x402 List

x402 Protocol Service Directory

OT Intel API

Data PAYMENT-READY imported

payment-ready until 2026-09-29

imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed

Pay-per-call OT/ICS threat intelligence API. Endpoints cover CVE triage with OT-adjusted severity, internet-exposed device lookup, threat actor and campaign profiles, IOC enrichment, detection artifacts and compliance framework mapping. Responses are LLM-enriched. Priced in USDC on Base.

Pay from $0.01 to $0.10 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

measured since 2026-05-21 (start of our harvest window) · $38.61 all-time · settled via coinbase

BASE URL https://ot-intel-api.onrender.com ENDPOINTS 10 NETWORK Base ASSET USDC MEMBER SINCE 2026-07-20 MONITORED SINCE 2026-07-20

VERDICT

ranking generation 3

solid 85/100 #131 of 317 in Data by measured score

What the score read on this service: status online, 100% uptime 30d, 582ms response p95, x402 compliance 14 of 14, $0.01 price against the category, on-chain traction measured. Each of those is measured, and each is published in full below.

The score comes from our own monitoring, never from reviews, operator claims, or a language model: reliability, x402 compliance, price against the category, a deterministic risk flag, and a small on-chain traction term, weighted by ranking generation 3. It is not placement anyone can buy: the paid verify tier is reported beside it and is not one of its inputs. Every component below stays published and read-only.

It is a score inside Data, and only there: price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, which here means 317 listings, this one among them. That set is wider than the 317 the position above is counted against, because a listing we have measured too little of to rank still sits in the field the price and the speed are normalized over. The same service in a different field would read differently. The same engine answers GET /api/v1/best, and asked for a different pool (the whole directory, or another filter) it returns a different number for this service under this same ranking generation. Neither is more correct: they answer different questions, and the methodology states which is which.

Bands on the 0 to 100 measured score: strong at 93 and above, solid from 75, mixed from 55, weak below 55. Price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, so the score places a service in its own field.

ALTERNATIVES IN DATA

Other Data services in this directory, ordered by the same measured score. The figures are ours: 30-day uptime from our own probes, 30-day settlement volume read on-chain (a conservative undercount, and null where we cannot measure it, never a zero).

Ranked alternative x402 services in the same category, with band, measured score, 30-day uptime and 30-day on-chain settlement volume
SERVICE BAND SCORE UPTIME 30D VOL 30D
glim.sh strong 96 100% $48.80
StableEnrich strong 96 100% $1.9k
SniperX•x402 strong 95 100% $344.73
cn402 strong 94 100% $36.64
API Acre solid 92 99.5% $31.95
5 of 316 other ranked services in Data · see the whole category

ASSESSMENT

updated 6h ago

The parts the verdict above is computed from, each with its proof. Click any chip. Measured values stay read-only; unknown is honest, and an unknown is never counted as a zero.

reliability 100%
uptime 24h
100%
uptime 7d
100%
uptime 30d
100%
uptime 90d
100%
response p95
582ms
avg response
354ms
total checks
2,756

Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.

compliance A (14/14)

14 of 14 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.01 to $0.10 (p60 in Data)
price (min)
$0.01
price (max)
$0.10
category percentile (min)
p60 in Data
category percentile (max)
p73 in Data
endpoints / prices
10 / 6
model
tiered
stability
100%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

domain age
-
registrar
-
hosting
free host
domain created
---

Identity facts, not a risk score.

traction $1.88 30d · 11 buyers
volume 30d
$1.88
buyers 30d
11
settlements 30d
81
measured since
2026-05-21 (start of our harvest window)
last settlement
2026-09-21
top buyer share
29% of 30d volume
trend 7d vs 30d
0.98x the 30d daily rate
networks
eip155:8453
volume all-time
$38.61
settlements all-time
473
median settlement 30d
$0.01
max settlement 30d
$0.20
settled via
coinbase ($1.88, 81 tx)

Conservative undercount: only USDC settlements via facilitators we measure are counted. A measured floor, not an estimate.

Top buyer share is a concentration signal, not part of the ranking score.

