Abnormal AI Detection360 API
The Detection360 API from Abnormal AI — 1 operation(s) for detection360.
The Detection360 API from Abnormal AI — 1 operation(s) for detection360.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/abnormal-detection360-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Abnormal Security Client Detection360 API
version: 1.4.3
description: This is the specification for Abnormal Security Client API which can be used for managing security threats detected by Abnormal Security.
termsOfService: https://legal.abnormalsecurity.com/legal-hub/abnormal-security-api-terms-of-service-6feee5e3
contact:
name: Abnormal Security Support
email: support@abnormalsecurity.com
servers:
- url: https://api.abnormalplatform.com/v1
description: Production Server for managing threats
- url: https://eu.rest.abnormalsecurity.com/v1
description: EU Production Server for managing threats.
security:
- BearerAuth: []
tags:
- name: Detection360
paths:
/detection360/reports:
get:
operationId: v1_detection360_reports_retrieve
description: Get a list of Detection 360 reports that you have submitted and view corresponding details for each case, including report summaries, statuses, message analyses, and more.
summary: List Detection 360 reports for a specific type of detection misclassification
parameters:
- in: query
name: inquiry_type
schema:
enum:
- MISSED_ATTACK
- FALSE_POSITIVE
type: string
minLength: 1
description: Whether to fetch missed attacks or false positives.
required: true
- in: query
name: start
schema:
type: string
format: date-time
description: The start of the datetime range, as an RFC 3339 timestamp, to fetch Detection 360 cases from. Defaults to 30 days before end.
examples:
Start:
value: '2022-01-01T00:00:00Z'
summary: start
- in: query
name: end
schema:
type: string
format: date-time
description: The end of the datetime range, as an RFC 3339 timestamp, to fetch Detection 360 cases from. Defaults to the current time.
examples:
End:
value: '2022-01-07T23:59:59Z'
summary: end
- in: query
name: status
schema:
type: array
items:
enum:
- UNREVIEWED
- CONTAINING_ATTACK
- IMPROVING_PLATFORM
- RESOLVED
- CORRECTING_JUDGEMENT
type: string
description: Only Detection 360 cases with these statuses will be retrieved. Defaults to all statuses.
tags:
- Detection360
responses:
'200':
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/Detection360Case'
description: Successful operation
'401':
$ref: '#/components/responses/UnauthorizedError'
'403':
$ref: '#/components/responses/ForbiddenError'
'429':
$ref: '#/components/responses/TooManyRequestsError'
post:
operationId: v1_detection360_reports_create
description: Use this to report a detection misclassification judgement by Abnormal Security. We use this data to improve our models, and also give customers transparency into the frequency of misclassifications.
summary: Submit a detection misclassification report
parameters:
- in: header
name: mock-data
schema:
type: string
default: 'False'
enum:
- 'False'
- 'True'
description: Returns test data if set to `True`
tags:
- Detection360
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Detection360ReportRequest'
responses:
'202':
description: Report was submitted successfully.
'401':
$ref: '#/components/responses/UnauthorizedError'
'403':
$ref: '#/components/responses/ForbiddenError'
'429':
$ref: '#/components/responses/TooManyRequestsError'
components:
schemas:
FalseNegative:
type: object
properties:
report_type:
$ref: '#/components/schemas/FalseNegativeReportTypeEnum'
description: Type of report
recipient_email:
type: string
description: Email address of the recipient
example: alice@aloha.com
sender_email:
type: string
description: Email address of the sender
example: alice@aloha.com
subject:
type: string
description: Subject of the email
example: hello!
received_date:
type: string
description: Date the email was received in YYYY-MM-DD format.
example: 2020/02/01
description:
type: string
description: Free text to provide more context on the issue.
example: Alice reported this email looked like an attack.
required:
- recipient_email
- report_type
- sender_email
- subject
MissedGraymail:
type: object
properties:
report_type:
$ref: '#/components/schemas/MissedGraymailReportTypeEnum'
description: Type of report
recipient_email:
type: string
sender_email:
type: string
subject:
type: string
received_date:
type: string
description: Date the email was received in YYYY-MM-DD format.
description:
type: string
description: Free text to provide more context on the issue.
