How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

UpGuard threatmonitoring API

The threatmonitoring API from UpGuard — 9 operation(s) for threatmonitoring.

UpGuard threatmonitoring API is one of 18 APIs that UpGuard publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Threat Monitoring. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 9 operations across 9 paths, and defines 51 schemas. It is described by OpenAPI 2.0, at version 1.13.2.

Requests are made against the base URL https://cyber-risk.upguard.com/api/public.

9 operations 9 paths 51 schemas 3 GET6 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 2.0
API Version
1.13.2
Base URL
https://cyber-risk.upguard.com/api/public
Authentication
API Key
Resource Areas
1

Authentication & Security 1

UpGuard threatmonitoring API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (API key in header). By default, every request must be authenticated.

Paths & Operations 9

Across 9 paths, the API surfaces 9 operations — 3 GET, 6 POST. Each is listed below with its method, path, parameters, and response codes.

threatmonitoring 9
GET
/threatmonitoring/threat
Get threat details
threatmonitoring_details 1 param → 200404422429500
POST
/threatmonitoring/threat/close
Close threat
threatmonitoring_close_threat 5 params → 200404422429500
POST
/threatmonitoring/threat/comment/add
Add comment to threat
threatmonitoring_add_comment 4 params → 200404422429500
GET
/threatmonitoring/threat/count
Count threats
threatmonitoring_results_count 10 params → 200403404422429500
POST
/threatmonitoring/threat/investigator/update
Update threat's investigator
threatmonitoring_assign_investigator 2 params → 200404422429500
GET
/threatmonitoring/threat/list
List threats
threatmonitoring_results 14 params → 200403404422429500
POST
/threatmonitoring/threat/remediation_request/add
Add remediation request to threat
threatmonitoring_remediation 7 params → 200400404422429500
POST
/threatmonitoring/threat/remediation_request/close
Close threat's remediation request
threatmonitoring_remediation_close 3 params → 200403404422429500
POST
/threatmonitoring/threat/reopen
Reopen threat
threatmonitoring_reopen_threat 2 params → 200404422429500

Schemas 51

The contract defines 51 schemas that model the data the API accepts and returns. The most detailed are ThreatMonitoringResultDetailed (35 properties), ThreatMonitoringResultSummary (30 properties), FacebookPostExternalAPIThreatAdditionalAttributes (29 properties), FacebookProfileExternalAPIThreatAdditionalAttributes (26 properties). Each schema is shown below with its type and property counts.

DataLeakExternalAPIThreatAdditionalAttributes
object
9 properties
RedditPostExternalAPIThreatAdditionalAttributes
object
21 properties
TwitterProfileExternalAPIThreatAdditionalAttributes
object
14 properties
InstagramProfileExternalAPIThreatAdditionalAttributes
object
22 properties
LinkedInUserProfileExternalAPIThreatAdditionalAttributes
object
22 properties
AddThreatCommentV1RequestBody
object
1 property 1 required
CreateThreatRemediationRequestV1RequestBody
object
CreateThreatRemediationRequestV1RequestBody represents the request body for creating a remediation request
1 property
endpointError
object
Error details coming from an endpoint
1 property
ReopenThreatV1ResponsePayloadBody
object
2 properties
TiktokProfileExternalAPIThreatAdditionalAttributes
object
18 properties
GetThreatMonitoringResultsResponsePayloadBody
object
2 properties
TelegramExternalAPIAddAttributes
object
5 properties
PasswordExternalAPIThreatAdditionalAttributes
object
17 properties
ThreatComment
object
5 properties
ThreatLabel
object
1 property
FacebookPostExternalAPIThreatAdditionalAttributes
object
29 properties
DataLeakTag
string
GetThreatDetailsResponsePayloadBody
object
1 property
ChatExternalAPIThreatAdditionalAttributes
object
3 properties
ExternalAPIThreadEntry
object
3 properties
MCPRegistryExternalAPIThreatAdditionalAttributes
object
6 properties
MonitoredThreatModule
string
MonitoredThreatModule Is used to indicate the threat monitoring module for which the data has been collected
LinkedInCompanyProfileHeadquartersExternal
object
5 properties
GithubExternalAPIThreatAdditionalAttributes
object
7 properties
StealerLogsExternalAPIThreatAdditionalAttributes
object
18 properties
ExposedServiceKeywordExternalAPIThreatAdditionalAttributes
object
5 properties
ThreatMonitoringResultSummary
object
a threat finding
30 properties
LinkedInCompanyProfileExternalAPIThreatAdditionalAttributes
object
16 properties
FacebookProfileExternalAPIThreatAdditionalAttributes
object
26 properties
OpenWebExternalAPIThreatAdditionalAttributes
object
3 properties
GenericStealerLogExternalAPIThreatAdditionalAttributes
object
3 properties
ThreatMonitoringResultDetailed
object
35 properties
ExposedServiceIdentifierExternalAPIThreatAdditionalAttributes
object
5 properties
ThreatMonitoringResultStatus
string
MonitoredThreatSourceType
string
MonitoredThreatSourceType Is used to indicate the type of source from which our data vendor discovered the dark web data. This is used to partially categorize…
InstagramPostExternalAPIThreatAdditionalAttributes
object
22 properties
MonitoredThreatType
string
MonitoredThreatType Is used to indicate the type of threat that a result represents. This is used to partially categorize the result and is derived from the co…
CloseThreatRemediationRequestV1ResponsePayloadBody
object
2 properties
ThreatActor
object
an actor for a threat finding (multiple contexts)
2 properties
AssignThreatInvestigatorV1ResponsePayloadBody
object
3 properties
MaskedPassword
object
2 properties
CreateThreatRemediationRequestV1ResponsePayloadBody
object
3 properties
GetThreatMonitoringResultsCountResponsePayloadBody
object
1 property
CookieExternalAPIThreatAdditionalAttributes
object
17 properties
DiscordExternalAPIAddAttributes
object
6 properties
TwitterPostExternalAPIThreatAdditionalAttributes
object
17 properties
ExposedServiceAttributionIdentifierExternalAPI
object
2 properties
CloseThreatV1ResponsePayloadBody
object
3 properties
ExternalAPIThreatAdditionalAttributes
object
22 properties
ThreatOutcome
string
PostExternalAPIThreatAdditionalAttributes
object
8 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

upguard-threatmonitoring-api-openapi.yml Raw ↑

Other APIs UpGuard publishes across the network.

UpGuard breaches API
UpGuard bulk API
UpGuard dataleaks API
UpGuard domains API
UpGuard ips API
UpGuard labels API
UpGuard notifications API
UpGuard organisation API
UpGuard reports API
UpGuard risks API
UpGuard subsidiaries API
UpGuard trust_exchange API
Where this information came from

This is an independent, third-party profile of UpGuard threatmonitoring API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.