Skip to main content

API Access to Retrieve Scanner Source IPs Used in Specific Scans

We would like to programmatically identify the exact IP addresses used by Halo’s scanning engines during each vulnerability scan. While the UI currently shows scanner IPs per scan under the “Scan Details” section, there is no API endpoint available to retrieve this information automatically.

Our team uses Tines for workflow automation and has integrated Halo Security’s API to pull scan data. However, without access to the scanner IPs via API, we’re unable to automatically correlate scan activity with logs and firewall data.

This feature would help streamline automation, improve security event correlation, and reduce time spent manually checking scan data in the UI.

Status: Completed2 comments

Log in to comment and vote

Comments2

  • Ben Tyler

    Team•

    Dec 11, 2025

    The scan get endpoint response now includes a “scan_parts” array with these details.

    https://api.halosecurity.com/api/v1/scan/get.json

  • Dany - AdminA Walker

    •

    Oct 1, 2025

    Hello, I am following up on this feature request to see if there are any updates.