Anomali Threat Stream v1
The Anomali Threat Stream v1 connector allows users to integrate threat intelligence capabilities into their security operations, enabling automated actions such as report retrieval, threat model management, and sandbox submissions.
Anomali Threat Stream v1 is a comprehensive threat intelligence platform that enables security professionals to detect, investigate, and respond to emerging threats. This connector allows Swimlane Turbine users to integrate real-time threat intelligence into their security workflows, enhancing their ability to tag, create, and manage threat models, as well as analyze and submit files or URLs for sandbox analysis. By leveraging Anomali's rich intelligence data, users can automate threat detection and response, streamline investigations, and improve their overall security posture.
Prerequisites
To effectively utilize the Anomali Threat Stream v1 connector with Turbine, ensure you have the following prerequisites:
- API Key Authentication with the following parameters:
- URL: The endpoint URL for the Anomali Threat Stream API.
- API Key: Your unique identifier to authenticate with the Anomali Threat Stream API.
- API User: The username associated with your Anomali Threat Stream account.
Capabilities
The Anomali ThreatStream connector has the following capabilities:
- Add Tag to Model
- Create Model
- Get Analysis Report
- Get Analysis Status
- Get Indicators by Model
- Get Model Description
- Get Model List
- Get Passive DNS
- Submit to Sandbox
- Update Model
Task Setup
Submit to Sandbox
report_radio-platform
Platform on which the submitted URL or file will be detonated. The following platforms are supported:
- For organizations using the Default Threat Stream Sandbox (Cuckoo): WINDOWS7
- For organizations using the Threat Stream JoeSandbox offering: MACOSX, WINDOWS7, WINDOWS7OFFICE2010, WINDOWS10x64.
- For organizations using Joe Sandbox via an individual subscription: ANDROID4.4, ANDROID5.1, ANDROID6.0, MACOSX, WINDOWSXP, WINDOWSXPNATIVE, WINDOWS7, WINDOWS7NATIVE, WINDOWS7OFFICE2010, WINDOWS7OFFICE2013, WINDOWS10, WINDOWS10x64, MACOSXVM, LINUX, ANDROID9.0.
Indicator Types
The following table lists all available indicator types in ThreatStream.
The severity values listed in the table below represent the default severity values that Anomali assigns to observables of a given indicator types. However, default values are not displayed in the following cases:
- When severity value assigned to observable by the source are used
- When users modify the assigned value while editing observables that belong to their organizations on ThreatStream
Indicator Type | Name | Type | Severity | Description |
|---|---|---|---|---|
actor_ip | Actor IP | IP | Low | IP address associated with a system involved in malicious activity. Example: itype="actor_ip" |
actor_ipv6 | Actor IPv6 | IP | Low | IPv6 address associated with a system involved in malicious activity. Example: itype="actor_ipv6" |
actor_subject | Actor Subject Line | String | High | Subject from an email associated with a threat actor. Example: itype="actor_subject" |
adware_domain | Adware Domain | Domain | Low | A domain name associated with adware or other Potentially Unwanted Applications (PUA). Example: itype="adware_domain" |
adware_registry_key | Adware Registry Key | String | Low | A registry key associated with adware or other Potentially Unwanted Applications (PUA). Example: itype="adware_registry_key" |
anon_proxy | Anonymous Proxy IP | IP | Low | IP address of the system on which anonymous proxy software is hosted. Example: itype="anon_proxy" |
anon_proxy_ipv6 | Anonymous Proxy IPv6 | IP | Low | IPv6 address of the system on which anonymous proxy software is hosted. Example: itype="anon_proxy_ipv6" |
anon_vpn | Anonymous VPN IP | IP | Low | IP address associated with commercial or free Virtual Private Networks (VPN). Example: itype="anon_vpn" |
anon_vpn_ipv6 | Anonymous | IP | Low | IPv6 address associated with commercial or free Virtual Private Networks (VPN). Example: itype:"anon_vpn_ipv6" |
apt_domain | APT Domain | Domain | Very-High | Domain name associated with a known Advanced Persistent Threat (APT) actor used for command and control, launching exploits, or data exfiltration. Example: itype=" apt_domain" |
apt_email | APT Email | High | Email address used by a known Advanced Persistent Threat (APT) actor for sending targeted, spear phishing emails. Example: itype="apt_email" | |
apt_email_subject_line | APT Email Subject Line | String | High | Subject from an email associated with an Advanced Persistent Threat (APT) actor. Example: itype="apt_email_subject_line" |
apt_file_name | APT File Name | String | Very-High | Name of a file used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_file_name" |
apt_file_path | APT File Path | String | Very-High | File path used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_file_path" |
apt_ip | APT IP | IP | Very-High | IP address associated with known Advanced Persistent Threat (APT) actor for command and control, data exfiltration, or targeted exploitation. Example: itype="apt_ip" |
apt_ipv6 | APT IPv6 | IP | Very-High | IPv6 address associated with known Advanced Persistent Threat (APT) actor for command and control, data exfiltration, or targeted exploitation. Example: itype="apt_ipv6" |
apt_md5 | APT File Hash | Hash | Very-High | MD5 or SHA hash of a malware sample used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_md5" |
apt_mta | APT Mail Transfer Agent | String | Very-High | Mail transfer agent used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_mta" |
apt_mutex | APT Mutex | String | Very-High | Mutex used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_mutex" |
apt_registry_key | APT Registry | String | Very-High | Registry key used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_registry_key" |
apt_service_description | APT Service Description | String | Very-High | Description used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_service_description" |
