Servis durumu kontrol ediliyor

Türkiye’ye özel tehdit istihbaratı. Tek bir API’de.

Bankaların dolandırıcılıkla mücadele ekipleri, SOC/CERT analistleri, MISP/OpenCTI kullanıcıları ve güvenlik duvarı (Firewall/DNS) yöneticileri için Türkiye odaklı, gerçek zamanlı oltalama ve sahtecilik veri beslemesi.

Sandbox demo anahtarıForm doldurmadan terminalden deneyin. Hız limiti: dakikada 60 istek.
olt_sandbox_public_demo_key
STIX 2.1JSON IoCPlain text EDLBIND 9 RPZMISPWebhook
GET/api/v1/feed/iocs
örnek yanıt
{
  "total_count": 1847,
  "generated_at": "2026-09-21T11:04:52Z",
  "iocs": [
    {
      "domain": "kargo-teslimat-takip.top",
      "target_brand": "Örnek Kargo",
      "threat_type": "phishing",
      "confidence_score": 94,
      "first_seen": "2026-09-21T09:17:03Z"
    },
    {
      "domain": "hgs-ceza-sorgula.xyz",
      "target_brand": "HGS",
      "threat_type": "fake_government_portal",
      "confidence_score": 88
    }
  ]
}
200 OKapplication/json
Servis durumu

Rakamlar süs değil, her ziyarette ölçülür.

Bu bölümdeki değerler sayfa açıldığında /api/v1/status uç noktasından canlı okunur. Yanıt süresi sizin tarayıcınızdan ölçülür.

API yanıt süresicanlı
000ms

Tarayıcınızdan yapılan son ölçümlerin ortancası

Siber Güvenlik Başkanlığı engelli alan adı
00.000

Bellekte tutulan ve her istekte sorgulanan kayıt

Son senkronizasyon00:00
KaynakSiber Güvenlik Başkanlığı ulusal listesi
Kesintisiz çalışma
0 00

Son yeniden başlatmadan bu yana

Platform sürümü0.0.0
Standart ve formatlar

Tüm güvenlik ekosistemi için dört çıktı formatı.

Oltanom CTI akışı; SIEM platformlarından en sade DNS sinkhole sunucularına kadar tüm güvenlik mimarilerine doğrudan entegre olur.

OASIS standardı

STIX 2.1 tehdit paketi

Indicator, Malware, Relationship, Identity ve Attack Pattern nesnelerini içeren küresel siber güvenlik standardı. MISP, OpenCTI, Splunk ES ve Microsoft Sentinel ile uyumludur.

GET/api/v1/feed/stix
Hafif JSON

Canlı IoC tehdit akışı

Yüksek performanslı otomasyonlar ve SOC panelleri için hafif JSON formatı. Alan adı, hedef marka, güven skoru, IP adresi ve ilk görülme zamanını içerir.

GET/api/v1/feed/iocs
Firewall / EDL

Düz metin engelleme listesi

FortiGate, Palo Alto Networks External Dynamic Lists (EDL), pfSense, Pi-hole ve AdGuard için satır satır engelleme listesi. Periyodik cron ile otomatik çekilebilir.

GET/api/v1/feed/domains.txt
DNS sinkhole

BIND 9 DNS RPZ bölgesi

Kurumsal DNS sunucularında zararlı alan adlarını anında sinkhole’a yönlendirmek için standart BIND Response Policy Zone (RPZ) formatı.

GET/api/v1/feed/rpz
İnteraktif konsol

Canlı API gezgini ve kod örnekleri.

Uç noktayı seçin; cURL, Python, Node.js veya Go kodunu kopyalayın ya da isteği doğrudan tarayıcıdan gönderip canlı yanıtı görün.

GEThttps://oltanom.com/api/v1/feed/stix
curl -X GET "https://oltanom.com/api/v1/feed/stix" \
  -H "Accept: application/json"
Canlı yanıthazır
Canlı veriyi görmek için “İsteği gönder” düğmesine basın.
Anlık olay bildirimleri

SOC webhook bildirimleri.

Oltanom yeni bir oltalama sitesi ya da markanızı taklit eden bir tuzak tespit ettiği anda SIEM/SOAR veya takedown sisteminize anlık HTTP POST bildirimi gönderir.

event: threat.detected · brand.impersonation

Webhook güvenliği ve HMAC-SHA256 doğrulaması

Tüm webhook paketleri X-Oltanom-Signature başlığı altında gizli anahtarınızla (secret) HMAC-SHA256 imzalı olarak iletilir. Sahte bildirimleri engellemek için imzayı mutlaka doğrulayın.

