TweetFeed
Qué hace este MCP
Searches and enriches community-reported indicators of compromise, campaigns, tags, trends, and threat-intelligence feed status.
Herramientas
Esquema de entrada
{'type': 'object', 'required': ['hash'], 'properties': {'hash': {'type': 'string', 'description': 'MD5 (32 hex chars) or SHA-256 (64 hex chars) hash. Case-insensitive. Non-hex characters or wrong length will return an INVALID_PARAMS error.'}}}
Esquema de entrada
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'description': "IPv4 or IPv6 address to search (e.g. '185.107.56.42', '2a02:...')."}}}
Esquema de entrada
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': "URL or URL substring to search (e.g. 'fake-bank.com/login', 'phish-domain.tld'). Case-insensitive."}}}
Esquema de entrada
{'type': 'object', 'required': ['value'], 'properties': {'value': {'type': 'string', 'description': "IOC value to look up. Type is auto-detected: 32 hex chars = MD5, 64 hex chars = SHA-256, dotted-quad = IPv4, label.tld = domain, anything containing '://' or '/' = URL."}}}
Esquema de entrada
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'Document id from search, e.g. ioc:example.com, tag:phishing, campaign:tfc-0123456789ab.'}}}
Esquema de salida
{'type': 'object', 'required': ['id', 'title', 'text', 'url'], 'properties': {'id': {'type': 'string'}, 'url': {'type': 'string'}, 'text': {'type': 'string'}, 'title': {'type': 'string'}, 'metadata': {'type': 'object'}}}
Esquema de entrada
{'type': 'object', 'required': ['campaign_id'], 'properties': {'type': {'enum': ['url', 'domain', 'ip', 'sha256', 'md5'], 'type': 'string', 'description': "Optional: filter the campaign's IOC rows to a single type."}, 'limit': {'type': 'number', 'default': 100, 'description': 'Optional: max IOC rows to return (1-500). Default 100.'}, 'campaign_id': {'type': 'string', 'description': "Campaign id in the 'tfc-' + 12 hex characters form (e.g. 'tfc-1a2b3c4d5e6f'). Get valid ids from get_campaigns."}}}
Esquema de entrada
{'type': 'object', 'properties': {'brand': {'type': 'string', 'description': "Optional: filter by targeted brand, case-insensitive substring match against targeted_brand (e.g. 'paypal', 'microsoft'). Campaigns with no identified brand are excluded when this is set."}, 'limit': {'type': 'number', 'default': 10, 'description': 'Optional: max campaigns to return (1-50). Default 10.'}, 'min_confidence': {'enum': ['low', 'medium', 'high'], 'type': 'string', 'description': 'Optional: minimum clustering confidence to include (low < medium < high). Only campaigns at or above this confidence are returned.'}}}
Esquema de entrada
{'type': 'object', 'properties': {}}
Esquema de entrada
{'type': 'object', 'required': ['tag'], 'properties': {'tag': {'type': 'string', 'description': "Tag to look up (e.g. 'phishing', 'CobaltStrike', 'lockbit'). Case-insensitive. The leading '#' is optional. 94 tags exist - see https://tweetfeed.live/tags/ for the full list."}, 'limit': {'type': 'number', 'default': 10, 'description': 'Max recent IOCs to include (1-100). Default 10.'}}}
Esquema de entrada
{'type': 'object', 'required': ['window'], 'properties': {'limit': {'type': 'number', 'default': 20, 'description': 'How many top tags to return (1-100). Default 20.'}, 'window': {'enum': ['today', 'week', 'month', 'year'], 'type': 'string', 'description': "Time window. 'today' = since UTC midnight, 'week' = last 7 days, 'month' = last 30 days, 'year' = last 365 days."}}}
Esquema de entrada
{'type': 'object', 'properties': {'section': {'enum': ['daily', 'movers', 'tlds', 'novelty', 'producers', 'all'], 'type': 'string', 'default': 'all', 'description': "Optional: which section to return. 'daily' = 31-day volume summary by type, 'movers' = top tags moving week-over-week (current 7d vs previous 7d), 'tlds' = most-abused TLDs among domain IOCs, 'novelty' = new vs recurring indicator ratio, 'producers' = feed producer concentration: top contributors, active producers and bus factor for 7d/30d windows, 'all' = every section. Default 'all'."}}}
Esquema de entrada
{'type': 'object', 'required': ['since'], 'properties': {'tag': {'type': 'string', 'description': 'Optional: filter by tag (case-insensitive substring match on the tag list).'}, 'type': {'enum': ['url', 'domain', 'ip', 'sha256', 'md5'], 'type': 'string', 'description': 'Optional: filter by IOC type.'}, 'limit': {'type': 'number', 'default': 100, 'description': 'Max results (1-1000). Default 100.'}, 'since': {'type': 'string', 'description': "ISO date (YYYY-MM-DD) for the lower bound. Example: '2026-04-15'."}}}
Esquema de entrada
{'type': 'object', 'required': ['time'], 'properties': {'tag': {'type': 'string', 'description': "Optional: filter by tag, case-insensitive substring match. Examples: 'phishing', 'cobaltstrike', 'ransomware', 'APT', 'Lockbit'. 94 tags exist - see https://tweetfeed.live/ for the live taxonomy."}, 'time': {'enum': ['today', 'week', 'month'], 'type': 'string', 'description': "Time window. 'today' = since UTC midnight, 'week' = last 7 days, 'month' = last 30 days."}, 'type': {'enum': ['url', 'domain', 'ip', 'sha256', 'md5'], 'type': 'string', 'description': 'Optional: filter by IOC type.'}, 'user': {'type': 'string', 'description': "Optional: filter by Twitter/X handle WITHOUT the @ prefix (e.g. 'malwrhunterteam', 'JCyberSec_')."}, 'limit': {'type': 'number', 'default': 100, 'description': 'Optional: max rows to return (1-1000). Default 100.'}}}
Esquema de entrada
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'description': 'IOC value, tag, campaign id or free text.'}}}
Esquema de salida
{'type': 'object', 'required': ['results'], 'properties': {'results': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'title', 'url'], 'properties': {'id': {'type': 'string'}, 'url': {'type': 'string'}, 'title': {'type': 'string'}}}}}}
Cambios recientes en herramientas
Servidores MCP similares
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
tollbooth
Provides paid OSINT, web intelligence, security threat and vulnerability lookups, prediction-market analysis, financial data, leg…
TunnelMind Data API
Aggregates web, routing, supply-chain, tracker, threat, and agent-registry intelligence into risk verdicts, evidence, receipts, a…
DataNexus MCP
Enables public-data research across domains, patents, government contracts, nonprofits, compliance registries, and software secur…
website-search
Provides security article search and structured guidance, templates, frameworks, and review criteria for incident response, threa…
1cent Web Intelligence for AI Agents
Performs SSRF-safe public web inspection, URL extraction, metadata and content analysis, accessibility checks, feed and sitemap d…
x402 Checker (AI Nock)
Offers paid x402 utilities for blockchain, crypto markets, academic and news search, DNS and email checks, CVE lookups, geocoding…
Urlscan Io
Searches urlscan.io historical scan results by domain or IP address and returns URLs, verdicts, screenshots, and scan metadata.