apt_service_displayname | APT Service Display Name | String | Very-High | Service display name used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_service_displayname" |
apt_service_name | APT Service Name | String | Very-High | Service name used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_service_name" |
apt_ssdeep | APT SSDeep Hash | String | Very-High | SSDeep Hash used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_ssdeep" |
apt_subject | APT Subject Line | String | High | Email subject line used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_subject" |
apt_ua | APT User Agent | String | High | User agent string used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_ua" |
apt_url | APT URL | URL | Very-High | URL used by a known Advanced Persistent Threat (APT) actor for command and control, launching web based exploits, or data exfiltration. Example: itype=" apt_url" |
bot_ip | Infected Bot IP | IP | Low | IP address of an infected machine acting as an autonomous bot. Example: itype="bot_ip" |
bot_ipv6 | Infected Bot IPv6 | IP | Low | IPv6 address of an infected machine acting as an autonomous bot. Example: itype="bot_ipv6" |
brute_ip | Brute Force IP | IP | Low | IP address associated with password brute force activity. Example: itype="brute_ip" |
brute_ipv6 | Brute Force IPv6 | IP | Low | IPv6 address associated with password brute force activity. Example: itype="brute_ipv6" |
c2_domain | Malware C&C Domain Name | Domain | High | Domain name used by malware for command and control communication. Example: itype="c2_domain" |
c2_ip | Malware C&C IP Address | IP | High | IP address used by malware for command and control communication. Example: itype="c2_ip" |
c2_ipv6 | Malw are C&C IPv6 Address | IP | High | IPv6 address used by malware for command and control communication. Example: itype="c2_ipv6" |
c2_url | Malware C&C URL | URL | High | URL used by malware for command and control communication. Example: itype="c2_url" |
comm_proxy_domain | Commercial Webproxy Domain | Domain | Low | Domain of the system on which commercial proxy software is hosted. Example: itype="comm_proxy_domain" |
comm_proxy_ip | Commercial Webproxy IP | IP | Low | IP address of the system on which commercial proxy software is hosted. Example: itype="comm_proxy_ip" |
compromised_domain | Compromised Domain | Domain | Low | Domain name of website or server that has been compromised. Example: itype="compromised_domain" |
compromised_email | Compromised Account Email | Low | Email address that has been compromised and/or taken over by a threat actor. Example: itype="compromised_email" | |
compromised_email_subject | Compromised Email Subject | String | Low | Email subject from a known compromised email address. Example: itype="compromised_email_subject" |
compromised_ip | Compromised IP | IP | Low | IP address of website or server that has been compromised. Example: itype="compromised_ip" |
compromised_ipv6 | Compromised IPv6 | IP | Low | IPv6 address of website or server that has been compromised. Example: itype="compromised_ipv6" |
compromised_serv_account | Compromised Service Account | String | Low | Account information associated with a service account that has been compromised and/or taken over by a threat actor. Example: itype="compromised_serv_account" |
compromised_url | Compromised URL | URL | Medium | URL of the website or server that has been compromised. Example: itype="compromised_url" |
crypto_hash | Cryptocurrency Mining Software | Hash | High | File hash for cryptocurrency mining software. Example: itype="crypto_hash" |
crypto_ip | Cryptocurrency IP | IP | High | IP address associated with cryptocurrency mining software. Example: itype="crypto_ip" |
crypto_pool | Cryptocurrency Pool Domain | Domain | High | Domain for cryptocurrency pool. Example: itype="crypto_pool" |
crypto_url | Cryptocurrency URL | URL | High | URL where cryptocurrency mining software is hosted. Example: itype="crypto_url" |
crypto_wallet | Cryptocurrency Wallet Address | String | Very-High | Public or private cryptocurrency wallet key. Example: itype="crypto_wallet" |
ddos_ip | DDOS IP | IP | Low | IP address associated with Distributed Denial of Service (DDoS) attacks. Example: itype="ddos_ip" |
ddos_ipv6 | DDOS IPv6 | IP | Low | IPv6 address associated with Distributed Denial of Service (DDoS) attacks. Example: itype="ddos_ipv6" |
disposable_email_domain | Disposable Email Domain | Domain | Low | Domain associated with disposable email activity. Example: itype="disposable_email_domain" |
dyn_dns | Dynamic DNS | Domain | Low | Domain name used for hosting Dynamic DNS services. Example: itype="dyn_dns" |
email_attachment_subject | Email Attachment Subject | String | Low | Email subject from a known compromised email attachment. Example: itype="email_attachment_subject" |
exfil_domain | Data Exfiltration Domain | Domain | High | Domain name associated with the infrastructure used for data exfiltration. Example: itype="exfil_domain" |
exfil_ip | Data Exfiltration IP | IP | High | IP address used for data exfiltration. Example: itype="exfil_ip" |
exfil_ipv6 | Data Exfiltration IP | IP | High | IPv6 address used for data exfiltration. Example: itype="exfil_ipv6" |
exfil_url | Data Exfiltration URL | URL | High | URL used for data exfiltration. Example: itype="exfil_url" |
exploit_domain | Exploit Kit Domain | Domain | Very-High | Domain name associated with the web server hosting an exploit kit or launching web-based exploits. Example: itype="exploit_domain" |
exploit_ip | Exploit Kit IP | IP | High | IP address associated with the web server hosting an exploit kit or launching web-based exploits. Example: itype="exploit_ip" |
exploit_ipv6 | Exploit Kit IPv6 | IP | High | IPv6 address associated with the web server hosting an exploit kit or launching web-based exploits. Example: itype="exploit_ipv6" |
exploit_url | Exploit Kit URL | URL | Very-High | URL used for launching web- based exploits. Example: itype="exploit_url" |
fraud_domain | Fraud Hash | Domain | High | Domain associated with fraudulent activity. Example: itype="fraud_domain" |