WHAT IT DOES

ai-derived

Provides OT/ICS/SCADA threat intelligence for AI agents and industrial SOC automation

category
threat-intelligence
threat-intelligencecybersecurityot-ics-scadacve-triagedevice-lookupactor-profilesioc-enrichmentcampaign-tracking

AI-generated summary. The measured data is never altered by it.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET 402 CHANNEL
GET /ot/actor/sector $0.03 Base USDC header
GET /ot/brief $0.10 Base USDC header
GET /ot/campaign $0.05 Base USDC header
GET /ot/compliance $0.04 Base USDC header
GET /ot/cve $0.02 Base USDC header
GET /ot/delta $0.03 Base USDC header
GET /ot/detection $0.05 Base USDC header
GET /ot/device $0.05 Base USDC header
GET /ot/exposure $0.05 Base USDC header
GET /ot/ioc $0.01 Base USDC header
10 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to GET /ot/actor/sector returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i 'https://ot-intel-api.onrender.com/ot/actor/sector'
// 402 response (captured by monitor) · 10 payloads · click to expand
[
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "20000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/cve",
      "mimeType": "application/json",
      "description": "OT-contextualised CVE triage for ICS/SCADA. Pass ?id=CVE-XXXX-XXXX. Returns OT-adjusted severity, cyber-physical impact, patch feasibility, CISA KEV status, and prioritised action. DeepSeek-enriched with live NVD and CISA-KEV data."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "id": "CVE-2023-38802"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "cve_id": "CVE-2019-13945",
              "summary": "A vulnerability has been identified in SIMATIC S7-1200 CPU family (All versions). The web server of the affected devices transmits data without TLS encryption.",
              "freshness": "2025-05-22T10:00:00.000Z",
              "cvss_score": 6.8,
              "ot_context": {
                "affected_layer": "field_device",
                "patch_feasibility": "low — requires maintenance window",
                "safety_system_risk": true,
                "production_downtime": true,
                "ot_adjusted_severity": "high"
              },
              "data_sources": [
                "NVD",
                "CISA-KEV",
                "DeepSeek-CTI-Analysis"
              ],
              "kev_due_date": null,
              "actively_exploited": false,
              "recommended_action": "HIGH: Schedule patch for next maintenance window.",
              "compensating_controls": [
                "Isolate PLC from IT network via VLAN",
                "Disable web server interface if unused",
                "Deploy unidirectional gateway for historian traffic"
              ]
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "id"
                  ],
                  "properties": {
                    "id": {
                      "type": "string",
                      "description": "CVE identifier e.g. CVE-2023-38802"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "50000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/detection",
      "mimeType": "application/json",
      "description": "ICS detection artifact retrieval. Pass ?target=PIPEDREAM or ?target=SANDWORM&format=sigma. Returns YARA/Sigma rules for the target malware or actor, sourced from public corpus (Florian Roth signature-base, CISA advisories) with validated:true, or DeepSeek-synthesised with validated:false. Designed for automated threat hunting pipelines that commit rules to SIEMs and EDRs — validated:true rules are safe to deploy; validated:false require lab testing first."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "target": "PIPEDREAM"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "target": "PIPEDREAM",
              "freshness": "2026-06-19T10:00:00Z",
              "signatures": [
                {
                  "type": "YARA",
                  "source": "manual",
                  "raw_rule": "rule PIPEDREAM_INCONTROLLER_Loader { meta: ... strings: ... condition: ... }",
                  "rule_name": "PIPEDREAM_INCONTROLLER_Loader",
                  "validated": false,
                  "ot_safe_note": "Synthesised from CISA advisory AA22-103A. Test against OT baseline before SIEM deployment.",
                  "target_layer": "engineering_workstation"
                }
              ],
              "data_sources": [
                "OT-Intel-DB",
                "DeepSeek-CTI-Analysis"
              ],
              "artifact_type": "malware",
              "validated_count": 0,
              "synthesised_count": 1,
              "ot_safe_validation": "0 of 1 rules sourced from public corpus. Rules with validated:false require lab testing before production deployment."
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "target"
                  ],
                  "properties": {
                    "format": {
                      "type": "string",
                      "description": "Rule format: yara | sigma | snort | all (default: all)"
                    },
                    "target": {
                      "type": "string",
                      "description": "Malware or actor name e.g. PIPEDREAM, INDUSTROYER2, TRITON, SANDWORM, CHERNOVITE"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "50000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/campaign",
      "mimeType": "application/json",
      "description": "Active ICS campaign tracker. Pass ?sector=electric&status=active. Returns campaigns currently targeting a sector with actor attribution, start date, targeted geography, TTPs in use, and CVEs being exploited. No free equivalent for live campaign status."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "sector": "electric",
              "status": "active"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "sector": "electric",
              "status": "active",
