diff --git a/docs/api-reference/spec/firework-v2-openapi.json b/docs/api-reference/spec/firework-v2-openapi.json index 6b3cfba7..6a8c3ef0 100644 --- a/docs/api-reference/spec/firework-v2-openapi.json +++ b/docs/api-reference/spec/firework-v2-openapi.json @@ -1692,7 +1692,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -2016,7 +2016,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -2591,7 +2591,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -2915,7 +2915,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -3329,7 +3329,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -3612,7 +3612,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -4740,7 +4740,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -5044,7 +5044,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -5556,33 +5556,33 @@ "search_types": { "items": { "enum": [ - "domain", - "ad", - "docker", - "ransomleak", - "paste", - "bucket", - "bucket_object", - "source_code_files", - "leak", + "social_media_account", "blog_post", - "stealer_log", - "source_code_secrets", - "forum_profile", "forum_topic", - "financial_data", + "stealer_log", + "google", + "docker", + "invalid_credential", + "bot", "service", - "social_media_account", - "valid_credential", + "financial_data", + "domain", "seller", + "valid_credential", + "paste", + "forum_profile", + "source_code_secrets", + "ad", + "bucket", + "mitigated_credential", + "forum_post", + "source_code_files", + "bucket_object", "chat_message", "listing", - "google", - "bot", - "invalid_credential", - "forum_post", "stack_exchange", - "mitigated_credential", + "ransomleak", + "leak", "illicit_networks", "open_web", "buckets", @@ -5596,7 +5596,7 @@ "infected_devices", "social_media" ], - "example": "domain", + "example": "social_media_account", "type": "string" }, "type": "array" @@ -5664,32 +5664,32 @@ "search_types": { "items": { "enum": [ - "domain", - "docker", - "ransomleak", - "paste", - "bucket", - "bucket_object", - "source_code_files", - "leak", + "social_media_account", "blog_post", - "stealer_log", - "source_code_secrets", - "forum_profile", "forum_topic", - "financial_data", + "stealer_log", + "google", + "docker", + "invalid_credential", + "bot", "service", - "social_media_account", - "valid_credential", + "financial_data", + "domain", "seller", + "valid_credential", + "paste", + "forum_profile", + "source_code_secrets", + "bucket", + "mitigated_credential", + "forum_post", + "source_code_files", + "bucket_object", "chat_message", "listing", - "google", - "bot", - "invalid_credential", - "forum_post", "stack_exchange", - "mitigated_credential", + "ransomleak", + "leak", "illicit_networks", "open_web", "buckets", @@ -5702,7 +5702,7 @@ "infected_devices", "social_media" ], - "example": "domain", + "example": "social_media_account", "type": "string" }, "type": "array" @@ -6001,17 +6001,6 @@ }, "type": "object" }, - "TenantWithCounts": { - "properties": { - "next": { - "type": "string" - }, - "items": { - "$ref": "#/components/schemas/TenantWithCounts" - } - }, - "type": "object" - }, "Tenant": { "properties": { "id": { @@ -6071,6 +6060,17 @@ }, "type": "object" }, + "TenantWithCounts": { + "properties": { + "next": { + "type": "string" + }, + "items": { + "$ref": "#/components/schemas/TenantWithCounts" + } + }, + "type": "object" + }, "UpdatedPermission": { "properties": { "updated_value": { @@ -6140,17 +6140,6 @@ ], "type": "object" }, - "OrganizationMemberPage": { - "properties": { - "members": { - "items": { - "$ref": "#/components/schemas/OrganizationMemberWithMetadata" - }, - "type": "array" - } - }, - "type": "object" - }, "OrganizationMemberWithMetadata": { "properties": { "user": { @@ -6204,6 +6193,17 @@ }, "type": "object" }, + "OrganizationMemberPage": { + "properties": { + "members": { + "items": { + "$ref": "#/components/schemas/OrganizationMemberWithMetadata" + }, + "type": "array" + } + }, + "type": "object" + }, "OrganizationMembersCount": { "properties": { "count": { diff --git a/docs/api-reference/spec/firework-v2-swagger.json b/docs/api-reference/spec/firework-v2-swagger.json index 3192e44a..1c635afb 100644 --- a/docs/api-reference/spec/firework-v2-swagger.json +++ b/docs/api-reference/spec/firework-v2-swagger.json @@ -462,6 +462,17 @@ "type": "string" } ], + "delete": { + "responses": { + "200": { + "description": "Success" + } + }, + "operationId": "delete_activity_user_metadata_tags_/activities////user_metadata/tags", + "tags": [ + "activities" + ] + }, "put": { "responses": { "200": { @@ -492,17 +503,6 @@ "activities" ] }, - "delete": { - "responses": { - "200": { - "description": "Success" - } - }, - "operationId": "delete_activity_user_metadata_tags_/activities////user_metadata/tags", - "tags": [ - "activities" - ] - }, "get": { "responses": { "200": { @@ -914,24 +914,6 @@ } }, "/firework/v2/assets/": { - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "properties": { - "assets": { - "$ref": "#/definitions/Identifier" - } - } - } - } - }, - "operationId": "get_assets_/assets/", - "tags": [ - "Identifiers" - ] - }, "post": { "responses": { "200": { @@ -965,27 +947,27 @@ "tags": [ "Identifiers" ] - } - }, - "/firework/v2/assets/groups/": { + }, "get": { "responses": { "200": { "description": "Success", "schema": { "properties": { - "assets_groups": { - "$ref": "#/definitions/IdentifierGroup" + "assets": { + "$ref": "#/definitions/Identifier" } } } } }, - "operationId": "get_assets_groups_/assets/groups/", + "operationId": "get_assets_/assets/", "tags": [ "Identifiers" ] - }, + } + }, + "/firework/v2/assets/groups/": { "post": { "responses": { "200": { @@ -1019,6 +1001,24 @@ "tags": [ "Identifiers" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "properties": { + "assets_groups": { + "$ref": "#/definitions/IdentifierGroup" + } + } + } + } + }, + "operationId": "get_assets_groups_/assets/groups/", + "tags": [ + "Identifiers" + ] } }, "/firework/v2/assets/groups/{assets_group_id}": { @@ -1030,6 +1030,17 @@ "type": "integer" } ], + "delete": { + "responses": { + "200": { + "description": "Success" + } + }, + "operationId": "delete_assets_group_api_/assets/groups/", + "tags": [ + "Identifiers" + ] + }, "put": { "responses": { "200": { @@ -1064,17 +1075,6 @@ "Identifiers" ] }, - "delete": { - "responses": { - "200": { - "description": "Success" - } - }, - "operationId": "delete_assets_group_api_/assets/groups/", - "tags": [ - "Identifiers" - ] - }, "get": { "responses": { "200": { @@ -1103,24 +1103,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "properties": { - "alerts": { - "$ref": "#/definitions/FeedAlert" - } - } - } - } - }, - "operationId": "get_assets_group_alerts_/assets/groups//alerts", - "tags": [ - "Identifiers" - ] - }, "post": { "responses": { "200": { @@ -1144,6 +1126,24 @@ "tags": [ "Identifiers" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "properties": { + "alerts": { + "$ref": "#/definitions/FeedAlert" + } + } + } + } + }, + "operationId": "get_assets_group_alerts_/assets/groups//alerts", + "tags": [ + "Identifiers" + ] } }, "/firework/v2/assets/groups/{assets_group_id}/alerts/{alert_id}": { @@ -1161,6 +1161,17 @@ "type": "integer" } ], + "delete": { + "responses": { + "200": { + "description": "Success" + } + }, + "operationId": "delete_assets_group_alert_/assets/groups//alerts/", + "tags": [ + "Identifiers" + ] + }, "put": { "responses": { "200": { @@ -1184,17 +1195,6 @@ "tags": [ "Identifiers" ] - }, - "delete": { - "responses": { - "200": { - "description": "Success" - } - }, - "operationId": "delete_assets_group_alert_/assets/groups//alerts/", - "tags": [ - "Identifiers" - ] } }, "/firework/v2/assets/groups/{assets_group_id}/feed": { @@ -1206,7 +1206,7 @@ "type": "integer" } ], - "get": { + "post": { "responses": { "404": { "description": "Identifier group does not exist.", @@ -1227,7 +1227,7 @@ } } }, - "operationId": "get_assets_group_feed_/assets/groups//feed", + "operationId": "post_assets_group_feed_/assets/groups//feed", "parameters": [ { "name": "fields", @@ -1284,7 +1284,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -1466,7 +1466,7 @@ "Identifiers" ] }, - "post": { + "get": { "responses": { "404": { "description": "Identifier group does not exist.", @@ -1487,7 +1487,7 @@ } } }, - "operationId": "post_assets_group_feed_/assets/groups//feed", + "operationId": "get_assets_group_feed_/assets/groups//feed", "parameters": [ { "name": "fields", @@ -1544,7 +1544,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -1736,6 +1736,17 @@ "type": "integer" } ], + "delete": { + "responses": { + "200": { + "description": "Success" + } + }, + "operationId": "delete_asset_api_/assets/", + "tags": [ + "Identifiers" + ] + }, "put": { "responses": { "400": { @@ -1770,17 +1781,6 @@ "Identifiers" ] }, - "delete": { - "responses": { - "200": { - "description": "Success" - } - }, - "operationId": "delete_asset_api_/assets/", - "tags": [ - "Identifiers" - ] - }, "get": { "responses": { "200": { @@ -1809,24 +1809,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "properties": { - "alerts": { - "$ref": "#/definitions/FeedAlert" - } - } - } - } - }, - "operationId": "get_asset_alerts_/assets//alerts", - "tags": [ - "Identifiers" - ] - }, "post": { "responses": { "200": { @@ -1850,6 +1832,24 @@ "tags": [ "Identifiers" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "properties": { + "alerts": { + "$ref": "#/definitions/FeedAlert" + } + } + } + } + }, + "operationId": "get_asset_alerts_/assets//alerts", + "tags": [ + "Identifiers" + ] } }, "/firework/v2/assets/{asset_id}/alerts/{alert_id}": { @@ -1867,6 +1867,17 @@ "type": "integer" } ], + "delete": { + "responses": { + "200": { + "description": "Success" + } + }, + "operationId": "delete_asset_alert_/assets//alerts/", + "tags": [ + "Identifiers" + ] + }, "put": { "responses": { "200": { @@ -1890,17 +1901,6 @@ "tags": [ "Identifiers" ] - }, - "delete": { - "responses": { - "200": { - "description": "Success" - } - }, - "operationId": "delete_asset_alert_/assets//alerts/", - "tags": [ - "Identifiers" - ] } }, "/firework/v2/assets/{asset_id}/feed": { @@ -1912,7 +1912,7 @@ "type": "integer" } ], - "get": { + "post": { "responses": { "404": { "description": "Identifier does not exist.", @@ -1933,7 +1933,7 @@ } } }, - "operationId": "get_asset_feed_/assets//feed", + "operationId": "post_asset_feed_/assets//feed", "parameters": [ { "name": "fields", @@ -1990,7 +1990,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -2172,7 +2172,7 @@ "Identifiers" ] }, - "post": { + "get": { "responses": { "404": { "description": "Identifier does not exist.", @@ -2193,7 +2193,7 @@ } } }, - "operationId": "post_asset_feed_/assets//feed", + "operationId": "get_asset_feed_/assets//feed", "parameters": [ { "name": "fields", @@ -2250,7 +2250,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -2523,7 +2523,7 @@ } }, "/firework/v2/me/feed": { - "get": { + "post": { "responses": { "200": { "description": "The user's home feed activities", @@ -2532,7 +2532,7 @@ } } }, - "operationId": "get_current_user_home_feed_/me/feed", + "operationId": "post_current_user_home_feed_/me/feed", "parameters": [ { "name": "time", @@ -2579,7 +2579,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -2761,7 +2761,7 @@ "me" ] }, - "post": { + "get": { "responses": { "200": { "description": "The user's home feed activities", @@ -2770,7 +2770,7 @@ } } }, - "operationId": "post_current_user_home_feed_/me/feed", + "operationId": "get_current_user_home_feed_/me/feed", "parameters": [ { "name": "time", @@ -2817,7 +2817,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -3001,6 +3001,30 @@ } }, "/firework/v2/me/feed/credentials": { + "post": { + "responses": { + "200": { + "description": "Success", + "schema": { + "$ref": "#/definitions/PaginatedCredentials" + } + } + }, + "operationId": "post_leaked_credentials_feed_endpoint_/me/feed/credentials", + "parameters": [ + { + "name": "payload", + "required": true, + "in": "body", + "schema": { + "$ref": "#/definitions/UserUpdate" + } + } + ], + "tags": [ + "me" + ] + }, "get": { "responses": { "200": { @@ -3037,30 +3061,6 @@ "tags": [ "me" ] - }, - "post": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/PaginatedCredentials" - } - } - }, - "operationId": "post_leaked_credentials_feed_endpoint_/me/feed/credentials", - "parameters": [ - { - "name": "payload", - "required": true, - "in": "body", - "schema": { - "$ref": "#/definitions/UserUpdate" - } - } - ], - "tags": [ - "me" - ] } }, "/firework/v2/me/profile": { @@ -3132,7 +3132,7 @@ "type": "integer" } ], - "get": { + "post": { "responses": { "404": { "description": "Organization not found", @@ -3143,34 +3143,30 @@ "200": { "description": "Success", "schema": { - "$ref": "#/definitions/OrganizationMemberPage" + "properties": { + "member": { + "$ref": "#/definitions/OrganizationMemberWithMetadata" + } + } } } }, - "operationId": "get_organization_members_api_/organizations//members", + "operationId": "post_organization_members_api_/organizations//members", "parameters": [ { - "name": "size", - "in": "query", - "type": "integer", - "default": 20 - }, - { - "name": "from", - "in": "query", - "type": "string" - }, - { - "name": "q", - "in": "query", - "type": "string" + "name": "payload", + "required": true, + "in": "body", + "schema": { + "$ref": "#/definitions/OrganizationMemberData" + } } ], "tags": [ "organizations" ] }, - "post": { + "get": { "responses": { "404": { "description": "Organization not found", @@ -3181,23 +3177,27 @@ "200": { "description": "Success", "schema": { - "properties": { - "member": { - "$ref": "#/definitions/OrganizationMemberWithMetadata" - } - } + "$ref": "#/definitions/OrganizationMemberPage" } } }, - "operationId": "post_organization_members_api_/organizations//members", + "operationId": "get_organization_members_api_/organizations//members", "parameters": [ { - "name": "payload", - "required": true, - "in": "body", - "schema": { - "$ref": "#/definitions/OrganizationMemberData" - } + "name": "size", + "in": "query", + "type": "integer", + "default": 20 + }, + { + "name": "from", + "in": "query", + "type": "string" + }, + { + "name": "q", + "in": "query", + "type": "string" } ], "tags": [ @@ -3480,20 +3480,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/TenantWithCounts" - } - } - }, - "operationId": "get_organization_tenants_api_/organizations//tenants", - "tags": [ - "organizations" - ] - }, "post": { "responses": { "200": { @@ -3517,20 +3503,23 @@ "tags": [ "organizations" ] - } - }, - "/firework/v2/reporting/reports": { + }, "get": { "responses": { "200": { - "description": "Lists reports for the current tenant, ordered from newest to oldest." + "description": "Success", + "schema": { + "$ref": "#/definitions/TenantWithCounts" + } } }, - "operationId": "get_reports_endpoint_/reporting/reports", + "operationId": "get_organization_tenants_api_/organizations//tenants", "tags": [ - "reporting" + "organizations" ] - }, + } + }, + "/firework/v2/reporting/reports": { "post": { "responses": { "200": { @@ -3551,6 +3540,17 @@ "tags": [ "reporting" ] + }, + "get": { + "responses": { + "200": { + "description": "Lists reports for the current tenant, ordered from newest to oldest." + } + }, + "operationId": "get_reports_endpoint_/reporting/reports", + "tags": [ + "reporting" + ] } }, "/firework/v2/reporting/reports/{report_id}": { @@ -3562,17 +3562,6 @@ "type": "integer" } ], - "delete": { - "responses": { - "200": { - "description": "Deletes a report." - } - }, - "operationId": "delete_report_endpoint_/reporting/reports/", - "tags": [ - "reporting" - ] - }, "patch": { "responses": { "200": { @@ -3594,6 +3583,17 @@ "reporting" ] }, + "delete": { + "responses": { + "200": { + "description": "Deletes a report." + } + }, + "operationId": "delete_report_endpoint_/reporting/reports/", + "tags": [ + "reporting" + ] + }, "get": { "responses": { "200": { @@ -3649,7 +3649,7 @@ } }, "/firework/v2/search/": { - "get": { + "post": { "responses": { "400": { "description": "Query is invalid.", @@ -3664,7 +3664,7 @@ } } }, - "operationId": "get_search_/search/", + "operationId": "post_search_/search/", "parameters": [ { "name": "fields", @@ -3721,7 +3721,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -3901,7 +3901,7 @@ "search" ] }, - "post": { + "get": { "responses": { "400": { "description": "Query is invalid.", @@ -3916,7 +3916,7 @@ } } }, - "operationId": "post_search_/search/", + "operationId": "get_search_/search/", "parameters": [ { "name": "fields", @@ -3973,7 +3973,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, blog_post, forum_profile, chat_message, forum_topic, bot, stealer_log, listing, financial_data, seller, ransomleak\n- open_web: paste, social_media_account, source_code_files, bucket_object, service, google, source_code_secrets, bucket, docker, stack_exchange\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -4232,20 +4232,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/TenantUsers" - } - } - }, - "operationId": "get_tenant_users_api_/tenants//users", - "tags": [ - "tenants" - ] - }, "post": { "responses": { "200": { @@ -4266,6 +4252,20 @@ "tags": [ "tenants" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "$ref": "#/definitions/TenantUsers" + } + } + }, + "operationId": "get_tenant_users_api_/tenants//users", + "tags": [ + "tenants" + ] } }, "/firework/v2/tenants/{tenant_id}/users/{user_id}": { @@ -4429,35 +4429,35 @@ "type": "array", "items": { "type": "string", - "example": "domain", + "example": "social_media_account", "enum": [ - "domain", - "ad", - "docker", - "ransomleak", - "paste", - "bucket", - "bucket_object", - "source_code_files", - "leak", + "social_media_account", "blog_post", - "stealer_log", - "source_code_secrets", - "forum_profile", "forum_topic", - "financial_data", + "stealer_log", + "google", + "docker", + "invalid_credential", + "bot", "service", - "social_media_account", - "valid_credential", + "financial_data", + "domain", "seller", + "valid_credential", + "paste", + "forum_profile", + "source_code_secrets", + "ad", + "bucket", + "mitigated_credential", + "forum_post", + "source_code_files", + "bucket_object", "chat_message", "listing", - "google", - "bot", - "invalid_credential", - "forum_post", "stack_exchange", - "mitigated_credential", + "ransomleak", + "leak", "illicit_networks", "open_web", "buckets", @@ -4536,34 +4536,34 @@ "type": "array", "items": { "type": "string", - "example": "domain", + "example": "social_media_account", "enum": [ - "domain", - "docker", - "ransomleak", - "paste", - "bucket", - "bucket_object", - "source_code_files", - "leak", + "social_media_account", "blog_post", - "stealer_log", - "source_code_secrets", - "forum_profile", "forum_topic", - "financial_data", + "stealer_log", + "google", + "docker", + "invalid_credential", + "bot", "service", - "social_media_account", - "valid_credential", + "financial_data", + "domain", "seller", + "valid_credential", + "paste", + "forum_profile", + "source_code_secrets", + "bucket", + "mitigated_credential", + "forum_post", + "source_code_files", + "bucket_object", "chat_message", "listing", - "google", - "bot", - "invalid_credential", - "forum_post", "stack_exchange", - "mitigated_credential", + "ransomleak", + "leak", "illicit_networks", "open_web", "buckets", @@ -5110,24 +5110,6 @@ }, "type": "object" }, - "TenantWithCounts": { - "properties": { - "next": { - "type": "string" - }, - "items": { - "$ref": "#/definitions/TenantWithCounts" - }, - "total_count": { - "type": [ - "integer", - "null" - ], - "example": "nullable integer" - } - }, - "type": "object" - }, "Tenant": { "properties": { "id": { @@ -5212,6 +5194,24 @@ }, "type": "object" }, + "TenantWithCounts": { + "properties": { + "next": { + "type": "string" + }, + "items": { + "$ref": "#/definitions/TenantWithCounts" + }, + "total_count": { + "type": [ + "integer", + "null" + ], + "example": "nullable integer" + } + }, + "type": "object" + }, "UpdatedPermission": { "properties": { "updated_value": { @@ -5319,24 +5319,6 @@ }, "type": "object" }, - "OrganizationMemberPage": { - "properties": { - "members": { - "type": "array", - "items": { - "$ref": "#/definitions/OrganizationMemberWithMetadata" - } - }, - "next": { - "type": [ - "string", - "null" - ], - "example": "nullable string" - } - }, - "type": "object" - }, "OrganizationMemberWithMetadata": { "properties": { "user": { @@ -5404,6 +5386,24 @@ }, "type": "object" }, + "OrganizationMemberPage": { + "properties": { + "members": { + "type": "array", + "items": { + "$ref": "#/definitions/OrganizationMemberWithMetadata" + } + }, + "next": { + "type": [ + "string", + "null" + ], + "example": "nullable string" + } + }, + "type": "object" + }, "OrganizationMembersCount": { "properties": { "count": { diff --git a/docs/api-reference/spec/firework-v3-openapi.json b/docs/api-reference/spec/firework-v3-openapi.json index 41508c28..97f25e9c 100644 --- a/docs/api-reference/spec/firework-v3-openapi.json +++ b/docs/api-reference/spec/firework-v3-openapi.json @@ -569,7 +569,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, forum_profile, blog_post, listing, ransomleak, seller, bot, stealer_log, chat_message, forum_post\n- open_web: source_code_files, social_media_account, bucket_object, stack_exchange, service, google, docker, bucket, paste, source_code_secrets\n- leaks: leak, invalid_credential, valid_credential, mitigated_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -893,7 +893,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, forum_profile, blog_post, listing, ransomleak, seller, bot, stealer_log, chat_message, forum_post\n- open_web: source_code_files, social_media_account, bucket_object, stack_exchange, service, google, docker, bucket, paste, source_code_secrets\n- leaks: leak, invalid_credential, valid_credential, mitigated_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", diff --git a/docs/api-reference/spec/firework-v3-swagger.json b/docs/api-reference/spec/firework-v3-swagger.json index 914efaca..a51820ec 100644 --- a/docs/api-reference/spec/firework-v3-swagger.json +++ b/docs/api-reference/spec/firework-v3-swagger.json @@ -409,7 +409,7 @@ "type": "string" } ], - "get": { + "post": { "responses": { "403": { "description": "Forbidden.", @@ -430,7 +430,7 @@ } } }, - "operationId": "get_asset_feeds_api_/assets//feed", + "operationId": "post_asset_feeds_api_/assets//feed", "parameters": [ { "name": "fields", @@ -487,7 +487,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, forum_profile, blog_post, listing, ransomleak, seller, bot, stealer_log, chat_message, forum_post\n- open_web: source_code_files, social_media_account, bucket_object, stack_exchange, service, google, docker, bucket, paste, source_code_secrets\n- leaks: leak, invalid_credential, valid_credential, mitigated_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -669,7 +669,7 @@ "assets" ] }, - "post": { + "get": { "responses": { "403": { "description": "Forbidden.", @@ -690,7 +690,7 @@ } } }, - "operationId": "post_asset_feeds_api_/assets//feed", + "operationId": "get_asset_feeds_api_/assets//feed", "parameters": [ { "name": "fields", @@ -747,7 +747,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, bot, blog_post, forum_post, stealer_log, listing, seller, ransomleak, chat_message, forum_profile, forum_topic\n- open_web: bucket_object, source_code_files, service, google, social_media_account, docker, source_code_secrets, bucket, paste, stack_exchange\n- leaks: invalid_credential, leak, mitigated_credential, valid_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, forum_profile, blog_post, listing, ransomleak, seller, bot, stealer_log, chat_message, forum_post\n- open_web: source_code_files, social_media_account, bucket_object, stack_exchange, service, google, docker, bucket, paste, source_code_secrets\n- leaks: leak, invalid_credential, valid_credential, mitigated_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -1432,6 +1432,20 @@ "type": "integer" } ], + "post": { + "responses": { + "200": { + "description": "Success", + "schema": { + "$ref": "#/definitions/PaginatedCredentials" + } + } + }, + "operationId": "post_leaked_credentials_feed_endpoint_/identifiers//feed/credentials", + "tags": [ + "identifiers" + ] + }, "get": { "responses": { "200": { @@ -1458,20 +1472,6 @@ "tags": [ "identifiers" ] - }, - "post": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/PaginatedCredentials" - } - } - }, - "operationId": "post_leaked_credentials_feed_endpoint_/identifiers//feed/credentials", - "tags": [ - "identifiers" - ] } }, "/firework/v3/identifiers/{identifier_id}/relations": { diff --git a/docs/api-reference/spec/firework-v4-openapi.json b/docs/api-reference/spec/firework-v4-openapi.json index 613f8ca9..f5e97718 100644 --- a/docs/api-reference/spec/firework-v4-openapi.json +++ b/docs/api-reference/spec/firework-v4-openapi.json @@ -374,143 +374,123 @@ } } }, - "/firework/v4/cti/entities": { - "get": { + "/firework/v4/entities/global/_search": { + "post": { "tags": [ "public", "team=data-intelligence" ], "summary": "List Entities", - "operationId": "list_entities_cti_entities_get", - "parameters": [ - { - "name": "query", - "in": "query", - "required": false, - "schema": { - "type": "string", - "default": "", - "title": "Query" + "operationId": "list_entities_entities_global__search_post", + "requestBody": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/EntitySearchParamsPayload" + } } - }, - { - "name": "types", - "in": "query", - "required": false, - "schema": { - "anyOf": [ - { - "type": "array", - "items": { - "$ref": "#/components/schemas/EntityType" - } - }, - { - "type": "null" + } + }, + "responses": { + "200": { + "description": "Successful Response", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResults_EntityLiteAPIResponseTypes_str_" } - ], - "title": "Types" - } - }, - { - "name": "time_field", - "in": "query", - "required": false, - "schema": { - "$ref": "#/components/schemas/CTITimeField", - "default": "created_at" + } } }, - { - "name": "time_range", - "in": "query", - "required": false, - "schema": { - "anyOf": [ - { - "$ref": "#/components/schemas/TimeRangeType" - }, - { - "type": "null" + "422": { + "description": "Validation Error", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/HTTPValidationError" } - ], - "title": "Time Range" + } } - }, + } + } + } + }, + "/firework/v4/entities/{id}": { + "get": { + "tags": [ + "public", + "team=data-intelligence" + ], + "summary": "Get Entity", + "operationId": "get_entity_entities__id__get", + "parameters": [ { - "name": "time_range_from", - "in": "query", - "required": false, + "name": "id", + "in": "path", + "required": true, "schema": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" + "type": "string", + "format": "uuid", + "title": "Id" + } + } + ], + "responses": { + "200": { + "description": "Successful Response", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/EntityAPIResponseTypes" } - ], - "title": "Time Range From" + } } }, - { - "name": "time_range_to", - "in": "query", - "required": false, - "schema": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" + "422": { + "description": "Validation Error", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/HTTPValidationError" } - ], - "title": "Time Range To" + } } - }, + } + } + } + }, + "/firework/v4/entities/{id}/relations": { + "get": { + "tags": [ + "public", + "team=data-intelligence" + ], + "summary": "List Entity Relations", + "operationId": "list_entity_relations_entities__id__relations_get", + "parameters": [ { - "name": "sources", - "in": "query", - "required": false, + "name": "id", + "in": "path", + "required": true, "schema": { - "anyOf": [ - { - "type": "array", - "items": { - "type": "string" - } - }, - { - "type": "null" - } - ], - "title": "Sources" + "type": "string", + "format": "uuid", + "title": "Id" } }, { - "name": "topic_ids", + "name": "size", "in": "query", "required": false, "schema": { - "anyOf": [ - { - "type": "array", - "items": { - "type": "string" - } - }, - { - "type": "null" - } - ], - "title": "Topic Ids" + "type": "integer", + "maximum": 1000, + "default": 10, + "title": "Size" } }, { - "name": "sort_by_key", + "name": "from_", "in": "query", "required": false, "schema": { @@ -522,86 +502,26 @@ "type": "null" } ], - "title": "Sort By Key" - } - }, - { - "name": "sort_by_direction", - "in": "query", - "required": false, - "schema": { - "$ref": "#/components/schemas/OrderType", - "default": "desc" + "title": "From " } }, { - "name": "search_after", + "name": "entity_types", "in": "query", "required": false, "schema": { "anyOf": [ { - "type": "string" + "type": "array", + "items": { + "$ref": "#/components/schemas/EntityType" + } }, { "type": "null" } ], - "title": "Search After" - } - }, - { - "name": "size", - "in": "query", - "required": false, - "schema": { - "type": "integer", - "default": 10, - "title": "Size" - } - } - ], - "responses": { - "200": { - "description": "Successful Response", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/PaginatedResults_EntityLiteAPIResponseTypes_str_" - } - } - } - }, - "422": { - "description": "Validation Error", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/HTTPValidationError" - } - } - } - } - } - } - }, - "/firework/v4/cti/entities/{asset_uuid}": { - "get": { - "tags": [ - "public", - "team=data-intelligence" - ], - "summary": "Get Entity", - "operationId": "get_entity_cti_entities__asset_uuid__get", - "parameters": [ - { - "name": "asset_uuid", - "in": "path", - "required": true, - "schema": { - "type": "string", - "format": "uuid", - "title": "Asset Uuid" + "title": "Entity Types" } } ], @@ -611,7 +531,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/EntityAPIResponseTypes" + "$ref": "#/components/schemas/PaginatedResults_CTIEntityRelationshipResponse_str_" } } } @@ -1175,6 +1095,9 @@ }, { "$ref": "#/components/schemas/PaginatedResults_StealerLogCookie_str_" + }, + { + "$ref": "#/components/schemas/PaginatedResults_FeedItem_str_" } ], "title": "Response Expand Event Field Events Expand Get" @@ -3061,7 +2984,6 @@ "bucket_object", "cc", "cc_bases", - "chat_channel_summary", "chat_message", "cookie", "docker_image", @@ -3131,195 +3053,54 @@ }, "ActorAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "actor", + "title": "Entity Type", + "default": "actor" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, - "name": { + "data": { + "$ref": "#/components/schemas/pyro__entities__cti__actors__actor_datamodels__ActorData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ActorAPIResponse" + }, + "ActorLiteAPIResponse": { + "properties": { + "entity_type": { "type": "string", - "title": "Name" + "const": "actor", + "title": "Entity Type", + "default": "actor" }, - "created_by": { - "type": "string", - "title": "Created By" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, - "description": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description" + "data": { + "$ref": "#/components/schemas/ActorLiteData" } }, "type": "object", "required": [ - "uuid", - "type", - "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description" + "metadata", + "data" ], - "title": "ActorAPIResponse" + "title": "ActorLiteAPIResponse" }, - "ActorLiteAPIResponse": { + "ActorLiteData": { "properties": { - "uuid": { - "type": "string", - "title": "Uuid" - }, - "type": { - "$ref": "#/components/schemas/EntityType" - }, "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -3334,16 +3115,10 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description" ], - "title": "ActorLiteAPIResponse" + "title": "ActorLiteData" }, "AddressData": { "properties": { @@ -3371,16 +3146,15 @@ }, "state": { "type": "string", - "minLength": 1, - "title": "State" + "title": "State", + "default": "" } }, "type": "object", "required": [ "street", "city", - "country", - "state" + "country" ], "title": "AddressData" }, @@ -4099,6 +3873,53 @@ ], "title": "AssetEnrichmentType" }, + "AssetRelationType": { + "type": "string", + "enum": [ + "analysis_of", + "attributed_to", + "authored_by", + "based_on", + "beacons_to", + "characterizes", + "commits_with", + "communicates_with", + "compromises", + "consists_of", + "contributed_to", + "controls", + "delivers", + "downloads", + "drops", + "dynamic_analysis_of", + "exfiltrate_to", + "exploits", + "found_from", + "has", + "has_account_on", + "has_favicon", + "has_screenshot", + "hosts", + "impersonates", + "indicates", + "investigates", + "links_to_azure_tenant", + "located_at", + "looks_like", + "mentioned_in", + "mitigates", + "originates_from", + "owns", + "related_to", + "resolves_to", + "static_analysis_of", + "subdomain_of", + "targets", + "uses", + "variant_of" + ], + "title": "AssetRelationType" + }, "AstpCookiesValue": { "properties": { "cookie_names": { @@ -4135,215 +3956,99 @@ }, "AttackPatternEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "attack_pattern", + "title": "Entity Type", + "default": "attack_pattern" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/AttackPatternEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "AttackPatternEntityAPIResponse" + }, + "AttackPatternEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" }, - "sources": { + "kill_chain_phases": { "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + "$ref": "#/components/schemas/KillChainAPIResponse" }, "type": "array", - "title": "Sources" + "title": "Kill Chain Phases" }, - "created_at": { + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "name", + "description", + "kill_chain_phases", + "marking_definitions" + ], + "title": "AttackPatternEntityData" + }, + "AttackPatternEntityLiteAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "attack_pattern", + "title": "Entity Type", + "default": "attack_pattern" + }, + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" + }, + "data": { + "$ref": "#/components/schemas/AttackPatternEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "AttackPatternEntityLiteAPIResponse" + }, + "AttackPatternEntityLiteData": { + "properties": { + "name": { + "type": "string", + "title": "Name" + }, + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, - "description": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description" - }, - "kill_chain_phases": { - "items": { - "$ref": "#/components/schemas/KillChainAPIResponse" - }, - "type": "array", - "title": "Kill Chain Phases" - }, - "marking_definitions": { - "items": { - "$ref": "#/components/schemas/MarkingDefinition" - }, - "type": "array", - "title": "Marking Definitions" - } - }, - "type": "object", - "required": [ - "uuid", - "type", - "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description", - "kill_chain_phases", - "marking_definitions" - ], - "title": "AttackPatternEntityAPIResponse" - }, - "AttackPatternEntityLiteAPIResponse": { - "properties": { - "uuid": { - "type": "string", - "title": "Uuid" - }, - "type": { - "$ref": "#/components/schemas/EntityType" - }, - "name": { - "type": "string", - "title": "Name" - }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, - "description": { - "anyOf": [ - { - "type": "string" + "type": "string" }, { "type": "null" @@ -4354,16 +4059,10 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description" ], - "title": "AttackPatternEntityLiteAPIResponse" + "title": "AttackPatternEntityLiteData" }, "AuthDomainQuery": { "properties": { @@ -4890,134 +4589,145 @@ ], "title": "CCBinData" }, - "CTIEntitySourceAPIResponse": { + "CTIEntityRelationshipResponse": { "properties": { - "id": { + "source_entity": { + "$ref": "#/components/schemas/EntityData" + }, + "target_entity": { + "$ref": "#/components/schemas/EntityData" + }, + "relation_type": { + "$ref": "#/components/schemas/AssetRelationType" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "modified_at": { "type": "string", - "title": "Id" + "format": "date-time", + "title": "Modified At" }, - "name": { + "valid_from": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Name" + "title": "Valid From" }, - "confidence": { + "valid_until": { "anyOf": [ { - "type": "integer" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Confidence" + "title": "Valid Until" } }, "type": "object", "required": [ - "id" - ], - "title": "CTIEntitySourceAPIResponse" - }, - "CTITimeField": { - "type": "string", - "enum": [ - "created_at", - "updated_at", - "first_seen_at", - "last_seen_at" + "source_entity", + "target_entity", + "relation_type", + "sources", + "modified_at" ], - "title": "CTITimeField", - "description": "A time-based field of a CTI entity.\n\nThe enum *value* is the API/wire token (e.g. ``\"created_at\"``); use\n:pyattr:`es_field` for the Elasticsearch field path (``metadata.created_at``)." + "title": "CTIEntityRelationshipResponse" }, - "CampaignEntityAPIResponse": { + "CTIEntitySourceAPIResponse": { "properties": { - "uuid": { + "id": { "type": "string", - "title": "Uuid" - }, - "type": { - "$ref": "#/components/schemas/EntityType" + "title": "Id" }, "name": { - "type": "string", - "title": "Name" - }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Name" }, - "updated_at": { + "confidence": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "integer" }, { "type": "null" } ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" + "title": "Confidence" + } + }, + "type": "object", + "required": [ + "id" + ], + "title": "CTIEntitySourceAPIResponse" + }, + "CTIEntityType": { + "type": "string", + "enum": [ + "actor", + "attack_pattern", + "campaign", + "chat_channel", + "external_report", + "forum_thread", + "indicator", + "infrastructure", + "location", + "malware", + "threat_actor", + "threat_actor_group", + "tool", + "vulnerability" + ] + }, + "CampaignEntityAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "campaign", + "title": "Entity Type", + "default": "campaign" }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" + "data": { + "$ref": "#/components/schemas/CampaignEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "CampaignEntityAPIResponse" + }, + "CampaignEntityData": { + "properties": { + "name": { + "type": "string", + "title": "Name" }, "description": { "anyOf": [ @@ -5047,102 +4757,41 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "aliases", "marking_definitions" ], - "title": "CampaignEntityAPIResponse" + "title": "CampaignEntityData" }, "CampaignEntityLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "campaign", + "title": "Entity Type", + "default": "campaign" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/CampaignEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "CampaignEntityLiteAPIResponse" + }, + "CampaignEntityLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -5164,153 +4813,92 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "aliases" ], - "title": "CampaignEntityLiteAPIResponse" + "title": "CampaignEntityLiteData" }, "ChatChannelEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "chat_channel", + "title": "Entity Type", + "default": "chat_channel" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ChatChannelEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ChatChannelEntityAPIResponse" + }, + "ChatChannelEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Description" }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" + "topics": { + "items": { + "$ref": "#/components/schemas/ThreadTopic" + }, + "type": "array", + "title": "Topics" }, - "first_seen_at": { + "conversation_link": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "First Seen At" + "title": "Conversation Link" }, - "last_seen_at": { + "chat_channel_profile_overview": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Chat Channel Profile Overview" }, - "confidence": { + "chat_channel_profile_content_and_activity": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Confidence" + "title": "Chat Channel Profile Content And Activity" }, - "description": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description" - }, - "topics": { - "items": { - "$ref": "#/components/schemas/ThreadTopic" - }, - "type": "array", - "title": "Topics" - }, - "conversation_link": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Conversation Link" - }, - "chat_channel_profile_overview": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Chat Channel Profile Overview" - }, - "chat_channel_profile_content_and_activity": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Chat Channel Profile Content And Activity" - }, - "chat_channel_profile_nature_and_sophistication": { + "chat_channel_profile_nature_and_sophistication": { "anyOf": [ { "type": "string" @@ -5324,13 +4912,7 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "topics", "conversation_link", @@ -5338,91 +4920,36 @@ "chat_channel_profile_content_and_activity", "chat_channel_profile_nature_and_sophistication" ], - "title": "ChatChannelEntityAPIResponse" + "title": "ChatChannelEntityData" }, "ChatChannelEntityLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "chat_channel", + "title": "Entity Type", + "default": "chat_channel" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ChatChannelEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ChatChannelEntityLiteAPIResponse" + }, + "ChatChannelEntityLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -5444,17 +4971,11 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "topics" ], - "title": "ChatChannelEntityLiteAPIResponse" + "title": "ChatChannelEntityLiteData" }, "ChatMessageEvent": { "properties": { @@ -6297,6 +5818,60 @@ ], "title": "CredentialsQueryPayload" }, + "DateFilter": { + "properties": { + "gt": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Gt" + }, + "gte": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Gte" + }, + "lt": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Lt" + }, + "lte": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Lte" + } + }, + "type": "object", + "title": "DateFilter" + }, "DockerImageEvent": { "properties": { "event_type": { @@ -6750,6 +6325,33 @@ } ] }, + "EntityData": { + "properties": { + "id": { + "type": "string", + "title": "Id" + }, + "entity_type": { + "$ref": "#/components/schemas/CTIEntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "confidence": { + "type": "integer", + "title": "Confidence" + } + }, + "type": "object", + "required": [ + "id", + "entity_type", + "name", + "confidence" + ], + "title": "EntityData" + }, "EntityLiteAPIResponseTypes": { "anyOf": [ { @@ -6796,49 +6398,241 @@ } ] }, - "EntityType": { - "type": "string", - "enum": [ - "attack_pattern", - "actor", - "campaign", - "chat_channel", - "external_report", - "forum_thread", - "identity", - "indicator", - "infrastructure", - "domain", - "location", - "malware", - "organization", - "threat_actor", - "threat_actor_group", - "tool", - "vulnerability" - ], - "title": "EntityType" - }, - "EventAction": { + "EntityMetadataAPIResponse": { "properties": { - "type": { + "id": { "type": "string", - "enum": [ - "remediate", - "unremediate", - "ignore", - "unignore" - ], - "title": "Type" - } - }, - "type": "object", - "required": [ - "type" - ], - "title": "EventAction" - }, - "EventActionTarget": { + "title": "Id" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + } + }, + "type": "object", + "required": [ + "id", + "created_by", + "sources", + "created_at", + "updated_at" + ], + "title": "EntityMetadataAPIResponse" + }, + "EntitySearchFilters": { + "properties": { + "types": { + "anyOf": [ + { + "items": { + "$ref": "#/components/schemas/EntityType" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Types" + }, + "sources": { + "anyOf": [ + { + "items": { + "type": "string" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Sources" + }, + "topic_ids": { + "anyOf": [ + { + "items": { + "type": "string" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Topic Ids" + }, + "created_at": { + "$ref": "#/components/schemas/DateFilter" + }, + "updated_at": { + "$ref": "#/components/schemas/DateFilter" + }, + "first_seen_at": { + "$ref": "#/components/schemas/DateFilter" + }, + "last_seen_at": { + "$ref": "#/components/schemas/DateFilter" + } + }, + "type": "object", + "title": "EntitySearchFilters" + }, + "EntitySearchParamsPayload": { + "properties": { + "query": { + "type": "string", + "title": "Query", + "default": "" + }, + "filters": { + "$ref": "#/components/schemas/EntitySearchFilters" + }, + "sort": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Sort" + }, + "order": { + "$ref": "#/components/schemas/OrderType", + "default": "desc" + }, + "from": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "From" + }, + "size": { + "type": "integer", + "title": "Size", + "default": 10 + } + }, + "type": "object", + "title": "EntitySearchParamsPayload" + }, + "EntityType": { + "type": "string", + "enum": [ + "attack_pattern", + "actor", + "campaign", + "chat_channel", + "external_report", + "forum_thread", + "identity", + "indicator", + "infrastructure", + "domain", + "location", + "malware", + "organization", + "threat_actor", + "threat_actor_group", + "tool", + "vulnerability" + ], + "title": "EntityType" + }, + "EventAction": { + "properties": { + "type": { + "type": "string", + "enum": [ + "remediate", + "unremediate", + "ignore", + "unignore" + ], + "title": "Type" + } + }, + "type": "object", + "required": [ + "type" + ], + "title": "EventAction" + }, + "EventActionTarget": { "properties": { "uid": { "type": "string", @@ -6944,7 +6738,8 @@ "type": "string", "enum": [ "credentials", - "cookies" + "cookies", + "associated_events" ], "title": "ExpandableField" }, @@ -6976,29 +6771,51 @@ }, "ExternalReportEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "external_report", + "title": "Entity Type", + "default": "external_report" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ExternalReportEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ExternalReportEntityAPIResponse" + }, + "ExternalReportEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" }, - "sources": { + "report_types": { "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + "type": "string" }, "type": "array", - "title": "Sources" + "title": "Report Types" }, - "created_at": { + "published": { "anyOf": [ { "type": "string", @@ -7008,84 +6825,7 @@ "type": "null" } ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, - "description": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description" - }, - "report_types": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Report Types" - }, - "published": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Published" + "title": "Published" }, "marking_definitions": { "items": { @@ -7097,103 +6837,42 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "report_types", "published", "marking_definitions" ], - "title": "ExternalReportEntityAPIResponse" + "title": "ExternalReportEntityData" }, "ExternalReportEntityLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "external_report", + "title": "Entity Type", + "default": "external_report" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ExternalReportEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ExternalReportEntityLiteAPIResponse" + }, + "ExternalReportEntityLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -7208,16 +6887,10 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description" ], - "title": "ExternalReportEntityLiteAPIResponse" + "title": "ExternalReportEntityLiteData" }, "FeedConfiguration": { "properties": { @@ -7266,60 +6939,6 @@ ], "title": "FeedConfiguration" }, - "FeedDateFilter": { - "properties": { - "gt": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Gt" - }, - "gte": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Gte" - }, - "lt": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Lt" - }, - "lte": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Lte" - } - }, - "type": "object", - "title": "FeedDateFilter" - }, "FeedDefinition": { "properties": { "type": { @@ -7367,10 +6986,10 @@ "title": "Type" }, "estimated_created_at": { - "$ref": "#/components/schemas/FeedDateFilter" + "$ref": "#/components/schemas/DateFilter" }, "materialized_at": { - "$ref": "#/components/schemas/FeedDateFilter" + "$ref": "#/components/schemas/DateFilter" }, "tags": { "items": { @@ -7407,6 +7026,17 @@ "metadata": { "$ref": "#/components/schemas/FeedItemMetadata" }, + "title": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Title" + }, "tenant_metadata": { "$ref": "#/components/schemas/FeedItemTenantMetadata" }, @@ -8086,88 +7716,95 @@ }, "ForumThreadAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "forum_thread", + "title": "Entity Type", + "default": "forum_thread" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ForumThreadData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ForumThreadAPIResponse" + }, + "ForumThreadData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Description" }, - "updated_at": { + "topics": { + "items": { + "$ref": "#/components/schemas/ThreadTopic" + }, + "type": "array", + "title": "Topics" + }, + "original_post_overview": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Updated At" + "title": "Original Post Overview" }, - "first_seen_at": { + "original_post_actor_intent": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "First Seen At" + "title": "Original Post Actor Intent" }, - "last_seen_at": { + "replies_overview": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Replies Overview" }, - "confidence": { + "replies_sentiment_analysis": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Confidence" + "title": "Replies Sentiment Analysis" }, - "description": { + "top_actors_overview": { "anyOf": [ { "type": "string" @@ -8176,113 +7813,50 @@ "type": "null" } ], - "title": "Description" - }, - "topics": { - "items": { - "$ref": "#/components/schemas/ThreadTopic" - }, - "type": "array", - "title": "Topics" + "title": "Top Actors Overview" } }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", - "topics" + "topics", + "original_post_overview", + "original_post_actor_intent", + "replies_overview", + "replies_sentiment_analysis", + "top_actors_overview" ], - "title": "ForumThreadAPIResponse" + "title": "ForumThreadData" }, "ForumThreadLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "forum_thread", + "title": "Entity Type", + "default": "forum_thread" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ForumThreadLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ForumThreadLiteAPIResponse" + }, + "ForumThreadLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -8304,17 +7878,11 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "topics" ], - "title": "ForumThreadLiteAPIResponse" + "title": "ForumThreadLiteData" }, "ForwardInfo": { "properties": { @@ -9455,6 +9023,18 @@ "source": { "$ref": "#/components/schemas/IdentifierSource" }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, "data_updated_at": { "type": "string", "format": "date-time", @@ -9509,6 +9089,7 @@ "type": "object", "required": [ "source", + "created_at", "data_updated_at", "event_count", "usage_count", @@ -9718,87 +9299,32 @@ }, "IndicatorEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "indicator", + "title": "Entity Type", + "default": "indicator" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/IndicatorEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "IndicatorEntityAPIResponse" + }, + "IndicatorEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "pattern": { "type": "string", "title": "Pattern" @@ -9873,13 +9399,7 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "pattern", "description", "pattern_version", @@ -9889,91 +9409,36 @@ "kill_chain_phases", "marking_definitions" ], - "title": "IndicatorEntityAPIResponse" + "title": "IndicatorEntityData" }, "IndicatorEntityLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "indicator", + "title": "Entity Type", + "default": "indicator" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/IndicatorEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "IndicatorEntityLiteAPIResponse" + }, + "IndicatorEntityLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "pattern": { "type": "string", "title": "Pattern" @@ -9992,101 +9457,40 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "pattern", "description" ], - "title": "IndicatorEntityLiteAPIResponse" + "title": "IndicatorEntityLiteData" }, "InfrastructureEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "infrastructure", + "title": "Entity Type", + "default": "infrastructure" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/InfrastructureEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "InfrastructureEntityAPIResponse" + }, + "InfrastructureEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -10129,152 +9533,85 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "aliases", "infrastructure_types", "kill_chain_phases", "marking_definitions" ], - "title": "InfrastructureEntityAPIResponse" + "title": "InfrastructureEntityData" }, "InfrastructureEntityLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "infrastructure", + "title": "Entity Type", + "default": "infrastructure" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/InfrastructureEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "InfrastructureEntityLiteAPIResponse" + }, + "InfrastructureEntityLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Description" }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, - "description": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description" - }, - "aliases": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Aliases" - } - }, - "type": "object", - "required": [ - "uuid", - "type", - "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description", - "aliases" - ], - "title": "InfrastructureEntityLiteAPIResponse" - }, - "IntelType": { - "type": "string", - "enum": [ - "unit_summary_based", - "custom_intel" - ], - "title": "IntelType" - }, - "InvalidCredentialEvent": { - "properties": { - "event_type": { - "type": "string", - "const": "invalid_credential", - "title": "Event Type", - "default": "invalid_credential" + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + } + }, + "type": "object", + "required": [ + "name", + "description", + "aliases" + ], + "title": "InfrastructureEntityLiteData" + }, + "IntelType": { + "type": "string", + "enum": [ + "unit_summary_based", + "custom_intel" + ], + "title": "IntelType" + }, + "InvalidCredentialEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "invalid_credential", + "title": "Event Type", + "default": "invalid_credential" }, "metadata": { "$ref": "#/components/schemas/EventMetadata" @@ -10731,41 +10068,148 @@ }, "LocationEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "location", + "title": "Entity Type", + "default": "location" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/LocationEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "LocationEntityAPIResponse" + }, + "LocationEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" }, - "sources": { + "country_code": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Country Code" + }, + "marking_definitions": { "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + "$ref": "#/components/schemas/MarkingDefinition" }, "type": "array", - "title": "Sources" + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "name", + "description", + "country_code", + "marking_definitions" + ], + "title": "LocationEntityData" + }, + "LocationEntityLiteAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "location", + "title": "Entity Type", + "default": "location" }, - "created_at": { + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" + }, + "data": { + "$ref": "#/components/schemas/LocationEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "LocationEntityLiteAPIResponse" + }, + "LocationEntityLiteData": { + "properties": { + "name": { + "type": "string", + "title": "Name" + }, + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Description" + } + }, + "type": "object", + "required": [ + "name", + "description" + ], + "title": "LocationEntityLiteData" + }, + "LookalikeDomainEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "lookalike", + "title": "Event Type", + "default": "lookalike" }, - "updated_at": { + "data": { + "$ref": "#/components/schemas/LookalikeDomainEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Lookalike Domain" + }, + "LookalikeDomainEventData": { + "properties": { + "domain": { + "type": "string", + "title": "Domain", + "description": "The domain of the lookalike domain." + }, + "registered_at": { "anyOf": [ { "type": "string", @@ -10775,44 +10219,50 @@ "type": "null" } ], - "title": "Updated At" + "title": "Registered At", + "description": "The date and time the lookalike domain was registered." }, - "first_seen_at": { + "identifier_domains": { "anyOf": [ { - "type": "string", - "format": "date-time" + "items": { + "type": "string" + }, + "type": "array" }, { "type": "null" } ], - "title": "First Seen At" + "title": "Identifier Domains", + "description": "Domain identifiers matching the lookalike domains" }, - "last_seen_at": { + "feed": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Feed", + "description": "The feed where the lookalike domain was found" }, - "confidence": { + "cert_data": { "anyOf": [ { - "type": "integer" + "additionalProperties": true, + "type": "object" }, { "type": "null" } ], - "title": "Confidence" + "title": "Cert Data", + "description": "The certificate data of the lookalike domain." }, - "description": { + "subject": { "anyOf": [ { "type": "string" @@ -10821,9 +10271,10 @@ "type": "null" } ], - "title": "Description" + "title": "Subject", + "description": "The subject of the certificate of the lookalike domain." }, - "country_code": { + "issuer": { "anyOf": [ { "type": "string" @@ -10832,197 +10283,167 @@ "type": "null" } ], - "title": "Country Code" - }, - "marking_definitions": { - "items": { - "$ref": "#/components/schemas/MarkingDefinition" - }, - "type": "array", - "title": "Marking Definitions" + "title": "Issuer", + "description": "The issuer of the certificate of the lookalike domain." } }, "type": "object", "required": [ - "uuid", - "type", - "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description", - "country_code", - "marking_definitions" + "domain" ], - "title": "LocationEntityAPIResponse" + "title": "LookalikeDomainEventData" }, - "LocationEntityLiteAPIResponse": { + "LuceneValue": { "properties": { - "uuid": { + "query": { "type": "string", - "title": "Uuid" + "title": "Query", + "description": "The lucene query of the matching policy" + } + }, + "type": "object", + "required": [ + "query" + ], + "title": "LuceneValue" + }, + "MalwareEntityAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "malware", + "title": "Entity Type", + "default": "malware" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/MalwareEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "MalwareEntityAPIResponse" + }, + "MalwareEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Updated At" + "title": "Description" }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" + "malware_types": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Malware Types" }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" + "kill_chain_phases": { + "items": { + "$ref": "#/components/schemas/KillChainAPIResponse" + }, + "type": "array", + "title": "Kill Chain Phases" }, - "description": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description" + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" } }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description" + "description", + "aliases", + "malware_types", + "kill_chain_phases", + "marking_definitions" ], - "title": "LocationEntityLiteAPIResponse" + "title": "MalwareEntityData" }, - "LookalikeDomainEvent": { + "MalwareEntityLiteAPIResponse": { "properties": { - "event_type": { + "entity_type": { "type": "string", - "const": "lookalike", - "title": "Event Type", - "default": "lookalike" - }, - "data": { - "$ref": "#/components/schemas/LookalikeDomainEventData" + "const": "malware", + "title": "Entity Type", + "default": "malware" }, "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "$ref": "#/components/schemas/EntityMetadataAPIResponse" + }, + "data": { + "$ref": "#/components/schemas/MalwareEntityLiteData" } }, "type": "object", "required": [ - "data", - "metadata" + "metadata", + "data" ], - "title": "Lookalike Domain" + "title": "MalwareEntityLiteAPIResponse" }, - "LookalikeDomainEventData": { + "MalwareEntityLiteData": { "properties": { - "domain": { + "name": { "type": "string", - "title": "Domain", - "description": "The domain of the lookalike domain." - }, - "registered_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Registered At", - "description": "The date and time the lookalike domain was registered." + "title": "Name" }, - "identifier_domains": { + "description": { "anyOf": [ { - "items": { - "type": "string" - }, - "type": "array" + "type": "string" }, { "type": "null" } ], - "title": "Identifier Domains", - "description": "Domain identifiers matching the lookalike domains" + "title": "Description" }, - "feed": { + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + } + }, + "type": "object", + "required": [ + "name", + "description", + "aliases" + ], + "title": "MalwareEntityLiteData" + }, + "MalwareInformation": { + "properties": { + "malware_family": { "anyOf": [ { "type": "string" @@ -11031,23 +10452,22 @@ "type": "null" } ], - "title": "Feed", - "description": "The feed where the lookalike domain was found" + "title": "Malware Family", + "description": "The malware family used for device infection." }, - "cert_data": { + "build_id": { "anyOf": [ { - "additionalProperties": true, - "type": "object" + "type": "string" }, { "type": "null" } ], - "title": "Cert Data", - "description": "The certificate data of the lookalike domain." + "title": "Build Id", + "description": "The build ID of the malware used for device infection." }, - "subject": { + "file_location": { "anyOf": [ { "type": "string" @@ -11056,266 +10476,350 @@ "type": "null" } ], - "title": "Subject", - "description": "The subject of the certificate of the lookalike domain." + "title": "File Location", + "description": "The file location of the malware used for device infection." }, - "issuer": { + "infected_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Issuer", - "description": "The issuer of the certificate of the lookalike domain." + "title": "Infected At", + "description": "The date and time the malware was used to infect the victim's device." } }, "type": "object", - "required": [ - "domain" - ], - "title": "LookalikeDomainEventData" + "title": "MalwareInformation" }, - "LuceneValue": { + "MarkingDefinition": { "properties": { - "query": { + "id": { "type": "string", - "title": "Query", - "description": "The lucene query of the matching policy" - } - }, - "type": "object", + "title": "Id" + }, + "definition_type": { + "$ref": "#/components/schemas/MarkingDefinitionType" + }, + "name": { + "type": "string", + "title": "Name" + } + }, + "type": "object", "required": [ - "query" + "id", + "definition_type", + "name" ], - "title": "LuceneValue" + "title": "MarkingDefinition" }, - "MalwareEntityAPIResponse": { + "MarkingDefinitionType": { + "type": "string", + "enum": [ + "tlp" + ], + "title": "MarkingDefinitionType" + }, + "MatchingPolicyAssignmentPayload": { "properties": { - "uuid": { + "matching_policy": { + "$ref": "#/components/schemas/MatchingPolicyPayload" + }, + "assigned_at": { "type": "string", - "title": "Uuid" + "format": "date-time", + "title": "Assigned At", + "description": "The date and time this policy was assigned to the identifier" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "clean_past_events": { + "type": "boolean", + "title": "Clean Past Events", + "description": "Whether this policy has been applied to historical events" + } + }, + "type": "object", + "required": [ + "matching_policy", + "assigned_at", + "clean_past_events" + ], + "title": "MatchingPolicyAssignmentPayload" + }, + "MatchingPolicyPayload": { + "properties": { + "uuid": { + "type": "string", + "format": "uuid4", + "title": "Uuid", + "description": "The UUID of the matching policy" }, "name": { "type": "string", - "title": "Name" + "title": "Name", + "description": "The name of the matching policy" }, - "created_by": { - "type": "string", - "title": "Created By" + "policy_type": { + "$ref": "#/components/schemas/MatchingPolicyType", + "description": "The type of the matching policy" }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" + "value": { + "$ref": "#/components/schemas/PolicyValue", + "description": "The value of the matching policy depending on its type" }, "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, - "description": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description" - }, - "aliases": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Aliases" - }, - "malware_types": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Malware Types" - }, - "kill_chain_phases": { - "items": { - "$ref": "#/components/schemas/KillChainAPIResponse" - }, - "type": "array", - "title": "Kill Chain Phases" + "type": "string", + "format": "date-time", + "title": "Created At", + "description": "The date and time the matching policy was created" }, - "marking_definitions": { - "items": { - "$ref": "#/components/schemas/MarkingDefinition" - }, - "type": "array", - "title": "Marking Definitions" + "last_updated_at": { + "type": "string", + "format": "date-time", + "title": "Last Updated At", + "description": "The date and time the matching policy was last updated" } }, "type": "object", "required": [ "uuid", - "type", "name", - "created_by", - "sources", + "policy_type", + "value", "created_at", - "updated_at", - "description", - "aliases", - "malware_types", - "kill_chain_phases", - "marking_definitions" + "last_updated_at" ], - "title": "MalwareEntityAPIResponse" + "title": "MatchingPolicyPayload" }, - "MalwareEntityLiteAPIResponse": { + "MatchingPolicyType": { + "type": "string", + "enum": [ + "INCLUDED_KEYWORDS", + "EXCLUDED_KEYWORDS", + "LUCENE_QUERY", + "ASTP_COOKIES", + "ASTP_DOMAIN" + ], + "title": "MatchingPolicyType" + }, + "MitigatedCredentialEvent": { "properties": { - "uuid": { + "event_type": { "type": "string", - "title": "Uuid" + "const": "mitigated_credential", + "title": "Event Type", + "default": "mitigated_credential" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EventMetadata" }, - "name": { + "data": { + "$ref": "#/components/schemas/MitigatedCredentialEventData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "Mitigated Credential" + }, + "MitigatedCredentialEventData": { + "properties": { + "identity_name": { "type": "string", - "title": "Name" + "title": "Identity Name", + "description": "The email or username associated with the credential." }, - "created_by": { + "credential_hash": { "type": "string", - "title": "Created By" + "title": "Credential Hash", + "description": "A hash uniquely identifying the credential." }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" + "tenant_integration_id": { + "type": "string", + "title": "Tenant Integration Id", + "description": "The UUID of the tenant's IdP integration that validated the credential." }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" + "mitigation_action": { + "type": "string", + "title": "Mitigation Action", + "description": "The action the tenant's IdP integration took to mitigate the credential" + } + }, + "type": "object", + "required": [ + "identity_name", + "credential_hash", + "tenant_integration_id", + "mitigation_action" + ], + "title": "MitigatedCredentialEventData" + }, + "NameData": { + "properties": { + "type": { + "type": "string", + "const": "name", + "title": "Type", + "default": "name" }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" + "first_name": { + "type": "string", + "title": "First Name" }, - "first_seen_at": { + "last_name": { + "type": "string", + "title": "Last Name" + }, + "is_strict": { + "type": "boolean", + "title": "Is Strict" + } + }, + "type": "object", + "required": [ + "first_name", + "last_name", + "is_strict" + ], + "title": "NameData" + }, + "NameQuery": { + "properties": { + "type": { + "type": "string", + "const": "name", + "title": "Type" + }, + "first_name": { + "type": "string", + "title": "First Name" + }, + "last_name": { + "type": "string", + "title": "Last Name" + }, + "is_strict": { + "type": "boolean", + "title": "Is Strict" + } + }, + "type": "object", + "required": [ + "type", + "first_name", + "last_name", + "is_strict" + ], + "title": "NameQuery" + }, + "OrderType": { + "type": "string", + "enum": [ + "asc", + "desc" + ], + "title": "OrderType" + }, + "PaginatedResults_Alert_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/Alert" + }, + "type": "array", + "title": "Items" + }, + "next": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "First Seen At" + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[Alert, str]" + }, + "PaginatedResults_CTIEntityRelationshipResponse_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/CTIEntityRelationshipResponse" + }, + "type": "array", + "title": "Items" }, - "last_seen_at": { + "next": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[CTIEntityRelationshipResponse, str]" + }, + "PaginatedResults_Credential_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/Credential" + }, + "type": "array", + "title": "Items" }, - "confidence": { + "next": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Confidence" + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[Credential, str]" + }, + "PaginatedResults_EntityLiteAPIResponseTypes_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/EntityLiteAPIResponseTypes" + }, + "type": "array", + "title": "Items" }, - "description": { + "next": { "anyOf": [ { "type": "string" @@ -11324,33 +10828,26 @@ "type": "null" } ], - "title": "Description" - }, - "aliases": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Aliases" + "title": "Next" } }, "type": "object", "required": [ - "uuid", - "type", - "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description", - "aliases" + "items", + "next" ], - "title": "MalwareEntityLiteAPIResponse" + "title": "PaginatedResults[EntityLiteAPIResponseTypes, str]" }, - "MalwareInformation": { + "PaginatedResults_FeedItem_str_": { "properties": { - "malware_family": { + "items": { + "items": { + "$ref": "#/components/schemas/FeedItem" + }, + "type": "array", + "title": "Items" + }, + "next": { "anyOf": [ { "type": "string" @@ -11359,10 +10856,26 @@ "type": "null" } ], - "title": "Malware Family", - "description": "The malware family used for device infection." + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[FeedItem, str]" + }, + "PaginatedResults_GlobalFeedItem_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/GlobalFeedItem" + }, + "type": "array", + "title": "Items" }, - "build_id": { + "next": { "anyOf": [ { "type": "string" @@ -11371,10 +10884,26 @@ "type": "null" } ], - "title": "Build Id", - "description": "The build ID of the malware used for device infection." + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[GlobalFeedItem, str]" + }, + "PaginatedResults_MatchingPolicyPayload_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/MatchingPolicyPayload" + }, + "type": "array", + "title": "Items" }, - "file_location": { + "next": { "anyOf": [ { "type": "string" @@ -11383,261 +10912,21 @@ "type": "null" } ], - "title": "File Location", - "description": "The file location of the malware used for device infection." - }, - "infected_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Infected At", - "description": "The date and time the malware was used to infect the victim's device." - } - }, - "type": "object", - "title": "MalwareInformation" - }, - "MarkingDefinition": { - "properties": { - "id": { - "type": "string", - "title": "Id" - }, - "definition_type": { - "$ref": "#/components/schemas/MarkingDefinitionType" - }, - "name": { - "type": "string", - "title": "Name" - } - }, - "type": "object", - "required": [ - "id", - "definition_type", - "name" - ], - "title": "MarkingDefinition" - }, - "MarkingDefinitionType": { - "type": "string", - "enum": [ - "tlp" - ], - "title": "MarkingDefinitionType" - }, - "MatchingPolicyAssignmentPayload": { - "properties": { - "matching_policy": { - "$ref": "#/components/schemas/MatchingPolicyPayload" - }, - "assigned_at": { - "type": "string", - "format": "date-time", - "title": "Assigned At", - "description": "The date and time this policy was assigned to the identifier" - }, - "clean_past_events": { - "type": "boolean", - "title": "Clean Past Events", - "description": "Whether this policy has been applied to historical events" - } - }, - "type": "object", - "required": [ - "matching_policy", - "assigned_at", - "clean_past_events" - ], - "title": "MatchingPolicyAssignmentPayload" - }, - "MatchingPolicyPayload": { - "properties": { - "uuid": { - "type": "string", - "format": "uuid4", - "title": "Uuid", - "description": "The UUID of the matching policy" - }, - "name": { - "type": "string", - "title": "Name", - "description": "The name of the matching policy" - }, - "policy_type": { - "$ref": "#/components/schemas/MatchingPolicyType", - "description": "The type of the matching policy" - }, - "value": { - "$ref": "#/components/schemas/PolicyValue", - "description": "The value of the matching policy depending on its type" - }, - "created_at": { - "type": "string", - "format": "date-time", - "title": "Created At", - "description": "The date and time the matching policy was created" - }, - "last_updated_at": { - "type": "string", - "format": "date-time", - "title": "Last Updated At", - "description": "The date and time the matching policy was last updated" - } - }, - "type": "object", - "required": [ - "uuid", - "name", - "policy_type", - "value", - "created_at", - "last_updated_at" - ], - "title": "MatchingPolicyPayload" - }, - "MatchingPolicyType": { - "type": "string", - "enum": [ - "INCLUDED_KEYWORDS", - "EXCLUDED_KEYWORDS", - "LUCENE_QUERY", - "ASTP_COOKIES", - "ASTP_DOMAIN" - ], - "title": "MatchingPolicyType" - }, - "MitigatedCredentialEvent": { - "properties": { - "event_type": { - "type": "string", - "const": "mitigated_credential", - "title": "Event Type", - "default": "mitigated_credential" - }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - }, - "data": { - "$ref": "#/components/schemas/MitigatedCredentialEventData" - } - }, - "type": "object", - "required": [ - "metadata", - "data" - ], - "title": "Mitigated Credential" - }, - "MitigatedCredentialEventData": { - "properties": { - "identity_name": { - "type": "string", - "title": "Identity Name", - "description": "The email or username associated with the credential." - }, - "credential_hash": { - "type": "string", - "title": "Credential Hash", - "description": "A hash uniquely identifying the credential." - }, - "tenant_integration_id": { - "type": "string", - "title": "Tenant Integration Id", - "description": "The UUID of the tenant's IdP integration that validated the credential." - }, - "mitigation_action": { - "type": "string", - "title": "Mitigation Action", - "description": "The action the tenant's IdP integration took to mitigate the credential" - } - }, - "type": "object", - "required": [ - "identity_name", - "credential_hash", - "tenant_integration_id", - "mitigation_action" - ], - "title": "MitigatedCredentialEventData" - }, - "NameData": { - "properties": { - "type": { - "type": "string", - "const": "name", - "title": "Type", - "default": "name" - }, - "first_name": { - "type": "string", - "title": "First Name" - }, - "last_name": { - "type": "string", - "title": "Last Name" - }, - "is_strict": { - "type": "boolean", - "title": "Is Strict" - } - }, - "type": "object", - "required": [ - "first_name", - "last_name", - "is_strict" - ], - "title": "NameData" - }, - "NameQuery": { - "properties": { - "type": { - "type": "string", - "const": "name", - "title": "Type" - }, - "first_name": { - "type": "string", - "title": "First Name" - }, - "last_name": { - "type": "string", - "title": "Last Name" - }, - "is_strict": { - "type": "boolean", - "title": "Is Strict" + "title": "Next" } }, "type": "object", "required": [ - "type", - "first_name", - "last_name", - "is_strict" - ], - "title": "NameQuery" - }, - "OrderType": { - "type": "string", - "enum": [ - "asc", - "desc" + "items", + "next" ], - "title": "OrderType" + "title": "PaginatedResults[MatchingPolicyPayload, str]" }, - "PaginatedResults_Alert_str_": { + "PaginatedResults_PartialAlertChannel_str_": { "properties": { "items": { "items": { - "$ref": "#/components/schemas/Alert" + "$ref": "#/components/schemas/PartialAlertChannel" }, "type": "array", "title": "Items" @@ -11659,13 +10948,13 @@ "items", "next" ], - "title": "PaginatedResults[Alert, str]" + "title": "PaginatedResults[PartialAlertChannel, str]" }, - "PaginatedResults_Credential_str_": { + "PaginatedResults_PolicyAssignedIdentifierPayload_str_": { "properties": { "items": { "items": { - "$ref": "#/components/schemas/Credential" + "$ref": "#/components/schemas/PolicyAssignedIdentifierPayload" }, "type": "array", "title": "Items" @@ -11687,177 +10976,9 @@ "items", "next" ], - "title": "PaginatedResults[Credential, str]" + "title": "PaginatedResults[PolicyAssignedIdentifierPayload, str]" }, - "PaginatedResults_EntityLiteAPIResponseTypes_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/EntityLiteAPIResponseTypes" - }, - "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[EntityLiteAPIResponseTypes, str]" - }, - "PaginatedResults_FeedItem_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/FeedItem" - }, - "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[FeedItem, str]" - }, - "PaginatedResults_GlobalFeedItem_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/GlobalFeedItem" - }, - "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[GlobalFeedItem, str]" - }, - "PaginatedResults_MatchingPolicyPayload_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/MatchingPolicyPayload" - }, - "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[MatchingPolicyPayload, str]" - }, - "PaginatedResults_PartialAlertChannel_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/PartialAlertChannel" - }, - "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[PartialAlertChannel, str]" - }, - "PaginatedResults_PolicyAssignedIdentifierPayload_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/PolicyAssignedIdentifierPayload" - }, - "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[PolicyAssignedIdentifierPayload, str]" - }, - "PaginatedResults_PublicIdentifierResponse_str_": { + "PaginatedResults_PublicIdentifierResponse_str_": { "properties": { "items": { "items": { @@ -12810,705 +11931,118 @@ }, { "type": "null" - } - ], - "title": "Published At" - }, - "updated_at": { - "type": "string", - "format": "date-time", - "title": "Updated At" - }, - "reading_time": { - "type": "integer", - "title": "Reading