How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Abnormal AI Threats API

APIs to manage threats notified in the Abnormal Threat Log

Abnormal AI Threats API is one of 17 APIs that Abnormal AI publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Threats. The published artifact set on APIs.io includes an OpenAPI specification and an API reference.

This API exposes 7 operations across 6 paths, and defines 14 schemas. It is described by OpenAPI 3.2.0, at version 1.4.3.

Requests are made against 2 base URLs: https://api.abnormalplatform.com/v1, https://eu.rest.abnormalsecurity.com/v1.

7 operations 6 paths 14 schemas 6 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.4.3
Base URL
https://api.abnormalplatform.com/v1
Authentication
HTTP Bearer
Terms of Service
Resource Areas
1

Authentication & Security 1

Abnormal AI Threats API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (BearerAuth). By default, every request must be authenticated.

Paths & Operations 7

Across 6 paths, the API surfaces 7 operations — 6 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Threats 7

APIs to manage threats notified in the Abnormal Threat Log

GET
/threats
Get a list of threats
v1_threats_retrieve 13 params → 200401403404429
GET
/threats/{threat_id}
Get details of a threat
v1_threats_retrieve_2 4 params → 200401403404429
POST
/threats/{threat_id}
Manage a Threat identified by Abnormal Security
v1_threats_create 2 params body → 202401403404429
GET
/threats/{threat_id}/actions/{action_id}
Check the status of an action requested on a threat.
v1_threats_actions_retrieve 3 params → 200401403404429
GET
/threats/{threat_id}/attachments
Get attachment details of a threat campaign.
v1_threats_attachments_retrieve 2 params → 200401403404429
GET
/threats/{threat_id}/links
Get information of links in a threat campagin.
v1_threats_links_retrieve 2 params → 200401403404429
GET
/threats_export/csv
Download data from Threat Log in .csv format
v1_threats_export_csv_retrieve 5 params → 200401403404429

Schemas 14

The contract defines 14 schemas that model the data the API accepts and returns. The most detailed are ThreatMessage (36 properties), ThreatLinks (7 properties), ThreatDetails (7 properties), CustomerOverride (4 properties). Each schema is shown below with its type and property counts.

ThreatLinks
object
7 properties 7 required
ActionStatus
object
4 properties 4 required
Threat
object
1 property 1 required
ThreatAttachments
object
3 properties 3 required
CustomerOverride
object
Serializes customer override attribution for a message. Present when blocklist or Custom AI Model attribution is enabled.
4 properties 2 required
PaginatedThreats
object
3 properties 1 required
PostThreatRequestActionEnum
string
PostThreatResponse
object
4 properties 4 required
ThreatAttachmentsResponse
object
3 properties 3 required
ThreatMessage
object
36 properties 32 required
ThreatDetails
object
7 properties 5 required
PostThreatRequest
object
1 property 1 required
ThreatLinksResponse
object
3 properties 3 required
ActionStatusStatusEnum
string

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

abnormal-threats-api-openapi.yml Raw ↑

Other APIs Abnormal AI publishes across the network.

Abnormal AI AI Security Mailbox (formerly known as Abuse Mailbox) API
Abnormal AI Audit Logs API
Abnormal AI Cases API
Abnormal AI Dashboard Aggregations API
Abnormal AI Detection360 API
Abnormal AI Employee Insights API
Abnormal AI Messages API
Abnormal AI Resources API
Abnormal AI Roles API
Abnormal AI Search and Respond API
Abnormal AI Security Settings API
Abnormal AI SPM API
Where this information came from

This is an independent, third-party profile of Abnormal AI Threats API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.