Skip to content
Start here

Cloudforce One

Cloudforce OneBinary Storage

Retrieves a file from Binary Storage
cloudforce_one.binary_storage.get(strhash, BinaryStorageGetParams**kwargs)
GET/accounts/{account_id}/cloudforce-one/binary/{hash}
Posts a file to Binary Storage
cloudforce_one.binary_storage.create(BinaryStorageCreateParams**kwargs) -> BinaryStorageCreateResponse
POST/accounts/{account_id}/cloudforce-one/binary
ModelsExpand Collapse
class BinaryStorageCreateResponse: …
content_type: str
md5: str
sha1: str
sha256: str

Cloudforce OneRequests

List Requests
cloudforce_one.requests.list(RequestListParams**kwargs) -> SyncSinglePage[ListItem]
POST/accounts/{account_id}/cloudforce-one/requests
Get a Request
cloudforce_one.requests.get(strrequest_id, RequestGetParams**kwargs) -> Item
GET/accounts/{account_id}/cloudforce-one/requests/{request_id}
Create a New Request.
cloudforce_one.requests.create(RequestCreateParams**kwargs) -> Item
POST/accounts/{account_id}/cloudforce-one/requests/new
Update a Request
cloudforce_one.requests.update(strrequest_id, RequestUpdateParams**kwargs) -> Item
PUT/accounts/{account_id}/cloudforce-one/requests/{request_id}
Delete a Request
cloudforce_one.requests.delete(strrequest_id, RequestDeleteParams**kwargs) -> RequestDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/requests/{request_id}
Get Request Quota
cloudforce_one.requests.quota(RequestQuotaParams**kwargs) -> Quota
GET/accounts/{account_id}/cloudforce-one/requests/quota
Get Request Types
cloudforce_one.requests.types(RequestTypesParams**kwargs) -> SyncSinglePage[RequestTypesResponse]
GET/accounts/{account_id}/cloudforce-one/requests/types
Get Request Priority, Status, and TLP constants
cloudforce_one.requests.constants(RequestConstantsParams**kwargs) -> RequestConstants
GET/accounts/{account_id}/cloudforce-one/requests/constants
ModelsExpand Collapse
class Item: …
id: str

UUID.

maxLength36
content: str

Request content.

created: datetime
formatdate-time
priority: datetime
formatdate-time
request: str

Requested information from request.

summary: str

Brief description of the request.

tlp: Literal["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

One of the following:
"clear"
"amber"
"amber-strict"
"green"
"red"
updated: datetime
formatdate-time
completed: Optional[datetime]
formatdate-time
message_tokens: Optional[int]

Tokens for the request messages.

readable_id: Optional[str]

Readable Request ID.

status: Optional[Literal["open", "accepted", "reported", 3 more]]

Request Status.

One of the following:
"open"
"accepted"
"reported"
"approved"
"completed"
"declined"
tokens: Optional[int]

Tokens for the request.

class ListItem: …
id: str

UUID.

maxLength36
created: datetime

Request creation time.

formatdate-time
priority: Literal["routine", "high", "urgent"]
One of the following:
"routine"
"high"
"urgent"
request: str

Requested information from request.

summary: str

Brief description of the request.

tlp: Literal["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

One of the following:
"clear"
"amber"
"amber-strict"
"green"
"red"
updated: datetime

Request last updated time.

formatdate-time
completed: Optional[datetime]

Request completion time.

formatdate-time
message_tokens: Optional[int]

Tokens for the request messages.

readable_id: Optional[str]

Readable Request ID.

status: Optional[Literal["open", "accepted", "reported", 3 more]]

Request Status.

One of the following:
"open"
"accepted"
"reported"
"approved"
"completed"
"declined"
tokens: Optional[int]

Tokens for the request.

class Quota: …
anniversary_date: Optional[datetime]

Anniversary date is when annual quota limit is refreshed.

formatdate-time
quarter_anniversary_date: Optional[datetime]

Quarter anniversary date is when quota limit is refreshed each quarter.

formatdate-time
quota: Optional[int]

Tokens for the quarter.

remaining: Optional[int]

Tokens remaining for the quarter.

class RequestConstants: …
priority: Optional[List[Literal["routine", "high", "urgent"]]]
One of the following:
"routine"
"high"
"urgent"
status: Optional[List[Literal["open", "accepted", "reported", 3 more]]]
One of the following:
"open"
"accepted"
"reported"
"approved"
"completed"
"declined"
tlp: Optional[List[Literal["clear", "amber", "amber-strict", 2 more]]]
One of the following:
"clear"
"amber"
"amber-strict"
"green"
"red"
class RequestDeleteResponse: …
errors: List[Error]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[ErrorSource]
pointer: Optional[str]
messages: List[Message]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[MessageSource]
pointer: Optional[str]
success: Literal[true]

Whether the API call was successful.

str

Request Types.

Cloudforce OneRequestsMessage

List Request Messages
cloudforce_one.requests.message.get(strrequest_id, MessageGetParams**kwargs) -> SyncSinglePage[Message]
POST/accounts/{account_id}/cloudforce-one/requests/{request_id}/message
Create a New Request Message
cloudforce_one.requests.message.create(strrequest_id, MessageCreateParams**kwargs) -> Message
POST/accounts/{account_id}/cloudforce-one/requests/{request_id}/message/new
Update a Request Message
cloudforce_one.requests.message.update(intmessage_id, MessageUpdateParams**kwargs) -> Message
PUT/accounts/{account_id}/cloudforce-one/requests/{request_id}/message/{message_id}
Delete a Request Message
cloudforce_one.requests.message.delete(intmessage_id, MessageDeleteParams**kwargs) -> MessageDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/requests/{request_id}/message/{message_id}
ModelsExpand Collapse
class Message: …
id: int

Message ID.

author: str

Author of message.

content: str

Content of message.

is_follow_on_request: bool

Whether the message is a follow-on request.

updated: datetime

Defines the message last updated time.

formatdate-time
created: Optional[datetime]

Defines the message creation time.

formatdate-time
class MessageDeleteResponse: …
errors: List[Error]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[ErrorSource]
pointer: Optional[str]
messages: List[Message]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[MessageSource]
pointer: Optional[str]
success: Literal[true]

Whether the API call was successful.

Cloudforce OneRequestsPriority

Get a Priority Intelligence Requirement
cloudforce_one.requests.priority.get(strpriority_id, PriorityGetParams**kwargs) -> Item
GET/accounts/{account_id}/cloudforce-one/requests/priority/{priority_id}
Create a New Priority Intelligence Requirement
cloudforce_one.requests.priority.create(PriorityCreateParams**kwargs) -> Priority
POST/accounts/{account_id}/cloudforce-one/requests/priority/new
Update a Priority Intelligence Requirement
cloudforce_one.requests.priority.update(strpriority_id, PriorityUpdateParams**kwargs) -> Item
PUT/accounts/{account_id}/cloudforce-one/requests/priority/{priority_id}
Delete a Priority Intelligence Requirement
cloudforce_one.requests.priority.delete(strpriority_id, PriorityDeleteParams**kwargs) -> PriorityDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/requests/priority/{priority_id}
Get Priority Intelligence Requirement Quota
cloudforce_one.requests.priority.quota(PriorityQuotaParams**kwargs) -> Quota
GET/accounts/{account_id}/cloudforce-one/requests/priority/quota
ModelsExpand Collapse
str
class Priority: …
id: str

UUID.

maxLength36
created: datetime

Priority creation time.

formatdate-time
labels: List[Label]

List of labels.

priority: int

Priority.

requirement: str

Requirement.

tlp: Literal["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

One of the following:
"clear"
"amber"
"amber-strict"
"green"
"red"
updated: datetime

Priority last updated time.

formatdate-time
class PriorityEdit: …
labels: List[Label]

List of labels.

priority: int

Priority.

requirement: str

Requirement.

tlp: Literal["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

One of the following:
"clear"
"amber"
"amber-strict"
"green"
"red"
class PriorityDeleteResponse: …
errors: List[Error]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[ErrorSource]
pointer: Optional[str]
messages: List[Message]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[MessageSource]
pointer: Optional[str]
success: Literal[true]

Whether the API call was successful.

