v1

latestOpenAPI 3.0.02026-07-17166300328.1 KB
Events

[restSearch] Get a filtered and paginated list of events

This is the recommended endpoint for searching events.

post/events/restSearch

Request body

pageinteger nullable
limitinteger nullable

Maximum number of results to be returned. Can't be greater than the one set for your role. 0 means maximum.

valuestring
type'md5' | 'sha1' | 'sha256' | 'filename' | 'pdb' | 'filename|md5' | 'filename|sha1' | 'filename|sha256' | 'ip-src' | 'ip-dst' | 'hostname' | 'domain' | 'domain|ip' | 'email' | 'email-src' | 'eppn' | 'email-dst' | 'email-subject' | 'email-attachment' | 'email-body' | 'float' | 'git-commit-id' | 'url' | 'http-method' | 'user-agent' | 'ja3-fingerprint-md5' | 'jarm-fingerprint' | 'favicon-mmh3' | 'hassh-md5' | 'hasshserver-md5' | 'regkey' | 'regkey|value' | 'AS' | 'snort' | 'suricata' | 'bro' | 'zeek' | 'community-id' | 'pattern-in-file' | 'pattern-in-traffic' | 'pattern-in-memory' | 'pattern-filename' | 'pgp-public-key' | 'pgp-private-key' | 'yara' | 'stix2-pattern' | 'sigma' | 'gene' | 'kusto-query' | 'mime-type' | 'identity-card-number' | 'cookie' | 'vulnerability' | 'cpe' | 'weakness' | 'attachment' | 'malware-sample' | 'link' | 'comment' | 'text' | 'hex' | 'other' | 'named pipe' | 'mutex' | 'process-state' | 'target-user' | 'target-email' | 'target-machine' | 'target-org' | 'target-location' | 'target-external' | 'btc' | 'dash' | 'xmr' | 'iban' | 'bic' | 'bank-account-nr' | 'aba-rtn' | 'bin' | 'cc-number' | 'prtn' | 'phone-number' | 'threat-actor' | 'campaign-name' | 'campaign-id' | 'malware-type' | 'uri' | 'authentihash' | 'vhash' | 'ssdeep' | 'imphash' | 'telfhash' | 'pehash' | 'impfuzzy' | 'sha224' | 'sha384' | 'sha512' | 'sha512/224' | 'sha512/256' | 'sha3-224' | 'sha3-256' | 'sha3-384' | 'sha3-512' | 'tlsh' | 'cdhash' | 'filename|authentihash' | 'filename|vhash' | 'filename|ssdeep' | 'filename|imphash' | 'filename|impfuzzy' | 'filename|pehash' | 'filename|sha224' | 'filename|sha384' | 'filename|sha512' | 'filename|sha512/224' | 'filename|sha512/256' | 'filename|sha3-224' | 'filename|sha3-256' | 'filename|sha3-384' | 'filename|sha3-512' | 'filename|tlsh' | 'windows-scheduled-task' | 'windows-service-name' | 'windows-service-displayname' | 'whois-registrant-email' | 'whois-registrant-phone' | 'whois-registrant-name' | 'whois-registrant-org' | 'whois-registrar' | 'whois-creation-date' | 'x509-fingerprint-sha1' | 'x509-fingerprint-md5' | 'x509-fingerprint-sha256' | 'dns-soa-email' | 'size-in-bytes' | 'counter' | 'datetime' | 'port' | 'ip-dst|port' | 'ip-src|port' | 'hostname|port' | 'mac-address' | 'mac-eui-64' | 'email-dst-display-name' | 'email-src-display-name' | 'email-header' | 'email-reply-to' | 'email-x-mailer' | 'email-mime-boundary' | 'email-thread-index' | 'email-message-id' | 'github-username' | 'github-repository' | 'github-organisation' | 'jabber-id' | 'twitter-id' | 'dkim' | 'dkim-signature' | 'first-name' | 'middle-name' | 'last-name' | 'full-name' | 'date-of-birth' | 'place-of-birth' | 'gender' | 'passport-number' | 'passport-country' | 'passport-expiration' | 'redress-number' | 'nationality' | 'visa-number' | 'issue-date-of-the-visa' | 'primary-residence' | 'country-of-residence' | 'special-service-request' | 'frequent-flyer-number' | 'travel-details' | 'payment-details' | 'place-port-of-original-embarkation' | 'place-port-of-clearance' | 'place-port-of-onward-foreign-destination' | 'passenger-name-record-locator-number' | 'mobile-application-id' | 'chrome-extension-id' | 'edge-extension-id' | 'cortex' | 'boolean' | 'anonymised'
category'Internal reference' | 'Targeting data' | 'Antivirus detection' | 'Payload delivery' | 'Artifacts dropped' | 'Payload installation' | 'Persistence mechanism' | 'Network activity' | 'Payload type' | 'Attribution' | 'External analysis' | 'Financial fraud' | 'Support Tool' | 'Social network' | 'Person' | 'Other'
tagsstring[] nullable
event_tagsstring[] nullable
searchallstring

