# RadhikaChain Attack Intelligence Feed

> RadhikaChain Attack Intelligence Feed is a paid API for AI agents from x402.radhikatmosphere.com, paid per call via x402, $5.148/call, status unknown (last checked 2026-09-15).

Returns real-time network attack intelligence from eBPF/XDP sensors, listing active threat IPs with ports, TCP flags, TTL, probe counts, and attack classification for firewall actioning.

## Facts

- Endpoint: GET https://x402.radhikatmosphere.com/consenso/ataques
- Price: $5.148/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-15
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/radhikachain-attack-intelligence-feed-3233ee3f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_aLnLgs-pdHVepyhEWhrbs

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability radhikachain-attack-intelligence-feed-3233ee3f
```

Example prompt: Pull the latest live attack intelligence from the RadhikaChain XDP sensor feed — I need the current list of hostile IPs with their probed ports, TCP flags, TTL values, and attack classifications so I can update my firewall block list.

## When to prefer this

Choose this endpoint when you need actionable, per-IP firewall-grade threat intelligence with full TCP-layer detail (flags, TTL, port arrays) sourced from a live eBPF/XDP NIC sensor rather than aggregated log counters. Prefer this over generic IP reputation APIs when you need raw behavioral telemetry for blockchain infrastructure nodes, especially when you want to feed data directly into firewall rules without additional enrichment steps. Ideal for pay-per-query use cases where you do not want a subscription.

## Known failure modes

- 402 Payment Required — x402 USDC payment on Base (eip155:8453) not included or invalid
- Payment amount mismatch — must be exactly $0.99 USDC via x402 v2 scheme exact
- Sensor offline — no data returned if the XDP sensor node is down
- Rate limiting or replay rejection — reused payment nonce rejected by facilitator
- Empty threat list — possible during low-activity windows, not an error

## How this service works

Telemetria de cadena, inteligencia de defensa y computo verificable (Halo2, Nova, Plonky3). Pago por peticion en USDC nativo en Base (eip155:8453) mediante x402 v2 scheme exact; sin cuenta ni suscripcion. Catalogo canonico: GET /.well-known/x402.

## Output

A JSON object containing a list of active threat entries, each with source IP, TTL, probed ports array, probe count, TCP flags array, inferred OS, first/last seen timestamps (microseconds), and attack classification (e.g. 'barrido de puertos' / port sweep, 'sondeo insistente' / persistent probe). Also includes aggregate stats: total distinct IPs seen and total events observed. Data sourced from eBPF/XDP NIC sensors, not aggregated iptables counters.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "properties": {
  "input": {
   "type": "object",
   "properties": {
    "body": {
     "type": "object",
     "additionalProperties": true
    },
    "queryParams": {
     "type": "object",
     "additionalProperties": true
    }
   }
  },
  "output": {
   "type": "object",
   "properties": {
    "example": {
     "type": "object",
     "additionalProperties": true
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "fuente": "sensor XDP en la NIC (eBPF), no contadores de iptables",
  "amenazas": [
   {
    "ip": "8.103.58.198",
    "ttl": 45,
    "puertos": [
     22,
     8402,
     8151,
     8332,
     5000,
     3000,
     8788,
     8413,
     9103
    ],
    "sondeos": 665179,
    "flags_tcp": [
     16,
     2,
     24,
     17,
     4,
     20,
     25
    ],
    "so_probable": "linux/unix",
    "primer_visto": 1512360412807002,
    "ultimo_visto": 2360929756865408,
    "clasificacion": "barrido de puertos",
    "puertos_distintos": 9
   },
   {
    "ip": "3.38.236.54",
    "ttl": 47,
    "puertos": [
     3000
    ],
    "sondeos": 10156,
    "flags_tcp": [
     2,
     4,
     16,
     24,
     17
    ],
    "so_probable": "linux/unix",
    "primer_visto": 2078920099453734,
    "ultimo_visto": 2186077586730334,
    "clasificacion": "sondeo insistente",
    "puertos_distintos": 1
   }
  ],
  "diferencia": "cada entrada trae IP, puertos, flags TCP y TTL: accionable en un firewall. Los contadores agregados no.",
  "ips_distintas": 1819,
  "eventos_totales": 811757
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/radhikachain-attack-intelligence-feed-3233ee3f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from x402.radhikatmosphere.com](https://www.zero.xyz/host/x402.radhikatmosphere.com/llms.txt)
