Creates a file SCO in the detailed STIX form submission.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| intel-id | string | optional | Pass the unique ID of the intel submission. |
Body Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| custom_properties | object | optional | Pass the list that contains the unique identifier for the custom property, type, name, and the value to add for the same. |
| tlp | object | optional | Pass the TLP of the SCO. |
| defanged | boolean | optional | Pass the TLP of the SCO. |
| file_name | string | optional | Pass the name of the file, including its extension. |
| hashes | array | optional | Pass an array of hash values used to identify the file. |
| atime | string | optional | Pass the access time of the file in UNIX timestamp format. |
| ctime | string | optional | Pass the creation time of the file in UNIX timestamp format. |
| mtime | string | optional | Pass the modification time of the file in UNIX timestamp format. |
| magic_number_hex | string | optional | Pass the file’s magic number in hexadecimal format. |
| size | number | optional | Pass the size of the file. |
| name_enc | string | optional | Pass the encoding used for the file name. |
| mime_type | string | optional | Pass the MIME type of the file. |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request POST \
--url "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/file/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
--data '{
"custom_properties": {},
"tlp": {},
"defanged": false,
"file_name": "some.text",
"hashes": [
{}
],
"atime": "1630567689",
"ctime": "1630481289",
"mtime": "1630567689",
"magic_number_hex": "FA",
"size": 23,
"name_enc": "utf8",
"mime_type": "application/text"
}'View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/file/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "POST",
headers: {},
body: JSON.stringify({
"custom_properties": {},
"tlp": {},
"defanged": false,
"file_name": "some.text",
"hashes": [
{}
],
"atime": "1630567689",
"ctime": "1630481289",
"mtime": "1630567689",
"magic_number_hex": "FA",
"size": 23,
"name_enc": "utf8",
"mime_type": "application/text"
}),
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/file/"
params = {
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {}
payload = {
"custom_properties": {},
"tlp": {},
"defanged": false,
"file_name": "some.text",
"hashes": [
{}
],
"atime": "1630567689",
"ctime": "1630481289",
"mtime": "1630567689",
"magic_number_hex": "FA",
"size": 23,
"name_enc": "utf8",
"mime_type": "application/text"
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"custom_properties": {},
"tlp": {},
"defanged": false,
"file_name": "some.text",
"hashes": [
{}
],
"atime": "1630567689",
"ctime": "1630481289",
"mtime": "1630567689",
"magic_number_hex": "FA",
"size": 23,
"name_enc": "utf8",
"mime_type": "application/text"
}View-only example — running live API calls requires a role with snippet testing access.
{
"id": "file--19c22f00-df81-486a-b352-47bab9f9a9e9",
"tlp": {},
"custom_properties": {},
"name": "some.text",
"defanged": false,
"hashes": [
{}
],
"size": 23,
"file_name": "some.text",
"name_enc": "utf8",
"magic_number_hex": "FA",
"mime_type": "application/text",
"ctime": 1630481289,
"mtime": 1630567689,
"atime": 1630567689
}View-only example — running live API calls requires a role with snippet testing access.