Threat Intelligence API

Interactive Swagger UI — click Authorize to try requests with your Threat Intelligence API token.

See Recent Changes for what's changed in the last 6 months.

Overview

The Threat Intelligence API provides access to eSentire's threat intelligence data: STIX 2.1-formatted threat indicators (domains, email addresses, file hashes, IP addresses, URLs), MISP-formatted indicator files, and IP blocklists (AMP rules and the combined IP Watch feed).

Base URL: https://api.esentire.com/ti

Subscription tiers: Advanced (full access to threat indicators and IP Watch), IP Watch (IP blocklists only), Standard (AMP rules only, no subscription check). GET /rules works for every subscriber; the other data endpoints return 401 if your subscription doesn't cover them.

Important: these APIs return STIX-formatted data but are not compatible with the TAXII protocol — use them for direct REST integration only.


Authentication

Requests need an Authorization header carrying your Threat Intelligence API token, generated in the Atlas Platform with the Threat Intelligence (Advanced) endpoint selected. Unlike the other self-service APIs, TI does not support Atlas OAuth client credentials — only its own token.

curl -H 'Authorization: <token>' 'https://api.esentire.com/ti/indicators/stix'

Endpoints

IP Blocklists

AMP rules — GET /rules

IP addresses sourced exclusively from the internal AMP (Advanced Malware Protection) detection system, as plain text (one IP/CIDR per line). No subscription required. For a more complete blocklist that also includes threat team-curated IOCs, use /ipwatch.

View in Swagger UI →

curl -H 'Authorization: <token>' 'https://api.esentire.com/ti/rules'

IP Watch — GET /ipwatch

Combines AMP-detected and threat team-curated IOCs into one blocklist, as plain text. Optional ip_source query parameter (amp or indicators) filters to one source; omit it for both combined (recommended). Requires IP Watch or Advanced subscription.

View in Swagger UI →

curl -H 'Authorization: <token>' 'https://api.esentire.com/ti/ipwatch'

Threat Indicators

Recent indicators (STIX) — GET /indicators

The 50 most recently updated STIX 2.1 Bundles, unpaginated. For pagination and access to older bundles, use /indicators/stix instead. Requires Advanced subscription.

View in Swagger UI →

curl -H 'Authorization: <token>' 'https://api.esentire.com/ti/indicators'

Paginated indicators (STIX) — GET /indicators/stix

Same STIX Bundle data as /indicators, with pagination: use either page+per_page or limit+offset (default/max limit is 50; if both styles are supplied, page/per_page wins). The response's paging.offset is already advanced to the next page's offset (i.e. offset + count), not the offset you requested. Requires Advanced subscription.

View in Swagger UI →

curl -G -H 'Authorization: <token>' \
  --data-urlencode 'limit=50' --data-urlencode 'offset=0' \
  'https://api.esentire.com/ti/indicators/stix'

MISP feed file — GET /indicators/misp/{year}/{file_name}

file_name must be 13–41 characters (e.g. manifest.json). Returns 404 if the year/file combination doesn't exist. Requires Advanced subscription.

View in Swagger UI →

curl -H 'Authorization: <token>' \
  'https://api.esentire.com/ti/indicators/misp/2024/manifest.json'

Health & metadata

API info — GET /info

Returns the deployed API's name, title and version.

View in Swagger UI →

Connectivity check — GET /test

A lightweight connectivity check with an empty response body.

View in Swagger UI →

Neither endpoint needs anything beyond a valid token.


Response Format

STIX Bundle

{
  "id": "bundle--c54c4051-e6a0-53ae-9140-bab5f26121ba",
  "objects": [
    {
      "id": "identity--d3e73ed7-1e20-3b30-9794-47bd7929ac3b",
      "type": "identity",
      "name": "eSentire, Inc.",
      "created": "2024-01-01T00:00:00.000Z",
      "modified": "2024-01-01T00:00:00.000Z",
      "spec_version": "2.1"
    },
    {
      "id": "indicator--d22a55c2-143a-5466-b86e-272416fe9070",
      "type": "indicator",
      "name": "Malicious IP Address",
      "pattern": "[ipv4-addr:value = '192.0.2.1']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "created": "2024-01-15T10:30:00.000Z",
      "modified": "2024-01-15T10:30:00.000Z",
      "valid_from": "2024-01-15T10:30:00.000Z",
      "spec_version": "2.1"
    }
  ],
  "type": "bundle"
}

Paginated STIX response (/indicators/stix)

bundles is an array of STIX Bundle objects, each shaped like the example above (omitted below for brevity).

{
  "bundles": [
    {
      "id": "bundle--c54c4051-e6a0-53ae-9140-bab5f26121ba",
      "objects": [],
      "type": "bundle"
    }
  ],
  "paging": {
    "count": 10,
    "limit": 50,
    "offset": 10
  }
}

HTTP Status Codes

Code Meaning Action
200 Success Request completed successfully
400 Bad Request Check request format and parameters
401 Unauthorized Missing/invalid/expired token, or your subscription tier doesn't cover this endpoint
404 Not Found Check URL spelling (e.g. the MISP year/file_name combination)
500 Server Error Retry after a short delay
502 Bad Gateway Upstream service (S3/Snowflake) error; retry after a short delay

Support

Email: deploymentsupport@esentire.com
Website: https://www.esentire.com
STIX format reference: https://oasis-open.github.io/cti-documentation/


Related APIs