Skip to main content
Assessment endpoints turn resolved subject context and evidence into deterministic decision support.

Assessment Endpoints

  • /v2/threat-assessments
  • /v2/cve-assessments
  • /v2/actor-assessments
  • /v2/environment-assessments
  • /v2/ioc-assessments

Response Envelope

Assessment endpoints return: Batch assessment responses use the standard batch envelope described in Batch responses.

What to Preserve

  • assessment result or verdict
  • score and confidence fields
  • rationale fields
  • evidence references
  • caveats
  • trace_id
  • request correlation fields

IOC Assessments

/v2/ioc-assessments focuses on the submitted IOC and returns deterministic disposition, confidence, caveats, and recommended actions for that observable. It does not include event-correlated IOC expansion inline. When Kyberis has indicator intelligence for the IOC, the response exposes the indicator’s lifecycle state and bounded enrichment contribution in metadata: When options.include_debug is true, the credential must include debug:assessments. Debug output includes:
  • debug.signal_data.correlation_boost
  • debug.signal_data.enrichment_boost
  • debug.signal_data.enrichment_boost_breakdown
  • debug.ioc_context, including the underlying source confidence and enrichment lists
The enrichment breakdown contains mitre_breadth, malware_context, attribution_context, target_context, and source_diversity. These components are independently capped, so compare the complete breakdown when explaining why one IOC ranked above another. When an agent needs related indicators, call /v2/relationships for the same IOC subject with relationship_types: ["ioc"]. This keeps assessment responses fast and separates verdict generation from pivot expansion.

Subject and Query Modes

For evidence, relationships, and assessments, provide exactly one of subject or query. Prefer subject after successful resolution. Use query for exact IOC strings, especially URLs or observables where canonicalization could lose important detail.

Reporting Guidance

Do not output a decisive remediation recommendation without evidence IDs or report references. Separate facts from inference.

CVE environment applicability

For /v2/environment-assessments, supply structured environment_context.products and set inventory_complete: true only when the list covers the entire environment you want assessed. Free-text environment is retained but is not interpreted. The response reports metadata.environment_text_evaluated: false. Read metadata.applicability before acting: A product match does not confirm that an asset is vulnerable. A product mismatch must not close an investigation automatically. Verify inventory and advisory coverage before excluding a CVE; verify versions/configuration before remediation. priority.basis explains whether urgency applies to applicability verification or to conditional product exclusion. Known exploitation plus exposure can still make verification urgent and recommend immediate patching if applicability is confirmed. A complete inventory with distinct known products lowers environment priority to monitor with a ranking score capped at 0.2. For CVE assessments, numeric confidence represents support for known exploitation, not confidence that your environment is vulnerable. Inspect metadata.evidence_support, metadata.conditional_on, caveats, and evidence references together. These qualifications remain available in brief responses.