MCP serverio.github.0xDanielLopez/tweetfeed
IOCs (URLs, domains, IPs, hashes) shared by the infosec community on X/Twitter.
Read more
IOCs (URLs, domains, IPs, hashes) shared by the infosec community on X/Twitter. No auth, CC0.Overview
Score?
UNRATED 0.833
of what a free look can see, on 32 looks
Looks
35
last 18 hr ago
Tools
14
changed 15 days ago
More info
URL
mcp.tweetfeed.live/
streamable-http
Says it is
tweetfeed-mcp 0.1.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.833 · highest on record 0.8561
Toolsfrom sha256:8f5635725f…12611f · +0 −0 15 days ago
| Tool | Schema |
|---|---|
| check_hash Check whether a file hash (MD5 or SHA-256) appears in the TweetFeed corpus. Exact match over the past 365 days (falls back to a 30-day window if there's no exact hit); also flags o |
input · no output |
| check_ip Check whether an IP address appears in the TweetFeed corpus. Exact match over the past 365 days (falls back to a 30-day substring window if there's no exact hit, so '1.2.3' will st |
input · no output |
| check_url Check whether a URL (or substring) appears in the TweetFeed corpus over the past 30 days. Useful for confirming if an observed URL has been flagged by the public infosec Twitter/X |
input · no output |
| enrich_ioc Look up an IOC value in TweetFeed. First an EXACT lookup over the past 365 days (aggregated: first_seen, last_seen, count, reporters, tags, last source tweets; accepts defanged inp |
input · no output |
| fetch Fetch the full TweetFeed document for an id returned by search: ioc:<value> (365-day exact lookup with AI/corroboration/registration context, archive and campaign membership), tag: |
input · output |
| get_campaign_iocs Return the full IOC membership of one AI-clustered campaign from the trailing 30-day window: campaign header (name, context, MITRE ATT&CK ttps, targeted_sector, targeted_country, i |
input · no output |
| get_campaigns AI-clustered campaign groupings of the last 30 days of community-shared TweetFeed IOCs: each campaign bundles related URLs/domains/IPs/hashes under a name, a short context summary, |
input · no output |
| get_feed_status Live health of the TweetFeed pipeline: a freshness verdict per artifact (stale, age_seconds) and source coverage (which hashtag/account X feeds delivered rows in the last 24h and w |
input · no output |
| get_tag_info Bundle of TweetFeed activity for a single tag: aggregate counts across today/week/month/year windows plus the most recent IOCs. Saves the agent from making three separate calls to |
input · no output |
| get_trending Top tags and IOC-type distribution for a given time window, computed from the live counts.json aggregate. Useful for 'what is the infosec community talking about right now' or 'whi |
input · no output |
| get_trends IOC trend analytics from the last 31 days: daily volume by type, top moving tags week-over-week, most-abused TLDs, new vs recurring indicator ratio, and feed producer concentration |
input · no output |
| list_recent_iocs List TweetFeed IOCs added since a given date, useful for delta-syncing a blocklist or Threat Intelligence pipeline. Source is the 30-day month window so 'since' must be within the |
input · no output |
| query_iocs Query the TweetFeed API for Indicators of Compromise (IOCs: URLs, domains, IPs, MD5/SHA256 hashes) shared by the infosec community on Twitter/X. Returns matching rows with date, re |
input · no output |
| search Search TweetFeed (CC0 IOC feed from the infosec Twitter/X community) for a document id to pass to fetch. Accepts an IOC value (URL, domain, IP, MD5/SHA256), a tag (e.g. 'phishing', |
input · output |
Verify it yourself
npx teppi-check https://mcp.tweetfeed.live/curl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2B71EGJW2YFD307X2XTK