Demisto Indicators API
The Indicators API from Demisto — 8 operation(s) for indicators.
The Indicators API from Demisto — 8 operation(s) for indicators.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/demisto-indicators-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: This is the public REST API to integrate with the demisto server.
title: Demisto Indicators API
version: 2.0.0
servers:
- url: https://hostname:443
security:
- api_key: []
- csrf_token: []
- x-xdr-auth-id: []
tags:
- name: Indicators
paths:
/indicators/batch/export/stix:
post:
description: Exports an indicators batch to STIX file (returns file ID)
summary: Batch export indicators to STIX
operationId: exportIndicatorsToStixBatch
responses:
'200':
description: STIX file name
content:
application/json:
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/genericIndicatorUpdateBatch'
application/xml:
schema:
$ref: '#/components/schemas/genericIndicatorUpdateBatch'
tags:
- Indicators
/indicators/batch/exportToCsv:
post:
description: Exports an indicators batch to CSV file (returns file ID)
summary: Batch export indicators to csv
operationId: exportIndicatorsToCsvBatch
responses:
'200':
description: csv file name
content:
application/json:
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/genericIndicatorUpdateBatch'
application/xml:
schema:
$ref: '#/components/schemas/genericIndicatorUpdateBatch'
description: 'Required parameters from `genericIndicatorUpdateBatch`: `columns`,
`filter`. You should also include either `all` or `ids`
'
tags:
- Indicators
/indicators/batchDelete:
post:
description: 'Batch whitelist or delete indicators entities
In order to delete indicators and not whitelist, set doNotWhitelist boolean field to true'
summary: Batch whitelist or delete indicators
operationId: deleteIndicatorsBatch
responses:
'200':
description: UpdateResponse
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateResponse'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/genericIndicatorUpdateBatch'
application/xml:
schema:
$ref: '#/components/schemas/genericIndicatorUpdateBatch'
tags:
- Indicators
/indicators/csv/{id}:
get:
description: Get an indicators CSV file that was exported, by ID
summary: Get indicators as CSV
operationId: getIndicatorsAsCsv
parameters:
- description: CSV file to fetch (returned from batch export to csv call)
name: id
in: path
required: true
schema:
type: string
responses:
'200':
description: Return Csv file
content:
application/octet-stream:
schema:
type: string
format: binary
tags:
- Indicators
/indicators/feed/json:
post:
description: 'Create indicators from raw JSON (similar to ingesting from a feed). Builds indicators according to the specified feed classifier,
or uses the default one if not specified.
Indicator properties (all optional except for value): **value** (string, required) | **type** (string) | **score** (number, 0-3,
default `0`, where `0` means None, `1` Good, `2` Suspicious, and `3` Bad) | **sourceBrand** (string, default `"External"`) | **sourceInstance**
(string, default `"External"`) | **reliability** (string, one of `"A - Completely reliable"`, `"B - Usually reliable"`, `"C - Fairly
reliable"`, `"D - Not usually reliable"`, `"E - Unreliable"`, `"F - Reliability cannot be judged"`) | **expirationPolicy** (string,
one of `"never"`, `"interval"`, `"indicatorType"`) | **expirationInterval** (number, in minutes)'
summary: Create feed indicators from JSON
operationId: createFeedIndicatorsJson
responses:
'201':
description: Indicators created
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/FeedIndicatorsRequest'
application/xml:
schema:
$ref: '#/components/schemas/FeedIndicatorsRequest'
required: true
tags:
- Indicators
/indicators/search:
post:
description: Search indicators by filter
summary: Search indicators
operationId: indicatorsSearch
responses:
'200':
description: indicatorResult
content:
application/json:
schema:
$ref: '#/components/schemas/IndicatorResult'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/IndicatorFilter'
application/xml:
schema:
$ref: '#/components/schemas/IndicatorFilter'
tags:
- Indicators
/indicators/stix/v2/{id}:
get:
description: Get an indicators STIX V2 file that was exported, by ID
summary: Get indicators as STIX V2
operationId: getIndicatorsAsSTIX
parameters:
- description: STIX V2 file to fetch (returned from batch export to STIX call)
name: id
in: path
required: true
schema:
type: string
responses:
'200':
description: Return STIX V2 file
content:
application/octet-stream:
schema:
type: string
format: binary
tags:
- Indicators
/indicators/upload:
post:
description: Create indicators from a file
summary: Create indicators
