-
Notifications
You must be signed in to change notification settings - Fork 2
API Reference
Base URL: http://localhost:8000
All responses follow this envelope format:
{
"success": true,
"message": "Description",
"data": { ... },
"timestamp": "2026-08-31T10:00:00"
}System health check.
curl http://localhost:8000/health{ "status": "healthy", "monitoring": true, "database": "connected" }Extended health check.
Current monitoring status.
curl http://localhost:8000/status{
"is_monitoring": true,
"current_interface": "Wi-Fi",
"alerts_generated": 47,
"monitoring_active": true
}Start packet capture and monitoring.
Stop packet capture and monitoring.
Get alerts with optional filtering.
| Query Param | Type | Description |
|---|---|---|
limit |
int | Max results (default: 100) |
offset |
int | Pagination offset |
risk_level |
string | Filter: low, medium, high, critical
|
attack_type |
string | Filter by attack type |
curl "http://localhost:8000/alerts?limit=10&risk_level=high"Get system logs.
| Query Param | Type | Description |
|---|---|---|
limit |
int | Max results |
level |
string |
INFO, WARNING, ERROR
|
curl "http://localhost:8000/logs?limit=20&level=ERROR"Get system statistics.
curl http://localhost:8000/statsReturns packet counts, attack type distribution, top IPs, protocol breakdown.
Get all blacklisted IPs.
Add IP to blacklist.
curl -X POST http://localhost:8000/blacklist \
-H "Content-Type: application/json" \
-d '{"ip_address": "198.51.100.1", "reason": "Malicious activity", "risk_level": "high"}'Remove IP from blacklist.
curl -X DELETE http://localhost:8000/blacklist/198.51.100.1Check IP reputation (JSON body).
curl -X POST http://localhost:8000/check-ip \
-H "Content-Type: application/json" \
-d '{"ip_address": "8.8.8.8"}'Check IP reputation (URL path).
curl http://localhost:8000/check-ip/8.8.8.8List all organizations.
Create a new organization.
{
"name": "Acme Security",
"slug": "acme-security",
"description": "Primary SOC org",
"plan": "enterprise"
}Suspend an organization.
Activate a suspended organization.
List all users.
Create a new user.
{
"email": "analyst@company.com",
"name": "Security Analyst",
"role": "security_analyst",
"org_id": "org-id-here"
}Update user role or status.
{ "role": "admin", "is_active": true }Delete a user.
Get audit logs with optional filtering.
| Query Param | Type | Description |
|---|---|---|
action |
string | Filter by action type |
user_id |
string | Filter by user |
date_from |
string | Start date (YYYY-MM-DD) |
date_to |
string | End date (YYYY-MM-DD) |
Record an audit event.
{
"action": "firewall_rule_created",
"resource_type": "firewall_rule",
"resource_id": "rule-42",
"details": { "port": 8080 }
}Export alerts as CSV file.
Export audit logs as CSV file.
Generate a full system report.
Real-time event stream.
const ws = new WebSocket("ws://localhost:8000/ws");
ws.onmessage = (e) => {
const msg = JSON.parse(e.data);
// msg.type: "alert" | "status" | "stats" | "log" | "connection"
};