Juniper Networks Indicators of Compromise API

IoC management and lookup

OpenAPI Specification

juniper-indicators-of-compromise-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Juniper Networks Juniper Apstra Allowlists and Blocklists Indicators of Compromise API
  description: Juniper Apstra is an intent-based networking platform for data center automation. The Apstra API provides RESTful access to manage blueprints, design elements, devices, connectivity templates, virtual networks, and intent-based analytics. It supports multivendor environments and enables closed-loop automation from design through deployment and operations.
  version: 4.2.0
  contact:
    name: Juniper Support
    url: https://www.juniper.net/us/en/products/network-automation/apstra.html
    email: support@juniper.net
  license:
    name: Proprietary
    url: https://www.juniper.net/us/en/legal-notices.html
  termsOfService: https://www.juniper.net/us/en/legal-notices.html
servers:
- url: https://{apstra_server}/api
  description: Apstra Server
  variables:
    apstra_server:
      default: apstra.example.com
      description: Hostname or IP of the Apstra server
security:
- authToken: []
tags:
- name: Indicators of Compromise
  description: IoC management and lookup
paths:
  /ioc/indicators:
    get:
      operationId: listIndicators
      summary: Juniper Networks List indicators of compromise
      description: Returns indicators of compromise detected in the environment.
      tags:
      - Indicators of Compromise
      parameters:
      - name: type
        in: query
        description: Filter by indicator type
        schema:
          type: string
          enum:
          - ip
          - domain
          - url
          - hash
          - email
      - name: limit
        in: query
        schema:
          type: integer
          default: 100
      responses:
        '200':
          description: List of indicators
          content:
            application/json:
              schema:
                type: object
                properties:
                  indicators:
                    type: array
                    items:
                      $ref: '#/components/schemas/Indicator'
                  total:
                    type: integer
components:
  schemas:
    Indicator:
      type: object
      properties:
        id:
          type: string
        type:
          type: string
          enum:
          - ip
          - domain
          - url
          - hash
          - email
        value:
          type: string
        threat_score:
          type: integer
          minimum: 0
          maximum: 10
        confidence:
          type: number
          minimum: 0
          maximum: 1
        source:
          type: string
        first_seen:
          type: string
          format: date-time
        last_seen:
          type: string
          format: date-time
        tags:
          type: array
          items:
            type: string
  securitySchemes:
    authToken:
      type: apiKey
      in: header
      name: AuthToken
      description: Authentication token obtained from the /aaa/login endpoint. Include as AuthToken header in all requests.
externalDocs:
  description: Apstra API Documentation
  url: https://www.juniper.net/documentation/us/en/software/apstra/