{"uid":"cap_6_40vYHtTjl8n3t249C0y","slug":"ot-control-loop-threat-hunt-rmm-lotl-detection-a7d47e43","name":"OT Control-Loop Threat Hunt – RMM/LotL Detection","description":"Flags control-loop recon patterns and living-off-the-land/RMM-tool abuse from caller-submitted process/command observations. Pass observed_processes? and/or observed_commands? (comma-separated, max 40 combined), optional zone (OT/IT/DMZ). Fully deterministic keyword matching, no LLM. Grounded in CyberAgentX and AgenticCyOps (arXiv 2603.09134). ADVISORY ONLY — never executes containment or any network action.","url":"https://ot-intel-api.onrender.com/ot/agentic/threat-hunt/control-loop","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":[],"properties":{"zone":{"type":"string","description":"Asset zone: OT, IT, or DMZ. Any RMM/LOTL match on OT is always scored HIGH."},"observed_commands":{"type":"string","description":"Comma-separated command strings observed. Must not contain literal commas within a command."},"observed_processes":{"type":"string","description":"Comma-separated process/tool names observed. At least one of observed_processes or observed_commands is required."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.15","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.15/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_GmLmeaVhZbKMH2JlStKPV","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.15","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Detects control-loop reconnaissance patterns and living-off-the-land/RMM tool abuse from submitted OT/ICS process names and command strings using deterministic keyword matching.","exampleAgentPrompt":"I'm seeing these processes running in our OT zone — psexec.exe, mstsc.exe, nmap — and these commands: 'net use \\\\plc01\\admin$, tasklist /svc'. Can you check if any of these look like control-loop recon or RMM tool abuse in an OT environment?","exampleUseCases":[{"title":"SOC triage of suspicious OT process list","prompt":"Our ICS SOC just captured this process list from a field device in the OT zone: psexec.exe, AnyDesk.exe, cmd.exe, schtasks.exe — can you flag any control-loop recon patterns or LotL abuse risks?"},{"title":"Alert enrichment for ICS command anomaly","prompt":"We got an alert on these commands from a SCADA server in the DMZ: 'wmic process call create, reg query HKLM\\SOFTWARE, net localgroup administrators'. Can you tell me if these look like living-off-the-land techniques targeting control systems?"},{"title":"Pre-incident hunt during red team exercise","prompt":"During our red team exercise in the IT zone, the team ran these tools: ScreenConnect, mimikatz, powershell -enc. Can you check whether this looks like RMM abuse or control-loop reconnaissance based on the OT threat intel patterns?"}],"resultDescription":"Returns a structured advisory report listing matched threat indicators per submitted process/command, severity scores (with OT-zone matches always rated HIGH for RMM/LotL hits), identified technique categories (control-loop recon, RMM abuse, LotL), and associated threat context grounded in CyberAgentX/AgenticCyOps research. No containment or network actions are taken — output is advisory only.","failureModes":["Missing both observed_processes and observed_commands returns a validation error requiring at least one","More than 40 combined entries triggers a limit error","Invalid zone value (not OT/IT/DMZ) may be ignored or cause a parameter error","Commas within individual command strings corrupt parsing due to comma-separated format requirement","Service cold-start on Render free tier may cause initial latency or timeout","Payment failure via x402 protocol results in 402 response and no analysis"],"whenToPreferThis":"Choose this endpoint when you need fast, deterministic (no LLM hallucination risk) detection of RMM tool abuse or living-off-the-land techniques in OT/ICS/SCADA environments. Prefer it over generic EDR or LLM-based analysis when you need reproducible, grounded results tied to published OT threat research (CyberAgentX/AgenticCyOps). Best suited for SOC automation pipelines, alert enrichment, and real-time threat hunting in industrial control system contexts where zone-aware severity (OT always HIGH) matters.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:46:39.943Z","isFirstParty":false}