# Aegister S.p.A. ## Docs - [Blocked requests over the last 7 days](https://docs.aegister.com/api-reference/atb/blocked-requests-over-the-last-7-days.md): Returns a daily count of denied requests for the specified ATB instance over the last 7 days. - [Create Threat Blocker configuration](https://docs.aegister.com/api-reference/atb/create-threat-blocker-configuration.md): Create a new Threat Blocker configuration in the Web Application. You can create only Threat Blocker configurations for organizations you can manage. - [Delete Threat Blocker configuration](https://docs.aegister.com/api-reference/atb/delete-threat-blocker-configuration.md): Soft delete an Threat Blocker configuration from the Web Application. You can delete only Threat Blocker configurations for organizations you can manage. - [Get ATB store window](https://docs.aegister.com/api-reference/atb/get-atb-store-window.md): Retrieve aggregated traffic window statistics for a Threat Blocker device. - [Get Threat Blocker configuration](https://docs.aegister.com/api-reference/atb/get-threat-blocker-configuration.md): Get an Threat Blocker configuration from the Web Application. You can retrieve only Threat Blocker configurations for organizations you can manage. - [Get Threat Blocker traffic statistics](https://docs.aegister.com/api-reference/atb/get-threat-blocker-traffic-statistics.md): Get traffic statistics for an Threat Blocker. Returns the most frequently occurring source and destination IPs, top denied traffic patterns, and top communicators overall. - [List Threat Blocker configurations](https://docs.aegister.com/api-reference/atb/list-threat-blocker-configurations.md): Retrieves Threat Blocker list configured in the Web Application. The list contains only Threat Blocker for organizations you can manage. - [List Threat Blocker traffic logs](https://docs.aegister.com/api-reference/atb/list-threat-blocker-traffic-logs.md): Retrieve Threat Blocker traffic logs from the Web Application. You can retrieve only Threat Blocker traffic logs for organizations you can manage. - [Most blocked source IPs](https://docs.aegister.com/api-reference/atb/most-blocked-source-ips.md): Returns the top 3 source IPs most frequently blocked (inbound traffic) in the last 7 days for the specified ATB instance. - [Post ATB store window](https://docs.aegister.com/api-reference/atb/post-atb-store-window.md): Ingest a batch of traffic log entries and aggregate them into time-bucketed statistics. - [Retrieve latest traffic logs for a specific device](https://docs.aegister.com/api-reference/atb/retrieve-latest-traffic-logs-for-a-specific-device.md): Returns up to 1000 of the most recent traffic log entries for a given ATB device ID, sorted in descending order by timestamp. Each entry includes metadata such as source and destination IPs, firewall rule, direction, and whether the request was considered malicious or blocked. - [Retrieve latest traffic logs for a specific device](https://docs.aegister.com/api-reference/atb/retrieve-latest-traffic-logs-for-a-specific-device-1.md): Returns up to 1000 of the most recent traffic log entries for a given ATB device ID, sorted in descending order by timestamp. Each entry includes metadata such as source and destination IPs, firewall rule, direction, and whether the request was considered malicious or blocked. - [Retrieve traffic statistics for a specific ATB device](https://docs.aegister.com/api-reference/atb/retrieve-traffic-statistics-for-a-specific-atb-device.md): Returns aggregated traffic logs (total and blocked requests) grouped into fixed time buckets within the last N minutes. - [Traffic stats per crime level](https://docs.aegister.com/api-reference/atb/traffic-stats-per-crime-level.md): Returns aggregated traffic logs for a specific ATB device, grouped by crime level (low, medium, high) over a specified time window. - [Update Threat Blocker configuration](https://docs.aegister.com/api-reference/atb/update-threat-blocker-configuration.md): Edit an Threat Blocker configuration in the Web Application. You can edit only Threat Blocker configurations for organizations you can manage. - [Upload Threat Blocker traffic logs](https://docs.aegister.com/api-reference/atb/upload-threat-blocker-traffic-logs.md): Create Threat Blocker traffic logs in the Web Application. You can create only