The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the Threat Explorer Data

Prev Next

This URL retrieves the threat explorer data.

Resource URL

GET /domain/<domain_id>/threatexplorer/alerts/TopN/<count>/direction/<direction>/duration/<duration>?includeChildDomain=<includeChildDomain>&&action=<action>&&value=<value>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domainId

Domain id

Number

Yes

count

Number of top attacks to display.

Values allowed are: 5,10,15,20 or 25

Boolean

No

direction

Direction of the attack.

Values allowed are: ANY, INBOUND & OUTBOUND

String

No

duration

Duration can be:

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOURS

  • LAST_12_HOURS

  • LAST_24_HOURS

  • LAST_48_HOURS

  • LAST_7_DAYS

  • LAST_14_DAYS

String

Yes

includeChildDomain

Include the child domains.

Default is true

Boolean

No

action

Should the data be filtered or grouped.

Values allowed are:

  • Group(default)

  • Filter

String

No

value

If action is group, then there is no need of any data,

default value is an empty string If the action is filter.

We can give multiple filters separated by ":::".

The format of value will be <filter_name1>=<filter_value>:::

<filter_name2>=<filter_value> .

The filter_name's and filter_values allowed are:

  • attack -> value should be a valid attack name.

  • severity -> value can be High, Low,

    Medium & Informational (all are case sensitive).

  • category -> value should be a valid category.

  • subCategory -> value should be a valid sub category.

  • attackerIp -> value should be a valid IP.

  • dnsName -> value should be a string.

  • country -> value should be a valid country name.

  • user -> value should be a

    valid user name/unknown.

  • victimIp -> value should be a valid IP.

  • victimDnsName -> value should be a string.

  • victimCountry -> value should be a valid country name.

  • victimUser -> value should be a

    valid user name/unknown.

  • applicationName -> value should be a

    valid application name.

  • applicationRisk -> value can be high,

    low & medium.

  • applicationCategory -> value should be a

    valid application category.

  • fileHash -> value should be a string.

  • executableHash -> value should be a string.

  • malwareConfidence -> value should be a

    valid malware confidence.

  • fileSize -> value should be a number.

  • executableConfidence -> value can be clean,

    high, low, medium, unknown,

    veryhigh & verylow.

  • executableClassification -> value can be

    block, none,

    unclassified, and allow.

  • executableName

String

No

Response Parameters

Following fields are returned.

Field Name

Description

Data Type

ThreatExplorerData

List of top attacks

Objectlist

Details of fields in ThreatExplorerData:

Field Name

Description

Data Type

topAttacks

List of all the top attacks. The data is same as TE top attacks explained in 1.2.3

Object

topAttackers

List of all the top attackers. The data is same as TE top attackers explained in 1.3.3

Object

topTargets

List of all the top targets. The data is same as TE top targets explained in 1.4.3

Object

topAttackApplications

List of all the top attack applications. The data is same as TE top attack applications explained in 1.5.3

Object

topAttackExecutables

List of all the top executables. The data is same as TE top executables explained in 1.7.3

Object

topMalware

List of all the top malwares. The data is same as TE top malware downloads explained in 1.6.3

Object

Example

Request

GET https:// <NSM_IP>/sdkapi/domain/0/threatexplorer/alerts/TopN/10/direction/ANY/duration/LAST_12_HOURS?action=filter&&value=malwareConfidence=Very High:::country=Thailand

Response

    {

    "topAttacks": {
        "TETopAttacksList": [
            {
                "attackName": "TFTP: 3CDaemon Reserved Device Name DOS",
                "attackCategory": "Exploit",
                "attackSubcategory": "dos",
                "attackSeverity": "Medium",
                "attackCount": 276598.0
            },
            {
                "attackName": "IPv4: Malformed Options Evasion Attempt Detected",
                "attackCategory": "Exploit",
                "attackSubcategory": "evasion-attempt",
                "attackSeverity": "High",
                "attackCount": 260349.0
            },
        ]
    },
    "topAttackers": {
        "TETopAttackersList": [
            {
                "attackerIP": "1.0.0.0",
                "attackerDNSName": "",
                "attackerCountry": "India",
                "attackerUser": "Unknown",
                "attackCount": 239891.0
            },
            {
                "attackerIP": "1.1.1.0",
                "attackerDNSName": "",
                "attackerCountry": "India",
                "attackerUser": "Unknown",
                "attackCount": 156007.0
            },
        ]
    },
    "topTargets": {
        "TETopTargetsList": [
            {
                "targetIP": "2.0.0.0",
                "targetDNSName": "",
                "targetCountry": "India",
                "targetUser": "Unknown",
                "attackCount": 357107.0
            },
            {
                "targetIP": "2.2.0.0",
                "targetDNSName": "",
                "targetCountry": "India",
                "targetUser": "Unknown",
                "attackCount": 160772.0
            },
        ]
    },
    "topAttackApplications": {
        "TETopAttackApplicationsList": [
            {
                "applicationName": "HTTP",
                "applicationRisk": "Low",
                "applicationCategory": "Infrastructure Services",
                "attackCount": 783360.0
            },
            {
                "applicationName": "TFTP",
                "applicationRisk": "High",
                "applicationCategory": "File Sharing",
                "attackCount": 285479.0
            },
        ]
    },
    "topAttackExecutables": {
        "TETopExecutablesList": []
    },
    "topMalware": {
        "TETopMalwareDownloadsList": [
            {
                "malwareFileHash": "119ed0d821a7c81d6b2277251c01ddc1",
                "malwareConfidence": "Very High",
                "malwareFileSizeInBytes": "5972",
                "attackCount": 798.0
            },
            {
                "malwareFileHash": "075c8160789eb0829434a4fc9b59ed6c",
                "malwareConfidence": "Very High",
                "malwareFileSizeInBytes": "2914",
                "attackCount": 404.0
        ]
    }
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1105

Invalid domain

2

404

4201

Invalid duration filter