  1. İsteğin ham gövdesini (raw body) değiştirmeden okuyun.
  2. Gövdeyi kendi secret anahtarınızla HMAC-SHA256 ile imzalayın.
  3. Sonucu X-Oltanom-Signature değeriyle sabit zamanlı karşılaştırın.
POST/webhook/oltanom
Örnek webhook paketi
{
  "event": "threat.detected",
  "event_id": "9b1deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d",
  "timestamp": "2026-08-21T02:45:00.000Z",
  "severity": "critical",
  "threat": {
    "domain": "ornek-banka-kredi-onay.xyz",
    "url": "https://ornek-banka-kredi-onay.xyz/giris",
    "ip": "203.0.113.45",
    "target_brand": "Örnek Banka",
    "threat_type": "malicious_phishing",
    "confidence_score": 95,
    "summary": "Sahte banka mobil giriş ve SMS tek kullanımlık şifre tuzağı.",
    "tags": [
      "turkey-cyber-threat",
      "banking-phishing",
      "target:ornek-banka"
    ]
  }
}
Örnek alıcı kodu
import hmac
import hashlib
import os
from flask import Flask, request, jsonify

app = Flask(__name__)
WEBHOOK_SECRET = os.getenv("OLTANOM_SECRET", "whsec_your_secret_key")

@app.route('/webhook/oltanom', methods=['POST'])
def handle_oltanom_webhook():
    signature_header = request.headers.get('X-Oltanom-Signature', '')
    raw_payload = request.get_data()

    # HMAC-SHA256 imza doğrulaması
    computed_signature = 'sha256=' + hmac.new(
        WEBHOOK_SECRET.encode('utf-8'),
        raw_payload,
        hashlib.sha256
    ).hexdigest()

    if not hmac.compare_digest(signature_header, computed_signature):
        return jsonify({"error": "Geçersiz imza"}), 401

    data = request.json
    threat = data.get("threat", {})

    print(f"[ALARM] Oltanom tehdit bildirimi: {threat.get('domain')} -> Hedef: {threat.get('target_brand')}")
    # TODO: SOAR / takedown tetikleme fonksiyonunuz

    return jsonify({"status": "received"}), 200

if __name__ == '__main__':
    app.run(port=8080)
HTTP hata durumları

API hata kodları ve şemaları.

Oltanom REST API tüm hata durumlarında standart ve öngörülebilir JSON formatında yanıt döner.

400Bad Request

Geçersiz URL parametresi veya eksik zorunlu alan.

{
  "success": false,
  "error_code": "INVALID_INPUT",
  "error": "Taranacak geçerli bir 'url' parametresi zorunludur."
}
401Unauthorized

Geçersiz ya da süresi dolmuş API anahtarı veya webhook imzası.

{
  "success": false,
  "error_code": "UNAUTHORIZED",
  "error": "Geçersiz API Anahtarı veya HMAC İmzası."
}
429Too Many Requests

Hız limiti aşıldı. Yanıt Retry-After başlığını içerir.

{
  "success": false,
  "error_code": "RATE_LIMIT_EXCEEDED",
  "retry_after_sec": 30,
  "error": "Çok fazla istek gönderildi."
}
500Server Error

Analiz motoru veya sunucu tarafında beklenmeyen hata.

{
  "success": false,
  "error_code": "INTERNAL_SERVER_ERROR",
  "error": "URL analizi gerçekleştirilemedi."
}
Şeffaflık ve güncellemeler

CTI feed sürüm geçmişi.