Cloudforce OneRequestsAssets

Get a Request Asset
cloudforce_one.requests.assets.get(strasset_id, AssetGetParams**kwargs) -> SyncSinglePage[AssetGetResponse]
GET/accounts/{account_id}/cloudforce-one/requests/{request_id}/asset/{asset_id}
List Request Assets
cloudforce_one.requests.assets.create(strrequest_id, AssetCreateParams**kwargs) -> SyncSinglePage[AssetCreateResponse]
POST/accounts/{account_id}/cloudforce-one/requests/{request_id}/asset
Update a Request Asset
cloudforce_one.requests.assets.update(strasset_id, AssetUpdateParams**kwargs) -> AssetUpdateResponse
PUT/accounts/{account_id}/cloudforce-one/requests/{request_id}/asset/{asset_id}
Delete a Request Asset
cloudforce_one.requests.assets.delete(strasset_id, AssetDeleteParams**kwargs) -> AssetDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/requests/{request_id}/asset/{asset_id}
ModelsExpand Collapse
class AssetGetResponse: …
id: int

Asset ID.

name: str

Asset name.

created: Optional[datetime]

Defines the asset creation time.

formatdate-time
description: Optional[str]

Asset description.

file_type: Optional[str]

Asset file type.

class AssetCreateResponse: …
id: int

Asset ID.

name: str

Asset name.

created: Optional[datetime]

Defines the asset creation time.

formatdate-time
description: Optional[str]

Asset description.

file_type: Optional[str]

Asset file type.

class AssetUpdateResponse: …
id: int

Asset ID.

name: str

Asset name.

created: Optional[datetime]

Defines the asset creation time.

formatdate-time
description: Optional[str]

Asset description.

file_type: Optional[str]

Asset file type.

class AssetDeleteResponse: …
errors: List[Error]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[ErrorSource]
pointer: Optional[str]
messages: List[Message]
code: int
minimum1000
message: str
documentation_url: Optional[str]
source: Optional[MessageSource]
pointer: Optional[str]
success: Literal[true]

Whether the API call was successful.

Cloudforce OneScans

Cloudforce OneScansResults

Get the Latest Scan Result
cloudforce_one.scans.results.get(strconfig_id, ResultGetParams**kwargs) -> ResultGetResponse
GET/accounts/{account_id}/cloudforce-one/scans/results/{config_id}
ModelsExpand Collapse
class ScanResult: …
number: Optional[float]
proto: Optional[str]
status: Optional[str]
class ResultGetResponse: …
_1_1_1_1: List[ScanResult]
number: Optional[float]
proto: Optional[str]
status: Optional[str]

Cloudforce OneScansConfig

List Scan Configs
cloudforce_one.scans.config.list(ConfigListParams**kwargs) -> SyncSinglePage[ConfigListResponse]
GET/accounts/{account_id}/cloudforce-one/scans/config
Create a new Scan Config
cloudforce_one.scans.config.create(ConfigCreateParams**kwargs) -> ConfigCreateResponse
POST/accounts/{account_id}/cloudforce-one/scans/config
Update an existing Scan Config
cloudforce_one.scans.config.edit(strconfig_id, ConfigEditParams**kwargs) -> ConfigEditResponse
PATCH/accounts/{account_id}/cloudforce-one/scans/config/{config_id}
Delete a Scan Config
cloudforce_one.scans.config.delete(strconfig_id, ConfigDeleteParams**kwargs) -> object
DELETE/accounts/{account_id}/cloudforce-one/scans/config/{config_id}
ModelsExpand Collapse
class ConfigListResponse: …
id: str

Defines the Config ID.

account_id: str
frequency: float

Defines the number of days between each scan (0 = One-off scan).

ips: List[str]

Defines a list of IP addresses or CIDR blocks to scan. The maximum number of total IP addresses allowed is 5000.

ports: List[str]

Defines a list of ports to scan. Valid values are:“default”, “all”, or a comma-separated list of ports or range of ports (e.g. [“1-80”, “443”]). “default” scans the 100 most commonly open ports.

class ConfigCreateResponse: …
id: str

Defines the Config ID.

account_id: str
frequency: float

Defines the number of days between each scan (0 = One-off scan).

ips: List[str]

Defines a list of IP addresses or CIDR blocks to scan. The maximum number of total IP addresses allowed is 5000.

ports: List[str]

Defines a list of ports to scan. Valid values are:“default”, “all”, or a comma-separated list of ports or range of ports (e.g. [“1-80”, “443”]). “default” scans the 100 most commonly open ports.

class ConfigEditResponse: …
id: str

Defines the Config ID.

account_id: str
frequency: float

Defines the number of days between each scan (0 = One-off scan).

ips: List[str]

Defines a list of IP addresses or CIDR blocks to scan. The maximum number of total IP addresses allowed is 5000.

ports: List[str]

Defines a list of ports to scan. Valid values are:“default”, “all”, or a comma-separated list of ports or range of ports (e.g. [“1-80”, “443”]). “default” scans the 100 most commonly open ports.

Cloudforce OneThreat Events

Filter and list events
cloudforce_one.threat_events.list(ThreatEventListParams**kwargs) -> ThreatEventListResponse
GET/accounts/{account_id}/cloudforce-one/events
Reads an event
Deprecated
cloudforce_one.threat_events.get(strevent_id, ThreatEventGetParams**kwargs) -> ThreatEventGetResponse
GET/accounts/{account_id}/cloudforce-one/events/{event_id}
Creates a new event
cloudforce_one.threat_events.create(ThreatEventCreateParams**kwargs) -> ThreatEventCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/create
Updates an event
cloudforce_one.threat_events.edit(strevent_id, ThreatEventEditParams**kwargs) -> ThreatEventEditResponse
PATCH/accounts/{account_id}/cloudforce-one/events/{event_id}
Creates bulk events
cloudforce_one.threat_events.bulk_create(ThreatEventBulkCreateParams**kwargs) -> ThreatEventBulkCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/create/bulk
Creates bulk DOS event with relationships and indicators
Deprecated
cloudforce_one.threat_events.bulk_create_relationships(ThreatEventBulkCreateRelationshipsParams**kwargs) -> ThreatEventBulkCreateRelationshipsResponse
POST/accounts/{account_id}/cloudforce-one/events/create/bulk/relationships
ModelsExpand Collapse
List[ThreatEventListResponseItem]
attacker: str
attacker_country: str
attacker_country_alpha3: str
category: str
dataset_id: str
date: str
event: str
has_children: bool
indicator: str
indicator_type: str
indicator_type_id: float
kill_chain: float
mitre_attack: List[str]
mitre_capec: List[str]
num_referenced: float
num_references: float
raw_id: str
referenced: List[str]
referenced_ids: List[float]
references: List[str]
references_ids: List[float]
tags: List[str]
target_country: str
target_country_alpha3: str
target_industry: str
tlp: str
uuid: str
insight: Optional[str]
releasability_id: Optional[str]
class ThreatEventGetResponse: …
attacker: str
attacker_country: str
attacker_country_alpha3: str
category: str
dataset_id: str
date: str
event: str
has_children: bool
indicator: str
indicator_type: str
indicator_type_id: float
kill_chain: float
mitre_attack: List[str]
mitre_capec: List[str]
num_referenced: float
num_references: float
raw_id: str
referenced: List[str]
referenced_ids: List[float]
references: List[str]
references_ids: List[float]
tags: List[str]
target_country: str
target_country_alpha3: str
target_industry: str
tlp: str
uuid: str
insight: Optional[str]
releasability_id: Optional[str]
class ThreatEventCreateResponse: …
attacker: str
attacker_country: str
attacker_country_alpha3: str
category: str
dataset_id: str
date: str
event: str
has_children: bool
indicator: str
indicator_type: str
indicator_type_id: float
kill_chain: float
mitre_attack: List[str]
mitre_capec: List[str]
num_referenced: float
num_references: float
raw_id: str
referenced: List[str]
referenced_ids: List[float]
references: List[str]
references_ids: List[float]
tags: List[str]
target_country: str
target_country_alpha3: str
target_industry: str
tlp: str
uuid: str
insight: Optional[str]
releasability_id: Optional[str]
class ThreatEventEditResponse: …
attacker: str
attacker_country: str
attacker_country_alpha3: str
category: str
dataset_id: str
date: str
event: str
has_children: bool
indicator: str
indicator_type: str
indicator_type_id: float
kill_chain: float
mitre_attack: List[str]
mitre_capec: List[str]
num_referenced: float
num_references: float
raw_id: str
referenced: List[str]
referenced_ids: List[float]
references: List[str]
references_ids: List[float]
tags: List[str]
target_country: str
target_country_alpha3: str
target_industry: str
tlp: str
uuid: str
insight: Optional[str]
releasability_id: Optional[str]
class ThreatEventBulkCreateResponse: …

