API Reference
thehive4py
client
TheHiveApi(url, apikey=None, username=None, password=None, organisation=None, verify=True, max_retries=DEFAULT_RETRY)
Create a client of TheHive API.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
url
|
str
|
TheHive's url. |
required |
apikey
|
Optional[str]
|
TheHive's apikey. It's required if |
None
|
username
|
Optional[str]
|
TheHive's username. It's required if |
None
|
password
|
Optional[str]
|
TheHive's password. It's required if |
None
|
organisation
|
Optional[str]
|
TheHive organisation to use in the session. |
None
|
verify
|
VerifyValue
|
Either a boolean, in which case it controls whether we verify the server's TLS certificate, or a string, in which case it must be a path to a CA bundle to use. |
True
|
max_retries
|
RetryValue
|
Either |
DEFAULT_RETRY
|
Source code in thehive4py/client.py
25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 |
|
session = TheHiveSession(url=url, apikey=apikey, username=username, password=password, verify=verify, max_retries=max_retries)
instance-attribute
alert = AlertEndpoint(self.session)
instance-attribute
case = CaseEndpoint(self.session)
instance-attribute
case_template = CaseTemplateEndpoint(self.session)
instance-attribute
comment = CommentEndpoint(self.session)
instance-attribute
observable = ObservableEndpoint(self.session)
instance-attribute
procedure = ProcedureEndpoint(self.session)
instance-attribute
task = TaskEndpoint(self.session)
instance-attribute
task_log = TaskLogEndpoint(self.session)
instance-attribute
timeline = TimelineEndpoint(self.session)
instance-attribute
user = UserEndpoint(self.session)
instance-attribute
organisation = OrganisationEndpoint(self.session)
instance-attribute
profile = ProfileEndpoint(self.session)
instance-attribute
custom_field = CustomFieldEndpoint(self.session)
instance-attribute
observable_type = ObservableTypeEndpoint(self.session)
instance-attribute
cortex = CortexEndpoint(self.session)
instance-attribute
query = QueryEndpoint(self.session)
instance-attribute
session_organisation
property
writable
session
DEFAULT_RETRY = Retry(total=5, backoff_factor=1, status_forcelist=[500, 502, 503, 504], allowed_methods=['GET', 'POST', 'PUT', 'PATCH', 'DELETE'], raise_on_status=False)
module-attribute
RetryValue = Union[Retry, int, None]
module-attribute
VerifyValue = Union[bool, str]
module-attribute
TheHiveSession(url, apikey=None, username=None, password=None, verify=True, max_retries=DEFAULT_RETRY)
Bases: Session
Source code in thehive4py/session.py
37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 |
|
hive_url = self._sanitize_hive_url(url)
instance-attribute
verify = verify
instance-attribute
make_request(method, path, params=None, data=None, json=None, files=None, download_path=None)
Source code in thehive4py/session.py
75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 |
|
endpoints
alert
AlertEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(alert, attachment_map=None)
Create an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert
|
InputAlert
|
The body of the alert. |
required |
attachment_map
|
Optional[Dict[str, str]]
|
An optional mapping of observable attachment keys and paths. |
None
|
Returns:
Type | Description |
---|---|
OutputAlert
|
The created alert. |
Source code in thehive4py/endpoints/alert.py
24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 |
|
get(alert_id)
Get an alert by id.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
Returns:
Type | Description |
---|---|
OutputAlert
|
The alert specified by the id. |
Source code in thehive4py/endpoints/alert.py
47 48 49 50 51 52 53 54 55 56 57 |
|
update(alert_id, fields)
Update an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
fields
|
InputUpdateAlert
|
The fields of the alert to update. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
59 60 61 62 63 64 65 66 67 68 69 70 71 |
|
delete(alert_id)
Delete an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
73 74 75 76 77 78 79 80 81 82 |
|
bulk_update(fields)
Update multiple alerts with the same values.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
fields
|
InputBulkUpdateAlert
|
The ids and the fields of the alerts to update. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
84 85 86 87 88 89 90 91 92 93 94 95 |
|
bulk_delete(ids)
Delete multiple alerts.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
ids
|
List[str]
|
The ids of the alerts to delete. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
97 98 99 100 101 102 103 104 105 106 107 108 |
|
follow(alert_id)
Follow an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
110 111 112 113 114 115 116 117 118 119 |
|
unfollow(alert_id)
Unfollow an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
121 122 123 124 125 126 127 128 129 130 |
|
promote_to_case(alert_id, fields={})
Promote an alert into a case.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
fields
|
InputPromoteAlert
|
Override for the fields of the case created from the alert. |
{}
|
Returns:
Type | Description |
---|---|
OutputCase
|
The case from the promoted alert. |
Source code in thehive4py/endpoints/alert.py
132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 |
|
create_observable(alert_id, observable, observable_path=None)
Create an observable in an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
observable
|
InputObservable
|
The fields of the observable to create. |
required |
observable_path
|
Optional[str]
|
Optional path in case of a file based observable. |
None
|
Returns:
Type | Description |
---|---|
List[OutputObservable]
|
The created alert observables. |
Source code in thehive4py/endpoints/alert.py
150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 |
|
add_attachment(alert_id, attachment_paths)
Create an observable in an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
attachment_paths
|
List[str]
|
List of paths to the attachments to create. |
required |
Returns:
Type | Description |
---|---|
List[OutputAttachment]
|
The created alert attachments. |
Source code in thehive4py/endpoints/alert.py
174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 |
