TeleSint
activeReal-time cyber threat intelligence sourced from public Telegram CTI channels. Eleven pay-per-call endpoints covering IOC extraction (IPs, domains, hashes, CVEs), C2 infrastructure lookup, threat actor profiles, breach disclosures, pre-attack intent signals, vulnerability and exploitation-in-the-wild tracking, ransomware group activity, malware family intelligence, dark web monitoring,…
Settled via Coinbase.
- Transactions · 30d
- 54
- Volume · 30d
- $0.98
- Unique buyers · 30d
- 10
- Uptime · 30d
- 100.0%
- Latency p50
- 131ms
- Reported calls · 30d
- 48
Endpoints (14 live)
GET/darkweb— Dark web intelligence from Telegram: marketplace listings, forum chatter, access broker posts, credential shops, Tor site activity. Filters: severity, min_confidence, since, tag, sector, country, organization, limit, offset. (0.03 USDC on Base)GET/ioc— IOC feed from Telegram CTI channels. Filters: type(ip|domain|url|hash|cve), severity, min_confidence, since, tlp, tag, channel, limit, offset. Returns items[] with iocs[], ttps[], confidence, severity, tlp, tags[]. (0.01 USDC on Base)GET/feed— Returns the Telesint feed data endpoint. (0.05 USDC on Base)GET/intent— Analyzes user intent from text or activity signals. (0.05 USDC on Base)GET/vulnerability— CVE and exploitation-in-the-wild signals from Telegram CTI channels. Filters: severity, min_confidence, since, tag(cve|exploit|poc|patch), ttp, type(cve), limit, offset. Returns CVE IDs, affected products, exploit status. (0.03 USDC on Base)GET/search— Cross-category pivot across all TeleSint intel. Use ?q= for broad keyword or combine filters: category, severity, sector, country, tag, ttp, name, organization, min_confidence, since. Returns items[] across any category. (0.04 USDC on Base)GET/asn— ASN threat intel from Telegram CTI channels. Pass ?asn=AS215540. Returns C2/phishing-kit associations, threat actor mentions, bulletproof hosting flag, blocking recommendation with WAF hint, and record IDs for pivoting into /c2 or /ioc. (0.03 USDC on Base)GET/source— Raw source verification for a TeleSint record. Pass id (UUID from any items[].id). Returns original defanged message text and source language alongside the AI summary for provenance checks. (0.02 USDC on Base)GET/ransomware— Ransomware group activity from Telegram: victim posts, leak site announcements, extortion demands. Filters: severity, min_confidence, since, tag(lockbit|blackcat|cl0p|ransomhub), sector, country, limit, offset. (0.04 USDC on Base)GET/malware— Malware family intelligence from Telegram: new sample drops, behavior analysis, loader/stealer/RAT/backdoor writeups. Filters: severity, min_confidence, since, tag(stealer|loader|rat|backdoor), limit, offset. (0.02 USDC on Base)GET/breach— Breach disclosures from Telegram. Filters: sector, country, organization, severity, min_confidence, since, limit. Returns items[] with target{sectors,countries,organizations}, leak iocs[], confidence. (0.03 USDC on Base)GET/actor— Threat actor profiles from Telegram. Filters: name, nation_state(kp|ru|cn|ir), motivation(financial|espionage|hacktivism), ttp, severity, limit. Returns items[] with actor{}, ttps[], target{sectors,countries}. (0.02 USDC on Base)GET/artifact— CTI artifact export from a TeleSint record. Required: id (record UUID), format (sigma|stix|report). Returns Sigma rule, STIX 2.1 bundle, or structured analyst report built from real enriched intel. (0.05 USDC on Base)GET/c2— C2 infrastructure from Telegram. Filters: framework(cobalt_strike|sliver|havoc|brute_ratel), severity, min_confidence, since, tag, limit, offset. Returns items[] with C2 IPs/domains, MITRE TTPs, confidence. (0.02 USDC on Base)
First seen · last seen · last active