canonical: https://jentic.com/apis/shadowserver.org/shadowserver

# Shadowserver Foundation API

Shadowserver Foundation provides APIs for querying ASN/network routing data, malware information, honeypot statistics, and security reports. The API exposes 10 endpoints secured with apiKey authentication.

## For AI agents

Programmatically query asn origin for ip addresses, get malware sample information. Covers 10 operations with apiKey authentication.

## Scope

Does not handle payments, communications, or crm - use for security only.

## Capabilities

- Query ASN origin for IP addresses
- Get malware sample information
- List subscribed report lists
- Query and filter Shadowserver Foundation API records by parameters
- Monitor Shadowserver Foundation API operational status and events

## Use cases

### Security Operations

Use the Shadowserver Foundation API to perform security operations programmatically. The API provides 10 endpoints covering core functionality including query asn origin for ip addresses, get malware sample information, get honeypot cve statistics.

Example prompt: Call GET `/net/asn` to query asn origin for ip addresses

### Automated ASN Management

Automate asn operations by combining multiple Shadowserver Foundation API endpoints. Agents can get malware sample information and then get honeypot cve statistics in a single workflow.

Example prompt: Call GET `/malware/info` to get malware sample information, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Shadowserver Foundation API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey tokens manually.

Example prompt: Search Jentic for 'query asn origin for ip addresses', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/net/asn` | Query ASN origin for IP addresses |
| GET | `/malware/info` | Get malware sample information |
| POST | `/honeypot/common-vulnerabilities` | Get honeypot CVE statistics |
| POST | `/honeypot/exploited-vulnerabilities` | Get exploited vulnerability statistics |
| POST | `/honeypot/vulnerability-count` | Get vulnerability count |
| POST | `/reports/subscribed` | List subscribed report lists |
| POST | `/reports/types` | List available report types |
| POST | `/reports/list` | List available reports |

## Key resources

- **ASN** — ASN and network routing queries
- **Malware** — Malware sample information queries
- **Honeypot** — Honeypot vulnerability statistics
- **Reports** — Security reports query and management

## Why Jentic

- **Setup:** Wiring the Shadowserver Foundation API by hand means passing your apikey as a query parameter on every call to api.shadowserver.org and threading it through each report and honeypot request yourself. Through Jentic you install once, import the Shadowserver Foundation API from the API Directory, store the key once, and your agent calls it.
- **Permission scoping:** Shadowserver takes its targets in the request body rather than as path resources, so scope the agent to the operations it needs, such as querying ASN origin or listing subscribed reports, and leave out the ones it should not run.
- **Credential handling:** Your Shadowserver Foundation API key is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'query ASN origin for an IP' or 'list subscribed reports', and Jentic returns the matching Shadowserver operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Snyk** — Alternative security API
- **Crowdstrike** — Alternative security API

## FAQ

### What authentication does the Shadowserver Foundation API use?

The Shadowserver Foundation API uses an API key passed in the `apikey` query. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I query asn origin for ip addresses with the Shadowserver Foundation API?

Yes. Use the GET `/net/asn` endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Shadowserver Foundation API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I query asn origin for ip addresses through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'query asn origin for ip addresses'. Jentic returns the matching Shadowserver Foundation API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Shadowserver Foundation API have?

The Shadowserver Foundation API exposes 10 endpoints covering asn, malware, honeypot operations.

### Can I limit what my agent is allowed to do with the Shadowserver Foundation API?

Yes. Jentic One is self-hosted, so you run it yourself and your own rules decide which Shadowserver operations and credentials the agent may use. Because Shadowserver takes its targets in the request body rather than as path resources, you scope the agent to only the operations it needs, such as GET `/net/asn` to query ASN origin or POST `/reports/subscribed` to list subscribed reports. You leave out the operations it should not run, so the agent cannot reach honeypot statistics or malware lookups unless you allow them.