Threat Blocker traffic logs for organizations you can manage. - [Upload Threat Blocker traffic v2](https://docs.aegister.com/api-reference/atb/upload-threat-blocker-traffic-v2.md): Ingest traffic log entries into the Elasticsearch index for a Threat Blocker device. - [Upload Threat Blocker traffic v2](https://docs.aegister.com/api-reference/atb/upload-threat-blocker-traffic-v2-1.md): Ingest traffic log entries into the Elasticsearch index for a Threat Blocker device. - [Authentication](https://docs.aegister.com/api-reference/authentication.md): Authentication methods supported by our API. - [Create Cloud Defender configuration](https://docs.aegister.com/api-reference/cloud-defender/create-cloud-defender-configuration.md): Create a new Cloud Defender configuration in the Web Application. You can create only Cloud Defender configurations for organizations you can manage. - [Delete Cloud Defender configuration](https://docs.aegister.com/api-reference/cloud-defender/delete-cloud-defender-configuration.md): Soft delete a Cloud Defender configuration from the Web Application. You can delete only a Cloud Defender configuration for an organizations you can manage. - [Get Cloud Defender configuration](https://docs.aegister.com/api-reference/cloud-defender/get-cloud-defender-configuration.md): Get a Cloud Defender configuration from the Web Application. You can retrieve only a Cloud Defender configuration for an organization you can manage. - [Get Cloud Defender traffic logs](https://docs.aegister.com/api-reference/cloud-defender/get-cloud-defender-traffic-logs.md): Retrieve Cloud Defender traffic logs from the Web Application. You can retrieve only Cloud Defender traffic logs for organizations you can manage. - [List Cloud Defender configurations](https://docs.aegister.com/api-reference/cloud-defender/list-cloud-defender-configurations.md): Retrieves Cloud Defender list configured in the Web Application. The list contains only Cloud Defenders for organizations you can manage. - [Update Cloud Defender configuration](https://docs.aegister.com/api-reference/cloud-defender/update-cloud-defender-configuration.md): Edit a Cloud Defender configuration in the Web Application. You can edit only a Cloud Defender configuration for an organization you can manage. - [Upload Cloud Defender traffic logs](https://docs.aegister.com/api-reference/cloud-defender/upload-cloud-defender-traffic-logs.md): Create Cloud Defender traffic logs in the Web Application. You can create only Cloud Defender traffic logs for organizations you can manage. - [Download a document version](https://docs.aegister.com/api-reference/cyber-assurance-•-documents/download-a-document-version.md): Returns the file content as a base64-encoded JSON response. - [List document versions for an artifact](https://docs.aegister.com/api-reference/cyber-assurance-•-documents/list-document-versions-for-an-artifact.md): Returns all stored versions of documents uploaded for a specific artifact (control/question) within a workflow. - [Upload a new document version](https://docs.aegister.com/api-reference/cyber-assurance-•-documents/upload-a-new-document-version.md): Upload a file as base64 JSON. Deduplicates by SHA256 checksum — if the same content already exists for this artifact, returns the existing version (200) instead of creating a new one (201). Trims old versions beyond 10 per artifact. - [Associate workflow to organization](https://docs.aegister.com/api-reference/cyber-assurance-•-workflows/associate-workflow-to-organization.md): Associate a workflow ID and name with an organization. - [Disassociate workflow from organization](https://docs.aegister.com/api-reference/cyber-assurance-•-workflows/disassociate-workflow-from-organization.md): Soft-disassociate a workflow from an organization. - [Proxy: fetch workflow data (GET only)](https://docs.aegister.com/api-reference/cyber-assurance-•-workflows/proxy:-fetch-workflow-data-get-only.md): Proxies a GET request to The workflow webhook sync endpoint. All query parameters are forwarded as-is, except `workflow_id` which is taken from the path. If `action` is not provided, it defaults to `get_framework`. Ensures `organization_id` is present (from path if not supplied). - [Download document](https://docs.aegister.com/api-reference/documents/download-document.md): Retrieve Document. This