              "campaigns": [
                {
                  "name": "VOLTZITE Pre-Positioning Campaign",
                  "actor": "VOLTZITE",
                  "status": "active",
                  "confidence": "high",
                  "start_date": "2023-Q1",
                  "ttps_in_use": [
                    "T0859",
                    "T0812",
                    "T0885"
                  ],
                  "exploited_cves": [
                    "CVE-2023-38380"
                  ],
                  "targeted_geography": [
                    "United States",
                    "Pacific Islands"
                  ]
                }
              ],
              "freshness": "2026-06-13T10:00:00Z",
              "data_sources": [
                "MITRE-ATT&CK-ICS",
                "CISA-ICS-CERT",
                "OT-Intel-DB",
                "DeepSeek-CTI-Analysis"
              ],
              "campaign_count": 2
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "sector"
                  ],
                  "properties": {
                    "sector": {
                      "type": "string",
                      "description": "Industrial sector e.g. energy, water, electric, manufacturing, oil-and-gas, nuclear, chemical"
                    },
                    "status": {
                      "type": "string",
                      "description": "active (default) | all"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "50000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/device",
      "mimeType": "application/json",
      "description": "ICS/OT device exposure lookup. Pass ?vendor=siemens&model=s7-1200. Returns default credential risk, exposed OT protocols (Modbus/502, S7comm/102, DNP3/20000), exploitation notes, and hardening steps. Covers Siemens, Schneider, Rockwell, Honeywell, GE, Unitronics, Beckhoff."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "model": "vision",
              "vendor": "unitronics"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "query": {
                "model": "vision",
                "vendor": "unitronics"
              },
              "freshness": "2025-05-22T10:00:00.000Z",
              "data_sources": [
                "NVD",
                "CISA-ICS-CERT",
                "DeepSeek-CTI-Analysis"
              ],
              "recommended_action": "Change default credentials immediately. No downtime required.",
              "ot_protocols_at_risk": [
                "PCOM (20256)",
                "Modbus TCP (502)"
              ],
              "default_credential_risk": {
                "note": "Default password 1111 on port 20256. Actively exploited by IRGC 2023–2024.",
                "risk": "critical"
              }
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "vendor",
                    "model"
                  ],
                  "properties": {
                    "model": {
                      "type": "string",
                      "description": "Model or product line e.g. s7-1200, quantum, logix, vision"
                    },
                    "vendor": {
                      "type": "string",
                      "description": "Vendor name e.g. siemens, schneider, rockwell, honeywell, unitronics, ge, beckhoff"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "50000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/exposure",
      "mimeType": "application/json",
      "description": "OT asset risk verdict. Pass ?vendor=siemens&model=s7-1500&sector=energy&network=internet-facing. Returns risk_score (0-100), risk_level, escalate (boolean), recommended_action, active CVEs, and threat actors. Optional firmware param enables firmware-specific CVE matching. Cached 1 hour."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "model": "s7-1500",
              "sector": "energy",
              "vendor": "siemens",
              "network": "internet-facing"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "model": "s7-1500",
              "sector": "energy",
              "vendor": "siemens",
              "network": "internet-facing",
              "escalate": true,
              "freshness": "2026-06-13T10:00:00Z",
              "confidence": "high",
              "risk_level": "critical",
              "risk_score": 87,
              "top_threat": "VOLTZITE pre-positioning via CVE-2023-38380",
              "active_cves": 3,
              "ttl_seconds": 3600,
              "data_sources": [
                "NVD",
                "CISA-KEV",
                "MITRE-ATT&CK-ICS",
                "DeepSeek-CTI-Analysis"
              ],
              "threat_actors": [
                "VOLTZITE",
                "SANDWORM"
              ],
              "active_campaigns": 2,
              "recommended_action": "isolate"
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "vendor",
                    "model",
                    "sector",
                    "network"
                  ],
                  "properties": {
                    "model": {
                      "type": "string",
                      "description": "Device model e.g. s7-1500, modicon-m340, controllogix"
                    },
                    "sector": {
                      "type": "string",
                      "description": "Industrial sector e.g. energy, water, manufacturing, oil-and-gas"
                    },
                    "vendor": {
                      "type": "string",
                      "description": "Vendor name e.g. siemens, schneider, rockwell, ge, honeywell"
                    },
                    "network": {
                      "type": "string",
                      "description": "Network exposure: internet-facing | dmz | lan-only | air-gapped"
                    },
                    "firmware": {
                      "type": "string",
