Skip to main content
Use this workflow for observables from SIEM, EDR, firewall, email, or alerting systems.

Workflow

  1. Resolve the observable with concrete expected types: ip, domain, url, hash, or email.
  2. Retrieve evidence for observed_in_the_wild, malware_association, campaign_association, or actor_association.
  3. Pivot relationships to actors, campaigns, malware, sectors, countries, and related indicators. Use relationship_types: ["ioc"] for event-correlated IOC expansion, sector for targeted industries, and country for targeted countries.
  4. Run /v2/ioc-assessments for disposition and recommended action on the submitted IOC.
  5. Retry in exact query mode when canonicalization may lose URL or observable detail.

Assessment vs. Expansion

IOC assessment and IOC expansion are separate calls. /v2/ioc-assessments assesses the submitted observable; /v2/relationships discovers related indicators and other pivots.

Enrichment-aware scoring

When Kyberis has indicator intelligence for an IOC, it starts with the indicator’s effective source confidence, applies the IOC state adjustment and event-correlation boost, and then applies a bounded enrichment boost. The enrichment boost is capped at 8 confidence points. Kyberis normalizes and deduplicates values before scoring. It excludes generic source labels, MITRE identifiers, and malware names already counted by the malware component from attribution scoring. No single unbounded list can dominate the result. The final priority.ranking_score reflects the combined bounded signals. A NEW IOC receives a modest state penalty rather than a hard confidence ceiling. A DEPRECATED IOC remains non-actionable and receives no enrichment boost, regardless of its enrichment richness. Use metadata.ioc_enrichment_boost to see the total enrichment contribution. With options.include_debug: true and the debug:assessments scope, inspect debug.signal_data.enrichment_boost_breakdown for the component values. Compare all components rather than assuming malware attribution alone determines which IOC ranks higher.

Important Rule

Do not use ioc in expected_types. Expand IOC intent into concrete types.

Final Answer Shape

Lead with disposition and confidence. Then include related entities, evidence IDs, caveats, and recommended next actions such as block, hunt, monitor, or ignore.