lookup-otx

Retrieve community pulse context for indicators from AlienVault OTX.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill lookup-otx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: lookup-otx
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/lookup-otx
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill lookup-otx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill retrieves community pulse context from AlienVault OTX for indicators (IP, domain, hash, URL), returning pulse counts, key pulses, tags, related indicators, and passive DNS. It provides retrieval-only context to support investigations.

Core Features & Use Cases

  • Retrieve pulse counts, key pulses, tags, and related indicators for an indicator.
  • Access passive DNS data for IPs and domains when available.
  • Enrich investigation workflows with up-to-date community context without interpretation.

Quick Start

Invoke the lookup by supplying an indicator type (ip, domain, hash, or url) and its value to fetch community pulse data from AlienVault OTX.

Frequently Asked Questions about lookup-otx

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I retrieve threat intelligence pulses from AlienVault OTX for an IP address?

To retrieve threat intelligence pulses from AlienVault OTX, supply the indicator type and value to fetch associated community pulse data, tags, and related indicators for your IP address investigation.

Can I enrich threat investigations with passive DNS data from AlienVault OTX?

Yes, you can enrich threat investigations with passive DNS data from AlienVault OTX by querying supported IP and domain indicators, returning available passive DNS records alongside pulse context.

What types of indicators can I query for OTX pulse context during IOC enrichment?

During IOC enrichment, you can query AlienVault OTX pulse context for IP, domain, hash, and URL indicators to retrieve related community pulses and threat intelligence tags.

Does the OTX lookup provide interpretation of threat intelligence indicators?

No, the OTX lookup satisfies a retrieval-only requirement by returning counts, pulses, tags, related indicators, and passive DNS without providing any threat intelligence interpretation or analysis.

What is the best way to get community pulse counts and related indicators for a suspicious domain?

The best way to get community pulse counts for a suspicious domain is to query AlienVault OTX, which returns key pulses, tags, related indicators, and passive DNS without interpretation.

Why does my OTX threat intelligence lookup return no pulses for a URL indicator?

An OTX threat intelligence lookup may return no pulses for a URL indicator if the community has not yet submitted any related context, as the retrieval strictly returns available data without interpretation.