Cisco Umbrella Top Threats API

The Top Threats API from Cisco Umbrella — 2 operation(s) for top threats.

Business capability
Threat Detection & Response Management BC-620.30

Operations 2

GET /top-threats Get Top Threats (All) #
GET /top-threats/{type} Get Top Threats (By Type) #

Documentation

📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/

Specifications

Other Resources

🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/key-admin.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/managed-providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/s3-key-rotation.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/service-providers-console.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/users-roles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/auth/token.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/cloudlock/cloudlock.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-domains.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-tunnels.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/policies.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/roaming-computers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/sites.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/swg-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/tagging.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/virtual-appliances.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/investigate/investigate.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/application-lists-internet-umb.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/destination-lists.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/api-usage.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/app-discovery.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/provider-consoles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-umbrella-top-threats-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-umbrella-top-threats-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cisco Umbrella Reporting Top Threats API
  description: The Reporting API provides the data to generate the Umbrella reports.
  version: 2.0.0
  contact:
    name: Cloud Security Developer Community
  x-provenance:
    method: harvested
    authored_by: Cisco Umbrella
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: pubhub.devnetcloud.com
    note: 26 first-party OpenAPI 3.0 documents (256 operations) listed by Cisco's own docs-nav config and fetched anonymously. Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source.
  x-evidence:
  - type: source
    url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/umbrella-config.json
  - type: source
    url: https://developer.cisco.com/docs/cloud-security/
servers:
- url: https://api.umbrella.com/{basePath}
  variables:
    basePath:
      default: reports/v2
security:
- oauthFlow: []
tags:
- name: Top Threats
paths:
  /top-threats:
    get:
      tags:
      - Top Threats
      summary: Get Top Threats (All)
      description: 'Get the top threats within the timeframe. Returns both DNS and proxy data.


        **Access Scope:** Reports > Aggregations > Read-Only'
      operationId: getTopThreats
      security:
      - oauthFlow:
        - reports.aggregations:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/domainsParam'
      - $ref: '#/components/parameters/categoriesParam'
      - $ref: '#/components/parameters/policyCategoriesParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/identityTypesParam'
      - $ref: '#/components/parameters/applicationIdParam'
      - $ref: '#/components/parameters/verdictParam'
      - $ref: '#/components/parameters/threatsParam'
      - $ref: '#/components/parameters/threatTypesParam'
      - $ref: '#/components/parameters/filterNoisyDomainsParam'
      - $ref: '#/components/parameters/timezoneParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/TopThreats'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - threat: Wannacry
                  threattype: Ransomware
                  count: 361
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /top-threats/{type}:
    get:
      tags:
      - Top Threats
      summary: Get Top Threats (By Type)
      description: 'Get the top threats within the timeframe.


        **Access Scope:** Reports > Aggregations > Read-Only'
      operationId: getTopThreatsByType
      security:
      - oauthFlow:
        - reports.aggregations:read
      parameters:
      - $ref: '#/components/parameters/typeDnsWebParam'
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/domainsParam'
      - $ref: '#/components/parameters/categoriesParam'
      - $ref: '#/components/parameters/policyCategoriesParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/identityTypesParam'
      - $ref: '#/components/parameters/applicationIdParam'
      - $ref: '#/components/parameters/verdictParam'
      - $ref: '#/components/parameters/threatsParam'
      - $ref: '#/components/parameters/threatTypesParam'
      - $ref: '#/components/parameters/filterNoisyDomainsParam'
      - $ref: '#/components/parameters/timezoneParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/TopThreats'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - threat: Wannacry
                  threattype: Ransomware
                  count: 361
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
components:
  parameters:
    fromParam:
      name: from
      in: query
      description: 'A timestamp or relative time string (for example: ''-1days'').

        Filter for data that appears after this time.'
      required: true
      schema:
        type: string
      example: '1639146300000'
    typeDnsWebParam:
      name: type
      in: path
      description: Specify the type of traffic.
      required: true
      schema:
        type: string
        enum:
        - dns
        - proxy
      example: dns
    policyCategoriesParam:
      name: policycategories
      in: query
      description: 'A category ID or comma-delimited list of category ID.

