includeTotal: true, so
you get the number without paging through every result.
Throughout, exclude deleted detections with
{ "property": "deleted", "operator": "notIn", "value": ["deleted"] }, because
/detection/list includes them by default.
How many confirmed threats do we have?
A confirmed threat is an asset ChainPatrol reviewed and blocked. If protection is not active for your organization, confirmed threats are held as Pending Blocked instead of being enforced, but they are still confirmed. Include both.metrics.newThreats is the all-time count, with domainThreats, twitterThreats,
telegramThreats and otherThreats as the breakdown. To list them from your
detections:
newThreats also counts threats you reported yourself
that no detector produced. To list every confirmed threat regardless of source, use
/threats/list with includePending: true and an early startDate.
How many detections for domains do we have?
total counts detections. Several detections can point at the same domain, so
de-duplicate by asset.id if you need unique domains.
How many watchlisted domains are there?
assetType for the whole watchlist. That total matches
threatsWatchlisted in /metrics/summary. Each item’s reason says why it is being
watched (DEAD, PARKING, NOT_ENOUGH_EVIDENCE, …).
How many detections are over 80% (or 90%) confidence?
Use the rawscore cut-off, not the confidence filter. Confidence levels are
bucketed from the score with your organization’s own thresholds, so "high" is not a
fixed percentage.
minScore is inclusive. Change it to 0.9 for the 90% question, and page with
nextCursor to list every match.
From the CLI or an AI agent
The same questions with the ChainPatrol CLI:detections list totals
include them. Use the API requests above when the exact number matters.
The ChainPatrol MCP server includes a detection_evaluation prompt that runs all of
these for an organization and reports the counts.