LiveDataLink
cyber-security · abuse.ch URLhaus

URLhaus Threat Intelligence data for AI agents

Read-only malware URL and payload metadata for defensive security investigation; sample downloads and submissions are excluded. Where the upstream source provides it, the response includes a timestamp or freshness note.

Get a free key → See all 7 tools

How to connect

These URLhaus Threat Intelligence tools use the same LiveDataLink endpoint as the rest of the catalog. Add it to an MCP client that supports Streamable HTTP and include your bearer key. Each source has its own coverage, update schedule, and credential requirements; those limits are listed in the catalog and response notes.

{
  "mcpServers": {
    "livedatalink": {
      "url": "https://livedatalink.ai/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" }
    }
  }
}

Once connected, call any tool below. The free tier covers 1,000 queries each month across the 349-tool catalog, with no credit card.

URLhaus Threat Intelligence tools (7)

urlhaus_recent_urlsList recent malware-distribution URLs added to URLhaus in its rolling three-day window. Returns bounded metadata and indicators only; it never visits the reported URLs.
urlhaus_recent_payloadsList metadata and cryptographic hashes for payloads recently observed by URLhaus. This tool does not download malware samples.
urlhaus_lookup_urlLook up URLhaus threat intelligence for exactly one HTTP(S) URL or numeric URLhaus record ID. Returns status, tags, blacklist metadata, and a bounded payload summary without contacting the reported URL.
urlhaus_lookup_hostLook up an IPv4 address, hostname, or domain in URLhaus and return a bounded list of associated malware URLs. The host is sent only to URLhaus; LiveDataLink never connects to it.
urlhaus_lookup_payloadLook up URLhaus metadata for an MD5 or SHA-256 malware-payload hash and return a bounded set of associated URLs. This tool does not download the payload.
urlhaus_lookup_tagLook up a URLhaus classification tag and return observation dates plus a bounded list of associated malware URLs.
urlhaus_lookup_signatureLook up a URLhaus malware-family signature and return counts plus a bounded list of associated URL and payload observations.

Common queries this domain answers: urlhaus · abuse.ch · malware · malicious url · ioc · payload hash · threat intelligence · signature.

Why LiveDataLink for URLhaus Threat Intelligence

FAQ

What can I look up in URLhaus Threat Intelligence?
Read-only malware URL and payload metadata for defensive security investigation; sample downloads and submissions are excluded. The catalog has 7 tools, including urlhaus_recent_urls, urlhaus_recent_payloads, urlhaus_lookup_url, urlhaus_lookup_host, urlhaus_lookup_payload, urlhaus_lookup_tag, plus others. They are available over the Model Context Protocol at https://livedatalink.ai/mcp. Coverage and update timing come from abuse.ch URLhaus.
How do I connect these tools?
Add https://livedatalink.ai/mcp as a Streamable HTTP MCP server in Claude, Cursor, n8n, or another compatible client, then send an "Authorization: Bearer YOUR_API_KEY" header. A free key includes 1,000 queries/month with no card at https://livedatalink.ai/signup/free. The same key works across domains, although some upstream sources have their own credentials or limits.
Can I reuse the results in my product?
That depends on abuse.ch URLhaus's terms. Check its attribution and redistribution rules before shipping results to customers. LiveDataLink's free tier includes 1,000 queries/month, and paid plans start at $10/month.

Start free, 1,000 queries/month → Browse all data domains