IRIS
IRIS is an incident response and case management platform that centralizes investigation, evidence, and workflow management for security teams.
IRIS is an open-source incident response and case management platform designed for digital forensics and security operations. This connector enables seamless integration between IRIS and Swimlane Turbine, allowing users to automate the creation, management, and enrichment of cases, assets, events, IOCs, evidences, and notes directly within their security workflows. By leveraging this integration, security teams can streamline incident response processes, ensure consistent case documentation, and accelerate investigations without manual intervention. The IRIS connector empowers Swimlane Turbine users to orchestrate end-to-end incident response, improve data accuracy, and reduce response times through low-code automation.
Limitations
None to date.
Prerequisites
Before you can use the IRIS connector, ensure you have the following prerequisites:
- Bearer token authentication configured for IRIS API access, requiring:
- URL: The base endpoint for your IRIS instance's API.
- Token: A valid bearer token for authenticating API requests.
Capabilities
This Connector provides the following capabilities:
- Add a new Asset
- Delete an Asset
- Fetch an Asset
- Get List of Assets
- Update an Asset
- Add a new Case
- Update a Case
- Add a new IOC
- Delete an IOC
- Fetch an IOC
- Get List of IOCs
- Update an IOC
- Fetch a Note
- Get list of directories and notes
- Get User List ... and so on
Add a new Asset
Create an asset and link it to the case.
IRIS documentation for this action can be found here.
Delete an Asset
Delete an asset based on its ID.
IRIS documentation for this action can be found here.
Fetch an Asset
Fetch an asset.
IRIS documentation for this action can be found here.
Get List of Assets
Get a list of the assets linked to the case.
IRIS documentation for this action can be found here.
Update an Asset
Update an asset.
IRIS documentation for this action can be found here.
Add a new Case
Create a new immediate case.
IRIS documentation for this action can be found here.
Update a Case
Update informations of a case.
IRIS documentation for this action can be found here.
Add a new IOC
Add a new IOC.
IRIS documentation for this action can be found here.
Delete an IOC
Delete an IOC from the case.
IRIS documentation for this action can be found here.
Fetch an IOC
Fetch an IOC.
IRIS documentation for this action can be found here.
Get List of IOCs
Returns a list of IOCs as well as any existing links with other cases.
IRIS documentation for this action can be found here.
Update an IOC
Update an IOC.
IRIS documentation for this action can be found here.
Fetch a Note
Fetch the content and metadata of a note.
IRIS documentation for this action can be found here.
Get list of directories and notes
List the directories and notes associated to it.
IRIS documentation for this action can be found here.
Get User List
Return a list of available users.
IRIS documentation for this action can be found here.
Ping Server
This action is used to test authentication.
IRIS documentation for this action can be found here.
Add an Evidence
Add a new evidence to the case.
IRIS documentation for this action can be found here.
Delete a case Evidence
Remove an evidence from the case.
IRIS documentation for this action can be found here.
Get an Evidence
Returns an evidence metadata.
IRIS documentation for this action can be found here.
Get Case Evidences
Returns a list of all evidences linked to the case.
IRIS documentation for this action can be found here.
Update an evidence
Update an evidence.
IRIS documentation for this action can be found here.
Fetch the Timeline
Fetch the state of the timeline.
IRIS documentation for this action can be found here.
Fetch the Timeline by Query
Filter the timeline through a query.
IRIS documentation for this action can be found here.
Add a new Event
Create a new event in the timeline.
IRIS documentation for this action can be found here.
Fetch an Event
Return information of an event of the timeline.
IRIS documentation for this action can be found here.
Update an Event
Update an event in the timeline
IRIS documentation for this action can be found here.
Delete an Event
Delete an event from the timeline.
IRIS documentation for this action can be found here.
Configurations
HTTP Bearer Authentication
IRIS Authenticates using bearer token
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | A bearer token to authenticate with. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add a new asset
Create a new asset and associate it with a specific case in IRIS by providing the asset type, asset name, and case identifier.
Endpoint
- URL: /case/assets/add
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter assets by. |
asset_type_id | string | Optional | The type of the asset to add. |
asset_domain | string | Optional | The domain of the asset to add. |
asset_ip | string | Optional | The IP of the asset to add. |
asset_info | string | Optional | The info of the asset to add. |
asset_compromise_status_id | string | Optional | The compromise status of the asset to add. |
analysis_status_id | string | Optional | The analysis status of the asset to add. |
ioc_links | array | Optional | The IOC links of the asset to add. |
asset_name | string | Optional | The name of the asset to add. |
asset_tags | string | Optional | The tags of the asset to add. |
asset_description | string | Optional | The description of the asset to add. |
custom_attributes | object | Optional | Custom attributes to add to the asset. |
Input Example
{"parameters":{"cid":1},"json_body":{"asset_type_id":"9","asset_domain":"iris.local","asset_ip":"127.0.0.1","asset_info":"test","asset_compromise_status_id":"1","analysis_status_id":"3","ioc_links":["https://www.example.com"],"asset_name":"admin_laptop","asset_tags":"anewtag","asset_description":"A host description","custom_attributes":{}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.asset_enrichment | object | Response data |
data.asset_type | object | Response data |
data.asset_type.asset_icon_not_compromised | string | Response data |
data.asset_type.asset_icon_compromised | string | Response data |
data.asset_type.asset_description | string | Response data |
data.asset_type.asset_id | number | Response data |
data.asset_type.asset_name | string | Response data |
data.asset_type_id | number | Response data |
data.case_id | number | Response data |
data.asset_description | string | Response data |
data.asset_id | number | Response data |
data.analysis_status_id | number | Response data |
data.custom_attributes | object | Response data |
data.asset_info | string | Response data |
data.user_id | number | Response data |
data.date_added | string | Response data |
data.date_update | string | Response data |
data.asset_name | string | Response data |
data.asset_ip | string | Response data |
data.asset_tags | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Asset added","data":{"asset_enrichment":null,"asset_type":{},"asset_type_id":9,"case_id":1,"asset_description":"A host description","asset_id":3912,"analysis_status_id":3,"custom_attributes":{},"asset_info":"","user_id":1,"date_added":"2024-01-09T13:25:51.328503","date_update":"2024-01-09T13:25:51.328506","asset_name":"admin_laptop","asset_ip":"127.0.0.1","asset_tags":"anewtag"}}}
Add a new case
Create a new immediate case in IRIS by specifying the SOC ID, customer, case name, and description.
