Retrieves a list of custom kill chains from the platform.
Query Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| page | string | optional | Pass the page number to retrieve records. |
| page_size | string | optional | Pass the number of records to retrieve on each page. |
| custom | boolean | optional | Pass true to retrieve kill chains manually created by users. Pass false to retrieve system-created kill chains. |
| ctix_created_from | string | optional | Pass the |
| ctix_created_to | string | optional | Pass the |
| ctix_modified_from | string | optional | Pass the |
| ctix_modified_to | string | optional | Pass the |
| created_by | string | optional | Pass the ID of a user to filter records based on the creator. |
| modified_by | string | optional | Pass the ID of a user to filter records based on the modifier. |
| sort | string | optional | Pass |
| q | string | optional | Pass a keyword to search for kill chains by the title. |
Headers
| Name | Type | Required | Description |
|---|---|---|---|
| accept | string | optional |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request GET \
--url "https://cs-testv2.cyware.com/ctixapi/ingestion/configuration/kill-chain/?page=1&page_size=10&custom=true&ctix_created_from=1711929600&ctix_created_to=1712966399&ctix_modified_from=1711929600&ctix_modified_to=1712966399&created_by=2e4cc862-08e2-4d77-a73b-16ac2bf5ce44&modified_by=2e4cc862-08e2-4d77-a73b-16ac2bf5ce44&sort=-ctix_created&q=keyword&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
--header "accept: application/json, text/plain, */*"View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/configuration/kill-chain/?page=1&page_size=10&custom=true&ctix_created_from=1711929600&ctix_created_to=1712966399&ctix_modified_from=1711929600&ctix_modified_to=1712966399&created_by=2e4cc862-08e2-4d77-a73b-16ac2bf5ce44&modified_by=2e4cc862-08e2-4d77-a73b-16ac2bf5ce44&sort=-ctix_created&q=keyword&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "GET",
headers: {
"accept": "application/json, text/plain, */*"
},
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/ingestion/configuration/kill-chain/"
params = {
"page": "1",
"page_size": "10",
"custom": "true",
"ctix_created_from": "1711929600",
"ctix_created_to": "1712966399",
"ctix_modified_from": "1711929600",
"ctix_modified_to": "1712966399",
"created_by": "2e4cc862-08e2-4d77-a73b-16ac2bf5ce44",
"modified_by": "2e4cc862-08e2-4d77-a73b-16ac2bf5ce44",
"sort": "-ctix_created",
"q": "keyword",
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {
"accept": "application/json, text/plain, */*"
}
response = requests.request("GET", url, params=params, headers=headers)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"next": "configuration/kill-chain/?page=2&page_size=2",
"page_size": 2,
"previous": {},
"results": [
{}
],
"total": 7
}View-only example — running live API calls requires a role with snippet testing access.