Skip to main content

GET /api/threats

GET 

/api/threats

The current live threats (one per hostile object), each with its rolled-up alert timeline and kill-chain stage. Carries the authored candidate plans too (the same snapshot the console's ONE poll feeds on, so the PLAN count updates as candidates land — no second poll).

Responses

the live threat board: one threat per hostile object, the executing plan, and the authored candidate set