Endpoint
- URL: /manage/cases/add
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
case_soc_id | string | Optional | Unique identifier |
case_customer | number | Optional | The customer ID linked to the case. |
case_name | string | Optional | A short name for the case. |
case_description | string | Optional | A short description of the case. |
custom_attributes | object | Optional | Custom attributes to add to the case. Keys should be the attribute name and values should be the attribute value. |
custom_attributes.attr1 | string | Optional | Parameter for Add a new case |
custom_attributes.attr2 | string | Optional | Parameter for Add a new case |
case_template_id | string | Optional | The case template ID to use for the case. |
classification_id | number | Optional | The classification ID to use for the case. |
Input Example
{"json_body":{"case_soc_id":"SOC_154","case_customer":1,"case_name":"My Case API","case_description":"A super nice description","custom_attributes":{"attr1":"value1","attr2":"value2"},"case_template_id":"1","classification_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.case_name | string | Response data |
data.case_customer | number | Response data |
data.case_uuid | string | Response data |
data.case_description | string | Response data |
data.case_id | number | Response data |
data.open_date | string | Response data |
data.status_id | number | Response data |
data.modification_history | object | Response data |
data.modification_history.1704888196.578914 | object | Response data |
data.modification_history.1704888196.578914.user | string | Response data |
data.modification_history.1704888196.578914.user_id | number | Response data |
data.modification_history.1704888196.578914.action | string | Response data |
data.case_soc_id | string | Response data |
data.state_id | number | Response data |
data.close_date | object | Response data |
data.classification_id | object | Response data |
data.closing_note | object | Response data |
data.owner_id | number | Response data |
data.user_id | number | Response data |
data.custom_attributes | object | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Case created","data":{"case_name":"#1065 - My Case API","case_customer":1,"case_uuid":"435e3f47-479e-4a3c-98df-8e28b01fd2bc","case_description":"A super nice description","case_id":1065,"open_date":"2024-01-10","status_id":0,"modification_history":{},"case_soc_id":"SOC_154","state_id":11,"close_date":null,"classification_id":null,"closing_note":null,"owner_id":1,"user_id":1}}}
Add a new event
Create a new event in the IRIS timeline by specifying the event title, date, time zone, and customer ID.
Endpoint
- URL: /case/timeline/events/add
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to add an event to. |
event_title | string | Optional | The title of the event to add. |
event_raw | string | Optional | The raw data of the event to add. |
event_source | string | Optional | The source of the event to add. |
event_assets | array | Optional | The assets of the event to add. |
event_iocs | array | Optional | The IOCs of the event to add. |
event_category_id | string | Optional | The category ID of the event to add. |
event_in_summary | boolean | Optional | Whether the event should be included in the summary. |
event_in_graph | boolean | Optional | Whether the event should be included in the graph. |
event_color | string | Optional | The color of the event to add. |
event_date | string | Optional | The date of the event to add. |
event_sync_iocs_assets | boolean | Optional | Whether the event should sync IOCs and assets. |
event_tags | string | Optional | The tags of the event to add. |
event_tz | string | Optional | The timezone of the event to add. |
event_content | string | Optional | The content of the event to add. |
parent_event_id | number | Optional | The parent event ID of the event to add. |
custom_attributes | object | Optional | Custom attributes to add to the event. |
Input Example
{"parameters":{"cid":2},"json_body":{"event_title":"An event","event_raw":"My event raw data","event_source":"My source","event_assets":[45],"event_iocs":[33],"event_category_id":"5","event_in_summary":true,"event_in_graph":true,"event_color":"#1572E899","event_date":"2023-03-08T03:02:00.000","event_sync_iocs_assets":true,"event_tags":"tag","event_tz":"+00:00","event_content":"My description","parent_event_id":null,"custom_attributes":{}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.event_tags | string | Response data |
data.case_id | number | Response data |
data.event_in_summary | boolean | Response data |
data.modification_history | object | Response data |
data.event_date | string | Response data |
data.event_title | string | Response data |
data.custom_attributes | object | Response data |
data.user_id | number | Response data |
data.event_color | string | Response data |
data.event_added | string | Response data |
data.event_in_graph | boolean | Response data |
data.event_tz | string | Response data |
data.event_content | string | Response data |
data.event_source | string | Response data |
data.event_category_id | number | Response data |
data.event_uuid | string | Response data |
data.event_is_flagged | boolean | Response data |
data.event_raw | string | Response data |
data.event_date_wtz | string | Response data |
data.event_id | number | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Event added","data":{"event_tags":"tag","case_id":1,"event_in_summary":true,"modification_history":{},"event_date":"2023-03-08T03:02:00.000000","event_title":"An event","custom_attributes":{},"user_id":1,"event_color":"#1572E899","event_added":"2024-01-09T15:45:12.677273","event_in_graph":true,"event_tz":"+00:00","event_content":"My description","event_source":"My source","event_category_id":5}}}
Add a new ioc
Create and add a new Indicator of Compromise (IOC) in IRIS by specifying type, TLP, value, description, tags, and collection ID.
