To embed a website or widget, add it to the properties panel.
To embed a website or widget, add it to the properties panel.
To embed a website or widget, add it to the properties panel.

Remote MCP Server

Connect AI tools
like Claude & ChatGPT
to our data

Connect AI tools
like Claude & ChatGPT
to our data

Connect AI tools
like Claude & ChatGPT
to our data

Hunt.io has a remote MCP server at mcp.hunt.io with OAuth support, so you can connect AI tools like Claude straight to the same Hunt.io data and endpoints without building a custom integration.

PKCE S256 is supported for browser-based clients

Authentication uses your existing API key, and dedicated MCP API keys can be created with fixed scopes

18 tools available out of the box

Organizations can manage MCP activation and access gating at the org level

Threat Enrichment Data Included

Structured intelligence for any IP addresses

Structured intelligence for any IP addresses

Structured intelligence for any IP addresses

This is the IP enrichment response. Instead of a reputation score, you get infrastructure-level context built from live scanning, validation, and continuous monitoring. Each response pulls several intelligence layers into one structured, automation-ready result.

Certificates & Cryptography

TLS certificates, serial numbers, issuers, fingerprints, and the usage patterns tied to them.

Malware & Tooling Signals

Malware families, tooling indicators, and infrastructure linked to known threats.

Network & Protocol Fingerprinting

JA4 and protocol-level fingerprints that show how a service behaves.

Exposed Infrastructure

Open directories, exposed services, and misconfigured assets seen in the wild.

Honeypots & Deception Signals

Signals showing interaction with honeypots or research infrastructure.

Phishing & Abuse Indicators

Infrastructure tied to phishing or abuse campaigns when we've observed it.

One API, One Key

More than enrichment.

The whole Hunt.io dataset.

More than enrichment.

The whole Hunt.io dataset.

More than enrichment.

The whole Hunt.io dataset.

Enrichment

IP & Domain Profiles

Single-IP and domain snapshots with certificates, malware signals, fingerprints, and observed activity.

Search

Fast IP Search & HuntSQL

Censys/Shodan-style queries against the live ip.current index, or SQL across the operational tables.

Pivoting

IP History & Timelines

Certificate, malware, JARM, SSH, and TLS continuity for one IP, plus ranked pivots for the next branch.

Domains

Domain & DNS Intel

WHOIS and DNS history, subdomains, nameserver clustering, and Cloudflare Buster to map hidden hosts.

Certificates

TLS & Transparency

Certificate detail lookups by SHA-256 and certificate transparency observations for infrastructure tracing.

AttackCapture

Open Directory Intel

Browse attacker infrastructure, search code and file names, and review flagged malicious hosts.

IOC Hunter

Sourced IOCs

Search hosts, IPs, posts, and SHA-256 values across reported infrastructure, with facets and daily counts.

Threat Actors

Actor Profiles & Naming

Verified actor dossiers, alias and naming details, and legacy-parity IP IOC listings per actor.

Vulnerabilities

CVE & Weaponized Threats

CVE advisory context with exploit and nuclei sections, plus top and weaponized threat shortlists.

Signals

Threat Signal Lookups

Enriched signal profiles per IP with tags, actor overlaps, and infrastructure context for fast triage.

C2 Feed

Command & Control Feed

Download observed C2 infrastructure as gzip NDJSON for blocking workflows and pipeline automation.

Bulk

Extract & Enrich

Pull IPs, domains, CIDRs, and hashes from raw text, then run batch summaries across a whole watchlist.

Search, Not Just Enrich

Find every host that matches, not just one.

Find every host that matches, not just one.

Find every host that matches, not just one.

Enrichment answers "tell me about this IP." Search answers "find me every IP that looks like this." Run bounded, Censys/Shodan-style queries against live scan data, or drop into SQL across the indexes when you need more control.

Fast IP search field:value, ranges, wildcards, booleans, and same_port() scoping.

HuntSQLpaged results, histograms, and JSON, NDJSON, or CSV exports.

All queries run against Hunt's own internet-wide scanning, updated continuously.

Why it's different

Why our Threat

Intelligence API Is Different

Why our Threat

Intelligence API Is Different

Why our Threat

Intelligence API Is Different

Built From Live Scanning

Every response comes from Hunt's own internet-wide scanning and validation.

Designed for Automation

Consistent schemas, timestamps, and structured fields, built for pipelines and integrations.

Infrastructure Context Over Raw IOCs

See how an indicator fits into an attacker's infrastructure, not just whether it showed up on a list.

Get Started

With The Threat Intelligence API

Get Started

With The Threat Intelligence API

Get Started

With The Threat Intelligence API

Get your API key and start querying live threat data in minutes.

What can I do with the API?

Enrich IPs and domains, search infrastructure with SQL and fast IP queries, pivot through infrastructure history, and pull AttackCapture open directories, IOC Hunter results, threat actor profiles, vulnerability intel, and the C2 feed. One API key covers all of it.

How is this different from reputation or blacklist APIs?

Reputation APIs give you a score or a yes/no. This gives you the infrastructure behind an indicator: certificates, fingerprints, history, and how it connects to other hosts, so you can make your own call.

How do I access the Threat Intelligence API?

Standard REST at a.hunt.io with a Bearer API key. You can also reach the same data from AI tools like Claude through the Hunt.io MCP server at mcp.hunt.io.

What formats are supported?

JSON on the REST endpoints. SQL results download as JSON, NDJSON, or CSV, and the C2 feed comes as gzip-compressed NDJSON.