Demisto Indicator API
The Indicator API from Demisto — 3 operation(s) for indicator.
The Indicator API from Demisto — 3 operation(s) for indicator.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/demisto-indicator-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: This is the public REST API to integrate with the demisto server.
title: Demisto Indicator API
version: 2.0.0
servers:
- url: https://hostname:443
security:
- api_key: []
- csrf_token: []
- x-xdr-auth-id: []
tags:
- name: Indicator
paths:
/indicator/create:
post:
description: 'Create an indicator entity
To update indicator custom fields you should lowercase them and remove all spaces. For example: Scan IP -> scanip'
summary: Create Indicator
operationId: indicatorsCreate
responses:
'200':
description: IocObject
content:
application/json:
schema:
$ref: '#/components/schemas/IocObject'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/indicatorContext'
application/xml:
schema:
$ref: '#/components/schemas/indicatorContext'
tags:
- Indicator
/indicator/edit:
post:
description: 'Edit an indicator entity
To update indicator custom fields you should lowercase them and remove all spaces. For example: Scan IP -> scanip'
summary: Edit Indicator
operationId: indicatorsEdit
responses:
'200':
description: IocObject
content:
application/json:
schema:
$ref: '#/components/schemas/IocObject'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/IocObject'
application/xml:
schema:
$ref: '#/components/schemas/IocObject'
tags:
- Indicator
/indicator/whitelist:
post:
description: 'Whitelists or deletes an indicator entity
In order to delete an indicator and not whitelist, set doNotWhitelist boolean field to true'
summary: Whitelists or deletes Indicator
operationId: indicatorWhitelist
responses:
'200':
description: UpdateResponse
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateResponse'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/updateIndicatorReputationData'
application/xml:
schema:
$ref: '#/components/schemas/updateIndicatorReputationData'
tags:
- Indicator
components:
schemas:
indicatorContext:
type: object
properties:
entryId:
type: string
x-go-name: EntryID
indicator:
$ref: '#/components/schemas/IocObject'
investigationId:
type: string
x-go-name: InvestigationID
seenNow:
type: boolean
x-go-name: SeenNow
x-go-package: github.com/demisto/server/web
InsightCache:
description: InsightCache - map insight name to all its metadata, name will be case insensitive
type: object
properties:
id:
type: string
x-go-name: ID
modified:
type: string
format: date-time
x-go-name: Modified
scores:
type: object
additionalProperties:
$ref: '#/components/schemas/DBotScore'
x-go-name: Scores
sequenceNumber:
type: integer
format: int64
x-go-name: SeqNum
sortValues:
type: array
items:
type: string
x-go-name: SortValues
version:
type: integer
format: int64
x-go-name: Versn
x-go-package: github.com/demisto/server/domain
CustomFields:
description: 'The keys should be the field''s display name all lower and without spaces. For example: Scan IP -> scanip
To get the actual key name you can also go to Demisto CLI and run /incident_add and look for the key that you would like to update'
type: object
title: CustomFields ...
additionalProperties:
type: object
x-go-package: github.com/demisto/server/domain
UpdateResponse:
type: object
title: UpdateResponse ...
properties:
notUpdated:
type: integer
format: int64
x-go-name: NotUpdated
updatedIds:
type: array
items:
type: string
x-go-name: UpdatedIds
x-go-package: github.com/demisto/server/repo/entities
IocObject:
description: IocObject - represents an Ioc (or simply an indicator) object
type: object
properties:
CustomFields:
$ref: '#/components/schemas/CustomFields'
account:
type: string
x-go-name: Account
calculatedTime:
description: Do not set the fields bellow this line
type: string
format: date-time
x-go-name: CalculatedTime
comment:
type: string
x-go-name: Comment
firstSeen:
type: string
format: date-time
x-go-name: FirstSeen
firstSeenEntryID:
type: string
x-go-name: FirstSeenEntryID
id:
type: string
x-go-name: ID
indicator_type:
type: string
x-go-name: IndicatorType
insightCache:
$ref: '#/components/schemas/InsightCache'
investigationIDs:
type: array
items:
type: string
x-go-name: InvestigationIDs
lastReputationRun:
type: string
format: date-time
x-go-name: LastReputationRun
lastSeen:
type: string
format: date-time
x-go-name: LastSeen
lastSeenEntryID:
type: string
x-go-name: LastSeenEntryID
manualScore:
type: boolean
x-go-name: ManualScore
manualSetTime:
type: string
format: date-time
x-go-name: ManualSetTime
manuallyEditedFields:
type: array
items:
type: string
x-go-name: ManuallyEditedFields
modified:
type: string
format: date-time
x-go-name: Modified
score:
type: integer
format: int64
x-go-name: Score
setBy:
type: string
x-go-name: SetBy
sortValues:
type: array
items:
type: string
x-go-name: SortValues
source:
type: string
x-go-name: Source
timestamp:
type: string
format: date-time
x-go-name: TimeStamp
value:
type: string
x-go-name: Value
version:
type: integer
format: int64
x-go-name: Versn
x-go-package: github.com/demisto/server/domain
DBotScore:
description: DBotScore - Contain the score of a specific brand for a specific insight
type: object
properties:
content:
type: string
x-go-name: Content
contentFormat:
type: string
x-go-name: ContentFormat
context:
type: object
additionalProperties:
type: object
x-go-name: Context
isTypedIndicator:
type: boolean
x-go-name: IsTypedIndicator
score:
type: integer
format: int64
x-go-name: Score
scoreChangeTimestamp:
description: We need to track when the score changes to know if we need to re-calculate the overall score
type: string
format: date-time
x-go-name: ScoreChangeTimeStamp
timestamp:
type: string
format: date-time
x-go-name: TimeStamp
type:
type: string
x-go-name: Type
x-go-package: github.com/demisto/server/domain
updateIndicatorReputationData:
type: object
properties:
InvestigationId:
type: string
x-go-name: InvID
doNotWhitelist:
type: boolean
x-go-name: DoNotWhitelist
entryId:
type: string
x-go-name: EntryID
manualScore:
type: boolean
x-go-name: ManualScore
reason:
type: string
x-go-name: Reason
reputation:
type: integer
format: int64
x-go-name: Reputation
reputations:
type: array
items:
type: string
x-go-name: Reputations
value:
type: string
x-go-name: Value
x-go-package: github.com/demisto/server/web
securitySchemes:
api_key:
type: apiKey
name: Authorization
in: header
csrf_token:
type: apiKey
name: X-XSRF-TOKEN
in: header
x-xdr-auth-id:
type: apiKey
name: x-xdr-auth-id
in: header