ot-intel-api.onrender.com
30 resources
All Resources
ot-intel-api.onrender.com
Deterministic remediation risk gate. Pass actor, sector, region, planned_action (e.g. block_ip, halt_pipeline, disable_account). Returns auto_approve/human_review/reject via capability x opportunity x intent scoring (same as /ot/threat-score) — no LLM in the loop. auto_approve requires vendor_stack; omitting it caps the verdict at human_review regardless of score. Optional asset_context escalates to human_review on shared cloud/CDN infra (e.g. shared_infra:cloudflare).
$0.12 USDC
ot-intel-api.onrender.com
ICS threat actor profile. Pass ?name=SANDWORM. Returns MITRE ATT&CK ICS techniques, known malware, attribution, physical impact, targeted sectors, and OT detection recommendations. Alias lookup supported: Volt Typhoon→VOLTZITE, APT44→SANDWORM. Covers all Dragos Activity Groups.
$0.03 USDC
ot-intel-api.onrender.com
ICS threat actors by sector. Pass ?sector=energy. Returns all groups targeting that sector from live MITRE ATT&CK ICS STIX data. Covers energy, water, manufacturing, oil-and-gas, chemical, transportation, nuclear.
$0.03 USDC
ot-intel-api.onrender.com
Live CISA ICS-CERT advisories filtered by vendor or sector. Pass ?vendor=siemens or ?sector=energy. Returns advisory IDs, CVSS scores, CVE lists, OT severity, and sector tags. Up to 25 results.
$0.02 USDC
ot-intel-api.onrender.com
Deterministic lookup against Cook et al. (ACM TOPS 2026) testing whether off-the-shelf LLMs generate working ICS attack code. Pass technique (name/ID, e.g. 'Brute Force I/O' or T0806), vendor (Siemens, Schneider Electric, Rockwell Automation — only these tested), and/or campaign (Industroyer2, Fuxnet, FrostyGoop, INCONTROLLER, Stuxnet, Triton). Only Network/Register-Tags techniques succeeded; 1.08% success rate; Claude excluded (stronger guardrails). No LLM in lookup path.
$0.20 USDC
ot-intel-api.onrender.com
AI/agentic copilot exposure lookup for OT/ICS vendors. Pass vendor (Siemens, Schneider Electric, Rockwell Automation, ABB, Emerson, Honeywell, Yokogawa, GE Vernova, Omron, Mitsubishi Electric). Returns the vendor's documented AI/agentic copilot, autonomy level (advisory vs agentic — the key risk differentiator), access, and applicable MITRE ATLAS techniques. Hand-verified mapping, ATLAS IDs confirmed against the live atlas.mitre.org matrix. Deterministic, no LLM in the lookup path.
$0.20 USDC
ot-intel-api.onrender.com
Assesses how much a general-purpose AI agent (not a specialized ICS tool) lowers the barrier for an attacker to reach a vendor's OT-adjacent footprint. Grounded in Dragos's May 2026 water-utility precedent, not governance thresholds. Distinct from /ot/ai-exposure (vendor's own AI copilot). Input: vendor (required); product, internet_facing, auth_type, segmented (all optional; unknown caps tier at informational). DeepSeek-synthesized, ICD-203 language.
$0.20 USDC
ot-intel-api.onrender.com
Publication-ready CTI article ~700 words. Pass ?actor=CHERNOVITE or ?cve=CVE-XXXX-XXXX. Fans out to actor/cve + campaign + malware + advisory. DeepSeek writes journalist-style: headline, lede, body with ATT&CK context, defanged IOCs, analyst assessment, TLP. Ready for threat intel blog or advisory publication.
$0.45 USDC
ot-intel-api.onrender.com
ICS threat actor ASN infrastructure profiling. Pass ?asn=AS215540. Returns ICS actor associations (SANDWORM, VOLTZITE, XENOTIME), phishing kit links (Tycoon2FA, EvilProxy, NakedPages), bulletproof hosting indicators, abuse categories (c2, staging, phishing), and an OT-specific blocking recommendation with WAF rule hint. ASN analysis reveals infrastructure clustering that survives IP/domain rotation — critical for OT defenders tracking persistent actor infrastructure.