                      "description": "Firmware version e.g. 2.9.2 (optional — enables firmware-specific CVE matching)"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "30000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/actor/sector",
      "mimeType": "application/json",
      "description": "ICS threat actors by sector. Pass ?sector=energy. Returns all groups targeting that sector from live MITRE ATT&CK ICS STIX data. Covers energy, water, manufacturing, oil-and-gas, chemical, transportation, nuclear."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "sector": "energy"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "count": 2,
              "query": {
                "sector": "energy"
              },
              "freshness": "2025-05-22T10:00:00.000Z",
              "data_sources": [
                "MITRE-ATT&CK-ICS",
                "DeepSeek-CTI-Analysis"
              ],
              "actors_targeting_sector": [
                {
                  "name": "SANDWORM",
                  "attribution": "Russia — GRU Unit 74455",
                  "activity_status": "ACTIVE",
                  "physical_impact": "CONFIRMED DESTRUCTIVE"
                },
                {
                  "name": "VOLTZITE",
                  "attribution": "China",
                  "activity_status": "ACTIVE",
                  "physical_impact": "LIKELY"
                }
              ]
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "sector"
                  ],
                  "properties": {
                    "sector": {
                      "type": "string",
                      "description": "Industry sector e.g. energy, water, manufacturing, oil-and-gas, chemical, transportation, nuclear"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "40000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/compliance",
      "mimeType": "application/json",
      "description": "Compliance gap mapping for a CVE or threat actor across 11 frameworks: NERC CIP, IEC 62443, NIST 800-82, NIST CSF 2.0, CISA CPG, Saudi NCA OTCC, UAE NESA IA. Pass ?cve_id=CVE-2023-38802 or ?actor=SANDWORM, optionally &framework=<value> to filter. Returns triggered controls (e.g. CIP-007-6 R2, IEC 62443-3-3 SR 5.1), status (NON_COMPLIANT_IF_UNMITIGATED / REVIEW_REQUIRED), required action, and compensating controls. For automated compliance reporting agents on cron."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "cve_id": "CVE-2023-38802"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "cve_id": "CVE-2023-38802",
              "query_id": "CVE-2023-38802",
              "freshness": "2026-06-19T10:00:00Z",
              "frameworks": {
                "nerc_cip": [
                  {
                    "title": "Security Patch Management",
                    "status": "NON_COMPLIANT_IF_UNMITIGATED",
                    "control": "CIP-007-6 R2",
                    "action_required": "Evaluate CVE-2023-38802 within 35 days of CISA KEV listing.",
                    "compensating_control": "Network segmentation restricting BGP traffic to SCADA DMZ pending patch."
                  }
                ],
                "iec_62443_3_3": [
                  {
                    "status": "NON_COMPLIANT_IF_UNMITIGATED",
                    "component": "3-3 SR 5.1",
                    "requirement": "Network Segmentation",
                    "compensating_control": "Enforce zone conduits: restrict BGP/ICS protocol traffic to whitelisted source/destination pairs."
                  }
                ]
              },
              "data_sources": [
                "OT-Intel-DB-Compliance",
                "DeepSeek-CTI-Analysis"
              ],
              "priority_action": "Apply network segmentation at the ESP boundary immediately; schedule CVE patch for next maintenance window.",
              "controls_triggered": 2
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [],
                  "properties": {
                    "actor": {
                      "type": "string",
                      "description": "Threat actor name e.g. SANDWORM, VOLTZITE, XENOTIME — triggers actor-specific control mappings. At least one of cve_id or actor is required."
                    },
                    "cve_id": {
                      "type": "string",
                      "description": "CVE identifier e.g. CVE-2023-38802 — triggers CVE-specific control mappings. At least one of cve_id or actor is required."
                    },
                    "framework": {
                      "type": "string",
                      "description": "Optional filter to one compliance framework. Valid values: nerc_cip, iec_62443_2_1, iec_62443_2_4, iec_62443_3_2, iec_62443_3_3, iec_62443_4_2, nist_800_82, nist_csf, cisa_cpg, nca_otcc, uae_nesa_ia. Omit (or pass 'all') to return matches across every framework."
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "10000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/ioc",
      "mimeType": "application/json",
      "description": "IOC enrichment with ICS campaign context. Pass ?value=1.2.3.4&type=ip or type=domain. Queries AlienVault OTX, AbuseIPDB, and DeepSeek CTI for OT campaign association. Returns verdict on whether the IOC is linked to ICS-targeting campaigns."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "type": "ip",
              "value": "185.220.101.45"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "ioc": {
                "type": "ip",
                "value": "185.220.101.45"
              },
              "isp": "Tor Project",
              "tor_node": true,
              "freshness": "2025-05-22T10:00:00.000Z",
              "reputation": -2,
              "pulse_count": 50,
              "country_code": "DE",
              "data_sources": [
                "AlienVault-OTX",
                "AbuseIPDB",
                "DeepSeek-CTI-Analysis"
              ],
              "ics_association": {
