v1

latestOpenAPI 3.0.02026-07-17166300328.1 KB
Objects

Add an object to an event

post/objects/add/{eventId}/{objectTemplateId}

Path parameters

string required
OR
string uuid required
Example:12345

UUID or numeric ID of the event

string required
OR
string uuid required
Example:12345

UUID or numeric ID of the object template

Request body

Example request

{
  "Attribute": [
    {
      "value": "127.0.0.1",
      "distribution": "4",
      "comment": "logged source ip",
      "object_relation": "sensor"
    }
  ]
}

Response

Object response

Example response

{
  "Object": {
    "id": "12345",
    "name": "ail-leak",
    "template_uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
    "template_version": "1",
    "event_id": "12345",
    "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
    "timestamp": "1617875568",
    "distribution": "4",
    "sharing_group_id": "1",
    "first_seen": "1581984000000000",
    "last_seen": "1581984000000000",
    "Attribute": [
      {
        "id": "12345",
        "event_id": "12345",
        "object_id": "12345",
        "object_relation": "sensor",
        "value": "127.0.0.1",
        "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
        "timestamp": "1617875568",
        "distribution": "4",
        "sharing_group_id": "1",
        "comment": "logged source ip",
        "first_seen": "1581984000000000",
        "last_seen": "1581984000000000",
        "Tag": [
          {
            "id": "12345",
            "name": "tlp:white",
            "colour": "#ffffff",
            "org_id": "12345",
            "user_id": "12345",
            "numerical_value": "12345"
          }
        ],
        "Galaxy": [
          {
            "id": "12345",
            "uuid": "c99506a6-1255-4b71-afa5-7b8ba48c3b1b",
            "name": "Ransomware",
            "type": "ransomware",
            "description": "Ransomware galaxy based on ...",
            "version": "1",
            "icon": "globe",
            "namespace": "misp",
            "kill_chain_order": {
              "fraud-tactics": [
                "Initiation",
                "Target Compromise",
                "Perform Fraud",
                "Obtain Fraudulent Assets",
                "Assets Transfer",
                "Monetisation"
              ]
            }
          }
        ]
      }
    ]
  }
}