OT Intel API
activeOT/ICS/SCADA threat intelligence for AI agents and industrial SOC automation. 40 pay-per-call endpoints across primitive, analytical, and composed-synthesis tiers, covering CVE triage, internet-exposed device lookup, ICS threat actor profiles (SANDWORM, VOLTZITE, XENOTIME), IOC enrichment with OT campaign context, CISA ICS-CERT advisory feed, patch feasibility assessment, asset risk verdict…
Settled via Coinbase.
- Transactions · 30d
- 66
- Volume · 30d
- $1.74
- Unique buyers · 30d
- 8
- Uptime · 30d
- 100.0%
- Latency p50
- 119ms
- Reported calls · 30d
- 37
Endpoints (40 live)
GET/ot/malware— ICS malware encyclopedia. Pass ?name=PIPEDREAM. Returns capabilities, targeted OT protocols, attributed actor, affected vendors, detection signatures, and MITRE ATT&CK ICS techniques. Covers PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY. (0.02 USDC on Base)GET/ot/delta— ICS sector change feed — only what is NEW in the last N days. Pass ?sector=water&days=7. Returns new CVEs, new CISA advisories, and new actor activity since the last call. Designed for cron-based monitoring agents. Eliminates redundant reprocessing. (0.03 USDC on Base)GET/ot/exposure— OT asset risk verdict. Pass ?vendor=siemens&model=s7-1500§or=energy&network=internet-facing. Returns risk_score (0-100), risk_level, escalate (boolean), recommended_action, active CVEs, and threat actors. Optional firmware param enables firmware-specific CVE matching. Cached 1 hour. (0.05 USDC on Base)GET/ot/patch— OT/ICS patch feasibility for a CVE. Pass ?id=CVE-XXXX-XXXX. Returns patch availability, OT-safe workarounds, patch complexity per ICS layer, estimated downtime, safe-to-patch-live flag, deployment strategy, and risk-vs-disruption score 1-10. (0.05 USDC on Base)GET/ot/campaign— Active ICS campaign tracker. Pass ?sector=electric&status=active. Returns campaigns currently targeting a sector with actor attribution, start date, targeted geography, TTPs in use, and CVEs being exploited. No free equivalent for live campaign status. (0.05 USDC on Base)GET/ot/actor/sector— ICS threat actors by sector. Pass ?sector=energy. Returns all groups targeting that sector from live MITRE ATT&CK ICS STIX data. Covers energy, water, manufacturing, oil-and-gas, chemical, transportation, nuclear. (0.03 USDC on Base)GET/ot/gcc-bulletin— Recurring public "State of OT Threat Intel — GCC" sitrep, human-reviewed before publish, sourced from the same intel.db pipeline as /ot/sitrep. Pass optional issue_date (YYYY-MM-DD) for a past edition; omit for the latest reviewed edition. (0.01 USDC on Base)GET/ot/ioc— IOC enrichment with ICS campaign context. Pass ?value=1.2.3.4&type=ip or type=domain. Queries AlienVault OTX, AbuseIPDB, and DeepSeek CTI for OT campaign association. Returns verdict on whether the IOC is linked to ICS-targeting campaigns. (0.01 USDC on Base)GET/ot/cve— Fetches operational technology CVE vulnerability intelligence for security analysis. (0.02 USDC on Base)GET/ot/report— Returns an on-chain intelligence report for the requested target. (0.25 USDC on Base)GET/ot/ai-attack-feasibility— Assesses whether a target is feasible for an AI-driven attack. (0.2 USDC on Base)GET/ot/threat-score— Calculates a threat score for OT assets, events, or indicators. (0.04 USDC on Base)GET/ot/ai-exposure— AI/agentic copilot exposure lookup for OT/ICS vendors. Pass vendor (Siemens, Schneider Electric, Rockwell Automation, ABB, Emerson, Honeywell, Yokogawa, GE Vernova, Omron, Mitsubishi Electric). Returns the vendor's documented AI/agentic copilot, autonomy level (advisory vs agentic — the key risk differentiator), access, and applicable MITRE ATLAS techniques. Hand-verified mapping, ATLAS IDs confirmed against the live atlas.mitre.org matrix. Deterministic, no LLM in the lookup path. (0.2 USDC on Base)GET/ot/vendor-risk-delta— Counterfactual vendor-swap risk comparison. Pass vendor_current, vendor_proposed (optionally product_current, product_proposed). Runs the same DeepSeek assessment used by /ot/vendor-risk on each vendor and returns the risk-tier delta plus per-vendor summaries — for pre-purchase or migration decisions. (0.2 USDC on Base)GET/ot/analyst-brief— Human-readable analyst brief: BLUF, key judgments, and ICD-203 confidence assessment for a threat actor (optionally scoped to a sector). Same fan-out data as /ot/report (actor, campaign, malware, advisory) but DeepSeek-synthesised into a short decision-ready brief instead of a full report. Pass actor (required), sector (optional). (0.12 USDC on Base)GET/ot/detection— ICS detection artifact retrieval. Pass ?target=PIPEDREAM or ?target=SANDWORM&format=sigma. Returns YARA/Sigma rules for the target malware or actor, sourced from public corpus (Florian Roth signature-base, CISA advisories) with validated:true, or DeepSeek-synthesised with validated:false. Designed for automated threat hunting pipelines that commit rules to SIEMs and EDRs — validated:true rules are safe to deploy; validated:false require lab testing first. (0.05 USDC on Base)GET/ot/risk-exposure— Board/GRC-level portfolio risk aggregator. Pass sector and region. Aggregates the same deterministic capability x opportunity x intent scoring used by /ot/threat-score across the actors relevant to that sector, ranks them, and returns a DeepSeek-written executive summary (BLUF structure, ICD-203 language). Optional compliance_framework noted qualitatively in the narrative. Portfolio-level companion to /ot/threat-score — for vCISO agents and GRC/board-reporting automation. (0.4 USDC on Base)GET/ot/mitigation-map— Prescriptive D3FEND-mapped mitigation guidance for OT/ICS threats. Pass one of ?actor=<threat actor name>, ?cve_id=<CVE ID>, or ?technique_id=<MITRE ATT&CK ICS technique ID e.g. T0836>, optionally with &vendor_stack=<vendor/product context e.g. Schneider Modicon>. Returns matched ATT&CK ICS techniques mapped to D3FEND defensive countermeasures with priority and rationale, plus prescriptive architecture recommendations. DeepSeek-synthesised, ICD-203 estimative language. (0.2 USDC on Base)GET/ot/dossier— Deep actor intelligence dossier. Pass ?actor=SANDWORM. Fans out to actor, campaign, malware, ioc, asn, detection primitives and synthesises via DeepSeek. Returns full profile, infrastructure, IOC table, detection rules, kill chain mapping. Most comprehensive single-call artifact available. (0.35 USDC on Base)GET/ot/agentic/threat-hunt/control-loop— Flags control-loop recon patterns and living-off-the-land/RMM-tool abuse from caller-submitted process/command observations. Pass observed_processes? and/or observed_commands? (comma-separated, max 40 combined), optional zone (OT/IT/DMZ). Fully deterministic keyword matching, no LLM. Grounded in CyberAgentX and AgenticCyOps (arXiv 2603.09134). ADVISORY ONLY — never executes containment or any network action. (0.15 USDC on Base)
+20 more endpoints.
First seen · last seen · last active