{"uid":"cap_za6OxxkY-QhiyVPYLAt1w","slug":"telesint-api-onrender-com-c4e87506","name":"TeleSint IOC Feed","description":"IOC feed from Telegram CTI channels. Filters: type(ip|domain|url|hash|cve), severity, min_confidence, since, tlp, tag, channel, limit, offset. Returns items[] with iocs[], ttps[], confidence, severity, tlp, tags[].","url":"https://telesint-api.onrender.com/ioc","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"tag":{"type":"string","description":"Tag keyword filter, e.g. ransomware, cobalt-strike, apt"},"tlp":{"type":"string","description":"TLP classification: WHITE | GREEN | AMBER | RED"},"type":{"type":"string","description":"IOC type: ip | domain | url | md5 | sha1 | sha256 | cve"},"limit":{"type":"number","description":"Page size, default 20, max 100"},"since":{"type":"string","description":"ISO 8601 timestamp filter, e.g. 2026-05-01T00:00:00Z"},"offset":{"type":"number","description":"Pagination offset, default 0"},"channel":{"type":"string","description":"Partial match on source Telegram channel name"},"severity":{"type":"string","description":"Minimum severity: critical | high | medium | low | info"},"min_confidence":{"type":"number","description":"Minimum AI confidence score 0-100"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"items":[{"id":"f8a3c1d2-4b5e-4f6a-9c8d-1e2f3a4b5c6d","ts":"2026-05-27T14:32:00Z","tlp":"WHITE","iocs":[{"type":"url","value":"https://github[.]com/Nightmare-Eclipse/MiniPlasma","context":"Exploit repository"},{"type":"ip","value":"185.220[.]101.47","context":"C2 callback address"},{"type":"sha256","value":"e3b0c44298fc1c149afb4c8996fb924...","context":"Dropper hash"}],"tags":["zero-day","windows","government","exploit"],"ttps":[{"id":"T1204.002","name":"User Execution: Malicious File","tactic":"Execution"},{"id":"T1071.001","name":"Application Layer Protocol: Web Protocols","tactic":"Command and Control"}],"channel":"https://t[.]me/vxunderground","summary":"Windows zero-day exploit released by Nightmare Eclipse threat group targeting government networks","category":"ioc","severity":"high","confidence":80}],"limit":20,"total":42,"offset":0,"source":"TeleSint","endpoint":"ioc"}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{}}},"response":{"_truncated":true,"_originalSize":17372}},"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_fH1rTo7O8yS-73IvgzEfj","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves indicators of compromise (IOCs) sourced from Telegram cyber threat intelligence channels, with filtering by type, severity, confidence, TLP, tags, and time window.","exampleAgentPrompt":"Pull all high-severity IP and domain IOCs from the TeleSint Telegram CTI feed posted since yesterday, with at least 70% confidence, TLP:WHITE only — give me up to 50 results.","exampleUseCases":[{"title":"Rapid incident response IOC blocking","prompt":"I need all critical-severity malicious IPs and URLs from TeleSint posted in the last 6 hours with 80%+ confidence — format them so I can feed them straight into our firewall blocklist."},{"title":"Ransomware gang activity monitoring","prompt":"Show me the latest hash and domain IOCs tagged with ransomware activity from Telegram threat channels, TLP:WHITE and TLP:GREEN only, sorted by confidence score descending."},{"title":"Pre-attack indicator detection pipeline","prompt":"Pull all IOCs from TeleSint that are tagged with initial access or reconnaissance TTPs from the last 48 hours, minimum 75% confidence, so we can proactively hunt for them in our logs."}],"resultDescription":"Returns a paginated list of feed items, each containing one or more IOCs (IPs, domains, URLs, hashes, or CVEs), associated TTPs, confidence score, severity rating, TLP classification, and tags sourced from Telegram CTI channels.","failureModes":["Invalid 'type' enum value returns 400 or empty results","'since' timestamp in unsupported format causes parse error","No matching results for highly restrictive filter combination returns empty items[]","Payment failure (x402) blocks access if USDC not provided","Rate limiting or server cold-start on Render.com may cause timeout","Unknown channel name silently returns no results"],"whenToPreferThis":"Use this endpoint when you need structured, curated IOC data specifically sourced from Telegram-based CTI communities, especially when you want to filter by indicator type (IP, domain, URL, hash, CVE), confidence threshold, TLP level, or specific Telegram channels. Prefer this over generic threat intel APIs when Telegram OSINT coverage is important or when you need TTP context alongside IOCs.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:40:24.947Z","isFirstParty":false}