Overview & Architecture
The CTI.FYI API is a high-performance query layer mirroring the real-time ransomware intelligence pipeline. It provides programmatic access to 400+ monitored darknet syndicates, victim leak blog disclosures, Ollama LLM-enriched metadata (canonical orgs, countries, sectors), and MITRE ATT&CK TTP profiles.
Client Integration Examples
# Query recent leaks across all threat groups
curl -s "https://cti.fyi/api/v1/posts/recent?limit=5"
# Search for healthcare-sector victims published since March 2026
curl -s "https://cti.fyi/api/v1/posts?sector=health&published_since=2026-03-01&limit=10"
# Fetch threat syndicate dossier for Akira
curl -s "https://cti.fyi/api/v1/groups/akira"
import requests
BASE_URL = "https://cti.fyi/api/v1"
# 1. Fetch latest enriched victim disclosures
resp = requests.get(f"{BASE_URL}/posts", params={"limit": 20})
data = resp.json()
print(f"Total Disclosures Tracked: {data['count']}")
for victim in data.get("results", []):
meta = victim.get("enriched_metadata") or {}
print(f"[{victim['group_name']}] {victim['post_title']} -> Org: {meta.get('canonical_name') or 'N/A'} ({meta.get('country_iso') or 'Global'})")
# 2. Inspect active threat groups
groups_resp = requests.get(f"{BASE_URL}/groups", params={"status": "online", "has_posts": True})
print(f"Active Groups Online: {groups_resp.json()['count']}")
// Fetch the 10 most recent ransomware disclosures
async function getRecentLeaks() {
const res = await fetch("https://cti.fyi/api/v1/posts/recent?limit=10");
const data = await res.json(); // => { count, results }
data.results.forEach(post => {
const meta = post.enriched_metadata || {};
console.log(`${post.group_name}: ${post.post_title} [${meta.country_iso || 'N/A'}]`);
});
}
getRecentLeaks();
Victim Disclosures
Query and search ransomware victim disclosures captured across all monitored darknet mirrors.
Paginated list of all tracked disclosures with support for group, sector, country, full-text substring search, and date windows.
| Parameter | Type | Status | Description |
|---|---|---|---|
| group | string | optional | Case-insensitive threat actor name (e.g. akira, lockbit3). |
| search | string | optional | Substring match against post_title, group_name, and enriched canonical_name, industry_sector, country_iso, domain. |
| sector | string | optional | Case-insensitive substring match against enriched industry_sector (e.g. health). |
| country | string | optional | Case-insensitive match against enriched country_iso (e.g. US, DE). |
| since | date | YYYY-MM-DD | Filter disclosures discovered on or after this UTC date. |
| until | date | YYYY-MM-DD | Filter disclosures discovered strictly before this UTC date. |
| published_since | date | YYYY-MM-DD | Filter disclosures published by the leak site on or after this UTC date. Disclosures without a published timestamp are excluded (no fallback to discovered). |
| published_until | date | YYYY-MM-DD | Filter disclosures published by the leak site strictly before this UTC date. Disclosures without a published timestamp are excluded. |
| limit | integer | default: 50, max: 500 | Maximum number of results to return. |
| offset | integer | default: 0 | Number of matching records to skip for pagination. |
{
"count": 14205,
"limit": 2,
"offset": 0,
"results": [
{
"post_title": "i2k2 Networks",
"group_name": "Vexy Ransomware",
"published": "2026-09-30 00:13:00",
"discovered": "2026-09-30 00:13:31.796539",
"post_url": "http://vexy...onion/#box_v27",
"screenshot_path": "screenshots/Vexy Ransomware/post_7e8aab99d8d6de21.webp",
"enriched_metadata": {
"canonical_name": "i2k2 Networks",
"domain": "i2k2networks.com",
"country_iso": "US",
"country_flag": "🇺🇸",
"industry_sector": "Cybersecurity Services",
"summary": "i2k2 Networks, a provider of network security solutions...",
"is_toxic": false
}
}
]
}
Convenience endpoint returning the freshest disclosures as a lightweight { count, results } envelope. Unlike /api/v1/posts it has no offset pagination and no filtering.
| Parameter | Type | Status | Description |
|---|---|---|---|
| limit | integer | default: 50, max: 500 | Number of recent posts to return. |
{
"count": 5,
"results": [
{
"post_title": "SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA",
"group_name": "Deadlock",
"published": "2026-10-02 08:06:00",
"discovered": "2026-10-02 08:06:20.982237",
"post_url": "http://...onion/...",
"screenshot_path": "screenshots/Deadlock/post_....webp"
}
]
}
Threat Syndicates & Profiles
Access monitored ransomware gang fleet statuses, darknet mirror availability, and MITRE ATT&CK dossiers.