Search events by matching any tag names, event descriptions, attribute values or attribute comments

fromstring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

tostring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

eventidstring
withAttachmentsboolean

Extends the response with the base64 representation of the attachment, if there is one

sharinggroupstring[] nullable

Sharing group ID(s), either as single string or list of IDs

metadataboolean nullable

Will only return the metadata of the given query scope, contained data is omitted.

uuidstring uuid
publish_timestampstring
timestampstring
publishedboolean
enforceWarninglistboolean nullable

Should the warning list be enforced. Adds blocked field for matching attributes

sgReferenceOnlyboolean

Will only return the sharing group ID

requested_attributesstring[]

List of properties that will be selected in the CSV export

includeContextboolean nullable

Adds events context fields in the CSV export

headerlessboolean nullable

Removes header in the CSV export

includeWarninglistHitsboolean nullable
attackGalaxystring nullable
to_idsboolean
deletedboolean

Whether to include soft-deleted attributes. Default value 0. If set to 1, only deleted attributes will be returned. If set to [0,1], both deleted and non-deleted attributes will be returned.

excludeLocalTagsboolean nullable

Exclude local tags from the export

datestring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

includeSightingdbboolean nullable

Extend response with Sightings DB results if the module is enabled

tagstring
object_relationstring nullable

Filter by the attribute object relation value

threat_level_id'1' | '2' | '3' | '4'

Represents the threat level.

  • 1 - High
  • 2 - Medium
  • 3 - Low
  • 4 - Undefined
extendingboolean

Whether to include events that are extending another one. If set to 1, only events extending another will be returned. If set to 0, only events that are not extending another will be returned. Omit or [0,1] to disregard extension state.

extendedboolean

Whether to include events that are extended by another one. If set to 1, only events extended by another will be returned. If set to 0, only events that are not extended by another will be returned. Omit or [0,1] to disregard extension state.

returnFormat'json' | 'xml' | 'csv' | 'text' | 'stix' | 'stix2' | 'stix-json' | 'attack' | 'attack-sightings' | 'cache' | 'count' | 'hashes' | 'netfilter' | 'opendata' | 'openioc' | 'rpz' | 'snort' | 'suricata' | 'yara' | 'yara-json'

Format of the response payload

Example request

{
  "value": "127.0.0.1",
  "org": "12345",
  "tags": [
    "tlp:amber"
  ],
  "event_tags": [
    "tlp:amber"
  ],
  "searchall": "malware",
  "eventid": "12345",
  "sharinggroup": [
    "1"
  ],
  "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
  "publish_timestamp": "1617875568",
  "timestamp": "1617875568",
  "requested_attributes": [
    "id"
  ],
  "attackGalaxy": "mitre-attack",
  "tag": "tlp:white",
  "object_relation": "filepath"
}

Response

Rest search events response

responseobject[]