v1

latestOpenAPI 3.0.02026-07-17166300328.1 KB
Attributes

[restSearch] Get a filtered and paginated list of attributes

This is the recommended endpoint for searching attributes.

post/attributes/restSearch

Request body

pageinteger nullable
limitinteger nullable

Maximum number of results to be returned. Can't be greater than the one set for your role. 0 means maximum.

valuestring
value1string
value2string
type'md5' | 'sha1' | 'sha256' | 'filename' | 'pdb' | 'filename|md5' | 'filename|sha1' | 'filename|sha256' | 'ip-src' | 'ip-dst' | 'hostname' | 'domain' | 'domain|ip' | 'email' | 'email-src' | 'eppn' | 'email-dst' | 'email-subject' | 'email-attachment' | 'email-body' | 'float' | 'git-commit-id' | 'url' | 'http-method' | 'user-agent' | 'ja3-fingerprint-md5' | 'jarm-fingerprint' | 'favicon-mmh3' | 'hassh-md5' | 'hasshserver-md5' | 'regkey' | 'regkey|value' | 'AS' | 'snort' | 'suricata' | 'bro' | 'zeek' | 'community-id' | 'pattern-in-file' | 'pattern-in-traffic' | 'pattern-in-memory' | 'pattern-filename' | 'pgp-public-key' | 'pgp-private-key' | 'yara' | 'stix2-pattern' | 'sigma' | 'gene' | 'kusto-query' | 'mime-type' | 'identity-card-number' | 'cookie' | 'vulnerability' | 'cpe' | 'weakness' | 'attachment' | 'malware-sample' | 'link' | 'comment' | 'text' | 'hex' | 'other' | 'named pipe' | 'mutex' | 'process-state' | 'target-user' | 'target-email' | 'target-machine' | 'target-org' | 'target-location' | 'target-external' | 'btc' | 'dash' | 'xmr' | 'iban' | 'bic' | 'bank-account-nr' | 'aba-rtn' | 'bin' | 'cc-number' | 'prtn' | 'phone-number' | 'threat-actor' | 'campaign-name' | 'campaign-id' | 'malware-type' | 'uri' | 'authentihash' | 'vhash' | 'ssdeep' | 'imphash' | 'telfhash' | 'pehash' | 'impfuzzy' | 'sha224' | 'sha384' | 'sha512' | 'sha512/224' | 'sha512/256' | 'sha3-224' | 'sha3-256' | 'sha3-384' | 'sha3-512' | 'tlsh' | 'cdhash' | 'filename|authentihash' | 'filename|vhash' | 'filename|ssdeep' | 'filename|imphash' | 'filename|impfuzzy' | 'filename|pehash' | 'filename|sha224' | 'filename|sha384' | 'filename|sha512' | 'filename|sha512/224' | 'filename|sha512/256' | 'filename|sha3-224' | 'filename|sha3-256' | 'filename|sha3-384' | 'filename|sha3-512' | 'filename|tlsh' | 'windows-scheduled-task' | 'windows-service-name' | 'windows-service-displayname' | 'whois-registrant-email' | 'whois-registrant-phone' | 'whois-registrant-name' | 'whois-registrant-org' | 'whois-registrar' | 'whois-creation-date' | 'x509-fingerprint-sha1' | 'x509-fingerprint-md5' | 'x509-fingerprint-sha256' | 'dns-soa-email' | 'size-in-bytes' | 'counter' | 'datetime' | 'port' | 'ip-dst|port' | 'ip-src|port' | 'hostname|port' | 'mac-address' | 'mac-eui-64' | 'email-dst-display-name' | 'email-src-display-name' | 'email-header' | 'email-reply-to' | 'email-x-mailer' | 'email-mime-boundary' | 'email-thread-index' | 'email-message-id' | 'github-username' | 'github-repository' | 'github-organisation' | 'jabber-id' | 'twitter-id' | 'dkim' | 'dkim-signature' | 'first-name' | 'middle-name' | 'last-name' | 'full-name' | 'date-of-birth' | 'place-of-birth' | 'gender' | 'passport-number' | 'passport-country' | 'passport-expiration' | 'redress-number' | 'nationality' | 'visa-number' | 'issue-date-of-the-visa' | 'primary-residence' | 'country-of-residence' | 'special-service-request' | 'frequent-flyer-number' | 'travel-details' | 'payment-details' | 'place-port-of-original-embarkation' | 'place-port-of-clearance' | 'place-port-of-onward-foreign-destination' | 'passenger-name-record-locator-number' | 'mobile-application-id' | 'chrome-extension-id' | 'edge-extension-id' | 'cortex' | 'boolean' | 'anonymised'
category'Internal reference' | 'Targeting data' | 'Antivirus detection' | 'Payload delivery' | 'Artifacts dropped' | 'Payload installation' | 'Persistence mechanism' | 'Network activity' | 'Payload type' | 'Attribution' | 'External analysis' | 'Financial fraud' | 'Support Tool' | 'Social network' | 'Person' | 'Other'
tagsstring[] nullable
searchallstring

