This URL retrieves the threat explorer data.
Resource URL
GET /domain/<domain_id>/threatexplorer/alerts/TopN/<count>/direction/<direction>/duration/<duration>?includeChildDomain=<includeChildDomain>&&action=<action>&&value=<value>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
| Number of top attacks to display. Values allowed are: 5,10,15,20 or 25 | Boolean | No |
| Direction of the attack. Values allowed are: ANY, INBOUND & OUTBOUND | String | No |
| Duration can be:
| String | Yes |
| Include the child domains. Default is true | Boolean | No |
| Should the data be filtered or grouped. Values allowed are:
| String | No |
| If action is group, then there is no need of any data, default value is an empty string If the action is filter. We can give multiple filters separated by ":::". The format of value will be <filter_name1>=<filter_value>::: <filter_name2>=<filter_value> . The filter_name's and filter_values allowed are:
| String | No |
Response Parameters
Following fields are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of top attacks | Objectlist |
Details of fields in ThreatExplorerData:
Field Name | Description | Data Type |
|---|---|---|
topAttacks | List of all the top attacks. The data is same as TE top attacks explained in 1.2.3 | Object |
topAttackers | List of all the top attackers. The data is same as TE top attackers explained in 1.3.3 | Object |
topTargets | List of all the top targets. The data is same as TE top targets explained in 1.4.3 | Object |
topAttackApplications | List of all the top attack applications. The data is same as TE top attack applications explained in 1.5.3 | Object |
topAttackExecutables | List of all the top executables. The data is same as TE top executables explained in 1.7.3 | Object |
topMalware | List of all the top malwares. The data is same as TE top malware downloads explained in 1.6.3 | Object |
Example
Request
Response
{
"topAttacks": {
"TETopAttacksList": [
{
"attackName": "TFTP: 3CDaemon Reserved Device Name DOS",
"attackCategory": "Exploit",
"attackSubcategory": "dos",
"attackSeverity": "Medium",
"attackCount": 276598.0
},
{
"attackName": "IPv4: Malformed Options Evasion Attempt Detected",
"attackCategory": "Exploit",
"attackSubcategory": "evasion-attempt",
"attackSeverity": "High",
"attackCount": 260349.0
},
]
},
"topAttackers": {
"TETopAttackersList": [
{
"attackerIP": "1.0.0.0",
"attackerDNSName": "",
"attackerCountry": "India",
"attackerUser": "Unknown",
"attackCount": 239891.0
},
{
"attackerIP": "1.1.1.0",
"attackerDNSName": "",
"attackerCountry": "India",
"attackerUser": "Unknown",
"attackCount": 156007.0
},
]
},
"topTargets": {
"TETopTargetsList": [
{
"targetIP": "2.0.0.0",
"targetDNSName": "",
"targetCountry": "India",
"targetUser": "Unknown",
"attackCount": 357107.0
},
{
"targetIP": "2.2.0.0",
"targetDNSName": "",
"targetCountry": "India",
"targetUser": "Unknown",
"attackCount": 160772.0
},
]
},
"topAttackApplications": {
"TETopAttackApplicationsList": [
{
"applicationName": "HTTP",
"applicationRisk": "Low",
"applicationCategory": "Infrastructure Services",
"attackCount": 783360.0
},
{
"applicationName": "TFTP",
"applicationRisk": "High",
"applicationCategory": "File Sharing",
"attackCount": 285479.0
},
]
},
"topAttackExecutables": {
"TETopExecutablesList": []
},
"topMalware": {
"TETopMalwareDownloadsList": [
{
"malwareFileHash": "119ed0d821a7c81d6b2277251c01ddc1",
"malwareConfidence": "Very High",
"malwareFileSizeInBytes": "5972",
"attackCount": 798.0
},
{
"malwareFileHash": "075c8160789eb0829434a4fc9b59ed6c",
"malwareConfidence": "Very High",
"malwareFileSizeInBytes": "2914",
"attackCount": 404.0
]
}
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1105 | Invalid domain |
2 | 404 | 4201 | Invalid duration filter |