Response Envelope
/v2/evidence returns:
Batch evidence responses use the standard batch envelope described in Batch responses.
Claim Types
Use only these claim types:active_exploitationsector_targetingactor_associationcampaign_associationmalware_associationrelevance_to_environmentobserved_in_the_wild
Key Fields
Look for evidence IDs, evidence type, source, published time, matched subject, confidence, and any pagination cursor fields. For IOCsector_targeting evidence, attributes may include targeted industries, targeted countries, record count, max confidence, and feed sources.
IOC Sector Targeting
sector_targeting can be used with IOC subjects (ip, domain, url, hash, or email) when target-industry context is available. Supplying context.sector filters evidence to that sector. Omitting context.sector lets agents discover the targeted sectors returned by Kyberis.
Hydration
UseGET /v2/evidence/{evidence_id} when a high-impact conclusion depends on details from a specific evidence item.
Identifier-style IDs such as ip--... or actor--... can return synthetic hydration with no report payload. Prefer hydrating report-backed evidence IDs such as report--... when available.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)