Time" - }, - "tenant_id": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Tenant Id" - }, - "organization_id": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Organization Id" - } - }, - "type": "object", - "required": [ - "id", - "title", - "subtitle", - "summary", - "content", - "tags", - "highlights", - "related_activity_uids", - "prompt_preset_uid", - "created_at", - "published_at", - "updated_at", - "reading_time", - "tenant_id", - "organization_id" - ], - "title": "PydanticThreatFlowReport" - }, - "QueryStringQuery": { - "properties": { - "type": { - "type": "string", - "const": "query_string", - "title": "Type" - }, - "query_string": { - "type": "string", - "maxLength": 10000, - "title": "Query String" - } - }, - "type": "object", - "required": [ - "type", - "query_string" - ], - "title": "QueryStringQuery" - }, - "RansomLeakData": { - "properties": { - "type": { - "type": "string", - "const": "ransomleak", - "title": "Type", - "default": "ransomleak" - }, - "source": { - "type": "string", - "minLength": 1, - "title": "Source" - }, - "id": { - "type": "string", - "minLength": 1, - "title": "Id" - } - }, - "type": "object", - "required": [ - "source", - "id" - ], - "title": "RansomLeakData" - }, - "RansomLeakEvent": { - "properties": { - "event_type": { - "type": "string", - "const": "ransomleak", - "title": "Event Type", - "default": "ransomleak" - }, - "data": { - "$ref": "#/components/schemas/RansomLeakEventData" - }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - } - }, - "type": "object", - "required": [ - "data", - "metadata" - ], - "title": "Ransom Leak" - }, - "RansomLeakEventData": { - "properties": { - "url": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Url", - "description": "The URL of the ransom leak post." - }, - "response_url": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Response Url", - "description": "The URL of the response to the ransom leak post." - }, - "title": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Title", - "description": "The title of the ransom leak post." - }, - "content": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Content", - "description": "The content of the ransom leak post." - }, - "body": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Body", - "description": "The body of the ransom leak post." - }, - "victim_information": { - "anyOf": [ - { - "$ref": "#/components/schemas/pyro__findings__ransomleaks__datamodels__VictimInformation" - }, - { - "type": "null" - } - ], - "description": "The information relating to the victim of the ransom leak." - } - }, - "type": "object", - "title": "RansomLeakEventData" - }, - "Recommendation": { - "properties": { - "id": { - "type": "integer", - "title": "Id" - }, - "data": { - "oneOf": [ - { - "$ref": "#/components/schemas/DomainData" - }, - { - "$ref": "#/components/schemas/AzureTenantData" - }, - { - "$ref": "#/components/schemas/EmailData" - }, - { - "$ref": "#/components/schemas/UsernameData" - } - ], - "title": "Data", - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantData", - "domain": "#/components/schemas/DomainData", - "email": "#/components/schemas/EmailData", - "username": "#/components/schemas/UsernameData" - } - } - } - }, - "type": "object", - "required": [ - "id", - "data" - ], - "title": "Recommendation" - }, - "RelatedConversationRequest": { - "properties": { - "uid": { - "type": "string", - "title": "Uid" - }, - "direction": { - "$ref": "#/components/schemas/ConversationSearchAfterDirection", - "default": "next" - }, - "size": { - "type": "integer", - "title": "Size", - "default": 10 - }, - "search_after": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Search After" - }, - "should_translate": { - "type": "boolean", - "title": "Should Translate", - "default": false - } - }, - "type": "object", - "required": [ - "uid" - ], - "title": "RelatedConversationRequest" - }, - "RelatedConversationResponse": { - "properties": { - "conversation_messages": { - "items": { - "$ref": "#/components/schemas/ConversationMessage" - }, - "type": "array", - "title": "Conversation Messages" - }, - "conversation_name": { - "type": "string", - "title": "Conversation Name" - }, - "conversation_name_en": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Conversation Name En" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - }, - "previous": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Previous" - } - }, - "type": "object", - "required": [ - "conversation_messages", - "conversation_name" - ], - "title": "RelatedConversationResponse" - }, - "ReportDownloadFormat": { - "type": "string", - "enum": [ - "docx", - "pdf", - "csv", - "zip" - ], - "title": "ReportDownloadFormat" - }, - "ReportRequestInfoResponse": { - "properties": { - "status": { - "$ref": "#/components/schemas/RequestStatus" - }, - "report": { - "anyOf": [ - { - "$ref": "#/components/schemas/ApiReport" - }, - { - "type": "null" - } - ] - } - }, - "type": "object", - "required": [ - "status" - ], - "title": "ReportRequestInfoResponse" - }, - "ReportRequestPayload": { - "properties": { - "report_title": { - "type": "string", - "title": "Report Title" - }, - "question": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Question" - }, - "time_range_type": { - "$ref": "#/components/schemas/TimeRangeType", - "default": "all" - }, - "time_range_from": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Time Range From" - }, - "time_range_to": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Time Range To" - }, - "included_keywords": { - "anyOf": [ - { - "items": { - "type": "string" - }, - "type": "array" - }, - { - "type": "null" - } - ], - "title": "Included Keywords" - }, - "excluded_keywords": { - "anyOf": [ - { - "items": { - "type": "string" - }, - "type": "array" - }, - { - "type": "null" - } - ], - "title": "Excluded Keywords" - } - }, - "type": "object", - "required": [ - "report_title" - ], - "title": "ReportRequestPayload" - }, - "ReportRequestResponse": { - "properties": { - "request_id": { - "type": "string", - "format": "uuid", - "title": "Request Id" - } - }, - "type": "object", - "required": [ - "request_id" - ], - "title": "ReportRequestResponse" - }, - "ReportStatus": { - "type": "string", - "enum": [ - "draft", - "processing", - "completed", - "scheduled", - "paused" - ], - "title": "ReportStatus" - }, - "ReportType-Output": { - "type": "string", - "enum": [ - "v1", - "event_based", - "feed_based" - ], - "title": "ReportType" - }, - "RequestStatus": { - "type": "string", - "enum": [ - "processing", - "completed", - "error" - ], - "title": "RequestStatus" - }, - "RiskScore": { - "type": "integer", - "enum": [ - 1, - 2, - 3, - 4, - 5 - ], - "title": "RiskScore" - }, - "RoleData": { - "properties": { - "type": { - "type": "string", - "const": "role", - "title": "Type", - "default": "role" - }, - "role": { - "type": "string", - "minLength": 1, - "title": "Role" - } - }, - "type": "object", - "required": [ - "role" - ], - "title": "RoleData" - }, - "SandboxSubmissionEventType": { - "type": "string", - "enum": [ - "asset_sync", - "report_sync" - ], - "title": "SandboxSubmissionEventType" - }, - "SandboxSyncRequest": { - "properties": { - "job": { - "$ref": "#/components/schemas/SandboxSubmissionEventType" - } - }, - "type": "object", - "required": [ - "job" - ], - "title": "SandboxSyncRequest" - }, - "SandboxUploadPutUrlResponse": { - "properties": { - "upload_url": { - "type": "string", - "title": "Upload Url" - } - }, - "type": "object", - "required": [ - "upload_url" - ], - "title": "SandboxUploadPutUrlResponse" - }, - "SandboxUploadUrlRequest": { - "properties": { - "filename": { - "type": "string", - "title": "Filename" - } - }, - "type": "object", - "required": [ - "filename" - ], - "title": "SandboxUploadUrlRequest" - }, - "SearchQueryData": { - "properties": { - "type": { - "type": "string", - "const": "search_query", - "title": "Type", - "default": "search_query" - }, - "search_query": { - "type": "string", - "minLength": 1, - "title": "Search Query" - } - }, - "type": "object", - "required": [ - "search_query" - ], - "title": "SearchQueryData" - }, - "SearchType": { - "type": "string", - "enum": [ - "attachment", - "listing", - "ransomleak", - "forum_post", - "forum_topic", - "forum_profile", - "blog_post", - "seller", - "paste", - "leak", - "chat_message", - "domain", - "bot", - "stealer_log", - "infected_devices", - "driller", - "driller_forum_topic", - "driller_forum_post", - "driller_profile", - "cc", - "ccbin", - "financial_data", - "leaked_data", - "leaked_file", - "document", - "account", - "actor", - "forum_content", - "blog_content", - "profile", - "leaked_credential", - "valid_credential", - "invalid_credential", - "mitigated_credential", - "illicit_networks", - "open_web", - "domains", - "intelligence_object", - "leaks", - "social_media_account", - "social_media", - "source_code", - "source_code_secrets_np", - "source_code_secrets", - "source_code_files", - "docker", - "stack_exchange", - "google", - "service", - "driller_host", - "buckets", - "bucket", - "bucket_object", - "whois", - "ad", - "ads", - "cookie", - "pii", - "experimental" + } + ], + "title": "Published At" + }, + "updated_at": { + "type": "string", + "format": "date-time", + "title": "Updated At" + }, + "reading_time": { + "type": "integer", + "title": "Reading Time" + }, + "tenant_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Tenant Id" + }, + "organization_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Organization Id" + } + }, + "type": "object", + "required": [ + "id", + "title", + "subtitle", + "summary", + "content", + "tags", + "highlights", + "related_activity_uids", + "prompt_preset_uid", + "created_at", + "published_at", + "updated_at", + "reading_time", + "tenant_id", + "organization_id" ], - "title": "SearchType" + "title": "PydanticThreatFlowReport" }, - "SecretData": { + "QueryStringQuery": { "properties": { "type": { "type": "string", - "const": "secret", - "title": "Type", - "default": "secret" + "const": "query_string", + "title": "Type" }, - "secret": { + "query_string": { "type": "string", - "minLength": 1, - "title": "Secret" + "maxLength": 10000, + "title": "Query String" } }, "type": "object", "required": [ - "secret" + "type", + "query_string" ], - "title": "SecretData" + "title": "QueryStringQuery" }, - "SecretQuery": { + "RansomLeakData": { "properties": { "type": { "type": "string", - "const": "secret", - "title": "Type" + "const": "ransomleak", + "title": "Type", + "default": "ransomleak" }, - "secret": { + "source": { "type": "string", - "title": "Secret" + "minLength": 1, + "title": "Source" + }, + "id": { + "type": "string", + "minLength": 1, + "title": "Id" } }, "type": "object", "required": [ - "type", - "secret" + "source", + "id" ], - "title": "SecretQuery" + "title": "RansomLeakData" }, - "ServiceEvent": { + "RansomLeakEvent": { "properties": { "event_type": { "type": "string", - "const": "service", + "const": "ransomleak", "title": "Event Type", - "default": "service" + "default": "ransomleak" }, "data": { - "$ref": "#/components/schemas/ServiceEventData" + "$ref": "#/components/schemas/RansomLeakEventData" }, "metadata": { "$ref": "#/components/schemas/EventMetadata" @@ -13519,9 +12053,9 @@ "data", "metadata" ], - "title": "Service" + "title": "Ransom Leak" }, - "ServiceEventData": { + "RansomLeakEventData": { "properties": { "url": { "anyOf": [ @@ -13533,9 +12067,9 @@ } ], "title": "Url", - "description": "The URL to the service. This may be an IP address and port combination." + "description": "The URL of the ransom leak post." }, - "asn": { + "response_url": { "anyOf": [ { "type": "string" @@ -13544,10 +12078,10 @@ "type": "null" } ], - "title": "Asn", - "description": "The Autonomous System Number." + "title": "Response Url", + "description": "The URL of the response to the ransom leak post." }, - "content": { + "title": { "anyOf": [ { "type": "string" @@ -13556,10 +12090,10 @@ "type": "null" } ], - "title": "Content", - "description": "The raw content returned by the service." + "title": "Title", + "description": "The title of the ransom leak post." }, - "service": { + "content": { "anyOf": [ { "type": "string" @@ -13568,10 +12102,10 @@ "type": "null" } ], - "title": "Service", - "description": "The protocol of the service e.g. https" + "title": "Content", + "description": "The content of the ransom leak post." }, - "product": { + "body": { "anyOf": [ { "type": "string" @@ -13580,117 +12114,116 @@ "type": "null" } ], - "title": "Product", - "description": "The software product that powers the service e.g. Apache httpd" + "title": "Body", + "description": "The body of the ransom leak post." }, - "port": { + "victim_information": { "anyOf": [ { - "type": "integer" + "$ref": "#/components/schemas/pyro__findings__ransomleaks__datamodels__VictimInformation" }, { "type": "null" } ], - "title": "Port", - "description": "The port the service listens on." + "description": "The information relating to the victim of the ransom leak." + } + }, + "type": "object", + "title": "RansomLeakEventData" + }, + "Recommendation": { + "properties": { + "id": { + "type": "integer", + "title": "Id" }, - "ip_address": { - "anyOf": [ + "data": { + "oneOf": [ { - "type": "string" + "$ref": "#/components/schemas/DomainData" }, { - "type": "null" - } - ], - "title": "Ip Address", - "description": "The IP address of the service." - }, - "organization": { - "anyOf": [ - { - "type": "string" + "$ref": "#/components/schemas/AzureTenantData" }, { - "type": "null" - } - ], - "title": "Organization", - "description": "The organization that manages the IP address, often a hosting provider." - }, - "hostname": { - "anyOf": [ - { - "type": "string" + "$ref": "#/components/schemas/EmailData" }, { - "type": "null" + "$ref": "#/components/schemas/UsernameData" } ], - "title": "Hostname", - "description": "The hostname the service is served under." - }, - "country_code": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "azure_tenant": "#/components/schemas/AzureTenantData", + "domain": "#/components/schemas/DomainData", + "email": "#/components/schemas/EmailData", + "username": "#/components/schemas/UsernameData" } - ], - "title": "Country Code", - "description": "The country code of the IP address." - }, - "vulnerabilities": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Vulnerabilities", - "description": "CVE identifiers of vulnerabilities the service is potentially affected by." + } } }, "type": "object", - "title": "ServiceEventData" - }, - "Severity": { - "type": "string", - "enum": [ - "info", - "low", - "medium", - "high", - "critical" + "required": [ + "id", + "data" ], - "title": "Severity" + "title": "Recommendation" }, - "SocialMediaEvent": { + "RelatedConversationRequest": { "properties": { - "event_type": { + "uid": { "type": "string", - "const": "social_media_account", - "title": "Event Type", - "default": "social_media_account" + "title": "Uid" }, - "data": { - "$ref": "#/components/schemas/SocialMediaEventData" + "direction": { + "$ref": "#/components/schemas/ConversationSearchAfterDirection", + "default": "next" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "size": { + "type": "integer", + "title": "Size", + "default": 10 + }, + "search_after": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Search After" + }, + "should_translate": { + "type": "boolean", + "title": "Should Translate", + "default": false } }, "type": "object", "required": [ - "data", - "metadata" + "uid" ], - "title": "Social Media Account" + "title": "RelatedConversationRequest" }, - "SocialMediaEventData": { + "RelatedConversationResponse": { "properties": { - "url": { + "conversation_messages": { + "items": { + "$ref": "#/components/schemas/ConversationMessage" + }, + "type": "array", + "title": "Conversation