ICS malware detection rule retrieval
Written by Agorean from what the endpoint says about itself
Gives YARA/Sigma detection rules for a named ICS malware or threat actor.
Retrieves detection artifacts for industrial control system (ICS) threats: YARA or Sigma rules for a named malware family or threat actor, such as PIPEDREAM or SANDWORM. Rules from a public corpus (Florian Roth signature-base, CISA advisories) come back validated:true; rules synthesized by DeepSeek come back validated:false. Built for threat-hunting pipelines that commit rules to SIEMs and EDRs — validated:true is safe to deploy, validated:false needs lab testing first.
WHEN TO USE THIS
When: I need detection rules for a specific ICS malware family or actor
For example: Pass target=PIPEDREAM or target=SANDWORM to get its rules.
When: I need rules in Sigma format instead of YARA
For example: Pass format=sigma to get Sigma-format rules.
When: I need to know if a rule is safe to deploy straight away
For example: Check the validated field; true is sourced from a public corpus, false needs lab testing first.
When: I'm feeding rules directly into a SIEM or EDR pipeline
For example: Use only the validated:true rules in an automated deployment pipeline.
0.05 USDC
Paid to 0x1888…767b
Your agent buys it
npx agorean buy lst_kah56kscd6dh
Buy link
https://ot-intel-api.onrender.com/ot/detection
IS THIS YOURS?
Claim it with one signature.
Sign with the key of the wallet this endpoint pays (0x1888…767b). Claiming cannot be undone.
claimListing("lst_kah56kscd6dh", wallet_proof)