        Filter the request by the categories that trigger a policy.'
      schema:
        type: string
      example: 67,69
    categoriesParam:
      name: categories
      in: query
      description: A category ID or comma-delimited list of category ID.
      schema:
        type: string
      example: 148,151,66
    applicationIdParam:
      name: applicationid
      in: query
      description: The ID of the application.
      schema:
        type: string
      example: '1'
    filterNoisyDomainsParam:
      name: filternoisydomains
      in: query
      description: Filter out domains that generate a lot of insignificant traffic (noise).
      schema:
        type: boolean
      example: true
    domainsParam:
      name: domains
      in: query
      description: A domain name or comma-delimited list of domain name.
      schema:
        type: string
      example: cisco.com,nasa.gov
    threatsParam:
      name: threats
      in: query
      description: A threat name or comma-delimited list of threat names.
      schema:
        type: string
    ipParam:
      name: ip
      in: query
      description: An IP address.
      schema:
        type: string
      example: 10.10.10.10
    timezoneParam:
      name: timezone
      in: query
      description: 'Display the timestamp of the traffic events in the specified timezone.

        For the timezone, provide a continent and city separated by an url-encoded forward slash (''/''), for example: timezone=''ASIA%2fCALCUTTA''.'
      schema:
        type: string
      example: ASIA%2fCALCUTTA
    toParam:
      name: to
      in: query
      description: 'A timestamp or relative time string (for example: ''now'').

        Filter for data that appears before this time.'
      required: true
      schema:
        type: string
      example: '1640010300000'
    offsetParam:
      name: offset
      in: query
      description: A number that represents an index in the collection.
      schema:
        type: number
        default: 0
      example: 0
    threatTypesParam:
      name: threattypes
      in: query
      description: A threat type or comma-delimited list of threat types.
      schema:
        type: string
    verdictParam:
      name: verdict
      in: query
      description: A string or comma-delimited string that describes whether the traffic can reach the destination.
      schema:
        type: string
      example: allowed,blocked,proxied
    limitParam:
      name: limit
      in: query
      description: The maximum number of records to return from the collection.
      required: true
      schema:
        type: number
        default: 100
      example: 100
    identityIdsParam:
      name: identityids
      in: query
      description: An identity ID or comma-delimited list of identity IDs.
      schema:
        type: string
      example: 1,2,3
    identityTypesParam:
      name: identitytypes
      in: query
      description: An identity type or comma-delimited list of identity types.
      schema:
        type: string
      example: network,roaming
  responses:
    500Error:
      description: Internal Server Error
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Internal Server Error
    403Error:
      description: Forbidden
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Forbidden
    401Error:
      description: Unauthorized
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Unauthorized
    404Error:
      description: Not Found
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Not Found
    400Error:
      description: Bad Request
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Bad Request
  schemas:
    Meta:
      type: object
      description: The properties of the metadata.
      example: {}
    TopThreats:
      type: object
      description: The information about the top threats.
      properties:
        threat:
          type: string
          description: The name of the threat.
        threattype:
          type: string
          description: The type of the threat.
        count:
          type: number
          description: The number of requests for the threat name.
      required:
      - count
      - threat
      - threattype
      example:
        threat: Wannacry
        threattype: Ransomware
        count: 361
  securitySchemes:
    oauthFlow:
      type: oauth2
      description: client credential flow
      flows:
        clientCredentials:
          tokenUrl: https://api.umbrella.com/auth/v2/token
          scopes:
            reports.granularEvents:read: Read reports granular events
            reports.utilities:read: Read reports utilities
            reports.aggregations:read: Read reports aggregations
            reports.summariesByRule:read: Read reports for the summaries of the rule
            reports.customers:read: Read reports for the customers
x-provenance:
  method: harvested
  first_party: true
  harvested: '2026-08-19'
  source: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml
  publisher: Cisco Systems, Inc. (Cisco DevNet Cloud Security docs)
x-evidence:
  fetched: '2026-08-19'
  url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml
  http_status: 200
  docs: https://developer.cisco.com/docs/cloud-security/