fraud_email | Fraud Email | Low | Email address associated with fraudulent activity. Example: itype="fraud_email" | |
fraud_email_subject | Fraud Email Subject | String | Medium | Subject from an email associated with fraud activity. Example: itype="fraud_ip" |
fraud_ip | Fraud IP Address | IP | High | IP address associated with fraudulent activity. Example: itype="fraud_email_subject" |
fraud_md5 | Fraud Hash | Hash | Very-High | Hash associated with fraudulent activity. Example: itype="fraud_md5" |
fraud_url | Fraud URL | URL | Medium | URL associated with fraudulent activity. Example: itype="fraud_url" |
free_email_domain | Free Email Domain | Domain | Low | Domain associated with free email service activity. Example: itype="free_email_domain" |
geolocation_url | IP Geolocation URL | URL | Low | URL that can be used to provide IP Geo location services. Example: itype="geolocation_url" |
hack_tool | Hacking Tool | String | High | Name of general hacking software tools used by threat actors. Example: itype="hack_tool" |
hack_tool_md5 | Hack Tool File Hash | Hash | Very-High | MD5 or SHA hash of general hacking software tools used by threat actors. Example: itype="hack_tool_md5" |
i2p_ip | I2P IP Address | IP | Low | IP address observed to be connecting to the I2P (Invisible Internet Project) network. Example: itype="i2p_ip" |
i2p_ipv6 | I2P IPv6 Address | IP | Low | IPv6 address observed to be connecting to the I2P (Invisible Internet Project) network. Example: itype="i2p_ipv6" |
ipcheck_url | IP Check URL | URL | Low | URL that can be used to provide IP checking services, such as echoing the Internet facing IP address of the client. Example: itype="ipcheck_url" |
mal_domain | Malware Domain | Domain | Very-High | Domain contacted by malware sample, could be for command and control commands, or to check if the client is online. Example: itype="mal_domain" |
mal_email | Malware Email | Low | Email address used to send malware through malicious links or attachments. Example: itype="mal_email" | |
mal_email_subject | Malware Email Subject | String | Medium | Subject from an email associated with malware activity. Example: itype="mal_email_subject" |
mal_file_name | Malware File Name | String | Very-High | File name of malware sample. Example: itype="mal_file_name" |
mal_file_path | Malware File Path | String | Very-High | File path of malware sample. Example: itype="mal_file_path" |
mal_ip | Malware C&C IP | IP | Very-High | IP address contacted by malware sample, could be for command and control commands, or to check if the client is online. Example: itype="mal_ip" |
mal_ipv6 | Malware C&C IPv6 | IP | Very-High | IPv6 address contacted by malware sample command and control commands, or to check if the client is online. Example: itype="mal_ipv6" |
mal_md5 | Malware File Hash | Hash | Very-High | MD5 or SHA hash of malware sample. Example: itype="mal_md5" |
mal_mutex | Malware Mutex | String | Very-High | Mutex of malware sample. Example: itype="mal_mutex" |
mal_registry_key | Malware Registry Key | String | High | Registry key of malware sample. Example: itype="mal_registry_key" |
mal_service_description | Malware Service Description | String | Very-High | Service description associated with the malware sample. Example: itype="mal_service_description" |
mal_service_displayname | Malware Service Display Name | String | Very-High | Service display name associated with the malware sample. Example: itype="mal_service_displayname" |
mal_service_name | Malware Service Name | String | Very-High | Service name associated with the malware sample. Example: itype="mal_service_name" |
mal_ssdeep | Malware SSDeep Hash | String | Very-High | SSDeep Hash associated with the malware sample. Example: itype="mal_ssdeep" |
mal_sslcert_sh1 | SSL Certificate Hash | Hash | High | MD5 or SHA hash of SSL certificate associated with malware or botnet activities. Example: itype="mal_sslcert_sh1" |
mal_ua | Malware User Agent | String | Low | User agent string used by malware sample when communicating via HTTP. Example: itype="mal_ua" |
mal_url | Malware URL | URL | Very-High | URL contacted by malware sample when run on an infected host. Example: itype="mal_url" |
p2pcnc | Peer-to-Peer C&C IP Address | IP | Medium | IP addressed associated with a peer-to-peer command and control infrastructure. Example: itype="p2pcnc" |
p2pcnc_ipv6 | Peer-to-Peer C&C IPv6 Address | IP | Medium | IPv6 addressed associated with a peer-to-peer command and control infrastructure. Example: itype="p2pcnc_ipv6" |
parked_domain | Parked Domain | Domain | Low | A domain name of a website which is currently parked. Example: itype="parked_domain" |
parked_ip | Domain Parking IP | IP | Low | An IP addressed used for parking newly registered or inactive domain names. Example: itype="parked_ip" |
parked_ipv6 | Domain Parking IPv6 | IP | Low | An IPv6 addressed used for parking newly registered or inactive domain names. Example: itype="parked_ipv6" |
parked_url | Parked URL | URL | Low | A URL of a website that is currently parked. Example: itype="parked_url" |
pastesite_url | Paste Site URL | URL | Low | A URL that can be used for sharing pastes or text content anonymously. Example: itype="pastesite_url" |
phish_domain | Phishing Domain | Domain | Very-High | A domain used to perform phishing or spear phishing attacks or contained in a phishing email. Example: itype="phish_domain" |
phish_email | Phishing Email Address | Very-High | An email address associated with sending phishing or spear phishing emails to victims. Example: itype="phish_email" | |
phish_email_subject | Phishing Email Subject | String | High | Subject from an email associated with phishing activity. Example: itype="phish_email_subject" |
phish_ip | Phishing IP Address | IP | Very-High | IP Address that has been used to perform phishing or spear phishing or is contained in a phishing email. Example: itype="phish_ip" |
phish_ipv6 | Phishing IPv6 Address | IP | Very-High | IPv6 Address that has been used to perform phishing or spear phishing or is contained in a phishing email. Example: itype="phish_ipv6" |
