{"uid":"cap_vp0gqoye8mZEnCPBhTOIP","slug":"ot-intel-api-ics-threat-score-19e0a9df","name":"OT Intel API — ICS Threat Score","description":"Capability x opportunity x intent threat score for an actor-target pairing. Pass actor, sector, region, vendor_stack. Deterministic scoring: actor/CVE/campaign data plus GDELT tension and OFAC sanctions pressure. Not LLM-generated.","url":"https://ot-intel-api.onrender.com/ot/threat-score","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["actor","sector","region","vendor_stack"],"properties":{"actor":{"type":"string","description":"ICS threat actor name e.g. SANDWORM, VOLTZITE, XENOTIME"},"region":{"type":"string","description":"Target region or country e.g. Europe, GCC, Ukraine"},"sector":{"type":"string","description":"Target sector e.g. energy, water, manufacturing"},"vendor_stack":{"type":"string","description":"Comma-separated OT/ICS vendors in the target environment e.g. Siemens,Schneider Electric. Pass 'none' if unknown."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"actor":"SANDWORM","intent":{"basis":["sector_history:direct","campaign_geography:match","geo_tension(Russia↔Europe):0.71 [moderate]","sanctions_pressure(Russia):0.60 [moderate]"],"score":0.52,"confidence":"moderate"},"region":"Europe","sector":"energy","coverage":1,"capability":{"basis":["physical_impact_tier:1","ttps_mapped:14","exploited_cves:3","vendor_stack_overlap:yes (documented: SIMATIC (vendor advisory))"],"score":0.82,"confidence":"moderate"},"confidence":"moderate","opportunity":{"basis":["cves_on_record:9","exploited_in_wild:2","avg_cvss:8.1"],"score":0.61,"confidence":"moderate"},"_methodology":"deterministic: product of capability x opportunity x intent (each 0-1), scaled to 0-100, where any leg with confidence:none has its exponent reduced from 1 to 0.3 so a data gap dampens the score instead of vetoing it outright. Identical to naive_product_score whenever coverage is 1 (no data gaps) — see exponents_applied. actor_record_quality:\"generic_descriptor\" means the queried name matches a known non-actor descriptive phrase (e.g. \"unknown cybercrime gang\") rather than a specific named threat actor — treat the score as noise, not a real assessment. See basis[] per leg.","data_sources":["OT-Intel-DB","GDELT Project (gdeltproject.org)","OFAC Sanctions List (US Treasury)"],"threat_score":26,"vendor_stack":["Siemens","Schneider Electric"],"exponents_applied":{"intent":1,"capability":1,"opportunity":1},"naive_product_score":26,"actor_record_quality":"named_entity"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.04","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.04/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.04","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.04","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_qrj0NunwuFzxNefiRHt-8","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.04","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a deterministic capability × opportunity × intent threat score for a specific ICS/OT threat actor targeting a given sector, region, and vendor stack.","exampleAgentPrompt":"What's the threat score for SANDWORM targeting the energy sector in Europe, where the environment runs Siemens and Schneider Electric OT equipment?","exampleUseCases":[{"title":"Water utility breach risk assessment","prompt":"Score the threat from VOLTZITE against our water treatment facilities in the Middle East—we're running Schneider Electric and Siemens PLCs. How dangerous is this actor right now?"},{"title":"Manufacturing sector OT attack likelihood","prompt":"We operate automotive plants across Southeast Asia with Rockwell CompactLogix controllers. Give me a threat score for XENOTIME targeting us—I need to know if we should escalate our incident response posture."},{"title":"Oil and gas regional threat prioritization","prompt":"Our oil and gas assets in Ukraine use Siemens industrial control systems. What's the current threat level from CHERNOVITE and other known ICS actors in that region? Should we be moving critical assets offline?"}],"resultDescription":"A structured threat score combining capability, opportunity, and intent dimensions for the specified actor-target pairing, derived deterministically from actor/CVE/campaign data, GDELT geopolitical tension signals, and OFAC sanctions pressure — not LLM-generated.","failureModes":["Unknown or misspelled actor name returns low-confidence or null score","Unsupported sector or region string returns validation error","Missing required query parameters (actor, sector, region, vendor_stack) returns 400 error","Render cold-start latency may cause timeout on first call","Payment not accepted or x402 flow fails returning 402 status"],"whenToPreferThis":"Use this endpoint when you need a fast, deterministic, non-LLM threat score for a specific ICS/OT actor against a defined sector, region, and vendor stack — especially when you need reproducible scoring driven by structured intelligence data (actor profiles, CVEs, GDELT, OFAC) rather than generative AI narrative output. Prefer this over generic cyber threat APIs when the target environment is specifically operational technology or industrial control systems.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:47:08.824Z","isFirstParty":false}