$0.03 USDC
ot-intel-api.onrender.com
Sector threat brief for ICS/OT. Pass ?sector=energy&period=30. Returns active actors, new CVE counts, active campaigns, top advisories, and risk_trend (increasing/stable/decreasing). One call replaces 5+ chained calls. Ideal for weekly reporting and compliance dashboards.
$0.10 USDC
ot-intel-api.onrender.com
Active ICS campaign tracker. Pass ?sector=electric&status=active. Returns campaigns currently targeting a sector with actor attribution, start date, targeted geography, TTPs in use, and CVEs being exploited. No free equivalent for live campaign status.
$0.05 USDC
ot-intel-api.onrender.com
CTI claim reliability scoring, grounded in Meng et al. (arXiv:2509.23573, Feb 2026). Pass claim=<text>, optionally actor= and/or cve_id= to ground against intel.db. Classifies the claim against three failure modes — spurious correlation, contradictory knowledge, constrained generalization — and returns a reliability score, verdict, and evidence. The confidence layer threat-score/dossier/report don't expose.
$0.20 USDC
ot-intel-api.onrender.com
Compliance gap mapping for a CVE or threat actor across 11 frameworks: NERC CIP, IEC 62443, NIST 800-82, NIST CSF 2.0, CISA CPG, Saudi NCA OTCC, UAE NESA IA. Pass ?cve_id=CVE-2023-38802 or ?actor=SANDWORM, optionally &framework=<value> to filter. Returns triggered controls (e.g. CIP-007-6 R2, IEC 62443-3-3 SR 5.1), status (NON_COMPLIANT_IF_UNMITIGATED / REVIEW_REQUIRED), required action, and compensating controls. For automated compliance reporting agents on cron.
$0.04 USDC
ot-intel-api.onrender.com
OT-contextualised CVE triage for ICS/SCADA. Pass ?id=CVE-XXXX-XXXX. Returns OT-adjusted severity, cyber-physical impact, patch feasibility, CISA KEV status, and prioritised action. DeepSeek-enriched with live NVD and CISA-KEV data.
$0.02 USDC
ot-intel-api.onrender.com
ICS sector change feed — only what is NEW in the last N days. Pass ?sector=water&days=7. Returns new CVEs, new CISA advisories, and new actor activity since the last call. Designed for cron-based monitoring agents. Eliminates redundant reprocessing.
$0.03 USDC
ot-intel-api.onrender.com
ICS detection artifact retrieval. Pass ?target=PIPEDREAM or ?target=SANDWORM&format=sigma. Returns YARA/Sigma rules for the target malware or actor, sourced from public corpus (Florian Roth signature-base, CISA advisories) with validated:true, or DeepSeek-synthesised with validated:false. Designed for automated threat hunting pipelines that commit rules to SIEMs and EDRs — validated:true rules are safe to deploy; validated:false require lab testing first.
$0.05 USDC
ot-intel-api.onrender.com
ICS/OT device exposure lookup. Pass ?vendor=siemens&model=s7-1200. Returns default credential risk, exposed OT protocols (Modbus/502, S7comm/102, DNP3/20000), exploitation notes, and hardening steps. Covers Siemens, Schneider, Rockwell, Honeywell, GE, Unitronics, Beckhoff.
$0.05 USDC
ot-intel-api.onrender.com
Deep actor intelligence dossier. Pass ?actor=SANDWORM. Fans out to actor, campaign, malware, ioc, asn, detection primitives and synthesises via DeepSeek. Returns full profile, infrastructure, IOC table, detection rules, kill chain mapping. Most comprehensive single-call artifact available.
$0.35 USDC
ot-intel-api.onrender.com
OT asset risk verdict. Pass ?vendor=siemens&model=s7-1500§or=energy&network=internet-facing. Returns risk_score (0-100), risk_level, escalate (boolean), recommended_action, active CVEs, and threat actors. Optional firmware param enables firmware-specific CVE matching. Cached 1 hour.
