/v2/relationships after entity resolution when you need connected actors, campaigns, malware, sectors, countries, indicators, or techniques.
Relationship Types
Supported relationship types include:actorcampaignmalwaresectorcountryioctechnique
technique pivots through the vulnerability described by the CVE.
For IOC subjects, ioc pivots through event-correlation context to related indicators. sector and country can return target-industry and target-country pivots when that context is available. Use concrete IOC entity types (ip, domain, url, hash, or email) rather than ioc as the subject type.
Workflow
- Start from a resolved
subjectwhen possible. - Request only the relationship types needed for the investigation.
- Keep
max_resultsbounded. - Hydrate important related entities before high-impact recommendations.
- Use evidence calls to validate material relationship claims.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)