Skip to content
Start here

Tags

Lists all tags (SoT)
GET/accounts/{account_id}/cloudforce-one/events/tags
Creates a new tag
POST/accounts/{account_id}/cloudforce-one/events/tags/create
Updates a tag (SoT)
PATCH/accounts/{account_id}/cloudforce-one/events/tags/{tag_uuid}
Deletes a tag (SoT)
DELETE/accounts/{account_id}/cloudforce-one/events/tags/{tag_uuid}
ModelsExpand Collapse
TagListResponse object { pagination, tags }
tags: array of object { uuid, value, activeDuration, 25 more }
uuid: string
value: string
activeDuration: optional string
actorCategory: optional string
actorCategoryConfidence: optional number

Confidence (1-10) in the actor variety (actorCategory). CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
aliases: optional array of object { value, confidence, tlp }

Structured aliases ({ value, confidence 1-10, tlp }). CFONE-only: stripped from responses to non-CFONE accounts.

value: string
confidence: optional number
maximum10
minimum1
tlp: optional "red" or "amber" or "green" or "white"
One of the following:
"red"
"amber"
"green"
"white"
aliasGroupNames: optional array of string
aliasGroupNamesInternal: optional array of string
analyticPriority: optional number
attributionConfidence: optional string
attributionConfidenceScore: optional number
maximum10
minimum1
attributionOrganization: optional string
categoryName: optional string
categoryUuid: optional string
dateOfDiscovery: optional string
externalReferences: optional array of object { url, description }

Structured external references ({ url, description }). Public: returned to all accounts.

url: string
description: optional string
internalAliases: optional array of object { value, confidence, tlp }

Internal structured aliases ({ value, confidence 1-10, tlp }). CFONE-only: never returned to non-CFONE accounts.

value: string
confidence: optional number
maximum10
minimum1
tlp: optional "red" or "amber" or "green" or "white"
One of the following:
"red"
"amber"
"green"
"white"
internalDescription: optional string
motive: optional string
motiveConfidence: optional number

Confidence (1-10) in the actor motive. CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
opsecLevel: optional string
originCountryConfidence: optional number

Confidence (1-10) in the origin-country attribution. CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
originCountryISO: optional string
originCountryISOAlpha3: optional string
originCountryTlp: optional "red" or "amber" or "green" or "white"

TLP marking for the origin-country attribution. CFONE-only: stripped from responses to non-CFONE accounts.

One of the following:
"red"
"amber"
"green"
"white"
priority: optional number
sophisticationLevel: optional string
TagCreateResponse object { uuid, value, activeDuration, 25 more }
uuid: string
value: string
activeDuration: optional string
actorCategory: optional string
actorCategoryConfidence: optional number

Confidence (1-10) in the actor variety (actorCategory). CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
aliases: optional array of object { value, confidence, tlp }

Structured aliases ({ value, confidence 1-10, tlp }). CFONE-only: stripped from responses to non-CFONE accounts.

value: string
confidence: optional number
maximum10
minimum1
tlp: optional "red" or "amber" or "green" or "white"
One of the following:
"red"
"amber"
"green"
"white"
aliasGroupNames: optional array of string
aliasGroupNamesInternal: optional array of string
analyticPriority: optional number
attributionConfidence: optional string
attributionConfidenceScore: optional number
maximum10
minimum1
attributionOrganization: optional string
categoryName: optional string
categoryUuid: optional string
dateOfDiscovery: optional string
externalReferences: optional array of object { url, description }

Structured external references ({ url, description }). Public: returned to all accounts.

url: string
description: optional string
internalAliases: optional array of object { value, confidence, tlp }

Internal structured aliases ({ value, confidence 1-10, tlp }). CFONE-only: never returned to non-CFONE accounts.

value: string
confidence: optional number
maximum10
minimum1
tlp: optional "red" or "amber" or "green" or "white"
One of the following:
"red"
"amber"
"green"
"white"
internalDescription: optional string
motive: optional string
motiveConfidence: optional number

Confidence (1-10) in the actor motive. CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
opsecLevel: optional string
originCountryConfidence: optional number

Confidence (1-10) in the origin-country attribution. CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
originCountryISO: optional string
originCountryISOAlpha3: optional string
originCountryTlp: optional "red" or "amber" or "green" or "white"

TLP marking for the origin-country attribution. CFONE-only: stripped from responses to non-CFONE accounts.

