# Adlumin Documentation > This site contains developer documentation for the N-able Adlumin product. This includes an API reference, sample scripts, and a list of useful resources. Append .md to any documentation page URL to get its markdown version. ## Guides - [Welcome to Adlumin](https://developer.n-able.com/adlumin/docs/getting-started.md) ## API Reference - [List detections](https://developer.n-able.com/adlumin/reference/get_detections.md): Returns a paginated list of security detections for the authenticated tenant. Results can be filtered by severity, date range, acknowledgement status, and free-text search. Default sort is newest-first by `event_time`. - [Acknowledge detections](https://developer.n-able.com/adlumin/reference/post_acknowledge-detections.md): Marks one or more detections as acknowledged, removing them from the active dashboard view. An acknowledged detection is not deleted — it remains available via the `/detections` endpoint with `acknowledged=true`. Pass an array of detection IDs to bulk-acknowledge. The response confirms which IDs were updated and which (if any) were not found or already acknowledged. - [List at-risk Active Directory groups](https://developer.n-able.com/adlumin/reference/get_at-risk-groups.md): Returns Active Directory groups flagged as at-risk due to overly broad permissions, privileged access, or policy violations. Results exclude groups that have been granted a full risk exemption. Use the `type` parameter to switch between active at-risk groups and groups currently in an exempted state. - [List at-risk network shares](https://developer.n-able.com/adlumin/reference/get_at-risk-shares.md): Returns network shares that have been identified as at-risk due to overly permissive access controls (e.g., world-readable or writable shares, shares accessible to privileged groups). Excludes shares with active exemptions. - [List at-risk systems (hosts)](https://developer.n-able.com/adlumin/reference/get_at-risk-systems.md): Returns hosts/workstations flagged as at-risk. A system may be at-risk due to misconfiguration, stale patches, privileged account exposure, or anomalous activity. Results support filtering by operating system, domain, and exemption state. - [List endpoint agent data](https://developer.n-able.com/adlumin/reference/get_endpoint-data.md): Returns endpoint security agent telemetry for devices managed under the authenticated tenant. Each record reflects the last-known state reported by the installed agent (Sentinel One, Carbon Black, etc.), including agent version, policy, and connectivity status. - [Get aggregated endpoint summary](https://developer.n-able.com/adlumin/reference/get_complete-endpoint-data.md): Returns a comprehensive rolled-up summary of endpoint health across the tenant, combining at-risk counts, sensor health metrics, compliance posture, and network health in a single response. Ideal for dashboard widgets and executive summaries. - [List registered devices](https://developer.n-able.com/adlumin/reference/get_device-data.md): Returns inventory-level device records for all hosts registered with the tenant. Unlike `/endpoint_data` (which reflects agent state), this endpoint returns the base device inventory including MAC address, OS, and domain membership regardless of agent installation status. - [Get network health statistics](https://developer.n-able.com/adlumin/reference/get_network-data.md): Returns the full set of network health metrics for the tenant. Each metric represents a risk indicator (e.g., stale accounts, locked-out accounts, GPO violations) with a current count and a contribution to the overall network health score (0–100, higher is healthier). Metric categories include: - Active Directory hygiene (stale accounts, expired passwords, reversible encryption) - Detection posture (unacknowledged high/critical detections) - Privilege management (delegated/privileged domain accounts) - IT operations (service account failures, circular groups) - [List firewall events](https://developer.n-able.com/adlumin/reference/get_firewall.md): Returns firewall log events from the tenant's network security devices. Events are sourced from the tenant's Elasticsearch index and include source/destination IPs, geographic data, action taken, and a UBA risk score. Use `action` to filter to blocked/dropped traffic only. Use `since`/`until` to scope to a time window. Geographic aggregations (top source/destination countries) are available as a separate query using `aggregate=geo`. - [Get compliance insights](https://developer.n-able.com/adlumin/reference/get_compliance-insights.md): Returns compliance and policy violation metrics for the tenant, covering Active Directory hygiene, Group Policy violations, and detection posture. These metrics feed the Compliance Insights section of the Adlumin dashboard and can be used to track improvement over time. Metric definitions: | Field | Description | |---|---| | `stale_accounts_count` | AD accounts inactive for 90+ days | | `password_never_expire_count` | Accounts with password expiry disabled | | `password_reversible_encryption_count` | Accounts storing passwords with reversible encryption | | `stale_passwords_count` | Passwords not changed in 90+ days | | `gpo_violations_count` | Group Policy Object rule violations | ## Recipes - [User Created N-central Detection](https://developer.n-able.com/adlumin/recipes/user-created-n-central-detection.md) - [User Deleted N-central Detection](https://developer.n-able.com/adlumin/recipes/user-deleted-n-central-detection.md) - [User Disabled N-central Detection](https://developer.n-able.com/adlumin/recipes/user-disabled-n-central-detection.md)