Detailed result of bulk event creation with auto-tag management

created_events_count: float

Number of events created

created_tags_count: float

Number of new tags created in SoT

error_count: float

Number of errors encountered

queued_indicators_count: float

Number of indicators queued for async processing

create_bulk_events_request_id: Optional[str]

Correlation ID for async indicator processing

formatuuid
created_events: Optional[List[CreatedEvent]]

Array of created events with UUIDs and shard locations. Only present when includeCreatedEvents=true

event_index: float

Original index in the input data array

shard_id: str

Dataset ID of the shard where the event was created

uuid: str

UUID of the created event

formatuuid
errors: Optional[List[Error]]

Array of error details

error: str

Error message

event_index: float

Index of the event that caused the error

class ThreatEventBulkCreateRelationshipsResponse: …

Result of bulk relationship creation operation

created_events_count: float

Number of events created

created_indicators_count: float

Number of indicators created

created_relationships_count: float

Number of relationships created

error_count: float

Number of errors encountered

errors: Optional[List[Error]]

Array of error details

error: str

Error message

event_index: float

Index of the event that caused the error

Cloudforce OneThreat EventsAggregate

Aggregate events by single or multiple columns with optional date filtering
cloudforce_one.threat_events.aggregate.list(AggregateListParams**kwargs) -> AggregateListResponse
GET/accounts/{account_id}/cloudforce-one/events/aggregate
ModelsExpand Collapse
class AggregateListResponse: …
aggregate_by: str

Column(s) that were aggregated by

aggregations: List[Aggregation]

Array of aggregation results with dynamic fields based on aggregateBy columns

count: float

Number of events for this aggregation

date: Optional[str]

Date (if groupByDate is true)

total: float

Total number of events in the aggregation

date_range: Optional[DateRange]

Date range used for filtering

end_date: Optional[str]
start_date: Optional[str]

Cloudforce OneThreat EventsGraphql

GraphQL endpoint for event aggregation
cloudforce_one.threat_events.graphql.create(GraphqlCreateParams**kwargs) -> GraphqlCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/graphql
ModelsExpand Collapse
class GraphqlCreateResponse: …
data: Optional[object]
errors: Optional[List[object]]

Cloudforce OneThreat EventsGraph

Query graph neighborhood from R2 Data Catalog
cloudforce_one.threat_events.graph.list(GraphListParams**kwargs) -> GraphListResponse
GET/accounts/{account_id}/cloudforce-one/events/graph
ModelsExpand Collapse
class GraphListResponse: …
edges: List[Edge]
id: str

Deterministic composite edge id (source→target:relationshipType)

relationship_type: str
source: str

Compact id of the source node (type:uuid)

source_id: str
source_type: str
target: str

Compact id of the target node (type:uuid)

target_id: str
target_type: str
node: Optional[Dict[str, object]]

Focal node object (legacy single-seed). Null when unavailable.

nodes: List[Dict[str, object]]

Cloudforce OneThreat EventsQueries

List all saved event queries
cloudforce_one.threat_events.queries.list(QueryListParams**kwargs) -> QueryListResponse
GET/accounts/{account_id}/cloudforce-one/events/queries
Create a saved event query
cloudforce_one.threat_events.queries.create(QueryCreateParams**kwargs) -> QueryCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/queries/create
Read a saved event query
cloudforce_one.threat_events.queries.get(intquery_id, QueryGetParams**kwargs) -> QueryGetResponse
GET/accounts/{account_id}/cloudforce-one/events/queries/{query_id}
Update a saved event query
cloudforce_one.threat_events.queries.edit(intquery_id, QueryEditParams**kwargs) -> QueryEditResponse
PATCH/accounts/{account_id}/cloudforce-one/events/queries/{query_id}
Delete a saved event query
cloudforce_one.threat_events.queries.delete(intquery_id, QueryDeleteParams**kwargs)
DELETE/accounts/{account_id}/cloudforce-one/events/queries/{query_id}
ModelsExpand Collapse
List[QueryListResponseItem]
id: int

Unique identifier for the saved query

account_id: int

Account ID

alert_enabled: bool

Whether alerts are enabled

alert_rollup_enabled: bool

Whether alert rollup is enabled

created_at: str

Creation timestamp

name: str

Name of the saved query

query_json: str

JSON string containing the query parameters

rule_enabled: bool

Whether rule is enabled

updated_at: str

Last update timestamp

user_email: str

Email of the user who created the query

custom_threat_feed_id: Optional[int]

Intel Indicator Feed ID (numeric)

rule_list_id: Optional[str]

WAF rules list ID for blocking

rule_scope: Optional[str]

Scope for the rule

class QueryCreateResponse: …
id: int

Unique identifier for the saved query

account_id: int

Account ID

alert_enabled: bool

Whether alerts are enabled

alert_rollup_enabled: bool

Whether alert rollup is enabled

created_at: str

Creation timestamp

name: str

Name of the saved query

query_json: str

JSON string containing the query parameters

rule_enabled: bool

Whether rule is enabled

updated_at: str

Last update timestamp

user_email: str

Email of the user who created the query

custom_threat_feed_id: Optional[int]

Intel Indicator Feed ID (numeric)

rule_list_id: Optional[str]

WAF rules list ID for blocking

rule_scope: Optional[str]

Scope for the rule

class QueryGetResponse: …
id: int

Unique identifier for the saved query

account_id: int

Account ID

alert_enabled: bool

Whether alerts are enabled

alert_rollup_enabled: bool

Whether alert rollup is enabled

created_at: str

Creation timestamp

name: str

Name of the saved query

query_json: str

JSON string containing the query parameters

rule_enabled: bool

Whether rule is enabled

updated_at: str

Last update timestamp

user_email: str

Email of the user who created the query

custom_threat_feed_id: Optional[int]

Intel Indicator Feed ID (numeric)

rule_list_id: Optional[str]

WAF rules list ID for blocking

rule_scope: Optional[str]

Scope for the rule

class QueryEditResponse: …
id: int

Unique identifier for the saved query

account_id: int

Account ID

alert_enabled: bool

Whether alerts are enabled

alert_rollup_enabled: bool

Whether alert rollup is enabled

created_at: str

Creation timestamp

name: str

Name of the saved query

query_json: str

JSON string containing the query parameters

rule_enabled: bool

Whether rule is enabled

updated_at: str

Last update timestamp

user_email: str

Email of the user who created the query

custom_threat_feed_id: Optional[int]

Intel Indicator Feed ID (numeric)

rule_list_id: Optional[str]

WAF rules list ID for blocking

rule_scope: Optional[str]

Scope for the rule

Cloudforce OneThreat EventsRelationships

Filter and list events related to specific event
Deprecated
cloudforce_one.threat_events.relationships.list(strevent_id, RelationshipListParams**kwargs) -> RelationshipListResponse
GET/accounts/{account_id}/cloudforce-one/events/{event_id}/relationships
ModelsExpand Collapse
List[RelationshipListResponseItem]
attacker: str
attacker_country: str
attacker_country_alpha3: str
category: str
dataset_id: str
date: str
event: str
has_children: bool
indicator: str
indicator_type: str
indicator_type_id: float
kill_chain: float
mitre_attack: List[str]
mitre_capec: List[str]
num_referenced: float
num_references: float
raw_id: str
referenced: List[str]
referenced_ids: List[float]
references: List[str]
references_ids: List[float]
tags: List[str]
target_country: str
target_country_alpha3: str
target_industry: str
tlp: str
uuid: str
insight: Optional[str]
releasability_id: Optional[str]

