# Google Threat Intelligence Documentation > Documentation for Google Threat Intelligence ## Guides - [Google Threat Intelligence API key](https://gtidocs.readme.io/docs/how-get-gti-api-keys.md) - [Google Threat Intelligence Platform Navigation](https://gtidocs.readme.io/docs/google-threat-intelligence-navigation.md) - [Google Threat Intelligence Customer Migration](https://gtidocs.readme.io/docs/google-threat-intelligence-customer-migration.md) - [Google Threat Intelligence - Migration guide for VirusTotal former users](https://gtidocs.readme.io/docs/vt-migration-guide.md) - [Google Threat Intelligence - Migration guide for Mandiant Advantage former users](https://gtidocs.readme.io/docs/mati-migration-guide.md) - [Google Threat Intelligence - API Migration guide for Mandiant Advantage former users](https://gtidocs.readme.io/docs/mati-api-migration-guide.md) - [Contributors](https://gtidocs.readme.io/docs/contributors.md) - [Walkthrough guide for Google Threat Intelligence group administrators](https://gtidocs.readme.io/docs/admins-guide.md) - [Single Sign On Authentication](https://gtidocs.readme.io/docs/sso-authentication.md) - [Configure SAML with Okta](https://gtidocs.readme.io/docs/saml-okta.md) - [Configure SAML with Ping](https://gtidocs.readme.io/docs/saml-ping.md) - [Configure SAML with Entra ID](https://gtidocs.readme.io/docs/saml-entraid.md) - [Understanding Consumption](https://gtidocs.readme.io/docs/quota-consumption.md) - [How consumption quotas are handled](https://gtidocs.readme.io/docs/consumption-quotas-handled.md) - [Multi-tenancy](https://gtidocs.readme.io/docs/multi-tenancy-guide.md) - [Agentic Platform](https://gtidocs.readme.io/docs/agentic-platform.md) - [Agentic User Guide](https://gtidocs.readme.io/docs/agentic-user-guide.md) - [Flows](https://gtidocs.readme.io/docs/flows-guide.md): Learn how to automate recurring investigations by scheduling prompts and saved searches with Agentic Flows. - [Getting Started with our new Dark Web Intel capabilities, powered by the relevance system](https://gtidocs.readme.io/docs/dark-web-intel.md) - [Organization Profile](https://gtidocs.readme.io/docs/my-landscape-organization-profile.md) - [Threat Scenarios](https://gtidocs.readme.io/docs/my-landscape-threat-scenarios.md) - [Alerts](https://gtidocs.readme.io/docs/my-landscape-alerts.md) - [Threat Profiles](https://gtidocs.readme.io/docs/manage-threat-profiles.md) - [Threat Actors](https://gtidocs.readme.io/docs/threat-actors-card.md) - [Malware & Tools](https://gtidocs.readme.io/docs/malware-tools.md) - [Campaigns](https://gtidocs.readme.io/docs/campaigns.md) - [IoC Collections](https://gtidocs.readme.io/docs/ioc-collections.md) - [TTP Analysis](https://gtidocs.readme.io/docs/ttp-analysis.md) - [New dark web research](https://gtidocs.readme.io/docs/dark-web-guide.md) - [Countries & Industries Profiles](https://gtidocs.readme.io/docs/countries-industries-profiles.md) - [How Your Threat Landscape Uses AI Recommendations](https://gtidocs.readme.io/docs/threat-landscape-ai-recommendations.md) - [Suspected Attribution](https://gtidocs.readme.io/docs/suspected-attribution.md) - [Mandiant Techniques and Key Events on the Timeline](https://gtidocs.readme.io/docs/mandiant-techniques-and-key-events-on-the-timeline.md) - [Get started with IOC Investigation](https://gtidocs.readme.io/docs/get-started-ioc-investigation.md) - [Check with VirusTotal](https://gtidocs.readme.io/docs/check-vt.md) - [Full list of Google Threat Intelligence search modifiers](https://gtidocs.readme.io/docs/full-list-of-google-threat-intelligence-search-modifiers.md) - [File search modifiers](https://gtidocs.readme.io/docs/file-search-modifiers.md) - [URL search modifiers](https://gtidocs.readme.io/docs/url-search-modifiers.md) - [Domain search modifiers](https://gtidocs.readme.io/docs/domain-search-modifiers.md) - [IP address search modifiers](https://gtidocs.readme.io/docs/ip-address-search-modifiers.md) - [Collection search modifiers](https://gtidocs.readme.io/docs/collection-search-modifiers.md) - [File similarity search](https://gtidocs.readme.io/docs/file-similarity-search.md) - [Content search (Grep)](https://gtidocs.readme.io/docs/content-search-grep.md) - [Batch file downloads](https://gtidocs.readme.io/docs/batch-file-downloads.md) - [Full list of Google Threat Intelligence tag modifier](https://gtidocs.readme.io/docs/full-list-of-google-threat-intelligence-tag-modifier.md) - [Full list of Google Threat Intelligence behaviour_tags modifier](https://gtidocs.readme.io/docs/full-list-of-google-threat-intelligence-behaviour_tags-modifier.md) - [File - List of Engines](https://gtidocs.readme.io/docs/file-list-of-engines.md) - [Reports search modifiers](https://gtidocs.readme.io/docs/reports-search-modifiers.md) - [Threat Intelligence objects search modifiers](https://gtidocs.readme.io/docs/threat-intelligence-objects-modifiers-values.md) - [IoC Reports](https://gtidocs.readme.io/docs/results-reports.md) - [Google Threat Intelligence Indicator Score](https://gtidocs.readme.io/docs/google-threat-intelligence-indicator-score.md) - [Saved Searches](https://gtidocs.readme.io/docs/saved-searches-guide.md) - [What's YARA Hunting?](https://gtidocs.readme.io/docs/whats-yara-hunting.md) - [Livehunt](https://gtidocs.readme.io/docs/livehunt-guide.md) - [Writing YARA rules for Livehunt](https://gtidocs.readme.io/docs/writing-yara-rules-for-livehunt.md) - [File hunting](https://gtidocs.readme.io/docs/hunting-metadata.md) - [Network hunting](https://gtidocs.readme.io/docs/nethunt.md) - [Behavior hunting](https://gtidocs.readme.io/docs/hunting-behavior.md) - [Network hunting examples](https://gtidocs.readme.io/docs/nethunt-examples.md) - [Reference](https://gtidocs.readme.io/docs/hunting-reference.md) - [Legacy variables](https://gtidocs.readme.io/docs/hunting-legacy-variables.md) - [Retrohunt](https://gtidocs.readme.io/docs/retrohunt-guide.md) - [IoC Stream](https://gtidocs.readme.io/docs/ioc-stream-guide.md) - [Sources Subscriptions](https://gtidocs.readme.io/docs/sources-subscriptions.md) - [Diff](https://gtidocs.readme.io/docs/diff.md) - [How does Diff work?](https://gtidocs.readme.io/docs/how-does-diff-work.md) - [Ask questions with Gemini](https://gtidocs.readme.io/docs/search-gemini.md) - [External behavioural engines sandboxes](https://gtidocs.readme.io/docs/external-sandboxes.md) - [In-house Sandboxes - behavioural analysis products](https://gtidocs.readme.io/docs/in-house-sandboxes.md) - [Reports & Analysis](https://gtidocs.readme.io/docs/reports-and-analysis.md) - [Threat Intelligence Report Types](https://gtidocs.readme.io/docs/report-types.md) - [Get started with Threat Graph](https://gtidocs.readme.io/docs/get-started-threat-graph.md) - [Commonalities and Hunting](https://gtidocs.readme.io/docs/threat-graph-commonalities.md) - [Search and start new investigation](https://gtidocs.readme.io/docs/threat-graph-search.md) - [Overview](https://gtidocs.readme.io/docs/threat-graph-overview.md) - [Nodes](https://gtidocs.readme.io/docs/threat-graph-nodes.md) - [Management](https://gtidocs.readme.io/docs/threat-graph-management.md) - [Private Scanning](https://gtidocs.readme.io/docs/private-scanning.md) - [OpenVPN support on private scanning](https://gtidocs.readme.io/docs/private-scanning-openvpn.md) - [How to Explore Vulnerabilities](https://gtidocs.readme.io/docs/explore-vulnerabilities.md) - [Vulnerability report details](https://gtidocs.readme.io/docs/vulnerability-report.md) - [Getting Started with ASM](https://gtidocs.readme.io/docs/get-started-asm.md) - [Dashboard](https://gtidocs.readme.io/docs/dashboard.md) - [Issues](https://gtidocs.readme.io/docs/issues-guide.md) - [Create Issues from Inferred CVEs](https://gtidocs.readme.io/docs/issues-creation.md) - [Issues Severity Definitions and Examples](https://gtidocs.readme.io/docs/issues-severity-definitions.md) - [How Issues Work](https://gtidocs.readme.io/docs/how-issues-work.md) - [Entities](https://gtidocs.readme.io/docs/entities-guide.md) - [How to Set Entities Out of Scope](https://gtidocs.readme.io/docs/how-to-set-entities-out-of-scope.md) - [Scan History](https://gtidocs.readme.io/docs/scan-history.md) - [Technologies](https://gtidocs.readme.io/docs/technologies-guide.md) - [Insights](https://gtidocs.readme.io/docs/insights.md) - [Understanding Attack Surface Management Seeds](https://gtidocs.readme.io/docs/understanding-attack-surface-management-seeds.md) - [Create a Collection](https://gtidocs.readme.io/docs/create-a-collection.md) - [Collections Tips and Tricks](https://gtidocs.readme.io/docs/collections-tips-and-tricks.md) - [Customize Collections](https://gtidocs.readme.io/docs/customize-collections.md) - [Third Party Monitoring Workflow](https://gtidocs.readme.io/docs/third-party-monitoring-workflow.md) - [Issue Settings](https://gtidocs.readme.io/docs/issue-settings.md) - [Assign Roles Within a Collection](https://gtidocs.readme.io/docs/assign-roles-within-a-collection.md) - [Collection Scan Rate](https://gtidocs.readme.io/docs/collection-scan-rate.md) - [ASM Scan Ranges](https://gtidocs.readme.io/docs/asm-scan-ranges.md) - [Discovery Context Visualizer](https://gtidocs.readme.io/docs/discovery-context-visualizer.md) - [Inferred Vulnerabilities](https://gtidocs.readme.io/docs/inferred-vulnerabilities.md) - [TLD List](https://gtidocs.readme.io/docs/tld-list.md) - [Exporting Search Results](https://gtidocs.readme.io/docs/exporting-search-results.md) - [Notifications](https://gtidocs.readme.io/docs/notifications.md) - [ASM Roles and Permissions](https://gtidocs.readme.io/docs/asm-roles-and-permissions.md) - [Assessment Capabilities](https://gtidocs.readme.io/docs/assessment-capabilities.md) - [Projects](https://gtidocs.readme.io/docs/asm-projects.md) - [Manage Project Membership](https://gtidocs.readme.io/docs/manage-project-membership.md) - [Search Summary](https://gtidocs.readme.io/docs/search-summary.md) - [Bulk Select](https://gtidocs.readme.io/docs/bulk-select.md) - [Analyzing SSL/TLS Issues](https://gtidocs.readme.io/docs/analyzing-ssltls-issues.md) - [Search Syntax for Attack Surface Management](https://gtidocs.readme.io/docs/asm-search-syntax.md) - [Opt Out of Attack Surface Management Scanning](https://gtidocs.readme.io/docs/asm-opt-out.md) - [Inbound Integrations](https://gtidocs.readme.io/docs/inbound-integrations.md) - [ASM Akamai Integration](https://gtidocs.readme.io/docs/asm-akamai-integration.md) - [ASM Credential Security Details](https://gtidocs.readme.io/docs/asm-credential-security-details.md) - [ASM AWS Integration](https://gtidocs.readme.io/docs/asm-aws-integration.md) - [Scale AWS Integration Across AWS Organizations](https://gtidocs.readme.io/docs/scale-aws-integration-across-aws-organizations.md) - [ASM Azure Integration](https://gtidocs.readme.io/docs/asm-azure-integration.md) - [ASM Cloudflare Integration](https://gtidocs.readme.io/docs/asm-cloudflare-integration.md) - [ASM DNS Made Easy Integration](https://gtidocs.readme.io/docs/asm-dns-made-easy-integration.md) - [ASM GitHub Integration](https://gtidocs.readme.io/docs/asm-github-integration.md) - [ASM GoDaddy Integration](https://gtidocs.readme.io/docs/asm-godaddy-integration.md) - [ASM Google Cloud Integration](https://gtidocs.readme.io/docs/asm-google-cloud-integration.md) - [Scale Google Cloud Integration](https://gtidocs.readme.io/docs/scale-google-cloud-integration.md) - [Outbound Integrations](https://gtidocs.readme.io/docs/outbound-integrations.md) - [ASM Google SecOps SIEM Integration](https://gtidocs.readme.io/docs/asm-siem-integration.md) - [ASM Google SecOps SOAR Integration Docs](https://gtidocs.readme.io/docs/asm-soar-integration.md) - [ASM Cortex XSOAR Integration](https://gtidocs.readme.io/docs/asm-cortex-xsoar-integration.md) - [ASM Jira Integration](https://gtidocs.readme.io/docs/asm-jira-integration.md) - [ASM ServiceNow Integration](https://gtidocs.readme.io/docs/asm-servicenow-integration.md) - [ASM Splunk Integration](https://gtidocs.readme.io/docs/asm-splunk-integration.md) - [Mandiant Advantage for Splunk](https://gtidocs.readme.io/docs/mandiant-advantage-for-splunk.md) - [How to delete an ASM project](https://gtidocs.readme.io/docs/delete-asm-project.md) - [ASM API Limits and Quotas](https://gtidocs.readme.io/docs/asm-limits-quotas.md) - [Get started with DTM](https://gtidocs.readme.io/docs/get-started-dtm.md) - [Alerts](https://gtidocs.readme.io/docs/alerts-guide.md) - [DTM Alert Severity Definitions and Examples](https://gtidocs.readme.io/docs/dtm-alert-severity.md) - [Group Alerts](https://gtidocs.readme.io/docs/dtm-group-alerts.md) - [Lucene Queries for DTM Alerts](https://gtidocs.readme.io/docs/dtm-lucene-queries-for-alerts.md) - [Monitors](https://gtidocs.readme.io/docs/monitors-guide.md) - [Monitor Fields](https://gtidocs.readme.io/docs/monitor-fields.md) - [Build Effective Monitors](https://gtidocs.readme.io/docs/monitor-scenarios.md) - [Monitor Matching Methodology](https://gtidocs.readme.io/docs/monitor-matching-methodology.md) - [Monitor Compromised Credentials](https://gtidocs.readme.io/docs/monitor-compromised-credentials.md) - [Research Tools](https://gtidocs.readme.io/docs/research-tools.md) - [Configuring DTM Email Notifications](https://gtidocs.readme.io/docs/configuring-dtm-email-notifications.md) - [Lucene Queries in DTM](https://gtidocs.readme.io/docs/lucene-queries-in-dtm.md) - [Digital Threat Monitoring FAQ](https://gtidocs.readme.io/docs/digital-threat-monitoring-faq.md) - [DTM API Limits and Quotas](https://gtidocs.readme.io/docs/dtm-limits-quotas.md) - [Digital Threat Monitoring](https://gtidocs.readme.io/docs/digital-threat-monitoring.md) - [Digital Threat Monitoring User Roles](https://gtidocs.readme.io/docs/dtm-user-roles.md) - [Migrate from VirusTotal](https://gtidocs.readme.io/docs/migrate-from-virustotal.md): How to move from VirusTotal integrations to the Google Threat Intelligence ones. - [List of Google TI Integrations](https://gtidocs.readme.io/docs/technology-integrations-list.md) - [Google Threat Intelligence for MSFT Sentinel](https://gtidocs.readme.io/docs/gti4sentinel-guide.md): Configuration and use guide - [MISP integration guide](https://gtidocs.readme.io/docs/gti4misp-guide.md) - [Splunk integration guide](https://gtidocs.readme.io/docs/gti4splunk-guide.md) - [TIP integration guide](https://gtidocs.readme.io/docs/tip-integration-guide.md) - [Palo Alto XSOAR