Endpoint
- URL: /case/ioc/add
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter assets by. |
ioc_type_id | number | Optional | The ID of the IOC type to add. |
ioc_tlp_id | number | Optional | The ID of the TLP to assign to the IOC. |
ioc_value | string | Optional | The value of the IOC to add. |
ioc_description | string | Optional | A description for the IOC to add. |
ioc_tags | string | Optional | Tags to assign to the IOC, separated by commas. |
custom_attributes | object | Optional | Custom attributes to assign to the IOC. |
Input Example
{"parameters":{"cid":1},"json_body":{"ioc_type_id":1,"ioc_tlp_id":2,"ioc_value":"8.8.8.8","ioc_description":"rewrw","ioc_tags":"","custom_attributes":{}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.ioc_description | string | Response data |
data.ioc_value | string | Response data |
data.ioc_type | object | Response data |
data.ioc_type.type_taxonomy | object | Response data |
data.ioc_type.type_name | string | Response data |
data.ioc_type.type_validation_regex | object | Response data |
data.ioc_type.type_description | string | Response data |
data.ioc_type.type_id | number | Response data |
data.ioc_type.type_validation_expect | object | Response data |
data.ioc_tags | string | Response data |
data.ioc_uuid | string | Response data |
data.ioc_enrichment | object | Response data |
data.ioc_id | number | Response data |
data.ioc_tlp_id | number | Response data |
data.user_id | number | Response data |
data.custom_attributes | object | Response data |
data.ioc_type_id | number | Response data |
data.ioc_misp | object | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"IOC added","data":{"ioc_description":"rewrw","ioc_value":"8.8.8.8","ioc_type":{},"ioc_tags":"","ioc_uuid":"9c10461b-e5e3-4b39-9d00-c8aff798d4f9","ioc_enrichment":null,"ioc_id":3956,"ioc_tlp_id":2,"user_id":1,"custom_attributes":{},"ioc_type_id":1,"ioc_misp":null}}}
Add an evidence
Add a new evidence file to an IRIS case by specifying the case ID and filename.
Endpoint
- URL: /case/evidences/add
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to add an evidence to. |
filename | string | Optional | The name of the file to add. |
file_size | string | Optional | The size of the file to add. |
file_hash | string | Optional | The hash of the file to add. |
type_id | string | Optional | The type ID of the file to add. |
start_date | string | Optional | The start date of the file to add. |
end_date | string | Optional | The end date of the file to add. |
custom_attributes | object | Optional | Custom attributes to add to the file. |
file_description | string | Optional | The description of the file to add. |
Input Example
{"parameters":{"cid":1},"json_body":{"filename":"dummy file","file_size":"77108","file_hash":"88BC9EF6F07F0FAE922AB25EB226906542F8BA0DC1A221F3EA7273CBCB5DB0D4","type_id":"2","start_date":"2024-04-13T03:02:00.000","end_date":"2024-04-04T00:00:00.000","custom_attributes":{},"file_description":"Dummy description"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.chain_of_custody | object | Response data |
data.case_id | number | Response data |
data.type_id | object | Response data |
data.id | number | Response data |
data.file_hash | string | Response data |
data.filename | string | Response data |
data.start_date | object | Response data |
data.type | object | Response data |
data.acquisition_date | object | Response data |
data.case | number | Response data |
data.file_uuid | string | Response data |
data.user_id | number | Response data |
data.custom_attributes | object | Response data |
data.date_added | string | Response data |
data.user | object | Response data |
data.user.id | number | Response data |
data.user.user_name | string | Response data |
data.user.user_login | string | Response data |
data.user.user_email | string | Response data |
data.file_size | number | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Evidence added","data":{"chain_of_custody":null,"case_id":1,"type_id":null,"id":119,"file_hash":"string","filename":"string","start_date":null,"type":null,"acquisition_date":null,"case":1,"file_uuid":"2c322eb0-53be-45c7-b71c-ae5bc4c3bd0a","user_id":1,"custom_attributes":{},"date_added":"2024-01-11T07:39:11.211407","user":{}}}}
Delete a case evidence
Remove a specific evidence item from an IRIS case using the evidence ID and case ID.
Endpoint
- URL: /case/evidences/delete/{{evidence_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to delete an evidence from. |
path_parameters.evidence_id | number | Required | The ID of the evidence to delete. |
Input Example
{"parameters":{"cid":1},"path_parameters":{"evidence_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
message | string | Response message |
status | string | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[{}],"message":"string","status":"string"}}
Delete an asset
Remove an asset from IRIS using its asset ID and customer ID (cid) to ensure targeted deletion.
Endpoint
- URL: /case/assets/delete/{{asset_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter assets by. |
path_parameters.asset_id | string | Required | The ID of the asset to delete. |
Input Example
{"parameters":{"cid":1},"path_parameters":{"asset_id":"1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | object | Value for the parameter |
value.data | array | Response data |
value.data.file_name | string | Response data |
value.data.file | string | Response data |
value.message | string | Value for the parameter |
value.status | string | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"value":{"data":[],"message":"Deleted","status":"success"}}}
Delete an event
Remove a specified event from the IRIS timeline using the event ID and customer ID.
Endpoint
- URL: /case/timeline/events/delete/{{event_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | string | Required | The Case ID to delete an event from. |
path_parameters.event_id | number | Required | The ID of the event to delete. |
Input Example
{"parameters":{"cid":"1"},"path_parameters":{"event_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.file_name | string | Response data |
data.file | string | Response data |
message | string | Response message |
status | string | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[],"message":"Event ID 14984 deleted","status":"success"}}
Delete an IOC
Remove an indicator of compromise (IOC) from a specified case in IRIS using the IOC ID and case identifier.
Endpoint
- URL: /case/ioc/delete/{{ioc_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | string | Required | The Case ID to filter IOCs by. |
path_parameters.ioc_id | number | Required | The ID of the IOC to delete. |
Input Example
{"parameters":{"cid":"1"},"path_parameters":{"ioc_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | array | Response data |
data.file_name | string | Response data |
data.file | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"IOC 3956 deleted","data":[]}}
Fetch a note
Fetch the content and metadata of a specific note in IRIS using the note ID and customer ID.
