CTIX
Network live
CTIXPUT

Update Malware SDO

Source docs
PUThttps://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/malware/{malware-id}/

Updates a malware SDO in the initiated detailed STIX form submission.

Path Parameters

NameTypeRequiredDescription
intel-idstringoptional

Pass the unique ID of intel submission.

malware-idstringoptional

Pass the malware ID.

Body Parameters

NameTypeRequiredDescription
created_by_refobjectoptional

Pass the list that contains the ID and name of the SDO being referred.

revokedbooleanoptional

Pass true to specify if the SDO is revoked, else pass false.

labelsarrayoptional

Pass the list that contains the ID and name of the labels attached to the SDO.

custom_propertiesarrayoptional

Pass the list that contains the unique identifier for the custom property, type, name, and the value to add for the same.

external_referencesobjectoptional

Pass the list that contains the details of the source acting as an external reference.

tlpobjectoptional

Pass the list that contains the UI labels and value of the TLP.

namestringrequired

Pass the name of the SDO.

descriptionstringoptional

Pass the description of the SDO.

malware_typesarrayoptional

Pass the list that contains the malware types open vocabulary.

is_familybooleanrequired

Pass true if the malware belongs to a family, else pass false.

aliasesarrayoptional

Pass the list of strings that specify the also-known names for the SDO.

kill_chain_phasesarrayoptional

Pass the list that contains the typical STIX standard kill chain name and the phase name for the same.

first_seennumberoptional

Pass the epoch timestamp when the malware was first seen.

last_seennumberoptional

Pass the epoch timestamp when the malware was last observed.

operating_system_refsarrayoptional

Pass the list that contains the object type, object category, and reference corresponding to the object type.

architecture_execution_envsarrayoptional

Pass the list of open vocabulary containing the UI label and the actual vocabulary value.

implementation_languagesarrayoptional

Pass the list of open vocabulary containing the UI label and the actual vocabulary value.

capabilitiesobjectoptional

Pass the list of open vocabulary containing the UI label and the actual vocabulary value.

sample_refsarrayoptional

Pass the list that contains the object type, object category, and reference corresponding to the object type.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for PUT

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Path Parameters
Request body (JSON)Valid JSON
cURL
curl --request PUT \
  --url "https://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/malware/{malware-id}/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "created_by_ref": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "custom_properties": [
    {}
  ],
  "external_references": {},
  "tlp": {},
  "name": "malware 1",
  "description": "malware desc",
  "malware_types": [
    {}
  ],
  "is_family": true,
  "aliases": [
    "mal1"
  ],
  "kill_chain_phases": [
    {}
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "operating_system_refs": [
    {}
  ],
  "architecture_execution_envs": [
    {}
  ],
  "implementation_languages": [
    {}
  ],
  "capabilities": {},
  "sample_refs": [
    {}
  ]
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/malware/{malware-id}/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "PUT",
  headers: {},
  body: JSON.stringify({
    "created_by_ref": {},
    "revoked": false,
    "labels": [
      {}
    ],
    "custom_properties": [
      {}
    ],
    "external_references": {},
    "tlp": {},
    "name": "malware 1",
    "description": "malware desc",
    "malware_types": [
      {}
    ],
    "is_family": true,
    "aliases": [
      "mal1"
    ],
    "kill_chain_phases": [
      {}
    ],
    "first_seen": 1630434600,
    "last_seen": 1631039400,
    "operating_system_refs": [
      {}
    ],
    "architecture_execution_envs": [
      {}
    ],
    "implementation_languages": [
      {}
    ],
    "capabilities": {},
    "sample_refs": [
      {}
    ]
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/malware/{malware-id}/"
params = {
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "created_by_ref": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "custom_properties": [
    {}
  ],
  "external_references": {},
  "tlp": {},
  "name": "malware 1",
  "description": "malware desc",
  "malware_types": [
    {}
  ],
  "is_family": true,
  "aliases": [
    "mal1"
  ],
  "kill_chain_phases": [
    {}
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "operating_system_refs": [
    {}
  ],
  "architecture_execution_envs": [
    {}
  ],
  "implementation_languages": [
    {}
  ],
  "capabilities": {},
  "sample_refs": [
    {}
  ]
}
response = requests.request("PUT", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "created_by_ref": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "custom_properties": [
    {}
  ],
  "external_references": {},
  "tlp": {},
  "name": "malware 1",
  "description": "malware desc",
  "malware_types": [
    {}
  ],
  "is_family": true,
  "aliases": [
    "mal1"
  ],
  "kill_chain_phases": [
    {}
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "operating_system_refs": [
    {}
  ],
  "architecture_execution_envs": [
    {}
  ],
  "implementation_languages": [
    {}
  ],
  "capabilities": {},
  "sample_refs": [
    {}
  ]
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "id": "malware--daed05c1-e944-4ce8-936e-4c7fcbb5ebf0",
  "created_by_ref": {},
  "tlp": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "external_references": {},
  "custom_properties": [
    {}
  ],
  "name": "malware 1",
  "description": "malware desc",
  "malware_types": [
    {}
  ],
  "is_family": true,
  "aliases": [
    "mal1"
  ],
  "kill_chain_phases": [
    {}
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "operating_system_refs": [
    {}
  ],
  "architecture_execution_envs": [
    {}
  ],
  "implementation_languages": [
    {}
  ],
  "capabilities": {},
  "sample_refs": [
    {}
  ]
}

View-only example — running live API calls requires a role with snippet testing access.