개발자 참고자료

취약점 인텔리전스

DomScan API로 공개 웹사이트에서 노출된 소프트웨어, 위험한 구성, 알려진 영향 대상 버전을 찾습니다. 각 결과에는 확인한 항목, 일치한 이유, 증거의 신뢰도가 설명됩니다.

취약점 인텔리전스

공개 웹사이트에서 노출된 소프트웨어, 위험한 구성, 알려진 영향 대상 버전을 찾습니다. 각 결과에는 확인한 항목, 일치한 이유, 증거의 신뢰도가 설명됩니다.

GET /v1/vulnerabilities

쿼리 매개변수

매개변수유형설명
url 선택 사항 string 분석할 완전한 공개 HTTP(S) URL입니다. URL과 도메인을 모두 제공하면 URL이 우선됩니다.
domain 선택 사항 string 분석할 공개 도메인 또는 HTTP(S) URL입니다. URL 또는 도메인 중 하나를 제공하세요.
mode 선택 사항 string standard | deep 스캔 모드: standard는 기본값이며 8크레딧을 소비하고, deep은 격리된 JavaScript 렌더링을 추가하며 12크레딧을 소비합니다. 다른 값은 허용되지 않습니다.

권고 출처 및 범위

검증된 공개 기술 버전을 권위 있는 패키지 보안 권고, 알려진 악용 정보, 악용 확률과 연계합니다. DomScan은 영향받는 버전, 보안 구성 오류, 알 수 없는 검사 범위를 구분하므로 팀은 증거가 가장 확실한 문제부터 해결할 수 있습니다.

필드설명
checked출처가 쿼리되었으며 결과가 조사 결과에 반영되어 있습니다.
not_requested출처에 요청할 것이 없었습니다. 감지된 구성요소 중 검토된 패키지에 매핑된 버전을 가진 것이 없었으므로 권고가 쿼리되지 않았으며 CVE가 악용 출처에 도달하지 않았습니다. 이것은 범위의 한계이지, 대상이 영향을 받지 않는다는 증거가 아닙니다.
partial / failed출처가 쿼리되었지만 불완전하게 또는 전혀 응답하지 않았습니다. 영향을 받는 구성요소는 불명확한 상태로 유지되며 안전하다고 보고되지 않습니다.

예제 요청

curl -H "X-API-Key: your-api-key" "https://domscan.net/v1/vulnerabilities?domain=example.com&mode=standard"   -H "x-api-key: YOUR_API_KEY"
import requests

domscan = requests.Session()
domscan.headers.update({"X-API-Key": "your-api-key"})

response = domscan.get(
    "https://domscan.net/v1/vulnerabilities",
    params={"domain": "example.com", "mode": "deep"},
    headers={"x-api-key": "YOUR_API_KEY"},
)
result = response.json()

print(result["summary"]["posture"])
print(result["coverage"]["package_advisories"])

응답 필드

필드 유형
target object
target.requested_url string
target.final_url string
target.hostname string
scan object
scan.mode string
scan.status string
scan.checked_at string
scan.duration_ms integer
scan.disclaimer string
summary object
summary.posture string
summary.risk_level string
summary.finding_count integer
summary.version_affected_count integer
summary.misconfiguration_count integer
summary.urgent_count integer
summary.severity_counts object
findings[] object[]
findings[] object
findings[].fingerprint string
findings[].classification string
findings[].severity string
findings[].priority string
findings[].title string
findings[].summary string
findings[].component object
findings[].component.technology_id string
findings[].component.name string
findings[].component.detected_version string
findings[].component.version_kind string
findings[].component.confidence string
findings[].component.confidence_score integer
findings[].component.ecosystem string
findings[].component.package string
findings[].component.purl string
findings[].advisory object
findings[].advisory.id string
findings[].advisory.aliases[] string[]
findings[].advisory.cves[] string[]
findings[].advisory.published_at string | null
findings[].advisory.modified_at string | null
findings[].advisory.cvss[] object[]
findings[].advisory.cvss[] object
findings[].advisory.cvss[].type string
findings[].advisory.cvss[].vector string
findings[].advisory.fixed_versions[] string[]
findings[].advisory.affected_ranges[] object[]
findings[].advisory.affected_ranges[] object
findings[].advisory.references[] string[]
findings[].exploitation object
findings[].exploitation.cisa_kev boolean | null
findings[].exploitation.kev_added_at string | null
findings[].exploitation.kev_required_action string | null
findings[].exploitation.known_ransomware_use string | null
findings[].exploitation.epss_probability number | null
findings[].exploitation.epss_percentile number | null
findings[].exploitation.epss_date string | null
findings[].evidence object
findings[].evidence.confidence string
findings[].evidence.observed[] string[]
findings[].evidence.limitations[] string[]
findings[].remediation object
findings[].remediation.summary string
findings[].remediation.fixed_versions[] string[]
findings[].sources[] string[]
components[] object[]
components[] object
components[].technology_id string
components[].name string
components[].detected_version string | null
components[].version_kind string | null
components[].confidence string
components[].advisory_status string
components[].matched_advisories integer
coverage object
coverage.target_response string
coverage.technology_detection string
coverage.package_advisories string
coverage.known_exploitation string
coverage.exploitation_probability string
coverage.detected_components integer
coverage.versioned_components integer
coverage.advisory_eligible_components integer
coverage.advisory_checked_components integer
coverage.advisory_deferred_components integer
coverage.advisory_query_limit integer
coverage.relay_used boolean
coverage.limitations[] string[]
sources[] object[]
sources[] object
sources[].id string
sources[].name string
sources[].owner string
sources[].url string
sources[].status string
sources[].retrieved_at string | null
sources[].cache_hit boolean
sources[].expected_freshness string
sources[].fallback_behavior string
sources[].cost string
_meta object

