{"uid":"cap_--T4DNPavGpMJjlF74ExK","slug":"radhikachain-crowdsec-threat-intelligence-feed-de8360e7","name":"RadhikaChain CrowdSec Threat Intelligence Feed","description":"Telemetria de cadena, inteligencia de defensa y computo verificable (Halo2, Nova, Plonky3). Pago por peticion en USDC nativo en Base (eip155:8453) mediante x402 v2 scheme exact; sin cuenta ni suscripcion. Catalogo canonico: GET /.well-known/x402.","url":"https://x402.radhikachain.xyz/amenazas/crowdsec","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"type":"object","properties":{"body":{"type":"object","additionalProperties":true},"queryParams":{"type":"object","additionalProperties":true}}},"output":{"type":"object","properties":{"example":{"type":"object","additionalProperties":true}}}}},"responseSchema":{"type":"json","example":{"fuente":"sensor XDP en la NIC (eBPF), no contadores de iptables","amenazas":[{"ip":"8.103.58.198","ttl":45,"puertos":[22,8402,8151,8332,5000,3000,8788,8413,9103],"sondeos":665179,"flags_tcp":[16,2,24,17,4,20,25],"so_probable":"linux/unix","primer_visto":1512360412807002,"ultimo_visto":2360929756865408,"clasificacion":"barrido de puertos","puertos_distintos":9},{"ip":"3.38.236.54","ttl":47,"puertos":[3000],"sondeos":10156,"flags_tcp":[2,4,16,24,17],"so_probable":"linux/unix","primer_visto":2078920099453734,"ultimo_visto":2186077586730334,"clasificacion":"sondeo insistente","puertos_distintos":1}],"diferencia":"cada entrada trae IP, puertos, flags TCP y TTL: accionable en un firewall. Los contadores agregados no.","ips_distintas":1819,"eventos_totales":811757}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"3.0888","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$3.0888/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"3.0888","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"3.0888","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_B4igi7GGFkdcJZqTsIWbR","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"3.0888","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns real-time per-IP threat intelligence from CrowdSec sensors, including ports probed, TCP flags, TTL, OS fingerprint, and attack classification, sourced from eBPF/XDP kernel telemetry.","exampleAgentPrompt":"Pull the latest CrowdSec threat intelligence from RadhikaChain right now — I need the full list of active attacker IPs with their probed ports, TCP flags, TTL, and attack classification so I can push firewall block rules.","exampleUseCases":[{"title":"Automated firewall rule generation","prompt":"Fetch the current threat feed from RadhikaChain's CrowdSec endpoint and give me the list of attacker IPs with their ports and TCP flags — I want to push those straight into my firewall block list."},{"title":"SOC dashboard threat enrichment","prompt":"Pull the latest CrowdSec sensor data from RadhikaChain — I need each attacking IP with its OS fingerprint, first and last seen timestamps, and classification like port sweep or persistent probe so I can enrich our SOC dashboard."},{"title":"Network intrusion investigation","prompt":"Get me the current RadhikaChain CrowdSec threat intel snapshot — specifically any IPs that have probed more than 500,000 times or hit more than 5 distinct ports, so I can prioritize which ones to investigate first."}],"resultDescription":"A JSON object containing a list of threat entries, each with: attacker IP address, TTL, list of probed ports, total probe count, TCP flag codes, probable OS, first-seen and last-seen timestamps (microseconds), and attack classification (e.g. port sweep, persistent probe). Also includes aggregate counts of distinct IPs and total events, plus a field explaining the data advantage over aggregated counters.","failureModes":["Payment not included or invalid x402 USDC payment header — request rejected with 402","Insufficient USDC balance on Base (eip155:8453) — payment failure","Sensor data temporarily unavailable — may return empty threat list","Rate limiting if payment is not accepted by the facilitator","Network timeout reaching the eBPF/XDP telemetry backend"],"whenToPreferThis":"Choose this endpoint when you need granular, per-IP firewall-actionable threat intelligence with TCP-level detail (flags, TTL, port lists, OS fingerprint) rather than aggregated block counts. It is specifically sourced from eBPF/XDP kernel sensors (not iptables counters), making it higher fidelity for IDS/firewall rule generation. Prefer this over generic threat feeds when you need behavioral classification (port sweep vs persistent probe) and microsecond-precision timestamps per attacker IP, and when you are comfortable with pay-per-request USDC micropayments on Base via x402.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:51:19.308Z","isFirstParty":false}