Bgp Hijacks
bgp_hijacksDetect BGP origin hijacks by searching for unauthorized prefix announcements, returning events with confidence scores, hijacker and victim ASNs, affected prefixes, and duration.
Instructions
Search for BGP origin hijack events.
Detects when an AS announces prefixes it is not authorized to originate (based on RPKI, IRR, and historical data). Each event includes a confidence score, the hijacker and victim ASNs, affected prefixes, and duration.
Requires Cloudflare Radar API token (CLOUDFLARE_API_TOKEN).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| asn | No | Filter by involved ASN (hijacker or victim) | |
| prefix | No | Filter by affected prefix (e.g. '1.1.1.0/24') | |
| date_end | No | End date in ISO 8601 | |
| date_start | No | Start date in ISO 8601 (e.g. '2026-03-01T00:00:00') | |
| max_results | No | Max events to return | |
| min_confidence | No | Minimum confidence score (0-100) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| error | No | Set when an upstream lookup failed; other fields may be empty or partial. | |
| total | Yes | Total matching events, even if the list is truncated | |
| events | Yes | Matching events (newest first) | |
| source | Yes | Which data source produced this result |