ip_reputation
ActiveTool of Isc Sans
Look up an IPv4 address in the SANS ISC DShield database — its attack-report history, ASN/owner, abuse contact, and risk. A high report_count means the IP is an active attack source (firewall logs submitted by sensors worldwide). report_count null/0 = no malicious activity reported. The comment field often names known infrastructure (e.g. "Google public recursive name server"). Keyless.
Parameters schema
{
"type": "object",
"required": [
"ip"
],
"properties": {
"ip": {
"type": "string",
"description": "An IPv4 address, e.g. \"8.8.8.8\" or \"45.155.205.233\"."
}
}
}No endpoints wrapped at confidence ≥ 0.70.
Parent server
Isc Sans
https://github.com/pipeworx-io/mcp-isc-sans
1/7 registries