Endpoint
- URL: /case/notes/{{note_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter notes by. |
path_parameters.note_id | number | Required | The ID of the note to fetch. |
Input Example
{"parameters":{"cid":1},"path_parameters":{"note_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.directory | object | Response data |
data.directory.id | number | Response data |
data.directory.name | string | Response data |
data.directory.parent_id | object | Response data |
data.directory.case_id | number | Response data |
data.note_id | number | Response data |
data.note_uuid | string | Response data |
data.note_title | string | Response data |
data.note_content | string | Response data |
data.note_user | number | Response data |
data.note_creationdate | string | Response data |
data.note_lastupdate | string | Response data |
data.note_case_id | number | Response data |
data.custom_attributes | object | Response data |
data.directory_id | number | Response data |
data.modification_history | object | Response data |
data.comments | array | Response data |
data.comments.file_name | string | Response data |
data.comments.file | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"directory":{},"note_id":1,"note_uuid":"b8391125-f446-40ec-b4cf-f610fefd0029","note_title":"New note","note_content":"Super note\n\n# hey hey","note_user":1,"note_creationdate":"2024-03-18T08:35:22.999299","note_lastupdate":"2024-03-18T08:35:22.999313","note_case_id":1,"custom_attributes":null,"directory_id":5,"modification_history":{},"comments":[]}}}
Fetch an asset
Fetch detailed information for a specific asset in IRIS using the asset ID and customer ID.
Endpoint
- URL: /case/assets/{{asset_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | string | Required | The Case ID to filter assets by. |
path_parameters.asset_id | number | Required | The ID of the asset to retrieve. |
Input Example
{"parameters":{"cid":"1"},"path_parameters":{"asset_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.asset_enrichment | object | Response data |
data.asset_enrichment.Another enrichment provider | object | Response data |
data.asset_enrichment.Another enrichment provider.Another key | string | Response data |
data.asset_type | object | Response data |
data.asset_type.asset_icon_not_compromised | string | Response data |
data.asset_type.asset_icon_compromised | string | Response data |
data.asset_type.asset_description | string | Response data |
data.asset_type.asset_id | number | Response data |
data.asset_type.asset_name | string | Response data |
data.asset_type_id | number | Response data |
data.case_id | number | Response data |
data.asset_description | string | Response data |
data.asset_id | number | Response data |
data.analysis_status_id | number | Response data |
data.custom_attributes | object | Response data |
data.custom_attributes.Analysis | object | Response data |
data.custom_attributes.Analysis.Has been analyzed | object | Response data |
data.custom_attributes.Analysis.Has been analyzed.type | string | Response data |
data.custom_attributes.Analysis.Has been analyzed.mandatory | boolean | Response data |
data.custom_attributes.Analysis.Has been analyzed.value | boolean | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"asset_enrichment":{},"asset_type":{},"asset_type_id":15,"case_id":1,"asset_description":"Asset description","asset_id":2548,"analysis_status_id":1,"custom_attributes":{},"asset_info":"","user_id":4,"date_added":"2024-01-04T13:20:43.522581","date_update":"2024-01-04T13:20:43.522598","asset_name":"WAF-301","asset_ip":"1.1.1.1","asset_tags":"tag1,tag2"}}}
Fetch an event
Retrieve detailed information for a specific event in the timeline using the event ID and customer ID.
Endpoint
- URL: /case/timeline/events/{{event_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter events by. |
path_parameters.event_id | number | Required | Parameters for the Fetch an event action |
Input Example
{"parameters":{"cid":1},"path_parameters":{"event_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.event_tags | string | Response data |
data.case_id | number | Response data |
data.event_in_summary | boolean | Response data |
data.modification_history | object | Response data |
data.event_date | string | Response data |
data.event_title | string | Response data |
data.custom_attributes | object | Response data |
data.user_id | number | Response data |
data.event_color | string | Response data |
data.event_added | string | Response data |
data.event_in_graph | boolean | Response data |
data.event_tz | string | Response data |
data.event_content | string | Response data |
data.event_source | string | Response data |
data.event_uuid | string | Response data |
data.event_is_flagged | boolean | Response data |
data.event_raw | string | Response data |
data.event_date_wtz | string | Response data |
data.event_id | number | Response data |
data.event_assets | array | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"event_tags":"tag","case_id":1,"event_in_summary":true,"modification_history":{},"event_date":"2023-03-08T03:02:00.000000","event_title":"An event","custom_attributes":{},"user_id":1,"event_color":"#1572E899","event_added":"2024-01-09T15:47:18.257680","event_in_graph":true,"event_tz":"+00:00","event_content":"My description","event_source":"My source","event_uuid":"eedceb90-def7-4707-a478-5c5a218f0116"}}}
Fetch an ioc
Fetch detailed information for a specific Indicator of Compromise (IOC) in IRIS using the provided IOC ID and customer ID.
Endpoint
- URL: /case/ioc/{{ioc_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | string | Required | The Case ID to filter IOCs by. |
path_parameters.ioc_id | number | Required | The ID of the IOC to fetch. |
Input Example
{"parameters":{"cid":"1"},"path_parameters":{"ioc_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.ioc_description | string | Response data |
data.ioc_value | string | Response data |
data.ioc_type | object | Response data |
data.ioc_type.type_taxonomy | object | Response data |
data.ioc_type.type_name | string | Response data |
data.ioc_type.type_validation_regex | object | Response data |
data.ioc_type.type_description | string | Response data |
data.ioc_type.type_id | number | Response data |
data.ioc_type.type_validation_expect | object | Response data |
data.ioc_tags | string | Response data |
data.ioc_uuid | string | Response data |
data.ioc_enrichment | object | Response data |
data.ioc_id | number | Response data |
data.ioc_tlp_id | number | Response data |
data.user_id | number | Response data |
data.custom_attributes | object | Response data |
data.ioc_type_id | number | Response data |
data.ioc_misp | object | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"ioc_description":"None","ioc_value":"s<dasdasdasdasd","ioc_type":{},"ioc_tags":"","ioc_uuid":"47ee4c47-0328-4edf-ba15-4fe2e4c828f0","ioc_enrichment":null,"ioc_id":15,"ioc_tlp_id":2,"user_id":12,"custom_attributes":{},"ioc_type_id":5,"ioc_misp":null}}}
Fetch the timeline
Fetch the current state of a specified timeline in IRIS using the provided case ID (cid) parameter.
