# Threat List

Threat List; Threat ID, Threat Display ID, Threat Name, Release Date, Severity, Tags, Affected Operating Systems, Is Predefined, Attack Categories, Attack Module Ids, Unified Kill Chain Phases, Mitres

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…

About

You can use Threat List endpoint to reach out Threat ID, Threat Display ID, Threat Name, Release Date, Severity, Tags, Affected Operating Systems, Is Predefined, Attack Categories, Attack Module Ids, Unified Kill Chain Phases, MITRE ATT&CK details as in Picus Threat Library.

Query Params
int64
int64
severities
array of strings

Filter with Severity (one or more severity): Low | Medium | High

severities
attack_category_ids
array of int64s

Filter with one or more Attack Category IDs.

Available attack categories, as id: name (attack module):

1: Malicious Code (Network Infiltration)
2: Attack Scenario (Windows Endpoint Scenario)
3: Vulnerability Exploitation (Network Infiltration)
4: Web Application (Web Application)
5: Malicious Code (E-mail Infiltration)
6: Vulnerability Exploitation (E-mail Infiltration)
7: Data Exfiltration (Data Exfiltration)
37: Attack Scenario (Linux Endpoint Scenario)
38: Attack Scenario (macOS Endpoint Scenario)
39: Lateral Movement Techniques (Windows Endpoint Scenario)
41: URL Filtering (URL Filtering)
42: Attack Scenario (Kubernetes Endpoint Scenario)
137: Azure ARM (Azure Cloud Emulation)
138: Azure Entra ID (Azure Cloud Emulation)
139: Azure m365 (Azure Cloud Emulation)
140: AWS (AWS Cloud Emulation)
141: GCP (GCP Cloud Emulation)

attack_category_ids
attack_module_ids
array of int64s

Filter with one or more Attack Module IDs.

Available attack modules, as id: name:

1: Network Infiltration
2: Windows Endpoint Scenario
3: Web Application
4: E-mail Infiltration
5: Data Exfiltration
6: Linux Endpoint Scenario
7: macOS Endpoint Scenario
9: URL Filtering
10: Kubernetes Endpoint Scenario
103: Azure Cloud Emulation
104: AWS Cloud Emulation
105: GCP Cloud Emulation

attack_module_ids
int64

Filter with Release Date Greater Than or Equals.

int64

Filter with Release Date Less Than or Equals.

boolean

Filter with whether threat is predefined.

affected_products
array of strings

Filter with Affected Products.

affected_products
affected_os
array of strings

Filter with Affected Operating Systems. Windows | Linux | macOS

affected_os
unified_kill_chains
array of strings

Filter with Unified Kill Chain Phases.

unified_kill_chains
threat_actors
array of strings

Threat Actors Filter

threat_actors
mitre_attack
array of strings

Mitre Tactics Filter

mitre_attack
attacker_objectives
array of strings

Attacker Objectives Filter

attacker_objectives
Responses

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json