MVS (Managed Vulnerability Service) API

Interactive Swagger UI — click Authorize to try requests with your access key, or with an OAuth client ID/secret (see Getting API Credentials for how to generate either).

See Recent Changes for what's changed in the last 6 months.

Overview

The MVS API provides access to your organization's asset inventory and vulnerability data, aggregated across your connected sources (CrowdStrike, Microsoft Defender, Tenable, Qualys, and others). Query assets, vulnerabilities, software vulnerabilities affecting installed software, missing patches, asset confidence/risk scores, patch-priority rankings, and CISA Known Exploited Vulnerabilities (KEV) status.

Base URL: https://api.esentire.com/mvs

Most list endpoints below also have a deprecated POST variant accepting the same filters as a JSON body instead of query parameters (existing integrations only; not documented here or in the Swagger UI, and scheduled for removal — use the GET form for anything new). The asset confidence, asset scores, patch-priority ranking, and CISA KEV endpoints added in version 1.16.0 are GET-only; they never had a POST variant.


Data Fields

These tables cover the most commonly used fields on the top-level list endpoints' rows, not every field — field names are the raw Snowflake column names (ALL_CAPS) and are returned exactly as shown; there's no per-field schema in the Swagger UI to cross-reference, since these endpoints return whatever columns the underlying view exposes. Other asset subresources (/assets/{asset_id}/ports, .../network-interfaces, .../software, .../missing-patches, etc.) each return a different row shape not covered by a table below — use include_fields or inspect a sample response to see their actual fields.

Asset Fields (/assets)

Field Description Example
ASSET_IDUnique identifier for the assetc7e4b938-e187-46de-9bf1-d54d78a2ad7e
ASSET_TYPEAsset categoryworkstation
HOSTNAMEAsset hostname (nullable)null
IPSIP addresses associated with the asset["10.6.100.80"]
TECHNOLOGIESConnected sources reporting on this asset["defender"]
HEALTH_STATUSPer-technology agent health, keyed by technology name{"defender": {"health_status": "Active", ...}}
VIRTUAL_HOSTWhether the asset is a virtual hostfalse
OSOperating systemOther
THREAT_RATINGAsset risk rating (not an enforced enum — observed values include at least LOW)LOW
FIRST_SEEN / LAST_SEENFirst/most recent time the asset was observed2026-07-06T13:23:18+00:00
LAST_PULLEDLast time this record was refreshed from the source technology2026-07-07T05:14:23.814484+00:00
MAC_ADDRESSESMAC addresses associated with the asset["70:e4:22:85:5d:82"]
TAGS_DATA / TAG_IDSCustom tags applied to the asset[{"tag_id": "...", "tag_name": "..."}]
VULN_CRITICAL_COUNT / _HIGH_COUNT / _MEDIUM_COUNT / _LOW_COUNT / _INFO_COUNTCount of vulnerabilities affecting this asset, by severity0
SOFTWARE_VULN_CRITICAL_COUNT / _HIGH_COUNT / _MEDIUM_COUNT / _LOW_COUNT / _UNKNOWN_COUNTCount of software vulnerabilities affecting this asset, by severity0
RISK_SCORE / CRITICALITY_SCORE / EXPOSURE_SCOREComputed risk metrics for the asset13.0

Vulnerability Fields (/vulnerabilities)

Field Description Example
VVIDVulnerability identifier (usually a CVE ID)CVE-2026-8948
NAMEHuman-readable vulnerability titleSame-origin policy bypass in the DOM: Networking component
SEVERITYSeverity, not an enforced enum — observed values include CRITICAL, HIGH, MEDIUMCRITICAL
STATECurrent state; the API description documents OPEN/FIXED as filterable valuesOPEN
CVEAssociated CVE identifier(s)["CVE-2026-8948"]
CVSS2 / CVSS3CVSS v2/v3 scores10
TOTAL_ASSETS / OPEN_ASSETSCount of affected assets, total and still-open1
EXPLOITABLEWhether a known exploit existsfalse
FIRST_DISCOVERED / LAST_OBSERVEDFirst/most recent detection timestamp2026-05-19T13:55:12+00:00
DESCRIPTION / SOLUTIONVulnerability description and remediation guidanceSolution exists, check details view.
REFERENCESExternal reference URLs (advisories, etc.)["https://..."]

