The identity and technical contract details declared by the specification.
BundleImportBundleIndicatorsCompositeIndicatorExpression
object
2 properties
BulkErrors
object
4 properties
IncidentSummarySearchResultsContextSightingsRelationsSource
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextSightingsContextRegistryDeleteEvents
object
8 properties
NewNote
object
Schema for submitting Notes
15 properties
3 required
BundleImportBundleAssetPropertiesProperties
object
2 properties
IncidentSummarySearchResultsContextNotes
object
A Note is intended to convey informative text to provide further context and/or to provide additional analysis not contained in the Objects, assigning Text/con…
15 properties
BundleImportBundleSightingsModificationInterval
object
The time interval during which the sighting record was created or last updated in the system.
2 properties
BundleImportBundleActorsIdentity
object
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties
Response8129956Policies
object
4 properties
3 required
MitreError
object
3 properties
3 required
BundleImportBundleAssets
object
Schema for submitting new Assets
16 properties
BundleImportBundleCoasOpenC2CoaActuator
object
2 properties
ConfigurationInsightsParamsPolicies
object
2 properties
2 required
BundleImportBundle
object
a Bundle to import
64 properties
IncidentWithEnrichmentStatus
object
36 properties
6 required
IncidentSummarySearchResultsContextWeaknessesOperatingSystems
object
5 properties
IncidentSummarySearchResultsContextWeaknessesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextToolsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
BundleImportBundleCoasOpenC2CoaModifiersAdditionalProperties
object
1 property
UpdateAssetPropertiesBody
object
2 properties
2 required
Response8129956Coverage
object
2 properties
2 required
IncidentSummarySearchResultsContextAttackPatterns
object
Attack Patterns are a type of TTP that describe ways that adversaries attempt to compromise targets.
19 properties
BundleImportBundleVulnerabilitiesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextDataTablesValidTime
object
Period of time when a cyber observation is valid.
2 properties
BundleImportBundleAssetPropertiesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
ModifierType
object
13 properties
IncidentSummarySearchResultsContextRelationships
object
Represents a relationship between two entities.
17 properties
IncidentSummarySearchResultsContextAssetMappings
object
A record that maps a specific Observable to an asset for a specified period of time.
18 properties
BundleImportBundleIndicatorsSpecification
object
An indicator based on a list of judgements. If any of the Observables in it's judgements are encountered, than it may be matches against. If there are any requ…
3 properties
Context
object
Context including the event type that best fits the type of the sighting.
12 properties
IncidentSummarySearchResultsContextVulnerabilitiesImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
IncidentSummarySearchResultsContextIdentityAssertions
object
Context attributes about the target or any of its observables. Providers could provide different types of assertions regarding a target depending on their own…
14 properties
MitreConfigurationInsights
object
4 properties
BundleImportBundleTargetRecords
object
Schema for submitting new TargetRecord.
15 properties
BundleImportBundleSightingsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BulkUpdateAssetPropertiesBody
object
3 properties
3 required
BundleImportBundleSightingsContextRegistryCreateEvents
object
7 properties
GetUserError
object
1 property
1 required
BundleImportBundleAssetProperties
object
Schema for submitting new AssetProperties
14 properties
BulkRefs
object
a new Bulk Delete object
BundleImportBundleWeaknessesNotes
object
2 properties
IncidentSummarySearchResults
object
37 properties
BundleImportBundleCoasExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleSightingsContextFileMoveEvents
object
10 properties
BundleImportBundleVulnerabilitiesImpactCvssV2
object
25 properties
IncidentSummarySearchResultsContextWeaknessesLanguages
object
3 properties
BundleImportBundleIdentityAssertionsIdentity
object
Attributes for which the assertion is being made.
1 property
IncidentSummarySearchResultsContextTools
object
Tools are legitimate software that can be used by threat actors to perform attacks. Knowing how and when threat actors use such tools can be important for unde…
18 properties
IncidentSummarySearchResultsContextTargetRecordsTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentStatusUpdate
object
1 property
1 required
Response8129956CoverageModesPoliciesConfigurationInsightsParams
object
1 property
1 required
IncidentSummarySearchResultsContextSightingsContextFileDeleteEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IdPMapping
object
5 properties
2 required
Note
object
20 properties
8 required
IncidentSummarySearchResultsContextSightingsContext
object
Context including the event type that best fits the type of the sighting.