Cloudforce OneThreat EventsIndicators

Lists indicators across multiple datasets
cloudforce_one.threat_events.indicators.list(IndicatorListParams**kwargs) -> IndicatorListResponse
GET/accounts/{account_id}/cloudforce-one/events/indicators
ModelsExpand Collapse
class IndicatorListResponse: …
properties: Properties
completeness: PropertiesCompleteness
properties: PropertiesCompletenessProperties
complete: PropertiesCompletenessPropertiesComplete
type: str
failed_datasets: PropertiesCompletenessPropertiesFailedDatasets
items: PropertiesCompletenessPropertiesFailedDatasetsItems
type: str
type: str
failed_shards: PropertiesCompletenessPropertiesFailedShards
items: PropertiesCompletenessPropertiesFailedShardsItems
properties: PropertiesCompletenessPropertiesFailedShardsItemsProperties
dataset_id: PropertiesCompletenessPropertiesFailedShardsItemsPropertiesDatasetID
type: str
shard_id: PropertiesCompletenessPropertiesFailedShardsItemsPropertiesShardID
type: str
type: str
type: str
warnings: PropertiesCompletenessPropertiesWarnings
items: PropertiesCompletenessPropertiesWarningsItems
type: str
type: str
type: str
indicators: PropertiesIndicators
items: PropertiesIndicatorsItems
created_at: datetime
formatdate-time
indicator_type: str
sources: List[PropertiesIndicatorsItemsSource]

RSS article sources from which this indicator was extracted.

resource_id: str
formatuuid
resource_type: Literal["article"]
system: Literal["threat-signals"]
title: Optional[str]

Threat Signals article title; null for historical provenance without a stored title.

updated_at: datetime
formatdate-time
uuid: str
value: str
dataset_id: Optional[str]

The dataset ID this indicator belongs to. Included in list responses.

related_events: Optional[List[PropertiesIndicatorsItemsRelatedEvent]]

Related events, capped by relatedEventsLimit (default 2). Check relatedEventsHasMore to detect a capped list; pass relatedEventsLimit=-1 to retrieve all of them.

dataset_id: str
event_id: str
event_date: Optional[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

related_events_has_more: Optional[bool]

True when this indicator appears in more events than relatedEvents contains because relatedEventsLimit capped the list. Pass relatedEventsLimit=-1 to retrieve every related event.

tags: Optional[List[PropertiesIndicatorsItemsTag]]
category_id: Optional[str]

The UUID of the tag category, or null when the tag is uncategorized.

category_name: Optional[str]
uuid: Optional[str]
value: Optional[str]
tlp: Optional[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

type: str
type: str

Cloudforce OneThreat EventsIndicatorsAggregate

Aggregate indicators by column(s)
cloudforce_one.threat_events.indicators.aggregate.list(AggregateListParams**kwargs) -> AggregateListResponse
GET/accounts/{account_id}/cloudforce-one/events/indicators/aggregate
ModelsExpand Collapse
class AggregateListResponse: …
aggregate_by: str

Column(s) that were aggregated by

aggregations: List[Aggregation]

Array of aggregation results with dynamic fields based on aggregateBy columns

count: float

Number of indicators for this aggregation

failed_datasets: float

Number of datasets whose aggregation failed and were excluded from the result

total: float

Total count in the aggregation: indicator rows when measure=indicators, or linked-event rows when measure=relationships

Cloudforce OneThreat EventsIndicatorsTypes

Lists indicator types across multiple datasets
cloudforce_one.threat_events.indicators.types.list(TypeListParams**kwargs) -> TypeListResponse
GET/accounts/{account_id}/cloudforce-one/events/indicator-types
ModelsExpand Collapse
class TypeListResponse: …
items: Items
type: str
type: str

Cloudforce OneThreat EventsIndicatorsBy Dataset

Lists indicators
Deprecated
cloudforce_one.threat_events.indicators.by_dataset.list(strdataset_id, ByDatasetListParams**kwargs) -> ByDatasetListResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/indicators
Reads an indicator
cloudforce_one.threat_events.indicators.by_dataset.get(strindicator_id, ByDatasetGetParams**kwargs) -> ByDatasetGetResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/indicators/{indicator_id}
ModelsExpand Collapse
class ByDatasetListResponse: …
indicators: List[Indicator]
created_at: datetime
formatdate-time
indicator_type: str
sources: List[IndicatorSource]

RSS article sources from which this indicator was extracted.

resource_id: str
formatuuid
resource_type: Literal["article"]
system: Literal["threat-signals"]
title: Optional[str]

Threat Signals article title; null for historical provenance without a stored title.

updated_at: datetime
formatdate-time
uuid: str
value: str
dataset_id: Optional[str]

The dataset ID this indicator belongs to. Included in list responses.

related_events: Optional[List[IndicatorRelatedEvent]]

Related events, capped by relatedEventsLimit (default 2). Check relatedEventsHasMore to detect a capped list; pass relatedEventsLimit=-1 to retrieve all of them.

dataset_id: str
event_id: str
event_date: Optional[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

related_events_has_more: Optional[bool]

True when this indicator appears in more events than relatedEvents contains because relatedEventsLimit capped the list. Pass relatedEventsLimit=-1 to retrieve every related event.

tags: Optional[List[IndicatorTag]]
category_id: Optional[str]

The UUID of the tag category, or null when the tag is uncategorized.

category_name: Optional[str]
uuid: Optional[str]
value: Optional[str]
tlp: Optional[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

class ByDatasetGetResponse: …
created_at: datetime
formatdate-time
indicator_type: str
updated_at: datetime
formatdate-time
uuid: str
value: str
dataset_id: Optional[str]

The dataset ID this indicator belongs to. Included in list responses.

related_events: Optional[List[RelatedEvent]]

Related events, capped by relatedEventsLimit (default 2). Check relatedEventsHasMore to detect a capped list; pass relatedEventsLimit=-1 to retrieve all of them.

dataset_id: str
event_id: str
event_date: Optional[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

related_events_has_more: Optional[bool]

True when this indicator appears in more events than relatedEvents contains because relatedEventsLimit capped the list. Pass relatedEventsLimit=-1 to retrieve every related event.

tags: Optional[List[Tag]]
category_id: Optional[str]

The UUID of the tag category, or null when the tag is uncategorized.

category_name: Optional[str]
uuid: Optional[str]
value: Optional[str]
tlp: Optional[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

Cloudforce OneThreat EventsIndicatorsBy DatasetTags

List mirrored tags for an indicator dataset
cloudforce_one.threat_events.indicators.by_dataset.tags.list(strdataset_id, TagListParams**kwargs) -> TagListResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/indicators/tags
ModelsExpand Collapse
List[object]

Array of mirror tag rows

Cloudforce OneThreat EventsAttackers

Lists attackers across multiple datasets
cloudforce_one.threat_events.attackers.list(AttackerListParams**kwargs) -> AttackerListResponse
GET/accounts/{account_id}/cloudforce-one/events/attackers
ModelsExpand Collapse
class AttackerListResponse: …
items: Items
type: str
type: str

Cloudforce OneThreat EventsCategories

Lists categories across multiple datasets
cloudforce_one.threat_events.categories.list(CategoryListParams**kwargs) -> CategoryListResponse
GET/accounts/{account_id}/cloudforce-one/events/categories
Reads a category
Deprecated
cloudforce_one.threat_events.categories.get(strcategory_id, CategoryGetParams**kwargs) -> CategoryGetResponse
GET/accounts/{account_id}/cloudforce-one/events/categories/{category_id}
Creates a new category
cloudforce_one.threat_events.categories.create(CategoryCreateParams**kwargs) -> CategoryCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/categories/create
Updates a category
Deprecated
cloudforce_one.threat_events.categories.edit(strcategory_id, CategoryEditParams**kwargs) -> CategoryEditResponse
PATCH/accounts/{account_id}/cloudforce-one/events/categories/{category_id}
Deletes a category
Deprecated
cloudforce_one.threat_events.categories.delete(strcategory_id, CategoryDeleteParams**kwargs) -> CategoryDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/events/categories/{category_id}
ModelsExpand Collapse
List[CategoryListResponseItem]
kill_chain: float
name: str
uuid: str
mitre_attack: Optional[List[str]]
mitre_capec: Optional[List[str]]
shortname: Optional[str]
class CategoryGetResponse: …
kill_chain: float
name: str
uuid: str
mitre_attack: Optional[List[str]]
mitre_capec: Optional[List[str]]
shortname: Optional[str]
class CategoryCreateResponse: …
kill_chain: float
name: str
uuid: str
mitre_attack: Optional[List[str]]
mitre_capec: Optional[List[str]]
shortname: Optional[str]
class CategoryEditResponse: …
kill_chain: float
name: str
uuid: str
mitre_attack: Optional[List[str]]
mitre_capec: Optional[List[str]]
shortname: Optional[str]
class CategoryDeleteResponse: …
uuid: str

