Retrieve the historical observations of hosts associated with a certificate. This is useful for threat hunting, detection engineering, and timeline generation. Certificate history is also visible to Adversary Investigation users in the Platform UI on the certificate timeline.
You can define a specific time frame of interest. If you do not specify a time frame, this endpoint will search the historical dataset that is available to your account.
For workspaces with a history limit, the API returns observation ranges that overlap the allowed history window. The window starts at 00:00 UTC the allowed number of days ago and ends at the time of the request. Ranges are returned in full, with their original start and end times, even if they extend outside the window.
You may also filter results by port and transport protocol.
This endpoint is available to organizations that have access to the Adversary Investigation module. This endpoint costs one credit per page of results.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
