---
title: "Check if the specified IOC exists in any of the existing IOC Sets."
method: GET
path: "/threatintel/v1/ioc/lookup"
tags: ["Threat Intel"]
---

# Check if the specified IOC exists in any of the existing IOC Sets.

`GET /threatintel/v1/ioc/lookup`

Check if the specified IOC exists in any of the existing IOC Sets.

## Query parameters

- `IocValue` string, required

## Response `200`

## Other responses

- `400` — Bad Request
- `401` — The request either did not include an authentication token, or you have provided an expired authentication token.
- `404` — The requested resource was not found.
- `500` — Internal error.

---

[API](https://skmtc.net/druva/apis/authentication.md) · [All operations](https://skmtc.net/druva/apis/authentication/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/druva/authentication/versions/2af2bf148b25/schema)
