curl --request POST \
--url https://api.example.com/v2/ioc-assessments \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": true
},
"parent_step_id": "<string>",
"tags": [
"<string>"
]
},
"context": {
"affected_cpes": [
"<string>"
],
"campaign_status": "<string>",
"evidence_refs": [
{
"id": "<string>",
"type": "<string>"
}
],
"intel_confidence": "<string>",
"known_exploited": true,
"known_targets": [
"<string>"
],
"targeted_industries": [
"<string>"
],
"targeted_regions": [
"<string>"
]
},
"expected_types": [
"<string>"
],
"options": {},
"query": "<string>",
"resolution": {
"include_aliases": false,
"include_metadata": false,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
},
"time_range": {}
}
'import requests
url = "https://api.example.com/v2/ioc-assessments"
payload = {
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": True
},
"parent_step_id": "<string>",
"tags": ["<string>"]
},
"context": {
"affected_cpes": ["<string>"],
"campaign_status": "<string>",
"evidence_refs": [
{
"id": "<string>",
"type": "<string>"
}
],
"intel_confidence": "<string>",
"known_exploited": True,
"known_targets": ["<string>"],
"targeted_industries": ["<string>"],
"targeted_regions": ["<string>"]
},
"expected_types": ["<string>"],
"options": {},
"query": "<string>",
"resolution": {
"include_aliases": False,
"include_metadata": False,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
},
"time_range": {}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_context: {
objective: '<string>',
requested_outcome: '<string>',
run_id: '<string>',
step_id: '<string>',
client: {agent_name: '<string>', agent_version: '<string>', framework: '<string>'},
constraints: {
latency_budget_ms: 15025,
max_results_budget: 100,
min_resolution_confidence: 0.5,
strict_mode: true
},
parent_step_id: '<string>',
tags: ['<string>']
},
context: {
affected_cpes: ['<string>'],
campaign_status: '<string>',
evidence_refs: [{id: '<string>', type: '<string>'}],
intel_confidence: '<string>',
known_exploited: true,
known_targets: ['<string>'],
targeted_industries: ['<string>'],
targeted_regions: ['<string>']
},
expected_types: ['<string>'],
options: {},
query: '<string>',
resolution: {include_aliases: false, include_metadata: false, max_results: 5},
subject: {canonical_id: '<string>', entity_type: '<string>', canonical_name: '<string>'},
time_range: {}
})
};
fetch('https://api.example.com/v2/ioc-assessments', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v2/ioc-assessments",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_context' => [
'objective' => '<string>',
'requested_outcome' => '<string>',
'run_id' => '<string>',
'step_id' => '<string>',
'client' => [
'agent_name' => '<string>',
'agent_version' => '<string>',
'framework' => '<string>'
],
'constraints' => [
'latency_budget_ms' => 15025,
'max_results_budget' => 100,
'min_resolution_confidence' => 0.5,
'strict_mode' => true
],
'parent_step_id' => '<string>',
'tags' => [
'<string>'
]
],
'context' => [
'affected_cpes' => [
'<string>'
],
'campaign_status' => '<string>',
'evidence_refs' => [
[
'id' => '<string>',
'type' => '<string>'
]
],
'intel_confidence' => '<string>',
'known_exploited' => true,
'known_targets' => [
'<string>'
],
'targeted_industries' => [
'<string>'
],
'targeted_regions' => [
'<string>'
]
],
'expected_types' => [
'<string>'
],
'options' => [
],
'query' => '<string>',
'resolution' => [
'include_aliases' => false,
'include_metadata' => false,
'max_results' => 5
],
'subject' => [
'canonical_id' => '<string>',
'entity_type' => '<string>',
'canonical_name' => '<string>'
],
'time_range' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v2/ioc-assessments"
