POSThttps://api.deepinfo.com/v1/easm/issues/search

Searches issues on your assets by state, severity, type, category, asset and dates.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
page_sizeOptional
Min 25, max 100. Default 100.
Example25
pageOptional
Min 1, max 800. Default 1.
Example1

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
asset.idThe ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.
asset.nameThe name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset host:port. The Issue List shows it as ASSET.
asset.tagsYour own tags on the asset the issue was found on, as a list of strings (the asset's tags in Asset Search).
asset.domain_asset.idThe ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. asset.domain_asset is null when the asset's domain is not one of your assets.
asset.domain_asset.nameThe name of the domain asset the issue's asset belongs to, such as acme.example for www.acme.example; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.
type.idThe ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (GET /easm/issues/types/{issue_type_id}), or filter on it to list every asset with that issue type.
type.nameThe name of the issue type, for example Missing SPF Record or SSL/TLS Not Implemented; the Issue List's SEARCH box matches it.
type.category.idThe ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (GET /easm/issues/categories/list).
type.category.nameThe name of the issue type's category, such as DNS, SSL/TLS, Web Application, Domain/Whois, Network or Database Server.

Operators eq in exists

FieldDescription
asset.typeThe type of the asset the issue was found on: domain, subdomain, ip or website (shown as Domain, Subdomain, IP Address and Website).
stateThe issue's state: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set.
severityThe severity of this issue: Critical, High, Medium, Low or Information; the Issue List severity tabs filter on it. It usually matches type.severity but can be higher, as seen on some issues about vulnerabilities detected on a technology.
type.severityThe severity of the issue type: Critical, High, Medium, Low or Information. Each issue also has its own severity, which usually matches it.

Operators eq in gte lte exists

FieldDescription
first_seen_dateWhen the issue was first detected on the asset, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). The platform's ACTIVE DAYS runs from this date to last_seen_date.
last_seen_dateWhen the issue was most recently detected on the asset, in ISO 8601 UTC.
last_check_dateWhen the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals last_seen_date.

Operators eq in

FieldDescription
idThe issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (GET /easm/issues/{issue_id}), or filter on it with in to select exact issues.

Sortable Fields

FieldDescription
asset.nameThe name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset host:port. The Issue List shows it as ASSET.
asset.typeThe type of the asset the issue was found on: domain, subdomain, ip or website (shown as Domain, Subdomain, IP Address and Website).
asset.domain_asset.nameThe name of the domain asset the issue's asset belongs to, such as acme.example for www.acme.example; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.
stateThe issue's state: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set.
severityThe severity of this issue: Critical, High, Medium, Low or Information; the Issue List severity tabs filter on it. It usually matches type.severity but can be higher, as seen on some issues about vulnerabilities detected on a technology.
type.nameThe name of the issue type, for example Missing SPF Record or SSL/TLS Not Implemented; the Issue List's SEARCH box matches it.
type.severityThe severity of the issue type: Critical, High, Medium, Low or Information. Each issue also has its own severity, which usually matches it.
type.category.nameThe name of the issue type's category, such as DNS, SSL/TLS, Web Application, Domain/Whois, Network or Database Server.
first_seen_dateWhen the issue was first detected on the asset, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). The platform's ACTIVE DAYS runs from this date to last_seen_date.
last_seen_dateWhen the issue was most recently detected on the asset, in ISO 8601 UTC.
last_check_dateWhen the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals last_seen_date.

Response Fields

FieldTypeDescription
pageinteger
page_sizeinteger
result_countinteger
resultsarray of object
results[].idstring
results[].assetobject
results[].statestring
One of newly_detected, reappeared, unresolved, marked_as_resolved, risk_accepted, ignored, marked_as_false_positive, not_applicable, verified_resolved
results[].severitystring
One of Critical, High, Medium, Low, Information
results[].first_seen_datestring
date-time
results[].last_seen_datestring
date-time
results[].last_check_datestring
date-time
results[].typeobject

Paginated. See Getting Started → Pagination.

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
pagenumber1
page_sizenumber25
result_countnumber21
resultsarray<object>
results[].idstring"000000000000000e8a020001"
results[].assetobject
results[].asset.idstring"000000000000000ea4f90001"
results[].asset.namestring"acme.example"
results[].asset.name_unicodestring"acme.example"
results[].asset.typestring"domain"
results[].asset.tagsarray
results[].asset.domain_assetobject | null
results[].asset.domain_asset.idstring"000000000000000e915c0001"
results[].asset.domain_asset.namestring"acme.example"
results[].asset.domain_asset.name_unicodestring"acme.example"
results[].statestring"reappeared"
results[].severitystring"Critical"
results[].first_seen_datestring"2025-06-01T08:00:00Z"
results[].last_seen_datestring"2025-07-31T08:00:00Z"
results[].last_check_datestring"2025-07-31T08:00:00Z"
results[].typeobject
results[].type.idstring"000000000000000e16fe0001"
results[].type.namestring"Expired SSL certificate"
results[].type.severitystring"Critical"
results[].type.categoryobject
results[].type.category.idstring"000000000000000e1c170001"
results[].type.category.namestring"SSL/TLS"

Examples

Selecting one loads it into the request and response panels.

Reference updated