emerging · 0.8 market domain

Threat Detection

Score 23.9 / 100 107 providers +8 via APIs 69 APIs Search apis.io →
Business capabilities this tag reaches
Cybersecurity Management 1

Providers using this tag (107)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Strong 8 Solid coverage with minor gaps
Developing 20 Usable, with meaningful gaps to close
Thin 21 Limited public surface area
Emerging 32 Early or largely undocumented
MitigaCompanySecurityCloud SecuritySaaS Security1 API25.4Lacework FortiCNAPPCloud SecurityCNAPPCompliance1 API22.6DaylightCompanySecurityCybersecurityManaged Detection and Response1 API22.5IBM QRadar Security Intelligence PlatformAnalyticsLog ManagementSecuritySIEM2 APIs22.0ResurfaceAPI AnalyticsAPI ComplianceAPI LoggingAPI Observability5 APIs21.9SentinelOneSecurityXDREDREndpoint Protection1 API21.07AICompanyCybersecuritySecurityArtificial Intelligence20.5CardinalOpsCompanyCybersecuritySecurity OperationsDetection Engineering20.1VorlonCompanySecuritySaaS SecurityAI Agents19.7Ambient.aiCompanyPhysical SecurityComputer VisionArtificial Intelligence19.5Carbon BlackCompanySecurityEndpoint SecurityEDR1 API19.0HalcyonCompanyAI InfrastructureCybersecurityRansomware1 API18.6Radiant SecurityCompanySecurityCybersecuritySecurity Operations18.6Vega SecurityCompanyCybersecuritySecurity OperationsSIEM17.7ClarotyCompanyCybersecurityOT SecurityCyber-Physical Systems17.3MimicCompanyEnterpriseCybersecurityRansomware Defense16.7CroglCompanySecurityCybersecuritySecurity Operations16.6AegisAICompanyArtificial IntelligenceEmail SecurityCybersecurity16.3CounterTackCompanySecurityCybersecurityEndpoint Security1 API16.0SkopenowCompanyOpen Source IntelligenceOSINTInvestigations15.2ClearvectorCompanySecurityCloud SecurityDetection and Response14.9Qevlar AICompanyEngineering ServicesSecurityCybersecurity14.6PeripheryCompanySecurityCybersecurityCritical Infrastructure14.0Abstract SecuritySecurityCybersecuritySIEMSecurity Data Pipeline13.9ExaforceCompanySecurityCybersecuritySecurity Operations13.6Legion SecurityCompanyCloud SaasSecuritySecurity Operations13.4Command ZeroCompanySecurityCybersecuritySOC13.2Prophet SecurityCompanyArtificial IntelligenceSecurityCybersecurity12.9Crosslayer LabsCompanySecurityNetwork SecurityWeb Infrastructure11.9EclypsiumCompanySecurityCybersecurityFirmware Security11.8SIEMonsterCompanySecuritySIEMCybersecurity11.6AndesiteCompanyDefense GovernmentCybersecuritySecurity Operations11.3
Minimal 20 Almost no public developer surface
Unrated 6 Not yet scored

