v1
latestOpenAPI 3.0.02026-07-17166300328.1 KBObjects
[restSearch] Get a filtered and paginated list of objects
This is the recommended endpoint for searching objects.
post/objects/restsearch
Request body
Example request
{
"quickFilter": "malware",
"searchall": "malware",
"timestamp": "1617875568",
"object_name": "ail-leak",
"object_template_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
"object_template_version": "1",
"eventid": "12345",
"eventinfo": "logged source ip",
"tags": [
"tlp:amber"
],
"event_timestamp": "1617875568",
"publish_timestamp": "1617875568",
"org": "12345",
"uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
"value": "127.0.0.1",
"object_relation": "filepath",
"attribute_timestamp": "1617875568",
"first_seen": "1581984000000000",
"last_seen": "1581984000000000",
"comment": "logged source ip",
"attackGalaxy": "mitre-attack",
"modelOverrides": {
"lifetime": 3,
"decay_speed": 2.3,
"threshold": 30,
"default_base_score": 80,
"base_score_config": {
"estimative-language:confidence-in-analytic-judgment": 0.25,
"estimative-language:likelihood-probability": 0.25,
"phishing:psychological-acceptability": 0.25,
"phishing:state": 0.2
}
}
}Response
Rest search objects response
Example response
{
"response": [
{
"Object": {
"id": "12345",
"name": "ail-leak",
"template_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
"template_version": "1",
"event_id": "12345",
"uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
"timestamp": "1617875568",
"distribution": "4",
"sharing_group_id": "1",
"first_seen": "1581984000000000",
"last_seen": "1581984000000000",
"Attribute": [
{
"id": "12345",
"event_id": "12345",
"object_id": "12345",
"object_relation": "sensor",
"value": "127.0.0.1",
"uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
"timestamp": "1617875568",
"distribution": "4",
"sharing_group_id": "1",
"comment": "logged source ip",
"first_seen": "1581984000000000",
"last_seen": "1581984000000000",
"Tag": [
{
"id": "12345",
"name": "tlp:white",
"colour": "#ffffff",
"org_id": "12345",
"user_id": "12345",
"numerical_value": "12345"
}
],
"Galaxy": [
{
"id": "12345",
"uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
"name": "Ransomware",
"type": "ransomware",
"description": "Ransomware galaxy based on ...",
"version": "1",
"icon": "globe",
"namespace": "misp",
"kill_chain_order": {
"fraud-tactics": [
"Initiation",
"Target Compromise",
"Perform Fraud",
"Obtain Fraudulent Assets",
"Assets Transfer",
"Monetisation"
]
}
}
]
}
]
}
}
]
}