# EclecticIQ Developer Portal Documentation > The EIQ Developer Portal organises all the developer resources in one easy-to-navigate, self-service website, empowering developers to get started quickly with EclecticIQ tools. Append .md to any documentation page URL to get its markdown version. ## Guides - [Documentation](https://developers.eclecticiq.com/docs.md): EclecticIQ Developer Portal documentation ## API Reference - [Get an aggregation that counts entities per field values usages](https://developers.eclecticiq.com/reference/get_aggregations-entities-counts.md): This endpoint is going to be replaced in v3 by `/entities/aggregations`. **Required permissions** - `read entities` - [Get an aggregation that counts uploaded-blobs per field values usages](https://developers.eclecticiq.com/reference/get_aggregations-uploaded-blobs-counts.md): This endpoint is going to be replaced in v3 by `/uploaded-blobs/aggregations`. **Required permissions** - `read blob-uploads` - [Delete a set of CSV Mappings referenced by IDs.](https://developers.eclecticiq.com/reference/delete_csv-mappings.md): **Required permissions** - `modify csv-mappings` - [Returns the list of CSV Mappings on the platform.](https://developers.eclecticiq.com/reference/get_csv-mappings.md): **Required permissions** - `read csv-mappings` - [Create a CSV Mapping.](https://developers.eclecticiq.com/reference/post_csv-mappings.md): **Required permissions** - `modify csv-mappings` - [Create (or modify if the name already exists) one or more csv-mappings.](https://developers.eclecticiq.com/reference/put_csv-mappings.md): **Required permissions** - `modify csv-mappings` - [Get Entity supported fields in a CSV Mapping.](https://developers.eclecticiq.com/reference/get_csv-mappings-supported-fields.md): **Required permissions** - `read csv-mappings` - [Delete a CSV Mapping by ID.](https://developers.eclecticiq.com/reference/delete_csv-mappings-id.md): **Required permissions** - `modify csv-mappings` - [Get a CSV Mapping by ID.](https://developers.eclecticiq.com/reference/get_csv-mappings-id.md): **Required permissions** - `read csv-mappings` - [Update a CSV Mapping.](https://developers.eclecticiq.com/reference/patch_csv-mappings-id.md): **Required permissions** - `modify csv-mappings` - [Get a list of content blocks.](https://developers.eclecticiq.com/reference/get_content-blocks.md): **Required permissions** - `read content-blocks` - [Get a content block by ID.](https://developers.eclecticiq.com/reference/get_content-blocks-id.md): **Required permissions** - `read content-blocks` - [Delete a set of datasets referenced by IDs.](https://developers.eclecticiq.com/reference/delete_datasets.md): **Required permissions** - `modify intel-sets` - [Get a list of datasets.](https://developers.eclecticiq.com/reference/get_datasets.md): **Required permissions** - `read intel-sets` - [Create a dataset.](https://developers.eclecticiq.com/reference/post_datasets.md): **Required permissions** - `modify intel-sets` - [Create (or update if the name already exists) one or more datasets.](https://developers.eclecticiq.com/reference/put_datasets.md): **Required permissions** - `modify intel-sets` - [Bulk delete entities from a dataset.](https://developers.eclecticiq.com/reference/put_datasets-dataset-id-entities.md): **Required permissions** - `modify intel-sets` - `read entities` - [Add entities to a dataset by query.](https://developers.eclecticiq.com/reference/post_datasets-dataset-id-entities-add-tasks.md): **Required permissions** - `modify intel-sets` - `read entities` - [Delete a dataset.](https://developers.eclecticiq.com/reference/delete_datasets-id.md): **Required permissions** - `modify intel-sets` - [Get a dataset by ID.](https://developers.eclecticiq.com/reference/get_datasets-id.md): **Required permissions** - `read intel-sets` - [Update a dataset.](https://developers.eclecticiq.com/reference/patch_datasets-id.md): **Required permissions** - `modify intel-sets` - [Delete a dataset in a background task.](https://developers.eclecticiq.com/reference/delete_datasets-id-delete-tasks.md): **Required permissions** - `modify intel-sets` - [Delete a set of discovery_rules referenced by IDs.](https://developers.eclecticiq.com/reference/delete_rules-discovery.md): **Required permissions** - `modify intel-sets` - [Get a list of discovery rules.](https://developers.eclecticiq.com/reference/get_rules-discovery.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `read rules` **Optional permissions** - `read tasks` Required to read the tasks attached to discovery rules - `read workspaces` Required to access the workspaces a discovery rule is attached to - [Create a new discovery rule.](https://developers.eclecticiq.com/reference/post_rules-discovery.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `modify rules` **Optional permissions** - `read tasks` Required to read the tasks attached to discovery rules - `read workspaces` Required to access the workspaces a discovery rule is attached to - [Create (or update if the name already exists) one or more discovery rules.](https://developers.eclecticiq.com/reference/put_rules-discovery.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `modify rules` **Optional permissions** - `read tasks` Required to read the tasks attached to discovery rules - `read workspaces` Required to access the workspaces a discovery rule is attached to - [Delete a discovery rule by ID.](https://developers.eclecticiq.com/reference/delete_rules-discovery-id.md): **Required permissions** - `modify rules` - [Get a discovery rule by ID.](https://developers.eclecticiq.com/reference/get_rules-discovery-id.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `read rules` **Optional permissions** - `read tasks` Required to read the tasks attached to discovery rules - `read workspaces` Required to access the workspaces a discovery rule is attached to - [Edit a discovery rule by ID.](https://developers.eclecticiq.com/reference/patch_rules-discovery-id.