GET /api/threats
GET/api/threats
The current live threats (one per hostile object), each with its rolled-up alert timeline and kill-chain stage. Carries the authored candidate plans too (the same snapshot the console's ONE poll feeds on, so the PLAN count updates as candidates land — no second poll).
Responses
- 200
the live threat board: one threat per hostile object, the executing plan, and the authored candidate set