integration guide](https://gtidocs.readme.io/docs/gti4xsoar-guide.md) - [VT4Browsers + Google TI](https://gtidocs.readme.io/docs/vt4browsers.md): VT4Browsers evolves with the power of Google Threat Intelligence - [Use cases and other resources](https://gtidocs.readme.io/docs/use-cases.md) - [Advanced Hunting](https://gtidocs.readme.io/docs/use-cases-advanced-hunting.md) - [Incident Response](https://gtidocs.readme.io/docs/use-cases-incident-response.md) - [Phishing & Brand Monitoring](https://gtidocs.readme.io/docs/use-cases-phishing-brand-monitoring.md) - [Vulnerability Management](https://gtidocs.readme.io/docs/use-cases-vulnerability-management.md) - [Automatic Security Telemetry Enrichment](https://gtidocs.readme.io/docs/automatic-security-telemetry-enrichment.md) - [Frequently Asked Questions](https://gtidocs.readme.io/docs/frequently-asked-questions.md) - [What kind of files will Google Threat Intelligence scan?](https://gtidocs.readme.io/docs/file-types.md) - [AV product on Google Threat Intelligence detects a file and its equivalent commercial version does not](https://gtidocs.readme.io/docs/antivirus-differs.md) - [What type of files are supported by code insight?](https://gtidocs.readme.io/docs/codeinsight-supported-files.md) - [I accidentally uploaded a file with confidential or sensitive information to Google TI, can you please delete it?](https://gtidocs.readme.io/docs/accidental-upload.md) - [Why does my signed file appear as "not signed" on VirusTotal?](https://gtidocs.readme.io/docs/why-does-my-signed-file-appear-as-not-signed-on-virustotal.md): I have a file that appears to be digitally signed on my Windows system, but VirusTotal's "Details" tab reports it as "File is not signed." Why is there a discrepancy? - [What type of compressed files are supported?](https://gtidocs.readme.io/docs/compressed-files.md) - [Why can't I see the gti_assessment attribute in the JSON response?](https://gtidocs.readme.io/docs/missing-gti-asssessment.md) - [Understanding Partial Files](https://gtidocs.readme.io/docs/partial-files.md) - [When is an analysis included in the feeds?](https://gtidocs.readme.io/docs/when-analysis-feeds.md) - [My Landscape](https://gtidocs.readme.io/docs/my-landscape-faq.md) - [How can I rotate my API key](https://gtidocs.readme.io/docs/rotate-api-key.md) - [I lost access to my authentication device/offline codes for 2FA](https://gtidocs.readme.io/docs/lost-access-2fa.md) ## API Reference - [Google Threat Intelligence API Overview](https://gtidocs.readme.io/reference/api-overview.md) - [API responses](https://gtidocs.readme.io/reference/api-responses.md) - [Key concepts](https://gtidocs.readme.io/reference/introduction-key-concepts.md) - [Objects](https://gtidocs.readme.io/reference/introduction-objects.md) - [Errors](https://gtidocs.readme.io/reference/introduction-errors.md) - [Relationships](https://gtidocs.readme.io/reference/introduction-relationships.md) - [Collections](https://gtidocs.readme.io/reference/introduction-collections.md) - [OpenAPI Specifications](https://gtidocs.readme.io/reference/openapi-specs.md) - [STIX responses](https://gtidocs.readme.io/reference/stix-responses.md) - [Threat Actors, Malware & Tools, Campaigns, IoC Collection, Country and Industry Profiles](https://gtidocs.readme.io/reference/threat-actors-malware-tools-campaigns-ioc-collections.md) - [List collections](https://gtidocs.readme.io/reference/list-collections.md) - [Create a new collection](https://gtidocs.readme.io/reference/create-collection.md) - [Get a collection](https://gtidocs.readme.io/reference/get-collection.md) - [Delete a collection](https://gtidocs.readme.io/reference/delete-collection.md) - [Update a collection](https://gtidocs.readme.io/reference/update-collection.md) - [Add new associations, IoCs and TTPs to a collection](https://gtidocs.readme.io/reference/add-element-to-collection.md) - [Delete associations, IoCs and TTPs from a collection](https://gtidocs.readme.io/reference/delete-element-from-collection.md) - [Get Hunting rulesets associated with an IoC Collection](https://gtidocs.readme.io/reference/get-related-hunting-rulesets.md) - [Delete Hunting rulesets association from IoC collection](https://gtidocs.readme.io/reference/delete-hunting-rulesets-relationship.md) - [Add Hunting rulesets association to an IoC Collection](https://gtidocs.readme.io/reference/add-hunting-rulesets-relationship.md) - [Get object descriptors related to a threat](https://gtidocs.readme.io/reference/get-threat-related-descriptors.md) - [Get objects related to a threat](https://gtidocs.readme.io/reference/get-threat-relationships.md) - [Get comments from a collection](https://gtidocs.readme.io/reference/get-collection-comments.md) - [Add a comment to a collection](https://gtidocs.readme.io/reference/create-collection-comment.md) - [Get MITRE tactics and techniques associated with a threat](https://gtidocs.readme.io/reference/get-threat-mitre-tree.md) - [Search IoCs inside a threat](https://gtidocs.readme.io/reference/search-iocs-inside-a-threat.md) - [Get a Threat's observed actions list](https://gtidocs.readme.io/reference/get-threat-timeline-events.md) - [Export IOCs from a threat](https://gtidocs.readme.io/reference/export-threat-iocs.md) - [Export aggregations / commonalities from a threat](https://gtidocs.readme.io/reference/export-threat-aggregations.md) - [Export IOCs from a given threat's relationship](https://gtidocs.readme.io/reference/export-iocs-threat-relationship.md) - [Subscribe to a threat object](https://gtidocs.readme.io/reference/create-threat-subscription-preferences.md) - [Check subscription preferences from threat object](https://gtidocs.readme.io/reference/get-threat-subscription-preferences.md) - [Delete subscription from a threat object](https://gtidocs.readme.io/reference/delete-threat-subscription-preferences.md) - [Download IoCs batch from a given collection](https://gtidocs.readme.io/reference/iocs-batch-download.md) - [Get Collection IoCs Deltas](https://gtidocs.readme.io/reference/ioc-deltas.md) - [List Threat Profiles](https://gtidocs.readme.io/reference/list-threat-profiles.md) - [Create a Threat Profile](https://gtidocs.readme.io/reference/create-threat-profile.md) - [Get a Threat Profile](https://gtidocs.readme.io/reference/get-threat-profile.md) - [Update a Threat Profiles](https://gtidocs.readme.io/reference/update-threat-profile.md) - [Delete a Threat Profile](https://gtidocs.readme.io/reference/delete-threat-profile.md) - [Get recommendations of a Threat Profile](https://gtidocs.readme.io/reference/get-threat-profile-recommendations.md) - [Get a Threat Profile's recommendations descriptors](https://gtidocs.readme.io/reference/get-threat-profile-recommendations-descriptors.md) - [Delete objects from a Threat Profile](https://gtidocs.readme.io/reference/delete-threat-profile-recommendations.md) - [Add objects to a Threat Profile](https://gtidocs.readme.io/reference/add-threat-profile-recommendations.md) - [Get objects related to a Threat Profile](https://gtidocs.readme.io/reference/get-threat-profile-relationships.md) - [Get object descriptors related to a Threat Profile](https://gtidocs.readme.io/reference/get-threat-profile-related-descriptors.md) - [Delete items from a Threat Profile](https://gtidocs.readme.io/reference/delete-threat-profile-relationships.md) - [Add or update relationships between a Threat Profile and other objects](https://gtidocs.readme.io/reference/add-threat-profile-relationships.md) - [Get a Threat Profile's timeline associations](https://gtidocs.readme.io/reference/get-threat-profile-timeline-associations.md) - [Export IoCs](https://gtidocs.readme.io/reference/threat-profile-download.md) - [Export URL for Large IoC Packages](https://gtidocs.readme.io/reference/threat-profile_download-url.md) - [Dark Web](https://gtidocs.readme.io/reference/dark-web.md) - [List Dark Web Communications](https://gtidocs.readme.io/reference/list-ddw-communications.md) - [Get a Dark Web Communication object](https://gtidocs.readme.io/reference/get-ddw-communication.md) - [Get objects related to a Dark Web Communication object](https://gtidocs.readme.io/reference/get-ddw-communication-relationships.md) - [Get a Dark Web Communication Channel object](https://gtidocs.readme.io/reference/get-ddw-communication-channel.md) - [Get Next Communication in a Channel](https://gtidocs.readme.io/reference/get-ddw-channel-next-communications.md) - [Get Previous Communication in a Channel](https://gtidocs.readme.io/reference/get-ddw-channel-previous-communications.md) - [Get a Dark Web User Profile](https://gtidocs.readme.io/reference/get-ddw-user-profile.md) - [Get a Dark Web Service object](https://gtidocs.readme.io/reference/get-ddw-service.md) - [Get objects related to a Dark Web Service object](https://gtidocs.readme.io/reference/get-ddw-service-relationships.md) - [Get Next Communication in a Thread](https://gtidocs.readme.io/reference/get-ddw-thread-next-communications.md) - [Get Previous Communication in a Thread](https://gtidocs.readme.io/reference/get-ddw-thread-previous-communications.md) - [Get an IP address report](https://gtidocs.readme.io/reference/ip-info.md) - [Get comments on an IP address](https://gtidocs.readme.io/reference/ip-comments-get.md) - [Request an IP address (re)scan](https://gtidocs.readme.io/reference/ip-analyse.md): Reanalyse an IP address already in Google Threat Intelligence - [Add a comment to an IP address](https://gtidocs.readme.io/reference/ip-comments-post.md) - [Get object descriptors related to an IP address](https://gtidocs.readme.io/reference/ip-relationships-ids.md) - [Get votes on an IP address](https://gtidocs.readme.io/reference/ip-votes.md) - [Add a vote to an IP address](https://gtidocs.readme.io/reference/ip-votes-post.md) - [Get objects related to an IP address](https://gtidocs.readme.io/reference/ip-relationships.md) - [Get a domain report](https://gtidocs.readme.io/reference/domain-info.md) - [Get comments on a domain](https://gtidocs.readme.io/reference/domains-comments-get.md) - [Request a domain (re)scan](https://gtidocs.readme.io/reference/domains-rescan.md) - [Add a comment to a domain](https://gtidocs.readme.io/reference/domains-comments-post.md) - [Get object descriptors related to a domain](https://gtidocs.readme.io/reference/domains-relationships-ids.md) - [Get votes on a domain](https://gtidocs.readme.io/reference/domains-votes-get.md) - [Add a vote to a domain](https://gtidocs.readme.io/reference/domain-votes-post.md) - [Get objects related to a domain](https://gtidocs.readme.io/reference/domains-relationships.md) - [Get a DNS resolution object](https://gtidocs.readme.io/reference/get-resolution-by-id.md) - [Files](https://gtidocs.readme.io/reference/files.md) - [Get a URL for uploading large files](https://gtidocs.readme.io/reference/files-upload-url.md) - [Upload a file](https://gtidocs.readme.io/reference/files-scan.md) - [Get a file report](https://gtidocs.readme.io/reference/file-info.md) - [Request a file rescan (re-analyse)](https://gtidocs.readme.io/reference/files-analyse.md) - [Get comments on a file](https://gtidocs.readme.io/reference/files-comments-get.md) - [Add a comment to a file](https://gtidocs.readme.io/reference/files-comments-post.md) - [Download a file](https://gtidocs.readme.io/reference/files-download.md) - [Get a file’s download URL](https://gtidocs.readme.io/reference/files-download-url.md) - [Get object descriptors related to a file](https://gtidocs.readme.io/reference/files-relationships-ids.md) - [Get votes on a file](https://gtidocs.readme.io/reference/files-votes-get.md) - [Add a vote on a file](https://gtidocs.readme.io/reference/files-votes-post.md) - [Get objects related to a file](https://gtidocs.readme.io/reference/files-relationships.md) - [Get a crowdsourced Sigma rule object](https://gtidocs.readme.io/reference/get-sigma-rules.md) - [Get a crowdsourced YARA ruleset](https://gtidocs.readme.io/reference/get-yara-rulesets.md) - [Get a file behavior report from a sandbox](https://gtidocs.readme.io/reference/get-file-behaviour-id.md) - [Get the EVTX file generated during a file’s behavior analysis](https://gtidocs.readme.io/reference/file-behaviour-evtx.md) - [Get a detailed HTML behaviour report](https://gtidocs.readme.io/reference/get-file-behaviour-html.md) - [Get the memdump file generated during a file’s behavior analysis](https://gtidocs.readme.io/reference/file-behaviour-memdump.md) - [Get the PCAP file generated during a file’s behavior analysis](https://gtidocs.readme.io/reference/file_behaviours_pcap.md) - [Get object descriptors related to a behaviour report](https://gtidocs.readme.io/reference/file_behaviourssandbox_idrelationshipsrelationship.md) - [Get objects related to a behaviour report](https://gtidocs.readme.io/reference/file_behaviourssandbox_idrelationship.md) - [Get a summary of all MITRE ATT&CK techniques observed in a file](https://gtidocs.readme.io/reference/get-a-summary-of-all-mitre-attck-techniques-observed-in-a-file.md) - [Get a summary of all behavior reports for a file](https://gtidocs.readme.io/reference/file-all-behaviours-summary.md) - [Get all behavior reports for a file](https://gtidocs.readme.io/reference/get-all-behavior-reports-for-a-file.md) - [URLs](https://gtidocs.readme.io/reference/urls.md) - [Scan URL](https://gtidocs.readme.io/reference/scan-url.md) - [Get a URL report](https://gtidocs.readme.io/reference/url-info.md) - [Request a URL rescan (re-analyse)](https://gtidocs.readme.io/reference/urls-analyse.md) - [Get comments on a URL](https://gtidocs.readme.io/reference/urls-comments-get.md) - [Add a comment on a URL](https://gtidocs.readme.io/reference/urls-comments-post.md) - [Get object descriptors related to a URL](https://gtidocs.readme.io/reference/urls-relationships-ids.md) - [Get votes on a URL](https://gtidocs.readme.io/reference/urls-votes-get.md) - [Add a vote on a URL](https://gtidocs.readme.io/reference/urls-votes-post.md) - [Get objects related to a URL](https://gtidocs.readme.io/reference/urls-relationships.md) - [Get a URL's latest analysis screenshot](https://gtidocs.readme.io/reference/urls-screenshot.md) - [Get the URL for a URL's latest analysis screenshot](https://gtidocs.readme.io/reference/urls-screenshot-url.md) - [Get a URL's latest analysis DOM](https://gtidocs.readme.io/reference/urls-dom.md) - [Get the URL for a URL's latest analysis