v1

latestOpenAPI 3.0.0Proprietary - Commercial Use Only2026-08-06172139621.6 KB
Findings

Get a attack surface finding of a company.

Attack surface is the technical analysis of open critical ports, out-of-date services, application weaknesses, SSL/TLS strength, and any misconfigurations. This information is gathered from Censys and Shodan databases and service/application versions are correlated with other subcategories' results. This category has 4% effect on total scan score.<br/><br/> For storage optimization, the system <b>permanently</b> deletes all findings that haven't been detected by the Black Kite scanner for over a year. Findings with manually changed statuses or associated tickets are excluded.

get/api/v2/companies/{id}/findings/attacksurface/{findingId}

Path parameters

idinteger required

The id of the company that includes finding.

findingIdinteger required

The id of the target finding.

Response

Success

FindingIdinteger

The unique identifier of this finding.

IPAddressstring

The related IP address which contains the finding.

Severity'Info' | 'Low' | 'Medium' | 'High' | 'Critical'

The severity of a finding.

Status'Active' | 'FalsePositive' | 'Suppressed' | 'Acknowledged' | 'Deleted' | 'Remediated'

The status of this finding.

  • Active, means the finding is still active with no review as of yet.
  • FalsePositive, means the finding is considered to be false alarm.
  • Suppressed, means the finding is suppressed, similar to FalsePositive.
  • Acknowledged, means the finding is accepted, for example will not be fixed.
  • Deleted, means the finding is deleted, similar to FalsePositive.
  • Remediated, means the finding is mitigated.
ControlIdstring

The unique identifier of the control that this finding relates to.

RiskScorenumber float

The addition of all related CWE and CVE scores. Attention: This field will deprecate.

Domainsstring[] nullable

The domains that live on the related IP Address

Portsinteger[] nullable
Protocolsstring[] nullable
Riskstring

HTML formatted finding details that constitute this finding.

FindingDatestring date-time

The date that Black Kite first seen the finding.

ConfidenceLevel'Low' | 'Medium' | 'High' | 'VeryHigh' nullable

The confidence level of this finding.

UpdateDatestring date-time nullable

The date that the finding was last updated.

Example response

{
  "FindingId": 2590965999,
  "IPAddress": "192.168.1.1",
  "Severity": "Medium",
  "Status": "Active",
  "Ticket": {
    "Status": "Assigned",
    "Owner": "John Doe"
  },
  "ControlId": "FRADOM-001",
  "Domains": [
    "data.acmeinc.com"
  ],
  "Protocols": [
    "http"
  ],
  "Risk": "Application Weakness(es): <br/> ...",
  "FindingDate": "2021-08-09T08:30:30.682Z",
  "ConfidenceLevel": "High",
  "UpdateDate": "2021-08-09T08:30:30.682Z"
}