CTIX
Network live
CTIXPOST

Create File SCO

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/file/

Creates a file SCO in the detailed STIX form submission.

Path Parameters

NameTypeRequiredDescription
intel-idstringoptional

Pass the unique ID of the intel submission.

Body Parameters

NameTypeRequiredDescription
custom_propertiesobjectoptional

Pass the list that contains the unique identifier for the custom property, type, name, and the value to add for the same.

tlpobjectoptional

Pass the TLP of the SCO.

defangedbooleanoptional

Pass the TLP of the SCO.

file_namestringoptional

Pass the name of the file, including its extension.

hashesarrayoptional

Pass an array of hash values used to identify the file.

atimestringoptional

Pass the access time of the file in UNIX timestamp format.

ctimestringoptional

Pass the creation time of the file in UNIX timestamp format.

mtimestringoptional

Pass the modification time of the file in UNIX timestamp format.

magic_number_hexstringoptional

Pass the file’s magic number in hexadecimal format.

sizenumberoptional

Pass the size of the file.

name_encstringoptional

Pass the encoding used for the file name.

mime_typestringoptional

Pass the MIME type of the file.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Path Parameters
Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/file/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "custom_properties": {},
  "tlp": {},
  "defanged": false,
  "file_name": "some.text",
  "hashes": [
    {}
  ],
  "atime": "1630567689",
  "ctime": "1630481289",
  "mtime": "1630567689",
  "magic_number_hex": "FA",
  "size": 23,
  "name_enc": "utf8",
  "mime_type": "application/text"
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/file/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "custom_properties": {},
    "tlp": {},
    "defanged": false,
    "file_name": "some.text",
    "hashes": [
      {}
    ],
    "atime": "1630567689",
    "ctime": "1630481289",
    "mtime": "1630567689",
    "magic_number_hex": "FA",
    "size": 23,
    "name_enc": "utf8",
    "mime_type": "application/text"
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/conversion/shareable-intel/{intel-id}/file/"
params = {
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "custom_properties": {},
  "tlp": {},
  "defanged": false,
  "file_name": "some.text",
  "hashes": [
    {}
  ],
  "atime": "1630567689",
  "ctime": "1630481289",
  "mtime": "1630567689",
  "magic_number_hex": "FA",
  "size": 23,
  "name_enc": "utf8",
  "mime_type": "application/text"
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "custom_properties": {},
  "tlp": {},
  "defanged": false,
  "file_name": "some.text",
  "hashes": [
    {}
  ],
  "atime": "1630567689",
  "ctime": "1630481289",
  "mtime": "1630567689",
  "magic_number_hex": "FA",
  "size": 23,
  "name_enc": "utf8",
  "mime_type": "application/text"
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "id": "file--19c22f00-df81-486a-b352-47bab9f9a9e9",
  "tlp": {},
  "custom_properties": {},
  "name": "some.text",
  "defanged": false,
  "hashes": [
    {}
  ],
  "size": 23,
  "file_name": "some.text",
  "name_enc": "utf8",
  "magic_number_hex": "FA",
  "mime_type": "application/text",
  "ctime": 1630481289,
  "mtime": 1630567689,
  "atime": 1630567689
}

View-only example — running live API calls requires a role with snippet testing access.