diff --git a/docs/api-reference/spec/firework-v2-openapi.json b/docs/api-reference/spec/firework-v2-openapi.json index f99f856c..864d38ec 100644 --- a/docs/api-reference/spec/firework-v2-openapi.json +++ b/docs/api-reference/spec/firework-v2-openapi.json @@ -1692,7 +1692,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -2016,7 +2016,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -2591,7 +2591,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -2915,7 +2915,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -3329,7 +3329,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -3612,7 +3612,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -4740,7 +4740,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -5044,7 +5044,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -5556,33 +5556,33 @@ "search_types": { "items": { "enum": [ + "forum_profile", + "invalid_credential", + "source_code_files", + "forum_post", + "bucket_object", + "social_media_account", "ad", - "paste", + "stack_exchange", + "bucket", + "google", "mitigated_credential", + "chat_message", + "seller", + "valid_credential", "ransomleak", - "stealer_log", + "blog_post", "listing", - "stack_exchange", - "forum_profile", - "financial_data", - "valid_credential", - "bucket", + "bot", + "leak", + "docker", "service", + "stealer_log", "forum_topic", + "financial_data", "source_code_secrets", - "social_media_account", "domain", - "seller", - "chat_message", - "bot", - "source_code_files", - "docker", - "google", - "bucket_object", - "leak", - "forum_post", - "blog_post", - "invalid_credential", + "paste", "illicit_networks", "open_web", "buckets", @@ -5596,7 +5596,7 @@ "infected_devices", "social_media" ], - "example": "ad", + "example": "forum_profile", "type": "string" }, "type": "array" @@ -5664,32 +5664,32 @@ "search_types": { "items": { "enum": [ - "paste", + "forum_profile", + "invalid_credential", + "source_code_files", + "forum_post", + "bucket_object", + "social_media_account", + "stack_exchange", + "bucket", + "google", "mitigated_credential", + "chat_message", + "seller", + "valid_credential", "ransomleak", - "stealer_log", + "blog_post", "listing", - "stack_exchange", - "forum_profile", - "financial_data", - "valid_credential", - "bucket", + "bot", + "leak", + "docker", "service", + "stealer_log", "forum_topic", + "financial_data", "source_code_secrets", - "social_media_account", "domain", - "seller", - "chat_message", - "bot", - "source_code_files", - "docker", - "google", - "bucket_object", - "leak", - "forum_post", - "blog_post", - "invalid_credential", + "paste", "illicit_networks", "open_web", "buckets", @@ -5702,7 +5702,7 @@ "infected_devices", "social_media" ], - "example": "ad", + "example": "forum_profile", "type": "string" }, "type": "array" @@ -6001,17 +6001,6 @@ }, "type": "object" }, - "TenantWithCounts": { - "properties": { - "next": { - "type": "string" - }, - "items": { - "$ref": "#/components/schemas/TenantWithCounts" - } - }, - "type": "object" - }, "Tenant": { "properties": { "id": { @@ -6071,6 +6060,17 @@ }, "type": "object" }, + "TenantWithCounts": { + "properties": { + "next": { + "type": "string" + }, + "items": { + "$ref": "#/components/schemas/TenantWithCounts" + } + }, + "type": "object" + }, "UpdatedPermission": { "properties": { "updated_value": { @@ -6140,17 +6140,6 @@ ], "type": "object" }, - "OrganizationMemberPage": { - "properties": { - "members": { - "items": { - "$ref": "#/components/schemas/OrganizationMemberWithMetadata" - }, - "type": "array" - } - }, - "type": "object" - }, "OrganizationMemberWithMetadata": { "properties": { "user": { @@ -6204,6 +6193,17 @@ }, "type": "object" }, + "OrganizationMemberPage": { + "properties": { + "members": { + "items": { + "$ref": "#/components/schemas/OrganizationMemberWithMetadata" + }, + "type": "array" + } + }, + "type": "object" + }, "OrganizationMembersCount": { "properties": { "count": { diff --git a/docs/api-reference/spec/firework-v2-swagger.json b/docs/api-reference/spec/firework-v2-swagger.json index c677ae73..7f587c08 100644 --- a/docs/api-reference/spec/firework-v2-swagger.json +++ b/docs/api-reference/spec/firework-v2-swagger.json @@ -462,20 +462,6 @@ "type": "string" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/ActivityUserMetadata" - } - } - }, - "operationId": "get_activity_user_metadata_tags_/activities////user_metadata/tags", - "tags": [ - "activities" - ] - }, "delete": { "responses": { "200": { @@ -516,6 +502,20 @@ "tags": [ "activities" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "$ref": "#/definitions/ActivityUserMetadata" + } + } + }, + "operationId": "get_activity_user_metadata_tags_/activities////user_metadata/tags", + "tags": [ + "activities" + ] } }, "/firework/v2/activities/{index}/{source}/{id}": { @@ -914,24 +914,6 @@ } }, "/firework/v2/assets/": { - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "properties": { - "assets": { - "$ref": "#/definitions/Identifier" - } - } - } - } - }, - "operationId": "get_assets_/assets/", - "tags": [ - "Identifiers" - ] - }, "post": { "responses": { "200": { @@ -965,27 +947,27 @@ "tags": [ "Identifiers" ] - } - }, - "/firework/v2/assets/groups/": { + }, "get": { "responses": { "200": { "description": "Success", "schema": { "properties": { - "assets_groups": { - "$ref": "#/definitions/IdentifierGroup" + "assets": { + "$ref": "#/definitions/Identifier" } } } } }, - "operationId": "get_assets_groups_/assets/groups/", + "operationId": "get_assets_/assets/", "tags": [ "Identifiers" ] - }, + } + }, + "/firework/v2/assets/groups/": { "post": { "responses": { "200": { @@ -1019,35 +1001,35 @@ "tags": [ "Identifiers" ] - } - }, - "/firework/v2/assets/groups/{assets_group_id}": { - "parameters": [ - { - "name": "assets_group_id", - "in": "path", - "required": true, - "type": "integer" - } - ], + }, "get": { "responses": { "200": { "description": "Success", "schema": { "properties": { - "assets_group": { + "assets_groups": { "$ref": "#/definitions/IdentifierGroup" } } } } }, - "operationId": "get_assets_group_api_/assets/groups/", + "operationId": "get_assets_groups_/assets/groups/", "tags": [ "Identifiers" ] - }, + } + }, + "/firework/v2/assets/groups/{assets_group_id}": { + "parameters": [ + { + "name": "assets_group_id", + "in": "path", + "required": true, + "type": "integer" + } + ], "delete": { "responses": { "200": { @@ -1092,35 +1074,35 @@ "tags": [ "Identifiers" ] - } - }, - "/firework/v2/assets/groups/{assets_group_id}/alerts": { - "parameters": [ - { - "name": "assets_group_id", - "in": "path", - "required": true, - "type": "integer" - } - ], + }, "get": { "responses": { "200": { "description": "Success", "schema": { "properties": { - "alerts": { - "$ref": "#/definitions/FeedAlert" + "assets_group": { + "$ref": "#/definitions/IdentifierGroup" } } } } }, - "operationId": "get_assets_group_alerts_/assets/groups//alerts", + "operationId": "get_assets_group_api_/assets/groups/", "tags": [ "Identifiers" ] - }, + } + }, + "/firework/v2/assets/groups/{assets_group_id}/alerts": { + "parameters": [ + { + "name": "assets_group_id", + "in": "path", + "required": true, + "type": "integer" + } + ], "post": { "responses": { "200": { @@ -1144,6 +1126,24 @@ "tags": [ "Identifiers" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "properties": { + "alerts": { + "$ref": "#/definitions/FeedAlert" + } + } + } + } + }, + "operationId": "get_assets_group_alerts_/assets/groups//alerts", + "tags": [ + "Identifiers" + ] } }, "/firework/v2/assets/groups/{assets_group_id}/alerts/{alert_id}": { @@ -1206,7 +1206,7 @@ "type": "integer" } ], - "get": { + "post": { "responses": { "404": { "description": "Identifier group does not exist.", @@ -1227,7 +1227,7 @@ } } }, - "operationId": "get_assets_group_feed_/assets/groups//feed", + "operationId": "post_assets_group_feed_/assets/groups//feed", "parameters": [ { "name": "fields", @@ -1284,7 +1284,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -1466,7 +1466,7 @@ "Identifiers" ] }, - "post": { + "get": { "responses": { "404": { "description": "Identifier group does not exist.", @@ -1487,7 +1487,7 @@ } } }, - "operationId": "post_assets_group_feed_/assets/groups//feed", + "operationId": "get_assets_group_feed_/assets/groups//feed", "parameters": [ { "name": "fields", @@ -1544,7 +1544,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -1736,24 +1736,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "properties": { - "asset": { - "$ref": "#/definitions/Identifier" - } - } - } - } - }, - "operationId": "get_asset_api_/assets/", - "tags": [ - "Identifiers" - ] - }, "delete": { "responses": { "200": { @@ -1798,35 +1780,35 @@ "tags": [ "Identifiers" ] - } - }, - "/firework/v2/assets/{asset_id}/alerts": { - "parameters": [ - { - "name": "asset_id", - "in": "path", - "required": true, - "type": "integer" - } - ], + }, "get": { "responses": { "200": { "description": "Success", "schema": { "properties": { - "alerts": { - "$ref": "#/definitions/FeedAlert" + "asset": { + "$ref": "#/definitions/Identifier" } } } } }, - "operationId": "get_asset_alerts_/assets//alerts", + "operationId": "get_asset_api_/assets/", "tags": [ "Identifiers" ] - }, + } + }, + "/firework/v2/assets/{asset_id}/alerts": { + "parameters": [ + { + "name": "asset_id", + "in": "path", + "required": true, + "type": "integer" + } + ], "post": { "responses": { "200": { @@ -1850,6 +1832,24 @@ "tags": [ "Identifiers" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "properties": { + "alerts": { + "$ref": "#/definitions/FeedAlert" + } + } + } + } + }, + "operationId": "get_asset_alerts_/assets//alerts", + "tags": [ + "Identifiers" + ] } }, "/firework/v2/assets/{asset_id}/alerts/{alert_id}": { @@ -1912,7 +1912,7 @@ "type": "integer" } ], - "get": { + "post": { "responses": { "404": { "description": "Identifier does not exist.", @@ -1933,7 +1933,7 @@ } } }, - "operationId": "get_asset_feed_/assets//feed", + "operationId": "post_asset_feed_/assets//feed", "parameters": [ { "name": "fields", @@ -1990,7 +1990,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -2172,7 +2172,7 @@ "Identifiers" ] }, - "post": { + "get": { "responses": { "404": { "description": "Identifier does not exist.", @@ -2193,7 +2193,7 @@ } } }, - "operationId": "post_asset_feed_/assets//feed", + "operationId": "get_asset_feed_/assets//feed", "parameters": [ { "name": "fields", @@ -2250,7 +2250,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -2523,7 +2523,7 @@ } }, "/firework/v2/me/feed": { - "get": { + "post": { "responses": { "200": { "description": "The user's home feed activities", @@ -2532,7 +2532,7 @@ } } }, - "operationId": "get_current_user_home_feed_/me/feed", + "operationId": "post_current_user_home_feed_/me/feed", "parameters": [ { "name": "time", @@ -2579,7 +2579,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -2761,7 +2761,7 @@ "me" ] }, - "post": { + "get": { "responses": { "200": { "description": "The user's home feed activities", @@ -2770,7 +2770,7 @@ } } }, - "operationId": "post_current_user_home_feed_/me/feed", + "operationId": "get_current_user_home_feed_/me/feed", "parameters": [ { "name": "time", @@ -2817,7 +2817,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -3001,6 +3001,30 @@ } }, "/firework/v2/me/feed/credentials": { + "post": { + "responses": { + "200": { + "description": "Success", + "schema": { + "$ref": "#/definitions/PaginatedCredentials" + } + } + }, + "operationId": "post_leaked_credentials_feed_endpoint_/me/feed/credentials", + "parameters": [ + { + "name": "payload", + "required": true, + "in": "body", + "schema": { + "$ref": "#/definitions/UserUpdate" + } + } + ], + "tags": [ + "me" + ] + }, "get": { "responses": { "200": { @@ -3037,45 +3061,10 @@ "tags": [ "me" ] - }, - "post": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/PaginatedCredentials" - } - } - }, - "operationId": "post_leaked_credentials_feed_endpoint_/me/feed/credentials", - "parameters": [ - { - "name": "payload", - "required": true, - "in": "body", - "schema": { - "$ref": "#/definitions/UserUpdate" - } - } - ], - "tags": [ - "me" - ] - } - }, - "/firework/v2/me/profile": { - "get": { - "responses": { - "200": { - "description": "Returns the current user's profile" - } - }, - "operationId": "get_current_user_profile_/me/profile", - "tags": [ - "me" - ] - }, - "put": { + } + }, + "/firework/v2/me/profile": { + "put": { "responses": { "400": { "description": "Update is invalid", @@ -3108,6 +3097,17 @@ "tags": [ "me" ] + }, + "get": { + "responses": { + "200": { + "description": "Returns the current user's profile" + } + }, + "operationId": "get_current_user_profile_/me/profile", + "tags": [ + "me" + ] } }, "/firework/v2/me/tenants": { @@ -3132,7 +3132,7 @@ "type": "integer" } ], - "get": { + "post": { "responses": { "404": { "description": "Organization not found", @@ -3143,34 +3143,30 @@ "200": { "description": "Success", "schema": { - "$ref": "#/definitions/OrganizationMemberPage" + "properties": { + "member": { + "$ref": "#/definitions/OrganizationMemberWithMetadata" + } + } } } }, - "operationId": "get_organization_members_api_/organizations//members", + "operationId": "post_organization_members_api_/organizations//members", "parameters": [ { - "name": "size", - "in": "query", - "type": "integer", - "default": 20 - }, - { - "name": "from", - "in": "query", - "type": "string" - }, - { - "name": "q", - "in": "query", - "type": "string" + "name": "payload", + "required": true, + "in": "body", + "schema": { + "$ref": "#/definitions/OrganizationMemberData" + } } ], "tags": [ "organizations" ] }, - "post": { + "get": { "responses": { "404": { "description": "Organization not found", @@ -3181,23 +3177,27 @@ "200": { "description": "Success", "schema": { - "properties": { - "member": { - "$ref": "#/definitions/OrganizationMemberWithMetadata" - } - } + "$ref": "#/definitions/OrganizationMemberPage" } } }, - "operationId": "post_organization_members_api_/organizations//members", + "operationId": "get_organization_members_api_/organizations//members", "parameters": [ { - "name": "payload", - "required": true, - "in": "body", - "schema": { - "$ref": "#/definitions/OrganizationMemberData" - } + "name": "size", + "in": "query", + "type": "integer", + "default": 20 + }, + { + "name": "from", + "in": "query", + "type": "string" + }, + { + "name": "q", + "in": "query", + "type": "string" } ], "tags": [ @@ -3250,7 +3250,7 @@ "type": "integer" } ], - "get": { + "put": { "responses": { "200": { "description": "Success", @@ -3263,12 +3263,22 @@ } } }, - "operationId": "get_organization_member_api_/organizations//members/", + "operationId": "put_organization_member_api_/organizations//members/", + "parameters": [ + { + "name": "payload", + "required": true, + "in": "body", + "schema": { + "$ref": "#/definitions/OrganizationMember" + } + } + ], "tags": [ "organizations" ] }, - "put": { + "get": { "responses": { "200": { "description": "Success", @@ -3281,17 +3291,7 @@ } } }, - "operationId": "put_organization_member_api_/organizations//members/", - "parameters": [ - { - "name": "payload", - "required": true, - "in": "body", - "schema": { - "$ref": "#/definitions/OrganizationMember" - } - } - ], + "operationId": "get_organization_member_api_/organizations//members/", "tags": [ "organizations" ] @@ -3480,20 +3480,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/TenantWithCounts" - } - } - }, - "operationId": "get_organization_tenants_api_/organizations//tenants", - "tags": [ - "organizations" - ] - }, "post": { "responses": { "200": { @@ -3517,20 +3503,23 @@ "tags": [ "organizations" ] - } - }, - "/firework/v2/reporting/reports": { + }, "get": { "responses": { "200": { - "description": "Lists reports for the current tenant, ordered from newest to oldest." + "description": "Success", + "schema": { + "$ref": "#/definitions/TenantWithCounts" + } } }, - "operationId": "get_reports_endpoint_/reporting/reports", + "operationId": "get_organization_tenants_api_/organizations//tenants", "tags": [ - "reporting" + "organizations" ] - }, + } + }, + "/firework/v2/reporting/reports": { "post": { "responses": { "200": { @@ -3551,6 +3540,17 @@ "tags": [ "reporting" ] + }, + "get": { + "responses": { + "200": { + "description": "Lists reports for the current tenant, ordered from newest to oldest." + } + }, + "operationId": "get_reports_endpoint_/reporting/reports", + "tags": [ + "reporting" + ] } }, "/firework/v2/reporting/reports/{report_id}": { @@ -3562,17 +3562,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Returns a report and its elements." - } - }, - "operationId": "get_report_endpoint_/reporting/reports/", - "tags": [ - "reporting" - ] - }, "delete": { "responses": { "200": { @@ -3604,6 +3593,17 @@ "tags": [ "reporting" ] + }, + "get": { + "responses": { + "200": { + "description": "Returns a report and its elements." + } + }, + "operationId": "get_report_endpoint_/reporting/reports/", + "tags": [ + "reporting" + ] } }, "/firework/v2/reporting/reports/{report_id}/archive": { @@ -3649,7 +3649,7 @@ } }, "/firework/v2/search/": { - "get": { + "post": { "responses": { "400": { "description": "Query is invalid.", @@ -3664,7 +3664,7 @@ } } }, - "operationId": "get_search_/search/", + "operationId": "post_search_/search/", "parameters": [ { "name": "fields", @@ -3721,7 +3721,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -3901,7 +3901,7 @@ "search" ] }, - "post": { + "get": { "responses": { "400": { "description": "Query is invalid.", @@ -3916,7 +3916,7 @@ } } }, - "operationId": "post_search_/search/", + "operationId": "get_search_/search/", "parameters": [ { "name": "fields", @@ -3973,7 +3973,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: forum_post, chat_message, forum_profile, stealer_log, seller, ransomleak, forum_topic, financial_data, blog_post, listing, bot\n- open_web: docker, service, bucket_object, social_media_account, stack_exchange, source_code_secrets, paste, bucket, google, source_code_files\n- leaks: valid_credential, invalid_credential, mitigated_credential, leak\n- domains: domain\n", "items": { "type": "string" }, @@ -4163,20 +4163,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/TenantWithCounts" - } - } - }, - "operationId": "get_tenant_api_/tenants/", - "tags": [ - "tenants" - ] - }, "put": { "responses": { "200": { @@ -4200,6 +4186,20 @@ "tags": [ "tenants" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "$ref": "#/definitions/TenantWithCounts" + } + } + }, + "operationId": "get_tenant_api_/tenants/", + "tags": [ + "tenants" + ] } }, "/firework/v2/tenants/{tenant_id}/archive": { @@ -4232,20 +4232,6 @@ "type": "integer" } ], - "get": { - "responses": { - "200": { - "description": "Success", - "schema": { - "$ref": "#/definitions/TenantUsers" - } - } - }, - "operationId": "get_tenant_users_api_/tenants//users", - "tags": [ - "tenants" - ] - }, "post": { "responses": { "200": { @@ -4266,6 +4252,20 @@ "tags": [ "tenants" ] + }, + "get": { + "responses": { + "200": { + "description": "Success", + "schema": { + "$ref": "#/definitions/TenantUsers" + } + } + }, + "operationId": "get_tenant_users_api_/tenants//users", + "tags": [ + "tenants" + ] } }, "/firework/v2/tenants/{tenant_id}/users/{user_id}": { @@ -4429,35 +4429,35 @@ "type": "array", "items": { "type": "string", - "example": "ad", + "example": "forum_profile", "enum": [ + "forum_profile", + "invalid_credential", + "source_code_files", + "forum_post", + "bucket_object", + "social_media_account", "ad", - "paste", + "stack_exchange", + "bucket", + "google", "mitigated_credential", + "chat_message", + "seller", + "valid_credential", "ransomleak", - "stealer_log", + "blog_post", "listing", - "stack_exchange", - "forum_profile", - "financial_data", - "valid_credential", - "bucket", + "bot", + "leak", + "docker", "service", + "stealer_log", "forum_topic", + "financial_data", "source_code_secrets", - "social_media_account", "domain", - "seller", - "chat_message", - "bot", - "source_code_files", - "docker", - "google", - "bucket_object", - "leak", - "forum_post", - "blog_post", - "invalid_credential", + "paste", "illicit_networks", "open_web", "buckets", @@ -4536,34 +4536,34 @@ "type": "array", "items": { "type": "string", - "example": "ad", + "example": "forum_profile", "enum": [ - "paste", + "forum_profile", + "invalid_credential", + "source_code_files", + "forum_post", + "bucket_object", + "social_media_account", + "stack_exchange", + "bucket", + "google", "mitigated_credential", + "chat_message", + "seller", + "valid_credential", "ransomleak", - "stealer_log", + "blog_post", "listing", - "stack_exchange", - "forum_profile", - "financial_data", - "valid_credential", - "bucket", + "bot", + "leak", + "docker", "service", + "stealer_log", "forum_topic", + "financial_data", "source_code_secrets", - "social_media_account", "domain", - "seller", - "chat_message", - "bot", - "source_code_files", - "docker", - "google", - "bucket_object", - "leak", - "forum_post", - "blog_post", - "invalid_credential", + "paste", "illicit_networks", "open_web", "buckets", @@ -5110,24 +5110,6 @@ }, "type": "object" }, - "TenantWithCounts": { - "properties": { - "next": { - "type": "string" - }, - "items": { - "$ref": "#/definitions/TenantWithCounts" - }, - "total_count": { - "type": [ - "integer", - "null" - ], - "example": "nullable integer" - } - }, - "type": "object" - }, "Tenant": { "properties": { "id": { @@ -5212,6 +5194,24 @@ }, "type": "object" }, + "TenantWithCounts": { + "properties": { + "next": { + "type": "string" + }, + "items": { + "$ref": "#/definitions/TenantWithCounts" + }, + "total_count": { + "type": [ + "integer", + "null" + ], + "example": "nullable integer" + } + }, + "type": "object" + }, "UpdatedPermission": { "properties": { "updated_value": { @@ -5319,24 +5319,6 @@ }, "type": "object" }, - "OrganizationMemberPage": { - "properties": { - "members": { - "type": "array", - "items": { - "$ref": "#/definitions/OrganizationMemberWithMetadata" - } - }, - "next": { - "type": [ - "string", - "null" - ], - "example": "nullable string" - } - }, - "type": "object" - }, "OrganizationMemberWithMetadata": { "properties": { "user": { @@ -5404,6 +5386,24 @@ }, "type": "object" }, + "OrganizationMemberPage": { + "properties": { + "members": { + "type": "array", + "items": { + "$ref": "#/definitions/OrganizationMemberWithMetadata" + } + }, + "next": { + "type": [ + "string", + "null" + ], + "example": "nullable string" + } + }, + "type": "object" + }, "OrganizationMembersCount": { "properties": { "count": { diff --git a/docs/api-reference/spec/firework-v3-openapi.json b/docs/api-reference/spec/firework-v3-openapi.json index daf7fe44..759e230e 100644 --- a/docs/api-reference/spec/firework-v3-openapi.json +++ b/docs/api-reference/spec/firework-v3-openapi.json @@ -569,7 +569,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, ransomleak, stealer_log, listing, blog_post, bot, seller, chat_message, forum_profile, forum_post\n- open_web: service, bucket, google, stack_exchange, source_code_files, social_media_account, bucket_object, source_code_secrets, paste, docker\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", @@ -893,7 +893,7 @@ } }, { - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, ransomleak, stealer_log, listing, blog_post, bot, seller, chat_message, forum_profile, forum_post\n- open_web: service, bucket, google, stack_exchange, source_code_files, social_media_account, bucket_object, source_code_secrets, paste, docker\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "explode": true, "in": "query", "name": "types", diff --git a/docs/api-reference/spec/firework-v3-swagger.json b/docs/api-reference/spec/firework-v3-swagger.json index 69269e73..0aabc2b4 100644 --- a/docs/api-reference/spec/firework-v3-swagger.json +++ b/docs/api-reference/spec/firework-v3-swagger.json @@ -487,7 +487,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, ransomleak, stealer_log, listing, blog_post, bot, seller, chat_message, forum_profile, forum_post\n- open_web: service, bucket, google, stack_exchange, source_code_files, social_media_account, bucket_object, source_code_secrets, paste, docker\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, @@ -747,7 +747,7 @@ "name": "types", "in": "query", "type": "array", - "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: seller, ransomleak, chat_message, bot, stealer_log, listing, forum_profile, financial_data, forum_topic, forum_post, blog_post\n- open_web: stack_exchange, paste, source_code_files, docker, social_media_account, source_code_secrets, google, bucket_object, bucket, service\n- leaks: valid_credential, leak, invalid_credential, mitigated_credential\n- domains: domain\n", + "description": "\nType of activities to search through.\n\n*Expected values* : attachment, listing, ransomleak, forum_post, forum_topic, forum_profile, blog_post, seller, paste, leak, chat_message, domain, bot, stealer_log, infected_devices, driller, driller_forum_topic, driller_forum_post, driller_profile, cc, ccbin, financial_data, leaked_data, leaked_file, document, account, actor, forum_content, blog_content, profile, leaked_credential, valid_credential, invalid_credential, mitigated_credential, illicit_networks, open_web, domains, intelligence_object, leaks, social_media_account, social_media, source_code, source_code_secrets_np, source_code_secrets, source_code_files, docker, stack_exchange, google, service, driller_host, buckets, bucket, bucket_object, whois, cookie, pii, experimental\n\n*Some search types contain others*\n- illicit_networks: financial_data, forum_topic, ransomleak, stealer_log, listing, blog_post, bot, seller, chat_message, forum_profile, forum_post\n- open_web: service, bucket, google, stack_exchange, source_code_files, social_media_account, bucket_object, source_code_secrets, paste, docker\n- leaks: leak, mitigated_credential, invalid_credential, valid_credential\n- domains: domain\n", "items": { "type": "string" }, diff --git a/docs/api-reference/spec/firework-v4-openapi.json b/docs/api-reference/spec/firework-v4-openapi.json index 68ff076c..c4e7067e 100644 --- a/docs/api-reference/spec/firework-v4-openapi.json +++ b/docs/api-reference/spec/firework-v4-openapi.json @@ -374,6 +374,261 @@ } } }, + "/firework/v4/cti/entities": { + "get": { + "tags": [ + "public", + "team=data-intelligence" + ], + "summary": "List Entities", + "operationId": "list_entities_cti_entities_get", + "parameters": [ + { + "name": "query", + "in": "query", + "required": false, + "schema": { + "type": "string", + "default": "", + "title": "Query" + } + }, + { + "name": "types", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "type": "array", + "items": { + "$ref": "#/components/schemas/EntityType" + } + }, + { + "type": "null" + } + ], + "title": "Types" + } + }, + { + "name": "time_field", + "in": "query", + "required": false, + "schema": { + "$ref": "#/components/schemas/CTITimeField", + "default": "created_at" + } + }, + { + "name": "time_range", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "$ref": "#/components/schemas/TimeRangeType" + }, + { + "type": "null" + } + ], + "title": "Time Range" + } + }, + { + "name": "time_range_from", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Time Range From" + } + }, + { + "name": "time_range_to", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Time Range To" + } + }, + { + "name": "sources", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "type": "array", + "items": { + "type": "string" + } + }, + { + "type": "null" + } + ], + "title": "Sources" + } + }, + { + "name": "topic_ids", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "type": "array", + "items": { + "type": "string" + } + }, + { + "type": "null" + } + ], + "title": "Topic Ids" + } + }, + { + "name": "sort_by_key", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Sort By Key" + } + }, + { + "name": "sort_by_direction", + "in": "query", + "required": false, + "schema": { + "$ref": "#/components/schemas/OrderType", + "default": "desc" + } + }, + { + "name": "search_after", + "in": "query", + "required": false, + "schema": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Search After" + } + }, + { + "name": "size", + "in": "query", + "required": false, + "schema": { + "type": "integer", + "default": 10, + "title": "Size" + } + } + ], + "responses": { + "200": { + "description": "Successful Response", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResults_EntityLiteAPIResponseTypes_str_" + } + } + } + }, + "422": { + "description": "Validation Error", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/HTTPValidationError" + } + } + } + } + } + } + }, + "/firework/v4/cti/entities/{asset_uuid}": { + "get": { + "tags": [ + "public", + "team=data-intelligence" + ], + "summary": "Get Entity", + "operationId": "get_entity_cti_entities__asset_uuid__get", + "parameters": [ + { + "name": "asset_uuid", + "in": "path", + "required": true, + "schema": { + "type": "string", + "format": "uuid", + "title": "Asset Uuid" + } + } + ], + "responses": { + "200": { + "description": "Successful Response", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/EntityAPIResponseTypes" + } + } + } + }, + "422": { + "description": "Validation Error", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/HTTPValidationError" + } + } + } + } + } + } + }, "/firework/v4/events/": { "get": { "tags": [ @@ -2530,14 +2785,14 @@ } } }, - "/firework/v4/sandbox/submissions/{submission_uuid}/asset_sync": { + "/firework/v4/sandbox/submissions/{submission_uuid}/sync": { "post": { "tags": [ "public", "team=integration" ], - "summary": "Trigger Submission Asset Sync", - "operationId": "trigger_submission_asset_sync_sandbox_submissions__submission_uuid__asset_sync_post", + "summary": "Trigger Submission Sync", + "operationId": "trigger_submission_sync_sandbox_submissions__submission_uuid__sync_post", "parameters": [ { "name": "submission_uuid", @@ -2550,6 +2805,16 @@ } } ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/SandboxSyncRequest" + } + } + } + }, "responses": { "200": { "description": "Successful Response", @@ -2779,36 +3044,252 @@ ], "title": "ActivityModelName" }, - "AddressData": { + "ActorAPIResponse": { "properties": { - "type": { + "uuid": { "type": "string", - "const": "address_data", - "title": "Type", - "default": "address_data" + "title": "Uuid" }, - "street": { - "type": "string", - "minLength": 1, - "title": "Street" + "type": { + "$ref": "#/components/schemas/EntityType" }, - "city": { + "name": { "type": "string", - "minLength": 1, - "title": "City" + "title": "Name" }, - "country": { + "created_by": { "type": "string", - "maxLength": 2, - "minLength": 2, - "title": "Country" + "title": "Created By" }, - "state": { - "type": "string", - "minLength": 1, - "title": "State" - } - }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description" + ], + "title": "ActorAPIResponse" + }, + "ActorLiteAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description" + ], + "title": "ActorLiteAPIResponse" + }, + "AddressData": { + "properties": { + "type": { + "type": "string", + "const": "address_data", + "title": "Type", + "default": "address_data" + }, + "street": { + "type": "string", + "minLength": 1, + "title": "Street" + }, + "city": { + "type": "string", + "minLength": 1, + "title": "City" + }, + "country": { + "type": "string", + "maxLength": 2, + "minLength": 2, + "title": "Country" + }, + "state": { + "type": "string", + "minLength": 1, + "title": "State" + } + }, "type": "object", "required": [ "street", @@ -3567,63 +4048,295 @@ "type": "object", "title": "AstpDomainValue" }, - "AuthDomainQuery": { + "AttackPatternEntityAPIResponse": { "properties": { - "type": { + "uuid": { "type": "string", - "const": "auth_domain", - "title": "Type" + "title": "Uuid" }, - "fqdn": { - "type": "string", - "title": "Fqdn" - } - }, - "type": "object", - "required": [ - "type", - "fqdn" - ], - "title": "AuthDomainQuery" - }, - "AzureTenantData": { - "properties": { "type": { - "type": "string", - "const": "azure_tenant", - "title": "Type", - "default": "azure_tenant" + "$ref": "#/components/schemas/EntityType" }, - "tenant_id": { - "type": "string", - "minLength": 1, - "title": "Tenant Id" - } - }, - "type": "object", - "required": [ - "tenant_id" - ], - "title": "AzureTenantData" - }, - "AzureTenantQuery": { - "properties": { - "type": { + "name": { "type": "string", - "const": "azure_tenant", - "title": "Type" + "title": "Name" }, - "tenant_id": { + "created_by": { "type": "string", - "title": "Tenant Id" - } - }, - "type": "object", - "required": [ - "type", - "tenant_id" - ], - "title": "AzureTenantQuery" + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + }, + "kill_chain_phases": { + "items": { + "$ref": "#/components/schemas/KillChainAPIResponse" + }, + "type": "array", + "title": "Kill Chain Phases" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "kill_chain_phases", + "marking_definitions" + ], + "title": "AttackPatternEntityAPIResponse" + }, + "AttackPatternEntityLiteAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description" + ], + "title": "AttackPatternEntityLiteAPIResponse" + }, + "AuthDomainQuery": { + "properties": { + "type": { + "type": "string", + "const": "auth_domain", + "title": "Type" + }, + "fqdn": { + "type": "string", + "title": "Fqdn" + } + }, + "type": "object", + "required": [ + "type", + "fqdn" + ], + "title": "AuthDomainQuery" + }, + "AzureTenantData": { + "properties": { + "type": { + "type": "string", + "const": "azure_tenant", + "title": "Type", + "default": "azure_tenant" + }, + "tenant_id": { + "type": "string", + "minLength": 1, + "title": "Tenant Id" + } + }, + "type": "object", + "required": [ + "tenant_id" + ], + "title": "AzureTenantData" + }, + "AzureTenantQuery": { + "properties": { + "type": { + "type": "string", + "const": "azure_tenant", + "title": "Type" + }, + "tenant_id": { + "type": "string", + "title": "Tenant Id" + } + }, + "type": "object", + "required": [ + "type", + "tenant_id" + ], + "title": "AzureTenantQuery" }, "BinQuery": { "properties": { @@ -4068,7 +4781,6 @@ }, "type": "object", "required": [ - "url", "bucket" ], "title": "BucketObjectEventData" @@ -4093,253 +4805,329 @@ ], "title": "CCBinData" }, - "ChatMessageEvent": { + "CTIEntitySourceAPIResponse": { "properties": { - "event_type": { + "id": { "type": "string", - "const": "chat_message", - "title": "Event Type", - "default": "chat_message" - }, - "data": { - "$ref": "#/components/schemas/ChatMessageEventData" + "title": "Id" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - } - }, - "type": "object", - "required": [ - "data", - "metadata" - ], - "title": "Chat Message" - }, - "ChatMessageEventData": { - "properties": { - "posted_at": { + "name": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Posted At", - "description": "The time the chat message was posted." - }, - "actor": { - "$ref": "#/components/schemas/pyro__findings__chat_messages__datamodels__ChatMessageEventData__Actor", - "description": "Collection of data about the actor of the chat message." - }, - "context": { - "$ref": "#/components/schemas/pyro__findings__chat_messages__datamodels__ChatMessageEventData__Context", - "description": "Collection of data about the context of the chat message." + "title": "Name" }, - "content": { + "confidence": { "anyOf": [ { - "type": "string" + "type": "integer" }, { "type": "null" } ], - "title": "Content", - "description": "The content of the chat message." + "title": "Confidence" + } + }, + "type": "object", + "required": [ + "id" + ], + "title": "CTIEntitySourceAPIResponse" + }, + "CTITimeField": { + "type": "string", + "enum": [ + "created_at", + "updated_at", + "first_seen_at", + "last_seen_at" + ], + "title": "CTITimeField", + "description": "A time-based field of a CTI entity.