{"openapi":"3.1.0","info":{"title":"VirusSign Intelligence API","version":"v1","description":"Query indicators and relationships, and retrieve intelligence feed events in native JSON or STIX format. Permissions and usage depend on your access plan."},"servers":[{"url":"https://api.virussign.com"}],"paths":{"/v1/ioc/files/{ioc_key}":{"get":{"summary":"Files lookup","tags":["IOC"],"security":[{"ApiKey":[]}],"parameters":[{"name":"ioc_key","in":"path","required":true,"description":"MD5, SHA-1 or SHA-256 hash.","schema":{"type":"string"}},{"name":"view","in":"query","required":false,"description":"Optional detail level. Omit to use the service default; encode + in full+relations.","schema":{"type":"string","enum":["compact","full","full+relations"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/IOCResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/ioc/domains/{ioc_key}":{"get":{"summary":"Domains lookup","tags":["IOC"],"security":[{"ApiKey":[]}],"parameters":[{"name":"ioc_key","in":"path","required":true,"description":"Domain name without a scheme or path.","schema":{"type":"string"}},{"name":"view","in":"query","required":false,"description":"Optional detail level. Omit to use the service default; encode + in full+relations.","schema":{"type":"string","enum":["compact","full","full+relations"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/IOCResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/ioc/ips/{ioc_key}":{"get":{"summary":"Ips lookup","tags":["IOC"],"security":[{"ApiKey":[]}],"parameters":[{"name":"ioc_key","in":"path","required":true,"description":"IP address.","schema":{"type":"string"}},{"name":"view","in":"query","required":false,"description":"Optional detail level. Omit to use the service default; encode + in full+relations.","schema":{"type":"string","enum":["compact","full","full+relations"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/IOCResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/ioc/urls":{"get":{"summary":"Complete URL lookup","tags":["IOC"],"security":[{"ApiKey":[]}],"parameters":[{"name":"view","in":"query","required":false,"description":"Optional detail level. Omit to use the service default; encode + in full+relations.","schema":{"type":"string","enum":["compact","full","full+relations"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}},{"name":"q","in":"query","required":true,"description":"Full URL; encode and place last in the query string.","schema":{"type":"string"}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/IOCResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/ioc/files/{ioc_key}/{relation}":{"get":{"summary":"Files relationship page","tags":["Relationships"],"security":[{"ApiKey":[]}],"parameters":[{"name":"ioc_key","in":"path","required":true,"description":"Source IOC key. For URLs, use the opaque identifier in the returned canonical link.","schema":{"type":"string"}},{"name":"relation","in":"path","required":true,"description":"Relationship to retrieve.","schema":{"type":"string","enum":["related_ips","related_domains","related_urls"]}},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the preceding page; omit for the first page.","schema":{"type":"string"}},{"name":"view","in":"query","required":false,"description":"Optional relationship detail; omit to use the service default.","schema":{"type":"string","enum":["compact","full"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RelationResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/ioc/ips/{ioc_key}/{relation}":{"get":{"summary":"Ips relationship page","tags":["Relationships"],"security":[{"ApiKey":[]}],"parameters":[{"name":"ioc_key","in":"path","required":true,"description":"Source IOC key. For URLs, use the opaque identifier in the returned canonical link.","schema":{"type":"string"}},{"name":"relation","in":"path","required":true,"description":"Relationship to retrieve.","schema":{"type":"string","enum":["related_files","related_domains","related_urls"]}},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the preceding page; omit for the first page.","schema":{"type":"string"}},{"name":"view","in":"query","required":false,"description":"Optional relationship detail; omit to use the service default.","schema":{"type":"string","enum":["compact","full"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RelationResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/ioc/domains/{ioc_key}/{relation}":{"get":{"summary":"Domains relationship page","tags":["Relationships"],"security":[{"ApiKey":[]}],"parameters":[{"name":"ioc_key","in":"path","required":true,"description":"Source