phish_md5 | Phishing File Hash | Hash | Very-High | Hash related to a file used to perform phishing or spear phishing attacks or contained in a phishing email. Example: itype="phish_md5" |
phish_url | Phishing URL | URL | Very-High | A URL used to perform phishing or spear phishing attacks or contained in a phishing email. Example: itype="phish_url" |
proxy_ip | Open Proxy IP | IP | Low | IP address hosting open or anonymous proxy software. Allows user to hide their IP address from target. Example: itype="proxy_ip" |
proxy_ipv6 | Open Proxy IPv6 | IP | Low | IPv6 address hosting open or anonymous proxy software. Allows user to hide their IP address from target. Example: itype="proxy_ipv6" |
scan_ip | Scanning IP | IP | Medium | IP address observed to perform port scanning and vulnerability scanning activities. Example: itype="scan_ip" |
scan_ipv6 | Scanning IPv6 | IP | Medium | IPv6 address observed to perform port scanning and vulnerability scanning activities. Example: itype="scan_ipv6" |
sinkhole_domain | Sinkhole Domain | Domain | Low | A domain name that researchers or security companies typically sinkhole. Example: itype="sinkhole_domain" |
sinkhole_ip | Sinkhole IP | IP | Low | An IP address that is known to be used to sinkhole malicious domain names. Example: itype="sinkhole_ip" |
sinkhole_ipv6 | Sinkhole IPv6 | IP | Low | An IPv6 address that is known to be used to sinkhole malicious domain names. Example: itype="sinkhole_ipv6" |
social_media_url | Social Media URL | URL | Medium | URL related to social media activity. This indicator type is provided by select feeds and cannot be imported through the ThreatStream user interface. Example: itype="social_media_url" |
spam_domain | Spam Domain | Domain | Low | A malicious domain name contained in the SPAM email messages. Example: itype="spam_domain" |
spam_email | Spammer Email Address | Low | Email address that has been observed sending SPAM emails. Example: itype="spam_email" | |
spam_email_subject | Spam Email Subject | String | Low | Subject from an email associated with spam activity. Example: itype="spam_email_subject" |
spam_ip | Spammer IP | IP | Low | An IP address that is known to send SPAM emails. Example: itype="spam_ip" |
spam_ipv6 | Spammer IPv6 | IP | Low | An IPv6 address that is known to send SPAM emails. Example: itype="spam_ipv6" |
spam_mta | Spam Mail Transfer Agent | String | Low | Mail transfer agent known to be associated with SPAM emails. Example: itype="spam_mta" |
spam_url | Spam URL | URL | Low | A malicious URL contained in the SPAM email messages. Example: itype="spam_url" |
speedtest_url | Speed Test URL | URL | Low | A URL that can be used to run internet speed tests or bandwidth measurements of the client's network connection. Example: itype="speedtest_url" |
ssh_ip | SSH Brute Force IP | IP | Low | IP addresses associated with SSH brute force attempts. Example: itype="ssh_ip" |
ssh_ipv6 | SSH Brute Force IPv6 | IP | Low | IPv6 addresses associated with SSH brute force attempts. Example: itype="ssh_ipv6" |
ssl_cert_serial_number | SSL Certificate Serial Number | String | Low | Serial number unique to the TLS certificate issuer that identifies the entity being signed. Example: itype="ssl_cert_serial_number" |
suppress | Suppress | n/a | n/a | Not a true indicator type. Used by Arcsight for suppressing false positives. Default Severity: n/a Example: itype="suppress" |
suspicious_domain | Suspicious Domain | Domain | Medium | A domain name that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_domain" |
suspicious_email | Suspicious Email | Low | An email address that appears to be used for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_email" | |
suspicious_email_subject | Suspicious Email Subject | String | Low | Email subject from a suspicious email address. |
suspicious_ip | Suspicious IP | IP | Medium | An IP address that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_ip" |
suspicious_reg_email | Suspicious Registrant Email | Low | A registrant email address that appears to be used for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_reg_email" | |
suspicious_url | Suspicious URL | URL | Medium | A URL that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_url" |
tor_ip | TOR Node IP | IP | Low | An IP address operating as part of The Onion Router (TOR) Network, also know as a TOR exit node. Example: itype="tor_ip" |
tor_ipv6 | TOR Node IPv6 | IP | Low | An IPv6 address operating as part of The Onion Router (TOR) Network, also know as a TOR exit node. Example: itype="tor_ipv6" |
torrent_tracker_url | Torrent Tracker URL | URL | Low | A URL used for tracking bittorrent file transfer activity. Example: itype="torrent_tracker_url" |
vpn_domain | Anonymous VPN Domain | Domain | Low | A domain name associated with commercial or free Virtual Private Networks (VPN). Example: itype="vpn_domain" |
vps_ip | Cloud Server IP | IP | Low | An IP address that is used for hosting Virtual Private Servers (VPS) or other server rentals. Example: itype="vps_ip" |
vps_ipv6 | Cloud Server IPv6 | IP | Low | An IPv6 address that is used for hosting Virtual Private Servers (VPS) or other server rentals. Example: itype="vps_ipv6" |
whois_bulk_reg_email | Whois Bulk Registrant Email | Low | A registrant email address associated with privacy domain purchased from Whois. Example: itype="whois_bulk_reg_email" | |
whois_privacy_domain | Whois Privacy Email Domain | Domain | Low | Privacy domain purchased from Whois. Example: itype="whois_privacy_domain" |
whois_privacy_email | Whois Privacy Email | Low | Email address associated with privacy domain purchased from Whois. Example: itype="whois_privacy_email" |
Threat Type
During the import process, ThreatStream uses machine learning to assign indicator types to imported observables based on the threat type you select. The following table lists all available threat types in ThreatStream, in addition to the indicator types with which they are associated.
