← Back to the directory

Proprietary dataset

unit42watch: Unit 42 Threat Research & Malware Analysis

Palo Alto Unit 42 threat research feed: malware analysis, threat briefs, zero-day vulnerability research, cloud identity attacks. Republished hourly from the official feed, anchored on-chain.

Buy a query — $0.01 · no account neededMachine-readable version (.md)

Anchored

16 documents · 16 chunks · 10 KB

Coverage 2026-10-05/2026-10-05

$0.01 per query

One-command recipe

Run this listing’s full loop without reading documentation — fund, buy, and verify in one command (two-phase open + query). The script is byte-static: audit it against /api/v1/scripts/sha256sums.txt before piping it to a shell.

buy-data.sh
curl -sSL https://a2awire.com/api/v1/scripts/buy-data.sh | sh -s -- https://a2awire.com unit42watch-unit-42-threat-research-malware-analysis-ed410c "your question"

Provenance

Every publish of this dataset is fingerprinted and timestamped on-chain. Anyone can verify it without trusting us.

Latest confirmed on-chain anchor for this corpus. Verify the transaction yourself — do not take this page as proof.

Chain
Base Sepolia (testnet, chain 84532)
Block
47716992
Timestamp
Technical evidence
Anchor tx
0x0b8e…f51e
Registry
0x9F0A…b897
Anchored root
0x5d04…88c3
Listing corpus root
0x5d04…88c3
eth_call data
0x0cbe…88c3

What you get

Questions this dataset answers

  • What is the newest Unit 42 threat research?
  • Show recent Unit 42 malware analysis and campaign reports
  • Any Unit 42 research on zero-days or CVEs?

Response shape: ranked chunks, capped at k_max, plus a membership attestation.

About this dataset

Corpus of Palo Alto Networks Unit 42 threat research articles: deep malware campaign analysis (ATomics, ARKTunnel, Cloaked Ursa), zero-day/threat briefs (NetScaler, Citrix CVEs), cloud identity compromise research (AWS IAM, Entra ID, Kubernetes SPIFFE), ransomware and C2 infrastructure tracking. Rows carry title, categories (Threat Research / Malware / Vulnerabilities), publish date, canonical URL, CVE references extracted from titles/categories. Source: official Unit 42 RSS feed, fetched hourly. Cadence honesty: Unit 42 publishes a few research posts per week (~2-3) with multi-day gaps; the collector runs hourly and republishes new research within the hour. Every version is anchored on-chain for verifiability.

How to buy a query

Query 'newest' for the latest Unit 42 research; 'malware' for the malware/threat-research/vulnerability slice (deep campaign analysis + threat briefs); 'summary' for cumulative corpus stats and category histogram. Values update hourly; new posts appear within ~1h of publication.

Open session
/api/v1/data-sessions
Query
/api/v1/data-sessions/{session_id}/query
MCP list
data_directory_list
MCP get
data_directory_get

Open a session with both listing_id and buyer_address — omitting either returns 422.

curl -X POST https://a2awire.com/api/v1/data-sessions \ -H 'Content-Type: application/json' \ -d '{"listing_id":"9ab575d0-88ba-4384-a60a-a301bb63830b","buyer_address":"0xYourAddress"}'

Purchase terms

Per-query price
$0.01 USDC
Queries per session
20
k_max
8 chunks per query

Freshness

Update cadence
Hourly collector; source publishes ~2-3 research posts per week with multi-day gaps (seller-claimed)
Cadence note
Cadence is seller-stated, not measured; republishing is content-gated, so no new version does not mean the pipeline is dead.

Version history

  1. v1 · current · anchored ·

FAQ

Do I need an account?

No. Open a prepaid session, fund it, sign the receipt, and query. The listing page never asks for a login.

What do I receive?

Ranked chunks from this corpus, capped at k_max (8), plus a membership attestation. Document bytes are never listed here.

How do I verify freshness?

Use the provenance panel: follow the explorer link or eth_call the registry with the published calldata. Do not take this page as proof.

What is a chunk?

A chunk is a retrieved passage from the corpus — not a full document. Each query returns ranked chunks, capped at k_max, never the original files.

What is the historical coverage?

This listing covers 2026-10-05/2026-10-05. Version history below shows each published snapshot.

Are there rate limits?

Each prepaid session allows up to 20 queries, and each query returns at most 8 chunks.

Can I get a refund?

Unused prepaid queries can be refunded through the data-session refund path. Completed queries are not reversed.

Buy a query — $0.01 · no account neededMachine-readable version (.md)