---
title: "Appendix D: Infoblox Threat Defense API Guide"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35406336/Appendix%20D%3A%20Infoblox%20Threat%20Defense%20API%20Guide"
format: markdown
---
Infoblox Threat Defense uses Swagger to publish and deliver its APIs. For a list of available APIs, first log in to the <span style="color: #172b4d">Infoblox</span> Portal, and then click the following link:*[ ](https://csp.infoblox.com/apidoc)*

<span style="color: #000000">Below is a list of currently supported calls along with their descriptions.</span><span style="color: #3e3f40"> </span>

## <span style="color: #000000">Infoblox Anycast API </span>

### <span style="color: #000000">**ANYCAST API **</span>

> ℹ️ ### ANYCAST API
> ℹ️ 
> ℹ️ <span style="color: #000000">Detailed information for the </span><span style="color: #000000">**ANYCAST API**</span><span style="color: #000000"> can be viewed on at</span>  
> ℹ️ <span style="color: #000000">[Infoblox Anycast Swagger API Guide](https://csp.infoblox.com/apidoc/?url=https%3A%2F%2Fcsp.infoblox.com%2Fapidoc%2Fdocs%2FAnycast)</span>

*Anycast capability enables HA (High Availability) configuration of Infoblox applications that run on equipment located on customer’s premises (on-prem hosts). Anycast supports DNS, as well as DNS-forwarding services.*

*Anycast-enabled application setups use multiple on-premises installations for one particular application type. Multiple application instances are configured to use the same endpoint address. Anycast capability is collocated with such application instance, monitoring the local application instance and advertising to the upstream router (a customer equipment) a per-instance, local route to the common application endpoint address, as long as the local application instance is available. Depending on the type of the upstream router, the customer may configure local route advertisement via either BGP (Boarder Gateway Protocol) or OSPF (Open Shortest Path First) routing protocols. Both protocols may be enabled as well. Multiple routes to the common application service address provide redundancy without the need to reconfigure application clients.*

*Should an application instance become unavailable, the local route advertisements stop, resulting in withdrawal of the route (in the upstream router) to the application instance that has gone out of service and ensuring that subsequent application requests thus get routed to the remaining available application instances.*

## <span style="color: #000000">Infoblox FW API (Infoblox Threat Defense)</span>

### **FW API**

> ℹ️ ### FW API
> ℹ️ 
> ℹ️ Detailed information for the **Infoblox** **FW API** can be viewed on at  
> ℹ️ <span style="color: #0000ff">[Infoblox FW Swagger API Guide](https://csp.infoblox.com/apidoc/?url=https://csp.infoblox.com/apidoc/docs/Atcfw)</span>

Infoblox Threat Defense is an extension of the Infoblox <span style="color: #000000">Platform</span> that provides visibility into infected and compromised off-premises devices, roaming users, remote sites, and branch offices. You can subscribe to Infoblox Infoblox Threat Defense and use its functionality to mitigate and control malware as well as provide unprecedented insight into your network security posture and enable timely action. Infoblox <span style="color: #000000">Platform</span> also offers unified policy management, reporting, and threat analytics across the entire spectrum. Using automated and high-quality threat intelligence feeds and unique behavioral analytics, it automatically stops device communications with C&Cs/botnets and prevents DNS based data exfiltration.

The mission-critical DNS infrastructure can become a vulnerable component in your network when it is inadequately protected by traditional security solutions and consequently used as an attack surface. Compromised DNS services can result in catastrophic network and system failures. To fully protect your network in today’s cyber security threat environment, Infoblox sets a new DNS security standard by offering scalable, enterprise-grade, and integrated protection for your DNS infrastructure.

Through the Infoblox Portal, you can view the status of your subscription and threat intelligence feeds, manage your network scope and roaming end users, and learn more about threats on your networks through the Infoblox Threat Lookup tool and predefined reports.

## <span style="color: #000000">Infoblox Endpoint API</span>

### **ENDPOINT API**

> ℹ️ ### EP API
> ℹ️ 
> ℹ️ Detailed information for the **Infoblox Endpoint API **can be viewed on at   
> ℹ️ [Infoblox Endpoint Swagger API Guide](https://csp.infoblox.com/apidoc/?url=https://csp.infoblox.com/apidoc/docs/Atcep)

Infoblox Endpoint is a lightweight mobile agent that redirects DNS traffic from your remote devices to Infoblox Threat Defense. It allows you to apply applicable security policies to your roaming end users in remote sites and branch offices.

In order for end users to connect to Infoblox services, you must download and install Infoblox Endpoint on their devices. The client enforces security policies that are applied to remote networks, regardless of where your end users are located, and to which networks they are connected. Infoblox Endpoint listens on port 53 of the device. If other software listens on the same port, DNS traffic cannot be redirected to Infoblox Threat Defense, and your device will not be protected by Infoblox Endpoint.

When you use Infoblox Endpoint, DNS queries are sent to Infoblox Threat Defense directly except for (1) queries that target the bypassed domains and (2) internal domains collected through the DHCP server. If you have internal domains that are served by your local DNS servers and you want to reach them without interruptions, you should consider adding them to the bypassed internal domains list so that DNS queries for these internal domains are sent to the local DNS servers instead of Infoblox Threat Defense.

Infoblox Endpoint supports dual-stack IPv4 and IPv6 DNS configurations, thereby protecting all devices regardless of their network environments. Infoblox Endpoint in a dual-stack environment is able to proxy IPv6 DNS queries and forward them to Infoblox <span style="color: #000000">Platform</span> over IPv4.