Cloudforce OneThreat EventsCategoriesCatalog

Lists categories
cloudforce_one.threat_events.categories.catalog.list(CatalogListParams**kwargs) -> CatalogListResponse
GET/accounts/{account_id}/cloudforce-one/events/categories/catalog
ModelsExpand Collapse
List[CatalogListResponseItem]
kill_chain: float
name: str
uuid: str
mitre_attack: Optional[List[str]]
mitre_capec: Optional[List[str]]
shortname: Optional[str]

Cloudforce OneThreat EventsCountries

Retrieves countries information for all countries
cloudforce_one.threat_events.countries.list(CountryListParams**kwargs) -> CountryListResponse
GET/accounts/{account_id}/cloudforce-one/events/countries
ModelsExpand Collapse
List[CountryListResponseItem]
result: List[CountryListResponseItemResult]
alpha2: str
alpha3: str
name: str
success: str

Cloudforce OneThreat EventsCrons

Cloudforce OneThreat EventsDatasets

Lists all datasets in an account
cloudforce_one.threat_events.datasets.list(DatasetListParams**kwargs) -> DatasetListResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset
Reads a dataset
cloudforce_one.threat_events.datasets.get(strdataset_id, DatasetGetParams**kwargs) -> DatasetGetResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}
Creates a dataset
cloudforce_one.threat_events.datasets.create(DatasetCreateParams**kwargs) -> DatasetCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/dataset/create
Updates an existing dataset
cloudforce_one.threat_events.datasets.edit(strdataset_id, DatasetEditParams**kwargs) -> DatasetEditResponse
PATCH/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}
Delete a dataset
cloudforce_one.threat_events.datasets.delete(strdataset_id, DatasetDeleteParams**kwargs) -> DatasetDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}
Reads raw data for an event by UUID
Deprecated
cloudforce_one.threat_events.datasets.raw(strevent_id, DatasetRawParams**kwargs) -> DatasetRawResponse
GET/accounts/{account_id}/cloudforce-one/events/raw/{dataset_id}/{event_id}
ModelsExpand Collapse
List[DatasetListResponseItem]
indicator_write_mode: Literal["read_only", "create_only", "full"]

Effective indicator mutation capability after account/dataset authorization and dataset storage capability are applied. API Gateway method permissions are separate and must also allow the requested operation.

One of the following:
"read_only"
"create_only"
"full"
is_analytics: bool
is_public: bool
name: str
uuid: str
deleted_at: Optional[str]
class DatasetGetResponse: …
is_analytics: bool
is_public: bool
name: str
uuid: str
class DatasetCreateResponse: …
is_analytics: bool
is_public: bool
name: str
uuid: str
class DatasetEditResponse: …
is_analytics: bool
is_public: bool
name: str
uuid: str
class DatasetDeleteResponse: …
name: str
uuid: str
class DatasetRawResponse: …
id: float
account_id: float
created: str
data: str
source: str
tlp: str

Cloudforce OneThreat EventsDatasetsHealth

Cloudforce OneThreat EventsDatasetsEvents

Reads an event
cloudforce_one.threat_events.datasets.events.get(strevent_id, EventGetParams**kwargs) -> EventGetResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/events/{event_id}
ModelsExpand Collapse
class EventGetResponse: …
attacker: str
attacker_country: str
attacker_country_alpha3: str
category: str
dataset_id: str
date: str
event: str
has_children: bool
indicator: str
indicator_type: str
indicator_type_id: float
kill_chain: float
mitre_attack: List[str]
mitre_capec: List[str]
num_referenced: float
num_references: float
raw_id: str
referenced: List[str]
referenced_ids: List[float]
references: List[str]
references_ids: List[float]
tags: List[str]
target_country: str
target_country_alpha3: str
target_industry: str
tlp: str
uuid: str
insight: Optional[str]
releasability_id: Optional[str]

Cloudforce OneThreat EventsRaw

Reads data for a raw event
cloudforce_one.threat_events.raw.get(strraw_id, RawGetParams**kwargs) -> RawGetResponse
GET/accounts/{account_id}/cloudforce-one/events/{event_id}/raw/{raw_id}
Updates a raw event
cloudforce_one.threat_events.raw.edit(strraw_id, RawEditParams**kwargs) -> RawEditResponse
PATCH/accounts/{account_id}/cloudforce-one/events/{event_id}/raw/{raw_id}
ModelsExpand Collapse
class RawGetResponse: …
id: str
account_id: float
created: str
data: object
source: str
tlp: str
class RawEditResponse: …
id: str
data: object

Cloudforce OneThreat EventsRelate

Removes an event reference
cloudforce_one.threat_events.relate.delete(strevent_id, RelateDeleteParams**kwargs) -> RelateDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/events/relate/{event_id}
ModelsExpand Collapse
class RelateDeleteResponse: …
success: bool

Cloudforce OneThreat EventsTags

Lists all tags (SoT)
cloudforce_one.threat_events.tags.list(TagListParams**kwargs) -> TagListResponse
GET/accounts/{account_id}/cloudforce-one/events/tags
Creates a new tag
cloudforce_one.threat_events.tags.create(TagCreateParams**kwargs) -> TagCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/tags/create
Updates a tag (SoT)
cloudforce_one.threat_events.tags.edit(strtag_uuid, TagEditParams**kwargs) -> TagEditResponse
PATCH/accounts/{account_id}/cloudforce-one/events/tags/{tag_uuid}
Deletes a tag (SoT)
cloudforce_one.threat_events.tags.delete(strtag_uuid, TagDeleteParams**kwargs) -> TagDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/events/tags/{tag_uuid}
ModelsExpand Collapse
class TagListResponse: …
tags: List[Tag]
uuid: str
value: str
active_duration: Optional[str]
active_duration_annotated: Optional[TagActiveDurationAnnotated]
value: str
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
actor_category: Optional[str]
actor_category_annotated: Optional[TagActorCategoryAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
aliases: Optional[List[TagAlias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

value: str
confidence: Optional[int]
maximum10
minimum1
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
alias_group_names: Optional[List[str]]
alias_group_names_internal: Optional[List[str]]
attribution_organization: Optional[str]
attribution_organization_annotated: Optional[TagAttributionOrganizationAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
category_name: Optional[str]
category_uuid: Optional[str]
confidence: Optional[int]

Overall tag confidence (1-10).

maximum10
minimum1
created_at: Optional[str]
date_of_discovery: Optional[str]
description: Optional[str]
external_references: Optional[List[TagExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

url: str
description: Optional[str]
external_references_annotated: Optional[List[TagExternalReferencesAnnotated]]
value: str
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
internal_aliases: Optional[List[TagInternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

value: str
confidence: Optional[int]
maximum10
minimum1
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
internal_description: Optional[str]
last_seen: Optional[str]
motive: Optional[str]
motive_annotated: Optional[TagMotiveAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
opsec_level: Optional[str]
opsec_level_annotated: Optional[TagOpsecLevelAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
origin_country_iso: Optional[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

origin_country_iso_annotated: Optional[TagOriginCountryISOAnnotated]
value: Optional[str]
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
priority: Optional[float]
priority_annotated: Optional[TagPriorityAnnotated]
value: float
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
properties: Optional[Dict[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

sophistication_level: Optional[str]
sophistication_level_annotated: Optional[TagSophisticationLevelAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
updated_at: Optional[str]
version: Optional[float]
class TagCreateResponse: …
uuid: str
value: str
active_duration: Optional[str]
active_duration_annotated: Optional[ActiveDurationAnnotated]
value: str
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
actor_category: Optional[str]
actor_category_annotated: Optional[ActorCategoryAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
aliases: Optional[List[Alias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

value: str
confidence: Optional[int]
maximum10
minimum1
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
alias_group_names: Optional[List[str]]
alias_group_names_internal: Optional[List[str]]
attribution_organization: Optional[str]
attribution_organization_annotated: Optional[AttributionOrganizationAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
category_name: Optional[str]
category_uuid: Optional[str]
confidence: Optional[int]