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `modify rules` **Optional permissions** - `read tasks` Required to read the tasks attached to discovery rules - `read workspaces` Required to access the workspaces a discovery rule is attached to - [Get a list of enrichers.](https://developers.eclecticiq.com/reference/get_enrichers.md): **Required permissions** - `read enrichers` **Optional permissions** - `read tasks` Required to access the task associated to an enricher - [Create a new enricher.](https://developers.eclecticiq.com/reference/post_enrichers.md): **Required permissions** - `modify enrichers` **Optional permissions** - `read tasks` Required to access the task associated to an enricher - [Create (or modify if the name already exists) one or more enrichers.](https://developers.eclecticiq.com/reference/put_enrichers.md): **Required permissions** - `modify enrichers` **Optional permissions** - `read tasks` Required to access the task associated to an enricher - [Enriches all given extracts and/or entities with a list of enrichers.](https://developers.eclecticiq.com/reference/post_enrichers-run.md): Note: - If `enricher_tasks` is empty, all available enrichers are used - If a list entities is provided, all entity extracts are enriched The endpoint return a TaskGroup with progress details for all invoked tasks. **Required permissions** - `modify enrichments` - `read enrichers` - `read tasks` **Optional permissions** - `read entities` Required to specify a list of entities - `read extracts` Required to specify a list of observables - [Get an enricher by ID.](https://developers.eclecticiq.com/reference/get_enrichers-id.md): **Required permissions** - `read enrichers` **Optional permissions** - `read tasks` Required to access the task associated to an enricher - [Modify an enricher.](https://developers.eclecticiq.com/reference/patch_enrichers-id.md): **Required permissions** - `modify enrichers` **Optional permissions** - `read tasks` Required to access the task associated to an enricher - [Delete a set of enrichment rules referenced by IDs.](https://developers.eclecticiq.com/reference/delete_rules-enrichments.md): **Required permissions** - `modify rules` - [Get a list of enrichment rules.](https://developers.eclecticiq.com/reference/get_rules-enrichments.md): **Required permissions** - `read rules` - [Create a new enrichment rule.](https://developers.eclecticiq.com/reference/post_rules-enrichments.md): **Required permissions** - `modify rules` - [Create (or update if the name already exists) one or more enrichment rules.](https://developers.eclecticiq.com/reference/put_rules-enrichments.md): **Required permissions** - `modify rules` - [Delete an enrichment rule by ID.](https://developers.eclecticiq.com/reference/delete_rules-enrichments-id.md): **Required permissions** - `modify rules` - [Get an enrichment rule by ID.](https://developers.eclecticiq.com/reference/get_rules-enrichments-id.md): **Required permissions** - `read rules` - [Edit an enrichment rule by ID.](https://developers.eclecticiq.com/reference/patch_rules-enrichments-id.md): **Required permissions** - `modify rules` - [Delete a set of entities referenced by internal or STIX IDs.](https://developers.eclecticiq.com/reference/delete_entities.md): Note: - Referencing an entity by internal (UUID) ID will delete _only_ that specific version/record of the entity. - Referencing an entity by STIX ID will delete all the versions of the specified entity. - Does not delete an entity if: - it has a draft - it is a part of a static dataset - it is a master entity in entity rules - it has related tasks - it is a part of a public dataset - it is outdated unless ``force`` flag is set to ``True`` **Required permissions** - `modify entities` - [Get a list of entities.](https://developers.eclecticiq.com/reference/get_entities.md): **Required permissions** - `read entities` **Optional permissions** - `read extracts` Required to access the observables attached with an entity - `read taxonomies` Required to access the taxonomies associated with an entity - `read attack` Required to access the MITRE ATT&CKs associated with an entity - `read intel-sets` Required to access the datasets associated with an entity - `read incoming-feeds` Required to access the incoming feeds associated with an entity - `read outgoing-feeds` Required to access the outgoing feeds associated with an entity - [Create an entity.](https://developers.eclecticiq.com/reference/post_entities.md): This endpoint leverages the external (STIX) ID provided on the payload's ``data`` attribute to de-duplicate the entity. If an entity with the provided STIX ID already exists, this endpoint returns ``409: Conflict``, and you should use ``PATCH /api//entities/`` instead to update it. **Required permissions** - `modify entities` **Optional permissions** - `read extracts` Required to access the observables attached with an entity - `read taxonomies` Required to access the taxonomies associated with an entity - `read attack` Required to access the MITRE ATT&CKs associated with an entity - `read intel-sets` Required to access the datasets associated with an entity - `read incoming-feeds` Required to access the incoming feeds associated with an entity - `read outgoing-feeds` Required to access the outgoing feeds associated with an entity - [Create (or update/create a new version if the STIX ID already exists) one or more entities.](https://developers.eclecticiq.com/reference/put_entities.md): **Required permissions** - `modify entities` **Optional permissions** - `read extracts` Required to access the observables attached with an entity - `read taxonomies` Required to access the taxonomies associated with an entity - `read attack` Required to access the MITRE ATT&CKs associated with an entity - `read intel-sets` Required to access the datasets associated with an entity - `read incoming-feeds` Required to access the incoming feeds associated with an entity - `read outgoing-feeds` Required to access the outgoing feeds associated with an entity - [Delete the entities that match the specified search query.](https://developers.eclecticiq.com/reference/post_entities-delete-tasks.md): The removal is applied in a background task. If no query is specified, there is no operation executed. Entities are usually exempt from deletion if: - in static datasets - in public workspaces - set in merge rules as master entity - having tasks attached - having drafts If `ignore_exemptions` flag is set to `True`, all checks except are bypassed and entities will be deleted. **Required permissions** - `modify entities` - `read tasks` - [Enrich entities by search query](https://developers.eclecticiq.com/reference/post_entities-enrich-tasks.md): Starts enricher tasks for the entities that match the