Abnormal AI Detection360 API

The Detection360 API from Abnormal AI — 1 operation(s) for detection360.

Operations 2

GET /detection360/reports List Detection 360 reports for a specific type of detection misclassification #
POST /detection360/reports Submit a detection misclassification report #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/abnormal-detection360-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

abnormal-detection360-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Abnormal Security Client Detection360 API
  version: 1.4.3
  description: This is the specification for Abnormal Security Client API which can be used for managing security threats detected by Abnormal Security.
  termsOfService: https://legal.abnormalsecurity.com/legal-hub/abnormal-security-api-terms-of-service-6feee5e3
  contact:
    name: Abnormal Security Support
    email: support@abnormalsecurity.com
servers:
- url: https://api.abnormalplatform.com/v1
  description: Production Server for managing threats
- url: https://eu.rest.abnormalsecurity.com/v1
  description: EU Production Server for managing threats.
security:
- BearerAuth: []
tags:
- name: Detection360
paths:
  /detection360/reports:
    get:
      operationId: v1_detection360_reports_retrieve
      description: Get a list of Detection 360 reports that you have submitted and view corresponding details for each case, including report summaries, statuses, message analyses, and more.
      summary: List Detection 360 reports for a specific type of detection misclassification
      parameters:
      - in: query
        name: inquiry_type
        schema:
          enum:
          - MISSED_ATTACK
          - FALSE_POSITIVE
          type: string
          minLength: 1
        description: Whether to fetch missed attacks or false positives.
        required: true
      - in: query
        name: start
        schema:
          type: string
          format: date-time
        description: The start of the datetime range, as an RFC 3339 timestamp, to fetch Detection 360 cases from. Defaults to 30 days before end.
        examples:
          Start:
            value: '2022-01-01T00:00:00Z'
            summary: start
      - in: query
        name: end
        schema:
          type: string
          format: date-time
        description: The end of the datetime range, as an RFC 3339 timestamp, to fetch Detection 360 cases from. Defaults to the current time.
        examples:
          End:
            value: '2022-01-07T23:59:59Z'
            summary: end
      - in: query
        name: status
        schema:
          type: array
          items:
            enum:
            - UNREVIEWED
            - CONTAINING_ATTACK
            - IMPROVING_PLATFORM
            - RESOLVED
            - CORRECTING_JUDGEMENT
            type: string
        description: Only Detection 360 cases with these statuses will be retrieved. Defaults to all statuses.
      tags:
      - Detection360
      responses:
        '200':
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Detection360Case'
          description: Successful operation
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '403':
          $ref: '#/components/responses/ForbiddenError'
        '429':
          $ref: '#/components/responses/TooManyRequestsError'
    post:
      operationId: v1_detection360_reports_create
      description: Use this to report a detection misclassification judgement by Abnormal Security. We use this data to improve our models, and also give customers transparency into the frequency of misclassifications.
      summary: Submit a detection misclassification report
      parameters:
      - in: header
        name: mock-data
        schema:
          type: string
          default: 'False'
          enum:
          - 'False'
          - 'True'
        description: Returns test data if set to `True`
      tags:
      - Detection360
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Detection360ReportRequest'
      responses:
        '202':
          description: Report was submitted successfully.
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '403':
          $ref: '#/components/responses/ForbiddenError'
        '429':
          $ref: '#/components/responses/TooManyRequestsError'
components:
  schemas:
    FalseNegative:
      type: object
      properties:
        report_type:
          $ref: '#/components/schemas/FalseNegativeReportTypeEnum'
          description: Type of report
        recipient_email:
          type: string
          description: Email address of the recipient
          example: alice@aloha.com
        sender_email:
          type: string
          description: Email address of the sender
          example: alice@aloha.com
        subject:
          type: string
          description: Subject of the email
          example: hello!
        received_date:
          type: string
          description: Date the email was received in YYYY-MM-DD format.
          example: 2020/02/01
        description:
          type: string
          description: Free text to provide more context on the issue.
          example: Alice reported this email looked like an attack.
      required:
      - recipient_email
      - report_type
      - sender_email
      - subject
    MissedGraymail:
      type: object
      properties:
        report_type:
          $ref: '#/components/schemas/MissedGraymailReportTypeEnum'
          description: Type of report
        recipient_email:
          type: string
        sender_email:
          type: string
        subject:
          type: string
        received_date:
          type: string
          description: Date the email was received in YYYY-MM-DD format.
