Skip to content
Start here

Threat Signals

Threat Signals API for managing threat intelligence feeds, articles, indicators, and AI skills in Cloudforce One.

Prerequisites

  1. API token — requests must use an API token with Cloudforce One permissions; write operations (creating, editing, or deleting feeds, skills, and tags) require write access.
  2. Plan limits — access on the Free plan is limited; feed quotas and managed default skills apply.

Threat SignalsSearch

Search Threat Signals articles using AI Search
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/search
ModelsExpand Collapse
SearchSearchResponse object { count, results }
count: number

Number of unique article candidates returned in this response. Equal to results.length.

minimum0
results: array of object { article_id, dataset_id, event_id, 3 more }
article_id: string
formatuuid
dataset_id: string
formatuuid
event_id: string
formatuuid
feed_id: string
formatuuid
score: number
text: string

Threat SignalsCategories

List Threat Signals feed categories
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/categories
ModelsExpand Collapse
CategoryListResponse object { categories }
categories: array of object { id, description, name }
id: string

Wire value accepted by the feed category_id field.

formatuuid
description: string

Plain-language description of the category.

name: string

Human-readable display label.

Threat SignalsFeeds

List Threat Signals feeds
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Create Threat Signals feed
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds
Update Threat Signals feed
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Delete Threat Signals feed
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}
Trigger Threat Signals feed poll
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/poll
ModelsExpand Collapse
FeedListResponse object { count, feeds, page, 2 more }
count: number

Number of feeds on this page.

feeds: array of object { id, category_id, category_name, 12 more }
id: string
formatuuid
category_id: string

Feed category identifier. Null when unset.

category_name: string

Display name of the feed category. Null when unset or unresolvable.

created_at: string
curated_feed_id: string

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: string
enabled: boolean
last_polled_at: string
poll_interval_s: number
source_type: string

custom for a feed added by URL, curated for a curated catalog feed.

status: string

Polling health: active, or error after a failed poll.

subscribed_at: string
title: string
updated_at: string
url: string
page: number
per_page: number
total_count: number
FeedCreateResponse object { id, category_id, category_name, 12 more }
id: string
formatuuid
category_id: string

Feed category identifier. Null when unset.

category_name: string

Display name of the feed category. Null when unset or unresolvable.

created_at: string
curated_feed_id: string

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: string
enabled: boolean
last_polled_at: string
poll_interval_s: number
source_type: string

custom for a feed added by URL, curated for a curated catalog feed.

status: string

Polling health: active, or error after a failed poll.

subscribed_at: string
title: string
updated_at: string
url: string
FeedEditResponse object { id, category_id, category_name, 12 more }
id: string
formatuuid
category_id: string

Feed category identifier. Null when unset.

category_name: string

Display name of the feed category. Null when unset or unresolvable.

created_at: string
curated_feed_id: string

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: string
enabled: boolean
last_polled_at: string
poll_interval_s: number
source_type: string

custom for a feed added by URL, curated for a curated catalog feed.

status: string

Polling health: active, or error after a failed poll.

subscribed_at: string
title: string
updated_at: string
url: string
FeedDeleteResponse object { id, category_id, category_name, 12 more }
id: string
formatuuid
category_id: string

Feed category identifier. Null when unset.

category_name: string

Display name of the feed category. Null when unset or unresolvable.

created_at: string
curated_feed_id: string

Curated catalog feed this subscription was created from. Null for custom feeds.

display_name: string
enabled: boolean
last_polled_at: string
poll_interval_s: number
source_type: string

custom for a feed added by URL, curated for a curated catalog feed.

status: string

Polling health: active, or error after a failed poll.

subscribed_at: string
title: string
updated_at: string
url: string
FeedPollResponse object { errors, feeds, triggered }
errors: number
feeds: array of object { feed_id, status, workflow_id, feed_enabled }
feed_id: string
formatuuid
status: "workflow_created" or "error"
One of the following:
"workflow_created"
"error"
workflow_id: string
feed_enabled: optional boolean
triggered: number

Threat SignalsFeedsRaw

Get Threat Signals feed XML
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/raw
ModelsExpand Collapse
RawGetResponse = string

