{"uid":"cap_daR-p0IOYcmG1SVd3r9Yn","slug":"ot-intel-api-ics-threat-actor-report-0af571ec","name":"OT Intel API – ICS Threat Actor Report","description":"Synthesised Markdown threat actor report for ICS/OT. Pass ?actor=CHERNOVITE&sector=energy. Fans out to actor, campaign, malware, advisory, detection primitives internally (no extra charge) and synthesises via DeepSeek. Returns executive summary, TTPs, campaigns, malware, recommended actions. TLP: WHITE.","url":"https://ot-intel-api.onrender.com/ot/report","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["actor"],"properties":{"actor":{"type":"string","description":"ICS threat actor name e.g. CHERNOVITE, SANDWORM, VOLTZITE, XENOTIME"},"sector":{"type":"string","description":"Optional sector focus e.g. energy, water, manufacturing"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"tlp":"WHITE","actor":"CHERNOVITE","sector":"energy","word_count":720,"generated_at":"2026-06-21T10:00:00.000Z","_composed_from":["ot/actor","ot/campaign","ot/malware","ot/advisory","ot/detection"],"report_markdown":"# Threat Report: CHERNOVITE\n## Executive Summary\nCHERNOVITE..."}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.25","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.25/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.25","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.25","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_jgydhtmYEwkTOjDz7vfmo","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.25","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Generates a comprehensive AI-enriched threat intelligence report for a named ICS/OT threat actor (e.g. CHERNOVITE, SANDWORM), covering campaigns, malware, advisories, and detection artifacts with MITRE ATT&CK ICS mapping","exampleAgentPrompt":"Pull a full OT threat intelligence report on CHERNOVITE focused on the energy sector — I need their campaigns, malware, MITRE ATT&CK ICS techniques, and any CISA advisories.","exampleUseCases":null,"resultDescription":"Returns a markdown-formatted threat report (~720 words) covering the requested ICS threat actor, including executive summary, campaign history, associated malware (e.g. PIPEDREAM, TRITON), CISA ICS-CERT advisories, MITRE ATT&CK for ICS technique mapping, IOC enrichment with OT campaign context, detection artifacts (YARA/Sigma), and TLP classification. Also includes metadata: generation timestamp, word count, and list of composed sub-reports.","failureModes":["Unknown or misspelled actor name returns empty or error response","Missing required 'actor' query parameter causes 400 bad request","Payment failure on Base mainnet (insufficient USDC) blocks access","Render.com cold start may cause first-request latency spike","Data freshness lag if upstream sources (CISA, NVD) are delayed","Rate limiting or micropayment processing errors on x402 protocol"],"whenToPreferThis":"Choose this endpoint when you need a consolidated, AI-enriched OT/ICS threat actor dossier in a single call rather than piecing together raw feeds. Ideal for industrial SOC automation, AI agent pipelines needing structured OT intelligence, or rapid threat briefing on named ICS actors like SANDWORM or CHERNOVITE. Best when you need cyber-physical impact context and MITRE ATT&CK ICS mapping that generic CTI APIs lack.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:35:05.653Z","isFirstParty":false}