IOC key. For URLs, use the opaque identifier in the returned canonical link.","schema":{"type":"string"}},{"name":"relation","in":"path","required":true,"description":"Relationship to retrieve.","schema":{"type":"string","enum":["related_files","related_ips","related_urls"]}},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the preceding page; omit for the first page.","schema":{"type":"string"}},{"name":"view","in":"query","required":false,"description":"Optional relationship detail; omit to use the service default.","schema":{"type":"string","enum":["compact","full"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RelationResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/ioc/urls/{ioc_key}/{relation}":{"get":{"summary":"Urls relationship page","tags":["Relationships"],"security":[{"ApiKey":[]}],"parameters":[{"name":"ioc_key","in":"path","required":true,"description":"Source IOC key. For URLs, use the opaque identifier in the returned canonical link.","schema":{"type":"string"}},{"name":"relation","in":"path","required":true,"description":"Relationship to retrieve.","schema":{"type":"string","enum":["related_files","related_ips","related_domains"]}},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the preceding page; omit for the first page.","schema":{"type":"string"}},{"name":"view","in":"query","required":false,"description":"Optional relationship detail; omit to use the service default.","schema":{"type":"string","enum":["compact","full"]}},{"name":"limit","in":"query","required":false,"description":"Requested items per relationship page. Start with 10; use pages of 50 or fewer for initial integrations. Contact support before requesting larger pages.","schema":{"type":"integer","minimum":1,"example":10}}],"responses":{"200":{"description":"Success. Optional fields depend on permissions and available data.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RelationResponse"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"404":{"description":"No matching IOC or supported relationship"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}}}},"/v1/feed/events":{"get":{"summary":"Retrieve intelligence feed events","tags":["Feeds"],"security":[{"ApiKey":[]}],"parameters":[{"name":"mode","in":"query","required":false,"description":"events returns additions, updates and revocations. snapshot returns current, unexpired upsert entries within the requested time window.","schema":{"type":"string","enum":["events","snapshot"],"default":"events"}},{"name":"types","in":"query","required":false,"description":"Comma-separated file, host and/or url. host includes both domains and IP addresses. Defaults to all three.","schema":{"type":"string","default":"file,host,url","example":"file,host,url"}},{"name":"since","in":"query","required":false,"description":"Inclusive start time. Use a timezone-aware ISO 8601 timestamp with whole seconds, for example 2026-10-04T00:00:00Z.","schema":{"type":"string","format":"date-time","example":"2026-10-04T00:00:00Z"}},{"name":"until","in":"query","required":false,"description":"Exclusive end time, later than since. Omit for ongoing polling.","schema":{"type":"string","format":"date-time","example":"2026-10-04T01:00:00Z"}},{"name":"cursor","in":"query","required":false,"description":"Opaque continuation cursor. Use the returned value unchanged with the same account, mode, format and types. The cursor retains the time window; omit it to start a new window.","schema":{"type":"string"}},{"name":"limit","in":"query","required":false,"description":"Maximum events per page. Start with 50 and set it explicitly to control page size. Charges use the actual number returned.","schema":{"type":"integer","minimum":1,"example":50}},{"name":"format","in":"query","required":false,"description":"native returns JSON with meta and items. stix returns a STIX 2.1 bundle with paging information in response headers.","schema":{"type":"string","enum":["native","stix"],"default":"native"}},{"name":"view","in":"query","required":false,"description":"compact returns core event information. full adds available context; native full responses also include STIX identifiers and patterns.","schema":{"type":"string","enum":["compact","full"],"default":"compact"}}],"responses":{"200":{"description":"Feed page, including an empty page. See the operation description for billing and continuation rules.