{"uid":"cap_SA09F_kgXf7NDkS9JS4F3","slug":"ot-intel-api-ics-threat-actor-x-post-thread-generator-c22dc430","name":"OT Intel API – ICS Threat Actor X-Post Thread Generator","description":"X/Twitter thread (5-7 posts) for an ICS actor or CVE. Pass ?actor=XENOTIME or ?cve=CVE-XXXX-XXXX. Fans out to actor or cve. Returns thread array: hook post, intel posts with ATT&CK IDs and affected OT systems, mitigation post, hashtag post. Each post under 280 characters.","url":"https://ot-intel-api.onrender.com/ot/xpost","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"cve":{"type":"string","description":"CVE ID (required if no actor)"},"actor":{"type":"string","description":"Actor name e.g. XENOTIME (required if no cve)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"thread":[{"text":"🧵 THREAD: XENOTIME (TRITON/TRISIS actor) activity update (1/6)","post_number":1,"character_count":68},{"text":"XENOTIME targets safety instrumented systems (SIS) — specifically Triconex controllers...","post_number":2,"character_count":142}],"post_count":6,"_composed_from":["ot/actor"]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_i0GzDc7-4c5J1PaOAoCCg","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Generates a Twitter/X-style multi-post thread on an OT/ICS threat actor or CVE, enriched with OT context, MITRE ATT&CK for ICS mapping, and cyber-physical impact analysis","exampleAgentPrompt":"Can you generate a Twitter thread about XENOTIME — the ICS threat actor behind the TRITON/TRISIS attacks on safety instrumented systems?","exampleUseCases":null,"resultDescription":"Returns a JSON object containing an array of numbered social media posts (thread), each with post text and character count, plus a total post_count field. The thread covers OT/ICS threat actor or CVE context formatted as a tweetstorm, referencing MITRE ATT&CK for ICS techniques and cyber-physical impact. Costs $0.10 USDC per call via x402 micropayment on Base mainnet.","failureModes":["Missing required query parameter: must supply either 'cve' (e.g. CVE-2022-12345) or 'actor' (e.g. XENOTIME) — returns error if neither provided","Unknown actor name or unrecognized CVE ID — may return empty thread or error response","Service hosted on Render free tier may experience cold-start latency or temporary downtime","Payment failure if USDC balance on Base mainnet is insufficient or x402 header is malformed","Rate limiting or 402 payment required if micropayment is not included"],"whenToPreferThis":"Use this endpoint when you need to produce a formatted, multi-post social media thread (X/Twitter style) about a specific ICS threat actor (SANDWORM, VOLTZITE, XENOTIME, etc.) or an OT-relevant CVE, with OT-adjusted severity, cyber-physical impact framing, and MITRE ATT&CK for ICS technique context already baked in. Prefer this over generic threat intel endpoints when the output format must be social-media-ready and OT/ICS-specific enrichment is required.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:40:43.837Z","isFirstParty":false}