Messages" + }, + "conversation_name": { + "type": "string", + "title": "Conversation Name" + }, + "conversation_name_en": { "anyOf": [ { "type": "string" @@ -13699,10 +12232,9 @@ "type": "null" } ], - "title": "Url", - "description": "The URL to the profile page of the social media account." + "title": "Conversation Name En" }, - "site": { + "next": { "anyOf": [ { "type": "string" @@ -13711,10 +12243,9 @@ "type": "null" } ], - "title": "Site", - "description": "The name of the platform where the account was found." + "title": "Next" }, - "username": { + "previous": { "anyOf": [ { "type": "string" @@ -13723,31 +12254,55 @@ "type": "null" } ], - "title": "Username", - "description": "The username of the account that was found." + "title": "Previous" } }, "type": "object", - "title": "SocialMediaEventData" + "required": [ + "conversation_messages", + "conversation_name" + ], + "title": "RelatedConversationResponse" }, - "SourceV2": { + "ReportDownloadFormat": { + "type": "string", + "enum": [ + "docx", + "pdf", + "csv", + "zip" + ], + "title": "ReportDownloadFormat" + }, + "ReportRequestInfoResponse": { "properties": { - "id": { - "type": "string", - "title": "Id" + "status": { + "$ref": "#/components/schemas/RequestStatus" }, - "name": { + "report": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/ApiReport" }, { "type": "null" } - ], - "title": "Name" + ] + } + }, + "type": "object", + "required": [ + "status" + ], + "title": "ReportRequestInfoResponse" + }, + "ReportRequestPayload": { + "properties": { + "report_title": { + "type": "string", + "title": "Report Title" }, - "description_en": { + "question": { "anyOf": [ { "type": "string" @@ -13756,46 +12311,37 @@ "type": "null" } ], - "title": "Description En" + "title": "Question" }, - "description_fr": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Description Fr" + "time_range_type": { + "$ref": "#/components/schemas/TimeRangeType", + "default": "all" }, - "breached_at": { + "time_range_from": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Breached At" + "title": "Time Range From" }, - "leaked_at": { + "time_range_to": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Leaked At" - }, - "is_alert_enabled": { - "type": "boolean", - "title": "Is Alert Enabled" + "title": "Time Range To" }, - "pii_tags": { + "included_keywords": { "anyOf": [ { "items": { @@ -13807,178 +12353,298 @@ "type": "null" } ], - "title": "Pii Tags" + "title": "Included Keywords" }, - "url": { + "excluded_keywords": { "anyOf": [ { - "type": "string" + "items": { + "type": "string" + }, + "type": "array" }, { "type": "null" } ], - "title": "Url" + "title": "Excluded Keywords" } }, "type": "object", "required": [ - "id", - "name", - "description_en", - "description_fr", - "breached_at", - "leaked_at", - "is_alert_enabled", - "pii_tags", - "url" + "report_title" ], - "title": "SourceV2" + "title": "ReportRequestPayload" }, - "StealerLogCookie": { + "ReportRequestResponse": { "properties": { - "host_key": { + "request_id": { "type": "string", - "title": "Host Key" - }, - "path": { + "format": "uuid", + "title": "Request Id" + } + }, + "type": "object", + "required": [ + "request_id" + ], + "title": "ReportRequestResponse" + }, + "ReportStatus": { + "type": "string", + "enum": [ + "draft", + "processing", + "completed", + "scheduled", + "paused" + ], + "title": "ReportStatus" + }, + "ReportType-Output": { + "type": "string", + "enum": [ + "v1", + "event_based", + "feed_based" + ], + "title": "ReportType" + }, + "RequestStatus": { + "type": "string", + "enum": [ + "processing", + "completed", + "error" + ], + "title": "RequestStatus" + }, + "RiskScore": { + "type": "integer", + "enum": [ + 1, + 2, + 3, + 4, + 5 + ], + "title": "RiskScore" + }, + "RoleData": { + "properties": { + "type": { "type": "string", - "title": "Path" - }, - "expires_utc": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Expires Utc" + "const": "role", + "title": "Type", + "default": "role" }, - "name": { + "role": { "type": "string", - "title": "Name" - }, - "value": { + "minLength": 1, + "title": "Role" + } + }, + "type": "object", + "required": [ + "role" + ], + "title": "RoleData" + }, + "SandboxSubmissionEventType": { + "type": "string", + "enum": [ + "asset_sync", + "report_sync" + ], + "title": "SandboxSubmissionEventType" + }, + "SandboxSyncRequest": { + "properties": { + "job": { + "$ref": "#/components/schemas/SandboxSubmissionEventType" + } + }, + "type": "object", + "required": [ + "job" + ], + "title": "SandboxSyncRequest" + }, + "SandboxUploadPutUrlResponse": { + "properties": { + "upload_url": { "type": "string", - "title": "Value" + "title": "Upload Url" } }, "type": "object", "required": [ - "host_key", - "path", - "expires_utc", - "name", - "value" + "upload_url" ], - "title": "StealerLogCookie" + "title": "SandboxUploadPutUrlResponse" }, - "StealerLogCredential": { + "SandboxUploadUrlRequest": { "properties": { - "url": { - "type": "string", - "title": "Url" - }, - "username": { + "filename": { "type": "string", - "title": "Username" - }, - "password": { + "title": "Filename" + } + }, + "type": "object", + "required": [ + "filename" + ], + "title": "SandboxUploadUrlRequest" + }, + "SearchQueryData": { + "properties": { + "type": { "type": "string", - "title": "Password" + "const": "search_query", + "title": "Type", + "default": "search_query" }, - "application": { + "search_query": { "type": "string", - "title": "Application" + "minLength": 1, + "title": "Search Query" } }, "type": "object", "required": [ - "url", - "username", - "password", - "application" + "search_query" ], - "title": "StealerLogCredential" + "title": "SearchQueryData" }, - "StealerLogEventData": { + "SearchType": { + "type": "string", + "enum": [ + "attachment", + "listing", + "ransomleak", + "forum_post", + "forum_topic", + "forum_profile", + "blog_post", + "seller", + "paste", + "leak", + "chat_message", + "domain", + "bot", + "stealer_log", + "infected_devices", + "driller", + "driller_forum_topic", + "driller_forum_post", + "driller_profile", + "cc", + "ccbin", + "financial_data", + "leaked_data", + "leaked_file", + "document", + "account", + "actor", + "forum_content", + "blog_content", + "profile", + "leaked_credential", + "valid_credential", + "invalid_credential", + "mitigated_credential", + "illicit_networks", + "open_web", + "domains", + "intelligence_object", + "leaks", + "social_media_account", + "social_media", + "source_code", + "source_code_secrets_np", + "source_code_secrets", + "source_code_files", + "docker", + "stack_exchange", + "google", + "service", + "driller_host", + "buckets", + "bucket", + "bucket_object", + "whois", + "ad", + "ads", + "cookie", + "pii", + "experimental" + ], + "title": "SearchType" + }, + "SecretData": { "properties": { - "victim_information": { - "anyOf": [ - { - "$ref": "#/components/schemas/pyro__findings__stealerlogs__datamodels__VictimInformation" - }, - { - "type": "null" - } - ], - "description": "Collection of data that relates to the victim and their infected device." + "type": { + "type": "string", + "const": "secret", + "title": "Type", + "default": "secret" }, - "malware_information": { - "anyOf": [ - { - "$ref": "#/components/schemas/MalwareInformation" - }, - { - "type": "null" - } - ], - "description": "Collection of data that relates to the malware that was used to infect the victim's device." + "secret": { + "type": "string", + "minLength": 1, + "title": "Secret" } }, "type": "object", - "title": "StealerLogEventData" + "required": [ + "secret" + ], + "title": "SecretData" }, - "SubdomainStatus": { + "SecretQuery": { "properties": { - "status": { - "$ref": "#/components/schemas/DomainStatus" + "type": { + "type": "string", + "const": "secret", + "title": "Type" }, - "updated_at": { + "secret": { "type": "string", - "format": "date-time", - "title": "Updated At" + "title": "Secret" } }, "type": "object", "required": [ - "status", - "updated_at" + "type", + "secret" ], - "title": "SubdomainStatus" + "title": "SecretQuery" }, - "SubdomainTag": { + "ServiceEvent": { "properties": { - "label": { + "event_type": { "type": "string", - "title": "Label" + "const": "service", + "title": "Event Type", + "default": "service" }, - "keyword": { - "type": "string", - "title": "Keyword" + "data": { + "$ref": "#/components/schemas/ServiceEventData" }, - "span": { - "items": { - "type": "integer" - }, - "type": "array", - "title": "Span" + "metadata": { + "$ref": "#/components/schemas/EventMetadata" } }, "type": "object", "required": [ - "label", - "keyword", - "span" + "data", + "metadata" ], - "title": "SubdomainTag" + "title": "Service" }, - "Tag": { + "ServiceEventData": { "properties": { - "name": { + "url": { "anyOf": [ { "type": "string" @@ -13987,9 +12653,10 @@ "type": "null" } ], - "title": "Name" + "title": "Url", + "description": "The URL to the service. This may be an IP address and port combination." }, - "repository_name": { + "asn": { "anyOf": [ { "type": "string" @@ -13998,46 +12665,10 @@ "type": "null" } ], - "title": "Repository Name" - } - }, - "type": "object", - "title": "Tag" - }, - "TakedownConsentBody": { - "properties": { - "token": { - "type": "string", - "minLength": 1, - "title": "Token" - } - }, - "type": "object", - "required": [ - "token" - ], - "title": "TakedownConsentBody" - }, - "TakedownConsentResponse": { - "properties": { - "identifier_name": { - "type": "string", - "title": "Identifier Name" - } - }, - "type": "object", - "required": [ - "identifier_name" - ], - "title": "TakedownConsentResponse" - }, - "TenantMetadataResponse": { - "properties": { - "uid": { - "type": "string", - "title": "Uid" + "title": "Asn", + "description": "The Autonomous System Number." }, - "notes": { + "content": { "anyOf": [ { "type": "string" @@ -14045,17 +12676,11 @@ { "type": "null" } - ], - "title": "Notes" - }, - "tags": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Tags" + ], + "title": "Content", + "description": "The raw content returned by the service." }, - "severity": { + "service": { "anyOf": [ { "type": "string" @@ -14064,125 +12689,70 @@ "type": "null" } ], - "title": "Severity" - } - }, - "type": "object", - "required": [ - "uid", - "notes", - "tags", - "severity" - ], - "title": "TenantMetadataResponse" - }, - "ThreadTopic": { - "properties": { - "topic_id": { - "type": "string", - "title": "Topic Id" - }, - "label": { - "type": "string", - "title": "Label" - }, - "description": { - "type": "string", - "title": "Description" - } - }, - "type": "object", - "required": [ - "topic_id", - "label", - "description" - ], - "title": "ThreadTopic" - }, - "ThreatActorEntityAPIResponse": { - "properties": { - "uuid": { - "type": "string", - "title": "Uuid" - }, - "type": { - "$ref": "#/components/schemas/EntityType" - }, - "name": { - "type": "string", - "title": "Name" - }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" + "title": "Service", + "description": "The protocol of the service e.g. https" }, - "created_at": { + "product": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Product", + "description": "The software product that powers the service e.g. Apache httpd" }, - "updated_at": { + "port": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "integer" }, { "type": "null" } ], - "title": "Updated At" + "title": "Port", + "description": "The port the service listens on." }, - "first_seen_at": { + "ip_address": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "First Seen At" + "title": "Ip Address", + "description": "The IP address of the service." }, - "last_seen_at": { + "organization": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Organization", + "description": "The organization that manages the IP address, often a hosting provider." }, - "confidence": { + "hostname": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Confidence" + "title": "Hostname", + "description": "The hostname the service is served under." }, - "description": { + "country_code": { "anyOf": [ { "type": "string" @@ -14191,37 +12761,57 @@ "type": "null" } ], - "title": "Description" - }, - "aliases": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Aliases" - }, - "threat_actor_types": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Threat Actor Types" + "title": "Country Code", + "description": "The country code of the IP address." }, - "roles": { + "vulnerabilities": { "items": { "type": "string" }, "type": "array", - "title": "Roles" + "title": "Vulnerabilities", + "description": "CVE identifiers of vulnerabilities the service is potentially affected by." + } + }, + "type": "object", + "title": "ServiceEventData" + }, + "Severity": { + "type": "string", + "enum": [ + "info", + "low", + "medium", + "high", + "critical" + ], + "title": "Severity" + }, + "SocialMediaEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "social_media_account", + "title": "Event Type", + "default": "social_media_account" }, - "goals": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Goals" + "data": { + "$ref": "#/components/schemas/SocialMediaEventData" }, - "sophistication": { + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Social Media Account" + }, + "SocialMediaEventData": { + "properties": { + "url": { "anyOf": [ { "type": "string" @@ -14230,9 +12820,10 @@ "type": "null" } ], - "title": "Sophistication" + "title": "Url", + "description": "The URL to the profile page of the social media account." }, - "resource_level": { + "site": { "anyOf": [ { "type": "string" @@ -14241,9 +12832,10 @@ "type": "null" } ], - "title": "Resource Level" + "title": "Site", + "description": "The name of the platform where the account was found." }, - "primary_motivation": { + "username": { "anyOf": [ { "type": "string" @@ -14252,137 +12844,93 @@ "type": "null" } ], - "title": "Primary Motivation" - }, - "secondary_motivation": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Secondary Motivation" - }, - "personal_motivations": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Personal Motivations" - }, - "marking_definitions": { - "items": { - "$ref": "#/components/schemas/MarkingDefinition" - }, - "type": "array", - "title": "Marking Definitions" + "title": "Username", + "description": "The username of the account that was found." } }, "type": "object", - "required": [ - "uuid", - "type", - "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description", - "aliases", - "threat_actor_types", - "roles", - "goals", - "sophistication", - "resource_level", - "primary_motivation", - "secondary_motivation", - "personal_motivations", - "marking_definitions" - ], - "title": "ThreatActorEntityAPIResponse" + "title": "SocialMediaEventData" }, - "ThreatActorEntityLiteAPIResponse": { + "SourceV2": { "properties": { - "uuid": { + "id": { "type": "string", - "title": "Uuid" - }, - "type": { - "$ref": "#/components/schemas/EntityType" + "title": "Id" }, "name": { - "type": "string", - "title": "Name" - }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Name" }, - "created_at": { + "description_en": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Description En" }, - "updated_at": { + "description_fr": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Updated At" + "title": "Description Fr" }, - "first_seen_at": { + "breached_at": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "First Seen At" + "title": "Breached At" }, - "last_seen_at": { + "leaked_at": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Leaked At" }, - "confidence": { + "is_alert_enabled": { + "type": "boolean", + "title": "Is Alert Enabled" + }, + "pii_tags": { "anyOf": [ { - "type": "integer" + "items": { + "type": "string" + }, + "type": "array" }, { "type": "null" } ], - "title": "Confidence" + "title": "Pii Tags" }, - "description": { + "url": { "anyOf": [ { "type": "string" @@ -14391,112 +12939,314 @@ "type": "null" } ], - "title": "Description" - }, - "aliases": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Aliases" + "title": "Url" } }, "type": "object", "required": [ - "uuid", - "type", + "id", "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description", - "aliases" + "description_en", + "description_fr", + "breached_at", + "leaked_at", + "is_alert_enabled", + "pii_tags", + "url" ], - "title": "ThreatActorEntityLiteAPIResponse" + "title": "SourceV2" }, - "ThreatActorGroupEntityAPIResponse": { + "StealerLogCookie": { "properties": { - "uuid": { + "host_key": { "type": "string", - "title": "Uuid" + "title": "Host Key" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "path": { + "type": "string", + "title": "Path" + }, + "expires_utc": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Expires Utc" }, "name": { "type": "string", "title": "Name" }, - "created_by": { + "value": { "type": "string", - "title": "Created By" + "title": "Value" + } + }, + "type": "object", + "required": [ + "host_key", + "path", + "expires_utc", + "name", + "value" + ], + "title": "StealerLogCookie" + }, + "StealerLogCredential": { + "properties": { + "url": { + "type": "string", + "title": "Url" }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" + "username": { + "type": "string", + "title": "Username" }, - "created_at": { + "password": { + "type": "string", + "title": "Password" + }, + "application": { + "type": "string", + "title": "Application" + } + }, + "type": "object", + "required": [ + "url", + "username", + "password", + "application" + ], + "title": "StealerLogCredential" + }, + "StealerLogEventData": { + "properties": { + "victim_information": { "anyOf": [ { - "type": "string", - "format": "date-time" + "$ref": "#/components/schemas/pyro__findings__stealerlogs__datamodels__VictimInformation" }, { "type": "null" } ], - "title": "Created At" + "description": "Collection of data that relates to the victim and their infected device." }, - "updated_at": { + "malware_information": { "anyOf": [ { - "type": "string", - "format": "date-time" + "$ref": "#/components/schemas/MalwareInformation" }, { "type": "null" } ], + "description": "Collection of data that relates to the malware that was used to infect the victim's device." + } + }, + "type": "object", + "title": "StealerLogEventData" + }, + "SubdomainStatus": { + "properties": { + "status": { + "$ref": "#/components/schemas/DomainStatus" + }, + "updated_at": { + "type": "string", + "format": "date-time", "title": "Updated At" + } + }, + "type": "object", + "required": [ + "status", + "updated_at" + ], + "title": "SubdomainStatus" + }, + "SubdomainTag": { + "properties": { + "label": { + "type": "string", + "title": "Label" }, - "first_seen_at": { + "keyword": { + "type": "string", + "title": "Keyword" + }, + "span": { + "items": { + "type": "integer" + }, + "type": "array", + "title": "Span" + } + }, + "type": "object", + "required": [ + "label", + "keyword", + "span" + ], + "title": "SubdomainTag" + }, + "Tag": { + "properties": { + "name": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "First Seen At" + "title": "Name" + }, + "repository_name": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Repository Name" + } + }, + "type": "object", + "title": "Tag" + }, + "TakedownConsentBody": { + "properties": { + "token": { + "type": "string", + "minLength": 1, + "title": "Token" + } + }, + "type": "object", + "required": [ + "token" + ], + "title": "TakedownConsentBody" + }, + "TakedownConsentResponse": { + "properties": { + "identifier_name": { + "type": "string", + "title": "Identifier Name" + } + }, + "type": "object", + "required": [ + "identifier_name" + ], + "title": "TakedownConsentResponse" + }, + "TenantMetadataResponse": { + "properties": { + "uid": { + "type": "string", + "title": "Uid" }, - "last_seen_at": { + "notes": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Notes" }, - "confidence": { + "tags": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Tags" + }, + "severity": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Confidence" + "title": "Severity" + } + }, + "type": "object", + "required": [ + "uid", + "notes", + "tags", + "severity" + ], + "title": "TenantMetadataResponse" + }, + "ThreadTopic": { + "properties": { + "topic_id": { + "type": "string", + "title": "Topic Id" + }, + "label": { + "type": "string", + "title": "Label" + }, + "description": { + "type": "string", + "title": "Description" + } + }, + "type": "object", + "required": [ + "topic_id", + "label", + "description" + ], + "title": "ThreadTopic" + }, + "ThreatActorEntityAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "threat_actor", + "title": "Entity Type", + "default": "threat_actor" + }, + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" + }, + "data": { + "$ref": "#/components/schemas/ThreatActorEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ThreatActorEntityAPIResponse" + }, + "ThreatActorEntityData": { + "properties": { + "name": { + "type": "string", + "title": "Name" }, "description": { "anyOf": [ @@ -14516,18 +13266,47 @@ "type": "array", "title": "Aliases" }, - "goals": { + "threat_actor_types": { "items": { "type": "string" }, "type": "array", - "title": "Goals" + "title": "Threat Actor Types" }, - "resource_level": { + "roles": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Roles" + }, + "goals": { "items": { "type": "string" }, "type": "array", + "title": "Goals" + }, + "sophistication": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Sophistication" + }, + "resource_level": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], "title": "Resource Level" }, "primary_motivation": { @@ -14541,12 +13320,19 @@ ], "title": "Primary Motivation" }, - "secondary_motivations": { + "secondary_motivation": { "items": { "type": "string" }, "type": "array", - "title": "Secondary Motivations" + "title": "Secondary Motivation" + }, + "personal_motivations": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Personal Motivations" }, "marking_definitions": { "items": { @@ -14558,105 +13344,202 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "aliases", + "threat_actor_types", + "roles", "goals", + "sophistication", "resource_level", "primary_motivation", - "secondary_motivations", + "secondary_motivation", + "personal_motivations", "marking_definitions" ], - "title": "ThreatActorGroupEntityAPIResponse" + "title": "ThreatActorEntityData" }, - "ThreatActorGroupEntityLiteAPIResponse": { + "ThreatActorEntityLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "threat_actor", + "title": "Entity Type", + "default": "threat_actor" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ThreatActorEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ThreatActorEntityLiteAPIResponse" + }, + "ThreatActorEntityLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Description" }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + } + }, + "type": "object", + "required": [ + "name", + "description", + "aliases" + ], + "title": "ThreatActorEntityLiteData" + }, + "ThreatActorGroupEntityAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "threat_actor_group", + "title": "Entity Type", + "default": "threat_actor_group" }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, - "last_seen_at": { + "data": { + "$ref": "#/components/schemas/ThreatActorGroupEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ThreatActorGroupEntityAPIResponse" + }, + "ThreatActorGroupEntityData": { + "properties": { + "name": { + "type": "string", + "title": "Name" + }, + "description": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Seen At" + "title": "Description" + }, + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + }, + "goals": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Goals" + }, + "resource_level": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Resource Level" }, - "confidence": { + "primary_motivation": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Confidence" + "title": "Primary Motivation" + }, + "secondary_motivations": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Secondary Motivations" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "name", + "description", + "aliases", + "goals", + "resource_level", + "primary_motivation", + "secondary_motivations", + "marking_definitions" + ], + "title": "ThreatActorGroupEntityData" + }, + "ThreatActorGroupEntityLiteAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "threat_actor_group", + "title": "Entity Type", + "default": "threat_actor_group" + }, + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" + }, + "data": { + "$ref": "#/components/schemas/ThreatActorGroupEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ThreatActorGroupEntityLiteAPIResponse" + }, + "ThreatActorGroupEntityLiteData": { + "properties": { + "name": { + "type": "string", + "title": "Name" }, "description": { "anyOf": [ @@ -14679,17 +13562,11 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "aliases" ], - "title": "ThreatActorGroupEntityLiteAPIResponse" + "title": "ThreatActorGroupEntityLiteData" }, "ThreatFlowReportDownloadFormat": { "type": "string", @@ -14724,87 +13601,32 @@ }, "ToolEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "tool", + "title": "Entity Type", + "default": "tool" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/ToolEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ToolEntityAPIResponse" + }, + "ToolEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -14833,121 +13655,60 @@ "tool_version": { "anyOf": [ { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Tool Version" - }, - "marking_definitions": { - "items": { - "$ref": "#/components/schemas/MarkingDefinition" - }, - "type": "array", - "title": "Marking Definitions" - } - }, - "type": "object", - "required": [ - "uuid", - "type", - "name", - "created_by", - "sources", - "created_at", - "updated_at", - "description", - "tool_types", - "kill_chain_phases", - "tool_version", - "marking_definitions" - ], - "title": "ToolEntityAPIResponse" - }, - "ToolEntityLiteAPIResponse": { - "properties": { - "uuid": { - "type": "string", - "title": "Uuid" - }, - "type": { - "$ref": "#/components/schemas/EntityType" - }, - "name": { - "type": "string", - "title": "Name" - }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Confidence" + "title": "Tool Version" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "name", + "description", + "tool_types", + "kill_chain_phases", + "tool_version", + "marking_definitions" + ], + "title": "ToolEntityData" + }, + "ToolEntityLiteAPIResponse": { + "properties": { + "entity_type": { + "type": "string", + "const": "tool", + "title": "Entity Type", + "default": "tool" + }, + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" + }, + "data": { + "$ref": "#/components/schemas/ToolEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "ToolEntityLiteAPIResponse" + }, + "ToolEntityLiteData": { + "properties": { + "name": { + "type": "string", + "title": "Name" }, "description": { "anyOf": [ @@ -14963,16 +13724,10 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description" ], - "title": "ToolEntityLiteAPIResponse" + "title": "ToolEntityLiteData" }, "Types": { "properties": { @@ -15204,87 +13959,32 @@ }, "VulnerabilityEntityAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "vulnerability", + "title": "Entity Type", + "default": "vulnerability" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/VulnerabilityEntityData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "VulnerabilityEntityAPIResponse" + }, + "VulnerabilityEntityData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -15306,101 +14006,40 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description", "marking_definitions" ], - "title": "VulnerabilityEntityAPIResponse" + "title": "VulnerabilityEntityData" }, "VulnerabilityEntityLiteAPIResponse": { "properties": { - "uuid": { + "entity_type": { "type": "string", - "title": "Uuid" + "const": "vulnerability", + "title": "Entity Type", + "default": "vulnerability" }, - "type": { - "$ref": "#/components/schemas/EntityType" + "metadata": { + "$ref": "#/components/schemas/EntityMetadataAPIResponse" }, + "data": { + "$ref": "#/components/schemas/VulnerabilityEntityLiteData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "VulnerabilityEntityLiteAPIResponse" + }, + "VulnerabilityEntityLiteData": { + "properties": { "name": { "type": "string", "title": "Name" }, - "created_by": { - "type": "string", - "title": "Created By" - }, - "sources": { - "items": { - "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" - }, - "type": "array", - "title": "Sources" - }, - "created_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Created At" - }, - "updated_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Updated At" - }, - "first_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "First Seen At" - }, - "last_seen_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Seen At" - }, - "confidence": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Confidence" - }, "description": { "anyOf": [ { @@ -15415,16 +14054,10 @@ }, "type": "object", "required": [ - "uuid", - "type", "name", - "created_by", - "sources", - "created_at", - "updated_at", "description" ], - "title": "VulnerabilityEntityLiteAPIResponse" + "title": "VulnerabilityEntityLiteData" }, "WebhookBasicAuth": { "properties": { @@ -15444,6 +14077,31 @@ ], "title": "WebhookBasicAuth" }, + "pyro__entities__cti__actors__actor_datamodels__ActorData": { + "properties": { + "name": { + "type": "string", + "title": "Name" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + } + }, + "type": "object", + "required": [ + "name", + "description" + ], + "title": "ActorData" + }, "pyro__findings__chat_messages__datamodels__ChatMessageEventData__Actor": { "properties": { "id": { diff --git a/docs/api-reference/v4/endpoints/public/get-entity.mdx b/docs/api-reference/v4/endpoints/public/get-entity.mdx new file mode 100644 index 00000000..6f029395 --- /dev/null +++ b/docs/api-reference/v4/endpoints/public/get-entity.mdx @@ -0,0 +1,4 @@ +--- +openapi: firework-v4-openapi get /firework/v4/entities/{id} +tag: "BETA" +--- diff --git a/docs/api-reference/v4/endpoints/public/list-entities.mdx b/docs/api-reference/v4/endpoints/public/list-entities.mdx new file mode 100644 index 00000000..990bf2a0 --- /dev/null +++ b/docs/api-reference/v4/endpoints/public/list-entities.mdx @@ -0,0 +1,4 @@ +--- +openapi: firework-v4-openapi post /firework/v4/entities/global/_search +tag: "BETA" +--- diff --git a/docs/api-reference/v4/endpoints/public/list-entity-relations.mdx b/docs/api-reference/v4/endpoints/public/list-entity-relations.mdx new file mode 100644 index 00000000..c8fc6e91 --- /dev/null +++ b/docs/api-reference/v4/endpoints/public/list-entity-relations.mdx @@ -0,0 +1,4 @@ +--- +openapi: firework-v4-openapi get /firework/v4/entities/{id}/relations +tag: "BETA" +--- diff --git a/docs/docs.json b/docs/docs.json index b7fed61c..49e09ae6 100644 --- a/docs/docs.json +++ b/docs/docs.json @@ -234,6 +234,14 @@ } ] }, + { + "group": "Entities API", + "pages": [ + "api-reference/v4/endpoints/public/list-entities", + "api-reference/v4/endpoints/public/get-entity", + "api-reference/v4/endpoints/public/list-entity-relations" + ] + }, { "group": "Threat-Flow API", "pages": [ @@ -630,6 +638,14 @@ { "source": "/api-reference/v2/endpoints/identifiers/get-assetsgroups-feed", "destination": "/api-reference/v2/endpoints/identifiers/get-fireworkv2assetsgroups-feed" + }, + { + "source": "/api-reference/v4/endpoints/list-entities", + "destination": "/api-reference/v4/endpoints/public/list-entities" + }, + { + "source": "/api-reference/v4/endpoints/get-entity", + "destination": "/api-reference/v4/endpoints/public/get-entity" } ] }