APIs with this tag (69)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Exemplar 1 Complete, well-documented, and agent-ready
Strong 50 Solid coverage with minor gaps
Cisco XDR Actor APIActor operations65.6Cisco XDR Asset APIAsset operations65.6Cisco XDR Asset Mapping APIAsset Mapping operations65.6Cisco XDR Asset Properties APIAsset Properties operations65.6Cisco XDR Attack Pattern APIAttack Pattern operations65.6Cisco XDR Bulk APIThe Bulk API from Cisco XDR — 1 operation(s) for bulk.65.6Cisco XDR Bundle APIThe Bundle API from Cisco XDR — 2 operation(s) for bundle.65.6Cisco XDR Campaign APICampaign operations65.6Cisco XDR Casebook APICasebook operations65.6Cisco XDR COA APICOA operations65.6Cisco XDR Deliberate APIThis set of routes allow to quickly get answers from your integrations You might use them at the start of a...65.6Cisco XDR Event APIEvents operations65.6Cisco XDR Feed APIFeed operations65.6Cisco XDR Feedback APIFeedback Routes65.6Cisco XDR Health APIThis set of routes allow to check the health of your integrations setup Verify if your modules are setup co...65.6Cisco XDR Incident APIIncident operations65.6Cisco XDR Indicator APIIndicator operations65.6Cisco XDR Inspect APIInspect related routes65.6Cisco XDR Investigation APIThe Investigation API from Cisco XDR — 8 operation(s) for investigation.65.6Cisco XDR INVITE APIThe INVITE API from Cisco XDR — 2 operation(s) for invite.65.6Cisco XDR Iroh APIThe Iroh API from Cisco XDR — 3 operation(s) for iroh.65.6Cisco XDR Judgement APIJudgement operations65.6Cisco XDR LOGIN APIThe LOGIN API from Cisco XDR — 4 operation(s) for login.65.6Cisco XDR Malware APIMalware operations65.6Cisco XDR MCP ServerModel Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investig...65.6Cisco XDR Metrics APIThe Metrics API from Cisco XDR — 1 operation(s) for metrics.65.6Cisco XDR Module Instance APIModuleInstance Routes65.6Cisco XDR Module Type APIModuleType Routes65.6Cisco XDR Module Type Patch APIModuleTypePatch Routes65.6Cisco XDR Note APIThe Note API from Cisco XDR — 8 operation(s) for note.65.6Cisco XDR Observe APIThis set of routes allow to get in depth investigation data about a threat You might use them at the start ...65.6Cisco XDR One Click APIOne-click Routes65.6Cisco XDR Private Intel APIAccess private-intel65.6Cisco XDR Properties APIThe Properties API from Cisco XDR — 1 operation(s) for properties.65.6Cisco XDR Query APIThis set of routes allow to query for records related to observable events.Results are returned in OCSF for...65.6Cisco XDR Refer APIThis set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a...65.6Cisco XDR Relationship APIRelationship operations65.6Cisco XDR Reputation APIThe Reputation API from Cisco XDR — 1 operation(s) for reputation.65.6Cisco XDR Response APIIROH Response65.6Cisco XDR Session Cookie APICookie-based session validation65.6Cisco XDR Sighting APISighting operations65.6Cisco XDR Status APIThe Status API from Cisco XDR — 1 operation(s) for status.65.6Cisco XDR Target Record APITarget Record operations65.6Cisco XDR Tool APITool operations65.6Cisco XDR Verdict APIThe Verdict API from Cisco XDR — 1 operation(s) for verdict.65.6Cisco XDR Version APIThe Version API from Cisco XDR — 1 operation(s) for version.65.6Cisco XDR Vulnerability APIThe Vulnerability API from Cisco XDR — 9 operation(s) for vulnerability.65.6Cisco XDR Webhook APIWebhook Routes65.6Cisco XDR Webhook Result APIThe WebhookResult API from Cisco XDR — 2 operation(s) for webhookresult.65.6Treblle API SecurityTreblle API Security provides real-time threat detection with 15+ automated security checks on every API re...63.2
Developing 12 Usable, with meaningful gaps to close
VMware vDefend APIAPI for VMware vDefend lateral security platform providing network security segmentation, threat detection,...52.3AT&T Threat Detection APIThe Threat Detection API from AT&T — 1 operation(s) for threat detection.49.7Trellix Detection as a Service APIAPI-driven malware detection service that leverages the Trellix Multi-Vector Virtual Execution (MVX) engine...43.3Trellix Email Security Cloud APIRESTful API for Trellix Email Security Cloud (formerly FireEye ETP) providing custom integration capabiliti...43.3Trellix Endpoint Security (HX) APIREST API for the Trellix Endpoint Security (HX) platform, formerly FireEye HX. Provides programmatic access...43.3Trellix Helix APIAPI for the Trellix Helix security operations platform that integrates security controls from Trellix and o...43.3Trellix Intelligent Sandbox APIREST API for Trellix Intelligent Sandbox (formerly Advanced Threat Defense) that enables automated submissi...43.3Trellix IOC (Indicators of Compromise) APIREST API interface for managing indicators of compromise within the Trellix security platform. Enables uplo...43.3Hexagate (Chainalysis)Web3 security product (acquired by Chainalysis) that monitors smart contracts and on-chain activity in real...41.8Red Canary REST API v3Tenant-scoped REST API over the Red Canary portal. Documented resources include detections, threats, events...40.8Imperva API SecurityAPI for managing Imperva's API security product, providing visibility into API traffic, detection of API vu...39.7Stream.Security Threat Detection APIThe Threat Detection API from Stream.Security — 4 operation(s) for threat detection.39.5
Thin 3 Limited public surface area
Emerging 3 Early or largely undocumented

