For AI agents: visit https://threatconnect.readme.io/llms.txt for an index of all pages formatted in Markdown and endpoints in OpenAPI. Append .md to any documentation page URL to get its markdown version.
Jump to Content
ThreatConnectThreatConnect
HomeGuidesAPI Reference
Log InThreatConnect
API Reference
Log In
HomeGuidesAPI Reference

ThreatConnect v3 API Overview

  • Introduction
  • Getting Started
  • Postman Configuration
  • Features
    • Create Activity Logs
    • Create and Manage Associations
    • Delete Case Objects in Bulk
    • Enable Pagination
    • Filter Results With TQL
    • HTTP Status Codes
    • Include Additional Fields in API Responses
    • Retrieve a List of Available Fields for an Endpoint
    • Retrieve OpenAPI Documentation
    • Return a Count of Items
    • Sort Results
    • Specify an Owner
    • Update an Object's Metadata
  • Available Endpoints

ThreatConnect API

  • Artifacts
    • Artifacts Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create Artifactpost
    • Retrieve Artifactsget
    • Retrieve Artifact by IDget
    • Update Artifactput
    • Delete Artifactsdel
    • Delete Artifact by IDdel
  • Artifact Types
    • Artifact Types Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Retrieve ArtifactTypesget
    • Retrieve ArtifactType by IDget
  • Attribute Types
    • Attribute Types Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Retrieve AttributeTypesget
    • Retrieve AttributeType by IDget
  • Case Attributes
    • Case Attributes Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create CaseAttributepost
    • Retrieve CaseAttributesget
    • Retrieve CaseAttribute by IDget
    • Update CaseAttribute by IDput
    • Delete CaseAttribute by IDdel
  • Case Notes
    • Notes Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create Notepost
    • Retrieve Notesget
    • Retrieve Note by IDget
    • Update Note by IDput
    • Delete Notesdel
    • Delete Note by IDdel
  • Cases
    • Cases Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create Casepost
    • Retrieve Casesget
    • Retrieve Case by IDget
    • Update Caseput
    • Delete Casesdel
    • Delete Case by IDdel
  • Exclusion List
    • Exclusion Lists Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create ExclusionListpost
    • Retrieve ExclusionListsget
    • Retrieve ExclusionList by IDget
    • Update ExclusionList by IDput
    • Delete ExclusionList by IDdel
  • Group Attributes
    • Group Attributes Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create GroupAttributepost
    • Retrieve GroupAttributesget
    • Retrieve GroupAttribute by IDget
    • Update GroupAttribute by IDput
    • Delete GroupAttribute by IDdel
  • Groups
    • Groups Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create Grouppost
    • Create Documentpost
    • Retrieve Groupsget
    • Retrieve Group by IDget
    • Retrieve Documentget
    • Retrieve PDFget
    • Retrieve Event Type Categoriesget
    • Update Group by IDput
    • Update Documentput
    • Delete Group by IDdel
  • Indicator Attributes
    • Indicator Attributes Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create IndicatorAttributepost
    • Retrieve IndicatorAttributesget
    • Retrieve IndicatorAttribute by IDget
    • Update IndicatorAttribute by IDput
    • Delete IndicatorAttribute by IDdel
  • Indicator Enrichment
    • Indicator Enrichment Overview
    • Enrich Indicatorspost
    • Enrich Indicatorpost
  • Indicators
    • Indicators Overview
    • Retrieve entity infooptns
    • Retrieve fieldsoptns
    • Retrieve tqloptns
    • Create Indicatorpost
    • Retrieve Indicatorsget
    • Retrieve Indicator by IDget
    • Retrieve Deleted Indicatorsget
    • Update Indicator by IDput