CTIX
Network live
CTIXPOST

Bulk IOC Lookup (Advanced)

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/ingestion/openapi/bulk-lookup/{object_type}/

Performs a lookup for threat data objects in Intel Exchange and retrieves the details of the objects, such as basic details, enriched data, and relations.

Path Parameters

NameTypeRequiredDescription
object_typestringrequired

Pass the object type to lookup. For the list of supported object types, see Supported SDO Types in Threat Data > Miscellaneous.

Query Parameters

NameTypeRequiredDescription
enrichment_databooleanoptional

Pass true to retrieve the latest five enrichment data objects.

relation_databooleanoptional

Pass true to retrieve the latest 100 relations details.

enrichment_toolsstringoptional

Pass the name of up to five enrichment tools separated by a comma. To retrieve a list of enrichment tools, use the GET Enrichment Tools API under Administration > Enrichment Management > Enrichment Tools.

fieldsstringoptional

Pass a comma-separated list of field names to retrieve specific details of the objects. By default, all fields are retrieved.

pageintegeroptional

Pass the page number to retrieve details from.

page_sizeintegeroptional

Pass the number of records to be retrieved per page.

Body Parameters

NameTypeRequiredDescription
valuearrayrequired

Pass the values of the IOCs you want to lookup.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Path Parameters
Query Parameters
Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/ingestion/openapi/bulk-lookup/indicator/?enrichment_data=true&relation_data=true&enrichment_tools=AbuseIPDB&fields=relations%2Cenrichment_data&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "value": [
    "76.77.23.225"
  ]
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/openapi/bulk-lookup/indicator/?enrichment_data=true&relation_data=true&enrichment_tools=AbuseIPDB&fields=relations%2Cenrichment_data&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "value": [
      "76.77.23.225"
    ]
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/ingestion/openapi/bulk-lookup/indicator/"
params = {
    "enrichment_data": "true",
    "relation_data": "true",
    "enrichment_tools": "AbuseIPDB",
    "fields": "relations,enrichment_data",
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "value": [
    "76.77.23.225"
  ]
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "value": [
    "76.77.23.225"
  ]
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "next": {},
  "previous": {},
  "total": 1,
  "results": [
    {}
  ],
  "page_size": 10
}

View-only example — running live API calls requires a role with snippet testing access.