Threat status values
The internal threat model uses these lifecycle states:activemonitoringcontainedresolveddismissedended
Severity values
criticalhighmediumlownegligible
Risk fields
Threats can carry a structured likelihood × impact assessment:likelihoodimpact_severityrisk_scorerisk_levellikelihood_rationaleimpact_rationale
Affected assets
A threat response can includeaffected_assets, which is a proximity-sorted list of monitored assets impacted by the event.
This is derived from:
- threat coordinates
- asset coordinates
- asset monitoring radius
Development and version fields
Threats can evolve over time. The API exposes summary counters that mirror the internal event development/version model:development_countlatest_development_titleversion_countlast_version_at
Incidents
Use incidents when you need a grouped narrative across related threats. Incidents are especially useful for:- operational handoff
- analyst review
- report generation
- timeline views