|
download_attachment(alert_id, attachment_id, attachment_path)
Download an alert attachment.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
attachment_id
|
str
|
The id of the alert attachment. |
required |
attachment_path
|
str
|
The local path to download the attachment to. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 |
|
delete_attachment(alert_id, attachment_id)
Delete an alert attachment.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
attachment_id
|
str
|
The id of the alert attachment. |
required |
Returns:
Type | Description |
---|---|
None
|
N/A |
Source code in thehive4py/endpoints/alert.py
213 214 215 216 217 218 219 220 221 222 223 224 225 226 |
|
merge_into_case(alert_id, case_id)
Merge an alert into an existing case.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert to merge. |
required |
case_id
|
str
|
The id of the case to merge the alert into. |
required |
Returns:
Type | Description |
---|---|
OutputCase
|
The case into which the alert was merged. |
Source code in thehive4py/endpoints/alert.py
228 229 230 231 232 233 234 235 236 237 238 239 240 |
|
bulk_merge_into_case(case_id, alert_ids)
Merge an alert into an existing case.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
case_id
|
str
|
The id of the case to merge the alerts into. |
required |
alert_ids
|
List[str]
|
The list of alert ids to merge. |
required |
Returns:
Type | Description |
---|---|
OutputCase
|
The case into which the alerts were merged. |
Source code in thehive4py/endpoints/alert.py
242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 |
|
find(filters=None, sortby=None, paginate=None)
Find multiple alerts.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
filters
|
Optional[FilterExpr]
|
The filter expressions to apply in the query. |
None
|
sortby
|
Optional[SortExpr]
|
The sort expressions to apply in the query. |
None
|
paginate
|
Optional[Paginate]
|
The pagination experssion to apply in the query. |
None
|
Returns:
Type | Description |
---|---|
List[OutputAlert]
|
The list of alerts matched by the query or an empty list. |
Source code in thehive4py/endpoints/alert.py
258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 |
|
count(filters=None)
Count alerts.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
filters
|
Optional[FilterExpr]
|
The filter expressions to apply in the query. |
None
|
Returns:
Type | Description |
---|---|
int
|
The count of alerts matched by the query. |
Source code in thehive4py/endpoints/alert.py
286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 |
|
find_observables(alert_id, filters=None, sortby=None, paginate=None)
Find observable related to an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
filters
|
Optional[FilterExpr]
|
The filter expressions to apply in the query. |
None
|
sortby
|
Optional[SortExpr]
|
The sort expressions to apply in the query. |
None
|
paginate
|
Optional[Paginate]
|
The pagination experssion to apply in the query. |
None
|
Returns:
Type | Description |
---|---|
List[OutputObservable]
|
The list of alert observables matched by the query or an empty list. |
Source code in thehive4py/endpoints/alert.py
309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 |
|
find_comments(alert_id, filters=None, sortby=None, paginate=None)
Find comments related to an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
filters
|
Optional[FilterExpr]
|
The filter expressions to apply in the query. |
None
|
sortby
|
Optional[SortExpr]
|
The sort expressions to apply in the query. |
None
|
paginate
|
Optional[Paginate]
|
The pagination experssion to apply in the query. |
None
|
Returns:
Type | Description |
---|---|
List[OutputComment]
|
The list of alert comments matched by the query or an empty list. |
Source code in thehive4py/endpoints/alert.py
339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 |
|
create_procedure(alert_id, procedure)
Create an alert procedure.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
procedure
|
InputProcedure
|
The fields of the procedure to create. |
required |
Returns:
Type | Description |
---|---|
OutputProcedure
|
The created alert procedure. |
Source code in thehive4py/endpoints/alert.py
369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 |
|
find_procedures(alert_id, filters=None, sortby=None, paginate=None)
Find procedures related to an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
filters
|
Optional[FilterExpr]
|
The filter expressions to apply in the query. |
None
|
sortby
|
Optional[SortExpr]
|
The sort expressions to apply in the query. |
None
|
paginate
|
Optional[Paginate]
|
The pagination experssion to apply in the query. |
None
|
Returns:
Type | Description |
---|---|
List[OutputProcedure]
|
The list of alert procedures matched by the query or an empty list. |
Source code in thehive4py/endpoints/alert.py
385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 |
|
find_attachments(alert_id, filters=None, sortby=None, paginate=None)
Find attachments related to an alert.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
alert_id
|
str
|
The id of the alert. |
required |
filters
|
Optional[FilterExpr]
|
The filter expressions to apply in the query. |
None
|
sortby
|
Optional[SortExpr]
|
The sort expressions to apply in the query. |
None
|
paginate
|
Optional[Paginate]
|
The pagination experssion to apply in the query. |
None
|
Returns:
Type | Description |
---|---|
List[OutputAttachment]
|
The list of alert attachments matched by the query or an empty list. |
Source code in thehive4py/endpoints/alert.py
416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 |
|
case
CaseId = Union[str, int]
module-attribute
CaseEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(case)
Source code in thehive4py/endpoints/case.py
34 35 |
|
get(case_id)
Source code in thehive4py/endpoints/case.py
37 38 |
|
delete(case_id)
Source code in thehive4py/endpoints/case.py
40 41 |
|
update(case_id, fields={}, **kwargs)
Source code in thehive4py/endpoints/case.py
43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 |
|
bulk_update(fields)
Source code in thehive4py/endpoints/case.py