operationId: indicatorsCreateBatch
responses:
'200':
description: IocObjects
content:
application/json:
schema:
$ref: '#/components/schemas/IocObjects'
requestBody:
content:
multipart/form-data:
schema:
type: object
properties:
fileName:
type: string
description: file name
file:
type: string
description: file
format: binary
required:
- file
tags:
- Indicators
components:
schemas:
IndicatorFilter:
description: IndicatorFilter is a general filter that fetches entities using a query string query using the Query value
type: object
properties:
Cache:
description: Cache of join functions
type: object
additionalProperties:
type: array
items:
type: string
earlyTimeInPage:
type: string
format: date-time
x-go-name: EarlyTimeInPage
firstSeen:
$ref: '#/components/schemas/DateRangeFilter'
fromDate:
type: string
format: date-time
x-go-name: FromDate
fromDateLicense:
type: string
format: date-time
x-go-name: FromDateLicenseVal
lastSeen:
$ref: '#/components/schemas/DateRangeFilter'
laterTimeInPage:
type: string
format: date-time
x-go-name: LaterTimeInPage
page:
description: 0-based page
type: integer
format: int64
x-go-name: Page
period:
$ref: '#/components/schemas/Period'
prevPage:
description: MT support - these fields are for indicator search according to calculatedTime
type: boolean
x-go-name: PrevPage
query:
type: string
x-go-name: Query
searchAfter:
description: Efficient next page, pass max sort value from previous page
type: array
items:
type: string
x-go-name: SearchAfter
searchBefore:
description: Efficient prev page, pass min sort value from next page
type: array
items:
type: string
x-go-name: SearchBefore
size:
description: Size is limited to 1000, if not passed it defaults to 0, and no results will return
type: integer
format: int64
x-go-name: Size
sort:
description: The sort order
type: array
items:
$ref: '#/components/schemas/Order'
x-go-name: Sort
timeFrame:
$ref: '#/components/schemas/Duration'
toDate:
type: string
format: date-time
x-go-name: ToDate
x-go-package: github.com/demisto/server/repo/entities
Period:
type: object
title: Period holds the 'Period' query, such as last 3 days, last 6 hours, between 6 days from now until 3 days from now.
properties:
by:
description: By is used for legacty, and if exists it will override ByTo and ByFrom
type: string
x-go-name: By
byFrom:
type: string
x-go-name: ByFrom
byTo:
type: string
x-go-name: ByTo
field:
type: string
x-go-name: Field
fromValue:
type: string
format: duration
x-go-name: FromValue
toValue:
type: string
format: duration
x-go-name: ToValue
x-go-package: github.com/demisto/server/domain
DateRangeFilter:
description: DateRangeFilter provides common fields for date filtering
type: object
properties:
fromDate:
type: string
format: date-time
x-go-name: FromDate
fromDateLicense:
type: string
format: date-time
x-go-name: FromDateLicenseVal
period:
$ref: '#/components/schemas/Period'
timeFrame:
$ref: '#/components/schemas/Duration'
toDate:
type: string
format: date-time
x-go-name: ToDate
x-go-package: github.com/demisto/server/repo/entities
InsightCache:
description: InsightCache - map insight name to all its metadata, name will be case insensitive
type: object
properties:
id:
type: string
x-go-name: ID
modified:
type: string
format: date-time
x-go-name: Modified
scores:
type: object
additionalProperties:
$ref: '#/components/schemas/DBotScore'
x-go-name: Scores
sequenceNumber:
type: integer
format: int64
x-go-name: SeqNum
sortValues:
type: array
items:
type: string
x-go-name: SortValues
version:
type: integer
format: int64
x-go-name: Versn
x-go-package: github.com/demisto/server/domain
Duration:
description: 'A Duration represents the elapsed time between two instants
as an int64 nanosecond count. The representation limits the
largest representable duration to approximately 290 years.'
type: integer
format: int64
x-go-package: time
IndicatorResult:
type: object
title: IndicatorResult ...
properties:
iocObjects:
$ref: '#/components/schemas/IocObjects'
total:
type: integer
format: int64
x-go-name: Total
x-go-package: github.com/demisto/server/web
CustomFields:
description: 'The keys should be the field''s display name all lower and without spaces. For example: Scan IP -> scanip
To get the actual key name you can also go to Demisto CLI and run /incident_add and look for the key that you would like to update'
type: object
title: CustomFields ...
additionalProperties:
type: object
x-go-package: github.com/demisto/server/domain
RawFeedIndicator:
description: RawFeedIndicator is an unparsed feed indicator from JSON ingestion
type: object
additionalProperties:
type: object
x-go-package: github.com/demisto/server/web
IocObjects:
type: array
title: IocObjects ...