specified search query. Enrichment is done on the entities extracts (observables) with a list of selected enrichers, if extracts are supported by specified enrichers. For a search query with a relatively big number of matched entities, the endpoint might have scalability issues since a new enricher task is triggered per single extract. Recommended way to work with big dataset is to use time-window filters to reduce the number of matching entities... The endpoint only starts enricher tasks, and the caller should later retrieve task group information to get the status of the whole operation. **Required permissions** - `modify enrichments` - `read entities` - `read tasks` - `read enrichers` - [Export the entities that match the specified search query.](https://developers.eclecticiq.com/reference/post_entities-export-tasks.md): The action is executed in a background task. If no query is specified, there is no operation executed. **Required permissions** - `modify entities` - `read tasks` - [Invoke a relational search query.](https://developers.eclecticiq.com/reference/post_entities-relational-search.md): **Relational search** allows users to find entities which have *relations* to other entities, while both `entity sets` have specific search criteria. The query representing nodes: `query_1.es_query`, or `query_2.es_query` are native elasticsearch supported query objects. It is possible to search: 1. Only directly related entities 2. Both entities related directly or indirectly through any intermediary entity For example, a relational query looking for "all ttps with tag 'bar' linked to indicators with tag 'apt-x'", will be: ``` { "data":{ "query_1": { "es_query": { "query_string": { "query": "data.type:ttp AND meta.tags: bar", "lenient": true, } }, "node_type": "entity", }, "query_2": { "es_query": { "query_string": { "query": "data.type:indicator AND meta.tags: apt-x", "lenient": true, } }, "node_type": "entity", }, "relation_query": {"query_string": {"query": "*", "lenient": true}}, "output": "query_1", } } ``` **Required permissions** - `read entities` - [Applies a change to the entities that match the specified search query.](https://developers.eclecticiq.com/reference/post_entities-update-tasks.md): The change is applied in a background task. If no query is specified, there is no operation executed. **Required permissions** - `modify entities` - `read tasks` **Optional permissions** - `read taxonomies` Required to access the taxonomies associated with an entity - `read attack` Required to access the MITRE ATT&CKs associated with an entity - [Delete an entity by ID. Does not delete an entity if:](https://developers.eclecticiq.com/reference/delete_entities-id.md): - it has a draft - it is a part of a static dataset - it is a master entity in entity rules - it has related tasks - it is a part of a public dataset - it is outdated unless ``force`` flag is set to ``True`` **Required permissions** - `modify entities` - [Get an entity by ID.](https://developers.eclecticiq.com/reference/get_entities-id.md): **Required permissions** - `read entities` **Optional permissions** - `read extracts` Required to access the observables attached with an entity - `read taxonomies` Required to access the taxonomies associated with an entity - `read attack` Required to access the MITRE ATT&CKs associated with an entity - `read intel-sets` Required to access the datasets associated with an entity - `read incoming-feeds` Required to access the incoming feeds associated with an entity - `read outgoing-feeds` Required to access the outgoing feeds associated with an entity - [Update an entity by ID.](https://developers.eclecticiq.com/reference/patch_entities-id.md): The ID can be either an internal ID or an external (STIX) ID. Note, that an unified entity (an entity with ``is_unified_entity`` flag set to ``True`` in meta) cannot be modified by user. An attempt to modify it will result in an error. **Required permissions** - `modify entities` **Optional permissions** - `read extracts` Required to access the observables attached with an entity - `read taxonomies` Required to access the taxonomies associated with an entity - `read attack` Required to access the MITRE ATT&CKs associated with an entity - `read intel-sets` Required to access the datasets associated with an entity - `read incoming-feeds` Required to access the incoming feeds associated with an entity - `read outgoing-feeds` Required to access the outgoing feeds associated with an entity - [Consolidate the entities that match the specified search query.](https://developers.eclecticiq.com/reference/post_entities-consolidate-tasks.md): Entities matching the query are consolidated into one. If entities are not of the same type or If an entity is already a contributor to another entity, an exception is raised. The action is applied in a background task. If no query is specified, there is no operation executed. **Required permissions** - `modify entities` - `read tasks` - [Undo consolidation of the entities that match the specified search query.](https://developers.eclecticiq.com/reference/post_entities-deconsolidate-tasks.md): Each matching entity is decoupled from its consolidation group. Decoupled entities are not going to be consolidated by future matching policies but can still be merged manually via ``consolidate-tasks`` endpoint. If remaining contributors for each respective consolidation group are a single entity, the group is dissolved, unified entities are removed and contibutors are returned to a standalone state. The action is applied in a background task. If no query is specified, there is no operation executed. **Required permissions** - `modify entities` - `read tasks` - [Get content of an entity attachment by ID.](https://developers.eclecticiq.com/reference/get_entities-attachments-id-content.md): **Required permissions** - `read entities` - [Delete a set of entity attachments referenced by IDs.](https://developers.eclecticiq.com/reference/delete_entities-attachments.md): **Required permissions** - `modify entities` - [Delete a set of files referenced by IDs.](https://developers.eclecticiq.com/reference/delete_files.md): **Required permissions** - `modify files` - [Get a list of entity attachments.](https://developers.eclecticiq.com/reference/get_entities-attachments.md): **Required permissions** - `read entities` - [Get a list of workspace