Search reports.
Results default to publication date, newest first. Reports without a publication date use the UTC date on which they were stored. Human requests require active platform access. Organisation, group, and user API keys require reports.view; individual root keys are allowed. API-key requests consume their owner’s monthly request quota.
Authorizations
Infrawatch API key. Supply the complete key directly as the header value.
Query Parameters
Report text, publisher, or exact IP indicator to search for.
256Case-insensitive publisher name or source identifier filter.
256Inclusive lower bound for the publication date, falling back to the UTC date first stored.
Inclusive upper bound for the publication date, falling back to the UTC date first stored.
Restrict results to reports with or without an IP indicator.
with, without upstream Indicator type to match. Must be provided together with indicator; combines with all other report filters using intersection semantics.
ip, domain, md5, sha1, sha256 A value matching indicator_type. Must be provided together with indicator_type. Domains and IP addresses may be defanged and are normalized before lookup; hashes must contain the exact number of hexadecimal bytes for their type.
1 - 512Ordered report catalogue fields. Repeat the parameter to add secondary sorts.
3report, coverage, published Directions aligned by position with each sort field. Repeat for secondary sorts.
3asc, desc 1 <= x <= 500x >= 0Response
Matching reports.
Present when the request supplied the paired indicator_type and indicator filters.
1 - 512Present when the request supplied the paired indicator_type and indicator filters.
ip, domain, md5, sha1, sha256