API serves documents for Security Framework self evaluations. - [Get incident taxonomy](https://docs.aegister.com/api-reference/incidents/get-incident-taxonomy.md): Retrieve the incident taxonomy, optionally filtered by predicate and search query. - [Create log analysis](https://docs.aegister.com/api-reference/log-analysis/create-log-analysis.md): Create a new analysis with enhanced validation - [Delete log analysis](https://docs.aegister.com/api-reference/log-analysis/delete-log-analysis.md): Deletes a log-analysis - [Get log analysis](https://docs.aegister.com/api-reference/log-analysis/get-log-analysis.md): Retrieves a log-analysis - [List log analyses](https://docs.aegister.com/api-reference/log-analysis/list-log-analyses.md): Retrieves all log-analysis - [List notifications](https://docs.aegister.com/api-reference/notifications/list-notifications.md): Retrieve authenticated user's Notifications. - [Mark notifications as read](https://docs.aegister.com/api-reference/notifications/mark-notifications-as-read.md): Edit current authenticated user's Notification. This endpoint doesn't actually edits Notification content, just sets it to read. - [Add user to organization](https://docs.aegister.com/api-reference/organizations/add-user-to-organization.md): Create Organization's user. The authenticated user can add the user to the organization if is part of the organization and has Owner priviledges. After the user has been added to the organization, an invitation email will be sent. - [Create organization](https://docs.aegister.com/api-reference/organizations/create-organization.md): Create a new Organization. The current authenticated user becomes the Organization Owner. - [Create organization subscription](https://docs.aegister.com/api-reference/organizations/create-organization-subscription.md): Create Organization's Subscription - [Create workflow evaluation](https://docs.aegister.com/api-reference/organizations/create-workflow-evaluation.md): Save a workflow evaluation result — allows multiple evaluations - [Delete organization](https://docs.aegister.com/api-reference/organizations/delete-organization.md): Soft delete an Organization. The authenticated user can delete only an Organization is part of and has Owner priviledges. - [Delete organization logo](https://docs.aegister.com/api-reference/organizations/delete-organization-logo.md): Remove the logo and favicon for an organization. Clears the logo_url and favicon_url from branding data and removes the files from storage. - [Delete organization subscription](https://docs.aegister.com/api-reference/organizations/delete-organization-subscription.md): Soft delete Organization's Subscription - [Delete workflow evaluations](https://docs.aegister.com/api-reference/organizations/delete-workflow-evaluations.md): Hard delete all workflow evaluations for a specific workflow_id - [Get organization](https://docs.aegister.com/api-reference/organizations/get-organization.md): Retrieve the Organization. The authenticated user can retrieve only an organization is part of. - [Get organization branding](https://docs.aegister.com/api-reference/organizations/get-organization-branding.md): Retrieve branding settings for an organization. Returns the branding object from organization.data, or default values if no branding has been configured. - [Get organization workflow associations](https://docs.aegister.com/api-reference/organizations/get-organization-workflow-associations.md): Retrieve workflow associations for a specific organization. - [List organization subscriptions](https://docs.aegister.com/api-reference/organizations/list-organization-subscriptions.md): Retrieve Organization's Subscription list. - [List organization users](https://docs.aegister.com/api-reference/organizations/list-organization-users.md): Retrieve Organization's user list. The authenticated user can retrieve the user list if is part of the organization and has at least Security Officer priviledges. - [List organizations](https://docs.aegister.com/api-reference/organizations/list-organizations.md): Retrieve Organization list. The list contains only Organizations the current authenticated user is part of. - [List workflow evaluations](https://docs.aegister.com/api-reference/organizations/list-workflow-evaluations.md): Retrieve active workflow evaluation