files.](https://developers.eclecticiq.com/reference/get_files.md): If the user is not admin, then only the files that are either public or attached to a workspace where the user is a collaborator will be returned. **Required permissions** - `read files` **Optional permissions** - `read workspaces` To access the workspace a file is attached to - `read user` To access the file creator information - [Create a new entity attachment.](https://developers.eclecticiq.com/reference/post_entities-attachments.md): **Required permissions** - `modify entities` - [Create a new file in a workspace.](https://developers.eclecticiq.com/reference/post_files.md): The creation of a file in a workspace is only allowed if: - The user is a collaborator of the workspace, or - The user is a platform admin **Required permissions** - `modify files` **Optional permissions** - `read workspaces` To access the workspace a file is attached to - `read user` To access the file creator information - [Delete an entity attachment by ID.](https://developers.eclecticiq.com/reference/delete_entities-attachments-id.md): On top of the required permissions, deleting attachments is allowed only if: - The user is the creator of the attachment, or - The user is a platform admin **Required permissions** - `modify entities` - [Delete a workspace file by ID.](https://developers.eclecticiq.com/reference/delete_files-id.md): On top of the required permissions, deleting files is allowed only if: - The user is the creator of the file, or - The user is a platform admin **Required permissions** - `modify files` - [Get an entity attachment by ID.](https://developers.eclecticiq.com/reference/get_entities-attachments-id.md): **Required permissions** - `read entities` - [Get a workspace file by ID.](https://developers.eclecticiq.com/reference/get_files-id.md): On top of the required permissions, reading a file attached to a workspace is allowed only if: - The user is a collaborator of the workspace, or - The user is a platform admin, or - The file has `is_public=True`. The file content hash must be unique per workspace. **Required permissions** - `read files` **Optional permissions** - `read workspaces` To access the workspace a file is attached to - `read user` To access the file creator information - [Get content of a file by ID.](https://developers.eclecticiq.com/reference/get_files-id-content.md): **Required permissions** - `read files` - [Download an entity attachment by ID.](https://developers.eclecticiq.com/reference/get_entities-attachments-id-download.md): Deprecated in favor of entities/attachments/{id}/content. **Required permissions** - `read entities` - [Download a file by ID.](https://developers.eclecticiq.com/reference/get_files-id-download.md): Deprecated in favor of /files/{id}/content. **Required permissions** - `read files` - [Delete a set of entity rules referenced by IDs.](https://developers.eclecticiq.com/reference/delete_rules-entities.md): **Required permissions** - `modify rules` - [Get a list of entity rules.](https://developers.eclecticiq.com/reference/get_rules-entities.md): **Required permissions** - `read rules` **Optional permissions** - `read intel-sets` Required to access the datasets attached to entity rules - `read entities` Required to access the master entity attached to entity rules - `read tasks` Required to access the tasks attached to entity rules - `read taxonomies` Required to access the taxonomies attached to entity rules - [Create a new entity rule.](https://developers.eclecticiq.com/reference/post_rules-entities.md): **Required permissions** - `modify rules` **Optional permissions** - `read intel-sets` Required to access the datasets attached to entity rules - `read entities` Required to access the master entity attached to entity rules - `read tasks` Required to access the tasks attached to entity rules - `read taxonomies` Required to access the taxonomies attached to entity rules - [Create (or update if the name already exists) one or more entity rules.](https://developers.eclecticiq.com/reference/put_rules-entities.md): **Required permissions** - `modify rules` **Optional permissions** - `read intel-sets` Required to access the datasets attached to entity rules - `read entities` Required to access the master entity attached to entity rules - `read tasks` Required to access the tasks attached to entity rules - `read taxonomies` Required to access the taxonomies attached to entity rules - [Delete an entity rule by ID.](https://developers.eclecticiq.com/reference/delete_rules-entities-id.md): **Required permissions** - `modify rules` - [Get an entity rule by ID.](https://developers.eclecticiq.com/reference/get_rules-entities-id.md): **Required permissions** - `read rules` **Optional permissions** - `read intel-sets` Required to access the datasets attached to entity rules - `read entities` Required to access the master entity attached to entity rules - `read tasks` Required to access the tasks attached to entity rules - `read taxonomies` Required to access the taxonomies attached to entity rules - [Edit an entity rule by ID.](https://developers.eclecticiq.com/reference/patch_rules-entities-id.md): **Required permissions** - `modify rules` **Optional permissions** - `read intel-sets` Required to access the datasets attached to entity rules - `read entities` Required to access the master entity attached to entity rules - `read tasks` Required to access the tasks attached to entity rules - `read taxonomies` Required to access the taxonomies attached to entity rules - [Get content of an export block by ID.](https://developers.eclecticiq.com/reference/get_export-blocks-id-content.md): **Required permissions** - `read entities` - [Delete a set of groups referenced by IDs.](https://developers.eclecticiq.com/reference/delete_groups.md): **Required permissions** - `modify groups` - [Returns a list of the groups on the platform.](https://developers.eclecticiq.com/reference/get_groups.md): Note that only the groups the user is a member of will be returned. Only global admin users can see the full list of groups. **Required permissions** - `read groups` **Optional permissions** - `read users` Required to access the list of users on a group (alternatively, you can only see users for the groups you administer) - [Create a group.](https://developers.eclecticiq.com/reference/post_groups.md): **Required