        description:
          type: string
          description: Free text to provide more context on the issue.
          example: Alice does not want to see this email in her inbox.
      required:
      - recipient_email
      - report_type
      - sender_email
      - subject
    MissedGraymailReportTypeEnum:
      enum:
      - missed-graymail
      type: string
    User:
      type: object
      properties:
        name:
          type: string
          description: The name of the user
          example: Ching Li-Hsieh
        email:
          type: string
          description: The email address of the user
          example: lhching@bigcompany.com
      required:
      - name
    MissedSpamReportTypeEnum:
      enum:
      - missed-spam
      type: string
    PortalVisibleRootCause:
      type: object
      properties:
        name:
          type: string
        description:
          type: string
      required:
      - description
      - name
    Detection360ReportRequest:
      oneOf:
      - $ref: '#/components/schemas/FalsePositive'
      - $ref: '#/components/schemas/FalseNegative'
      - $ref: '#/components/schemas/MissedAttack'
      - $ref: '#/components/schemas/MissedSpam'
      - $ref: '#/components/schemas/MissedGraymail'
      discriminator:
        propertyName: report_type
        mapping:
          null: '#/components/schemas/MissedGraymail'
    Detection360Report:
      type: object
      properties:
        analysis:
          type: string
        root_causes:
          type: array
          items:
            $ref: '#/components/schemas/PortalVisibleRootCause'
      required:
      - analysis
      - root_causes
    InquiryTypeEnum:
      enum:
      - MISSED_ATTACK
      - FALSE_POSITIVE
      type: string
    MissedSpam:
      type: object
      properties:
        report_type:
          $ref: '#/components/schemas/MissedSpamReportTypeEnum'
          description: Type of report
        recipient_email:
          type: string
        sender_email:
          type: string
        subject:
          type: string
        received_date:
          type: string
          description: Date the email was received in YYYY-MM-DD format.
        description:
          type: string
          description: Free text to provide more context on the issue.
          example: Alice reported this email looked like spam.
      required:
      - recipient_email
      - report_type
      - sender_email
      - subject
    Detection360Case:
      type: object
      properties:
        id:
          type: integer
        inquiry_type:
          $ref: '#/components/schemas/InquiryTypeEnum'
        messages:
          type: array
          items:
            type: integer
        report:
          $ref: '#/components/schemas/Detection360Report'
        status:
          $ref: '#/components/schemas/Detection360CaseStatusEnum'
        submission_datetime:
          type: string
          format: date-time
        submitted_by:
          $ref: '#/components/schemas/User'
      required:
      - id
      - inquiry_type
      - messages
      - status
      - submission_datetime
      - submitted_by
    FalseNegativeReportTypeEnum:
      enum:
      - false-negative
      type: string
    FalsePositive:
      type: object
      properties:
        report_type:
          $ref: '#/components/schemas/FalsePositiveReportTypeEnum'
          description: Type of report
        portal_link:
          type: string
          description: Link in Portal of the False Positive Threat
          example: https://portal.abnormalsecurity.com/home/threat-center/remediation-history/1234567890
        received_date:
          type: string
          description: Date the email was received in YYYY-MM-DD format.
          example: 2020/02/01
        description:
          type: string
          description: Free text to provide more context on the issue.
          example: Alice reported this email was missing from their inbox.
      required:
      - portal_link
      - report_type
    FalsePositiveReportTypeEnum:
      enum:
      - false-positive
      type: string
    Detection360CaseStatusEnum:
      enum:
      - UNREVIEWED
      - CONTAINING_ATTACK
      - IMPROVING_PLATFORM
      - RESOLVED
      - CORRECTING_JUDGEMENT
      type: string
    MissedAttackReportTypeEnum:
      enum:
      - missed-attack
      type: string
    MissedAttack:
      type: object
      properties:
        report_type:
          $ref: '#/components/schemas/MissedAttackReportTypeEnum'
          description: Type of report
        recipient_email:
          type: string
          description: Email address of the sender
          example: alice@aloha.com
        sender_email:
          type: string
          description: Email address of the sender
          example: alice@aloha.com
        subject:
          type: string
          description: Subject of the email
          example: hello!
        received_date:
          type: string
          description: Date the email was received in YYYY-MM-DD format.
        description:
          type: string
          description: Free text to provide more context on the issue.
          example: Alice reported this email looked like an attack.
      required:
      - recipient_email
      - report_type
      - sender_email
      - subject
  responses:
    TooManyRequestsError:
      description: Request count exceeds allowed number of concurrent requests for this resource type
    UnauthorizedError:
      description: Access token is missing or invalid
    ForbiddenError:
      description: Access to the resource is forbidden (e.g. IP not in allowlist)
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer