generated: '2026-07-15' method: generated source: openapi/virustotal-access-control-openapi.yml, openapi/virustotal-ioc-feeds-openapi.yml, openapi/virustotal-ioc-investigation-openapi.yml, openapi/virustotal-private-scanning-openapi.yml, openapi/virustotal-threat-graphs-openapi.yml, openapi/virustotal-threat-landscape-openapi.yml, openapi/virustotal-yara-hunting-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 206 by_action_class: connected: 150 acting: 56 by_consequence: read: 150 safety-critical: 11 write: 39 physical: 6 human_in_the_loop_required: 11 operations: - path: /groups/{id} method: get operationId: groups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id} method: patch operationId: patchGroup x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /groups/{id}/relationships/administrators method: get operationId: getGroupAdministrators x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/relationships/administrators method: post operationId: postGroupAdministrators x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /groups/{id}/relationships/administrators/{user_id} method: delete operationId: deleteUserGroupAdministrator x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /groups/{id}/relationships/administrators/{user_id} method: get operationId: checkUserGroupAdministrator x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/relationships/users method: get operationId: getGroupUsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/relationships/users method: post operationId: updateGroupUsers x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /groups/{id}/relationships/users/{user_id} method: delete operationId: deleteUserFromGroup x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /groups/{id}/relationships/users/{user_id} method: get operationId: checkUserInGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/relationships/{relationship} method: get operationId: groupsRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/{relationship} method: get operationId: groupsRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{id}/api_usage method: get operationId: userApiUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{id}/overall_quotas method: get operationId: getUserOverallQuotas x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/api_usage method: get operationId: groupApiUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/relationships/service_accounts method: get operationId: getServiceAccountsOfAGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{id}/relationships/service_accounts method: post operationId: createANewServiceAccount x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /service_accounts/{id} method: get operationId: getAServiceAccountObject x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{id} method: delete operationId: deleteUserId x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /users/{id} method: get operationId: user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{id} method: patch operationId: patchUserId x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /users/{id}/relationships/{relationship} method: get operationId: getUsersRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{id}/{relationship} method: get operationId: usersRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/domains/hourly/{time} method: get operationId: feedsdomainshourly2time x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/domains/{time} method: get operationId: feedsdomains2time x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/files/hourly/{time} method: get operationId: feedsFileHourly x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/files/{time} method: get operationId: feedsFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/files/{token}/download method: get operationId: fileFeedDownload x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/ip_addresses/hourly/{time} method: get operationId: feedsipAddresseshourly2time x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/ip_addresses/{time} method: get operationId: feedsipAddressestime x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/file_behaviours/hourly/{time} method: get operationId: feedsFileBehaviourHourly x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/file_behaviours/{time} method: get operationId: feedsFileBehaviour x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/file_behaviours/{token}/evtx method: get operationId: fileBehaviourFeedEvtx x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/file_behaviours/{token}/html method: get operationId: fileBehaviourFeedHtml x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/file_behaviours/{token}/memdump method: get operationId: fileBehaviourFeedMemdump x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/file_behaviours/{token}/pcap method: get operationId: fileBehaviourFeedPcap x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/urls/hourly/{time} method: get operationId: feedsUrlHourly x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds/urls/{time} method: get operationId: feedsUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /analyses/{id} method: get operationId: analysis x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /analyses/{id}/relationships/{relationship} method: get operationId: analysesGetDescriptors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /analyses/{id}/{relationship} method: get operationId: analysesGetObjects x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /submission/{id} method: get operationId: getSubmission x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /operations/{id} method: get operationId: getOperationsId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /attack_tactics/{id} method: get operationId: attackTacticsid x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /attack_tactics/{id}/relationships/{relationship} method: get operationId: attackTacticsidrelationshipsrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /attack_tactics/{id}/{relationship} method: get operationId: attackTacticsidrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /attack_techniques/{id} method: get operationId: attackTechniqueid x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /attack_techniques/{id}/relationships/{relationship} method: get operationId: attackTechniquesidrelationshipsrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /attack_techniques/{id}/{relationship} method: get operationId: attackTechniqueidrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /comments method: get operationId: getComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /comments/{id} method: delete operationId: commentIdDelete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /comments/{id} method: get operationId: getComment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /comments/{id}/relationships/{relationship} method: get operationId: commentsRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /comments/{id}/vote method: post operationId: voteComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /comments/{id}/{relationship} method: get operationId: commentsRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domains/{domain} method: get operationId: domainInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domains/{domain}/comments method: get operationId: domainsCommentsGet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domains/{domain}/comments method: post operationId: domainsCommentsPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domains/{domain}/relationships/{relationship} method: get operationId: domainsRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domains/{domain}/votes method: get operationId: domainsVotesGet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domains/{domain}/votes method: post operationId: domainVotesPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domains/{domain}/{relationship} method: get operationId: domainsRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /resolutions/{id} method: get operationId: getResolutionById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/upload_url method: get operationId: filesUploadUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files method: post operationId: filesScan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /files/{id} method: get operationId: fileInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/analyse method: post operationId: filesAnalyse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /files/{id}/comments method: get operationId: filesCommentsGet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/comments method: post operationId: filesCommentsPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /files/{id}/download method: get operationId: filesDownload x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/download_url method: get operationId: filesDownloadUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/relationships/{relationship} method: get operationId: filesRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/votes method: get operationId: filesVotesGet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/votes method: post operationId: filesVotesPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /files/{id}/{relationship} method: get operationId: filesRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sigma_rules/{id} method: get operationId: getSigmaRules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /yara_rulesets/{id} method: get operationId: getYaraRulesets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /file_behaviours/{sandbox_id} method: get operationId: getFileBehaviourId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /file_behaviours/{sandbox_id}/evtx method: get operationId: fileBehaviourEvtx x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /file_behaviours/{sandbox_id}/html method: get operationId: getFileBehaviourHtml x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /file_behaviours/{sandbox_id}/memdump method: get operationId: fileBehaviourMemdump x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /file_behaviours/{sandbox_id}/pcap method: get operationId: fileBehavioursPcap x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /file_behaviours/{sandbox_id}/relationships/{relationship} method: get operationId: fileBehaviourssandboxIdrelationshipsrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /file_behaviours/{sandbox_id}/{relationship} method: get operationId: fileBehaviourssandboxIdrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/behaviour_mitre_trees method: get operationId: getASummaryOfAllMitreAttckTechniquesObservedInAFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/behaviour_summary method: get operationId: fileAllBehavioursSummary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /files/{id}/behaviours method: get operationId: getAllBehaviorReportsForAFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ip_addresses/{ip} method: get operationId: ipInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ip_addresses/{ip}/comments method: get operationId: ipCommentsGet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ip_addresses/{ip}/comments method: post operationId: ipCommentsPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ip_addresses/{ip}/relationships/{relationship} method: get operationId: ipRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ip_addresses/{ip}/votes method: get operationId: ipVotes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ip_addresses/{ip}/votes method: post operationId: ipVotesPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ip_addresses/{ip}/{relationship} method: get operationId: ipRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /popular_threat_categories method: get operationId: popularThreatCategories x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/search method: get operationId: intelligenceSearch x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/search/snippets/{snippet} method: get operationId: intelligenceSearchSnippets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /metadata method: get operationId: metadata x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search method: get operationId: apiSearch x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /urls method: post operationId: scanUrl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /urls/{id} method: get operationId: urlInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /urls/{id}/analyse method: post operationId: urlsAnalyse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /urls/{id}/comments method: get operationId: urlsCommentsGet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /urls/{id}/comments method: post