Cyware Detailed Submission API

Detailed Submission

Operations 102

DELETE /conversion/shareable-intel/{intel-id}/attack-pattern/ Bulk Delete Attack Pattern SDO #
POST /conversion/shareable-intel/{intel-id}/attack-pattern/ Create Attack Pattern SDO #
GET /conversion/shareable-intel/{intel-id}/attack-pattern/ Get Attack Pattern SDOs List #
DELETE /conversion/shareable-intel/{intel-id}/attack-pattern/{attack-pattern-id}/ Delete Attack Pattern SDO #
GET /conversion/shareable-intel/{intel-id}/attack-pattern/{attack-pattern-id}/ Get Attack Pattern SDO #
PUT /conversion/shareable-intel/{intel-id}/attack-pattern/{attack-pattern-id}/ Update Attack Pattern SDO #
DELETE /ingestion/shareable-intel/{intel-id}/campaign/ Bulk Delete Campaign SDO #
POST /ingestion/shareable-intel/{intel-id}/campaign/ Create Campaign SDO #
GET /ingestion/shareable-intel/{intel-id}/campaign/ Get Campaign SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/campaign/{campaign-id}/ Delete Campaign SDO #
GET /ingestion/shareable-intel/{intel-id}/campaign/{campaign-id}/ Get Campaign SDO #
PUT /ingestion/shareable-intel/{intel-id}/campaign/{campaign-id}/ Update Campaign SDO #
GET /conversion/shareable-intel/vocab/{vocab-type}/ Get Vocabulary List #
GET /conversion/shareable-intel/relation/ Get Relation List #
DELETE /ingestion/shareable-intel/{intel-id}/course-of-action/ Bulk Delete Course of Action SDO #
POST /ingestion/shareable-intel/{intel-id}/course-of-action/ Create Course of Action SDO #
GET /ingestion/shareable-intel/{intel-id}/course-of-action/ Get Course of Action SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/course-of-action/{course-of-action-id}/ Delete Course of Action SDO #
GET /ingestion/shareable-intel/{intel-id}/course-of-action/{course-of-action-id}/ Get Course of Action SDO #
PUT /ingestion/shareable-intel/{intel-id}/course-of-action/{course-of-action-id}/ Update Course of Action SDO #
POST /conversion/shareable-intel/ Create DRAFT Intel #
DELETE /conversion/shareable-intel/{intel-id}/ Discard Draft API #
GET /conversion/shareable-intel/{intel-id}/ Get DRAFT Intel #
PUT /conversion/shareable-intel/{intel-id}/ Update DRAFT Intel #
POST /conversion/shareable-intel/clone/ Clone API for Partial Success #
GET /conversion/file/ Download Logs from Detailed Submission/Threat Bulletin #
GET /conversion/file/{file_id}/ Download Logs from Notification #
GET /conversion/export/download/{token}/ Get Export API #
DELETE /ingestion/shareable-intel/{intel-id}/identity/ Bulk Delete Identity SDO #
POST /ingestion/shareable-intel/{intel-id}/identity/ Create Identity SDO #
GET /ingestion/shareable-intel/{intel-id}/identity/ Get Identity SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/identity/{identity-id}/ Delete Identity SDO #
GET /ingestion/shareable-intel/{intel-id}/identity/{identity-id}/ Get Identity SDO #
PUT /ingestion/shareable-intel/{intel-id}/identity/{identity-id}/ Update Identity SDO #
DELETE /conversion/shareable-intel/{intel-id}/indicator/ Bulk Delete Indicator SDO #
POST /conversion/shareable-intel/{intel-id}/indicator/ Create indicator SDO #
GET /conversion/shareable-intel/{intel-id}/indicator/ Get Indicator SDOs List #
DELETE /conversion/shareable-intel/{intel-id}/indicator/{indicator-id}/ Delete Indicator SDO #
GET /conversion/shareable-intel/{intel-id}/indicator/{indicator-id}/ Get Indicator SDO #
