Skip to main content
GET
STIX 2.1 Indicator-of-Compromise feed

Query Parameters

type
enum<string>
Available options:
substrate_fingerprint,
sha256,
domain,
url,
technique_id
after
string<date-time>

Cursor — ISO-8601 timestamp; rows with last_seen_at < after are returned.

limit
integer
default:100
Required range: 1 <= x <= 1000

Response

STIX 2.1 Bundle (possibly empty at GA — see calm-at-GA contract).

type
any
required
id
string
required

STIX 2.1 bundle identifier (UUID-suffixed).

objects
object[]
required

STIX 2.1 indicator SDOs. Each carries a Mnemom extension with the internal indicator type + TLP + linkage to a related advisory.

next_after
string<date-time>

Mnemom-extension pagination cursor. Present iff the response was capped at limit. Pass as ?after= to fetch the next page.