Juniper Networks Threat Intelligence API

Threat feed and intelligence data

OpenAPI Specification

juniper-threat-intelligence-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Juniper Networks Juniper Apstra Allowlists and Blocklists Threat Intelligence API
  description: Juniper Apstra is an intent-based networking platform for data center automation. The Apstra API provides RESTful access to manage blueprints, design elements, devices, connectivity templates, virtual networks, and intent-based analytics. It supports multivendor environments and enables closed-loop automation from design through deployment and operations.
  version: 4.2.0
  contact:
    name: Juniper Support
    url: https://www.juniper.net/us/en/products/network-automation/apstra.html
    email: support@juniper.net
  license:
    name: Proprietary
    url: https://www.juniper.net/us/en/legal-notices.html
  termsOfService: https://www.juniper.net/us/en/legal-notices.html
servers:
- url: https://{apstra_server}/api
  description: Apstra Server
  variables:
    apstra_server:
      default: apstra.example.com
      description: Hostname or IP of the Apstra server
security:
- authToken: []
tags:
- name: Threat Intelligence
  description: Threat feed and intelligence data
paths:
  /threat-intelligence/feeds:
    get:
      operationId: listThreatFeeds
      summary: Juniper Networks List threat feeds
      description: Returns available threat intelligence feeds and their status.
      tags:
      - Threat Intelligence
      responses:
        '200':
          description: List of threat feeds
          content:
            application/json:
              schema:
                type: object
                properties:
                  feeds:
                    type: array
                    items:
                      $ref: '#/components/schemas/ThreatFeed'
  /threat-intelligence/ip-lookup:
    get:
      operationId: lookupIpReputation
      summary: Juniper Networks Look up IP reputation
      description: Returns the threat reputation score and details for an IP address.
      tags:
      - Threat Intelligence
      parameters:
      - name: ip
        in: query
        required: true
        description: IP address to look up
        schema:
          type: string
      responses:
        '200':
          description: IP reputation data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IpReputation'
  /threat-intelligence/url-lookup:
    get:
      operationId: lookupUrlReputation
      summary: Juniper Networks Look up URL reputation
      description: Returns the threat reputation and category for a URL.
      tags:
      - Threat Intelligence
      parameters:
      - name: url
        in: query
        required: true
        description: URL to look up
        schema:
          type: string
      responses:
        '200':
          description: URL reputation data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UrlReputation'
  /threat-intelligence/domain-lookup:
    get:
      operationId: lookupDomainReputation
      summary: Juniper Networks Look up domain reputation
      description: Returns the threat reputation for a domain name.
      tags:
      - Threat Intelligence
      parameters:
      - name: domain
        in: query
        required: true
        description: Domain name to look up
        schema:
          type: string
      responses:
        '200':
          description: Domain reputation data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DomainReputation'
  /threat-intelligence/hash-lookup:
    get:
      operationId: lookupFileHash
      summary: Juniper Networks Look up file hash
      description: Returns the malware analysis verdict for a file hash.
      tags:
      - Threat Intelligence
      parameters:
      - name: hash
        in: query
        required: true
        description: File hash (MD5, SHA1, or SHA256)
        schema:
          type: string
      - name: hash_type
        in: query
        description: Hash type
        schema:
          type: string
          enum:
          - md5
          - sha1
          - sha256
      responses:
        '200':
          description: File hash verdict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FileVerdict'
components:
  schemas:
    ThreatFeed:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        description:
          type: string
        enabled:
          type: boolean
        last_updated:
          type: string
          format: date-time
        entry_count:
          type: integer
        feed_type:
          type: string
          enum:
          - ip
          - domain
          - url
          - hash
    IpReputation:
      type: object
      properties:
        ip:
          type: string
        threat_score:
          type: integer
          minimum: 0
          maximum: 10
          description: Threat score from 0 (clean) to 10 (malicious)
        categories:
          type: array
          items:
            type: string
        country:
          type: string
        asn:
          type: integer
        last_seen:
          type: string
          format: date-time
        feeds:
          type: array
          items:
            type: string
    DomainReputation:
      type: object
      properties:
        domain:
          type: string
        threat_score:
          type: integer
          minimum: 0
          maximum: 10
        categories:
          type: array
          items:
            type: string
        registrar:
          type: string
        created_date:
          type: string
          format: date-time
        last_seen:
          type: string
          format: date-time
    FileVerdict:
      type: object
      properties:
        sha256:
          type: string
        md5:
          type: string
        sha1:
          type: string
        verdict:
          type: string
          enum:
          - clean
          - malicious
          - suspicious
          - unknown
        malware_family:
          type: string
        threat_score:
          type: integer
          minimum: 0
          maximum: 10
        first_seen:
          type: string
          format: date-time
        last_seen:
          type: string
          format: date-time
    UrlReputation:
      type: object
      properties:
        url:
          type: string
        threat_score:
          type: integer
          minimum: 0
          maximum: 10
        categories:
          type: array
          items:
            type: string
        host:
          type: string
        last_seen:
          type: string
          format: date-time
  securitySchemes:
    authToken:
      type: apiKey
      in: header
      name: AuthToken
      description: Authentication token obtained from the /aaa/login endpoint. Include as AuthToken header in all requests.
externalDocs:
  description: Apstra API Documentation
  url: https://www.juniper.net/documentation/us/en/software/apstra/