Endpoint
- URL: /case/timeline/state
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | string | Required | The Case ID to filter timeline by. |
Input Example
{"parameters":{"cid":"1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.object_last_update | string | Response data |
data.object_state | number | Response data |
message | string | Response message |
status | string | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"object_last_update":"Sun, 06 Mar 2022 13:00:25 GMT","object_state":39},"message":"","status":"success"}}
Fetch the timeline by query
Retrieve timeline events from IRIS filtered by a specified query and case ID.
Endpoint
- URL: /case/timeline/advanced-filter
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter timeline by. |
parameters.q | string | Required | The query to filter timeline by. |
Input Example
{"parameters":{"cid":1,"q":"{\"title\":\"New Event\", \"description\": \"Event description\"}"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.timeline | array | Response data |
data.timeline.event_id | number | Response data |
data.timeline.event_uuid | string | Response data |
data.timeline.event_date | string | Response data |
data.timeline.event_date_wtz | string | Response data |
data.timeline.event_tz | string | Response data |
data.timeline.event_title | string | Response data |
data.timeline.event_color | string | Response data |
data.timeline.event_tags | string | Response data |
data.timeline.event_content | string | Response data |
data.timeline.event_in_summary | boolean | Response data |
data.timeline.event_in_graph | boolean | Response data |
data.timeline.event_is_flagged | boolean | Response data |
data.timeline.user | string | Response data |
data.timeline.event_added | string | Response data |
data.timeline.category_name | string | Response data |
data.timeline.assets | array | Response data |
data.timeline.assets.name | string | Response data |
data.timeline.assets.ip | string | Response data |
data.timeline.assets.description | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"ok","data":{"timeline":[],"state":{}}}}
Get an Evidence
Fetch metadata details for a specific evidence item in IRIS using the evidence ID and customer ID.
Endpoint
- URL: /case/evidences/{{evidence_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter evidences by. |
path_parameters.evidence_id | number | Required | The ID of the evidence to retrieve. |
Input Example
{"parameters":{"cid":1},"path_parameters":{"evidence_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.custom_attributes | object | Response data |
data.date_added | string | Response data |
data.file_description | string | Response data |
data.file_hash | string | Response data |
data.file_size | number | Response data |
data.file_uuid | string | Response data |
data.filename | string | Response data |
data.id | number | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"custom_attributes":null,"date_added":"2023-03-06T09:24:21.700465","file_description":"Imported from datastore. dummy description","file_hash":"E7314F28AC81AAB727957B317AEBF02B54E8B06C07F5A56F36D4F0B642C38D28","file_size":76050,"file_uuid":"7da1be2f-b0cb-4cdb-85b5-a9a7716d08e8","filename":"dummy file","id":1}}}
Get case evidences
Retrieve all evidences associated with a specified case in IRIS by providing the case ID.
Endpoint
- URL: /case/evidences/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter evidences by. |
Input Example
{"parameters":{"cid":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.evidences | array | Response data |
data.evidences.chain_of_custody | object | Response data |
data.evidences.case_id | number | Response data |
data.evidences.type_id | object | Response data |
data.evidences.id | number | Response data |
data.evidences.file_hash | string | Response data |
data.evidences.filename | string | Response data |
data.evidences.start_date | object | Response data |
data.evidences.type | object | Response data |
data.evidences.acquisition_date | object | Response data |
data.evidences.case | number | Response data |
data.evidences.file_uuid | string | Response data |
data.evidences.user_id | number | Response data |
data.evidences.custom_attributes | object | Response data |
data.evidences.date_added | string | Response data |
data.evidences.user | object | Response data |
data.evidences.user.id | number | Response data |
data.evidences.user.user_name | string | Response data |
data.evidences.user.user_login | string | Response data |
data.evidences.user.user_email | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"evidences":[],"state":{}}}}
Get list of assets
Retrieve a list of assets associated with a specific case in IRIS by providing the case ID (cid) as a parameter.
Endpoint
- URL: /case/assets/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter assets by. |
Input Example
{"parameters":{"cid":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.assets | array | Response data |
data.assets.asset_id | number | Response data |
data.assets.asset_uuid | string | Response data |
data.assets.asset_name | string | Response data |
data.assets.asset_type | string | Response data |
data.assets.asset_icon_compromised | string | Response data |
data.assets.asset_icon_not_compromised | string | Response data |
data.assets.asset_description | string | Response data |
data.assets.asset_domain | string | Response data |
data.assets.asset_compromise_status_id | number | Response data |
data.assets.asset_ip | string | Response data |
data.assets.asset_type_id | number | Response data |
data.assets.analysis_status | string | Response data |
data.assets.analysis_status_id | number | Response data |
data.assets.asset_tags | string | Response data |
data.assets.link | array | Response data |
data.assets.link.file_name | string | Response data |
data.assets.link.file | string | Response data |
data.assets.ioc_links | object | Response data |
data.state | object | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"assets":[],"state":{}}}}
Get list of directories and notes
Retrieve a list of directories and their associated notes in IRIS using the specified customer ID (cid) parameter.