PUT /conversion/shareable-intel/{intel-id}/indicator/{indicator-id}/ Update Indicator SDO #
DELETE /ingestion/shareable-intel/{intel-id}/infrastructure/ Bulk Delete Infrastructure SDO #
POST /ingestion/shareable-intel/{intel-id}/infrastructure/ Create Infrastructure SDO #
GET /ingestion/shareable-intel/{intel-id}/infrastructure/ Get Infrastructure SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/infrastructure/{infrastructure-id}/ Delete Infrastructure SDO #
GET /ingestion/shareable-intel/{intel-id}/infrastructure/{infrastructure-id}/ Get Infrastructure SDO #
PUT /ingestion/shareable-intel/{intel-id}/infrastructure/{infrastructure-id}/ Update Infrastructure SDO #
DELETE /ingestion/shareable-intel/{intel-id}/location/ Bulk Delete Location SDO #
POST /ingestion/shareable-intel/{intel-id}/location/ Create Location SDO #
GET /ingestion/shareable-intel/{intel-id}/location/ Get Location SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/location/{location-id}/ Delete Location SDO #
GET /ingestion/shareable-intel/{intel-id}/location/{location-id}/ Get Location SDO #
PUT /ingestion/shareable-intel/{intel-id}/location/{location-id}/ Update Location SDO #
DELETE /conversion/shareable-intel/{intel-id}/malware/ Bulk Delete Malware SDO #
POST /ingestion/shareable-intel/{intel-id}/malware/ Create Malware SDO #
GET /ingestion/shareable-intel/{intel-id}/malware/ Get Malware SDOs List #
DELETE /conversion/shareable-intel/{intel-id}/malware/{malware-id}/ Delete Malware SDO #
GET /ingestion/shareable-intel/{intel-id}/malware/{malware-id}/ Get Malware SDO #
PUT /ingestion/shareable-intel/{intel-id}/malware/{malware-id}/ Update Malware SDO #
DELETE /ingestion/shareable-intel/{intel-id}/relationship/ Bulk Delete Relationship SDOs #
POST /ingestion/shareable-intel/{intel-id}/relationship/ Create Relationship SDO #
GET /ingestion/shareable-intel/{intel-id}/relationship/ Get Relationship SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/relationship/{relationship-id}/ Delete Relationship SDO #
GET /ingestion/shareable-intel/{intel-id}/relationship/{relationship-id}/ Get Relationship SDO #
PUT /ingestion/shareable-intel/{intel-id}/relationship/{relationship-id}/ Update Relationship SDO #
DELETE /ingestion/shareable-intel/{intel-id}/report/ Bulk Delete Report SDO #
POST /ingestion/shareable-intel/{intel-id}/report/ Create Report SDO #
GET /ingestion/shareable-intel/{intel-id}/report/ Get Report SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/report/{report-id}/ Delete Report SDO #
GET /ingestion/shareable-intel/{intel-id}/report/{report-id}/ Get Report SDO #
PUT /ingestion/shareable-intel/{intel-id}/report/{report-id}/ Update Report SDO #
POST /conversion/shareable-intel/{intel-id}/domain-name/ Create Domain Name SCO #
POST /ingestion/shareable-intel/{intel-id}/email-addr/ Create Email-addr SCO #
POST /conversion/shareable-intel/{intel-id}/email-message/ Create Email Message SCO #
POST /conversion/shareable-intel/{intel-id}/file/ Create File SCO #
POST /conversion/shareable-intel/{intel-id}/ipv4-addr/ Create IPv4-addr SCO #
POST /conversion/shareable-intel/{intel-id}/ipv6-addr/ Create IPv6-addr SCO #
POST /ingestion/shareable-intel/{intel-id}/mutex/ Create Mutex SCO #
POST /ingestion/shareable-intel/{intel-id}/software/ Create Software SCO #
POST /conversion/shareable-intel/{intel-id}/url/ Create URL SCO #
