BreachSpiderBREACHSPIDER
Research Intel Features Docs About Sign In Sign Up Free

BreachSpider for developers

Check devices against known vulnerabilities from your own code

Send a vendor, a product and a version for each device. BreachSpider returns the CVEs that affect that exact version, ranked, with known-exploited flags, the fix where one is known, and links to the vendor advisories.

14 days, no card, no sales call.

The device API

correlate-cves

Resolves each device to a catalog product and returns the CVEs that affect its version. Every result says how it matched, how confident the resolution is, and what to do next.

correlate-cves/check

A cheap staleness check. Send the result hash you stored last time and learn which devices have new findings, without pulling every CVE again.

CVE detail

Look up any CVE by ID for the full record: scores, known-exploited status, affected versions, fixes and references.

POST /api/v1/assets/correlate-cves
Authorization: Bearer bs_live_...

{"assets": [
  {"asset_id": "plc-7", "vendor": "Siemens",
   "product": "SIMATIC S7-1500", "version": "2.8"}
]}

MCP server

An MCP server is on the way, so AI agents can check devices and look up CVEs through the same API and the same trial key.

Coming soon

The free trial

14
days
750
device checks
25
devices per request

A device sent to correlate-cves counts as one check. A device sent to the staleness check counts as a tenth of a check. The trial key is read only and stops working when the trial ends. One trial per organization.

When the trial ends, the API says so plainly and never returns a partial result without telling you. To keep going, we scope an agreement to your devices and your use.

Docs and SDK