List responses from GET /vulnerabilities also include a top-level last_scanned field alongside data/paging — the RECORD_TIMESTAMP of the newest matched vulnerability record, not to be confused with the per-vulnerability LAST_OBSERVED field above (detection time, not record-refresh time). No other list endpoint (/assets, /software-vulnerabilities, /missing-patches) returns this field.

Software Vulnerability Fields (/software-vulnerabilities)

Field Description Example
CVE_IDCVE identifierCVE-2017-8647
SEVERITYSeverity, not an enforced enum — observed values include HIGH, MEDIUMHIGH
CVSS2 / CVSS3CVSS v2/v3 scores9
VENDORSConnected sources reporting this vulnerability["defender", "sentinelone"]
TOTAL_ASSETSCount of assets with this vulnerable software installed34
ASSET_IDS / ASSET_HOSTNAMESAffected asset identifiers/hostnames[]
LAST_OBSERVEDMost recent detection timestamp2026-08-27T03:39:18.351000+00:00
IS_CISA_VULNERABILITYWhether this is on CISA's known-exploited listfalse

Missing Patch Fields (/missing-patches)

Field Description Example
MISSING_PATCHPatch description/nameUbuntu 20.04 LTS : OpenJDK 8 vulnerabilities (USN-8330-1)
PATCH_TYPEPatch categoryThird Party
ASSET_COUNTNumber of assets missing this patch1

Asset Confidence Fields (/assets-confidence, /assets/{asset_id}/confidence)

Field Description Example
ASSET_IDAsset this confidence score belongs toc7e4b938-e187-46de-9bf1-d54d78a2ad7e
CONFIDENCE_SCOREConfidence score, 0–100, based on source coverage and data recency87.6
CONFIDENCE_GRADEPlain-language grade — observed values include High, Medium, Low, Very LowHigh
CONFIDENCE_DESCRIPTIONOne-sentence explanation of the score (source type, data coverage, recency)Confirmed by an on-host agent (esentire_agent); rich attribute coverage; last seen 42 days ago.

Asset Scores Fields (/assets/{asset_id}/scores)

Field Description Example
CRITICALITY_SCORE / RISK_SCORE / EXPOSURE_SCORESame computed risk metrics as the /assets list row (see Asset Fields above), here alongside their contributing factors16.2
CRITICALITY_FACTORS / RISK_FACTORS / EXPOSURE_FACTORSBreakdown of what drove each score — a list of objects with category, score, weight, and contribution. Nullable/empty independently of the others (e.g. a given asset can have RISK_FACTORS empty while CRITICALITY_FACTORS/EXPOSURE_FACTORS are populated)[{"category": "asset_criticality", "score": 25, "weight": 0.6, "contribution": 15}]
PROCESS_DATEDate these scores were computed2026-05-21

Returns 404 if the asset doesn't exist or has no computed scores yet.

CISA KEV Fields (/cisa-kev)

Field Description Example
CVE_IDCVE identifierCVE-2021-44228
VULNERABILITY_NAMECISA's name for the vulnerabilityApache Log4j2 Remote Code Execution Vulnerability
SHORT_DESCRIPTIONCISA catalog descriptionApache Log4j2 contains a remote code execution vulnerability...
NOTESJSON-encoded array (as a string) of CISA reference URLs for this CVE, not free-text notes["https://nvd.nist.gov/vuln/detail/CVE-2021-44228"]
DATE_ADDEDDate the CVE was added to CISA's KEV catalog2021-12-10
ASSET_COUNT_BY_VULNS / ASSET_COUNT_BY_SW_VULNSCount of your assets affected via /vulnerabilities vs. /software-vulnerabilities respectively3

