MVS (Managed Vulnerability Service) API
Interactive Swagger UI — click Authorize to try requests with your access key, or with an OAuth client ID/secret (see Getting API Credentials for how to generate either).
See Recent Changes for what's changed in the last 6 months.
Overview
The MVS API provides access to your organization's asset inventory and vulnerability data, aggregated across your connected sources (CrowdStrike, Microsoft Defender, Tenable, Qualys, and others). Query assets, vulnerabilities, software vulnerabilities affecting installed software, missing patches, asset confidence/risk scores, patch-priority rankings, and CISA Known Exploited Vulnerabilities (KEV) status.
Base URL: https://api.esentire.com/mvs
Most list endpoints below also have a deprecated POST variant accepting the same filters as a JSON body instead of query parameters (existing integrations only; not documented here or in the Swagger UI, and scheduled for removal — use the GET form for anything new). The asset confidence, asset scores, patch-priority ranking, and CISA KEV endpoints added in version 1.16.0 are GET-only; they never had a POST variant.
Data Fields
These tables cover the most commonly used fields on the top-level list endpoints' rows, not every field — field names are the raw Snowflake column names (ALL_CAPS) and are returned exactly as shown; there's no per-field schema in the Swagger UI to cross-reference, since these endpoints return whatever columns the underlying view exposes. Other asset subresources (/assets/{asset_id}/ports, .../network-interfaces, .../software, .../missing-patches, etc.) each return a different row shape not covered by a table below — use include_fields or inspect a sample response to see their actual fields.
Asset Fields (/assets)
| Field | Description | Example |
|---|---|---|
ASSET_ID | Unique identifier for the asset | c7e4b938-e187-46de-9bf1-d54d78a2ad7e |
ASSET_TYPE | Asset category | workstation |
HOSTNAME | Asset hostname (nullable) | null |
IPS | IP addresses associated with the asset | ["10.6.100.80"] |
TECHNOLOGIES | Connected sources reporting on this asset | ["defender"] |
HEALTH_STATUS | Per-technology agent health, keyed by technology name | {"defender": {"health_status": "Active", ...}} |
VIRTUAL_HOST | Whether the asset is a virtual host | false |
OS | Operating system | Other |
THREAT_RATING | Asset risk rating (not an enforced enum — observed values include at least LOW) | LOW |
FIRST_SEEN / LAST_SEEN | First/most recent time the asset was observed | 2026-07-06T13:23:18+00:00 |
LAST_PULLED | Last time this record was refreshed from the source technology | 2026-07-07T05:14:23.814484+00:00 |
MAC_ADDRESSES | MAC addresses associated with the asset | ["70:e4:22:85:5d:82"] |
TAGS_DATA / TAG_IDS | Custom tags applied to the asset | [{"tag_id": "...", "tag_name": "..."}] |
VULN_CRITICAL_COUNT / _HIGH_COUNT / _MEDIUM_COUNT / _LOW_COUNT / _INFO_COUNT | Count of vulnerabilities affecting this asset, by severity | 0 |
SOFTWARE_VULN_CRITICAL_COUNT / _HIGH_COUNT / _MEDIUM_COUNT / _LOW_COUNT / _UNKNOWN_COUNT | Count of software vulnerabilities affecting this asset, by severity | 0 |
RISK_SCORE / CRITICALITY_SCORE / EXPOSURE_SCORE | Computed risk metrics for the asset | 13.0 |
Vulnerability Fields (/vulnerabilities)
| Field | Description | Example |
|---|---|---|
VVID | Vulnerability identifier (usually a CVE ID) | CVE-2026-8948 |
NAME | Human-readable vulnerability title | Same-origin policy bypass in the DOM: Networking component |
SEVERITY | Severity, not an enforced enum — observed values include CRITICAL, HIGH, MEDIUM | CRITICAL |
STATE | Current state; the API description documents OPEN/FIXED as filterable values | OPEN |
CVE | Associated CVE identifier(s) | ["CVE-2026-8948"] |
CVSS2 / CVSS3 | CVSS v2/v3 scores | 10 |
TOTAL_ASSETS / OPEN_ASSETS | Count of affected assets, total and still-open | 1 |
EXPLOITABLE | Whether a known exploit exists | false |
FIRST_DISCOVERED / LAST_OBSERVED | First/most recent detection timestamp | 2026-05-19T13:55:12+00:00 |
DESCRIPTION / SOLUTION | Vulnerability description and remediation guidance | Solution exists, check details view. |
REFERENCES | External reference URLs (advisories, etc.) | ["https://..."] |
List responses from GET /vulnerabilities also include a top-level last_scanned field alongside data/paging — the RECORD_TIMESTAMP of the newest matched vulnerability record, not to be confused with the per-vulnerability LAST_OBSERVED field above (detection time, not record-refresh time). No other list endpoint (/assets, /software-vulnerabilities, /missing-patches) returns this field.
