The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the List of Top Attacks

Prev Next

This URL retrieves the list of top attacks.

Resource URL

GET /domain/<domain_id>/threatexplorer/alerts/TopN/<count>/direction/<direction>/duration/<duration>/attacks?includeChildDomain=<includeChildDomain>&&action=<action>&&value=<value>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domainId Domain id Number Yes
count Number of top attacks to display.

Values allowed are: 5,10,15,20 or 25

Boolean No
direction Direction of the attack.

Values allowed are: ANY, INBOUND & OUTBOUND

String No
duration Duration can be:
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOURS
  • LAST_12_HOURS
  • LAST_24_HOURS
  • LAST_48_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
String Yes
includeChildDomain Include the child domains. Default is true Boolean No
action Should the data be filtered or grouped.

Values allowed are:

  • Group(default)
  • Filter
String No
value

If action is group, the values allowed are:

  • attack (default)
  • severity
  • category
  • subCategory

If the action is filter, we can give multiple filters separated by ":::".

The format of value will be <filter_name1>=<filter_value>:::

<filter_name2>=<filter_value> .

The filter_name's and filter_values allowed are:

  • attack -> value should be a valid attack name.
  • severity -> value can be High, Low,

    Medium & Informational (all are case sensitive).

  • category -> value should be a valid category.
  • subCategory -> value should be a valid sub category.
  • attackerIp -> value should be a valid IP.
  • dnsName -> value should be a string.
  • country -> value should be a valid country name.
  • user -> value should be a

    valid user name/unknown.

  • victimIp -> value should be a valid IP.
  • victimDnsName -> value should be a string.
  • victimCountry -> value should be a valid country name.
  • victimUser -> value should be a

    valid user name/unknown.

  • applicationName -> value should be a

    valid application name.

  • applicationRisk -> value can be high,

    low & medium.

  • applicationCategory -> value should be a

    valid application category.

  • fileHash -> value should be a string.
  • executableHash -> value should be a string.
  • malwareConfidence -> value should be a

    valid malware confidence.

  • fileSize -> value should be a number.
  • executableConfidence -> value can be clean,

    high, low, medium, unknown,

    veryhigh & verylow.

  • executableClassification -> value can be

    block, none,

    unclassified, and allow.

  • executableName
String No

Response Parameters

Following fields are returned.

Field Name Description Data Type
TETopAttacks List of top attacks. It contains TE top attacks list. Object

Details of fields in TETopAttacksList:

Field Name Description Data Type
attackName Name of the attack String
attackCategory Category of the attack String
attackSubcategory Sub category of the attack String
attackSeverity Severity of the attack String
attackCount Numbers of the attack Number

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/threatexplorer/alerts/TopN/10/direction/ANY/duration/LAST_12_HOURS/attacks?action=filter&&value=malwareConfidence=Very High

Response

 {
    "TETopAttacksList": [
        {
            "attackName": "MALWARE: Malicious PDF file transfer detected",
            "attackCategory": "Malware",
            "attackSubcategory": "PDF-Emulation",
            "attackSeverity": "High",
            "attackCount": 3950.0
        },
    ]
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1105 Invalid domain
2 400 3707 Top count should be 5,10,15,20 or 25
3 400 3702 Invalid action
4 400 3701 Invalid "GroupBy" string specified
5 400 3704 Invalid filters specified
6 400 3703 Invalid direction
7 400 3601 Invalid duration