Share on social
Feb 24, 2026
Lorem ipsum

Searchlight Threat (Monitor)'s API provides programmatic access to all platform capabilities – from ingestion through alert triage – including new support for tracking changes to discovered phishing domains.
Searchlight users can now programmatically complete any action they can do in the Searchlight Threat Monitor platform (formerly DarkIQ), including ingesting and triaging any action, such as tracking changes to discovered phishing domains as they become weaponized for attacks, as well as core functionality required for integration with other workflows and systems.
Key benefits
- Centralize all endpoints in a single SIEM/SOAR.
- Dynamically add new attributes for continuous monitoring.
- Comprehensive support for GET, POST, PATCH, and DELETE methods across the platform.
This full programmatic access brings DarkIQ in line with our attack surface management platform, Searchlight Exposure, empowering defenders to better prioritize and manage alerts using the tools and workflows they already use.
How it works
For more information, view our API and integrations page. Searchlight Threat users can also find more detailed information on using the API in the Documentation (click to login).







