Skip to main content
POST
Bounded relationship retrieval for canonical entities

Scope and credits

IOC relationship behavior

/v2/relationships accepts IOC subjects with concrete entity_type values: ip, domain, url, hash, or email. For IOC subjects, request relationship_types: ["ioc"] to retrieve related indicators from event-correlation context. You may also request actor, campaign, or malware relationships for attribution-style context, sector relationships for targeted industries, and country relationships for targeted countries when available. Do not use ioc as a subject entity_type; use the concrete observable type.

ATT&CK traversal

Use relationship_types for target entity types and predicates for link semantics. ATT&CK types are tactic, technique, detection-strategy, analytic, data-component, and data-source. direction accepts incoming, outgoing, or both (default). platform filters target platforms; include_inactive controls inactive techniques, strategies, and analytics. Legacy telemetry components and sources remain visible with lifecycle status. For example, request query: "T1059.001", relationship_types: ["detection-strategy"], predicates: ["detects"], and direction: "incoming". Make separate requests for general actor/IOC pivots; those target types cannot be mixed into ATT&CK traversal. Follow the ATT&CK workflow for a complete request and subsequent analytics and telemetry pivots.

Pagination

max_results accepts 1–100. Pass next_cursor back unchanged as cursor with the same subject, filters, and context. ATT&CK cursors are bound to the request and result snapshot. A changed request or snapshot returns HTTP 400; restart without the cursor. General relationship pivots use cached snapshots of up to 500 ranked results and cursors that expire after ten minutes. See relationship response pagination for the separate cursor contracts and ATT&CK response metadata.

Authorizations

Authorization
string
header
required

ApiKey <key_id>:

Body

application/json
agent_context
AgentContext · object | null
context
ClaimEvidenceContext · object | null
cursor
string | null
Maximum string length: 512
direction
enum<string>
default:both
Available options:
incoming,
outgoing,
both
expected_types
string[] | null
include_inactive
boolean
default:false
max_results
integer
default:10
Required range: 1 <= x <= 100
platform
string | null
Required string length: 1 - 128
predicates
enum<string>[] | null
Available options:
belongs_to,
detects,
has_analytic,
requires_data_component,
belongs_to_data_source
query
string | null
Maximum string length: 1024
relationship_types
enum<string>[] | null
Available options:
actor,
campaign,
malware,
sector,
country,
ioc,
technique,
tactic,
detection-strategy,
analytic,
data-component,
data-source
resolution
ResolutionOptions · object | null
subject
RelationshipSubject · object | null

Response

Successful Response

input_mode
enum<string>
required
Available options:
subject,
query
items
RelationshipItem · object[]
required
max_results
integer
required
metadata
Metadata · object
required
relationship_types
enum<string>[]
required
Available options:
actor,
campaign,
malware,
sector,
country,
ioc,
technique,
tactic,
detection-strategy,
analytic,
data-component,
data-source
resolution
ResolutionResult · object
required
status
enum<string>
required
Available options:
ok,
no_relationships
next_cursor
string | null
subject
RelationshipSubject · object | null