{"uid":"cap_0kTud211OkN-Yhs6pHII5","slug":"domain-cyberattack-target-risk-scorer-0fc873c9","name":"Domain Cyberattack Target Risk Scorer","description":"Score a domain's probability of being an active or upcoming cyberattack target using a 6-signal correlation model (breach, infostealer, ransomware, session, CVE, and threat-actor targeting history). Call for proactive risk triage, not just after-the-fact breach checking.","url":"https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod/v1/payg/target-risk","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain to score (e.g. acme.com)"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.5","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.5/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.5","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.5","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_QmlE2Xc4PmRjDlbO8ddO1","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.5","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scores a domain's probability of being an active or upcoming cyberattack target using a 6-signal correlation model covering breach, infostealer, ransomware, session, CVE, and threat-actor targeting history.","exampleAgentPrompt":"Can you run a proactive cyberattack target risk assessment on acme.com and tell me the risk score, probability tier, and which of the six signals — breach, infostealer, ransomware, session, CVE, and threat-actor targeting — are firing?","exampleUseCases":[{"title":"Pre-attack vendor risk triage","prompt":"I'm doing a quarterly vendor security review. Can you score contoso.com for cyberattack target risk and tell me the probability tier and which signals are elevated? I want to flag it before anything happens, not after."},{"title":"Prioritizing internal domain exposure","prompt":"We have three business units on different domains — northwindtraders.com, fabrikam.com, and tailspintoys.com. Can you run a target risk score on each and rank them by how likely they are to be hit by a cyberattack in the near term?"},{"title":"Threat actor targeting check before M&A","prompt":"We're about to acquire a company and I need to know if their primary domain, woodgrovebank.com, is already on any threat actor radar. Can you get me the target risk score and flag any ransomware or CVE signals that are active?"}],"resultDescription":"Returns a JSON object containing the queried domain, a target_risk_score integer (0–100), a probability_tier string indicating attack likelihood category, and a signals array detailing the status of each of the six correlation signals (breach exposure, infostealer data, ransomware history, session compromise, CVE exposure, and threat-actor targeting history).","failureModes":["Missing or malformed domain input returns a validation error","Domain with no threat intelligence data may return a low score with empty signals array","Rate limiting or quota exhaustion returns an error if too many calls are made","Payment failure ($0.50 USDC per call) results in request rejection","Invalid domain format (e.g. bare IP or non-existent TLD) may return an error or zero-score result"],"whenToPreferThis":"Use this endpoint when you need proactive, forward-looking attack targeting risk rather than purely retrospective breach checking. It is especially valuable for security triage workflows where you want to prioritize which domains are most likely to be targeted next, vendor risk assessments, M&A due diligence, and threat hunting. Prefer this over a simple breach-check endpoint when you need multi-signal correlation including threat-actor history, ransomware gang activity, and CVE exposure together in a single score.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-16T12:39:29.281Z","isFirstParty":false}