Performs paginated search of high-risk lookalike domains with advanced filtering, sorting, and pagination.
Filter Pattern
Filters follow the pattern: {field}[{operator}]={value}
Available Fields
String/Keyword Fields
Operators: contains, equals, is, startsWith, endsWith, isEmpty, isNotEmpty, isAnyOf, not_equal, is_not, not, not_contain, isNotAnyOf
Fields: id, domain, unicodeDomain, looks_like, similarity, dmarc_status, ns_records, apexDomain, matchBasedOn, industry, source, origin, dns_providers, agenticTag, classification, tags, keywords, annotations, face_annotations, ns_records_list, dns_providers_list
Boolean Fields
Values: true, false, any
Fields: email_ready, reputation, web_presence, riskBump, read, is_subdomain, has_screenshot, has_annotations, has_face_annotations, has_detected_keywords, reportedAsFalsePositive, in_takedown, flagged_by_google_safe_browsing, hasSubdomailer, manuallyAdded, hasNotes, detected_emails
Numeric Fields
Operators: equals, equalOrLargerThan, largerThan, lessThan, lessThanOrEqual, between
Fields: traffic_rank, risk_rating, new_risk_rating, numThreatEmails
Date Fields (YYYY-MM-DD format)
Operators: is, not, after, onOrAfter, before, onOrBefore, isEmpty, isNotEmpty
Fields: observed_date, updated_at, lastScanCrux, deletionCountdownSince
Examples
- String:
unicodeDomain[contains]=threat&similarity[equals]=very-high - Boolean:
flagged_by_google_safe_browsing[eq]=true&in_takedown[eq]=false&email_ready[eq]=true - Numeric:
new_risk_rating[equalOrLargerThan]=8&numThreatEmails[largerThan]=0 - Date:
observed_date[after]=2024-01-01&deletionCountdownSince[isEmpty]=true - Arrays:
classification[isAnyOf]=list[phishing,malware]&keywords[contains]=login
Sorting
_sortColumn=[field,ordering] (e.g., _sortColumn=[new_risk_rating,desc])
Pagination
Use page and pageSize parameters
Combining Filters
Use linkOperator=and (all must match) or linkOperator=or (any must match)