$0.05 USDC
ot-intel-api.onrender.com
IOC enrichment with ICS campaign context. Pass ?value=1.2.3.4&type=ip or type=domain. Queries AlienVault OTX, AbuseIPDB, and DeepSeek CTI for OT campaign association. Returns verdict on whether the IOC is linked to ICS-targeting campaigns.
$0.01 USDC
ot-intel-api.onrender.com
LinkedIn post for CTI/ICS security audience. Pass ?actor=VOLTZITE or ?cve=CVE-XXXX-XXXX. Fans out to actor or cve + advisory. Returns hook line, 3-5 intelligence bullets, call to action, hashtags. Ready to publish. Ideal for security practitioners and threat intelligence teams sharing findings.
$0.15 USDC
ot-intel-api.onrender.com
ICS malware encyclopedia. Pass ?name=PIPEDREAM. Returns capabilities, targeted OT protocols, attributed actor, affected vendors, detection signatures, and MITRE ATT&CK ICS techniques. Covers PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY.
$0.02 USDC
ot-intel-api.onrender.com
Prescriptive D3FEND-mapped mitigation guidance for OT/ICS threats. Pass one of ?actor=<threat actor name>, ?cve_id=<CVE ID>, or ?technique_id=<MITRE ATT&CK ICS technique ID e.g. T0836>, optionally with &vendor_stack=<vendor/product context e.g. Schneider Modicon>. Returns matched ATT&CK ICS techniques mapped to D3FEND defensive countermeasures with priority and rationale, plus prescriptive architecture recommendations. DeepSeek-synthesised, ICD-203 estimative language.
$0.20 USDC
ot-intel-api.onrender.com
OT/ICS patch feasibility for a CVE. Pass ?id=CVE-XXXX-XXXX. Returns patch availability, OT-safe workarounds, patch complexity per ICS layer, estimated downtime, safe-to-patch-live flag, deployment strategy, and risk-vs-disruption score 1-10.
$0.05 USDC
ot-intel-api.onrender.com
Synthesised Markdown threat actor report for ICS/OT. Pass ?actor=CHERNOVITE§or=energy. Fans out to actor, campaign, malware, advisory, detection primitives internally (no extra charge) and synthesises via DeepSeek. Returns executive summary, TTPs, campaigns, malware, recommended actions. TLP: WHITE.
$0.25 USDC
ot-intel-api.onrender.com
Board/GRC-level portfolio risk aggregator. Pass sector and region. Aggregates the same deterministic capability x opportunity x intent scoring used by /ot/threat-score across the actors relevant to that sector, ranks them, and returns a DeepSeek-written executive summary (BLUF structure, ICD-203 language). Optional compliance_framework noted qualitatively in the narrative. Portfolio-level companion to /ot/threat-score — for vCISO agents and GRC/board-reporting automation.
$0.40 USDC
ot-intel-api.onrender.com
Sector situation report. Pass ?sector=energy&period=30. Fans out to actor/sector, advisory, campaign, delta, compliance primitives. Returns 30-day threat landscape, top actors, new advisories, what changed, compliance posture, recommended priorities. Designed for weekly security briefing automation.
$0.35 USDC
ot-intel-api.onrender.com
Capability x opportunity x intent threat score for an actor-target pairing. Pass actor, sector, region, vendor_stack. Deterministic scoring: actor/CVE/campaign data plus GDELT tension and OFAC sanctions pressure. Not LLM-generated.
$0.04 USDC
ot-intel-api.onrender.com
OT/ICS supply-chain vendor risk assessment. Pass ?vendor=(name) e.g. Schneider Electric, Siemens, Rockwell Automation, optionally &product=(line) e.g. Modicon. Returns risk tier, confidence, cited CVEs (KEV/EPSS), threat actors with historical targeting interest, and supply-chain mitigation recommendations. DeepSeek-synthesised, ICD-203 language. Certain restricted-license sources excluded.
$0.15 USDC
ot-intel-api.onrender.com
X/Twitter thread (5-7 posts) for an ICS actor or CVE. Pass ?actor=XENOTIME or ?cve=CVE-XXXX-XXXX. Fans out to actor or cve. Returns thread array: hook post, intel posts with ATT&CK IDs and affected OT systems, mitigation post, hashtag post. Each post under 280 characters.
$0.10 USDC