Iru

Iru Threat Details API

The Threat Details API from Iru — 1 operation(s) for threat details.

Operations 1

GET /api/v1/threat-details Get Threat Details #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/kandji-threat-details-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

kandji-threat-details-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Iru Endpoint Management Threat Details API
  description: '# Welcome to the Iru Endpoint Management API Documentation


    **Note:** Kandji is in the process of changing to Iru.'
  version: 1.0.0
servers:
- url: https://{subdomain}.api.kandji.io
  description: US Server
  variables:
    subdomain:
      default: your-subdomain
      description: Your Iru Endpoint Management subdomain
- url: https://{subdomain}.api.eu.kandji.io
  description: EU Server
  variables:
    subdomain:
      default: your-subdomain
      description: Your Iru Endpoint Management subdomain
security:
- BearerAuth: []
tags:
- name: Threat Details
paths:
  /api/v1/threat-details:
    get:
      summary: Get Threat Details
      description: Get threat details.
      parameters:
      - name: classification
        in: query
        required: false
        description: 'Return all records matching a specified classification. The following classification options are available: `malware` and `pup`. Leave this parameter empty to return all classification types. Example: `malware`'
        schema:
          type: string
          enum:
          - malware
          - pup
        example: malware
      - name: date_range
        in: query
        required: false
        description: 'Return all records within a specified number of days. Any positive number of days may be specified. Examples: `7`, `30`, `60`, `90`, `180`, or `365`. Example: `7`'
        schema:
          type: integer
          minimum: 1
        example: 7
      - name: device_id
        in: query
        required: false
        description: 'Search for a specific device by the device id (uuid). Example: `15fcec08-xxxx-xxxx-xxxx-7c2f950910eb`'
        schema:
          type: string
        example: 15fcec08-xxxx-xxxx-xxxx-7c2f950910eb
      - name: status
        in: query
        required: false
        description: 'Return all records matching a specified status. The following status options are available: `quarantined`, `not_quarantined`, or `released`. Leave this parameter empty to return all status types. Example: `quarantined`'
        schema:
          type: string
          enum:
          - quarantined
          - not_quarantined
          - released
        example: quarantined
      - name: sort_by
        in: query
        required: false
        description: 'Results can be sorted with the following options: `threat_name`, `classification`, `device_name`, `process_name`, `process_owner`, `detection_date`, `status`. Prepending a dash (-) to the parameter value will reverse the order of the returned results. Example: `status` or `-device_name`'
        schema:
          type: string
          enum:
          - threat_name
          - classification
          - device_name
          - process_name
          - process_owner
          - detection_date
          - status
        example: status
      - name: term
        in: query
        required: false
        description: 'Search term to filter threat results. The response will include anything matching the following fields: `device_name`, `file_hash`, and `file_path`. Example: `Chrome`'
        schema:
          type: string
        example: Chrome
      - name: limit
        in: query
        required: false
        description: 'A hard upper `limit` is set at 1000 records returned per request. If more records are expected, pagination should be used using the `limit` and `offset` parameters. Example: `1000`'
        schema:
          type: integer
          maximum: 1000
          default: 1000
        example: 1000
      - name: offset
        in: query
        required: false
        description: 'Specify the starting record to return. Example: `1`'
        schema:
          type: integer
          minimum: 0
          default: 0
        example: 1
      responses:
        '200':
          description: using term param
          content:
            application/json:
              schema:
                type: object
                example:
                  count: 24
                  next: null
                  previous: null
                  malware_count: 24
                  pup_count: 0
                  results:
                  - threat_name: malware_5
                    classification: MALWARE
                    status: QUARANTINED
                    process_name: chmod
                    process_owner: root
                    device_name: accuhive MacBook Air
                    device_id: df1badd0-1dc9-448b-9b2a-c614a844c69e
                    detection_date: '2023-04-21T17:23:13.883134'
                    date_of_quarantine: '2023-04-21T17:23:15.071621'
                    date_of_release: ''
                    released_by: ''
                    release_note: ''
                    file_path: /Users/Shared/malware/malware_5
                    file_hash: 2ab79665b07b3be11dd1d4f2d0bafa886a4b393b28ffedb2a02f62efd0061858
                    bundle_path: ''
                    device_serial_number: FVFGHGK7Q6L7
                    blueprint_id: 396cdae2-147e-4e61-8a27-2f6b6963da4f
                    blueprint_name: Threat
                    library_item_name: Avert
                    library_item_id: d0afe50a-1102-4568-86ed-44863b757c85
                    pup_posture: protect
                    malware_posture: protect
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    example: Bad Request
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    example: Unauthorized
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    example: Not Found
      tags:
      - Threat Details
      operationId: getApiV1ThreatDetails
      x-operation-id-source: derived
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT