{"uid":"cap_8s0jquhemGd5F-19TR5kL","slug":"ot-intel-api-yara-sigma-snort-detection-artifacts-083f1a65","name":"OT Intel API – YARA/Sigma/Snort Detection Artifacts","description":"ICS detection artifact retrieval. Pass ?target=PIPEDREAM or ?target=SANDWORM&format=sigma. Returns YARA/Sigma rules for the target malware or actor, sourced from public corpus (Florian Roth signature-base, CISA advisories) with validated:true, or DeepSeek-synthesised with validated:false. Designed for automated threat hunting pipelines that commit rules to SIEMs and EDRs — validated:true rules are safe to deploy; validated:false require lab testing first.","url":"https://ot-intel-api.onrender.com/ot/detection","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["target"],"properties":{"format":{"type":"string","description":"Rule format: yara | sigma | snort | all (default: all)"},"target":{"type":"string","description":"Malware or actor name e.g. PIPEDREAM, INDUSTROYER2, TRITON, SANDWORM, CHERNOVITE"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"target":"PIPEDREAM","freshness":"2026-06-19T10:00:00Z","signatures":[{"type":"YARA","source":"manual","raw_rule":"rule PIPEDREAM_INCONTROLLER_Loader { meta: ... strings: ... condition: ... }","rule_name":"PIPEDREAM_INCONTROLLER_Loader","validated":false,"ot_safe_note":"Synthesised from CISA advisory AA22-103A. Test against OT baseline before SIEM deployment.","target_layer":"engineering_workstation"}],"data_sources":["OT-Intel-DB","DeepSeek-CTI-Analysis"],"artifact_type":"malware","validated_count":0,"synthesised_count":1,"ot_safe_validation":"0 of 1 rules sourced from public corpus. Rules with validated:false require lab testing before production deployment."}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_OYj4fQW2ztlwEqq44InbG","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns YARA, Sigma, and/or Snort detection rules for named OT/ICS malware families and threat actors, enriched with OT safety notes and ATT&CK ICS context","exampleAgentPrompt":"Pull all detection rule formats — YARA, Sigma, and Snort — for the PIPEDREAM malware from the OT Intel API so I can deploy them in my industrial SOC SIEM.","exampleUseCases":[{"title":"ICS malware detection for NERC CIP","prompt":"Fetch me the validated Sigma rules for TRITON so I can add them to our control-system SIEM and make sure we're compliant with NERC CIP audit requirements."},{"title":"Threat hunting artifacts for engineering","prompt":"Get all YARA rules for SANDWORM that are safe to deploy on our engineering workstations, and flag anything that needs lab testing first before we push it live."},{"title":"Multi-format rule deployment for SOC","prompt":"Retrieve Snort, YARA, and Sigma detection rules for INDUSTROYER2 so I can ingest them into our automated threat hunting pipeline and cover all our ICS network layers."}],"resultDescription":"A JSON object containing one or more detection rule objects (YARA, Sigma, Snort) for the queried malware or actor, each with: rule name, raw rule text, source, validated flag, OT-safe deployment note, target OT layer (e.g. engineering_workstation), artifact type, freshness timestamp, and counts of validated vs synthesised rules. Includes a top-level OT safe validation summary warning if rules are AI-synthesised and not yet lab-validated.","failureModes":["Unknown malware or actor name returns empty signatures array or 404","Payment not received (402) — USDC micropayment on Base mainnet required before response","Rule format enum value invalid — must be yara, sigma, snort, or all","Synthesised rules (validated:false) may not match real traffic — requires lab testing before production deployment","Freshness lag — AI-synthesised rules may not reflect the most recent threat actor TTPs","Render.com cold start may cause initial latency spike"],"whenToPreferThis":"Use this endpoint when you need detection engineering artifacts (YARA/Sigma/Snort) specifically tuned for OT/ICS environments, with OT safety annotations and ATT&CK for ICS technique context. Prefer over generic threat intel APIs when targeting industrial SOC environments, NERC CIP compliance workflows, or when you need per-layer (e.g. engineering_workstation, historian) deployment guidance. Best for AI-driven SOC automation pipelines that need machine-readable detection rules for ICS malware like PIPEDREAM, TRITON, or INDUSTROYER2.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:43:30.226Z","isFirstParty":false}