# Deepinfo Docs > Documentation for the Deepinfo API and the Deepinfo Platform: authentication, endpoints, request and response examples, and a guide to the platform screen by screen. Base URL: https://api.deepinfo.com/v1. Authentication: send your API key in the `apikey` request header. Every page below is linked as markdown. Append `.md` to any page URL (`/reference/lookup/domain-whois/` → `/reference/lookup/domain-whois.md`) for its markdown version, request/response examples included. [llms-full.txt](https://docs.deepinfo.com/llms-full.txt) has every page in one file, without the examples. ## Getting Started - [Postman Collection](https://docs.deepinfo.com/getting-started/postman.md): Every Deepinfo API endpoint as a Postman collection. Download it with the Production environment, add your API key and send requests. - [Getting Started](https://docs.deepinfo.com/getting-started.md): Authenticate with your API key, send your first Deepinfo API request and find your way around the reference. - [Authentication](https://docs.deepinfo.com/getting-started/authentication.md): Every Deepinfo API request is authenticated with your API key in the apikey header. - [Environments & Base URL](https://docs.deepinfo.com/getting-started/environments-and-base-url.md): Paid accounts use the Production addresses and demo accounts the Demo addresses; the version is the first path segment, bodies are JSON and timestamps UTC. - [Rate Limits](https://docs.deepinfo.com/getting-started/rate-limits.md): Limits apply per API key and per endpoint; responses carry ratelimit headers that show where you stand. - [Pagination](https://docs.deepinfo.com/getting-started/pagination.md): Paginated endpoints take page and page_size and share one response envelope. - [Search & Filters](https://docs.deepinfo.com/getting-started/search-and-filters.md): The filters body used by search endpoints, its operators, which operators each field accepts, the errors a filter returns, and query-parameter filters on list endpoints. - [Errors](https://docs.deepinfo.com/getting-started/errors.md): The Deepinfo error formats, the status codes they use, the forms a search filter error takes, and an example request and response for each one. ## Platform Guide - [Platform Guide](https://docs.deepinfo.com/guide.md): How to use the Deepinfo Platform, the web application for External Attack Surface Management, Cyber Threat Intelligence, Brand Risk Protection and Deep Search & Insights, from your first sign-in to reports and notifications. - [Getting Started With the Platform](https://docs.deepinfo.com/guide/basics.md): Start using the Deepinfo Platform by signing in, securing your account, finding your way around and learning the list controls every module shares. - [Sign In and Sign Out](https://docs.deepinfo.com/guide/basics/sign-in.md): Sign in to the Deepinfo Platform with your e-mail address and password, and sign out when you are done. - [Reset a Forgotten Password](https://docs.deepinfo.com/guide/basics/reset-password.md): Request a password-reset link by e-mail and set a new password that meets the password rules. - [Set Up Your Account From an E-mail Link](https://docs.deepinfo.com/guide/basics/set-up-your-account.md): Accept an invitation to your organization, or activate a Deepinfo account, and set your first password. - [Use Two-Factor Authentication](https://docs.deepinfo.com/guide/basics/two-factor-authentication.md): Turn two-factor authentication on or off for your account, and sign in with an authenticator code or a recovery code. - [Find Your Way Around](https://docs.deepinfo.com/guide/basics/navigation.md): Learn the frame of every platform page, from the sidebar and its module groups to the breadcrumb, in-page tabs and the +, Cybersecurity News and profile menus. - [What You Can Access](https://docs.deepinfo.com/guide/basics/packages-and-roles.md): Learn how your organization's package decides which screens you can open, and what the Admin and Member roles can do. - [Search, Filter and Export Lists](https://docs.deepinfo.com/guide/basics/lists-filters-and-exports.md): Use the list controls that every module shares, from search, filters, views and columns to bulk selection, record drawers, exports and history comparison. - [Account and Workspace](https://docs.deepinfo.com/guide/settings.md): Find your way around Settings, where you manage your own account, admins manage the organization, and everyone reaches API keys, usage and logs. - [Update Your Profile](https://docs.deepinfo.com/guide/settings/account-details.md): Change your photo, your name and your time zone; your e-mail address is fixed. - [Change Your Password](https://docs.deepinfo.com/guide/settings/change-password.md): Change your password from Settings while you are signed in. - [Review Your Sign-In History](https://docs.deepinfo.com/guide/settings/sessions.md): Read your own session list, with the date, IP address, browser, operating system and type of each entry. - [Choose Which Deepinfo E-mails You Receive](https://docs.deepinfo.com/guide/settings/email-preferences.md): Turn Deepinfo's own e-mails to you on or off; these preferences do not control security alerts. - [Change Your Organization's Name and Logo](https://docs.deepinfo.com/guide/settings/organization.md): Admins can change the organization's name and upload or remove its logo. - [Manage Members and Invitations](https://docs.deepinfo.com/guide/settings/members.md): Admins can invite people, change roles, deactivate or delete members, resend or revoke invitations, and review member activity. - [Require Two-Factor Authentication](https://docs.deepinfo.com/guide/settings/require-two-factor-authentication.md): As an admin, require two-factor authentication for everyone in your organization, and see what people experience once it is required. - [Create and Manage API Keys](https://docs.deepinfo.com/guide/settings/api-keys.md): Generate, rename, delete and choose the default API key, see which member each key belongs to, and understand why the default key matters. - [Check API Usage and Quota](https://docs.deepinfo.com/guide/settings/api-usage.md): Read the quota, the usage and what remains for each group of API endpoints in your package. - [Review API Logs](https://docs.deepinfo.com/guide/settings/api-logs.md): Read and filter the log of API calls, with the endpoint, date, IP address, key, method, status and parameters of each call. - [Global Dashboard](https://docs.deepinfo.com/guide/global-dashboard.md): The platform's landing page shows summary cards for External Attack Surface Management (EASM), Cyber Threat Intelligence (CTI) and Brand Risk Protection (BRP), with your EASM security score, 30-day trends and top lists, and links into each module. - [External Attack Surface Management (EASM)](https://docs.deepinfo.com/guide/easm.md): External Attack Surface Management (EASM) keeps an inventory of your internet-facing assets, suggests related assets through discovery, and reports the issues, vulnerabilities and technologies found on them. - [EASM Dashboard](https://docs.deepinfo.com/guide/easm/dashboard.md): Read the one-page summary of your attack surface, from the security score dial and totals with trends to the top assets, issues, technologies and vulnerabilities. - [How Security Scores Work](https://docs.deepinfo.com/guide/easm/security-score.md): What the A to F security grades mean, how asset weight feeds your organization's score, and where you see organization, asset, domain and issue-type scores. - [Add Assets](https://docs.deepinfo.com/guide/easm/add-assets.md): Add domains, subdomains, IP addresses and websites to your inventory by typing them or uploading a file, then read the result. - [Browse Your Asset Inventory](https://docs.deepinfo.com/guide/easm/asset-inventory.md): Use Inventory to see every monitored asset with its risk signals, and to filter, sort, tag, export, rescan and remove assets. - [Investigate an Asset](https://docs.deepinfo.com/guide/easm/asset-details.md): Open an asset's drawer or detail page to see its score, issues, related assets, technologies, open ports, vulnerabilities, and its WHOIS, DNS, SSL and website records with their history. - [Tag, Weight and Configure Assets](https://docs.deepinfo.com/guide/easm/asset-settings.md): Tag your assets, set how much an asset weighs in your security score, mark a main asset, and choose whether discovery starts from an asset. - [Remove and Restore Assets](https://docs.deepinfo.com/guide/easm/remove-and-restore-assets.md): Remove assets you no longer want to monitor, one at a time or several at once, and add them back from Deleted Assets. - [Asset Insights](https://docs.deepinfo.com/guide/easm/asset-insights.md): See how your assets are spread across registrars, name servers, mail servers, IP addresses and networks, certificates and HTTP status codes. - [Review Discovered Assets](https://docs.deepinfo.com/guide/easm/discovery.md): Approve the assets discovery found into your inventory or ignore them, and find past decisions in the Approved Assets and Ignored Assets lists. - [Tune Smart Discovery](https://docs.deepinfo.com/guide/easm/discovery-settings.md): Turn Deepinfo's smart discovery and smart monitoring rules on or off, exclude seed assets and seed values, choose auto approval, and keep assets out of discovery for good. - [Create Custom Discovery Rules](https://docs.deepinfo.com/guide/easm/custom-discovery-rules.md): Build your own discovery rules from domain filters, add tags and auto approval, and edit, pause or delete them. - [Triage Issues](https://docs.deepinfo.com/guide/easm/issues.md): Use the Issue List to see every security issue on your assets, grouped by issue type or one row per issue, and to filter, open, export and act on them. - [Issue Type Details](https://docs.deepinfo.com/guide/easm/issue-types.md): Open one issue type to see its score, how long it stays open, which assets have it and in what state, its related CVEs, and its description, remedy and classifications. - [Change the State of Issues and Vulnerabilities](https://docs.deepinfo.com/guide/easm/change-issue-state.md): Mark issues and asset vulnerabilities as ignored, risk accepted, resolved or false positive, one at a time or in bulk, and revert or undo the change. - [Issue Insights](https://docs.deepinfo.com/guide/easm/issue-insights.md): Track how your issues develop over time, from resolution, reappearance and false-positive rates to severity and state mix, categories, the most affected assets and fix times. - [Prioritize Vulnerabilities](https://docs.deepinfo.com/guide/easm/vulnerabilities.md): Use the Vulnerability List to rank the CVEs on your assets by CVSS score, EPSS and CISA KEV status, open a CVE with its affected assets, and export the list. - [Vulnerability Details](https://docs.deepinfo.com/guide/easm/vulnerability-details.md): Open one CVE to see its severity and exploitation signals, which of your assets it affects and in what state, and its full CVE record. - [Vulnerability Insights](https://docs.deepinfo.com/guide/easm/vulnerability-insights.md): See how many vulnerabilities your assets have over time, how many assets are exposed to known-exploited CVEs, the average exploitability score and the highest-scoring CVEs. - [Review Detected Technologies](https://docs.deepinfo.com/guide/easm/technologies.md): See the software, frameworks and services detected on your assets with their versions and known vulnerabilities, find out-of-date versions, and export the list. - [Technology Details](https://docs.deepinfo.com/guide/easm/technology-details.md): Open one technology to see which of your assets run it and in which version, its known vulnerabilities, and its end-of-life dates. - [Technology Insights](https://docs.deepinfo.com/guide/easm/technology-insights.md): See how many of your technologies are vulnerable or out of date, which categories dominate, and which technologies carry the most vulnerabilities. - [Cyber Threat Intelligence (CTI)](https://docs.deepinfo.com/guide/cti.md): Cyber Threat Intelligence (CTI) shows the employee, customer and payment card credentials found in leaked data for your organization, lets you record what you did about each one, and adds cyber security news and a dark web search. - [CTI Dashboard](https://docs.deepinfo.com/guide/cti/dashboard.md): Read the one-page Cyber Threat Intelligence summary of employee, client and payment card credentials found in leaked data, with exposure timelines, risk levels, credential states and the latest exposures. - [Compromised Employee Data Overview](https://docs.deepinfo.com/guide/cti/compromised-employee-data.md): The OVERVIEW tab of Compromised Employee Data sums up the employee