Threat Intel / Due Diligence data for AI agents
OSINT and due-diligence signals: domain and IP ownership via RDAP, IP risk profiling (Tor and botnet C2 flags), and FBI Wanted screening. Where the upstream source provides it, the response includes a timestamp or freshness note.
Get a free key → See all 4 tools Test a due-diligence workflow
How to connect
These Threat Intel / Due Diligence tools use the same LiveDataLink endpoint as the rest of the catalog. Add it to an MCP client that supports Streamable HTTP and include your bearer key. Each source has its own coverage, update schedule, and credential requirements; those limits are listed in the catalog and response notes.
{
"mcpServers": {
"livedatalink": {
"url": "https://livedatalink.ai/mcp",
"headers": { "Authorization": "Bearer YOUR_API_KEY" }
}
}
}
Once connected, call any tool below. The free tier covers 1,000 queries each month across the 377-tool catalog, with no credit card.
Threat Intel / Due Diligence tools (4)
| rdap_domain | Domain registration record via RDAP (modern WHOIS): registrar, dates, status, nameservers, DNSSEC. |
| rdap_ip | IP/block ownership via RDAP: network name, owning org, ASN, CIDR, country. |
| ip_reputation | IP risk profile: geolocation, ASN/ISP, Tor-exit-node flag, and abuse.ch botnet C2 blocklist check. |
| fbi_wanted | Search the FBI Wanted/fugitive list by name or keyword; returns subjects, aliases, field offices, and a link. |
Common queries this domain answers: rdap · whois · domain owner · ip owner · asn · ip reputation · tor · exit node · botnet · c2 · command and control · abuse · threat intel · osint · fbi wanted · fugitive · due diligence · registrar.
Why LiveDataLink for Threat Intel / Due Diligence
- One key, 81 domains. These tools sit alongside FMCSA carrier safety, sanctions screening, SEC filings, courts, Census, and FRED through the same endpoint. Source coverage and credentials vary by tool.
- Check source terms. Sourced from RDAP / abuse.ch / FBI; review its attribution and redistribution rules before shipping results.
- For agent workflows. Read-only annotated MCP tools over Streamable HTTP with Bearer auth. Use them with clients that support this transport, including compatible Claude, Cursor, and n8n setups.
FAQ
- What can I look up in Threat Intel / Due Diligence?
- OSINT and due-diligence signals: domain and IP ownership via RDAP, IP risk profiling (Tor and botnet C2 flags), and FBI Wanted screening. The catalog has 4 tools, including rdap_domain, rdap_ip, ip_reputation, fbi_wanted. They are available over the Model Context Protocol at https://livedatalink.ai/mcp. Coverage and update timing come from RDAP / abuse.ch / FBI.
- How do I connect these tools?
- Add https://livedatalink.ai/mcp as a Streamable HTTP MCP server in Claude, Cursor, n8n, or another compatible client, then send an "Authorization: Bearer YOUR_API_KEY" header. A free key includes 1,000 queries/month with no card at https://livedatalink.ai/signup/free. The same key works across domains, although some upstream sources have their own credentials or limits.
- Can I reuse the results in my product?
- That depends on RDAP / abuse.ch / FBI's terms. Check its attribution and redistribution rules before shipping results to customers. LiveDataLink's free tier includes 1,000 queries/month, and paid plans start at $10/month.