12 properties
BundleImportBundleSightingsContextHttpEventsTraffic
object
9 properties
BundleImportBundleDataTablesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleDataTablesColumns
object
5 properties
BundleImportBundleSightingsContextRegistrySetEvents
object
10 properties
NoteRelatedEntity
object
2 properties
2 required
IncidentSummarySearchResultsContextSightingsContextRegistryCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextSightingsContextRegistryDeleteEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleAssetMappings
object
Schema for submitting new AssetMapping.
18 properties
IncidentSummarySearchResultsContextVulnerabilitiesImpactCvssV2
object
25 properties
BundleImportBundleSightingsContextFileModifyEvents
object
9 properties
IncidentSummarySearchResultsContextVulnerabilitiesConfigurationsNodesChildren
object
3 properties
RiskScore
object
10 properties
9 required
BundleImportBundleActorsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
Response8129956CoverageModesPolicies
object
1 property
1 required
IncidentSummarySearchResultsContextVulnerabilitiesCveCveDataMeta
object
2 properties
IncidentSummarySearchResultsContextSightingsModificationInterval
object
The time interval during which the sighting record was created or last updated in the system.
2 properties
BundleImportBundleTargetRecordsTargets
object
Schema for TargetRecord Targets
7 properties
BundleImportBundleSightingsTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleIncidentsIncidentTime
object
Relevant time values associated with this Incident.
7 properties
BundleImportBundleToolsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextAttackPatternsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
User
object
21 properties
6 required
BundleImportBundleSightingsContextRegistryRenameEvents
object
8 properties
BundleImportBundleSightingsContextNetflowEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextAssetsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextToolsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
TechniqueCoverage
object
7 properties
3 required
BundleImportBundleSightingsContextHttpEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleWeaknessesArchitectures
object
3 properties
IncidentSummarySearchResultsContextActorsValidTime
object
Indicates the time span for which the information about the Actor is relevant, and after which it could become outdated.
2 properties
IncidentSummarySearchResultsContextCampaignsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextCoasOpenC2CoaTarget
object
2 properties
BundleImportBundleSightingsContextLibraryLoadEvents
object
8 properties
BundleImportBundleCoasOpenC2CoaAction
object
1 property
IncidentSummarySearchResultsContextSightingsContextNetflowEventsTraffic
object
9 properties
BundleImportBundleAssetsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextSightingsContextNetflowEvents
object
22 properties
IncidentSummarySearchResultsContextIdentityAssertionsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleWeaknessesModesOfIntroduction
object
2 properties
IncidentSummarySearchResultsContextSightingsContextRegistryRenameEvents
object
8 properties
MutableCtrProperties
object
A map from asset property name to asset property value used to replace existing properties with those names for the specified asset.
2 properties
2 required
TacticCoverage
object
7 properties
4 required
IncidentSummarySearchResultsContextIncidentsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextVulnerabilitiesConfigurationsNodesChildrenCpeMatch
object
6 properties
IncidentSummarySearchResultsContextSightingsSensorCoordinatesObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextVulnerabilitiesConfigurationsNodes
object
4 properties
IncidentSummarySearchResultsContextCoasOpenC2CoaModifiersAdditionalProperties
object
1 property
IncidentSummarySearchResultsContextIdentityAssertionsValidTime
object
Period of time when a cyber observation is valid.
2 properties
IncidentSummarySearchResultsContextIndicatorsSpecificationRequiredJudgements
object
4 properties
IncidentSummarySearchResultsContextIncidents
object
Information about computer security incident response. A computer security incident is a violation or imminent threat of violation of computer security policie…
30 properties
IncidentSummarySearchResultsContextCampaignsValidTime
object
Timestamp for the definition of a specific version of a campaign.
2 properties
IncidentSummarySearchResultsContextAssetPropertiesProperties
object
2 properties
BundleImportResult
object
1 property
1 required
IncidentSummarySearchResultsContextAssetPropertiesValidTime
object
The time range during which the AssetProperties is considered valid.
2 properties
IncidentSummarySearchResultsContextActors
object
Describes malicious actors or adversaries related to a cyber attack.
23 properties
IncidentSummarySearchResultsContextJudgementsObservable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleSightingsSensorCoordinatesObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
Response8129956CoverageModes
object
6 properties
4 required
BundleImportBundleWeaknesses
object
For submitting a new weakness.