operationId: urlsCommentsPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /urls/{id}/relationships/{relationship} method: get operationId: urlsRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /urls/{id}/votes method: get operationId: urlsVotesGet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /urls/{id}/votes method: post operationId: urlsVotesPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /urls/{id}/{relationship} method: get operationId: urlsRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/zip_files method: post operationId: zipFiles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/zip_files/{id} method: get operationId: getZipFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/zip_files/{id}/download method: get operationId: zipFilesDownload x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/zip_files/{id}/download_url method: get operationId: zipFilesDownloadUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/analyses method: get operationId: listPrivateAnalyses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/analyses/{id} method: get operationId: privateAnalysis x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/analyses/{id}/relationships/{relationship} method: get operationId: analysesidrelationshipsrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/analyses/{id}/{relationship} method: get operationId: analysesidrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files method: post operationId: uploadFilePrivateScanning x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /private/files method: get operationId: listPrivateFiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files/upload_url method: get operationId: privateFilesUploadUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files/{id} method: delete operationId: deleteFilePrivateScanning x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /private/files/{id} method: get operationId: privateFilesInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files/{id}/relationships/{relationship} method: get operationId: privatefilesidrelationshipsrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files/{id}/{relationship} method: get operationId: privateFilesRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files/{sha256}/analyse method: post operationId: rescanAPrivateFile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /private/file/{id}/behaviours method: get operationId: getAllBehaviourReportsFromAPrivateFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/file_behaviours/{sandbox_id} method: get operationId: privatefileBehaviourssandboxId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/file_behaviours/{sandbox_id}/evtx method: get operationId: fileBehaviourssandboxIdevtx x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/file_behaviours/{sandbox_id}/html method: get operationId: privatefileBehaviourssandboxIdhtml x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/file_behaviours/{sandbox_id}/memdump method: get operationId: privatefileBehaviourssandboxIdpcap x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/file_behaviours/{sandbox_id}/pcap method: get operationId: fileBehaviourssandboxIdmemdump x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/file_behaviours/{sandbox_id}/relationships/{relationship} method: get operationId: privatefileBehaviourssandboxIdrelationshipsrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/file_behaviours/{sandbox_id}/{relationship} method: get operationId: privatefileBehaviourssandboxIdrelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files/{id}/behaviour_mitre_trees method: get operationId: getSummaryAllMitreAttackTechniquesObservedInAFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/files/{id}/behaviour_summary method: get operationId: privatefilesidbehaviourSummary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/urls method: post operationId: privateScanUrl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /private/urls/{id} method: get operationId: getAPrivateUrlAnalysisReport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/urls/{id}/{relationship} method: get operationId: privateGetObjectsRelatedToAUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/urls/{id}/relationships/{relationship} method: get operationId: privateGetObjectDescriptorsRelatedToAUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/zip_files method: post operationId: privateScanningZipFiles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /private/zip_files/{id} method: get operationId: privateScanningGetZipFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/zip_files/{id}/download method: get operationId: privateScanningDownloadZipFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /private/zip_files/{id}/download_url method: get operationId: privateScanningGetZipDownloadUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs method: get operationId: graphs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs method: post operationId: createGraphs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /graphs/{id} method: delete operationId: graphsDelete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /graphs/{id} method: get operationId: graphsInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id} method: patch operationId: graphsUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /graphs/{id}/comments method: get operationId: getGraphComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id}/comments method: post operationId: postGraphsComments x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /graphs/{id}/relationships/{relationship} method: get operationId: graphsRelationshipsIds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id}/{relationship} method: get operationId: graphsRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id}/relationships/editors method: get operationId: graphsEditors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id}/relationships/editors method: post operationId: graphsAddEditor x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /graphs/{id}/relationships/editors/{user_or_group_id} method: delete operationId: graphsDeleteEditor x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /graphs/{id}/relationships/editors/{user_or_group_id} method: get operationId: graphsCheckEditor x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id}/relationships/viewers/{user_or_group_id} method: delete operationId: graphsDeleteViewer x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /graphs/{id}/relationships/viewers/{user_or_group_id} method: get operationId: graphsCheckViewer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id}/relationships/viewers method: get operationId: graphsViewers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /graphs/{id}/relationships/viewers method: post operationId: graphsAddViewer x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections method: get operationId: listThreats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections method: post operationId: createIocCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{id} method: get operationId: getThreat x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id} method: delete operationId: deleteIocCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{id} method: patch operationId: updateIocCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{id}/relationships/{relationship} method: get operationId: getThreatRelatedDescriptors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id}/{relationship} method: get operationId: getThreatRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id}/{relationship} method: delete operationId: deleteElementFromIocCollection x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{id}/{relationship} method: post operationId: addElementToIocCollection x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{id}/comments method: get operationId: getThreatComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id}/comments method: post operationId: createThreatComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{id}/mitre_tree method: get operationId: getThreatMitreTree x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id}/search method: get operationId: searchIocsInsideAThreat x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id}/download/{format} method: get operationId: exportThreatIocs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id}/aggregations/download/{format} method: get operationId: exportThreatAggregations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{id}/{relationship}/download/{format} method: get operationId: exportIocsThreatRelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ioc_stream method: delete operationId: deleteNotificationsFromTheIocStream x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ioc_stream method: get operationId: getObjectsFromTheIocStream x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ioc_stream_notifications/{id} method: delete operationId: deleteAnIocStreamNotification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ioc_stream_notifications/{id} method: get operationId: getAnIocStreamNotification x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_notification_files method: get operationId: huntingNotificationFiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_notifications method: delete operationId: deleteHuntingNotifications x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_notifications method: get operationId: listHuntingNotifications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_notifications/{id} method: delete operationId: deleteHuntingNotification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_notifications/{id} method: get operationId: getHuntingNotification x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_rulesets method: delete operationId: deleteAllHuntingRulesets x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_rulesets method: get operationId: listHuntingRulesets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_rulesets method: post operationId: createHuntingRuleset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_rulesets/{id} method: delete operationId: deleteHuntingRuleset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_rulesets/{id} method: get operationId: getHuntingRuleset x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_rulesets/{id} method: patch operationId: modifyHuntingRuleset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_rulesets/{id}/relationships/editors method: post operationId: editHuntingRulesetRelationship x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_rulesets/{id}/relationships/editors/{user_or_group_id} method: delete operationId: deleteHuntingRulesetEditor x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /intelligence/hunting_rulesets/{id}/relationships/editors/{user_or_group_id} method: get operationId: checkUserHuntingRulesetEditor x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_rulesets/{id}/relationships/owner method: post operationId: transferLivehuntRulesetToAnotherUser x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/hunting_rulesets/{id}/relationships/{relationship} method: get operationId: getHuntingRulesetRelationship x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/hunting_rulesets/{id}/{relationship} method: get operationId: getHuntingRulesetFullRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/retrohunt_jobs method: get operationId: getRetrohuntJobs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/retrohunt_jobs method: post operationId: createRetrohuntJob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/retrohunt_jobs/{id} method: delete operationId: deleteRetrohuntJob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/retrohunt_jobs/{id} method: get operationId: getRetrohuntJob x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /intelligence/retrohunt_jobs/{id}/abort method: post operationId: abortRetrohuntJob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /intelligence/retrohunt_jobs/{id}/matching_files method: get operationId: getRetrohuntJobRelationships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /yara_rules method: get operationId: listCrowdsourcedYaraRules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /yara_rules/{id} method: get operationId: getACrowdsourcedYaraRule x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /yara_rules/{id}/relationships/{relationship} method: get operationId: crowdsourcedYaraRuleRelationshipDescriptorsEndpoint x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /yara_rules/{id}/{relationship} method: get operationId: crowdsourcedYaraRuleRelationshipEndpoint x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none