Tehdit akışı ve veri modellerimizdeki son geliştirmeler ve değişiklik kayıtları.

v1.2.0güncel21 Ağustos 2026

SOC webhook desteği, BIND 9 RPZ ve canlı status servisi

  • SOC ve dolandırıcılıkla mücadele birimleri için anlık HMAC-SHA256 imzalı webhook bildirim mimarisi (Python ve Node.js alıcıları) dokümante edildi.
  • BIND 9 DNS RPZ sinkhole zone desteği (/api/v1/feed/rpz) eklendi.
  • CTI altyapısının çalışma durumunu anlık sunan /api/v1/status uç noktası devreye alındı.
  • Anında otomatik API anahtarı üretimi aktifleştirildi.
v1.1.020 Ağustos 2026

STIX 2.1 toplu bundle ve MISP formatı

  • OASIS STIX 2.1 standartlarına tam uyumlu toplu bundle ihracı (/api/v1/feed/stix) devreye alındı.
  • Hafif JSON IoC akışı ile FortiGate/Palo Alto EDL uyumlu düz metin engelleme listesi eklendi.
  • MISP Event ihracı (/api/v1/feed/misp) aktif edildi.
v1.0.015 Ağustos 2026

İlk milli CTI feed ve URL risk analizi REST API lansmanı

  • Oltanom otonom yapay zekâ tespit motoru CTI veri besleme çekirdeği oluşturuldu.
  • Kurumsal URL risk analizi REST API (/api/v1/scan) yayına girdi.
SOC / SIEM / Firewall

Kurumsal entegrasyon rehberleri.

Mevcut güvenlik altyapınıza Oltanom CTI akışını birkaç dakikada bağlayın.

MISP entegrasyonu

MISP panelinde Feeds → Add Feed bölümüne gidin. Feed URL alanına Oltanom MISP besleme adresini ekleyin.

https://oltanom.com/api/v1/feed/misp

FortiGate / Palo Alto EDL

Güvenlik duvarı konsolunda External Threat Feeds (EDL) oluşturun. Formatı IP/Domain listesi olarak seçip adresi tanımlayın.

https://oltanom.com/api/v1/feed/domains.txt

OpenCTI connector

OpenCTI STIX 2.1 connector yapılandırmasında (docker-compose) akış adresini Oltanom STIX uç noktasına bağlayın.

https://oltanom.com/api/v1/feed/stix

BIND 9 DNS sinkhole

named.conf dosyanıza response-policy tanımlayın ve RPZ zone dosyasını periyodik curl/wget ile güncelleyin.

zone "rpz.oltanom.com" { type master; file "..."; };
Yetkili erişim ve onay süreci

Kurumsal CTI ve REST API başvurusu.

Oltanom tehdit istihbaratı ve API beslemeleri, operasyonel güvenlik ve veri gizliliği politikaları gereği yalnızca bankalar, finans kuruluşları, kamu kurumları, SOC/MSSP ve altyapı sağlayıcılarına kontrollü olarak sunulur.

Güvenlik ve yetkilendirme politikası. Başvurunuz, kurum unvanı ve kurumsal e-posta doğrulamasının ardından Oltanom Güvenlik Kurulu tarafından incelenir. Onaylanan kurumlara tahsis edilen API anahtarı, IP beyaz liste onayı ve SOC webhook secret bilgisi yetkili kurumsal e-posta adresine güvenli kanaldan iletilir.
Erişim ve pilot. Erişim kapsamı, sorgu hacmi ve SLA gereksinimleri başvuru sonrasında kurumunuzla birlikte belirlenir. Onaylanan kurumlar entegrasyonu kendi ortamlarında 30 günlük pilot (POC) erişimiyle test edebilir.
Jenerik e-posta adresleriyle (gmail, hotmail vb.) yapılan başvurular onaylanmaz.

Kurumsal erişim başvurunuz alındı

Talebiniz kayıt altına alındı ve güvenlik ve yetkilendirme incelemesi başlatıldı. Kurumsal e-posta doğrulamasının ardından onaylandığında API erişim anahtarlarınız ve entegrasyon kılavuzunuz yetkili e-posta adresinize iletilecektir.

Başvuru referans no-
Başvuran kurum-
Değerlendirme durumuİncelemede
Checking service status

Threat intelligence built for Türkiye. In a single API.

A Türkiye-focused, real-time phishing and fraud intelligence feed for bank anti-fraud teams, SOC/CERT analysts, MISP/OpenCTI operators and firewall/DNS administrators.

Sandbox demo keyTest from your terminal without filling in a form. Rate limit: 60 requests per minute.
olt_sandbox_public_demo_key
STIX 2.1JSON IoCPlain text EDLBIND 9 RPZMISPWebhook
GET/api/v1/feed/iocs
sample response
{
  "total_count": 1847,
  "generated_at": "2026-09-21T11:04:52Z",
  "iocs": [
    {
      "domain": "kargo-teslimat-takip.top",
      "target_brand": "Örnek Kargo",
      "threat_type": "phishing",
      "confidence_score": 94,
      "first_seen": "2026-09-21T09:17:03Z"
    },
    {
      "domain": "hgs-ceza-sorgula.xyz",
      "target_brand": "HGS",
      "threat_type": "fake_government_portal",
      "confidence_score": 88
    }
  ]
}
200 OKapplication/json
Service status

These numbers are measured on every visit.

