Skip to main content
This endpoint is deprecated and will be out of service from Aug 31. Please migrate to the List IOC (/ioc/v2) endpoint which provides enriched data with threat actor and malware linkage.

Endpoint

Authentication


Query Parameters


Request


Response

string
Status message from the API.
array
Array of IOC objects.
string
Unique identifier for the IOC.
string
The indicator value (e.g., an IP address, domain, or hash).
string
The type of indicator (e.g., ip, domain, md5).
string | null
Associated threat name, or null if unknown.
string | null
Timestamp when the IOC was first observed.
string | null
Timestamp when the IOC was last observed.
array
Tags associated with the IOC.
string
Confidence level of the IOC classification.
array
Countries associated with this IOC.
string
Source of the IOC data.
array
Threat types associated with this IOC.
string | null
Cursor for the next page, or null if no more results.