Threat Type | Name | Example | Associated Indicator Types |
|---|---|---|---|
adware | Adware | threat_type="adware" | adware_domain |
anomalous | Anomalous | threat_type="anomalous" | geolocation_url,ipcheck_url,speedtest_url |
anonymization | Anonymization | threat_type="anonymization" | anon_proxy, anon_proxy_ipv6, anon_vpn, anon_vpn_ipv6,proxy_ip, proxy_ipv6,vpn_domain |
apt | APT | threat_type="apt" | apt_domain, apt_email, apt_email_subject, apt_file_name, apt_file_path,apt_ip, apt_ipv6, apt_md5, apt_mta, apt_mutex, apt_registry_key, apt_service_description, apt_service_displayname, apt_service_name, apt_ssdeep, apt_subject,apt_ua apt_url |
bot | Bot | threat_type="bot" | bot_ip, bot_ipv6 |
brute | Brute | threat_type="brute" | brute_ip , brute_ipv6, ssh_ip, ssh_ipv6 |
c2 | C2 | threat_type="c2" | c2_domain, c2_ip,c2_ipv6, c2_url |
compromised | Compromised | threat_type="compromised" | compromised_domain,compromised_email,compromised_email_subject,compromised_ip,compromised_ipv6,compromised_url |
crypto | Crypto | threat_type="crypto" | crypto_hash, crypto_ip, crypto_pool,crypto_url, crypto_wallet |
data_leakage | Data Leakage | threat_type="data_leakage" | pastesite_url |
ddos | DDOS | threat_type="ddos" | ddos_ip, ddos_ipv6 |
dyn_dns | Dynamic DNS | threat_type="dyn_dns" | dyn_dns |
exfil | Exfil | threat_type="exfil" | exfil_domain, exfil_ip, exfil_ipv6, exfil_url |
exploit | Exploit | threat_type="exploit" | exploit_domain,exploit_ip, exploit_ipv6, exploit_url |
fraud | Fraud | threat_type="fraud" | fraud_domain, fraud_email, fraud_email_subject, fraud_ip,fraud_md5, fraud_url |
hack_tool | Hacking Tool | threat_type="hack_tool" | hack_tool |
i2p | I2P | threat_type="i2p" | i2p_ip, i2p_ipv6 |
informational | Informational | threat_type="informational" | comm_proxy_domain, comm_proxy_ip,disposable_email_domain, free_email_domain, passphrase,ssl_cert_serial_number, whois_bulk_reg_email, whois_privacy_domain,whois_privacy_email |
malware | Malware | threat_type="malware" | mal_domain, mal_email, mal_email_subject, email_attachment_subject,mal_file_name, mal_file_path, mal_ip,mal_ipv6, mal_md5,mal_mutex, mal_registry_key, mal_service_description,mal_service_displayname, mal_service_name, mal_ssdeep, mal_sslcert_sha1, mal_ua, mal_url |
p2p | P2P | threat_type="p2p" | actor_ip actor_ipv6,actor_subject,p2pcnc, p2pcnc_ipv6, torrent_tracker_url |
parked | Parked | threat_type="parked" | parked_domain,parked_ip, parked_ipv6, parked_url |
phish | Phish | threat_type="phish" | phish_domain,phish_email, phish_email_subject,phish_ip, phish_ipv6,phish_url |
scan | Scan | threat_type="scan" | scan_ip, scan_ipv6 |
sinkhole | Sinkhole | threat_type="sinkhole" | sinkhole_domain,sinkhole_ip,sinkhole_ipv6 |
spam | Spam | threat_type="spam" | adware_registry_key,spam_domain,spam_email, spam_email_subject,spam_ip, spam_ipv6,spam_mta spam_url |
suppress | Suppress | threat_type="suppress" | suppress |
suspicious | Suspicious | threat_type="suspicious" | suspicious_domain, suspicious_email,suspicious_email_subject, suspicious_ip, suspicious_reg_email, suspicious_url |
tor | TOR | threat_type="tor" | tor_ip, tor_ipv6 |
vps | VPS | threat_type="vps" | vps_ip, vps_ipv6 |
Configurations
Anomali ThreatStream v1 API Key Authentication
Authenticates using an API Key.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
x-apikey | API key. | string | Required |
verify_ssl | Verify SSL certificate. | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
api_user | API User used for authentication. | string | Required |
Actions
Add Tag to Model
Adds tags to a specific intelligence model in Anomali Threat Stream v1, aiding in filtering for related entities.
Endpoint
- URL: /api/v1/{{model}}/{{model_id}}/tag
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.model | string | Required | Model is the type of threat model entity on which you are adding the tag(actor, campaign, incident, intelligence(observables), signature, tipreport, ttp, or vulnerability). |
path_parameters.model_id | number | Required | Model ID is the ID of the threat model entity or tag. |
data_body | object | Required | Response data |
data_body.ids | number | Optional | Unique IDs of the threat model entities or observables to which you are adding tags. |
data_body.tags | array | Required | Tags applied to the specified threat model entities or observables. |
data_body.tags.name | string | Required | The value of the tag you want to add. |
data_body.tags.tlp | string | Required | The visibility setting for the tag. Possible values include red(visible to your organization only) and white(visible to all ThreatStream users with access to the data). |
Input Example
{"path_parameters":{"model":"incident","model_id":130},"data_body":{"ids":34,"tags":[{"name":"test","tlp":"red"}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Create Model
Creates a threat model in Anomali Threat Stream v1 using specified path parameters and JSON body content.