permissions** - `modify groups` - [Create (or modify if the name already exists) one or more groups.](https://developers.eclecticiq.com/reference/put_groups.md): **Required permissions** - `modify groups` - [Delete a group by ID.](https://developers.eclecticiq.com/reference/delete_groups-id.md): **Required permissions** - `modify groups` - [Get a group by ID.](https://developers.eclecticiq.com/reference/get_groups-id.md): Note that only the groups the user is a member of will be returned. Only global admin users can see the full list of groups. **Required permissions** - `read groups` **Optional permissions** - `read users` Required to access the list of users on a group (alternatively, you can only see users for the groups you administer) - [Update a group.](https://developers.eclecticiq.com/reference/patch_groups-id.md): Note that you can only update groups that you administer (unless you are a global admin), and modifying the sources attached to a group requires the `modify groups` permission. **Required permissions** - `read groups` **Optional permissions** - `modify groups` Required to modify the sources attached to a group - [Delete a set of incoming feeds referenced by IDs.](https://developers.eclecticiq.com/reference/delete_incoming-feeds.md): **Required permissions** - `modify incoming-feeds` - [Get a list of incoming feeds.](https://developers.eclecticiq.com/reference/get_incoming-feeds.md): **Required permissions** - `read incoming-feeds` **Optional permissions** - `read tasks` To read the tasks associated to the feeds - [Configure a new incoming feed.](https://developers.eclecticiq.com/reference/post_incoming-feeds.md): Depending on the content type it will be required to provide additional transport configuration fields. For more details see the documentation **Required permissions** - `modify incoming-feeds` **Optional permissions** - `read tasks` To read/modify the task associated to this feed - [Create (or update if the name already exists) an incoming feed.](https://developers.eclecticiq.com/reference/put_incoming-feeds.md): **Required permissions** - `modify incoming-feeds` **Optional permissions** - `read tasks` To read/modify the task associated to this feed - [Delete an incoming feed configuration by ID.](https://developers.eclecticiq.com/reference/delete_incoming-feeds-id.md): **Required permissions** - `modify incoming-feeds` - [Get an incoming feed by ID.](https://developers.eclecticiq.com/reference/get_incoming-feeds-id.md): **Required permissions** - `read incoming-feeds` **Optional permissions** - `read tasks` To read the task associated to this feed - [Edit an incoming feed configuration by ID.](https://developers.eclecticiq.com/reference/patch_incoming-feeds-id.md): **Required permissions** - `modify incoming-feeds` **Optional permissions** - `read tasks` To read/modify the task associated to this feed - [Returns a list of knowledge packs.](https://developers.eclecticiq.com/reference/get_knowledge-packs.md): **Required permissions** - `read knowledge-packs` - [Create a new knowledge pack.](https://developers.eclecticiq.com/reference/post_knowledge-packs.md): **Note:** Setting the "state" field only supported with PATCH method. **Required permissions** - `modify knowledge-packs` - `read knowledge-packs` - [Create (or modify if already exists) one or more knowledge packs.](https://developers.eclecticiq.com/reference/put_knowledge-packs.md): **Note:** Setting the "state" field only supported with PATCH method. **Required permissions** - `modify knowledge-packs` - `read knowledge-packs` - [Delete a knowledge pack as publisher.](https://developers.eclecticiq.com/reference/delete_knowledge-packs-id.md): **Required permissions** - `modify knowledge-packs` - `read knowledge-packs` - [Get a Knowledge Pack by ID.](https://developers.eclecticiq.com/reference/get_knowledge-packs-id.md): **Required permissions** - `read knowledge-packs` - [Update a knowledge pack.](https://developers.eclecticiq.com/reference/patch_knowledge-packs-id.md): Knowledge pack life cycle can be managed by setting "state" to one of following values: `INSTALLED`, `UNINSTALLED`, `PUBLISHED` or `NEW`. **Note:** Setting state only supported with PATCH method and cannot be mixed with update of other fields. **Required permissions** - `modify knowledge-packs` - `read knowledge-packs` - [Delete a set of Attack Analysis referenced by IDs.](https://developers.eclecticiq.com/reference/delete_attack-analyses.md): **Required permissions** - `modify attack` - [Get a list of Attack Analyses.](https://developers.eclecticiq.com/reference/get_attack-analyses.md): **Required permissions** - `read attack` - [Create an Attack Analysis.](https://developers.eclecticiq.com/reference/post_attack-analyses.md): **Required permissions** - `modify attack` - [Delete a dataset from the scope of an Attack Analysis.](https://developers.eclecticiq.com/reference/delete_attack-analyses-analysis-id-datasets-dataset-id.md): **Required permissions** - `modify attack` - `read intel-sets` - [Add a dataset to the scope of an Attack Analysis.](https://developers.eclecticiq.com/reference/put_attack-analyses-analysis-id-datasets-dataset-id.md): **Required permissions** - `modify attack` - `read intel-sets` - [Bulk delete entities from the scope of an Attack Analysis.](https://developers.eclecticiq.com/reference/delete_attack-analyses-analysis-id-entities.md): **Required permissions** - `modify attack` - `read entities` - [Bulk add entities to the scope of an Attack Analysis.](https://developers.eclecticiq.com/reference/put_attack-analyses-analysis-id-entities.md): **Required permissions** - `modify attack` - `read entities` - [Delete an Attack Analysis by ID.](https://developers.eclecticiq.com/reference/delete_attack-analyses-id.md): **Required permissions** - `modify attack` - [Get an Attack Analysis by ID.](https://developers.eclecticiq.com/reference/get_attack-analyses-id.md): **Required permissions** - `read attack` - [Update an Attack Analysis by ID.](https://developers.eclecticiq.com/reference/patch_attack-analyses-id.md): **Required permissions** - `modify attack` - [Get a list of Attack Analysis Annotations.](https://developers.eclecticiq.com/reference/get_attack-analysis-annotations.md): **Required permissions** - `read attack` - [Create an Attack Analysis Annotation.](https://developers.eclecticiq.com/reference/post_attack-analysis-annotations.md): **Required