items:
$ref: '#/components/schemas/IocObject'
x-go-package: github.com/demisto/server/domain
Order:
description: Order struct holds a sort field and the direction of sorting
type: object
properties:
asc:
type: boolean
x-go-name: Asc
field:
type: string
x-go-name: Field
fieldType:
type: string
x-go-name: FieldType
x-go-package: github.com/demisto/server/domain
genericIndicatorUpdateBatch:
type: object
properties:
all:
type: boolean
x-go-name: All
columns:
type: array
items:
type: string
x-go-name: Columns
doNotWhitelist:
type: boolean
x-go-name: DoNotWhitelist
filter:
$ref: '#/components/schemas/IndicatorFilter'
ids:
type: array
items:
type: string
x-go-name: IDs
reason:
type: string
x-go-name: Reason
reputations:
type: array
items:
type: string
x-go-name: Reputations
x-go-package: github.com/demisto/server/web
FeedIndicatorsRequest:
description: FeedIndicatorsRequest is the input for JSON feed indicator ingestion
type: object
properties:
bypassExclusionList:
type: boolean
x-go-name: ShouldBypassExclusionList
classifierId:
type: string
x-go-name: ClassifierID
indicators:
type: array
items:
$ref: '#/components/schemas/RawFeedIndicator'
x-go-name: Indicators
mapperId:
type: string
x-go-name: MapperID
x-go-package: github.com/demisto/server/web
UpdateResponse:
type: object
title: UpdateResponse ...
properties:
notUpdated:
type: integer
format: int64
x-go-name: NotUpdated
updatedIds:
type: array
items:
type: string
x-go-name: UpdatedIds
x-go-package: github.com/demisto/server/repo/entities
IocObject:
description: IocObject - represents an Ioc (or simply an indicator) object
type: object
properties:
CustomFields:
$ref: '#/components/schemas/CustomFields'
account:
type: string
x-go-name: Account
calculatedTime:
description: Do not set the fields bellow this line
type: string
format: date-time
x-go-name: CalculatedTime
comment:
type: string
x-go-name: Comment
firstSeen:
type: string
format: date-time
x-go-name: FirstSeen
firstSeenEntryID:
type: string
x-go-name: FirstSeenEntryID
id:
type: string
x-go-name: ID
indicator_type:
type: string
x-go-name: IndicatorType
insightCache:
$ref: '#/components/schemas/InsightCache'
investigationIDs:
type: array
items:
type: string
x-go-name: InvestigationIDs
lastReputationRun:
type: string
format: date-time
x-go-name: LastReputationRun
lastSeen:
type: string
format: date-time
x-go-name: LastSeen
lastSeenEntryID:
type: string
x-go-name: LastSeenEntryID
manualScore:
type: boolean
x-go-name: ManualScore
manualSetTime:
type: string
format: date-time
x-go-name: ManualSetTime
manuallyEditedFields:
type: array
items:
type: string
x-go-name: ManuallyEditedFields
modified:
type: string
format: date-time
x-go-name: Modified
score:
type: integer
format: int64
x-go-name: Score
setBy:
type: string
x-go-name: SetBy
sortValues:
type: array
items:
type: string
x-go-name: SortValues
source:
type: string
x-go-name: Source
timestamp:
type: string
format: date-time
x-go-name: TimeStamp
value:
type: string
x-go-name: Value
version:
type: integer
format: int64
x-go-name: Versn
x-go-package: github.com/demisto/server/domain
DBotScore:
description: DBotScore - Contain the score of a specific brand for a specific insight
type: object
properties:
content:
type: string
x-go-name: Content
contentFormat:
type: string
x-go-name: ContentFormat
context:
type: object
additionalProperties:
type: object
x-go-name: Context
isTypedIndicator:
type: boolean
x-go-name: IsTypedIndicator
score:
type: integer
format: int64
x-go-name: Score
scoreChangeTimestamp:
description: We need to track when the score changes to know if we need to re-calculate the overall score
type: string
format: date-time
x-go-name: ScoreChangeTimeStamp
timestamp:
type: string
format: date-time
x-go-name: TimeStamp
type:
type: string
x-go-name: Type
x-go-package: github.com/demisto/server/domain
securitySchemes:
api_key:
type: apiKey
name: Authorization
in: header
csrf_token:
type: apiKey
name: X-XSRF-TOKEN
in: header
x-xdr-auth-id:
type: apiKey
name: x-xdr-auth-id
in: header