Software-to-Patch Fields (/software-to-patch)

Field Description Example
RANKPosition in the patch-priority ranking (1 = highest priority)1
VENDOR / PRODUCTSoftware vendor and product nameApache / Log4j
AFFECTED_ASSETSCount of assets with this product installed42
MIN_VERSION / MAX_VERSION / DISTINCT_VERSIONSVersion spread across your fleet — only meaningful when VERSION_SCHEME_OK is true (see below)2.14.1 / 2.17.1 / 3
VERSION_SCHEME_OKWhether the detected versions followed a comparable scheme; if false, ignore MIN_VERSION/MAX_VERSIONtrue
ASSETS_ON_MIN_VERSIONCount of assets still on the oldest detected version30
CVE_COUNT / CRITICAL_CVES / HIGH_CVES / KEV_CVESCVE counts affecting this product, total and by severity/KEV presence5
MAX_CVSS / WORST_CVE_RISK / AVG_CVE_RISKCVSS and internal risk-score extremes/average across this product's CVEs10.0
PATCHABLE_SHAREShare of affected assets that can be remediated by patching0.9
PATCH_PRIORITY_SCOREOverall ranking score this row was sorted by91.4

Assets-to-Patch Fields (/assets-to-patch)

Field Description Example
RANKPosition in the patch-priority ranking (1 = highest priority)1
ASSET_ID / HOSTNAMEAsset identifier and hostnamec7e4b938-e187-46de-9bf1-d54d78a2ad7e
OS_NAME / OS_TYPE / ASSET_TYPEOperating system and asset categoryWindows 10
IPSIP addresses associated with the asset["10.6.100.80"]
VULNERABLE_PRODUCTSCount of vulnerable software products installed on this asset2
TOP_VENDOR / TOP_PRODUCT / TOP_PRODUCT_CVESThis asset's single highest-priority vendor/product and its CVE countApache / Log4j / 5
TOP_PRODUCT_VERSION / TOP_PRODUCT_FLEET_MAX / TOP_PRODUCT_MAJOR_LAGThis asset's installed version of the top product, the newest version seen fleet-wide, and how many major versions behind it is2.14.1 / 2.17.1 / 1
CVE_COUNT / CRITICAL_CVES / HIGH_CVES / KEV_CVESCVE counts affecting this asset, total and by severity/KEV presence5
MAX_CVSS / WORST_CVE_RISK / AVG_CVE_RISKCVSS and internal risk-score extremes/average across this asset's CVEs10.0
PATCHABLE_SHAREShare of this asset's vulnerable software that can be remediated by patching0.9
PATCH_PRIORITY_SCOREOverall ranking score this row was sorted by91.4

Authentication

Requests need an Authorization header carrying either an Atlas API access key or an OAuth-issued bearer token (see Getting API Credentials):

curl -H 'Authorization: <token>' 'https://api.esentire.com/mvs/assets'

read-data scope covers every endpoint below.


Endpoints

All list endpoints accept filters/sorts (JSON-encoded arrays, URL-encoded) and include_fields, plus limit/offset or page/per_page for pagination (default limit 100). GET /software-to-patch and GET /assets-to-patch additionally accept top_n (default 50, max 200) — the size of the ranked result set computed server-side, not a page size; limit/offset still page within it.

Assets

List assets — GET /assets

View in Swagger UI →

curl -G -H 'Authorization: <token>' \
  --data-urlencode 'filters=[{"field":"THREAT_RATING","op":"eq","value":"HIGH"}]' \
  'https://api.esentire.com/mvs/assets'

List asset confidence scores — GET /assets-confidence

View in Swagger UI →

List assets missing patches — GET /assets-missing-patches

Convenience filter over /assets for assets that have at least one missing patch.

