v1

latestOpenAPI 3.0.0Proprietary - Commercial Use Only2026-08-06172139621.6 KB
Findings

List all social network findings of a company.

Hackers publicize their targets in underground forums or on the darkweb. Black Kite collects information from hundreds of darkweb forums, criminal sites, and hacktivist sites and filters the results for information pertaining to the company. This category has 5% effect on total scan score.<br/><br/> For storage optimization, the system <b>permanently</b> deletes all findings that haven't been detected by the Black Kite scanner for over a year. Findings with manually changed statuses or associated tickets are excluded.

get/api/v2/companies/{id}/findings/socialnetwork

Path parameters

idinteger required

The id of the target company.

Query parameters

page_numberinteger
Example:1

The number of the page requested.

page_size10 | 20 | 30 | 50 | 100 | 250
Example:10

The number of result items in a single response.

statusstring
Example:Suppressed,Acknowledged

Comma separated current status of this finding. Possible values are; Active, FalsePositive, Suppressed, Acknowledged and Deleted. When left out, all is implied.

severitystring
Example:Critical,High

Comma separated severity values of this finding. Possible values are; Info, Low, Medium, High and Critical. When left out, all is implied.

Response

Success

FindingIdinteger

The unique identifier of this finding.

Domainstring

The domain which this finding is related.

Severity'Info' | 'Low' | 'Medium' | 'High' | 'Critical'

The severity of a finding.

Status'Active' | 'FalsePositive' | 'Suppressed' | 'Acknowledged' | 'Deleted' | 'Remediated'

The status of this finding.

  • Active, means the finding is still active with no review as of yet.
  • FalsePositive, means the finding is considered to be false alarm.
  • Suppressed, means the finding is suppressed, similar to FalsePositive.
  • Acknowledged, means the finding is accepted, for example will not be fixed.
  • Deleted, means the finding is deleted, similar to FalsePositive.
  • Remediated, means the finding is mitigated.
ControlIdstring

The unique identifier of the control that this finding relates to.

FindingDatestring date-time

The date that Black Kite first seen the finding.

LastCheckDatestring date-time

The date that Black Kite last checked the finding.

FindingTitlestring

A title for the finding. Same with the security control's title referenced by the ControlId.

ScreenshotUrlstring nullable

The URL of the possibly fraudulent application screenshot.

ShareUrlstring

The URL of the possibly social network share.

Snippetstring

Some part of the social network share.

Example response

[
  {
    "FindingId": 2590965999,
    "Domain": "acmeinc.com",
    "Severity": "Medium",
    "Status": "Active",
    "ControlId": "FRADOM-001",
    "Ticket": {
      "Status": "Assigned",
      "Owner": "John Doe"
    },
    "FindingDate": "2021-08-09T08:30:30.682Z",
    "LastCheckDate": "2021-08-09T08:30:30.682Z",
    "FindingTitle": "X-Content-Type-Options HTTP Header",
    "ScreenshotUrl": "https://image.normshield.com/api/v1/ss?f=2018_05_31_b64735ed3c444499b779f59a041101a5.png",
    "ShareUrl": "https://acmeinc.slideshare.com/cvq134",
    "Snippet": "... information is of a commercially sensitive nature or is deemed confidential ..."
  }
]