Software Vulnerability Fields (/software-vulnerabilities)
| Field | Description | Example |
|---|---|---|
CVE_ID | CVE identifier | CVE-2017-8647 |
SEVERITY | Severity, not an enforced enum — observed values include HIGH, MEDIUM | HIGH |
CVSS2 / CVSS3 | CVSS v2/v3 scores | 9 |
VENDORS | Connected sources reporting this vulnerability | ["defender", "sentinelone"] |
TOTAL_ASSETS | Count of assets with this vulnerable software installed | 34 |
ASSET_IDS / ASSET_HOSTNAMES | Affected asset identifiers/hostnames | [] |
LAST_OBSERVED | Most recent detection timestamp | 2026-08-27T03:39:18.351000+00:00 |
IS_CISA_VULNERABILITY | Whether this is on CISA's known-exploited list | false |
Missing Patch Fields (/missing-patches)
| Field | Description | Example |
|---|---|---|
MISSING_PATCH | Patch description/name | Ubuntu 20.04 LTS : OpenJDK 8 vulnerabilities (USN-8330-1) |
PATCH_TYPE | Patch category | Third Party |
ASSET_COUNT | Number of assets missing this patch | 1 |
Asset Confidence Fields (/assets-confidence, /assets/{asset_id}/confidence)
| Field | Description | Example |
|---|---|---|
ASSET_ID | Asset this confidence score belongs to | c7e4b938-e187-46de-9bf1-d54d78a2ad7e |
CONFIDENCE_SCORE | Confidence score, 0–100, based on source coverage and data recency | 87.6 |
CONFIDENCE_GRADE | Plain-language grade — observed values include High, Medium, Low, Very Low | High |
CONFIDENCE_DESCRIPTION | One-sentence explanation of the score (source type, data coverage, recency) | Confirmed by an on-host agent (esentire_agent); rich attribute coverage; last seen 42 days ago. |
Asset Scores Fields (/assets/{asset_id}/scores)
| Field | Description | Example |
|---|---|---|
CRITICALITY_SCORE / RISK_SCORE / EXPOSURE_SCORE | Same computed risk metrics as the /assets list row (see Asset Fields above), here alongside their contributing factors | 16.2 |
CRITICALITY_FACTORS / RISK_FACTORS / EXPOSURE_FACTORS | Breakdown of what drove each score — a list of objects with category, score, weight, and contribution. Nullable/empty independently of the others (e.g. a given asset can have RISK_FACTORS empty while CRITICALITY_FACTORS/EXPOSURE_FACTORS are populated) | [{"category": "asset_criticality", "score": 25, "weight": 0.6, "contribution": 15}] |
PROCESS_DATE | Date these scores were computed | 2026-05-21 |
Returns 404 if the asset doesn't exist or has no computed scores yet.
