash', {
"hash": "2a85f2e5876b278a7af9393483de455b"
});
More examples
{
"hash": "da168c3ff95c749beec0a2f29a1e6b82"
}
Response shape
Always returns: query, status, count, results
| Field | Type | Description |
|---|---|---|
query | string | The query type sent (search_hash) |
status | string | null | Query status (ok, no_result, or null) |
count | integer | Number of results returned |
results | array | IOCs associated with the file hash |
matched_relation | string | null | WHICH of ThreatFox’s two hash relations answered. “sample_to_c2”: the hash is a malware sample and the rows are the C&C servers it talks to. “hash_listed_as_ioc”: the hash is itself published as an indicator (threat_type “payload”) and the row IS the answer. null: neither matched - both were searched, see searched_relations. |
searched_relations | array | Present only when nothing matched: the relations that WERE searched, so an empty answer cannot be mistaken for a partial lookup. |
Full JSON Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "The query type sent (search_hash)"
},
"status": {
"type": [
"string",
"null"
],
"description": "Query status (ok, no_result, or null)"
},
"count": {
"type": "integer",
"description": "Number of results returned"
},
"results": {
"type": "array",
"description": "IOCs associated with the file hash",
"items": {
"type": "object"
}
},
"matched_relation": {
"type": [
"string",
"null"
],
"enum": [
"sample_to_c2",
"hash_listed_as_ioc",
null
],
"description": "WHICH of ThreatFox's two hash relations answered. \"sample_to_c2\": the hash is a malware sample and the rows are the C&C servers it talks to. \"hash_listed_as_ioc\": the hash is itself published as an indicator (threat_type \"payload\") and the row IS the answer. null: neither matched - both were searched, see searched_relations."
},
"searched_relations": {
"type": "array",
"items": {
"type": "string"
},
"description": "Present only when nothing matched: the relations that WERE searched, so an empty answer cannot be mistaken for a partial lookup."
}
},
"required": [
"query",
"status",
"count",
"results"
]
}
Connect
Add this to your MCP client config — every tool in the catalog, including this one — or use one-click install buttons:
{
"mcpServers": {
"pipeworx": {
"url": "https://pipeworx.io/mcp"
}
}
}
Connect to just the threatfox pack
{
"mcpServers": {
"threatfox": {
"url": "https://gateway.pipeworx.io/threatfox/mcp"
}
}
}
See Getting Started for client-specific install steps.