Skip to content
Start here

Threat Signals

Threat Signals API for managing threat intelligence feeds, articles, indicators, and AI skills in Cloudforce One.

Prerequisites

  1. API token — requests must use an API token with Cloudforce One permissions; write operations (creating, editing, or deleting feeds, skills, and tags) require write access.
  2. Plan limits — access on the Free plan is limited; feed quotas and managed default skills apply.

Threat SignalsSearch

Search Threat Signals articles using AI Search
cloudforce_one.threat_signals.search.search(SearchSearchParams**kwargs) -> SearchSearchResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/search
ModelsExpand Collapse
class SearchSearchResponse: …
count: int

Number of unique article candidates returned in this response. Equal to results.length.

minimum0
results: List[Result]
article_id: str
formatuuid
dataset_id: Optional[str]
formatuuid
event_id: Optional[str]
formatuuid
feed_id: str
formatuuid
score: float
text: str

Threat SignalsCategories

List Threat Signals feed categories
cloudforce_one.threat_signals.categories.list(CategoryListParams**kwargs) -> CategoryListResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/categories
ModelsExpand Collapse
class CategoryListResponse: …
categories: List[Category]
id: str

Wire value accepted by the feed category_id field.

formatuuid
description: str

Plain-language description of the category.

name: str

Human-readable display label.

Threat SignalsFeeds

List Threat Signals feeds
cloudforce_one.threat_signals.feeds.list(FeedListParams**kwargs) -> SyncV4PagePagination[FeedListResponse]
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Create Threat Signals feed
cloudforce_one.threat_signals.feeds.create(FeedCreateParams**kwargs) -> FeedCreateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Update Threat Signals feed
cloudforce_one.threat_signals.feeds.edit(strfeed_id, FeedEditParams**kwargs) -> FeedEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Delete Threat Signals feed
cloudforce_one.threat_signals.feeds.delete(strfeed_id, FeedDeleteParams**kwargs) -> FeedDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Trigger Threat Signals feed poll
cloudforce_one.threat_signals.feeds.poll(FeedPollParams**kwargs) -> FeedPollResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/poll
ModelsExpand Collapse
class FeedListResponse: …
count: int

Number of feeds on this page.

feeds: List[Feed]
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
page: int
per_page: int
total_count: int
class FeedCreateResponse: …
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
class FeedEditResponse: …
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
class FeedDeleteResponse: …
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
class FeedPollResponse: …
errors: float
feeds: List[Feed]
feed_id: str
formatuuid
status: Literal["workflow_created", "error"]
One of the following:
"workflow_created"
"error"
workflow_id: str
feed_enabled: Optional[bool]
triggered: float

Threat SignalsFeedsRaw

Get Threat Signals feed XML
cloudforce_one.threat_signals.feeds.raw.get(strfeed_id, RawGetParams**kwargs) -> RawGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/raw
ModelsExpand Collapse
str

Threat SignalsFeedsSkills

Get Threat Signals feed skills
cloudforce_one.threat_signals.feeds.skills.get(strfeed_id, SkillGetParams**kwargs) -> SkillGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills
Set Threat Signals feed skills
cloudforce_one.threat_signals.feeds.skills.update(strfeed_id, SkillUpdateParams**kwargs) -> SkillUpdateResponse
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills
ModelsExpand Collapse
class SkillGetResponse: …
feed_id: str
formatuuid
skills: List[Skill]
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillUpdateResponse: …
feed_id: str
formatuuid
skills: List[Skill]
position: int

Zero-based pipeline position.

skill_id: str

Threat SignalsArticles

List Threat Signals articles
cloudforce_one.threat_signals.articles.list(ArticleListParams**kwargs) -> ArticleListResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Bulk update Threat Signals article read status
cloudforce_one.threat_signals.articles.bulk_edit(ArticleBulkEditParams**kwargs) -> ArticleBulkEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Get Threat Signals article
cloudforce_one.threat_signals.articles.get(strarticle_id, ArticleGetParams**kwargs) -> ArticleGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
Update Threat Signals article read status
cloudforce_one.threat_signals.articles.edit(strarticle_id, ArticleEditParams**kwargs) -> ArticleEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
ModelsExpand Collapse
class ArticleListResponse: …
articles: List[Article]
id: str
formatuuid
dataset_id: Optional[str]

Threat Events dataset identifier for the article redirect. Null when the account feeds dataset mapping is unavailable.

event_id: Optional[str]

Threat Events event identifier associated with this article for a UI redirect. Null when no event has been linked.

feed_display_name: Optional[str]
feed_id: str
formatuuid
fetched_at: str
link: Optional[str]
published_at: Optional[str]
read: bool
read_at: Optional[str]
summary: Optional[str]

Persisted enrichment summary. Null until enrichment produces a summary.

tags: List[ArticleTag]
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
title: Optional[str]
has_more: bool
next_cursor: Optional[str]
total_count: Optional[float]
total_count_is_exact: bool
class ArticleBulkEditResponse: …
updated_count: float
class ArticleGetResponse: …
id: str
formatuuid
bullet_points: Optional[BulletPoints]
impact: str
what_happened: str
who_affected: str
content_r2_key: Optional[str]
feed_display_name: Optional[str]
feed_id: str
formatuuid
fetched_at: str
indicator_extraction_status: Literal["in_progress", "complete", "failed", "unknown"]

