Palo Alto Networks · Schema

ThreatSignature

Threat signature metadata record.

Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR

Properties

Name Type Description
id integer Unique signature identifier.
name string Signature name.
type string Signature type category.
subtype string Signature subtype (e.g., virus, trojan, exploit).
severity string
description string Human-readable description of the threat.
cve array Associated CVE identifiers.
default_action string Default action applied to traffic matching this signature.
min_version string Minimum PAN-OS version supporting this signature.
max_version string Maximum PAN-OS version supporting this signature (empty if still active).
status string
ori_release_version string Content version in which this signature was first released.
latest_release_version string Most recent content version that updated this signature.
first_release_time string Timestamp when the signature was first released.
latest_release_time string Timestamp of the most recent signature update.
sha256 array SHA-256 hashes associated with this signature (antivirus).
View JSON Schema on GitHub

JSON Schema

threat-vault-api-threat-signature-schema.json Raw ↑
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "ThreatSignature",
  "description": "Threat signature metadata record.",
  "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/threat-vault-api-threat-signature-schema.json",
  "type": "object",
  "properties": {
    "id": {
      "type": "integer",
      "description": "Unique signature identifier."
    },
    "name": {
      "type": "string",
      "description": "Signature name."
    },
    "type": {
      "type": "string",
      "enum": [
        "antivirus",
        "antispyware",
        "vulnerability",
        "dns",
        "fileformat"
      ],
      "description": "Signature type category."
    },
    "subtype": {
      "type": "string",
      "description": "Signature subtype (e.g., virus, trojan, exploit)."
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low",
        "informational"
      ]
    },
    "description": {
      "type": "string",
      "description": "Human-readable description of the threat."
    },
    "cve": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Associated CVE identifiers."
    },
    "default_action": {
      "type": "string",
      "enum": [
        "alert",
        "allow",
        "drop",
        "reset-both",
        "reset-client",
        "reset-server",
        "block-ip",
        "sinkhole"
      ],
      "description": "Default action applied to traffic matching this signature."
    },
    "min_version": {
      "type": "string",
      "description": "Minimum PAN-OS version supporting this signature."
    },
    "max_version": {
      "type": "string",
      "description": "Maximum PAN-OS version supporting this signature (empty if still active)."
    },
    "status": {
      "type": "string",
      "enum": [
        "released",
        "deprecated",
        "disabled"
      ]
    },
    "ori_release_version": {
      "type": "string",
      "description": "Content version in which this signature was first released."
    },
    "latest_release_version": {
      "type": "string",
      "description": "Most recent content version that updated this signature."
    },
    "first_release_time": {
      "type": "string",
      "format": "date-time",
      "description": "Timestamp when the signature was first released."
    },
    "latest_release_time": {
      "type": "string",
      "format": "date-time",
      "description": "Timestamp of the most recent signature update."
    },
    "sha256": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "SHA-256 hashes associated with this signature (antivirus)."
    }
  }
}

Work with this as data

Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for schemas

4 MCP tools reach this
  • find_json_schemasBrowse and filter every JSON Schema in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/threat-vault-api-threat-signature"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.