results. Optional: ?latest=N to fetch only the N most recent evaluations. - [Remove user from organization](https://docs.aegister.com/api-reference/organizations/remove-user-from-organization.md): Soft delete an Organization's user. The authenticated user can remove the user from the organization if is part of the organization and has Owner priviledges. - [Update organization](https://docs.aegister.com/api-reference/organizations/update-organization.md): Edit an Organization. The authenticated user can edit only and organization is part of and has at least Security Officer priviledges. - [Update organization branding](https://docs.aegister.com/api-reference/organizations/update-organization-branding.md): Update branding settings for an organization. Accepts: - palette: One of 'blue', 'purple', 'teal', 'green', 'orange', 'red', 'indigo', 'pink', 'slate', 'custom' - custom_colors: Object with primary, primary_hover, primary_dark hex colors Only super_admin users can update branding. - [Update organization subscription](https://docs.aegister.com/api-reference/organizations/update-organization-subscription.md): Edit Organization's Subscription - [Update organization user role](https://docs.aegister.com/api-reference/organizations/update-organization-user-role.md): Create Organization's user. The authenticated user can edit the user in the organization if is part of the organization and has Owner priviledges. - [Update workflow evaluation](https://docs.aegister.com/api-reference/organizations/update-workflow-evaluation.md): Update an existing workflow evaluation's evaluation_data. Request body: { "id": , "evaluation_data": {...} } - [Upload organization logo](https://docs.aegister.com/api-reference/organizations/upload-organization-logo.md): Upload a logo for an organization. Accepts PNG, JPG, or SVG files up to 2MB. Automatically generates: - Resized logo (max 400x400) - Favicon (32x32) Updates the organization's branding data with the new URLs. - [Check domain threat intelligence](https://docs.aegister.com/api-reference/perimeter-protection/check-domain-threat-intelligence.md): Retrieves Threat Intelligence Domain check. Provided by OneFirewall - [Check file threat intelligence](https://docs.aegister.com/api-reference/perimeter-protection/check-file-threat-intelligence.md): Retrieves Threat Intelligence File digest check. Provided by OneFirewall - [Check IP threat intelligence](https://docs.aegister.com/api-reference/perimeter-protection/check-ip-threat-intelligence.md): Retrieves Threat Intelligence IPv4 check. Provided by OneFirewall - [Check URL threat intelligence](https://docs.aegister.com/api-reference/perimeter-protection/check-url-threat-intelligence.md): Retrieve Threat Intelligence URL check. Provided by OneFirewall - [Get threat intelligence domain list](https://docs.aegister.com/api-reference/perimeter-protection/get-threat-intelligence-domain-list.md): Retrieve Threat Intelligence Domain list. Provided by OneFirewall - [Get threat intelligence IP list](https://docs.aegister.com/api-reference/perimeter-protection/get-threat-intelligence-ip-list.md): Retrieve Threat Intelligence IPv4 list. Provided by OneFirewall - [Search](https://docs.aegister.com/api-reference/search/search.md): Retrieve items based on keyword filter. - [Get apiv1terms](https://docs.aegister.com/api-reference/terms/get-apiv1terms.md): GET /api/v1/terms — returns current terms version and acceptance status. - [Post apiv1termsaccept](https://docs.aegister.com/api-reference/terms/post-apiv1termsaccept.md): POST /api/v1/terms/accept — record terms acceptance. - [Token](https://docs.aegister.com/api-reference/token.md): Steps to create a new authentication token for accessing the API. - [Proxy: fetch a single workflow document](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-fetch-a-single-workflow-document.md): GET /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/document/{artifactId} - [Proxy: fetch a single workflow question](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-fetch-a-single-workflow-question.md): GET /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/questions/{qid} - [Proxy: fetch workflow documents list](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-fetch-workflow-documents-list.md): GET /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/documents-list - [Proxy: fetch workflow framework](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-fetch-workflow-framework.md): GET /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/framework - [Proxy: fetch workflow report](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-fetch-workflow-report.md): GET /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/report - [Proxy: fetch workflow step data](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-fetch-workflow-step-data.md): GET /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/steps/{stepId} - [Proxy: fetch workflow tasks view](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-fetch-workflow-tasks-view.md): GET /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/tasks - [Proxy: generic Activepieces action forwarder](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-generic-activepieces-action-forwarder.md): GET/POST .../proxy?action=X&... Generic Activepieces proxy — accepts any action and query parameters. - [Proxy: generic Activepieces action forwarder (POST)](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-generic-activepieces-action-forwarder-post.md): GET/POST .../proxy?action=X&... Generic Activepieces proxy — accepts any action and query parameters. - [Proxy: request workflow translation](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-request-workflow-translation.md): POST /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/translate - [Proxy: submit workflow evaluation / scoring](https://docs.aegister.com/api-reference/v-ciso-•-workflows/proxy:-submit-workflow-evaluation-scoring.md): POST /api/v1/v-ciso/organizations/{oid}/workflows/{wid}/evaluate - [Create incident](https://docs.aegister.com/api-reference/v-ciso/create-incident.md): Create a new incident notification for an organization. - [Create workflow evaluation](https://docs.aegister.com/api-reference/v-ciso/create-workflow-evaluation.md): Save a workflow evaluation result — allows multiple evaluations - [Delete incident](https://docs.aegister.com/api-reference/v-ciso/delete-incident.md): Delete a draft incident notification. - [Delete incident attachment](https://docs.aegister.com/api-reference/v-ciso/delete-incident-attachment.md): DELETE /api/v1/v-ciso/incidents/{organizationid}/{incidentid}/attachments/{attachmentid} - [Delete workflow evaluations](https://docs.aegister.com/api-reference/v-ciso/delete-workflow-evaluations.md): Hard delete all workflow evaluations for a specific workflow_id - [Download incident attachment](https://docs.aegister.com/api-reference/v-ciso/download-incident-attachment.md): Download an incident attachment as base64-encoded content. - [Enrich incident with threat intelligence](https://docs.aegister.com/api-reference/v-ciso/enrich-incident-with-threat-intelligence.md): Look up threat intelligence for a list of indicators (IPs, domains, URLs, hashes). - [Generate incident report template](https://docs.aegister.com/api-reference/v-ciso/generate-incident-report-template.md): Generate an incident notification template using the rule engine. - [Get incident](https://docs.aegister.com/api-reference/v-ciso/get-incident.md): Retrieve a single incident notification by ID. - [Get incident taxonomy](https://docs.aegister.com/api-reference/v-ciso/get-incident-taxonomy.md): Retrieve the incident taxonomy, optionally filtered by predicate and search query. - [Get organization workflow associations](https://docs.aegister.com/api-reference/v-ciso/get-organization-workflow-associations.md): Retrieve workflow associations for a specific organization. - [List incident attachments](https://docs.aegister.com/api-reference/v-ciso/list-incident-attachments.md): List all attachments for an incident. - [List incidents](https://docs.aegister.com/api-reference/v-ciso/list-incidents.md): List all incident notifications for an organization. - [List workflow associations](https://docs.aegister.com/api-reference/v-ciso/list-workflow-associations.md): Retrieve all workflow associations across organizations. - [List workflow evaluations](https://docs.aegister.com/api-reference/v-ciso/list-workflow-evaluations.md): Retrieve active workflow evaluation results. Optional: ?latest=N to fetch only the N most recent evaluations. - [Update incident](https://docs.aegister.com/api-reference/v-ciso/update-incident.md): Partially update an incident notification. - [Update workflow evaluation](https://docs.aegister.com/api-reference/v-ciso/update-workflow-evaluation.md): Update an existing workflow evaluation's evaluation_data. Request body: { "id": , "evaluation_data": {...