emerging · 2.4

Threat Detection

Score 23.7 / 100 115 providers 72 APIs Search apis.io →
Variants seen in the corpus: Threat Detectionthreat-detection

Providers using this tag (113)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Strong 6 Solid coverage with minor gaps
Developing 25 Usable, with meaningful gaps to close
PantherCompanySecuritySIEMDetection and Response21 APIs54.0Amazon GuardDutyAnomaly DetectionComplianceMachine-LearningMonitoring4 APIs53.0LevelBlueCompanyEnterpriseCybersecuritySecurity4 APIs52.2Amazon Security LakeData LakeSecuritySIEM3 APIs51.4AT&T5GBroadbandCAMARAConnectivity28 APIs50.9Nord SecurityCybersecurityThreat IntelligenceDark Web MonitoringAttack Surface Management10 APIs50.7Google Cloud Security Command CenterCloud SecurityComplianceRisk ManagementSecurity4 APIs48.1VMwareCloud ComputingContainer ManagementHybrid CloudInfrastructure59 APIs47.7TaniumComplianceEndpoint ManagementPatch ManagementSecurity22 APIs47.3TracebitCompanyCloud SaasSecurityDeception2 APIs46.8Push SecurityCompanyEnterpriseSecurityIdentity1 API45.7TrellixCloud SecurityCybersecurityEndpoint Security27 APIs43.5SaaS AlertsMSPSaaS SecuritySecurity Monitoring2 APIs43.0Google Cloud ChronicleIncident ResponseLog ManagementSecurity AnalyticsSecurity Operations4 APIs42.9ImpervaSecurityCybersecurityWAFDDoS Protection15 APIs42.5FortaCompanySecurityBlockchainWeb31 API42.3Microsoft SentinelMicrosoftSecuritySIEMSOAR5 APIs42.2BlockaidCompanyFintechWeb3 SecurityBlockchain23 APIs40.8ScannerCompanySecuritySIEMLog Analytics6 APIs40.8CybereasonCybersecurityXDREDRNGAV10 APIs40.4Ocean SecurityCompanySecurityEmail SecurityCybersecurity4 APIs40.1Vectra AICompanyCybersecurityNetwork Detection and Response17 APIs39.9RunRevealCompanySecuritySIEMSecurity Log Management1 API39.7Sublime SecurityCompanySecurityEmail SecurityPhishing16 APIs39.7Red CanaryCompanySecurityCybersecurityManaged Detection and Response1 API39.3
Thin 19 Limited public surface area
Emerging 38 Early or largely undocumented
SentinelOneSecurityXDREDREndpoint Protection1 API26.1UptycsSecurityCybersecurityCNAPPXDR1 API24.8Lacework FortiCNAPPCloud SecurityCNAPPCompliance1 API24.3MitigaCompanySecurityCloud SecuritySaaS Security1 API23.7ResurfaceAPI AnalyticsAPI ComplianceAPI LoggingAPI Observability5 APIs23.3Corelight (fka Broala)CompanyCybersecurityNetwork Detection and ResponseNDR23.1IBM QRadar Security Intelligence PlatformAnalyticsLog ManagementSecuritySIEM2 APIs20.7DaylightCompanySecurityCybersecurityManaged Detection and Response1 API20.57AICompanyCybersecuritySecurityArtificial Intelligence19.7Ambient.aiCompanyPhysical SecurityComputer-VisionArtificial Intelligence19.4Carbon BlackCompanySecurityEndpoint SecurityEDR1 API19.3CardinalOpsCompanyCybersecuritySecurity OperationsDetection Engineering19.1VorlonCompanySecuritySaaS SecurityAI Agents18.8Radiant SecurityCompanySecurityCybersecuritySecurity Operations18.6HalcyonCompanyAI InfrastructureCybersecurityRansomware1 API18.4ChainalysisComplianceAMLKYTSanctions12 APIs18.3ClarotyCompanyCybersecurityOT SecurityCyber-Physical Systems17.9CroglCompanySecurityCybersecuritySecurity Operations17.0AegisAICompanyArtificial IntelligenceEmail SecurityCybersecurity16.2SkopenowCompanyOpen Source IntelligenceOSINTInvestigations15.6MimicCompanyEnterpriseCybersecurityRansomware Defense15.5VegaCompanySecuritySecurity OperationsSIEM15.3CounterTackCompanySecurityCybersecurityEndpoint Security1 API14.9ClearvectorCompanySecurityCloud SecurityDetection and Response14.5Qevlar AICompanyEngineering ServicesSecurityCybersecurity14.5Vega SecurityCompanyCybersecuritySecurity OperationsSIEM14.5Legion SecurityCompanyCloud SaasSecuritySecurity Operations14.2PeripheryCompanySecurityCybersecurityCritical Infrastructure13.6ExaforceCompanySecurityCybersecuritySecurity Operations13.5Prophet SecurityCompanyArtificial IntelligenceSecurityCybersecurity13.4Command ZeroCompanySecurityCybersecuritySOC13.0Noname SecurityAPI DiscoveryAPI SecurityAPI TestingPosture Management4 APIs12.8Crosslayer LabsCompanySecurityNetwork SecurityWeb Infrastructure12.3SIEMonsterCompanySecuritySIEMCybersecurity12.1AndesiteCompanyDefense GovernmentCybersecuritySecurity Operations11.6EclypsiumCompanySecurityCybersecurityFirmware Security11.4Tenex AICompanyCybersecuritySecurity OperationsManaged Detection and Response11.4SemperisCompanyCybersecurityIdentity SecurityActive Directory11.0
Minimal 25 Almost no public developer surface

