Full Threat Analysis
Comprehensive threat intelligence check for IPs, domains, URLs, and file hashes.
Enrichment Levels:
- basic - Malicious status, reputation counters, sources, blocklist counters, plus whatever the dataset holds (geo, whois, certificates, vulnerabilities, dns, …). No risk score.
- standard (default) - Basic + risk score, classification, confidence, MITRE mapping, cross-correlation, ASN reputation, OTX context
- full - Standard + detection timeline and related infrastructure
With no target parameter at all, answers a minimal 200 body (malicious: false + dataTrust/evidence) instead of an error.
Query parameters
IP address, domain, URL or file hash to check. Supply this or one of the ip / domain / hash aliases.
Alias for query restricted in intent to IP addresses
Alias for query restricted in intent to domains
Alias for query restricted in intent to file hashes (MD5/SHA1/SHA256)
Enrichment level: basic, standard, or full
Response
Threat analysis response. Field availability depends on the entity type, the enrichment level, and the dataset — see the schema description.
Example response
{
"apiVersion": "v2",
"classification": {
"indicators": [
{
"category": "phishing",
"type": "source_category"
}
],
"primary": "safe"
},
"confidence": {
"factors": [
{
"name": "source_agreement"
}
],
"level": "high"
},
"enrichmentLevel": "standard",
"firstSeen": "2026-08-25T14:17:40Z",
"hashInfo": {
"hash": "44d88612fea8a8f36de82e1278abb02f",
"hashType": "md5"
},
"infrastructure": {
"attributes": [
"cloud",
"saas"
],
"sources": [
{
"category": "infrastructure",
"id": "azure-ip-ranges",
"name": "Azure - Published IP Ranges",
"threatClass": "infrastructure"
}
]
},
"lastSeen": "2026-09-20T06:00:00Z",
"lastUpdated": "2026-09-01T00:00:00Z",
"lookupStatus": "unknown",
"riskScore": {
"factors": [
{
"name": "domain_age"
}
],
"level": "safe"
}
}Changes
Changed in 5 of the 14 revisions of this API.33364
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
- ▲
the response property
became nullable for the statusresponse-property-became-nullable
- ▲
the response property
became nullable for the statusresponse-property-became-nullable
- ▲
the response property
became nullable for the statusresponse-property-became-nullable
- ▲
the response property
became nullable for the statusresponse-property-became-nullable
- ▲
the response property
became nullable for the statusresponse-property-became-nullable
- ▲
the response property
became nullable for the statusresponse-property-became-nullable
- ▲
the response property
became nullable for the statusresponse-property-became-nullable
- ▲
the response property
became optional for the statusresponse-property-became-optional
- ▲
the response property
became optional for the statusresponse-property-became-optional
- ▲
the response property
became optional for the statusresponse-property-became-optional
- ▲
the response property
became optional for the statusresponse-property-became-optional
- ▲
the response property
became optional for the statusresponse-property-became-optional
- ▲
added
subschema #1to theresponse propertyoneOflist for the response statusresponse-property-one-of-added
- ▲
added
subschema #1to theresponse propertyoneOflist for the response statusresponse-property-one-of-added
- ▲
the
response's property type changed from no type toobjectnullfor statusresponse-property-type-changed
- ▲
the
response's property type changed fromobjectto no type for statusresponse-property-type-changed
- ▲
the
response's property type changed fromobjectto no type for statusresponse-property-type-changed
- ▲
the
response's property type changed from no type toobjectfor statusresponse-property-type-changed
- ▲
the
response's property type changed from no type toobjectfor statusresponse-property-type-changed
- ▲
the
response's property type changed from no type toobjectnullfor statusresponse-property-type-changed
- ▲
the
response's property type changed from no type toobjectnullfor statusresponse-property-type-changed
- ▲
the
response's property type changed from no type toobjectnullfor statusresponse-property-type-changed
- ▲
removed the required property
from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
/from the response with the statusresponse-required-property-removed
- ▲
removed the required property
from the response with the statusresponse-required-property-removed
- ●
deleted the
pathrequest parameterenrichmentrequest-parameter-removed
- ●
deleted the
pathrequest parameterqueryrequest-parameter-removed
- ○
added the new optional
queryrequest parameterdomainnew-optional-request-parameter
- ○
added the new optional
queryrequest parameterenrichmentnew-optional-request-parameter
- ○
added the new optional
queryrequest parameterhashnew-optional-request-parameter
- ○
added the new optional
queryrequest parameteripnew-optional-request-parameter
- ○
added the new optional
queryrequest parameterquerynew-optional-request-parameter
- ○
removed the non-success response with the status
response-non-success-status-removed
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
/to the response with the statusresponse-optional-property-added
- ○
added the optional property
/to the response with the statusresponse-optional-property-added
- ○
added the optional property
/to the response with the statusresponse-optional-property-added
- ○
added the optional property
/to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
/to the response with the statusresponse-optional-property-added
- ○
added the optional property
/to the response with the statusresponse-optional-property-added
- ○
added the optional property
/to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
the response property
became required for the statusresponse-property-became-required
- ○
the response property
became required for the statusresponse-property-became-required
- ○
removed
subschema #1from theresponse propertyoneOflist for the response statusresponse-property-one-of-removed
- ○
removed
subschema #1from theresponse propertyoneOflist for the response statusresponse-property-one-of-removed
- ○
removed
subschema #1from theresponse propertyoneOflist for the response statusresponse-property-one-of-removed
- ○
removed
subschema #1from theresponse propertyoneOflist for the response statusresponse-property-one-of-removed
- ○
removed
subschema #1from theresponse propertyoneOflist for the response statusresponse-property-one-of-removed
- ○
removed
subschema #1from theresponse propertyoneOflist for the response statusresponse-property-one-of-removed
- ○
added the required property
to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
- ○
added the required property
/to the response with the statusresponse-required-property-added
This revision also has 17 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog
- ▲
- ●
deleted the
pathrequest parametertrack_reportsrequest-parameter-removed
- ●