CTIX
Network live
CTIXPOST

Create Threat Actor SDO

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/threat-actor/

Adds a threat actor SDO in the initiated detailed submission.

Path Parameters

NameTypeRequiredDescription
intel-idstringoptional

Pass the unique ID of the intel submission.

Body Parameters

NameTypeRequiredDescription
created_by_refobjectoptional

Pass the list of IDs and names of the threat actor SDO being referred.

revokedbooleanoptional

Pass true to specify if the SDO is revoked. Else pass false.

labelsarrayoptional

Pass the list of IDs and names of the labels attached to the SDO.

custom_propertiesarrayoptional

Pass the list of the unique identifiers for the custom property, type, name, and the value to add.

tlpobjectoptional

Pass the list of UI labels and values of TLP.

namestringrequired

Pass the name of the SDO.

descriptionstringoptional

Pass the description of the SDO.

aliasesarrayoptional

Pass the list of strings of the also-known names for the SDO.

first_seennumberoptional

Pass the date and time the threat actor SDO first appeared.

last_seennumberoptional

Pass the date and time the threat actor SDO last appeared.

threat_actor_typesarrayoptional

Pass the list that contains the labels and values for a particular threat actor SDO.

rolesarrayoptional

Pass the list that contains the labels and values for a particular threat actor SDO.

goalsarrayoptional

Pass a string that describes the aim of the threat actor SDO.

sophisticationobjectoptional

Pass the list that contains the labels and values for a particular threat actor SDO.

resource_levelobjectoptional

Pass the list that contains the labels and values for a particular threat actor SDO.

primary_motivationobjectoptional

Pass the list that contains labels and values for a particular threat actor SDO.

secondary_motivationsarrayoptional

Pass the list that contains the labels and values for a particular threat actor SDO.

personal_motivationsarrayoptional

Pass the list that contains labels and values for a particular threat actor SDO.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Path Parameters
Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/threat-actor/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "created_by_ref": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "custom_properties": [
    {}
  ],
  "tlp": {},
  "name": "ta 1",
  "description": "ta desc",
  "aliases": [
    "ta1"
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "threat_actor_types": [
    {}
  ],
  "roles": [
    {}
  ],
  "goals": [
    "a"
  ],
  "sophistication": {},
  "resource_level": {},
  "primary_motivation": {},
  "secondary_motivations": [
    {}
  ],
  "personal_motivations": [
    {}
  ]
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/threat-actor/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "created_by_ref": {},
    "revoked": false,
    "labels": [
      {}
    ],
    "custom_properties": [
      {}
    ],
    "tlp": {},
    "name": "ta 1",
    "description": "ta desc",
    "aliases": [
      "ta1"
    ],
    "first_seen": 1630434600,
    "last_seen": 1631039400,
    "threat_actor_types": [
      {}
    ],
    "roles": [
      {}
    ],
    "goals": [
      "a"
    ],
    "sophistication": {},
    "resource_level": {},
    "primary_motivation": {},
    "secondary_motivations": [
      {}
    ],
    "personal_motivations": [
      {}
    ]
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/ingestion/shareable-intel/{intel-id}/threat-actor/"
params = {
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "created_by_ref": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "custom_properties": [
    {}
  ],
  "tlp": {},
  "name": "ta 1",
  "description": "ta desc",
  "aliases": [
    "ta1"
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "threat_actor_types": [
    {}
  ],
  "roles": [
    {}
  ],
  "goals": [
    "a"
  ],
  "sophistication": {},
  "resource_level": {},
  "primary_motivation": {},
  "secondary_motivations": [
    {}
  ],
  "personal_motivations": [
    {}
  ]
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "created_by_ref": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "custom_properties": [
    {}
  ],
  "tlp": {},
  "name": "ta 1",
  "description": "ta desc",
  "aliases": [
    "ta1"
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "threat_actor_types": [
    {}
  ],
  "roles": [
    {}
  ],
  "goals": [
    "a"
  ],
  "sophistication": {},
  "resource_level": {},
  "primary_motivation": {},
  "secondary_motivations": [
    {}
  ],
  "personal_motivations": [
    {}
  ]
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "created_by_ref": {},
  "tlp": {},
  "revoked": false,
  "labels": [
    {}
  ],
  "custom_properties": [
    {}
  ],
  "name": "ta 1",
  "description": "ta desc",
  "aliases": [
    "ta1"
  ],
  "first_seen": 1630434600,
  "last_seen": 1631039400,
  "threat_actor_types": [
    {}
  ],
  "roles": [
    {}
  ],
  "goals": [
    "a"
  ],
  "sophistication": {},
  "resource_level": {},
  "primary_motivation": {},
  "secondary_motivations": [
    {}
  ],
  "personal_motivations": [
    {}
  ],
  "id": "threat-actor--11600004-3719-41f1-9b16-5131b00fb7bb"
}

View-only example — running live API calls requires a role with snippet testing access.