Response Envelope
/v2/relationships returns:
Batch relationship responses use the standard batch envelope described in Batch responses.
General relationship pagination
For general actor, malware, IOC, and other existing pivots, relationship pagination uses opaque snapshot cursors. Whennext_cursor is
present, pass it back unchanged with the same request inputs to retrieve the
next slice of the original ranked result set. Do not parse or modify the cursor.
For unchanged request inputs, paged traversal is page-size invariant: requesting
two pages of five items returns the same ordered set as requesting one page of
ten items, subject to cursor expiry. Relationship cursors expire after 10
minutes and are retained in cache longer so clients can distinguish an expired
cursor from a cursor that cannot be found.
max_results controls page size and is capped at 100. Each traversal snapshot
contains up to 500 ranked results, which allows up to five full pages from a
single snapshot. A request path that attempts to continue beyond the bounded
snapshot, such as a sixth 100-result page, is not covered by the stable-result
guarantee.
ATT&CK relationship responses
ATT&CK items userelationship_type and target_entity_type for the related
entity type. predicate gives the link meaning, and direction is incoming
or outgoing relative to your subject.
ATT&CK
score is currently 1.0 for a matched link, not a threat likelihood or
detection effectiveness estimate. evidence_count counts link provenance
references; it does not count observed procedure executions. A no_relationships
result means no links matched this request in the available dataset, not that a
behavior is undetectable.
ATT&CK pagination uses deterministic ordering and cursors bound to the resolved
subject, filters, context, and result snapshot. Pass next_cursor unchanged as
cursor. If the request or snapshot changes, the API returns HTTP 400; restart
without the cursor. The general traversal’s ten-minute expiry and 500-result
snapshot rules above do not apply to ATT&CK cursors. max_results remains 1–100.
An ATT&CK catalog exceeding the supported retrieval bound returns HTTP 503
instead of a silently incomplete traversal.
See the ATT&CK workflow
for predicates, filters, and a PowerShell example.
Key fields
Relationship items may include:- related entity ID and name
- relationship type
- direction or role
- confidence
- supporting evidence references
- pagination cursor fields
IOC Relationship Expansion
For IOC subjects (ip, domain, url, hash, or email), relationship_types: ["ioc"] returns related indicators from event-correlation context when available. This is the supported path for IOC expansion; /v2/ioc-assessments does not return correlated IOCs inline.
IOC subjects can also return sector relationships for targeted industries and country relationships for targeted countries when that context is available. These pivots are useful for environment relevance, especially when they match a caller-provided sector or operating region.
IOC relationship items use relationship_type: "ioc", target_entity_type: "ioc", and include metadata.indicator_type when known. Sector and country relationship items use matching relationship_type and target_entity_type values. Treat all relationship items as pivots for hunting or blocking review, not proof by themselves.
How to use Relationships
Use relationships to select the next investigation step:- Actor links can trigger actor assessments.
- Malware links can trigger malware or generic threat assessment paths.
- IOC links can trigger IOC assessment or blocking review.
- Sector links can support industry relevance.
- Country links can support geography relevance.
- Technique links can guide detection and hunting.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)