## <span style="color: #000000">Infoblox Platform DNS Forwarding Proxy API (DNS Forwarding Policy)</span>

### **DNS Forwarding Proxy API**

> ℹ️ ### DNS Forwarding Proxy API
> ℹ️ 
> ℹ️ Detailed information for the **Infoblox Platform DNS Forwarding Proxy API **can be viewed on at  
> ℹ️ [Infoblox DNS Forwarding Proxy Swagger API Guide](https://csp.infoblox.com/apidoc/?url=https://csp.infoblox.com/apidoc/docs/Atcdfp)

  
Infoblox <span style="color: #000000">Platform</span> is a SaaS offering designed to provide protection to devices on and off-premises, including roaming, remote, and branch offices. It provides visibility into infected and compromised devices, prevents DNS-based data exfiltration, and automatically stops device communications with command-and-control servers (C&Cs) and botnets, in addition to providing recursive DNS services in the cloud. You can access the services by deploying Endpoint agent or the DNS Forwarding Proxy.

For remote office deployments, or in cases where installing an endpoint agent is not desirable or possible, you can use the DNS Forwarding Proxy. It is a software application that runs on bare-metal, VM infrastructures, or Infoblox NIOS appliances, and embeds the client IPs in DNS queries before forwarding them to Infoblox <span style="color: #000000">Platform</span>. The communications are encrypted and client visibility is maintained. The proxy also provides DNS resolution to local DNS zones when you configure local resolvers. Once you set up a DNS Forwarding Proxy, it becomes the main DNS server for your remote site. It will also cache responses to speed resolution of future queries.

By implementing the DNS Forwarding Proxy, you can rest assured that Infoblox <span style="color: #000000">Platform</span> effectively enforces DNS client-based security policies at your remote sites. On-premises devices that send DNS queries reveal their actual client IP addresses (instead of their NAT IP address), thus allowing Infoblox <span style="color: #000000">Platform</span> to apply the security policies applicable to the respective endpoints and identify infected clients.

## <span style="color: #000000">Infoblox LAD API (Infoblox Lookalike Domains)</span>

### **LAD API**

> ℹ️ ### LAD API
> ℹ️ 
> ℹ️ Detailed information for the **LAD API **can be viewed on at  
> ℹ️ [Infoblox Lookalike Domains Swagger API Guide](https://csp.infoblox.com/apidoc/?url=https%3A%2F%2Fcsp.infoblox.com%2Fapidoc%2Fdocs%2FTdlad)

Infoblox LAD is an extension of the Infoblox <span style="color: #000000">Platform</span> that provides lookalike domains detection. You can subscribe to Infoblox LAD and use its functionality to protect domains from spoofing threats.

## <span style="color: #000000">Infoblox Dossier API (Dossier and TIDE)</span>

### **Dossier API**

> ℹ️ ### Dossier API
> ℹ️ 
> ℹ️ Detailed information for the **Dossier API **can be viewed on at  
> ℹ️ [Infoblox Dossier Swagger API Guide](https://csp.infoblox.com/apidoc/?url=https%3A%2F%2Fcsp.infoblox.com%2Fapidoc%2Fdocs%2FTIDEDossier)

<span style="color: #3b4151">Dossier, sometimes referred to as Intel Lookup, is a threat research tool that provides contextual information from multiple sources simultaneously for a given indicator. The APIs listed below allow a user to search on specific sources and view the results that they return.</span>


## <span style="color: #000000">TIDE Data Service API (TIDE Data)</span>

### **TIDE Data API**

> ℹ️ ### TIDE Data Service API
> ℹ️ 
> ℹ️ Detailed information for the **TIDE Data API **can be viewed on at  
> ℹ️ [Infoblox TIDE Swagger API Guide](https://csp.infoblox.com/apidoc/?url=https%3A%2F%2Fcsp.infoblox.com%2Fapidoc%2Fdocs%2FTIDEData)

The heart of TIDE is the threats submitted by the Infoblox Cyber Intelligence group and external partners.

There are two main categories of bulk threat data retrievable in TIDE: threat state and threats by age. Threat state consists of records that are considered current threats, that is, threats that have not expired and have not been superseded by newer threats for the same indicator (host name, IP address, URL, hash, or email). Threats by age consists of all threats submitted in a specified time period.

If the same indicator was submitted by a data provider four times in one day, a threats-by-age call for daily results would return four records, while a threat state call would return only one, the most recent one submitted.

TIDE threat data is generally event oriented. Sometimes it is necessary instead to see threats by their current state, that is, threats that have not expired and have not been superseded by newer threats for the same indicator (host name, IP address, URL, hash, or email).

The materialized threat state objects contain the current active threats for all indicators of the specified record type. Threat state objects are materialized multiple times an hour.


> ⚠️ ### Note
> ⚠️ 
> ⚠️ **API key expiration notification**: <span style="color: #000000">The maximum expiration time for an API key is 56 weeks or 13 months. </span>You will receive notification when your API key is about to expire. A new API key will need to be created to replace the expiring key. To create a new API key, select the expiring API key from the list of API keys and remove it by clicking **Disable** followed by **Delete**. To create a new API key to replace an expiring api key, see *[How Do I Create an API Key](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/230394187)*.


<span style="color: #3e3f40">**Additional API Resources**</span>

Listed below are additional API resources.

- <u><span style="color: #0000ff">*[DNS Event](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35437944)*</span></u>