{"uid":"cap_4SsyXW2iPKe6nfsyffG_z","slug":"telesint-api-onrender-com-c2adaec8","name":"TeleSint Pre-Attack Intent Signals API","description":"Pre-attack intent signals from Telegram: access sales, 0days, ransomware targeting. Filters: sector, country, organization, intent_type(access_sale|0day|ransomware|exploit), limit. Signals appear before attacks.","url":"https://telesint-api.onrender.com/intent","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"limit":{"type":"number","description":"Page size, default 20, max 100"},"offset":{"type":"number","description":"Pagination offset, default 0"},"sector":{"type":"string","description":"Targeted sector: finance | healthcare | government | energy | retail"},"country":{"type":"string","description":"Targeted country keyword, e.g. us | uk | de | fr"},"intent_type":{"type":"string","description":"Signal type: access_sale | 0day | ransomware | exploit | recruitment"},"organization":{"type":"string","description":"Targeted organization name partial match"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"items":[{"id":"i1n2t3e4-n5t6-7890-abcd-intent789012","ts":"2026-05-27T07:22:00Z","tlp":"WHITE","iocs":[{"type":"url","value":"https://exploit[.]in/threads/healthcare-access","context":"Access sale listing"}],"tags":["access-sale","healthcare","vpn","initial-access-broker"],"ttps":[{"id":"T1078","name":"Valid Accounts","tactic":"Initial Access"},{"id":"T1110","name":"Brute Force","tactic":"Credential Access"}],"target":{"sectors":["healthcare"],"countries":["US"],"organizations":[]},"channel":"https://t[.]me/ctifeeds","summary":"Threat actor selling VPN access to US healthcare network: 5,000 employee credentials, domain admin included","category":"intent","severity":"critical","confidence":72}],"limit":20,"total":3,"offset":0,"source":"TeleSint","endpoint":"intent"}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{}}},"response":{"items":[{"id":"d78f29e11e6614ae","ts":"2026-05-27T19:39:13.000Z","tlp":"GREEN","iocs":[],"tags":["phishing","AI","autonomous operations"],"ttps":[],"actor":{"name":null,"aliases":[],"motivation":null,"nation_state":null},"msg_id":250921,"target":{"sectors":[],"countries":[],"organizations":[]},"channel":"https://t.me/ctinow","summary":"Discusses the evolution of AI-driven phishing from broad campaigns to autonomous operations.","category":"intent","raw_text":"The AI Phishing Revolution: From Spray-and-Pray to Autonomous Operations\nhttps://ift.tt/WjM63fK","severity":"medium","confidence":50,"translated":false,"ingested_at":"2026-05-28T01:45:50.198Z","source_language":"en"},{"id":"9e47f197a6600ac4","ts":"2026-05-27T18:44:18.000Z","tlp":"GREEN","iocs":[],"tags":["AI","exploit development","scanner detection"],"ttps":[],"actor":{"name":null,"aliases":[],"motivation":null,"nation_state":null},"msg_id":250917,"target":{"sectors":[],"countries":[],"organizations":[]},"channel":"https://t.me/ctinow","summary":"AI-assisted exploit development is outpacing scanner detection capabilities.","category":"intent","raw_text":"AI-Assisted Exploit Development Outpaces Scanner Detection\nhttps://ift.tt/jZh5do9","severity":"medium","confidence":50,"translated":false,"ingested_at":"2026-05-28T01:46:03.896Z","source_language":"en"},{"id":"6ba1dcd77e90503d","ts":"2026-05-27T09:02:27.000Z","tlp":"AMBER","iocs":[{"type":"url","value":"https[://]demonforums[.]net/Thread-Non-vbv-cc-Apple-Pay-CC--205651","context":"Link to a thread on DemonForums selling non-VBV credit cards for Apple Pay."}],"tags":["carding","non-vbv","apple pay","demonforums","credit card fraud"],"ttps":[],"actor":{"name":null,"aliases":[],"motivation":"Financial gain","nation_state":null},"msg_id":130698,"target":{"sectors":["Financial"],"countries":[],"organizations":[]},"channel":"https://t.me/ctifeeds","summary":"A forum post on DemonForums advertises non-VBV credit cards for Apple Pay, indicating intent to sell stolen credit card data.","category":"intent","raw_text":"DemonForums - Non vbv cc Apple Pay CC ? https://demonforums.net/Thread-Non-vbv-cc-Apple-Pay-CC--205651","severity":"high","confidence":80,"translated":false,"ingested_at":"2026-05-28T02:04:04.382Z","source_language":"en"},{"id":"30ea7f3c9b4319f8","ts":"2026-05-26T22:03:20.000Z","tlp":"GREEN","iocs":[],"tags":["zero-day","exploit disclosure","GitLab","GitHub","Microsoft","platform ban"],"ttps":[],"actor":{"name":"Nightmare-Eclipse","aliases":[],"motivation":null,"nation_state":null},"msg_id":689,"target":{"sectors":[],"countries":[],"organizations":["Microsoft"]},"channel":"https://t.me/intcyberdigest","summary":"Security researcher Nightmare-Eclipse removed from GitLab after GitHub account was wiped for publicly dropping zero-day PoCs targeting Microsoft products, signaling platform policy enforcement against unpatched exploit disclosure.","category":"intent","raw_text":"‼️🚨 Security researcher \"Nightmare-Eclipse\" has now also been removed from GitLab..