One of the following:
"red"
"amber"
"green"
"white"
priority: optional number
sophisticationLevel: optional string
TagEditResponse object { uuid, value, activeDuration, 25 more }
uuid: string
value: string
activeDuration: optional string
actorCategory: optional string
actorCategoryConfidence: optional number

Confidence (1-10) in the actor variety (actorCategory). CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
aliases: optional array of object { value, confidence, tlp }

Structured aliases ({ value, confidence 1-10, tlp }). CFONE-only: stripped from responses to non-CFONE accounts.

value: string
confidence: optional number
maximum10
minimum1
tlp: optional "red" or "amber" or "green" or "white"
One of the following:
"red"
"amber"
"green"
"white"
aliasGroupNames: optional array of string
aliasGroupNamesInternal: optional array of string
analyticPriority: optional number
attributionConfidence: optional string
attributionConfidenceScore: optional number
maximum10
minimum1
attributionOrganization: optional string
categoryName: optional string
categoryUuid: optional string
dateOfDiscovery: optional string
externalReferences: optional array of object { url, description }

Structured external references ({ url, description }). Public: returned to all accounts.

url: string
description: optional string
internalAliases: optional array of object { value, confidence, tlp }

Internal structured aliases ({ value, confidence 1-10, tlp }). CFONE-only: never returned to non-CFONE accounts.

value: string
confidence: optional number
maximum10
minimum1
tlp: optional "red" or "amber" or "green" or "white"
One of the following:
"red"
"amber"
"green"
"white"
internalDescription: optional string
motive: optional string
motiveConfidence: optional number

Confidence (1-10) in the actor motive. CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
opsecLevel: optional string
originCountryConfidence: optional number

Confidence (1-10) in the origin-country attribution. CFONE-only: stripped from responses to non-CFONE accounts.

maximum10
minimum1
originCountryISO: optional string
originCountryISOAlpha3: optional string
originCountryTlp: optional "red" or "amber" or "green" or "white"

TLP marking for the origin-country attribution. CFONE-only: stripped from responses to non-CFONE accounts.

One of the following:
"red"
"amber"
"green"
"white"
priority: optional number
sophisticationLevel: optional string
TagDeleteResponse object { uuid }
uuid: string

TagsCategories

Lists all tag categories (SoT)
GET/accounts/{account_id}/cloudforce-one/events/tags/categories
Creates a new tag category (SoT)
POST/accounts/{account_id}/cloudforce-one/events/tags/categories/create
Updates a tag category (SoT)
PATCH/accounts/{account_id}/cloudforce-one/events/tags/categories/{category_uuid}
Deletes a tag category (SoT)
DELETE/accounts/{account_id}/cloudforce-one/events/tags/categories/{category_uuid}
ModelsExpand Collapse
CategoryListResponse object { categories }
categories: array of object { name, uuid, createdAt, 2 more }
name: string
uuid: string
createdAt: optional string
description: optional string
updatedAt: optional string
CategoryCreateResponse object { name, uuid, createdAt, 2 more }
name: string
uuid: string
createdAt: optional string
description: optional string
updatedAt: optional string
CategoryEditResponse object { name, uuid, createdAt, 2 more }
name: string
uuid: string
createdAt: optional string
description: optional string
updatedAt: optional string
CategoryDeleteResponse object { uuid }
uuid: string

TagsIndicators

List indicators related to a tag
GET/accounts/{account_id}/cloudforce-one/events/tags/{tag_uuid}/indicators
ModelsExpand Collapse
IndicatorListResponse object { indicators, pagination }
indicators: array of object { createdAt, indicatorType, updatedAt, 5 more }
createdAt: string
formatdate-time
indicatorType: string
updatedAt: string
formatdate-time
uuid: string
value: string
datasetId: optional string

The dataset ID this indicator belongs to. Included in list responses.

relatedEvents: optional array of object { datasetId, eventId, eventDate }
datasetId: string
eventId: string
eventDate: optional string

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

tags: optional array of object { categoryName, uuid, value }
categoryName: optional string
uuid: optional string
value: optional string

TagsIndicatorsBy Dataset

List indicators related to a tag within a dataset (deprecated)
Deprecated
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/tags/{tag_uuid}/indicators
ModelsExpand Collapse
ByDatasetListResponse object { indicators, pagination }
indicators: array of object { createdAt, indicatorType, updatedAt, 5 more }
createdAt: string
formatdate-time
indicatorType: string
updatedAt: string
formatdate-time
uuid: string
value: string
datasetId: optional string

The dataset ID this indicator belongs to. Included in list responses.

relatedEvents: optional array of object { datasetId, eventId, eventDate }
datasetId: string
eventId: string
eventDate: optional string

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

tags: optional array of object { categoryName, uuid, value }
categoryName: optional string
uuid: optional string
value: optional string