{"uid":"cap_68LIomLDdxeOWN59QqMIg","slug":"ot-intel-api-onrender-com-0cbb849d","name":"OT Intel API – ICS Threat Actor Profile Lookup","description":"ICS threat actor profile. Pass ?name=SANDWORM. Returns MITRE ATT&CK ICS techniques, known malware, attribution, physical impact, targeted sectors, and OT detection recommendations. Alias lookup supported: Volt Typhoon→VOLTZITE, APT44→SANDWORM. Covers all Dragos Activity Groups.","url":"https://ot-intel-api.onrender.com/ot/actor","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["name"],"properties":{"name":{"type":"string","description":"Actor name or alias e.g. VOLTZITE, SANDWORM, XENOTIME, Volt Typhoon, APT44"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"mitre_id":"G0034","freshness":"2025-05-22T10:00:00.000Z","attribution":"Russia — GRU Unit 74455","data_sources":["MITRE-ATT&CK-ICS","Dragos-ICS-Threat-Intelligence"],"canonical_name":"SANDWORM","physical_impact":"CONFIRMED DESTRUCTIVE","targeted_sectors":["energy","water","government"]}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"name":"SANDWORM"}}},"response":{"_type":"actor","query":{"name":"SANDWORM"},"aliases":["Sandworm Team","ELECTRUM","Telebots","IRON VIKING","BlackEnergy (Group)","Quedagh","Voodoo Bear","IRIDIUM","Seashell Blizzard","FROZENBARENTS","APT44"],"mitre_id":null,"freshness":"2026-06-03T18:13:59.965Z","mitre_url":null,"attribution":"Russia — GRU Unit 74455","known_tools":[],"data_sources":["MITRE-ATT&CK-ICS","DeepSeek-CTI-Analysis"],"known_malware":[{"id":null,"name":"Bad Rabbit","type":"malware","description":"[Bad Rabbit](https://attack.mitre.org/software/S0606) is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. [Bad Rabbit](https://attack.mitre.org/software/S0606) "},{"id":null,"name":"VPNFilter","type":"malware","description":"[VPNFilter](https://attack.mitre.org/software/S1010) is a multi-stage, modular platform with versatile capabilities to support both intelligence-collection and destructive cyber attack operations. [VP"},{"id":null,"name":"Industroyer","type":"malware","description":"[Industroyer](https://attack.mitre.org/software/S0604) is a sophisticated malware framework designed to cause an impact to the working processes of Industrial Control Systems (ICS), specifically compo"},{"id":null,"name":"Industroyer2","type":"malware","description":"[Industroyer2](https://attack.mitre.org/software/S1072) is a compiled and static piece of malware that has the ability to communicate over the IEC-104 protocol. It is similar to the IEC-104 module fou"},{"id":null,"name":"BlackEnergy","type":"malware","description":"[BlackEnergy](https://attack.mitre.org/software/S0089) is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create bot"},{"id":null,"name":"NotPetya","type":"malware","description":"[NotPetya](https://attack.mitre.org/software/S0368) is malware that was used by [Sandworm Team](https://attack.mitre.org/groups/G0034) in a worldwide attack starting on June 27, 2017. While [NotPetya]"},{"id":null,"name":"KillDisk","type":"malware","description":"[KillDisk](https://attack.mitre.org/software/S0607) is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable. It was first observed as a component of [BlackEnergy"}],"canonical_name":"Sandworm Team","related_groups":[],"cisa_advisories":[],"physical_impact":"CONFIRMED DESTRUCTIVE","targeted_sectors":["Energy","Electricity","Government","Transportation","Financial Services"],"attack_techniques":[{"id":null,"url":null,"name":"Command-Line Interface","tactic":"execution"},{"id":null,"url":null,"name":"Exploit Public-Facing Application","tactic":"initial-access"},{"id":null,"url":null,"name":"Connection Proxy","tactic":"command-and-control"}],"last_known_reporting":{"url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a","date":"2024-10","source":"CISA","summary":"CISA and FBI released a joint advisory detailing Sandworm's use of compromised routers and IoT devices for initial access to critical infrastructure, with observed targeting of energy and water sectors.","assessment":"ACTIVE"},"recommended_detections":["ET EXPLOIT Possible BlackEnergy HTTP C2 Beacon","ET MALWARE Industroyer IEC 61850 MMS Write Request","ET MALWARE KillDisk ICS Component Detection","ET TROJAN NotPetya Ransomware Payload Delivery","ET SCADA Suspicious Modbus Write to Multiple Coils"]}},"exampleRequest":{"name":"SANDWORM"},"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_fzJaEkQA5bnDsBUHWaJuu","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a comprehensive ICS/OT threat actor profile by name, including MITRE ATT&CK for ICS technique mappings, known malware/tools, attribution, physical impact assessment, and recommended OT detections.","exampleAgentPrompt":"Pull the full ICS threat actor profile for SANDWORM — I want their MITRE ATT&CK for ICS technique mappings, known malware and tools, physical impact assessment, and recommended OT detections.","exampleUseCases":null,"resultDescription":"Returns a structured threat actor profile including: ICS-specific MITRE ATT&CK T-code technique mappings, known malware and tools used by the actor, related threat groups, recommended OT/ICS detection strategies, attribution details, physical impact assessment, and last known activity dates — sourced live from the MITRE ATT&CK for ICS STIX bundle and CISA ICS advisories, enriched by DeepSeek.","failureModes":["Unknown or misspelled actor name with no alias match — returns empty or error response","MITRE ATT&CK or CISA upstream data unavailable — service may return partial results or timeout","Actor exists in enterprise ATT&CK but not in ICS-specific context — limited results returned","Render.com cold-start latency on first request after inactivity — slow response or timeout"],"whenToPreferThis":"Use this endpoint when you need ICS/OT-specific threat intelligence for a named threat actor, especially when you need MITRE ATT&CK for ICS T-code mappings, OT-relevant malware associations, physical impact context, or CISA ICS advisory linkage. Prefer this over generic CTI APIs when the use case involves industrial control systems, SCADA, or critical infrastructure defense. Supports alias resolution, making it useful even when only common names or alternate designations are known.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:37:27.748Z","isFirstParty":false}