APIs with this tag (70)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Strong 53 Solid coverage with minor gaps
Logz.io Cloud SIEM APILogz.io Cloud SIEM control plane — manage detection rules (correlation and threshold), retrieve raised secu...65.2Cisco XDR Actor APIActor operations60.7Cisco XDR Asset APIAsset operations60.7Cisco XDR Asset Mapping APIAsset Mapping operations60.7Cisco XDR Asset Properties APIAsset Properties operations60.7Cisco XDR Attack Pattern APIAttack Pattern operations60.7Cisco XDR Bulk APIThe Bulk API from Cisco XDR — 1 operation(s) for bulk.60.7Cisco XDR Bundle APIThe Bundle API from Cisco XDR — 2 operation(s) for bundle.60.7Cisco XDR Campaign APICampaign operations60.7Cisco XDR Casebook APICasebook operations60.7Cisco XDR COA APICOA operations60.7Cisco XDR Deliberate APIThis set of routes allow to quickly get answers from your integrations You might use them at the start of a...60.7Cisco XDR Event APIEvents operations60.7Cisco XDR Feed APIFeed operations60.7Cisco XDR Feedback APIFeedback Routes60.7Cisco XDR Graph QL APIThe GraphQL API from Cisco XDR — 1 operation(s) for graphql.60.7Cisco XDR Health APIThis set of routes allow to check the health of your integrations setup Verify if your modules are setup co...60.7Cisco XDR Incident APIIncident operations60.7Cisco XDR Indicator APIIndicator operations60.7Cisco XDR Inspect APIInspect related routes60.7Cisco XDR Investigation APIThe Investigation API from Cisco XDR — 8 operation(s) for investigation.60.7Cisco XDR INVITE APIThe INVITE API from Cisco XDR — 2 operation(s) for invite.60.7Cisco XDR Iroh APIThe Iroh API from Cisco XDR — 3 operation(s) for iroh.60.7Cisco XDR Judgement APIJudgement operations60.7Cisco XDR LOGIN APIThe LOGIN API from Cisco XDR — 4 operation(s) for login.60.7Cisco XDR Malware APIMalware operations60.7Cisco XDR MCP ServerModel Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investig...60.7Cisco XDR Metrics APIThe Metrics API from Cisco XDR — 1 operation(s) for metrics.60.7Cisco XDR Module Instance APIModuleInstance Routes60.7Cisco XDR Module Type APIModuleType Routes60.7Cisco XDR Module Type Patch APIModuleTypePatch Routes60.7Cisco XDR Note APIThe Note API from Cisco XDR — 8 operation(s) for note.60.7Cisco XDR Observe APIThis set of routes allow to get in depth investigation data about a threat You might use them at the start ...60.7Cisco XDR One Click APIOne-click Routes60.7Cisco XDR Private Intel APIAccess private-intel60.7Cisco XDR Properties APIThe Properties API from Cisco XDR — 1 operation(s) for properties.60.7Cisco XDR Query APIThis set of routes allow to query for records related to observable events.Results are returned in OCSF for...60.7Cisco XDR Refer APIThis set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a...60.7Cisco XDR Relationship APIRelationship operations60.7Cisco XDR Reputation APIThe Reputation API from Cisco XDR — 1 operation(s) for reputation.60.7Cisco XDR Response APIIROH Response60.7Cisco XDR Session Cookie APICookie-based session validation60.7Cisco XDR Sighting APISighting operations60.7Cisco XDR Status APIThe Status API from Cisco XDR — 1 operation(s) for status.60.7Cisco XDR Target Record APITarget Record operations60.7Cisco XDR Tool APITool operations60.7Cisco XDR Verdict APIThe Verdict API from Cisco XDR — 1 operation(s) for verdict.60.7Cisco XDR Version APIThe Version API from Cisco XDR — 1 operation(s) for version.60.7Cisco XDR Vulnerability APIThe Vulnerability API from Cisco XDR — 9 operation(s) for vulnerability.60.7Cisco XDR Webhook APIWebhook Routes60.7Cisco XDR Webhook Result APIThe WebhookResult API from Cisco XDR — 2 operation(s) for webhookresult.60.7Red Hat Malware Detection APIAPI for detecting potential malware signatures on RHEL systems registered with the Hybrid Cloud Console, pr...59.1Treblle API SecurityTreblle API Security provides real-time threat detection with 15+ automated security checks on every API re...55.1
Developing 11 Usable, with meaningful gaps to close
AT&T Threat Detection APIThe Threat Detection API from AT&T — 1 operation(s) for threat detection.50.9NordStellar Cybersec APIURL and file scanning API with allow/deny list management and account usage control (AUC). 23 operations, O...50.7VMware vDefend APIAPI for VMware vDefend lateral security platform providing network security segmentation, threat detection,...47.7Trellix Detection as a Service APIAPI-driven malware detection service that leverages the Trellix Multi-Vector Virtual Execution (MVX) engine...43.5Trellix Email Security Cloud APIRESTful API for Trellix Email Security Cloud (formerly FireEye ETP) providing custom integration capabiliti...43.5Trellix Endpoint Security (HX) APIREST API for the Trellix Endpoint Security (HX) platform, formerly FireEye HX. Provides programmatic access...43.5Trellix Helix APIAPI for the Trellix Helix security operations platform that integrates security controls from Trellix and o...43.5Trellix Intelligent Sandbox APIREST API for Trellix Intelligent Sandbox (formerly Advanced Threat Defense) that enables automated submissi...43.5Trellix IOC (Indicators of Compromise) APIREST API interface for managing indicators of compromise within the Trellix security platform. Enables uplo...43.5Imperva API SecurityAPI for managing Imperva's API security product, providing visibility into API traffic, detection of API vu...42.5Red Canary REST API v3Tenant-scoped REST API over the Red Canary portal. Documented resources include detections, threats, events...39.3
Thin 2 Limited public surface area
Emerging 4 Early or largely undocumented

