CTIX
Network live
CTIXGET

Get Enrichment Policies

Source docs
GEThttps://cs-testv2.cyware.com/ctixapi/ingestion/policy/

Lists the enrichment policies in the Intel Exchange application.

Query Parameters

NameTypeRequiredDescription
qstringoptional

Pass the enrichment policy name to retrieve the policy.

is_activebooleanoptional

Pass true to retrieve active policies, else pass false.

created_by_idstringoptional

Pass the user ID to retrieve policies created by the particular user.

updated_by_idstringoptional

Pass the user ID to retrieve policies updated by the particular user.

created_fromstringoptional

Pass the created from date in epoch format to retrieve policies created in the provided timestamp.

created_tostringoptional

Pass the created date in epoch format to retrieve policies created in the provided timestamp.

sortstringoptional

Pass -ctix_created to sort records by the last modified date in descending order. Pass ctix_created to sort records by the last modified date in ascending order.

object_typestringoptional

Pass the object type to filter the enrichment policies on the object type specified in the policy, such as IP, hash, domain, or URL.

published_collectionsstringoptional

Pass the collection ID to filter the enrichment policies based on published collection IDs.

collection_idstringoptional

Pass the collection ID to filter the enrichment policies based on the collection ID.

source_idstringoptional

Pass the source ID to filter the enrichment policies based on the source ID.

pagestringoptional

Pass the page number to retrieve records.

page_sizestringoptional

Pass the number of records to retrieve on each page.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeConnect to run

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Query Parameters
cURL
curl --request GET \
  --url "https://cs-testv2.cyware.com/ctixapi/ingestion/policy/?q=malware&is_active=true&created_by_id=c0fe874d-6c0e-4ee0-82c9-1b72440fe104&updated_by_id=c0fe874d-6c0e-4ee0-82c9-1b72440fe104&created_from=1627025129&created_to=1627025133&sort=-ctix_created&object_type=ip%2Chash&published_collections=d7f7e3ff-94ff-483a-9615-95c6aac7ed2a&collection_id=e1183a5e-86cb-47e3-a4a9-0236170efda7&source_id=689773e1-5f0f-42ce-9f50-1cf13c3ee91c&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E"

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/policy/?q=malware&is_active=true&created_by_id=c0fe874d-6c0e-4ee0-82c9-1b72440fe104&updated_by_id=c0fe874d-6c0e-4ee0-82c9-1b72440fe104&created_from=1627025129&created_to=1627025133&sort=-ctix_created&object_type=ip%2Chash&published_collections=d7f7e3ff-94ff-483a-9615-95c6aac7ed2a&collection_id=e1183a5e-86cb-47e3-a4a9-0236170efda7&source_id=689773e1-5f0f-42ce-9f50-1cf13c3ee91c&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "GET",
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/ingestion/policy/"
params = {
    "q": "malware",
    "is_active": "true",
    "created_by_id": "c0fe874d-6c0e-4ee0-82c9-1b72440fe104",
    "updated_by_id": "c0fe874d-6c0e-4ee0-82c9-1b72440fe104",
    "created_from": "1627025129",
    "created_to": "1627025133",
    "sort": "-ctix_created",
    "object_type": "ip,hash",
    "published_collections": "d7f7e3ff-94ff-483a-9615-95c6aac7ed2a",
    "collection_id": "e1183a5e-86cb-47e3-a4a9-0236170efda7",
    "source_id": "689773e1-5f0f-42ce-9f50-1cf13c3ee91c",
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
response = requests.request("GET", url, params=params, headers=headers)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "next": "policy/?page=2&page_size=10",
  "page_size": 10,
  "previous": {},
  "results": [
    {}
  ],
  "total": 2
}

View-only example — running live API calls requires a role with snippet testing access.