Read the IoC feed (enterprise-only)
Enterprise feeds
IoC feed (enterprise-only)
Synchronize a local indicator dataset with paginated snapshots and daily incremental changes. Requires enterprise feed access.
GET
Read the IoC feed (enterprise-only)
Use the feed to maintain a local set of indicators of compromise for matching and
investigation. Start with a paginated snapshot, then retrieve additions, updates,
and removals using a saved cursor. The feed is published daily; it is not a live
stream or a record of every change between publications.
Omit
Access and credits
Use
Authorization: ApiKey <key_id>:<secret> or
Authorization: Bearer <access_token>. See authentication.
This endpoint does not require an agent_context body or agent-context headers.
Normal account and credential rate limits apply.
The exact charge is ceil(upserts / 100): 5 or 100 upserts cost 1 credit, 101 cost
2, and 1,000 cost 10. Removals count toward page size but not the charge. A mixed
page of 100 upserts and 900 removals costs 1 credit. Smaller pages can increase
rounding costs. A 500,000-record snapshot retrieved in full pages costs 5,000 credits.
Retrieve the first page
SetKYBERIS_API_KEY to your API key credential (<key_id>:<secret>):
cursor for the initial snapshot. There is no request that returns the
entire dataset without pagination. Dataset size changes as indicators become
eligible or are removed.
Continue pages and daily polling
Use the previous response’snext_cursor as the cursor query parameter:
- Apply each record to your local dataset using
idas the key. Replace or insert onupsert; delete onremove, even if the ID is already absent. - Save
next_cursoratomically with those local changes. - While
has_moreistrue, fetch the next page immediately. - When
has_moreisfalse, keep the returned cursor and resume with it at your next poll, typically 24 hours later. Save the returned cursor even on an empty page.
Select a confidence interval
The default feed includes all eligible indicators, including those with unknown source confidence. You can select a confidence interval on the first request:
For example,
?min_confidence=40&max_confidence=65 selects [40,65).
?min_confidence=65 includes scores from 65 through 100. An explicit
max_confidence=100 excludes 100; omit the maximum to include it. Fractional
bounds are supported. Unknown confidence is excluded whenever either bound is
specified, including min_confidence=0.
Confidence describes source threat confidence, not freshness. The selected bounds
are fixed in the cursor. Subsequent requests should send only cursor and optional
limit, or repeat identical bounds. Changing a bound returns
400 cursor_filter_mismatch. Start a new snapshot to change selection.
An indicator entering your interval produces an upsert; one leaving it produces a
free removal. For example, a score falling from 70 to 50 produces a removal for a
consumer using min_confidence=65, but an update for one using min_confidence=40.
Each consumer should keep its own dataset and cursor. Cursors belong to the account,
not a particular API key. Overlapping downloads by separate consumers are each billable.
Unsupported or duplicate query parameters are rejected. Type, country, industry,
not_older_than, and verbose filters are not supported.
Read the response
This illustrative incremental page contains one upsert and one removal. Cursor strings in examples are placeholders.
Upserts include
id, operation, type, value, changed_at, freshness_at,
and freshness_basis. confidence is omitted when unknown. last_seen is actual
source observation time and is omitted when unavailable. freshness_basis is
last_seen or last_feed_occurrence; a feed occurrence describes source feed
recency, not a confirmed malicious sighting. changed_at indicates when the feed
detected the change, not when malicious activity occurred.
Removals contain only id, operation, and changed_at. They include withdrawals,
indicators aging out, and indicators leaving a selected confidence interval.
A quiet poll returns records: [], has_more: false, a new checkpoint, and zero credits.
The feed contains minimal indicators, not enriched investigation results or internal
lifecycle fields. Use IoC assessment
for a separate, billable investigation of an indicator.
Cursor expiry and recovery
Feed history is retained for seven days from each publication’s evaluation cutoff. A cursor expires with its retained base publication; each page does not reset that clock. Catching up to a newer publication advances the checkpoint. Complete initial snapshots promptly and poll regularly. On410 snapshot_required, build a replacement snapshot without a cursor and
replace your local dataset after completing all its pages. Reapply your confidence
bounds when starting it. The replacement snapshot is billable. A cursor invalidated
by signing-key rotation also requires a fresh snapshot.
Errors and retries
Replaying a cursor lets you apply records idempotently, but every successful
response is charged again for its upserts. Request IDs do not deduplicate charges.
A connection failure after a debit commits may leave you charged without receiving
the response; retrying is a new retrieval. Validation and access errors before a
debit do not charge. Keep your last successfully applied cursor on errors.
Authorizations
ApiKey <key_id>:
Query Parameters
Required string length:
1 - 4096Required range:
1 <= x <= 1000Inclusive source-confidence minimum. Fixed for this cursor chain.
Required range:
0 <= x <= 100Exclusive source-confidence maximum. Omit to include 100. Must exceed the minimum (or zero).
Required range:
0 <= x <= 100.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)