Returns the details of a sub-technique.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| id | string | optional | Pass the unique ID of a sub-technique. |
Query Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| page | string | optional | Pass the page number to retrieve records. |
| page_size | string | optional | Pass the number of records to retrieve on each page. |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request GET \
--url "https://cs-testv2.cyware.com/ctixapi/ingestion/attack-navigator/sub-techniques/1cc4c302-efca-49f3-a59c-c529d70ee78d/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E"View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/attack-navigator/sub-techniques/1cc4c302-efca-49f3-a59c-c529d70ee78d/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "GET",
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/ingestion/attack-navigator/sub-techniques/1cc4c302-efca-49f3-a59c-c529d70ee78d/"
params = {
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {}
response = requests.request("GET", url, params=params, headers=headers)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"description": "An attacker might use setuid or setgid bits to run programs with higher privileges. This lets their malware act like it’s being run by another user, helping it do things it normally couldn’t—like bypassing restrictions or accessing sensitive data.",
"modified": 1643003227,
"mitigation": [
{}
],
"detection": "Monitor the file system for files that have the setuid or setgid bits set. Monitor for execution of utilities, like chmod, and their command-line arguments to look for setuid or setguid bits being set.",
"technique_id": "2a4f6845-f4e2-4c55-bd14-62b44601bb58",
"tactics": [
{}
],
"platforms": [
{}
],
"softwares": [
{}
],
"data_source": [
{}
],
"defense_bypassed": [],
"details_page_link": "https://attack.mitre.org/techniques/T1548/001"
}View-only example — running live API calls requires a role with snippet testing access.