31 properties
Response8129956EnginesCoverageConfigurationInsightsParamsCoverage
object
1 property
1 required
BundleImportBundleVulnerabilitiesConfigurationsNodesChildrenCpeMatch
object
6 properties
IncidentSummarySearchResultsContextVulnerabilitiesConfigurations
object
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
2 properties
BundleImportBundleVerdicts
object
A Verdict is chosen from all of the Judgements on that Observable which have not yet expired. The highest priority Judgement becomes the active verdict. If the…
6 properties
IncidentSummarySearchResultsContextWeaknessesAlternateTerms
object
2 properties
IncidentSummarySearchResultsContextSightingsTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextIdentityAssertionsIdentity
object
Attributes for which the assertion is being made.
1 property
BundleImportBundleWeaknessesParadigms
object
2 properties
IncidentSummarySearchResultsContextWeaknessesDetectionMethods
object
4 properties
IncidentSummarySearchResultsContextCoasOpenC2Coa
object
6 properties
IncidentSummarySearchResultsContextWeaknessesTechnologies
object
2 properties
BundleImportBundleToolsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
IncidentSummarySearchResultsContextCoasRelatedCoAs
object
4 properties
IncidentSummarySearchResultsContextCoasOpenC2CoaModifiers
object
13 properties
IncidentSummarySearchResultsContextAssets
object
Describes a protected resource. It could be a Device, User, Network, Application or Data.
16 properties
BundleImportBundleSightingsDataColumns
object
5 properties
IncidentSummarySearchResultsContextMalwaresExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextTargetRecordsTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextWeaknessesParadigms
object
2 properties
Response8129956CoverageModesPoliciesConfigurationInsightsParamsPolicies
object
2 properties
2 required
IncidentSummarySearchResultsContextValidTime
object
Period of time when a cyber observation is valid.
2 properties
IncidentSummarySearchResultsContextSightingsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleSightingsContextRegistryRenameEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextCampaigns
object
Represents a campaign by an [actor](actor.md) pursing an intent.
21 properties
BundleImportBundleExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleSightingsContextFileDeleteEvents
object
9 properties
IncidentSummarySearchResultsContextWeaknessesArchitectures
object
3 properties
BundleImportBundleIncidentsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextWeaknessesModesOfIntroduction
object
2 properties
IncidentSummarySearchResultsContextVulnerabilitiesCve
object
1 property
IncidentSummarySearchResultsContextWeaknessesNotes
object
2 properties
IncidentSummarySearchResultsContextActorsIdentity
object
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties
IncidentSummarySearchResultsContextDataTables
object
A generic table of data, consisting of types and documented columns, and 1 or more rows of data.
18 properties
BundleImportBundleVulnerabilitiesConfigurationsNodes
object
4 properties
IncidentSummarySearchResultsContextSightingsContextRegistrySetEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
EntityImportResult
object
7 properties
BundleImportBundleSightingsRelations
object
A relation inside a Sighting.
6 properties
IncidentSummarySearchResultsContextTargetRecordsTargets
object
Schema for TargetRecord Targets
7 properties
IncidentSummarySearchResultsContextSightingsRelations
object
A relation inside a Sighting.
6 properties
ConfigurationInsightsParams
object
1 property
1 required
IncidentSummarySearchResultsContextVerdictsValidTime
object
Period of time when a cyber observation is valid.
2 properties
IncidentSummarySearchResultsContextSightingsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleJudgementsObservable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextVulnerabilitiesImpactCvssV3
object
31 properties
MitreCoverageAdversaries
object
BundleImportBundleVulnerabilitiesCve
object
1 property
IncidentSummarySearchResultsContextFeedbacks
object
Feedback on any entity. Is it wrong? If so why? Was it right-on, and worthy of confirmation?
14 properties
BundleImportBundleJudgements
object
Schema for submitting new Judgements.