Values in this section are read live from the /api/v1/status endpoint when the page loads. Response time is measured from your own browser.

API response timelive
000ms

Median of the latest measurements from your browser

Cyber Security Directorate blocked domains
00.000

Held in memory and checked on every request

Last sync00:00
SourceCyber Security Directorate national list
Uptime
0 00

Since the last restart

Platform version0.0.0
Standards and formats

Four output formats for the whole security stack.

The Oltanom CTI feed plugs directly into any security architecture, from enterprise SIEM platforms to the simplest DNS sinkhole servers.

OASIS standard

STIX 2.1 threat bundle

The global threat intelligence standard with Indicator, Malware, Relationship, Identity and Attack Pattern objects. Compatible with MISP, OpenCTI, Splunk ES and Microsoft Sentinel.

GET/api/v1/feed/stix
Lightweight JSON

Live IoC threat feed

A lightweight JSON format for high-throughput automations and SOC dashboards. Includes domain, target brand, confidence score, IP address and first-seen time.

GET/api/v1/feed/iocs
Firewall / EDL

Plain text blocklist

A line-by-line blocklist for FortiGate, Palo Alto Networks External Dynamic Lists (EDL), pfSense, Pi-hole and AdGuard. Can be pulled automatically with a periodic cron job.

GET/api/v1/feed/domains.txt
DNS sinkhole

BIND 9 DNS RPZ zone

Standard BIND Response Policy Zone (RPZ) format for instantly sinkholing malicious domains on enterprise DNS servers.

GET/api/v1/feed/rpz
Interactive console

Live API explorer and code samples.

Pick an endpoint, copy the cURL, Python, Node.js or Go snippet, or send the request straight from your browser and see the live response.

GEThttps://oltanom.com/api/v1/feed/stix
curl -X GET "https://oltanom.com/api/v1/feed/stix" \
  -H "Accept: application/json"
Live responseready
Press “Send request” to see live data.
Real-time event notifications

SOC webhook notifications.

The moment Oltanom detects a new phishing site or a trap impersonating your brand, it sends a real-time HTTP POST notification to your SIEM/SOAR or takedown system.

event: threat.detected · brand.impersonation

Webhook security and HMAC-SHA256 verification

Every webhook payload is signed with your secret using HMAC-SHA256 and delivered in the X-Oltanom-Signature header. Always verify the signature to reject forged notifications.

  1. Read the raw request body without modifying it.
  2. Sign the body with your own secret using HMAC-SHA256.
  3. Compare the result with X-Oltanom-Signature in constant time.
POST/webhook/oltanom
Sample webhook payload
{
  "event": "threat.detected",
  "event_id": "9b1deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d",
  "timestamp": "2026-08-21T02:45:00.000Z",
  "severity": "critical",
  "threat": {
    "domain": "ornek-banka-kredi-onay.xyz",
    "url": "https://ornek-banka-kredi-onay.xyz/giris",
    "ip": "203.0.113.45",
    "target_brand": "Örnek Banka",
    "threat_type": "malicious_phishing",
    "confidence_score": 95,
    "summary": "Fake bank mobile login and SMS one-time password trap.",
    "tags": [
      "turkey-cyber-threat",
      "banking-phishing",
      "target:ornek-banka"
    ]
  }
}
Sample receiver code
import hmac
import hashlib
import os
from flask import Flask, request, jsonify

app = Flask(__name__)
WEBHOOK_SECRET = os.getenv("OLTANOM_SECRET", "whsec_your_secret_key")

@app.route('/webhook/oltanom', methods=['POST'])
def handle_oltanom_webhook():
    signature_header = request.headers.get('X-Oltanom-Signature', '')
    raw_payload = request.get_data()

    # HMAC-SHA256 signature verification
    computed_signature = 'sha256=' + hmac.new(
        WEBHOOK_SECRET.encode('utf-8'),
        raw_payload,
        hashlib.sha256
    ).hexdigest()

    if not hmac.compare_digest(signature_header, computed_signature):
        return jsonify({"error": "Invalid signature"}), 401

    data = request.json
    threat = data.get("threat", {})

    print(f"[ALERT] Oltanom threat notification: {threat.get('domain')} -> Target: {threat.get('target_brand')}")
    # TODO: trigger your SOAR / takedown function

    return jsonify({"status": "received"}), 200

if __name__ == '__main__':
    app.run(port=8080)
HTTP error states

API error codes and schemas.