Endpoint
- URL: /api/v1/{{model}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.model | string | Required | The type of threat model to update. Can be "actor", "campaign", "incident", "ttp", "vulnerability", or "tipreport". Possible values are actor, campaign, incident, ttp, vulnerability, tipreport. |
data_body | object | Optional | Response data |
data_body.name | string | Required | The name of the threat model to create. |
data_body.is_public | boolean | Optional | Whether the scope of threat model is visible. Possible values are true, false. Default is false. |
data_body.tlp | string | Optional | The Traffic Light Protocol designation for the threat model. Can be "red", "amber", "green", or "white". Possible values are red, amber, green, white. Default is red. |
data_body.tags | array | Optional | A comma separated list of tags. |
data_body.tags.name | string | Optional | The value of the tag you want to add. |
data_body.tags.tlp | string | Optional | The visibility setting for the tag. Possible values include red(visible to your organization only) and white (visible to all ThreatStream users with access to the data). |
data_body.description | string | Optional | The description of the threat model. |
data_body.intelligence | number | Optional | A comma separated list of indicators IDs associated with the threat model on the ThreatStream platform. |
Input Example
{"path_parameters":{"model":"incident"},"data_body":{"name":"New_Created_Actor_1","is_public":false,"tlp":"red","tags":[{"name":"test","tlp":"red"}],"description":"Description of the actor threat model","intelligence":191431508}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.Model | object | Output field: ThreatStream.Model |
ThreatStream.Model.Indicators | array | Output field: ThreatStream.Model.Indicators |
ThreatStream.Model.Indicators.ASN | string | Output field: ThreatStream.Model.Indicators.ASN |
ThreatStream.Model.Indicators.Confidence | number | Unique identifier |
ThreatStream.Model.Indicators.Country | object | Output field: ThreatStream.Model.Indicators.Country |
ThreatStream.Model.Indicators.ID | number | Unique identifier |
ThreatStream.Model.Indicators.IType | string | Type of the resource |
ThreatStream.Model.Indicators.Modified | string | Output field: ThreatStream.Model.Indicators.Modified |
ThreatStream.Model.Indicators.Organization | string | Output field: ThreatStream.Model.Indicators.Organization |
ThreatStream.Model.Indicators.Severity | string | Output field: ThreatStream.Model.Indicators.Severity |
ThreatStream.Model.Indicators.Source | string | Output field: ThreatStream.Model.Indicators.Source |
ThreatStream.Model.Indicators.Status | string | Status value |
ThreatStream.Model.Indicators.Tags | object | Output field: ThreatStream.Model.Indicators.Tags |
ThreatStream.Model.Indicators.Type | string | Type of the resource |
ThreatStream.Model.Indicators.Value | string | Value for the parameter |
ThreatStream.Model.ModelID | string | Unique identifier |
ThreatStream.Model.ModelType | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"Model":{}}}}
Get Analysis Report
Retrieves the analysis report for a submitted file or URL in Anomali Threat Stream using the specified report ID.
Endpoint
- URL: /api/v1/submit/{{report_id}}/report
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.report_id | number | Required | The report ID to return. |
Input Example
{"path_parameters":{"report_id":12414}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.Analysis | object | Output field: ThreatStream.Analysis |
ThreatStream.Analysis.Category | string | Output field: ThreatStream.Analysis.Category |
ThreatStream.Analysis.Completed | string | Output field: ThreatStream.Analysis.Completed |
ThreatStream.Analysis.Duration | number | Output field: ThreatStream.Analysis.Duration |
ThreatStream.Analysis.Network | array | Output field: ThreatStream.Analysis.Network |
ThreatStream.Analysis.Network.UdpDestinaton | string | Output field: ThreatStream.Analysis.Network.UdpDestinaton |
ThreatStream.Analysis.Network.UdpPort | number | Output field: ThreatStream.Analysis.Network.UdpPort |
ThreatStream.Analysis.Network.UdpSource | string | Output field: ThreatStream.Analysis.Network.UdpSource |
ThreatStream.Analysis.Network.Hosts | string | Output field: ThreatStream.Analysis.Network.Hosts |
ThreatStream.Analysis.ReportID | string | Unique identifier |
ThreatStream.Analysis.Started | string | Output field: ThreatStream.Analysis.Started |
ThreatStream.Analysis.Verdict | string | Output field: ThreatStream.Analysis.Verdict |
ThreatStream.Analysis.VmID | string | Unique identifier |
ThreatStream.Analysis.VmName | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"Analysis":{}}}}
Get Analysis Status
Retrieve the current status of a sandbox report in Anomali Threat Stream using the report ID.
Endpoint
- URL: /api/v1/submit/{{report_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.report_id | number | Required | The report ID to check the status. |
Input Example
{"path_parameters":{"report_id":12414}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.Analysis | object | Output field: ThreatStream.Analysis |
ThreatStream.Analysis.Platform | string | Output field: ThreatStream.Analysis.Platform |
ThreatStream.Analysis.ReportID | string | Unique identifier |
ThreatStream.Analysis.Status | string | Status value |
ThreatStream.Analysis.Verdict | string | Output field: ThreatStream.Analysis.Verdict |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"Analysis":{}}}}
Get Indicators by Model
Retrieve a list of indicators linked to a specific model and its ID in Anomali Threat Stream v1.