example: Alice does not want to see this email in her inbox.
required:
- recipient_email
- report_type
- sender_email
- subject
MissedGraymailReportTypeEnum:
enum:
- missed-graymail
type: string
User:
type: object
properties:
name:
type: string
description: The name of the user
example: Ching Li-Hsieh
email:
type: string
description: The email address of the user
example: lhching@bigcompany.com
required:
- name
MissedSpamReportTypeEnum:
enum:
- missed-spam
type: string
PortalVisibleRootCause:
type: object
properties:
name:
type: string
description:
type: string
required:
- description
- name
Detection360ReportRequest:
oneOf:
- $ref: '#/components/schemas/FalsePositive'
- $ref: '#/components/schemas/FalseNegative'
- $ref: '#/components/schemas/MissedAttack'
- $ref: '#/components/schemas/MissedSpam'
- $ref: '#/components/schemas/MissedGraymail'
discriminator:
propertyName: report_type
mapping:
null: '#/components/schemas/MissedGraymail'
Detection360Report:
type: object
properties:
analysis:
type: string
root_causes:
type: array
items:
$ref: '#/components/schemas/PortalVisibleRootCause'
required:
- analysis
- root_causes
InquiryTypeEnum:
enum:
- MISSED_ATTACK
- FALSE_POSITIVE
type: string
MissedSpam:
type: object
properties:
report_type:
$ref: '#/components/schemas/MissedSpamReportTypeEnum'
description: Type of report
recipient_email:
type: string
sender_email:
type: string
subject:
type: string
received_date:
type: string
description: Date the email was received in YYYY-MM-DD format.
description:
type: string
description: Free text to provide more context on the issue.
example: Alice reported this email looked like spam.
required:
- recipient_email
- report_type
- sender_email
- subject
Detection360Case:
type: object
properties:
id:
type: integer
inquiry_type:
$ref: '#/components/schemas/InquiryTypeEnum'
messages:
type: array
items:
type: integer
report:
$ref: '#/components/schemas/Detection360Report'
status:
$ref: '#/components/schemas/Detection360CaseStatusEnum'
submission_datetime:
type: string
format: date-time
submitted_by:
$ref: '#/components/schemas/User'
required:
- id
- inquiry_type
- messages
- status
- submission_datetime
- submitted_by
FalseNegativeReportTypeEnum:
enum:
- false-negative
type: string
FalsePositive:
type: object
properties:
report_type:
$ref: '#/components/schemas/FalsePositiveReportTypeEnum'
description: Type of report
portal_link:
type: string
description: Link in Portal of the False Positive Threat
example: https://portal.abnormalsecurity.com/home/threat-center/remediation-history/1234567890
received_date:
type: string
description: Date the email was received in YYYY-MM-DD format.
example: 2020/02/01
description:
type: string
description: Free text to provide more context on the issue.
example: Alice reported this email was missing from their inbox.
required:
- portal_link
- report_type
FalsePositiveReportTypeEnum:
enum:
- false-positive
type: string
Detection360CaseStatusEnum:
enum:
- UNREVIEWED
- CONTAINING_ATTACK
- IMPROVING_PLATFORM
- RESOLVED
- CORRECTING_JUDGEMENT
type: string
MissedAttackReportTypeEnum:
enum:
- missed-attack
type: string
MissedAttack:
type: object
properties:
report_type:
$ref: '#/components/schemas/MissedAttackReportTypeEnum'
description: Type of report
recipient_email:
type: string
description: Email address of the sender
example: alice@aloha.com
sender_email:
type: string
description: Email address of the sender
example: alice@aloha.com
subject:
type: string
description: Subject of the email
example: hello!
received_date:
type: string
description: Date the email was received in YYYY-MM-DD format.
description:
type: string
description: Free text to provide more context on the issue.
example: Alice reported this email looked like an attack.
required:
- recipient_email
- report_type
- sender_email
- subject
responses:
TooManyRequestsError:
description: Request count exceeds allowed number of concurrent requests for this resource type
UnauthorizedError:
description: Access token is missing or invalid
ForbiddenError:
description: Access to the resource is forbidden (e.g. IP not in allowlist)
securitySchemes:
BearerAuth:
type: http
scheme: bearer