20 properties
BundleImportBundleCoasRelatedCoAs
object
4 properties
IncidentSummarySearchResultsContextActorsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextDataTablesColumns
object
5 properties
IncidentSummarySearchResultsContextSightingsContextLibraryLoadEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleCampaignsActivity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
2 properties
BundleImportBundleSightingsDetectionInterval
object
The time interval during which the malicious activity was detected by the source engine or security tool. This may differ from the activityinterval if detectio…
2 properties
IncidentSummarySearchResultsContextIndicatorsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
BundleImportBundleSightingsTargets
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties
CVEDataMeta
object
2 properties
IncidentSummarySearchResultsContextSightingsContextFileMoveEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextSightingsContextNetflowEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextAssetsValidTime
object
Specifies the time range during which the asset is considered valid or accurate. For example, if an asset entity represents a device, the validtime field could…
2 properties
IncidentSummarySearchResultsContextSightingsRelationsRelationInfo
object
IncidentSummarySearchResultsContextVerdictsObservable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleAssetMappingsObservable
object
An AssetMapping is a record that a specific Observable maps to an Asset for an indicated period of time.
2 properties
KillChainPhase
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
2 required
PatchIncident
object
For submitting a new Incident.
30 properties
BundleImportBundleNotesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
RiskScores
object
3 properties
Adversary
object
7 properties
4 required
BundleImportBundleNotes
object
Schema for submitting Notes
15 properties
ValidTime
object
Period of time when a cyber observation is valid.
2 properties
IncidentSummarySearchResultsContextRelationshipsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleSightingsContextLibraryLoadEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextWeaknessesPotentialMitigations
object
5 properties
Response8129956Engines
object
8 properties
8 required
IncidentSummarySearchResultsContextAssetMappingsObservable
object
An AssetMapping is a record that a specific Observable maps to an Asset for an indicated period of time.
2 properties
BundleImportBundleSightingsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextSightingsContextFileCreateEvents
object
9 properties
IncidentSummarySearchResultsContextSightingsContextFileDeleteEvents
object
9 properties
CoveringProduct
object
5 properties
1 required
NewAttackPattern
object
For submitting a new AttackPattern
19 properties
3 required
BundleImportBundleSightingsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextSightingsContextHttpEventsTraffic
object
9 properties
VulnerabilityImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
Incident
object
35 properties
6 required
IncidentSummarySearchResultsContextSightingsData
object
An embedded data table for the Sighting.
3 properties
BundleImportBundleSightingsRelationsRelated
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleSightings
object
For submitting a new Sighting.
30 properties
IncidentSummarySearchResultsIncidentTime
object
Relevant time values associated with this Incident.
7 properties
BundleImportBundleNotesRelatedEntities
object
2 properties
IncidentSummarySearchResultsContextNotesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleMalwaresExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleCampaignsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
TacticView
object
25 properties
7 required
IncidentScores
object
Used to indicate the severity or impact score of the threat represented by the incident.
ComparedAdversary
object
8 properties
5 required
IncidentSummarySearchResultsContextSightingsDetectionInterval
object
The time interval during which the malicious activity was detected by the source engine or security tool. This may differ from the activityinterval if detectio…
2 properties
BundleImportBundleWeaknessesOperatingSystems
object
5 properties
IncidentSummarySearchResultsContextIndicators
object
An indicator is a test, or a collection of judgements that define criteria for identifying the activity, or presence of malware, or other unwanted software. We…
26 properties
IncidentSummarySearchResultsContextSightingsContextFileModifyEvents
object
9 properties
IncidentSummarySearchResultsContextIdentityAssertionsIdentityObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextActorsIdentityRelatedIdentities
object
Describes a related Identity
4 properties
BundleImportBundleWeaknessesPotentialMitigations
object
5 properties
ErrorMessage
object
7 properties
5 required
IncidentSummarySearchResultsContextIndicatorsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextSightingsActivityInterval
object
The time interval during which the malicious activity occurred. For example, the time when a malware sample was executing, or the time range of a network intru…
2 properties
IncidentSummarySearchResultsContextMalwaresKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
Response8129956EnginesCoverageConfigurationInsightsParams
object
1 property
1 required
IncidentSummarySearchResultsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextSightingsContextProcessCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleIndicatorsSpecificationRequiredJudgements
object
4 properties
BulkActions
object
4 properties
BundleImportBundleActorsIdentityRelatedIdentities
object
Describes a related Identity
4 properties
BundleImportBundleMalwares
object
For submitting a new Malware.
18 properties
BundleImportBundleCoasOpenC2CoaTarget
object
2 properties
IncidentSummarySearchResultsContextSightingsContextLibraryLoadEvents
object
8 properties
BundleImportBundleIdentityAssertionsIdentityObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleAssetMappingsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleSightingsContextFileCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
NewIncident
object
For submitting a new Incident.