View in Swagger UI →

Get asset details — GET /assets/{asset_id}

Returns 404 if the asset doesn't exist. Note: this detail response has a different, larger field set than the list row above (e.g. it includes VULN_ALL_COUNT, AD_DOMAINS, ORG_UNITS instead of the list's DOMAIN/ORGANIZATIONAL_UNIT) — don't assume the two shapes match field-for-field.

View in Swagger UI →

Get asset confidence score — GET /assets/{asset_id}/confidence

Returns 404 if the asset doesn't exist or has no computed confidence score yet.

View in Swagger UI →

List an asset's missing patches — GET /assets/{asset_id}/missing-patches

View in Swagger UI →

List an asset's network interfaces — GET /assets/{asset_id}/network-interfaces

View in Swagger UI →

List an asset's open ports — GET /assets/{asset_id}/ports

View in Swagger UI →

Get asset criticality/risk/exposure scores — GET /assets/{asset_id}/scores

Returns 404 if the asset doesn't exist or has no computed scores yet.

View in Swagger UI →

List an asset's installed software — GET /assets/{asset_id}/software

View in Swagger UI →

List an asset's software vulnerabilities — GET /assets/{asset_id}/software-vulnerabilities

View in Swagger UI →

List an asset's vulnerabilities — GET /assets/{asset_id}/vulnerabilities

View in Swagger UI →

Get one of an asset's vulnerabilities — GET /assets/{asset_id}/vulnerabilities/{vulnerability_id}

View in Swagger UI →

Missing Patches

List all missing patches — GET /missing-patches

View in Swagger UI →

List assets missing a specific patch — GET /missing-patches/{patch_type}/{patch_name}/assets

patch_type and patch_name must be URL-encoded (e.g. Third%20Party).

View in Swagger UI →

List software ranked by patch priority — GET /software-to-patch

Ranks vendor/product pairs by removable Tier III risk (version spread, CVE severity/count, KEV presence, CVSS, patchability). See top_n above.

View in Swagger UI →

List assets ranked by patch priority — GET /assets-to-patch

Same ranking, per-asset instead of per-product. See top_n above.

View in Swagger UI →

Vulnerabilities & Software Vulnerabilities

List vulnerabilities — GET /vulnerabilities

View in Swagger UI →

curl -G -H 'Authorization: <token>' \
  --data-urlencode 'filters=[{"field":"SEVERITY","op":"eq","value":"CRITICAL"}]' \
  'https://api.esentire.com/mvs/vulnerabilities'

Get vulnerability details — GET /vulnerabilities/{vulnerability_id}

View in Swagger UI →

List assets affected by a vulnerability — GET /vulnerabilities/{vulnerability_id}/assets

View in Swagger UI →

List software vulnerabilities — GET /software-vulnerabilities

View in Swagger UI →

Get software vulnerability details — GET /software-vulnerabilities/{cve_id}

View in Swagger UI →

List assets affected by a software vulnerability — GET /software-vulnerabilities/{cve_id}/assets

View in Swagger UI →

List CISA KEV vulnerabilities — GET /cisa-kev

Your organization's vulnerabilities that appear on CISA's Known Exploited Vulnerabilities catalog.

View in Swagger UI →

Health & metadata

API info — GET /info

View in Swagger UI →

Connectivity check — GET /test

View in Swagger UI →

Neither endpoint needs anything beyond a valid token.


Response Format

{
  "data": [
    {
      "ASSET_ID": "c7e4b938-e187-46de-9bf1-d54d78a2ad7e",
      "HOSTNAME": null,
      "TECHNOLOGIES": ["defender"],
      "IPS": ["10.6.100.80"],
      "THREAT_RATING": "LOW",
      "LAST_PULLED": "2026-07-07T05:14:23.814484+00:00",
      "VULN_CRITICAL_COUNT": 0,
      "VULN_HIGH_COUNT": 0
    }
  ],
  "paging": {
    "total_count": 96,
    "limit": 1,
    "offset": 0
  }
}

GET /vulnerabilities responses additionally include a top-level last_scanned field (see the Vulnerability Fields note above).


Related APIs