Assessment Endpoints
/v2/threat-assessments/v2/cve-assessments/v2/actor-assessments/v2/environment-assessments/v2/ioc-assessments
Response Envelope
Assessment endpoints return:
Batch assessment responses use the standard batch envelope described in Batch responses.
What to Preserve
- assessment result or verdict
- score and confidence fields
- rationale fields
- evidence references
- caveats
trace_id- request correlation fields
IOC Assessments
/v2/ioc-assessments focuses on the submitted IOC and returns deterministic disposition, confidence, caveats, and recommended actions for that observable. It does not include event-correlated IOC expansion inline.
When Kyberis has indicator intelligence for the IOC, the response exposes the indicator’s lifecycle state and bounded enrichment contribution in metadata:
When
options.include_debug is true, the credential must include debug:assessments. Debug output includes:
debug.signal_data.correlation_boostdebug.signal_data.enrichment_boostdebug.signal_data.enrichment_boost_breakdowndebug.ioc_context, including the underlying source confidence and enrichment lists
mitre_breadth, malware_context, attribution_context, target_context, and source_diversity. These components are independently capped, so compare the complete breakdown when explaining why one IOC ranked above another.
When an agent needs related indicators, call /v2/relationships for the same IOC subject with relationship_types: ["ioc"]. This keeps assessment responses fast and separates verdict generation from pivot expansion.
Subject and Query Modes
For evidence, relationships, and assessments, provide exactly one ofsubject or query.
Prefer subject after successful resolution. Use query for exact IOC strings, especially URLs or observables where canonicalization could lose important detail.
Reporting Guidance
Do not output a decisive remediation recommendation without evidence IDs or report references. Separate facts from inference.CVE environment applicability
For/v2/environment-assessments, supply structured environment_context.products
and set inventory_complete: true only when the list covers the entire environment
you want assessed. Free-text environment is retained but is not interpreted.
The response reports metadata.environment_text_evaluated: false.
Read metadata.applicability before acting:
A product match does not confirm that an asset is vulnerable. A product mismatch
must not close an investigation automatically. Verify inventory and advisory
coverage before excluding a CVE; verify versions/configuration before remediation.
priority.basis explains whether urgency applies to applicability verification or
to conditional product exclusion. Known exploitation plus exposure can still make
verification urgent and recommend immediate patching if applicability is
confirmed. A complete inventory with distinct known products lowers environment
priority to monitor with a ranking score capped at 0.2.
For CVE assessments, numeric confidence represents support for known exploitation,
not confidence that your environment is vulnerable. Inspect
metadata.evidence_support, metadata.conditional_on, caveats, and evidence
references together. These qualifications remain available in brief responses..png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)