30 properties
3 required
BundleImportBundleVulnerabilitiesConfigurationsNodesChildren
object
3 properties
BundleImportBundleSightingsContextRegistryDeleteEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleSightingsContextFileModifyEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleIdentityAssertions
object
For submitting a new IdentityAssertion.
14 properties
IncidentSummarySearchResultsContextCampaignsActivity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
2 properties
IncidentSummarySearchResultsContextVulnerabilities
object
Indicates weakness or flaw in the system that can be exploited by an attacker to gain unauthorized access or cause harm to the system. Vulnerabilities can exis…
19 properties
BundleImportBundleSightingsContextRegistryDeleteEvents
object
8 properties
BundleImportBundleWeaknessesDetectionMethods
object
4 properties
IncidentSummarySearchResultsContextJudgements
object
A judgement about the intent or nature of an observable. For example, is it malicious, meaning is is malware and subverts system operations? It could also be c…
20 properties
BundleImportBundleWeaknessesCommonConsequences
object
4 properties
BundleImportBundleSightingsContextRegistrySetEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleSightingsSensorCoordinates
object
Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
3 properties
IncidentSummarySearchResultsContextNotesRelatedEntities
object
2 properties
BundleImportBundleSightingsContextNetflowEvents
object
22 properties
IncidentSummarySearchResultsContextFeedbacksExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleTargetRecordsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
TechniqueView
object
24 properties
7 required
BundleImportBundleJudgementsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextAssetMappingsValidTime
object
For each asset, we allow for the assertion of time bound properties.This gives us both a record of the current state of the asset,as well as history.
2 properties
BundleImportBundleCoasOpenC2Coa
object
6 properties
BundleImportBundleIndicatorsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
Response8129956EnginesModes
object
3 properties
3 required
IncidentSummarySearchResultsContextSightingsRelationsRelated
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextIndicatorsValidTime
object
The time range during which this Indicator is considered valid.
2 properties
IncidentSummarySearchResultsContextSightings
object
A sighting indicates that a particular entity or [indicator](indicator.md) was observed in an environment and can be an indication of a current or potential th…
30 properties
IncidentSummarySearchResultsContextCoasOpenC2CoaModifiersTime
object
Period of time when a cyber observation is valid.
2 properties
BaseTTPCoverage
object
6 properties
3 required
BundleImportBundleWeaknessesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextCoasOpenC2CoaAction
object
1 property
IncidentSummarySearchResultsContextSightingsContextRegistryCreateEvents
object
7 properties
BundleImportBundleSightingsRelationsRelationInfo
object
IncidentSummarySearchResultsContextSightingsContextRegistrySetEvents
object
10 properties
BundleImportBundleVulnerabilitiesImpactCvssV3
object
31 properties
BundleImportBundleTools
object
For submitting a new Tool.
18 properties
IncidentSummarySearchResultsContextDataTablesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
ExternalReference
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextSightingsContextFileMoveEvents
object
10 properties
BundleImportBundleSightingsRelationsSource
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
IncidentSummarySearchResultsContextSightingsDataColumns
object
5 properties
IncidentSearchResults
object
37 properties
NewCOA
object
Schema for submitting new COAs
24 properties
BundleImportBundleSightingsContextProcessCreateEvents
object
19 properties
BundleImportBundleIdentityAssertionsAssertions
object
2 properties
BundleImportBundleSightingsContextHttpEvents
object
12 properties
BundleImportBundleSightingsContextFileMoveEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
SCIMInfos
object
3 properties
3 required
IncidentSummarySearchResultsContextJudgementsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleWeaknessesTechnologies
object
2 properties
IncidentSummarySearchResultsContextAttackPatternsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleVerdictsObservable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleIndicatorsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
IncidentSummarySearchResultsContextSightingsContextHttpEvents
object
12 properties
BundleImportBundleIndicators
object
For submitting a new Indicator
26 properties
Response8129956EnginesCoverage
object
1 property
1 required
IncidentSummarySearchResultsContextTargetRecords
object
A TargetRecord is a Sighting that has no threat or observables associated with it, it's a way of saying they saw a set of observables together as a Target.
15 properties
IncidentSummarySearchResultsContextSightingsContextFileModifyEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextIndicatorsCompositeIndicatorExpression
object
2 properties
BundleImportBundleFeedbacksExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleTargetRecordsTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties
BundleImportBundleSightingsActivityInterval
object
The time interval during which the malicious activity occurred. For example, the time when a malware sample was executing, or the time range of a network intru…
2 properties
BundleImportBundleDataTables
object
Schema for submitting a NewDataTable record.