예제 응답

{
  "target": {
    "requested_url": "https://example.com",
    "final_url": "https://example.com",
    "hostname": "example.com"
  },
  "scan": {
    "mode": "standard",
    "status": "complete",
    "checked_at": "2026-08-27T12:00:00Z",
    "duration_ms": 1,
    "disclaimer": "example"
  },
  "summary": {
    "posture": "action_required",
    "risk_level": "critical",
    "finding_count": 1,
    "version_affected_count": 1,
    "misconfiguration_count": 1,
    "urgent_count": 1,
    "severity_counts": {}
  },
  "findings": [
    {
      "fingerprint": "example",
      "classification": "version_affected",
      "severity": "critical",
      "priority": "urgent",
      "title": "example",
      "summary": "example",
      "evidence": {
        "confidence": "high",
        "observed": [
          "example"
        ],
        "limitations": [
          "example"
        ]
      },
      "remediation": {
        "summary": "example",
        "fixed_versions": [
          "example"
        ]
      },
      "sources": [
        "osv"
      ],
      "component": {
        "technology_id": "example",
        "name": "example",
        "detected_version": "example",
        "version_kind": "product",
        "confidence": "high",
        "confidence_score": 85,
        "ecosystem": "example",
        "package": "example",
        "purl": "https://example.com"
      },
      "advisory": {
        "id": "example-id",
        "aliases": [
          "example"
        ],
        "cves": [
          "example"
        ],
        "published_at": "2026-08-27T12:00:00Z",
        "modified_at": "2026-08-27T12:00:00Z",
        "cvss": [
          {
            "type": "domain",
            "vector": "example"
          }
        ],
        "fixed_versions": [
          "example"
        ],
        "affected_ranges": [
          {}
        ],
        "references": [
          "https://example.com"
        ]
      },
      "exploitation": {
        "cisa_kev": false,
        "kev_added_at": "2026-08-27",
        "kev_required_action": "example",
        "known_ransomware_use": "example",
        "epss_probability": 0.85,
        "epss_percentile": 0.5,
        "epss_date": "2026-08-27"
      }
    }
  ],
  "components": [
    {
      "technology_id": "example",
      "name": "example",
      "detected_version": "example",
      "version_kind": "example",
      "confidence": "high",
      "advisory_status": "checked",
      "matched_advisories": 1
    }
  ],
  "coverage": {
    "target_response": "example",
    "technology_detection": "example",
    "package_advisories": "example",
    "known_exploitation": "example",
    "exploitation_probability": "example",
    "detected_components": 1,
    "versioned_components": 1,
    "advisory_eligible_components": 1,
    "advisory_checked_components": 1,
    "advisory_deferred_components": 1,
    "advisory_query_limit": 1,
    "relay_used": false,
    "limitations": [
      "example"
    ]
  },
  "sources": [
    {
      "id": "example-id",
      "name": "example",
      "owner": "example",
      "url": "https://example.com",
      "status": "available",
      "retrieved_at": "2026-08-27T12:00:00Z",
      "cache_hit": false,
      "expected_freshness": "example",
      "fallback_behavior": "example",
      "cost": "none"
    }
  ],
  "_meta": {}
}
검사 범위와 출처: 문제가 탐지되지 않은 결과만으로 애플리케이션에 취약점이 없다고 증명하거나, 승인된 모의 침투 테스트를 대체할 수는 없습니다.

놀라운 회사의 사람들이 사용함

InstantOutseerMongoDBRespondentSage Expense ManagementInstantlyD.R. HortonWhatConvertsAdobeMotionElementsLLM Pulse