LiveDataLink
threat-intel · RDAP / abuse.ch / FBI

Threat Intel / Due Diligence data for AI agents

OSINT and due-diligence signals: domain and IP ownership via RDAP, IP risk profiling (Tor and botnet C2 flags), and FBI Wanted screening. Where the upstream source provides it, the response includes a timestamp or freshness note.

Get a free key → See all 4 tools Test a due-diligence workflow

How to connect

These Threat Intel / Due Diligence tools use the same LiveDataLink endpoint as the rest of the catalog. Add it to an MCP client that supports Streamable HTTP and include your bearer key. Each source has its own coverage, update schedule, and credential requirements; those limits are listed in the catalog and response notes.

{
  "mcpServers": {
    "livedatalink": {
      "url": "https://livedatalink.ai/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" }
    }
  }
}

Once connected, call any tool below. The free tier covers 1,000 queries each month across the 377-tool catalog, with no credit card.

Threat Intel / Due Diligence tools (4)

rdap_domainDomain registration record via RDAP (modern WHOIS): registrar, dates, status, nameservers, DNSSEC.
rdap_ipIP/block ownership via RDAP: network name, owning org, ASN, CIDR, country.
ip_reputationIP risk profile: geolocation, ASN/ISP, Tor-exit-node flag, and abuse.ch botnet C2 blocklist check.
fbi_wantedSearch the FBI Wanted/fugitive list by name or keyword; returns subjects, aliases, field offices, and a link.

Common queries this domain answers: rdap · whois · domain owner · ip owner · asn · ip reputation · tor · exit node · botnet · c2 · command and control · abuse · threat intel · osint · fbi wanted · fugitive · due diligence · registrar.

Why LiveDataLink for Threat Intel / Due Diligence

FAQ

What can I look up in Threat Intel / Due Diligence?
OSINT and due-diligence signals: domain and IP ownership via RDAP, IP risk profiling (Tor and botnet C2 flags), and FBI Wanted screening. The catalog has 4 tools, including rdap_domain, rdap_ip, ip_reputation, fbi_wanted. They are available over the Model Context Protocol at https://livedatalink.ai/mcp. Coverage and update timing come from RDAP / abuse.ch / FBI.
How do I connect these tools?
Add https://livedatalink.ai/mcp as a Streamable HTTP MCP server in Claude, Cursor, n8n, or another compatible client, then send an "Authorization: Bearer YOUR_API_KEY" header. A free key includes 1,000 queries/month with no card at https://livedatalink.ai/signup/free. The same key works across domains, although some upstream sources have their own credentials or limits.
Can I reuse the results in my product?
That depends on RDAP / abuse.ch / FBI's terms. Check its attribution and redistribution rules before shipping results to customers. LiveDataLink's free tier includes 1,000 queries/month, and paid plans start at $10/month.

Start free, 1,000 queries/month → Browse all data domains