{"x402Version":2,"payTo":"0x7F74cE6d34ee0180f0217A16Ce05f3B91272570F","resources":[{"id":5053,"slug":"5053","resource":"https://telesint-api.onrender.com/ioc","description":"IOC feed from Telegram CTI channels. Filters: type(ip|domain|url|hash|cve), severity, min_confidence, since, tlp, tag, channel, limit, offset. Returns items[] with iocs[], ttps[], confidence, severity, tlp, tags[].","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x7F74cE6d34ee0180f0217A16Ce05f3B91272570F","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"10000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"channel":"vxunderground","limit":20,"min_confidence":70,"offset":0,"severity":"high","since":"2026-05-01T00:00:00Z","tag":"ransomware","tlp":"WHITE","type":"ip"},"type":"http"},"output":{"example":{"endpoint":"ioc","items":[{"category":"ioc","channel":"https://t[.]me/vxunderground","confidence":80,"id":"f8a3c1d2-4b5e-4f6a-9c8d-1e2f3a4b5c6d","iocs":[{"context":"Exploit repository","type":"url","value":"https://github[.]com/Nightmare-Eclipse/MiniPlasma"},{"context":"C2 callback address","type":"ip","value":"185.220[.]101.47"},{"context":"Dropper hash","type":"sha256","value":"e3b0c44298fc1c149afb4c8996fb924..."}],"severity":"high","summary":"Windows zero-day exploit released by Nightmare Eclipse threat group targeting government networks","tags":["zero-day","windows","government","exploit"],"tlp":"WHITE","ts":"2026-05-27T14:32:00Z","ttps":[{"id":"T1204.002","name":"User Execution: Malicious File","tactic":"Execution"},{"id":"T1071.001","name":"Application Layer Protocol: Web Protocols","tactic":"Command and Control"}]}],"limit":20,"offset":0,"source":"TeleSint","total":42},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET"],"type":"string"},"queryParams":{"properties":{"channel":{"description":"Partial match on source Telegram channel name","type":"string"},"limit":{"description":"Page size, default 20, max 100","type":"number"},"min_confidence":{"description":"Minimum AI confidence score 0-100","type":"number"},"offset":{"description":"Pagination offset, default 0","type":"number"},"severity":{"description":"Minimum severity: critical | high | medium | low | info","type":"string"},"since":{"description":"ISO 8601 timestamp filter, e.g. 2026-05-01T00:00:00Z","type":"string"},"tag":{"description":"Tag keyword filter, e.g. ransomware, cobalt-strike, apt","type":"string"},"tlp":{"description":"TLP classification: WHITE | GREEN | AMBER | RED","type":"string"},"type":{"description":"IOC type: ip | domain | url | md5 | sha1 | sha256 | cve","type":"string"}},"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"telesint-api.onrender.com","lastUpdated":"2026-09-14T19:54:36.619Z","quality":{"calls30d":8,"uniquePayers30d":7,"lastCalledAt":"2026-09-14T19:54:36.24Z"},"liveness":{},"verified":false,"featured":false},{"id":5054,"slug":"5054","resource":"https://telesint-api.onrender.com/darkweb","description":"Dark web intelligence from Telegram: marketplace listings, forum chatter, access broker posts, credential shops, Tor site activity. Filters: severity, min_confidence, since, tag, sector, country, organization, limit, offset.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x7F74cE6d34ee0180f0217A16Ce05f3B91272570F","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"30000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"limit":20,"min_confidence":60,"offset":0,"sector":"finance","severity":"high","since":"2026-05-01T00:00:00Z","tag":"access-broker"},"type":"http"},"output":{"example":{"endpoint":"darkweb","items":[{"category":"darkweb","channel":"https://t[.]me/darkwebinformer","confidence":78,"id":"d1a2r3k4-w5e6-7890-abcd-darkweb78901","iocs":[{"context":"Underground forum listing","type":"url","value":"https://exploit[.]in/threads/healthcare-access-12345"}],"severity":"critical","summary":"Access broker selling domain admin access to US healthcare network (5,000 employees) — asking $15,000 on exploit.in forum","tags":["access-broker","healthcare","initial-access","domain-admin","exploit-in"],"target":{"countries":["US"],"organizations":[],"sectors":["healthcare"]},"tlp":"WHITE","ts":"2026-05-27T06:45:00Z","ttps":[{"id":"T1078","name":"Valid Accounts","tactic":"Initial Access"}]}],"limit":20,"offset":0,"source":"TeleSint","total":14},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET"],"type":"string"},"queryParams":{"properties":{"country":{"description":"Targeted country keyword, e.g. us | uk | de | fr","type":"string"},"limit":{"description":"Page size, default 20, max 100","type":"number"},"min_confidence":{"description":"Minimum AI confidence score 0-100","type":"number"},"offset":{"description":"Pagination offset, default 0","type":"number"},"organization":{"description":"Targeted organization name partial match","type":"string"},"sector":{"description":"Targeted sector: finance | healthcare | government | energy | retail","type":"string"},"severity":{"description":"Minimum severity: critical | high | medium | low | info","type":"string"},"since":{"description":"ISO 8601 timestamp filter, e.g. 2026-05-01T00:00:00Z","type":"string"},"tag":{"description":"Tag keyword: access-broker | credential-shop | combo-list | carding | forum | marketplace","type":"string"}},"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"telesint-api.onrender.com","lastUpdated":"2026-09-16T17:39:13.409Z","quality":{"calls30d":3,"uniquePayers30d":2,"lastCalledAt":"2026-09-16T17:39:11.748Z"},"liveness":{},"verified":false,"featured":false},{"id":5055,"slug":"5055","resource":"https://telesint-api.onrender.com/vulnerability","description":"CVE and exploitation-in-the-wild signals from Telegram CTI channels. Filters: severity, min_confidence, since, tag(cve|exploit|poc|patch), ttp, type(cve), limit, offset. Returns CVE IDs, affected products, exploit status.