Use this workflow for observables from SIEM, EDR, firewall, email, or alerting systems.Documentation Index
Fetch the complete documentation index at: https://docs.kyberis.ai/llms.txt
Use this file to discover all available pages before exploring further.
Workflow
- Resolve the observable with concrete expected types:
ip,domain,url,hash, oremail. - Retrieve evidence for
observed_in_the_wild,malware_association,campaign_association, oractor_association. - Pivot relationships to actors, campaigns, malware, sectors, and related indicators.
- Run
/v2/ioc-assessments. - Retry in exact
querymode when canonicalization may lose URL or observable detail.
Important rule
Do not useioc in expected_types. Expand IOC intent into concrete types.
