{"uid":"cap_shs3TR6UmHcilxO7d2jTB","slug":"halowerk-netz-bgp-route-hijack-suspicion-detector-48373e8a","name":"Halowerk Netz BGP Route Hijack Suspicion Detector","description":"Collects the observable signs of a route hijack for one prefix and reports which of them are present, with the measurement behind each. Four signs carry different weight. RPKI invalidity is the only hard one: a ROA exists and does not authorise this announcement. An origin AS that appears in the current state but nowhere in the history window is the classic sign, and the response gives the historical origins so the change can be dated.","url":"https://netz.halowerk.com/v1/hijack-suspicion","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"prefix":{"type":"string","maxLength":60,"minLength":4},"expected_asn":{"type":"string","maxLength":15,"description":"The AS you expect to announce this prefix. Supplying it turns a general check into a targeted one."},"history_days":{"type":"integer","default":30,"maximum":180,"minimum":1}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.006","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.006/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_QkJhkuWE-gVbon_-T373d","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.006","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes a BGP prefix announcement for observable signs of a route hijack, scoring four weighted indicators including RPKI invalidity, unexpected origin AS, and historical origin changes.","exampleAgentPrompt":"Check prefix 192.0.2.0/24 announced by AS64496 for all signs of a BGP route hijack — I want to know if RPKI marks it invalid, whether that origin AS has ever been seen for this prefix before, and the full evidence behind each indicator.","exampleUseCases":[{"title":"ISP detecting unauthorized prefix takeover","prompt":"Someone seems to be announcing our prefix 203.0.113.0/24 from AS65001, but we only use AS64512 — can you check all the hijack suspicion indicators for that prefix and tell me if RPKI invalidates it and whether AS65001 has ever appeared in the routing history?"},{"title":"Security team investigating BGP anomaly alert","prompt":"We got an alert that prefix 198.51.100.0/24 has a new origin AS that wasn't there last month. Can you pull the hijack suspicion report for that prefix so I can see which warning signs are present and when the origin AS change first appeared?"},{"title":"Network operator validating a legitimate route change","prompt":"We just moved prefix 10.20.30.0/24 to a new upstream AS45678 and want to make sure it doesn't look like a hijack — can you run the hijack suspicion check and show me all four indicators with the measurements behind them?"}],"resultDescription":"A structured report listing up to four weighted hijack suspicion indicators: RPKI invalidity (hard indicator — ROA exists but does not authorize the announcement), unexpected origin AS not seen in historical records, and other observable signs. Each indicator states whether it is present and includes the underlying measurement or evidence, such as the list of historical origin ASes with approximate dates of change.","failureModes":["Prefix not found in BGP routing tables — no data returned","RPKI repository unavailable — RPKI indicator may be absent or stale","Origin AS with very short history window may produce false positives for new legitimate announcements","Malformed prefix CIDR input returns validation error","Rate limiting or payment failure returns 402 or 429 error"],"whenToPreferThis":"Use this endpoint when you need a consolidated, multi-signal hijack suspicion verdict for a single prefix in one call, rather than querying RPKI validity, AS path anomalies, and origin history separately. It is ideal for security monitoring pipelines, incident triage, and alerting workflows where you want weighted evidence rather than a single binary check. Prefer this over the standalone RPKI validation endpoint when historical origin AS context and composite scoring matter.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:31:54.025Z","isFirstParty":false}