payload := strings.NewReader("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"affected_cpes\": [\n \"<string>\"\n ],\n \"campaign_status\": \"<string>\",\n \"evidence_refs\": [\n {\n \"id\": \"<string>\",\n \"type\": \"<string>\"\n }\n ],\n \"intel_confidence\": \"<string>\",\n \"known_exploited\": true,\n \"known_targets\": [\n \"<string>\"\n ],\n \"targeted_industries\": [\n \"<string>\"\n ],\n \"targeted_regions\": [\n \"<string>\"\n ]\n },\n \"expected_types\": [\n \"<string>\"\n ],\n \"options\": {},\n \"query\": \"<string>\",\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n },\n \"time_range\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/v2/ioc-assessments")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"affected_cpes\": [\n \"<string>\"\n ],\n \"campaign_status\": \"<string>\",\n \"evidence_refs\": [\n {\n \"id\": \"<string>\",\n \"type\": \"<string>\"\n }\n ],\n \"intel_confidence\": \"<string>\",\n \"known_exploited\": true,\n \"known_targets\": [\n \"<string>\"\n ],\n \"targeted_industries\": [\n \"<string>\"\n ],\n \"targeted_regions\": [\n \"<string>\"\n ]\n },\n \"expected_types\": [\n \"<string>\"\n ],\n \"options\": {},\n \"query\": \"<string>\",\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n },\n \"time_range\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v2/ioc-assessments")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"affected_cpes\": [\n \"<string>\"\n ],\n \"campaign_status\": \"<string>\",\n \"evidence_refs\": [\n {\n \"id\": \"<string>\",\n \"type\": \"<string>\"\n }\n ],\n \"intel_confidence\": \"<string>\",\n \"known_exploited\": true,\n \"known_targets\": [\n \"<string>\"\n ],\n \"targeted_industries\": [\n \"<string>\"\n ],\n \"targeted_regions\": [\n \"<string>\"\n ]\n },\n \"expected_types\": [\n \"<string>\"\n ],\n \"options\": {},\n \"query\": \"<string>\",\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n },\n \"time_range\": {}\n}"
response = http.request(request)
puts response.read_body{
"assessment_type": "<string>",
"caveats": [
"<string>"
],
"confidence": 123,
"evidence_refs": [
{}
],
"input": {},
"metadata": {},
"priority": {},
"rationale_codes": [
"<string>"
],
"recommended_actions": [
"<string>"
],
"resolution": {
"status": "resolved",
"candidates": [
{
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"match_type": "<string>",
"score": 123,
"aliases": [
"<string>"
],
"matched_on": "<string>",
"metadata": {}
}
],
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"input_mode": "subject",
"resolution_confidence": 123
},
"signals": {},
"timestamp": 123,
"trace_id": "<string>",
"debug": {}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Assess IOC
curl --request POST \
--url https://api.example.com/v2/ioc-assessments \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": true
},
"parent_step_id": "<string>",
"tags": [
"<string>"
]
},
"context": {
"affected_cpes": [
"<string>"
],
"campaign_status": "<string>",
"evidence_refs": [
{
"id": "<string>",
"type": "<string>"
}
],
"intel_confidence": "<string>",
"known_exploited": true,
"known_targets": [
"<string>"
],
"targeted_industries": [
"<string>"
],
"targeted_regions": [
"<string>"
]
},
"expected_types": [
"<string>"
],
"options": {},
"query": "<string>",
"resolution": {
"include_aliases": false,
"include_metadata": false,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
},
"time_range": {}
}
'import requests
url = "https://api.example.com/v2/ioc-assessments"
payload = {
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": True
},
"parent_step_id": "<string>",
"tags": ["<string>"]
},
"context": {
"affected_cpes": ["<string>"],
"campaign_status": "<string>",
"evidence_refs": [
{
"id": "<string>",
"type": "<string>"
}
],
"intel_confidence": "<string>",
"known_exploited": True,
"known_targets": ["<string>"],
"targeted_industries": ["<string>"],
"targeted_regions": ["<string>"]
},
"expected_types": ["<string>"],
"options": {},
"query": "<string>",
"resolution": {
"include_aliases": False,
"include_metadata": False,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
},
"time_range": {}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_context: {
objective: '<string>',
requested_outcome: '<string>',
run_id: '<string>',
step_id: '<string>',
