{"uid":"cap_IkAqzNtjvQgWy7X85mgRJ","slug":"ot-ics-d3fend-mitigation-map-35ef2b92","name":"OT/ICS D3FEND Mitigation Map","description":"Prescriptive D3FEND-mapped mitigation guidance for OT/ICS threats. Pass one of ?actor=<threat actor name>, ?cve_id=<CVE ID>, or ?technique_id=<MITRE ATT&CK ICS technique ID e.g. T0836>, optionally with &vendor_stack=<vendor/product context e.g. Schneider Modicon>. Returns matched ATT&CK ICS techniques mapped to D3FEND defensive countermeasures with priority and rationale, plus prescriptive architecture recommendations. DeepSeek-synthesised, ICD-203 estimative language.","url":"https://ot-intel-api.onrender.com/ot/mitigation-map","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":[],"properties":{"actor":{"type":"string","description":"Threat actor name e.g. SANDWORM. At least one of actor, cve_id, or technique_id is required."},"cve_id":{"type":"string","description":"CVE identifier. At least one of actor, cve_id, or technique_id is required."},"technique_id":{"type":"string","description":"MITRE ATT&CK ICS technique ID e.g. T0836. At least one of actor, cve_id, or technique_id is required."},"vendor_stack":{"type":"string","description":"Optional vendor/product context e.g. Schneider Modicon."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"tlp":"TLP:CLEAR","actor":"SANDWORM","cve_id":null,"confidence":"moderate","mitigations":[{"attack_technique_id":"T0836","attack_technique_name":"Modify Parameter","d3fend_countermeasures":[{"id":"D3-PSMD","name":"Process Segment Monitoring / Deviation Detection","priority":"high","rationale":"Detects unauthorized setpoint changes."}]}],"vendor_stack":"Schneider Modicon","architecture_recommendations":["Deploy baseline deviation monitoring on Modicon controller parameter writes."]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Ez2n42qLuAA8Ds5AHiHcN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns MITRE ATT&CK ICS techniques mapped to D3FEND defensive countermeasures with prioritized prescriptive remediation guidance, given a threat actor, CVE, or technique ID.","exampleAgentPrompt":"What D3FEND mitigations should we prioritize for SANDWORM tactics in our Schneider Modicon environment — give me the ATT&CK ICS techniques they use and prescriptive architecture recommendations.","exampleUseCases":null,"resultDescription":"A structured response containing matched ATT&CK ICS techniques relevant to the queried actor, CVE, or technique ID, each mapped to specific D3FEND defensive countermeasures with priority rankings and rationale, plus prescriptive OT/ICS architecture hardening recommendations. Language follows ICD-203 estimative standards (e.g. 'likely', 'almost certainly').","failureModes":["No recognized threat actor, CVE, or technique ID provided — returns error requiring at least one of actor, cve_id, or technique_id","Unknown or misspelled actor name not in knowledge base — may return empty or low-confidence results","CVE not mapped to any ICS technique — returns limited or no D3FEND countermeasures","Rate limiting or service unavailability from Render.com hosting — HTTP 429 or 503","Payment not processed — HTTP 402 blocking access"],"whenToPreferThis":"Use this endpoint when you need prescriptive, D3FEND-framework-aligned defensive guidance specifically for OT/ICS environments, especially when starting from a known threat actor, CVE, or ATT&CK ICS technique ID. Prefer this over generic SIEM or IT security advice endpoints when the target environment includes industrial control systems, PLCs, SCADA, or similar OT infrastructure. Particularly valuable when vendor stack context (e.g. Schneider, Siemens) is known and can refine recommendations.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:45:27.047Z","isFirstParty":false}