Playbook Alerts: Malicious Sites Bulk

Batch-retrieve detailed intelligence for up to 250 Malicious Sites alerts in a single request.

What this endpoint does

Retrieves detailed information for multiple Malicious Sites alerts at once (up to 250 alert IDs), with each alert's data grouped into UI-ready panels. These alerts flag attacker domains impersonating or abusing your protected brands — phishing pages, fake login forms, logo-cloning sites, parked/for-sale lookalikes, and re-registered malicious domains.

It returns the same panels and per-alert data as Playbook Alerts: Malicious Sites Detail — just for many alerts in one call. Use the Playbook Alerts: Search endpoint with category: malicious_sites to discover alert IDs; to download captured screenshots, use Playbook Alerts: Malicious Sites Image.


Body Params
playbook_alert_ids
array of strings
required

The unique ids of the triggered Playbook Alerts. Maximum number of ids in a single request is 250.

playbook_alert_ids*
panels
array of strings

Request inclusion of detailed Malicious Sites alert data, grouped into a set of panels. If left unset, all panels will be returned.

panels
Allowed:
Response

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json