REST API
Getting Started
v3 API
Overview
Features
- Create Activity Logs
- Create and Manage Associations
- Delete Case Objects in Bulk
- Enable Pagination
- Filter Results With TQL
- HTTP Status Codes
- Include Additional Fields in API Responses
- Retrieve a List of Available Fields for an Endpoint
- Retrieve OpenAPI Documentation
- Return a Count of Items
- Sort Results
- Specify an Owner
- Update an Object’s Metadata
Case Management Endpoints
Case Management and the Workflow feature in ThreatConnect enables analysts and their teams to define and operationalize consistent, standardized processes for managing threat intelligence and performing security operations.
Attention
To add, edit, and delete Case Management data, the API user must have an Organization role of Organization Administrator.
Threat Intelligence Endpoints
Miscellaneous Endpoints
TC Exchange Administration Endpoints
v2 API
- API Overview
- Associations
- Attributes
- Batch API
- Custom Metrics
- Groups
- Retrieve Groups
- Retrieve Group Metadata
- Retrieve Group Associations
- Create Groups
- Create Group Metadata
- Create Group Associations
- Update Groups
- Update Group Metadata
- Delete Groups
- Delete Group Metadata
- Delete/Disassociate Group Associations
- Publish Groups
- Create PDF Report for Groups
- Batch Upload: Groups
- Indicators
- Retrieve Indicators
- Retrieve Indicator Metadata
- Retrieve Indicator Associations
- Create Indicators
- Create Indicator Metadata
- Create Indicator Associations
- Update Indicators
- Update Indicator Metadata
- Delete Indicators
- Viewing Recently Deleted Indicators
- Delete Indicator Metadata
- Delete/Disassociate Indicator Associations
- Indicator to Indicator Associations
- Private Indicators
- Bulk Indicator Reports
- Batch Upload: Indicators
- Notifications
- Owners
- Playbooks
- Security Labels
- Tags
- Tasks
- Victims
- Retrieve Victims
- Retrieve Victim Metadata
- Retrieve Victim Associations
- Create Victims
- Create Victim Assets
- Create Victim Metadata
- Create Victim Associations
- Update Victims
- Update Victim Assets
- Update Victim Metadata
- Delete Victims
- Delete Victim Assets
- Delete Victim Metadata
- Delete/Disassociate Victim Associations