66 67 68 69 |
|
merge(case_ids)
Source code in thehive4py/endpoints/case.py
71 72 73 74 75 |
|
unlink_alert(case_id, alert_id)
Source code in thehive4py/endpoints/case.py
77 78 79 80 |
|
merge_similar_observables(case_id)
Source code in thehive4py/endpoints/case.py
82 83 84 85 86 |
|
get_linked_cases(case_id)
Source code in thehive4py/endpoints/case.py
88 89 |
|
delete_custom_field(custom_field_id)
Source code in thehive4py/endpoints/case.py
91 92 93 94 |
|
import_from_file(import_case, import_path)
Source code in thehive4py/endpoints/case.py
96 97 98 99 100 101 102 103 |
|
export_to_file(case_id, password, export_path)
Source code in thehive4py/endpoints/case.py
105 106 107 108 109 110 111 |
|
get_timeline(case_id)
Source code in thehive4py/endpoints/case.py
113 114 |
|
add_attachment(case_id, attachment_paths)
Source code in thehive4py/endpoints/case.py
116 117 118 119 120 121 122 123 124 125 |
|
download_attachment(case_id, attachment_id, attachment_path)
Source code in thehive4py/endpoints/case.py
127 128 129 130 131 132 133 134 |
|
delete_attachment(case_id, attachment_id)
Source code in thehive4py/endpoints/case.py
136 137 138 139 |
|
list_shares(case_id)
Source code in thehive4py/endpoints/case.py
141 142 |
|
share(case_id, shares)
Source code in thehive4py/endpoints/case.py
144 145 146 147 |
|
unshare(case_id, organisation_ids)
Source code in thehive4py/endpoints/case.py
149 150 151 152 153 154 |
|
set_share(case_id, shares)
Source code in thehive4py/endpoints/case.py
156 157 158 159 |
|
remove_share(share_id)
Source code in thehive4py/endpoints/case.py
161 162 163 164 |
|
update_share(share_id, profile)
Source code in thehive4py/endpoints/case.py
166 167 168 169 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case.py
171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 |
|
count(filters=None)
Source code in thehive4py/endpoints/case.py
189 190 191 192 193 194 195 196 197 198 199 200 201 |
|
create_task(case_id, task)
Source code in thehive4py/endpoints/case.py
203 204 205 206 207 208 |
|
find_tasks(case_id, filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case.py
210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 |
|
create_observable(case_id, observable, observable_path=None)
Source code in thehive4py/endpoints/case.py
230 231 232 233 234 235 236 237 238 239 240 241 |
|
find_observables(case_id, filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case.py
243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 |
|
create_procedure(case_id, procedure)
Source code in thehive4py/endpoints/case.py
262 263 264 265 266 267 |
|
find_procedures(case_id, filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case.py
269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 |
|
create_page(case_id, page)
Source code in thehive4py/endpoints/case.py
289 290 291 292 |
|
delete_page(case_id, page_id)
Source code in thehive4py/endpoints/case.py
294 295 296 297 |
|
update_page(case_id, page_id, page)
Source code in thehive4py/endpoints/case.py
299 300 301 302 303 304 |
|
find_pages(case_id, filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case.py
306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 |
|
find_attachments(case_id, filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case.py
326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 |
|
find_comments(case_id, filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case.py
345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 |
|
close(case_id, status, summary, impact_status='NotApplicable')
Source code in thehive4py/endpoints/case.py
364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 |
|
open(case_id, status=CaseStatus.InProgress)
Source code in thehive4py/endpoints/case.py
381 382 383 384 385 |
|
case_template
CaseTemplateEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/case_template.py
11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 |
|
get(case_template_id)
Source code in thehive4py/endpoints/case_template.py
29 30 31 32 |
|
create(case_template)
Source code in thehive4py/endpoints/case_template.py
34 35 36 37 |
|
delete(case_template_id)
Source code in thehive4py/endpoints/case_template.py
39 40 41 42 |
|
update(case_template_id, fields)
Source code in thehive4py/endpoints/case_template.py
44 45 46 47 |
|
comment
CommentEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create_in_alert(alert_id, comment)
Source code in thehive4py/endpoints/comment.py
7 8 9 10 |
|
create_in_case(case_id, comment)
Source code in thehive4py/endpoints/comment.py
12 13 14 15 |
|
get(comment_id)
Source code in thehive4py/endpoints/comment.py
17 18 19 20 21 22 23 24 25 26 27 |
|
delete(comment_id)
Source code in thehive4py/endpoints/comment.py
29 30 31 32 |
|
update(comment_id, fields)
Source code in thehive4py/endpoints/comment.py
34 35 36 37 |
|
cortex
CortexEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create_analyzer_job(job)
Source code in thehive4py/endpoints/cortex.py
14 15 16 17 |
|
create_responder_action(action)
Source code in thehive4py/endpoints/cortex.py
19 20 21 22 23 24 |
|
list_analyzers(range=None)
Source code in thehive4py/endpoints/cortex.py
26 27 28 29 30 |
|
list_analyzers_by_type(data_type)
Source code in thehive4py/endpoints/cortex.py
32 33 34 35 |
|
get_analyzer(analyzer_id)
Source code in thehive4py/endpoints/cortex.py
37 38 39 40 |
|
get_analyzer_job(job_id)
Source code in thehive4py/endpoints/cortex.py
42 43 44 45 |
|
list_responders(entity_type, entity_id)
Source code in thehive4py/endpoints/cortex.py
47 48 49 50 51 52 |
|
custom_field
CustomFieldEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(custom_field)
Source code in thehive4py/endpoints/custom_field.py
12 13 14 15 |
|
list()
Source code in thehive4py/endpoints/custom_field.py
17 18 |
|
delete(custom_field_id)
Source code in thehive4py/endpoints/custom_field.py
20 21 22 23 |
|
update(custom_field_id, fields)
Source code in thehive4py/endpoints/custom_field.py
25 26 27 28 |
|
observable
ObservableEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create_in_alert(alert_id, observable, observable_path=None)