DOM](https://gtidocs.readme.io/reference/urls-dom-url.md) - [Comments](https://gtidocs.readme.io/reference/comments.md) - [Get latest comments](https://gtidocs.readme.io/reference/get-comments.md) - [Delete a comment](https://gtidocs.readme.io/reference/comment-id-delete.md) - [Get a comment object](https://gtidocs.readme.io/reference/get-comment.md) - [Get object descriptors related to a comment](https://gtidocs.readme.io/reference/comments-relationships-ids.md) - [Add a vote to a comment](https://gtidocs.readme.io/reference/vote-comment.md) - [Get objects related to a comment](https://gtidocs.readme.io/reference/comments-relationships.md) - [Get a URL / file analysis](https://gtidocs.readme.io/reference/analysis.md) - [Get object descriptors related to an analysis](https://gtidocs.readme.io/reference/analyses-get-descriptors.md) - [Get objects related to an analysis](https://gtidocs.readme.io/reference/analyses-get-objects.md) - [Get a submission object](https://gtidocs.readme.io/reference/get-submission.md) - [Get an operation object](https://gtidocs.readme.io/reference/get-operations-id.md) - [Get a URL analysis screenshot](https://gtidocs.readme.io/reference/analysis-screenshot.md) - [Get the URL for a URL analysis screenshot](https://gtidocs.readme.io/reference/analysis-screenshot-url.md) - [Get a URL analysis DOM](https://gtidocs.readme.io/reference/analysis-dom.md) - [Get the URL for a URL analysis DOM](https://gtidocs.readme.io/reference/analysis-dom-url.md) - [Get strings extracted from the content downloaded during a URL analysis](https://gtidocs.readme.io/reference/analysis-content-strings.md) - [Get a preview of the content downloaded during a URL analysis](https://gtidocs.readme.io/reference/analysis-content-preview.md) - [Download strings extracted from the content downloaded during a URL analysis](https://gtidocs.readme.io/reference/analysis-content-strings-download.md) - [Get an attack tactic object](https://gtidocs.readme.io/reference/attack_tacticsid.md) - [Get object descriptors related to an attack tactic](https://gtidocs.readme.io/reference/attack_tacticsidrelationshipsrelationship.md) - [Get objects related to an attack tactic](https://gtidocs.readme.io/reference/attack_tacticsidrelationship.md) - [Get an attack technique object](https://gtidocs.readme.io/reference/attack_techniqueid.md) - [Get object descriptors related to an attack technique](https://gtidocs.readme.io/reference/attack_techniquesidrelationshipsrelationship.md) - [Get objects related to an attack technique](https://gtidocs.readme.io/reference/attack_techniqueidrelationship.md) - [Get a list of popular threat categories](https://gtidocs.readme.io/reference/popular_threat_categories.md) - [Zipping files](https://gtidocs.readme.io/reference/zipping-files.md) - [Create a password-protected ZIP with Google Threat Intelligence files](https://gtidocs.readme.io/reference/zip_files.md) - [Check a ZIP file’s status](https://gtidocs.readme.io/reference/get-zip-file.md) - [Download a ZIP file](https://gtidocs.readme.io/reference/zip-files-download.md) - [Get a ZIP file’s download URL](https://gtidocs.readme.io/reference/zip-files-download-url.md) - [Search & Metadata](https://gtidocs.readme.io/reference/search-metadata.md) - [Advanced corpus search](https://gtidocs.readme.io/reference/intelligence-search.md) - [Get file content search snippets](https://gtidocs.readme.io/reference/intelligence-search-snippets.md) - [Get Google Threat Intel metadata](https://gtidocs.readme.io/reference/metadata.md) - [Search for files, URLs, domains, IPs and comments](https://gtidocs.readme.io/reference/api-search.md) - [Analyse code blocks with Code Insights](https://gtidocs.readme.io/reference/analyse-binary.md) - [List Saved Searches](https://gtidocs.readme.io/reference/list-saved-searches.md) - [Get a Saved Search](https://gtidocs.readme.io/reference/get-saved-searches.md) - [Create a Saved Search](https://gtidocs.readme.io/reference/create-saved-searches.md) - [Share a Saved Search](https://gtidocs.readme.io/reference/share-saved-searches.md) - [Update a Saved Search](https://gtidocs.readme.io/reference/update-saved-searches.md) - [Delete a Saved Search](https://gtidocs.readme.io/reference/delete-saved-searches.md) - [Revoke access to a Saved Search](https://gtidocs.readme.io/reference/revoke-saved-searches-access.md) - [Get object descriptors related to a Saved Search](https://gtidocs.readme.io/reference/get-saved-searches-related-descriptors.md) - [Get objects related to a Saved Search](https://gtidocs.readme.io/reference/get-saved-searches-relationships.md) - [Retrieve summary for a list of IoCs](https://gtidocs.readme.io/reference/get-ioc-summary.md): Retrieve summary for a list of IoCs.The request body should contain a list of IoC descriptors. - [List Crowdsourced YARA Rules](https://gtidocs.readme.io/reference/list-crowdsourced-yara-rules.md) - [Get a Crowdsourced YARA rule](https://gtidocs.readme.io/reference/get-a-crowdsourced-yara-rule.md) - [Get objects descriptors related to a Crowdsourced YARA rule](https://gtidocs.readme.io/reference/crowdsourced-yara-rule-relationship-descriptors-endpoint.md) - [Get objects related to a Crowdsourced YARA rule](https://gtidocs.readme.io/reference/crowdsourced-yara-rule-relationship-endpoint.md) - [Delete notifications from the IoC Stream](https://gtidocs.readme.io/reference/delete-notifications-from-the-ioc-stream.md) - [Get objects from the IoC Stream](https://gtidocs.readme.io/reference/get-objects-from-the-ioc-stream.md) - [Delete an IoC Stream notification](https://gtidocs.readme.io/reference/delete-an-ioc-stream-notification.md) - [Get an IoC Stream notification](https://gtidocs.readme.io/reference/get-an-ioc-stream-notification.md) - [Remove all Livehunt rulesets](https://gtidocs.readme.io/reference/delete-all-hunting-rulesets.md) - [Get Livehunt rulesets](https://gtidocs.readme.io/reference/list-hunting-rulesets.md) - [Create a new Livehunt ruleset](https://gtidocs.readme.io/reference/create-hunting-ruleset.md) - [Delete a Livehunt ruleset](https://gtidocs.readme.io/reference/delete-hunting-ruleset.md) - [Get a Livehunt ruleset](https://gtidocs.readme.io/reference/get-hunting-ruleset.md) - [Update a Livehunt ruleset](https://gtidocs.readme.io/reference/modify-hunting-ruleset.md) - [Delete IoC Collections association from Hunting ruleset](https://gtidocs.readme.io/reference/delete-ioc-collections-relationship.md) - [Get IoC Collections associated with a Hunting ruleset](https://gtidocs.readme.io/reference/get-related-ioc-collections.md) - [Add IoC Collectios association to a Hunting ruleset](https://gtidocs.readme.io/reference/add-ioc-collections-relationship.md) - [Grant Livehunt ruleset edit permissions for a user or group](https://gtidocs.readme.io/reference/edit-hunting-ruleset-relationship.md) - [Revoke Livehunt ruleset edit permission from a user or group](https://gtidocs.readme.io/reference/delete-hunting-ruleset-editor.md) - [Check if a user or group is a Livehunt ruleset editor](https://gtidocs.readme.io/reference/check-user-hunting-ruleset-editor.md) - [Transfer Livehunt ruleset to another user](https://gtidocs.readme.io/reference/transfer-livehunt-ruleset-to-another-user.md) - [Get object descriptors related to a Livehunt ruleset](https://gtidocs.readme.io/reference/get-hunting-ruleset-relationship.md) - [Get objects related to a Livehunt ruleset](https://gtidocs.readme.io/reference/get-hunting-ruleset-full-relationships.md) - [Get a list of Retrohunt jobs](https://gtidocs.readme.io/reference/get-retrohunt-jobs.md) - [Create a new Retrohunt job](https://gtidocs.readme.io/reference/create-retrohunt-job.md) - [Delete a Retrohunt job](https://gtidocs.readme.io/reference/delete-retrohunt-job.md) - [Get a Retrohunt job object](https://gtidocs.readme.io/reference/get-retrohunt-job.md) - [Abort a Retrohunt job](https://gtidocs.readme.io/reference/abort-retrohunt-job.md) - [Retrieve matches for a Retrohunt job](https://gtidocs.readme.io/reference/get-retrohunt-job-relationships.md) - [Reports](https://gtidocs.readme.io/reference/reports.md) - [List reports](https://gtidocs.readme.io/reference/list-reports.md) - [Get a report](https://gtidocs.readme.io/reference/get-report.md) - [Create a new report](https://gtidocs.readme.io/reference/create-report.md) - [Delete a report](https://gtidocs.readme.io/reference/delete-report.md) - [Update a report](https://gtidocs.readme.io/reference/update-report.md) - [Add new associations, IoCs or TTPs to a report](https://gtidocs.readme.io/reference/add-element-to-report.md) - [Delete associations, IoCs and TTPs from a report](https://gtidocs.readme.io/reference/delete-element-from-report.md) - [Get object descriptors related to a report](https://gtidocs.readme.io/reference/get-report-related-descriptors.md) - [Get objects related to a report](https://gtidocs.readme.io/reference/get-report-relationships.md) - [Get comments from a report](https://gtidocs.readme.io/reference/get-report-comments.md) - [Add a comment to a report](https://gtidocs.readme.io/reference/create-report-comment.md) - [Get MITRE tactics and techniques associated with a report](https://gtidocs.readme.io/reference/get-report-mitre-tree.md) - [Search IoCs inside a report](https://gtidocs.readme.io/reference/search-iocs-inside-a-report.md) - [Export IOCs from a report](https://gtidocs.readme.io/reference/export-report-iocs.md) - [Export aggregations / commonalities from a report](https://gtidocs.readme.io/reference/export-report-aggregations.md) - [Export IOCs from a given report's relationship](https://gtidocs.readme.io/reference/export-iocs-report-relationship.md) - [Download a Report](https://gtidocs.readme.io/reference/download-report.md) - [Subscribe to a report](https://gtidocs.readme.io/reference/create-report-subscription-preferences.md) - [Check subscription preferences from a report](https://gtidocs.readme.io/reference/get-report-subscription-preferences.md) - [Delete subscription from a report](https://gtidocs.readme.io/reference/delete-report-subscription-preferences.md) - [Private Files](https://gtidocs.readme.io/reference/private-files.md) - [Upload a file](https://gtidocs.readme.io/reference/upload-file-private-scanning.md) - [List private files](https://gtidocs.readme.io/reference/list-private-files.md) - [Get a URL for uploading large files](https://gtidocs.readme.io/reference/private-files-upload-url.md) - [Delete a private file report](https://gtidocs.readme.io/reference/delete-file-private-scanning.md) - [Get a private file report](https://gtidocs.readme.io/reference/private-files-info.md) - [Get object descriptors related to a file](https://gtidocs.readme.io/reference/privatefilesidrelationshipsrelationship.md) - [Get objects related to a private file](https://gtidocs.readme.io/reference/private-files-relationships.md) - [Rescan a private file](https://gtidocs.readme.io/reference/rescan-a-private-file.md) - [Get the behaviour reports from a private file](https://gtidocs.readme.io/reference/get-all-behaviour-reports-from-a-private-file.md) - [Get a behaviour report from a private file](https://gtidocs.readme.io/reference/privatefile-behaviourssandbox-id.md) - [Get the EVTX file generated during a private file’s behavior analysis](https://gtidocs.readme.io/reference/file-behaviourssandbox-idevtx.md) - [Get a detailed HTML behaviour report](https://gtidocs.readme.io/reference/privatefile-behaviourssandbox-idhtml.md) - [Get the memdump file generated during a private file’s behavior analysis](https://gtidocs.readme.io/reference/privatefile-behaviourssandbox-idpcap.md) - [Get the PCAP file generated during a private file’s behavior analysis](https://gtidocs.readme.io/reference/file-behaviourssandbox-idmemdump.md) - [Get object descriptors related to a private file's behaviour report](https://gtidocs.readme.io/reference/privatefile-behaviourssandbox-idrelationshipsrelationship.md) - [Get objects related to a private file's behaviour report](https://gtidocs.readme.io/reference/privatefile-behaviourssandbox-idrelationship.md) - [Get a summary of all MITRE ATT&CK techniques observed in a file](https://gtidocs.readme.io/reference/get-summary-all-mitre-attack-techniques-observed-in-a-file.md) - [Get a summary of all behavior reports for a file](https://gtidocs.readme.io/reference/privatefilesidbehaviour-summary.md) - [List private analyses](https://gtidocs.readme.io/reference/list-private-analyses.md) - [Get a private analysis](https://gtidocs.readme.io/reference/private-analysis.md) - [Get object descriptors related to a private analysis](https://gtidocs.readme.io/reference/private-analyses-relationships-descriptor.md) - [Get objects related to a private analysis](https://gtidocs.readme.io/reference/private-analyses-relationship.md) - [Private URLs](https://gtidocs.readme.io/reference/private-urls.md) - [Private Scan URL](https://gtidocs.readme.io/reference/private-scan-url.md) - [Get a URL analysis report](https://gtidocs.readme.io/reference/get-a-private-url-analysis-report.md) - [Get objects related to a private URL](https://gtidocs.readme.io/reference/private-get-objects-related-to-a-url.md) - [Get object descriptors related to a private URL](https://gtidocs.readme.io/reference/private-get-object-descriptors-related-to-a-url.md) - [Private Zipping files](https://gtidocs.readme.io/reference/private-zipping-files.md) - [Create a password-protected ZIP with Google Threat Intelligence files](https://gtidocs.readme.io/reference/private-scanning-zip-files.md) - [Check a ZIP file’s status](https://gtidocs.readme.io/reference/private-scanning-get-zip-file.md) - [Download a ZIP file](https://gtidocs.readme.io/reference/private-scanning-download-zip-file.md) - [Get a ZIP file’s download URL](https://gtidocs.readme.io/reference/private-scanning-get-zip-download-url.md) - [List vulnerabilities](https://gtidocs.readme.io/reference/list-vulnerabilities.md) - [Get a vulnerability](https://gtidocs.readme.io/reference/get-vulnerability.md) - [Get object descriptors related to a vulnerability](https://gtidocs.readme.io/reference/get-vulnerability-related-descriptors.md) - [Get objects related to a vulnerability](https://gtidocs.readme.io/reference/get-vulnerability-relationships.md) - [Get comments from a vulnerability](https://gtidocs.readme.io/reference/get-vulnerability-comments.md) - [Add a comment to a