Companies reaching this through an API (8)

These companies publish an API, specification or operation carrying “Threat Detection” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.

AT&T Chainalysis Imperva Noname Security Protect AI Red Hat Treblle VMware

Score breakdown

Frequency
61.0
log-scaled weighted occurrences
Breadth
2.8
spread across providers
Quality lift
33.1
mean composite of providers using it
Cohesion
9.0
strength of nearest seed neighbor

Where this tag sits

Security broader

Related tags

SIEM 32 co-occurrences Security Operations 29 co-occurrences Incident Response 30 co-occurrences SOC 16 co-occurrences Cybersecurity 67 co-occurrences Cloud Security 21 co-occurrences Endpoint Security 15 co-occurrences Security 81 co-occurrences

Where this tag comes from

Provider tag107
Api tag69
Openapi tag2
Openapi op tag6

Cohort brief

Auto-generated

The 100 providers in the APIs.io catalog tagged Threat Detection, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
100
all scored
Mean Kin Score
27.2
+4.3 vs catalog 22.9
Mean Agent Readiness
12.4
+0.5 vs catalog 11.9
Spread
0–65.6
median 24 · σ 16.3
How the 100 split by band
Exemplar 0Strong 8Developing 20Thin 21Emerging 32Minimal 19
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Access Clarity 31.5 26.5 +5 100
Developer Ergonomics 27.4 23.2 +4.2 100
Discoverability 61.9 58.1 +3.8 100
Contract Quality 20.8 17.6 +3.2 100
Contract Governance 8.5 6.3 +2.2 100
Operational Transparency 15.5 13.7 +1.8 100

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 17% 14% +3
MCP server (first-party) 16% 12% +4
Agent Skills 0% 0% 0
OAuth scopes 12% 11% +1
Security 94% 98% -4
Arazzo workflows 4% 2% +2
Governance rules 14% 14% 0

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

Top by Kin Score
  1. 1 Cisco XDR 65.6
  2. 2 OpenText Cybersecurity 60.3
  3. 3 AppOmni 59
  4. 4 Malwarebytes 59
  5. 5 Amazon GuardDuty 57.7
  6. 6 AirMDR 55.1
  7. 7 Amazon Security Lake 55.1
  8. 8 Panther 54.6
  9. 9 Upwind 52
  10. 10 LevelBlue 50
Top by Agent Readiness
  1. 1 AirMDR 45.8
  2. 2 Upwind 41.5
  3. 3 Cisco XDR 38.5
  4. 4 Amazon GuardDuty 37.1
  5. 5 OpenText Cybersecurity 36.7
  6. 6 AppOmni 36.7
  7. 7 Stream.Security 34.4
  8. 8 Adlumin 33.6
  9. 9 Panther 30.8
  10. 10 Varonis 30.6
All 107 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 5 October 2026, across 29093 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/threat-detection"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/threat-detection"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/threat-detection/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.