List IP Address risk rules

Get the catalog of ~90 IP risk rules with criticality levels, entity counts, and MITRE ATT&CK codes.

What this endpoint does

Returns the complete catalog of risk rules (~90) used to evaluate IP address risk scores. Use this as a reference to discover valid riskRule filter values for IP Address: Search and IP risk list downloads. Rules cover C2 server activity, botnet traffic, brute force attacks, scanning behavior, spam origination, BGP anomalies, phishing hosting, open proxy usage, and threat list membership. No parameters required.

Response data

Returns every IP risk rule with its name (the API filter value), criticality level, description, and current count of IPs triggering it — use the counts to estimate result set sizes before downloading filtered risk lists. Counts range from zero to over 100 million depending on rule breadth.

Response

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json