vulnerability](https://gtidocs.readme.io/reference/create-vulnerability-comment.md) - [Get MITRE tactics and techniques associated with a vulnerability](https://gtidocs.readme.io/reference/get-vulnerability-mitre-tree.md) - [Search IoCs inside a vulnerability](https://gtidocs.readme.io/reference/search-iocs-inside-a-vulnerability.md) - [Export IoCs from a vulnerability](https://gtidocs.readme.io/reference/export-vulnerability-iocs.md) - [Export aggregations / commonalities from a vulnerability](https://gtidocs.readme.io/reference/export-vulnerability-aggregations.md) - [Export IoCs from a given vulnerability's relationship](https://gtidocs.readme.io/reference/export-iocs-vulnerability-relationship.md) - [Subscribe to a vulnerability](https://gtidocs.readme.io/reference/create-vulnerability-subscription-preferences.md) - [Check subscription preferences from a vulnerability](https://gtidocs.readme.io/reference/get-vulnerability-subscription-preferences.md) - [Delete subscription from a vulnerability](https://gtidocs.readme.io/reference/delete-vulnerability-subscription-preferences.md) - [Index](https://gtidocs.readme.io/reference/get_projects.md): List all projects - [Create](https://gtidocs.readme.io/reference/post_projects.md): Create a new project Body: ``` json { "name" : "New Project Name" } ``` - [Delete](https://gtidocs.readme.io/reference/delete_projects-uuid.md): This api endpoint will delete a project. - [Index](https://gtidocs.readme.io/reference/get_user-collections.md): List all collections. if invalid, or no PROJECT-ID is passed, only collections from top project are returned. - [Create](https://gtidocs.readme.io/reference/post_user-collections.md): Creates a new collection - [Read](https://gtidocs.readme.io/reference/get_user-collections-uuid.md): Show details for a specified collection - [Delete](https://gtidocs.readme.io/reference/delete_user-collections-uuid.md): Delete a collection - [Archive](https://gtidocs.readme.io/reference/patch_user-collections-uuid-archive.md): Archive a collection - [Unarchive](https://gtidocs.readme.io/reference/patch_user-collections-uuid-unarchive.md): Unarchive a collection - [Index](https://gtidocs.readme.io/reference/get_collections-collection-uuid-collection-runs.md): Returns up to last 10 collection scans - [Create](https://gtidocs.readme.io/reference/post_collections-collection-uuid-collection-runs.md): This will schedule a scan for the collection entered - [Search Entities](https://gtidocs.readme.io/reference/get_search-entities-search-string.md): Search Endpoint for all entity data. If no operator is used, "name" field is searched Valid Search Keywords ('**search_string' parameter)**: - collection:intrigue_123k221 - type:string - ApiEndpoint, AppEndpoint, AutonomousSystem, AwsEC2Instance, AwsRdsDbInstance, AwsS3Bucket, AzureStorageAccount, AzureVirtualMachine, DnsRecord, Domain, EmailAddress, GcpApiGateway, GcpAppEngineApplication, GcpCloudFunction, GcpCloudSQLInstance, GcpComputeEngineInstance, GcpStorageBucket, GithubAccount, GithubRepository, IpAddress, Nameserver, NetBlock, NetworkService, SslCertificate, UniqueKeyword, UniqueToken, Uri - name:string - hidden:false | true - tag:tagname - country:us (alpha-2 country coded) - uid:12345 - last_seen_after:string - last_scan_count_1 (1-10) - last_refresh - configured_scan_count - YYYY-MM-DD - last_seen_before:string - last_scan_count_1 (1-10) - last_refresh - configured_scan_count - YYYY-MM-DD - first_seen_after:string - last_scan_count_1 (1-10) - last_refresh - configured_scan_count - YYYY-MM-DD - scoped:true | false - http_code:404 - http_auth:true | false - http_auth_basic:true | false - http_auth_ntlm:true | false - http_title:string - http_forms:true | false - http_cookie - technology:jquery - cloud:true | false - cloud_provider - network - port_tcp - port_udp - port_count_lte:1 - port_count_gte:1 - issue_count_lte:1 - issue_count_gte:1 - vuln:cve - vuln_count_gte:1 - vuln_count_lte:1 - critical_or_high:true | false - resolves_to:string - [Get Detail](https://gtidocs.readme.io/reference/get_entities-entity-uid.md): Obtains an individual entity's searchable details - [Get Full Detail](https://gtidocs.readme.io/reference/get_entities-entity-uid-raw.md): Obtains an individual entity's full details - [Search Issues](https://gtidocs.readme.io/reference/get_search-issues-search-string.md): Search Endpoint for all issue data. If no operator is used, "name" field is searched Valid Search Keywords ('**search_string' parameter)**: - collection:name_123k221 - name:string - uid:12345 - tag:tag_name - last_seen_after:string - last_scan_count_1 (1-10) - last_refresh - YYYY-MM-DD - configured_scan_count - last_seen_before:string - last_scan_count_1 (1-10) - last_refresh - YYYY-MM-DD - configured_scan_count - first_seen_after:string - last_scan_count_1 (1-10) - last_refresh - YYYY-MM-DD - configured_scan_count - entity_uid:12345 - entity_type:string - ApiEndpoint, AppEndpoint, AutonomousSystem, AwsEC2Instance, AwsRdsDbInstance, AwsS3Bucket, AzureStorageAccount, AzureVirtualMachine, DnsRecord, Domain, EmailAddress, GcpApiGateway, GcpAppEngineApplication, GcpCloudFunction, GcpCloudSQLInstance, GcpComputeEngineInstance, GcpStorageBucket, GithubAccount, GithubRepository, IpAddress, Nameserver, NetBlock, NetworkService, SslCertificate, UniqueKeyword, UniqueToken, Uri - entity_name:string - scoped:true | false - severity:integer 1-5 - severity_lte:integer 1-5 - severity_gte:integer 1-5 - status_new:open or closed - status_detailed:string - open_triaged, open_in_progress, closed_mitigated, closed_resolved, closed_duplicate, closed_out_of_scope, closed_benign, closed_risk_accepted, closed_false_positive, closed_no_reproduce, closed_tracked_externally - [Get Detail](https://gtidocs.readme.io/reference/get_issues-id.md): Gets an individual entity's details - [Set Status](https://gtidocs.readme.io/reference/post_issues-id-status.md): Set status on an individual entity. The body takes a json input with a single 'status' field. Values for Payload status: - open_new - open_triaged - open_in_progress - closed_resolved - closed_duplicate - closed_out_of_scope - closed_benign - closed_risk_accepted - closed_false_positive - closed_no_repro - closed_tracked_externally - closed - [Get Entity point in time](https://gtidocs.readme.io/reference/get_time-series-point-in-time-entities-uid.md): Returns entity details of an entity for a specific point in time. | **Key** | Format | **Notes** | | --- | --- | --- | | uid | string | required

id or uuid from [https://asm-api.advantage.mandiant.com/search/entities/:search_string](https://asm-api.advantage.mandiant.com/search/entities/:search_string) | | point_in_time | YYYY-MM-DD or ISO8601 timestamp string (UTC) | required

Results from from [https://asm-api.advantage.mandiant.com/time_series/points_in_time/entities/:uid?start=](https://asm-api.advantage.mandiant.com/time_series/points_in_time/entities/:uid?start=)


Example: 2023-06-26T09:50:20Z, or YYYY-MM-DD | - [Get Entity points in time](https://gtidocs.readme.io/reference/get_time-series-points-in-time-entities-uid.md): Returns the dates of when an entity was seen. - [Get Issue points in time](https://gtidocs.readme.io/reference/get_time-series-points-in-time-issues-uid.md): Returns the dates of when an issue was seen. - [Get Issue point in time](https://gtidocs.readme.io/reference/get_time-series-point-in-time-issues-uid.md): Returns issue details for issues associated with an entity at a specific point in time. | key | Format | **Notes** | | --- | --- | --- | | property | status, last_seen | required | | property_end_value_filter | string | optional
If provided, the result set will be filtered to only return results where the property value at the end point in time is equal to the provided filter value. | | transition | changed, unchanged, stagnated | required

changed means the property had more than one value over the time period

Example: 1, 2, 3, 4

unchanged means the property had only one value over the time period

Example: 1, 1, 1, 1

stagnated means the property initially was changing but ended up unchanged (more than one consecutive trailing value are the same)

Example: 1, 2, 3, 3 | | start | ISO8601 timestamp string (UTC) | required

Example: 2023-06-16T09:50:20Z | | end | ISO8601 timestamp string (UTC) | required

Example: 2023-06-26T09:50:20Z | - [Search Technologies](https://gtidocs.readme.io/reference/get_search-technologies-search-string.md): Search Endpoint for all technology data. If no operator is used, "name" field is searched Valid Search Keywords ('**search_string' parameter)**: - collection:intrigue_123k221 - name:google_analytics - label:wordpress_plugin - last_seen_after:string - last_scan_count_1 (1-10) - last_refresh - configured_scan_count - YYYY-MM-DD - last_seen_before:string - last_scan_count_1 (1-10) - last_refresh - configured_scan_count - YYYY-MM-DD - first_seen_after:string - last_scan_count_1 (1-10) - last_refresh - configured_scan_count - YYYY-MM-DD - cpe_type:application or service, hardware, os - product:text - vendor:google - [Index](https://gtidocs.readme.io/reference/get_notes-item-type-item-uid.md): Lists all notes on an entity or issue. - [Create](https://gtidocs.readme.io/reference/post_notes-item-type-item-uid.md): Creates a note on an entity or issue. - [Delete](https://gtidocs.readme.io/reference/delete_notes-item-type-item-uid-note-uid.md): Deletes all notes on an entity or issue. - [Index](https://gtidocs.readme.io/reference/get_tags-item-type-item-uid.md): Lists all tags on an entity or issue. - [Create](https://gtidocs.readme.io/reference/post_tags-item-type-item-uid.md): Creates a tag on an entity or issue. - [Delete](https://gtidocs.readme.io/reference/delete_tags-item-type-item-uid-tag-name.md): Deletes a tag on an issue - [Index](https://gtidocs.readme.io/reference/get_user-collections-collection-uuid-user-entities.md): endpoint to list user entities / seeds - [Create](https://gtidocs.readme.io/reference/post_user-collections-collection-uuid-user-entities.md): endpoint which creates a user entity (could be a seed or not) for a collection - [Delete](https://gtidocs.readme.io/reference/delete_entities-entity-id.md): delete a user entity / seed - [Create](https://gtidocs.readme.io/reference/post_projects-uuid-integrations.md): Attack Surface Management currently supports the following integrations, Use the samples in the post body: _**GCP**_: ``` json { "name": "Test GCP Integration", "secrets": { "service_account_email": "Email.Address@Service-Account-here.com" }, "type": "GcpCredential" } ``` **Jira:** ``` json { "name": "Test JIRA Integration", "secrets": { "jira_api_key": "APIKEYHERE", "host": "hostname.com", "username": "Email.Address@here.com" }, "type": "jira" } ``` **Azure:** ``` json { "name": "Test Azure Integration", "secrets": { "tenant_id": "TenantIdhere" }, "type": "azure" } ``` **Github:** ``` json { "name": "Test github Integration", "secrets": { "github_access_token": "TokenHere" }, "type": "github" } ``` **Akamai:** ``` json { "name": "Test akamai Integration", "secrets": { "client_secret": "SecretHere", "host": "hosthere.com", "access_token": "AccessTokenHere", "client_token": "ClientTokenHere" }, "type": "akamai" } ``` **Godaddy:** ``` json { "name": "Test godaddy Integration", "secrets": { "api_key": "KeyHere", "api_secret": "SecretHere" }, "type": "godaddy" } ``` **Cloudflare:** ``` json { "name": "Test cloudflare Integration", "secrets": { "cloudflare_api_key": "APIKeyHere" }, "type": "cloudflare" } ``` **AWS Roles:** ``` json { "name": "Test AwsCredential Integration", "secrets": { "aws_role_arn": "RoleHere" }, "type": "AwsCredential" } ``` **AWS Keys:** ``` json { "name": "Test AwsCredential Integration", "secrets": { "aws_access_key_id": "KeyHere", "aws_secret_access_key": "SecretHere", }, "type": "AwsCredential" } ``` - [Index](https://gtidocs.readme.io/reference/get_projects-uuid-integrations.md): List all integrations configured for the project. - [Jira projects](https://gtidocs.readme.io/reference/get_projects-uuid-integrations-jira-projects.md) - [Destroy](https://gtidocs.readme.io/reference/delete_integrations-uuid.md): Delete an existing integration. This cannot be undone! To obtain a UUID for your integration, please see the GET Index query first: ![](https://content.pstmn.io/f577cdca-1f0b-49b5-9515-14872c74b4ca/SW50ZWdyYXRpb24gRGVzdHJveS5wbmc=) - [Index](https://gtidocs.readme.io/reference/get_integration-collections.md): Returns current integrations assigned to collections. - [Destroy](https://gtidocs.readme.io/reference/delete_integration-collections-uuid.md): Removes integration from a Collection. Integration will not be deleted from the platform. UUID is of the integration_collection. found in /api/v3/asm/integration_collections. This value is also displayed in the post Create /api/v3/asm/user_collections/:collection_uuid/integration_collections - [Create](https://gtidocs.readme.io/reference/post_user-collections-collection-uuid-integration-collections.md): Assigns an existing integration to a collection. To create an integration, see Integrations Section. "integration_uuid" within the body can be found in /api/v3/asm/projects/:uuid/integrations - [Entities List](https://gtidocs.readme.io/reference/get_library-entities.md): Returns types of entities. - [Entities Stats](https://gtidocs.readme.io/reference/get_library-entities-stats.md) - [Issues List](https://gtidocs.readme.io/reference/get_library-issues.md): View list of all issue types. Change Page value to display next 100 issues. - [Issues List - Specific Isssue](https://gtidocs.readme.io/reference/get_library-issues-issue-name.md): Send a specific entity type, and get the definition - [Issues Stats](https://gtidocs.readme.io/reference/get_library-issues-stats.md): Statistics about the issues, Total count, Count by category: - [Tasks List](https://gtidocs.readme.io/reference/get_library-tasks.md): View all tasks. Change Page value to display next 100 - [Tasks Stats](https://gtidocs.readme.io/reference/get_library-tasks-stats.md): Returns a list of current task type count, and count by Author: - [Fingerprints List](https://gtidocs.readme.io/reference/get_library-fingerprints.md): Returns Technology fingerprints from Library. - [Fingerprint Stats](https://gtidocs.readme.io/reference/get_library-fingerprints-stats.md): Statistics about the