post
https://api.recordedfuture.com/playbook-alert/malicious_sites/
Retrieve detailed information about a Malicious Sites Playbook Alert with data grouped into UI-ready panels.
What this endpoint does
Retrieves detailed information for one Malicious Sites alert, identified by its playbook_alert_id in the URL path, with the data grouped into UI-ready panels. These alerts flag attacker domains impersonating or abusing your protected brands — phishing pages, fake login forms, logo-cloning sites, parked/for-sale lookalikes, and re-registered malicious domains.
Use the Playbook Alerts: Search endpoint with category: malicious_sites to discover alert IDs. For many alerts in one call, use Playbook Alerts: Malicious Sites Bulk; to download captured screenshots, use Playbook Alerts: Malicious Sites Image.
