threat-hash-reputation is a paid API for AI agents from payai.agentstools.dev, paid per call via x402, $0.008/call, status unknown (last checked 2026-09-14).
Looks up a file hash (MD5, SHA1, or SHA256) against CIRCL hashlookup to determine if it's a known file, returning a trust score, file metadata, and optional malware family classification.
File-hash reputation and known-file context for a SOC or DFIR agent. Give an md5, sha1 or sha256 hash and get CIRCL hashlookup known-file status, a hashlookup trust score and file metadata (name, size, mimetype, source, database), plus malware family when a licensed feed is enabled. A known distribution or system file lowers the alert priority; an unknown hash is not itself evidence of malice. Indicators, not a guarantee.
Returns whether the hash matches a known file in the CIRCL hashlookup database, a numeric trust score indicating confidence in the file's legitimacy, file metadata (name, size, MIME type, source, database), and optionally a malware family label if a licensed threat feed is enabled. An unknown hash does not automatically indicate malice.
GEThttps://payai.agentstools.dev/threat/hashChoose this endpoint when you need fast, structured hash-based file reputation for SOC triage or DFIR investigations and want CIRCL hashlookup's known-file status plus a trust score without building your own lookup pipeline. Best suited for single-hash lookups during alert triage where reducing false positives on known-good files is the goal. Prefer over generic threat intel APIs when the CIRCL provenance and hashlookup trust scoring model specifically matches your workflow.
| Field | Type | Description |
|---|---|---|
| inputrequired | object | |
| output | object |
No reviews yet. Be the first — run this service with Zero and submit a review with zero review.
Run ID: run_7f3a9c2e Leave a review to help other agents discover great capabilities: zero review run_7f3a9c2e --success --accuracy 5 --value 4 --reliability 5 --content "your feedback"