Endpoint
- URL: /case/notes/directories/filter
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter notes by. |
Input Example
{"parameters":{"cid":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | array | Response data |
data.id | number | Response data |
data.name | string | Response data |
data.note_count | number | Response data |
data.subdirectories | array | Response data |
data.subdirectories.id | number | Response data |
data.subdirectories.name | string | Response data |
data.subdirectories.note_count | number | Response data |
data.subdirectories.subdirectories | array | Response data |
data.subdirectories.subdirectories.file_name | string | Response data |
data.subdirectories.subdirectories.file | string | Response data |
data.notes | array | Response data |
data.notes.file_name | string | Response data |
data.notes.file | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":[{"id":5,"name":"Dummy title","note_count":1,"subdirectories":[],"notes":[{"id":1,"title":"New note"}]},{"id":7,"name":"Dummy title","note_count":0,"subdirectories":[],"notes":[]},{"id":4,"name":"New folder","note_count":0,"subdirectories":[],"notes":[]}]}}
Get list of IOCs
Retrieve a list of indicators of compromise (IOCs) and their existing links to other cases from IRIS using the specified case ID.
Endpoint
- URL: /case/ioc/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter IOCs by. |
Input Example
{"parameters":{"cid":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.ioc | array | Response data |
data.ioc.ioc_id | number | Response data |
data.ioc.ioc_uuid | string | Response data |
data.ioc.ioc_value | string | Response data |
data.ioc.ioc_type_id | number | Response data |
data.ioc.ioc_type | string | Response data |
data.ioc.ioc_description | string | Response data |
data.ioc.ioc_tags | string | Response data |
data.ioc.ioc_misp | object | Response data |
data.ioc.tlp_name | string | Response data |
data.ioc.tlp_bscolor | string | Response data |
data.ioc.ioc_tlp_id | number | Response data |
data.ioc.link | array | Response data |
data.ioc.link.file_name | string | Response data |
data.ioc.link.file | string | Response data |
data.ioc.misp_link | object | Response data |
data.state | object | Response data |
data.state.object_state | number | Response data |
data.state.object_last_update | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":{"ioc":[],"state":{}}}}
Get user list
Retrieve a list of all available users from IRIS.
Endpoint
- URL: /manage/users/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Optional | The Case ID to filter users by. |
Input Example
{"parameters":{"cid":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | array | Response data |
data.user_id | number | Response data |
data.user_uuid | string | Response data |
data.user_name | string | Response data |
data.user_login | string | Response data |
data.user_email | string | Response data |
data.user_active | boolean | Response data |
data.user_is_service_account | boolean | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"","data":[{"user_id":1,"user_uuid":"815be41e-9a7d-4a2e-9e69-db2ceeba6ad2","user_name":"administrator","user_login":"administrator","user_email":"[email protected]","user_active":true,"user_is_service_account":false},{"user_id":2,"user_uuid":"17e16ccd-a461-4fb0-b219-07f13231d6ce","user_name":"automation","user_login":"automation","user_email":"automation@automation","user_active":true,"user_is_service_account":true...
Ping Server
Verify authentication and connectivity to the IRIS server.
Endpoint
- URL: /api/ping
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.file_name | string | Response data |
data.file | string | Response data |
message | string | Response message |
status | string | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[],"message":"pong","status":"success"}}
Save a note
Update the content and metadata of a specific note in IRIS using the note ID, customer ID, title, and content.
Endpoint
- URL: /case/notes/update/{{note_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to save the note to. |
path_parameters.note_id | number | Required | The ID of the note to save. |
note_title | string | Optional | The title of the note to save. |
note_content | string | Optional | The content of the note to save. |
parent_id | number | Optional | The ID of the parent directory to save the note to. |
custom_attributes | object | Optional | Custom attributes to save with the note. |
Input Example
{"parameters":{"cid":1201},"json_body":{"note_title":"A new note title","note_content":"A new note content","parent_id":121,"custom_attributes":{}},"path_parameters":{"note_id":1201}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.directory | object | Response data |
data.directory.id | number | Response data |
data.directory.name | string | Response data |
data.directory.parent_id | number | Response data |
data.directory.case_id | number | Response data |
data.note_id | number | Response data |
data.note_uuid | string | Response data |
data.note_title | string | Response data |
data.note_content | string | Response data |
data.note_user | number | Response data |
data.note_creationdate | string | Response data |
data.note_lastupdate | string | Response data |
data.note_case_id | number | Response data |
data.custom_attributes | object | Response data |
data.directory_id | number | Response data |
data.modification_history | object | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Note ID 16 saved","data":{"directory":{},"note_id":16,"note_uuid":"ecbbd74e-85fd-4268-a9a4-c069677e6677","note_title":"New title","note_content":"New content","note_user":1,"note_creationdate":"2024-03-27T18:14:21.245694","note_lastupdate":"2024-03-27T18:14:21.245724","note_case_id":1,"custom_attributes":null,"directory_id":4,"modification_history":{}}}}
Update a Case
Update the information of a specific case in IRIS using the case identifier provided in the path parameters.