Source code in thehive4py/endpoints/observable.py
18 19 20 21 22 23 24 25 26 27 28 29 |
|
create_in_case(case_id, observable, observable_path=None)
Source code in thehive4py/endpoints/observable.py
31 32 33 34 35 36 37 38 39 40 41 42 |
|
get(observable_id)
Source code in thehive4py/endpoints/observable.py
44 45 46 47 |
|
delete(observable_id)
Source code in thehive4py/endpoints/observable.py
49 50 51 52 |
|
update(observable_id, fields)
Source code in thehive4py/endpoints/observable.py
54 55 56 57 |
|
bulk_update(fields)
Source code in thehive4py/endpoints/observable.py
59 60 61 62 |
|
share(observable_id, organisations)
Source code in thehive4py/endpoints/observable.py
64 65 66 67 68 69 |
|
unshare(observable_id, organisations)
Source code in thehive4py/endpoints/observable.py
71 72 73 74 75 76 |
|
list_shares(observable_id)
Source code in thehive4py/endpoints/observable.py
78 79 80 81 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/observable.py
83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 |
|
count(filters=None)
Source code in thehive4py/endpoints/observable.py
101 102 103 104 105 106 107 108 109 110 111 112 113 |
|
download_attachment(observable_id, attachment_id, observable_path, as_zip=False)
Source code in thehive4py/endpoints/observable.py
115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 |
|
observable_type
ObservableTypeEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(observable_type)
Source code in thehive4py/endpoints/observable_type.py
15 16 17 18 |
|
get(observable_type_id)
Source code in thehive4py/endpoints/observable_type.py
20 21 22 23 |
|
delete(observable_type_id)
Source code in thehive4py/endpoints/observable_type.py
25 26 27 28 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/observable_type.py
30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 |
|
organisation
OrganisationEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(organisation)
Source code in thehive4py/endpoints/organisation.py
19 20 21 22 |
|
get(org_id)
Source code in thehive4py/endpoints/organisation.py
24 25 |
|
update(org_id, fields)
Source code in thehive4py/endpoints/organisation.py
27 28 29 30 |
|
delete(org_id)
Source code in thehive4py/endpoints/organisation.py
32 33 34 35 |
|
link(org_id, other_org_id, link)
Source code in thehive4py/endpoints/organisation.py
37 38 39 40 |
|
unlink(org_id, other_org_id)
Source code in thehive4py/endpoints/organisation.py
42 43 44 45 |
|
list_links(org_id)
Source code in thehive4py/endpoints/organisation.py
47 48 49 50 |
|
bulk_link(org_id, links)
Source code in thehive4py/endpoints/organisation.py
52 53 54 55 |
|
list_sharing_profiles()
Source code in thehive4py/endpoints/organisation.py
57 58 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/organisation.py
60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 |
|
count(filters=None)
Source code in thehive4py/endpoints/organisation.py
78 79 80 81 82 83 84 85 86 87 88 89 90 |
|
procedure
ProcedureEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create_in_alert(alert_id, procedure)
Source code in thehive4py/endpoints/procedure.py
17 18 19 20 21 22 |
|
create_in_case(case_id, procedure)
Source code in thehive4py/endpoints/procedure.py
24 25 26 27 28 29 |
|
get(procedure_id)
Source code in thehive4py/endpoints/procedure.py
31 32 33 34 35 36 37 38 39 40 41 |
|
delete(procedure_id)
Source code in thehive4py/endpoints/procedure.py
43 44 45 46 |
|
update(procedure_id, fields)
Source code in thehive4py/endpoints/procedure.py
48 49 50 51 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/procedure.py
53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 |
|
profile
ProfileEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(profile)
Source code in thehive4py/endpoints/profile.py
12 13 |
|
get(profile_id)
Source code in thehive4py/endpoints/profile.py
15 16 |
|
delete(profile_id)
Source code in thehive4py/endpoints/profile.py
18 19 |
|
update(profile_id, fields)
Source code in thehive4py/endpoints/profile.py
21 22 23 24 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/profile.py
26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 |
|
count(filters=None)
Source code in thehive4py/endpoints/profile.py
44 45 46 47 48 49 50 51 52 53 54 55 56 |
|
query
QueryEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
run(query, exclude_fields=[])
Source code in thehive4py/endpoints/query.py
7 8 9 10 11 12 13 14 |
|
task
TaskEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(case_id, task)
Source code in thehive4py/endpoints/task.py
18 19 20 21 |
|
get(task_id)
Source code in thehive4py/endpoints/task.py
23 24 |
|
delete(task_id)
Source code in thehive4py/endpoints/task.py
26 27 |
|
update(task_id, fields)
Source code in thehive4py/endpoints/task.py
29 30 31 32 |
|
bulk_update(fields)
Source code in thehive4py/endpoints/task.py
34 35 36 37 |
|
get_required_actions(task_id)
Source code in thehive4py/endpoints/task.py
39 40 41 42 |
|
set_as_required(task_id, org_id)
Source code in thehive4py/endpoints/task.py
44 45 46 47 |
|
set_as_done(task_id, org_id)
Source code in thehive4py/endpoints/task.py
49 50 51 52 |
|
share()
Source code in thehive4py/endpoints/task.py
54 55 |
|
list_shares()
Source code in thehive4py/endpoints/task.py
57 58 |
|
unshare()
Source code in thehive4py/endpoints/task.py
60 61 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/task.py
63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 |
|
count(filters=None)
Source code in thehive4py/endpoints/task.py
81 82 83 84 85 86 87 88 89 90 91 92 93 |
|
create_log(task_id, task_log)
Source code in thehive4py/endpoints/task.py
95 96 97 98 |
|
find_logs(task_id, filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/task.py
100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 |
|
task_log
TaskLogEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(task_id, task_log)
Source code in thehive4py/endpoints/task_log.py
9 10 11 12 |
|
get(task_log_id)
Source code in thehive4py/endpoints/task_log.py
14 15 16 17 18 19 20 21 22 23 24 25 |
|
delete(task_log_id)
Source code in thehive4py/endpoints/task_log.py
27 28 |
|
update(task_log_id, fields)
