Skip to main content

The current live threats (one per hostile object), each with its rolled-up alert timeline and kill-chain stage.

GET 

/api/threats

Carries the authored candidate plans too (the same snapshot the console's ONE poll feeds on, so the PLAN count updates as candidates land — no second poll).

Responses​

the live threat board: one threat per hostile object, the executing plan, and the authored candidate set