\n\nThis follows their GitHub being wiped last week after they publicly dropped zero-day PoCs targeting Microsoft products.\n\nThe message from major code hosts is clear: drop unpatched exploits in public, lose the platform.","severity":"medium","confidence":85,"translated":false,"ingested_at":"2026-05-28T11:58:36.611Z","source_language":"en"},{"id":"174fd0aa1e876c06","ts":"2026-05-12T16:35:15.000Z","tlp":"AMBER","iocs":[{"type":"url","value":"https[://]github[.]com/Nightmare-Eclipse","context":"GitHub profile of the threat actor releasing Windows 0-days"}],"tags":["0-day","Windows","GitHub","Microsoft"],"ttps":[],"actor":{"name":"Nightmare-Eclipse","aliases":[],"motivation":null,"nation_state":null},"msg_id":8842,"target":{"sectors":[],"countries":[],"organizations":[]},"channel":"https://t.me/vxunderground","summary":"A threat actor known for releasing Microsoft 0-days has created two new GitHub repos with ominous names, indicating upcoming Windows 0-day releases.","category":"intent","raw_text":"Big news for Blue Team nerds\n\nThat nerd who released those Microsoft 0days has created two new repos on GitHub with spooky sounding names indicating they will be releasing two new Windows 0days.\n\nVery cool\n\nhttps://github.com/Nightmare-Eclipse","severity":"high","confidence":70,"translated":false,"ingested_at":"2026-05-28T01:42:11.827Z","source_language":"en"}],"total":5,"source":"TeleSint","endpoint":"intent"}},"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_PHQ8PnhwleYhJGj4IONTe","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves pre-attack intent signals from Telegram channels, including access sales, zero-day listings, ransomware targeting, and exploit discussions, before attacks materialize.","exampleAgentPrompt":"Pull the latest pre-attack intent signals from Telegram for the healthcare sector in the US — specifically access_sale and ransomware intent types, limit to 20 results — I want to see if anyone is targeting hospital organizations before anything goes live.","exampleUseCases":[{"title":"Early warning for financial sector","prompt":"Check Telegram CTI channels for any pre-attack intent signals targeting financial sector companies in Germany right now — I want to see access sales, zero-day listings, and ransomware targeting announcements before any of those threats go live against banks or insurance firms."},{"title":"Monitor critical infrastructure threats","prompt":"Pull the latest Telegram intent signals for critical infrastructure — specifically energy and utilities in the US — I need to know if any threat actors are advertising access or planning ransomware hits on power grids or water systems before anything materializes."},{"title":"Detect zero-day exploit advertisements","prompt":"Search Telegram CTI channels for any active zero-day exploit listings or exploit-in-the-wild discussions from the last 48 hours — I want to see what vulnerabilities threat actors are currently advertising or trading so we can prioritize our patching before those exploits get weaponized."}],"resultDescription":"Returns a list of intent signal items sourced from Telegram CTI channels, each describing a pre-attack indicator such as an access sale, zero-day listing, ransomware targeting announcement, or exploit discussion, filtered by the requested sector, country, organization, and intent type.","failureModes":["No signals found matching the specified filters — returns empty results list","Invalid intent_type enum value causes a 400 bad request error","Rate limiting or payment failure results in 402 or 429 response","Service temporarily unavailable on Render.com free tier cold start — returns 503","Unrecognized country or sector value may return empty or unfiltered results"],"whenToPreferThis":"Use this endpoint when you need early warning signals specifically sourced from Telegram channels about imminent cyberattacks, access sales, or ransomware targeting — before attacks are publicly reported. Prefer this over generic threat feeds when you want pre-attack intelligence with Telegram-sourced provenance and need to filter by sector, geography, or specific intent type like 0day or ransomware.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:45:45.954Z","isFirstParty":false}