CTIX
Network live
CTIXPOST

AI-Assisted Search

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/ingestion/threat-data/ai-search/

Converts a natural language prompt into an Intel Exchange search query.

Changelog

Added a new endpoint for AI-assisted search in Threat Data.

Body Parameters

NameTypeRequiredDescription
promptstringrequired

Pass the natural language query to convert into a search filter.

timezone_offsetnumberoptional

Pass the timezone offset in minutes from UTC. For example, pass -330 for IST (UTC+5:30).

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/ingestion/threat-data/ai-search/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "prompt": "Show IPv4 objects with risk score greater than 80 created in the last week",
  "timezone_offset": -330
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/threat-data/ai-search/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "prompt": "Show IPv4 objects with risk score greater than 80 created in the last week",
    "timezone_offset": -330
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/ingestion/threat-data/ai-search/"
params = {
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "prompt": "Show IPv4 objects with risk score greater than 80 created in the last week",
  "timezone_offset": -330
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "prompt": "Show IPv4 objects with risk score greater than 80 created in the last week",
  "timezone_offset": -330
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "query": "'type' = \"indicator\" AND 'ioc_type' = \"ipv4-addr\" AND 'confidence_score' > \"80\" AND 'ctix_created' >= \"1779185864000\""
}

View-only example — running live API calls requires a role with snippet testing access.