ThreatPrevent
ThreatPrevent
Cyber Trust Intelligence
POST/v1/infrastructure-risk

Infrastructure Risk API

Evaluate an IP address as part of infrastructure validation, exposure assessment and security investigation workflows.

Common use cases

Asset validationInfrastructure inventoriesSecurity investigationsExternal exposure reviews
Single request

Check one IP address

Send a JSON object containing ip.

cURL
curl -X POST https://api.threatprevent.io/v1/infrastructure-risk \
  -H "Content-Type: application/json" \
  -H "x-api-key: YOUR_API_KEY" \
  -d '{"ip":"8.8.8.8"}'
Example response
200 OK
{
  "endpoint": "infrastructure-risk",
  "risk": "low",
  "risk_score": 20,
  "source_type": "infrastructure_scan",
  "target": "hashed-or-normalised-target",
  "charged": true,
  "is_free": false,
  "unit_price_pence": 25,
  "billable_units": 1,
  "total_price_pence": 25,
  "charged_from_credit_pence": 25,
  "overage_pence": 0,
  "remaining_credit_pence": 2475
}
Try it

Interactive API explorer

Response
Response will appear here.
The API key stays in this browser component state and is sent directly to the ThreatPrevent API.
POST/v1/infrastructure-risk/bulk

Bulk Infrastructure Risk

Submit up to 10,000 IP addresss in one HTTP request. Billing is calculated by records processed.

cURL
curl -X POST https://api.threatprevent.io/v1/infrastructure-risk/bulk \
  -H "Content-Type: application/json" \
  -H "x-api-key: YOUR_API_KEY" \
  -d '{"ips":["8.8.8.8","1.1.1.1","9.9.9.9"]}'
Illustrative bulk response
{
  "results": [
    {
      "ip": "8.8.8.8",
      "risk": "low"
    },
    {
      "ip": "1.1.1.1",
      "risk": "medium"
    },
    {
      "ip": "9.9.9.9",
      "risk": "low"
    }
  ],
  "charged": true,
  "is_free": false,
  "unit_price_pence": 25,
  "billable_units": 3,
  "total_price_pence": 75,
  "charged_from_credit_pence": 75,
  "overage_pence": 0
}
Try it

Interactive API explorer

Response
Response will appear here.
The API key stays in this browser component state and is sent directly to the ThreatPrevent API.

Risk interpretation

Low

No significant risk signal identified from the intelligence currently available.

Medium

A risk signal warrants additional review before making the decision.

High

Significant risk indicators are present and the decision should be escalated.

High

Escalate the infrastructure for investigation.

Medium

Review the infrastructure context and supporting evidence.

Low

Proceed according to your normal infrastructure controls.

Decision-support notice

Threat intelligence is time-sensitive and cannot provide visibility of every threat. Risk results should be used as an additional decision signal rather than as the sole control for critical business decisions.