Returns basic correlated details of a threat data object in Intel Exchange.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| object_type | string | required | Pass the type of threat data objects. To get the list of supported object types, see Supported SDO Types in Threat Data > Miscellaneous. |
| object_id | string | required | Pass the ID of the object to retrieve the details. To retrieve a list of object IDs, use the List Threat Data API under the Threat Data section. |
Query Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| page | string | optional | Pass the page number to retrieve records. |
| page_size | string | optional | Pass the number of records to retrieve on each page. |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request GET \
--url "https://cs-testv2.cyware.com/ctixapi/ingestion/threat-data/indicator/b711cafa-719a-4846-93dd-11741f0c10f5/basic/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E"View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/threat-data/indicator/b711cafa-719a-4846-93dd-11741f0c10f5/basic/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "GET",
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/ingestion/threat-data/indicator/b711cafa-719a-4846-93dd-11741f0c10f5/basic/"
params = {
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {}
response = requests.request("GET", url, params=params, headers=headers)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"analyst_description": {},
"analyst_score": {},
"analyst_tlp": {},
"asn": {},
"attribute_field": "value",
"attribute_value": "47.92.78.238",
"base_type": "sdo",
"confidence_score": 81,
"confidence_type": "CTIX",
"country": "China",
"created": 1685352651,
"ctix_created": 1685353115,
"ctix_modified": 1685353115,
"ctix_score": 81,
"ctix_tlp": {},
"defang_analyst_description": {},
"description": {},
"fang_analyst_description": {},
"first_seen": {},
"last_seen": {},
"modified": 1685352662,
"name": "47.92.78.238",
"sources": [
{}
],
"sub_type": "ipv4-addr",
"tld": "",
"tlp": "AMBER",
"type": "indicator",
"valid_from": 1685352651,
"valid_until": 1745240203
}View-only example — running live API calls requires a role with snippet testing access.