client: {agent_name: '<string>', agent_version: '<string>', framework: '<string>'},
constraints: {
latency_budget_ms: 15025,
max_results_budget: 100,
min_resolution_confidence: 0.5,
strict_mode: true
},
parent_step_id: '<string>',
tags: ['<string>']
},
context: {
affected_cpes: ['<string>'],
campaign_status: '<string>',
evidence_refs: [{id: '<string>', type: '<string>'}],
intel_confidence: '<string>',
known_exploited: true,
known_targets: ['<string>'],
targeted_industries: ['<string>'],
targeted_regions: ['<string>']
},
expected_types: ['<string>'],
options: {},
query: '<string>',
resolution: {include_aliases: false, include_metadata: false, max_results: 5},
subject: {canonical_id: '<string>', entity_type: '<string>', canonical_name: '<string>'},
time_range: {}
})
};
fetch('https://api.example.com/v2/ioc-assessments', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v2/ioc-assessments",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_context' => [
'objective' => '<string>',
'requested_outcome' => '<string>',
'run_id' => '<string>',
'step_id' => '<string>',
'client' => [
'agent_name' => '<string>',
'agent_version' => '<string>',
'framework' => '<string>'
],
'constraints' => [
'latency_budget_ms' => 15025,
'max_results_budget' => 100,
'min_resolution_confidence' => 0.5,
'strict_mode' => true
],
'parent_step_id' => '<string>',
'tags' => [
'<string>'
]
],
'context' => [
'affected_cpes' => [
'<string>'
],
'campaign_status' => '<string>',
'evidence_refs' => [
[
'id' => '<string>',
'type' => '<string>'
]
],
'intel_confidence' => '<string>',
'known_exploited' => true,
'known_targets' => [
'<string>'
],
'targeted_industries' => [
'<string>'
],
'targeted_regions' => [
'<string>'
]
],
'expected_types' => [
'<string>'
],
'options' => [
],
'query' => '<string>',
'resolution' => [
'include_aliases' => false,
'include_metadata' => false,
'max_results' => 5
],
'subject' => [
'canonical_id' => '<string>',
'entity_type' => '<string>',
'canonical_name' => '<string>'
],
'time_range' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v2/ioc-assessments"
payload := strings.NewReader("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"affected_cpes\": [\n \"<string>\"\n ],\n \"campaign_status\": \"<string>\",\n \"evidence_refs\": [\n {\n \"id\": \"<string>\",\n \"type\": \"<string>\"\n }\n ],\n \"intel_confidence\": \"<string>\",\n \"known_exploited\": true,\n \"known_targets\": [\n \"<string>\"\n ],\n \"targeted_industries\": [\n \"<string>\"\n ],\n \"targeted_regions\": [\n \"<string>\"\n ]\n },\n \"expected_types\": [\n \"<string>\"\n ],\n \"options\": {},\n \"query\": \"<string>\",\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n },\n \"time_range\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/v2/ioc-assessments")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"affected_cpes\": [\n \"<string>\"\n ],\n \"campaign_status\": \"<string>\",\n \"evidence_refs\": [\n {\n \"id\": \"<string>\",\n \"type\": \"<string>\"\n }\n ],\n \"intel_confidence\": \"<string>\",\n \"known_exploited\": true,\n \"known_targets\": [\n \"<string>\"\n ],\n \"targeted_industries\": [\n \"<string>\"\n ],\n \"targeted_regions\": [\n \"<string>\"\n ]\n },\n \"expected_types\": [\n \"<string>\"\n ],\n \"options\": {},\n \"query\": \"<string>\",\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n },\n \"time_range\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v2/ioc-assessments")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"affected_cpes\": [\n \"<string>\"\n ],\n \"campaign_status\": \"<string>\",\n \"evidence_refs\": [\n {\n \"id\": \"<string>\",\n \"type\": \"<string>\"\n }\n ],\n \"intel_confidence\": \"<string>\",\n \"known_exploited\": true,\n \"known_targets\": [\n \"<string>\"\n ],\n \"targeted_industries\": [\n \"<string>\"\n ],\n \"targeted_regions\": [\n \"<string>\"\n ]\n },\n \"expected_types\": [\n \"<string>\"\n ],\n \"options\": {},\n \"query\": \"<string>\",\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n },\n \"time_range\": {}\n}"