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x7F74cE6d34ee0180f0217A16Ce05f3B91272570F","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"30000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"limit":20,"min_confidence":60,"offset":0,"severity":"high","since":"2026-05-01T00:00:00Z","tag":"cve","type":"cve"},"type":"http"},"output":{"example":{"endpoint":"vulnerability","items":[{"category":"vulnerability","channel":"https://t[.]me/vxunderground","confidence":91,"id":"v1u2l3n4-5678-90ab-cdef-vuln56789012","iocs":[{"context":"Critical RCE in PAN-OS","type":"cve","value":"CVE-2026-1234"},{"context":"PoC repository","type":"url","value":"https://github[.]com/exploit-db/CVE-2026-1234"}],"severity":"critical","summary":"PoC released for CVE-2026-1234 (CVSS 9.8): unauthenticated RCE in Palo Alto PAN-OS. Exploitation observed in the wild targeting government networks.","tags":["cve","rce","palo-alto","pan-os","poc","exploit-in-the-wild"],"tlp":"WHITE","ts":"2026-05-27T10:00:00Z","ttps":[{"id":"T1190","name":"Exploit Public-Facing Application","tactic":"Initial Access"},{"id":"T1203","name":"Exploitation for Client Execution","tactic":"Execution"}]}],"limit":20,"offset":0,"source":"TeleSint","total":34},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET"],"type":"string"},"queryParams":{"properties":{"limit":{"description":"Page size, default 20, max 100","type":"number"},"min_confidence":{"description":"Minimum AI confidence score 0-100","type":"number"},"offset":{"description":"Pagination offset, default 0","type":"number"},"severity":{"description":"Minimum severity: critical | high | medium | low | info","type":"string"},"since":{"description":"ISO 8601 timestamp filter, e.g. 2026-05-01T00:00:00Z","type":"string"},"tag":{"description":"Tag keyword filter, e.g. cve, exploit, poc, patch, zero-day","type":"string"},"ttp":{"description":"MITRE ATT&CK technique ID prefix, e.g. T1190, T1203","type":"string"},"type":{"description":"IOC type filter: cve","type":"string"}},"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"telesint-api.onrender.com","lastUpdated":"2026-08-30T15:54:26.906Z","quality":{"calls30d":2,"uniquePayers30d":2,"lastCalledAt":"2026-08-30T15:54:26.652Z"},"liveness":{},"verified":false,"featured":false},{"id":5056,"slug":"5056","resource":"https://telesint-api.onrender.com/search","description":"Cross-category pivot across all TeleSint intel. Use ?q= for broad keyword or combine filters: category, severity, sector, country, tag, ttp, name, organization, min_confidence, since. Returns items[] across any category.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x7F74cE6d34ee0180f0217A16Ce05f3B91272570F","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"40000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"category":"breach","country":"us","limit":20,"min_confidence":60,"offset":0,"q":"lockbit","sector":"finance","severity":"high"},"type":"http"},"output":{"example":{"endpoint":"search","items":[{"category":"breach","channel":"https://t[.]me/cyberinsider","confidence":82,"id":"s1e2a3r4-c5h6-7890-abcd-search789012","iocs":[{"context":"Ransomware leak site","type":"url","value":"https://lockbit3[.]onion/leak/fin-data"}],"severity":"critical","summary":"LockBit claims breach of US financial institution — 2.4M records including SSNs and account numbers","tags":["lockbit","ransomware","finance","data-leak"],"tlp":"WHITE","ts":"2026-05-27T12:00:00Z","ttps":[{"id":"T1486","name":"Data Encrypted for Impact","tactic":"Impact"}]}],"limit":20,"offset":0,"source":"TeleSint","total":12},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET"],"type":"string"},"queryParams":{"properties":{"category":{"description":"Narrow to one category: ioc | c2 | actor | breach | intent | vulnerability","type":"string"},"country":{"description":"Target country keyword, e.g. us | uk | de | fr","type":"string"},"limit":{"description":"Page size, default 20, max 100","type":"number"},"min_confidence":{"description":"Minimum AI confidence score 0-100","type":"number"},"name":{"description":"Actor name partial match, e.g. lazarus, sandworm","type":"string"},"offset":{"description":"Pagination offset, default 0","type":"number"},"organization":{"description":"Target organization name partial match","type":"string"},"q":{"description":"Broad keyword search across tags and summaries, e.g. lockbit, lazarus, cve-2026","type":"string"},"sector":{"description":"Target sector: finance | healthcare | government | energy | retail","type":"string"},"severity":{"description":"Minimum severity: critical | high | medium | low | info","type":"string"},"since":{"description":"ISO 8601 timestamp filter, e.g. 2026-05-01T00:00:00Z","type":"string"},"tag":{"description":"Tag keyword filter, e.g. ransomware, apt, cobalt-strike","type":"string"},"ttp":{"description":"MITRE ATT&CK technique ID prefix, e.g. T1059","type":"string"}},"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"telesint-api.onrender.com","lastUpdated":"2026-08-23T02:06:31.054Z","quality":{"calls30d":1,"uniquePayers30d":1,"lastCalledAt":"2026-08-23T02:06:30.659Z"},"liveness":{},"verified":false,"featured":false}]}