accounts and credentials found in leaked data, with totals, credential states, top domains, an exposure timeline, risk levels and the latest exposures. - [Investigate Compromised Employees](https://docs.deepinfo.com/guide/cti/compromised-employees.md): Find the employees whose accounts appear in leaked credential data, see their risk level and password habits, review their exposed credentials, correct their details and export the list. - [Review Exposed Credentials](https://docs.deepinfo.com/guide/cti/credential-exposures.md): The EXPOSED CREDENTIALS tab lists every leaked login of your employees, with the site or app it belongs to, the masked password, its state and an analysis of the password. - [Change the State of Exposed Credentials](https://docs.deepinfo.com/guide/cti/change-credential-state.md): Record what you did about a leaked credential by ignoring it, accepting the risk, or marking it as resolved or as a false positive, one at a time or in bulk, and revert the change. - [Review Compromised Client Credentials](https://docs.deepinfo.com/guide/cti/compromised-client-credentials.md): See your customers' credentials for your services that were found in leaked data, with the login address, the state of each credential and an exposure timeline, and export them. - [Review Compromised Payment Credentials](https://docs.deepinfo.com/guide/cti/compromised-payment-credentials.md): See the payment card data related to your organization that was found in leaked data, with where it came from, how often it was seen and its state, and export it. - [Handle Leaked Data Safely](https://docs.deepinfo.com/guide/cti/sensitive-data.md): See what Cyber Threat Intelligence masks on screen, what showing a password does, which leaked data stays visible, and how to handle leaked credentials, exports and dark web results responsibly. - [Cyber Security News](https://docs.deepinfo.com/guide/cti/cybersecurity-news.md): Browse and filter curated cyber security news, read an article with the threat actors, targets, vendors, products and CVEs it mentions, and open the latest headlines from the top bar. - [Search the Dark Web](https://docs.deepinfo.com/guide/cti/dark-web-search.md): Search dark web sources such as forums, markets, paste sites and chat channels by text and filters, and open each result to read its details. - [Brand Risk Protection (BRP)](https://docs.deepinfo.com/guide/brp.md): Brand Risk Protection (BRP) finds domain names that imitate your brand, lets you confirm them as fraudulent or ignore them, and keeps the confirmed ones on their own list with a risk score. - [Review Suspicious Domains](https://docs.deepinfo.com/guide/brp/review-suspicious-domains.md): Check the lookalike domains your detection rules found, then mark each one as fraudulent or ignore it, one at a time or in bulk. - [Track Fraudulent Domains](https://docs.deepinfo.com/guide/brp/fraudulent-domains.md): Follow the domains you confirmed as fraudulent, with their risk score over time and a screenshot of the site, and remove a domain from the list. - [Restore Ignored Domains](https://docs.deepinfo.com/guide/brp/ignored-domains.md): Find the suspicious domains you ignored and send them back for review with UNDO IGNORE. - [Set Up Detection Rules](https://docs.deepinfo.com/guide/brp/detection-rules.md): Create the custom rules that find domains imitating your brand, turn them on or off, let a rule mark its matches as fraudulent automatically, and keep your own domains out. - [Deep Search & Insights (DSI)](https://docs.deepinfo.com/guide/dsi.md): Deep Search & Insights (DSI) gives you Deepinfo's internet-wide data inside the platform, with domain and vulnerability statistics, domain and CVE search, real-time lookups and downloadable data feeds. - [Domain Intelligence](https://docs.deepinfo.com/guide/dsi/domain-intelligence.md): Read global domain registration statistics, and rank TLDs and keywords in newly registered domain names over the period you choose. - [Search Domains](https://docs.deepinfo.com/guide/dsi/domain-search.md): Search Deepinfo's domain and subdomain data by name, WHOIS, DNS, SSL and website fields, sort and trim the results, and export them. - [Domain Details and Reverse Lookups](https://docs.deepinfo.com/guide/dsi/domain-details.md): Open one domain's full record from Domain Search, with WHOIS and DNS history, certificate, website and name data, its subdomains and related domains, and find other domains that share its details. - [Vulnerability Intelligence](https://docs.deepinfo.com/guide/dsi/vulnerability-intelligence.md): Read global CVE statistics, including recent CISA KEV additions, severity by year, the most common weaknesses (CWE), the CVSS distribution and the latest CVEs. - [Search Vulnerabilities](https://docs.deepinfo.com/guide/dsi/vulnerability-search.md): Search Deepinfo's CVE database by ID, product, weakness, CVSS metrics and exploitability, read a CVE with its CISA KEV entry, and export the results. - [Run Instant Lookups](https://docs.deepinfo.com/guide/dsi/instant-lookup.md): Run a real-time Whois, DNS, SSL, Webdata, Technology, Screenshot or Port Scanner lookup on one domain or IP address, read the parsed or raw result, and open its Whois or DNS history. - [Download Data Feeds](https://docs.deepinfo.com/guide/dsi/feeds.md): Download Deepinfo's daily and full domain and subdomain data files, see when each was last updated, and get sample data for feeds outside your package. - [Reports](https://docs.deepinfo.com/guide/reports.md): The Reports screen lists the PDF reports you can generate and the CSV or JSON exports you can download, grouped by module; Scheduled Reports sends PDF reports by e-mail on a schedule. - [Generate and Download a PDF Report](https://docs.deepinfo.com/guide/reports/generate-a-report.md): Generate a PDF report for your organization, one asset or one CVE, preview it in the browser, save it as PDF and reopen past reports. - [Schedule a Report](https://docs.deepinfo.com/guide/reports/schedule-a-report.md): Have the platform generate a PDF report daily, weekly or monthly and e-mail it to members of your organization. - [What Each Report Contains](https://docs.deepinfo.com/guide/reports/report-contents.md): See what each PDF report includes, from the EASM Executive Summary to the Vulnerability Detail Report, and what every report has in common. - [Export All Data as CSV or JSON](https://docs.deepinfo.com/guide/reports/export-data.md): Download your complete asset, issue, technology, vulnerability, compromised-credential, fraudulent-domain or suspicious-domain dataset as one CSV or JSON file. - [Notification Center](https://docs.deepinfo.com/guide/notifications.md): Notification rules e-mail the members you choose when something happens, such as a new asset, issue or vulnerability, a score change, a lookalike domain, a leaked credential or a security news item. - [Create a Notification Rule](https://docs.deepinfo.com/guide/notifications/create-a-rule.md): Create a rule that e-mails chosen members when an event happens, in four steps: event, rule settings, filters and review. - [Events and Filters Reference](https://docs.deepinfo.com/guide/notifications/events-and-filters.md): Look up every notification event, the name each one has in the rules list, and the filters each event offers with their values. - [Manage Notification Rules](https://docs.deepinfo.com/guide/notifications/manage-rules.md): Find your notification rules, activate or deactivate them one by one or in bulk, edit their name and recipients, duplicate them and remove them. - [Glossary](https://docs.deepinfo.com/guide/glossary.md): Look up the terms and UI labels used in the Deepinfo Platform and in this guide, and what each one means. ## API Reference - [API Reference](https://docs.deepinfo.com/reference.md): Every Deepinfo API endpoint, with parameters, responses and ready-to-run examples. ## Lookup - [Lookup Overview](https://docs.deepinfo.com/reference/lookup.md): Look up a single domain, host, IP address or website, either in real time or from Deepinfo's history. - [Domain WHOIS (GET /lookup/whois)](https://docs.deepinfo.com/reference/lookup/domain-whois.md): Returns the current WHOIS registration record of a domain: registrar, registrant, creation, update and expiry dates, name servers and status codes. - [Domain WHOIS Examples by TLD](https://docs.deepinfo.com/reference/lookup/domain-whois/examples.md): Worked examples, each on its own page with the request and its response - [DNS (GET /lookup/dns)](https://docs.deepinfo.com/reference/lookup/dns.md): GET /lookup/dns: Resolves the current DNS records of a domain or hostname in real time. Request up to five record types in one call. - [DNS Lookup Examples](https://docs.deepinfo.com/reference/lookup/dns/examples.md): Worked examples, each on its own page with the request and its response - [IP WHOIS (GET /lookup/ip-whois)](https://docs.deepinfo.com/reference/lookup/ip-whois.md): GET /lookup/ip-whois: Returns the current registration details of an IP address from the regional internet registries (RDAP/WHOIS): the owning network and its… - [IP WHOIS Examples](https://docs.deepinfo.com/reference/lookup/ip-whois/examples.md): Worked examples, each on its own page with the request and its response - [SSL (GET /lookup/ssl)](https://docs.deepinfo.com/reference/lookup/ssl.md): GET /lookup/ssl: Connects to a host in real time and returns the SSL/TLS certificate it serves: subject, issuer, validity, fingerprints, extensions (including… - [SSL Certificate Examples](https://docs.deepinfo.com/reference/lookup/ssl/examples.md): Worked examples, each on its own page with the request and its response - [Port Scan (POST /lookup/port-scan)](https://docs.deepinfo.com/reference/lookup/port-scan.md): POST /lookup/port-scan: Scans a host in real time and returns its open TCP/UDP ports and the services running on them. - [Technology (GET /lookup/technology)](https://docs.deepinfo.com/reference/lookup/technology.md): Loads a website in real time and detects the technologies it runs on: CMS, web frameworks, JavaScript libraries, CDN, analytics, chat widgets and more. - [Technology Lookup Examples](https://docs.deepinfo.com/reference/lookup/technology/examples.md): Worked examples, each on its own page with the request and its response - [Screenshot (GET /lookup/screenshot)](https://docs.deepinfo.com/reference/lookup/screenshot.md): GET /lookup/screenshot: Opens a web page in a real browser and returns a link to a screenshot of it. - [Screenshot Examples](https://docs.deepinfo.com/reference/lookup/screenshot/examples.md): Worked examples, each on its own page with the request and its response - [Screenshot (POST) (POST /lookup/screenshot)](https://docs.deepinfo.com/reference/lookup/screenshot-post.md): POST /lookup/screenshot: Same as Screenshot, with the options in a JSON body instead of the query string. - [Web Data (GET /lookup/webdata)](https://docs.deepinfo.com/reference/lookup/web-data.md): GET /lookup/webdata: Loads a web page in a real browser and returns everything Deepinfo extracts from it, in one call: detected technologies, page metadata… - [Web Data Examples](https://docs.deepinfo.com/reference/lookup/web-data/examples.md): Worked examples, each on its own page with the request and its response - [DNS History (GET /analyze/dns-history)](https://docs.deepinfo.com/reference/lookup/dns-history.md): Returns the historical DNS records Deepinfo has observed for a domain or FQDN, including values that have since changed or been removed (passive DNS). - [DNS History Examples](https://docs.deepinfo.com/reference/lookup/dns-history/examples.md): Worked examples, each on its own page with the request and its response - [WHOIS History (GET /analyze/whois-history)](https://docs.deepinfo.com/reference/lookup/whois-history.md): Returns the historical WHOIS records of a domain: every distinct registration record Deepinfo has observed, with the dates it was seen. - [WHOIS History Examples](https://docs.deepinfo.com/reference/lookup/whois-history/examples.md): Worked examples, each on its own page with the request and its response ## Discovery - [Discovery Overview](https://docs.deepinfo.com/reference/discovery.md): Search Deepinfo's internet-wide domain dataset: find subdomains, associated domains, domains registered at the same time, and domains that share a WHOIS… - [Domain Search (POST /discovery/domain-search)](https://docs.deepinfo.com/reference/discovery/domain-search.md): POST /discovery/domain-search: Searches Deepinfo's whole domain dataset with filters on WHOIS, DNS, SSL, web data and more. - [Domain Search Examples](https://docs.deepinfo.com/reference/discovery/domain-search/examples.md): Worked