Skip to content

Scans API

Cree, gestione y monitoree escaneos de vulnerabilidades de forma programática.

Endpoints

MétodoEndpointDescripción
GET/api/v1/scansListar todos los escaneos
POST/api/v1/scansCrear un nuevo escaneo
GET/api/v1/scans/{id}Obtener detalles de escaneo
DELETE/api/v1/scans/{id}Cancelar/eliminar escaneo
GET/api/v1/scans/{id}/findingsObtener hallazgos de escaneo

Listar Escaneos

Recupere todos los escaneos de su organización.

bash
GET /api/v1/scans

Parámetros de Consulta

ParámetroTipoDescripción
pageintegerNúmero de página (predeterminado: 1)
per_pageintegerElementos por página (predeterminado: 20, máx: 100)
statusstringFiltrar por estado: pending, running, completed, failed
targetstringFiltrar por dominio objetivo
from_datestringFiltrar escaneos después de fecha (ISO 8601)
to_datestringFiltrar escaneos antes de fecha (ISO 8601)

Respuesta

json
{
  "items": [
    {
      "id": "scan_abc123",
      "target": "example.com",
      "scan_type": "full",
      "status": "completed",
      "progress": 100,
      "phase": "complete",
      "created_at": "2025-12-21T10:00:00Z",
      "completed_at": "2025-12-21T10:45:00Z",
      "vulnerabilities_found": 12,
      "critical_count": 1,
      "high_count": 3,
      "medium_count": 5,
      "low_count": 3
    }
  ],
  "total": 45,
  "page": 1,
  "per_page": 20,
  "pages": 3
}

Crear Escaneo

Inicie un nuevo escaneo de vulnerabilidades.

bash
POST /api/v1/scans
Content-Type: application/json

Cuerpo de Solicitud

json
{
  "target": "example.com",
  "scan_type": "full",
  "frameworks": ["soc2", "pci-dss"],
  "ports": "1-1000",
  "authorized": true
}

Parámetros

CampoTipoRequeridoDescripción
targetstringDominio, IP o rango CIDR
scan_typestringNoquick, full, o compliance (predeterminado: full)
frameworksarrayNoFrameworks de cumplimiento a verificar
portsstringNoRango de puertos (predeterminado: puertos comunes)
authorizedbooleanCertificación de autorización de escaneo

Tipos de Escaneo

TipoDuraciónCobertura
quick5-10 minPrincipales vulnerabilidades, puertos comunes
full30-60 minLas 11 fases, cobertura completa
compliance15-30 minVerificaciones específicas de framework

Respuesta

json
{
  "id": "scan_xyz789",
  "target": "example.com",
  "scan_type": "full",
  "status": "pending",
  "created_at": "2025-12-21T14:00:00Z",
  "estimated_duration": 2700
}

Obtener Detalles de Escaneo

Recupere detalles de un escaneo específico.

bash
GET /api/v1/scans/{scan_id}

Respuesta

json
{
  "id": "scan_abc123",
  "target": "example.com",
  "scan_type": "full",
  "status": "running",
  "progress": 45,
  "phase": "vulnerability_scanning",
  "current_tool": "nuclei",
  "created_at": "2025-12-21T10:00:00Z",
  "started_at": "2025-12-21T10:01:00Z",
  "phases_completed": [
    "discovery",
    "enumeration"
  ],
  "phases_remaining": [
    "vulnerability_scanning",
    "web_analysis",
    "cloud_analysis",
    "threat_intelligence",
    "correlation",
    "ai_analysis",
    "remediation_planning",
    "reporting"
  ]
}

Cancelar Escaneo

Detenga un escaneo en ejecución.

bash
DELETE /api/v1/scans/{scan_id}

Respuesta

json
{
  "id": "scan_abc123",
  "status": "cancelled",
  "message": "Scan cancelled successfully"
}

Obtener Hallazgos de Escaneo

Recupere vulnerabilidades encontradas durante un escaneo.

bash
GET /api/v1/scans/{scan_id}/findings

Parámetros de Consulta

ParámetroTipoDescripción
severitystringFiltrar: critical, high, medium, low, info
statusstringFiltrar: open, in_progress, resolved, false_positive

Respuesta

json
{
  "items": [
    {
      "id": "finding_123",
      "title": "SQL Injection in Login Form",
      "severity": "critical",
      "cvss_score": 9.8,
      "status": "open",
      "tool": "sqlmap",
      "affected_component": "https://example.com/login",
      "description": "...",
      "remediation": "...",
      "cve_ids": ["CVE-2024-1234"],
      "detected_at": "2025-12-21T10:30:00Z"
    }
  ],
  "total": 12
}

Cuota de Escaneos

Verifique la cuota de escaneos restante.

bash
GET /api/v1/scans/quota

Respuesta

json
{
  "plan": "professional",
  "monthly_limit": 150,
  "used_this_month": 45,
  "remaining": 105,
  "resets_at": "2026-01-01T00:00:00Z"
}

Escaneos Programados

Professional y Enterprise

Los escaneos programados están disponibles en los planes Professional y Enterprise.

Crear Programación

bash
POST /api/v1/scans/schedules
Content-Type: application/json

{
  "target": "example.com",
  "scan_type": "full",
  "frequency": "weekly",
  "day_of_week": 1,
  "hour": 2,
  "timezone": "UTC"
}

Listar Programaciones

bash
GET /api/v1/scans/schedules

Eliminar Programación

bash
DELETE /api/v1/scans/schedules/{schedule_id}

Webhooks para Escaneos

Regístrese para recibir notificaciones de eventos de escaneo:

bash
POST /api/v1/webhooks
Content-Type: application/json

{
  "url": "https://your-server.com/webhook",
  "events": [
    "scan.started",
    "scan.completed",
    "scan.failed",
    "vulnerability.critical"
  ]
}

Límites de Tasa

PlanEscaneos ConcurrentesEscaneos/Mes
Startup125
Professional3150
EnterpriseIlimitadoIlimitado

Updated at:

Agentic AI-Powered Security & Compliance