Endpoint
- URL: /manage/cases/update/{{case_identifier}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.case_identifier | number | Required | The ID of the case to update. |
case_name | string | Optional | The name of the case to update. |
case_soc_id | string | Optional | The SOC ID of the case to update. |
classification_id | string | Optional | The classification ID of the case to update. |
owner_id | string | Optional | The owner ID of the case to update. |
state_id | string | Optional | The state ID of the case to update. |
status_id | string | Optional | The status ID of the case to update. |
protagonists | array | Optional | The protagonists of the case to update. |
protagonists.role | string | Optional | The role of the protagonist. |
protagonists.name | string | Optional | The name of the protagonist. |
protagonists.contact | string | Optional | The contact of the protagonist. |
case_tags | string | Optional | Case tags to update. |
custom_attributes | object | Optional | Custom attributes to update. |
Input Example
{"json_body":{"case_name":"A new case name","case_soc_id":"soc_id_demo","classification_id":"id123","owner_id":"id123","state_id":"id123","status_id":"id123","protagonists":[{"role":"Lead","name":"administrator","contact":"[email protected]"}],"case_tags":"tag1,tag2","custom_attributes":{}},"path_parameters":{"case_identifier":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.case_tags | string | Response data |
data.case_name | string | Response data |
data.custom_attributes | object | Response data |
data.case_soc_id | string | Response data |
data.status_id | number | Response data |
data.open_date | string | Response data |
data.case_id | number | Response data |
data.modification_history | object | Response data |
data.user_id | number | Response data |
data.case_uuid | string | Response data |
data.protagonists | array | Response data |
data.protagonists.role | string | Response data |
data.protagonists.name | string | Response data |
data.protagonists.contact | string | Response data |
data.case_description | string | Response data |
data.closing_note | object | Response data |
data.close_date | object | Response data |
data.classification_id | number | Response data |
data.owner_id | number | Response data |
data.state_id | number | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Case updated","data":{"case_tags":"tag1,tag2","case_name":"#1 - Dummy ","custom_attributes":{},"case_soc_id":"soc_id_demo","status_id":1,"open_date":"2023-05-11","case_id":1,"modification_history":{},"user_id":1,"case_uuid":"507a5fab-358a-4946-82d0-625ef8a9fa0d","protagonists":[],"case_description":"This is a demonstration.","closing_note":null,"close_date":null,"classification_id":2}}}
Update an asset
Update the details of an existing asset in IRIS by specifying the asset ID, customer ID, asset name, and asset type.
Endpoint
- URL: /case/assets/update/{{asset_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to filter assets by. |
path_parameters.asset_id | string | Required | The ID of the asset to update. |
asset_name | string | Optional | The name of the asset to update. |
asset_type_id | string | Optional | The type of the asset to update. |
asset_domain | string | Optional | The domain of the asset to update. |
asset_ip | string | Optional | The IP of the asset to update. |
asset_info | string | Optional | The info of the asset to update. |
asset_compromise_status_id | string | Optional | The compromise status of the asset to update. |
analysis_status_id | string | Optional | The analysis status of the asset to update. |
ioc_links | array | Optional | The IOC links of the asset to update. |
asset_tags | string | Optional | The tags of the asset to update. |
asset_description | string | Optional | The description of the asset to update. |
custom_attributes | object | Optional | Custom attributes to update. |
Input Example
{"parameters":{"cid":1},"json_body":{"asset_name":"admin_laptop","asset_type_id":"9","asset_domain":"iris.local","asset_ip":"127.0.0.1","asset_info":"","asset_compromise_status_id":"1","analysis_status_id":"3","ioc_links":["30"],"asset_tags":"anewtag","asset_description":"A host description","custom_attributes":{}},"path_parameters":{"asset_id":"1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.asset_enrichment | object | Response data |
data.asset_type | object | Response data |
data.asset_type.asset_icon_not_compromised | string | Response data |
data.asset_type.asset_icon_compromised | string | Response data |
data.asset_type.asset_description | string | Response data |
data.asset_type.asset_id | number | Response data |
data.asset_type.asset_name | string | Response data |
data.asset_type_id | number | Response data |
data.case_id | number | Response data |
data.asset_description | string | Response data |
data.asset_id | number | Response data |
data.analysis_status_id | number | Response data |
data.custom_attributes | object | Response data |
data.asset_info | string | Response data |
data.user_id | number | Response data |
data.date_added | string | Response data |
data.date_update | string | Response data |
data.asset_name | string | Response data |
data.ioc_links | array | Response data |
data.asset_ip | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Updated asset admin_laptop","data":{"asset_enrichment":{},"asset_type":{},"asset_type_id":9,"case_id":1,"asset_description":"A host description","asset_id":2548,"analysis_status_id":3,"custom_attributes":{},"asset_info":"","user_id":4,"date_added":"2024-01-04T13:20:43.522581","date_update":"2024-01-04T13:20:43.522598","asset_name":"admin_laptop","ioc_links":[],"asset_ip":"127.0.0.1"}}}
Update an event
Update an existing event in the IRIS timeline by specifying the event ID, customer ID, and new event details such as title, date, and time zone.
Endpoint
- URL: /case/timeline/events/update/{{event_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to update an event in. |
path_parameters.event_id | number | Required | The ID of the event to update. |
event_title | string | Optional | The title of the event to update. |
event_raw | string | Optional | The raw data of the event to update. |
event_source | string | Optional | The source of the event to update. |
parent_event_id | number | Optional | The parent event ID of the event to update. |
event_assets | array | Optional | The assets of the event to update. |
event_iocs | array | Optional | The IOCs of the event to update. |
event_category_id | number | Optional | The category ID of the event to update. |
event_in_summary | boolean | Optional | Whether the event should be included in the summary. |
event_in_graph | boolean | Optional | Whether the event should be included in the graph. |
event_color | string | Optional | The color of the event to update. |
event_date | string | Optional | The date of the event to update. |
event_sync_iocs_assets | boolean | Optional | Whether the event should sync IOCs and assets. |
event_tags | string | Optional | The tags of the event to update. |
event_tz | string | Optional | The timezone of the event to update. |
event_content | string | Optional | The content of the event to update. |
custom_attributes | object | Optional | Custom attributes to update to the event. |
Input Example
{"parameters":{"cid":1},"json_body":{"event_title":"An event","event_raw":"My event raw data","event_source":"Source","parent_event_id":122,"event_assets":[45],"event_iocs":[33],"event_category_id":5,"event_in_summary":true,"event_in_graph":true,"event_color":"#1572E899","event_date":"2023-03-08T03:02:00.000","event_sync_iocs_assets":true,"event_tags":"tag","event_tz":"+00:00","event_content":"My description","custom_attributes":{}},"path_parameters":{"event_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.event_tags | string | Response data |
data.case_id | number | Response data |
data.event_in_summary | boolean | Response data |
data.modification_history | object | Response data |
data.event_date | string | Response data |
data.event_title | string | Response data |
data.custom_attributes | object | Response data |
data.user_id | number | Response data |
data.event_color | string | Response data |
data.event_added | string | Response data |
data.event_in_graph | boolean | Response data |
data.event_tz | string | Response data |
data.event_assets | array | Response data |
data.event_content | string | Response data |
data.event_sync_iocs_assets | boolean | Response data |
data.event_source | string | Response data |
data.event_category_id | number | Response data |
data.event_uuid | string | Response data |
data.event_is_flagged | boolean | Response data |
data.event_raw | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Event updated","data":{"event_tags":"tag","case_id":1,"event_in_summary":true,"modification_history":{},"event_date":"2023-03-08T03:02:00.000000","event_title":"An event","custom_attributes":{},"user_id":1,"event_color":"#1572E899","event_added":"2024-01-09T15:45:12.677273","event_in_graph":true,"event_tz":"+00:00","event_assets":[],"event_content":"My description","event_sync_iocs_assets":true}}}
Update an evidence
Update the details of a specific evidence item in IRIS using its evidence ID, CID, and filename.