Fingerprint (ident) capabilities - [Issues List - Export as CSV](https://gtidocs.readme.io/reference/get_library-issues-export-csv.md) - [Tasks List - Export as CSV](https://gtidocs.readme.io/reference/get_library-tasks-export-csv.md) - [Catalog Stats](https://gtidocs.readme.io/reference/get_library-catalog-stats.md): Statistics about the Catalog - [DTM Pagination](https://gtidocs.readme.io/reference/dtm-pagination.md) - [List alerts](https://gtidocs.readme.io/reference/get-alerts.md): Get alerts for the current organization. This API uses the next link header to provide the URI of the next page of results. When fetching subsequent pages, only use the link header URI. - [Get an existing alert by its ID](https://gtidocs.readme.io/reference/get-alerts-id.md): Get an existing alert by ID. - [Update field(s) of an alert](https://gtidocs.readme.io/reference/patch-alerts-id.md): Updates the specified fields for an existing alert. Note that not all fields of an alert are writable. - [List child alerts for a given aggregated alert bucket](https://gtidocs.readme.io/reference/get-agg-child-alerts.md): Get child alerts for a given bucket. This API uses the next link header to provide the URI of the next page of results. When fetching subsequent pages, only use the link header URI. - [Synchronously bulk update alerts](https://gtidocs.readme.io/reference/post-alerts-bulk.md): Bulk apply updates to alerts. The only updatable fields are those available via the PATCH alert API. Updates occur synchronously. - [Asynchronously bulk update alerts using query params to target the alerts](https://gtidocs.readme.io/reference/post-alerts-bulk-apply.md): Asynchronously update alerts using query params to taget which alerts will be updated. - [Update the analysis text on an alert](https://gtidocs.readme.io/reference/put-alert-analysis.md): Update the analysis text on an alert object. The empty string will clear out existing analysis. Markdown format can be used. - [List the file attachments for the alert](https://gtidocs.readme.io/reference/get-alert-analysis-attachments.md): List the file attachments for a given alert. - [Upload attachments to an alert's analysis](https://gtidocs.readme.io/reference/post-alert-analysis-attachment.md): Upload one or more files to the alert's analysis. The following file type extensions are supported; doc, docx, xls, xlsx, pdf, png, zip, csv, txt - [Delete a file attachment from an alert](https://gtidocs.readme.io/reference/delete-alert-attachment.md): Delete an existing file attachment from an alert. - [Download a file attachment from an alert](https://gtidocs.readme.io/reference/download-alert-analysis-attachment.md): Download the file attachment from an alert. - [List audit records for a given alert](https://gtidocs.readme.io/reference/get-alert-audit.md): Get alert audit records for a given alert. This API uses the next link header to provide the URI of the next page of results. When fetching subsequent pages, only use the link header URI. - [List alert audit records](https://gtidocs.readme.io/reference/get-all-alert-audit.md): Get alert audit records. This API uses the next link header to provide the URI of the next page of results. When fetching subsequent pages, only use the link header URI. - [List monitors](https://gtidocs.readme.io/reference/get-monitors.md): Lists all monitors belonging to the current organization. Pagination is supported and the URI to next page of results is provided in the response link header. If fetching subsequent pages, only use the next link header provided in the previous page of results. - [Create a new monitor](https://gtidocs.readme.io/reference/post-monitor.md): Create a new monitor. - [Delete an existing monitor](https://gtidocs.readme.io/reference/delete-monitor-id.md): Delete an existing monitor by its ID. - [Get a monitor by its ID](https://gtidocs.readme.io/reference/get-monitor-id.md): Get an existing monitor by ID. - [Partial update an existing monitor](https://gtidocs.readme.io/reference/patch-monitor-id.md): Partial update an existing monitor with the fields in the request body. This request only updates the specified fields in the request body; the remaining fields of the existing monitor are unchanged. - [Update an existing monitor](https://gtidocs.readme.io/reference/put-monitor-id.md): Update an existing monitor by replacing all its fields with the given body. - [Asynchronously backfill alerts for new domains](https://gtidocs.readme.io/reference/patch-monitor-backfill.md): Asynchronously backfill alerts for the new domains added in the latest version of the monitor (when compared to it's previous version) using the time range specified. This API is only supported for monitors created from the Compromised Credential monitor template and will create at most 10,000 alerts. - [Asynchronously backfill alerts for the monitor](https://gtidocs.readme.io/reference/post-monitor-backfill.md): Begin a new alert backfill for the current monitor using the time range specified. This API is only supported for monitors created from the Compromised Credential monitor template and will create at most 10,000 alerts. - [Estimate how many alerts will be created for the backfill of an updated monitor](https://gtidocs.readme.io/reference/patch-monitor-backfill-estimate.md): Estimate how many alerts will be created when backfilling the given updated monitor. Only newly added domains are considered for backfill. Backfill is only applicable for monitors created from the Compromised Credential monitor template. - [Estimate how many alerts will be created for the backfill of a newly created monitor](https://gtidocs.readme.io/reference/post-monitor-backfill-estimate.md): Estimate how many alerts will be created when backfilling the given new monitor. Backfill is only applicable for monitors created from the Compromised Credential monitor template. - [List monitor templates for top DTM use cases](https://gtidocs.readme.io/reference/get-monitor-templates.md): Lists all monitor templates for top DTM use cases. Templates are intended to be the starting place for montior creation based on a specific use case. - [List email settings](https://gtidocs.readme.io/reference/list-settings-email.md): List email settings for your organization. - [Create email settings](https://gtidocs.readme.io/reference/post-settings-email.md): Create email settings for your organization. Note that only 1 email setting per organization is allowed. - [Delete email settings](https://gtidocs.readme.io/reference/delete-settings-email-id.md): Delete existing email settings by ID. - [Fetch an email setting](https://gtidocs.readme.io/reference/get-settings-email-id.md): Get email settings by ID. - [Update email settings](https://gtidocs.readme.io/reference/patch-settings-email-id.md): Update existing email settings for the properties given in the request body. All other properties remain unchanged. - [Reverify one or more email recipients](https://gtidocs.readme.io/reference/post-settings-email-id-reverify.md): Reverify existing email settings recipients by setting their status to "pending" and resending the email address verification email. This can be used if existing recipients did not verify their email address before the verify link expired in thier verification email. - [List verified domains for the current organization](https://gtidocs.readme.io/reference/get-verified-domains.md): Lists all verified domains. Pagination is supported and the URI to next page of results is provided in the response link header. If fetching subsequent pages, only use the next link header provided in the previous page of results. - [Add a new verified domain](https://gtidocs.readme.io/reference/post-domain.md): Add a new verified domain. - [Delete an existing verified domain.](https://gtidocs.readme.io/reference/delete-domain-id.md): Delete an existing verified domain by its ID. - [Get a verified domain by ID](https://gtidocs.readme.io/reference/get-verified-domain.md): Get a verified domain by its ID. - [Perform a synchronous verification check for the domain's TXT record code.](https://gtidocs.readme.io/reference/reverify-domain-id.md): Perform a check of the domains TXT record verification code. - [Add new verified domains](https://gtidocs.readme.io/reference/post-domain-bulk.md): Add multiple verified domains. - [Download all verified domains with their TXT verification code in CSV format](https://gtidocs.readme.io/reference/get-verified-domains-csv.md): Lists all verified domains in CSV format suitable for getting an inventory of the domain TXT record codes to verify. - [Retrieve an indexed document by its type and ID](https://gtidocs.readme.io/reference/get-docs-type-id.md): A read-only endpoint that fetches an indexed document (optionally) along with its topics and labels. - [Fetch the labels for an existing document](https://gtidocs.readme.io/reference/get-docs-type-id-labels.md): A read-only endpoint to fetch the labels for an existing document indexed in our system. - [Fetch the topics for an existing document](https://gtidocs.readme.io/reference/get-docs-type-id-topics.md): A read-only endpoint to fetch the topics for an existing document saved in the system. - [Search for documents](https://gtidocs.readme.io/reference/post-docs-search.md): Search documents using Lucene syntax. Search requests are limited to 60 seconds in duration. Requests exceeding this time will be terminated and should be scoped using date ranges. - [Search graphs](https://gtidocs.readme.io/reference/graphs.md) - [Create a graph](https://gtidocs.readme.io/reference/create-graphs.md) - [Delete a graph](https://gtidocs.readme.io/reference/graphs-delete.md) - [Get a graph object](https://gtidocs.readme.io/reference/graphs-info.md) - [Update a graph object](https://gtidocs.readme.io/reference/graphs-update.md) - [Get comments on a graph](https://gtidocs.readme.io/reference/get-graph-comments.md) - [Add a comment to a graph](https://gtidocs.readme.io/reference/post-graphs-comments.md) - [Get object descriptors related to a graph](https://gtidocs.readme.io/reference/graphs-relationships-ids.md) - [Get objects related to a graph](https://gtidocs.readme.io/reference/graphs-relationships.md) - [Get users and groups that can edit a graph](https://gtidocs.readme.io/reference/graphs-editors.md) - [Grant users and groups permission to edit a graph](https://gtidocs.readme.io/reference/graphs-add-editor.md) - [Revoke edit graph permissions from a user or group](https://gtidocs.readme.io/reference/graphs-delete-editor.md) - [Check if a user or group can edit a graph](https://gtidocs.readme.io/reference/graphs-check-editor.md) - [Revoke view permission from a user or group](https://gtidocs.readme.io/reference/graphs-delete-viewer.md) - [Check if a user or group can view a graph](https://gtidocs.readme.io/reference/graphs-check-viewer.md) - [Get users and groups that can view a graph](https://gtidocs.readme.io/reference/graphs-viewers.md) - [Grant users and groups permission to see a graph](https://gtidocs.readme.io/reference/graphs-add-viewer.md) - [Delete a user](https://gtidocs.readme.io/reference/delete-user-id.md) - [Get a user object](https://gtidocs.readme.io/reference/user.md) - [Update a user object](https://gtidocs.readme.io/reference/patch-user-id.md) - [Get object descriptors related to a user](https://gtidocs.readme.io/reference/get-users-relationships-ids.md) - [Get objects related to a user](https://gtidocs.readme.io/reference/users-relationships.md) - [Get a group object](https://gtidocs.readme.io/reference/groups.md) - [Update a group object](https://gtidocs.readme.io/reference/patch-group.md) - [Get administrators for a group](https://gtidocs.readme.io/reference/get-group-administrators.md) - [Manage Roles](https://gtidocs.readme.io/reference/patch-group-users-roles.md) - [Check if a user is a group admin](https://gtidocs.readme.io/reference/check-user-group-administrator.md) - [Get group users](https://gtidocs.readme.io/reference/get-group-users.md) - [Add users to a group](https://gtidocs.readme.io/reference/update-group-users.md) - [Remove a user from a group](https://gtidocs.readme.io/reference/delete-user-from-group.md) - [Check if a user is a group member](https://gtidocs.readme.io/reference/check-user-in-group.md) - [Get object descriptors related to a group](https://gtidocs.readme.io/reference/groups-relationships-ids.md) - [Get objects related to a group](https://gtidocs.readme.io/reference/groups-relationships.md) - [Get SAML configuration details of a group.](https://gtidocs.readme.io/reference/groups-get-samlconfig.md) - [Update SAML configuration of a group.](https://gtidocs.readme.io/reference/groups-patch-samlconfig.md) - [Delete SAML configuration of a group.](https://gtidocs.readme.io/reference/groups-del-samlconfig.md) - [Get a user’s API usage](https://gtidocs.readme.io/reference/user-api-usage.md) - [Get a group’s API usage](https://gtidocs.readme.io/reference/group-api-usage.md) - [Get a group's usage per feature](https://gtidocs.readme.io/reference/get-group-usage.md) - [Get Service Accounts of a group](https://gtidocs.readme.io/reference/get-service-accounts-of-a-group.md) - [Create a new Service Account](https://gtidocs.readme.io/reference/create-a-new-service-account.md) - [Get a Service Account object](https://gtidocs.readme.io/reference/get-a-service-account-object.md) - [Get Activity Logs](https://gtidocs.readme.io/reference/get-activity-log.md) - [File intelligence feed](https://gtidocs.readme.io/reference/file-intelligence-feed.md) - [Get a hourly file feed batch](https://gtidocs.readme.io/reference/feeds-file-hourly.md) - [Get a per-minute file feed batch](https://gtidocs.readme.io/reference/feeds-file.md) - [Download a file published in the file feed](https://gtidocs.readme.io/reference/file-feed-download.md) - [Sandbox analyses feed](https://gtidocs.readme.io/reference/sandbox-analyses-feed.md) - [Get an hourly file behaviour feed batch](https://gtidocs.readme.io/reference/feeds-file-behaviour-hourly.md) - [Get a per-minute file behaviour feed batch](https://gtidocs.readme.io/reference/feeds-file-behaviour.md) - [Get the EVTX file generated during a file’s behavior analysis](https://gtidocs.readme.io/reference/file-behaviour-feed-evtx.md) - [Get a file behaviour's detailed HTML report](https://gtidocs.readme.io/reference/file-behaviour-feed-html.md) - [Get