---
title: "Read active attack data"
method: GET
path: "/v1/security/firewall/attack-status"
tags: ["security"]
---

# Read active attack data

`GET /v1/security/firewall/attack-status`

Retrieve active attack data within the last N days (default: 1 day)

## Query parameters

- `projectId` string, required
- `since` number
- `teamId` string
- `slug` string

## Response `200`

- union
  - object
  - object
    - `anomalies` object[], required
      - `projectId` string, required
      - `ownerId` string, required
      - `startTime` number, required
      - `endTime` number, nullable, required
      - `atMinute` number, required
      - `state` string
      - `affectedHostMap` object, required

## Other responses

- `400` — One of the provided values in the request query is invalid.
- `401` — The request is not authorized.
- `403` — You do not have permission to access this resource.
- `404`
- `410`

## Changes

> 39 revisions in range; 16 could not be searched.

- **2026-07-21** `2ae10ee9d21c` — 1 info
  - added the non-success response with the status `410`

[Change history](https://skmtc.dev/vercel/apis/api/changes/v1/security/firewall/attack-status/get.md)

---

[API](https://skmtc.dev/vercel/apis/api.md) · [All operations](https://skmtc.dev/vercel/apis/api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/vercel/api/revisions/4191ba96b0c1/schema)
