Skip to content

List findings across campaigns for a target

Request

Returns findings across campaigns of the target, newest first. Campaigns are ordered by creation time descending; findings within a campaign by execution order descending. Filter with type (failed, passed, or errors).

Campaign selection: by default only the latest finished campaign of each campaign group (an original campaign and its re-scans) is used, so a re-scan replaces the campaign it re-ran; running, errored or canceled re-scans are skipped in favor of the previous finished one. allCampaigns=true uses every campaign with results. lastNCampaigns keeps only the N newest campaigns of that selection. campaigns replaces the selection with an explicit list of campaign ids (cannot be combined with lastNCampaigns). lastN then caps the listing to the N newest findings. The next link carries every filter.

Security
bearer-key
Path
orgUuidstring, (uuid)required
applicationUuidstring, (uuid)required
projectUuidstring, (uuid)required
targetIdstring, (uuid)required
Query
prettyboolean

When true, indent the JSON body (2 spaces) and render multiline string fields (e.g. YAML config) with literal newlines for human readability. Default off (compact JSON). Intended for interactive use; omit for clients that parse the body as strict JSON.

Default:false
cursorinteger, >= 0
Default:0
limitinteger, [ 1 .. 200 ]
Default:50
typestring
Default:"failed"
Enum:"failed""passed""errors"
campaignsArray of strings, (uuid), [ 1 .. 100 ] items

Comma-separated campaign ids to list findings for, used exactly as given (allCampaigns does not apply). Sent once as a single value; each id must be a UUID, with no empty items, whitespace or duplicates (case-insensitive), at most 100 ids. Any id that does not belong to the target returns 404. Cannot be combined with lastNCampaigns. Campaigns that have no results yet contribute no findings.

lastNinteger, [ 1 .. 10000 ]

Return only the N newest findings (after the other filters). totalItems is capped at N and cursor / limit page within those N findings. Must be sent once.

lastNCampaignsinteger, [ 1 .. 200 ]

List findings from only the N newest campaigns of the default (latest per campaign group) or allCampaigns selection. Cannot be combined with campaigns. Must be sent once.

allCampaignsboolean

When true, list findings from every campaign with results (including re-scans and errored or canceled campaigns). When omitted or false, only the latest finished campaign of each campaign group (an original campaign and its re-scans) is used. Must be sent once.

Default:false
Headers
X-Correlation-IDstring, (uuid)

Optional caller-supplied correlation id. Must be a UUID when present. When omitted or blank, the API generates a UUID. A non-UUID value returns 400 CORRELATION.INVALID. If a write fails because a UUID is already in use, the API returns 409 UUID.DUPLICATE. The value used (caller or generated) is echoed as supportToken and in the X-Correlation-ID response header.

curl -i -X GET \
  'https://baseUrl/api/v3.0/redteaming/orgs/{orgUuid}/applications/{applicationUuid}/projects/{projectUuid}/targets/{targetId}/findings?pretty=false&cursor=0&limit=50&type=failed&campaigns=497f6eca-6276-4993-bfeb-53cbbbba6f08&lastN=1&lastNCampaigns=1&allCampaigns=false' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'X-Correlation-ID: 497f6eca-6276-4993-bfeb-53cbbbba6f08'

Responses

Finding collection. probeId and strategyId are human-readable probe and strategy names. gradingResult includes pass, score (finding risk score), and reason. Failed findings expose the explanation only under gradingResult.reason; top-level error appears only when type=errors. Suppressed findings count as passed. _links.suppress is present when the finding is not suppressed; _links.unsuppress when it is suppressed.

Headers
X-Correlation-IDstring, (uuid)

Correlation id used for this request (caller-supplied UUID, or a UUID generated when the request omitted the header). Same value as supportToken.

Bodyapplication/json
supportTokenstring, (uuid)(SupportToken)required

Correlation id used for this request. Same value as the X-Correlation-ID response header.

additionalDataobject(AdditionalData)required
responseArray of objects(Finding)required
Response
{ "supportToken": "5bac741e-3f1c-4cd4-ad0d-a1492df0a5cc", "additionalData": { "totalItems": "string", "cursor": 0, "next": "string" }, "response": [ { … } ] }