\n\nThe enum *value* is the API/wire token (e.g. ``\"created_at\"``); use\n:pyattr:`es_field` for the Elasticsearch field path (``metadata.created_at``)." + }, + "CampaignEntityAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" }, - "parent_context": { - "$ref": "#/components/schemas/ParentContext", - "description": "Collection of data about the context of the parent chat message." + "type": { + "$ref": "#/components/schemas/EntityType" }, - "forward_info": { - "$ref": "#/components/schemas/ForwardInfo", - "description": "Collection of data about the forward information of the chat message." + "name": { + "type": "string", + "title": "Name" }, - "was_forwarded": { + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Was Forwarded", - "description": "Whether the chat message was forwarded." - } - }, - "type": "object", - "title": "ChatMessageEventData" - }, - "Classes": { - "properties": { - "is_carding": { + "title": "Created At" + }, + "updated_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Is Carding", - "description": "Whether the listing is classified as carding." + "title": "Updated At" }, - "is_bypass": { + "first_seen_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Is Bypass", - "description": "Whether the listing is classified as a bypass." + "title": "First Seen At" }, - "is_ident_fraud": { + "last_seen_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Is Ident Fraud", - "description": "Whether the listing is classified as identity fraud." + "title": "Last Seen At" }, - "is_doc_fraud": { + "confidence": { "anyOf": [ { - "type": "boolean" + "type": "integer" }, { "type": "null" } ], - "title": "Is Doc Fraud", - "description": "Whether the listing is classified as document fraud." + "title": "Confidence" }, - "is_phishing": { + "description": { "anyOf": [ { - "type": "boolean" + "type": "string" }, { "type": "null" } ], - "title": "Is Phishing", - "description": "Whether the listing is classified as phishing." + "title": "Description" }, - "is_money_xfer": { + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases", + "marking_definitions" + ], + "title": "CampaignEntityAPIResponse" + }, + "CampaignEntityLiteAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Is Money Xfer", - "description": "Whether the listing is classified as money transfer." + "title": "Created At" }, - "is_cashout": { + "updated_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Is Cashout", - "description": "Whether the listing is classified as a cashout." + "title": "Updated At" }, - "is_virt_currency": { + "first_seen_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Is Virt Currency", - "description": "Whether the listing is classified as a virtual currency transaction." + "title": "First Seen At" }, - "is_hacking": { + "last_seen_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Is Hacking", - "description": "Whether the listing is classified as hacking activities." + "title": "Last Seen At" }, - "is_misc_financial": { + "confidence": { "anyOf": [ { - "type": "boolean" + "type": "integer" }, { "type": "null" } ], - "title": "Is Misc Financial", - "description": "Whether the listing is classified as miscellaneous financial activities." - } - }, - "type": "object", - "title": "Classes" - }, - "Classification": { - "properties": { - "classes": { - "$ref": "#/components/schemas/Classes", - "description": "Data about the classes identified in the listing." + "title": "Confidence" }, - "types": { - "$ref": "#/components/schemas/Types", - "description": "Data about the possible listing type." + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + }, + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" } }, "type": "object", - "title": "Classification" + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases" + ], + "title": "CampaignEntityLiteAPIResponse" }, - "ConversationMessage": { + "ChatChannelEntityAPIResponse": { "properties": { - "uid": { + "uuid": { "type": "string", - "title": "Uid" + "title": "Uuid" }, - "message": { + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { "type": "string", - "title": "Message" + "title": "Name" }, - "message_en": { + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Message En" - }, - "author_name": { - "type": "string", - "title": "Author Name" + "title": "Created At" }, - "date_time": { + "updated_at": { "anyOf": [ { "type": "string", @@ -4349,472 +5137,487 @@ "type": "null" } ], - "title": "Date Time" - } - }, - "type": "object", - "required": [ - "uid", - "message", - "author_name", - "date_time" - ], - "title": "ConversationMessage" - }, - "ConversationSearchAfterDirection": { - "type": "string", - "enum": [ - "next", - "previous" - ], - "title": "ConversationSearchAfterDirection" - }, - "CreateAlertChannel": { - "properties": { - "name": { - "type": "string", - "title": "Name" + "title": "Updated At" }, - "params": { - "oneOf": [ + "first_seen_at": { + "anyOf": [ { - "$ref": "#/components/schemas/AlertChannelEmailParams" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/AlertChannelSlackParams" - }, + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ { - "$ref": "#/components/schemas/AlertChannelDiscordParams" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/AlertChannelSplunkParams" - }, + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ { - "$ref": "#/components/schemas/AlertChannelChannelParams" + "type": "integer" }, { - "$ref": "#/components/schemas/AlertChannelLegacySentinelParams" - }, + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ { - "$ref": "#/components/schemas/AlertChannelSentinelV2Params" + "type": "string" }, { - "$ref": "#/components/schemas/AlertChannelTeamsParams" - }, + "type": "null" + } + ], + "title": "Description" + }, + "topics": { + "items": { + "$ref": "#/components/schemas/ThreadTopic" + }, + "type": "array", + "title": "Topics" + }, + "conversation_link": { + "anyOf": [ { - "$ref": "#/components/schemas/AlertChannelJiraParams" + "type": "string" }, { - "$ref": "#/components/schemas/AlertChannelServiceNowParams" + "type": "null" + } + ], + "title": "Conversation Link" + }, + "chat_channel_profile_overview": { + "anyOf": [ + { + "type": "string" }, { - "$ref": "#/components/schemas/AlertChannelWebhookParams" + "type": "null" } ], - "title": "Params", - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_sentinel": "#/components/schemas/AlertChannelLegacySentinelParams", - "azure_sentinel_v2": "#/components/schemas/AlertChannelSentinelV2Params", - "channel": "#/components/schemas/AlertChannelChannelParams", - "discord": "#/components/schemas/AlertChannelDiscordParams", - "email": "#/components/schemas/AlertChannelEmailParams", - "jira": "#/components/schemas/AlertChannelJiraParams", - "servicenow": "#/components/schemas/AlertChannelServiceNowParams", - "slack": "#/components/schemas/AlertChannelSlackParams", - "splunk": "#/components/schemas/AlertChannelSplunkParams", - "teams": "#/components/schemas/AlertChannelTeamsParams", - "webhook": "#/components/schemas/AlertChannelWebhookParams" + "title": "Chat Channel Profile Overview" + }, + "chat_channel_profile_content_and_activity": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" } - } + ], + "title": "Chat Channel Profile Content And Activity" }, - "state": { + "chat_channel_profile_nature_and_sophistication": { "anyOf": [ { - "$ref": "#/components/schemas/AlertChannelState" + "type": "string" }, { "type": "null" } - ] + ], + "title": "Chat Channel Profile Nature And Sophistication" } }, "type": "object", "required": [ + "uuid", + "type", "name", - "params" + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "topics", + "conversation_link", + "chat_channel_profile_overview", + "chat_channel_profile_content_and_activity", + "chat_channel_profile_nature_and_sophistication" ], - "title": "CreateAlertChannel" + "title": "ChatChannelEntityAPIResponse" }, - "CreateAstpCookiesBody": { + "ChatChannelEntityLiteAPIResponse": { "properties": { - "name": { + "uuid": { "type": "string", - "minLength": 1, - "title": "Name", - "description": "The name of the matching policy" + "title": "Uuid" }, "type": { - "type": "string", - "const": "ASTP_COOKIES", - "title": "Type" + "$ref": "#/components/schemas/EntityType" }, - "value": { - "$ref": "#/components/schemas/AstpCookiesValue", - "description": "The value of the matching policy in the form of cookie names" - } - }, - "type": "object", - "required": [ - "name", - "type", - "value" - ], - "title": "CreateAstpCookiesBody" - }, - "CreateAstpDomainBody": { - "properties": { "name": { "type": "string", - "minLength": 1, - "title": "Name", - "description": "The name of the matching policy" + "title": "Name" }, - "type": { + "created_by": { "type": "string", - "const": "ASTP_DOMAIN", - "title": "Type" + "title": "Created By" }, - "value": { - "$ref": "#/components/schemas/AstpDomainValue", - "description": "The value of the matching policy in the form of a domain match mode" + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + }, + "topics": { + "items": { + "$ref": "#/components/schemas/ThreadTopic" + }, + "type": "array", + "title": "Topics" } }, "type": "object", "required": [ - "name", + "uuid", "type", - "value" + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "topics" ], - "title": "CreateAstpDomainBody" + "title": "ChatChannelEntityLiteAPIResponse" }, - "CreateExcludedKeywordsBody": { + "ChatMessageEvent": { "properties": { - "name": { + "event_type": { "type": "string", - "minLength": 1, - "title": "Name", - "description": "The name of the matching policy" + "const": "chat_message", + "title": "Event Type", + "default": "chat_message" }, - "type": { - "type": "string", - "const": "EXCLUDED_KEYWORDS", - "title": "Type" + "data": { + "$ref": "#/components/schemas/ChatMessageEventData" }, - "value": { - "$ref": "#/components/schemas/KeywordsValue", - "description": "The value of the matching policy in the form of keywords" + "metadata": { + "$ref": "#/components/schemas/EventMetadata" } }, "type": "object", "required": [ - "name", - "type", - "value" + "data", + "metadata" ], - "title": "CreateExcludedKeywordsBody" + "title": "Chat Message" }, - "CreateIncludedKeywordsBody": { + "ChatMessageEventData": { "properties": { - "name": { - "type": "string", - "minLength": 1, - "title": "Name", - "description": "The name of the matching policy" + "posted_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Posted At", + "description": "The time the chat message was posted." }, - "type": { - "type": "string", - "const": "INCLUDED_KEYWORDS", - "title": "Type" + "actor": { + "$ref": "#/components/schemas/pyro__findings__chat_messages__datamodels__ChatMessageEventData__Actor", + "description": "Collection of data about the actor of the chat message." }, - "value": { - "$ref": "#/components/schemas/KeywordsValue", - "description": "The value of the matching policy in the form of keywords" - } - }, - "type": "object", - "required": [ - "name", - "type", - "value" - ], - "title": "CreateIncludedKeywordsBody" - }, - "CreateLuceneQueryBody": { - "properties": { - "name": { - "type": "string", - "minLength": 1, - "title": "Name", - "description": "The name of the matching policy" + "context": { + "$ref": "#/components/schemas/pyro__findings__chat_messages__datamodels__ChatMessageEventData__Context", + "description": "Collection of data about the context of the chat message." }, - "type": { - "type": "string", - "const": "LUCENE_QUERY", - "title": "Type" + "content": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Content", + "description": "The content of the chat message." }, - "value": { - "$ref": "#/components/schemas/LuceneValue", - "description": "The value of the matching policy in the form of a Lucene query" + "parent_context": { + "$ref": "#/components/schemas/ParentContext", + "description": "Collection of data about the context of the parent chat message." + }, + "forward_info": { + "$ref": "#/components/schemas/ForwardInfo", + "description": "Collection of data about the forward information of the chat message." + }, + "was_forwarded": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Was Forwarded", + "description": "Whether the chat message was forwarded." } }, "type": "object", - "required": [ - "name", - "type", - "value" - ], - "title": "CreateLuceneQueryBody" + "title": "ChatMessageEventData" }, - "Credential": { + "Classes": { "properties": { - "id": { - "type": "integer", - "title": "Id" - }, - "identity_name": { - "type": "string", - "title": "Identity Name" - }, - "domain": { + "is_carding": { "anyOf": [ { - "type": "string" + "type": "boolean" }, { "type": "null" } ], - "title": "Domain" - }, - "source_id": { - "type": "string", - "title": "Source Id" + "title": "Is Carding", + "description": "Whether the listing is classified as carding." }, - "imported_at": { - "type": "string", - "title": "Imported At" + "is_bypass": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Is Bypass", + "description": "Whether the listing is classified as a bypass." }, - "hash": { + "is_ident_fraud": { "anyOf": [ { - "type": "string" + "type": "boolean" }, { "type": "null" } ], - "title": "Hash" + "title": "Is Ident Fraud", + "description": "Whether the listing is classified as identity fraud." }, - "hash_type": { + "is_doc_fraud": { "anyOf": [ { - "type": "string" + "type": "boolean" }, { "type": "null" } ], - "title": "Hash Type" + "title": "Is Doc Fraud", + "description": "Whether the listing is classified as document fraud." }, - "source": { + "is_phishing": { "anyOf": [ { - "$ref": "#/components/schemas/SourceV2" + "type": "boolean" }, { "type": "null" } - ] + ], + "title": "Is Phishing", + "description": "Whether the listing is classified as phishing." }, - "known_password_id": { + "is_money_xfer": { "anyOf": [ { - "type": "integer" + "type": "boolean" }, { "type": "null" } ], - "title": "Known Password Id" + "title": "Is Money Xfer", + "description": "Whether the listing is classified as money transfer." }, - "credential_hash": { + "is_cashout": { "anyOf": [ { - "type": "string" + "type": "boolean" }, { "type": "null" } ], - "title": "Credential Hash" + "title": "Is Cashout", + "description": "Whether the listing is classified as a cashout." }, - "event_uid": { + "is_virt_currency": { "anyOf": [ { - "type": "string" + "type": "boolean" }, { "type": "null" } ], - "title": "Event Uid" + "title": "Is Virt Currency", + "description": "Whether the listing is classified as a virtual currency transaction." }, - "auth_domains": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Auth Domains" + "is_hacking": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Is Hacking", + "description": "Whether the listing is classified as hacking activities." }, - "urls": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Urls" + "is_misc_financial": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Is Misc Financial", + "description": "Whether the listing is classified as miscellaneous financial activities." } }, "type": "object", - "required": [ - "id", - "identity_name", - "domain", - "source_id", - "imported_at", - "hash", - "hash_type", - "source", - "known_password_id", - "credential_hash", - "event_uid" - ], - "title": "Credential" + "title": "Classes" }, - "CredentialActionBody": { + "Classification": { "properties": { - "type": { - "$ref": "#/components/schemas/LeakedCredentialsBulkActionType" + "classes": { + "$ref": "#/components/schemas/Classes", + "description": "Data about the classes identified in the listing." + }, + "types": { + "$ref": "#/components/schemas/Types", + "description": "Data about the possible listing type." } }, "type": "object", - "required": [ - "type" - ], - "title": "CredentialActionBody" + "title": "Classification" }, - "CredentialActionRequestBody": { + "ConversationMessage": { "properties": { - "targets": { - "items": { - "$ref": "#/components/schemas/CredentialActionTarget" - }, - "type": "array", - "maxItems": 100, - "title": "Targets" + "uid": { + "type": "string", + "title": "Uid" }, - "action": { - "$ref": "#/components/schemas/CredentialActionBody" - } - }, - "type": "object", - "required": [ - "targets", - "action" - ], - "title": "CredentialActionRequestBody" - }, - "CredentialActionTarget": { - "properties": { - "credential_hash": { - "type": "string", - "title": "Credential Hash" - } - }, - "type": "object", - "required": [ - "credential_hash" - ], - "title": "CredentialActionTarget" - }, - "CredentialEventData": { - "properties": { - "identity_name": { - "type": "string", - "title": "Identity Name", - "description": "The email or username associated with the credential." - }, - "credential_hash": { - "type": "string", - "title": "Credential Hash", - "description": "A hash uniquely identifying the credential." - }, - "tenant_integration_id": { - "type": "string", - "title": "Tenant Integration Id", - "description": "The UUID of the tenant's IdP integration that validated the credential." - } - }, - "type": "object", - "required": [ - "identity_name", - "credential_hash", - "tenant_integration_id" - ], - "title": "CredentialEventData" - }, - "CredentialsData": { - "properties": { - "type": { - "type": "string", - "const": "credentials", - "title": "Type", - "default": "credentials" - }, - "username": { + "message": { "type": "string", - "minLength": 1, - "title": "Username" + "title": "Message" }, - "password": { - "type": "string", - "minLength": 1, - "title": "Password" - } - }, - "type": "object", - "required": [ - "username", - "password" - ], - "title": "CredentialsData" - }, - "CredentialsDateFilter": { - "properties": { - "gte": { + "message_en": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Gte" + "title": "Message En" }, - "lte": { + "author_name": { + "type": "string", + "title": "Author Name" + }, + "date_time": { "anyOf": [ { "type": "string", @@ -4824,252 +5627,245 @@ "type": "null" } ], - "title": "Lte" - } - }, - "type": "object", - "title": "CredentialsDateFilter" - }, - "CredentialsQuery": { - "properties": { - "type": { - "type": "string", - "const": "credentials", - "title": "Type" - }, - "username": { - "type": "string", - "title": "Username" - }, - "password": { - "type": "string", - "title": "Password" + "title": "Date Time" } }, "type": "object", "required": [ - "type", - "username", - "password" + "uid", + "message", + "author_name", + "date_time" ], - "title": "CredentialsQuery" + "title": "ConversationMessage" }, - "CredentialsQueryFilters": { - "properties": { - "imported_at": { - "$ref": "#/components/schemas/CredentialsDateFilter" - } - }, - "type": "object", - "title": "CredentialsQueryFilters" + "ConversationSearchAfterDirection": { + "type": "string", + "enum": [ + "next", + "previous" + ], + "title": "ConversationSearchAfterDirection" }, - "CredentialsQueryPayload": { + "CreateAlertChannel": { "properties": { - "query": { + "name": { + "type": "string", + "title": "Name" + }, + "params": { "oneOf": [ { - "$ref": "#/components/schemas/DomainQuery" + "$ref": "#/components/schemas/AlertChannelEmailParams" }, { - "$ref": "#/components/schemas/EmailQuery" + "$ref": "#/components/schemas/AlertChannelSlackParams" }, { - "$ref": "#/components/schemas/KeywordQuery" + "$ref": "#/components/schemas/AlertChannelDiscordParams" }, { - "$ref": "#/components/schemas/SecretQuery" + "$ref": "#/components/schemas/AlertChannelSplunkParams" }, { - "$ref": "#/components/schemas/AuthDomainQuery" + "$ref": "#/components/schemas/AlertChannelChannelParams" + }, + { + "$ref": "#/components/schemas/AlertChannelLegacySentinelParams" + }, + { + "$ref": "#/components/schemas/AlertChannelSentinelV2Params" + }, + { + "$ref": "#/components/schemas/AlertChannelTeamsParams" + }, + { + "$ref": "#/components/schemas/AlertChannelJiraParams" + }, + { + "$ref": "#/components/schemas/AlertChannelServiceNowParams" + }, + { + "$ref": "#/components/schemas/AlertChannelWebhookParams" } ], - "title": "Query", + "title": "Params", "discriminator": { "propertyName": "type", "mapping": { - "auth_domain": "#/components/schemas/AuthDomainQuery", - "domain": "#/components/schemas/DomainQuery", - "email": "#/components/schemas/EmailQuery", - "keyword": "#/components/schemas/KeywordQuery", - "secret": "#/components/schemas/SecretQuery" + "azure_sentinel": "#/components/schemas/AlertChannelLegacySentinelParams", + "azure_sentinel_v2": "#/components/schemas/AlertChannelSentinelV2Params", + "channel": "#/components/schemas/AlertChannelChannelParams", + "discord": "#/components/schemas/AlertChannelDiscordParams", + "email": "#/components/schemas/AlertChannelEmailParams", + "jira": "#/components/schemas/AlertChannelJiraParams", + "servicenow": "#/components/schemas/AlertChannelServiceNowParams", + "slack": "#/components/schemas/AlertChannelSlackParams", + "splunk": "#/components/schemas/AlertChannelSplunkParams", + "teams": "#/components/schemas/AlertChannelTeamsParams", + "webhook": "#/components/schemas/AlertChannelWebhookParams" } } }, - "filters": { - "$ref": "#/components/schemas/CredentialsQueryFilters" - }, - "from": { + "state": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/AlertChannelState" }, { "type": "null" } - ], - "title": "From" - }, - "size": { - "type": "integer", - "maximum": 10000.0, - "minimum": 1.0, - "title": "Size", - "default": 10 - }, - "include": { - "items": { - "$ref": "#/components/schemas/IncludeOptions" - }, - "type": "array", - "title": "Include" - }, - "order": { - "$ref": "#/components/schemas/OrderType", - "default": "desc" + ] } }, "type": "object", "required": [ - "query" + "name", + "params" ], - "title": "CredentialsQueryPayload" + "title": "CreateAlertChannel" }, - "DockerImageEvent": { + "CreateAstpCookiesBody": { "properties": { - "event_type": { + "name": { "type": "string", - "const": "docker_image", - "title": "Event Type", - "default": "docker_image" + "minLength": 1, + "title": "Name", + "description": "The name of the matching policy" }, - "data": { - "$ref": "#/components/schemas/DockerImageEventData" + "type": { + "type": "string", + "const": "ASTP_COOKIES", + "title": "Type" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "value": { + "$ref": "#/components/schemas/AstpCookiesValue", + "description": "The value of the matching policy in the form of cookie names" } }, "type": "object", "required": [ - "data", - "metadata" + "name", + "type", + "value" ], - "title": "Docker Image" + "title": "CreateAstpCookiesBody" }, - "DockerImageEventData": { + "CreateAstpDomainBody": { "properties": { - "content": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Content" + "name": { + "type": "string", + "minLength": 1, + "title": "Name", + "description": "The name of the matching policy" }, - "digest": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Digest" + "type": { + "type": "string", + "const": "ASTP_DOMAIN", + "title": "Type" }, - "architecture": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Architecture" + "value": { + "$ref": "#/components/schemas/AstpDomainValue", + "description": "The value of the matching policy in the form of a domain match mode" + } + }, + "type": "object", + "required": [ + "name", + "type", + "value" + ], + "title": "CreateAstpDomainBody" + }, + "CreateExcludedKeywordsBody": { + "properties": { + "name": { + "type": "string", + "minLength": 1, + "title": "Name", + "description": "The name of the matching policy" }, - "os": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Os" + "type": { + "type": "string", + "const": "EXCLUDED_KEYWORDS", + "title": "Type" }, - "last_pushed_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Pushed At" + "value": { + "$ref": "#/components/schemas/KeywordsValue", + "description": "The value of the matching policy in the form of keywords" + } + }, + "type": "object", + "required": [ + "name", + "type", + "value" + ], + "title": "CreateExcludedKeywordsBody" + }, + "CreateIncludedKeywordsBody": { + "properties": { + "name": { + "type": "string", + "minLength": 1, + "title": "Name", + "description": "The name of the matching policy" }, - "last_pulled_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Last Pulled At" + "type": { + "type": "string", + "const": "INCLUDED_KEYWORDS", + "title": "Type" }, - "tags": { - "anyOf": [ - { - "items": { - "$ref": "#/components/schemas/Tag" - }, - "type": "array" - }, - { - "type": "null" - } - ], - "title": "Tags", - "default": [] + "value": { + "$ref": "#/components/schemas/KeywordsValue", + "description": "The value of the matching policy in the form of keywords" } }, "type": "object", - "title": "DockerImageEventData" + "required": [ + "name", + "type", + "value" + ], + "title": "CreateIncludedKeywordsBody" }, - "DockerRepositoryEvent": { + "CreateLuceneQueryBody": { "properties": { - "event_type": { + "name": { "type": "string", - "const": "docker_repository", - "title": "Event Type", - "default": "docker_repository" + "minLength": 1, + "title": "Name", + "description": "The name of the matching policy" }, - "data": { - "$ref": "#/components/schemas/DockerRepositoryEventData" + "type": { + "type": "string", + "const": "LUCENE_QUERY", + "title": "Type" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "value": { + "$ref": "#/components/schemas/LuceneValue", + "description": "The value of the matching policy in the form of a Lucene query" } }, "type": "object", "required": [ - "data", - "metadata" + "name", + "type", + "value" ], - "title": "Docker Repository" + "title": "CreateLuceneQueryBody" }, - "DockerRepositoryEventData": { + "Credential": { "properties": { - "url": { + "id": { + "type": "integer", + "title": "Id" + }, + "identity_name": { + "type": "string", + "title": "Identity Name" + }, + "domain": { "anyOf": [ { "type": "string" @@ -5078,324 +5874,213 @@ "type": "null" } ], - "title": "Url", - "description": "The URL of the Docker repository." + "title": "Domain" }, - "star_count": { + "source_id": { + "type": "string", + "title": "Source Id" + }, + "imported_at": { + "type": "string", + "title": "Imported At" + }, + "hash": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Star Count", - "description": "The number of stars the repository has received." + "title": "Hash" }, - "pull_count": { + "hash_type": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Pull Count", - "description": "The total number of pulls made against the repository." + "title": "Hash Type" }, - "collaborator_count": { + "source": { "anyOf": [ { - "type": "integer" + "$ref": "#/components/schemas/SourceV2" }, { "type": "null" } - ], - "title": "Collaborator Count", - "description": "The number of collaborators associated with the repository." + ] }, - "last_updated_at": { + "known_password_id": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "integer" }, { "type": "null" } ], - "title": "Last Updated At", - "description": "The timestamp at which the repository was last updated." + "title": "Known Password Id" }, - "last_modified_at": { + "credential_hash": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Last Modified At", - "description": "The timestamp at which the repository's metadata was last modified." + "title": "Credential Hash" }, - "registered_at": { + "event_uid": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Registered At", - "description": "The timestamp at which the repository was first registered." - } - }, - "type": "object", - "title": "DockerRepositoryEventData" - }, - "DomainAssetEnrichment": { - "properties": { - "type": { - "$ref": "#/components/schemas/AssetEnrichmentType" + "title": "Event Uid" }, - "sources": { + "auth_domains": { "items": { "type": "string" }, "type": "array", - "title": "Sources" + "title": "Auth Domains" }, - "entries": { + "urls": { "items": { "type": "string" }, "type": "array", - "title": "Entries" - }, - "tags": { - "items": { - "$ref": "#/components/schemas/SubdomainTag" - }, - "type": "array", - "title": "Tags" - }, - "statuses": { - "items": { - "$ref": "#/components/schemas/SubdomainStatus" - }, - "type": "array", - "title": "Statuses" - }, - "external_links": { - "items": { - "type": "string" - }, - "type": "array", - "title": "External Links" - }, - "title": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Title" + "title": "Urls" } }, "type": "object", "required": [ - "type", - "sources", - "entries", - "tags", - "statuses", - "external_links", - "title" + "id", + "identity_name", + "domain", + "source_id", + "imported_at", + "hash", + "hash_type", + "source", + "known_password_id", + "credential_hash", + "event_uid" ], - "title": "DomainAssetEnrichment" + "title": "Credential" }, - "DomainData": { + "CredentialActionBody": { "properties": { "type": { - "type": "string", - "const": "domain", - "title": "Type", - "default": "domain" - }, - "fqdn": { - "type": "string", - "minLength": 