                "confidence": "high",
                "ics_tags_found": [
                  "ics",
                  "scada",
                  "modbus"
                ],
                "campaign_context": "IP observed in VOLTZITE reconnaissance activity against US electric utilities.",
                "known_threat_actor": "VOLTZITE",
                "associated_with_ics_campaign": true
              },
              "total_abuse_reports": 142,
              "abuse_confidence_score": 87
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "value",
                    "type"
                  ],
                  "properties": {
                    "type": {
                      "enum": [
                        "ip",
                        "domain"
                      ],
                      "type": "string",
                      "description": "IOC type: ip or domain"
                    },
                    "value": {
                      "type": "string",
                      "description": "The IOC: IP address or domain name"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "100000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/brief",
      "mimeType": "application/json",
      "description": "Sector threat brief for ICS/OT. Pass ?sector=energy&period=30. Returns active actors, new CVE counts, active campaigns, top advisories, and risk_trend (increasing/stable/decreasing). One call replaces 5+ chained calls. Ideal for weekly reporting and compliance dashboards."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "period": "30",
              "sector": "energy"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "sector": "energy",
              "new_cves": 12,
              "freshness": "2026-06-13T10:00:00Z",
              "confidence": "high",
              "risk_trend": "increasing",
              "period_days": 30,
              "data_sources": [
                "NVD",
                "CISA-ICS-CERT",
                "MITRE-ATT&CK-ICS",
                "OT-Intel-DB",
                "DeepSeek-CTI-Analysis"
              ],
              "active_actors": [
                "VOLTZITE",
                "SANDWORM",
                "BENTONITE"
              ],
              "critical_cves": 3,
              "top_advisories": [
                {
                  "id": "ICSA-26-150-01",
                  "title": "Siemens SIMATIC S7-1500",
                  "cvss_max": 9.8
                }
              ],
              "active_campaigns": 2,
              "recommended_actions": [
                "Patch CVE-2023-38380 on all internet-facing Siemens devices",
                "Monitor for LOTL techniques on OT-adjacent hosts",
                "Review remote access paths into the energy DMZ"
              ],
              "risk_trend_rationale": "VOLTZITE pre-positioning activity increased in Q2 2026 targeting US electric grid."
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "sector"
                  ],
                  "properties": {
                    "period": {
                      "type": "string",
                      "description": "Lookback window in days, default 30"
                    },
                    "sector": {
                      "type": "string",
                      "description": "Industrial sector e.g. energy, water, manufacturing, oil-and-gas, electric, nuclear"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B",
        "amount": "30000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://ot-intel-api.onrender.com/ot/delta",
      "mimeType": "application/json",
      "description": "ICS sector change feed — only what is NEW in the last N days. Pass ?sector=water&days=7. Returns new CVEs, new CISA advisories, and new actor activity since the last call. Designed for cron-based monitoring agents. Eliminates redundant reprocessing."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "type": "http",
            "method": "GET",
            "queryParams": {
              "days": "7",
              "sector": "water"
            }
          },
          "output": {
            "type": "json",
            "example": {
              "since": "2026-06-06T00:00:00Z",
              "sector": "water",
              "new_cves": [
                {
                  "id": "CVE-2026-1234",
                  "cvss": 9.1,
                  "ot_severity": "critical",
                  "affected_vendors": [
                    "Schneider Electric"
                  ]
                }
              ],
              "freshness": "2026-06-13T10:00:00Z",
              "net_change": "1 new critical CVE, 1 new advisory",
              "data_sources": [
                "NVD",
                "CISA-ICS-CERT",
                "MITRE-ATT&CK-ICS"
              ],
              "new_advisories": [
                {
                  "id": "ICSA-26-164-01",
                  "title": "Schneider Electric Modicon",
                  "cvss_max": 9.1
                }
              ],
              "new_actor_activity": []
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method"
              ],
              "properties": {
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "GET"
                  ],
                  "type": "string"
                },
                "queryParams": {
                  "type": "object",
                  "required": [
                    "sector"
                  ],
                  "properties": {
                    "days": {
                      "type": "string",
                      "description": "Lookback window in days, default 7, max 30"
                    },
                    "sector": {
                      "type": "string",
                      "description": "Industrial sector e.g. energy, water, manufacturing, oil-and-gas, electric"
                    }
                  }
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  }
]