Threat SignalsFeedsSkills

Get Threat Signals feed skills
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills
Set Threat Signals feed skills
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds/{feed_id}/skills
ModelsExpand Collapse
SkillGetResponse object { feed_id, skills }
feed_id: string
formatuuid
skills: array of object { id, config, created_at, 7 more }
id: string
config: string

JSON-encoded skill configuration. Always null for default skills.

created_at: string
is_active: number

1 when active, 0 when inactive.

name: string
output_schema: string

JSON-encoded JSON Schema the skill output must satisfy.

prompt: string
source: "default" or "custom"

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: string
updated_at: string
SkillUpdateResponse object { feed_id, skills }
feed_id: string
formatuuid
skills: array of object { position, skill_id }
position: number

Zero-based pipeline position.

skill_id: string

Threat SignalsArticles

List Threat Signals articles
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Bulk update Threat Signals article read status
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles
Get Threat Signals article
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
Update Threat Signals article read status
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}
ModelsExpand Collapse
ArticleListResponse object { articles, has_more, next_cursor, 2 more }
articles: array of object { id, dataset_id, event_id, 10 more }
id: string
formatuuid
dataset_id: string

Threat Events dataset identifier for the article redirect. Null when the account feeds dataset mapping is unavailable.

event_id: string

Threat Events event identifier associated with this article for a UI redirect. Null when no event has been linked.

feed_display_name: string
feed_id: string
formatuuid
fetched_at: string
link: string
published_at: string
read: boolean
read_at: string
summary: string

Persisted enrichment summary. Null until enrichment produces a summary.

tags: array of object { applied_by, categoryId, uuid, value }
applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string
title: string
has_more: boolean
next_cursor: string
total_count: number
total_count_is_exact: boolean
ArticleBulkEditResponse object { updated_count }
updated_count: number
ArticleGetResponse object { id, bullet_points, content_r2_key, 16 more }
id: string
formatuuid
bullet_points: object { impact, what_happened, who_affected }
impact: string
what_happened: string
who_affected: string
content_r2_key: string
feed_display_name: string
feed_id: string
formatuuid
fetched_at: string
indicator_extraction_status: "in_progress" or "complete" or "failed" or "unknown"

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

One of the following:
"in_progress"
"complete"
"failed"
"unknown"
link: string
metadata: map[unknown]
published_at: string
read: boolean
read_at: string
source_count: number
summary: string

Persisted enrichment summary. Null until enrichment produces a summary.

summary_r2_key: string
tags: array of object { applied_by, categoryId, uuid, value }
applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string
title: string
skill_version: optional string
tag_skill_version: optional string
ArticleEditResponse object { id, bullet_points, content_r2_key, 16 more }
id: string
formatuuid
bullet_points: object { impact, what_happened, who_affected }
impact: string
what_happened: string
who_affected: string
content_r2_key: string
feed_display_name: string
feed_id: string
formatuuid
fetched_at: string
indicator_extraction_status: "in_progress" or "complete" or "failed" or "unknown"

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

One of the following:
"in_progress"
"complete"
"failed"
"unknown"
link: string
metadata: map[unknown]
published_at: string
read: boolean
read_at: string
source_count: number
summary: string

Persisted enrichment summary. Null until enrichment produces a summary.

summary_r2_key: string
tags: array of object { applied_by, categoryId, uuid, value }
applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string
title: string
skill_version: optional string
tag_skill_version: optional string

Threat SignalsArticlesContent

Get Threat Signals article content
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/content
ModelsExpand Collapse
ContentGetResponse = string

Threat SignalsArticlesTags

Add tag to Threat Signals article
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags
Remove tag from Threat Signals article
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tags/{tag_id}
Generate Threat Signals article AI tags
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/tag
ModelsExpand Collapse
TagCreateResponse object { applied_by, categoryId, uuid, value }
applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string
TagDeleteResponse object { applied_by, categoryId, uuid, value }
applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string
TagGenerateResponse object { tag_skill_version, tags }
tag_skill_version: string
tags: array of object { applied_by, categoryId, uuid, value }

Final hydrated assignment set; may be empty when no applicable tags are selected.

applied_by: "ai" or "analyst" or "system"
One of the following:
"ai"
"analyst"
"system"
categoryId: string
formatuuid
uuid: string
formatuuid
value: string

Threat SignalsArticlesSkill Outputs

Get Threat Signals article skill output
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/articles/{article_id}/skills/{skill_id}/output
ModelsExpand Collapse
SkillOutputGetResponse object { article_id, custom_skill_version, output_schema, 2 more }
article_id: string
formatuuid
custom_skill_version: string
output_schema: string

JSON-encoded output schema of the skill. Null when the skill no longer exists.

skill_id: string
custom_output: optional unknown

Skill output. Parsed JSON when the stored output is valid JSON, otherwise the raw string.