Overall tag confidence (1-10).

maximum10
minimum1
created_at: Optional[str]
date_of_discovery: Optional[str]
description: Optional[str]
external_references: Optional[List[ExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

url: str
description: Optional[str]
external_references_annotated: Optional[List[ExternalReferencesAnnotated]]
value: str
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
internal_aliases: Optional[List[InternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

value: str
confidence: Optional[int]
maximum10
minimum1
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
internal_description: Optional[str]
last_seen: Optional[str]
motive: Optional[str]
motive_annotated: Optional[MotiveAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
opsec_level: Optional[str]
opsec_level_annotated: Optional[OpsecLevelAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
origin_country_iso: Optional[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

origin_country_iso_annotated: Optional[OriginCountryISOAnnotated]
value: Optional[str]
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
priority: Optional[float]
priority_annotated: Optional[PriorityAnnotated]
value: float
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
properties: Optional[Dict[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

sophistication_level: Optional[str]
sophistication_level_annotated: Optional[SophisticationLevelAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
updated_at: Optional[str]
version: Optional[float]
class TagEditResponse: …
uuid: str
value: str
active_duration: Optional[str]
active_duration_annotated: Optional[ActiveDurationAnnotated]
value: str
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
actor_category: Optional[str]
actor_category_annotated: Optional[ActorCategoryAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
aliases: Optional[List[Alias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

value: str
confidence: Optional[int]
maximum10
minimum1
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
alias_group_names: Optional[List[str]]
alias_group_names_internal: Optional[List[str]]
attribution_organization: Optional[str]
attribution_organization_annotated: Optional[AttributionOrganizationAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
category_name: Optional[str]
category_uuid: Optional[str]
confidence: Optional[int]

Overall tag confidence (1-10).

maximum10
minimum1
created_at: Optional[str]
date_of_discovery: Optional[str]
description: Optional[str]
external_references: Optional[List[ExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

url: str
description: Optional[str]
external_references_annotated: Optional[List[ExternalReferencesAnnotated]]
value: str
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
internal_aliases: Optional[List[InternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

value: str
confidence: Optional[int]
maximum10
minimum1
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
internal_description: Optional[str]
last_seen: Optional[str]
motive: Optional[str]
motive_annotated: Optional[MotiveAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
opsec_level: Optional[str]
opsec_level_annotated: Optional[OpsecLevelAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
origin_country_iso: Optional[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

origin_country_iso_annotated: Optional[OriginCountryISOAnnotated]
value: Optional[str]
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
priority: Optional[float]
priority_annotated: Optional[PriorityAnnotated]
value: float
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
properties: Optional[Dict[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

sophistication_level: Optional[str]
sophistication_level_annotated: Optional[SophisticationLevelAnnotated]
value: str
confidence: Optional[float]
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]
One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
tlp: Optional[Literal["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

One of the following:
"red"
"amber"
"amber-strict"
"green"
"clear"
"purple"
"amber+strict"
updated_at: Optional[str]
version: Optional[float]
class TagDeleteResponse: …
uuid: str

Cloudforce OneThreat EventsTagsCategories

Lists all tag categories (SoT)
cloudforce_one.threat_events.tags.categories.list(CategoryListParams**kwargs) -> CategoryListResponse
GET/accounts/{account_id}/cloudforce-one/events/tags/categories
Creates a new tag category (SoT)
cloudforce_one.threat_events.tags.categories.create(CategoryCreateParams**kwargs) -> CategoryCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/tags/categories/create
Updates a tag category (SoT)
Deprecated
cloudforce_one.threat_events.tags.categories.edit(strcategory_uuid, CategoryEditParams**kwargs) -> CategoryEditResponse
PATCH/accounts/{account_id}/cloudforce-one/events/tags/categories/{category_uuid}
Deletes a tag category (SoT)
Deprecated
cloudforce_one.threat_events.tags.categories.delete(strcategory_uuid, CategoryDeleteParams**kwargs) -> CategoryDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/events/tags/categories/{category_uuid}
ModelsExpand Collapse
class CategoryListResponse: …
categories: List[Category]
name: str
uuid: str
created_at: Optional[str]
description: Optional[str]
schema: Optional[List[CategorySchema]]

Parsed FieldDefinition[] defining custom fields for this category, or null if none.

key: str
kind: Literal["string", "number", "enum", 3 more]
One of the following:
"string"
"number"
"enum"
"date"
"array"
"object"
allowed_values: Optional[List[str]]
annotations: Optional[CategorySchemaAnnotations]
confidence: Optional[bool]
tlp: Optional[bool]
deprecated: Optional[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

deprecated_values: Optional[List[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

element: Optional[object]
enforcement: Optional[Literal["error", "warn", "off"]]
One of the following:
"error"
"warn"
"off"
format: Optional[Literal["date", "url", "duration", "country"]]
One of the following:
"date"
"url"
"duration"
"country"
label: Optional[str]
maxLength128
minLength1
max_length: Optional[int]
exclusiveMinimum
minimum0
number_constraint: Optional[CategorySchemaNumberConstraint]
integer: Optional[bool]
max: Optional[float]
min: Optional[float]
properties: Optional[Dict[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

required: Optional[bool]
updated_at: Optional[str]
class CategoryCreateResponse: …
name: str
uuid: str
created_at: Optional[str]
description: Optional[str]
schema: Optional[List[Schema]]

Parsed FieldDefinition[] defining custom fields for this category, or null if none.

key: str
kind: Literal["string", "number", "enum", 3 more]
One of the following:
"string"
"number"
"enum"
"date"
"array"
"object"
allowed_values: Optional[List[str]]
annotations: Optional[SchemaAnnotations]
confidence: Optional[bool]
tlp: Optional[bool]
deprecated: Optional[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

deprecated_values: Optional[List[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

element: Optional[object]
enforcement: Optional[Literal["error", "warn", "off"]]
One of the following:
"error"
"warn"
"off"
format: Optional[Literal["date", "url", "duration", "country"]]
One of the following:
"date"
"url"
"duration"
"country"
label: Optional[str]
maxLength128
minLength1
max_length: Optional[int]
exclusiveMinimum
minimum0
number_constraint: Optional[SchemaNumberConstraint]
integer: Optional[bool]
max: Optional[float]
min: Optional[float]
properties: Optional[Dict[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

required: Optional[bool]
updated_at: Optional[str]
class CategoryEditResponse: …
name: str
uuid: str
created_at: Optional[str]
description: Optional[str]
schema: Optional[List[Schema]]

Parsed FieldDefinition[] defining custom fields for this category, or null if none.

key: str
kind: Literal["string", "number", "enum", 3 more]
One of the following:
"string"
"number"
"enum"
"date"
"array"
"object"
allowed_values: Optional[List[str]]
annotations: Optional[SchemaAnnotations]
confidence: Optional[bool]
tlp: Optional[bool]
deprecated: Optional[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

deprecated_values: Optional[List[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

element: Optional[object]
enforcement: Optional[Literal["error", "warn", "off"]]
One of the following:
"error"
"warn"
"off"
format: Optional[Literal["date", "url", "duration", "country"]]
One of the following:
"date"
"url"
"duration"
"country"
label: Optional[str]
maxLength128
minLength1
max_length: Optional[int]
exclusiveMinimum
minimum0
number_constraint: Optional[SchemaNumberConstraint]
integer: Optional[bool]
max: Optional[float]
min: Optional[float]
properties: Optional[Dict[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

required: Optional[bool]
updated_at: Optional[str]
class CategoryDeleteResponse: …
uuid: str

Cloudforce OneThreat EventsTagsIndicators

List indicators related to a tag
cloudforce_one.threat_events.tags.indicators.list(strtag_uuid, IndicatorListParams**kwargs) -> IndicatorListResponse
GET/accounts/{account_id}/cloudforce-one/events/tags/{tag_uuid}/indicators
ModelsExpand Collapse
class IndicatorListResponse: …
indicators: List[Indicator]
created_at: datetime
formatdate-time
indicator_type: str
updated_at: datetime
formatdate-time
uuid: str
value: str
dataset_id: Optional[str]