Source code in thehive4py/endpoints/task_log.py
30 31 32 33 |
|
add_attachments(task_log_id, attachment_paths)
Source code in thehive4py/endpoints/task_log.py
35 36 37 38 39 40 41 42 |
|
delete_attachment(task_log_id, attachment_id)
Source code in thehive4py/endpoints/task_log.py
44 45 46 47 |
|
timeline
TimelineEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
get(case_id)
Source code in thehive4py/endpoints/timeline.py
11 12 |
|
create_event(case_id, event)
Source code in thehive4py/endpoints/timeline.py
14 15 16 17 |
|
delete_event(event_id)
Source code in thehive4py/endpoints/timeline.py
19 20 21 22 |
|
update_event(event_id, fields)
Source code in thehive4py/endpoints/timeline.py
24 25 26 27 |
|
user
UserEndpoint(session)
Bases: EndpointBase
Source code in thehive4py/endpoints/_base.py
15 16 |
|
create(user)
Source code in thehive4py/endpoints/user.py
18 19 |
|
get(user_id)
Source code in thehive4py/endpoints/user.py
21 22 |
|
get_current()
Source code in thehive4py/endpoints/user.py
24 25 |
|
delete(user_id, organisation=None)
Source code in thehive4py/endpoints/user.py
27 28 29 30 31 32 |
|
update(user_id, fields)
Source code in thehive4py/endpoints/user.py
34 35 36 37 |
|
lock(user_id)
Source code in thehive4py/endpoints/user.py
39 40 |
|
unlock(user_id)
Source code in thehive4py/endpoints/user.py
42 43 |
|
set_organisations(user_id, organisations)
Source code in thehive4py/endpoints/user.py
45 46 47 48 49 50 51 52 |
|
set_password(user_id, password)
Source code in thehive4py/endpoints/user.py
54 55 56 57 58 59 |
|
get_apikey(user_id)
Source code in thehive4py/endpoints/user.py
61 62 |
|
remove_apikey(user_id)
Source code in thehive4py/endpoints/user.py
64 65 |
|
renew_apikey(user_id)
Source code in thehive4py/endpoints/user.py
67 68 69 70 |
|
get_avatar(user_id)
Source code in thehive4py/endpoints/user.py
72 73 74 |
|
find(filters=None, sortby=None, paginate=None)
Source code in thehive4py/endpoints/user.py
76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 |
|
count(filters=None)
Source code in thehive4py/endpoints/user.py
94 95 96 97 98 99 100 101 102 103 104 105 106 |
|
types
alert
InputAlertRequired
Bases: TypedDict
type
instance-attribute
source
instance-attribute
sourceRef
instance-attribute
title
instance-attribute
description
instance-attribute
InputAlert
Bases: InputAlertRequired
date
instance-attribute
externalLink
instance-attribute
severity
instance-attribute
tags
instance-attribute
flag
instance-attribute
tlp
instance-attribute
pap
instance-attribute
customFields
instance-attribute
summary
instance-attribute
status
instance-attribute
assignee
instance-attribute
caseTemplate
instance-attribute
observables
instance-attribute
procedures
instance-attribute
OutputAlertRequired
Bases: TypedDict
type
instance-attribute
source
instance-attribute
sourceRef
instance-attribute
title
instance-attribute
description
instance-attribute
severity
instance-attribute
severityLabel
instance-attribute
date
instance-attribute
tlp
instance-attribute
tlpLabel
instance-attribute
pap
instance-attribute
papLabel
instance-attribute
follow
instance-attribute
observableCount
instance-attribute
status
instance-attribute
stage
instance-attribute
extraData
instance-attribute
newDate
instance-attribute
timeToDetect
instance-attribute
OutputAlert
Bases: OutputAlertRequired
externalLink
instance-attribute
tags
instance-attribute
customFields
instance-attribute
caseTemplate
instance-attribute
caseId
instance-attribute
assignee
instance-attribute
summary
instance-attribute
inProgressDate
instance-attribute
closedDate
instance-attribute
importedDate
instance-attribute
timeToTriage
instance-attribute
timeToQualify
instance-attribute
timeToAcknowledge
instance-attribute
InputUpdateAlert
Bases: TypedDict
type
instance-attribute
source
instance-attribute
sourceRef
instance-attribute
externalLink
instance-attribute
title
instance-attribute
description
instance-attribute
severity
instance-attribute
date
instance-attribute
lastSyncDate
instance-attribute
tags
instance-attribute
tlp
instance-attribute
pap
instance-attribute
follow
instance-attribute
customFields
instance-attribute
status
instance-attribute
summary
instance-attribute
assignee
instance-attribute
addTags
instance-attribute
removeTags
instance-attribute
InputBulkUpdateAlert
Bases: InputUpdateAlert
ids
instance-attribute
InputPromoteAlert
Bases: TypedDict
title
instance-attribute
description
instance-attribute
severity
instance-attribute
startDate
instance-attribute
endDate
instance-attribute
tags
instance-attribute
flag
instance-attribute
tlp
instance-attribute
pap
instance-attribute
status
instance-attribute
summary
instance-attribute
assignee
instance-attribute
customFields
instance-attribute
caseTemplate
instance-attribute
tasks
instance-attribute
pages
instance-attribute
sharingParameters
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
attachment
OutputAttachmentRequired
Bases: TypedDict
name
instance-attribute
size
instance-attribute
contentType
instance-attribute
id
instance-attribute
OutputAttachment
Bases: OutputAttachmentRequired
hashes
instance-attribute
case
CaseStatusValue = Literal['New', 'InProgress', 'Indeterminate', 'FalsePositive', 'TruePositive', 'Other', 'Duplicated']
module-attribute
ImpactStatusValue = Literal['NotApplicable', 'WithImpact', 'NoImpact']
module-attribute
CaseStatus
New = 'New'
class-attribute
instance-attribute
InProgress = 'InProgress'
class-attribute
instance-attribute
Indeterminate = 'Indeterminate'
class-attribute
instance-attribute
FalsePositive = 'FalsePositive'
class-attribute
instance-attribute
TruePositive = 'TruePositive'
class-attribute
instance-attribute
Other = 'Other'
class-attribute
instance-attribute
Duplicated = 'Duplicated'
class-attribute
instance-attribute
ImpactStatus
NotApplicable = 'NotApplicable'
class-attribute
instance-attribute
WithImpact = 'WithImpact'
class-attribute
instance-attribute
NoImpact = 'NoImpact'
class-attribute
instance-attribute
InputCaseRequired
Bases: TypedDict
title
instance-attribute
description
instance-attribute
InputCase
Bases: InputCaseRequired
severity
instance-attribute