examples, each on its own page with the request and its response - [Domain Detail (GET /discovery/domain-detail)](https://docs.deepinfo.com/reference/discovery/domain-detail.md): GET /discovery/domain-detail: Returns everything Deepinfo has on one domain: WHOIS, DNS, SSL, web data and more. - [Domain Detail Examples](https://docs.deepinfo.com/reference/discovery/domain-detail/examples.md): Worked examples, each on its own page with the request and its response - [All TLDs (GET /discovery/all-tlds)](https://docs.deepinfo.com/reference/discovery/all-tlds.md): GET /discovery/all-tlds: Finds the same name registered under other TLDs (e.g. deepinfo.net, deepinfo.io). - [All TLDs Examples](https://docs.deepinfo.com/reference/discovery/all-tlds/examples.md): Worked examples, each on its own page with the request and its response - [Associated Domain Finder (GET /discovery/associated-domain-finder)](https://docs.deepinfo.com/reference/discovery/associated-domain-finder.md): Finds domains associated with a domain: same registrant email, organization or phone, same name servers, IP, mail servers or SSL organization. - [Associated Domain Finder Examples](https://docs.deepinfo.com/reference/discovery/associated-domain-finder/examples.md): Worked examples, each on its own page with the request and its response - [Reverse IP (GET /discovery/reverse-ip)](https://docs.deepinfo.com/reference/discovery/reverse-ip.md): GET /discovery/reverse-ip: Finds domains that resolve to ip, or to its network when mask is 8, 16 or 24. - [Reverse IP Examples](https://docs.deepinfo.com/reference/discovery/reverse-ip/examples.md): Worked examples, each on its own page with the request and its response - [Reverse MX (GET /discovery/reverse-mx)](https://docs.deepinfo.com/reference/discovery/reverse-mx.md): GET /discovery/reverse-mx: Finds domains that use the mail server mx. - [Reverse MX Examples](https://docs.deepinfo.com/reference/discovery/reverse-mx/examples.md): Worked examples, each on its own page with the request and its response - [Reverse NS (GET /discovery/reverse-ns)](https://docs.deepinfo.com/reference/discovery/reverse-ns.md): GET /discovery/reverse-ns: Finds domains that use the name server ns. - [Reverse NS Examples](https://docs.deepinfo.com/reference/discovery/reverse-ns/examples.md): Worked examples, each on its own page with the request and its response - [Reverse WHOIS Email (GET /discovery/reverse-email)](https://docs.deepinfo.com/reference/discovery/reverse-whois-email.md): GET /discovery/reverse-email: Finds domains whose WHOIS registrant email is email. apex=true matches the whole email domain. - [Reverse WHOIS Email Examples](https://docs.deepinfo.com/reference/discovery/reverse-whois-email/examples.md): Worked examples, each on its own page with the request and its response - [Same-Time Registered Domain Finder (GET /discovery/sametime-domain-finder)](https://docs.deepinfo.com/reference/discovery/same-time-registered-domain-finder.md): GET /discovery/sametime-domain-finder: Finds domains registered by the same registrant within interval minutes (1–60, default 5) of the given domain. - [Same-Time Registered Domain Finder Examples](https://docs.deepinfo.com/reference/discovery/same-time-registered-domain-finder/examples.md): Worked examples, each on its own page with the request and its response - [Subdomain Finder (GET /discovery/subdomain-finder)](https://docs.deepinfo.com/reference/discovery/subdomain-finder.md): GET /discovery/subdomain-finder: Finds all known subdomains of a domain. - [Subdomain Finder Examples](https://docs.deepinfo.com/reference/discovery/subdomain-finder/examples.md): Worked examples, each on its own page with the request and its response ## Darkweb - [Darkweb Overview](https://docs.deepinfo.com/reference/darkweb.md): Search dark web sources (forums, markets, paste sites, chats, leaks). Results are paged 25 per page, up to page 250. - [Search (POST /discovery/darkweb-search)](https://docs.deepinfo.com/reference/darkweb/search.md): POST /discovery/darkweb-search: Searches dark web content by free text, by indicators and by sources. At least one of them is required. ## Vulnerability - [Vulnerability Overview](https://docs.deepinfo.com/reference/vulnerability.md): Deepinfo's vulnerability (CVE) database: search, CVE details, EPSS history and global statistics. - [Search (POST /discovery/vulnerability-search)](https://docs.deepinfo.com/reference/vulnerability/search.md): POST /discovery/vulnerability-search: Searches Deepinfo's CVE database with filters. - [Vulnerability Search Examples](https://docs.deepinfo.com/reference/vulnerability/search/examples.md): Worked examples, each on its own page with the request and its response - [Detail (GET /discovery/vulnerability-detail)](https://docs.deepinfo.com/reference/vulnerability/detail.md): GET /discovery/vulnerability-detail: Returns full details of a CVE: description, CVSS, CWE, EPSS, KEV status, affected products (CPE) and references. - [Vulnerability Detail Examples](https://docs.deepinfo.com/reference/vulnerability/detail/examples.md): Worked examples, each on its own page with the request and its response - [EPSS History (GET /explore/vulnerability-insight/epss-history/{cve})](https://docs.deepinfo.com/reference/vulnerability/epss-history.md): GET /explore/vulnerability-insight/epss-history/{cve}: Returns the EPSS (exploit prediction) score history of a CVE. - [EPSS History Examples](https://docs.deepinfo.com/reference/vulnerability/epss-history/examples.md): Worked examples, each on its own page with the request and its response - [Finder (GET /discovery/vulnerability-finder)](https://docs.deepinfo.com/reference/vulnerability/finder.md): GET /discovery/vulnerability-finder: Finds vulnerabilities that affect the technologies detected on a url. - [Latest Added (GET /explore/vulnerability-insight/latest-added-vulnerabilities-list)](https://docs.deepinfo.com/reference/vulnerability/latest-added.md): GET /explore/vulnerability-insight/latest-added-vulnerabilities-list: Lists the latest added CVEs. - [Latest Added Vulnerabilities Examples](https://docs.deepinfo.com/reference/vulnerability/latest-added/examples.md): Worked examples, each on its own page with the request and its response - [CISA KEV Stats (GET /explore/vulnerability-insight/cisa-kev-stats)](https://docs.deepinfo.com/reference/vulnerability/cisa-kev-stats.md): GET /explore/vulnerability-insight/cisa-kev-stats: Statistics on the CISA Known Exploited Vulnerabilities catalog. - [CISA KEV Stats Examples](https://docs.deepinfo.com/reference/vulnerability/cisa-kev-stats/examples.md): Worked examples, each on its own page with the request and its response - [CVE Stats (GET /explore/vulnerability-insight/cve-stats)](https://docs.deepinfo.com/reference/vulnerability/cve-stats.md): GET /explore/vulnerability-insight/cve-stats: Number of CVEs published in the last 1, 7, 30 and 365 days. - [CVE Stats Examples](https://docs.deepinfo.com/reference/vulnerability/cve-stats/examples.md): Worked examples, each on its own page with the request and its response - [CVSS Score Stats (GET /explore/vulnerability-insight/vulnerability-stats-by-cvss-scores)](https://docs.deepinfo.com/reference/vulnerability/cvss-score-stats.md): GET /explore/vulnerability-insight/vulnerability-stats-by-cvss-scores: Distribution of CVEs by CVSS score. - [CVSS Score Stats Examples](https://docs.deepinfo.com/reference/vulnerability/cvss-score-stats/examples.md): Worked examples, each on its own page with the request and its response - [CWE Timeline (GET /explore/vulnerability-insight/cwe-timeline)](https://docs.deepinfo.com/reference/vulnerability/cwe-timeline.md): GET /explore/vulnerability-insight/cwe-timeline: Time series of CVEs per CWE (weakness type). - [CWE Timeline Examples](https://docs.deepinfo.com/reference/vulnerability/cwe-timeline/examples.md): Worked examples, each on its own page with the request and its response - [Severity by Year Stats (GET /explore/vulnerability-insight/vulnerability-severity-stats-by-year)](https://docs.deepinfo.com/reference/vulnerability/severity-by-year-stats.md): GET /explore/vulnerability-insight/vulnerability-severity-stats-by-year: CVE counts per severity and year. - [Severity by Year Stats Examples](https://docs.deepinfo.com/reference/vulnerability/severity-by-year-stats/examples.md): Worked examples, each on its own page with the request and its response ## Domain Intelligence - [Domain Intelligence Overview](https://docs.deepinfo.com/reference/domain-intelligence.md): Global domain registration statistics. - [Keyword Stats (GET /explorer/domain-intelligence/keyword-stats)](https://docs.deepinfo.com/reference/domain-intelligence/keyword-stats.md): GET /explorer/domain-intelligence/keyword-stats: Top keywords in newly registered domain names. Same parameters as TLD Stats. Can take several seconds. - [Keyword Stats Examples](https://docs.deepinfo.com/reference/domain-intelligence/keyword-stats/examples.md): Worked examples, each on its own page with the request and its response - [Registration Stats (GET /explorer/domain-intelligence/registration-stats)](https://docs.deepinfo.com/reference/domain-intelligence/registration-stats.md): GET /explorer/domain-intelligence/registration-stats: Number of domains registered in the last 1, 7, 30 and 365 days. - [Registration Stats Examples](https://docs.deepinfo.com/reference/domain-intelligence/registration-stats/examples.md): Worked examples, each on its own page with the request and its response - [Registration Timeline (GET /explorer/domain-intelligence/registration-timeline)](https://docs.deepinfo.com/reference/domain-intelligence/registration-timeline.md): GET /explorer/domain-intelligence/registration-timeline: Daily registration counts for the last interval days (1–30). - [Registration Timeline Examples](https://docs.deepinfo.com/reference/domain-intelligence/registration-timeline/examples.md): Worked examples, each on its own page with the request and its response - [TLD Stats (GET /explorer/domain-intelligence/tld-stats)](https://docs.deepinfo.com/reference/domain-intelligence/tld-stats.md): GET /explorer/domain-intelligence/tld-stats: Top TLDs by registrations. interval (days: 1, 7, 30, 365), size (10–10000). - [TLD Stats Examples](https://docs.deepinfo.com/reference/domain-intelligence/tld-stats/examples.md): Worked examples, each on its own page with the request and its response ## Feeds - [Feeds Overview](https://docs.deepinfo.com/reference/feeds.md): Download Deepinfo data feeds (all domains/subdomains, daily registered/updated/deleted domains, daily discovered subdomains). - [List (GET /feeds/latest)](https://docs.deepinfo.com/reference/feeds/list.md): GET /feeds/latest: Lists every feed with its files (format, size, line count, update time) and the API URL to get each. - [Feed List Examples](https://docs.deepinfo.com/reference/feeds/list/examples.md): Worked examples, each on its own page with the request and its response - [All Domains (GET /feeds/all-domains)](https://docs.deepinfo.com/reference/feeds/all-domains.md): GET /feeds/all-domains: All registered domains Deepinfo knows about. - [All Domains Feed Examples](https://docs.deepinfo.com/reference/feeds/all-domains/examples.md): Worked examples, each on its own page with the request and its response - [All Subdomains (GET /feeds/all-subdomains)](https://docs.deepinfo.com/reference/feeds/all-subdomains.md): GET /feeds/all-subdomains: All subdomains Deepinfo knows about. - [All Subdomains Feed Examples](https://docs.deepinfo.com/reference/feeds/all-subdomains/examples.md): Worked examples, each on its own page with the request and its response - [Daily Deleted Domains (GET /feeds/daily-deleted-domains)](https://docs.deepinfo.com/reference/feeds/daily-deleted-domains.md): GET /feeds/daily-deleted-domains: Domains deleted in the last day. - [Daily Deleted Domains Feed Examples](https://docs.deepinfo.com/reference/feeds/daily-deleted-domains/examples.md): Worked examples, each on its own page with the request and its response - [Daily Discovered Subdomains (GET /feeds/daily-discovered-subdomains)](https://docs.deepinfo.com/reference/feeds/daily-discovered-subdomains.md): GET /feeds/daily-discovered-subdomains: Subdomains discovered in the last day. - [Daily Discovered Subdomains Feed Examples](https://docs.deepinfo.com/reference/feeds/daily-discovered-subdomains/examples.md): Worked examples, each on its own page with the request and its response - [Daily Registered Domains (GET /feeds/daily-registered-domains)](https://docs.deepinfo.com/reference/feeds/daily-registered-domains.md): GET /feeds/daily-registered-domains: Domains registered in the last day. - [Daily Registered