Tenable Attack API

Attacks as detected by Tenable.ad

Operations 2

GET /api/profiles/{profileId}/attacks Get all attacks #
GET /api/profiles/{profileId}/attacks/export Get all attacks in CSV rows format #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/tenable-attack-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

tenable-attack-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Identity Exposure Attack API
  description: API to interact with Identity Exposure.
  version: production
servers:
- url: '{protocol}://customer.tenable.ad'
  variables:
    protocol:
      default: https
tags:
- name: Attack
  description: Attacks as detected by Tenable.ad
paths:
  /api/profiles/{profileId}/attacks:
    get:
      summary: Get all attacks
      description: 'Required license type: ioa, ioaPreview'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Validates attack search response payload
                type: array
                items:
                  description: Attack instance
                  type: object
                  additionalProperties: false
                  required:
                  - id
                  - directoryId
                  - attackTypeId
                  - dc
                  - date
                  - vector
                  - source
                  - destination
                  - isClosed
                  properties:
                    id:
                      type: number
                      description: Unique numeric identifier of the attack
                    directoryId:
                      type: number
                      description: Identifier of the directory the attacked Domain Controller belongs to
                    attackTypeId:
                      type: number
                      description: Identifier of the attack-type that has identified the attack
                    dc:
                      type: string
                      description: Fully qualified domain name of the attacked Domain Controller
                    date:
                      type: string
                      format: date-time
                      description: Date on which the attack has been identified
                    vector:
                      type: object
                      additionalProperties: false
                      properties:
                        template:
                          type: string
                          description: Localized description template for the attack vector
                        attributes:
                          type: array
                          items:
                            type: object
                            additionalProperties: false
                            required:
                            - name
                            - value
                            - valueType
                            properties:
                              name:
                                type: string
                                description: Name of the attack vector attribute
                              value:
                                type: string
                                description: JSON-stringified value of the attack vector attribute
                              valueType:
                                type: string
                                description: Type of the attack vector attribute
                      description: Attack vector data
                    source:
                      type: object
                      additionalProperties: false
                      properties:
                        ip:
                          type:
                          - string
                          - 'null'
                          description: Endpoint IP, if available
                        type:
                          enum:
                          - computer
                          - dc
                          - server
                          - user
                          - null
                          description: Endpoint object type, if available
                        hostname:
                          type:
                          - string
                          - 'null'
                          description: Endpoint hostname, if available
                      description: Information on the source of the attack
                    destination:
                      type: object
                      additionalProperties: false
                      properties:
                        ip:
                          type:
                          - string
                          - 'null'
                          description: Endpoint IP, if available
                        type:
                          enum:
                          - computer
                          - dc
                          - server
                          - user
                          - null
                          description: Endpoint object type, if available
                        hostname:
                          type:
                          - string
                          - 'null'
                          description: Endpoint hostname, if available
                      description: Information on the destination of the attack
                    isClosed:
                      type: boolean
                      description: Whether the customer has closed the attack
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Attack
      x-tenablead-required-product-license-type:
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: profileId
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      - name: attackTypeIds
        in: query
        schema:
          type: array
          items:
            type: string
        required: false
        deprecated: false
      - name: dateEnd
        in: query
        schema:
          type: string
          format: date-time
        required: false
        deprecated: false
      - name: dateStart
        in: query
        schema:
          type: string
          format: date-time
        required: false
        deprecated: false
      - name: includeClosed
        in: query
        schema:
          type: string
          enum:
          - 'true'
          - 'false'
        required: false
        deprecated: false
      - name: limit
        in: query
        schema:
          type: string
          pattern: ^[0-9]+$
        required: false
        deprecated: false
      - name: order
        in: query
        schema:
          type: string
          enum:
          - desc
          - asc
        required: false
        deprecated: false
      - name: resourceType
        in: query
        schema:
          type: string
          enum:
          - infrastructure
          - directory
          - hostname
          - ip
        required: true
        deprecated: false
      - name: resourceValue
        in: query
        schema:
          type: string
        required: true
        deprecated: false
      - name: search