startDate
instance-attribute
endDate
instance-attribute
tags
instance-attribute
flag
instance-attribute
tlp
instance-attribute
pap
instance-attribute
status
instance-attribute
summary
instance-attribute
assignee
instance-attribute
customFields
instance-attribute
caseTemplate
instance-attribute
tasks
instance-attribute
pages
instance-attribute
sharingParameters
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
OutputCaseRequired
Bases: TypedDict
number
instance-attribute
title
instance-attribute
description
instance-attribute
severity
instance-attribute
severityLabel
instance-attribute
startDate
instance-attribute
flag
instance-attribute
tlp
instance-attribute
tlpLabel
instance-attribute
pap
instance-attribute
papLabel
instance-attribute
status
instance-attribute
stage
instance-attribute
extraData
instance-attribute
newDate
instance-attribute
timeToDetect
instance-attribute
OutputCase
Bases: OutputCaseRequired
endDate
instance-attribute
tags
instance-attribute
summary
instance-attribute
impactStatus
instance-attribute
assignee
instance-attribute
customFields
instance-attribute
userPermissions
instance-attribute
inProgressDate
instance-attribute
closedDate
instance-attribute
alertDate
instance-attribute
alertNewDate
instance-attribute
alertInProgressDate
instance-attribute
alertImportedDate
instance-attribute
timeToTriage
instance-attribute
timeToQualify
instance-attribute
timeToAcknowledge
instance-attribute
timeToResolve
instance-attribute
handlingDuration
instance-attribute
InputUpdateCase
Bases: TypedDict
title
instance-attribute
description
instance-attribute
severity
instance-attribute
startDate
instance-attribute
endDate
instance-attribute
tags
instance-attribute
flag
instance-attribute
tlp
instance-attribute
pap
instance-attribute
status
instance-attribute
summary
instance-attribute
assignee
instance-attribute
impactStatus
instance-attribute
customFields
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
addTags
instance-attribute
removeTags
instance-attribute
InputBulkUpdateCase
Bases: InputUpdateCase
ids
instance-attribute
InputImportCaseRequired
Bases: TypedDict
password
instance-attribute
InputImportCase
Bases: InputImportCaseRequired
sharingParameters
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
case_template
SeverityValue = Literal[1, 2, 3, 4]
module-attribute
TlpValue = Literal[0, 1, 2, 3, 4]
module-attribute
PapValue = Literal[0, 1, 2, 3]
module-attribute
InputCaseTemplateRequired
Bases: TypedDict
name
instance-attribute
InputCaseTemplate
Bases: InputCaseTemplateRequired
displayName
instance-attribute
titlePrefix
instance-attribute
description
instance-attribute
severity
instance-attribute
tags
instance-attribute
flag
instance-attribute
tlp
instance-attribute
pap
instance-attribute
summary
instance-attribute
tasks
instance-attribute
pageTemplateIds
instance-attribute
customFields
instance-attribute
OutputCaseTemplateRequired
Bases: TypedDict
name
instance-attribute
OutputCaseTemplate
Bases: OutputCaseTemplateRequired
displayName
instance-attribute
titlePrefix
instance-attribute
description
instance-attribute
severity
instance-attribute
tags
instance-attribute
flag
instance-attribute
tlp
instance-attribute
pap
instance-attribute
summary
instance-attribute
tasks
instance-attribute
pageTemplateIds
instance-attribute
customFields
instance-attribute
comment
InputComment
Bases: TypedDict
message
instance-attribute
OutputCommentRequired
Bases: TypedDict
createdBy
instance-attribute
createdAt
instance-attribute
message
instance-attribute
isEdited
instance-attribute
OutputComment
Bases: OutputCommentRequired
updatedAt
instance-attribute
InputUpdateComment
Bases: TypedDict
message
instance-attribute
cortex
OutputAnalyzerRequired
Bases: TypedDict
id
instance-attribute
name
instance-attribute
version
instance-attribute
description
instance-attribute
OutputAnalyzer
Bases: OutputAnalyzerRequired
dataTypeList
instance-attribute
cortexIds
instance-attribute
OutputResponderRequired
Bases: TypedDict
id
instance-attribute
name
instance-attribute
version
instance-attribute
description
instance-attribute
OutputResponder
Bases: OutputResponderRequired
dataTypeList
instance-attribute
cortexIds
instance-attribute
OutputAnalyzerJobRequired
Bases: TypedDict
analyzerId
instance-attribute
analyzerName
instance-attribute
analyzerDefinition
instance-attribute
status
instance-attribute
startDate
instance-attribute
cortexId
instance-attribute
cortexJobId
instance-attribute
id
instance-attribute
operations
instance-attribute
OutputAnalyzerJob
Bases: TypedDict
endDate
instance-attribute
report
instance-attribute
case_artifact
instance-attribute
OutputResponderActionRequired
Bases: TypedDict
responderId
instance-attribute
status
instance-attribute
startDate
instance-attribute
cortexId
instance-attribute
cortexJobId
instance-attribute
id
instance-attribute
operations
instance-attribute
OutputResponderAction
Bases: OutputResponderActionRequired
endDate
instance-attribute
report
instance-attribute
responderName
instance-attribute
responderDefinition
instance-attribute
InputResponderActionRequired
Bases: TypedDict
objectId
instance-attribute
objectType
instance-attribute
responderId
instance-attribute
InputResponderAction
Bases: InputResponderActionRequired
parameters
instance-attribute
tlp
instance-attribute
InputAnalyzerJobRequired
Bases: TypedDict
analyzerId
instance-attribute
cortexId
instance-attribute
observableId
instance-attribute
InputAnalyzerJob
Bases: InputAnalyzerJobRequired
parameters
instance-attribute
custom_field
InputCustomFieldValueRequired
Bases: TypedDict
name
instance-attribute
InputCustomFieldValue
Bases: InputCustomFieldValueRequired
value
instance-attribute
order
instance-attribute
OutputCustomFieldValue
Bases: TypedDict
name
instance-attribute
description
instance-attribute
type
instance-attribute
value
instance-attribute
order
instance-attribute
InputCustomFieldRequired
Bases: TypedDict
name
instance-attribute
group
instance-attribute
description
instance-attribute
type
instance-attribute
InputCustomField
Bases: InputCustomFieldRequired
displayName
instance-attribute
mandatory
instance-attribute