Domains Feed Examples](https://docs.deepinfo.com/reference/feeds/daily-registered-domains/examples.md): Worked examples, each on its own page with the request and its response - [Daily Updated Domains (GET /feeds/daily-updated-domains)](https://docs.deepinfo.com/reference/feeds/daily-updated-domains.md): GET /feeds/daily-updated-domains: Domains whose registration was updated in the last day. - [Daily Updated Domains Feed Examples](https://docs.deepinfo.com/reference/feeds/daily-updated-domains/examples.md): Worked examples, each on its own page with the request and its response ## EASM - [EASM Overview](https://docs.deepinfo.com/reference/easm.md): External Attack Surface Management: your monitored assets (domains, subdomains, IPs, websites), what Deepinfo discovers around them, and the issues… - [Asset Search (POST /easm/assets/search)](https://docs.deepinfo.com/reference/easm/asset-search.md): POST /easm/assets/search: Searches your monitored assets with filters and sorting. An empty body {} returns all assets. - [Asset Export (POST /easm/assets/search:export)](https://docs.deepinfo.com/reference/easm/asset-export.md): POST /easm/assets/search:export: Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. - [Asset Detail (GET /easm/assets/{asset_id})](https://docs.deepinfo.com/reference/easm/asset-detail.md): GET /easm/assets/{asset_id}: Returns everything Deepinfo knows about one asset: latest WHOIS, DNS, SSL, HTTP and web data, open ports, technologies, issue and… - [Asset Create (POST /easm/assets)](https://docs.deepinfo.com/reference/easm/asset-create.md): POST /easm/assets: Adds assets to monitoring. Send up to 1,000 domains, subdomains, IPs or website URLs in assets. - [Asset Delete (POST /easm/assets/search:delete)](https://docs.deepinfo.com/reference/easm/asset-delete.md): POST /easm/assets/search:delete: Removes every asset matching filters from monitoring. Deleted assets are listed under Deleted Assets. - [Asset Enable Discovery (POST /easm/assets/search:enable-discovery)](https://docs.deepinfo.com/reference/easm/asset-enable-discovery.md): POST /easm/assets/search:enable-discovery: Enables (enabled=true) or disables discovery for every asset matching filters. - [Asset Instant Scan (POST /easm/assets/{asset_id}/instant-scan)](https://docs.deepinfo.com/reference/easm/asset-instant-scan.md): POST /easm/assets/{asset_id}/instant-scan: Starts an on-demand scan of an asset. Track it with Asset Instant Scan Status. - [Asset Set Tag (POST /easm/assets/search:set-tag)](https://docs.deepinfo.com/reference/easm/asset-set-tag.md): POST /easm/assets/search:set-tag: Adds tags (1–10) to every asset matching filters. - [Asset Set Weight (POST /easm/assets/search:set-weight)](https://docs.deepinfo.com/reference/easm/asset-set-weight.md): POST /easm/assets/search:set-weight: Sets a business-importance weight (0–1000) on every asset matching filters. Weights influence prioritization and scores. - [Asset Instant Scan Status (GET /easm/assets/{asset_id}/instant-scan-status)](https://docs.deepinfo.com/reference/easm/asset-instant-scan-status.md): GET /easm/assets/{asset_id}/instant-scan-status: Returns the state of the latest on-demand scan: pending, queued, monitoring, failed, issue_queued or finished. - [Asset Update (PUT /easm/assets/{asset_id})](https://docs.deepinfo.com/reference/easm/asset-update.md): PUT /easm/assets/{asset_id}: Updates an asset's settings: discovery_enabled (use the asset as a discovery seed) and is_main_asset. - [Asset Remove Tag (DELETE /easm/assets/{asset_id}/tags/{tag_id})](https://docs.deepinfo.com/reference/easm/asset-remove-tag.md): DELETE /easm/assets/{asset_id}/tags/{tag_id}: Removes one tag from one asset. tag_id is the tag name. - [Asset Tag List (GET /easm/asset-tags)](https://docs.deepinfo.com/reference/easm/asset-tag-list.md): GET /easm/asset-tags: Lists the tags used on your assets (tag names). - [Asset Tag Update (PUT /easm/asset-tags/{tag_id})](https://docs.deepinfo.com/reference/easm/asset-tag-update.md): PUT /easm/asset-tags/{tag_id}: Renames a tag on every asset that has it. tag_id is the current tag name; tag (3–100 characters) is the new name. - [Asset Tag Delete (DELETE /easm/asset-tags/{tag_id})](https://docs.deepinfo.com/reference/easm/asset-tag-delete.md): DELETE /easm/asset-tags/{tag_id}: Deletes a tag and removes it from all assets. tag_id is the tag name. - [Deleted Asset Search (POST /easm/deleted-assets/search)](https://docs.deepinfo.com/reference/easm/deleted-asset-search.md): POST /easm/deleted-assets/search: Searches assets that were removed from monitoring, with their deleted_date. - [Deleted Asset Export (POST /easm/deleted-assets/search:export)](https://docs.deepinfo.com/reference/easm/deleted-asset-export.md): POST /easm/deleted-assets/search:export: Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. - [Asset DNS History List (GET /easm/assets/{asset_id}/dns-history)](https://docs.deepinfo.com/reference/easm/asset-dns-history-list.md): GET /easm/assets/{asset_id}/dns-history: Lists the DNS snapshots recorded for an asset (newest first): id and check_date of each. - [Asset HTTP History List (GET /easm/assets/{asset_id}/http-history)](https://docs.deepinfo.com/reference/easm/asset-http-history-list.md): GET /easm/assets/{asset_id}/http-history: Lists the HTTP snapshots recorded for an asset (newest first): id and check_date of each. - [Asset IP DNS PTR History List (GET /easm/assets/{asset_id}/ipdns-history)](https://docs.deepinfo.com/reference/easm/asset-ip-dns-ptr-history-list.md): GET /easm/assets/{asset_id}/ipdns-history: Lists the IP DNS (PTR) snapshots recorded for an asset (newest first): id and check_date of each. - [Asset IP Whois History List (GET /easm/assets/{asset_id}/ipwhois-history)](https://docs.deepinfo.com/reference/easm/asset-ip-whois-history-list.md): GET /easm/assets/{asset_id}/ipwhois-history: Lists the IP WHOIS snapshots recorded for an asset (newest first): id and check_date of each. - [Asset Port Scan History List (GET /easm/assets/{asset_id}/port-scan-history)](https://docs.deepinfo.com/reference/easm/asset-port-scan-history-list.md): GET /easm/assets/{asset_id}/port-scan-history: Lists the port scan snapshots recorded for an asset (newest first): id and check_date of each. - [Asset SSL History List (GET /easm/assets/{asset_id}/ssl-history)](https://docs.deepinfo.com/reference/easm/asset-ssl-history-list.md): GET /easm/assets/{asset_id}/ssl-history: Lists the SSL certificate snapshots recorded for an asset (newest first): id and check_date of each. - [Asset Webdata History List (GET /easm/assets/{asset_id}/webdata-history)](https://docs.deepinfo.com/reference/easm/asset-webdata-history-list.md): Lists the web data (page content, technologies, headers) snapshots recorded for an asset (newest first): id and check_date of each. - [Asset Whois History List (GET /easm/assets/{asset_id}/whois-history)](https://docs.deepinfo.com/reference/easm/asset-whois-history-list.md): GET /easm/assets/{asset_id}/whois-history: Lists the WHOIS snapshots recorded for an asset (newest first): id and check_date of each. - [Asset DNS History Detail (GET /easm/assets/{asset_id}/dns-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-dns-history-detail.md): GET /easm/assets/{asset_id}/dns-history/{history_id}: Returns one DNS snapshot of an asset, by the history_id returned by the list endpoint. - [Asset HTTP History Detail (GET /easm/assets/{asset_id}/http-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-http-history-detail.md): GET /easm/assets/{asset_id}/http-history/{history_id}: Returns one HTTP snapshot of an asset, by the history_id returned by the list endpoint. - [Asset IP DNS PTR History Detail (GET /easm/assets/{asset_id}/ipdns-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-ip-dns-ptr-history-detail.md): GET /easm/assets/{asset_id}/ipdns-history/{history_id}: Returns one IP DNS (PTR) snapshot of an asset, by the history_id returned by the list endpoint. - [Asset IP Whois History Detail (GET /easm/assets/{asset_id}/ipwhois-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-ip-whois-history-detail.md): GET /easm/assets/{asset_id}/ipwhois-history/{history_id}: Returns one IP WHOIS snapshot of an asset, by the history_id returned by the list endpoint. - [Asset Port Scan History Detail (GET /easm/assets/{asset_id}/port-scan-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-port-scan-history-detail.md): GET /easm/assets/{asset_id}/port-scan-history/{history_id}: Returns one port scan snapshot of an asset, by the history_id returned by the list endpoint. - [Asset SSL History Detail (GET /easm/assets/{asset_id}/ssl-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-ssl-history-detail.md): GET /easm/assets/{asset_id}/ssl-history/{history_id}: Returns one SSL certificate snapshot of an asset, by the history_id returned by the list endpoint. - [Asset Webdata History Detail (GET /easm/assets/{asset_id}/webdata-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-webdata-history-detail.md): Returns one web data (page content, technologies, headers) snapshot of an asset, by the history_id returned by the list endpoint. - [Asset Whois History Detail (GET /easm/assets/{asset_id}/whois-history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-whois-history-detail.md): GET /easm/assets/{asset_id}/whois-history/{history_id}: Returns one WHOIS snapshot of an asset, by the history_id returned by the list endpoint. - [Asset Open Port History List (GET /easm/assets/{asset_id}/open-ports/history)](https://docs.deepinfo.com/reference/easm/asset-open-port-history-list.md): GET /easm/assets/{asset_id}/open-ports/history: Lists the port scan snapshots of an asset: id and check_date. - [Asset Open Port List (GET /easm/assets/{asset_id}/open-ports)](https://docs.deepinfo.com/reference/easm/asset-open-port-list.md): GET /easm/assets/{asset_id}/open-ports: Lists the ports found on an asset, with the state and protocol of each. - [Asset Open Port History Detail (GET /easm/assets/{asset_id}/open-ports/history/{history_id})](https://docs.deepinfo.com/reference/easm/asset-open-port-history-detail.md): GET /easm/assets/{asset_id}/open-ports/history/{history_id}: Returns the ports of one historical port scan. Same filters as Asset Open Port List. - [Asset Instant Open Port Scan (POST /easm/assets/{asset_id}/open-ports/instant-scan)](https://docs.deepinfo.com/reference/easm/asset-instant-open-port-scan.md): Runs a port scan of the asset right away and returns the result in the response (status is host_down if the host did not respond). - [Asset Open Port Count Timeline (GET /easm/assets/{asset_id}/open-ports/count-timeline)](https://docs.deepinfo.com/reference/easm/asset-open-port-count-timeline.md): GET /easm/assets/{asset_id}/open-ports/count-timeline: Time series of the number of open ports on an asset. - [Asset Open Port State Stats (GET /easm/assets/{asset_id}/stats/open-port-state)](https://docs.deepinfo.com/reference/easm/asset-open-port-state-stats.md): GET /easm/assets/{asset_id}/stats/open-port-state: Counts the asset's ports per state (open, closed, filtered, unfiltered, open_filtered, closed_filtered). - [Asset Issue Severity Stats Timeline (GET /easm/assets/{asset_id}/stats/issue-severity-timeline)](https://docs.deepinfo.com/reference/easm/asset-issue-severity-stats-timeline.md): GET /easm/assets/{asset_id}/stats/issue-severity-timeline: Time series of issue severity for the selected interval (daily, weekly, monthly). - [Asset Security Score Timeline (GET /easm/assets/{asset_id}/stats/security-score-timeline)](https://docs.deepinfo.com/reference/easm/asset-security-score-timeline.md): GET /easm/assets/{asset_id}/stats/security-score-timeline: Time series of security score for the selected interval (daily, weekly, monthly). - [Asset Technology Count Timeline (GET /easm/assets/{asset_id}/stats/technology-count-timeline)](https://docs.deepinfo.com/reference/easm/asset-technology-count-timeline.md): GET /easm/assets/{asset_id}/stats/technology-count-timeline: Time series of technology count for the selected interval (daily, weekly, monthly). - [Asset Vulnerability Severity Stats Timeline (GET /easm/assets/{asset_id}/stats/vulnerability-severity-timeline)](https://docs.deepinfo.com/reference/easm/asset-vulnerability-severity-stats-timeline.md): GET /easm/assets/{asset_id}/stats/vulnerability-severity-timeline: Time series of vulnerability severity for the selected interval (daily, weekly, monthly). - [Asset Website Count Timeline (GET /easm/assets/{asset_id}/stats/website-count-timeline)](https://docs.deepinfo.com/reference/easm/asset-website-count-timeline.md): GET /easm/assets/{asset_id}/stats/website-count-timeline: Time series