{"uid":"cap_OOgv_u5SdZTK3jjMuKFY4","slug":"ot-intel-api-ot-asset-exposure-risk-verdict-68ea69ad","name":"OT Intel API – OT Asset Exposure & Risk Verdict","description":"OT asset risk verdict. Pass ?vendor=siemens&model=s7-1500&sector=energy&network=internet-facing. Returns risk_score (0-100), risk_level, escalate (boolean), recommended_action, active CVEs, and threat actors. Optional firmware param enables firmware-specific CVE matching. Cached 1 hour.","url":"https://ot-intel-api.onrender.com/ot/exposure","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["vendor","model","sector","network"],"properties":{"model":{"type":"string","description":"Device model e.g. s7-1500, modicon-m340, controllogix"},"sector":{"type":"string","description":"Industrial sector e.g. energy, water, manufacturing, oil-and-gas"},"vendor":{"type":"string","description":"Vendor name e.g. siemens, schneider, rockwell, ge, honeywell"},"network":{"type":"string","description":"Network exposure: internet-facing | dmz | lan-only | air-gapped"},"firmware":{"type":"string","description":"Firmware version e.g. 2.9.2 (optional — enables firmware-specific CVE matching)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"model":"s7-1500","sector":"energy","vendor":"siemens","network":"internet-facing","escalate":true,"freshness":"2026-06-13T10:00:00Z","confidence":"high","risk_level":"critical","risk_score":87,"top_threat":"VOLTZITE pre-positioning via CVE-2023-38380","active_cves":3,"ttl_seconds":3600,"data_sources":["NVD","CISA-KEV","MITRE-ATT&CK-ICS","DeepSeek-CTI-Analysis"],"threat_actors":["VOLTZITE","SANDWORM"],"active_campaigns":2,"recommended_action":"isolate"}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"model":"s7-1500","sector":"energy","vendor":"siemens","network":"internet-facing","firmware":"2.9.2"}}},"response":{"model":"s7-1500","sector":"energy","vendor":"siemens","network":"internet-facing","escalate":true,"firmware":"2.9.2","freshness":"2026-06-16T17:40:26.519Z","confidence":"high","risk_level":"high","risk_score":78,"top_threat":"Internet-facing Siemens S7-1500 PLC in the energy sector is at high risk from known firmware vulnerabilities (CVE-2020-15782, CVE-2022-38465) that allow cryptographic key extraction and native code execution, combined with active targeting by state-sponsored groups like Dragonfly and Industroyer/CrashOverride malware.","active_cves":2,"ttl_seconds":3600,"data_sources":["MITRE-ATT&CK-ICS","OT-Intel-DB","DeepSeek-CTI-Analysis"],"threat_actors":["Dragonfly","APT33","MuddyWater","OilRig","Russian government cyber actors","LockBit","RansomHub"],"active_campaigns":3,"recommended_action":"patch"}},"exampleRequest":{"model":"s7-1500","sector":"energy","vendor":"siemens","network":"internet-facing","firmware":"2.9.2"},"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_m-H4JK7Owwn3ebF53uLGr","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a risk score, risk level, escalation flag, recommended action, active CVEs, and associated threat actors for an OT/ICS device identified by vendor, model, sector, and network exposure.","exampleAgentPrompt":"What's the risk verdict for a Siemens S7-1500 running firmware 2.9.2, deployed internet-facing in the energy sector — do I need to escalate, and what CVEs are active against it?","exampleUseCases":null,"resultDescription":"A JSON object containing: risk_score (0–100 integer), risk_level (e.g. critical/high/medium/low), escalate (boolean indicating whether immediate escalation is warranted), recommended_action (plain-text remediation or response guidance), a list of active CVEs relevant to the device, and known threat actor groups targeting it. Results are cached for 1 hour.","failureModes":["Missing required query parameters (vendor, model, sector, network) returns a 400 error","Unknown or unsupported vendor/model combination may return empty CVE list or low-confidence score","Firmware parameter mismatch may fall back to generic CVE matching without firmware-specific results","Service hosted on Render free tier may have cold-start latency or be unavailable","Payment not processed results in 402 response blocking access"],"whenToPreferThis":"Use this endpoint when you need a single aggregated risk verdict for a specific OT/ICS device — combining CVE exposure, threat actor intelligence, and network posture into one actionable score. Prefer this over raw CVE lookup endpoints when you want an escalation decision and recommended action rather than raw vulnerability data. Best suited for asset risk triage in ICS/SCADA environments across energy, water, manufacturing, and oil-and-gas sectors.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:41:48.295Z","isFirstParty":false}