Dragos Indicators API

The Indicators API from Dragos — 3 operation(s) for indicators.

Operations 3

GET /api/v1/indicators Returns a paginated list of indicators
GET /api/v1/indicators.stix2 Returns a paginated stix2 bundle of indicators
GET /api/v1/indicators/stix2 Returns a cached stix2 bundle of the last 12 months of indicators (not available to trial users)

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/dragos-indicators-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

dragos-indicators-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Dragos WorldView Indicators API
  version: v1
  description: API access to the WorldView Reports and Indicators
  contact:
    name: the developer
    email: support@dragos.com
servers:
- url: https://portal.dragos.com
  description: Base URL declared by the provider in apis.yml (roadmap#122).
tags:
- name: Indicators
paths:
  /api/v1/indicators:
    get:
      summary: Returns a paginated list of indicators
      tags:
      - Indicators
      security:
      - api_token: []
        api_secret: []
        npe_token: []
      parameters:
      - name: exclude_suspect_domain
        in: query
        description: Exclude indicators that are only associated with Suspect Domain Reports
        required: false
        schema:
          type: boolean
      - name: page
        in: query
        description: Page number (default 1)
        required: false
        schema:
          type: string
      - name: page_size
        in: query
        description: Page size (default 500) (must be less than 1001)
        required: false
        schema:
          type: string
      - name: updated_after
        in: query
        description: UTC timestamp in YYYY-mm-dd (optionally with HH:mm:ss) to filter to recent indicators
        required: false
        schema:
          type: string
      - name: value
        in: query
        description: Search for indicators that match a specific value
        required: false
        schema:
          type: string
      - name: type
        in: query
        description: Search for indicators of a specific type
        required: false
        schema:
          type: string
          enum:
          - domain
          - filename
          - hostname
          - ip
          - md5
          - sha1
          - sha256
      - name: serial[]
        in: query
        description: Search for indicators matching a report serial
        required: false
        schema:
          type: array
          items:
            type: string
            example: ''
      - name: tags[]
        in: query
        description: Search for indicators matching tag(s) text
        required: false
        schema:
          type: array
          items:
            type: string
            example: ''
      responses:
        '200':
          description: Success
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: Too Many Requests
  /api/v1/indicators.stix2:
    get:
      summary: Returns a paginated stix2 bundle of indicators
      tags:
      - Indicators
      security:
      - api_token: []
        api_secret: []
        npe_token: []
      parameters:
      - name: page
        in: query
        description: Page number (default 1)
        required: false
        schema:
          type: string
      - name: page_size
        in: query
        description: Page size (default 500) (must be less than 1001)
        required: false
        schema:
          type: string
      - name: updated_after
        in: query
        description: UTC timestamp in YYYY-mm-dd (optionally with HH:mm:ss) to filter to recent indicators
        required: false
        schema:
          type: string
      - name: value
        in: query
        description: Search for indicators that match a specific value
        required: false
        schema:
          type: string
      - name: type
        in: query
        description: Search for indicators of a specific type
        required: false
        schema:
          type: string
          enum:
          - domain
          - filename
          - hostname
          - ip
          - md5
          - sha1
          - sha256
      - name: serial[]
        in: query
        description: Search for indicators matching a report serial
        required: false
        schema:
          type: array
          items:
            type: string
            example: ''
      - name: tags[]
        in: query
        description: Search for indicators matching tag(s) text
        required: false
        schema:
          type: array
          items:
            type: string
            example: ''
      responses:
        '200':
          description: Success
          headers:
            X-Page:
              type: integer
              description: Page number
            X-Page-Size:
              type: integer
              description: How many indicators per page
            X-Total:
              type: integer
              description: Total indicator count
            X-Total-Pages:
              type: integer
              description: How many pages of indicators
  /api/v1/indicators/stix2:
    get:
      summary: Returns a cached stix2 bundle of the last 12 months of indicators (not available to trial users)
      tags:
      - Indicators
      security:
      - api_token: []
        api_secret: []
        npe_token: []
      responses:
        '200':
          description: Success
components:
  securitySchemes:
    api_token:
      description: API Access Token
      in: header
      name: API-Token
      type: apiKey
    api_secret:
      description: API Secret Key
      in: header
      name: API-Secret
      type: apiKey
    npe_token:
      description: NPE Token
      in: header
      name: Authorization
      type: apiKey