Endpoint
- URL: /api/v1/{{model}}/{{id}}/intelligence
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.model | string | Required | The threat model of the returned list. Possible values are actor, campaign, incident, signature, ttp, vulnerability, tipreport, malware, attack pattern. |
path_parameters.id | string | Required | The threat model ID. |
Input Example
{"path_parameters":{"model":"actor","id":"1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.Model | object | Output field: ThreatStream.Model |
ThreatStream.Model.Indicators | array | Output field: ThreatStream.Model.Indicators |
ThreatStream.Model.Indicators.ASN | string | Output field: ThreatStream.Model.Indicators.ASN |
ThreatStream.Model.Indicators.Confidence | number | Unique identifier |
ThreatStream.Model.Indicators.Country | object | Output field: ThreatStream.Model.Indicators.Country |
ThreatStream.Model.Indicators.ID | number | Unique identifier |
ThreatStream.Model.Indicators.IType | string | Type of the resource |
ThreatStream.Model.Indicators.Modified | string | Output field: ThreatStream.Model.Indicators.Modified |
ThreatStream.Model.Indicators.Organization | string | Output field: ThreatStream.Model.Indicators.Organization |
ThreatStream.Model.Indicators.Severity | string | Output field: ThreatStream.Model.Indicators.Severity |
ThreatStream.Model.Indicators.Source | string | Output field: ThreatStream.Model.Indicators.Source |
ThreatStream.Model.Indicators.Status | string | Status value |
ThreatStream.Model.Indicators.Tags | string | Output field: ThreatStream.Model.Indicators.Tags |
ThreatStream.Model.Indicators.Type | string | Type of the resource |
ThreatStream.Model.Indicators.Value | string | Value for the parameter |
ThreatStream.Model.ModelID | string | Unique identifier |
ThreatStream.Model.ModelType | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"Model":{}}}}
Get Model Description
Retrieve an HTML file detailing the threat model from Anomali Threat Stream, requiring specific model and ID path parameters.
Endpoint
- URL: /api/v1/{{model}}/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.model | string | Required | The threat model. Can be "actor", "campaign", "incident", "signature", "ttp", "vulnerability", or "tipreport". Possible values are actor, campaign, incident, signature, ttp, vulnerability, tipreport. |
path_parameters.id | string | Required | The threat model ID. |
Input Example
{"path_parameters":{"model":"actor","id":"1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
File | object | Output field: File |
File.EntryID | string | Unique identifier |
File.Extension | string | Output field: File.Extension |
File.Info | string | Output field: File.Info |
File.MD5 | string | Output field: File.MD5 |
File.Name | string | Name of the resource |
File.SHA1 | string | Output field: File.SHA1 |
File.SHA256 | string | Output field: File.SHA256 |
File.SHA512 | string | Output field: File.SHA512 |
File.SSDeep | string | Output field: File.SSDeep |
File.Size | number | Output field: File.Size |
File.Type | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"File":{"EntryID":"3171@3c9bd2a0-9eac-465b-8799-459df4997b2d","Extension":"html","Info":"text/html; charset=utf-8","MD5":"18d7610f85c1216e78c59cbde5c470d9","Name":"actor_1.html","SHA1":"c778f72fd7799108db427f632ca6b2bb07c9bde4","SHA256":"6d06bdc613490216373e2b189c8d41143974c7a128da26e8fc4ba4f45a7e718b","SHA512":"989b0ae32b61b3b5a7ea1c3...
Get Model List
Retrieves a list of threat models from Anomali Threat Stream v1 based on the specified model path parameter.
Endpoint
- URL: /api/v1/{{model}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.model | string | Required | The threat model of the returned list. Possible values are actor, campaign, incident, signature, ttp, vulnerability, tipreport, malware, attack pattern. |
Input Example
{"path_parameters":{"model":"actor"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.List | array | Output field: ThreatStream.List |
ThreatStream.List.CreatedTime | string | Time value |
ThreatStream.List.ID | number | Unique identifier |
ThreatStream.List.Name | string | Name of the resource |
ThreatStream.List.Type | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"List":[]}}}
Get Passive DNS
Retrieve enrichment data for domains, IPs, and URLs from Anomali Threat Stream v1 using specified observables.
Endpoint
- URL: /api/v1/pdns/{{domain}}/{{observable_value}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain | string | Required | The type of passive DNS search ("ip", "domain"). Possible values are ip, domain. Default is ip. |
path_parameters.observable_value | string | Required | The values that can be sent to the API should correspond to the type that is chosen. For example, if IP is chosen in the type argument, then a valid IP address should be sent in the value argument. |
Input Example
{"path_parameters":{"domain":"ip","observable_value":"Observable value"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.PassiveDNS | array | Output field: ThreatStream.PassiveDNS |
ThreatStream.PassiveDNS.Domain | string | Output field: ThreatStream.PassiveDNS.Domain |
ThreatStream.PassiveDNS.FirstSeen | string | Output field: ThreatStream.PassiveDNS.FirstSeen |
ThreatStream.PassiveDNS.Ip | string | Output field: ThreatStream.PassiveDNS.Ip |
ThreatStream.PassiveDNS.LastSeen | string | Output field: ThreatStream.PassiveDNS.LastSeen |
ThreatStream.PassiveDNS.Rrtype | string | Type of the resource |
ThreatStream.PassiveDNS.Source | string | Output field: ThreatStream.PassiveDNS.Source |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"PassiveDNS":[]}}}
Submit to Sandbox
Submit a file or URL to the Anomali Threat Stream-hosted sandbox for analysis and detonation.