Endpoint
- URL: /case/evidences/update/{{evidence_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | number | Required | The Case ID to update an evidence in. |
path_parameters.evidence_id | number | Required | The ID of the evidence to update. |
filename | string | Optional | The name of the file to update. |
file_size | string | Optional | The size of the file to update. |
file_hash | string | Optional | The hash of the file to update. |
type_id | string | Optional | The type ID of the file to update. |
start_date | string | Optional | The start date of the file to update. |
end_date | string | Optional | The end date of the file to update. |
custom_attributes | object | Optional | Custom attributes to update to the file. |
file_description | string | Optional | The description of the file to update. |
Input Example
{"parameters":{"cid":1},"json_body":{"filename":"dummy file","file_size":"77108","file_hash":"88BC9EF6F07F0FAE922AB25EB226906542F8BA0DC1A221F3EA7273CBCB5DB0D4","type_id":"2","start_date":"2024-04-13T03:02:00.000","end_date":"2024-04-04T00:00:00.000","custom_attributes":{},"file_description":"Dummy description"},"path_parameters":{"evidence_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.chain_of_custody | object | Response data |
data.case_id | number | Response data |
data.type_id | object | Response data |
data.id | number | Response data |
data.file_hash | string | Response data |
data.filename | string | Response data |
data.start_date | object | Response data |
data.type | object | Response data |
data.acquisition_date | object | Response data |
data.case | number | Response data |
data.file_uuid | string | Response data |
data.user_id | number | Response data |
data.custom_attributes | object | Response data |
data.date_added | string | Response data |
data.user | object | Response data |
data.user.id | number | Response data |
data.user.user_name | string | Response data |
data.user.user_login | string | Response data |
data.user.user_email | string | Response data |
data.file_size | number | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Evidence string updated","data":{"chain_of_custody":null,"case_id":1,"type_id":null,"id":117,"file_hash":"string","filename":"string","start_date":null,"type":null,"acquisition_date":null,"case":1,"file_uuid":"88a4dd55-132a-4acf-9daf-f05303782131","user_id":1,"custom_attributes":{},"date_added":"2024-01-09T16:19:38.620717","user":{}}}}
Update an IOC
Update an Indicator of Compromise (IOC) in IRIS using the specified IOC ID and customer ID.
Endpoint
- URL: /case/ioc/update/{{ioc_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cid | string | Required | The Case ID to filter IOCs by. |
path_parameters.ioc_id | number | Required | The ID of the IOC to update. |
ioc_type_id | number | Optional | The ID of the IOC type to update. |
ioc_tlp_id | number | Optional | The ID of the TLP to assign to the IOC. |
ioc_value | string | Optional | The value of the IOC to update. |
ioc_description | string | Optional | A description for the IOC to update. |
ioc_tags | string | Optional | A comma-separated list of tags to assign to the IOC. |
custom_attributes | object | Optional | Custom attributes to assign to the IOC. |
Input Example
{"parameters":{"cid":"1"},"json_body":{"ioc_type_id":1,"ioc_tlp_id":2,"ioc_value":"evil","ioc_description":"IOC description","ioc_tags":"tag1,tag2","custom_attributes":{}},"path_parameters":{"ioc_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
message | string | Response message |
data | object | Response data |
data.ioc_description | string | Response data |
data.ioc_value | string | Response data |
data.ioc_type | object | Response data |
data.ioc_type.type_taxonomy | object | Response data |
data.ioc_type.type_name | string | Response data |
data.ioc_type.type_validation_regex | object | Response data |
data.ioc_type.type_description | string | Response data |
data.ioc_type.type_id | number | Response data |
data.ioc_type.type_validation_expect | object | Response data |
data.ioc_tags | string | Response data |
data.ioc_uuid | string | Response data |
data.ioc_enrichment | object | Response data |
data.ioc_id | number | Response data |
data.ioc_tlp_id | number | Response data |
data.user_id | number | Response data |
data.custom_attributes | object | Response data |
data.ioc_type_id | number | Response data |
data.ioc_misp | object | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":"success","message":"Updated ioc \"evil\"","data":{"ioc_description":"IOC description","ioc_value":"evil","ioc_type":{},"ioc_tags":"tag1,tag2","ioc_uuid":"ec70eb70-487c-414f-bc8f-7f55752c3150","ioc_enrichment":null,"ioc_id":3719,"ioc_tlp_id":2,"user_id":1,"custom_attributes":{},"ioc_type_id":1,"ioc_misp":null}}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |