v1

latestOpenAPI 3.0.02026-07-17166300328.1 KB
Objects

[restSearch] Get a filtered and paginated list of objects

This is the recommended endpoint for searching objects.

post/objects/restsearch

Request body

pageinteger nullable
limitinteger nullable

Maximum number of results to be returned. Can't be greater than the one set for your role. 0 means maximum.

quickFilterstring

Search events by matching any tag names, event descriptions, attribute values or attribute comments

searchallstring

Search events by matching any tag names, event descriptions, attribute values or attribute comments

timestampstring
object_namestring
object_template_uuidstring uuid
object_template_versionstring
eventidstring
eventinfostring
ignoreboolean

If true matches both true and false values for to_ids and published

fromstring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

tostring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

datestring nullable

You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)

tagsstring[] nullable
event_timestampstring
publish_timestampstring
uuidstring uuid
valuestring
type'md5' | 'sha1' | 'sha256' | 'filename' | 'pdb' | 'filename|md5' | 'filename|sha1' | 'filename|sha256' | 'ip-src' | 'ip-dst' | 'hostname' | 'domain' | 'domain|ip' | 'email' | 'email-src' | 'eppn' | 'email-dst' | 'email-subject' | 'email-attachment' | 'email-body' | 'float' | 'git-commit-id' | 'url' | 'http-method' | 'user-agent' | 'ja3-fingerprint-md5' | 'jarm-fingerprint' | 'favicon-mmh3' | 'hassh-md5' | 'hasshserver-md5' | 'regkey' | 'regkey|value' | 'AS' | 'snort' | 'suricata' | 'bro' | 'zeek' | 'community-id' | 'pattern-in-file' | 'pattern-in-traffic' | 'pattern-in-memory' | 'pattern-filename' | 'pgp-public-key' | 'pgp-private-key' | 'yara' | 'stix2-pattern' | 'sigma' | 'gene' | 'kusto-query' | 'mime-type' | 'identity-card-number' | 'cookie' | 'vulnerability' | 'cpe' | 'weakness' | 'attachment' | 'malware-sample' | 'link' | 'comment' | 'text' | 'hex' | 'other' | 'named pipe' | 'mutex' | 'process-state' | 'target-user' | 'target-email' | 'target-machine' | 'target-org' | 'target-location' | 'target-external' | 'btc' | 'dash' | 'xmr' | 'iban' | 'bic' | 'bank-account-nr' | 'aba-rtn' | 'bin' | 'cc-number' | 'prtn' | 'phone-number' | 'threat-actor' | 'campaign-name' | 'campaign-id' | 'malware-type' | 'uri' | 'authentihash' | 'vhash' | 'ssdeep' | 'imphash' | 'telfhash' | 'pehash' | 'impfuzzy' | 'sha224' | 'sha384' | 'sha512' | 'sha512/224' | 'sha512/256' | 'sha3-224' | 'sha3-256' | 'sha3-384' | 'sha3-512' | 'tlsh' | 'cdhash' | 'filename|authentihash' | 'filename|vhash' | 'filename|ssdeep' | 'filename|imphash' | 'filename|impfuzzy' | 'filename|pehash' | 'filename|sha224' | 'filename|sha384' | 'filename|sha512' | 'filename|sha512/224' | 'filename|sha512/256' | 'filename|sha3-224' | 'filename|sha3-256' | 'filename|sha3-384' | 'filename|sha3-512' | 'filename|tlsh' | 'windows-scheduled-task' | 'windows-service-name' | 'windows-service-displayname' | 'whois-registrant-email' | 'whois-registrant-phone' | 'whois-registrant-name' | 'whois-registrant-org' | 'whois-registrar' | 'whois-creation-date' | 'x509-fingerprint-sha1' | 'x509-fingerprint-md5' | 'x509-fingerprint-sha256' | 'dns-soa-email' | 'size-in-bytes' | 'counter' | 'datetime' | 'port' | 'ip-dst|port' | 'ip-src|port' | 'hostname|port' | 'mac-address' | 'mac-eui-64' | 'email-dst-display-name' | 'email-src-display-name' | 'email-header' | 'email-reply-to' | 'email-x-mailer' | 'email-mime-boundary' | 'email-thread-index' | 'email-message-id' | 'github-username' | 'github-repository' | 'github-organisation' | 'jabber-id' | 'twitter-id' | 'dkim' | 'dkim-signature' | 'first-name' | 'middle-name' | 'last-name' | 'full-name' | 'date-of-birth' | 'place-of-birth' | 'gender' | 'passport-number' | 'passport-country' | 'passport-expiration' | 'redress-number' | 'nationality' | 'visa-number' | 'issue-date-of-the-visa' | 'primary-residence' | 'country-of-residence' | 'special-service-request' | 'frequent-flyer-number' | 'travel-details' | 'payment-details' | 'place-port-of-original-embarkation' | 'place-port-of-clearance' | 'place-port-of-onward-foreign-destination' | 'passenger-name-record-locator-number' | 'mobile-application-id' | 'chrome-extension-id' | 'edge-extension-id' | 'cortex' | 'boolean' | 'anonymised'
category'Internal reference' | 'Targeting data' | 'Antivirus detection' | 'Payload delivery' | 'Artifacts dropped' | 'Payload installation' | 'Persistence mechanism' | 'Network activity' | 'Payload type' | 'Attribution' | 'External analysis' | 'Financial fraud' | 'Support Tool' | 'Social network' | 'Person' | 'Other'
object_relationstring nullable

Filter by the attribute object relation value

attribute_timestampstring
first_seenstring nullable
last_seenstring nullable
commentstring
to_idsboolean nullable
publishedboolean
deletedboolean
withAttachmentsboolean

Extends the response with the base64 representation of the attachment, if there is one

enforceWarninglistboolean nullable

Should the warning list be enforced. Adds blocked field for matching attributes

includeAllTagsboolean

Include also exportable tags

includeEventUuidboolean

Include matching eventUuids in the response

include_event_uuidboolean

Include matching eventUuids in the response

includeEventTagsboolean

Include tags of matching events in the response

includeProposalsboolean

Include proposals of matching events in the response

includeWarninglistHitsboolean nullable
includeContextboolean nullable

Adds events context fields in the CSV export

includeSightingsboolean nullable

Adds events context fields in the CSV export

includeSightingdbboolean nullable

Extend response with Sightings DB results if the module is enabled

includeCorrelationsboolean nullable
includeDecayScoreboolean

Include all enabled decaying score

includeFullModelboolean

Include all model information of matching events in the response

allow_proposal_blockingboolean

Allow blocking attributes from to_ids sensitive exports if a proposal has been made to it to remove the IDS flag

metadataboolean nullable

Will only return the metadata of the given query scope, contained data is omitted.

attackGalaxystring nullable
excludeDecayedboolean

Should the decayed elements by excluded

decayingModelstring

Specify the decaying model from which the decaying score should be calculated

scorestring

An alias to override on-the-fly the threshold of the decaying model

returnFormat'json'

Format of the response payload

Example request

{
  "quickFilter": "malware",
  "searchall": "malware",
  "timestamp": "1617875568",
  "object_name": "ail-leak",
  "object_template_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
  "object_template_version": "1",
  "eventid": "12345",
  "eventinfo": "logged source ip",
  "tags": [
    "tlp:amber"
  ],
  "event_timestamp": "1617875568",
  "publish_timestamp": "1617875568",
  "org": "12345",
  "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
  "value": "127.0.0.1",
  "object_relation": "filepath",
  "attribute_timestamp": "1617875568",
  "first_seen": "1581984000000000",
  "last_seen": "1581984000000000",
  "comment": "logged source ip",
  "attackGalaxy": "mitre-attack",
  "modelOverrides": {
    "lifetime": 3,
    "decay_speed": 2.3,
    "threshold": 30,
    "default_base_score": 80,
    "base_score_config": {
      "estimative-language:confidence-in-analytic-judgment": 0.25,
      "estimative-language:likelihood-probability": 0.25,
      "phishing:psychological-acceptability": 0.25,
      "phishing:state": 0.2
    }
  }
}

Response

Rest search objects response

Example response

{
  "response": [
    {
      "Object": {
        "id": "12345",
        "name": "ail-leak",
        "template_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
        "template_version": "1",
        "event_id": "12345",
        "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
        "timestamp": "1617875568",
        "distribution": "4",
        "sharing_group_id": "1",
        "first_seen": "1581984000000000",
        "last_seen": "1581984000000000",
        "Attribute": [
          {
            "id": "12345",
            "event_id": "12345",
            "object_id": "12345",
            "object_relation": "sensor",
            "value": "127.0.0.1",
            "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
            "timestamp": "1617875568",
            "distribution": "4",
            "sharing_group_id": "1",
            "comment": "logged source ip",
            "first_seen": "1581984000000000",
            "last_seen": "1581984000000000",
            "Tag": [
              {
                "id": "12345",
                "name": "tlp:white",
                "colour": "#ffffff",
                "org_id": "12345",
                "user_id": "12345",
                "numerical_value": "12345"
              }
            ],
            "Galaxy": [
              {
                "id": "12345",
                "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
                "name": "Ransomware",
                "type": "ransomware",
                "description": "Ransomware galaxy based on ...",
                "version": "1",
                "icon": "globe",
                "namespace": "misp",
                "kill_chain_order": {
                  "fraud-tactics": [
                    "Initiation",
                    "Target Compromise",
                    "Perform Fraud",
                    "Obtain Fraudulent Assets",
                    "Assets Transfer",
                    "Monetisation"
                  ]
                }
              }
            ]
          }
        ]
      }
    }
  ]
}