18 properties
BundleImportBundleSightingsContextProcessCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextIdentityAssertionsAssertions
object
2 properties
IncidentSummarySearchResultsContextSightingsSensorCoordinates
object
Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
3 properties
BundleImportBundleWeaknessesLanguages
object
3 properties
IncidentSummarySearchResultsContextVulnerabilitiesConfigurationsNodesCpeMatch
object
6 properties
BundleImportBundleMalwaresKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties
IncidentSummarySearchResultsContextCoas
object
Course of Action. A corrective or preventative action to be taken in response to a threat.
24 properties
IncidentSummarySearchResultsContextSightingsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextWeaknesses
object
A mistake or condition that, if left unaddressed, could under the proper conditions contribute to a cyber-enabled capability being vulnerable to attack, allowi…
31 properties
MitreCoverage
object
4 properties
IncidentSummarySearchResultsContextAssetPropertiesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
BundleImportBundleSightingsContextFileCreateEvents
object
9 properties
BundleImportBundleSightingsData
object
An embedded data table for the Sighting.
3 properties
BundleImportBundleSightingsContextRegistryCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleSightingsContextFileDeleteEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextTargetRecordsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextCoasOpenC2CoaActuator
object
2 properties
BundleImportBundleCampaigns
object
Schema for submitting new Campaigns
21 properties
IncidentSummarySearchResultsContextVerdicts
object
A Verdict is chosen from all of the Judgements on that Observable which have not yet expired. The highest priority Judgement becomes the active verdict. If the…
6 properties
BundleImportBundleActors
object
Schema for submitting new Actors
23 properties
CompareAdversariesParams
object
2 properties
1 required
IncidentSummarySearchResultsContextSightingsContextRegistryRenameEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextIndicatorsSpecification
object
An indicator based on a list of judgements. If any of the Observables in it's judgements are encountered, than it may be matches against. If there are any requ…
3 properties
BundleImportBundleVulnerabilitiesConfigurations
object
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
2 properties
MetaData
object
metadata associated to the incident.
IncidentTime
object
Relevant time values associated with this Incident.
7 properties
BundleImportBundleVulnerabilities
object
For submitting a new vulnerability.
19 properties
BundleImportBundleSightingsTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
BundleImportBundleFeedbacks
object
Schema for submitting new Feedback.
14 properties
BundleImportBundleWeaknessesAlternateTerms
object
2 properties
IncidentSummarySearchResultsContextExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextVulnerabilitiesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextJudgementsValidTime
object
Period of time when a cyber observation is valid.
2 properties
IncidentSummarySearchResultsContextCoasExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
TotalIncidentsPerTechnique
object
IncidentSummarySearchResultsContextSightingsContextHttpEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextAssetProperties
object
Assets do not have any product specific properties, those are represented in AssetProperties - which is a record that asserts one or more properties of an Asse…
14 properties
IncidentSummarySearchResultsContextMalwares
object
Malware is a type of TTP that is also known as malicious code and malicious software, and refers to a program that is inserted into a system, usually covertly,…
18 properties
BundleImportBundleTargetRecordsTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextSightingsContextProcessCreateEvents
object
19 properties
NewRelationship
object
Schema for submitting new Relationships.
17 properties
3 required
IncidentSummarySearchResultsContextAssetMappingsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextCoasValidTime
object
Period of time when a cyber observation is valid.
2 properties
BundleImportBundleSightingsContextNetflowEventsTraffic
object
9 properties
IncidentSummarySearchResultsContextSightingsTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextSightingsContextFileCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties
IncidentSummarySearchResultsContextIncidentsIncidentTime
object
Relevant time values associated with this Incident.
7 properties
BundleImportBundleVulnerabilitiesConfigurationsNodesCpeMatch
object
6 properties
BundleImportBundleIdentityAssertionsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties
IncidentSummarySearchResultsContextSightingsTargets
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties
IncidentSummarySearchResultsContextWeaknessesCommonConsequences
object
4 properties
BundleImportBundleIncidents
object
For submitting a new Incident.
30 properties
PartialBundle
object
Describes a Bundle of any set of CTIM entities.
64 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Cisco XDR publishes across the network.