        in: query
        schema:
          type: string
        required: false
        deprecated: false
      security:
      - ApiKey: []
      operationId: getApiProfilesByProfileIdAttacks
      x-operation-id-source: derived
  /api/profiles/{profileId}/attacks/export:
    get:
      summary: Get all attacks in CSV rows format
      description: 'Required license type: ioa, ioaPreview'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Validates attack search response payload
                type: array
                items:
                  description: Attack instance
                  type: object
                  additionalProperties: false
                  required:
                  - id
                  - directoryId
                  - attackTypeId
                  - dc
                  - date
                  - vector
                  - source
                  - destination
                  - isClosed
                  properties:
                    id:
                      type: number
                      description: Unique numeric identifier of the attack
                    directoryId:
                      type: number
                      description: Identifier of the directory the attacked Domain Controller belongs to
                    attackTypeId:
                      type: number
                      description: Identifier of the attack-type that has identified the attack
                    dc:
                      type: string
                      description: Fully qualified domain name of the attacked Domain Controller
                    date:
                      type: string
                      format: date-time
                      description: Date on which the attack has been identified
                    vector:
                      type: object
                      additionalProperties: false
                      properties:
                        template:
                          type: string
                          description: Localized description template for the attack vector
                        attributes:
                          type: array
                          items:
                            type: object
                            additionalProperties: false
                            required:
                            - name
                            - value
                            - valueType
                            properties:
                              name:
                                type: string
                                description: Name of the attack vector attribute
                              value:
                                type: string
                                description: JSON-stringified value of the attack vector attribute
                              valueType:
                                type: string
                                description: Type of the attack vector attribute
                      description: Attack vector data
                    source:
                      type: object
                      additionalProperties: false
                      properties:
                        ip:
                          type:
                          - string
                          - 'null'
                          description: Endpoint IP, if available
                        type:
                          enum:
                          - computer
                          - dc
                          - server
                          - user
                          - null
                          description: Endpoint object type, if available
                        hostname:
                          type:
                          - string
                          - 'null'
                          description: Endpoint hostname, if available
                      description: Information on the source of the attack
                    destination:
                      type: object
                      additionalProperties: false
                      properties:
                        ip:
                          type:
                          - string
                          - 'null'
                          description: Endpoint IP, if available
                        type:
                          enum:
                          - computer
                          - dc
                          - server
                          - user
                          - null
                          description: Endpoint object type, if available
                        hostname:
                          type:
                          - string
                          - 'null'
                          description: Endpoint hostname, if available
                      description: Information on the destination of the attack
                    isClosed:
                      type: boolean
                      description: Whether the customer has closed the attack
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Attack
      x-tenablead-required-product-license-type:
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: profileId
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      - name: attackTypeIds
        in: query
        schema:
          type: array
          items:
            type: string
        required: false
        deprecated: false
      - name: dateEnd
        in: query
        schema:
          type: string
          format: date-time
        required: false
        deprecated: false
      - name: dateStart
        in: query
        schema:
          type: string
          format: date-time
        required: false
        deprecated: false
      - name: includeClosed
        in: query
        schema:
          type: string
          enum:
          - 'true'
          - 'false'
        required: false
        deprecated: false
      - name: limit
        in: query
        schema:
          type: string
          pattern: ^[0-9]+$
        required: false
        deprecated: false
      - name: order
        in: query
        schema:
          type: string
          enum:
          - desc
          - asc
        required: false
        deprecated: false
      - name: resourceType
        in: query
        schema:
          type: string
          enum:
          - infrastructure
          - directory
          - hostname
          - ip
        required: true
        deprecated: false
      - name: resourceValue
        in: query
        schema:
          type: string
        required: true
        deprecated: false
      - name: search
        in: query
        schema:
          type: string
        required: false
        deprecated: false
      security:
      - ApiKey: []
      operationId: getApiProfilesByProfileIdAttacksExport
      x-operation-id-source: derived
components:
  securitySchemes:
    ApiKey:
      name: x-api-key
      description: The user's API key
      in: header
      type: apiKey
x-readme:
  explorer-enabled: true
  proxy-enabled: true