of website count for the selected interval (daily, weekly, monthly). - [Domain Security Score Timeline (GET /easm/assets/{asset_id}/stats/domain-security-score-timeline)](https://docs.deepinfo.com/reference/easm/domain-security-score-timeline.md): GET /easm/assets/{asset_id}/stats/domain-security-score-timeline: Time series of domain security score for the selected interval (daily, weekly, monthly). - [Domain Subdomain Count Timeline (GET /easm/assets/{asset_id}/stats/subdomain-count-timeline)](https://docs.deepinfo.com/reference/easm/domain-subdomain-count-timeline.md): GET /easm/assets/{asset_id}/stats/subdomain-count-timeline: Time series of subdomain count for the selected interval (daily, weekly, monthly). - [Asset Instant Snapshot (POST /easm/assets/{asset_id}/instant-snapshot)](https://docs.deepinfo.com/reference/easm/asset-instant-snapshot.md): POST /easm/assets/{asset_id}/instant-snapshot: Recalculates the asset snapshot now. - [Asset Latest Snapshot (GET /easm/assets/{asset_id}/latest-snapshot)](https://docs.deepinfo.com/reference/easm/asset-latest-snapshot.md): GET /easm/assets/{asset_id}/latest-snapshot: Returns the latest pre-computed summary of an asset (security score and statistics) in snapshot. - [Domain Instant Snapshot (POST /easm/assets/{domain_id}/domain-instant-snapshot)](https://docs.deepinfo.com/reference/easm/domain-instant-snapshot.md): POST /easm/assets/{domain_id}/domain-instant-snapshot: Recalculates the domain snapshot now. - [Domain Latest Snapshot (GET /easm/assets/{domain_id}/domain-latest-snapshot)](https://docs.deepinfo.com/reference/easm/domain-latest-snapshot.md): GET /easm/assets/{domain_id}/domain-latest-snapshot: Returns the latest summary of a domain including all its subdomains and websites. - [Instant Snapshot (POST /easm/instant-snapshot)](https://docs.deepinfo.com/reference/easm/instant-snapshot.md): POST /easm/instant-snapshot: Recalculates the attack-surface snapshot now. - [Latest Snapshot (GET /easm/latest-snapshot)](https://docs.deepinfo.com/reference/easm/latest-snapshot.md): GET /easm/latest-snapshot: Returns the latest summary of your whole attack surface. - [Assets With Most Issues (GET /easm/assets/stats/most-issues)](https://docs.deepinfo.com/reference/easm/assets-with-most-issues.md): GET /easm/assets/stats/most-issues: Lists your assets with the most active issues. - [Assets With Most Websites (GET /easm/assets/stats/most-websites)](https://docs.deepinfo.com/reference/easm/assets-with-most-websites.md): GET /easm/assets/stats/most-websites: Lists your assets with the most websites. - [Domains With Most Subdomains (GET /easm/assets/stats/most-subdomains)](https://docs.deepinfo.com/reference/easm/domains-with-most-subdomains.md): GET /easm/assets/stats/most-subdomains: Lists your domains with the most subdomains. - [Latest Added Assets (GET /easm/assets/stats/latest)](https://docs.deepinfo.com/reference/easm/latest-added-assets.md): GET /easm/assets/stats/latest: Lists the most recently added assets. - [Asset Type Stats (GET /easm/assets/stats/type)](https://docs.deepinfo.com/reference/easm/asset-type-stats.md): GET /easm/assets/stats/type: Counts your assets per type (domain, subdomain, ip, website). - [Asset Type Stats Timeline (GET /easm/assets/stats/type-timeline)](https://docs.deepinfo.com/reference/easm/asset-type-stats-timeline.md): GET /easm/assets/stats/type-timeline: Time series of your asset counts per type. - [Insight Stats (GET /easm/assets/stats/insights)](https://docs.deepinfo.com/reference/easm/insight-stats.md): GET /easm/assets/stats/insights: Groups assets of an asset_type by an attribute (insight_by: registrar, expiry date, registrant organization, IP, name server… - [Open Port Count Timeline (GET /easm/stats/open-port-count-timeline)](https://docs.deepinfo.com/reference/easm/open-port-count-timeline.md): GET /easm/stats/open-port-count-timeline: Time series of open ports across all your assets. - [Security Score Timeline (GET /easm/stats/security-score-timeline)](https://docs.deepinfo.com/reference/easm/security-score-timeline.md): GET /easm/stats/security-score-timeline: Time series of your overall security score. - [Discovered Asset Search (POST /easm/discovery/assets/search)](https://docs.deepinfo.com/reference/easm/discovered-asset-search.md): POST /easm/discovery/assets/search: Searches discovered assets (candidates found by discovery rules) and their state. - [Discovered Asset Export (POST /easm/discovery/assets/search:export)](https://docs.deepinfo.com/reference/easm/discovered-asset-export.md): POST /easm/discovery/assets/search:export: Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. - [Discovered Asset Detail (GET /easm/discovery/assets/{asset_id})](https://docs.deepinfo.com/reference/easm/discovered-asset-detail.md): GET /easm/discovery/assets/{asset_id}: Returns one discovered asset with the rules and seeds that discovered it. - [Discovered Asset Approve (POST /easm/discovery/assets/search:approve)](https://docs.deepinfo.com/reference/easm/discovered-asset-approve.md): POST /easm/discovery/assets/search:approve: Approves the discovered assets that match filters (approved). Approved assets are added to your monitored assets. - [Discovered Asset Ignore (POST /easm/discovery/assets/search:ignore)](https://docs.deepinfo.com/reference/easm/discovered-asset-ignore.md): POST /easm/discovery/assets/search:ignore: Ignores the discovered assets that match filters (ignored). - [Discovered Asset Revert (POST /easm/discovery/assets/search:revert)](https://docs.deepinfo.com/reference/easm/discovered-asset-revert.md): POST /easm/discovery/assets/search:revert: Reverts the discovered assets that match filters to their previous, active state. - [Discovered Asset State Stats (GET /easm/discovery/stats/asset-state)](https://docs.deepinfo.com/reference/easm/discovered-asset-state-stats.md): GET /easm/discovery/stats/asset-state: Counts discovered assets per state, overall and per rule type. - [Asset Discovery Custom Discovery Rule Search (POST /easm/discovery/custom-rules/search)](https://docs.deepinfo.com/reference/easm/asset-discovery-custom-discovery-rule-search.md): POST /easm/discovery/custom-rules/search: Lists your custom discovery rules. - [Asset Discovery Rule List (GET /easm/discovery/rules)](https://docs.deepinfo.com/reference/easm/asset-discovery-rule-list.md): GET /easm/discovery/rules: Lists all discovery rules (smart discovery, smart monitoring and custom) with their counts. - [Asset Discovery Smart Discovery Rule List (GET /easm/discovery/smart-discovery-rules)](https://docs.deepinfo.com/reference/easm/asset-discovery-smart-discovery-rule-list.md): GET /easm/discovery/smart-discovery-rules: Lists the smart discovery rules Deepinfo runs for you. - [Asset Discovery Smart Monitoring Rule List (GET /easm/discovery/smart-monitoring-rules)](https://docs.deepinfo.com/reference/easm/asset-discovery-smart-monitoring-rule-list.md): GET /easm/discovery/smart-monitoring-rules: Lists the smart monitoring rules Deepinfo runs for you. - [Asset Discovery Custom Discovery Rule Detail (GET /easm/discovery/custom-rules/{rule_id})](https://docs.deepinfo.com/reference/easm/asset-discovery-custom-discovery-rule-detail.md): GET /easm/discovery/custom-rules/{rule_id}: Returns one custom discovery rule. - [Asset Discovery Smart Discovery Rule Detail (GET /easm/discovery/smart-discovery-rules/{rule_id})](https://docs.deepinfo.com/reference/easm/asset-discovery-smart-discovery-rule-detail.md): GET /easm/discovery/smart-discovery-rules/{rule_id}: Returns one smart discovery rule. - [Asset Discovery Smart Monitoring Rule Detail (GET /easm/discovery/smart-monitoring-rules/{rule_id})](https://docs.deepinfo.com/reference/easm/asset-discovery-smart-monitoring-rule-detail.md): GET /easm/discovery/smart-monitoring-rules/{rule_id}: Returns one smart monitoring rule. - [Asset Discovery Custom Discovery Rule Create (POST /easm/discovery/custom-rules)](https://docs.deepinfo.com/reference/easm/asset-discovery-custom-discovery-rule-create.md): POST /easm/discovery/custom-rules: Creates a custom discovery rule. - [Asset Discovery Custom Discovery Rule Update (PUT /easm/discovery/custom-rules/{rule_id})](https://docs.deepinfo.com/reference/easm/asset-discovery-custom-discovery-rule-update.md): PUT /easm/discovery/custom-rules/{rule_id}: Updates a custom discovery rule (send all fields). - [Asset Discovery Smart Discovery Rule Update (PUT /easm/discovery/smart-discovery-rules/{rule_id})](https://docs.deepinfo.com/reference/easm/asset-discovery-smart-discovery-rule-update.md): PUT /easm/discovery/smart-discovery-rules/{rule_id}: Tunes a smart discovery rule with the settings in the request body. - [Asset Discovery Smart Monitoring Rule Update (PUT /easm/discovery/smart-monitoring-rules/{rule_id})](https://docs.deepinfo.com/reference/easm/asset-discovery-smart-monitoring-rule-update.md): PUT /easm/discovery/smart-monitoring-rules/{rule_id}: Tunes a smart monitoring rule with the settings in the request body. - [Asset Discovery Custom Discovery Rule Delete (DELETE /easm/discovery/custom-rules/{rule_id})](https://docs.deepinfo.com/reference/easm/asset-discovery-custom-discovery-rule-delete.md): DELETE /easm/discovery/custom-rules/{rule_id}: Deletes a custom discovery rule. - [Asset Discovery Settings Detail (GET /easm/discovery/settings)](https://docs.deepinfo.com/reference/easm/asset-discovery-settings-detail.md): GET /easm/discovery/settings: Returns discovery settings: ignored_assets are never proposed as candidates. - [Asset Discovery Settings Update (PUT /easm/discovery/settings)](https://docs.deepinfo.com/reference/easm/asset-discovery-settings-update.md): PUT /easm/discovery/settings: Replaces discovery settings. Send the full ignored_assets list. - [Issue Search (POST /easm/issues/search)](https://docs.deepinfo.com/reference/easm/issue-search.md): POST /easm/issues/search: Searches issues on your assets by state, severity, type, category, asset and dates. - [Issue Export (POST /easm/issues/search:export)](https://docs.deepinfo.com/reference/easm/issue-export.md): POST /easm/issues/search:export: Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. - [Issue Detail (GET /easm/issues/{issue_id})](https://docs.deepinfo.com/reference/easm/issue-detail.md): GET /easm/issues/{issue_id}: Returns one issue with its asset, type, state history and evidence. - [Issue Accept Risk (POST /easm/issues/search:accept-risk)](https://docs.deepinfo.com/reference/easm/issue-accept-risk.md): POST /easm/issues/search:accept-risk: Accepts the risk of the issues that match filters (risk_accepted). - [Issue Ignore (POST /easm/issues/search:ignore)](https://docs.deepinfo.com/reference/easm/issue-ignore.md): POST /easm/issues/search:ignore: Ignores the issues that match filters (ignored). - [Issue Mark False Positive (POST /easm/issues/search:mark-false-positive)](https://docs.deepinfo.com/reference/easm/issue-mark-false-positive.md): POST /easm/issues/search:mark-false-positive: Marks the issues that match filters as false positive (marked_as_false_positive). - [Issue Mark Resolved (POST /easm/issues/search:mark-resolved)](https://docs.deepinfo.com/reference/easm/issue-mark-resolved.md): POST /easm/issues/search:mark-resolved: Marks the issues that match filters as resolved (marked_as_resolved). - [Issue Revert (POST /easm/issues/search:revert)](https://docs.deepinfo.com/reference/easm/issue-revert.md): POST /easm/issues/search:revert: Reverts the issues that match filters to their previous, active state. Only states set by a user can be reverted. - [Issue Asset Type Stats (GET /easm/issues/stats/asset-type)](https://docs.deepinfo.com/reference/easm/issue-asset-type-stats.md): GET /easm/issues/stats/asset-type: Counts issues per asset type. - [Issue Category Stats (GET /easm/issues/stats/category-type)](https://docs.deepinfo.com/reference/easm/issue-category-stats.md): GET /easm/issues/stats/category-type: Counts issues per category and type. - [Issue Duration Stats (GET /easm/issues/stats/duration)](https://docs.deepinfo.com/reference/easm/issue-duration-stats.md): GET /easm/issues/stats/duration: Average time issues stay open and time to fix. - [Issue Severity Stats (GET /easm/issues/stats/severity)](https://docs.deepinfo.com/reference/easm/issue-severity-stats.md): GET /easm/issues/stats/severity: Counts active issues per severity. - [Issue Severity Stats Timeline (GET /easm/issues/stats/severity-timeline)](https://docs.deepinfo.com/reference/easm/issue-severity-stats-timeline.md): GET /easm/issues/stats/severity-timeline: Time series of severity for the selected interval (daily, weekly, monthly). - [Issue State Stats (GET /easm/issues/stats/state)](https://docs.deepinfo.com/reference/easm/issue-state-stats.md): GET /easm/issues/stats/state: Counts issues per state. - [Issue Type Stats (GET /easm/issues/stats/type)](https://docs.deepinfo.com/reference/easm/issue-type-stats.md): GET /easm/issues/stats/type: Counts issues per issue type (filter by severity, sort with ordering). - [Issue Type Detail (GET /easm/issues/types/{issue_type_id})](https://docs.deepinfo.com/reference/easm/issue-type-detail.md): GET /easm/issues/types/{issue_type_id}: Returns an issue type: description, severity, category and remediation. - [Issue Type Instant Snapshot (POST /easm/issues/types/{issue_type_id}/instant-snapshot)](https://docs.deepinfo.com/reference/easm/issue-type-instant-snapshot.md): POST /easm/issues/types/{issue_type_id}/instant-snapshot: Recalculates the issue type snapshot now. - [Issue Type Latest Snapshot (GET /easm/issues/types/{issue_type_id}/latest-snapshot)](https://docs.deepinfo.com/reference/easm/issue-type-latest-snapshot.md): GET /easm/issues/types/{issue_type_id}/latest-snapshot: Latest summary of one issue type across your assets. - [Issue Type Security Score Timeline (GET /easm/issues/types/{issue_type_id}/security-score-timeline)](https://docs.deepinfo.com/reference/easm/issue-type-security-score-timeline.md): GET /easm/issues/types/{issue_type_id}/security-score-timeline: Time series of the security score for one issue type. interval: daily, weekly, monthly. - [Issue Categories (GET /easm/issues/categories/list)](https://docs.deepinfo.com/reference/easm/issue-categories.md): GET /easm/issues/categories/list: Lists issue categories. - [Issue Categories Instant Snapshot (POST /easm/issues/categories/{issue_type_category_id}/instant-snapshot)](https://docs.deepinfo.com/reference/easm/issue-categories-instant-snapshot.md): POST /easm/issues/categories/{issue_type_category_id}/instant-snapshot: Recalculates the issue category snapshot now. - [Issue Categories Latest Snapshot (GET /easm/issues/categories/{issue_type_category_id}/latest-snapshot)](https://docs.deepinfo.com/reference/easm/issue-categories-latest-snapshot.md): GET /easm/issues/categories/{issue_type_category_id}/latest-snapshot: Latest summary of one issue category. - [Issue Categories Security Score Timeline (GET /easm/issues/categories/{issue_type_category_id}/security-score-timeline)](https://docs.deepinfo.com/reference/easm/issue-categories-security-score-timeline.md): GET /easm/issues/categories/{issue_type_category_id}/security-score-timeline: Time series of the security score for one issue category. - [Vulnerability Asset Search (POST /easm/vulnerabilities/asset-search)](https://docs.deepinfo.com/reference/easm/vulnerability-asset-search.md): POST /easm/vulnerabilities/asset-search: Searches vulnerabilities per asset (one record per asset + CVE), with state. - [Vulnerability Search (POST /easm/vulnerabilities/search)](https://docs.deepinfo.com/reference/easm/vulnerability-search.md): POST /easm/vulnerabilities/search: Searches vulnerabilities (CVEs) affecting your assets, one record per CVE. - [Vulnerability Asset Export (POST /easm/vulnerabilities/asset-search:export)](https://docs.deepinfo.com/reference/easm/vulnerability-asset-export.md): POST /easm/vulnerabilities/asset-search:export: Exports every record matching filters (no pagination). - [Vulnerability Export (POST /easm/vulnerabilities/search:export)](https://docs.deepinfo.com/reference/easm/vulnerability-export.md): POST /easm/vulnerabilities/search:export: Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. - [Vulnerability Detail (GET /easm/vulnerabilities/{vulnerability_id})](https://docs.deepinfo.com/reference/easm/vulnerability-detail.md): GET /easm/vulnerabilities/{vulnerability_id}: Returns one vulnerability with CVE details and affected assets. - [Vulnerability Accept Risk (POST /easm/vulnerabilities/search:accept-risk)](https://docs.deepinfo.com/reference/easm/vulnerability-accept-risk.md): POST /easm/vulnerabilities/search:accept-risk: Accepts the risk of the asset vulnerabilities that match filters (risk_accepted). - [Vulnerability Ignore (POST /easm/vulnerabilities/search:ignore)](https://docs.deepinfo.com/reference/easm/vulnerability-ignore.md): POST /easm/vulnerabilities/search:ignore: Ignores the asset vulnerabilities that match filters (ignored). - [Vulnerability Mark False Positive (POST /easm/vulnerabilities/search:mark-false-positive)](https://docs.deepinfo.com/reference/easm/vulnerability-mark-false-positive.md): POST /easm/vulnerabilities/search:mark-false-positive: Marks the asset vulnerabilities that match filters as false positive (marked_as_false_positive). - [Vulnerability Mark Resolved (POST /easm/vulnerabilities/search:mark-resolved)](https://docs.deepinfo.com/reference/easm/vulnerability-mark-resolved.md): POST /easm/vulnerabilities/search:mark-resolved: Marks the asset vulnerabilities that match filters as resolved (marked_as_resolved). - [Vulnerability Revert (POST /easm/vulnerabilities/search:revert)](https://docs.deepinfo.com/reference/easm/vulnerability-revert.md): POST /easm/vulnerabilities/search:revert: Reverts the asset vulnerabilities that match filters to their previous, active state. - [Vulnerability Exploitability Score Stats (GET /easm/vulnerabilities/stats/exploitability-score)](https://docs.deepinfo.com/reference/easm/vulnerability-exploitability-score-stats.md): GET /easm/vulnerabilities/stats/exploitability-score: Distribution of vulnerabilities by exploitability score. - [Vulnerability Known Exploitable Stats (GET /easm/vulnerabilities/stats/known-exploitable)](https://docs.deepinfo.com/reference/easm/vulnerability-known-exploitable-stats.md): GET /easm/vulnerabilities/stats/known-exploitable: Counts known-exploited (CISA KEV) vulnerabilities. - [Vulnerability Severity Stats (GET /easm/vulnerabilities/stats/severity)](https://docs.deepinfo.com/reference/easm/vulnerability-severity-stats.md): GET /easm/vulnerabilities/stats/severity: Counts vulnerabilities per severity. - [Vulnerability Severity Stats Timeline (GET /easm/vulnerabilities/stats/severity-timeline)](https://docs.deepinfo.com/reference/easm/vulnerability-severity-stats-timeline.md): GET /easm/vulnerabilities/stats/severity-timeline: Time series of severity for the selected interval (daily, weekly, monthly). - [Technology Asset Search (POST /easm/technologies/asset-search)](https://docs.deepinfo.com/reference/easm/technology-asset-search.md): POST /easm/technologies/asset-search: Searches technologies per asset (one record per asset + technology). - [Technology Search (POST /easm/technologies/search)](https://docs.deepinfo.com/reference/easm/technology-search.md): POST /easm/technologies/search: Searches technologies detected on your assets, with versions and vulnerability counts. - [Technology Asset Export (POST /easm/technologies/asset-search:export)](https://docs.deepinfo.com/reference/easm/technology-asset-export.md): POST /easm/technologies/asset-search:export: Exports every record matching filters (no pagination). - [Technology Export (POST /easm/technologies/search:export)](https://docs.deepinfo.com/reference/easm/technology-export.md): POST /easm/technologies/search:export: Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. - [Technology Detail (GET /easm/technologies/{tech_id})](https://docs.deepinfo.com/reference/easm/technology-detail.md): GET /easm/technologies/{tech_id}: Returns one technology with its versions and affected assets. - [Most Vulnerable Technologies (GET /easm/technologies/stats/most-vulnerable)](https://docs.deepinfo.com/reference/easm/most-vulnerable-technologies.md): GET /easm/technologies/stats/most-vulnerable: Lists the technologies with the most vulnerabilities. - [Technology End of Life Status (GET /easm/technologies/eol/{product})](https://docs.deepinfo.com/reference/easm/technology-end-of-life-status.md): GET /easm/technologies/eol/{product}: Returns end-of-life information for a product (e.g. nginx, php). - [Technology Vulnerabilities (GET /easm/technologies/vulnerabilities)](https://docs.deepinfo.com/reference/easm/technology-vulnerabilities.md): GET /easm/technologies/vulnerabilities: Lists vulnerabilities of a technology (tech_id), optionally for a version and severity. - [Technology Asset Stats (GET /easm/technologies/stats/assets)](https://docs.deepinfo.com/reference/easm/technology-asset-stats.md): GET /easm/technologies/stats/assets: Counts assets per technology. - [Technology Category Stats (GET /easm/technologies/stats/category)](https://docs.deepinfo.com/reference/easm/technology-category-stats.md): GET /easm/technologies/stats/category: Counts technologies per category. - [Technology Count Timeline (GET /easm/technologies/stats/count-timeline)](https://docs.deepinfo.com/reference/easm/technology-count-timeline.md): GET /easm/technologies/stats/count-timeline: Time series of count for the selected interval (daily, weekly, monthly). - [Technology Vulnerability Stats (GET /easm/technologies/stats/vulnerability)](https://docs.deepinfo.com/reference/easm/technology-vulnerability-stats.md): GET /easm/technologies/stats/vulnerability: Vulnerability statistics for technologies (filter by tech_id, version). ## CTI - [CTI Overview](https://docs.deepinfo.com/reference/cti.md): Cyber Threat Intelligence: email breaches, compromised employee/client/payment credentials, compromised devices, threat actors and security news relevant… - [Breached Account List (GET /cti/email-breaches/accounts)](https://docs.deepinfo.com/reference/cti/breached-account-list.md): GET /cti/email-breaches/accounts: Lists your breached email accounts. Filter and sort with the optional query parameters. - [Email Breach List (GET /cti/email-breaches/breaches)](https://docs.deepinfo.com/reference/cti/email-breach-list.md): GET /cti/email-breaches/breaches: Lists breaches that include your email addresses. Filter and sort with the optional query parameters. - [Breached Account Detail (GET /cti/email-breaches/accounts/{account_id})](https://docs.deepinfo.com/reference/cti/breached-account-detail.md): GET /cti/email-breaches/accounts/{account_id}: Returns one breached account and its breaches. - [Email Breach Detail (GET /cti/email-breaches/breaches/{breach_id})](https://docs.deepinfo.com/reference/cti/email-breach-detail.md): GET /cti/email-breaches/breaches/{breach_id}: Returns one breach: date, description, data types and affected accounts count. - [Email Breach Account Titles (GET /cti/email-breaches/account-titles)](https://docs.deepinfo.com/reference/cti/email-breach-account-titles.md): GET /cti/email-breaches/account-titles: Lists the job titles set on breached accounts. - [Email Breach Data Types (GET /cti/email-breaches/data-types)](https://docs.deepinfo.com/reference/cti/email-breach-data-types.md): GET /cti/email-breaches/data-types: Lists every data type (kind of exposed data) found in breaches. - [Latest Email Breaches (GET /cti/email-breaches/breaches/latest)](https://docs.deepinfo.com/reference/cti/latest-email-breaches.md): GET /cti/email-breaches/breaches/latest: Lists the most recent breaches affecting you. - [Breached Account Stats (GET /cti/email-breaches/accounts/{account_id}/stats)](https://docs.deepinfo.com/reference/cti/breached-account-stats.md): GET /cti/email-breaches/accounts/{account_id}/stats: Breach statistics for one account. - [Breached Accounts Domain Stats (GET /cti/email-breaches/accounts/stats/domain)](https://docs.deepinfo.com/reference/cti/breached-accounts-domain-stats.md): GET /cti/email-breaches/accounts/stats/domain: Breached account counts per domain. - [Email Breach Stats (GET /cti/email-breaches/breaches/stats)](https://docs.deepinfo.com/reference/cti/email-breach-stats.md): GET /cti/email-breaches/breaches/stats: Breach statistics. - [Breached Account Update (PUT /cti/email-breaches/accounts/{account_id})](https://docs.deepinfo.com/reference/cti/breached-account-update.md): PUT /cti/email-breaches/accounts/{account_id}: Updates a breached account's profile with the fields in the request body. - [Compromised Employee Account Search (POST /cti/compromised-employee-accounts/search)](https://docs.deepinfo.com/reference/cti/compromised-employee-account-search.md): POST /cti/compromised-employee-accounts/search: Searches employee accounts found in leaked credentials. - [Compromised Employee Account Export (POST /cti/compromised-employee-accounts/search:export)](https://docs.deepinfo.com/reference/cti/compromised-employee-account-export.md): POST /cti/compromised-employee-accounts/search:export: Exports every record matching filters (no pagination). - [Compromised Employee Account Detail (GET /cti/compromised-employee-accounts/{account_id})](https://docs.deepinfo.com/reference/cti/compromised-employee-account-detail.md): GET /cti/compromised-employee-accounts/{account_id}: Returns one compromised employee account. - [Compromised Employee Account Risk Distribution Stats (GET /cti/compromised-employee-accounts/stats/risk-distribution)](https://docs.deepinfo.com/reference/cti/compromised-employee-account-risk-distribution-stats.md): GET /cti/compromised-employee-accounts/stats/risk-distribution: Distribution of compromised employee accounts by risk. - [Compromised Employee Accounts Domain Stats (GET /cti/compromised-employee-accounts/stats/domain)](https://docs.deepinfo.com/reference/cti/compromised-employee-accounts-domain-stats.md): GET /cti/compromised-employee-accounts/stats/domain: Compromised employee account counts per domain. - [Compromised Employee Account Update (PUT /cti/compromised-employee-accounts/{account_id})](https://docs.deepinfo.com/reference/cti/compromised-employee-account-update.md): PUT /cti/compromised-employee-accounts/{account_id}: Updates an account's profile with the fields in the request body. - [Compromised Employee Credential Search (POST /cti/compromised-employee-credentials/search)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-search.md): POST /cti/compromised-employee-credentials/search: Searches leaked employee credentials and their state. - [Compromised Employee Credential Export (POST /cti/compromised-employee-credentials/search:export)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-export.md): POST /cti/compromised-employee-credentials/search:export: Exports every record matching filters (no pagination). - [Compromised Employee Credential Accept Risk (POST /cti/compromised-employee-credentials/search:accept-risk)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-accept-risk.md): POST /cti/compromised-employee-credentials/search:accept-risk: Accepts the risk of the compromised employee credentials that match filters (risk_accepted). - [Compromised Employee Credential Ignore (POST /cti/compromised-employee-credentials/search:ignore)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-ignore.md): POST /cti/compromised-employee-credentials/search:ignore: Ignores the compromised employee credentials that match filters (ignored). - [Compromised Employee Credential Mark False Positive (POST /cti/compromised-employee-credentials/search:mark-false-positive)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-mark-false-positive.md): Marks the compromised employee credentials that match filters as false positive (marked_as_false_positive). - [Compromised Employee Credential Mark Resolved (POST /cti/compromised-employee-credentials/search:mark-resolved)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-mark-resolved.md): POST /cti/compromised-employee-credentials/search:mark-resolved: Marks the compromised employee credentials that match filters as resolved (marked_as_resolved). - [Compromised Employee Credential Revert (POST /cti/compromised-employee-credentials/search:revert)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-revert.md): POST /cti/compromised-employee-credentials/search:revert: Reverts the compromised employee credentials that match filters to their previous, active state. - [Compromised Employee Credential Exposure Timeline (GET /cti/compromised-employee-credentials/stats/exposure-timeline)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-exposure-timeline.md): GET /cti/compromised-employee-credentials/stats/exposure-timeline: Time series of newly exposed employee credentials. - [Compromised Employee Credential Stats (GET /cti/compromised-employee-credentials/stats)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-stats.md): GET /cti/compromised-employee-credentials/stats: Compromised employee credential statistics. - [Compromised Employee Credential Status Stats (GET /cti/compromised-employee-credentials/stats/status)](https://docs.deepinfo.com/reference/cti/compromised-employee-credential-status-stats.md): GET /cti/compromised-employee-credentials/stats/status: Compromised employee credential counts per state. - [Compromised Client Credential Search (POST /cti/compromised-client-credentials/search)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-search.md): POST /cti/compromised-client-credentials/search: Searches leaked credentials of your customers and their state. - [Compromised Client Credential Export (POST /cti/compromised-client-credentials/search:export)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-export.md): POST /cti/compromised-client-credentials/search:export: Exports every record matching filters (no pagination). - [Compromised Client Credential Accept Risk (POST /cti/compromised-client-credentials/search:accept-risk)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-accept-risk.md): POST /cti/compromised-client-credentials/search:accept-risk: Accepts the risk of the compromised client credentials that match filters (risk_accepted). - [Compromised Client Credential Ignore (POST /cti/compromised-client-credentials/search:ignore)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-ignore.md): POST /cti/compromised-client-credentials/search:ignore: Ignores the compromised client credentials that match filters (ignored). - [Compromised Client Credential Mark False Positive (POST /cti/compromised-client-credentials/search:mark-false-positive)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-mark-false-positive.md): Marks the compromised client credentials that match filters as false positive (marked_as_false_positive). - [Compromised Client Credential Mark Resolved (POST /cti/compromised-client-credentials/search:mark-resolved)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-mark-resolved.md): POST /cti/compromised-client-credentials/search:mark-resolved: Marks the compromised client credentials that match filters as resolved (marked_as_resolved). - [Compromised Client Credential Revert (POST /cti/compromised-client-credentials/search:revert)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-revert.md): POST /cti/compromised-client-credentials/search:revert: Reverts the compromised client credentials that match filters to their previous, active state. - [Compromised Client Credential Stats (GET /cti/compromised-client-credentials/stats)](https://docs.deepinfo.com/reference/cti/compromised-client-credential-stats.md): GET /cti/compromised-client-credentials/stats: Compromised client credential statistics. - [Compromised Payment Credential Search (POST /cti/compromised-payment-credentials/search)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-search.md): POST /cti/compromised-payment-credentials/search: Searches leaked payment cards and their state. - [Compromised Payment Credential Export (POST /cti/compromised-payment-credentials/search:export)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-export.md): POST /cti/compromised-payment-credentials/search:export: Exports every record matching filters (no pagination). - [Compromised Payment Credential Detail (GET /cti/compromised-payment-credentials/{credential_id})](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-detail.md): GET /cti/compromised-payment-credentials/{credential_id}: Returns one compromised payment credential. - [Compromised Payment Credential Accept Risk (POST /cti/compromised-payment-credentials/search:accept-risk)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-accept-risk.md): POST /cti/compromised-payment-credentials/search:accept-risk: Accepts the risk of the compromised payment credentials that match filters (risk_accepted). - [Compromised Payment Credential Ignore (POST /cti/compromised-payment-credentials/search:ignore)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-ignore.md): POST /cti/compromised-payment-credentials/search:ignore: Ignores the compromised payment credentials that match filters (ignored). - [Compromised Payment Credential Mark False Positive (POST /cti/compromised-payment-credentials/search:mark-false-positive)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-mark-false-positive.md): Marks the compromised payment credentials that match filters as false positive (marked_as_false_positive). - [Compromised Payment Credential Mark Resolved (POST /cti/compromised-payment-credentials/search:mark-resolved)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-mark-resolved.md): POST /cti/compromised-payment-credentials/search:mark-resolved: Marks the compromised payment credentials that match filters as resolved (marked_as_resolved). - [Compromised Payment Credential Revert (POST /cti/compromised-payment-credentials/search:revert)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-revert.md): POST /cti/compromised-payment-credentials/search:revert: Reverts the compromised payment credentials that match filters to their previous, active state. - [Compromised Payment Credential Stats (GET /cti/compromised-payment-credentials/stats)](https://docs.deepinfo.com/reference/cti/compromised-payment-credential-stats.md): GET /cti/compromised-payment-credentials/stats: Compromised payment credential statistics. - [Compromised Device Search (POST /cti/compromised-devices)](https://docs.deepinfo.com/reference/cti/compromised-device-search.md): POST /cti/compromised-devices: Searches compromised (infostealer-infected) devices linked to your employees. - [Compromised Device Detail (GET /cti/compromised-devices/{compromised_employee_device_id})](https://docs.deepinfo.com/reference/cti/compromised-device-detail.md): GET /cti/compromised-devices/{compromised_employee_device_id}: Returns one compromised device. - [Threat Actor Search (POST /cti/threat-actors/search)](https://docs.deepinfo.com/reference/cti/threat-actor-search.md): POST /cti/threat-actors/search: Searches threat actors. - [Threat Actor Detail (GET /cti/threat-actors/{threat_actor_id})](https://docs.deepinfo.com/reference/cti/threat-actor-detail.md): GET /cti/threat-actors/{threat_actor_id}: Returns one threat actor profile. - [Most Actor Hosting Countries by Threat Actors (GET /cti/threat-actors/stats/most-actor-hosting-countries)](https://docs.deepinfo.com/reference/cti/most-actor-hosting-countries-by-threat-actors.md): GET /cti/threat-actors/stats/most-actor-hosting-countries: Countries hosting the most threat actors. - [Most Targeted Countries by Threat Actors (GET /cti/threat-actors/stats/most-targeted-countries)](https://docs.deepinfo.com/reference/cti/most-targeted-countries-by-threat-actors.md): GET /cti/threat-actors/stats/most-targeted-countries: Countries most targeted by threat actors (size: number of rows). - [Most Targeted Industries by Threat Actors (GET /cti/threat-actors/stats/most-targeted-industries)](https://docs.deepinfo.com/reference/cti/most-targeted-industries-by-threat-actors.md): GET /cti/threat-actors/stats/most-targeted-industries: Industries most targeted by threat actors. - [Most Targeted Organizations by Threat Actors (GET /cti/threat-actors/stats/most-targeted-organizations)](https://docs.deepinfo.com/reference/cti/most-targeted-organizations-by-threat-actors.md): GET /cti/threat-actors/stats/most-targeted-organizations: Organizations most targeted by threat actors. - [Most Used CVEs by Threat Actors (GET /cti/threat-actors/stats/most-used-cves)](https://docs.deepinfo.com/reference/cti/most-used-cves-by-threat-actors.md): GET /cti/threat-actors/stats/most-used-cves: CVEs most used by threat actors. - [Most Used Tools by Threat Actors (GET /cti/threat-actors/stats/most-used-tools)](https://docs.deepinfo.com/reference/cti/most-used-tools-by-threat-actors.md): GET /cti/threat-actors/stats/most-used-tools: Tools most used by threat actors. - [Security News Search (POST /cti/news/search)](https://docs.deepinfo.com/reference/cti/security-news-search.md): POST /cti/news/search: Searches curated cybersecurity news. - [Security News Detail (GET /cti/news/{id})](https://docs.deepinfo.com/reference/cti/security-news-detail.md): GET /cti/news/{id}: Returns one news item. ## BRP - [BRP Overview](https://docs.deepinfo.com/reference/brp.md): Brand Risk Protection: domains that imitate your brand. Suspicious domains are candidates for review; approved ones become fraudulent domains and are… - [Fraudulent Settings Detail (GET /brp/fraudulent-settings)](https://docs.deepinfo.com/reference/brp/fraudulent-settings-detail.md): GET /brp/fraudulent-settings: Returns the Brand Risk Protection settings: ignored_domains are never reported. - [Fraudulent Settings Update (PUT /brp/fraudulent-settings)](https://docs.deepinfo.com/reference/brp/fraudulent-settings-update.md): PUT /brp/fraudulent-settings: Replaces the Brand Risk Protection settings. Send the full ignored_domains list. - [Fraudulent