CTIX
Network live
CTIXPOST

Create indicator SDO

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/indicator/

Adds an Indicator SDO in the initiated detailed STIX form submission.

Path Parameters

NameTypeRequiredDescription
intel-idstringoptional

Pass the unique ID of intel submission.

Body Parameters

NameTypeRequiredDescription
custom_propertiesarrayoptional

Pass the list that contains the unique identifier for the custom property, type, name, and the value to add for the same.

namestringrequired

Pass the name of the SDO.

descriptionstringoptional

Pass the description of the SDO.

indicator_typesarrayoptional

Pass the list of indicator types.

pattern_typeobjectoptional

Pass the pattern syntax of the indicator.

observablesobjectoptional

Pass the list that contains parameters, such as expressions and indicator patterns.

valid_fromnumberrequired

Pass the date and time since when the SDO is valid.

valid_untilnumberrequired

Pass the date and time till which the SDO is valid.

labelsarrayoptional

Pass the list that contains the ID and name of the labels attached to the SDO.

tlpobjectoptional

Pass the list that contains the UI labels and value of the TLP.

created_by_refobjectoptional

Pass the list containing the ID and name of the referred SDO.

revokedbooleanoptional

Pass true to specify if the SDO is revoked; otherwise, pass false.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Path Parameters
Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/indicator/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "custom_properties": [
    {}
  ],
  "name": "Test 1234",
  "description": "descf",
  "indicator_types": [
    {}
  ],
  "pattern_type": {},
  "observables": {},
  "valid_from": 1630434600,
  "valid_until": 1631039400,
  "labels": [
    {}
  ],
  "tlp": {},
  "created_by_ref": {},
  "revoked": true
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/indicator/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "custom_properties": [
      {}
    ],
    "name": "Test 1234",
    "description": "descf",
    "indicator_types": [
      {}
    ],
    "pattern_type": {},
    "observables": {},
    "valid_from": 1630434600,
    "valid_until": 1631039400,
    "labels": [
      {}
    ],
    "tlp": {},
    "created_by_ref": {},
    "revoked": true
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/indicator/"
params = {
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "custom_properties": [
    {}
  ],
  "name": "Test 1234",
  "description": "descf",
  "indicator_types": [
    {}
  ],
  "pattern_type": {},
  "observables": {},
  "valid_from": 1630434600,
  "valid_until": 1631039400,
  "labels": [
    {}
  ],
  "tlp": {},
  "created_by_ref": {},
  "revoked": true
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "custom_properties": [
    {}
  ],
  "name": "Test 1234",
  "description": "descf",
  "indicator_types": [
    {}
  ],
  "pattern_type": {},
  "observables": {},
  "valid_from": 1630434600,
  "valid_until": 1631039400,
  "labels": [
    {}
  ],
  "tlp": {},
  "created_by_ref": {},
  "revoked": true
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "created": 1647066037.916789,
  "modified": 1647066037.916789,
  "id": "indicator--c95efb77-e2e6-476b-a02e-160a2b6cb1a4",
  "created_by_ref": {},
  "tlp": {},
  "revoked": true,
  "labels": [
    {}
  ],
  "external_references": {},
  "custom_properties": [
    {}
  ],
  "name": "Test 1234",
  "description": "descf",
  "indicator_types": [
    {}
  ],
  "pattern_type": {},
  "valid_from": 1630434600,
  "valid_until": 1631039400,
  "observables": {},
  "test_mechanism": {},
  "kill_chain_phases": {}
}

View-only example — running live API calls requires a role with snippet testing access.