options
instance-attribute
OutputCustomFieldRequired
Bases: TypedDict
name
instance-attribute
displayName
instance-attribute
group
instance-attribute
description
instance-attribute
type
instance-attribute
mandatory
instance-attribute
OutputCustomField
Bases: OutputCustomFieldRequired
options
instance-attribute
InputUpdateCustomField
Bases: TypedDict
displayName
instance-attribute
group
instance-attribute
description
instance-attribute
type
instance-attribute
options
instance-attribute
mandatory
instance-attribute
observable
InputObservableRequired
Bases: TypedDict
dataType
instance-attribute
InputObservable
Bases: InputObservableRequired
data
instance-attribute
message
instance-attribute
startDate
instance-attribute
tlp
instance-attribute
pap
instance-attribute
tags
instance-attribute
ioc
instance-attribute
sighted
instance-attribute
sightedAt
instance-attribute
ignoreSimilarity
instance-attribute
isZip
instance-attribute
zipPassword
instance-attribute
attachment
instance-attribute
OutputObservableRequired
Bases: TypedDict
dataType
instance-attribute
startDate
instance-attribute
tlp
instance-attribute
pap
instance-attribute
ioc
instance-attribute
sighted
instance-attribute
reports
instance-attribute
extraData
instance-attribute
ignoreSimilarity
instance-attribute
OutputObservable
Bases: OutputObservableRequired
data
instance-attribute
attachment
instance-attribute
tags
instance-attribute
sightedAt
instance-attribute
message
instance-attribute
InputUpdateObservable
Bases: TypedDict
dataType
instance-attribute
message
instance-attribute
tlp
instance-attribute
pap
instance-attribute
tags
instance-attribute
ioc
instance-attribute
sighted
instance-attribute
sightedAt
instance-attribute
ignoreSimilarity
instance-attribute
InputBulkUpdateObservable
Bases: InputUpdateObservable
ids
instance-attribute
observable_type
InputObservableTypeRequired
Bases: TypedDict
name
instance-attribute
InputObservableType
Bases: InputObservableTypeRequired
isAttachment
instance-attribute
OutputObservableTypeRequired
Bases: TypedDict
name
instance-attribute
isAttachment
instance-attribute
OutputObservableType
Bases: OutputObservableTypeRequired
organisation
InputOrganisationLink
Bases: TypedDict
linkType
instance-attribute
otherLinkType
instance-attribute
InputBulkOrganisationLink
Bases: TypedDict
toOrganisation
instance-attribute
linkType
instance-attribute
otherLinkType
instance-attribute
OutputSharingProfile
Bases: TypedDict
name
instance-attribute
description
instance-attribute
autoShare
instance-attribute
editable
instance-attribute
permissionProfile
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
InputOrganisationRequired
Bases: TypedDict
name
instance-attribute
description
instance-attribute
InputOrganisation
Bases: InputOrganisationRequired
taskRule
instance-attribute
observableRule
instance-attribute
locked
instance-attribute
OutputOrganisationRequired
Bases: TypedDict
name
instance-attribute
description
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
locked
instance-attribute
extraData
instance-attribute
OutputOrganisation
Bases: OutputOrganisationRequired
links
instance-attribute
avatar
instance-attribute
InputUpdateOrganisation
Bases: TypedDict
name
instance-attribute
description
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
locked
instance-attribute
avatar
instance-attribute
page
InputCasePageRequired
Bases: TypedDict
title
instance-attribute
content
instance-attribute
category
instance-attribute
InputCasePage
Bases: InputCasePageRequired
order
instance-attribute
OutputCasePageRequired
Bases: TypedDict
id
instance-attribute
createdBy
instance-attribute
createdAt
instance-attribute
title
instance-attribute
content
instance-attribute
slug
instance-attribute
order
instance-attribute
category
instance-attribute
OutputCasePage
Bases: OutputCasePageRequired
updatedBy
instance-attribute
updatedAt
instance-attribute
InputUpdateCasePage
Bases: TypedDict
title
instance-attribute
content
instance-attribute
category
instance-attribute
order
instance-attribute
procedure
InputProcedureRequired
Bases: TypedDict
occurDate
instance-attribute
patternId
instance-attribute
InputProcedure
Bases: InputProcedureRequired
tactic
instance-attribute
description
instance-attribute
OutputProcedureRequired
Bases: TypedDict
occurDate
instance-attribute
tactic
instance-attribute
tacticLabel
instance-attribute
extraData
instance-attribute
OutputProcedure
Bases: OutputProcedureRequired
description
instance-attribute
patternId
instance-attribute
patternName
instance-attribute
InputUpdateProcedure
Bases: TypedDict
description
instance-attribute
occurDate
instance-attribute
profile
InputProfileRequired
Bases: TypedDict
name
instance-attribute
InputProfile
Bases: InputProfileRequired
permissions
instance-attribute
OutputProfileRequired
Bases: TypedDict
name
instance-attribute
editable
instance-attribute
isAdmin
instance-attribute
OutputProfile
Bases: OutputProfileRequired
permissions
instance-attribute
InputUpdateProfile
Bases: TypedDict
name
instance-attribute
permissions
instance-attribute
share
OutputShareRequired
Bases: TypedDict
caseId
instance-attribute
profileName
instance-attribute
organisationName
instance-attribute
owner
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
OutputShare
Bases: OutputShareRequired
InputShareRequired
Bases: TypedDict
organisation
instance-attribute
InputShare
Bases: InputShareRequired
share
instance-attribute
profile
instance-attribute
taskRule
instance-attribute
observableRule
instance-attribute
task
InputTaskRequired
Bases: TypedDict
title
instance-attribute
InputTask
Bases: InputTaskRequired
group
instance-attribute
description
instance-attribute
status
instance-attribute
flag
instance-attribute
startDate
instance-attribute
endDate
instance-attribute
order
instance-attribute
dueDate
instance-attribute
assignee
instance-attribute
mandatory
instance-attribute
OutputTaskRequired
Bases: TypedDict
title
instance-attribute
group
instance-attribute
status
instance-attribute
flag
instance-attribute
order
instance-attribute
mandatory
instance-attribute
extraData
instance-attribute
OutputTask
Bases: OutputTaskRequired
