Developer API & Threat Intelligence Feeds
Programmatically query 90 landmark cyberattack legal records, mapped MITRE ATT&CK techniques, CISA advisories, and STIX 2.1 bundles for automated SIEM/SOAR ingestion and threat modeling pipelines.
Key Facts
- Zero authentication required; open static REST JSON endpoints updated on every automated pipeline run.
- STIX 2.1 compliant object bundle for direct ingestion into OpenCTI, MISP, and Microsoft Sentinel.
- Complete historical case dataset includes court citations, financial losses, and CISA advisory mappings.
- Permits free research, academic, and internal enterprise defensive modeling usage under public domain terms.
Retrieve full array of 90 primary-sourced landmark cyberattack cases with financial losses, court dockets, and MITRE ATT&CK techniques.
curl -s https://cybercaselibrary.com/api/v1/cases.json | jq ".[0]" Retrieve all mapped MITRE ATT&CK enterprise techniques cross-referenced against primary evidentiary citations in federal indictments.
curl -s https://cybercaselibrary.com/api/v1/techniques.json | jq ".[:3]" List attributed nation-state advanced persistent threats (APTs) and cybercrime syndicates with country of origin and aliases.
curl -s https://cybercaselibrary.com/api/v1/threat-actors.json | jq ".[0]" Download the complete canonical STIX 2.1 Threat Intelligence Bundle for direct ingestion into MISP, OpenCTI, or Sentinel.
curl -s https://cybercaselibrary.com/api/v1/stix2.json | jq ".objects | length" Bulk Data Exports Hub
Need full offline SQLite database files, bulk CSV tables, or CISA KEV crosswalk mappings? Visit our Data Downloads Hub for direct one-click downloads.