Threat SignalsIndicators

List Threat Signals article indicators
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/indicators
ModelsExpand Collapse
IndicatorListResponse object { indicators, pagination }
indicators: array of object { id, article_id, article_title, 5 more }
id: string
formatuuid
article_id: string
formatuuid
article_title: string
dataset_id: string

Threat Events dataset identifier for navigating from this indicator. Null when the account feeds dataset mapping is unavailable.

feed_display_name: string
feed_id: string
formatuuid
type: string
value: string

Threat SignalsSkills

List Threat Signals skills
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Create Threat Signals skill
POST/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills
Get Threat Signals skill
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Update Threat Signals skill
PATCH/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
Delete Threat Signals skill
DELETE/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}
ModelsExpand Collapse
SkillListResponse object { count, custom_skills_available, page, 3 more }
count: number

Number of skills on this page.

custom_skills_available: boolean

Whether the authenticated account may access custom-skill capabilities under Stakeout’s Threat Signals access-mode policy. This is a policy availability indicator, not a row-existence indicator. False for threat_signals_only mode; true for entitled, allowlisted, cfone_internal, and service modes.

page: number
per_page: number
skills: array of object { id, config, created_at, 7 more }
id: string
config: string

JSON-encoded skill configuration. Always null for default skills.

created_at: string
is_active: number

1 when active, 0 when inactive.

name: string
output_schema: string

JSON-encoded JSON Schema the skill output must satisfy.

prompt: string
source: "default" or "custom"

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: string
updated_at: string
total_count: number
SkillCreateResponse object { id, config, created_at, 7 more }
id: string
config: string

JSON-encoded skill configuration. Always null for default skills.

created_at: string
is_active: number

1 when active, 0 when inactive.

name: string
output_schema: string

JSON-encoded JSON Schema the skill output must satisfy.

prompt: string
source: "default" or "custom"

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: string
updated_at: string
SkillGetResponse object { id, config, created_at, 7 more }
id: string
config: string

JSON-encoded skill configuration. Always null for default skills.

created_at: string
is_active: number

1 when active, 0 when inactive.

name: string
output_schema: string

JSON-encoded JSON Schema the skill output must satisfy.

prompt: string
source: "default" or "custom"

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: string
updated_at: string
SkillEditResponse object { id, config, created_at, 7 more }
id: string
config: string

JSON-encoded skill configuration. Always null for default skills.

created_at: string
is_active: number

1 when active, 0 when inactive.

name: string
output_schema: string

JSON-encoded JSON Schema the skill output must satisfy.

prompt: string
source: "default" or "custom"

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: string
updated_at: string
SkillDeleteResponse object { id, config, created_at, 7 more }
id: string
config: string

JSON-encoded skill configuration. Always null for default skills.

created_at: string
is_active: number

1 when active, 0 when inactive.

name: string
output_schema: string

JSON-encoded JSON Schema the skill output must satisfy.

prompt: string
source: "default" or "custom"

default for Cloudforce One managed skills (read-only), custom for account skills.

One of the following:
"default"
"custom"
type: string
updated_at: string

Threat SignalsSkillsTag Categories

Get Threat Signals skill tag categories
GET/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
Replace Threat Signals skill tag categories
PUT/accounts/{account_id}/cloudforce-one/v2/threat-signals/skills/{skill_id}/tag-categories
ModelsExpand Collapse
TagCategoryGetResponse object { category_uuids, skill_id }
category_uuids: array of string
skill_id: "default-tagging-skill"
TagCategoryUpdateResponse object { category_uuids, skill_id }
category_uuids: array of string
skill_id: "default-tagging-skill"