description
instance-attribute
startDate
instance-attribute
endDate
instance-attribute
assignee
instance-attribute
dueDate
instance-attribute
InputUpdateTask
Bases: TypedDict
title
instance-attribute
group
instance-attribute
description
instance-attribute
status
instance-attribute
flag
instance-attribute
startDate
instance-attribute
endDate
instance-attribute
order
instance-attribute
dueDate
instance-attribute
assignee
instance-attribute
mandatory
instance-attribute
InputBulkUpdateTask
Bases: InputUpdateTask
ids
instance-attribute
task_log
InputTaskLogRequired
Bases: TypedDict
message
instance-attribute
InputTaskLog
Bases: InputTaskLogRequired
startDate
instance-attribute
includeInTimeline
instance-attribute
OutputTaskLogRequired
Bases: TypedDict
message
instance-attribute
date
instance-attribute
owner
instance-attribute
extraData
instance-attribute
OutputTaskLog
Bases: OutputTaskLogRequired
attachments
instance-attribute
includeInTimeline
instance-attribute
InputUpdateTaskLog
Bases: TypedDict
message
instance-attribute
includeInTimeline
instance-attribute
timeline
OutputTimelineEventRequired
Bases: TypedDict
date
instance-attribute
kind
instance-attribute
entity
instance-attribute
entityId
instance-attribute
details
instance-attribute
OutputTimelineEvent
Bases: OutputTimelineEventRequired
endDate
instance-attribute
OutputTimeline
Bases: TypedDict
events
instance-attribute
InputCustomEventRequired
Bases: TypedDict
date
instance-attribute
title
instance-attribute
InputCustomEvent
Bases: InputCustomEventRequired
endDate
instance-attribute
description
instance-attribute
OutputCustomEventRequired
Bases: TypedDict
date
instance-attribute
title
instance-attribute
OutputCustomEvent
Bases: OutputCustomEventRequired
endDate
instance-attribute
description
instance-attribute
InputUpdateCustomEvent
Bases: TypedDict
date
instance-attribute
endDate
instance-attribute
title
instance-attribute
description
instance-attribute
user
InputUserRequired
Bases: TypedDict
login
instance-attribute
name
instance-attribute
profile
instance-attribute
InputUser
Bases: InputUserRequired
email
instance-attribute
password
instance-attribute
organisation
instance-attribute
type
instance-attribute
OutputOrganisationProfile
Bases: TypedDict
organisationId
instance-attribute
organisation
instance-attribute
profile
instance-attribute
OutputUserRequired
Bases: TypedDict
login
instance-attribute
name
instance-attribute
hasKey
instance-attribute
hasPassword
instance-attribute
hasMFA
instance-attribute
locked
instance-attribute
profile
instance-attribute
organisation
instance-attribute
type
instance-attribute
extraData
instance-attribute
OutputUser
Bases: OutputUserRequired
email
instance-attribute
permissions
instance-attribute
avatar
instance-attribute
organisations
instance-attribute
defaultOrganisation
instance-attribute
InputUpdateUser
Bases: TypedDict
name
instance-attribute
organisation
instance-attribute
profile
instance-attribute
locked
instance-attribute
avatar
instance-attribute
email
instance-attribute
defaultOrganisation
instance-attribute
InputUserOrganisationRequired
Bases: TypedDict
organisation
instance-attribute
profile
instance-attribute
InputUserOrganisation
Bases: InputUserOrganisationRequired
default
instance-attribute
OutputUserOrganisation
Bases: TypedDict
organisation
instance-attribute
profile
instance-attribute
default
instance-attribute
query
QueryExpr = List[Union[_FilterExpr, _SortExpr, Paginate, dict]]
module-attribute
filters
FilterExpr = _Union['_FilterBase', dict]
module-attribute
Lt(field, value)
Bases: _FilterBase
Field less than value.
Source code in thehive4py/query/filters.py
37 38 |
|
Gt(field, value)
Bases: _FilterBase
Field greater than value.
Source code in thehive4py/query/filters.py
44 45 |
|
Lte(field, value)
Bases: _FilterBase
Field less than or equal value.
Source code in thehive4py/query/filters.py
51 52 |
|
Gte(field, value)
Bases: _FilterBase
Field less than or equal value.
Source code in thehive4py/query/filters.py
58 59 |
|
Ne(field, value)
Bases: _FilterBase
Field not equal value.
Source code in thehive4py/query/filters.py
65 66 |
|
Eq(field, value)
Bases: _FilterBase
Field equal value.
Source code in thehive4py/query/filters.py
72 73 |
|
StartsWith(field, value)
Bases: _FilterBase
Field starts with value.
Source code in thehive4py/query/filters.py
79 80 |
|
EndsWith(field, value)
Bases: _FilterBase
Field ends with value.
Source code in thehive4py/query/filters.py
86 87 |
|
Id(id)
Bases: _FilterBase
FIlter by ID.
Source code in thehive4py/query/filters.py
93 94 |
|
Between(field, start, end)
Bases: _FilterBase
Field between inclusive from and exclusive to values.
Source code in thehive4py/query/filters.py
100 101 |
|
In(field, values)
Bases: _FilterBase
Field is one of the values.
Source code in thehive4py/query/filters.py
107 108 |
|
Contains(field)
Bases: _FilterBase
Object contains the field.
Source code in thehive4py/query/filters.py
114 115 116 117 118 119 120 121 122 |
|
Has(field)
Bases: _FilterBase
Object contains the field.
Source code in thehive4py/query/filters.py
128 129 |
|
Like(field, value)
Bases: _FilterBase
Field contains the value.
Source code in thehive4py/query/filters.py
135 136 |
|
Match(field, value)
Bases: _FilterBase
Field contains the value
Source code in thehive4py/query/filters.py
142 143 |
|
page
Paginate(start, end, extra_data=[])
Bases: UserDict
Source code in thehive4py/query/page.py
5 6 |
|
sort
SortExpr
Bases: UserDict
Base class for sort expressions.
__and__(other)
Source code in thehive4py/query/sort.py
7 8 |
|
__or__(other)
Source code in thehive4py/query/sort.py
10 11 |
|
Asc(field)
Bases: SortExpr
Source code in thehive4py/query/sort.py
28 29 |
|
Desc(field)
Bases: SortExpr
Source code in thehive4py/query/sort.py
33 34 |
|
errors
TheHiveError(message, response=None, *args, **kwargs)
Bases: Exception
Base error class of thehive4py.
Parameters:
Name | Type | Description | Default |
---|---|---|---|
message
|
str
|
The exception message. |
required |
response
|
Optional[Response]
|
Either |
None
|
Source code in thehive4py/errors.py
8 9 10 11 12 13 14 15 16 17 18 19 |
|