the memdump file generated during a file’s behavior analysis](https://gtidocs.readme.io/reference/file-behaviour-feed-memdump.md) - [Get the PCAP file generated during a file’s behavior analysis](https://gtidocs.readme.io/reference/file-behaviour-feed-pcap.md) - [Domain intelligence feed](https://gtidocs.readme.io/reference/domain-intelligence-feed.md) - [Get an hourly domain feed batch](https://gtidocs.readme.io/reference/feedsdomainshourly2time.md) - [Get a minutely domain feed batch](https://gtidocs.readme.io/reference/feedsdomains2time.md) - [IP intelligence feed](https://gtidocs.readme.io/reference/ip-intelligence-feed.md) - [Get an hourly IP address feed batch](https://gtidocs.readme.io/reference/feedsip_addresseshourly2time.md) - [Get a minutely IP address feed batch](https://gtidocs.readme.io/reference/feedsip_addressestime.md) - [URL intelligence feed](https://gtidocs.readme.io/reference/url-intelligence-feed.md) - [Get an hourly URL feed batch](https://gtidocs.readme.io/reference/feeds-url-hourly.md) - [Get a minutely URL feed batch](https://gtidocs.readme.io/reference/feeds-url.md) - [Generate a personal Authorization Token](https://gtidocs.readme.io/reference/get-auth-token.md) - [List provisioned Categorised Threat Lists](https://gtidocs.readme.io/reference/list-provisioned-threat-lists.md) - [Get the latest Threat List](https://gtidocs.readme.io/reference/get-latest-threat-list.md) - [Get an hourly Threat List](https://gtidocs.readme.io/reference/get-hourly-threat-list.md) - [Export Dashboard Data](https://gtidocs.readme.io/reference/dashboards-download.md) - [Key Concepts](https://gtidocs.readme.io/reference/ti-key-concepts.md) - [Get Started](https://gtidocs.readme.io/reference/ti-get-started.md) - [Authentication](https://gtidocs.readme.io/reference/ti-authentication.md): This is your first endpoint! Edit this page to start documenting your API. - [Overview](https://gtidocs.readme.io/reference/alerts-overview.md) - [Get Alert](https://gtidocs.readme.io/reference/get-alert.md): Get an alert by name. - [List Alerts](https://gtidocs.readme.io/reference/list-alerts.md): Get a list of alerts that meet the filter criteria. - [Enumerate Facets](https://gtidocs.readme.io/reference/enumerate-alert-facets.md): EnumerateAlertFacets returns the facets and the number of alerts that meet the filter criteria and have that value for each facet. - [Mark as Benign](https://gtidocs.readme.io/reference/markalertasbenign.md): Marks an alert as benign - BENIGN. - [Mark as Duplicate](https://gtidocs.readme.io/reference/markalertasduplicate.md): Marks an alert as a duplicate of another alert. - DUPLICATE. - [Mark as Escalated](https://gtidocs.readme.io/reference/markalertasescalated.md): Marks an alert as escalated - ESCALATED. - [Mark as False Positive](https://gtidocs.readme.io/reference/markalertasfalsepositive.md): Marks an alert as a false positive - FALSE_POSITIVE. - [Mark as Not Actionable](https://gtidocs.readme.io/reference/markalertasnotactionable.md): Marks an alert as not actionable - NOT_ACTIONABLE. - [Mark as Read](https://gtidocs.readme.io/reference/markalertasread.md): Marks an alert as read - READ. - [Mark as Resolved](https://gtidocs.readme.io/reference/markalertasresolved.md): Marks an alert to closed state - RESOLVED. - [Mark as Triaged](https://gtidocs.readme.io/reference/markalertastriaged.md): Marks an alert as triaged - TRIAGED. - [Mak as Externally Tracked](https://gtidocs.readme.io/reference/markalertastrackedexternally.md): Marks an alert as tracked externally - TRACKED_EXTERNALLY. - [Overview](https://gtidocs.readme.io/reference/alert-documents-overview.md) - [Get Document](https://gtidocs.readme.io/reference/get-alert-document.md): Gets a specific document associated with an alert. - [Overview](https://gtidocs.readme.io/reference/configurations-overview.md) - [Get Configuration](https://gtidocs.readme.io/reference/get-configuration.md): Get a configuration by name. - [List Configurations](https://gtidocs.readme.io/reference/list-configurations.md): Get a list of configurations that meet the filter criteria. - [Upsert Configuration](https://gtidocs.readme.io/reference/upsert-configuration.md): Creates or updates a configuration. - [Overview](https://gtidocs.readme.io/reference/configuration-revisions-overview.md) - [List Revisions](https://gtidocs.readme.io/reference/list-configuration-revisions.md): List configuration revisions that meet the filter criteria. - [Overview](https://gtidocs.readme.io/reference/findings-overview.md) - [Get finding](https://gtidocs.readme.io/reference/get-finding.md): Get a finding by name. - [List Findings](https://gtidocs.readme.io/reference/list-findings.md): Get a list of findings that meet the filter criteria. - [Search Findings](https://gtidocs.readme.io/reference/search-findings.md): SearchFindings is a more powerful version of ListFindings that supports complex queries like "findings for issues" using functions such as `has_issue` and `has_asset` in the query string. Example to search for findings for a specific issue: `has_issue("name=\"vaults/vault-12345/issues/issue-12345\"")`) - [Flows](https://gtidocs.readme.io/reference/flows.md): API endpoints for managing and executing Agentic Flows. - [List Flows](https://gtidocs.readme.io/reference/list-flows.md): Retrieve a list of Agentic Flows. - [Create a Flow](https://gtidocs.readme.io/reference/create-flow.md): Create a new Agentic Flow. - [Get a Flow](https://gtidocs.readme.io/reference/info-flow.md): Retrieve details of a specific Agentic Flow. - [Update a Flow](https://gtidocs.readme.io/reference/update-flow.md): Update an existing Agentic Flow. - [Delete a Flow](https://gtidocs.readme.io/reference/delete-flow.md): Delete an existing Agentic Flow. - [Run a Flow now](https://gtidocs.readme.io/reference/execute-flow.md): Trigger an immediate manual run of an Agentic Flow. - [Get objects related to a Flow](https://gtidocs.readme.io/reference/get-flow-relationships.md): Retrieve objects related to a specific Agentic Flow. - [Get object descriptors related to a Flow](https://gtidocs.readme.io/reference/get-flow-related-descriptors.md): Retrieve descriptors (type + id) of objects related to an Agentic Flow. - [Unsubscribe from a Flow's email notifications](https://gtidocs.readme.io/reference/unsubscribe-flow.md): Unsubscribe an email address from Flow notifications. - [Flow Executions](https://gtidocs.readme.io/reference/flow-executions.md): API endpoints for monitoring and managing Agentic Flow Executions. - [List Flow Executions](https://gtidocs.readme.io/reference/list-flow-executions.md): Retrieve a list of Agentic Flow Executions. - [Get a Flow Execution](https://gtidocs.readme.io/reference/info-flow-execution.md): Retrieve details of a specific Flow Execution. - [Get objects related to a Flow Execution](https://gtidocs.readme.io/reference/get-flow-execution-relationships.md): Retrieve objects related to a specific Flow Execution. - [Get object descriptors related to a Flow Execution](https://gtidocs.readme.io/reference/get-flow-execution-related-descriptors.md): Retrieve descriptors (type + id) of objects related to a Flow Execution. - [Cancel a Flow Execution](https://gtidocs.readme.io/reference/cancel-flow-execution.md): Cancel an in-progress Flow Execution. - [Sessions](https://gtidocs.readme.io/reference/sessions.md): Overview of Google Threat Intelligence agentic chat sessions and authentication. - [List sessions](https://gtidocs.readme.io/reference/list-sessions.md) - [Get a session](https://gtidocs.readme.io/reference/get-session.md) - [Get a session share token](https://gtidocs.readme.io/reference/get-session-token.md) - [Create a session from a shared token](https://gtidocs.readme.io/reference/create-session-from-token.md) - [Post a message to a new session](https://gtidocs.readme.io/reference/create-session.md) - [Post a message to an existing session](https://gtidocs.readme.io/reference/post-session-message.md) - [Update a session](https://gtidocs.readme.io/reference/update-session.md) - [Delete a session](https://gtidocs.readme.io/reference/delete-session.md) - [Activity Log](https://gtidocs.readme.io/reference/activity-log.md) - [Agentic Session](https://gtidocs.readme.io/reference/agentic-session-object.md): Information about Google Threat Intelligence Agentic Sessions - [Audit](https://gtidocs.readme.io/reference/audit-object.md): Tracks basic CRUD facts. - [ConfidenceLevel](https://gtidocs.readme.io/reference/confidencelevel-object.md): Enum to indicate the level of confidence in a verdict. - [RelevanceAnalysis](https://gtidocs.readme.io/reference/relevanceanalysis-object.md): Structured relevance analysis for a threat. - [SeverityAnalysis](https://gtidocs.readme.io/reference/severityanalysis-object.md): Structured severity analysis for a threat. - [Analyses](https://gtidocs.readme.io/reference/analyses-object.md): Partner contributors' analyses for files and URLs. - [🔀 item](https://gtidocs.readme.io/reference/item.md): Item being analysed - [Attack Tactics](https://gtidocs.readme.io/reference/object-attack-tactics.md): Information about attack tactics - [🔀 attack_techniques](https://gtidocs.readme.io/reference/attack_techniques.md): Attack tactic's techniques. - [Attack Techniques](https://gtidocs.readme.io/reference/object-attack-techniques.md): Information about attack techniques - [🔀 attack_tactics](https://gtidocs.readme.io/reference/attack_tactics.md): Attack technique's tactics. - [🔀 parent_technique](https://gtidocs.readme.io/reference/parent_technique.md): Attack technique's parent technique. - [🔀 revoking_technique](https://gtidocs.readme.io/reference/revoking_technique.md): Attack technique's revoking technique. - [🔀 subtechniques](https://gtidocs.readme.io/reference/subtechniques.md): Attack technique's sub-techniques. - [🔀 threat_actors](https://gtidocs.readme.io/reference/attack-techniques-threat_actors.md): Attack technique's threat actors - [Campaign](https://gtidocs.readme.io/reference/campaign-object.md): Information about campaigns - [Comments](https://gtidocs.readme.io/reference/comment-object.md): comment object - [🔀 author](https://gtidocs.readme.io/reference/comment-object-author.md): Comment votes. - [Country Profile](https://gtidocs.readme.io/reference/country-profile-object.md) - [Dark Web Communication](https://gtidocs.readme.io/reference/dark-web-communication-object.md) - [Dark Web Communication Channel](https://gtidocs.readme.io/reference/dark-web-communication-channel-object.md) - [Dark Web Conversation Thread](https://gtidocs.readme.io/reference/dark-web-conversation-thread-object.md) - [Dark Web Service](https://gtidocs.readme.io/reference/dark-web-service-object.md) - [Dark Web User Profile](https://gtidocs.readme.io/reference/dark-web-user-profile-object.md) - [Domains](https://gtidocs.readme.io/reference/domains-object.md): Along with URLs, Google Threat Intelligence stores information related network locations, as domains and IP addresses. Within this section we will go through the information provided by Domain objects. - [🔀 communicating_files](https://gtidocs.readme.io/reference/domain-communicating_files.md) - [🔀 downloaded_files](https://gtidocs.readme.io/reference/domain-downloaded_files.md) - [🔀 referrer_files](https://gtidocs.readme.io/reference/domain-referrer_files.md): Files containing the domain on its strings. - [🔀 graphs](https://gtidocs.readme.io/reference/domains-object-graphs.md) - [🔀 resolutions](https://gtidocs.readme.io/reference/domain-resolutions.md): Domain's IP resolutions. - [🔀 siblings](https://gtidocs.readme.io/reference/siblings.md) - [🔀 comments](https://gtidocs.readme.io/reference/domain-comments.md): Comments in Domain objects - [🔀 related_comments](https://gtidocs.readme.io/reference/domain-related_comments.md): Comments posted in related objects - [🔀 historical_ssl_certificates](https://gtidocs.readme.io/reference/domain-historical_ssl_certificates.md): All SSL certificates that have been associated with the domain at some moment in time. - [🔀 historical_whois](https://gtidocs.readme.io/reference/domain-historical_whois.md): All whois records that have been associated with the domain at some moment in time. - [🔀 immediate_parent](https://gtidocs.readme.io/reference/immediate_parent.md): Domain's immediate parent. - [🔀 parent](https://gtidocs.readme.io/reference/parent.md): Domain's parent. - [🔀 subdomains](https://gtidocs.readme.io/reference/subdomains.md): Domain's subdomains. - [🔀 urls](https://gtidocs.readme.io/reference/domain-urls.md): Domain's URLs. - [🔀 caa_records](https://gtidocs.readme.io/reference/caa_records.md): Records CAA for the domain. - [🔀 cname_records](https://gtidocs.readme.io/reference/cname_records.md): Records CNAME for the domain. - [🔀 mx_records](https://gtidocs.readme.io/reference/mx_records.md): Records MX for the domain. - [🔀 ns_records](https://gtidocs.readme.io/reference/ns_records.md): Records NS for the domain. - [🔀 soa_records](https://gtidocs.readme.io/reference/soa_records.md): Records SOA for the domain. - [🔀 votes](https://gtidocs.readme.io/reference/domains-object-votes.md): Domain's votes. - [🔀🧑‍💻 user_votes](https://gtidocs.readme.io/reference/domains-object-user_votes.md): Domain's user votes. - [🔀 collections](https://gtidocs.readme.io/reference/domains-object-collections.md): Collections containing this domain. - [🔀 related_threat_actors](https://gtidocs.readme.io/reference/domains-object-related_threat_actors.md): Related Threat Actors for a given domain. - [Files](https://gtidocs.readme.io/reference/file-object.md): Information about files - [exiftool](https://gtidocs.readme.io/reference/file-object-exiftool.md): information about EXIF metadata from files. - [ssdeep](https://gtidocs.readme.io/reference/file-object-ssdeep.md): CTPH hash of the file content. - [authentihash](https://gtidocs.readme.io/reference/file-object-authentihash.md): hash to verify PE files. - [trid](https://gtidocs.readme.io/reference/file-object-trid.md): file type identification tool. - [pe_info](https://gtidocs.readme.io/reference/file-object-pe-info.md): Microsoft Windows Portable Executable file format info. - [signature_info](https://gtidocs.readme.io/reference/file-object-signature-info.md): Information about signed PE and Mach-O files. - [androguard](https://gtidocs.readme.io/reference/file-object-androguard.md): information