CTI.FYI API v1 Threat Intelligence Reference & Feeds
Base URL
https://cti.fyi/api/v1
Rate Limiting 60 req / min per IP
Ingestion Velocity ~Hourly Tor Cycles
Authentication Public (Read Endpoints)

Overview & Architecture

The CTI.FYI API is a high-performance query layer mirroring the real-time ransomware intelligence pipeline. It provides programmatic access to 400+ monitored darknet syndicates, victim leak blog disclosures, Ollama LLM-enriched metadata (canonical orgs, countries, sectors), and MITRE ATT&CK TTP profiles.

Client Integration Examples

cURL
# Query recent leaks across all threat groups
curl -s "https://cti.fyi/api/v1/posts/recent?limit=5"

# Search for healthcare-sector victims published since March 2026
curl -s "https://cti.fyi/api/v1/posts?sector=health&published_since=2026-03-01&limit=10"

# Fetch threat syndicate dossier for Akira
curl -s "https://cti.fyi/api/v1/groups/akira"
Python 3.11+ (httpx / requests)
import requests

BASE_URL = "https://cti.fyi/api/v1"

# 1. Fetch latest enriched victim disclosures
resp = requests.get(f"{BASE_URL}/posts", params={"limit": 20})
data = resp.json()

print(f"Total Disclosures Tracked: {data['count']}")
for victim in data.get("results", []):
    meta = victim.get("enriched_metadata") or {}
    print(f"[{victim['group_name']}] {victim['post_title']} -> Org: {meta.get('canonical_name') or 'N/A'} ({meta.get('country_iso') or 'Global'})")

# 2. Inspect active threat groups
groups_resp = requests.get(f"{BASE_URL}/groups", params={"status": "online", "has_posts": True})
print(f"Active Groups Online: {groups_resp.json()['count']}")
JavaScript (ES Modules / Fetch API)
// Fetch the 10 most recent ransomware disclosures
async function getRecentLeaks() {
  const res = await fetch("https://cti.fyi/api/v1/posts/recent?limit=10");
  const data = await res.json();   // => { count, results }

  data.results.forEach(post => {
    const meta = post.enriched_metadata || {};
    console.log(`${post.group_name}: ${post.post_title} [${meta.country_iso || 'N/A'}]`);
  });
}

getRecentLeaks();

Victim Disclosures

Query and search ransomware victim disclosures captured across all monitored darknet mirrors.

GET /api/v1/posts

Paginated list of all tracked disclosures with support for group, sector, country, full-text substring search, and date windows.

Parameter Type Status Description
group string optional Case-insensitive threat actor name (e.g. akira, lockbit3).
search string optional Substring match against post_title, group_name, and enriched canonical_name, industry_sector, country_iso, domain.
sector string optional Case-insensitive substring match against enriched industry_sector (e.g. health).
country string optional Case-insensitive match against enriched country_iso (e.g. US, DE).
since date YYYY-MM-DD Filter disclosures discovered on or after this UTC date.
until date YYYY-MM-DD Filter disclosures discovered strictly before this UTC date.
published_since date YYYY-MM-DD Filter disclosures published by the leak site on or after this UTC date. Disclosures without a published timestamp are excluded (no fallback to discovered).
published_until date YYYY-MM-DD Filter disclosures published by the leak site strictly before this UTC date. Disclosures without a published timestamp are excluded.
limit integer default: 50, max: 500 Maximum number of results to return.
offset integer default: 0 Number of matching records to skip for pagination.
Response Schema (200 OK)
{
  "count": 14205,
  "limit": 2,
  "offset": 0,
  "results": [
    {
      "post_title": "i2k2 Networks",
      "group_name": "Vexy Ransomware",
      "published": "2026-09-30 00:13:00",
      "discovered": "2026-09-30 00:13:31.796539",
      "post_url": "http://vexy...onion/#box_v27",
      "screenshot_path": "screenshots/Vexy Ransomware/post_7e8aab99d8d6de21.webp",
      "enriched_metadata": {
        "canonical_name": "i2k2 Networks",
        "domain": "i2k2networks.com",
        "country_iso": "US",
        "country_flag": "🇺🇸",
        "industry_sector": "Cybersecurity Services",
        "summary": "i2k2 Networks, a provider of network security solutions...",
        "is_toxic": false
      }
    }
  ]
}
GET /api/v1/posts/recent

Convenience endpoint returning the freshest disclosures as a lightweight { count, results } envelope. Unlike /api/v1/posts it has no offset pagination and no filtering.

ParameterTypeStatusDescription
limit integer default: 50, max: 500 Number of recent posts to return.
Response Schema (200 OK)
{
  "count": 5,
  "results": [
    {
      "post_title": "SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA",
      "group_name": "Deadlock",
      "published": "2026-10-02 08:06:00",
      "discovered": "2026-10-02 08:06:20.982237",
      "post_url": "http://...onion/...",
      "screenshot_path": "screenshots/Deadlock/post_....webp"
    }
  ]
}

Threat Syndicates & Profiles

Access monitored ransomware gang fleet statuses, darknet mirror availability, and MITRE ATT&CK dossiers.

GET /api/v1/groups

Retrieve all tracked ransomware groups with location telemetry, site availability, and post counts. profile uses the v3 object schema; a small number of legacy groups may expose it as an array of research references.

