Action required at the top of an entry marks a change that may require you
to update a client, integration, or automation. Filter entries by tag, or
subscribe to this page with RSS at
/changelog/rss.xml.New
- Traverse ATT&CK detection knowledge.
/v2/relationshipsnow links techniques to tactics, detection strategies, analytics, data components, and data sources. Userelationship_typesfor the related entity type,predicatesfor the link meaning, anddirection,platform, andinclude_inactiveto narrow results. See Traverse ATT&CK detection knowledge. - Existing relationship requests are unchanged. General actor, campaign, malware, IOC, sector, and country pivots keep their default behavior; ATT&CK traversal applies only when you request an ATT&CK predicate or target type. ATT&CK cursors follow their own rules. See ATT&CK relationship responses.
New
- IoC feed for enterprise accounts.
GET /v2/ioc-feedkeeps a local indicator dataset in sync: retrieve a paginated snapshot, then poll daily for additions, updates, and removals with the savednext_cursor. Kyberis must enable feed access for your account. See IoC feed. - Confidence intervals. Set
min_confidenceandmax_confidenceon the first request to limit the feed to an interval of source confidence. See Select a confidence interval. - Upsert-based credits. Each page costs 10 credits per 1,000 upserts, rounded up; removals and empty responses are free. Cursors expire with retained feed history after seven days, so poll regularly. See Access and credits.
New
- Structured inventory for environment assessments. Send
environment_context.productsto/v2/environment-assessments, and setinventory_complete: trueonly when the list covers the entire environment. Readmetadata.applicabilityfor product-levelaffected,unaffected, orunknownstatus. See CVE environment applicability. - Product applicability on prioritized CVEs. CVE items from
/v2/prioritizeincludeproduct_matchandapplicabilitywithout debug mode. See CVE inventory applicability.
Improved
- Consistent product matching. Equivalent inventory and source product names now produce the same product applicability on
/v2/prioritizeand/v2/environment-assessments. Free-textenvironmentis retained but not interpreted; the response reportsmetadata.environment_text_evaluated: false. See CVE environment applicability.
Improved
- IoC scores reflect enrichment context. When Kyberis has indicator intelligence for an IOC,
/v2/ioc-assessmentsadds a bounded enrichment boost, capped at 8 confidence points, for MITRE breadth, malware context, attribution, targeting, and source diversity. IOCs with richer context can now rank above sparser IOCs with similar base confidence. See Enrichment-aware scoring. - Inspect the enrichment contribution. Read the total in
metadata.ioc_enrichment_boost. Withoptions.include_debug: trueand thedebug:assessmentsscope,debug.signal_data.enrichment_boost_breakdownreturns the five component values. See Enrichment scoring.
New
- Direct API-key authentication for MCP. One-command MCP setup now installs
Authorization: ApiKey <key_id>:<secret>in your MCP client, so tool calls use your API key directly. To switch a client you set up earlier, reconnect it from API keys. See How MCP access works.
Improved
- Stable, larger relationship pages. Paged traversal returns the same ordered results regardless of page size within a snapshot of up to 500 ranked results.
max_resultsaccepts 1–100. See General relationship pagination.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)