Signatures
To create, update or retrieve Signatures from the ThreatStream platform.
Request
/api/v1/signature/
HTTP Methods: GET, POST, PATCH
| Create a new Signature | POST /api/v1/signature/ |
| Update the specified Signature | PATCH /api/v1/signature/{id}/ |
| Get details of the specified Signature | GET /api/v1/signature/{id}/ |
| Get a list of Signatures |
Anomali recommends to use the For example, GET |
| Get a list of signatures associated with the specified observable value or observable ID |
GET GET For example,
|
| Get a list of the specified entity type (such as Malware, Actor, Campaign, and so on) associated with the specified Signature |
GET For example, GET |
| Get a list of observables associated with the specified Signature | GET /api/v1/signature/{id}/intelligence/ |
Response
Format: JSON
Attributes: See the table below
- Attributes with "related" data type return 0 to N number of values. For example, if a threat model entity belongs to more than one trusted circle, both will be returned.
For information on limiting results and returning large datasets while mitigating performance impacts, see Limiting Results.
Attributes
| Attribute | Type | Description |
|---|---|---|
| circles | related (see item 1 in the Notes above) | All Trusted Circles to which the Signature belongs. |
| created_ts |
datetime |
Time stamp of when the signature was created on ThreatStream, in UTC format. Date is in this format: YYYYMMDDThhmmss where T denotes the start of the value for time. For example, 2014-10-02T20:44:35. Note: This attribute is returned in the response to a GET call and is set by ThreatStream; it cannot be configured.
|
| is_public | boolean |
Whether the Signature is public or private (including belonging to a trusted circle). False—if the Signature is private or belongs to a Trusted Circle True—if the Signature is public Default: False |
| limit | numeric |
The If |
| modified_ts | datetime |
Time stamp of when the Signature was last updated on ThreatStream, in UTC format. Date is in this format: YYYYMMDDThhmmss where T denotes the start of the value for time. For example, 2014-10-02T20:44:35. Note: This attribute is returned in the response to a GET call and is set by ThreatStream; it cannot be configured.
|
| name | string |
Name of the Signature. Signature name is associated with your organization. Therefore, the name must be unique within your organization. However, two Signatures with the same name can exist on ThreatStream as long as they belong to different organizations. The name can contain up to 255 characters.
Note: This is a required parameter.
|
| notes | string | Free-form text description and any other significant information about the signature. |
| publication_status | string |
A signature can be in new, pending_review, review_requested, reviewed, published statuses. Note: A signature must be in published status for it to be visible to other users outside your organization.
|
| remote_api (for ThreatStream OnPrem only) | boolean |
Whether the entity is remote (stored on Cloud). Value returned for this attribute is |
| s_type | string |
Signature type such as Snort, YARA, OpenIOC, Suricata. When creating a Signature, specify the ID of the signature type. To obtain a list of Signature type IDs, make an API call to
Note: This is a required parameter.
|
|
skip_associations (On ThreatStream OnPrem only) |
boolean |
By default, up to 1000 threat model and observable associations are returned with GET requests for details of a threat model entity on ThreatStream OnPrem. When a threat model entity has a large number of associations, association retrieval can take a long time and impact performance. Therefore, Anomali recommends setting the For example, GET |
|
skip_intelligence (On ThreatStream OnPrem only) |
boolean |
By default, up to 1000 threat model and observable associations are returned with GET requests for details of a threat model entity on ThreatStream OnPrem. When a threat model entity has a large number of associations, association retrieval can take a long time and impact performance. Therefore, Anomali recommends setting the For example, GET |
| source_created | datetime | Time stamp of when the Signature was created by its original source. |
| source_modified | datetime | Time stamp of when the Signature was last updated by its original source. |
| tags | list |
Tags assigned to the Signature. A tag is a meaningful name or any other string value assigned to identify the information. For example, spear phishing,exploitation. |
| tlp | string |
Traffic Light Protocol designation for the Signature—red, amber, amber+strict, green, clear. Note: The value is case-sensitive and must be specified in lower case.
|
Examples
-
To create a private Signature whose s_type ID is 3 (for CybOX):
Copycurl --request POST --data '{"name": "dummy test signature", "tlp": "red", "s_type": 3, "tags": ["big signature", "dummy tag"], "intelligence": [165546], "publication_status": "published", "notes": "the definition of this CybOX signature"}' 'https://api.threatstream.com/api/v1/signature/' -H 'Content-Type:application/json' -H 'Authorization: apikey <username>:<api_key>' -
To update the existing Signature whose ID is 10:
Copycurl --request PATCH --data '{"name": "another dummy test signature", "tlp": "orange"}' 'https://api.threatstream.com/api/v1/signature/10/' -H 'Authorization: apikey <username>:<api_key>' -H 'Content-Type:application/json' -
To get the details of an existing Signature whose ID is 10:
Copycurl 'https://api.threatstream.com/api/v1/signature/10/' -H 'Authorization: apikey <username>:<api_key>' -
To get the first 10 Signatures from ThreatStream:
Copycurl 'https://api.threatstream.com/api/v1/signature/?limit=10' -H 'Authorization: apikey <username>:<api_key>' -
(Only on ThreatStream OnPrem) To get the details of the remote Signature whose ID is 11:
Copycurl 'https://<ThreatStream_OnPrem_IP_or_FQDN>/api/v1/signature/11/?remote_api=true' -H 'Authorization: apikey <username>:<api_key>' -
(Only on ThreatStream OnPrem) To skip associations when retrieving details of the local Signature with ID 234678:
Copycurl 'https://<ThreatStream_OnPrem_IP_or_FQDN>/api/v1/signature/234678/?skip_associations=true' -H 'Authorization: apikey <username>:<api_key>'