ParameterTypeStatusDescription
status string optional Filter by mirror health: online, issue, or offline. Matches when any location reports the status.
search string optional Substring match against the syndicate name or its known aliases.
has_posts boolean optional When true, only returns syndicates with at least one published victim.
Response Schema (200 OK)
{
  "count": 1,
  "results": [
    {
      "name": "qilin",
      "captcha": false,
      "parser": true,
      "javascript_render": true,
      "meta": null,
      "locations": [
        {
          "fqdn": "ijzn3...onion",
          "slug": "http://ijzn3...onion",
          "available": true,
          "site_status": "online",
          "home_screenshot": "screenshots/qilin/home.png",
          "last_html_hash": null
        }
      ],
      "profile": { "description": null, "aliases": [], "ttps": [], "references": [] },
      "post_count": 2371
    }
  ]
}
GET /api/v1/groups/{name}

Detailed intelligence dossier for a single threat actor, including MITRE ATT&CK TTPs, aliases, and paginated victim history.

ParameterTypeStatusDescription
name string path required Case-insensitive threat actor name (e.g. qilin).
include_posts boolean default: true Whether to embed the syndicate's victim disclosures.
limit integer default: 50, max: 500 Victim posts per page.
offset integer default: 0 Offset for victim post pagination.
Response Schema (200 OK)
{
  "name": "qilin",
  "captcha": false,
  "parser": true,
  "javascript_render": true,
  "locations": [ /* ...mirror objects... */ ],
  "profile": { "description": "...", "aliases": [], "ttps": [], "references": [] },
  "post_count": 2371,
  "posts": {
    "count": 2371,
    "limit": 50,
    "offset": 0,
    "results": [ /* ...victim disclosure objects... */ ]
  }
}

Stats & Velocity

Global platform telemetry, scrape execution metrics, and historical daily disclosure totals.

GET /api/v1/stats

Current intelligence summary, including 24-hour and 7-day leak velocity, active fleet ratio, and last scrape run metrics.

Response Schema (200 OK)
{
  "last_scrape": "2026-10-02T11:09:13Z",
  "groups_total": 402,
  "groups_active": 121,
  "posts_total": 33993,
  "posts_last_7d": 188,
  "timeframe_counts": { "24h": 41, "7d": 188, "30d": 980, "90d": 2208, "180d": 3806, "365d": 8367 },
  "group_post_counts": { "qilin": 2371, "play": 1284, "akira": 1701, "...": 0 },
  "group_latest_dates": { "qilin": "2026-10-01 00:00:00", "...": "..." },
  "scraper_version": "3.0.0",
  "last_scrape_details": {
    "last_run": "2026-10-02T11:09:12Z",
    "duration_seconds": 549,
    "groups_attempted": 119,
    "groups_succeeded": 79,
    "groups_failed": 40,
    "captcha_blocks": 1,
    "new_posts_found": 1,
    "posts_enriched": 1,
    "parser_breakages": [ /* ... */ ],
    "recent_runs": [ /* ... */ ]
  }
}
GET /api/v1/stats/history

Chronological time-series snapshots of daily victim disclosure volume per group over up to 365 days.

ParameterTypeStatusDescription
days integer default: 30, max: 365 Number of daily history records to return.
Response Schema (200 OK)
{
  "count": 2,
  "results": [
    {
      "date": "2026-10-01",
      "total_posts": 33859,
      "groups_active": 132,
      "groups": { "qilin": 2370, "play": 1272, "...": 0 }
    }
  ]
}

Health & Administration

Health monitoring and authorized data cache reload endpoints.

GET /api/v1/health

Lightweight liveness probe returning API operational status and total loaded record counts in memory.

Response Schema (200 OK)
{ "status": "ok", "posts_loaded": 33993, "groups_loaded": 402 }
POST /api/v1/reload

Forces an immediate reload of in-memory stores from disk or Cloudflare R2 CDN. Requires authorization.

HeaderTypeStatusDescription
X-API-Key string required Must match the configured RELOAD_API_KEY environment secret.
Responses
200 OK      { "status": "ok", "posts": 33993, "groups": 402 }
403 Forbidden  { "detail": "Invalid API key" }
503 Service Unavailable  { "detail": "Reload endpoint not configured (no RELOAD_API_KEY)" }

Static R2 Data Feeds

For bulk data analysis, threat ingestion pipelines, and SIEM/SOAR platforms, access raw static JSON and syndication feeds served directly via global CDN.

Usage & Operational Notes

Rate Limiting Public read endpoints are limited to 60 requests per minute per IP using a memory-backed token bucket. Responses return HTTP 429 when exceeded.
Safe Threat Intel Access Post URLs link to darknet .onion sites and should only be accessed via Tor browser or isolated proxies. CTI.FYI never provides direct downloads of leaked stolen data.
UTC Timestamps Disclosure timestamps (discovered and published) and all date filter parameters use UTC (YYYY-MM-DD HH:MM:SS.ffffff, YYYY-MM-DD HH:MM:SS, or YYYY-MM-DD).
Integrations & Support For inquiries, bulk ingestion access, or parser integration suggestions, contact ransom@cti.fyi.