Catalogs API

HTTP reference for CWE, ATT&CK techniques, approval classes and report-profile field descriptors.

All paths are relative to https://api.aleex-rank.ai/api/v2 and authenticate with X-API-Key: rk_... (see REST API). Catalogs are read-only reference data used when writing RoE, mapping findings and configuring report profiles.

CWE

GET /catalogs/cwe
GET /catalogs/cwe/{cweId}

List is paginated (page, per_page). Filter with q (name or cwe_id substring). mapping=allowed restricts the list to CWEs findings may be mapped to. detail=full includes description and extended_description; the default list is compact.

GET /catalogs/cwe?q=injection&mapping=allowed&detail=full&page=1&per_page=20
{
  "success": true,
  "data": {
    "items": [
      {
        "cwe_id": "CWE-89",
        "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
        "abstraction": "Base",
        "status": "Stable",
        "mapping_usage": "Allowed",
        "url": "https://cwe.mitre.org/data/definitions/89.html",
        "cwe_version": "4.16",
        "description": "The product constructs all or part of an SQL command using externally-influenced input..."
      }
    ],
    "pagination": {"total": 1, "count": 1, "per_page": 20, "current_page": 1, "total_pages": 1}
  }
}

{cweId} is the full id, for example CWE-89:

GET /catalogs/cwe/CWE-89
{
  "success": true,
  "data": {
    "cwe_id": "CWE-89",
    "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
    "abstraction": "Base",
    "status": "Stable",
    "mapping_usage": "Allowed",
    "url": "https://cwe.mitre.org/data/definitions/89.html",
    "cwe_version": "4.16",
    "description": "The product constructs all or part of an SQL command using externally-influenced input...",
    "extended_description": "..."
  }
}

Unknown ids return 404.

ATT&CK techniques

GET /catalogs/attack-techniques
GET /catalogs/attack-techniques/{techniqueId}

Ids match the RoE allowed_techniques / forbidden_techniques format: Txxxx or Txxxx.xxx. Filter the list with tactic — the exact stored tactic name, for example Initial Access (not a slug). detail=full adds description. Paginate with page and per_page.

GET /catalogs/attack-techniques?tactic=Initial%20Access&detail=full
{
  "success": true,
  "data": {
    "items": [
      {
        "technique_id": "T1190",
        "name": "Exploit Public-Facing Application",
        "is_subtechnique": false,
        "parent_technique_id": null,
        "tactics": ["Initial Access"],
        "platforms": ["PRE"],
        "url": "https://attack.mitre.org/techniques/T1190/",
        "attack_version": "16.1",
        "description": "Adversaries may attempt to exploit a weakness in an Internet-facing application..."
      }
    ],
    "pagination": {"total": 1, "count": 1, "per_page": 20, "current_page": 1, "total_pages": 1}
  }
}
GET /catalogs/attack-techniques/T1059.001
{
  "success": true,
  "data": {
    "technique_id": "T1059.001",
    "name": "PowerShell",
    "is_subtechnique": true,
    "parent_technique_id": "T1059",
    "tactics": ["Execution"],
    "platforms": ["Windows", "Linux", "macOS"],
    "description": "Adversaries may abuse PowerShell commands and scripts for execution..."
  }
}

Use these ids in Engagement & RoE allow/forbid lists.

Approval classes

GET /catalogs/approval-classes

The closed set of classes a RoE may list in requires_approval_for. The same ids appear as available_approval_classes on GET /pentests/{id}/roe.

{
  "success": true,
  "data": {
    "items": [
      {"id": "shell", "description": "Interactive or one-shot shell commands (shell_tool)"},
      {"id": "script", "description": "Interpreter scripts (script_tool)"},
      {"id": "destructive", "description": "Shell or script whose payload looks destructive (rm -rf, DROP TABLE, and similar)"},
      {"id": "exploit", "description": "Active exploitation tools (sqlmap, commix, hydra, metasploit, and similar)"},
      {"id": "scope_expansion", "description": "Widening the active RoE of a pentest that is already running"},
      {"id": "low_scope_confidence", "description": "An action whose target could not be confidently matched to the authorised scope"}
    ],
    "total": 6
  }
}

scope_expansion is never auto-approved.

Report-profile fields

GET /catalogs/report-profiles

Field descriptors (enums and types) for building a profile — not a saved profile. Request/response shapes, methodologies and formats are documented on the Reports API.

{
  "success": true,
  "data": {
    "fields": [
      {
        "key": "methodology",
        "label": "Testing methodology",
        "type": "enum",
        "multiple": false,
        "options": [
          {"id": "wstg", "label": "OWASP Web Security Testing Guide"},
          {"id": "asvs_l2", "label": "OWASP ASVS Level 2"},
          {"id": "ptes", "label": "PTES"},
          {"id": "nist_800_115", "label": "NIST SP 800-115"}
        ]
      },
      {
        "key": "audience",
        "label": "Audience",
        "type": "enum",
        "multiple": false,
        "options": [
          {"id": "executive", "label": "Executive"},
          {"id": "technical", "label": "Technical"},
          {"id": "attestation", "label": "Attestation"}
        ]
      }
    ]
  }
}

Where to go next