Catalogs API
HTTP reference for CWE, ATT&CK techniques, approval classes and report-profile field descriptors.
All paths are relative to https://api.aleex-rank.ai/api/v2 and authenticate with X-API-Key: rk_... (see REST API). Catalogs are read-only reference data used when writing RoE, mapping findings and configuring report profiles.
CWE
GET /catalogs/cwe
GET /catalogs/cwe/{cweId}
List is paginated (page, per_page). Filter with q (name or cwe_id substring). mapping=allowed restricts the list to CWEs findings may be mapped to. detail=full includes description and extended_description; the default list is compact.
GET /catalogs/cwe?q=injection&mapping=allowed&detail=full&page=1&per_page=20
{
"success": true,
"data": {
"items": [
{
"cwe_id": "CWE-89",
"name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
"abstraction": "Base",
"status": "Stable",
"mapping_usage": "Allowed",
"url": "https://cwe.mitre.org/data/definitions/89.html",
"cwe_version": "4.16",
"description": "The product constructs all or part of an SQL command using externally-influenced input..."
}
],
"pagination": {"total": 1, "count": 1, "per_page": 20, "current_page": 1, "total_pages": 1}
}
}
{cweId} is the full id, for example CWE-89:
GET /catalogs/cwe/CWE-89
{
"success": true,
"data": {
"cwe_id": "CWE-89",
"name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
"abstraction": "Base",
"status": "Stable",
"mapping_usage": "Allowed",
"url": "https://cwe.mitre.org/data/definitions/89.html",
"cwe_version": "4.16",
"description": "The product constructs all or part of an SQL command using externally-influenced input...",
"extended_description": "..."
}
}
Unknown ids return 404.
ATT&CK techniques
GET /catalogs/attack-techniques
GET /catalogs/attack-techniques/{techniqueId}
Ids match the RoE allowed_techniques / forbidden_techniques format: Txxxx or Txxxx.xxx. Filter the list with tactic — the exact stored tactic name, for example Initial Access (not a slug). detail=full adds description. Paginate with page and per_page.
GET /catalogs/attack-techniques?tactic=Initial%20Access&detail=full
{
"success": true,
"data": {
"items": [
{
"technique_id": "T1190",
"name": "Exploit Public-Facing Application",
"is_subtechnique": false,
"parent_technique_id": null,
"tactics": ["Initial Access"],
"platforms": ["PRE"],
"url": "https://attack.mitre.org/techniques/T1190/",
"attack_version": "16.1",
"description": "Adversaries may attempt to exploit a weakness in an Internet-facing application..."
}
],
"pagination": {"total": 1, "count": 1, "per_page": 20, "current_page": 1, "total_pages": 1}
}
}
GET /catalogs/attack-techniques/T1059.001
{
"success": true,
"data": {
"technique_id": "T1059.001",
"name": "PowerShell",
"is_subtechnique": true,
"parent_technique_id": "T1059",
"tactics": ["Execution"],
"platforms": ["Windows", "Linux", "macOS"],
"description": "Adversaries may abuse PowerShell commands and scripts for execution..."
}
}
Use these ids in Engagement & RoE allow/forbid lists.
Approval classes
GET /catalogs/approval-classes
The closed set of classes a RoE may list in requires_approval_for. The same ids appear as available_approval_classes on GET /pentests/{id}/roe.
{
"success": true,
"data": {
"items": [
{"id": "shell", "description": "Interactive or one-shot shell commands (shell_tool)"},
{"id": "script", "description": "Interpreter scripts (script_tool)"},
{"id": "destructive", "description": "Shell or script whose payload looks destructive (rm -rf, DROP TABLE, and similar)"},
{"id": "exploit", "description": "Active exploitation tools (sqlmap, commix, hydra, metasploit, and similar)"},
{"id": "scope_expansion", "description": "Widening the active RoE of a pentest that is already running"},
{"id": "low_scope_confidence", "description": "An action whose target could not be confidently matched to the authorised scope"}
],
"total": 6
}
}
scope_expansion is never auto-approved.
Report-profile fields
GET /catalogs/report-profiles
Field descriptors (enums and types) for building a profile — not a saved profile. Request/response shapes, methodologies and formats are documented on the Reports API.
{
"success": true,
"data": {
"fields": [
{
"key": "methodology",
"label": "Testing methodology",
"type": "enum",
"multiple": false,
"options": [
{"id": "wstg", "label": "OWASP Web Security Testing Guide"},
{"id": "asvs_l2", "label": "OWASP ASVS Level 2"},
{"id": "ptes", "label": "PTES"},
{"id": "nist_800_115", "label": "NIST SP 800-115"}
]
},
{
"key": "audience",
"label": "Audience",
"type": "enum",
"multiple": false,
"options": [
{"id": "executive", "label": "Executive"},
{"id": "technical", "label": "Technical"},
{"id": "attestation", "label": "Attestation"}
]
}
]
}
}