Rank malware families by prevalence and opportunity scores for a specific organization.
What this endpoint does
Returns the malware threat map for a specific organization within a multi-organization enterprise. Identical to Malware Threat Map but requires an explicit orgId path parameter. Obtain valid org IDs from Available Threat Maps — use the organization.id field (uhash format). The url field from Available Threat Maps is the literal request path. Filter by malware entity IDs, category IDs, or watchlist IDs; empty body returns the full map.
Response data
Returns malware families ranked by prevalence and opportunity scores with watchlist-triggered log entries — same structure as the primary-org variant. The field is prevalence, not intent as the spec documents.
