Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Censys Threat Hunting API

Endpoints related to the Adversary Investigation product

Censys Threat Hunting API is one of 14 APIs that Censys publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Threat Hunting. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, a getting-started guide, and a changelog.

This API exposes 13 operations across 12 paths, and defines 43 schemas. It is described by OpenAPI 3.1.0, at version 1.0.12.

Requests are made against a single base URL, https://graph.data.censys.io.

13 operations 12 paths 43 schemas 10 GET3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
1.0.12
Base URL
https://api.platform.censys.io
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Censys Threat Hunting API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (PersonalAccessToken).

  • PersonalAccessToken — Your Censys personal access token.

Paths & Operations 13

Across 12 paths, the API surfaces 13 operations — 10 GET, 3 POST. Each is listed below with its method, path, parameters, and response codes.

Threat Hunting 13

Endpoints related to the Adversary Investigation product

GET
/v3/threat-hunting/censeye/jobs
Censys CensEye: List Jobs
v3-threathunting-censeye-jobs-list 7 params → 200400401403409500
POST
/v3/threat-hunting/censeye/jobs
Censys CensEye: Create a Pivot Analysis Job
v3-threathunting-censeye-jobs-create 2 params body → 200400401403422500
GET
/v3/threat-hunting/censeye/jobs/{job_id}
Censys CensEye: Get Job Status
v3-threathunting-censeye-jobs-get 3 params → 200400401403404500
GET
/v3/threat-hunting/censeye/jobs/{job_id}/results
Censys CensEye: Get Job Results
v3-threathunting-censeye-job-results 5 params → 200400401403404500
GET
/v3/threat-hunting/certificate/{certificate_id}/observations/hosts
Censys Get Host History for a Certificate
v3-threathunting-get-host-observations-with-certificate 9 params → 200400401403404500
GET
/v3/threat-hunting/host/{ip}/observations/endpoints
Censys Get Endpoint Observation History for a Host
v3-threathunting-endpoint-observations-on-host 11 params → 200400401403404409500
GET
/v3/threat-hunting/host/{ip}/observations/fingerprints
Censys Get Fingerprint Observation History for a Host
v3-threathunting-fingerprint-observations-on-host 12 params → 200400401403404409500
GET
/v3/threat-hunting/host/{ip}/observations/threats
Censys Get Threat History for a Host
v3-threathunting-threats-on-host 12 params → 200400401403404409500
POST
/v3/threat-hunting/scans/discovery
Censys Live Discovery: Initiate a New Scan
v3-threathunting-scans-discovery 2 params body → 200400401403422500
GET
/v3/threat-hunting/scans/{scan_id}
Censys Get Scan Status
v3-threathunting-scans-get 3 params → 200400401403404500
GET
/v3/threat-hunting/threats
Censys List Active Threats
v3-threathunting-threats-list 3 params → 200400401403422500
POST
/v3/threat-hunting/value-counts
Censys CensEye: Retrieve Value Counts to Discover Pivots
v3-threathunting-value-counts 2 params body → 200400401403422500
GET
/v3/threat-hunting/web/{webproperty_id}/observations/threats
Censys Get Threat History for a Web Property
v3-threathunting-threats-on-web 9 params → 200400401403404409500

Schemas 43

The contract defines 43 schemas that model the data the API accepts and returns. The most detailed are CenseyeJob (9 properties), ThreatListItem (8 properties), ThreatOnHostRange (7 properties), HashObservationOnHostRange (7 properties). Each schema is shown below with its type and property counts.

ThreatsListResponse
object
1 property 1 required
TrackedScan_Task
object
3 properties
CountCondition
object
1 property 1 required
TrackedScan_ScanTarget_HostnamePort
object
2 properties
ThreatOnHostRange
object
7 properties 7 required
HashObservationOnHostRange
object
7 properties 6 required
ThreatListItem
object
8 properties 4 required
CenseyeJobsListResponse
object
2 properties 1 required
ResponseEnvelopeCenseyeResultsResponse
object
1 property
ErrorDetail
object
3 properties
ScansDiscoveryInputBody
object
1 property 1 required
ResponseEnvelopeValueCountsResponse
object
1 property
CenseyeResultsResponse
object
2 properties 1 required
SearchValueCountsInputBody
object
2 properties 1 required
CenseyeJob
object
9 properties 3 required
ThreatsOnHostResponse
object
2 properties 2 required
CreateCenseyeJobInputBody
object
1 property 1 required
TrackedScan_ScanTarget
object
4 properties
ServiceId
object
4 properties
ResponseEnvelopeThreatsOnHostResponse
object
1 property
FieldValuePair
object
2 properties 2 required
AuthenticationErrorDetail
object
5 properties
ThreatsOnWebResponse
object
2 properties 2 required
ResponseEnvelopeHashObservationsOnHostResponse
object
1 property
AuthenticationError
object
1 property
ResponseEnvelopeThreatsOnWebResponse
object
1 property
HostObservationRange
object
6 properties 6 required
ThreatReference
object
1 property 1 required
HashObservationsOnHostResponse
object
2 properties 2 required
HostObservationResponse
object
3 properties 2 required
TrackedScan
object
5 properties
ResponseEnvelopeHostObservationResponse
object
1 property
ResponseEnvelopeCenseyeJobsListResponse
object
1 property
ErrorModel
object
6 properties
CenseyeTarget
object
3 properties
ResponseEnvelopeThreatsListResponse
object
1 property
CenseyeResult
object
2 properties 2 required
ResponseEnvelopeCenseyeJob
object
1 property
TrackedScan_ScanTarget_HostPort
object
2 properties
ThreatOnWebRange
object
3 properties 3 required
ValueCountsResponse
object
1 property 1 required
ResponseEnvelopeTrackedScan
object
1 property
WebOrigin
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

censys-threat-hunting-api-openapi.yml Raw ↑

Other APIs Censys publishes across the network.

Censys Account Management API
Censys Adversary Investigation API
Censys Asset Graphs API
Censys Assets API
Censys Collections API
Censys Excluded Assets API
Censys Global Data API
Censys Graph Executions API
Censys Risks API
Censys Seeds API
Censys Shards API
Censys Supply Chain Intelligence API