OVER TIME

All charts use the 30d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/ot-intel-api/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

UPTIME
08-24 · uptime 100.0% · 438ms avg08-25 · uptime 100.0% · 457ms avg08-26 · uptime 100.0% · 474ms avg08-27 · uptime 100.0% · 605ms avg08-28 · uptime 100.0% · 469ms avg08-29 · uptime 100.0% · 454ms avg08-30 · uptime 100.0% · 383ms avg08-31 · uptime 100.0% · 202ms avg09-01 · uptime 100.0% · 163ms avg09-02 · uptime 100.0% · 273ms avg09-03 · uptime 100.0% · 405ms avg09-04 · uptime 100.0% · 394ms avg09-05 · uptime 100.0% · 333ms avg09-06 · uptime 100.0% · 285ms avg09-07 · uptime 100.0% · 372ms avg09-08 · uptime 100.0% · 347ms avg09-09 · uptime 100.0% · 307ms avg09-10 · uptime 100.0% · 339ms avg09-11 · uptime 100.0% · 234ms avg09-12 · uptime 100.0% · 239ms avg09-13 · uptime 100.0% · 233ms avg09-14 · uptime 100.0% · 477ms avg09-15 · uptime 100.0% · 500ms avg09-16 · uptime 100.0% · 292ms avg09-17 · uptime 100.0% · 286ms avg09-18 · uptime 100.0% · 334ms avg09-19 · uptime 100.0% · 363ms avg09-20 · uptime 100.0% · 193ms avg09-21 · uptime 100.0% · 317ms avg09-22 · uptime 100.0% · 417ms avg08-2409-22
30d UPTIME 100%
RESPONSE TIME
08-24 · 438ms avg08-24 · 438ms avg08-25 · 457ms avg08-25 · 457ms avg08-26 · 474ms avg08-26 · 474ms avg08-27 · 605ms avg08-27 · 605ms avg08-28 · 469ms avg08-28 · 469ms avg08-29 · 454ms avg08-29 · 454ms avg08-30 · 383ms avg08-30 · 383ms avg08-31 · 202ms avg08-31 · 202ms avg09-01 · 163ms avg09-01 · 163ms avg09-02 · 273ms avg09-02 · 273ms avg09-03 · 405ms avg09-03 · 405ms avg09-04 · 394ms avg09-04 · 394ms avg09-05 · 333ms avg09-05 · 333ms avg09-06 · 285ms avg09-06 · 285ms avg09-07 · 372ms avg09-07 · 372ms avg09-08 · 347ms avg09-08 · 347ms avg09-09 · 307ms avg09-09 · 307ms avg09-10 · 339ms avg09-10 · 339ms avg09-11 · 234ms avg09-11 · 234ms avg09-12 · 239ms avg09-12 · 239ms avg09-13 · 233ms avg09-13 · 233ms avg09-14 · 477ms avg09-14 · 477ms avg09-15 · 500ms avg09-15 · 500ms avg09-16 · 292ms avg09-16 · 292ms avg09-17 · 286ms avg09-17 · 286ms avg09-18 · 334ms avg09-18 · 334ms avg09-19 · 363ms avg09-19 · 363ms avg09-20 · 193ms avg09-20 · 193ms avg09-21 · 317ms avg09-21 · 317ms avg09-22 · 417ms avg09-22 · 417ms avg08-2409-22
AVG RESP 355ms
PRICE (captured 402, USD)
08-23 · $0.04509-22 · $0.045$0.04508-2309-22

Median across 10 endpoints. Use the selector to isolate one.