CISA KEV Fields (/cisa-kev)
| Field | Description | Example |
|---|---|---|
CVE_ID | CVE identifier | CVE-2021-44228 |
VULNERABILITY_NAME | CISA's name for the vulnerability | Apache Log4j2 Remote Code Execution Vulnerability |
SHORT_DESCRIPTION | CISA catalog description | Apache Log4j2 contains a remote code execution vulnerability... |
NOTES | JSON-encoded array (as a string) of CISA reference URLs for this CVE, not free-text notes | ["https://nvd.nist.gov/vuln/detail/CVE-2021-44228"] |
DATE_ADDED | Date the CVE was added to CISA's KEV catalog | 2021-12-10 |
ASSET_COUNT_BY_VULNS / ASSET_COUNT_BY_SW_VULNS | Count of your assets affected via /vulnerabilities vs. /software-vulnerabilities respectively | 3 |
Software-to-Patch Fields (/software-to-patch)
| Field | Description | Example |
|---|---|---|
RANK | Position in the patch-priority ranking (1 = highest priority) | 1 |
VENDOR / PRODUCT | Software vendor and product name | Apache / Log4j |
AFFECTED_ASSETS | Count of assets with this product installed | 42 |
MIN_VERSION / MAX_VERSION / DISTINCT_VERSIONS | Version spread across your fleet — only meaningful when VERSION_SCHEME_OK is true (see below) | 2.14.1 / 2.17.1 / 3 |
VERSION_SCHEME_OK | Whether the detected versions followed a comparable scheme; if false, ignore MIN_VERSION/MAX_VERSION | true |
ASSETS_ON_MIN_VERSION | Count of assets still on the oldest detected version | 30 |
CVE_COUNT / CRITICAL_CVES / HIGH_CVES / KEV_CVES | CVE counts affecting this product, total and by severity/KEV presence | 5 |
MAX_CVSS / WORST_CVE_RISK / AVG_CVE_RISK | CVSS and internal risk-score extremes/average across this product's CVEs | 10.0 |
PATCHABLE_SHARE | Share of affected assets that can be remediated by patching | 0.9 |
PATCH_PRIORITY_SCORE | Overall ranking score this row was sorted by | 91.4 |
Assets-to-Patch Fields (/assets-to-patch)
| Field | Description | Example |
|---|---|---|
RANK | Position in the patch-priority ranking (1 = highest priority) | 1 |
ASSET_ID / HOSTNAME | Asset identifier and hostname | c7e4b938-e187-46de-9bf1-d54d78a2ad7e |
OS_NAME / OS_TYPE / ASSET_TYPE | Operating system and asset category | Windows 10 |
IPS | IP addresses associated with the asset | ["10.6.100.80"] |
VULNERABLE_PRODUCTS | Count of vulnerable software products installed on this asset | 2 |
TOP_VENDOR / TOP_PRODUCT / TOP_PRODUCT_CVES | This asset's single highest-priority vendor/product and its CVE count | Apache / Log4j / 5 |
TOP_PRODUCT_VERSION / TOP_PRODUCT_FLEET_MAX / TOP_PRODUCT_MAJOR_LAG | This asset's installed version of the top product, the newest version seen fleet-wide, and how many major versions behind it is | 2.14.1 / 2.17.1 / 1 |
CVE_COUNT / CRITICAL_CVES / HIGH_CVES / KEV_CVES | CVE counts affecting this asset, total and by severity/KEV presence | 5 |
MAX_CVSS / WORST_CVE_RISK / AVG_CVE_RISK | CVSS and internal risk-score extremes/average across this asset's CVEs | 10.0 |
PATCHABLE_SHARE | Share of this asset's vulnerable software that can be remediated by patching | 0.9 |
PATCH_PRIORITY_SCORE | Overall ranking score this row was sorted by | 91.4 |
Authentication
Requests need an Authorization header carrying either an Atlas API access key or an OAuth-issued bearer token (see Getting API Credentials):
curl -H 'Authorization: <token>' 'https://api.esentire.com/mvs/assets'
read-data scope covers every endpoint below.
Endpoints
All list endpoints accept filters/sorts (JSON-encoded arrays, URL-encoded) and include_fields, plus limit/offset or page/per_page for pagination (default limit 100). GET /software-to-patch and GET /assets-to-patch additionally accept top_n (default 50, max 200) — the size of the ranked result set computed server-side, not a page size; limit/offset still page within it.