The Oltanom REST API returns a consistent, predictable JSON body for every error state.

400Bad Request

Invalid URL parameter or a missing required field.

{
  "success": false,
  "error_code": "INVALID_INPUT",
  "error": "A valid 'url' parameter is required."
}
401Unauthorized

Invalid or expired API key, or an invalid webhook signature.

{
  "success": false,
  "error_code": "UNAUTHORIZED",
  "error": "Invalid API key or HMAC signature."
}
429Too Many Requests

Rate limit exceeded. The response includes a Retry-After header.

{
  "success": false,
  "error_code": "RATE_LIMIT_EXCEEDED",
  "retry_after_sec": 30,
  "error": "Too many requests."
}
500Server Error

An unexpected error in the analysis engine or on the server.

{
  "success": false,
  "error_code": "INTERNAL_SERVER_ERROR",
  "error": "URL analysis could not be completed."
}
Transparency and updates

CTI feed changelog.

The latest improvements and change records for our threat feed and data models.

v1.2.0currentAugust 21, 2026

SOC webhooks, BIND 9 RPZ and a live status service

  • Documented the real-time, HMAC-SHA256 signed webhook architecture for SOC and anti-fraud teams (Python and Node.js receivers).
  • Added BIND 9 DNS RPZ sinkhole zone support (/api/v1/feed/rpz).
  • Launched the /api/v1/status endpoint that reports the live state of the CTI infrastructure.
  • Enabled instant automatic API key generation.
v1.1.0August 20, 2026

STIX 2.1 bulk bundle and MISP format

  • Launched bulk bundle export fully compliant with OASIS STIX 2.1 (/api/v1/feed/stix).
  • Added the lightweight JSON IoC feed and a FortiGate/Palo Alto EDL compatible plain text blocklist.
  • Enabled MISP Event export (/api/v1/feed/misp).
v1.0.0August 15, 2026

First national CTI feed and URL risk analysis REST API

  • Built the CTI data feed core of the Oltanom autonomous AI detection engine.
  • Released the enterprise URL risk analysis REST API (/api/v1/scan).
SOC / SIEM / Firewall

Enterprise integration guides.

Connect the Oltanom CTI feed to your existing security stack in a few minutes.

MISP integration

In MISP, go to Feeds → Add Feed and add the Oltanom MISP feed address as the feed URL.

https://oltanom.com/api/v1/feed/misp

FortiGate / Palo Alto EDL

Create an External Threat Feed (EDL) in the firewall console, choose the IP/Domain list format and enter the address.

https://oltanom.com/api/v1/feed/domains.txt

OpenCTI connector

Point the feed address in your OpenCTI STIX 2.1 connector configuration (docker-compose) to the Oltanom STIX endpoint.

https://oltanom.com/api/v1/feed/stix

BIND 9 DNS sinkhole

Define a response-policy in named.conf and refresh the RPZ zone file with a periodic curl/wget job.

zone "rpz.oltanom.com" { type master; file "..."; };
Authorized access and review

Enterprise CTI and REST API application.

Under our operational security and data privacy policies, Oltanom threat intelligence and API feeds are provided on a controlled basis only to banks, financial institutions, public bodies, SOC/MSSP teams and infrastructure providers.

Security and authorization policy. Your application is reviewed by the Oltanom Security Board after the organization name and corporate email address are verified. Approved organizations receive their API key, IP allowlist confirmation and SOC webhook secret at the authorized corporate email address over a secure channel.
Access and pilot. Access scope, query volume and SLA requirements are defined together with your organization after you apply. Approved organizations can test the integration in their own environment with a 30-day pilot (POC).
Applications from generic email providers (gmail, hotmail, etc.) are not approved.

Your enterprise access application has been received

Your request has been recorded and a security and authorization review has started. Once your corporate email is verified and the application is approved, your API access keys and integration guide will be sent to the authorized email address.

Application reference-
Organization-
Review statusUnder review