1, - "title": "Fqdn" + "$ref": "#/components/schemas/LeakedCredentialsBulkActionType" } }, "type": "object", "required": [ - "fqdn" - ], - "title": "DomainData" - }, - "DomainMatchMode": { - "type": "string", - "enum": [ - "email_domain_only", - "auth_domain_and_email_domain", - "auth_domain_only" + "type" ], - "title": "DomainMatchMode" + "title": "CredentialActionBody" }, - "DomainQuery": { + "CredentialActionRequestBody": { "properties": { - "type": { - "type": "string", - "const": "domain", - "title": "Type" + "targets": { + "items": { + "$ref": "#/components/schemas/CredentialActionTarget" + }, + "type": "array", + "maxItems": 100, + "title": "Targets" }, - "fqdn": { - "type": "string", - "title": "Fqdn" + "action": { + "$ref": "#/components/schemas/CredentialActionBody" } }, "type": "object", "required": [ - "type", - "fqdn" - ], - "title": "DomainQuery" - }, - "DomainStatus": { - "type": "string", - "enum": [ - "found", - "resolves", - "reachable" + "targets", + "action" ], - "title": "DomainStatus" + "title": "CredentialActionRequestBody" }, - "EmailData": { + "CredentialActionTarget": { "properties": { - "type": { - "type": "string", - "const": "email", - "title": "Type", - "default": "email" - }, - "email": { + "credential_hash": { "type": "string", - "format": "email", - "title": "Email" + "title": "Credential Hash" } }, "type": "object", "required": [ - "email" + "credential_hash" ], - "title": "EmailData" + "title": "CredentialActionTarget" }, - "EmailQuery": { + "CredentialEventData": { "properties": { - "type": { + "identity_name": { "type": "string", - "const": "email", - "title": "Type" + "title": "Identity Name", + "description": "The email or username associated with the credential." }, - "email": { + "credential_hash": { "type": "string", - "title": "Email" - } - }, - "type": "object", - "required": [ - "type", - "email" - ], - "title": "EmailQuery" - }, - "EmptyFireworkEvent": { - "properties": { - "event_type": { - "$ref": "#/components/schemas/ActivityModelName" - }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "title": "Credential Hash", + "description": "A hash uniquely identifying the credential." }, - "data": { - "additionalProperties": true, - "type": "object", - "title": "Data" + "tenant_integration_id": { + "type": "string", + "title": "Tenant Integration Id", + "description": "The UUID of the tenant's IdP integration that validated the credential." } }, "type": "object", "required": [ - "event_type", - "metadata" + "identity_name", + "credential_hash", + "tenant_integration_id" ], - "title": "EmptyFireworkEvent" + "title": "CredentialEventData" }, - "EventAction": { + "CredentialsData": { "properties": { "type": { "type": "string", - "enum": [ - "remediate", - "unremediate", - "ignore", - "unignore" - ], - "title": "Type" - } - }, - "type": "object", - "required": [ - "type" - ], - "title": "EventAction" - }, - "EventActionTarget": { - "properties": { - "uid": { + "const": "credentials", + "title": "Type", + "default": "credentials" + }, + "username": { "type": "string", - "title": "Uid" - } - }, - "type": "object", - "required": [ - "uid" - ], - "title": "EventActionTarget" - }, - "EventActionsBody": { - "properties": { - "targets": { - "items": { - "$ref": "#/components/schemas/EventActionTarget" - }, - "type": "array", - "maxItems": 10, - "title": "Targets" + "minLength": 1, + "title": "Username" }, - "action": { - "$ref": "#/components/schemas/EventAction" + "password": { + "type": "string", + "minLength": 1, + "title": "Password" } }, "type": "object", "required": [ - "action" + "username", + "password" ], - "title": "EventActionsBody" + "title": "CredentialsData" }, - "EventMetadata": { + "CredentialsDateFilter": { "properties": { - "estimated_created_at": { + "gte": { "anyOf": [ { "type": "string", @@ -5405,16 +6090,9 @@ "type": "null" } ], - "title": "Estimated Created At" - }, - "flare_url": { - "type": "string", - "maxLength": 2083, - "minLength": 1, - "format": "uri", - "title": "Flare Url" + "title": "Gte" }, - "matched_at": { + "lte": { "anyOf": [ { "type": "string", @@ -5424,143 +6102,185 @@ "type": "null" } ], - "title": "Matched At" + "title": "Lte" + } + }, + "type": "object", + "title": "CredentialsDateFilter" + }, + "CredentialsQuery": { + "properties": { + "type": { + "type": "string", + "const": "credentials", + "title": "Type" }, - "severity": { - "$ref": "#/components/schemas/EventSeverity" + "username": { + "type": "string", + "title": "Username" }, - "uid": { + "password": { "type": "string", - "title": "Uid" + "title": "Password" } }, "type": "object", "required": [ - "flare_url", - "severity", - "uid" - ], - "title": "EventMetadata" - }, - "EventSeverity": { - "type": "string", - "enum": [ - "info", - "low", - "medium", - "high", - "critical" - ], - "title": "EventSeverity" - }, - "ExpandableField": { - "type": "string", - "enum": [ - "credentials", - "cookies" + "type", + "username", + "password" ], - "title": "ExpandableField" + "title": "CredentialsQuery" }, - "ExternalIdData": { + "CredentialsQueryFilters": { "properties": { - "type": { - "type": "string", - "const": "external_id", - "title": "Type", - "default": "external_id" - }, - "id": { - "type": "string", - "minLength": 1, - "title": "Id" - }, - "source": { - "type": "string", - "minLength": 1, - "title": "Source" + "imported_at": { + "$ref": "#/components/schemas/CredentialsDateFilter" } }, "type": "object", - "required": [ - "id", - "source" - ], - "title": "ExternalIdData" + "title": "CredentialsQueryFilters" }, - "FeedConfiguration": { + "CredentialsQueryPayload": { "properties": { - "search_types": { - "items": { - "$ref": "#/components/schemas/SearchType" - }, - "type": "array", - "title": "Search Types" - }, - "experimental_search_types": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Experimental Search Types" + "query": { + "oneOf": [ + { + "$ref": "#/components/schemas/DomainQuery" + }, + { + "$ref": "#/components/schemas/EmailQuery" + }, + { + "$ref": "#/components/schemas/KeywordQuery" + }, + { + "$ref": "#/components/schemas/SecretQuery" + }, + { + "$ref": "#/components/schemas/AuthDomainQuery" + } + ], + "title": "Query", + "discriminator": { + "propertyName": "type", + "mapping": { + "auth_domain": "#/components/schemas/AuthDomainQuery", + "domain": "#/components/schemas/DomainQuery", + "email": "#/components/schemas/EmailQuery", + "keyword": "#/components/schemas/KeywordQuery", + "secret": "#/components/schemas/SecretQuery" + } + } }, - "risks": { - "items": { - "$ref": "#/components/schemas/RiskScore" - }, - "type": "array", - "title": "Risks" + "filters": { + "$ref": "#/components/schemas/CredentialsQueryFilters" }, - "blacklist": { + "from": { "anyOf": [ { - "items": { - "type": "string" - }, - "type": "array" + "type": "string" }, { "type": "null" } ], - "title": "Blacklist" + "title": "From" + }, + "size": { + "type": "integer", + "maximum": 10000.0, + "minimum": 1.0, + "title": "Size", + "default": 10 + }, + "include": { + "items": { + "$ref": "#/components/schemas/IncludeOptions" + }, + "type": "array", + "title": "Include" + }, + "order": { + "$ref": "#/components/schemas/OrderType", + "default": "desc" } }, "type": "object", "required": [ - "search_types", - "experimental_search_types", - "risks", - "blacklist" + "query" ], - "title": "FeedConfiguration" + "title": "CredentialsQueryPayload" }, - "FeedDateFilter": { + "DockerImageEvent": { "properties": { - "gt": { + "event_type": { + "type": "string", + "const": "docker_image", + "title": "Event Type", + "default": "docker_image" + }, + "data": { + "$ref": "#/components/schemas/DockerImageEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Docker Image" + }, + "DockerImageEventData": { + "properties": { + "content": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Gt" + "title": "Content" }, - "gte": { + "digest": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Gte" + "title": "Digest" }, - "lt": { + "architecture": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Architecture" + }, + "os": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Os" + }, + "last_pushed_at": { "anyOf": [ { "type": "string", @@ -5570,9 +6290,9 @@ "type": "null" } ], - "title": "Lt" + "title": "Last Pushed At" }, - "lte": { + "last_pulled_at": { "anyOf": [ { "type": "string", @@ -5582,211 +6302,113 @@ "type": "null" } ], - "title": "Lte" - } - }, - "type": "object", - "title": "FeedDateFilter" - }, - "FeedDefinition": { - "properties": { - "type": { - "$ref": "#/components/schemas/FeedType" + "title": "Last Pulled At" }, - "id": { + "tags": { "anyOf": [ { - "type": "integer" + "items": { + "$ref": "#/components/schemas/Tag" + }, + "type": "array" }, { "type": "null" } ], - "title": "Id" + "title": "Tags", + "default": [] + } + }, + "type": "object", + "title": "DockerImageEventData" + }, + "DockerRepositoryEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "docker_repository", + "title": "Event Type", + "default": "docker_repository" + }, + "data": { + "$ref": "#/components/schemas/DockerRepositoryEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" } }, "type": "object", "required": [ - "type" + "data", + "metadata" ], - "title": "FeedDefinition" + "title": "Docker Repository" }, - "FeedFilters": { + "DockerRepositoryEventData": { "properties": { - "severity": { + "url": { "anyOf": [ { - "$ref": "#/components/schemas/Severity" + "type": "string" }, { - "items": { - "$ref": "#/components/schemas/Severity" - }, - "type": "array" + "type": "null" } ], - "title": "Severity" - }, - "type": { - "items": { - "$ref": "#/components/schemas/SearchType" - }, - "type": "array", - "title": "Type" - }, - "estimated_created_at": { - "$ref": "#/components/schemas/FeedDateFilter" - }, - "materialized_at": { - "$ref": "#/components/schemas/FeedDateFilter" - }, - "tags": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Tags" - }, - "is_ignored": { - "type": "boolean", - "title": "Is Ignored", - "default": false - }, - "is_remediated": { - "type": "boolean", - "title": "Is Remediated", - "default": false - } - }, - "type": "object", - "title": "FeedFilters" - }, - "FeedItem": { - "properties": { - "metadata": { - "$ref": "#/components/schemas/FeedItemMetadata" - }, - "tenant_metadata": { - "$ref": "#/components/schemas/FeedItemTenantMetadata" - }, - "identifiers": { - "items": { - "$ref": "#/components/schemas/FeedItemIdentifier" - }, - "type": "array", - "title": "Identifiers" + "title": "Url", + "description": "The URL of the Docker repository." }, - "highlights": { - "additionalProperties": { - "items": { - "type": "string" + "star_count": { + "anyOf": [ + { + "type": "integer" }, - "type": "array" - }, - "type": "object", - "title": "Highlights" - } - }, - "type": "object", - "required": [ - "metadata" - ], - "title": "FeedItem" - }, - "FeedItemIdentifier": { - "properties": { - "id": { - "type": "integer", - "title": "Id" - }, - "name": { - "type": "string", - "title": "Name" - } - }, - "type": "object", - "required": [ - "id", - "name" - ], - "title": "FeedItemIdentifier" - }, - "FeedItemMetadata": { - "properties": { - "uid": { - "type": "string", - "title": "Uid" - }, - "estimated_created_at": { - "type": "string", - "format": "date-time", - "title": "Estimated Created At" + { + "type": "null" + } + ], + "title": "Star Count", + "description": "The number of stars the repository has received." }, - "matched_at": { + "pull_count": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "integer" }, { "type": "null" } ], - "title": "Matched At" - }, - "type": { - "$ref": "#/components/schemas/ActivityModelName" - }, - "severity": { - "$ref": "#/components/schemas/Severity" + "title": "Pull Count", + "description": "The total number of pulls made against the repository." }, - "flare_url": { - "type": "string", - "title": "Flare Url" - } - }, - "type": "object", - "required": [ - "uid", - "estimated_created_at", - "matched_at", - "type", - "severity", - "flare_url" - ], - "title": "FeedItemMetadata" - }, - "FeedItemTenantMetadata": { - "properties": { - "severity": { + "collaborator_count": { "anyOf": [ { - "$ref": "#/components/schemas/FeedItemTenantMetadataSeverity" + "type": "integer" }, { "type": "null" } - ] + ], + "title": "Collaborator Count", + "description": "The number of collaborators associated with the repository." }, - "notes": { + "last_updated_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Notes" - }, - "tags": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Tags" + "title": "Last Updated At", + "description": "The timestamp at which the repository was last updated." }, - "remediated_at": { + "last_modified_at": { "anyOf": [ { "type": "string", @@ -5796,9 +6418,10 @@ "type": "null" } ], - "title": "Remediated At" + "title": "Last Modified At", + "description": "The timestamp at which the repository's metadata was last modified." }, - "ignored_at": { + "registered_at": { "anyOf": [ { "type": "string", @@ -5808,316 +6431,480 @@ "type": "null" } ], - "title": "Ignored At" + "title": "Registered At", + "description": "The timestamp at which the repository was first registered." } }, "type": "object", - "title": "FeedItemTenantMetadata" + "title": "DockerRepositoryEventData" }, - "FeedItemTenantMetadataSeverity": { + "DomainAssetEnrichment": { "properties": { - "original": { - "$ref": "#/components/schemas/Severity" + "type": { + "$ref": "#/components/schemas/AssetEnrichmentType" }, - "override": { - "$ref": "#/components/schemas/Severity" + "sources": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Sources" + }, + "entries": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Entries" + }, + "tags": { + "items": { + "$ref": "#/components/schemas/SubdomainTag" + }, + "type": "array", + "title": "Tags" + }, + "statuses": { + "items": { + "$ref": "#/components/schemas/SubdomainStatus" + }, + "type": "array", + "title": "Statuses" + }, + "external_links": { + "items": { + "type": "string" + }, + "type": "array", + "title": "External Links" + }, + "title": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Title" } }, "type": "object", "required": [ - "original", - "override" - ], - "title": "FeedItemTenantMetadataSeverity" - }, - "FeedOrder": { - "type": "string", - "enum": [ - "asc", - "desc" + "type", + "sources", + "entries", + "tags", + "statuses", + "external_links", + "title" ], - "title": "FeedOrder" + "title": "DomainAssetEnrichment" }, - "FeedRequestBody": { + "DomainData": { "properties": { - "query": { - "anyOf": [ - { - "oneOf": [ - { - "$ref": "#/components/schemas/GithubRepositoryQuery" - }, - { - "$ref": "#/components/schemas/UsernameQuery" - }, - { - "$ref": "#/components/schemas/DomainQuery" - }, - { - "$ref": "#/components/schemas/BrandQuery" - }, - { - "$ref": "#/components/schemas/NameQuery" - }, - { - "$ref": "#/components/schemas/KeywordQuery" - }, - { - "$ref": "#/components/schemas/QueryStringQuery" - }, - { - "$ref": "#/components/schemas/BinQuery" - }, - { - "$ref": "#/components/schemas/IpQuery" - }, - { - "$ref": "#/components/schemas/EmailQuery" - }, - { - "$ref": "#/components/schemas/SecretQuery" - }, - { - "$ref": "#/components/schemas/CredentialsQuery" - }, - { - "$ref": "#/components/schemas/AzureTenantQuery" - } - ], - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantQuery", - "bin": "#/components/schemas/BinQuery", - "brand": "#/components/schemas/BrandQuery", - "credentials": "#/components/schemas/CredentialsQuery", - "domain": "#/components/schemas/DomainQuery", - "email": "#/components/schemas/EmailQuery", - "github_repository": "#/components/schemas/GithubRepositoryQuery", - "ip": "#/components/schemas/IpQuery", - "keyword": "#/components/schemas/KeywordQuery", - "name": "#/components/schemas/NameQuery", - "query_string": "#/components/schemas/QueryStringQuery", - "secret": "#/components/schemas/SecretQuery", - "username": "#/components/schemas/UsernameQuery" - } - } - }, - { - "type": "null" - } - ], - "title": "Query", - "examples": [ - { - "fqdn": "test.com", - "type": "domain" - } - ] - }, - "filters": { - "$ref": "#/components/schemas/FeedFilters" - }, - "order": { - "$ref": "#/components/schemas/FeedOrder", - "default": "desc" - }, - "from": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "From" + "type": { + "type": "string", + "const": "domain", + "title": "Type", + "default": "domain" }, - "size": { - "type": "integer", - "maximum": 10.0, - "exclusiveMinimum": 0.0, - "title": "Size", - "default": 10 + "fqdn": { + "type": "string", + "minLength": 1, + "title": "Fqdn" } }, "type": "object", - "title": "FeedRequestBody" + "required": [ + "fqdn" + ], + "title": "DomainData" }, - "FeedType": { + "DomainMatchMode": { "type": "string", "enum": [ - "tenant", - "identifier", - "group" + "email_domain_only", + "auth_domain_and_email_domain", + "auth_domain_only" ], - "title": "FeedType" - }, - "FilterSeverities": { - "properties": { - "severities": { - "items": { - "$ref": "#/components/schemas/FilterSeverity" - }, - "type": "array", - "title": "Severities" - } - }, - "type": "object", - "title": "FilterSeverities" + "title": "DomainMatchMode" }, - "FilterSeverity": { + "DomainQuery": { "properties": { - "value": { - "type": "string", - "title": "Value" - }, - "label": { + "type": { "type": "string", - "title": "Label" + "const": "domain", + "title": "Type" }, - "color": { + "fqdn": { "type": "string", - "title": "Color" + "title": "Fqdn" } }, "type": "object", "required": [ - "value", - "label", - "color" + "type", + "fqdn" ], - "title": "FilterSeverity" + "title": "DomainQuery" }, - "FilterSourceType": { + "DomainStatus": { + "type": "string", + "enum": [ + "found", + "resolves", + "reachable" + ], + "title": "DomainStatus" + }, + "EmailData": { "properties": { - "value": { + "type": { "type": "string", - "title": "Value" + "const": "email", + "title": "Type", + "default": "email" }, - "label": { + "email": { "type": "string", - "title": "Label" + "format": "email", + "title": "Email" } }, "type": "object", "required": [ - "value", - "label" + "email" ], - "title": "FilterSourceType" + "title": "EmailData" }, - "FilterSourceTypeCategory": { + "EmailQuery": { "properties": { - "value": { + "type": { "type": "string", - "title": "Value" + "const": "email", + "title": "Type" }, - "label": { + "email": { "type": "string", - "title": "Label" - }, - "types": { - "items": { - "$ref": "#/components/schemas/FilterSourceType" - }, - "type": "array", - "title": "Types" + "title": "Email" } }, "type": "object", "required": [ - "value", - "label" + "type", + "email" ], - "title": "FilterSourceTypeCategory" - }, - "FilterSourceTypes": { - "properties": { - "categories": { - "items": { - "$ref": "#/components/schemas/FilterSourceTypeCategory" - }, - "type": "array", - "title": "Categories" - } - }, - "type": "object", - "title": "FilterSourceTypes" + "title": "EmailQuery" }, - "FinancialEvent": { + "EmptyFireworkEvent": { "properties": { "event_type": { - "type": "string", - "const": "cc", - "title": "Event Type", - "default": "cc" - }, - "data": { - "$ref": "#/components/schemas/FinancialEventData" + "$ref": "#/components/schemas/ActivityModelName" }, "metadata": { "$ref": "#/components/schemas/EventMetadata" + }, + "data": { + "additionalProperties": true, + "type": "object", + "title": "Data" } }, "type": "object", "required": [ - "data", + "event_type", "metadata" ], - "title": "Credit Card" + "title": "EmptyFireworkEvent" }, - "FinancialEventData": { - "properties": { - "bank": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Bank", - "description": "The bank associated with the leaked credit card." + "EntityAPIResponseTypes": { + "anyOf": [ + { + "$ref": "#/components/schemas/ActorAPIResponse" }, - "bin": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } + { + "$ref": "#/components/schemas/AttackPatternEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/CampaignEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/ChatChannelEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/ExternalReportEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/ForumThreadAPIResponse" + }, + { + "$ref": "#/components/schemas/IndicatorEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/InfrastructureEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/LocationEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/MalwareEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/ThreatActorEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/ThreatActorGroupEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/ToolEntityAPIResponse" + }, + { + "$ref": "#/components/schemas/VulnerabilityEntityAPIResponse" + } + ] + }, + "EntityLiteAPIResponseTypes": { + "anyOf": [ + { + "$ref": "#/components/schemas/ActorLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/AttackPatternEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/CampaignEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/ChatChannelEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/ExternalReportEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/ForumThreadLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/IndicatorEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/InfrastructureEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/LocationEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/MalwareEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/ThreatActorEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/ThreatActorGroupEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/ToolEntityLiteAPIResponse" + }, + { + "$ref": "#/components/schemas/VulnerabilityEntityLiteAPIResponse" + } + ] + }, + "EntityType": { + "type": "string", + "enum": [ + "attack_pattern", + "actor", + "campaign", + "chat_channel", + "external_report", + "forum_thread", + "identity", + "indicator", + "infrastructure", + "domain", + "location", + "malware", + "organization", + "threat_actor", + "threat_actor_group", + "tool", + "vulnerability" + ], + "title": "EntityType" + }, + "EventAction": { + "properties": { + "type": { + "type": "string", + "enum": [ + "remediate", + "unremediate", + "ignore", + "unignore" ], - "title": "Bin", - "description": "The BIN (Bank Identification Number) of the credit card." + "title": "Type" + } + }, + "type": "object", + "required": [ + "type" + ], + "title": "EventAction" + }, + "EventActionTarget": { + "properties": { + "uid": { + "type": "string", + "title": "Uid" + } + }, + "type": "object", + "required": [ + "uid" + ], + "title": "EventActionTarget" + }, + "EventActionsBody": { + "properties": { + "targets": { + "items": { + "$ref": "#/components/schemas/EventActionTarget" + }, + "type": "array", + "maxItems": 10, + "title": "Targets" }, - "brand": { + "action": { + "$ref": "#/components/schemas/EventAction" + } + }, + "type": "object", + "required": [ + "action" + ], + "title": "EventActionsBody" + }, + "EventMetadata": { + "properties": { + "estimated_created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Brand", - "description": "The brand of the leakedcredit card. Ex: VISA" + "title": "Estimated Created At" }, - "country": { + "flare_url": { + "type": "string", + "maxLength": 2083, + "minLength": 1, + "format": "uri", + "title": "Flare Url" + }, + "matched_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Country", - "description": "The country the leakedcredit card was issued in." + "title": "Matched At" }, - "expiration": { + "severity": { + "$ref": "#/components/schemas/EventSeverity" + }, + "uid": { + "type": "string", + "title": "Uid" + } + }, + "type": "object", + "required": [ + "flare_url", + "severity", + "uid" + ], + "title": "EventMetadata" + }, + "EventSeverity": { + "type": "string", + "enum": [ + "info", + "low", + "medium", + "high", + "critical" + ], + "title": "EventSeverity" + }, + "ExpandableField": { + "type": "string", + "enum": [ + "credentials", + "cookies" + ], + "title": "ExpandableField" + }, + "ExternalIdData": { + "properties": { + "type": { + "type": "string", + "const": "external_id", + "title": "Type", + "default": "external_id" + }, + "id": { + "type": "string", + "minLength": 1, + "title": "Id" + }, + "source": { + "type": "string", + "minLength": 1, + "title": "Source" + } + }, + "type": "object", + "required": [ + "id", + "source" + ], + "title": "ExternalIdData" + }, + "ExternalReportEntityAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { "type": "string", @@ -6127,156 +6914,170 @@ "type": "null" } ], - "title": "Expiration", - "description": "The expiration date of the leaked credit card." + "title": "Created At" }, - "owner": { + "updated_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Owner", - "description": "The owner of the leaked credit card." + "title": "Updated At" }, - "state_code": { + "first_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "State Code", - "description": "The state code tied to the leaked credit card." + "title": "First Seen At" }, - "zip": { + "last_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Zip", - "description": "The zip code tied to the leaked credit card." + "title": "Last Seen At" }, - "has_cvv": { + "confidence": { "anyOf": [ { - "type": "boolean" + "type": "integer" }, { "type": "null" } ], - "title": "Has Cvv", - "description": "Whether the CVV was included in the leaked data." + "title": "Confidence" }, - "has_date_of_birth": { + "description": { "anyOf": [ { - "type": "boolean" + "type": "string" }, { "type": "null" } ], - "title": "Has Date Of Birth", - "description": "Whether the date of birth was included in the leaked data." + "title": "Description" }, - "has_mother_maiden_name": { - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "null" - } - ], - "title": "Has Mother Maiden Name", - "description": "Whether the mother's maiden name was included in the leaked data." + "report_types": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Report Types" }, - "has_phone": { + "published": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Has Phone", - "description": "Whether the phone number was included in the leaked data." + "title": "Published" }, - "has_pin": { - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "null" - } - ], - "title": "Has Pin", - "description": "Whether the card's PIN was included in the leaked data." + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "report_types", + "published", + "marking_definitions" + ], + "title": "ExternalReportEntityAPIResponse" + }, + "ExternalReportEntityLiteAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" }, - "has_ssn": { + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Has Ssn", - "description": "Whether the card owner's SSN was included in the leaked data." + "title": "Created At" }, - "has_track_1": { + "updated_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Has Track 1", - "description": "Whether the card's track 1 (magnetic stripe data) was included in the leaked data." + "title": "Updated At" }, - "has_vbv": { + "first_seen_at": { "anyOf": [ { - "type": "boolean" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Has Vbv", - "description": "Whether the card's VBV (Verified by Visa) data was included in the leaked data." - } - }, - "type": "object", - "title": "FinancialEventData" - }, - "ForumPostData": { - "properties": { - "actor": { - "$ref": "#/components/schemas/pyro__findings__forum_posts__datamodels__ForumPostData__Actor", - "description": "Details about the author of the forum post." - }, - "context": { - "$ref": "#/components/schemas/pyro__findings__forum_posts__datamodels__ForumPostData__Context", - "description": "Details about the context of the forum post." + "title": "First Seen At" }, - "posted_at": { + "last_seen_at": { "anyOf": [ { "type": "string", @@ -6286,22 +7087,20 @@ "type": "null" } ], - "title": "Posted At", - "description": "Date and time the forum post was made." + "title": "Last Seen At" }, - "content": { + "confidence": { "anyOf": [ { - "type": "string" + "type": "integer" }, { "type": "null" } ], - "title": "Content", - "description": "Content of the forum post." + "title": "Confidence" }, - "url": { + "description": { "anyOf": [ { "type": "string" @@ -6310,90 +7109,129 @@ "type": "null" } ], - "title": "Url", - "description": "URL to the forum post." + "title": "Description" } }, "type": "object", "required": [ - "actor", - "context" + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description" ], - "title": "ForumPostData" + "title": "ExternalReportEntityLiteAPIResponse" }, - "ForumPostEvent": { + "FeedConfiguration": { "properties": { - "event_type": { - "type": "string", - "const": "forum_post", - "title": "Event Type", - "default": "forum_post" + "search_types": { + "items": { + "$ref": "#/components/schemas/SearchType" + }, + "type": "array", + "title": "Search Types" }, - "data": { - "$ref": "#/components/schemas/ForumPostData" + "experimental_search_types": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Experimental Search Types" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "risks": { + "items": { + "$ref": "#/components/schemas/RiskScore" + }, + "type": "array", + "title": "Risks" + }, + "blacklist": { + "anyOf": [ + { + "items": { + "type": "string" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Blacklist" } }, "type": "object", "required": [ - "data", - "metadata" + "search_types", + "experimental_search_types", + "risks", + "blacklist" ], - "title": "Forum Post" + "title": "FeedConfiguration" }, - "ForwardInfo": { + "FeedDateFilter": { "properties": { - "forwarded_from": { + "gt": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Forwarded From", - "description": "The username of the chat message forwarder." + "title": "Gt" }, - "forwarded_from_author_id": { + "gte": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Forwarded From Author Id", - "description": "The ID of the chat message forwarder." + "title": "Gte" }, - "forwarded_from_chat_id": { + "lt": { "anyOf": [ { - "type": "integer" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Forwarded From Chat Id", - "description": "The ID of the chat the message is being forwarded from." + "title": "Lt" }, - "forwarded_from_conversation_id": { + "lte": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Forwarded From Conversation Id", - "description": "The conversation ID the message is being forwarded from." + "title": "Lte" + } + }, + "type": "object", + "title": "FeedDateFilter" + }, + "FeedDefinition": { + "properties": { + "type": { + "$ref": "#/components/schemas/FeedType" }, - "forwarded_from_user_id": { + "id": { "anyOf": [ { "type": "integer" @@ -6402,89 +7240,66 @@ "type": "null" } ], - "title": "Forwarded From User Id", - "description": "The ID of the user the message is being forwarded from." - }, - "forwarded_from_username": { + "title": "Id" + } + }, + "type": "object", + "required": [ + "type" + ], + "title": "FeedDefinition" + }, + "FeedFilters": { + "properties": { + "severity": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/Severity" }, { - "type": "null" + "items": { + "$ref": "#/components/schemas/Severity" + }, + "type": "array" } ], - "title": "Forwarded From Username", - "description": "The username of the user the message is being forwarded from." + "title": "Severity" }, - "forwarded_message_time": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Forwarded Message Time", - "description": "The time the message was forwarded." - } - }, - "type": "object", - "title": "ForwardInfo" - }, - "GithubRepositoryData": { - "properties": { "type": { - "type": "string", - "const": "github_repository", - "title": "Type", - "default": "github_repository" + "items": { + "$ref": "#/components/schemas/SearchType" + }, + "type": "array", + "title": "Type" }, - "repo_name": { - "type": "string", - "minLength": 1, - "title": "Repo Name" + "estimated_created_at": { + "$ref": "#/components/schemas/FeedDateFilter" }, - "repo_owner": { - "type": "string", - "minLength": 1, - "title": "Repo Owner" - } - }, - "type": "object", - "required": [ - "repo_name", - "repo_owner" - ], - "title": "GithubRepositoryData" - }, - "GithubRepositoryQuery": { - "properties": { - "type": { - "type": "string", - "const": "github_repository", - "title": "Type" + "materialized_at": { + "$ref": "#/components/schemas/FeedDateFilter" }, - "repo_owner": { - "type": "string", - "title": "Repo