Retrieve all tracked ransomware groups with location telemetry, site availability, and post counts. profile uses the v3 object schema; a small number of legacy groups may expose it as an array of research references.
| Parameter | Type | Status | Description |
|---|---|---|---|
| status | string | optional | Filter by mirror health: online, issue, or offline. Matches when any location reports the status. |
| search | string | optional | Substring match against the syndicate name or its known aliases. |
| has_posts | boolean | optional | When true, only returns syndicates with at least one published victim. |
{
"count": 1,
"results": [
{
"name": "qilin",
"captcha": false,
"parser": true,
"javascript_render": true,
"meta": null,
"locations": [
{
"fqdn": "ijzn3...onion",
"slug": "http://ijzn3...onion",
"available": true,
"site_status": "online",
"home_screenshot": "screenshots/qilin/home.png",
"last_html_hash": null
}
],
"profile": { "description": null, "aliases": [], "ttps": [], "references": [] },
"post_count": 2371
}
]
}
Detailed intelligence dossier for a single threat actor, including MITRE ATT&CK TTPs, aliases, and paginated victim history.
| Parameter | Type | Status | Description |
|---|---|---|---|
| name | string | path required | Case-insensitive threat actor name (e.g. qilin). |
| include_posts | boolean | default: true | Whether to embed the syndicate's victim disclosures. |
| limit | integer | default: 50, max: 500 | Victim posts per page. |
| offset | integer | default: 0 | Offset for victim post pagination. |
{
"name": "qilin",
"captcha": false,
"parser": true,
"javascript_render": true,
"locations": [ /* ...mirror objects... */ ],
"profile": { "description": "...", "aliases": [], "ttps": [], "references": [] },
"post_count": 2371,
"posts": {
"count": 2371,
"limit": 50,
"offset": 0,
"results": [ /* ...victim disclosure objects... */ ]
}
}
Stats & Velocity
Global platform telemetry, scrape execution metrics, and historical daily disclosure totals.
Current intelligence summary, including 24-hour and 7-day leak velocity, active fleet ratio, and last scrape run metrics.
{
"last_scrape": "2026-10-02T11:09:13Z",
"groups_total": 402,
"groups_active": 121,
"posts_total": 33993,
"posts_last_7d": 188,
"timeframe_counts": { "24h": 41, "7d": 188, "30d": 980, "90d": 2208, "180d": 3806, "365d": 8367 },
"group_post_counts": { "qilin": 2371, "play": 1284, "akira": 1701, "...": 0 },
"group_latest_dates": { "qilin": "2026-10-01 00:00:00", "...": "..." },
"scraper_version": "3.0.0",
"last_scrape_details": {
"last_run": "2026-10-02T11:09:12Z",
"duration_seconds": 549,
"groups_attempted": 119,
"groups_succeeded": 79,
"groups_failed": 40,
"captcha_blocks": 1,
"new_posts_found": 1,
"posts_enriched": 1,
"parser_breakages": [ /* ... */ ],
"recent_runs": [ /* ... */ ]
}
}
Chronological time-series snapshots of daily victim disclosure volume per group over up to 365 days.
| Parameter | Type | Status | Description |
|---|---|---|---|
| days | integer | default: 30, max: 365 | Number of daily history records to return. |
{
"count": 2,
"results": [
{
"date": "2026-10-01",
"total_posts": 33859,
"groups_active": 132,
"groups": { "qilin": 2370, "play": 1272, "...": 0 }
}
]
}
Health & Administration
Health monitoring and authorized data cache reload endpoints.
Lightweight liveness probe returning API operational status and total loaded record counts in memory.
{ "status": "ok", "posts_loaded": 33993, "groups_loaded": 402 }
Forces an immediate reload of in-memory stores from disk or Cloudflare R2 CDN. Requires authorization.
| Header | Type | Status | Description |
|---|---|---|---|
| X-API-Key | string | required | Must match the configured RELOAD_API_KEY environment secret. |
200 OK { "status": "ok", "posts": 33993, "groups": 402 }
403 Forbidden { "detail": "Invalid API key" }
503 Service Unavailable { "detail": "Reload endpoint not configured (no RELOAD_API_KEY)" }
Static R2 Data Feeds
For bulk data analysis, threat ingestion pipelines, and SIEM/SOAR platforms, access raw static JSON and syndication feeds served directly via global CDN.
Complete unpaginated array of all victim disclosures with full enriched metadata.
Trimmed array of the 150 most recent disclosures, for lightweight polling.
All monitored threat groups, .onion mirror URLs, parser flags, and ATT&CK profiles.
Platform telemetry snapshot (group totals, timeframe velocity counts, per-group activity).
Latest scrape execution metrics: parser breakages, CAPTCHA blocks, and recent run history.
Daily snapshot time-series covering the trailing 365 days of activity.
Standard RSS 2.0 feed containing the 50 most recent victim disclosures.
OPML subscription export for RSS feed readers and automated ingestion.
XML sitemap covering the dashboard, API reference, and every threat-actor page.
Usage & Operational Notes
discovered and published) and all date filter parameters use UTC (YYYY-MM-DD HH:MM:SS.ffffff, YYYY-MM-DD HH:MM:SS, or YYYY-MM-DD).