OPEN REST API & STIX 2.1

Developer API & Threat Intelligence Feeds

Programmatically query 90 landmark cyberattack legal records, mapped MITRE ATT&CK techniques, CISA advisories, and STIX 2.1 bundles for automated SIEM/SOAR ingestion and threat modeling pipelines.

Key Facts

  • Zero authentication required; open static REST JSON endpoints updated on every automated pipeline run.
  • STIX 2.1 compliant object bundle for direct ingestion into OpenCTI, MISP, and Microsoft Sentinel.
  • Complete historical case dataset includes court citations, financial losses, and CISA advisory mappings.
  • Permits free research, academic, and internal enterprise defensive modeling usage under public domain terms.
GET /api/v1/cases.json
JSON REST

Retrieve full array of 90 primary-sourced landmark cyberattack cases with financial losses, court dockets, and MITRE ATT&CK techniques.

Example Query: curl -s https://cybercaselibrary.com/api/v1/cases.json | jq ".[0]"
GET /api/v1/techniques.json
JSON REST

Retrieve all mapped MITRE ATT&CK enterprise techniques cross-referenced against primary evidentiary citations in federal indictments.

Example Query: curl -s https://cybercaselibrary.com/api/v1/techniques.json | jq ".[:3]"
GET /api/v1/threat-actors.json
JSON REST

List attributed nation-state advanced persistent threats (APTs) and cybercrime syndicates with country of origin and aliases.

Example Query: curl -s https://cybercaselibrary.com/api/v1/threat-actors.json | jq ".[0]"
GET /api/v1/stix2.json
JSON REST

Download the complete canonical STIX 2.1 Threat Intelligence Bundle for direct ingestion into MISP, OpenCTI, or Sentinel.

Example Query: curl -s https://cybercaselibrary.com/api/v1/stix2.json | jq ".objects | length"

Bulk Data Exports Hub

Need full offline SQLite database files, bulk CSV tables, or CISA KEV crosswalk mappings? Visit our Data Downloads Hub for direct one-click downloads.