Domain Search (POST /brp/fraudulent-domains/search)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-search.md): POST /brp/fraudulent-domains/search: Searches your monitored fraudulent domains by name, type, risk score and indicators. - [Fraudulent Domain Export (POST /brp/fraudulent-domains/search:export)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-export.md): POST /brp/fraudulent-domains/search:export: Exports every record matching filters (no pagination). - [Fraudulent Domain Detail (GET /brp/fraudulent-domains/{fraudulent_id})](https://docs.deepinfo.com/reference/brp/fraudulent-domain-detail.md): GET /brp/fraudulent-domains/{fraudulent_id}: Returns one fraudulent domain with its latest data and risk score. - [Fraudulent Domain Delete (POST /brp/fraudulent-domains/search:delete)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-delete.md): POST /brp/fraudulent-domains/search:delete: Stops monitoring every fraudulent domain matching filters. - [Fraudulent Domain Instant Scan (POST /brp/fraudulent-domains/{fraudulent_id}/instant-scan)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-instant-scan.md): POST /brp/fraudulent-domains/{fraudulent_id}/instant-scan: Starts an on-demand scan of a fraudulent domain. - [Fraudulent Domain DNS History (GET /brp/fraudulent-domains/{fraudulent_id}/dns-history)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-dns-history.md): GET /brp/fraudulent-domains/{fraudulent_id}/dns-history: Returns the DNS history recorded for a fraudulent domain. - [Fraudulent Domain Latest Scan (GET /brp/fraudulent-domains/{fraudulent_id}/latest-scan)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-latest-scan.md): GET /brp/fraudulent-domains/{fraudulent_id}/latest-scan: Returns the latest scan of a fraudulent domain. - [Fraudulent Domain Port Scan History (GET /brp/fraudulent-domains/{fraudulent_id}/port-scan-history)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-port-scan-history.md): GET /brp/fraudulent-domains/{fraudulent_id}/port-scan-history: Returns the port scan history recorded for a fraudulent domain. - [Fraudulent Domain SSL History (GET /brp/fraudulent-domains/{fraudulent_id}/ssl-history)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-ssl-history.md): GET /brp/fraudulent-domains/{fraudulent_id}/ssl-history: Returns the SSL certificate history recorded for a fraudulent domain. - [Fraudulent Domain Webdata History (GET /brp/fraudulent-domains/{fraudulent_id}/webdata-history)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-webdata-history.md): Returns the web data (page content, technologies, headers) history recorded for a fraudulent domain. - [Fraudulent Domain Whois History (GET /brp/fraudulent-domains/{fraudulent_id}/whois-history)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-whois-history.md): GET /brp/fraudulent-domains/{fraudulent_id}/whois-history: Returns the WHOIS history recorded for a fraudulent domain. - [Fraudulent Domain Instant Snapshot (POST /brp/fraudulent-domains/{fraudulent_id}/instant-snapshot)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-instant-snapshot.md): POST /brp/fraudulent-domains/{fraudulent_id}/instant-snapshot: Recalculates the fraudulent domain snapshot now. - [Fraudulent Domain Latest Snapshot (GET /brp/fraudulent-domains/{fraudulent_id}/latest-snapshot)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-latest-snapshot.md): GET /brp/fraudulent-domains/{fraudulent_id}/latest-snapshot: Latest summary of a fraudulent domain. - [Fraudulent Domain Risk Score Timeline (GET /brp/fraudulent-domains/{fraudulent_id}/risk-score-timeline)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-risk-score-timeline.md): GET /brp/fraudulent-domains/{fraudulent_id}/risk-score-timeline: Time series of a fraudulent domain's risk score. - [Fraudulent Domain Type Stats (GET /brp/fraudulent-domains/stats/type)](https://docs.deepinfo.com/reference/brp/fraudulent-domain-type-stats.md): GET /brp/fraudulent-domains/stats/type: Counts fraudulent domains per type (domain, subdomain). - [Suspicious Domain Search (POST /brp/suspicious-domains/search)](https://docs.deepinfo.com/reference/brp/suspicious-domain-search.md): POST /brp/suspicious-domains/search: Searches suspicious domains (candidates found by your fraudulent rules) and their state. - [Suspicious Domain Export (POST /brp/suspicious-domains/search:export)](https://docs.deepinfo.com/reference/brp/suspicious-domain-export.md): POST /brp/suspicious-domains/search:export: Exports every record matching filters (no pagination). - [Suspicious Domain Detail (GET /brp/suspicious-domains/{detected_fraudulent_id})](https://docs.deepinfo.com/reference/brp/suspicious-domain-detail.md): GET /brp/suspicious-domains/{detected_fraudulent_id}: Returns one suspicious domain with the rule that detected it. - [Suspicious Domain Approve (POST /brp/suspicious-domains/search:approve)](https://docs.deepinfo.com/reference/brp/suspicious-domain-approve.md): POST /brp/suspicious-domains/search:approve: Approves the suspicious domains that match filters (approved). - [Suspicious Domain Ignore (POST /brp/suspicious-domains/search:ignore)](https://docs.deepinfo.com/reference/brp/suspicious-domain-ignore.md): POST /brp/suspicious-domains/search:ignore: Ignores the suspicious domains that match filters (ignored). - [Suspicious Domain Revert (POST /brp/suspicious-domains/search:revert)](https://docs.deepinfo.com/reference/brp/suspicious-domain-revert.md): POST /brp/suspicious-domains/search:revert: Reverts the suspicious domains that match filters to their previous, active state. - [Suspicious Domain State Stats (GET /brp/suspicious-domains/stats/state)](https://docs.deepinfo.com/reference/brp/suspicious-domain-state-stats.md): GET /brp/suspicious-domains/stats/state: Counts suspicious domains per state. - [Fraudulent Rule Search (POST /brp/fraudulent-rules/search)](https://docs.deepinfo.com/reference/brp/fraudulent-rule-search.md): POST /brp/fraudulent-rules/search: Searches your fraudulent rules. - [Fraudulent Rule List (GET /brp/fraudulent-rules)](https://docs.deepinfo.com/reference/brp/fraudulent-rule-list.md): GET /brp/fraudulent-rules: Lists your fraudulent rules. - [Fraudulent Rule Detail (GET /brp/fraudulent-rules/{rule_id})](https://docs.deepinfo.com/reference/brp/fraudulent-rule-detail.md): GET /brp/fraudulent-rules/{rule_id}: Returns one fraudulent rule. - [Fraudulent Rule Create (POST /brp/fraudulent-rules)](https://docs.deepinfo.com/reference/brp/fraudulent-rule-create.md): POST /brp/fraudulent-rules: Creates a fraudulent rule: a keyword with match_type and helper keywords. - [Fraudulent Rule Update (PUT /brp/fraudulent-rules/{rule_id})](https://docs.deepinfo.com/reference/brp/fraudulent-rule-update.md): PUT /brp/fraudulent-rules/{rule_id}: Updates a fraudulent rule (send all fields). - [Fraudulent Rule Delete (DELETE /brp/fraudulent-rules/{rule_id})](https://docs.deepinfo.com/reference/brp/fraudulent-rule-delete.md): DELETE /brp/fraudulent-rules/{rule_id}: Deletes a fraudulent rule. ## Platform - [Platform Overview](https://docs.deepinfo.com/reference/platform.md): Notifications and reports. - [Notification Email List (GET /platform/notification-emails)](https://docs.deepinfo.com/reference/platform/notification-email-list.md): GET /platform/notification-emails: Lists notification emails that were sent, with the rule that triggered them. - [Notification Rule List (GET /platform/notification-rules)](https://docs.deepinfo.com/reference/platform/notification-rule-list.md): GET /platform/notification-rules: Lists notification rules. Filter and sort with the optional query parameters. - [Notification Rule Detail (GET /platform/notification-rules/{rule_id})](https://docs.deepinfo.com/reference/platform/notification-rule-detail.md): GET /platform/notification-rules/{rule_id}: Returns one notification rule. - [Notification Rule Create (POST /platform/notification-rules)](https://docs.deepinfo.com/reference/platform/notification-rule-create.md): POST /platform/notification-rules: Creates a notification rule: the event scope (e.g. new_issue_detected), an optional strategy (conditions such as asset… - [Notification Rule Update (PUT /platform/notification-rules/{rule_id})](https://docs.deepinfo.com/reference/platform/notification-rule-update.md): PUT /platform/notification-rules/{rule_id}: Updates a notification rule's name, delivery time, members and enabled. scope and strategy cannot be changed. - [Notification Rule Delete (DELETE /platform/notification-rules/{rule_id})](https://docs.deepinfo.com/reference/platform/notification-rule-delete.md): DELETE /platform/notification-rules/{rule_id}: Deletes a notification rule. - [Report Search (POST /platform/reports/search)](https://docs.deepinfo.com/reference/platform/report-search.md): POST /platform/reports/search: Searches reports. - [Report Detail (GET /platform/reports/{report_id})](https://docs.deepinfo.com/reference/platform/report-detail.md): GET /platform/reports/{report_id}: Returns one report and its generation status. - [Report Create (POST /platform/reports)](https://docs.deepinfo.com/reference/platform/report-create.md): POST /platform/reports: Generates a report. - [Report Download (GET /platform/reports/{report_id}/download)](https://docs.deepinfo.com/reference/platform/report-download.md): GET /platform/reports/{report_id}/download: Returns a pre-signed download_url for the report PDF. - [Report Delete (DELETE /platform/reports/{report_id})](https://docs.deepinfo.com/reference/platform/report-delete.md): DELETE /platform/reports/{report_id}: Deletes a report. - [Scheduled Report Rule List (GET /platform/scheduled-reports/rules)](https://docs.deepinfo.com/reference/platform/scheduled-report-rule-list.md): GET /platform/scheduled-reports/rules: Lists scheduled report rules. - [Scheduled Report Rule Detail (GET /platform/scheduled-reports/rules/{rule_id})](https://docs.deepinfo.com/reference/platform/scheduled-report-rule-detail.md): GET /platform/scheduled-reports/rules/{rule_id}: Returns one scheduled report rule with last and next send dates. - [Scheduled Report Rule Create (POST /platform/scheduled-reports/rules)](https://docs.deepinfo.com/reference/platform/scheduled-report-rule-create.md): POST /platform/scheduled-reports/rules: Creates a scheduled report: type, frequency (daily, weekly, monthly) and the team members (user ids) who receive it. - [Scheduled Report Rule Delete (DELETE /platform/scheduled-reports/rules/{rule_id})](https://docs.deepinfo.com/reference/platform/scheduled-report-rule-delete.md): DELETE /platform/scheduled-reports/rules/{rule_id}: Deletes a scheduled report rule. (There is no update; delete and create again.) ## Changelog - [Changelog](https://docs.deepinfo.com/changelog.md): What changed in the Deepinfo API, the Deepinfo Platform and this documentation, newest first. - [2026-10-05: The New Deepinfo Documentation Site](https://docs.deepinfo.com/changelog/the-new-documentation-site.md): docs.deepinfo.com now documents every API endpoint, generated from the Deepinfo Postman collection, with Getting Started guides, search and a Markdown version of every page. - [2026-09-27: Operator Support per Field](https://docs.deepinfo.com/changelog/operator-support.md): Search endpoints now list their searchable fields grouped by the operators each field accepts, measured against the API, and the docs show the forms a filter error takes. - [2026-09-24: A Guide to the Deepinfo Platform](https://docs.deepinfo.com/changelog/platform-guide.md): A new section of the documentation explains the Deepinfo Platform screen by screen, from your first sign-in to reports and notification rules. - [2026-09-23: Rate Limits per Endpoint and Rate-Limit Headers](https://docs.deepinfo.com/changelog/rate-limits.md): Rate limits apply per API key and per endpoint, default to 1 request per second, and responses report them in ratelimit headers. - [2026-09-23: Production and Demo Environments](https://docs.deepinfo.com/changelog/production-and-demo-environments.md): The documentation now states which addresses each account uses, and the Environment switch in the API Reference sidebar shows every example with the Demo addresses. - [2026-09-23: Port Scan Is Documented as a POST Request](https://docs.deepinfo.com/changelog/port-scan-post.md): The Port Scan lookup is documented as POST /lookup/port-scan, with the scan options in a JSON body; the previous documentation showed a GET request. - [2026-09-23: Both Error Formats Documented](https://docs.deepinfo.com/changelog/error-formats.md): Gateway errors and application errors have different JSON bodies; the Errors page describes both, with a request and response for each status code.