---
title: "Categorize Stealer Domains"
method: POST
path: "/search-by-stealer/categorize-domains"
tags: ["Investigations"]
---

# Categorize Stealer Domains

`POST /search-by-stealer/categorize-domains`

Categorize the domains associated with a stealer (from employeeAt and clientAt fields) by their purpose using AI. Results are cached on the stealer document.

## Request body

- object
  - `stealerId` string, required — Stealer ID to categorize domains for

## Response `200`

Successful operation

- object
  - `success` boolean
  - `data` object[] — Array of domain categories
    - `name` string — Category name
    - `domains` string[] — Domains belonging to this category
  - `cached` boolean — Whether the result was returned from cache

## Other responses

- `400` — Validation error - the request or request body was invalid
- `401` — Unauthorized - the server could not authenticate the request
- `403` — Forbidden - the server authenticated the request but refuses to process it because of insufficient permissions
- `404` — Not found - the server could not find the requested resource
- `408` — Timeout - the server timed out while waiting for a response (90 seconds)
- `429` — Rate limit exceeded - the server has received too many requests in a short period of time
- `500` — Internal server error - the server encountered an unexpected condition that prevented it from fulfilling the request

---

[API](https://skmtc.net/hudsonrock/apis/cavalier-api.md) · [All operations](https://skmtc.net/hudsonrock/apis/cavalier-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/hudsonrock/cavalier-api/revisions/5ba0142eec4d/schema)
