A read-only, public API over the platform's real intelligence. Every response is JSON with Access-Control-Allow-Origin: *, so it works from the browser or the command line. No API key is required today; requests are rate limited to 60 per minute per IP.
curl https://threats.cyronixsecurity.com/api/v1/cve/CVE-2024-3400 curl https://threats.cyronixsecurity.com/api/v1/domain/cloudflare.com curl https://threats.cyronixsecurity.com/api/v1/stix/cve/CVE-2024-3400
/api/v1API index and endpoint catalog.
/api/v1/cve/{cve}CVE intelligence: NVD, EPSS, CISA KEV, affected products, and the transparent priority score.
Try: /api/v1/cve/CVE-2024-3400/api/v1/ip/{ip}Passive IP intelligence: ASN, network operator, RDAP allocation, country, reverse DNS.
Try: /api/v1/ip/1.1.1.1/api/v1/domain/{domain}Passive domain intelligence: DNS records, SPF/DMARC, certificates, observed subdomains.
Try: /api/v1/domain/cloudflare.com/api/v1/attack/{technique}MITRE ATT&CK technique detail and associated tracked actors.
Try: /api/v1/attack/T1071.004/api/v1/actorsList of tracked GCC-relevant threat actors.
/api/v1/actors/{slug}Threat actor detail with mapped ATT&CK techniques.
Try: /api/v1/actors/oilrig-apt34/api/v1/stix/cve/{cve}CVE as a STIX 2.1 bundle (Vulnerability object).
Try: /api/v1/stix/cve/CVE-2024-3400/api/v1/stix/actorsAll tracked actors and techniques as a STIX 2.1 bundle (Intrusion Set + Attack Pattern + Relationship).