} } - [Upload incident attachment](https://docs.aegister.com/api-reference/v-ciso/upload-incident-attachment.md): Upload a file attachment to an incident. - [Create VPN profile](https://docs.aegister.com/api-reference/vpn/create-vpn-profile.md): Insert new VPN profile. - [Delete VPN profile](https://docs.aegister.com/api-reference/vpn/delete-vpn-profile.md): Soft delete a VPN profile. You can delete only VPN profiles you have created. - [Get VPN profile](https://docs.aegister.com/api-reference/vpn/get-vpn-profile.md): Retrieves VPN Profile by id. You can get only VPN profiles you have created. - [List VPN profiles](https://docs.aegister.com/api-reference/vpn/list-vpn-profiles.md): Retrieves all VPN profiles assigned to the user - [Creazione account e primo accesso](https://docs.aegister.com/documentation/it/acc/how-get-account.md): Guida per la registrazione e l'accesso alla Aegister Cyber Console (ACC) in base al metodo di autenticazione. - [Introduzione](https://docs.aegister.com/documentation/it/acc/what-is-acc.md): Scopri la piattaforma integrata per la sicurezza informatica offerta da Aegister. - [FAQ](https://docs.aegister.com/documentation/it/atb/faq.md): Frequently Asked Questions sul servizio ATB - [Come Funziona](https://docs.aegister.com/documentation/it/atb/how-atb-works.md): Guida al funzionamento di ATB: modalità in serie e in parallelo per soddisfare le diverse esigenze di protezione perimetrale. - [Come Attivare (Installazione Parallelo)](https://docs.aegister.com/documentation/it/atb/how-to-get-started.md): Guida passo-passo per l'attivazione e il collegamento di Aegister Threat Blocker alla tua infrastruttura di sicurezza. - [Introduzione](https://docs.aegister.com/documentation/it/atb/what-is-atb.md): Scopri Aegister Threat Blocker, il dispositivo all-in-one per la protezione della sicurezza perimetrale aziendale. - [FAQs](https://docs.aegister.com/documentation/it/cloud-defender/faq.md): Frequently Asked Questions - [Come Funziona](https://docs.aegister.com/documentation/it/cloud-defender/how-it-works.md): Scopri il funzionamento del sistema Cloud Defender, che integra Cloud WAF e OneFirewall Threat Prevention per analizzare e proteggere il traffico web. - [Come Attivarlo](https://docs.aegister.com/documentation/it/cloud-defender/how-to-get-started.md): Guida alla procedura di attivazione e configurazione di Aegister Cloud Defender per proteggere la tua applicazione web. - [Introduzione](https://docs.aegister.com/documentation/it/cloud-defender/what-is-cloud-defender.md): Scopri Aegister Cloud Defender, il Web Application Firewall (WAF) avanzato per proteggere le applicazioni web dalle minacce comuni e mitigare i principali rischi OWASP. - [FAQs](https://docs.aegister.com/documentation/it/faq.md): Di seguito sono riportate le domande più frequenti sull'utilizzo dell'app Aegister. - [Chi siamo](https://docs.aegister.com/documentation/it/introduzione.md) - [Servizi](https://docs.aegister.com/documentation/it/servizi.md): Panoramica dei servizi di cybersecurity offerti da Aegister, con particolare attenzione alla protezione aziendale attraverso soluzioni integrate e strumenti avanzati. - [Come iniziare](https://docs.aegister.com/documentation/it/vciso/how-to-get-started.md): Guida rapida per iniziare a utilizzare i servizi inerenti il Virtual CISO attraverso la piattaforma ACC. - [Introduzione](https://docs.aegister.com/documentation/it/vciso/what-is-vciso.md): Scopri il servizio Virtual CISO di Aegister, il partner strategico per la sicurezza informatica senza l'onere di un CISO full-time. - [Come attivare la VPN](https://docs.aegister.com/documentation/it/vpn/how-to-get-started.md): Guida passo-passo per l'attivazione di Aegister VPN: dall'acquisto della licenza alla registrazione degli utenti. - [Introduzione](https://docs.aegister.com/documentation/it/vpn/what-is-vpn.md): Scopri AegisterVPN, la soluzione avanzata per la protezione dei dati e per connessioni sicure e criptate su dispositivi mobili. ## OpenAPI Specs - [schema](https://app.aegister.com/api/v1/schema/)