Integrations · Security

abuse.ch

Threat-intel from abuse.ch in your agents' hands — indicator checks and malware URL sweeps, with plain receipts.

3 actions · out of the box: Threat Analyst

Missions

What agents get done with it.

Is this indicator known-bad?

An IOC from a log comes back with malware family, threat type, confidence, and seen dates.

Runs on: threatfox.ioc

Hash verdict in one call

A file hash check returns malware family, threat type, confidence, and the first time ThreatFox saw it.

Runs on: threatfox.hash

Fresh malware URL sweep

Recent URLhaus entries arrive newest first with host, threat label, status, and tags for triage.

Runs on: urlhaus.recent

Unknown stays honest

ThreatFox misses are reported as unknown, not clean, while URLhaus sweeps keep watchlists moving.

Runs on: threatfox.ioc · threatfox.hash · urlhaus.recent

The catalog

Every action, honestly listed.

  • threatfox.iocThreatFox IOC lookup

    IOC lookup: malware family, confidence, first/last seen.

    read-onlyno vendor charge
  • threatfox.hashThreatFox hash lookup

    Hash lookup: malware family, confidence, first seen.

    read-onlyno vendor charge
  • urlhaus.recentURLhaus recent malware URLs

    Recent malware URLs feed: host, threat, status, tags.

    read-onlyno vendor charge
Out of the box:Threat AnalystAny agent can hold these actions.

Connect

Your key, their prices.

Your key
pasted once in the desktop app · stored by your runtime, never by us · removable any time
Markup
none — abuse.ch usage at the vendor’s own prices
Vendor charge
none — all three actions are free on abuse.ch
Scope
ThreatFox checks one IOC/hash; URLhaus action is a recent-feed sweep
Key
abuse.ch community key, sent to ThreatFox and URLhaus APIs

abuse.ch runs ThreatFox and URLhaus as a free non-commercial threat-intel service with a community key. Their service, their terms; Ahel adds no markup.

FAQ

Questions people actually ask.

Is the abuse.ch API free?

Yes — ThreatFox and URLhaus are abuse.ch's free non-commercial threat-intel service. Ahel adds no markup.

What can agents check with abuse.ch here?

Three seeded reads: threatfox.ioc, threatfox.hash, and urlhaus.recent. URLhaus here is a feed sweep, not a one-URL lookup.

If ThreatFox says no result, is it safe?

No. query_status no_result means unknown to ThreatFox, not clean.

Put abuse.ch in your agents’ hands.

Ahel is invite-only while access opens in batches. Request yours, connect abuse.ch with your own key, and hand an agent its first real job.