Retrieve detailed threat intelligence information for a specific indicator by looking up the indicator’s value. To query links and properties, retrieve the indicator by ID instead.
Your Pulsedive API key.
API key authentication is optional. However, requests without a key have stricter rate limits. We recommend including an API key for better performance and reliability.
Value of the indicator to retrieve. May be:
microsoft.com)8.8.8.8)https://pulsedive.com/explore)Indicates whether to return indicator properties as they appeared in previous scans. Use to analyze trends or audit historical threat activity.
For historical data, set to 1. For recent data, set to 0.
0, 1 Indicates whether to return attributes associated with the indicator type you are querying.
To return associated attributes, set to 1. To return default data, set to 0.
0, 1 Indicates whether to format returned JSON results.
For pretty-printed output, set to 1.
For compact output, set to 0.
0, 1 Successful request. Returns indicator information in JSON format.
Unique identifier of an associated previous submission request, if available.
Unique identifier of the indicator.
Value of the indicator.
Type of indicator.
domain, ip, url Final risk score for the indicator.
If the risk score has been manually adjusted, this value may differ from the recommended risk score.
In this case, manualrisk is set to 1.
unknown, very low, low, medium, high, critical Recommended risk level based on Pulsedive automated risk scoring.
unknown, very low, low, medium, high, critical Indicates whether the risk score has been manually adjusted.
When set to 1, the risk score has been manually adjusted.
When set to 0, the risk score reflects Pulsedive's automated assessment.
0, 1 Indicates whether this indicator is inactive or obsolete.
An indicator is automatically retired if, in the past three months, it has not been:
Pulsedive research can also retire indicators manually.
When set to 1, this indicator is retired.
When set to 0, this indicator is active.
0, 1 Timestamp when the indicator was first added to Pulsedive. 24-hour format, UTC time zone.
^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}$"2025-05-19 14:23:45"
Timestamp when the indicator record was last updated in Pulsedive. 24-hour format, UTC time zone.
^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}$"2025-05-19 14:23:45"
Timestamp when the indicator was last reported or seen in feeds or user submissions in Pulsedive. 24-hour format, UTC time zone.
^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}$"2025-05-19 14:23:45"
Timestamp when the indicator was last actively scanned (probed) by Pulsedive. 24-hour format, UTC time zone.
^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}$"2025-05-19 14:23:45"
Timestamp when the indicator was retired in Pulsedive, if applicable. 24-hour format, UTC time zone.
^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}$"2025-05-19 14:23:45"
Indicates whether this indicator has had recent activity. Deprecated and non-functional.
When set to 1, the indicator has had recent activity.
When set to 0, the indicator has not had recent activity.
0, 1 Number of times the indicator has been submitted by any user.
Rank of the indicator on Cisco Umbrella's top one million domains list. This list reflects the most frequently queried domains, based on passive DNS data across Cisco's global Umbrella network.
11032
Canonical (base) domain as recognized by Cisco Umbrella. Populated when umbrella_rank is present.
List of risk factors influencing this indicator's score.
Redirect relationships involving this indicator.
Known threats associated with this indicator.
Threat intelligence feeds that reference this indicator.
Comments submitted by Pulsedive contributors for this indicator.
Technical metadata observed for this indicator.
Detailed sub-properties for this indicator, grouped by type or data source.