Batch-retrieve detailed intelligence for up to 250 Malicious Sites alerts in a single request.
What this endpoint does
Retrieves detailed information for multiple Malicious Sites alerts at once (up to 250 alert IDs), with each alert's data grouped into UI-ready panels. These alerts flag attacker domains impersonating or abusing your protected brands — phishing pages, fake login forms, logo-cloning sites, parked/for-sale lookalikes, and re-registered malicious domains.
It returns the same panels and per-alert data as Playbook Alerts: Malicious Sites Detail — just for many alerts in one call. Use the Playbook Alerts: Search endpoint with category: malicious_sites to discover alert IDs; to download captured screenshots, use Playbook Alerts: Malicious Sites Image.
