Adds a malware SDO in the initiated detailed STIX form submission.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| intel-id | string | optional | Pass the unique ID of intel submission. |
Body Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| created_by_ref | object | optional | Pass the list that contains the ID and name of the SDO being referred. |
| revoked | boolean | optional | Pass true to specify if the SDO is revoked, else pass false. |
| labels | array | optional | Pass the list that contains the ID and name of the labels attached to the SDO. |
| custom_properties | array | optional | Pass the list that contains the unique identifier for the custom property, type, name, and the value to add for the same. |
| external_references | object | optional | Pass the list that contains the details of the source acting as an external reference. |
| tlp | object | optional | Pass the list that contains the UI labels and value of the TLP. |
| name | string | required | Pass the name of the SDO. |
| description | string | optional | Pass the description of the SDO. |
| malware_types | array | optional | Pass the list that contains the malware types open vocabulary. |
| is_family | boolean | optional | Pass true if the malware belongs to a family, else pass false. |
| aliases | array | optional | Pass the list of strings that specify the also-known names for the SDO. |
| kill_chain_phases | array | optional | Pass the list that contains the typical STIX standard kill chain name and the phase name for the same. |
| first_seen | number | optional | Pass the epoch timestamp when the malware was first seen. |
| last_seen | number | optional | Pass the epoch timestamp when the malware was last observed. |
| operating_system_refs | array | optional | Pass the list that contains the object type, object category, and reference corresponding to the object type. |
| architecture_execution_envs | array | optional | Pass the list of open vocabulary containing the UI label and the actual vocabulary value. |
| implementation_languages | array | optional | Pass the list of open vocabulary containing the UI label and the actual vocabulary value. |
| capabilities | array | optional | Pass the list of open vocabulary containing the UI label and the actual vocabulary value. |
| sample_refs | array | optional | Pass the list that contains the object type, object category, and reference corresponding to the object type. |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request POST \
--url "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/malware/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
--data '{
"created_by_ref": {},
"revoked": false,
"labels": [
{}
],
"custom_properties": [
{}
],
"external_references": {},
"tlp": {},
"name": "malware 1",
"description": "malware desc",
"malware_types": [
{}
],
"is_family": true,
"aliases": [
"mal1"
],
"kill_chain_phases": [
{}
],
"first_seen": 1630434600,
"last_seen": 1631039400,
"operating_system_refs": [
{}
],
"architecture_execution_envs": [
{}
],
"implementation_languages": [
{}
],
"capabilities": [
{}
],
"sample_refs": [
{}
]
}'View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/malware/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "POST",
headers: {},
body: JSON.stringify({
"created_by_ref": {},
"revoked": false,
"labels": [
{}
],
"custom_properties": [
{}
],
"external_references": {},
"tlp": {},
"name": "malware 1",
"description": "malware desc",
"malware_types": [
{}
],
"is_family": true,
"aliases": [
"mal1"
],
"kill_chain_phases": [
{}
],
"first_seen": 1630434600,
"last_seen": 1631039400,
"operating_system_refs": [
{}
],
"architecture_execution_envs": [
{}
],
"implementation_languages": [
{}
],
"capabilities": [
{}
],
"sample_refs": [
{}
]
}),
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/malware/"
params = {
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {}
payload = {
"created_by_ref": {},
"revoked": false,
"labels": [
{}
],
"custom_properties": [
{}
],
"external_references": {},
"tlp": {},
"name": "malware 1",
"description": "malware desc",
"malware_types": [
{}
],
"is_family": true,
"aliases": [
"mal1"
],
"kill_chain_phases": [
{}
],
"first_seen": 1630434600,
"last_seen": 1631039400,
"operating_system_refs": [
{}
],
"architecture_execution_envs": [
{}
],
"implementation_languages": [
{}
],
"capabilities": [
{}
],
"sample_refs": [
{}
]
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"created_by_ref": {},
"revoked": false,
"labels": [
{}
],
"custom_properties": [
{}
],
"external_references": {},
"tlp": {},
"name": "malware 1",
"description": "malware desc",
"malware_types": [
{}
],
"is_family": true,
"aliases": [
"mal1"
],
"kill_chain_phases": [
{}
],
"first_seen": 1630434600,
"last_seen": 1631039400,
"operating_system_refs": [
{}
],
"architecture_execution_envs": [
{}
],
"implementation_languages": [
{}
],
"capabilities": [
{}
],
"sample_refs": [
{}
]
}View-only example — running live API calls requires a role with snippet testing access.
{
"id": "malware--daed05c1-e944-4ce8-936e-4c7fcbb5ebf0",
"created_by_ref": {},
"tlp": {},
"revoked": false,
"labels": [
{}
],
"external_references": {},
"custom_properties": [
{}
],
"name": "malware 1",
"description": "malware desc",
"malware_types": [
{}
],
"is_family": true,
"aliases": [
"mal1"
],
"kill_chain_phases": [
{}
],
"first_seen": 1630434600,
"last_seen": 1631039400,
"operating_system_refs": [
{}
],
"architecture_execution_envs": [
{}
],
"implementation_languages": [
{}
],
"capabilities": [
{}
],
"sample_refs": [
{}
]
}View-only example — running live API calls requires a role with snippet testing access.