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/FeedResponse"}},"application/stix+json;version=2.1":{"schema":{"$ref":"#/components/schemas/STIXBundle"}}},"headers":{"X-Limit":{"description":"STIX responses only. Requested page size.","schema":{"type":"string"}},"X-Has-More":{"description":"STIX responses only. 1 means more events are available now; 0 means the current end has been reached.","schema":{"type":"string"}},"X-Next-Cursor":{"description":"STIX responses only. Continuation checkpoint, when available. Its presence alone does not mean another page is available.","schema":{"type":"string"}},"X-Quota-Remaining":{"description":"STIX responses only. Remaining token balance or cycle allowance after charging.","schema":{"type":"string"}},"Link":{"description":"STIX responses only. Continuation URL with rel=\"next\", when a cursor is available. Check X-Has-More before following it immediately.","schema":{"type":"string"}}}},"400":{"description":"Invalid parameters"},"401":{"description":"Authentication failed"},"403":{"description":"Quota, account or permission restriction"},"422":{"description":"Validation error"},"429":{"description":"Rate limit"},"500":{"description":"Server error. Contact support if you need a usage review."}},"operationId":"feedEvents","description":"Requires feed permission. On the first request, supply since or until; a recent since is recommended. Timestamps require an explicit timezone and whole seconds. since is inclusive and until is exclusive. Results follow feed event time order. Use events for change tracking; snapshot lists current, unexpired upsert entries in the selected window. Continue with the returned cursor and the same account, mode, format and types. The cursor retains the time window; omit it to change the window. Use meta.has_next (native) or X-Has-More (stix) to decide whether to fetch another page now. A cursor can remain at the end. Feed queries are charged after the query completes, based on events returned: one query unit per started block of 50 events, with a minimum of one unit per request, including empty results. At the standard rate, one query unit costs one token. Your access plan defines any account-specific rate."}}},"components":{"securitySchemes":{"ApiKey":{"type":"apiKey","in":"header","name":"x-api-key"}},"schemas":{"FeedResponse":{"type":"object","required":["meta","items"],"properties":{"meta":{"type":"object","properties":{"request_id":{"type":"string"},"timestamp":{"type":"string","format":"date-time"},"limit":{"type":"integer","minimum":1},"returned":{"type":"integer","minimum":0},"has_next":{"type":"boolean","description":"More matching events are available now."},"next_cursor":{"type":["string","null"],"description":"May remain present at the end. Check has_next before fetching another page."},"quota_remaining":{"type":"integer","minimum":0,"description":"Remaining balance or cycle allowance after charging."},"took_ms":{"type":"integer","minimum":0}},"additionalProperties":true},"items":{"type":"array","items":{"$ref":"#/components/schemas/FeedEvent"}}}},"FeedEvent":{"type":"object","properties":{"id":{"type":"string","description":"Event identifier for deduplication."},"timestamp":{"type":"string","format":"date-time","description":"Feed event time used by since/until."},"action":{"type":"string","enum":["upsert","revoke"]},"reason":{"type":"string"},"indicator":{"type":"object","properties":{"type":{"type":"string","enum":["file","ip","domain","url"]},"value":{"type":"string"},"version":{"type":"string","enum":["v4","v6"]},"md5":{"type":"string"},"sha1":{"type":"string"},"sha256":{"type":"string"},"links":{"type":"object","additionalProperties":true}},"additionalProperties":true},"analysis":{"type":"object","additionalProperties":true},"validity":{"type":"object","additionalProperties":true},"tags":{"type":"array","items":{"type":"string"}},"context":{},"stix":{"type":"object","additionalProperties":true}},"additionalProperties":true},"STIXBundle":{"type":"object","required":["type","id","objects"],"properties":{"type":{"type":"string","const":"bundle"},"id":{"type":"string"},"objects":{"type":"array","items":{"type":"object","additionalProperties":true}}},"additionalProperties":true},"IOCResponse":{"type":"object","properties":{"meta":{"type":"object","additionalProperties":true},"indicator":{"type":"object","additionalProperties":true}}},"RelationResponse":{"type":"object","properties":{"meta":{"type":"object","additionalProperties":true},"returned":{"type":"integer","minimum":0},"items":{"type":"array","items":{"type":"object","additionalProperties":true}},"has_next":{"type":"boolean"},"next_cursor":{"type":["string","null"]}}}}}}