CTIX
Network live
CTIXPOST

Enrich Nodes

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/integration/investigation/enrichment/

Enrich threat data objects for threat investigation using third-party enrichment tools configured in Intel Exchange.

Query Parameters

NameTypeRequiredDescription
pagestringoptional

Pass the page number to retrieve enrichment results.

page_sizestringoptional

Pass the number of results to retrieve per page.

Body Parameters

NameTypeRequiredDescription
object_idstringrequired

Pass the ID of the threat data object.

object_typestringrequired

Pass the type of the threat data object such as indicator, vulnerability, and more.

typestringrequired

Pass the type or the sub type of the threat data object such as url, domain, ipv4-addr, and more.

app_slugstringrequired

Pass the slug of an enrichment tool to use for enrichment. To retrieve the list of enrichment tools, use the GET Enrichment Tools API.

action_slugstringrequired

Pass the slug value of the action. For example, get_ip.

valuestringrequired

Pass the value of the threat data object.

identifierstringrequired

Pass ctix to indicate that the threat data object already exists in the Intel Exchange database. If you pass anything else, it indicates a custom object.

raw_dataobjectrequired

If the node is already enriched, then pass the raw data to prevent it from getting re-enriched.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Query Parameters
Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/integration/investigation/enrichment/?page=1&page_size=10&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "object_id": "01cde415-bed4-40c0-aed4-dd4a52ea6450",
  "object_type": "indicator",
  "type": "ipv4-addr",
  "app_slug": "alien_vault",
  "action_slug": "get_ip",
  "value": "311.76.208.163",
  "identifier": "ctix",
  "raw_data": {}
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/integration/investigation/enrichment/?page=1&page_size=10&AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "object_id": "01cde415-bed4-40c0-aed4-dd4a52ea6450",
    "object_type": "indicator",
    "type": "ipv4-addr",
    "app_slug": "alien_vault",
    "action_slug": "get_ip",
    "value": "311.76.208.163",
    "identifier": "ctix",
    "raw_data": {}
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/integration/investigation/enrichment/"
params = {
    "page": "1",
    "page_size": "10",
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "object_id": "01cde415-bed4-40c0-aed4-dd4a52ea6450",
  "object_type": "indicator",
  "type": "ipv4-addr",
  "app_slug": "alien_vault",
  "action_slug": "get_ip",
  "value": "311.76.208.163",
  "identifier": "ctix",
  "raw_data": {}
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "object_id": "01cde415-bed4-40c0-aed4-dd4a52ea6450",
  "object_type": "indicator",
  "type": "ipv4-addr",
  "app_slug": "alien_vault",
  "action_slug": "get_ip",
  "value": "311.76.208.163",
  "identifier": "ctix",
  "raw_data": {}
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "next": "investigation/enrichment/?page=2&page_size=10",
  "previous": {},
  "page_size": 10,
  "total": 24,
  "results": [
    {}
  ]
}

View-only example — running live API calls requires a role with snippet testing access.