Owner" + "tags": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Tags" }, - "repo_name": { - "type": "string", - "title": "Repo Name" + "is_ignored": { + "type": "boolean", + "title": "Is Ignored", + "default": false + }, + "is_remediated": { + "type": "boolean", + "title": "Is Remediated", + "default": false } }, "type": "object", - "required": [ - "type", - "repo_owner", - "repo_name" - ], - "title": "GithubRepositoryQuery" + "title": "FeedFilters" }, - "GlobalFeedItem": { + "FeedItem": { "properties": { "metadata": { "$ref": "#/components/schemas/FeedItemMetadata" @@ -6492,6 +7307,13 @@ "tenant_metadata": { "$ref": "#/components/schemas/FeedItemTenantMetadata" }, + "identifiers": { + "items": { + "$ref": "#/components/schemas/FeedItemIdentifier" + }, + "type": "array", + "title": "Identifiers" + }, "highlights": { "additionalProperties": { "items": { @@ -6507,148 +7329,84 @@ "required": [ "metadata" ], - "title": "GlobalFeedItem" + "title": "FeedItem" }, - "GlobalSearchRequestBody": { + "FeedItemIdentifier": { "properties": { - "query": { - "oneOf": [ - { - "$ref": "#/components/schemas/GithubRepositoryQuery" - }, - { - "$ref": "#/components/schemas/UsernameQuery" - }, - { - "$ref": "#/components/schemas/DomainQuery" - }, - { - "$ref": "#/components/schemas/BrandQuery" - }, - { - "$ref": "#/components/schemas/NameQuery" - }, - { - "$ref": "#/components/schemas/KeywordQuery" - }, - { - "$ref": "#/components/schemas/QueryStringQuery" - }, - { - "$ref": "#/components/schemas/BinQuery" - }, - { - "$ref": "#/components/schemas/IpQuery" - }, - { - "$ref": "#/components/schemas/EmailQuery" - }, - { - "$ref": "#/components/schemas/SecretQuery" - }, - { - "$ref": "#/components/schemas/CredentialsQuery" - }, - { - "$ref": "#/components/schemas/AzureTenantQuery" - } - ], - "title": "Query", - "examples": [ - { - "fqdn": "test.com", - "type": "domain" - } - ], - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantQuery", - "bin": "#/components/schemas/BinQuery", - "brand": "#/components/schemas/BrandQuery", - "credentials": "#/components/schemas/CredentialsQuery", - "domain": "#/components/schemas/DomainQuery", - "email": "#/components/schemas/EmailQuery", - "github_repository": "#/components/schemas/GithubRepositoryQuery", - "ip": "#/components/schemas/IpQuery", - "keyword": "#/components/schemas/KeywordQuery", - "name": "#/components/schemas/NameQuery", - "query_string": "#/components/schemas/QueryStringQuery", - "secret": "#/components/schemas/SecretQuery", - "username": "#/components/schemas/UsernameQuery" - } - } + "id": { + "type": "integer", + "title": "Id" }, - "filters": { - "$ref": "#/components/schemas/FeedFilters" + "name": { + "type": "string", + "title": "Name" + } + }, + "type": "object", + "required": [ + "id", + "name" + ], + "title": "FeedItemIdentifier" + }, + "FeedItemMetadata": { + "properties": { + "uid": { + "type": "string", + "title": "Uid" }, - "order": { - "$ref": "#/components/schemas/FeedOrder", - "default": "desc" + "estimated_created_at": { + "type": "string", + "format": "date-time", + "title": "Estimated Created At" }, - "from": { + "matched_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "From" + "title": "Matched At" }, - "size": { - "type": "integer", - "maximum": 10.0, - "exclusiveMinimum": 0.0, - "title": "Size", - "default": 10 + "type": { + "$ref": "#/components/schemas/ActivityModelName" + }, + "severity": { + "$ref": "#/components/schemas/Severity" + }, + "flare_url": { + "type": "string", + "title": "Flare Url" } }, "type": "object", "required": [ - "query" - ], - "title": "GlobalSearchRequestBody" - }, - "HTTPValidationError": { - "properties": { - "detail": { - "items": { - "$ref": "#/components/schemas/ValidationError" - }, - "type": "array", - "title": "Detail" - } - }, - "type": "object", - "title": "HTTPValidationError" - }, - "HubspotLifecycleStage": { - "type": "string", - "enum": [ - "1281177943" + "uid", + "estimated_created_at", + "matched_at", + "type", + "severity", + "flare_url" ], - "title": "HubspotLifecycleStage" + "title": "FeedItemMetadata" }, - "HubspotWebhookFlareSyncEvent": { + "FeedItemTenantMetadata": { "properties": { - "hubspot_id": { - "type": "integer", - "title": "Hubspot Id" - }, - "domain": { + "severity": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/FeedItemTenantMetadataSeverity" }, { "type": "null" } - ], - "title": "Domain" + ] }, - "name": { + "notes": { "anyOf": [ { "type": "string" @@ -6657,363 +7415,597 @@ "type": "null" } ], - "title": "Name" + "title": "Notes" }, - "organization_id": { - "anyOf": [ - { - "type": "integer" - }, + "tags": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Tags" + }, + "remediated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, { "type": "null" } ], - "title": "Organization Id" + "title": "Remediated At" }, - "lifecycle_stage": { + "ignored_at": { "anyOf": [ { - "$ref": "#/components/schemas/HubspotLifecycleStage" + "type": "string", + "format": "date-time" }, { "type": "null" } - ] + ], + "title": "Ignored At" + } + }, + "type": "object", + "title": "FeedItemTenantMetadata" + }, + "FeedItemTenantMetadataSeverity": { + "properties": { + "original": { + "$ref": "#/components/schemas/Severity" }, - "merged_object_ids": { - "items": { - "type": "integer" - }, - "type": "array", - "title": "Merged Object Ids", - "default": [] + "override": { + "$ref": "#/components/schemas/Severity" } }, "type": "object", "required": [ - "hubspot_id" + "original", + "override" ], - "title": "HubspotWebhookFlareSyncEvent" + "title": "FeedItemTenantMetadataSeverity" }, - "HubspotWebhookFlareSyncTenantEvent": { + "FeedOrder": { + "type": "string", + "enum": [ + "asc", + "desc" + ], + "title": "FeedOrder" + }, + "FeedRequestBody": { "properties": { - "hubspot_company_id": { - "type": "integer", - "title": "Hubspot Company Id" - }, - "hubspot_tenant_id": { - "type": "integer", - "title": "Hubspot Tenant Id" - }, - "merged_object_ids": { - "items": { - "type": "integer" - }, - "type": "array", - "title": "Merged Object Ids", - "default": [] - }, - "flare_tenant_name": { - "type": "string", - "title": "Flare Tenant Name" - }, - "organization_id": { + "query": { "anyOf": [ { - "type": "integer" + "oneOf": [ + { + "$ref": "#/components/schemas/GithubRepositoryQuery" + }, + { + "$ref": "#/components/schemas/UsernameQuery" + }, + { + "$ref": "#/components/schemas/DomainQuery" + }, + { + "$ref": "#/components/schemas/BrandQuery" + }, + { + "$ref": "#/components/schemas/NameQuery" + }, + { + "$ref": "#/components/schemas/KeywordQuery" + }, + { + "$ref": "#/components/schemas/QueryStringQuery" + }, + { + "$ref": "#/components/schemas/BinQuery" + }, + { + "$ref": "#/components/schemas/IpQuery" + }, + { + "$ref": "#/components/schemas/EmailQuery" + }, + { + "$ref": "#/components/schemas/SecretQuery" + }, + { + "$ref": "#/components/schemas/CredentialsQuery" + }, + { + "$ref": "#/components/schemas/AzureTenantQuery" + } + ], + "discriminator": { + "propertyName": "type", + "mapping": { + "azure_tenant": "#/components/schemas/AzureTenantQuery", + "bin": "#/components/schemas/BinQuery", + "brand": "#/components/schemas/BrandQuery", + "credentials": "#/components/schemas/CredentialsQuery", + "domain": "#/components/schemas/DomainQuery", + "email": "#/components/schemas/EmailQuery", + "github_repository": "#/components/schemas/GithubRepositoryQuery", + "ip": "#/components/schemas/IpQuery", + "keyword": "#/components/schemas/KeywordQuery", + "name": "#/components/schemas/NameQuery", + "query_string": "#/components/schemas/QueryStringQuery", + "secret": "#/components/schemas/SecretQuery", + "username": "#/components/schemas/UsernameQuery" + } + } }, { "type": "null" } ], - "title": "Organization Id" + "title": "Query", + "examples": [ + { + "fqdn": "test.com", + "type": "domain" + } + ] }, - "tenant_id": { + "filters": { + "$ref": "#/components/schemas/FeedFilters" + }, + "order": { + "$ref": "#/components/schemas/FeedOrder", + "default": "desc" + }, + "from": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Tenant Id" + "title": "From" + }, + "size": { + "type": "integer", + "maximum": 10.0, + "exclusiveMinimum": 0.0, + "title": "Size", + "default": 10 } }, "type": "object", - "required": [ - "hubspot_company_id", - "hubspot_tenant_id", - "flare_tenant_name" + "title": "FeedRequestBody" + }, + "FeedType": { + "type": "string", + "enum": [ + "tenant", + "identifier", + "group" ], - "title": "HubspotWebhookFlareSyncTenantEvent" + "title": "FeedType" }, - "IPData": { + "FilterSeverities": { "properties": { - "type": { + "severities": { + "items": { + "$ref": "#/components/schemas/FilterSeverity" + }, + "type": "array", + "title": "Severities" + } + }, + "type": "object", + "title": "FilterSeverities" + }, + "FilterSeverity": { + "properties": { + "value": { "type": "string", - "const": "ip", - "title": "Type", - "default": "ip" + "title": "Value" }, - "ip": { + "label": { "type": "string", - "minLength": 1, - "title": "Ip" + "title": "Label" + }, + "color": { + "type": "string", + "title": "Color" } }, "type": "object", "required": [ - "ip" + "value", + "label", + "color" ], - "title": "IPData" + "title": "FilterSeverity" }, - "Identifier": { + "FilterSourceType": { "properties": { - "id": { - "type": "integer", - "title": "Id" - }, - "name": { + "value": { "type": "string", - "title": "Name" - }, - "tenant_id": { - "type": "integer", - "title": "Tenant Id" + "title": "Value" }, - "type": { - "$ref": "#/components/schemas/IdentifierType" + "label": { + "type": "string", + "title": "Label" + } + }, + "type": "object", + "required": [ + "value", + "label" + ], + "title": "FilterSourceType" + }, + "FilterSourceTypeCategory": { + "properties": { + "value": { + "type": "string", + "title": "Value" }, - "feed": { - "$ref": "#/components/schemas/IdentifierFeed" + "label": { + "type": "string", + "title": "Label" }, - "feed_config": { - "$ref": "#/components/schemas/FeedConfiguration" - }, - "asset_uuid": { + "types": { + "items": { + "$ref": "#/components/schemas/FilterSourceType" + }, + "type": "array", + "title": "Types" + } + }, + "type": "object", + "required": [ + "value", + "label" + ], + "title": "FilterSourceTypeCategory" + }, + "FilterSourceTypes": { + "properties": { + "categories": { + "items": { + "$ref": "#/components/schemas/FilterSourceTypeCategory" + }, + "type": "array", + "title": "Categories" + } + }, + "type": "object", + "title": "FilterSourceTypes" + }, + "FinancialEvent": { + "properties": { + "event_type": { "type": "string", - "title": "Asset Uuid" + "const": "cc", + "title": "Event Type", + "default": "cc" }, "data": { - "oneOf": [ + "$ref": "#/components/schemas/FinancialEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Credit Card" + }, + "FinancialEventData": { + "properties": { + "bank": { + "anyOf": [ { - "$ref": "#/components/schemas/CCBinData" + "type": "string" }, { - "$ref": "#/components/schemas/IPData" - }, + "type": "null" + } + ], + "title": "Bank", + "description": "The bank associated with the leaked credit card." + }, + "bin": { + "anyOf": [ { - "$ref": "#/components/schemas/BrandData" + "type": "string" }, { - "$ref": "#/components/schemas/KeywordData" - }, + "type": "null" + } + ], + "title": "Bin", + "description": "The BIN (Bank Identification Number) of the credit card." + }, + "brand": { + "anyOf": [ { - "$ref": "#/components/schemas/AzureTenantData" + "type": "string" }, { - "$ref": "#/components/schemas/DomainData" - }, + "type": "null" + } + ], + "title": "Brand", + "description": "The brand of the leakedcredit card. Ex: VISA" + }, + "country": { + "anyOf": [ { - "$ref": "#/components/schemas/NameData" + "type": "string" }, { - "$ref": "#/components/schemas/SearchQueryData" - }, + "type": "null" + } + ], + "title": "Country", + "description": "The country the leakedcredit card was issued in." + }, + "expiration": { + "anyOf": [ { - "$ref": "#/components/schemas/GithubRepositoryData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/UsernameData" - }, + "type": "null" + } + ], + "title": "Expiration", + "description": "The expiration date of the leaked credit card." + }, + "owner": { + "anyOf": [ { - "$ref": "#/components/schemas/EmailData" + "type": "string" }, { - "$ref": "#/components/schemas/SecretData" - }, + "type": "null" + } + ], + "title": "Owner", + "description": "The owner of the leaked credit card." + }, + "state_code": { + "anyOf": [ { - "$ref": "#/components/schemas/CredentialsData" + "type": "string" }, { - "$ref": "#/components/schemas/IdentityData" - }, + "type": "null" + } + ], + "title": "State Code", + "description": "The state code tied to the leaked credit card." + }, + "zip": { + "anyOf": [ { - "$ref": "#/components/schemas/RansomLeakData" + "type": "string" }, { - "$ref": "#/components/schemas/AddressData" - }, + "type": "null" + } + ], + "title": "Zip", + "description": "The zip code tied to the leaked credit card." + }, + "has_cvv": { + "anyOf": [ { - "$ref": "#/components/schemas/BirthYearData" + "type": "boolean" }, { - "$ref": "#/components/schemas/RoleData" - }, + "type": "null" + } + ], + "title": "Has Cvv", + "description": "Whether the CVV was included in the leaked data." + }, + "has_date_of_birth": { + "anyOf": [ { - "$ref": "#/components/schemas/PhoneNumberData" + "type": "boolean" }, { - "$ref": "#/components/schemas/ExternalIdData" + "type": "null" } ], - "title": "Data", - "discriminator": { - "propertyName": "type", - "mapping": { - "address_data": "#/components/schemas/AddressData", - "azure_tenant": "#/components/schemas/AzureTenantData", - "bin": "#/components/schemas/CCBinData", - "birth_year": "#/components/schemas/BirthYearData", - "brand": "#/components/schemas/BrandData", - "credentials": "#/components/schemas/CredentialsData", - "domain": "#/components/schemas/DomainData", - "email": "#/components/schemas/EmailData", - "external_id": "#/components/schemas/ExternalIdData", - "github_repository": "#/components/schemas/GithubRepositoryData", - "identity": "#/components/schemas/IdentityData", - "ip": "#/components/schemas/IPData", - "keyword": "#/components/schemas/KeywordData", - "name": "#/components/schemas/NameData", - "phone_number": "#/components/schemas/PhoneNumberData", - "ransomleak": "#/components/schemas/RansomLeakData", - "role": "#/components/schemas/RoleData", - "search_query": "#/components/schemas/SearchQueryData", - "secret": "#/components/schemas/SecretData", - "username": "#/components/schemas/UsernameData" - } - } + "title": "Has Date Of Birth", + "description": "Whether the date of birth was included in the leaked data." }, - "collection": { + "has_mother_maiden_name": { "anyOf": [ { - "$ref": "#/components/schemas/IdentifierCollectionGroupId" + "type": "boolean" }, { - "$ref": "#/components/schemas/IdentifierCollectionGroupType" + "type": "null" } ], - "title": "Collection" + "title": "Has Mother Maiden Name", + "description": "Whether the mother's maiden name was included in the leaked data." }, - "urn": { - "type": "string", - "title": "Urn" + "has_phone": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Has Phone", + "description": "Whether the phone number was included in the leaked data." }, - "entity": { + "has_pin": { "anyOf": [ { - "$ref": "#/components/schemas/IdentityIdentifierEntity" + "type": "boolean" }, { "type": "null" } - ] + ], + "title": "Has Pin", + "description": "Whether the card's PIN was included in the leaked data." }, - "enrichments": { + "has_ssn": { "anyOf": [ { - "items": { - "$ref": "#/components/schemas/DomainAssetEnrichment" - }, - "type": "array" + "type": "boolean" }, { "type": "null" } ], - "title": "Enrichments" + "title": "Has Ssn", + "description": "Whether the card owner's SSN was included in the leaked data." }, - "metadata": { - "$ref": "#/components/schemas/IdentifierMetadata" + "has_track_1": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Has Track 1", + "description": "Whether the card's track 1 (magnetic stripe data) was included in the leaked data." }, - "state": { - "$ref": "#/components/schemas/IdentifierState" - } - }, - "type": "object", - "required": [ - "id", - "name", - "tenant_id", - "type", - "feed", - "feed_config", - "asset_uuid", - "data", - "collection", - "urn", - "entity", - "enrichments", - "metadata", - "state" - ], - "title": "Identifier" - }, - "IdentifierAuthorizationRequestStatus": { - "type": "string", - "enum": [ - "pending", - "rejected" - ], - "title": "IdentifierAuthorizationRequestStatus" - }, - "IdentifierAuthorizationStatus": { - "type": "string", - "enum": [ - "pending", - "rejected", - "authorized" - ], - "title": "IdentifierAuthorizationStatus" + "has_vbv": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Has Vbv", + "description": "Whether the card's VBV (Verified by Visa) data was included in the leaked data." + } + }, + "type": "object", + "title": "FinancialEventData" }, - "IdentifierCollectionGroupId": { + "ForumPostData": { "properties": { - "type": { - "type": "string", - "const": "group_id", - "title": "Type" + "actor": { + "$ref": "#/components/schemas/pyro__findings__forum_posts__datamodels__ForumPostData__Actor", + "description": "Details about the author of the forum post." }, - "group_id": { + "context": { + "$ref": "#/components/schemas/pyro__findings__forum_posts__datamodels__ForumPostData__Context", + "description": "Details about the context of the forum post." + }, + "posted_at": { "anyOf": [ { - "type": "integer" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Group Id" + "title": "Posted At", + "description": "Date and time the forum post was made." + }, + "content": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Content", + "description": "Content of the forum post." + }, + "url": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Url", + "description": "URL to the forum post." } }, "type": "object", "required": [ - "type", - "group_id" + "actor", + "context" ], - "title": "IdentifierCollectionGroupId" + "title": "ForumPostData" }, - "IdentifierCollectionGroupType": { + "ForumPostEvent": { "properties": { - "type": { + "event_type": { "type": "string", - "const": "group_type", - "title": "Type" + "const": "forum_post", + "title": "Event Type", + "default": "forum_post" }, - "group_type": { - "$ref": "#/components/schemas/IdentifierGroupType" + "data": { + "$ref": "#/components/schemas/ForumPostData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" } }, "type": "object", "required": [ - "type", - "group_type" + "data", + "metadata" ], - "title": "IdentifierCollectionGroupType" + "title": "Forum Post" }, - "IdentifierEnrichments": { + "ForumThreadAPIResponse": { "properties": { - "domain_reachable_at": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { "type": "string", @@ -7023,9 +8015,9 @@ "type": "null" } ], - "title": "Domain Reachable At" + "title": "Created At" }, - "domain_resolves_at": { + "updated_at": { "anyOf": [ { "type": "string", @@ -7035,13 +8027,33 @@ "type": "null" } ], - "title": "Domain Resolves At" + "title": "Updated At" }, - "usage_count": { - "type": "integer", - "title": "Usage Count" + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" }, - "event_count": { + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { "anyOf": [ { "type": "integer" @@ -7050,1292 +8062,1164 @@ "type": "null" } ], - "title": "Event Count" + "title": "Confidence" }, - "authorization_status": { + "description": { "anyOf": [ { - "$ref": "#/components/schemas/IdentifierAuthorizationStatus" + "type": "string" }, { "type": "null" } ], - "examples": [ - "authorized", - "pending", - "rejected" - ] - } - }, - "type": "object", - "required": [ - "domain_reachable_at", - "domain_resolves_at", - "usage_count", - "event_count", - "authorization_status" - ], - "title": "IdentifierEnrichments" - }, - "IdentifierEntityType": { - "type": "string", - "enum": [ - "identity" - ], - "title": "IdentifierEntityType" - }, - "IdentifierFeed": { - "properties": { - "id": { - "type": "integer", - "title": "Id" + "title": "Description" }, - "owner_id": { - "type": "integer", - "title": "Owner Id" + "topics": { + "items": { + "$ref": "#/components/schemas/ThreadTopic" + }, + "type": "array", + "title": "Topics" } }, "type": "object", "required": [ - "id", - "owner_id" + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "topics" ], - "title": "IdentifierFeed" + "title": "ForumThreadAPIResponse" }, - "IdentifierFeedRateLimit": { + "ForumThreadLiteAPIResponse": { "properties": { - "activity_type": { + "uuid": { "type": "string", - "title": "Activity Type" + "title": "Uuid" }, - "first_rate_limited_at": { - "type": "string", - "format": "date-time", - "title": "First Rate Limited At" + "type": { + "$ref": "#/components/schemas/EntityType" }, - "last_rate_limited_at": { - "type": "string", - "format": "date-time", - "title": "Last Rate Limited At" - } - }, - "type": "object", - "required": [ - "activity_type", - "first_rate_limited_at", - "last_rate_limited_at" - ], - "title": "IdentifierFeedRateLimit" - }, - "IdentifierFeedRateLimits": { - "properties": { - "first_rate_limited_at": { + "name": { "type": "string", - "format": "date-time", - "title": "First Rate Limited At" + "title": "Name" }, - "last_rate_limited_at": { + "created_by": { "type": "string", - "format": "date-time", - "title": "Last Rate Limited At" + "title": "Created By" }, - "activity_types": { + "sources": { "items": { - "type": "string" - }, - "type": "array", - "title": "Activity Types" - }, - "items": { - "items": { - "$ref": "#/components/schemas/IdentifierFeedRateLimit" - }, - "type": "array", - "title": "Items" - } - }, - "type": "object", - "required": [ - "first_rate_limited_at", - "last_rate_limited_at", - "activity_types", - "items" - ], - "title": "IdentifierFeedRateLimits" - }, - "IdentifierGroupType": { - "type": "string", - "enum": [ - "person", - "corporate_identities" - ], - "title": "IdentifierGroupType" - }, - "IdentifierMatchingPolicyBody": { - "properties": { - "matching_policy_uuid": { - "type": "string", - "format": "uuid", - "title": "Matching Policy Uuid" - }, - "clean_past_events": { - "type": "boolean", - "title": "Clean Past Events", - "description": "Determines whether or not this policy should be applied to events that have already matched this identifier.", - "default": false - } - }, - "type": "object", - "required": [ - "matching_policy_uuid" - ], - "title": "IdentifierMatchingPolicyBody" - }, - "IdentifierMetadata": { - "properties": { - "critical": { - "type": "boolean", - "title": "Critical" - }, - "is_disabled": { - "type": "boolean", - "title": "Is Disabled" - } - }, - "type": "object", - "required": [ - "critical", - "is_disabled" - ], - "title": "IdentifierMetadata" - }, - "IdentifierOrderBy": { - "type": "string", - "enum": [ - "id", - "name", - "type" - ], - "title": "IdentifierOrderBy" - }, - "IdentifierRecommendationAction": { - "properties": { - "type": { - "$ref": "#/components/schemas/IdentifierRecommendationActionType" - } - }, - "type": "object", - "required": [ - "type" - ], - "title": "IdentifierRecommendationAction" - }, - "IdentifierRecommendationActionTarget": { - "properties": { - "id": { - "type": "integer", - "title": "Id" - } - }, - "type": "object", - "required": [ - "id" - ], - "title": "IdentifierRecommendationActionTarget" - }, - "IdentifierRecommendationActionType": { - "type": "string", - "enum": [ - "accept", - "reject" - ], - "title": "IdentifierRecommendationActionType" - }, - "IdentifierRecommendationActionsBody": { - "properties": { - "targets": { - "items": { - "$ref": "#/components/schemas/IdentifierRecommendationActionTarget" + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" }, "type": "array", - "maxItems": 100, - "title": "Targets" + "title": "Sources" }, - "action": { - "$ref": "#/components/schemas/IdentifierRecommendationAction" - } - }, - "type": "object", - "required": [ - "action" - ], - "title": "IdentifierRecommendationActionsBody" - }, - "IdentifierRecommendationState": { - "type": "string", - "enum": [ - "recommended", - "accepted", - "rejected" - ], - "title": "IdentifierRecommendationState" - }, - "IdentifierRequestBody": { - "properties": { - "data": { - "oneOf": [ - { - "$ref": "#/components/schemas/CCBinData" - }, - { - "$ref": "#/components/schemas/IPData" - }, - { - "$ref": "#/components/schemas/BrandData" - }, - { - "$ref": "#/components/schemas/KeywordData" - }, - { - "$ref": "#/components/schemas/AzureTenantData" - }, - { - "$ref": "#/components/schemas/DomainData" - }, - { - "$ref": "#/components/schemas/SearchQueryData" - }, - { - "$ref": "#/components/schemas/GithubRepositoryData" - }, + "created_at": { + "anyOf": [ { - "$ref": "#/components/schemas/CredentialsData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/EmailData" - }, + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ { - "$ref": "#/components/schemas/UsernameData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/SecretData" - }, + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ { - "$ref": "#/components/schemas/NameData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/IdentityDataRequestBody" + "type": "null" } ], - "title": "Data", - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantData", - "bin": "#/components/schemas/CCBinData", - "brand": "#/components/schemas/BrandData", - "credentials": "#/components/schemas/CredentialsData", - "domain": "#/components/schemas/DomainData", - "email": "#/components/schemas/EmailData", - "github_repository": "#/components/schemas/GithubRepositoryData", - "identity": "#/components/schemas/IdentityDataRequestBody", - "ip": "#/components/schemas/IPData", - "keyword": "#/components/schemas/KeywordData", - "name": "#/components/schemas/NameData", - "search_query": "#/components/schemas/SearchQueryData", - "secret": "#/components/schemas/SecretData", - "username": "#/components/schemas/UsernameData" - } - } + "title": "First Seen At" }, - "name": { + "last_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Name" + "title": "Last Seen At" }, - "feed_config": { - "$ref": "#/components/schemas/FeedConfiguration" - }, - "collection": { + "confidence": { "anyOf": [ { - "$ref": "#/components/schemas/IdentifierCollectionGroupId" + "type": "integer" }, { - "$ref": "#/components/schemas/IdentifierCollectionGroupType" + "type": "null" } ], - "title": "Collection" - }, - "metadata": { - "$ref": "#/components/schemas/IdentifierMetadata" + "title": "Confidence" }, - "matching_policies": { + "description": { "anyOf": [ { - "items": { - "$ref": "#/components/schemas/IdentifierMatchingPolicyBody" - }, - "type": "array" + "type": "string" }, { "type": "null" } ], - "title": "Matching Policies" + "title": "Description" + }, + "topics": { + "items": { + "$ref": "#/components/schemas/ThreadTopic" + }, + "type": "array", + "title": "Topics" } }, "type": "object", "required": [ - "data", + "uuid", + "type", "name", - "feed_config", - "collection", - "metadata" + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "topics" ], - "title": "IdentifierRequestBody" + "title": "ForumThreadLiteAPIResponse" }, - "IdentifierResponse": { + "ForwardInfo": { "properties": { - "identifier": { + "forwarded_from": { "anyOf": [ { - "$ref": "#/components/schemas/Identifier" + "type": "string" }, { "type": "null" } - ] - }, - "is_materialized": { - "type": "boolean", - "title": "Is Materialized", - "default": false + ], + "title": "Forwarded From", + "description": "The username of the chat message forwarder." }, - "created_at": { + "forwarded_from_author_id": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Created At" + "title": "Forwarded From Author Id", + "description": "The ID of the chat message forwarder." }, - "last_updated_at": { + "forwarded_from_chat_id": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "integer" }, { "type": "null" } ], - "title": "Last Updated At" - } - }, - "type": "object", - "title": "IdentifierResponse" - }, - "IdentifierScope": { - "properties": { - "name": { - "type": "string", - "title": "Name" - }, - "is_disabled": { - "type": "boolean", - "title": "Is Disabled", - "default": false - } - }, - "type": "object", - "required": [ - "name" - ], - "title": "IdentifierScope" - }, - "IdentifierSource": { - "type": "string", - "enum": [ - "USER", - "SYSTEM_RELATION", - "SELF_ONBOARDING", - "ATTRIBUTE", - "AUTO_MONITOR", - "IDP_SYNC" - ], - "title": "IdentifierSource" - }, - "IdentifierState": { - "properties": { - "source": { - "$ref": "#/components/schemas/IdentifierSource" - }, - "data_updated_at": { - "type": "string", - "format": "date-time", - "title": "Data Updated At" + "title": "Forwarded From Chat Id", + "description": "The ID of the chat the message is being forwarded from." }, - "event_count": { + "forwarded_from_conversation_id": { "anyOf": [ { - "type": "integer" + "type": "string" }, { "type": "null" } ], - "title": "Event Count" - }, - "usage_count": { - "type": "integer", - "title": "Usage Count" + "title": "Forwarded From Conversation Id", + "description": "The conversation ID the message is being forwarded from." }, - "rate_limits": { + "forwarded_from_user_id": { "anyOf": [ { - "$ref": "#/components/schemas/IdentifierFeedRateLimits" + "type": "integer" }, { "type": "null" } - ] + ], + "title": "Forwarded From User Id", + "description": "The ID of the user the message is being forwarded from." }, - "validation_status": { + "forwarded_from_username": { "anyOf": [ { - "$ref": "#/components/schemas/IdentifierValidationStatus" + "type": "string" }, { "type": "null" } - ] + ], + "title": "Forwarded From Username", + "description": "The username of the user the message is being forwarded from." }, - "authorization_request_status": { + "forwarded_message_time": { "anyOf": [ { - "$ref": "#/components/schemas/IdentifierAuthorizationRequestStatus" + "type": "string", + "format": "date-time" }, { "type": "null" } - ] + ], + "title": "Forwarded Message Time", + "description": "The time the message was forwarded." + } + }, + "type": "object", + "title": "ForwardInfo" + }, + "GithubRepositoryData": { + "properties": { + "type": { + "type": "string", + "const": "github_repository", + "title": "Type", + "default": "github_repository" + }, + "repo_name": { + "type": "string", + "minLength": 1, + "title": "Repo Name" + }, + "repo_owner": { + "type": "string", + "minLength": 1, + "title": "Repo Owner" } }, "type": "object", "required": [ - "source", - "data_updated_at", - "event_count", - "usage_count", - "rate_limits", - "validation_status", - "authorization_request_status" + "repo_name", + "repo_owner" ], - "title": "IdentifierState" + "title": "GithubRepositoryData" }, - "IdentifierType": { - "type": "string", - "enum": [ - "domain", - "name", - "keyword", - "github_repository", - "username", - "email", - "search_query", - "bin", - "ip", - "secret", - "azure_tenant", - "identity", - "ransomleak", - "external_id", - "address_data", - "birth_year", - "role", - "phone_number" + "GithubRepositoryQuery": { + "properties": { + "type": { + "type": "string", + "const": "github_repository", + "title": "Type" + }, + "repo_owner": { + "type": "string", + "title": "Repo Owner" + }, + "repo_name": { + "type": "string", + "title": "Repo Name" + } + }, + "type": "object", + "required": [ + "type", + "repo_owner", + "repo_name" ], - "title": "IdentifierType" + "title": "GithubRepositoryQuery" }, - "IdentifierValidationStatus": { - "type": "string", - "enum": [ - "FIRST_PARTY" + "GlobalFeedItem": { + "properties": { + "metadata": { + "$ref": "#/components/schemas/FeedItemMetadata" + }, + "tenant_metadata": { + "$ref": "#/components/schemas/FeedItemTenantMetadata" + }, + "highlights": { + "additionalProperties": { + "items": { + "type": "string" + }, + "type": "array" + }, + "type": "object", + "title": "Highlights" + } + }, + "type": "object", + "required": [ + "metadata" ], - "title": "IdentifierValidationStatus" + "title": "GlobalFeedItem" }, - "IdentityAttribute": { + "GlobalSearchRequestBody": { "properties": { - "asset_uuid": { - "type": "string", - "title": "Asset Uuid" - }, - "data": { + "query": { "oneOf": [ { - "$ref": "#/components/schemas/EmailData" + "$ref": "#/components/schemas/GithubRepositoryQuery" }, { - "$ref": "#/components/schemas/UsernameData" + "$ref": "#/components/schemas/UsernameQuery" }, { - "$ref": "#/components/schemas/NameData" + "$ref": "#/components/schemas/DomainQuery" }, { - "$ref": "#/components/schemas/ExternalIdData" + "$ref": "#/components/schemas/BrandQuery" }, { - "$ref": "#/components/schemas/AddressData" + "$ref": "#/components/schemas/NameQuery" }, { - "$ref": "#/components/schemas/BirthYearData" + "$ref": "#/components/schemas/KeywordQuery" }, { - "$ref": "#/components/schemas/RoleData" + "$ref": "#/components/schemas/QueryStringQuery" }, { - "$ref": "#/components/schemas/PhoneNumberData" + "$ref": "#/components/schemas/BinQuery" + }, + { + "$ref": "#/components/schemas/IpQuery" + }, + { + "$ref": "#/components/schemas/EmailQuery" + }, + { + "$ref": "#/components/schemas/SecretQuery" + }, + { + "$ref": "#/components/schemas/CredentialsQuery" + }, + { + "$ref": "#/components/schemas/AzureTenantQuery" } ], - "title": "Data", - "discriminator": { - "propertyName": "type", + "title": "Query", + "examples": [ + { + "fqdn": "test.com", + "type": "domain" + } + ], + "discriminator": { + "propertyName": "type", "mapping": { - "address_data": "#/components/schemas/AddressData", - "birth_year": "#/components/schemas/BirthYearData", - "email": "#/components/schemas/EmailData", - "external_id": "#/components/schemas/ExternalIdData", - "name": "#/components/schemas/NameData", - "phone_number": "#/components/schemas/PhoneNumberData", - "role": "#/components/schemas/RoleData", - "username": "#/components/schemas/UsernameData" + "azure_tenant": "#/components/schemas/AzureTenantQuery", + "bin": "#/components/schemas/BinQuery", + "brand": "#/components/schemas/BrandQuery", + "credentials": "#/components/schemas/CredentialsQuery", + "domain": "#/components/schemas/DomainQuery", + "email": "#/components/schemas/EmailQuery", + "github_repository": "#/components/schemas/GithubRepositoryQuery", + "ip": "#/components/schemas/IpQuery", + "keyword": "#/components/schemas/KeywordQuery", + "name": "#/components/schemas/NameQuery", + "query_string": "#/components/schemas/QueryStringQuery", + "secret": "#/components/schemas/SecretQuery", + "username": "#/components/schemas/UsernameQuery" } } + }, + "filters": { + "$ref": "#/components/schemas/FeedFilters" + }, + "order": { + "$ref": "#/components/schemas/FeedOrder", + "default": "desc" + }, + "from": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "From" + }, + "size": { + "type": "integer", + "maximum": 10.0, + "exclusiveMinimum": 0.0, + "title": "Size", + "default": 10 } }, "type": "object", "required": [ - "asset_uuid", - "data" + "query" ], - "title": "IdentityAttribute" + "title": "GlobalSearchRequestBody" }, - "IdentityData": { + "HTTPValidationError": { "properties": { - "type": { - "type": "string", - "const": "identity", - "title": "Type", - "default": "identity" - }, - "uuid": { - "type": "string", - "minLength": 1, - "title": "Uuid" + "detail": { + "items": { + "$ref": "#/components/schemas/ValidationError" + }, + "type": "array", + "title": "Detail" } }, "type": "object", - "required": [ - "uuid" + "title": "HTTPValidationError" + }, + "HubspotLifecycleStage": { + "type": "string", + "enum": [ + "1281177943" ], - "title": "IdentityData" + "title": "HubspotLifecycleStage" }, - "IdentityDataRequestBody": { + "HubspotWebhookFlareSyncEvent": { "properties": { - "type": { - "type": "string", - "const": "identity", - "title": "Type" + "hubspot_id": { + "type": "integer", + "title": "Hubspot Id" }, - "attributes": { - "items": { - "oneOf": [ - { - "$ref": "#/components/schemas/EmailData" - }, - { - "$ref": "#/components/schemas/UsernameData" - }, - { - "$ref": "#/components/schemas/NameData" - }, - { - "$ref": "#/components/schemas/ExternalIdData" - }, - { - "$ref": "#/components/schemas/AddressData" - }, - { - "$ref": "#/components/schemas/BirthYearData" - }, - { - "$ref": "#/components/schemas/RoleData" - }, - { - "$ref": "#/components/schemas/PhoneNumberData" - } - ], - "discriminator": { - "propertyName": "type", - "mapping": { - "address_data": "#/components/schemas/AddressData", - "birth_year": "#/components/schemas/BirthYearData", - "email": "#/components/schemas/EmailData", - "external_id": "#/components/schemas/ExternalIdData", - "name": "#/components/schemas/NameData", - "phone_number": "#/components/schemas/PhoneNumberData", - "role": "#/components/schemas/RoleData", - "username": "#/components/schemas/UsernameData" - } + "domain": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Domain" + }, + "name": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Name" + }, + "organization_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Organization Id" + }, + "lifecycle_stage": { + "anyOf": [ + { + "$ref": "#/components/schemas/HubspotLifecycleStage" + }, + { + "type": "null" } + ] + }, + "merged_object_ids": { + "items": { + "type": "integer" }, "type": "array", - "maxItems": 15, - "minItems": 1, - "title": "Attributes" + "title": "Merged Object Ids", + "default": [] } }, "type": "object", "required": [ - "type", - "attributes" + "hubspot_id" ], - "title": "IdentityDataRequestBody" + "title": "HubspotWebhookFlareSyncEvent" }, - "IdentityIdentifierEntity": { + "HubspotWebhookFlareSyncTenantEvent": { "properties": { - "type": { - "$ref": "#/components/schemas/IdentifierEntityType" + "hubspot_company_id": { + "type": "integer", + "title": "Hubspot Company Id" }, - "attributes": { + "hubspot_tenant_id": { + "type": "integer", + "title": "Hubspot Tenant Id" + }, + "merged_object_ids": { "items": { - "$ref": "#/components/schemas/IdentityAttribute" + "type": "integer" }, "type": "array", - "title": "Attributes" + "title": "Merged Object Ids", + "default": [] + }, + "flare_tenant_name": { + "type": "string", + "title": "Flare Tenant Name" + }, + "organization_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Organization Id" + }, + "tenant_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Tenant Id" } }, "type": "object", "required": [ - "type", - "attributes" - ], - "title": "IdentityIdentifierEntity" - }, - "IncludeOptions": { - "type": "string", - "enum": [ - "known_password_id", - "auth_domains", - "urls" + "hubspot_company_id", + "hubspot_tenant_id", + "flare_tenant_name" ], - "title": "IncludeOptions" + "title": "HubspotWebhookFlareSyncTenantEvent" }, - "IntelType": { - "type": "string", - "enum": [ - "unit_summary_based", - "custom_intel" - ], - "title": "IntelType" - }, - "InvalidCredentialEvent": { - "properties": { - "event_type": { - "type": "string", - "const": "invalid_credential", - "title": "Event Type", - "default": "invalid_credential" - }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - }, - "data": { - "$ref": "#/components/schemas/CredentialEventData" - } - }, - "type": "object", - "required": [ - "metadata", - "data" - ], - "title": "Invalid Credential" - }, - "IpQuery": { + "IPData": { "properties": { "type": { "type": "string", "const": "ip", - "title": "Type" + "title": "Type", + "default": "ip" }, "ip": { "type": "string", + "minLength": 1, "title": "Ip" } }, "type": "object", "required": [ - "type", "ip" ], - "title": "IpQuery" + "title": "IPData" }, - "KeywordData": { + "Identifier": { "properties": { - "type": { - "type": "string", - "const": "keyword", - "title": "Type", - "default": "keyword" + "id": { + "type": "integer", + "title": "Id" }, - "keyword": { + "name": { "type": "string", - "minLength": 1, - "title": "Keyword" - } - }, - "type": "object", - "required": [ - "keyword" - ], - "title": "KeywordData" - }, - "KeywordQuery": { - "properties": { + "title": "Name" + }, + "tenant_id": { + "type": "integer", + "title": "Tenant Id" + }, "type": { - "type": "string", - "const": "keyword", - "title": "Type" + "$ref": "#/components/schemas/IdentifierType" }, - "keyword": { - "type": "string", - "title": "Keyword" - } - }, - "type": "object", - "required": [ - "type", - "keyword" - ], - "title": "KeywordQuery" - }, - "KeywordsValue": { - "properties": { - "keywords": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Keywords" - } - }, - "type": "object", - "required": [ - "keywords" - ], - "title": "KeywordsValue" - }, - "Language": { - "type": "string", - "enum": [ - "en", - "fr" - ], - "title": "Language" - }, - "LeakEvent": { - "properties": { - "event_type": { - "type": "string", - "const": "leak", - "title": "Event Type", - "default": "leak" + "feed": { + "$ref": "#/components/schemas/IdentifierFeed" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "feed_config": { + "$ref": "#/components/schemas/FeedConfiguration" }, - "data": { - "$ref": "#/components/schemas/LeakEventData" - } - }, - "type": "object", - "required": [ - "metadata", - "data" - ], - "title": "Leak" - }, - "LeakEventData": { - "properties": { - "term": { + "asset_uuid": { "type": "string", - "title": "Term", - "description": "The search term that matched this leak." + "title": "Asset Uuid" }, - "site_url": { + "data": { + "oneOf": [ + { + "$ref": "#/components/schemas/CCBinData" + }, + { + "$ref": "#/components/schemas/IPData" + }, + { + "$ref": "#/components/schemas/BrandData" + }, + { + "$ref": "#/components/schemas/KeywordData" + }, + { + "$ref": "#/components/schemas/AzureTenantData" + }, + { + "$ref": "#/components/schemas/DomainData" + }, + { + "$ref": "#/components/schemas/NameData" + }, + { + "$ref": "#/components/schemas/SearchQueryData" + }, + { + "$ref": "#/components/schemas/GithubRepositoryData" + }, + { + "$ref": "#/components/schemas/UsernameData" + }, + { + "$ref": "#/components/schemas/EmailData" + }, + { + "$ref": "#/components/schemas/SecretData" + }, + { + "$ref": "#/components/schemas/CredentialsData" + }, + { + "$ref": "#/components/schemas/IdentityData" + }, + { + "$ref": "#/components/schemas/RansomLeakData" + }, + { + "$ref": "#/components/schemas/AddressData" + }, + { + "$ref": "#/components/schemas/BirthYearData" + }, + { + "$ref": "#/components/schemas/RoleData" + }, + { + "$ref": "#/components/schemas/PhoneNumberData" + }, + { + "$ref": "#/components/schemas/ExternalIdData" + } + ], + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "address_data": "#/components/schemas/AddressData", + "azure_tenant": "#/components/schemas/AzureTenantData", + "bin": "#/components/schemas/CCBinData", + "birth_year": "#/components/schemas/BirthYearData", + "brand": "#/components/schemas/BrandData", + "credentials": "#/components/schemas/CredentialsData", + "domain": "#/components/schemas/DomainData", + "email": "#/components/schemas/EmailData", + "external_id": "#/components/schemas/ExternalIdData", + "github_repository": "#/components/schemas/GithubRepositoryData", + "identity": "#/components/schemas/IdentityData", + "ip": "#/components/schemas/IPData", + "keyword": "#/components/schemas/KeywordData", + "name": "#/components/schemas/NameData", + "phone_number": "#/components/schemas/PhoneNumberData", + "ransomleak": "#/components/schemas/RansomLeakData", + "role": "#/components/schemas/RoleData", + "search_query": "#/components/schemas/SearchQueryData", + "secret": "#/components/schemas/SecretData", + "username": "#/components/schemas/UsernameData" + } + } + }, + "collection": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/IdentifierCollectionGroupId" }, { - "type": "null" + "$ref": "#/components/schemas/IdentifierCollectionGroupType" } ], - "title": "Site Url", - "description": "The URL of the site the leak originated from." + "title": "Collection" }, - "leaked_at": { + "urn": { + "type": "string", + "title": "Urn" + }, + "entity": { "anyOf": [ { - "type": "string", - "format": "date-time" + "$ref": "#/components/schemas/IdentityIdentifierEntity" }, { "type": "null" } - ], - "title": "Leaked At", - "description": "When the leak occurred." + ] }, - "breached_at": { + "enrichments": { "anyOf": [ { - "type": "string", - "format": "date-time" + "items": { + "$ref": "#/components/schemas/DomainAssetEnrichment" + }, + "type": "array" }, { "type": "null" } ], - "title": "Breached At", - "description": "When the breach was disclosed." - }, - "leaked_credential_count": { - "type": "integer", - "title": "Leaked Credential Count", - "description": "Number of credentials contained in this leak." - }, - "pii_tags": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Pii Tags", - "description": "PII categories present in this leak." + "title": "Enrichments" }, - "source": { - "$ref": "#/components/schemas/LeakEventSource", - "description": "The source of the leak." - } - }, - "type": "object", - "required": [ - "term", - "leaked_credential_count", - "source" - ], - "title": "LeakEventData" - }, - "LeakEventSource": { - "properties": { - "id": { - "type": "string", - "title": "Id", - "description": "The identifier of the leak source category." + "metadata": { + "$ref": "#/components/schemas/IdentifierMetadata" }, - "name": { - "type": "string", - "title": "Name", - "description": "The name of the leak source category." + "state": { + "$ref": "#/components/schemas/IdentifierState" } }, "type": "object", "required": [ "id", - "name" + "name", + "tenant_id", + "type", + "feed", + "feed_config", + "asset_uuid", + "data", + "collection", + "urn", + "entity", + "enrichments", + "metadata", + "state" ], - "title": "LeakEventSource" + "title": "Identifier" }, - "LeakedCredentialEvent": { - "properties": { - "event_type": { - "type": "string", - "const": "leaked_credential", - "title": "Event Type", - "default": "leaked_credential" - }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - }, - "data": { - "$ref": "#/components/schemas/LeakedCredentialEventData" - } - }, - "type": "object", - "required": [ - "metadata", - "data" + "IdentifierAuthorizationRequestStatus": { + "type": "string", + "enum": [ + "pending", + "rejected" ], - "title": "Leaked Credential" + "title": "IdentifierAuthorizationRequestStatus" }, - "LeakedCredentialEventData": { - "properties": { - "identity_name": { - "type": "string", - "title": "Identity Name", - "description": "The email or username associated with the leaked credential." - }, - "imported_at": { - "type": "string", - "format": "date-time", - "title": "Imported At", - "description": "When the credential was imported into Flare." - }, - "password": { - "type": "string", - "title": "Password", - "description": "The leaked password, or its hash if not available in cleartext." - }, - "source": { - "$ref": "#/components/schemas/LeakedCredentialEventSource", - "description": "The source the credential was leaked from." - } - }, - "type": "object", - "required": [ - "identity_name", - "imported_at", - "password", - "source" + "IdentifierAuthorizationStatus": { + "type": "string", + "enum": [ + "pending", + "rejected", + "authorized" ], - "title": "LeakedCredentialEventData" + "title": "IdentifierAuthorizationStatus" }, - "LeakedCredentialEventSource": { + "IdentifierCollectionGroupId": { "properties": { - "id": { + "type": { "type": "string", - "title": "Id", - "description": "The identifier of the leak source category." + "const": "group_id", + "title": "Type" }, - "name": { - "type": "string", - "title": "Name", - "description": "The name of the leak source category." + "group_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Group Id" } }, "type": "object", "required": [ - "id", - "name" - ], - "title": "LeakedCredentialEventSource" - }, - "LeakedCredentialsBulkActionType": { - "type": "string", - "enum": [ - "remediate", - "unremediate", - "ignore", - "unignore" + "type", + "group_id" ], - "title": "LeakedCredentialsBulkActionType" + "title": "IdentifierCollectionGroupId" }, - "ListingEvent": { + "IdentifierCollectionGroupType": { "properties": { - "event_type": { + "type": { "type": "string", - "const": "listing", - "title": "Event Type", - "default": "listing" - }, - "data": { - "$ref": "#/components/schemas/ListingEventData" + "const": "group_type", + "title": "Type" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "group_type": { + "$ref": "#/components/schemas/IdentifierGroupType" } }, "type": "object", "required": [ - "data", - "metadata" + "type", + "group_type" ], - "title": "Listing" + "title": "IdentifierCollectionGroupType" }, - "ListingEventData": { + "IdentifierEnrichments": { "properties": { - "url": { + "domain_reachable_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Url", - "description": "The URL to the listing." + "title": "Domain Reachable At" }, - "title": { + "domain_resolves_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Title", - "description": "The title of the listing." + "title": "Domain Resolves At" }, - "content": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Content", - "description": "The content within the listing." + "usage_count": { + "type": "integer", + "title": "Usage Count" }, - "currency": { + "event_count": { "anyOf": [ { - "type": "string" + "type": "integer" }, { "type": "null" } ], - "title": "Currency", - "description": "The currency expected in the listing." + "title": "Event Count" }, - "escrow": { + "authorization_status": { "anyOf": [ { - "type": "boolean" + "$ref": "#/components/schemas/IdentifierAuthorizationStatus" }, { "type": "null" } ], - "title": "Escrow", - "description": "Whether the listing requires escrow." + "examples": [ + "authorized", + "pending", + "rejected" + ] + } + }, + "type": "object", + "required": [ + "domain_reachable_at", + "domain_resolves_at", + "usage_count", + "event_count", + "authorization_status" + ], + "title": "IdentifierEnrichments" + }, + "IdentifierEntityType": { + "type": "string", + "enum": [ + "identity" + ], + "title": "IdentifierEntityType" + }, + "IdentifierFeed": { + "properties": { + "id": { + "type": "integer", + "title": "Id" }, - "price": { - "anyOf": [ - { - "type": "number" - }, - { - "type": "null" - } - ], - "title": "Price", - "description": "The price of the listing." + "owner_id": { + "type": "integer", + "title": "Owner Id" + } + }, + "type": "object", + "required": [ + "id", + "owner_id" + ], + "title": "IdentifierFeed" + }, + "IdentifierFeedRateLimit": { + "properties": { + "activity_type": { + "type": "string", + "title": "Activity Type" }, - "ship_to": { + "first_rate_limited_at": { + "type": "string", + "format": "date-time", + "title": "First Rate Limited At" + }, + "last_rate_limited_at": { + "type": "string", + "format": "date-time", + "title": "Last Rate Limited At" + } + }, + "type": "object", + "required": [ + "activity_type", + "first_rate_limited_at", + "last_rate_limited_at" + ], + "title": "IdentifierFeedRateLimit" + }, + "IdentifierFeedRateLimits": { + "properties": { + "first_rate_limited_at": { + "type": "string", + "format": "date-time", + "title": "First Rate Limited At" + }, + "last_rate_limited_at": { + "type": "string", + "format": "date-time", + "title": "Last Rate Limited At" + }, + "activity_types": { "items": { "type": "string" }, "type": "array", - "title": "Ship To", - "description": "The countries eligible for shipping.", - "default": [] + "title": "Activity Types" }, - "ship_from": { + "items": { "items": { - "type": "string" + "$ref": "#/components/schemas/IdentifierFeedRateLimit" }, "type": "array", - "title": "Ship From", - "description": "The countries eligible for shipping.", - "default": [] - }, - "stock_count": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Stock Count", - "description": "The quantity of the items or service in stock." - }, - "actor": { - "$ref": "#/components/schemas/pyro__findings__listing__datamodels__ListingEventData__Actor", - "description": "Data about the seller." - }, - "classification": { - "$ref": "#/components/schemas/Classification", - "description": "Data about the possible classifications of the listing." - }, - "context": { - "$ref": "#/components/schemas/pyro__findings__listing__datamodels__ListingEventData__Context", - "description": "Data offering context to the listing." + "title": "Items" } }, "type": "object", - "title": "ListingEventData" + "required": [ + "first_rate_limited_at", + "last_rate_limited_at", + "activity_types", + "items" + ], + "title": "IdentifierFeedRateLimits" }, - "LookalikeDomainEvent": { + "IdentifierGroupType": { + "type": "string", + "enum": [ + "person", + "corporate_identities" + ], + "title": "IdentifierGroupType" + }, + "IdentifierMatchingPolicyBody": { "properties": { - "event_type": { + "matching_policy_uuid": { "type": "string", - "const": "lookalike", - "title": "Event Type", - "default": "lookalike" - }, - "data": { - "$ref": "#/components/schemas/LookalikeDomainEventData" + "format": "uuid", + "title": "Matching Policy Uuid" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "clean_past_events": { + "type": "boolean", + "title": "Clean Past Events", + "description": "Determines whether or not this policy should be applied to events that have already matched this identifier.", + "default": false } }, "type": "object", "required": [ - "data", - "metadata" + "matching_policy_uuid" ], - "title": "Lookalike Domain" + "title": "IdentifierMatchingPolicyBody" }, - "LookalikeDomainEventData": { + "IdentifierMetadata": { "properties": { - "domain": { - "type": "string", - "title": "Domain", - "description": "The domain of the lookalike domain." - }, - "registered_at": { - "anyOf": [ - { - "type": "string", - "format": "date-time" - }, - { - "type": "null" - } - ], - "title": "Registered At", - "description": "The date and time the lookalike domain was registered." - }, - "identifier_domains": { - "anyOf": [ - { - "items": { - "type": "string" - }, - "type": "array" - }, - { - "type": "null" - } - ], - "title": "Identifier Domains", - "description": "Domain identifiers matching the lookalike domains" - }, - "feed": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Feed", - "description": "The feed where the lookalike domain was found" - }, - "cert_data": { - "anyOf": [ - { - "additionalProperties": true, - "type": "object" - }, - { - "type": "null" - } - ], - "title": "Cert Data", - "description": "The certificate data of the lookalike domain." - }, - "subject": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Subject", - "description": "The subject of the certificate of the lookalike domain." + "critical": { + "type": "boolean", + "title": "Critical" }, - "issuer": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Issuer", - "description": "The issuer of the certificate of the lookalike domain." + "is_disabled": { + "type": "boolean", + "title": "Is Disabled" } }, "type": "object", "required": [ - "domain" + "critical", + "is_disabled" ], - "title": "LookalikeDomainEventData" + "title": "IdentifierMetadata" }, - "LuceneValue": { + "IdentifierOrderBy": { + "type": "string", + "enum": [ + "id", + "name", + "type" + ], + "title": "IdentifierOrderBy" + }, + "IdentifierRecommendationAction": { "properties": { - "query": { - "type": "string", - "title": "Query", - "description": "The lucene query of the matching policy" + "type": { + "$ref": "#/components/schemas/IdentifierRecommendationActionType" } }, "type": "object", "required": [ - "query" + "type" ], - "title": "LuceneValue" + "title": "IdentifierRecommendationAction" }, - "MalwareInformation": { + "IdentifierRecommendationActionTarget": { "properties": { - "malware_family": { - "anyOf": [ - { - "type": "string" + "id": { + "type": "integer", + "title": "Id" + } + }, + "type": "object", + "required": [ + "id" + ], + "title": "IdentifierRecommendationActionTarget" + }, + "IdentifierRecommendationActionType": { + "type": "string", + "enum": [ + "accept", + "reject" + ], + "title": "IdentifierRecommendationActionType" + }, + "IdentifierRecommendationActionsBody": { + "properties": { + "targets": { + "items": { + "$ref": "#/components/schemas/IdentifierRecommendationActionTarget" + }, + "type": "array", + "maxItems": 100, + "title": "Targets" + }, + "action": { + "$ref": "#/components/schemas/IdentifierRecommendationAction" + } + }, + "type": "object", + "required": [ + "action" + ], + "title": "IdentifierRecommendationActionsBody" + }, + "IdentifierRecommendationState": { + "type": "string", + "enum": [ + "recommended", + "accepted", + "rejected" + ], + "title": "IdentifierRecommendationState" + }, + "IdentifierRequestBody": { + "properties": { + "data": { + "oneOf": [ + { + "$ref": "#/components/schemas/CCBinData" }, { - "type": "null" + "$ref": "#/components/schemas/IPData" + }, + { + "$ref": "#/components/schemas/BrandData" + }, + { + "$ref": "#/components/schemas/KeywordData" + }, + { + "$ref": "#/components/schemas/AzureTenantData" + }, + { + "$ref": "#/components/schemas/DomainData" + }, + { + "$ref": "#/components/schemas/SearchQueryData" + }, + { + "$ref": "#/components/schemas/GithubRepositoryData" + }, + { + "$ref": "#/components/schemas/CredentialsData" + }, + { + "$ref": "#/components/schemas/EmailData" + }, + { + "$ref": "#/components/schemas/UsernameData" + }, + { + "$ref": "#/components/schemas/SecretData" + }, + { + "$ref": "#/components/schemas/NameData" + }, + { + "$ref": "#/components/schemas/IdentityDataRequestBody" } ], - "title": "Malware Family", - "description": "The malware family used for device infection." + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "azure_tenant": "#/components/schemas/AzureTenantData", + "bin": "#/components/schemas/CCBinData", + "brand": "#/components/schemas/BrandData", + "credentials": "#/components/schemas/CredentialsData", + "domain": "#/components/schemas/DomainData", + "email": "#/components/schemas/EmailData", + "github_repository": "#/components/schemas/GithubRepositoryData", + "identity": "#/components/schemas/IdentityDataRequestBody", + "ip": "#/components/schemas/IPData", + "keyword": "#/components/schemas/KeywordData", + "name": "#/components/schemas/NameData", + "search_query": "#/components/schemas/SearchQueryData", + "secret": "#/components/schemas/SecretData", + "username": "#/components/schemas/UsernameData" + } + } }, - "build_id": { + "name": { "anyOf": [ { "type": "string" @@ -8344,606 +9228,479 @@ "type": "null" } ], - "title": "Build Id", - "description": "The build ID of the malware used for device infection." + "title": "Name" }, - "file_location": { + "feed_config": { + "$ref": "#/components/schemas/FeedConfiguration" + }, + "collection": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/IdentifierCollectionGroupId" }, { - "type": "null" + "$ref": "#/components/schemas/IdentifierCollectionGroupType" } ], - "title": "File Location", - "description": "The file location of the malware used for device infection." + "title": "Collection" }, - "infected_at": { + "metadata": { + "$ref": "#/components/schemas/IdentifierMetadata" + }, + "matching_policies": { "anyOf": [ { - "type": "string", - "format": "date-time" + "items": { + "$ref": "#/components/schemas/IdentifierMatchingPolicyBody" + }, + "type": "array" }, { "type": "null" } ], - "title": "Infected At", - "description": "The date and time the malware was used to infect the victim's device." + "title": "Matching Policies" } }, "type": "object", - "title": "MalwareInformation" + "required": [ + "data", + "name", + "feed_config", + "collection", + "metadata" + ], + "title": "IdentifierRequestBody" }, - "MatchingPolicyAssignmentPayload": { + "IdentifierResponse": { "properties": { - "matching_policy": { - "$ref": "#/components/schemas/MatchingPolicyPayload" - }, - "assigned_at": { - "type": "string", - "format": "date-time", - "title": "Assigned At", - "description": "The date and time this policy was assigned to the identifier" + "identifier": { + "anyOf": [ + { + "$ref": "#/components/schemas/Identifier" + }, + { + "type": "null" + } + ] }, - "clean_past_events": { + "is_materialized": { "type": "boolean", - "title": "Clean Past Events", - "description": "Whether this policy has been applied to historical events" + "title": "Is Materialized", + "default": false + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "last_updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Updated At" } }, "type": "object", - "required": [ - "matching_policy", - "assigned_at", - "clean_past_events" - ], - "title": "MatchingPolicyAssignmentPayload" + "title": "IdentifierResponse" }, - "MatchingPolicyPayload": { + "IdentifierScope": { "properties": { - "uuid": { - "type": "string", - "format": "uuid4", - "title": "Uuid", - "description": "The UUID of the matching policy" - }, "name": { "type": "string", - "title": "Name", - "description": "The name of the matching policy" - }, - "policy_type": { - "$ref": "#/components/schemas/MatchingPolicyType", - "description": "The type of the matching policy" - }, - "value": { - "$ref": "#/components/schemas/PolicyValue", - "description": "The value of the matching policy depending on its type" - }, - "created_at": { - "type": "string", - "format": "date-time", - "title": "Created At", - "description": "The date and time the matching policy was created" + "title": "Name" }, - "last_updated_at": { - "type": "string", - "format": "date-time", - "title": "Last Updated At", - "description": "The date and time the matching policy was last updated" + "is_disabled": { + "type": "boolean", + "title": "Is Disabled", + "default": false } }, "type": "object", "required": [ - "uuid", - "name", - "policy_type", - "value", - "created_at", - "last_updated_at" + "name" ], - "title": "MatchingPolicyPayload" + "title": "IdentifierScope" }, - "MatchingPolicyType": { + "IdentifierSource": { "type": "string", "enum": [ - "INCLUDED_KEYWORDS", - "EXCLUDED_KEYWORDS", - "LUCENE_QUERY", - "ASTP_COOKIES", - "ASTP_DOMAIN" - ], - "title": "MatchingPolicyType" - }, - "MitigatedCredentialEvent": { - "properties": { - "event_type": { - "type": "string", - "const": "mitigated_credential", - "title": "Event Type", - "default": "mitigated_credential" - }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - }, - "data": { - "$ref": "#/components/schemas/MitigatedCredentialEventData" - } - }, - "type": "object", - "required": [ - "metadata", - "data" - ], - "title": "Mitigated Credential" - }, - "MitigatedCredentialEventData": { - "properties": { - "identity_name": { - "type": "string", - "title": "Identity Name", - "description": "The email or username associated with the credential." - }, - "credential_hash": { - "type": "string", - "title": "Credential Hash", - "description": "A hash uniquely identifying the credential." - }, - "tenant_integration_id": { - "type": "string", - "title": "Tenant Integration Id", - "description": "The UUID of the tenant's IdP integration that validated the credential." - }, - "mitigation_action": { - "type": "string", - "title": "Mitigation Action", - "description": "The action the tenant's IdP integration took to mitigate the credential" - } - }, - "type": "object", - "required": [ - "identity_name", - "credential_hash", - "tenant_integration_id", - "mitigation_action" - ], - "title": "MitigatedCredentialEventData" - }, - "NameData": { - "properties": { - "type": { - "type": "string", - "const": "name", - "title": "Type", - "default": "name" - }, - "first_name": { - "type": "string", - "title": "First Name" - }, - "last_name": { - "type": "string", - "title": "Last Name" - }, - "is_strict": { - "type": "boolean", - "title": "Is Strict" - } - }, - "type": "object", - "required": [ - "first_name", - "last_name", - "is_strict" + "USER", + "SYSTEM_RELATION", + "SELF_ONBOARDING", + "ATTRIBUTE", + "AUTO_MONITOR", + "IDP_SYNC" ], - "title": "NameData" + "title": "IdentifierSource" }, - "NameQuery": { + "IdentifierState": { "properties": { - "type": { - "type": "string", - "const": "name", - "title": "Type" - }, - "first_name": { - "type": "string", - "title": "First Name" + "source": { + "$ref": "#/components/schemas/IdentifierSource" }, - "last_name": { + "data_updated_at": { "type": "string", - "title": "Last Name" - }, - "is_strict": { - "type": "boolean", - "title": "Is Strict" - } - }, - "type": "object", - "required": [ - "type", - "first_name", - "last_name", - "is_strict" - ], - "title": "NameQuery" - }, - "OrderType": { - "type": "string", - "enum": [ - "asc", - "desc" - ], - "title": "OrderType" - }, - "PaginatedResults_Alert_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/Alert" - }, - "type": "array", - "title": "Items" + "format": "date-time", + "title": "Data Updated At" }, - "next": { + "event_count": { "anyOf": [ { - "type": "string" + "type": "integer" }, { "type": "null" } ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[Alert, str]" - }, - "PaginatedResults_Credential_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/Credential" - }, - "type": "array", - "title": "Items" + "title": "Event Count" }, - "next": { + "usage_count": { + "type": "integer", + "title": "Usage Count" + }, + "rate_limits": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/IdentifierFeedRateLimits" }, { "type": "null" } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[Credential, str]" - }, - "PaginatedResults_FeedItem_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/FeedItem" - }, - "type": "array", - "title": "Items" + ] }, - "next": { + "validation_status": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/IdentifierValidationStatus" }, { "type": "null" } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[FeedItem, str]" - }, - "PaginatedResults_GlobalFeedItem_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/GlobalFeedItem" - }, - "type": "array", - "title": "Items" + ] }, - "next": { + "authorization_request_status": { "anyOf": [ { - "type": "string" + "$ref": "#/components/schemas/IdentifierAuthorizationRequestStatus" }, { "type": "null" } - ], - "title": "Next" + ] } }, "type": "object", "required": [ - "items", - "next" + "source", + "data_updated_at", + "event_count", + "usage_count", + "rate_limits", + "validation_status", + "authorization_request_status" ], - "title": "PaginatedResults[GlobalFeedItem, str]" + "title": "IdentifierState" }, - "PaginatedResults_MatchingPolicyPayload_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/MatchingPolicyPayload" - }, - "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" + "IdentifierType": { + "type": "string", + "enum": [ + "domain", + "name", + "keyword", + "github_repository", + "username", + "email", + "search_query", + "bin", + "ip", + "secret", + "azure_tenant", + "identity", + "ransomleak", + "external_id", + "address_data", + "birth_year", + "role", + "phone_number" ], - "title": "PaginatedResults[MatchingPolicyPayload, str]" + "title": "IdentifierType" }, - "PaginatedResults_PartialAlertChannel_str_": { + "IdentifierValidationStatus": { + "type": "string", + "enum": [ + "FIRST_PARTY" + ], + "title": "IdentifierValidationStatus" + }, + "IdentityAttribute": { "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/PartialAlertChannel" - }, - "type": "array", - "title": "Items" + "asset_uuid": { + "type": "string", + "title": "Asset Uuid" }, - "next": { - "anyOf": [ + "data": { + "oneOf": [ { - "type": "string" + "$ref": "#/components/schemas/EmailData" }, { - "type": "null" + "$ref": "#/components/schemas/UsernameData" + }, + { + "$ref": "#/components/schemas/NameData" + }, + { + "$ref": "#/components/schemas/ExternalIdData" + }, + { + "$ref": "#/components/schemas/AddressData" + }, + { + "$ref": "#/components/schemas/BirthYearData" + }, + { + "$ref": "#/components/schemas/RoleData" + }, + { + "$ref": "#/components/schemas/PhoneNumberData" } ], - "title": "Next" + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "address_data": "#/components/schemas/AddressData", + "birth_year": "#/components/schemas/BirthYearData", + "email": "#/components/schemas/EmailData", + "external_id": "#/components/schemas/ExternalIdData", + "name": "#/components/schemas/NameData", + "phone_number": "#/components/schemas/PhoneNumberData", + "role": "#/components/schemas/RoleData", + "username": "#/components/schemas/UsernameData" + } + } } }, "type": "object", "required": [ - "items", - "next" + "asset_uuid", + "data" ], - "title": "PaginatedResults[PartialAlertChannel, str]" + "title": "IdentityAttribute" }, - "PaginatedResults_PolicyAssignedIdentifierPayload_str_": { + "IdentityData": { "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/PolicyAssignedIdentifierPayload" - }, - "type": "array", - "title": "Items" + "type": { + "type": "string", + "const": "identity", + "title": "Type", + "default": "identity" }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" + "uuid": { + "type": "string", + "minLength": 1, + "title": "Uuid" } }, "type": "object", "required": [ - "items", - "next" + "uuid" ], - "title": "PaginatedResults[PolicyAssignedIdentifierPayload, str]" + "title": "IdentityData" }, - "PaginatedResults_PublicIdentifierResponse_str_": { + "IdentityDataRequestBody": { "properties": { - "items": { + "type": { + "type": "string", + "const": "identity", + "title": "Type" + }, + "attributes": { "items": { - "$ref": "#/components/schemas/PublicIdentifierResponse" + "oneOf": [ + { + "$ref": "#/components/schemas/EmailData" + }, + { + "$ref": "#/components/schemas/UsernameData" + }, + { + "$ref": "#/components/schemas/NameData" + }, + { + "$ref": "#/components/schemas/ExternalIdData" + }, + { + "$ref": "#/components/schemas/AddressData" + }, + { + "$ref": "#/components/schemas/BirthYearData" + }, + { + "$ref": "#/components/schemas/RoleData" + }, + { + "$ref": "#/components/schemas/PhoneNumberData" + } + ], + "discriminator": { + "propertyName": "type", + "mapping": { + "address_data": "#/components/schemas/AddressData", + "birth_year": "#/components/schemas/BirthYearData", + "email": "#/components/schemas/EmailData", + "external_id": "#/components/schemas/ExternalIdData", + "name": "#/components/schemas/NameData", + "phone_number": "#/components/schemas/PhoneNumberData", + "role": "#/components/schemas/RoleData", + "username": "#/components/schemas/UsernameData" + } + } }, "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" + "maxItems": 15, + "minItems": 1, + "title": "Attributes" } }, "type": "object", "required": [ - "items", - "next" + "type", + "attributes" ], - "title": "PaginatedResults[PublicIdentifierResponse, str]" + "title": "IdentityDataRequestBody" }, - "PaginatedResults_PublicReport_str_": { + "IdentityIdentifierEntity": { "properties": { - "items": { + "type": { + "$ref": "#/components/schemas/IdentifierEntityType" + }, + "attributes": { "items": { - "$ref": "#/components/schemas/PublicReport" + "$ref": "#/components/schemas/IdentityAttribute" }, "type": "array", - "title": "Items" - }, - "next": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Next" + "title": "Attributes" } }, "type": "object", "required": [ - "items", - "next" + "type", + "attributes" ], - "title": "PaginatedResults[PublicReport, str]" + "title": "IdentityIdentifierEntity" }, - "PaginatedResults_PydanticThreatFlowReport_str_": { + "IncludeOptions": { + "type": "string", + "enum": [ + "known_password_id", + "auth_domains", + "urls" + ], + "title": "IncludeOptions" + }, + "IndicatorEntityAPIResponse": { "properties": { - "items": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { "items": { - "$ref": "#/components/schemas/PydanticThreatFlowReport" + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" }, "type": "array", - "title": "Items" + "title": "Sources" }, - "next": { + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[PydanticThreatFlowReport, str]" - }, - "PaginatedResults_Recommendation_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/Recommendation" - }, - "type": "array", - "title": "Items" + "title": "Created At" }, - "next": { + "updated_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[Recommendation, str]" - }, - "PaginatedResults_StealerLogCookie_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/StealerLogCookie" - }, - "type": "array", - "title": "Items" + "title": "Updated At" }, - "next": { + "first_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[StealerLogCookie, str]" - }, - "PaginatedResults_StealerLogCredential_str_": { - "properties": { - "items": { - "items": { - "$ref": "#/components/schemas/StealerLogCredential" - }, - "type": "array", - "title": "Items" + "title": "First Seen At" }, - "next": { + "last_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Next" - } - }, - "type": "object", - "required": [ - "items", - "next" - ], - "title": "PaginatedResults[StealerLogCredential, str]" - }, - "ParentContext": { - "properties": { - "parent_uid": { + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "pattern": { + "type": "string", + "title": "Pattern" + }, + "description": { "anyOf": [ { "type": "string" @@ -8952,9 +9709,9 @@ "type": "null" } ], - "title": "Parent Uid" + "title": "Description" }, - "parent_type": { + "pattern_version": { "anyOf": [ { "type": "string" @@ -8963,123 +9720,162 @@ "type": "null" } ], - "title": "Parent Type" - } - }, - "type": "object", - "title": "ParentContext" - }, - "PartialAlertChannel": { - "properties": { - "id": { - "type": "integer", - "title": "Id" + "title": "Pattern Version" }, - "name": { - "type": "string", - "title": "Name" + "indicator_types": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Indicator Types" }, - "type": { - "$ref": "#/components/schemas/AlertType" + "valid_from": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Valid From" }, - "state": { - "$ref": "#/components/schemas/AlertChannelState" + "valid_until": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Valid Until" }, - "alert_count": { - "type": "integer", - "title": "Alert Count" + "kill_chain_phases": { + "items": { + "$ref": "#/components/schemas/KillChainAPIResponse" + }, + "type": "array", + "title": "Kill Chain Phases" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" } }, "type": "object", "required": [ - "id", - "name", + "uuid", "type", - "state", - "alert_count" + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "pattern", + "description", + "pattern_version", + "indicator_types", + "valid_from", + "valid_until", + "kill_chain_phases", + "marking_definitions" ], - "title": "PartialAlertChannel" + "title": "IndicatorEntityAPIResponse" }, - "PasteEvent": { + "IndicatorEntityLiteAPIResponse": { "properties": { - "event_type": { + "uuid": { "type": "string", - "const": "paste", - "title": "Event Type", - "default": "paste" + "title": "Uuid" }, - "data": { - "$ref": "#/components/schemas/PasteEventData" + "type": { + "$ref": "#/components/schemas/EntityType" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - } - }, - "type": "object", - "required": [ - "data", - "metadata" - ], - "title": "Paste" - }, - "PasteEventData": { - "properties": { - "url": { + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Url" + "title": "Created At" }, - "title": { + "updated_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Title" + "title": "Updated At" }, - "content": { + "first_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Content" + "title": "First Seen At" }, - "actor": { + "last_seen_at": { "anyOf": [ { - "$ref": "#/components/schemas/pyro__findings__paste__datamodels__PasteEventData__Actor" + "type": "string", + "format": "date-time" }, { "type": "null" } - ] + ], + "title": "Last Seen At" }, - "expires_at": { + "confidence": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "integer" }, { "type": "null" } ], - "title": "Expires At" + "title": "Confidence" }, - "syntax": { + "pattern": { + "type": "string", + "title": "Pattern" + }, + "description": { "anyOf": [ { "type": "string" @@ -9088,153 +9884,107 @@ "type": "null" } ], - "title": "Syntax" + "title": "Description" } }, "type": "object", - "title": "PasteEventData" + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "pattern", + "description" + ], + "title": "IndicatorEntityLiteAPIResponse" }, - "PhoneNumberData": { + "InfrastructureEntityAPIResponse": { "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { "type": "string", - "const": "phone_number", - "title": "Type", - "default": "phone_number" + "title": "Name" }, - "phone_number": { + "created_by": { "type": "string", - "minLength": 7, - "title": "Phone Number" - } - }, - "type": "object", - "required": [ - "phone_number" - ], - "title": "PhoneNumberData" - }, - "PolicyAssignedIdentifierPayload": { - "properties": { - "identifier_id": { - "type": "integer", - "title": "Identifier Id", - "description": "The ID of the identifier this policy is assigned to" - }, - "identifier_name": { - "type": "string", - "title": "Identifier Name", - "description": "The name of the identifier this policy is assigned to" - }, - "clean_past_events": { - "type": "boolean", - "title": "Clean Past Events", - "description": "Whether this policy has been applied to historical events" + "title": "Created By" }, - "assigned_at": { - "type": "string", - "format": "date-time", - "title": "Assigned At", - "description": "The date and time this policy was assigned to the identifier" - } - }, - "type": "object", - "required": [ - "identifier_id", - "identifier_name", - "clean_past_events", - "assigned_at" - ], - "title": "PolicyAssignedIdentifierPayload" - }, - "PolicyAssignmentsBody": { - "properties": { - "identifier_ids": { + "sources": { "items": { - "type": "integer" + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" }, "type": "array", - "title": "Identifier Ids", - "description": "The IDs of the identifiers to assign the policy to" - }, - "clean_past_events": { - "type": "boolean", - "title": "Clean Past Events", - "description": "Whether this policy will be applied to historical events", - "default": false - } - }, - "type": "object", - "required": [ - "identifier_ids" - ], - "title": "PolicyAssignmentsBody" - }, - "PolicyValue": { - "anyOf": [ - { - "$ref": "#/components/schemas/KeywordsValue" - }, - { - "$ref": "#/components/schemas/LuceneValue" - }, - { - "$ref": "#/components/schemas/AstpCookiesValue" + "title": "Sources" }, - { - "$ref": "#/components/schemas/AstpDomainValue" - } - ] - }, - "PublicIdentifierRequestBody": { - "properties": { - "data": { - "oneOf": [ + "created_at": { + "anyOf": [ { - "$ref": "#/components/schemas/CCBinData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/IPData" - }, + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ { - "$ref": "#/components/schemas/KeywordData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/AzureTenantData" - }, + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ { - "$ref": "#/components/schemas/DomainData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/SearchQueryData" - }, + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ { - "$ref": "#/components/schemas/GithubRepositoryData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/SecretData" + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" }, { - "$ref": "#/components/schemas/PublicIdentityData" + "type": "null" } ], - "title": "Data", - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantData", - "bin": "#/components/schemas/CCBinData", - "domain": "#/components/schemas/DomainData", - "github_repository": "#/components/schemas/GithubRepositoryData", - "identity": "#/components/schemas/PublicIdentityData", - "ip": "#/components/schemas/IPData", - "keyword": "#/components/schemas/KeywordData", - "search_query": "#/components/schemas/SearchQueryData", - "secret": "#/components/schemas/SecretData" - } - } + "title": "Confidence" }, - "name": { + "description": { "anyOf": [ { "type": "string" @@ -9243,426 +9993,330 @@ "type": "null" } ], - "title": "Name" + "title": "Description" }, - "categories": { + "aliases": { "items": { - "$ref": "#/components/schemas/SearchType" + "type": "string" }, "type": "array", - "title": "Categories" + "title": "Aliases" }, - "emerging_categories": { + "infrastructure_types": { "items": { "type": "string" }, "type": "array", - "title": "Emerging Categories" + "title": "Infrastructure Types" }, - "severities": { + "kill_chain_phases": { "items": { - "$ref": "#/components/schemas/Severity" + "$ref": "#/components/schemas/KillChainAPIResponse" }, "type": "array", - "title": "Severities" + "title": "Kill Chain Phases" }, - "group_id": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Group Id" + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" } }, "type": "object", "required": [ - "data", - "categories", - "emerging_categories", - "severities" + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases", + "infrastructure_types", + "kill_chain_phases", + "marking_definitions" ], - "title": "PublicIdentifierRequestBody" + "title": "InfrastructureEntityAPIResponse" }, - "PublicIdentifierResponse": { + "InfrastructureEntityLiteAPIResponse": { "properties": { - "id": { - "type": "integer", - "title": "Id" + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" }, "name": { "type": "string", "title": "Name" }, - "tenant_id": { - "type": "integer", - "title": "Tenant Id" + "created_by": { + "type": "string", + "title": "Created By" }, - "data": { - "oneOf": [ + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ { - "$ref": "#/components/schemas/CCBinData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/IPData" - }, + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ { - "$ref": "#/components/schemas/KeywordData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/AzureTenantData" - }, + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ { - "$ref": "#/components/schemas/DomainData" + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/SearchQueryData" + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" }, { - "$ref": "#/components/schemas/GithubRepositoryData" + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" }, { - "$ref": "#/components/schemas/SecretData" + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" }, { - "$ref": "#/components/schemas/PublicIdentityData" + "type": "null" } ], - "title": "Data", - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantData", - "bin": "#/components/schemas/CCBinData", - "domain": "#/components/schemas/DomainData", - "github_repository": "#/components/schemas/GithubRepositoryData", - "identity": "#/components/schemas/PublicIdentityData", - "ip": "#/components/schemas/IPData", - "keyword": "#/components/schemas/KeywordData", - "search_query": "#/components/schemas/SearchQueryData", - "secret": "#/components/schemas/SecretData" - } - } - }, - "categories": { - "items": { - "$ref": "#/components/schemas/SearchType" - }, - "type": "array", - "title": "Categories" + "title": "Description" }, - "emerging_categories": { + "aliases": { "items": { "type": "string" }, "type": "array", - "title": "Emerging Categories" - }, - "severities": { - "items": { - "$ref": "#/components/schemas/Severity" - }, - "type": "array", - "title": "Severities" - }, - "group_id": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Group Id" - }, - "enrichments": { - "anyOf": [ - { - "$ref": "#/components/schemas/IdentifierEnrichments" - }, - { - "type": "null" - } - ] - }, - "is_disabled": { - "type": "boolean", - "title": "Is Disabled" - }, - "updated_at": { - "type": "string", - "format": "date-time", - "title": "Updated At" + "title": "Aliases" } }, "type": "object", "required": [ - "id", + "uuid", + "type", "name", - "tenant_id", - "data", - "categories", - "emerging_categories", - "severities", - "group_id", - "enrichments", - "is_disabled", - "updated_at" + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases" ], - "title": "IdentifierResponse" + "title": "InfrastructureEntityLiteAPIResponse" }, - "PublicIdentifierUpdateRequestBody": { + "IntelType": { + "type": "string", + "enum": [ + "unit_summary_based", + "custom_intel" + ], + "title": "IntelType" + }, + "InvalidCredentialEvent": { "properties": { - "data": { - "oneOf": [ - { - "$ref": "#/components/schemas/CCBinData" - }, - { - "$ref": "#/components/schemas/IPData" - }, - { - "$ref": "#/components/schemas/KeywordData" - }, - { - "$ref": "#/components/schemas/AzureTenantData" - }, - { - "$ref": "#/components/schemas/DomainData" - }, - { - "$ref": "#/components/schemas/SearchQueryData" - }, - { - "$ref": "#/components/schemas/GithubRepositoryData" - }, - { - "$ref": "#/components/schemas/SecretData" - }, - { - "$ref": "#/components/schemas/PublicIdentityData" - } - ], - "title": "Data", - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantData", - "bin": "#/components/schemas/CCBinData", - "domain": "#/components/schemas/DomainData", - "github_repository": "#/components/schemas/GithubRepositoryData", - "identity": "#/components/schemas/PublicIdentityData", - "ip": "#/components/schemas/IPData", - "keyword": "#/components/schemas/KeywordData", - "search_query": "#/components/schemas/SearchQueryData", - "secret": "#/components/schemas/SecretData" - } - } - }, - "name": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Name" - }, - "categories": { - "items": { - "$ref": "#/components/schemas/SearchType" - }, - "type": "array", - "title": "Categories" - }, - "emerging_categories": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Emerging Categories" - }, - "severities": { - "items": { - "$ref": "#/components/schemas/Severity" - }, - "type": "array", - "title": "Severities" + "event_type": { + "type": "string", + "const": "invalid_credential", + "title": "Event Type", + "default": "invalid_credential" }, - "group_id": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Group Id" + "metadata": { + "$ref": "#/components/schemas/EventMetadata" }, - "is_disabled": { - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "null" - } - ], - "title": "Is Disabled" + "data": { + "$ref": "#/components/schemas/CredentialEventData" } }, "type": "object", "required": [ - "data", - "categories", - "emerging_categories", - "severities" + "metadata", + "data" ], - "title": "PublicIdentifierUpdateRequestBody" + "title": "Invalid Credential" }, - "PublicIdentityData": { + "IpQuery": { "properties": { "type": { "type": "string", - "const": "identity", - "title": "Type", - "default": "identity" + "const": "ip", + "title": "Type" }, - "attributes": { - "items": { - "oneOf": [ - { - "$ref": "#/components/schemas/EmailData" - }, - { - "$ref": "#/components/schemas/UsernameData" - }, - { - "$ref": "#/components/schemas/NameData" - } - ], - "discriminator": { - "propertyName": "type", - "mapping": { - "email": "#/components/schemas/EmailData", - "name": "#/components/schemas/NameData", - "username": "#/components/schemas/UsernameData" - } - } - }, - "type": "array", - "maxItems": 15, - "minItems": 1, - "title": "Attributes" + "ip": { + "type": "string", + "title": "Ip" } }, "type": "object", "required": [ - "attributes" + "type", + "ip" ], - "title": "IdentityData" + "title": "IpQuery" }, - "PublicReport": { + "KeywordData": { "properties": { - "id": { - "type": "integer", - "title": "Id" - }, - "title": { + "type": { "type": "string", - "title": "Title" + "const": "keyword", + "title": "Type", + "default": "keyword" }, - "author": { + "keyword": { "type": "string", - "title": "Author" - }, - "tenant_id": { - "type": "integer", - "title": "Tenant Id" - }, - "report_group_id": { - "type": "integer", - "title": "Report Group Id" - }, - "report_type": { - "$ref": "#/components/schemas/ReportType-Output" - }, - "status": { - "$ref": "#/components/schemas/ReportStatus" - }, - "created_at": { + "minLength": 1, + "title": "Keyword" + } + }, + "type": "object", + "required": [ + "keyword" + ], + "title": "KeywordData" + }, + "KeywordQuery": { + "properties": { + "type": { "type": "string", - "format": "date-time", - "title": "Created At" + "const": "keyword", + "title": "Type" }, - "updated_at": { + "keyword": { "type": "string", - "format": "date-time", - "title": "Updated At" - }, - "is_archived": { - "type": "boolean", - "title": "Is Archived" + "title": "Keyword" } }, "type": "object", "required": [ - "id", - "title", - "author", - "tenant_id", - "report_group_id", - "report_type", - "status", - "created_at", - "updated_at", - "is_archived" + "type", + "keyword" ], - "title": "PublicReport" + "title": "KeywordQuery" }, - "PublishReportPayload": { + "KeywordsValue": { "properties": { - "title": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Title" + "keywords": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Keywords" } }, "type": "object", - "title": "PublishReportPayload" + "required": [ + "keywords" + ], + "title": "KeywordsValue" }, - "PydanticThreatFlowReport": { + "KillChainAPIResponse": { "properties": { - "id": { - "type": "integer", - "title": "Id" + "kill_chain_name": { + "type": "string", + "title": "Kill Chain Name" }, - "format_type": { - "$ref": "#/components/schemas/ThreatFlowReportFormatType", - "default": "simple_summary" + "phase_name": { + "type": "string", + "title": "Phase Name" + } + }, + "type": "object", + "required": [ + "kill_chain_name", + "phase_name" + ], + "title": "KillChainAPIResponse" + }, + "Language": { + "type": "string", + "enum": [ + "en", + "fr" + ], + "title": "Language" + }, + "LeakEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "leak", + "title": "Event Type", + "default": "leak" }, - "intel_type": { - "$ref": "#/components/schemas/IntelType", - "default": "unit_summary_based" + "metadata": { + "$ref": "#/components/schemas/EventMetadata" }, - "title": { + "data": { + "$ref": "#/components/schemas/LeakEventData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "Leak" + }, + "LeakEventData": { + "properties": { + "term": { "type": "string", - "title": "Title" + "title": "Term", + "description": "The search term that matched this leak." }, - "subtitle": { + "site_url": { "anyOf": [ { "type": "string" @@ -9671,54 +10325,23 @@ "type": "null" } ], - "title": "Subtitle" - }, - "summary": { - "type": "string", - "title": "Summary" - }, - "content": { - "type": "string", - "title": "Content" - }, - "tags": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Tags" - }, - "highlights": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Highlights" - }, - "related_activity_uids": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Related Activity Uids" + "title": "Site Url", + "description": "The URL of the site the leak originated from." }, - "prompt_preset_uid": { + "leaked_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Prompt Preset Uid" - }, - "created_at": { - "type": "string", - "format": "date-time", - "title": "Created At" + "title": "Leaked At", + "description": "When the leak occurred." }, - "published_at": { + "breached_at": { "anyOf": [ { "type": "string", @@ -9728,116 +10351,149 @@ "type": "null" } ], - "title": "Published At" - }, - "updated_at": { - "type": "string", - "format": "date-time", - "title": "Updated At" + "title": "Breached At", + "description": "When the breach was disclosed." }, - "reading_time": { + "leaked_credential_count": { "type": "integer", - "title": "Reading Time" + "title": "Leaked Credential Count", + "description": "Number of credentials contained in this leak." }, - "tenant_id": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Tenant Id" + "pii_tags": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Pii Tags", + "description": "PII categories present in this leak." }, - "organization_id": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ], - "title": "Organization Id" + "source": { + "$ref": "#/components/schemas/LeakEventSource", + "description": "The source of the leak." } }, "type": "object", "required": [ - "id", - "title", - "subtitle", - "summary", - "content", - "tags", - "highlights", - "related_activity_uids", - "prompt_preset_uid", - "created_at", - "published_at", - "updated_at", - "reading_time", - "tenant_id", - "organization_id" + "term", + "leaked_credential_count", + "source" ], - "title": "PydanticThreatFlowReport" + "title": "LeakEventData" }, - "QueryStringQuery": { + "LeakEventSource": { "properties": { - "type": { + "id": { "type": "string", - "const": "query_string", - "title": "Type" + "title": "Id", + "description": "The identifier of the leak source category." }, - "query_string": { + "name": { "type": "string", - "maxLength": 10000, - "title": "Query String" + "title": "Name", + "description": "The name of the leak source category." } }, "type": "object", "required": [ - "type", - "query_string" + "id", + "name" ], - "title": "QueryStringQuery" + "title": "LeakEventSource" }, - "RansomLeakData": { + "LeakedCredentialEvent": { "properties": { - "type": { + "event_type": { "type": "string", - "const": "ransomleak", - "title": "Type", - "default": "ransomleak" + "const": "leaked_credential", + "title": "Event Type", + "default": "leaked_credential" }, - "source": { + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + }, + "data": { + "$ref": "#/components/schemas/LeakedCredentialEventData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "Leaked Credential" + }, + "LeakedCredentialEventData": { + "properties": { + "identity_name": { "type": "string", - "minLength": 1, - "title": "Source" + "title": "Identity Name", + "description": "The email or username associated with the leaked credential." + }, + "imported_at": { + "type": "string", + "format": "date-time", + "title": "Imported At", + "description": "When the credential was imported into Flare." + }, + "password": { + "type": "string", + "title": "Password", + "description": "The leaked password, or its hash if not available in cleartext." }, + "source": { + "$ref": "#/components/schemas/LeakedCredentialEventSource", + "description": "The source the credential was leaked from." + } + }, + "type": "object", + "required": [ + "identity_name", + "imported_at", + "password", + "source" + ], + "title": "LeakedCredentialEventData" + }, + "LeakedCredentialEventSource": { + "properties": { "id": { "type": "string", - "minLength": 1, - "title": "Id" + "title": "Id", + "description": "The identifier of the leak source category." + }, + "name": { + "type": "string", + "title": "Name", + "description": "The name of the leak source category." } }, "type": "object", "required": [ - "source", - "id" + "id", + "name" ], - "title": "RansomLeakData" + "title": "LeakedCredentialEventSource" }, - "RansomLeakEvent": { + "LeakedCredentialsBulkActionType": { + "type": "string", + "enum": [ + "remediate", + "unremediate", + "ignore", + "unignore" + ], + "title": "LeakedCredentialsBulkActionType" + }, + "ListingEvent": { "properties": { "event_type": { "type": "string", - "const": "ransomleak", + "const": "listing", "title": "Event Type", - "default": "ransomleak" + "default": "listing" }, "data": { - "$ref": "#/components/schemas/RansomLeakEventData" + "$ref": "#/components/schemas/ListingEventData" }, "metadata": { "$ref": "#/components/schemas/EventMetadata" @@ -9848,9 +10504,9 @@ "data", "metadata" ], - "title": "Ransom Leak" + "title": "Listing" }, - "RansomLeakEventData": { + "ListingEventData": { "properties": { "url": { "anyOf": [ @@ -9862,19 +10518,7 @@ } ], "title": "Url", - "description": "The URL of the ransom leak post." - }, - "response_url": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], - "title": "Response Url", - "description": "The URL of the response to the ransom leak post." + "description": "The URL to the listing." }, "title": { "anyOf": [ @@ -9886,7 +10530,7 @@ } ], "title": "Title", - "description": "The title of the ransom leak post." + "description": "The title of the listing." }, "content": { "anyOf": [ @@ -9898,9 +10542,9 @@ } ], "title": "Content", - "description": "The content of the ransom leak post." + "description": "The content within the listing." }, - "body": { + "currency": { "anyOf": [ { "type": "string" @@ -9909,138 +10553,163 @@ "type": "null" } ], - "title": "Body", - "description": "The body of the ransom leak post." + "title": "Currency", + "description": "The currency expected in the listing." }, - "victim_information": { + "escrow": { "anyOf": [ { - "$ref": "#/components/schemas/pyro__findings__ransomleaks__datamodels__VictimInformation" + "type": "boolean" }, { "type": "null" } ], - "description": "The information relating to the victim of the ransom leak." - } - }, - "type": "object", - "title": "RansomLeakEventData" - }, - "Recommendation": { - "properties": { - "id": { - "type": "integer", - "title": "Id" + "title": "Escrow", + "description": "Whether the listing requires escrow." }, - "data": { - "oneOf": [ - { - "$ref": "#/components/schemas/DomainData" - }, - { - "$ref": "#/components/schemas/AzureTenantData" - }, + "price": { + "anyOf": [ { - "$ref": "#/components/schemas/EmailData" + "type": "number" }, { - "$ref": "#/components/schemas/UsernameData" + "type": "null" } ], - "title": "Data", - "discriminator": { - "propertyName": "type", - "mapping": { - "azure_tenant": "#/components/schemas/AzureTenantData", - "domain": "#/components/schemas/DomainData", - "email": "#/components/schemas/EmailData", - "username": "#/components/schemas/UsernameData" - } - } - } - }, - "type": "object", - "required": [ - "id", - "data" - ], - "title": "Recommendation" - }, - "RelatedConversationRequest": { - "properties": { - "uid": { - "type": "string", - "title": "Uid" + "title": "Price", + "description": "The price of the listing." }, - "direction": { - "$ref": "#/components/schemas/ConversationSearchAfterDirection", - "default": "next" + "ship_to": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Ship To", + "description": "The countries eligible for shipping.", + "default": [] }, - "size": { - "type": "integer", - "title": "Size", - "default": 10 + "ship_from": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Ship From", + "description": "The countries eligible for shipping.", + "default": [] }, - "search_after": { + "stock_count": { "anyOf": [ { - "type": "string" + "type": "integer" }, { "type": "null" } ], - "title": "Search After" + "title": "Stock Count", + "description": "The quantity of the items or service in stock." }, - "should_translate": { - "type": "boolean", - "title": "Should Translate", - "default": false + "actor": { + "$ref": "#/components/schemas/pyro__findings__listing__datamodels__ListingEventData__Actor", + "description": "Data about the seller." + }, + "classification": { + "$ref": "#/components/schemas/Classification", + "description": "Data about the possible classifications of the listing." + }, + "context": { + "$ref": "#/components/schemas/pyro__findings__listing__datamodels__ListingEventData__Context", + "description": "Data offering context to the listing." } }, "type": "object", - "required": [ - "uid" - ], - "title": "RelatedConversationRequest" + "title": "ListingEventData" }, - "RelatedConversationResponse": { + "LocationEntityAPIResponse": { "properties": { - "conversation_messages": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { "items": { - "$ref": "#/components/schemas/ConversationMessage" + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" }, "type": "array", - "title": "Conversation Messages" - }, - "conversation_name": { - "type": "string", - "title": "Conversation Name" + "title": "Sources" }, - "conversation_name_en": { + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Conversation Name En" + "title": "Created At" }, - "next": { + "updated_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Next" + "title": "Updated At" }, - "previous": { + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { "anyOf": [ { "type": "string" @@ -10049,70 +10718,91 @@ "type": "null" } ], - "title": "Previous" - } - }, - "type": "object", - "required": [ - "conversation_messages", - "conversation_name" - ], - "title": "RelatedConversationResponse" - }, - "ReportDownloadFormat": { - "type": "string", - "enum": [ - "docx", - "pdf", - "csv", - "zip" - ], - "title": "ReportDownloadFormat" - }, - "ReportRequestInfoResponse": { - "properties": { - "status": { - "$ref": "#/components/schemas/RequestStatus" + "title": "Description" }, - "report": { + "country_code": { "anyOf": [ { - "$ref": "#/components/schemas/ApiReport" + "type": "string" }, { "type": "null" } - ] + ], + "title": "Country Code" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" } }, "type": "object", "required": [ - "status" + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "country_code", + "marking_definitions" ], - "title": "ReportRequestInfoResponse" + "title": "LocationEntityAPIResponse" }, - "ReportRequestPayload": { + "LocationEntityLiteAPIResponse": { "properties": { - "report_title": { + "uuid": { "type": "string", - "title": "Report Title" + "title": "Uuid" }, - "question": { + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Question" + "title": "Created At" }, - "time_range_type": { - "$ref": "#/components/schemas/TimeRangeType", - "default": "all" + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" }, - "time_range_from": { + "first_seen_at": { "anyOf": [ { "type": "string", @@ -10122,9 +10812,9 @@ "type": "null" } ], - "title": "Time Range From" + "title": "First Seen At" }, - "time_range_to": { + "last_seen_at": { "anyOf": [ { "type": "string", @@ -10134,328 +10824,3435 @@ "type": "null" } ], - "title": "Time Range To" + "title": "Last Seen At" }, - "included_keywords": { + "confidence": { "anyOf": [ { - "items": { - "type": "string" - }, - "type": "array" + "type": "integer" }, { "type": "null" } ], - "title": "Included Keywords" + "title": "Confidence" }, - "excluded_keywords": { + "description": { "anyOf": [ { - "items": { - "type": "string" - }, - "type": "array" + "type": "string" }, { "type": "null" } ], - "title": "Excluded Keywords" - } - }, - "type": "object", - "required": [ - "report_title" - ], - "title": "ReportRequestPayload" - }, - "ReportRequestResponse": { - "properties": { - "request_id": { - "type": "string", - "format": "uuid", - "title": "Request Id" + "title": "Description" } }, "type": "object", "required": [ - "request_id" - ], - "title": "ReportRequestResponse" - }, - "ReportStatus": { - "type": "string", - "enum": [ - "draft", - "processing", - "completed", - "scheduled", - "paused" - ], - "title": "ReportStatus" - }, - "ReportType-Output": { - "type": "string", - "enum": [ - "v1", - "event_based", - "feed_based" - ], - "title": "ReportType" - }, - "RequestStatus": { - "type": "string", - "enum": [ - "processing", - "completed", - "error" - ], - "title": "RequestStatus" - }, - "RiskScore": { - "type": "integer", - "enum": [ - 1, - 2, - 3, - 4, - 5 + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description" ], - "title": "RiskScore" + "title": "LocationEntityLiteAPIResponse" }, - "RoleData": { + "LookalikeDomainEvent": { "properties": { - "type": { + "event_type": { "type": "string", - "const": "role", - "title": "Type", - "default": "role" + "const": "lookalike", + "title": "Event Type", + "default": "lookalike" }, - "role": { - "type": "string", - "minLength": 1, - "title": "Role" - } - }, - "type": "object", - "required": [ - "role" - ], - "title": "RoleData" - }, - "SandboxUploadPutUrlResponse": { - "properties": { - "upload_url": { - "type": "string", - "title": "Upload Url" + "data": { + "$ref": "#/components/schemas/LookalikeDomainEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" } }, "type": "object", "required": [ - "upload_url" + "data", + "metadata" ], - "title": "SandboxUploadPutUrlResponse" + "title": "Lookalike Domain" }, - "SandboxUploadUrlRequest": { + "LookalikeDomainEventData": { "properties": { - "filename": { + "domain": { "type": "string", - "title": "Filename" - } - }, - "type": "object", - "required": [ - "filename" - ], - "title": "SandboxUploadUrlRequest" - }, - "SearchQueryData": { + "title": "Domain", + "description": "The domain of the lookalike domain." + }, + "registered_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Registered At", + "description": "The date and time the lookalike domain was registered." + }, + "identifier_domains": { + "anyOf": [ + { + "items": { + "type": "string" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Identifier Domains", + "description": "Domain identifiers matching the lookalike domains" + }, + "feed": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Feed", + "description": "The feed where the lookalike domain was found" + }, + "cert_data": { + "anyOf": [ + { + "additionalProperties": true, + "type": "object" + }, + { + "type": "null" + } + ], + "title": "Cert Data", + "description": "The certificate data of the lookalike domain." + }, + "subject": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Subject", + "description": "The subject of the certificate of the lookalike domain." + }, + "issuer": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Issuer", + "description": "The issuer of the certificate of the lookalike domain." + } + }, + "type": "object", + "required": [ + "domain" + ], + "title": "LookalikeDomainEventData" + }, + "LuceneValue": { + "properties": { + "query": { + "type": "string", + "title": "Query", + "description": "The lucene query of the matching policy" + } + }, + "type": "object", + "required": [ + "query" + ], + "title": "LuceneValue" + }, + "MalwareEntityAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + }, + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + }, + "malware_types": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Malware Types" + }, + "kill_chain_phases": { + "items": { + "$ref": "#/components/schemas/KillChainAPIResponse" + }, + "type": "array", + "title": "Kill Chain Phases" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases", + "malware_types", + "kill_chain_phases", + "marking_definitions" + ], + "title": "MalwareEntityAPIResponse" + }, + "MalwareEntityLiteAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + }, + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases" + ], + "title": "MalwareEntityLiteAPIResponse" + }, + "MalwareInformation": { + "properties": { + "malware_family": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Malware Family", + "description": "The malware family used for device infection." + }, + "build_id": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Build Id", + "description": "The build ID of the malware used for device infection." + }, + "file_location": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "File Location", + "description": "The file location of the malware used for device infection." + }, + "infected_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Infected At", + "description": "The date and time the malware was used to infect the victim's device." + } + }, + "type": "object", + "title": "MalwareInformation" + }, + "MarkingDefinition": { + "properties": { + "id": { + "type": "string", + "title": "Id" + }, + "definition_type": { + "$ref": "#/components/schemas/MarkingDefinitionType" + }, + "name": { + "type": "string", + "title": "Name" + } + }, + "type": "object", + "required": [ + "id", + "definition_type", + "name" + ], + "title": "MarkingDefinition" + }, + "MarkingDefinitionType": { + "type": "string", + "enum": [ + "tlp" + ], + "title": "MarkingDefinitionType" + }, + "MatchingPolicyAssignmentPayload": { + "properties": { + "matching_policy": { + "$ref": "#/components/schemas/MatchingPolicyPayload" + }, + "assigned_at": { + "type": "string", + "format": "date-time", + "title": "Assigned At", + "description": "The date and time this policy was assigned to the identifier" + }, + "clean_past_events": { + "type": "boolean", + "title": "Clean Past Events", + "description": "Whether this policy has been applied to historical events" + } + }, + "type": "object", + "required": [ + "matching_policy", + "assigned_at", + "clean_past_events" + ], + "title": "MatchingPolicyAssignmentPayload" + }, + "MatchingPolicyPayload": { + "properties": { + "uuid": { + "type": "string", + "format": "uuid4", + "title": "Uuid", + "description": "The UUID of the matching policy" + }, + "name": { + "type": "string", + "title": "Name", + "description": "The name of the matching policy" + }, + "policy_type": { + "$ref": "#/components/schemas/MatchingPolicyType", + "description": "The type of the matching policy" + }, + "value": { + "$ref": "#/components/schemas/PolicyValue", + "description": "The value of the matching policy depending on its type" + }, + "created_at": { + "type": "string", + "format": "date-time", + "title": "Created At", + "description": "The date and time the matching policy was created" + }, + "last_updated_at": { + "type": "string", + "format": "date-time", + "title": "Last Updated At", + "description": "The date and time the matching policy was last updated" + } + }, + "type": "object", + "required": [ + "uuid", + "name", + "policy_type", + "value", + "created_at", + "last_updated_at" + ], + "title": "MatchingPolicyPayload" + }, + "MatchingPolicyType": { + "type": "string", + "enum": [ + "INCLUDED_KEYWORDS", + "EXCLUDED_KEYWORDS", + "LUCENE_QUERY", + "ASTP_COOKIES", + "ASTP_DOMAIN" + ], + "title": "MatchingPolicyType" + }, + "MitigatedCredentialEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "mitigated_credential", + "title": "Event Type", + "default": "mitigated_credential" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + }, + "data": { + "$ref": "#/components/schemas/MitigatedCredentialEventData" + } + }, + "type": "object", + "required": [ + "metadata", + "data" + ], + "title": "Mitigated Credential" + }, + "MitigatedCredentialEventData": { + "properties": { + "identity_name": { + "type": "string", + "title": "Identity Name", + "description": "The email or username associated with the credential." + }, + "credential_hash": { + "type": "string", + "title": "Credential Hash", + "description": "A hash uniquely identifying the credential." + }, + "tenant_integration_id": { + "type": "string", + "title": "Tenant Integration Id", + "description": "The UUID of the tenant's IdP integration that validated the credential." + }, + "mitigation_action": { + "type": "string", + "title": "Mitigation Action", + "description": "The action the tenant's IdP integration took to mitigate the credential" + } + }, + "type": "object", + "required": [ + "identity_name", + "credential_hash", + "tenant_integration_id", + "mitigation_action" + ], + "title": "MitigatedCredentialEventData" + }, + "NameData": { + "properties": { + "type": { + "type": "string", + "const": "name", + "title": "Type", + "default": "name" + }, + "first_name": { + "type": "string", + "title": "First Name" + }, + "last_name": { + "type": "string", + "title": "Last Name" + }, + "is_strict": { + "type": "boolean", + "title": "Is Strict" + } + }, + "type": "object", + "required": [ + "first_name", + "last_name", + "is_strict" + ], + "title": "NameData" + }, + "NameQuery": { + "properties": { + "type": { + "type": "string", + "const": "name", + "title": "Type" + }, + "first_name": { + "type": "string", + "title": "First Name" + }, + "last_name": { + "type": "string", + "title": "Last Name" + }, + "is_strict": { + "type": "boolean", + "title": "Is Strict" + } + }, + "type": "object", + "required": [ + "type", + "first_name", + "last_name", + "is_strict" + ], + "title": "NameQuery" + }, + "OrderType": { + "type": "string", + "enum": [ + "asc", + "desc" + ], + "title": "OrderType" + }, + "PaginatedResults_Alert_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/Alert" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[Alert, str]" + }, + "PaginatedResults_Credential_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/Credential" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[Credential, str]" + }, + "PaginatedResults_EntityLiteAPIResponseTypes_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/EntityLiteAPIResponseTypes" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[EntityLiteAPIResponseTypes, str]" + }, + "PaginatedResults_FeedItem_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/FeedItem" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[FeedItem, str]" + }, + "PaginatedResults_GlobalFeedItem_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/GlobalFeedItem" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[GlobalFeedItem, str]" + }, + "PaginatedResults_MatchingPolicyPayload_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/MatchingPolicyPayload" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[MatchingPolicyPayload, str]" + }, + "PaginatedResults_PartialAlertChannel_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/PartialAlertChannel" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[PartialAlertChannel, str]" + }, + "PaginatedResults_PolicyAssignedIdentifierPayload_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/PolicyAssignedIdentifierPayload" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[PolicyAssignedIdentifierPayload, str]" + }, + "PaginatedResults_PublicIdentifierResponse_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/PublicIdentifierResponse" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[PublicIdentifierResponse, str]" + }, + "PaginatedResults_PublicReport_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/PublicReport" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[PublicReport, str]" + }, + "PaginatedResults_PydanticThreatFlowReport_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/PydanticThreatFlowReport" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[PydanticThreatFlowReport, str]" + }, + "PaginatedResults_Recommendation_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/Recommendation" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[Recommendation, str]" + }, + "PaginatedResults_StealerLogCookie_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/StealerLogCookie" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[StealerLogCookie, str]" + }, + "PaginatedResults_StealerLogCredential_str_": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/StealerLogCredential" + }, + "type": "array", + "title": "Items" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + } + }, + "type": "object", + "required": [ + "items", + "next" + ], + "title": "PaginatedResults[StealerLogCredential, str]" + }, + "ParentContext": { + "properties": { + "parent_uid": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Parent Uid" + }, + "parent_type": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Parent Type" + } + }, + "type": "object", + "title": "ParentContext" + }, + "PartialAlertChannel": { + "properties": { + "id": { + "type": "integer", + "title": "Id" + }, + "name": { + "type": "string", + "title": "Name" + }, + "type": { + "$ref": "#/components/schemas/AlertType" + }, + "state": { + "$ref": "#/components/schemas/AlertChannelState" + }, + "alert_count": { + "type": "integer", + "title": "Alert Count" + } + }, + "type": "object", + "required": [ + "id", + "name", + "type", + "state", + "alert_count" + ], + "title": "PartialAlertChannel" + }, + "PasteEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "paste", + "title": "Event Type", + "default": "paste" + }, + "data": { + "$ref": "#/components/schemas/PasteEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Paste" + }, + "PasteEventData": { + "properties": { + "url": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Url" + }, + "title": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Title" + }, + "content": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Content" + }, + "actor": { + "anyOf": [ + { + "$ref": "#/components/schemas/pyro__findings__paste__datamodels__PasteEventData__Actor" + }, + { + "type": "null" + } + ] + }, + "expires_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Expires At" + }, + "syntax": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Syntax" + } + }, + "type": "object", + "title": "PasteEventData" + }, + "PhoneNumberData": { + "properties": { + "type": { + "type": "string", + "const": "phone_number", + "title": "Type", + "default": "phone_number" + }, + "phone_number": { + "type": "string", + "minLength": 7, + "title": "Phone Number" + } + }, + "type": "object", + "required": [ + "phone_number" + ], + "title": "PhoneNumberData" + }, + "PolicyAssignedIdentifierPayload": { + "properties": { + "identifier_id": { + "type": "integer", + "title": "Identifier Id", + "description": "The ID of the identifier this policy is assigned to" + }, + "identifier_name": { + "type": "string", + "title": "Identifier Name", + "description": "The name of the identifier this policy is assigned to" + }, + "clean_past_events": { + "type": "boolean", + "title": "Clean Past Events", + "description": "Whether this policy has been applied to historical events" + }, + "assigned_at": { + "type": "string", + "format": "date-time", + "title": "Assigned At", + "description": "The date and time this policy was assigned to the identifier" + } + }, + "type": "object", + "required": [ + "identifier_id", + "identifier_name", + "clean_past_events", + "assigned_at" + ], + "title": "PolicyAssignedIdentifierPayload" + }, + "PolicyAssignmentsBody": { + "properties": { + "identifier_ids": { + "items": { + "type": "integer" + }, + "type": "array", + "title": "Identifier Ids", + "description": "The IDs of the identifiers to assign the policy to" + }, + "clean_past_events": { + "type": "boolean", + "title": "Clean Past Events", + "description": "Whether this policy will be applied to historical events", + "default": false + } + }, + "type": "object", + "required": [ + "identifier_ids" + ], + "title": "PolicyAssignmentsBody" + }, + "PolicyValue": { + "anyOf": [ + { + "$ref": "#/components/schemas/KeywordsValue" + }, + { + "$ref": "#/components/schemas/LuceneValue" + }, + { + "$ref": "#/components/schemas/AstpCookiesValue" + }, + { + "$ref": "#/components/schemas/AstpDomainValue" + } + ] + }, + "PublicIdentifierRequestBody": { + "properties": { + "data": { + "oneOf": [ + { + "$ref": "#/components/schemas/CCBinData" + }, + { + "$ref": "#/components/schemas/IPData" + }, + { + "$ref": "#/components/schemas/KeywordData" + }, + { + "$ref": "#/components/schemas/AzureTenantData" + }, + { + "$ref": "#/components/schemas/DomainData" + }, + { + "$ref": "#/components/schemas/SearchQueryData" + }, + { + "$ref": "#/components/schemas/GithubRepositoryData" + }, + { + "$ref": "#/components/schemas/SecretData" + }, + { + "$ref": "#/components/schemas/PublicIdentityData" + } + ], + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "azure_tenant": "#/components/schemas/AzureTenantData", + "bin": "#/components/schemas/CCBinData", + "domain": "#/components/schemas/DomainData", + "github_repository": "#/components/schemas/GithubRepositoryData", + "identity": "#/components/schemas/PublicIdentityData", + "ip": "#/components/schemas/IPData", + "keyword": "#/components/schemas/KeywordData", + "search_query": "#/components/schemas/SearchQueryData", + "secret": "#/components/schemas/SecretData" + } + } + }, + "name": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Name" + }, + "categories": { + "items": { + "$ref": "#/components/schemas/SearchType" + }, + "type": "array", + "title": "Categories" + }, + "emerging_categories": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Emerging Categories" + }, + "severities": { + "items": { + "$ref": "#/components/schemas/Severity" + }, + "type": "array", + "title": "Severities" + }, + "group_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Group Id" + } + }, + "type": "object", + "required": [ + "data", + "categories", + "emerging_categories", + "severities" + ], + "title": "PublicIdentifierRequestBody" + }, + "PublicIdentifierResponse": { + "properties": { + "id": { + "type": "integer", + "title": "Id" + }, + "name": { + "type": "string", + "title": "Name" + }, + "tenant_id": { + "type": "integer", + "title": "Tenant Id" + }, + "data": { + "oneOf": [ + { + "$ref": "#/components/schemas/CCBinData" + }, + { + "$ref": "#/components/schemas/IPData" + }, + { + "$ref": "#/components/schemas/KeywordData" + }, + { + "$ref": "#/components/schemas/AzureTenantData" + }, + { + "$ref": "#/components/schemas/DomainData" + }, + { + "$ref": "#/components/schemas/SearchQueryData" + }, + { + "$ref": "#/components/schemas/GithubRepositoryData" + }, + { + "$ref": "#/components/schemas/SecretData" + }, + { + "$ref": "#/components/schemas/PublicIdentityData" + } + ], + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "azure_tenant": "#/components/schemas/AzureTenantData", + "bin": "#/components/schemas/CCBinData", + "domain": "#/components/schemas/DomainData", + "github_repository": "#/components/schemas/GithubRepositoryData", + "identity": "#/components/schemas/PublicIdentityData", + "ip": "#/components/schemas/IPData", + "keyword": "#/components/schemas/KeywordData", + "search_query": "#/components/schemas/SearchQueryData", + "secret": "#/components/schemas/SecretData" + } + } + }, + "categories": { + "items": { + "$ref": "#/components/schemas/SearchType" + }, + "type": "array", + "title": "Categories" + }, + "emerging_categories": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Emerging Categories" + }, + "severities": { + "items": { + "$ref": "#/components/schemas/Severity" + }, + "type": "array", + "title": "Severities" + }, + "group_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Group Id" + }, + "enrichments": { + "anyOf": [ + { + "$ref": "#/components/schemas/IdentifierEnrichments" + }, + { + "type": "null" + } + ] + }, + "is_disabled": { + "type": "boolean", + "title": "Is Disabled" + }, + "updated_at": { + "type": "string", + "format": "date-time", + "title": "Updated At" + } + }, + "type": "object", + "required": [ + "id", + "name", + "tenant_id", + "data", + "categories", + "emerging_categories", + "severities", + "group_id", + "enrichments", + "is_disabled", + "updated_at" + ], + "title": "IdentifierResponse" + }, + "PublicIdentifierUpdateRequestBody": { + "properties": { + "data": { + "oneOf": [ + { + "$ref": "#/components/schemas/CCBinData" + }, + { + "$ref": "#/components/schemas/IPData" + }, + { + "$ref": "#/components/schemas/KeywordData" + }, + { + "$ref": "#/components/schemas/AzureTenantData" + }, + { + "$ref": "#/components/schemas/DomainData" + }, + { + "$ref": "#/components/schemas/SearchQueryData" + }, + { + "$ref": "#/components/schemas/GithubRepositoryData" + }, + { + "$ref": "#/components/schemas/SecretData" + }, + { + "$ref": "#/components/schemas/PublicIdentityData" + } + ], + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "azure_tenant": "#/components/schemas/AzureTenantData", + "bin": "#/components/schemas/CCBinData", + "domain": "#/components/schemas/DomainData", + "github_repository": "#/components/schemas/GithubRepositoryData", + "identity": "#/components/schemas/PublicIdentityData", + "ip": "#/components/schemas/IPData", + "keyword": "#/components/schemas/KeywordData", + "search_query": "#/components/schemas/SearchQueryData", + "secret": "#/components/schemas/SecretData" + } + } + }, + "name": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Name" + }, + "categories": { + "items": { + "$ref": "#/components/schemas/SearchType" + }, + "type": "array", + "title": "Categories" + }, + "emerging_categories": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Emerging Categories" + }, + "severities": { + "items": { + "$ref": "#/components/schemas/Severity" + }, + "type": "array", + "title": "Severities" + }, + "group_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Group Id" + }, + "is_disabled": { + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ], + "title": "Is Disabled" + } + }, + "type": "object", + "required": [ + "data", + "categories", + "emerging_categories", + "severities" + ], + "title": "PublicIdentifierUpdateRequestBody" + }, + "PublicIdentityData": { + "properties": { + "type": { + "type": "string", + "const": "identity", + "title": "Type", + "default": "identity" + }, + "attributes": { + "items": { + "oneOf": [ + { + "$ref": "#/components/schemas/EmailData" + }, + { + "$ref": "#/components/schemas/UsernameData" + }, + { + "$ref": "#/components/schemas/NameData" + } + ], + "discriminator": { + "propertyName": "type", + "mapping": { + "email": "#/components/schemas/EmailData", + "name": "#/components/schemas/NameData", + "username": "#/components/schemas/UsernameData" + } + } + }, + "type": "array", + "maxItems": 15, + "minItems": 1, + "title": "Attributes" + } + }, + "type": "object", + "required": [ + "attributes" + ], + "title": "IdentityData" + }, + "PublicReport": { + "properties": { + "id": { + "type": "integer", + "title": "Id" + }, + "title": { + "type": "string", + "title": "Title" + }, + "author": { + "type": "string", + "title": "Author" + }, + "tenant_id": { + "type": "integer", + "title": "Tenant Id" + }, + "report_group_id": { + "type": "integer", + "title": "Report Group Id" + }, + "report_type": { + "$ref": "#/components/schemas/ReportType-Output" + }, + "status": { + "$ref": "#/components/schemas/ReportStatus" + }, + "created_at": { + "type": "string", + "format": "date-time", + "title": "Created At" + }, + "updated_at": { + "type": "string", + "format": "date-time", + "title": "Updated At" + }, + "is_archived": { + "type": "boolean", + "title": "Is Archived" + } + }, + "type": "object", + "required": [ + "id", + "title", + "author", + "tenant_id", + "report_group_id", + "report_type", + "status", + "created_at", + "updated_at", + "is_archived" + ], + "title": "PublicReport" + }, + "PublishReportPayload": { + "properties": { + "title": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Title" + } + }, + "type": "object", + "title": "PublishReportPayload" + }, + "PydanticThreatFlowReport": { + "properties": { + "id": { + "type": "integer", + "title": "Id" + }, + "format_type": { + "$ref": "#/components/schemas/ThreatFlowReportFormatType", + "default": "simple_summary" + }, + "intel_type": { + "$ref": "#/components/schemas/IntelType", + "default": "unit_summary_based" + }, + "title": { + "type": "string", + "title": "Title" + }, + "subtitle": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Subtitle" + }, + "summary": { + "type": "string", + "title": "Summary" + }, + "content": { + "type": "string", + "title": "Content" + }, + "tags": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Tags" + }, + "highlights": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Highlights" + }, + "related_activity_uids": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Related Activity Uids" + }, + "prompt_preset_uid": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Prompt Preset Uid" + }, + "created_at": { + "type": "string", + "format": "date-time", + "title": "Created At" + }, + "published_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Published At" + }, + "updated_at": { + "type": "string", + "format": "date-time", + "title": "Updated At" + }, + "reading_time": { + "type": "integer", + "title": "Reading Time" + }, + "tenant_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Tenant Id" + }, + "organization_id": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Organization Id" + } + }, + "type": "object", + "required": [ + "id", + "title", + "subtitle", + "summary", + "content", + "tags", + "highlights", + "related_activity_uids", + "prompt_preset_uid", + "created_at", + "published_at", + "updated_at", + "reading_time", + "tenant_id", + "organization_id" + ], + "title": "PydanticThreatFlowReport" + }, + "QueryStringQuery": { + "properties": { + "type": { + "type": "string", + "const": "query_string", + "title": "Type" + }, + "query_string": { + "type": "string", + "maxLength": 10000, + "title": "Query String" + } + }, + "type": "object", + "required": [ + "type", + "query_string" + ], + "title": "QueryStringQuery" + }, + "RansomLeakData": { + "properties": { + "type": { + "type": "string", + "const": "ransomleak", + "title": "Type", + "default": "ransomleak" + }, + "source": { + "type": "string", + "minLength": 1, + "title": "Source" + }, + "id": { + "type": "string", + "minLength": 1, + "title": "Id" + } + }, + "type": "object", + "required": [ + "source", + "id" + ], + "title": "RansomLeakData" + }, + "RansomLeakEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "ransomleak", + "title": "Event Type", + "default": "ransomleak" + }, + "data": { + "$ref": "#/components/schemas/RansomLeakEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Ransom Leak" + }, + "RansomLeakEventData": { + "properties": { + "url": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Url", + "description": "The URL of the ransom leak post." + }, + "response_url": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Response Url", + "description": "The URL of the response to the ransom leak post." + }, + "title": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Title", + "description": "The title of the ransom leak post." + }, + "content": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Content", + "description": "The content of the ransom leak post." + }, + "body": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Body", + "description": "The body of the ransom leak post." + }, + "victim_information": { + "anyOf": [ + { + "$ref": "#/components/schemas/pyro__findings__ransomleaks__datamodels__VictimInformation" + }, + { + "type": "null" + } + ], + "description": "The information relating to the victim of the ransom