Endpoint
- URL: /api/v1/submit/new
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
form_data | object | Optional | Response data |
form_data.file_has_password | boolean | Optional | If using Joe Sandbox to detonate a file, set this attribute to true if the file is password protected. You must specify the password using the file_password attribute. Do not specify a value for the attribute if using Cuckoo or VMRay for detonation. |
form_data.file_password | string | Optional | If detonating a password protected file on Joe Sandbox, use this attribute to specify the value of the password. You must set file_has_password to true if using this attribute. |
form_data.import_indicators | boolean | Optional | If you want to initiate an import job for observables discovered during detonation, set this value to true. |
form_data.report_radio-classification | string | Optional | Classification of the Sandbox submissionβpublic or private. |
form_data.report_radio-notes | string | Optional | A comma-separated list that provides additional details for imported observables. This information is displayed in the Tag column of the ThreatStream UI. For example, "Credential- Exposure,compromised_email". |
form_data.report_radio-platform | string | Optional | Platform on which the submitted URL or file will be detonated. |
form_data.report_radio-url | string | Optional | Specify the URL that you want to detonate. |
form_data.report_radio-file | object | Optional | Specify the file that you want to detonate. |
form_data.report_radio-file.file | string | Required | Response data |
form_data.report_radio-file.file_name | string | Required | Response data |
form_data.trusted_circles | string | Optional | ID of the trusted circle to which the Sandbox data should be associated. If you want to specify multiple trusted circles, enter the list of comma-separated IDs. |
form_data.use_premium_sandbox | boolean | Optional | If you want to use the Joe Sandbox service for detonation, set this attribute to true. If no value is set for use_premium_sandbox, the default Cuckoo sandbox is used. Cuckoo and ThreatStream Joe Sandbox services are limited to 150 submissions per day. |
form_data.use_vmray_sandbox | boolean | Optional | If you want to use the VMRay sandbox service for detonation, set this attribute to true. If no value is set for use_premium_sandbox or use_vmray_ sandbox, the default Cuckoo sandbox is used. You must have an active VMRay integration on ThreatStream in order to use the VMRay sandbox service. |
form_data.vmray_max_jobs | number | Optional | Specify the number of detonations you want VMRay to perform for the submission. If you specify a number greater than 1, VMRay performs the detonations on different platforms. A Sandbox Report is created on ThreatStream for each detonation that returns results. Only specify a value for this attribute if use_vmray_ sandbox is set to true. |
Input Example
{"form_data":{"file_has_password":false,"file_password":"password","import_indicators":true,"report_radio-classification":"public","report_radio-notes":"Credential- Exposure","report_radio-platform":"WINDOWS7","report_radio-url":"https://example.com","report_radio-file":[],"trusted_circles":"13","use_premium_sandbox":true,"use_vmray_sandbox":true,"vmray_max_jobs":3}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.Analysis | object | Output field: ThreatStream.Analysis |
ThreatStream.Analysis.Platform | string | Output field: ThreatStream.Analysis.Platform |
ThreatStream.Analysis.ReportID | number | Unique identifier |
ThreatStream.Analysis.Status | string | Status value |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"Analysis":{}}}}
Update Model
Updates a specific threat model in Anomali Threat Stream v1 using model and model_id path parameters, with the option to override previous data.
Endpoint
- URL: /api/v1/{{model}}/{{model_id}}
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.model | string | Required | The type of threat model to update. Can be "actor", "campaign", "incident", "ttp", "vulnerability", or "tipreport". Possible values are actor, campaign, incident, ttp, vulnerability, tipreport. |
path_parameters.model_id | number | Required | The ID of the threat model to update. |
data_body | object | Required | Response data |
data_body.name | string | Optional | The name of the threat model to update. |
data_body.is_public | boolean | Optional | Whether the scope of threat model is visible. Possible values are true, false. Default is false. |
data_body.tlp | string | Optional | The Traffic Light Protocol designation for the threat model. Can be "red", "amber", "green", or "white". Possible values are red, amber, green, white. Default is red. |
data_body.tags | array | Optional | A comma separated list of tags. |
data_body.tags.name | string | Optional | Response data |
data_body.tags.tlp | string | Optional | Response data |
data_body.description | string | Optional | The description of the threat model. |
data_body.intelligence | number | Optional | A comma separated list of indicator IDs associated with the threat model on the ThreatStream platform. |
Input Example
{"path_parameters":{"model":"incident","model_id":26769},"data_body":{"name":"New_Created_Actor_1","is_public":false,"tlp":"red","tags":[{"name":"test","tlp":"red"}],"description":"Description of the actor threat model.","intelligence":191431508}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ThreatStream | object | Output field: ThreatStream |
ThreatStream.Model | object | Output field: ThreatStream.Model |
ThreatStream.Model.Indicators | array | Output field: ThreatStream.Model.Indicators |
ThreatStream.Model.Indicators.ASN | string | Output field: ThreatStream.Model.Indicators.ASN |
ThreatStream.Model.Indicators.Confidence | number | Unique identifier |
ThreatStream.Model.Indicators.Country | object | Output field: ThreatStream.Model.Indicators.Country |
ThreatStream.Model.Indicators.ID | number | Unique identifier |
ThreatStream.Model.Indicators.IType | string | Type of the resource |
ThreatStream.Model.Indicators.Modified | string | Output field: ThreatStream.Model.Indicators.Modified |
ThreatStream.Model.Indicators.Organization | string | Output field: ThreatStream.Model.Indicators.Organization |
ThreatStream.Model.Indicators.Severity | string | Output field: ThreatStream.Model.Indicators.Severity |
ThreatStream.Model.Indicators.Source | string | Output field: ThreatStream.Model.Indicators.Source |
ThreatStream.Model.Indicators.Status | string | Status value |
ThreatStream.Model.Indicators.Tags | object | Output field: ThreatStream.Model.Indicators.Tags |
ThreatStream.Model.Indicators.Type | string | Type of the resource |
ThreatStream.Model.Indicators.Value | string | Value for the parameter |
ThreatStream.Model.ModelID | string | Unique identifier |
ThreatStream.Model.ModelType | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 19 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ThreatStream":{"Model":{}}}}
Response Headers
Header | Description | Example |
|---|---|---|
content-length | The length of the response body in bytes | 140 |
content-type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Tue, 19 Dec 2023 20:37:23 GMT |