about Android files. - [asf_info](https://gtidocs.readme.io/reference/file-object-asf-info.md): information about Microsoft Advanced Streaming/Systems Format (ASF) files. - [rombios_info](https://gtidocs.readme.io/reference/file-object-rombios-info.md): information about BIOS, EFI, UEFI and related archives. - [class_info](https://gtidocs.readme.io/reference/file-object-class-info.md): information about Java .class bytecode files. - [bundle_info](https://gtidocs.readme.io/reference/file-object-bundle-info.md): information about compressed files. - [deb_info](https://gtidocs.readme.io/reference/file-object-deb-info.md): information about Debian packages. - [magic](https://gtidocs.readme.io/reference/file-object-magic.md): identification of files via magic number. - [dmg_info](https://gtidocs.readme.io/reference/file-object-dmg-info.md): information about mountable macOS disk images. - [elf_info](https://gtidocs.readme.io/reference/file-object-elf-info.md): information about Unix ELF files. - [image_code_injections](https://gtidocs.readme.io/reference/file-object-image-code-injections.md): code injection inside image files. - [ipa_info](https://gtidocs.readme.io/reference/file-object-ipa-info.md): information about iOS App Store Package files. - [jar_info](https://gtidocs.readme.io/reference/file-object-jar-info.md): information about Java Archive files. - [javascript_info](https://gtidocs.readme.io/reference/file-object-javascript-info.md): Information extracted out of Javascript files - [macho_info](https://gtidocs.readme.io/reference/file-object-macho-info.md): information about Apple MachO files. - [office_info](https://gtidocs.readme.io/reference/file-object-office-info.md): Microsoft Office files structure information. - [openxml_info](https://gtidocs.readme.io/reference/file-object-openxml-info.md): Microsoft OpenXML files information. - [pdf_info](https://gtidocs.readme.io/reference/file-object-pdf-info.md): information about Adobe PDF files. - [packers](https://gtidocs.readme.io/reference/file-object-peid.md): identification of packers used by files. - [rtf_info](https://gtidocs.readme.io/reference/file-object-rtf-info.md): information about Microsoft Rich Text Format files. - [swf_info](https://gtidocs.readme.io/reference/file-object-swf-info.md): Information about Adobe Shockwave Flash files. - [isoimage_info](https://gtidocs.readme.io/reference/file-object-isoimage-info.md): information about ISO image files. - [dot_net_assembly](https://gtidocs.readme.io/reference/file-object-dot-net-assembly.md): information about Microsoft .NET files. - [dot_net_guids](https://gtidocs.readme.io/reference/file-object-dot-net-guids.md): identifiers for Microsoft .NET assemblies. - [password_info](https://gtidocs.readme.io/reference/file-object-password-info.md): Information from password protected files - [nsrl_info](https://gtidocs.readme.io/reference/file-object-nsrl-info.md): Whitelisted files from the NSRL. - [malware_config](https://gtidocs.readme.io/reference/file-object-malware-config.md): Malware configuration for certain malware families - [🔀 analyses](https://gtidocs.readme.io/reference/file-object-analyses.md): All analyses made for a given file. - [🔀 comments](https://gtidocs.readme.io/reference/file-object-comments.md): Comments in file objects. - [🔀 carbonblack_children](https://gtidocs.readme.io/reference/file-object-carbonblack-children.md): Files derived from the file according to Carbon Black. - [🔀 carbonblack_parents](https://gtidocs.readme.io/reference/file-object-carbonblack-parents.md): Files from where the file was derived according to Carbon Black. - [🔀 contacted_domains](https://gtidocs.readme.io/reference/file-object-contacted-domains.md): Domains contacted by a given file - [🔀 contacted_ips](https://gtidocs.readme.io/reference/file-object-contacted-ips.md): IP addresses contacted by a given file - [🔀 bundled_files](https://gtidocs.readme.io/reference/files-bundled_files.md): Files bundled within the file. - [🔀 bundled_files](https://gtidocs.readme.io/reference/file-object-bundled-files.md): Files bundled within the file. - [🔀 dropped_files](https://gtidocs.readme.io/reference/file-object-dropped-files.md) - [🔀 email_parents](https://gtidocs.readme.io/reference/file-object-email-parents.md): Email files containing the file. - [🔀 embedded_domains](https://gtidocs.readme.io/reference/file-object-embedded-domains.md): Domain names embedded in the file. - [🔀 embedded_ips](https://gtidocs.readme.io/reference/file-object-embedded-ips.md): IP addresses embedded in the file. - [🔀 embedded_urls](https://gtidocs.readme.io/reference/files-embedded_urls.md): IP addresses embedded in the file. - [🔀 embedded_urls](https://gtidocs.readme.io/reference/file-object-embedded-urls.md): IP addresses embedded in the file. - [🔀 execution_parents](https://gtidocs.readme.io/reference/file-object-execution-parents.md): Files that executed the file. - [🔀 graphs](https://gtidocs.readme.io/reference/file-object-graphs.md) - [🔀 memory_pattern_domains](https://gtidocs.readme.io/reference/file-object-memory-pattern-domains.md): Domains extracted from the memory pattern of the file. - [🔀 memory_pattern_ips](https://gtidocs.readme.io/reference/file-object-memory-pattern-ips.md): IPs extracted from the memory pattern of the file. - [🔀 memory_pattern_urls](https://gtidocs.readme.io/reference/file-object-memory-pattern-urls.md): URLs extracted from the memory pattern of the file. - [🔀 screenshots](https://gtidocs.readme.io/reference/file-object-screenshots.md): Screenshots obtained from the execution of the file. - [🔀 itw_urls](https://gtidocs.readme.io/reference/file-object-itw-urls.md): In the wild URLs from where the file has been downloaded. - [🔀 itw_domains](https://gtidocs.readme.io/reference/file-object-itw-domains.md): In the wild domain names from where the file has been downloaded. - [🔀 overlay_parents](https://gtidocs.readme.io/reference/file-object-overlay-parents.md): Files containing the file as an overlay. - [🔀 pcap_parents](https://gtidocs.readme.io/reference/file-object-pcap-parents.md): PCAP files that contain the file. - [🔀 pe_resource_parents](https://gtidocs.readme.io/reference/file-object-pe-resource-parents.md): PE files containing the file as a resource. - [🔀 similar_files](https://gtidocs.readme.io/reference/file-object-similar-files.md): Files similar to the file. - [🔀 sigma_analysis](https://gtidocs.readme.io/reference/file-object-sigma-analysis.md): Last Sigma analysis results. - [🔀 submissions](https://gtidocs.readme.io/reference/file-object-submissions.md): File submissions - [snort](https://gtidocs.readme.io/reference/file-object-snort.md): Matched Snort alerts in PCAP network captures. - [suricata](https://gtidocs.readme.io/reference/file-object-suricata.md): Matched suricata alerts for PCAP network captures. - [traffic_inspection](https://gtidocs.readme.io/reference/file-object-traffic-inspection.md): Traffic notions extracted from PCAP network captures. - [wireshark](https://gtidocs.readme.io/reference/file-object-wireshark.md): Metadata produced by Wireshark when acting on the file. - [vba_info](https://gtidocs.readme.io/reference/file-object-vba-info.md): VBA macros information - [🔀 compressed_parents](https://gtidocs.readme.io/reference/file-object-compressed-parents.md): File bundles from where the file was found inside. - [🔀 contacted_urls](https://gtidocs.readme.io/reference/file-object-contacted-urls.md): URL addresses contacted by a given file - [🔀 email_attachments](https://gtidocs.readme.io/reference/file-object-email-attachments.md): Files attached to a given email file. - [🔀 votes](https://gtidocs.readme.io/reference/file-object-votes.md): Votes for a given file - [monitor_info](https://gtidocs.readme.io/reference/file-object-monitor-info.md): Information from VT monitor - [html_info](https://gtidocs.readme.io/reference/file-object-html-info.md): Information from HTML files - [🔀 itw_ips](https://gtidocs.readme.io/reference/file-object-itw-ips.md): In the wild IP addresses from where the file has been downloaded. - [🔀 overlay_children](https://gtidocs.readme.io/reference/file-object-overlay-children.md): Files contained by the file as an overlay. - [🔀 pcap_children](https://gtidocs.readme.io/reference/file-object-pcap-children.md): PCAP files seen in the file. - [🔀 pe_resource_children](https://gtidocs.readme.io/reference/file-object-pe-resource-children.md): PE files contained by the file as a resource. - [telfhash](https://gtidocs.readme.io/reference/file-object-telfhash.md): File's Trend Micro ELF Hash (aka telfhash) - [tlsh](https://gtidocs.readme.io/reference/file-object-tlsh.md): Trend Micro's TLSH hash - [🔀 urls_for_embedded_js](https://gtidocs.readme.io/reference/file-object-urls-for-embedded-js.md): URLs where a given JS file is embedded - [known_distributors](https://gtidocs.readme.io/reference/file-object-known-distributors.md): Information about the file's distributors - [lnk_info](https://gtidocs.readme.io/reference/file-object-lnk-info.md): information about Microsoft Windows LNK files - [🔀🧑‍💻 user_votes](https://gtidocs.readme.io/reference/file-object-user-votes.md): Votes for a given file made by the current user - [popular_threat_classification](https://gtidocs.readme.io/reference/file-object-popular-threat-classification.md): Human readable names extracted from the AV verdicts and clustering hashes - [🔀 collections](https://gtidocs.readme.io/reference/file-object-collections.md): Collections containing this file. - [🔀 related_threat_actors](https://gtidocs.readme.io/reference/file-object-related-threat-actors.md): Related Threat Actors for a given file. - [crowdsourced_yara_results](https://gtidocs.readme.io/reference/file-object-crowdsourced-yara-results.md): YARA matches from crowdsourced rules. - [crowdsourced_ids_results](https://gtidocs.readme.io/reference/file-object-crowdsourced-ids-results.md): IDS matches for the file. - [crowdsourced_ids_stats](https://gtidocs.readme.io/reference/file-object-crowdsourced-ids-stats.md): IDS results stats. - [sigma_analysis_stats](https://gtidocs.readme.io/reference/file-object-sigma-analysis-stats.md): Sigma analysis stats for the file. - [sigma_analysis_results](https://gtidocs.readme.io/reference/file-object-sigma-analysis-results.md): Sigma results for the file. - [sandbox_verdicts](https://gtidocs.readme.io/reference/file-object-sandbox-verdicts.md): Sandbox verdicts for the file. - [detectiteasy](https://gtidocs.readme.io/reference/file-object-detectiteasy.md): File type identification tool. - [powershell_info](https://gtidocs.readme.io/reference/file-object-powershell-info.md) - [Files Behaviour](https://gtidocs.readme.io/reference/file-behaviour-summary-object.md): File behaviour reports - [verdicts](https://gtidocs.readme.io/reference/file-behaviour-object-verdicts.md): Verdicts to tag a sample from sandbox behaviour - [files_dropped](https://gtidocs.readme.io/reference/file-behaviour-object-files-dropped.md): Interesting files written to disk during execution. - [files_copied](https://gtidocs.readme.io/reference/file-behaviour-object-files-copied.md): Object that describes a file copy or move. - [permissions_checked](https://gtidocs.readme.io/reference/file-behaviour-object-permissions-checked.md): Records a query to see whether a given component/package/process/service has a particular permission. - [http_conversations](https://gtidocs.readme.io/reference/file-behaviour-object-http-conversations.md): HTTP Calls. - [dns_lookups](https://gtidocs.readme.io/reference/file-behaviour-object-dns-lookup.md): DNS queries - [ip_traffic](https://gtidocs.readme.io/reference/file-behaviour-object-ip-traffic.md): Outgoing connections seen during the execution of the given file. - [processes_tree](https://gtidocs.readme.io/reference/file-behaviour-object-processes-tree.md): Created processes during the execution of a given file. - [sms_sent](https://gtidocs.readme.io/reference/file-behaviour-object-sms-sent.md): Sent SMSs during the execution of the file under study. - [🔀 file](https://gtidocs.readme.io/reference/file-behaviour-object-file.md): File behaviour's file - [🔀 attack_techniques](https://gtidocs.readme.io/reference/file-behaviour-object-attack-techniques.md): File behaviour's ATT&CK techniques - [tags](https://gtidocs.readme.io/reference/file-behaviour-object-tags.md): Sandbox behavior tagged with a complex operation - [Flow](https://gtidocs.readme.io/reference/flow-object.md): Information about Agentic Flows - [Flow Execution](https://gtidocs.readme.io/reference/flow-execution-object.md): Information about Agentic Flow Executions - [Graphs](https://gtidocs.readme.io/reference/graph-object.md): Information about graphs. - [🔀 comments](https://gtidocs.readme.io/reference/graph-comments.md): Comments in a graph - [🔀 editors](https://gtidocs.readme.io/reference/graph-editors.md): Users that can edit a graph - [🔀 group](https://gtidocs.readme.io/reference/graph-group.md): Group owning the graph - [🔀 items](https://gtidocs.readme.io/reference/graph-items.md): Contained objects in the graph - [🔀 owner](https://gtidocs.readme.io/reference/graph-owner.md): User owning the graph - [🔀 viewers](https://gtidocs.readme.io/reference/graph-viewers.md): Users that can view a graph - [Groups](https://gtidocs.readme.io/reference/group-object.md): Groups of users in Google Threat Intelligence - [🔀🧑‍💻 administrators](https://gtidocs.readme.io/reference/group-administrators.md): Users administrating the group - [🔀🧑‍💻 graphs](https://gtidocs.readme.io/reference/group-graphs.md): VT Graphs the group is owner/editor/viewer of. - [🔀🧑‍💻 users](https://gtidocs.readme.io/reference/group-users.md): Group members - [Hunting Notifications](https://gtidocs.readme.io/reference/hunting-notification-object.md): Generated notifications by matches in Hunting Rulesets - [Hunting Rulesets](https://gtidocs.readme.io/reference/hunting-ruleset-object.md): User's hunting rulesets - [Industry Profile](https://gtidocs.readme.io/reference/industry-profile-object.md) - [IoC Collection](https://gtidocs.readme.io/reference/ioc-collection-object.md): Information about IoC collections - [IoC-Stream Notifications](https://gtidocs.readme.io/reference/ioc-stream-notifications-object.md): Generated notifications by matches in the IoC-Stream - [IP