permissions** - `modify attack` - [Create (or update) one or more Attack Analysis Annotations.](https://developers.eclecticiq.com/reference/put_attack-analysis-annotations.md): **Required permissions** - `modify attack` - [Delete an Attack Analysis Annotation by ID.](https://developers.eclecticiq.com/reference/delete_attack-analysis-annotations-id.md): **Required permissions** - `modify attack` - [Get an Attack Analysis Annotation by ID.](https://developers.eclecticiq.com/reference/get_attack-analysis-annotations-id.md): **Required permissions** - `read attack` - [Update an Attack Analysis Annotation by ID.](https://developers.eclecticiq.com/reference/patch_attack-analysis-annotations-id.md): **Required permissions** - `modify attack` - [Get a list of MITRE Attack Defense Relationships.](https://developers.eclecticiq.com/reference/get_attack-defense-relationships.md): **Required permissions** - `read attack` - [Get a list of MITRE Attack Defenses.](https://developers.eclecticiq.com/reference/get_attack-defenses.md): **Required permissions** - `read attack` - [Get a list of MITRE Attacks.](https://developers.eclecticiq.com/reference/get_attacks.md): **Required permissions** - `read attack` - [Get MITRE Attack by ID.](https://developers.eclecticiq.com/reference/get_attacks-id.md): **Required permissions** - `read attack` - [Delete a set of observable rules referenced by IDs.](https://developers.eclecticiq.com/reference/delete_rules-observables.md): **Required permissions** - `modify rules` - [Get a list of observable rules.](https://developers.eclecticiq.com/reference/get_rules-observables.md): **Required permissions** - `read rules` **Optional permissions** - `read tasks` Required to access the tasks associated to observable rules - [Create a new observable rule.](https://developers.eclecticiq.com/reference/post_rules-observables.md): **Required permissions** - `modify rules` **Optional permissions** - `read tasks` Required to access the tasks associated to observable rules - [Create (or update if the name already exists) one or more observable rules.](https://developers.eclecticiq.com/reference/put_rules-observables.md): **Required permissions** - `modify rules` **Optional permissions** - `read tasks` Required to access the tasks associated to observable rules - [Delete an observable rule by ID.](https://developers.eclecticiq.com/reference/delete_rules-observables-id.md): **Required permissions** - `modify rules` **Optional permissions** - `read tasks` Required to access the tasks associated to observable rules - [Get an observable rule by ID.](https://developers.eclecticiq.com/reference/get_rules-observables-id.md): **Required permissions** - `read rules` **Optional permissions** - `read tasks` Required to access the tasks associated to observable rules - [Edit an observable rule by ID.](https://developers.eclecticiq.com/reference/patch_rules-observables-id.md): **Required permissions** - `modify rules` **Optional permissions** - `read tasks` Required to access the tasks associated to observable rules - [Delete a set of observables referenced by IDs.](https://developers.eclecticiq.com/reference/delete_observables.md): **Required permissions** - `modify extracts` - [Get a list of observables.](https://developers.eclecticiq.com/reference/get_observables.md): **Required permissions** - `read extracts` - [Create a new observable.](https://developers.eclecticiq.com/reference/post_observables.md): **Required permissions** - `modify extracts` - [Create (or update if the (`type`, `value`) pair already exists) one or more observables.](https://developers.eclecticiq.com/reference/put_observables.md): **Required permissions** - `modify extracts` - [Delete the extracts that match the specified search query. Only extracts matching the query are deleted.](https://developers.eclecticiq.com/reference/post_observables-delete-tasks.md): **Required permissions** - `modify extracts` - `read tasks` - [Enrich the extracts that match the specified search query.](https://developers.eclecticiq.com/reference/post_observables-enrich-tasks.md): Starts enricher tasks for the extracts that match the specified search query. Enrichment is done on the extracts (observables) with a list of selected enrichers, if extracts are supported by specified enrichers. The endpoint only starts enricher tasks, and the caller should later retrieve task groups information to get the status of the whole operation. **Required permissions** - `modify extracts` - `read tasks` - `modify enrichments` - `read enrichers` - [Export the extracts that match the specified search query.](https://developers.eclecticiq.com/reference/post_observables-export-tasks.md): Action is executed in a background task. If no query is specified, there is no operation executed. **Required permissions** - `modify extracts` - `read tasks` - [Update risk score of extracts that match the specified search query and create score update records.](https://developers.eclecticiq.com/reference/post_observables-score-update-tasks.md): Action is executed in a background task. If no query is specified, there is no operation executed. **Required permissions** - `modify extracts` - `modify tasks` - [Update the extracts that match the specified search query.](https://developers.eclecticiq.com/reference/post_observables-update-tasks.md): Action is executed in a background task. If no query is specified, there is no operation executed. **Required permissions** - `modify extracts` - `read tasks` - [Delete an observable by ID.](https://developers.eclecticiq.com/reference/delete_observables-id.md): **Required permissions** - `modify extracts` - [Get an observable by ID.](https://developers.eclecticiq.com/reference/get_observables-id.md): **Required permissions** - `read extracts` - [Edit an observable by ID.](https://developers.eclecticiq.com/reference/patch_observables-id.md): **Required permissions** - `modify extracts` - [Get a history of risk score changes for an observable.](https://developers.eclecticiq.com/reference/get_observables-id-score-updates.md): **Required permissions** - `read extracts` - [Create an observable risk score update.](https://developers.eclecticiq.com/reference/post_observables-id-score-updates.md): **Required permissions** - `modify extracts` - [Delete a set of outgoing feeds referenced by