v1

latestOpenAPI 3.1.02026-07-2481742657.4 KB
Threat Hunting
Adversary Investigation

Get endpoint observation history for a host

Retrieve historical endpoint-level hash observations for a host. This action returns time frames during which Censys observed host service endpoint body, favicon, and banner hash values. You must provide an observation_type and can optionally filter by a specific value using the observation_value parameter. You may also filter by port number.<br><br>To use this endpoint, your organization must have access to the Adversary Investigation module.

get/v3/threat-hunting/host/{ip}/observations/endpoints

Path parameters

ipstring ip required

The IP address of a host.

Example:8.8.8.8

The IP address of a host.

Query parameters

organization_idstring uuid required

The ID of a Censys organization to associate the request with. See the Getting Started docs for more information.

Example:11111111-2222-3333-4444-555555555555

The ID of a Censys organization to associate the request with. See the Getting Started docs for more information.

start_timestring

Start of date range (RFC3339 format, e.g., 2024-01-01T00:00:00Z). If not specified, defaults to the maximum query window back from the end time.

Example:2024-01-01T00:00:00Z

Start of date range (RFC3339 format, e.g., 2024-01-01T00:00:00Z). If not specified, defaults to the maximum query window back from the end time.

end_timestring

End of date range (RFC3339 format, e.g., 2024-01-31T23:59:59Z). If not specified, defaults to now. Cannot be in the future.

Example:2024-01-31T23:59:59Z

End of date range (RFC3339 format, e.g., 2024-01-31T23:59:59Z). If not specified, defaults to now. Cannot be in the future.

page_sizeinteger

Number of results per page (max 100)

Example:50

Number of results per page (max 100)

page_tokenstring

Pagination token from previous response

Pagination token from previous response

portinteger

Filter by port number

Example:443

Filter by port number

observation_valuestring

Filter by observation value for the selected observation_type

Filter by observation value for the selected observation_type

observation_type'body_hash_sha1' | 'body_hash_sha256' | 'favicon_hash_md5' | 'favicon_hash_sha256' | 'favicon_hash_shodan' | 'banner_hash_sha256' | 'endpoints_banner_hash_sha256' required

Endpoint observation type to query.

Endpoint observation type to query.

order_bystring[] nullable

Order observations by these fields. Multiple values can be provided (e.g., ['port DESC', 'observation_value ASC']).

Order observations by these fields. Multiple values can be provided (e.g., ['port DESC', 'observation_value ASC']).

Headers

X-Organization-IDstring uuid

The ID of a Censys organization to associate the request with. See the Getting Started docs for more information. Note: The header parameter is supported for atypical use cases; we recommend always providing this field via the query parameter.

Example:11111111-2222-3333-4444-555555555555

The ID of a Censys organization to associate the request with. See the Getting Started docs for more information. Note: The header parameter is supported for atypical use cases; we recommend always providing this field via the query parameter.

Response

A list of observation ranges