Assets
List assets — GET /assets
curl -G -H 'Authorization: <token>' \
--data-urlencode 'filters=[{"field":"THREAT_RATING","op":"eq","value":"HIGH"}]' \
'https://api.esentire.com/mvs/assets'
List asset confidence scores — GET /assets-confidence
List assets missing patches — GET /assets-missing-patches
Convenience filter over /assets for assets that have at least one missing patch.
Get asset details — GET /assets/{asset_id}
Returns 404 if the asset doesn't exist. Note: this detail response has a different, larger field set than the list row above (e.g. it includes VULN_ALL_COUNT, AD_DOMAINS, ORG_UNITS instead of the list's DOMAIN/ORGANIZATIONAL_UNIT) — don't assume the two shapes match field-for-field.
Get asset confidence score — GET /assets/{asset_id}/confidence
Returns 404 if the asset doesn't exist or has no computed confidence score yet.
List an asset's missing patches — GET /assets/{asset_id}/missing-patches
List an asset's network interfaces — GET /assets/{asset_id}/network-interfaces
List an asset's open ports — GET /assets/{asset_id}/ports
Get asset criticality/risk/exposure scores — GET /assets/{asset_id}/scores
Returns 404 if the asset doesn't exist or has no computed scores yet.
List an asset's installed software — GET /assets/{asset_id}/software
List an asset's software vulnerabilities — GET /assets/{asset_id}/software-vulnerabilities
List an asset's vulnerabilities — GET /assets/{asset_id}/vulnerabilities
Get one of an asset's vulnerabilities — GET /assets/{asset_id}/vulnerabilities/{vulnerability_id}
Missing Patches
List all missing patches — GET /missing-patches
List assets missing a specific patch — GET /missing-patches/{patch_type}/{patch_name}/assets
patch_type and patch_name must be URL-encoded (e.g. Third%20Party).
List software ranked by patch priority — GET /software-to-patch
Ranks vendor/product pairs by removable Tier III risk (version spread, CVE severity/count, KEV presence, CVSS, patchability). See top_n above.
List assets ranked by patch priority — GET /assets-to-patch
Same ranking, per-asset instead of per-product. See top_n above.
Vulnerabilities & Software Vulnerabilities
List vulnerabilities — GET /vulnerabilities
curl -G -H 'Authorization: <token>' \
--data-urlencode 'filters=[{"field":"SEVERITY","op":"eq","value":"CRITICAL"}]' \
'https://api.esentire.com/mvs/vulnerabilities'
Get vulnerability details — GET /vulnerabilities/{vulnerability_id}
List assets affected by a vulnerability — GET /vulnerabilities/{vulnerability_id}/assets
List software vulnerabilities — GET /software-vulnerabilities
Get software vulnerability details — GET /software-vulnerabilities/{cve_id}
List assets affected by a software vulnerability — GET /software-vulnerabilities/{cve_id}/assets
List CISA KEV vulnerabilities — GET /cisa-kev
Your organization's vulnerabilities that appear on CISA's Known Exploited Vulnerabilities catalog.
Health & metadata
API info — GET /info
Connectivity check — GET /test
Neither endpoint needs anything beyond a valid token.
Response Format
{
"data": [
{
"ASSET_ID": "c7e4b938-e187-46de-9bf1-d54d78a2ad7e",
"HOSTNAME": null,
"TECHNOLOGIES": ["defender"],
"IPS": ["10.6.100.80"],
"THREAT_RATING": "LOW",
"LAST_PULLED": "2026-07-07T05:14:23.814484+00:00",
"VULN_CRITICAL_COUNT": 0,
"VULN_HIGH_COUNT": 0
}
],
"paging": {
"total_count": 96,
"limit": 1,
"offset": 0
}
}
GET /vulnerabilities responses additionally include a top-level last_scanned field (see the Vulnerability Fields note above).
Related APIs
- Tickets API - Ticket and case management
- Findings API - Security findings
- Base API Reference - General API concepts