Search events by matching any tag names, event descriptions, attribute values or attribute comments

fromstring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

tostring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

eventidstring
withAttachmentsboolean

Extends the response with the base64 representation of the attachment, if there is one

uuidstring uuid
publish_timestampstring
publishedboolean
timestampstring
attribute_timestampstring
enforceWarninglistboolean nullable

Should the warning list be enforced. Adds blocked field for matching attributes

to_idsboolean nullable
deletedboolean

Whether to include soft-deleted attributes. Default value 0. If set to 1, only deleted attributes will be returned. If set to [0,1], both deleted and non-deleted attributes will be returned.

event_timestampstring
threat_level_id'1' | '2' | '3' | '4'

Represents the threat level.

  • 1 - High
  • 2 - Medium
  • 3 - Low
  • 4 - Undefined
eventinfostring

Quick event description

sharinggroupstring[] nullable

Sharing group ID(s), either as single string or list of IDs

decayingModelstring

Specify the decaying model from which the decaying score should be calculated

scorestring

An alias to override on-the-fly the threshold of the decaying model

first_seenstring

Seen within the last x amount of time, where x can be defined in days, hours, minutes (for example 5d or 12h or 30m)

last_seenstring

Seen within the last x amount of time, where x can be defined in days, hours, minutes (for example 5d or 12h or 30m)

includeEventUuidboolean

Include matching eventUuids in the response

includeEventTagsboolean

Include tags of matching events in the response

includeProposalsboolean

Include proposals of matching events in the response

requested_attributesstring[]

List of properties that will be selected in the CSV export

includeContextboolean nullable

Adds events context fields in the CSV export

headerlessboolean nullable

Removes header in the CSV export

includeWarninglistHitsboolean nullable
attackGalaxystring nullable
object_relationstring nullable

Filter by the attribute object relation value

includeSightingsboolean nullable

Extend response with Sightings DB results if the module is enabled

includeCorrelationsboolean nullable
includeDecayScoreboolean

Include all enabled decaying score

includeFullModelboolean

Include all model information of matching events in the response

excludeDecayedboolean

Should the decayed elements by excluded

returnFormat'json' | 'xml' | 'csv' | 'text' | 'stix' | 'stix2' | 'stix-json' | 'hashes' | 'cache' | 'count' | 'netfilter' | 'opendata' | 'openioc' | 'rpz' | 'snort' | 'suricata' | 'text' | 'yara' | 'yara-json'