SUB-SCORES (uptime + x402 compliance)
08-23 uptime: 100.0% compliance: 100% checks08-24 uptime: 100.0% compliance: 100% checks08-25 uptime: 100.0% compliance: 100% checks08-26 uptime: 100.0% compliance: 100% checks08-27 uptime: 100.0% compliance: 100% checks08-28 uptime: 100.0% compliance: 100% checks08-29 uptime: 100.0% compliance: 100% checks08-30 uptime: 100.0% compliance: 100% checks08-31 uptime: 100.0% compliance: 100% checks09-01 uptime: 100.0% compliance: 100% checks09-02 uptime: 100.0% compliance: 100% checks09-03 uptime: 100.0% compliance: 100% checks09-04 uptime: 100.0% compliance: 100% checks09-05 uptime: 100.0% compliance: 100% checks09-06 uptime: 100.0% compliance: 100% checks09-07 uptime: 100.0% compliance: 100% checks09-08 uptime: 100.0% compliance: 100% checks09-09 uptime: 100.0% compliance: 100% checks09-10 uptime: 100.0% compliance: 100% checks09-11 uptime: 100.0% compliance: 100% checks09-12 uptime: 100.0% compliance: 100% checks09-13 uptime: 100.0% compliance: 100% checks09-14 uptime: 100.0% compliance: 100% checks09-15 uptime: 100.0% compliance: 100% checks09-16 uptime: 100.0% compliance: 100% checks09-17 uptime: 100.0% compliance: 100% checks09-18 uptime: 100.0% compliance: 100% checks09-19 uptime: 100.0% compliance: 100% checks09-20 uptime: 100.0% compliance: 100% checks09-21 uptime: 100.0% compliance: 100% checksuptimecompliance08-2309-21

checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression

PILLARS OVER TIME (measured)

Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.

VOLUME (on-chain settlement, USD)
08-24 · $0.0108-25 · $0.0508-30 · $0.0209-04 · $0.4509-06 · $0.2209-09 · $0.2609-11 · $0.1609-12 · $0.2109-14 · $0.0509-16 · $0.1709-18 · $0.1009-20 · $0.1309-21 · $0.03peak $0.4508-2409-21
DISTINCT BUYERS
08-24 · 1 buyer08-25 · 1 buyer08-30 · 1 buyer09-04 · 3 buyers09-06 · 1 buyer09-09 · 3 buyers09-11 · 1 buyer09-12 · 4 buyers09-14 · 1 buyer09-16 · 2 buyers09-18 · 1 buyer09-20 · 2 buyers09-21 · 1 buyerpeak 4 buyers08-2409-21

COMPLIANCE

14/14 checks pass · grade A

last 402 captured 2026-07-20 · last up 2026-09-22

  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS
  • declares the current x402 version (2)
  • EIP-712 domain parameters present on every EVM entry
  • x402 v2 envelope delivered in the payment-required header

SITE PILLARS

  • homepage reachable
  • openapi doc
  • pricing page
  • llms.txt
  • robots.txt
  • terms page
recent checks (18) live · click to expand
TIME STATUS RESP CAUSE
● OK 448ms
● OK 219ms
● OK 264ms
● OK 241ms
● OK 271ms
● SLOW 890ms
● SLOW 871ms
● SLOW 562ms
● SLOW 749ms
● SLOW 860ms
● SLOW 565ms
● SLOW 710ms
● SLOW 840ms
● SLOW 736ms
● OK 501ms
● SLOW 573ms
● OK 409ms
● OK 274ms

EMBED THIS BADGE

Show that OT Intel API is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

OT Intel API listed on x402-list
status
OT Intel API uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/ot-intel-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ot-intel-api.svg" alt="OT Intel API listed on x402-list" height="28">
</a>
// Markdown
[![OT Intel API on x402-list](https://x402-list.com/badge/ot-intel-api.svg)](https://x402-list.com/services/ot-intel-api?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/ot-intel-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ot-intel-api.svg?data=uptime" alt="OT Intel API uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]

Earn the verified tier: x402list pays a real call to this endpoint and, if it delivers, the service is delivery-verified. The fee covers the cost of the probe, not the badge; there is no refund if the call does not deliver. Agent and API only, no in-browser signing. See /api.

[ verify this service ($0.25) ]

To request delisting, email info@x402-list.com or update your listing at /services/ot-intel-api/update.