response = http.request(request)
puts response.read_body{
"assessment_type": "<string>",
"caveats": [
"<string>"
],
"confidence": 123,
"evidence_refs": [
{}
],
"input": {},
"metadata": {},
"priority": {},
"rationale_codes": [
"<string>"
],
"recommended_actions": [
"<string>"
],
"resolution": {
"status": "resolved",
"candidates": [
{
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"match_type": "<string>",
"score": 123,
"aliases": [
"<string>"
],
"matched_on": "<string>",
"metadata": {}
}
],
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"input_mode": "subject",
"resolution_confidence": 123
},
"signals": {},
"timestamp": 123,
"trace_id": "<string>",
"debug": {}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Scope and credits
| Requirement | Value |
|---|---|
| Required scopes | read:assessments |
| Additional debug scope | debug:assessments when options.include_debug is true |
| Credits | 6 credits per request |
IOC assessment behavior
/v2/ioc-assessments assesses the submitted IOC itself. It may enrich the assessment with intelligence about the exact IP, domain, URL, hash, or email subject, including targeted industries, targeted countries, and targeted campaigns when available. It does not expand event-correlated or co-occurring IOCs inline.
Use /v2/relationships with relationship_types: ["ioc"] when you need related indicators or event-correlation pivots for an IOC subject. Use relationship_types: ["sector"] or relationship_types: ["country"] when you need industry or geography pivots from indicator intelligence.
Enrichment scoring
When Kyberis has indicator intelligence for an IOC, it applies a bounded enrichment contribution after the IOC state adjustment and event-correlation boost. The total enrichment contribution is capped at8.0 confidence points and considers:
- MITRE tactic and technique breadth, capped at
3.0 - MITRE software and MALPEDIA malware-family context, capped at
2.0 - actor and campaign attribution, capped at
1.5 - targeted industries and countries, capped at
1.0 - feed and source diversity, capped at
0.5
metadata.ioc_enrichment_boost contains the total contribution. Request debug output to receive debug.signal_data.enrichment_boost_breakdown with the five component values.
The score uses the complete weighted breakdown. An IOC with more malware families does not necessarily rank above an IOC with broader MITRE, attribution, or targeting context. NEW applies a modest state penalty rather than a hard ceiling. DEPRECATED IOCs remain non-actionable and receive no enrichment boost.Authorizations
ApiKey <key_id>:
Body
Show child attributes
Show child attributes
Show child attributes
Show child attributes
1024Show child attributes
Show child attributes
Show child attributes
Show child attributes
Response
Successful Response
Includes caller_assertions (values, verification status, use in decision, and supporting_refs), conditional_on (unverified input paths), confidence_basis, and enrichment availability/degradation. CVE subjects additionally expose evidence_support, risk_basis, severity, and publication_context. A KEV flag establishes known exploitation, not current activity or customer applicability. CVE environment assessments also include applicability: product_status (affected/unaffected/unknown) is scoped to known source product names; full status stays unknown because versions and configuration are not evaluated. environment_text_evaluated is false.
Risk ranking and proposed action timing, not evidence certainty. For CVEs, severity, exploitation, exposure, and conditional caller premises affect priority; publication freshness does not. Unknown evidence alone never means safe to close. CVE environment assessments include basis: verify_applicability or known_product_mismatch_conditional_on_complete_inventory.
Show child attributes
Show child attributes
Was this page helpful?
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)