IDs.](https://developers.eclecticiq.com/reference/delete_outgoing-feeds.md): **Required permissions** - `modify outgoing-feeds` - [Get a list of outgoing feeds.](https://developers.eclecticiq.com/reference/get_outgoing-feeds.md): **Required permissions** - `read outgoing-feeds` **Optional permissions** - `read intel-sets` To read the datasets associated to the feeds - `read tasks` To read the tasks associated to the feeds - `read taxonomies` To read the whitelisted taxonomy nodes associated to the feeds - [Configure a new outgoing feed.](https://developers.eclecticiq.com/reference/post_outgoing-feeds.md): Depending on the content type it will be required to provide additional transport configuration fields. For more details see the documentation **Required permissions** - `modify outgoing-feeds` **Optional permissions** - `read intel-sets` To read/modify the datasets associated to this feed - `read tasks` To read/modify the tasks associated to this feed - `read taxonomies` To read/modify the whitelisted taxonomy nodes associated to this feed - [Create (or update if the name already exists) one or more outgoing feeds.](https://developers.eclecticiq.com/reference/put_outgoing-feeds.md): **Required permissions** - `modify outgoing-feeds` **Optional permissions** - `read intel-sets` To read/modify the datasets associated to this feed - `read tasks` To read/modify the tasks associated to this feed - `read taxonomies` To read/modify the whitelisted taxonomy nodes associated to this feed - [Delete an outgoing feed configuration by ID.](https://developers.eclecticiq.com/reference/delete_outgoing-feeds-id.md): **Required permissions** - `modify outgoing-feeds` - [Get an outgoing feed by ID.](https://developers.eclecticiq.com/reference/get_outgoing-feeds-id.md): **Required permissions** - `read outgoing-feeds` **Optional permissions** - `read intel-sets` To read the datasets associated to this feed - `read tasks` To read the tasks associated to this feed - `read taxonomies` To read the whitelisted taxonomy nodes associated to this feed - [Edit an outgoing feed configuration by ID.](https://developers.eclecticiq.com/reference/patch_outgoing-feeds-id.md): **Required permissions** - `modify outgoing-feeds` **Optional permissions** - `read intel-sets` To read/modify the datasets associated to this feed - `read tasks` To read/modify the tasks associated to this feed - `read taxonomies` To read/modify the whitelisted taxonomy nodes associated to this feed - [Returns a list of permissions on the platform.](https://developers.eclecticiq.com/reference/get_permissions.md): **Required permissions** - `read permissions` - [Get a user permission by ID.](https://developers.eclecticiq.com/reference/get_permissions-id.md): **Required permissions** - `read permissions` - [Generic endpoint for bulk deleting relations based on "main object" type and id and related objects type and ids (provided in request body).](https://developers.eclecticiq.com/reference/delete_object-type-object-id-relation-type.md) - [Generic endpoint for bulk adding relations based on "main object" type and id and related objects type and ids (provided in request body).](https://developers.eclecticiq.com/reference/put_object-type-object-id-relation-type.md) - [Generic endpoint for deleting a relation based on "main object" type and id and related object type and id.](https://developers.eclecticiq.com/reference/delete_object-type-object-id-relation-type-relation-id.md) - [Generic endpoint for adding a relation based on "main object" type and id and related object type and id.](https://developers.eclecticiq.com/reference/put_object-type-object-id-relation-type-relation-id.md) - [Delete relationships based on source and/or target.](https://developers.eclecticiq.com/reference/delete_relationships.md): **Required permissions** - `modify entities` - [Get a list of relationships.](https://developers.eclecticiq.com/reference/get_relationships.md): **Required permissions** - `read entities` - [Create a relationship.](https://developers.eclecticiq.com/reference/post_relationships.md): **Required permissions** - `modify entities` - [Create, update, or de-duplicate one or more relationships.](https://developers.eclecticiq.com/reference/put_relationships.md): For each relationship in the request body: 1. If an ``id`` or ``data.id`` is provided and matches an existing relationship, that relationship is updated in place. On update there are some restrictions: a. Only ``data.key`` and ``data.description``, and ``meta`` can be changed else a 400 is raised b. Other existing properties in ``data`` can be provided but only with the same value c. Any other root properties than ``data`` and ``meta`` are ignored 2. If no id is provided but a relationship with the same source entity, target entity and relationship type (``data.key``) already exists, the incoming relationship is de-duplicated: it is merged into the existing one following the relationship de-duplication rules (highest TLP wins, earliest ``estimated_threat_start_time`` and latest ``estimated_threat_end_time`` are kept, and descriptions are concatenated). The provided source is added to the existing sources. 3. Otherwise, a new relationship is created. Duplicates within the same request body (matching on source, target and type) are merged together following the same de-duplication rules before being persisted. Returns ``201`` if at least one relationship was created, otherwise ``200``. **Required permissions** - `modify entities` - [Delete a relationship by ID.](https://developers.eclecticiq.com/reference/delete_relationships-id.md): **Required permissions** - `modify entities` - [Get a relationship by ID.](https://developers.eclecticiq.com/reference/get_relationships-id.md): **Required permissions** - `read entities` - [Update a relationship by ID.](https://developers.eclecticiq.com/reference/patch_relationships-id.md): Restriction: 1. Only ``data.key`` and ``data.description``, and ``meta`` can be changed else a 400 is raised 2. Other existing properties in ``data`` can be provided but only with the same value 3. Any other root properties than ``data`` and ``meta`` are ignored **Required permissions** - `modify entities` - [Delete a set of roles referenced by IDs.](https://developers.eclecticiq.com/reference/delete_roles.md): **Required permissions** - `modify roles` - [Returns a list of roles on the