Skip to main content
POST
Structured IOC assessment (LLM-free)

Scope and credits

IOC assessment behavior

/v2/ioc-assessments assesses the submitted IOC itself. It may enrich the assessment with intelligence about the exact IP, domain, URL, hash, or email subject, including targeted industries, targeted countries, and targeted campaigns when available. It does not expand event-correlated or co-occurring IOCs inline. Use /v2/relationships with relationship_types: ["ioc"] when you need related indicators or event-correlation pivots for an IOC subject. Use relationship_types: ["sector"] or relationship_types: ["country"] when you need industry or geography pivots from indicator intelligence.

Enrichment scoring

When Kyberis has indicator intelligence for an IOC, it applies a bounded enrichment contribution after the IOC state adjustment and event-correlation boost. The total enrichment contribution is capped at 8.0 confidence points and considers:
  • MITRE tactic and technique breadth, capped at 3.0
  • MITRE software and MALPEDIA malware-family context, capped at 2.0
  • actor and campaign attribution, capped at 1.5
  • targeted industries and countries, capped at 1.0
  • feed and source diversity, capped at 0.5
metadata.ioc_enrichment_boost contains the total contribution. Request debug output to receive debug.signal_data.enrichment_boost_breakdown with the five component values. The score uses the complete weighted breakdown. An IOC with more malware families does not necessarily rank above an IOC with broader MITRE, attribution, or targeting context. NEW applies a modest state penalty rather than a hard ceiling. DEPRECATED IOCs remain non-actionable and receive no enrichment boost.

Authorizations

Authorization
string
header
required

ApiKey <key_id>:

Body

application/json
agent_context
AgentContext · object
required
context
AssessmentContext · object | null
expected_types
string[] | null
options
Options · object | null
query
string | null
Maximum string length: 1024
resolution
ResolutionOptions · object | null
subject
AssessmentSubject · object | null
time_range
Time Range · object | null

Response

Successful Response

assessment_type
string
required
caveats
string[]
required
confidence
number
required
evidence_refs
Evidence Refs · object[]
required
input
Input · object
required
metadata
Metadata · object
required

Includes caller_assertions (values, verification status, use in decision, and supporting_refs), conditional_on (unverified input paths), confidence_basis, and enrichment availability/degradation. CVE subjects additionally expose evidence_support, risk_basis, severity, and publication_context. A KEV flag establishes known exploitation, not current activity or customer applicability. CVE environment assessments also include applicability: product_status (affected/unaffected/unknown) is scoped to known source product names; full status stays unknown because versions and configuration are not evaluated. environment_text_evaluated is false.

priority
Priority · object
required

Risk ranking and proposed action timing, not evidence certainty. For CVEs, severity, exploitation, exposure, and conditional caller premises affect priority; publication freshness does not. Unknown evidence alone never means safe to close. CVE environment assessments include basis: verify_applicability or known_product_mismatch_conditional_on_complete_inventory.

rationale_codes
string[]
required
resolution
ResolutionResult · object
required
signals
Signals · object
required
timestamp
number
required
trace_id
string
required
debug
Debug · object | null