개발자 참고자료
취약점 인텔리전스
DomScan API로 공개 웹사이트에서 노출된 소프트웨어, 위험한 구성, 알려진 영향 대상 버전을 찾습니다. 각 결과에는 확인한 항목, 일치한 이유, 증거의 신뢰도가 설명됩니다.
취약점 인텔리전스
공개 웹사이트에서 노출된 소프트웨어, 위험한 구성, 알려진 영향 대상 버전을 찾습니다. 각 결과에는 확인한 항목, 일치한 이유, 증거의 신뢰도가 설명됩니다.
GET
/v1/vulnerabilities
쿼리 매개변수
| 매개변수 | 유형 | 설명 |
|---|---|---|
| url 선택 사항 | string | 분석할 완전한 공개 HTTP(S) URL입니다. URL과 도메인을 모두 제공하면 URL이 우선됩니다. |
| domain 선택 사항 | string | 분석할 공개 도메인 또는 HTTP(S) URL입니다. URL 또는 도메인 중 하나를 제공하세요. |
| mode 선택 사항 | string standard | deep |
스캔 모드: standard는 기본값이며 8크레딧을 소비하고, deep은 격리된 JavaScript 렌더링을 추가하며 12크레딧을 소비합니다. 다른 값은 허용되지 않습니다. |
권고 출처 및 범위
검증된 공개 기술 버전을 권위 있는 패키지 보안 권고, 알려진 악용 정보, 악용 확률과 연계합니다. DomScan은 영향받는 버전, 보안 구성 오류, 알 수 없는 검사 범위를 구분하므로 팀은 증거가 가장 확실한 문제부터 해결할 수 있습니다.
| 필드 | 설명 |
|---|---|
checked | 출처가 쿼리되었으며 결과가 조사 결과에 반영되어 있습니다. |
not_requested | 출처에 요청할 것이 없었습니다. 감지된 구성요소 중 검토된 패키지에 매핑된 버전을 가진 것이 없었으므로 권고가 쿼리되지 않았으며 CVE가 악용 출처에 도달하지 않았습니다. 이것은 범위의 한계이지, 대상이 영향을 받지 않는다는 증거가 아닙니다. |
partial / failed | 출처가 쿼리되었지만 불완전하게 또는 전혀 응답하지 않았습니다. 영향을 받는 구성요소는 불명확한 상태로 유지되며 안전하다고 보고되지 않습니다. |
예제 요청
curl -H "X-API-Key: your-api-key" "https://domscan.net/v1/vulnerabilities?domain=example.com&mode=standard" -H "x-api-key: YOUR_API_KEY"
import requests
domscan = requests.Session()
domscan.headers.update({"X-API-Key": "your-api-key"})
response = domscan.get(
"https://domscan.net/v1/vulnerabilities",
params={"domain": "example.com", "mode": "deep"},
headers={"x-api-key": "YOUR_API_KEY"},
)
result = response.json()
print(result["summary"]["posture"])
print(result["coverage"]["package_advisories"])
응답 필드
| 필드 | 유형 |
|---|---|
target |
object |
target.requested_url |
string |
target.final_url |
string |
target.hostname |
string |
scan |
object |
scan.mode |
string |
scan.status |
string |
scan.checked_at |
string |
scan.duration_ms |
integer |
scan.disclaimer |
string |
summary |
object |
summary.posture |
string |
summary.risk_level |
string |
summary.finding_count |
integer |
summary.version_affected_count |
integer |
summary.misconfiguration_count |
integer |
summary.urgent_count |
integer |
summary.severity_counts |
object |
findings[] |
object[] |
findings[] |
object |
findings[].fingerprint |
string |
findings[].classification |
string |
findings[].severity |
string |
findings[].priority |
string |
findings[].title |
string |
findings[].summary |
string |
findings[].component |
object |
findings[].component.technology_id |
string |
findings[].component.name |
string |
findings[].component.detected_version |
string |
findings[].component.version_kind |
string |
findings[].component.confidence |
string |
findings[].component.confidence_score |
integer |
findings[].component.ecosystem |
string |
findings[].component.package |
string |
findings[].component.purl |
string |
findings[].advisory |
object |
findings[].advisory.id |
string |
findings[].advisory.aliases[] |
string[] |
findings[].advisory.cves[] |
string[] |
findings[].advisory.published_at |
string | null |
findings[].advisory.modified_at |
string | null |
findings[].advisory.cvss[] |
object[] |
findings[].advisory.cvss[] |
object |
findings[].advisory.cvss[].type |
string |
findings[].advisory.cvss[].vector |
string |
findings[].advisory.fixed_versions[] |
string[] |
findings[].advisory.affected_ranges[] |
object[] |
findings[].advisory.affected_ranges[] |
object |
findings[].advisory.references[] |
string[] |
findings[].exploitation |
object |
findings[].exploitation.cisa_kev |
boolean | null |
findings[].exploitation.kev_added_at |
string | null |
findings[].exploitation.kev_required_action |
string | null |
findings[].exploitation.known_ransomware_use |
string | null |
findings[].exploitation.epss_probability |
number | null |
findings[].exploitation.epss_percentile |
number | null |
findings[].exploitation.epss_date |
string | null |
findings[].evidence |
object |
findings[].evidence.confidence |
string |
findings[].evidence.observed[] |
string[] |
findings[].evidence.limitations[] |
string[] |
findings[].remediation |
