API Catalog
Introduction
The API Catalog displays statistics about the API traffic to the sites in your environment under ThreatX protection. It lists all the known sites, their endpoints, any threats or attacks, type of attack, and the number of times API traffic at a site matched a rule. You can view details about a specific site and then view details about a single endpoint within the site.
If your account has the Sensitive Data feature, the ThreatX platform monitors API responses to detect various data types as shown in the following table. The metrics within the API Catalog indicate the data type, counts and which sites and endpoints are exposing the data.
Data Type | Classification |
---|---|
Bearer Token |
Authentication Credentials |
Credit Card â AMEX |
Payment Card Industry Data Security Standard (PCI-DSS) |
Credit Card â Diners Club |
Payment Card Industry Data Security Standard (PCI-DSS) |
Credit Card â Discover |
Payment Card Industry Data Security Standard (PCI-DSS) |
Credit Card â JCB |
Payment Card Industry Data Security Standard (PCI-DSS) |
Credit Card â Maestro |
Payment Card Industry Data Security Standard (PCI-DSS) |
Credit Card â MasterCard |
Payment Card Industry Data Security Standard (PCI-DSS) |
Credit Card â Visa |
Payment Card Industry Data Security Standard (PCI-DSS) |
Individual Taxpayer Identification Number (ITIN) |
Personally Identifiable Information (PII) |
Passport â Next Gen |
Personally Identifiable Information (PII) |
Social Security Number |
Personally Identifiable Information (PII) |
|
The catalog displays changes over time so that you can determine if there are any trends that need attention. |
Over time, the number of endpoints in the API Catalog might change as the ThreatX API Profiler confirms endpoints or determines that an endpoint was inaccurate. The API Profiler is a function within the ThreatX Sensor that detects, categorizes, and archives API traffic patterns for later analysis within the ThreatX platform.
Site Details
You can click a site to see API traffic details for that site. The page focuses on one site and its endpoints and includes the following:
-
Rule matches compared to blocked request over time
-
Total Blocked requests
-
Total Requests
-
Sensitive data detections
Any percentages are change over time. |
Endpoint Details
You can click an endpoint to see API traffic details for that endpoint. The page displays data specific to one endpoint.
The navigation bar includes all the endpoints and number of rule matches. You can navigate to different endpoints to view their details.
If you see traffic that should be monitored, click Request a Rule to request that the ThreatX SOC write a rule for a specific situation. |