The dataset ID this indicator belongs to. Included in list responses.

related_events: Optional[List[IndicatorRelatedEvent]]

Related events, capped by relatedEventsLimit (default 2). Check relatedEventsHasMore to detect a capped list; pass relatedEventsLimit=-1 to retrieve all of them.

dataset_id: str
event_id: str
event_date: Optional[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

related_events_has_more: Optional[bool]

True when this indicator appears in more events than relatedEvents contains because relatedEventsLimit capped the list. Pass relatedEventsLimit=-1 to retrieve every related event.

tags: Optional[List[IndicatorTag]]
category_id: Optional[str]

The UUID of the tag category, or null when the tag is uncategorized.

category_name: Optional[str]
uuid: Optional[str]
value: Optional[str]
tlp: Optional[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

Cloudforce OneThreat EventsTagsIndicatorsBy Dataset

List indicators related to a tag within a dataset (deprecated)
Deprecated
cloudforce_one.threat_events.tags.indicators.by_dataset.list(strtag_uuid, ByDatasetListParams**kwargs) -> ByDatasetListResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/tags/{tag_uuid}/indicators
ModelsExpand Collapse
class ByDatasetListResponse: …
indicators: List[Indicator]
created_at: datetime
formatdate-time
indicator_type: str
updated_at: datetime
formatdate-time
uuid: str
value: str
dataset_id: Optional[str]

The dataset ID this indicator belongs to. Included in list responses.

related_events: Optional[List[IndicatorRelatedEvent]]

Related events, capped by relatedEventsLimit (default 2). Check relatedEventsHasMore to detect a capped list; pass relatedEventsLimit=-1 to retrieve all of them.

dataset_id: str
event_id: str
event_date: Optional[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

related_events_has_more: Optional[bool]

True when this indicator appears in more events than relatedEvents contains because relatedEventsLimit capped the list. Pass relatedEventsLimit=-1 to retrieve every related event.

tags: Optional[List[IndicatorTag]]
category_id: Optional[str]

The UUID of the tag category, or null when the tag is uncategorized.

category_name: Optional[str]
uuid: Optional[str]
value: Optional[str]
tlp: Optional[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

Cloudforce OneThreat EventsEvent Tags

Adds a tag to an event
cloudforce_one.threat_events.event_tags.create(strevent_id, EventTagCreateParams**kwargs) -> EventTagCreateResponse
POST/accounts/{account_id}/cloudforce-one/events/event_tag/{event_id}/create
Removes a tag from an event
cloudforce_one.threat_events.event_tags.delete(strevent_id, EventTagDeleteParams**kwargs) -> EventTagDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/events/event_tag/{event_id}
ModelsExpand Collapse
class EventTagCreateResponse: …
success: bool
class EventTagDeleteResponse: …
success: bool

Cloudforce OneThreat EventsTarget Industries

Lists target industries across multiple datasets
cloudforce_one.threat_events.target_industries.list(TargetIndustryListParams**kwargs) -> TargetIndustryListResponse
GET/accounts/{account_id}/cloudforce-one/events/targetIndustries
ModelsExpand Collapse
class TargetIndustryListResponse: …
items: Items
type: str
type: str

Cloudforce OneThreat EventsTarget IndustriesBy Dataset

Lists all target industries for a specific dataset
cloudforce_one.threat_events.target_industries.by_dataset.list(strdataset_id, ByDatasetListParams**kwargs) -> ByDatasetListResponse
GET/accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/targetIndustries
ModelsExpand Collapse
class ByDatasetListResponse: …
items: Items
type: str
type: str

Cloudforce OneThreat EventsTarget IndustriesCatalog

Lists all target industries from industry map catalog
cloudforce_one.threat_events.target_industries.catalog.list(CatalogListParams**kwargs) -> CatalogListResponse
GET/accounts/{account_id}/cloudforce-one/events/targetIndustries/catalog
ModelsExpand Collapse
class CatalogListResponse: …
items: Items
type: str
type: str

Cloudforce OneThreat EventsInsights

Cloudforce OneThreat Signals

Threat Signals API for managing threat intelligence feeds, articles, indicators, and AI skills in Cloudforce One.

Prerequisites

  1. API token — requests must use an API token with Cloudforce One permissions; write operations (creating, editing, or deleting feeds, skills, and tags) require write access.
  2. Plan limits — access on the Free plan is limited; feed quotas and managed default skills apply.

Cloudforce OneThreat SignalsSearch

Search Threat Signals articles using AI Search
cloudforce_one.threat_signals.search.search(SearchSearchParams**kwargs) -> SearchSearchResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/search
ModelsExpand Collapse
class SearchSearchResponse: …
count: int

Number of unique article candidates returned in this response. Equal to results.length.

minimum0
results: List[Result]
article_id: str
formatuuid
dataset_id: Optional[str]
formatuuid
event_id: Optional[str]
formatuuid
feed_id: str
formatuuid
score: float
text: str

Cloudforce OneThreat SignalsCategories

List Threat Signals feed categories
cloudforce_one.threat_signals.categories.list(CategoryListParams**kwargs) -> CategoryListResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/categories
ModelsExpand Collapse
class CategoryListResponse: …
categories: List[Category]
id: str

Wire value accepted by the feed category_id field.

formatuuid
description: str

Plain-language description of the category.

name: str

Human-readable display label.

Cloudforce OneThreat SignalsFeeds

List Threat Signals feeds
cloudforce_one.threat_signals.feeds.list(FeedListParams**kwargs) -> SyncV4PagePagination[FeedListResponse]
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Create Threat Signals feed
cloudforce_one.threat_signals.feeds.create(FeedCreateParams**kwargs) -> FeedCreateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Update Threat Signals feed
cloudforce_one.threat_signals.feeds.edit(strfeed_id, FeedEditParams**kwargs) -> FeedEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Delete Threat Signals feed
cloudforce_one.threat_signals.feeds.delete(strfeed_id, FeedDeleteParams**kwargs) -> FeedDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Trigger Threat Signals feed poll
cloudforce_one.threat_signals.feeds.poll(FeedPollParams**kwargs) -> FeedPollResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/poll
ModelsExpand Collapse
class FeedListResponse: …
count: int

Number of feeds on this page.

feeds: List[Feed]
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
page: int
per_page: int
total_count: int
class FeedCreateResponse: …
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
class FeedEditResponse: …
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
class FeedDeleteResponse: …
id: str
formatuuid
category_id: Optional[str]

Feed category identifier. Null when unset.

category_name: Optional[str]

Display name of the feed category. Null when unset or unresolvable.

created_at: str
curated_feed_id: Optional[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: Optional[str]
enabled: bool
last_polled_at: Optional[str]
poll_interval_s: int
source_type: str

custom for a feed added by URL, curated for a curated catalog feed.

status: str

Polling health: active, or error after a failed poll.

subscribed_at: Optional[str]
title: Optional[str]
updated_at: str
url: str
class FeedPollResponse: …
errors: float
feeds: List[Feed]
feed_id: str
formatuuid
status: Literal["workflow_created", "error"]
One of the following:
"workflow_created"
"error"
workflow_id: str
feed_enabled: Optional[bool]
triggered: float

Cloudforce OneThreat SignalsFeedsRaw

Get Threat Signals feed XML
cloudforce_one.threat_signals.feeds.raw.get(strfeed_id, RawGetParams**kwargs) -> RawGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/raw
ModelsExpand Collapse
str

Cloudforce OneThreat SignalsFeedsSkills

Get Threat Signals feed skills
cloudforce_one.threat_signals.feeds.skills.get(strfeed_id, SkillGetParams**kwargs) -> SkillGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills
Set Threat Signals feed skills
cloudforce_one.threat_signals.feeds.skills.update(strfeed_id, SkillUpdateParams**kwargs) -> SkillUpdateResponse
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills
ModelsExpand Collapse
class SkillGetResponse: …
feed_id: str
formatuuid
skills: List[Skill]
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillUpdateResponse: …
feed_id: str
formatuuid
skills: List[Skill]
position: int

