# Druva Threat Hunting API

**Canonical:** https://apis.io/apis/druva/druva-threat-hunting-api/  
**Provider:** Druva — https://apis.io/providers/druva/  
**Base URL:** https://apis.druva.com  
**Documentation:** https://developer.druva.com

Druva Threat Hunting API is one of 86 APIs that [Druva](https://apis.io/providers/druva/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Threat Hunting. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, and a getting-started guide.

List of APIs to get information and perform operations on the resources managed in Druva Cloud for threat hunt.

## Operations (16)

| Method | Path | Summary |
|---|---|---|
| POST | `/threathunting/v1/search/backupset` | Search resources for VMware resource type |
| POST | `/threathunting/v1/threathunts` | Create a threat hunt |
| GET | `/threathunting/v1/threathunts` | List all threat hunts |
| PUT | `/threathunting/v1/threathunts/{threatHuntID}/cancel` | Cancel a threat hunt |
| DELETE | `/threathunting/v1/threathunts/{threatHuntID}` | Delete a threat hunt |
| GET | `/threathunting/v1/threathunts/{threatHuntID}` | List threat hunt configuration details |
| GET | `/threathunting/v1/threathunts/{threatHuntID}/summary` | Get threat hunt summary for a specific threat hunt |
| GET | `/threathunting/v1/threathunts/{threatHuntID}/devices` | Lists the devices that are a part of a Threat Hunt job |
| GET | `/threathunting/v1/threathunts/{threatHuntID}/devices/stats` | List statistics of devices configured for threat hunt |
| GET | `/threathunting/v1/threathunts/{threatHuntID}/devices/{deviceID}` | Get resource details for a specific threat hunt |
| GET | `/threathunting/v1/threathunts/{threatHuntID}/devices/{deviceID}/stats` | Get device statistics for a specific threat hunt |
| GET | `/threathunting/v1/threathunts/{threatHuntID}/devices/{deviceID}/snapshots` | List impacted snapshots for a specific threat hunt |
| GET | `/threathunting/v1/threathunts/{threatHuntID}/report` | Download a report |
| GET | `/common/v1/search/aws/awsaccounts` | Search AWS Accounts |
| GET | `/common/v1/search/aws/resourceids` | List AWS Resources |
| POST | `/common/v1/search/aws/resources` | Search AWS Resources |

## Machine-readable artifacts (5)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/druva/refs/heads/main/openapi/druva-threat-hunting-api-openapi.yml
- **Documentation** — https://developer.druva.com/reference
- **Authentication** — https://developer.druva.com/docs/authentication
- **GettingStarted** — https://developer.druva.com/docs/getting-started-with-cloudranger-api-trial
- **GettingStarted** — https://developer.druva.com/docs/getting-started-with-druva-msp-api-1

## Other Druva APIs (12)

- [Druva MCP Server](https://apis.io/apis/druva/mcp/)
- [Druva Accounts API](https://apis.io/apis/druva/druva-accounts-api/)
- [Druva AD/LDAP Management API](https://apis.io/apis/druva/druva-ad-ldap-management-api/)
- [Druva Admin Roles API](https://apis.io/apis/druva/druva-admin-roles-api/)
- [Druva Administration API](https://apis.io/apis/druva/druva-administration-api/)
- [Druva Administrators API](https://apis.io/apis/druva/druva-administrators-api/)
- [Druva Admins API](https://apis.io/apis/druva/druva-admins-api/)
- [Druva AHV API](https://apis.io/apis/druva/druva-ahv-api/)
- [Druva Alerts API](https://apis.io/apis/druva/druva-alerts-api/)
- [Druva App Management API](https://apis.io/apis/druva/druva-app-management-api/)
- [Druva Audit API](https://apis.io/apis/druva/druva-audit-api/)
- [Druva Audit Trail API](https://apis.io/apis/druva/druva-audit-trail-api/)

## Tags

Threat Hunting

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/druva/druva-threat-hunting-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/druva/.