object |
findings[].remediation.summary |
string |
findings[].remediation.fixed_versions[] |
string[] |
findings[].sources[] |
string[] |
components[] |
object[] |
components[] |
object |
components[].technology_id |
string |
components[].name |
string |
components[].detected_version |
string | null |
components[].version_kind |
string | null |
components[].confidence |
string |
components[].advisory_status |
string |
components[].matched_advisories |
integer |
coverage |
object |
coverage.target_response |
string |
coverage.technology_detection |
string |
coverage.package_advisories |
string |
coverage.known_exploitation |
string |
coverage.exploitation_probability |
string |
coverage.detected_components |
integer |
coverage.versioned_components |
integer |
coverage.advisory_eligible_components |
integer |
coverage.advisory_checked_components |
integer |
coverage.advisory_deferred_components |
integer |
coverage.advisory_query_limit |
integer |
coverage.relay_used |
boolean |
coverage.limitations[] |
string[] |
sources[] |
object[] |
sources[] |
object |
sources[].id |
string |
sources[].name |
string |
sources[].owner |
string |
sources[].url |
string |
sources[].status |
string |
sources[].retrieved_at |
string | null |
sources[].cache_hit |
boolean |
sources[].expected_freshness |
string |
sources[].fallback_behavior |
string |
sources[].cost |
string |
_meta |
object |
예제 응답
{
"target": {
"requested_url": "https://example.com",
"final_url": "https://example.com",
"hostname": "example.com"
},
"scan": {
"mode": "standard",
"status": "complete",
"checked_at": "2026-08-27T12:00:00Z",
"duration_ms": 1,
"disclaimer": "example"
},
"summary": {
"posture": "action_required",
"risk_level": "critical",
"finding_count": 1,
"version_affected_count": 1,
"misconfiguration_count": 1,
"urgent_count": 1,
"severity_counts": {}
},
"findings": [
{
"fingerprint": "example",
"classification": "version_affected",
"severity": "critical",
"priority": "urgent",
"title": "example",
"summary": "example",
"evidence": {
"confidence": "high",
"observed": [
"example"
],
"limitations": [
"example"
]
},
"remediation": {
"summary": "example",
"fixed_versions": [
"example"
]
},
"sources": [
"osv"
],
"component": {
"technology_id": "example",
"name": "example",
"detected_version": "example",
"version_kind": "product",
"confidence": "high",
"confidence_score": 85,
"ecosystem": "example",
"package": "example",
"purl": "https://example.com"
},
"advisory": {
"id": "example-id",
"aliases": [
"example"
],
"cves": [
"example"
],
"published_at": "2026-08-27T12:00:00Z",
"modified_at": "2026-08-27T12:00:00Z",
"cvss": [
{
"type": "domain",
"vector": "example"
}
],
"fixed_versions": [
"example"
],
"affected_ranges": [
{}
],
"references": [
"https://example.com"
]
},
"exploitation": {
"cisa_kev": false,
"kev_added_at": "2026-08-27",
"kev_required_action": "example",
"known_ransomware_use": "example",
"epss_probability": 0.85,
"epss_percentile": 0.5,
"epss_date": "2026-08-27"
}
}
],
"components": [
{
"technology_id": "example",
"name": "example",
"detected_version": "example",
"version_kind": "example",
"confidence": "high",
"advisory_status": "checked",
"matched_advisories": 1
}
],
"coverage": {
"target_response": "example",
"technology_detection": "example",
"package_advisories": "example",
"known_exploitation": "example",
"exploitation_probability": "example",
"detected_components": 1,
"versioned_components": 1,
"advisory_eligible_components": 1,
"advisory_checked_components": 1,
"advisory_deferred_components": 1,
"advisory_query_limit": 1,
"relay_used": false,
"limitations": [
"example"
]
},
"sources": [
{
"id": "example-id",
"name": "example",
"owner": "example",
"url": "https://example.com",
"status": "available",
"retrieved_at": "2026-08-27T12:00:00Z",
"cache_hit": false,
"expected_freshness": "example",
"fallback_behavior": "example",
"cost": "none"
}
],
"_meta": {}
}
검사 범위와 출처:
문제가 탐지되지 않은 결과만으로 애플리케이션에 취약점이 없다고 증명하거나, 승인된 모의 침투 테스트를 대체할 수는 없습니다.