Zero-based pipeline position.

skill_id: str

Cloudforce OneThreat SignalsArticles

List Threat Signals articles
cloudforce_one.threat_signals.articles.list(ArticleListParams**kwargs) -> ArticleListResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Bulk update Threat Signals article read status
cloudforce_one.threat_signals.articles.bulk_edit(ArticleBulkEditParams**kwargs) -> ArticleBulkEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Get Threat Signals article
cloudforce_one.threat_signals.articles.get(strarticle_id, ArticleGetParams**kwargs) -> ArticleGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
Update Threat Signals article read status
cloudforce_one.threat_signals.articles.edit(strarticle_id, ArticleEditParams**kwargs) -> ArticleEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
ModelsExpand Collapse
class ArticleListResponse: …
articles: List[Article]
id: str
formatuuid
dataset_id: Optional[str]

Threat Events dataset identifier for the article redirect. Null when the account feeds dataset mapping is unavailable.

event_id: Optional[str]

Threat Events event identifier associated with this article for a UI redirect. Null when no event has been linked.

feed_display_name: Optional[str]
feed_id: str
formatuuid
fetched_at: str
link: Optional[str]
published_at: Optional[str]
read: bool
read_at: Optional[str]
summary: Optional[str]

Persisted enrichment summary. Null until enrichment produces a summary.

tags: List[ArticleTag]
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
title: Optional[str]
has_more: bool
next_cursor: Optional[str]
total_count: Optional[float]
total_count_is_exact: bool
class ArticleBulkEditResponse: …
updated_count: float
class ArticleGetResponse: …
id: str
formatuuid
bullet_points: Optional[BulletPoints]
impact: str
what_happened: str
who_affected: str
content_r2_key: Optional[str]
feed_display_name: Optional[str]
feed_id: str
formatuuid
fetched_at: str
indicator_extraction_status: Literal["in_progress", "complete", "failed", "unknown"]

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

One of the following:
"in_progress"
"complete"
"failed"
"unknown"
link: Optional[str]
metadata: Optional[Dict[str, object]]
published_at: Optional[str]
read: bool
read_at: Optional[str]
source_count: float
summary: Optional[str]

Persisted enrichment summary. Null until enrichment produces a summary.

summary_r2_key: Optional[str]
tags: List[Tag]
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
title: Optional[str]
skill_version: Optional[str]
tag_skill_version: Optional[str]
class ArticleEditResponse: …
id: str
formatuuid
bullet_points: Optional[BulletPoints]
impact: str
what_happened: str
who_affected: str
content_r2_key: Optional[str]
feed_display_name: Optional[str]
feed_id: str
formatuuid
fetched_at: str
indicator_extraction_status: Literal["in_progress", "complete", "failed", "unknown"]

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

One of the following:
"in_progress"
"complete"
"failed"
"unknown"
link: Optional[str]
metadata: Optional[Dict[str, object]]
published_at: Optional[str]
read: bool
read_at: Optional[str]
source_count: float
summary: Optional[str]

Persisted enrichment summary. Null until enrichment produces a summary.

summary_r2_key: Optional[str]
tags: List[Tag]
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
title: Optional[str]
skill_version: Optional[str]
tag_skill_version: Optional[str]

Cloudforce OneThreat SignalsArticlesContent

Get Threat Signals article content
cloudforce_one.threat_signals.articles.content.get(strarticle_id, ContentGetParams**kwargs) -> ContentGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/content
ModelsExpand Collapse
str

Cloudforce OneThreat SignalsArticlesTags

Add tag to Threat Signals article
cloudforce_one.threat_signals.articles.tags.create(strarticle_id, TagCreateParams**kwargs) -> TagCreateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags
Remove tag from Threat Signals article
cloudforce_one.threat_signals.articles.tags.delete(strtag_id, TagDeleteParams**kwargs) -> TagDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags/{tag_id}
Generate Threat Signals article AI tags
cloudforce_one.threat_signals.articles.tags.generate(strarticle_id, TagGenerateParams**kwargs) -> TagGenerateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tag
ModelsExpand Collapse
class TagCreateResponse: …
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
class TagDeleteResponse: …
applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str
class TagGenerateResponse: …
tag_skill_version: str
tags: List[Tag]

Final hydrated assignment set; may be empty when no applicable tags are selected.

applied_by: Literal["ai", "analyst", "system"]
One of the following:
"ai"
"analyst"
"system"
category_id: Optional[str]
formatuuid
uuid: str
formatuuid
value: str

Cloudforce OneThreat SignalsArticlesSkill Outputs

Get Threat Signals article skill output
cloudforce_one.threat_signals.articles.skill_outputs.get(strskill_id, SkillOutputGetParams**kwargs) -> SkillOutputGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/skills/{skill_id}/output
ModelsExpand Collapse
class SkillOutputGetResponse: …
article_id: str
formatuuid
custom_skill_version: Optional[str]
output_schema: Optional[str]

JSON-encoded output schema of the skill. Null when the skill no longer exists.

skill_id: str
custom_output: Optional[object]

Skill output. Parsed JSON when the stored output is valid JSON, otherwise the raw string.

Cloudforce OneThreat SignalsIndicators

List Threat Signals article indicators
cloudforce_one.threat_signals.indicators.list(IndicatorListParams**kwargs) -> IndicatorListResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/indicators
ModelsExpand Collapse
class IndicatorListResponse: …
indicators: List[Indicator]
id: str
formatuuid
article_id: str
formatuuid
article_title: Optional[str]
dataset_id: Optional[str]

Threat Events dataset identifier for navigating from this indicator. Null when the account feeds dataset mapping is unavailable.

feed_display_name: Optional[str]
feed_id: str
formatuuid
type: str
value: str

Cloudforce OneThreat SignalsSkills

List Threat Signals skills
cloudforce_one.threat_signals.skills.list(SkillListParams**kwargs) -> SyncV4PagePagination[SkillListResponse]
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Create Threat Signals skill
cloudforce_one.threat_signals.skills.create(SkillCreateParams**kwargs) -> SkillCreateResponse
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Get Threat Signals skill
cloudforce_one.threat_signals.skills.get(strskill_id, SkillGetParams**kwargs) -> SkillGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Update Threat Signals skill
cloudforce_one.threat_signals.skills.edit(strskill_id, SkillEditParams**kwargs) -> SkillEditResponse
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Delete Threat Signals skill
cloudforce_one.threat_signals.skills.delete(strskill_id, SkillDeleteParams**kwargs) -> SkillDeleteResponse
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
ModelsExpand Collapse
class SkillListResponse: …
count: int

Number of skills on this page.

custom_skills_available: bool

Whether the authenticated account may access custom-skill capabilities under Stakeout’s Threat Signals access-mode policy. This is a policy availability indicator, not a row-existence indicator. False for threat_signals_only mode; true for entitled, allowlisted, cfone_internal, and service modes.

page: int
per_page: int
skills: List[Skill]
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
total_count: int
class SkillCreateResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillGetResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillEditResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str
class SkillDeleteResponse: …
id: str
config: Optional[str]

JSON-encoded skill configuration. Always null for default skills.

created_at: str
is_active: int

1 when active, 0 when inactive.

name: str
output_schema: Optional[str]

JSON-encoded JSON Schema the skill output must satisfy.

prompt: str
source: Literal["default", "custom"]

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: str
updated_at: str

Cloudforce OneThreat SignalsSkillsTag Categories

Get Threat Signals skill tag categories
cloudforce_one.threat_signals.skills.tag_categories.get(Literal["default-tagging-skill"]skill_id, TagCategoryGetParams**kwargs) -> TagCategoryGetResponse
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
Replace Threat Signals skill tag categories
cloudforce_one.threat_signals.skills.tag_categories.update(Literal["default-tagging-skill"]skill_id, TagCategoryUpdateParams**kwargs) -> TagCategoryUpdateResponse
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
ModelsExpand Collapse
class TagCategoryGetResponse: …
category_uuids: List[str]
skill_id: Literal["default-tagging-skill"]
class TagCategoryUpdateResponse: …
category_uuids: List[str]
skill_id: Literal["default-tagging-skill"]