Format of the response payload

Example request

{
  "value": "127.0.0.1",
  "value1": "127.0.0.1",
  "value2": "127.0.0.1",
  "org": "12345",
  "tags": [
    "tlp:amber"
  ],
  "searchall": "malware",
  "eventid": "12345",
  "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
  "publish_timestamp": "1617875568",
  "timestamp": "1617875568",
  "attribute_timestamp": "1617875568",
  "event_timestamp": "1617875568",
  "sharinggroup": [
    "1"
  ],
  "requested_attributes": [
    "id"
  ],
  "attackGalaxy": "mitre-attack",
  "object_relation": "filepath",
  "modelOverrides": {
    "lifetime": 3,
    "decay_speed": 2.3,
    "threshold": 30,
    "default_base_score": 80,
    "base_score_config": {
      "estimative-language:confidence-in-analytic-judgment": 0.25,
      "estimative-language:likelihood-probability": 0.25,
      "phishing:psychological-acceptability": 0.25,
      "phishing:state": 0.2
    }
  }
}

Response

Rest search attributes response

Example response

{
  "response": {
    "Attribute": [
      {
        "id": "12345",
        "event_id": "12345",
        "object_id": "12345",
        "object_relation": "sensor",
        "value": "127.0.0.1",
        "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
        "timestamp": "1617875568",
        "distribution": "4",
        "sharing_group_id": "1",
        "comment": "logged source ip",
        "first_seen": "1581984000000000",
        "last_seen": "1581984000000000",
        "Tag": [
          {
            "id": "12345",
            "name": "tlp:white",
            "colour": "#ffffff",
            "org_id": "12345",
            "user_id": "12345",
            "numerical_value": "12345"
          }
        ],
        "Galaxy": [
          {
            "id": "12345",
            "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
            "name": "Ransomware",
            "type": "ransomware",
            "description": "Ransomware galaxy based on ...",
            "version": "1",
            "icon": "globe",
            "namespace": "misp",
            "kill_chain_order": {
              "fraud-tactics": [
                "Initiation",
                "Target Compromise",
                "Perform Fraud",
                "Obtain Fraudulent Assets",
                "Assets Transfer",
                "Monetisation"
              ]
            }
          }
        ],
        "event_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
        "decay_score": [
          {
            "score": 10.5,
            "base_score": 80,
            "DecayingModel": {
              "id": "12345",
              "name": "Phishing model"
            }
          }
        ],
        "Event": {
          "id": "12345",
          "org_id": "12345",
          "distribution": "4",
          "info": "logged source ip",
          "orgc_id": "12345",
          "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
          "date": "1991-01-15",
          "attribute_count": "321",
          "timestamp": "1617875568",
          "sharing_group_id": "1",
          "publish_timestamp": "1617875568",
          "sighting_timestamp": "1617875568",
          "extends_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b"
        },
        "Object": {
          "id": "12345",
          "name": "ail-leak",
          "template_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
          "template_version": "1",
          "event_id": "12345",
          "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
          "timestamp": "1617875568",
          "distribution": "4",
          "sharing_group_id": "1",
          "first_seen": "1581984000000000",
          "last_seen": "1581984000000000",
          "Attribute": [
            {
              "id": "12345",
              "event_id": "12345",
              "object_id": "12345",
              "object_relation": "sensor",
              "value": "127.0.0.1",
              "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
              "timestamp": "1617875568",
              "distribution": "4",
              "sharing_group_id": "1",
              "comment": "logged source ip",
              "first_seen": "1581984000000000",
              "last_seen": "1581984000000000",
              "Tag": [
                {
                  "id": "12345",
                  "name": "tlp:white",
                  "colour": "#ffffff",
                  "org_id": "12345",
                  "user_id": "12345",
                  "numerical_value": "12345"
                }
              ],
              "Galaxy": [
                {
                  "id": "12345",
                  "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
                  "name": "Ransomware",
                  "type": "ransomware",
                  "description": "Ransomware galaxy based on ...",
                  "version": "1",
                  "icon": "globe",
                  "namespace": "misp",
                  "kill_chain_order": {
                    "fraud-tactics": [
                      "Initiation",
                      "Target Compromise",
                      "Perform Fraud",
                      "Obtain Fraudulent Assets",
                      "Assets Transfer",
                      "Monetisation"
                    ]
                  }
                }
              ]
            }
          ]
        }
      }
    ]
  }
}