DCSO's Threat Intelligence API v2
This is DCSO implementation of STIX/TAXII standard as specified by the OASIS Organization:
Endpoints
We implemented the following endpoints:
| Endpoint | Purpose |
|---|---|
GET /taxii2 | This API endpoint provides details for a TAXII consumer to retrieve basic information on the actual service endpoint serving the threat intelligence data. This "well-known" endpoint provides general information about a TAXII Server, including the advertised API Roots. It is a common entry point for TAXII Clients into the data and services provided by a TAXII Server. |
GET /collections | This Endpoint provides information about the Collections hosted under the respective API Root. This is similar to the response to get a Collection but rather than providing information about one Collection it provides information about all of the Collections. Most importantly, it provides the Collection's id, which is used to request objects or manifest entries from the Collection. |
GET /collections/{id} | This Endpoint provides general information about a Collection, which can be used to help users and clients decide whether and how they want to interact with it. |
GET /collections/{id}/objects | This Endpoint retrieves objects from a Collection. Clients can search for objects in the Collection, retrieve all objects in a Collection, or paginate through objects in the Collection. |
Release Notes TIE v2
2023-08-25 (tie.v2.20230825)
Release
- Endpoints
GET /taxii2: retrieve basic information on the actual STIX/TAXII service endpoint serving the threat intelligence dataGET /collections: retrieve available collectionsGET /collection/{collection_id}: retrieve details for a specific collectionGET /collection/{collection_id}/objects: retrieve objects for a specific collection