Score breakdown

Frequency
61.3
log-scaled weighted occurrences
Breadth
3.2
spread across providers
Quality lift
31.7
mean composite of providers using it
Cohesion
8.7
strength of nearest seed neighbor

Related tags

SIEM 32 co-occurrences Security Operations 29 co-occurrences Incident Response 28 co-occurrences Cybersecurity 68 co-occurrences SOC 16 co-occurrences Endpoint Security 15 co-occurrences Cloud Security 18 co-occurrences Security 78 co-occurrences

Where this tag comes from

Provider tag103
Api tag72
Openapi tag3
Openapi op tag3

Cohort brief

Auto-generated

The 113 providers in the APIs.io catalog tagged Threat Detection, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
113
of 115 on the roster
Mean Kin Score
25.9
+5.2 vs catalog 20.7
Mean Agent Readiness
11.4
+1.7 vs catalog 9.7
Spread
1.5–65.2
median 20.7 · σ 16.5
How the 113 split by band
Exemplar 0Strong 6Developing 25Thin 19Emerging 38Minimal 25
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Access Clarity 30.3 22.3 +8 113
Developer Ergonomics 24.9 17.9 +7 113
Contract Quality 21.3 17.5 +3.8 113
Discoverability 64.1 60.4 +3.7 113
Contract Governance 9.7 6.4 +3.3 113
Operational Transparency 14.5 11.3 +3.2 113

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 21% 16% +5
MCP server (first-party) 12% 7% +5
Agent Skills 0% 0% 0
OAuth scopes 12% 9% +3
Security 94% 88% +6
Arazzo workflows 6% 2% +4
Governance rules 18% 13% +5

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

Top by Kin Score
  1. 1 Logz.io 65.2
  2. 2 Cisco XDR 60.7
  3. 3 Red Hat 59.1
  4. 4 Upwind 57
  5. 5 Malwarebytes 55.3
  6. 6 Treblle 55.1
  7. 7 Panther 54
  8. 8 Amazon GuardDuty 53
  9. 9 LevelBlue 52.2
  10. 10 Amazon Security Lake 51.4
Top by Agent Readiness
  1. 1 Red Hat 52.3
  2. 2 Nord Security 45.7
  3. 3 Upwind 43.7
  4. 4 Cisco XDR 38.9
  5. 5 AT&T 37.3
  6. 6 Amazon GuardDuty 37.1
  7. 7 Malwarebytes 32.9
  8. 8 Stairwell 32.2
  9. 9 LevelBlue 30.8
  10. 10 Panther 30.8
This roster declares 115 members; 113 resolve to a provider in the catalog and 113 carry a score (100%). The figures above describe the scored members only.Generated from the catalog build of 25 August 2026, across 26891 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/threat-detection"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/threat-detection"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/threat-detection/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.