DELETE /ingestion/shareable-intel/{intel-id}/sighting/ Bulk Delete Sighting SDO #
GET /ingestion/shareable-intel/{intel-id}/sighting/ Get Sighting SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/sighting/{sighting-id}/ Delete Sighting SDO #
GET /ingestion/shareable-intel/{intel-id}/sighting/{sighting-id}/ Get Sighting SDO #
PUT /ingestion/shareable-intel/{intel-id}/sighting/{sighting-id}/ Update Sighting SDO #
DELETE /ingestion/shareable-intel/{intel-id}/threat-actor/ Bulk Delete Threat Actor SDO #
POST /ingestion/shareable-intel/{intel-id}/threat-actor/ Create Threat Actor SDO #
GET /ingestion/shareable-intel/{intel-id}/threat-actor/ Get Threat Actor SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/threat-actor/{threat-actor-id}/ Delete Threat Actor SDO #
GET /ingestion/shareable-intel/{intel-id}/threat-actor/{threat-actor-id}/ Get Threat Actor SDO #
PUT /ingestion/shareable-intel/{intel-id}/threat-actor/{threat-actor-id}/ Update Threat Actor SDO #
DELETE /ingestion/shareable-intel/{intel-id}/tool/ Bulk Delete Tool SDO #
POST /ingestion/shareable-intel/{intel-id}/tool/ Create Tool SDO #
GET /ingestion/shareable-intel/{intel-id}/tool/ Get Tool SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/tool/{tool-id}/ Delete Tool SDO #
GET /ingestion/shareable-intel/{intel-id}/tool/{tool-id}/ Get Tool SDO #
PUT /ingestion/shareable-intel/{intel-id}/tool/{tool-id}/ Update Tool SDO #
DELETE /ingestion/shareable-intel/{intel-id}/vulnerability/ Bulk Delete Vulnerability SDO #
POST /ingestion/shareable-intel/{intel-id}/vulnerability/ Create Vulnerability SDO #
GET /ingestion/shareable-intel/{intel-id}/vulnerability/ Get Vulnerability SDOs List #
DELETE /ingestion/shareable-intel/{intel-id}/vulnerability/{vulnerability-id}/ Delete Vulnerability SDO #
GET /ingestion/shareable-intel/{intel-id}/vulnerability/{vulnerability-id}/ Get Vulnerability SDO #
PUT /ingestion/shareable-intel/{intel-id}/vulnerability/{vulnerability-id}/ Update Vulnerability SDO #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cyware-detailed-submission-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cyware-detailed-submission-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cyware Intel Exchange (CTIX) v3 Open Detailed Submission API
  version: 3.6.2
  description: Public Open API for Cyware Intel Exchange (formerly CTIX), Cyware's threat intelligence platform for the ingestion, enrichment, analysis, correlation and bi-directional sharing of structured and unstructured threat intelligence using STIX 2.x and TAXII 2.x.
  contact:
    name: Cyware
    url: https://www.cyware.com/contact-us
  termsOfService: https://www.cyware.com/legal/terms-of-use
  x-apievangelist-source: https://ctixapiv3.cyware.com/llms.txt
  x-apievangelist-method: generated
servers:
- url: https://{ctix_host}/ctixapi
  description: Tenant Intel Exchange deployment. Replace {ctix_host} with your own Intel Exchange host. Cyware documents the base URL form https://sample.domain.com/ctixapi in its authentication guide and uses https://demo.cyware.com/ctix/ as the example host in the config of its open-source MCP server.
  variables:
    ctix_host:
      default: demo.cyware.com
security:
- ctixOpenApiSignature: []
tags:


# --- truncated at 32 KB (750 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cyware/refs/heads/main/openapi/cyware-detailed-submission-api-openapi.yml