{"uid":"cap_ypnFDAmOaM4wnNxghJxYc","slug":"ot-ics-ai-attack-feasibility-lookup-66fbd4b3","name":"OT/ICS AI Attack Feasibility Lookup","description":"Deterministic lookup against Cook et al. (ACM TOPS 2026) testing whether off-the-shelf LLMs generate working ICS attack code. Pass technique (name/ID, e.g. 'Brute Force I/O' or T0806), vendor (Siemens, Schneider Electric, Rockwell Automation — only these tested), and/or campaign (Industroyer2, Fuxnet, FrostyGoop, INCONTROLLER, Stuxnet, Triton). Only Network/Register-Tags techniques succeeded; 1.08% success rate; Claude excluded (stronger guardrails). No LLM in lookup path.","url":"https://ot-intel-api.onrender.com/ot/ai-attack-feasibility","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":[],"properties":{"vendor":{"type":"string","description":"Siemens, Schneider Electric, or Rockwell Automation — only these three vendors were tested in the study."},"campaign":{"type":"string","description":"Industroyer2, Fuxnet, FrostyGoop, INCONTROLLER, Stuxnet, or Triton."},"technique":{"type":"string","description":"MITRE ICS technique name or ID, e.g. 'Brute Force I/O' or T0806. At least one of technique, vendor, or campaign must be present."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"query":{"vendor":null,"campaign":null,"technique":"Brute Force I/O"},"source":"Cook, Stoica, Shah & Pezaros, ACM Trans. Priv. Sec. 29, 3, Article 31 (June 2026), DOI: 10.1145/3815116","technique_result":{"status":"llm_achievable","category":"Register and Tags","cvss_3_1":5.7,"id_status":"confirmed_current_matrix","cia_impact":{"integrity":true,"availability":true,"confidentiality":false},"technique_id":"T0806","technique_name":"Brute Force I/O","min_context_level":"High"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_4G0bN079qYBCcE0nusttM","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Looks up whether off-the-shelf LLMs can generate working ICS attack code for a given MITRE technique, vendor, or known campaign, based on a peer-reviewed study.","exampleAgentPrompt":"Using the Cook et al. AI attack feasibility study, look up whether off-the-shelf LLMs could generate working attack code for the Brute Force I/O technique (T0806) against Siemens equipment — I want to know if this is a realistic AI-assisted threat.","exampleUseCases":[{"title":"Assess AI threat for critical infrastructure","prompt":"Check the Cook et al. study to see if modern LLMs can actually generate working attack code for the Industroyer2 campaign — I need to know how serious the AI-assisted risk is for our SCADA systems."},{"title":"Evaluate vendor-specific AI attack vectors","prompt":"Using that peer-reviewed dataset, look up whether off-the-shelf LLMs succeeded in creating functional exploits for Schneider Electric gear, so I can prioritize our patching strategy accordingly."},{"title":"Identify feasible MITRE ICS techniques","prompt":"Query the Cook et al. research to find out which MITRE ICS techniques LLMs actually managed to weaponize — I want to focus our defense on the AI-generated threats that are empirically proven."}],"resultDescription":"Returns a deterministic lookup result from the Cook et al. (ACM TOPS 2026) dataset indicating whether LLMs succeeded in generating functional ICS attack code for the specified technique, vendor, and/or campaign, including success rates (overall 1.08%) and which technique categories (Network/Register-Tags only) proved feasible. No LLM inference occurs in the lookup path.","failureModes":["Missing all filter parameters (technique, vendor, campaign) — at least one required","Vendor not in tested set (only Siemens, Schneider Electric, Rockwell Automation) — returns no data or error","Campaign name not in tested set (Industroyer2, Fuxnet, FrostyGoop, INCONTROLLER, Stuxnet, Triton) — no match","Unrecognized MITRE technique name or ID — returns empty result","Service cold-start latency on Render free tier may cause initial delay"],"whenToPreferThis":"Use this endpoint when you need a fast, deterministic, research-backed answer on whether LLMs can realistically generate ICS attack code for a specific MITRE technique, vendor platform, or known ICS campaign — without invoking any LLM in the query path. Prefer this over general threat intelligence APIs when the specific question is about AI-assisted attack feasibility grounded in peer-reviewed empirical data.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:54:02.649Z","isFirstParty":false}