40 Services from ot-intel-api.onrender.com
Returns OT-adjusted CVE severity, cyber-physical impact, patch feasibility, and CISA KEV status for a given CVE ID in ICS/SCADA environments
$0.02/messageFetches a comprehensive ICS/OT threat actor profile by name, including MITRE ATT&CK for ICS technique mappings, known malware/tools, attribution, physical impact assessment, and recommended OT detections.
$0.03/messageReturns MITRE ATT&CK ICS techniques mapped to D3FEND defensive countermeasures with prioritized prescriptive remediation guidance, given a threat actor, CVE, or technique ID.
$0.2/messageClassifies a named ICS/OT threat actor's known ATT&CK-for-ICS TTPs into pre-impact (recon through C2) vs impact-stage categories using deterministic tactic-taxonomy lookup.
$0.04/messageReturns the latest CISA ICS-CERT security advisories filtered by vendor and/or industrial sector, including CVE lists, CVSS scores, and severity ratings.
$0.02/messageScores the reliability of a cyber threat intelligence claim by classifying it against three LLM failure modes and returning a verdict with supporting evidence
$0.2/messageReturns a hand-verified mapping of an OT/ICS vendor's AI/agentic copilot capabilities, autonomy level, access model, and applicable MITRE ATLAS attack techniques.
$0.2/messageEnriches an IP address or domain IOC with OT/ICS-specific threat intelligence, combining AlienVault OTX, AbuseIPDB, and DeepSeek CTI to determine if it is linked to industrial control system targeting campaigns.
$0.01/messageAggregates capability-opportunity-intent threat scores across all relevant threat actors for a given sector and region, returning a ranked actor list and AI-written executive summary (BLUF/ICD-203) for board and GRC reporting.
$0.4/messagePerforms a single aggregated compliance-gap assessment across up to 25 CVEs and/or threat actors, returning deduplicated control gaps and a remediation summary across OT/ICS security frameworks.
$0.2/messageEvaluates a planned OT/ICS remediation action (e.g. block_ip, quarantine_host) against threat intelligence scoring rules and returns an auto_approve, human_review, or reject decision without LLM involvement.
$0.12/messageLooks up whether off-the-shelf LLMs can generate working ICS attack code for a given MITRE technique, vendor, or known campaign, based on a peer-reviewed study.
$0.2/messageValidates whether a tank or vessel's reported level change is physically consistent with its metered inflow and outflow using conservation of mass.
$0.2/messageReturns a deterministic capability × opportunity × intent threat score for a specific ICS/OT threat actor targeting a given sector, region, and vendor stack.
$0.04/messageReturns a risk tier, confidence score, cited CVEs (KEV/EPSS), threat actor targeting history, and supply-chain mitigation recommendations for a named OT/ICS vendor and optional product line.
$0.15/messageReturns OT-safe patch feasibility analysis for a given CVE ID, including patch availability, vendor advisories, workarounds, downtime estimates, CISA KEV status, and a risk-vs-disruption score tailored for ICS/SCADA environments.
$0.05/messageDetects control-loop reconnaissance patterns and living-off-the-land/RMM tool abuse from submitted OT/ICS process names and command strings using deterministic keyword matching.
$0.15/messageReturns all known ICS/SCADA/OT threat actor groups targeting a specified industrial sector, sourced from live MITRE ATT&CK for ICS STIX data.
$0.03/messageGenerates a DeepSeek-synthesised, decision-ready analyst brief (BLUF, key judgments, ICD-203 confidence) for a named ICS/OT threat actor, optionally scoped to a sector.
$0.12/messageReturns a risk score, risk level, escalation flag, recommended action, active CVEs, and associated threat actors for an OT/ICS device identified by vendor, model, sector, and network exposure.
$0.05/messageRanks which OT/ICS sensors most likely caused a reported anomaly by computing z-score deviations from each sensor's baseline, returning a deterministic ordered list of suspect sensors.
$0.15/messageCompares cybersecurity risk tiers between a current and proposed OT/ICS vendor, returning a risk-tier delta and per-vendor summaries to support pre-purchase or migration decisions.
$0.2/messageSubmits an anonymized IOC or TTP sighting observed in an OT/ICS environment to enrich a shared threat correlation corpus, without storing any organizational identifier.
$0.05/messageReturns detailed intelligence on named ICS/OT malware including capabilities, targeted OT protocols, attributed actor, affected vendors, detection signatures, and MITRE ATT&CK ICS techniques.
$0.02/messageReturns a comprehensive AI-enriched intelligence dossier for a named ICS/OT threat actor (e.g. SANDWORM, XENOTIME, VOLTZITE), including campaigns, malware, IOCs, detection artifacts, and MITRE ATT&CK ICS mappings.
$0.35/messageReturns currently active (or all) threat campaigns targeting a specified industrial sector, with actor attribution, start dates, geographies, TTPs, and exploited CVEs.
$0.05/messageReturns only new CVEs, CISA advisories, and threat actor activity for a given ICS/OT sector since the last N days — a change-only feed for efficient cron-based monitoring.
$0.03/messageMaps a CVE or ICS threat actor to specific NERC CIP and IEC 62443 compliance control gaps, returning compliance status, required actions, and compensating controls for OT/ICS environments.
$0.04/messageReturns an AI-enriched OT/ICS threat intelligence article for a given CVE or ICS threat actor, including MITRE ATT&CK for ICS mapping, cyber-physical impact, and CISA KEV status
$0.45/messageProfiles an Autonomous System Number (ASN) for ICS/OT threat relevance, including bulletproof hosting indicators, ICS actor associations, abuse categories, and blocking recommendations.
$0.03/messageReturns a consolidated ICS/OT threat intelligence brief for a given industrial sector and lookback period, including active threat actors, new CVE counts, active campaigns, top advisories, and risk trend.
$0.1/messageGenerates a comprehensive AI-enriched threat intelligence report for a named ICS/OT threat actor (e.g. CHERNOVITE, SANDWORM), covering campaigns, malware, advisories, and detection artifacts with MITRE ATT&CK ICS mapping
$0.25/messageGenerates a comprehensive AI-enriched OT/ICS threat situation report for a specified industrial sector covering active campaigns, advisories, actor activity, compliance gaps, and sector deltas over a configurable lookback period.
$0.35/messageRetrieves a human-reviewed OT/ICS threat intelligence situational report (sitrep) scoped to the Gulf Cooperation Council (GCC) region, optionally for a specific past edition date.
$0.01/messageReturns YARA, Sigma, and/or Snort detection rules for named OT/ICS malware families and threat actors, enriched with OT safety notes and ATT&CK ICS context
$0.05/messageGenerates a LinkedIn-ready social post about an OT/ICS threat actor or CVE, formatted with hashtags and character count, drawing on AI-enriched OT threat intelligence.
$0.15/messageLooks up internet-exposed industrial control system devices by vendor and model, returning default credential risks, at-risk OT protocols, exploitation notes, and hardening recommendations.
$0.05/messageReturns STIX object coverage and actionability scoring for ICS/OT threat observables, mapped from academic research to ATT&CK-for-ICS techniques, CVEs, and ICS protocols.
$0.2/messageGenerates a Twitter/X-style multi-post thread on an OT/ICS threat actor or CVE, enriched with OT context, MITRE ATT&CK for ICS mapping, and cyber-physical impact analysis
$0.1/messageAssesses how much a general-purpose AI agent lowers the barrier for an attacker to reach a vendor's OT/ICS-adjacent footprint, returning a tiered exposure verdict grounded in ICS threat intelligence.
$0.2/message