Skip to content
Start here

Threat Signals

Threat Signals API for managing threat intelligence feeds, articles, indicators, and AI skills in Cloudforce One.

Prerequisites

  1. API token — requests must use an API token with Cloudforce One permissions; write operations (creating, editing, or deleting feeds, skills, and tags) require write access.
  2. Plan limits — access on the Free plan is limited; feed quotas and managed default skills apply.
Check Threat Signals service health
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/health

Threat SignalsCategories

List Threat Signals feed categories
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/categories
ModelsExpand Collapse
CategoryListResponse object { categories }
categories: array of object { id, description, name }
id: string

Wire value accepted by the feed category_id field.

formatuuid
description: string

Plain-language description of the category.

name: string

Human-readable display label.

Threat SignalsFeeds

List Threat Signals feeds
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Create Threat Signals feed
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Update Threat Signals feed
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Delete Threat Signals feed
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Trigger Threat Signals feed poll
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/poll
ModelsExpand Collapse
FeedPollResponse object { errors, feeds, triggered }
errors: number
feeds: array of object { feed_id, status, workflow_id, feed_enabled }
feed_id: string
formatuuid
status: "workflow_created" or "error"
One of the following:
"workflow_created"
"error"
workflow_id: string
feed_enabled: optional boolean
triggered: number

Threat SignalsFeedsRaw

Get Threat Signals feed XML
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/raw

Threat SignalsFeedsSkills

Get Threat Signals feed skills
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills
Set Threat Signals feed skills
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills

Threat SignalsArticles

List Threat Signals articles
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Bulk update Threat Signals article read status
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Get Threat Signals article
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
Update Threat Signals article read status
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
ModelsExpand Collapse
ArticleListResponse object { articles, has_more, next_cursor, 2 more }
articles: array of object { id, dataset_id, event_id, 10 more }
id: string
formatuuid
dataset_id: string

Threat Events dataset identifier for the article redirect. Null when the account feeds dataset mapping is unavailable.

event_id: string

Threat Events event identifier associated with this article for a UI redirect. Null when no event has been linked.

feed_display_name: string
feed_id: string
formatuuid
fetched_at: string
link: string
published_at: string
read: boolean
read_at: string
summary: string

Persisted enrichment summary. Null until enrichment produces a summary.

tags: array of object { applied_by, categoryId, uuid, value }
applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string
title: string
has_more: boolean
next_cursor: string
total_count: number
total_count_is_exact: boolean

Threat SignalsArticlesContent

Get Threat Signals article content
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/content

Threat SignalsArticlesTags

Add tag to Threat Signals article
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags
Remove tag from Threat Signals article
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags/{tag_id}
Generate Threat Signals article AI tags
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tag
ModelsExpand Collapse
TagGenerateResponse object { tag_skill_version, tags }
tag_skill_version: string
tags: array of object { applied_by, categoryId, uuid, value }

Final hydrated assignment set; may be empty when no applicable tags are selected.

applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string

Threat SignalsArticlesSkill Outputs

Get Threat Signals article skill output
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/skills/{skill_id}/output

Threat SignalsIndicators

List Threat Signals article indicators
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/indicators
ModelsExpand Collapse
IndicatorListResponse object { indicators, pagination }
indicators: array of object { id, article_id, article_title, 5 more }
id: string
formatuuid
article_id: string
formatuuid
article_title: string
dataset_id: string

Threat Events dataset identifier for navigating from this indicator. Null when the account feeds dataset mapping is unavailable.

feed_display_name: string
feed_id: string
formatuuid
type: string
value: string

Threat SignalsSkills

List Threat Signals skills
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Create Threat Signals skill
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Get Threat Signals skill
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Update Threat Signals skill
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Delete Threat Signals skill
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}

Threat SignalsSkillsTag Categories

Get Threat Signals skill tag categories
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
Replace Threat Signals skill tag categories
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
ModelsExpand Collapse
TagCategoryGetResponse object { category_uuids, skill_id }
category_uuids: array of string
skill_id: "default-tagging-skill"
TagCategoryUpdateResponse object { category_uuids, skill_id }
category_uuids: array of string
skill_id: "default-tagging-skill"