Skip to main content

JSON objects

SearchCriteria

The name, operator and value fields must be used together.
The junction and elements fields must be used together and are used to create more complex queries.

NameRequiredTypeDefault valueDescription
nameNoStringThe ThreatEvent field you want to search for.
Allowed values : eventId, domain
Example: domain
operatorNoStringEQUALSThe search operator.
Allowed values : EQUALS, NOT_EQUALS, EQUALS_CASE_INSENSITIVE, STARTS_WITH, ENDS_WITH, CONTAINS, IN, GREATER_THAN, LESS_THAN, GREATER_THAN_OR_EQUALS, LESS_THAN_OR_EQUALS
valueNoString, String[], Integer, Integer[]The value of the name field.
Examples :
  • example.com
  • ['example.com', 'example.net']
junctionNoStringANDLogical operator used with the elements field.
Allowed values : AND, OR
elementsNoList of SearchCriteriaA list of SearchCriteria which will be used with the junction logical operator

SearchResult

NameTypeDefault valueDescription
totalIntegerTotal number of events matching the search criteria
limitInteger100Number of events returned
offsetInteger0Offset used
resultsList of ThreatEventList of events matching the search criteria

ThreatEvent

NameTypeDefault valueDescription
idStringThreat event identifier
dateStringDatetime of the event
typeStringEvent type (DOMAIN_REPORTED)
brandBrandBrand related to the threat event
domainStringDomain on which the threat event was detected
criticalityCriticalityThreat event's criticality
commentsList of CommentComments submitted
customer_idIntegerThe customer identifier of the event
observed_dataThreatEventObservedDataObserved data of the threat event (whois, dns records, website details/redirections)

Brand

NameTypeDefault valueDescription
idStringThreat event identifier
monitored_sinceStringDatetime of the first analyze
nameStringBrand name

Criticality

NameTypeDefault valueDescription
levelStringCriticality of the event
nameStringName of event's criticality

Comment

NameTypeDefault valueDescription
contentStringComment content
dateStringDatetime of comment submission

ThreatEventObservedData

NameTypeDefault valueDescription
dns_recordsDnsRecord[]DNS records of domain observed
whoisWhoisWhois of domain observed
websiteWebsiteWebsite of domain observed

DnsRecord

NameTypeDefault valueDescription
country_codeStringDns record country code
ipStringDns record ip
nameStringDns record name
typeStringDns record type (CNAME, A, PTR, CAA, TXT...)

Whois

NameTypeDefault valueDescription
owner_nameStringWhois owner name
owner_emailStringWhois owner email
owner_organisationStringWhois owner organization name
admin_nameStringWhois admin name
admin_emailStringWhois admin email
admin_organisationStringWhois admin organization name
registrar_nameStringRegistrar name of the domain
statusesString[]Domain statuses
creation_dateStringDomain creation date time
updated_dateStringDomain update date time
expiration_dateStringDomain expiration date time
resource_urlStringResource url of the raw whois

Website

NameTypeDefault valueDescription
page_titleStringWebsite page title
page_descriptionStringWebsite page description
origin_urlStringWebsite origin url
final_urlStringFinal url after redirection chain
redirection_typesString[]HTTP redirection code(s)
screenshot_resource_urlStringResource url of the website's screenshot
source_resource_urlStringResource url of the website's source code

GenericPage

NameTypeDefault valueDescription
dataArray[]Array of requested data
current_pageInteger0Current page number
total_pagesInteger0Total number of pages
total_itemsInteger0Total number of datas
page_sizeInteger100Page size
has_nextbooleanfalseNext page available
has_previousbooleanfalsePrevious page available