addresses](https://gtidocs.readme.io/reference/ip-object.md): IPv4 addresses are other of the network locations that Google Threat Intelligence stores information about. A description of the fields stored within these objects follows. - [🔀 comments](https://gtidocs.readme.io/reference/ip-object-comments.md): Comments posted in a IP address. - [🔀 graphs](https://gtidocs.readme.io/reference/ip-object-graphs.md) - [🔀 historical_ssl_certificates](https://gtidocs.readme.io/reference/ip-object-historical-ssl-certificates.md): All SSL certificates that have been associated with the IP at some moment in time. - [🔀 historical_whois](https://gtidocs.readme.io/reference/ip-object-historical-whois.md): All whois records associated with the IP address at some moment in time. - [🔀 communicating_files](https://gtidocs.readme.io/reference/ip-object-communicating-files.md) - [🔀 downloaded_files](https://gtidocs.readme.io/reference/ip-object-downloaded-files.md) - [🔀 referrer_files](https://gtidocs.readme.io/reference/ip-object-referrer-files.md): File containing the IP address on its strings. - [🔀 resolutions](https://gtidocs.readme.io/reference/ip-object-resolutions.md): Domain resolutions for a IP address. - [🔀 urls](https://gtidocs.readme.io/reference/ip-object-urls.md): IP address' URLs - [🔀 related_comments](https://gtidocs.readme.io/reference/ip-object-related-comments.md): Comments posted in related objects. - [🔀 votes](https://gtidocs.readme.io/reference/ip-object-votes.md): IP address' votes. - [🔀🧑‍💻 user_votes](https://gtidocs.readme.io/reference/ip-object-user-votes.md): IP address' user votes. - [🔀 collections](https://gtidocs.readme.io/reference/ip-object-collections.md): Collections containing this IP address. - [🔀 related_threat_actors](https://gtidocs.readme.io/reference/ip-object-related-threat-actors.md): Related Threat Actors for a given IP address. - [Malware Family](https://gtidocs.readme.io/reference/malware-family-object.md): Information about malware families - [Operations](https://gtidocs.readme.io/reference/operation-object.md): Asynchronous operations - [Private Analyses](https://gtidocs.readme.io/reference/private-analyses-object.md): Private file's analyses - [🔀 item](https://gtidocs.readme.io/reference/private-analyses-object-item.md): Item being analysed - [🔀 submitter](https://gtidocs.readme.io/reference/submitter.md): User who submitted the analysis - [Private Files](https://gtidocs.readme.io/reference/private-files-object.md): Information about private files - [🔀 behaviours](https://gtidocs.readme.io/reference/behaviours.md): Behaviour reports for the private file - [🔀 dropped_files](https://gtidocs.readme.io/reference/private-files-object-dropped_files.md): Files dropped during the file's execution - [🔀 execution_parents](https://gtidocs.readme.io/reference/execution_parents.md): Files dropping the file during its execution - [🔀 embedded_urls](https://gtidocs.readme.io/reference/embedded_urls.md): URLs contained in the file - [🔀 embedded_domains](https://gtidocs.readme.io/reference/private-files-object-embedded_domains.md): Domains contained in the file - [🔀 embedded_ips](https://gtidocs.readme.io/reference/embedded_ips.md): IP addresses contained in the file - [Private Files Behaviours](https://gtidocs.readme.io/reference/private-file-behaviours-object.md): Information about private file behaviours - [🔀 file](https://gtidocs.readme.io/reference/private-file-behaviours-file.md): Private file behaviour's file. - [🔀 attack_techniques](https://gtidocs.readme.io/reference/private-file-behaviours-attack_techniques.md): Private file behaviour's ATT&CK techniques - [Private URLs](https://gtidocs.readme.io/reference/private-urls-object.md): Information about private URLs - [Private URLs Behaviours](https://gtidocs.readme.io/reference/private-url-behaviours-object.md): Information about private URL behaviours - [Report](https://gtidocs.readme.io/reference/report-object.md): Information about reports - [Retrohunt Jobs](https://gtidocs.readme.io/reference/retrohunt-job-object.md): YARA matching against Google Threat Intelligence's file corpus - [🔀🧑‍💻 matching_files](https://gtidocs.readme.io/reference/retrohunt-job-matching-files.md): Files matching the Retrohunt job. - [🔀🧑‍💻 owner](https://gtidocs.readme.io/reference/retrohunt-job-owner.md): Retrohunt job's owner - [Resolutions](https://gtidocs.readme.io/reference/resolution-object.md): Domain-IP resolutions. - [Saved Searches](https://gtidocs.readme.io/reference/saved-search-object.md) - [Screenshots](https://gtidocs.readme.io/reference/screenshots-object.md): screenshot objects - [Service Accounts](https://gtidocs.readme.io/reference/service-accounts-object.md): Information about a Google Threat Intelligence Service Account - [🔀🧑‍💻 api_quota_group](https://gtidocs.readme.io/reference/service-account-object-api-quota-group.md): Group which the user consumes API quota from. - [🔀 comments](https://gtidocs.readme.io/reference/service-account-object-comments.md): Comments posted by a certain user - [🔀🧑‍💻 groups](https://gtidocs.readme.io/reference/service-account-object-groups.md): Groups for which the user is a member. - [🔀🧑‍💻 intelligence_quota_group](https://gtidocs.readme.io/reference/service-account-object-intelligence-quota-group.md): Group which the user consumes Intelligence quota from. - [🔀 mentions](https://gtidocs.readme.io/reference/service-account-object-mentions.md): Comments mentioning the user. - [Sigma Analyses](https://gtidocs.readme.io/reference/sigma-analyses-object.md): Sigma analyses run in sandbox generated sysmon logs. - [🔀 rules](https://gtidocs.readme.io/reference/sigma-analyses-object-rules.md): Matched rules in a Sigma analysis. - [Sigma Rules](https://gtidocs.readme.io/reference/sigma-rule-object.md): Sigma rules matched in Sigma analyses - [Software and Toolkit](https://gtidocs.readme.io/reference/software-toolkit-object.md): Information about software and toolkits - [SSL Certificate](https://gtidocs.readme.io/reference/ssl-certificate-object.md): SSL certificates information. - [Submissions](https://gtidocs.readme.io/reference/submission-object.md): Information about submissions - [Threat Actor](https://gtidocs.readme.io/reference/threat-actor-object.md): Information about threat actors - [Threat Profile](https://gtidocs.readme.io/reference/threat-profile-object.md): Information about threat profile - [URLs](https://gtidocs.readme.io/reference/url-object.md): Information about URLs. - [🔀 analyses](https://gtidocs.readme.io/reference/url-analyses.md): All analyses made for a given URL. - [🔀 comments](https://gtidocs.readme.io/reference/url-comments.md): Comments in URL objects. - [🔀 related_comments](https://gtidocs.readme.io/reference/url-related_comments.md): Comments in URL's related objects. - [🔀 contacted_domains](https://gtidocs.readme.io/reference/url-contacted_domains.md): Distinct domains from which the URL loads some kind of resource. - [🔀 contacted_ips](https://gtidocs.readme.io/reference/url-contacted_ips.md): Distinct IP addresses from which the URL loads some kind of resource. - [🔀 downloaded_files](https://gtidocs.readme.io/reference/url-downloaded_files.md): Files downloaded from the URL. - [🔀 graphs](https://gtidocs.readme.io/reference/url-graphs.md) - [🔀 last_serving_ip_address](https://gtidocs.readme.io/reference/url-last_serving_ip_address.md): Last IP address that served the URL. - [🔀 network_location](https://gtidocs.readme.io/reference/url-network_location.md): Domain or IP address for the URL. - [🔀 redirecting_urls](https://gtidocs.readme.io/reference/url-redirecting_urls.md): URLs that redirected to the given URL. - [🔀 redirects_to](https://gtidocs.readme.io/reference/url-redirects_to.md): URLs that this url redirects to. - [🔀 submissions](https://gtidocs.readme.io/reference/url-submissions.md): URL submissions - [🔀 embedded_js_files](https://gtidocs.readme.io/reference/urls-embedded_js_files.md): Found javascript scripts in the URL's HTML response - [🔀 referrer_files](https://gtidocs.readme.io/reference/urls-referrer_files.md): Files containing a given URL. - [🔀 referrer_urls](https://gtidocs.readme.io/reference/urls-referrer_urls.md): URLs that refer to the given URL. - [🔀 urls_related_by_tracker_id](https://gtidocs.readme.io/reference/urls-urls_related_by_tracker_id.md): URLs having trackers with the same IDs - [🔀 communicating_files](https://gtidocs.readme.io/reference/urls-communicating_files.md): Files that communicate with this url when they are executed. - [🔀 votes](https://gtidocs.readme.io/reference/votes.md): Votes for a given URL - [🔀🧑‍💻 user_votes](https://gtidocs.readme.io/reference/urls-object-user_votes.md): Votes for a given URL made by the current user - [🔀 collections](https://gtidocs.readme.io/reference/urls-object-collections.md): Collections containing this URL. - [🔀 related_threat_actors](https://gtidocs.readme.io/reference/urls-object-related_threat_actors.md): Related Threat Actors for a given URL. - [File Analyses](https://gtidocs.readme.io/reference/file-analysis-object.md) - [URL Analyses](https://gtidocs.readme.io/reference/url-analysis-object.md) - [Users](https://gtidocs.readme.io/reference/user-object.md): Information about a Google Threat Intelligence user - [🔀 comments](https://gtidocs.readme.io/reference/user-object-comments.md): Comments posted by a certain user - [🔀🧑‍💻 groups](https://gtidocs.readme.io/reference/user-object-groups.md): Groups for which the user is a member. - [🔀🧑‍💻 hunting_rulesets](https://gtidocs.readme.io/reference/user-object-hunting-rulesets.md): Hunting rulesets editable by the user. - [🔀🧑‍💻 hunting_notifications](https://gtidocs.readme.io/reference/user-object-hunting-notifications.md): Hunting notifications for the user. - [🔀🧑‍💻 hunting_notification_files](https://gtidocs.readme.io/reference/user-object-hunting-notification-files.md): Files flagged in the hunting notifications for the user. - [🔀 mentions](https://gtidocs.readme.io/reference/user-object-mentions.md): Comments mentioning the user. - [🔀 graphs](https://gtidocs.readme.io/reference/user-object-graphs.md): VT Graphs the user is owner/editor/viewer of - [🔀🧑‍💻 retrohunt_jobs](https://gtidocs.readme.io/reference/user-object-retrohunt-job.md): User's Retrohunt jobs - [🔀🧑‍💻 api_quota_group](https://gtidocs.readme.io/reference/user-object-api-quota-group.md): Group which the user consumes API quota from. - [🔀🧑‍💻 intelligence_quota_group](https://gtidocs.readme.io/reference/user-object-intelligence-quota-group.md): Group which the user consumes Intelligence quota from. - [🔀 collections](https://gtidocs.readme.io/reference/user-object-collections.md) - [🔀 votes](https://gtidocs.readme.io/reference/user-object-votes.md): Votes posted by a certain user - [Votes](https://gtidocs.readme.io/reference/vote-object.md): vote objects - [Vulnerability](https://gtidocs.readme.io/reference/vulnerability-object.md): Information about vulnerabilities - [Whois](https://gtidocs.readme.io/reference/whois-object.md): Domain and IP addresses whois records. - [YARA Rules](https://gtidocs.readme.io/reference/yara-rule-object.md): YARA rules objects - [YARA Rulesets](https://gtidocs.readme.io/reference/yara-rulesets-object.md): YARA rulesets objects - [Google Threat Intelligence Widget Quick guide](https://gtidocs.readme.io/reference/widget-quick-guide.md) - [Get a widget rendering URL](https://gtidocs.readme.io/reference/get-widget-url.md): Get a widget rendering URL ## Changelog - [August 12th, 2026 — Agentic Flows & API, and Threat Actor Naming Updates](https://gtidocs.readme.io/changelog/august-5th-2026-agentic-flows-api-and-threat-actor-naming-updates.md) - [July 21st, 2026 — Agentic URL Scanning 2.0 Integration, Target Technology Watchlists, and Sharper Domain Reputation](https://gtidocs.readme.io/changelog/july-21st-2026-agentic-url-scanning-20-integration-target-technology-watchlists-and-sharper-domain-reputation.md) - [July 14th, 2026 — URL Scanning 2.0, RBAC for Service Accounts, and Invitations Page Improvements](https://gtidocs.readme.io/changelog/july-14th-2026-url-scanning-20-rbac-for-service-accounts-and-audit-log-updates.md) - [June 30th, 2026 — Splunk Observed Threats, GTI Score Explainability, and Private Scanning Access Control Lists (ACLs)](https://gtidocs.readme.io/changelog/june-29th-2026-splunk-observed-threats-gti-score-explainability-and-private-scanning-access-control-lists-acls.md) - [June 18th, 2026 — Crowdsourced AI += Knostic, Self-Service API Key Rotation, domain_exact: Search Modifier, and Advanced Agentic Disassembly & Relationship Mapping](https://gtidocs.readme.io/changelog/june-22nd-2026-crowdsourced-ai-knostic-self-service-api-key-rotation-domain_exact-search-modifier-and-advanced-agentic-disassembly-relationship-mapping.md) - [May 25th, 2026 - Advanced HTA & Office Document Analysis + Persistent File System in Agentic, macOS CDHash Extraction, 3rd-Party Integrations, Threat Profiles Bulk IoC Downloads, Collections Expansion, and more](https://gtidocs.readme.io/changelog/may-25th-2026-advanced-hta-office-document-analysis-persistent-file-system-in-agentic-macos-cdhash-extraction-3rd-party-integrations-threat-profiles-bulk-ioc-downloads-collections-expansion-and-more.md) - [May 18th, 2026 - Automated Package Sandbox Detonation, Advanced Attribute Pivoting, Expanded Collections & Deep Malware Format Analysis in Agentic, CAPA Binary Enhancements, and more](https://gtidocs.readme.io/changelog/may-18th-2026-automated-package-sandbox-detonation-advanced-attribute-pivoting-expanded-collections-deep-malware-format-analysis-in-agentic-capa-binary-enhancements-and-more.md) - [May 4th, 2026 - Two-Factor Authentication Enforcement, Private Scanning Routing through Chile, Network Livehunt Rules + Typosquatting, Agentic + OWASP, and more](https://gtidocs.readme.io/changelog/may-4th-2026-two-factor-authentication-enforcement-private-scanning-routing-through-chile-network-livehunt-rules-typosquatting-agentic-owasp-and-more.md) - [April 13th, 2026 - Visual Insights and Saved Search Integration in Agentic, SCIM Token Updates, and more](https://gtidocs.readme.io/changelog/visual-insights-and-saved-search-integration-in-agentic-scim-token-updates-and-more.md) - [April 6th, 2026 - AutoIt Deobfuscation for Agentic, Improved RBAC, and more](https://gtidocs.readme.io/changelog/april-6th-2026-autoit-deobfuscation-for-agentic-improved-rbac-and-more.md)