CVEExploitationActivity is a JSON Structure definition published by GreyNoise Intelligence, describing 7 properties. It conforms to the https://json-structure.org/meta/core/v0/# meta-schema.
{
"$schema": "https://json-structure.org/meta/core/v0/#",
"$id": "https://api-evangelist.github.io/greynoise/json-structure/greynoise-cve-exploitation-activity-structure.json",
"name": "CVEExploitationActivity",
"type": "object",
"properties": {
"activity_seen": {
"type": "boolean",
"description": "Whether exploitation activity has been observed.",
"example": true
},
"benign_ip_count_1d": {
"type": "int32",
"description": "The count of benign IPs in the last day.",
"example": 100
},
"benign_ip_count_10d": {
"type": "int32",
"description": "The count of benign IPs in the last 10 days.",
"example": 500
},
"benign_ip_count_30d": {
"type": "int32",
"description": "The count of benign IPs in the last 30 days.",
"example": 1000
},
"threat_ip_count_1d": {
"type": "int32",
"description": "The count of threat IPs in the last day.",
"example": 10
},
"threat_ip_count_10d": {
"type": "int32",
"description": "The count of threat IPs in the last 10 days.",
"example": 50
},
"threat_ip_count_30d": {
"type": "int32",
"description": "The count of threat IPs in the last 30 days.",
"example": 100
}
}
}
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.