leak." + } + }, + "type": "object", + "title": "RansomLeakEventData" + }, + "Recommendation": { + "properties": { + "id": { + "type": "integer", + "title": "Id" + }, + "data": { + "oneOf": [ + { + "$ref": "#/components/schemas/DomainData" + }, + { + "$ref": "#/components/schemas/AzureTenantData" + }, + { + "$ref": "#/components/schemas/EmailData" + }, + { + "$ref": "#/components/schemas/UsernameData" + } + ], + "title": "Data", + "discriminator": { + "propertyName": "type", + "mapping": { + "azure_tenant": "#/components/schemas/AzureTenantData", + "domain": "#/components/schemas/DomainData", + "email": "#/components/schemas/EmailData", + "username": "#/components/schemas/UsernameData" + } + } + } + }, + "type": "object", + "required": [ + "id", + "data" + ], + "title": "Recommendation" + }, + "RelatedConversationRequest": { + "properties": { + "uid": { + "type": "string", + "title": "Uid" + }, + "direction": { + "$ref": "#/components/schemas/ConversationSearchAfterDirection", + "default": "next" + }, + "size": { + "type": "integer", + "title": "Size", + "default": 10 + }, + "search_after": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Search After" + }, + "should_translate": { + "type": "boolean", + "title": "Should Translate", + "default": false + } + }, + "type": "object", + "required": [ + "uid" + ], + "title": "RelatedConversationRequest" + }, + "RelatedConversationResponse": { + "properties": { + "conversation_messages": { + "items": { + "$ref": "#/components/schemas/ConversationMessage" + }, + "type": "array", + "title": "Conversation Messages" + }, + "conversation_name": { + "type": "string", + "title": "Conversation Name" + }, + "conversation_name_en": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Conversation Name En" + }, + "next": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Next" + }, + "previous": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Previous" + } + }, + "type": "object", + "required": [ + "conversation_messages", + "conversation_name" + ], + "title": "RelatedConversationResponse" + }, + "ReportDownloadFormat": { + "type": "string", + "enum": [ + "docx", + "pdf", + "csv", + "zip" + ], + "title": "ReportDownloadFormat" + }, + "ReportRequestInfoResponse": { + "properties": { + "status": { + "$ref": "#/components/schemas/RequestStatus" + }, + "report": { + "anyOf": [ + { + "$ref": "#/components/schemas/ApiReport" + }, + { + "type": "null" + } + ] + } + }, + "type": "object", + "required": [ + "status" + ], + "title": "ReportRequestInfoResponse" + }, + "ReportRequestPayload": { + "properties": { + "report_title": { + "type": "string", + "title": "Report Title" + }, + "question": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Question" + }, + "time_range_type": { + "$ref": "#/components/schemas/TimeRangeType", + "default": "all" + }, + "time_range_from": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Time Range From" + }, + "time_range_to": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Time Range To" + }, + "included_keywords": { + "anyOf": [ + { + "items": { + "type": "string" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Included Keywords" + }, + "excluded_keywords": { + "anyOf": [ + { + "items": { + "type": "string" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Excluded Keywords" + } + }, + "type": "object", + "required": [ + "report_title" + ], + "title": "ReportRequestPayload" + }, + "ReportRequestResponse": { + "properties": { + "request_id": { + "type": "string", + "format": "uuid", + "title": "Request Id" + } + }, + "type": "object", + "required": [ + "request_id" + ], + "title": "ReportRequestResponse" + }, + "ReportStatus": { + "type": "string", + "enum": [ + "draft", + "processing", + "completed", + "scheduled", + "paused" + ], + "title": "ReportStatus" + }, + "ReportType-Output": { + "type": "string", + "enum": [ + "v1", + "event_based", + "feed_based" + ], + "title": "ReportType" + }, + "RequestStatus": { + "type": "string", + "enum": [ + "processing", + "completed", + "error" + ], + "title": "RequestStatus" + }, + "RiskScore": { + "type": "integer", + "enum": [ + 1, + 2, + 3, + 4, + 5 + ], + "title": "RiskScore" + }, + "RoleData": { + "properties": { + "type": { + "type": "string", + "const": "role", + "title": "Type", + "default": "role" + }, + "role": { + "type": "string", + "minLength": 1, + "title": "Role" + } + }, + "type": "object", + "required": [ + "role" + ], + "title": "RoleData" + }, + "SandboxSubmissionEventType": { + "type": "string", + "enum": [ + "asset_sync", + "report_sync" + ], + "title": "SandboxSubmissionEventType" + }, + "SandboxSyncRequest": { + "properties": { + "job": { + "$ref": "#/components/schemas/SandboxSubmissionEventType" + } + }, + "type": "object", + "required": [ + "job" + ], + "title": "SandboxSyncRequest" + }, + "SandboxUploadPutUrlResponse": { + "properties": { + "upload_url": { + "type": "string", + "title": "Upload Url" + } + }, + "type": "object", + "required": [ + "upload_url" + ], + "title": "SandboxUploadPutUrlResponse" + }, + "SandboxUploadUrlRequest": { + "properties": { + "filename": { + "type": "string", + "title": "Filename" + } + }, + "type": "object", + "required": [ + "filename" + ], + "title": "SandboxUploadUrlRequest" + }, + "SearchQueryData": { + "properties": { + "type": { + "type": "string", + "const": "search_query", + "title": "Type", + "default": "search_query" + }, + "search_query": { + "type": "string", + "minLength": 1, + "title": "Search Query" + } + }, + "type": "object", + "required": [ + "search_query" + ], + "title": "SearchQueryData" + }, + "SearchType": { + "type": "string", + "enum": [ + "attachment", + "listing", + "ransomleak", + "forum_post", + "forum_topic", + "forum_profile", + "blog_post", + "seller", + "paste", + "leak", + "chat_message", + "domain", + "bot", + "stealer_log", + "infected_devices", + "driller", + "driller_forum_topic", + "driller_forum_post", + "driller_profile", + "cc", + "ccbin", + "financial_data", + "leaked_data", + "leaked_file", + "document", + "account", + "actor", + "forum_content", + "blog_content", + "profile", + "leaked_credential", + "valid_credential", + "invalid_credential", + "mitigated_credential", + "illicit_networks", + "open_web", + "domains", + "intelligence_object", + "leaks", + "social_media_account", + "social_media", + "source_code", + "source_code_secrets_np", + "source_code_secrets", + "source_code_files", + "docker", + "stack_exchange", + "google", + "service", + "driller_host", + "buckets", + "bucket", + "bucket_object", + "whois", + "ad", + "ads", + "cookie", + "pii", + "experimental" + ], + "title": "SearchType" + }, + "SecretData": { + "properties": { + "type": { + "type": "string", + "const": "secret", + "title": "Type", + "default": "secret" + }, + "secret": { + "type": "string", + "minLength": 1, + "title": "Secret" + } + }, + "type": "object", + "required": [ + "secret" + ], + "title": "SecretData" + }, + "SecretQuery": { + "properties": { + "type": { + "type": "string", + "const": "secret", + "title": "Type" + }, + "secret": { + "type": "string", + "title": "Secret" + } + }, + "type": "object", + "required": [ + "type", + "secret" + ], + "title": "SecretQuery" + }, + "ServiceEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "service", + "title": "Event Type", + "default": "service" + }, + "data": { + "$ref": "#/components/schemas/ServiceEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Service" + }, + "ServiceEventData": { + "properties": { + "url": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Url", + "description": "The URL to the service. This may be an IP address and port combination." + }, + "asn": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Asn", + "description": "The Autonomous System Number." + }, + "content": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Content", + "description": "The raw content returned by the service." + }, + "service": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Service", + "description": "The protocol of the service e.g. https" + }, + "product": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Product", + "description": "The software product that powers the service e.g. Apache httpd" + }, + "port": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Port", + "description": "The port the service listens on." + }, + "ip_address": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Ip Address", + "description": "The IP address of the service." + }, + "organization": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Organization", + "description": "The organization that manages the IP address, often a hosting provider." + }, + "hostname": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Hostname", + "description": "The hostname the service is served under." + }, + "country_code": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Country Code", + "description": "The country code of the IP address." + }, + "vulnerabilities": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Vulnerabilities", + "description": "CVE identifiers of vulnerabilities the service is potentially affected by." + } + }, + "type": "object", + "title": "ServiceEventData" + }, + "Severity": { + "type": "string", + "enum": [ + "info", + "low", + "medium", + "high", + "critical" + ], + "title": "Severity" + }, + "SocialMediaEvent": { + "properties": { + "event_type": { + "type": "string", + "const": "social_media_account", + "title": "Event Type", + "default": "social_media_account" + }, + "data": { + "$ref": "#/components/schemas/SocialMediaEventData" + }, + "metadata": { + "$ref": "#/components/schemas/EventMetadata" + } + }, + "type": "object", + "required": [ + "data", + "metadata" + ], + "title": "Social Media Account" + }, + "SocialMediaEventData": { + "properties": { + "url": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Url", + "description": "The URL to the profile page of the social media account." + }, + "site": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Site", + "description": "The name of the platform where the account was found." + }, + "username": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Username", + "description": "The username of the account that was found." + } + }, + "type": "object", + "title": "SocialMediaEventData" + }, + "SourceV2": { + "properties": { + "id": { + "type": "string", + "title": "Id" + }, + "name": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Name" + }, + "description_en": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description En" + }, + "description_fr": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description Fr" + }, + "breached_at": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Breached At" + }, + "leaked_at": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Leaked At" + }, + "is_alert_enabled": { + "type": "boolean", + "title": "Is Alert Enabled" + }, + "pii_tags": { + "anyOf": [ + { + "items": { + "type": "string" + }, + "type": "array" + }, + { + "type": "null" + } + ], + "title": "Pii Tags" + }, + "url": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Url" + } + }, + "type": "object", + "required": [ + "id", + "name", + "description_en", + "description_fr", + "breached_at", + "leaked_at", + "is_alert_enabled", + "pii_tags", + "url" + ], + "title": "SourceV2" + }, + "StealerLogCookie": { "properties": { - "type": { + "host_key": { "type": "string", - "const": "search_query", - "title": "Type", - "default": "search_query" + "title": "Host Key" }, - "search_query": { + "path": { "type": "string", - "minLength": 1, - "title": "Search Query" + "title": "Path" + }, + "expires_utc": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Expires Utc" + }, + "name": { + "type": "string", + "title": "Name" + }, + "value": { + "type": "string", + "title": "Value" } }, "type": "object", "required": [ - "search_query" + "host_key", + "path", + "expires_utc", + "name", + "value" ], - "title": "SearchQueryData" + "title": "StealerLogCookie" }, - "SearchType": { - "type": "string", - "enum": [ - "attachment", - "listing", - "ransomleak", - "forum_post", - "forum_topic", - "forum_profile", - "blog_post", - "seller", - "paste", - "leak", - "chat_message", - "domain", - "bot", - "stealer_log", - "infected_devices", - "driller", - "driller_forum_topic", - "driller_forum_post", - "driller_profile", - "cc", - "ccbin", - "financial_data", - "leaked_data", - "leaked_file", - "document", - "account", - "actor", - "forum_content", - "blog_content", - "profile", - "leaked_credential", - "valid_credential", - "invalid_credential", - "mitigated_credential", - "illicit_networks", - "open_web", - "domains", - "intelligence_object", - "leaks", - "social_media_account", - "social_media", - "source_code", - "source_code_secrets_np", - "source_code_secrets", - "source_code_files", - "docker", - "stack_exchange", - "google", - "service", - "driller_host", - "buckets", - "bucket", - "bucket_object", - "whois", - "ad", - "ads", - "cookie", - "pii", - "experimental" + "StealerLogCredential": { + "properties": { + "url": { + "type": "string", + "title": "Url" + }, + "username": { + "type": "string", + "title": "Username" + }, + "password": { + "type": "string", + "title": "Password" + }, + "application": { + "type": "string", + "title": "Application" + } + }, + "type": "object", + "required": [ + "url", + "username", + "password", + "application" ], - "title": "SearchType" + "title": "StealerLogCredential" }, - "SecretData": { + "StealerLogEventData": { "properties": { - "type": { + "victim_information": { + "anyOf": [ + { + "$ref": "#/components/schemas/pyro__findings__stealerlogs__datamodels__VictimInformation" + }, + { + "type": "null" + } + ], + "description": "Collection of data that relates to the victim and their infected device." + }, + "malware_information": { + "anyOf": [ + { + "$ref": "#/components/schemas/MalwareInformation" + }, + { + "type": "null" + } + ], + "description": "Collection of data that relates to the malware that was used to infect the victim's device." + } + }, + "type": "object", + "title": "StealerLogEventData" + }, + "SubdomainStatus": { + "properties": { + "status": { + "$ref": "#/components/schemas/DomainStatus" + }, + "updated_at": { "type": "string", - "const": "secret", - "title": "Type", - "default": "secret" + "format": "date-time", + "title": "Updated At" + } + }, + "type": "object", + "required": [ + "status", + "updated_at" + ], + "title": "SubdomainStatus" + }, + "SubdomainTag": { + "properties": { + "label": { + "type": "string", + "title": "Label" }, - "secret": { + "keyword": { + "type": "string", + "title": "Keyword" + }, + "span": { + "items": { + "type": "integer" + }, + "type": "array", + "title": "Span" + } + }, + "type": "object", + "required": [ + "label", + "keyword", + "span" + ], + "title": "SubdomainTag" + }, + "Tag": { + "properties": { + "name": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Name" + }, + "repository_name": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Repository Name" + } + }, + "type": "object", + "title": "Tag" + }, + "TenantMetadataResponse": { + "properties": { + "uid": { "type": "string", - "minLength": 1, - "title": "Secret" + "title": "Uid" + }, + "notes": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Notes" + }, + "tags": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Tags" + }, + "severity": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Severity" } }, "type": "object", "required": [ - "secret" + "uid", + "notes", + "tags", + "severity" ], - "title": "SecretData" + "title": "TenantMetadataResponse" }, - "SecretQuery": { + "ThreadTopic": { "properties": { - "type": { + "topic_id": { "type": "string", - "const": "secret", - "title": "Type" + "title": "Topic Id" }, - "secret": { + "label": { "type": "string", - "title": "Secret" + "title": "Label" + }, + "description": { + "type": "string", + "title": "Description" } }, "type": "object", "required": [ - "type", - "secret" + "topic_id", + "label", + "description" ], - "title": "SecretQuery" + "title": "ThreadTopic" }, - "ServiceEvent": { + "ThreatActorEntityAPIResponse": { "properties": { - "event_type": { + "uuid": { "type": "string", - "const": "service", - "title": "Event Type", - "default": "service" + "title": "Uuid" }, - "data": { - "$ref": "#/components/schemas/ServiceEventData" + "type": { + "$ref": "#/components/schemas/EntityType" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + }, + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + }, + "threat_actor_types": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Threat Actor Types" + }, + "roles": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Roles" + }, + "goals": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Goals" + }, + "sophistication": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Sophistication" + }, + "resource_level": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Resource Level" + }, + "primary_motivation": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Primary Motivation" + }, + "secondary_motivation": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Secondary Motivation" + }, + "personal_motivations": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Personal Motivations" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" } }, "type": "object", "required": [ - "data", - "metadata" - ], - "title": "Service" - }, - "ServiceEventData": { + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases", + "threat_actor_types", + "roles", + "goals", + "sophistication", + "resource_level", + "primary_motivation", + "secondary_motivation", + "personal_motivations", + "marking_definitions" + ], + "title": "ThreatActorEntityAPIResponse" + }, + "ThreatActorEntityLiteAPIResponse": { "properties": { - "url": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Url", - "description": "The URL to the service. This may be an IP address and port combination." + "title": "First Seen At" }, - "asn": { + "last_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Asn", - "description": "The Autonomous System Number." + "title": "Last Seen At" }, - "content": { + "confidence": { "anyOf": [ { - "type": "string" + "type": "integer" }, { "type": "null" } ], - "title": "Content", - "description": "The raw content returned by the service." + "title": "Confidence" }, - "service": { + "description": { "anyOf": [ { "type": "string" @@ -10464,58 +14261,114 @@ "type": "null" } ], - "title": "Service", - "description": "The protocol of the service e.g. https" + "title": "Description" }, - "product": { + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases" + ], + "title": "ThreatActorEntityLiteAPIResponse" + }, + "ThreatActorGroupEntityAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Product", - "description": "The software product that powers the service e.g. Apache httpd" + "title": "Created At" }, - "port": { + "updated_at": { "anyOf": [ { - "type": "integer" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Port", - "description": "The port the service listens on." + "title": "Updated At" }, - "ip_address": { + "first_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Ip Address", - "description": "The IP address of the service." + "title": "First Seen At" }, - "organization": { + "last_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Organization", - "description": "The organization that manages the IP address, often a hosting provider." + "title": "Last Seen At" }, - "hostname": { + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { "anyOf": [ { "type": "string" @@ -10524,10 +14377,30 @@ "type": "null" } ], - "title": "Hostname", - "description": "The hostname the service is served under." + "title": "Description" }, - "country_code": { + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" + }, + "goals": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Goals" + }, + "resource_level": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Resource Level" + }, + "primary_motivation": { "anyOf": [ { "type": "string" @@ -10536,81 +14409,126 @@ "type": "null" } ], - "title": "Country Code", - "description": "The country code of the IP address." + "title": "Primary Motivation" }, - "vulnerabilities": { + "secondary_motivations": { "items": { "type": "string" }, "type": "array", - "title": "Vulnerabilities", - "description": "CVE identifiers of vulnerabilities the service is potentially affected by." + "title": "Secondary Motivations" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" } }, "type": "object", - "title": "ServiceEventData" - }, - "Severity": { - "type": "string", - "enum": [ - "info", - "low", - "medium", - "high", - "critical" + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases", + "goals", + "resource_level", + "primary_motivation", + "secondary_motivations", + "marking_definitions" ], - "title": "Severity" + "title": "ThreatActorGroupEntityAPIResponse" }, - "SocialMediaEvent": { + "ThreatActorGroupEntityLiteAPIResponse": { "properties": { - "event_type": { + "uuid": { "type": "string", - "const": "social_media_account", - "title": "Event Type", - "default": "social_media_account" + "title": "Uuid" }, - "data": { - "$ref": "#/components/schemas/SocialMediaEventData" + "type": { + "$ref": "#/components/schemas/EntityType" }, - "metadata": { - "$ref": "#/components/schemas/EventMetadata" - } - }, - "type": "object", - "required": [ - "data", - "metadata" - ], - "title": "Social Media Account" - }, - "SocialMediaEventData": { - "properties": { - "url": { + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Url", - "description": "The URL to the profile page of the social media account." + "title": "Created At" }, - "site": { + "updated_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Site", - "description": "The name of the platform where the account was found." + "title": "Updated At" }, - "username": { + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { "anyOf": [ { "type": "string" @@ -10619,93 +14537,145 @@ "type": "null" } ], - "title": "Username", - "description": "The username of the account that was found." + "title": "Description" + }, + "aliases": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Aliases" } }, "type": "object", - "title": "SocialMediaEventData" + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "aliases" + ], + "title": "ThreatActorGroupEntityLiteAPIResponse" + }, + "ThreatFlowReportDownloadFormat": { + "type": "string", + "enum": [ + "docx", + "pdf" + ], + "title": "ThreatFlowReportDownloadFormat" + }, + "ThreatFlowReportFormatType": { + "type": "string", + "enum": [ + "simple_summary", + "expanded_summary", + "finished_intel_standard" + ], + "title": "ThreatFlowReportFormatType" }, - "SourceV2": { + "TimeRangeType": { + "type": "string", + "enum": [ + "all", + "last_24h", + "last_2d", + "last_7d", + "last_1m", + "last_3m", + "last_6m", + "range" + ], + "title": "TimeRangeType" + }, + "ToolEntityAPIResponse": { "properties": { - "id": { + "uuid": { "type": "string", - "title": "Id" + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" }, "name": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ], + "type": "string", "title": "Name" }, - "description_en": { + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Description En" + "title": "Created At" }, - "description_fr": { + "updated_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Description Fr" + "title": "Updated At" }, - "breached_at": { + "first_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Breached At" + "title": "First Seen At" }, - "leaked_at": { + "last_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Leaked At" - }, - "is_alert_enabled": { - "type": "boolean", - "title": "Is Alert Enabled" + "title": "Last Seen At" }, - "pii_tags": { + "confidence": { "anyOf": [ { - "items": { - "type": "string" - }, - "type": "array" + "type": "integer" }, { "type": "null" } ], - "title": "Pii Tags" + "title": "Confidence" }, - "url": { + "description": { "anyOf": [ { "type": "string" @@ -10714,217 +14684,142 @@ "type": "null" } ], - "title": "Url" - } - }, - "type": "object", - "required": [ - "id", - "name", - "description_en", - "description_fr", - "breached_at", - "leaked_at", - "is_alert_enabled", - "pii_tags", - "url" - ], - "title": "SourceV2" - }, - "StealerLogCookie": { - "properties": { - "host_key": { - "type": "string", - "title": "Host Key" + "title": "Description" }, - "path": { - "type": "string", - "title": "Path" + "tool_types": { + "items": { + "type": "string" + }, + "type": "array", + "title": "Tool Types" }, - "expires_utc": { + "kill_chain_phases": { + "items": { + "$ref": "#/components/schemas/KillChainAPIResponse" + }, + "type": "array", + "title": "Kill Chain Phases" + }, + "tool_version": { "anyOf": [ { - "type": "string", - "format": "date-time" + "type": "string" }, { "type": "null" } ], - "title": "Expires Utc" - }, - "name": { - "type": "string", - "title": "Name" + "title": "Tool Version" }, - "value": { - "type": "string", - "title": "Value" + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" } }, "type": "object", "required": [ - "host_key", - "path", - "expires_utc", + "uuid", + "type", "name", - "value" + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "tool_types", + "kill_chain_phases", + "tool_version", + "marking_definitions" ], - "title": "StealerLogCookie" + "title": "ToolEntityAPIResponse" }, - "StealerLogCredential": { + "ToolEntityLiteAPIResponse": { "properties": { - "url": { + "uuid": { "type": "string", - "title": "Url" + "title": "Uuid" }, - "username": { - "type": "string", - "title": "Username" + "type": { + "$ref": "#/components/schemas/EntityType" }, - "password": { + "name": { "type": "string", - "title": "Password" + "title": "Name" }, - "application": { + "created_by": { "type": "string", - "title": "Application" - } - }, - "type": "object", - "required": [ - "url", - "username", - "password", - "application" - ], - "title": "StealerLogCredential" - }, - "StealerLogEventData": { - "properties": { - "victim_information": { - "anyOf": [ - { - "$ref": "#/components/schemas/pyro__findings__stealerlogs__datamodels__VictimInformation" - }, - { - "type": "null" - } - ], - "description": "Collection of data that relates to the victim and their infected device." + "title": "Created By" }, - "malware_information": { + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { "anyOf": [ { - "$ref": "#/components/schemas/MalwareInformation" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "description": "Collection of data that relates to the malware that was used to infect the victim's device." - } - }, - "type": "object", - "title": "StealerLogEventData" - }, - "SubdomainStatus": { - "properties": { - "status": { - "$ref": "#/components/schemas/DomainStatus" + "title": "Created At" }, "updated_at": { - "type": "string", - "format": "date-time", - "title": "Updated At" - } - }, - "type": "object", - "required": [ - "status", - "updated_at" - ], - "title": "SubdomainStatus" - }, - "SubdomainTag": { - "properties": { - "label": { - "type": "string", - "title": "Label" - }, - "keyword": { - "type": "string", - "title": "Keyword" - }, - "span": { - "items": { - "type": "integer" - }, - "type": "array", - "title": "Span" - } - }, - "type": "object", - "required": [ - "label", - "keyword", - "span" - ], - "title": "SubdomainTag" - }, - "Tag": { - "properties": { - "name": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Name" + "title": "Updated At" }, - "repository_name": { + "first_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" - } - ], - "title": "Repository Name" - } - }, - "type": "object", - "title": "Tag" - }, - "TenantMetadataResponse": { - "properties": { - "uid": { - "type": "string", - "title": "Uid" + } + ], + "title": "First Seen At" }, - "notes": { + "last_seen_at": { "anyOf": [ { - "type": "string" + "type": "string", + "format": "date-time" }, { "type": "null" } ], - "title": "Notes" + "title": "Last Seen At" }, - "tags": { - "items": { - "type": "string" - }, - "type": "array", - "title": "Tags" + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" }, - "severity": { + "description": { "anyOf": [ { "type": "string" @@ -10933,48 +14828,21 @@ "type": "null" } ], - "title": "Severity" + "title": "Description" } }, "type": "object", "required": [ - "uid", - "notes", - "tags", - "severity" - ], - "title": "TenantMetadataResponse" - }, - "ThreatFlowReportDownloadFormat": { - "type": "string", - "enum": [ - "docx", - "pdf" - ], - "title": "ThreatFlowReportDownloadFormat" - }, - "ThreatFlowReportFormatType": { - "type": "string", - "enum": [ - "simple_summary", - "expanded_summary", - "finished_intel_standard" - ], - "title": "ThreatFlowReportFormatType" - }, - "TimeRangeType": { - "type": "string", - "enum": [ - "all", - "last_24h", - "last_2d", - "last_7d", - "last_1m", - "last_3m", - "last_6m", - "range" + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description" ], - "title": "TimeRangeType" + "title": "ToolEntityLiteAPIResponse" }, "Types": { "properties": { @@ -11204,6 +15072,230 @@ ], "title": "ValidationError" }, + "VulnerabilityEntityAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + }, + "marking_definitions": { + "items": { + "$ref": "#/components/schemas/MarkingDefinition" + }, + "type": "array", + "title": "Marking Definitions" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description", + "marking_definitions" + ], + "title": "VulnerabilityEntityAPIResponse" + }, + "VulnerabilityEntityLiteAPIResponse": { + "properties": { + "uuid": { + "type": "string", + "title": "Uuid" + }, + "type": { + "$ref": "#/components/schemas/EntityType" + }, + "name": { + "type": "string", + "title": "Name" + }, + "created_by": { + "type": "string", + "title": "Created By" + }, + "sources": { + "items": { + "$ref": "#/components/schemas/CTIEntitySourceAPIResponse" + }, + "type": "array", + "title": "Sources" + }, + "created_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Created At" + }, + "updated_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Updated At" + }, + "first_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "First Seen At" + }, + "last_seen_at": { + "anyOf": [ + { + "type": "string", + "format": "date-time" + }, + { + "type": "null" + } + ], + "title": "Last Seen At" + }, + "confidence": { + "anyOf": [ + { + "type": "integer" + }, + { + "type": "null" + } + ], + "title": "Confidence" + }, + "description": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "title": "Description" + } + }, + "type": "object", + "required": [ + "uuid", + "type", + "name", + "created_by", + "sources", + "created_at", + "updated_at", + "description" + ], + "title": "VulnerabilityEntityLiteAPIResponse" + }, "WebhookBasicAuth": { "properties": { "username": { diff --git a/docs/api-reference/v4/endpoints/public/get-entity.mdx b/docs/api-reference/v4/endpoints/public/get-entity.mdx new file mode 100644 index 00000000..d342e8b4 --- /dev/null +++ b/docs/api-reference/v4/endpoints/public/get-entity.mdx @@ -0,0 +1,3 @@ +--- +openapi: firework-v4-openapi get /firework/v4/cti/entities/{asset_uuid} +--- \ No newline at end of file diff --git a/docs/api-reference/v4/endpoints/public/list-entities.mdx b/docs/api-reference/v4/endpoints/public/list-entities.mdx new file mode 100644 index 00000000..b05f8649 --- /dev/null +++ b/docs/api-reference/v4/endpoints/public/list-entities.mdx @@ -0,0 +1,3 @@ +--- +openapi: firework-v4-openapi get /firework/v4/cti/entities +--- \ No newline at end of file diff --git a/docs/docs.json b/docs/docs.json index b7fed61c..b3462f96 100644 --- a/docs/docs.json +++ b/docs/docs.json @@ -234,6 +234,18 @@ } ] }, + { + "group": "Entities API", + "pages": [ + { + "group": "Entities", + "pages": [ + "api-reference/v4/endpoints/public/list-entities", + "api-reference/v4/endpoints/public/get-entity" + ] + } + ] + }, { "group": "Threat-Flow API", "pages": [ @@ -630,6 +642,14 @@ { "source": "/api-reference/v2/endpoints/identifiers/get-assetsgroups-feed", "destination": "/api-reference/v2/endpoints/identifiers/get-fireworkv2assetsgroups-feed" + }, + { + "source": "/api-reference/v4/endpoints/list-entities", + "destination": "/api-reference/v4/endpoints/public/list-entities" + }, + { + "source": "/api-reference/v4/endpoints/get-entity", + "destination": "/api-reference/v4/endpoints/public/get-entity" } ] }