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

One of the following:
"in_progress"
"complete"
"failed"
"unknown"
link: Optional[str]
metadata: Optional[Dict[str, object]]
published_at: Optional[str]
read: bool
read_at: Optional[str]
source_count: float
summary: Optional[str]

Persisted enrichment summary. Null until enrichment produces a summary.

summary_r2_key: Optional[str]
tags: List[Tag]
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
title: Optional[str]
skill_version: Optional[str]
tag_skill_version: Optional[str]
class ArticleEditResponse: …
id: str
formatuuid
bullet_points: Optional[BulletPoints]
impact: str
what_happened: str
who_affected: str
content_r2_key: Optional[str]
feed_display_name: Optional[str]
feed_id: str
formatuuid
fetched_at: str
indicator_extraction_status: Literal["in_progress", "complete", "failed", "unknown"]

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

One of the following:
"in_progress"
"complete"
"failed"
"unknown"
link: Optional[str]
metadata: Optional[Dict[str, object]]
published_at: Optional[str]
read: bool
read_at: Optional[str]
source_count: float
summary: Optional[str]

Persisted enrichment summary. Null until enrichment produces a summary.

summary_r2_key: Optional[str]
tags: List[Tag]
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
title: Optional[str]
skill_version: Optional[str]
tag_skill_version: Optional[str]

Threat SignalsArticlesContent

Get Threat Signals article content
cloudforce_one.threat_signals.articles.content.get(strarticle_id, ContentGetParams**kwargs) -> ContentGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/content
ModelsExpand Collapse
str

Threat SignalsArticlesTags

Add tag to Threat Signals article
cloudforce_one.threat_signals.articles.tags.create(strarticle_id, TagCreateParams**kwargs) -> TagCreateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags
Remove tag from Threat Signals article
cloudforce_one.threat_signals.articles.tags.delete(strtag_id, TagDeleteParams**kwargs) -> TagDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags/{tag_id}
Generate Threat Signals article AI tags
cloudforce_one.threat_signals.articles.tags.generate(strarticle_id, TagGenerateParams**kwargs) -> TagGenerateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tag
ModelsExpand Collapse
class TagCreateResponse: …
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
class TagDeleteResponse: …
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
class TagGenerateResponse: …
tag_skill_version: str
tags: List[Tag]

Final hydrated assignment set; may be empty when no applicable tags are selected.

applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str

Threat SignalsArticlesSkill Outputs

Get Threat Signals article skill output
cloudforce_one.threat_signals.articles.skill_outputs.get(strskill_id, SkillOutputGetParams**kwargs) -> SkillOutputGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/skills/{skill_id}/output
ModelsExpand Collapse
class SkillOutputGetResponse: …
article_id: str
formatuuid
custom_skill_version: Optional[str]
output_schema: Optional[str]

JSON-encoded output schema of the skill. Null when the skill no longer exists.

skill_id: str
custom_output: Optional[object]

Skill output. Parsed JSON when the stored output is valid JSON, otherwise the raw string.

Threat SignalsIndicators

List Threat Signals article indicators
cloudforce_one.threat_signals.indicators.list(IndicatorListParams**kwargs) -> IndicatorListResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/indicators
ModelsExpand Collapse
class IndicatorListResponse: …
indicators: List[Indicator]
id: str
formatuuid
article_id: str
formatuuid
article_title: Optional[str]
dataset_id: Optional[str]

Threat Events dataset identifier for navigating from this indicator. Null when the account feeds dataset mapping is unavailable.

feed_display_name: Optional[str]
feed_id: str
formatuuid
type: str
value: str

Threat SignalsSkills

List Threat Signals skills
cloudforce_one.threat_signals.skills.list(SkillListParams**kwargs) -> SyncV4PagePagination[SkillListResponse]
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Create Threat Signals skill
cloudforce_one.threat_signals.skills.create(SkillCreateParams**kwargs) -> SkillCreateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Get Threat Signals skill
cloudforce_one.threat_signals.skills.get(strskill_id, SkillGetParams**kwargs) -> SkillGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Update Threat Signals skill
cloudforce_one.threat_signals.skills.edit(strskill_id, SkillEditParams**kwargs) -> SkillEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Delete Threat Signals skill
cloudforce_one.threat_signals.skills.delete(strskill_id, SkillDeleteParams**kwargs) -> SkillDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
ModelsExpand Collapse
class SkillListResponse: …
count: int

Number of skills on this page.

custom_skills_available: bool

Whether the authenticated account may access custom-skill capabilities under Stakeout’s Threat Signals access-mode policy. This is a policy availability indicator, not a row-existence indicator. False for threat_signals_only mode; true for entitled, allowlisted, cfone_internal, and service modes.

page: int
per_page: int
skills: List[Skill]
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
total_count: int
class SkillCreateResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillGetResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillEditResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillDeleteResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str

Threat SignalsSkillsTag Categories

Get Threat Signals skill tag categories
cloudforce_one.threat_signals.skills.tag_categories.get(Literal["default-tagging-skill"]skill_id, TagCategoryGetParams**kwargs) -> TagCategoryGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
Replace Threat Signals skill tag categories
cloudforce_one.threat_signals.skills.tag_categories.update(Literal["default-tagging-skill"]skill_id, TagCategoryUpdateParams**kwargs) -> TagCategoryUpdateResponse
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
ModelsExpand Collapse
class TagCategoryGetResponse: …
category_uuids: List[str]
skill_id: Literal["default-tagging-skill"]
class TagCategoryUpdateResponse: …
category_uuids: List[str]
skill_id: Literal["default-tagging-skill"]