platform.](https://developers.eclecticiq.com/reference/get_roles.md): **Required permissions** - `read roles` **Optional permissions** - `read users` Required to get the list of users associated to a role - [Create a role.](https://developers.eclecticiq.com/reference/post_roles.md): **Required permissions** - `modify roles` - [Create (or modify if the name already exists) one or more roles.](https://developers.eclecticiq.com/reference/put_roles.md): **Required permissions** - `modify roles` - [Delete a role by ID.](https://developers.eclecticiq.com/reference/delete_roles-id.md): **Required permissions** - `modify roles` - [Get a role by ID.](https://developers.eclecticiq.com/reference/get_roles-id.md): **Required permissions** - `read roles` **Optional permissions** - `read users` Required to get the list of users associated to a role - [Update a role.](https://developers.eclecticiq.com/reference/patch_roles-id.md): **Required permissions** - `modify roles` - [Get a list of all sources.](https://developers.eclecticiq.com/reference/get_sources.md): **Required permissions** - `read sources` - [Get an source by ID.](https://developers.eclecticiq.com/reference/get_sources-id.md): **Required permissions** - `read sources` - [Get a list of tasks.](https://developers.eclecticiq.com/reference/get_tasks.md): **Required permissions** - `read tasks` - [Get a list of task runs.](https://developers.eclecticiq.com/reference/get_tasks-runs.md): **Required permissions** - `read tasks` - [Run a task.](https://developers.eclecticiq.com/reference/post_tasks-runs.md): **Optional permissions** - `modify tasks` Users with modify tasks permissions can modify any task - `modify incoming-feeds` Required to modify, run or stop tasks linked to incoming feeds - `modify outgoing-feeds` Required to modify, run or stop tasks linked to outgoing feeds - `modify retention-policies` Required to modify, run or stop tasks linked to retention policies - `modify discovery-rules` Required to modify, run or stop tasks linked to discovery rules - `modify enrichments` Required to modify, run or stop tasks linked to enrichers - `modify rules` Required to modify, run or stop tasks linked to entity or observable rules - `read users` Required to read the user that triggered a task - [Get a task run group by ID.](https://developers.eclecticiq.com/reference/get_tasks-runs-groups-id.md): **Optional permissions** - `read tasks` Users with read tasks permissions can read any task - `read incoming-feeds` Required to read tasks linked to incoming feeds - `read outgoing-feeds` Required to read tasks linked to outgoing feeds - `read retention-policies` Required to read tasks linked to retention policies - `read discovery-rules` Required to read tasks linked to discovery rules - `read enrichments` Required to read tasks linked to enrichers - `read rules` Required to read tasks linked to entity or observable rules - `read users` Required to read the user that triggered a task - [Stop a task execution by task run ID.](https://developers.eclecticiq.com/reference/delete_tasks-runs-id.md): **Optional permissions** - `modify tasks` Users with modify tasks permissions can modify any task - `modify incoming-feeds` Required to modify, run or stop tasks linked to incoming feeds - `modify outgoing-feeds` Required to modify, run or stop tasks linked to outgoing feeds - `modify retention-policies` Required to modify, run or stop tasks linked to retention policies - `modify discovery-rules` Required to modify, run or stop tasks linked to discovery rules - `modify enrichments` Required to modify, run or stop tasks linked to enrichers - `modify rules` Required to modify, run or stop tasks linked to entity or observable rules - `read users` Required to read the user that triggered a task - [Get a task run by ID.](https://developers.eclecticiq.com/reference/get_tasks-runs-id.md): **Optional permissions** - `read tasks` Users with read tasks permissions can read any task - `read incoming-feeds` Required to read tasks linked to incoming feeds - `read outgoing-feeds` Required to read tasks linked to outgoing feeds - `read retention-policies` Required to read tasks linked to retention policies - `read discovery-rules` Required to read tasks linked to discovery rules - `read enrichments` Required to read tasks linked to enrichers - `read rules` Required to read tasks linked to entity or observable rules - `read users` Required to read the user that triggered a task - [Get a task by ID.](https://developers.eclecticiq.com/reference/get_tasks-id.md): **Optional permissions** - `read tasks` Users with read tasks permissions can read any task - `read incoming-feeds` Required to read tasks linked to incoming feeds - `read outgoing-feeds` Required to read tasks linked to outgoing feeds - `read retention-policies` Required to read tasks linked to retention policies - `read discovery-rules` Required to read tasks linked to discovery rules - `read enrichments` Required to read tasks linked to enrichers - `read rules` Required to read tasks linked to entity or observable rules - `read users` Required to read the user that triggered a task - [Edit a task by ID.](https://developers.eclecticiq.com/reference/patch_tasks-id.md): **Optional permissions** - `modify tasks` Users with modify tasks permissions can modify any task - `modify incoming-feeds` Required to modify, run or stop tasks linked to incoming feeds - `modify outgoing-feeds` Required to modify, run or stop tasks linked to outgoing feeds - `modify retention-policies` Required to modify, run or stop tasks linked to retention policies - `modify discovery-rules` Required to modify, run or stop tasks linked to discovery rules - `modify enrichments` Required to modify, run or stop tasks linked to enrichers - `modify rules` Required to modify, run or stop tasks linked to entity or observable rules - `read users` Required to read the user that triggered a task - [Delete a set of taxonomies nodes referenced by IDs.](https://developers.eclecticiq.com/reference/delete_taxonomies.md): **Required permissions** - `modify taxonomies` - [Get a list of taxonomies.](https://developers.eclecticiq.com/reference/get_taxonomies.md): **Required permissions** - `read taxonomies` - [Create taxonomy nodes by specifying a single node or a node path.](https://developers.eclecticiq.com/reference/post_taxonomies.md): Same as `PUT` for taxonomies endpoint. POST for taxonomies is also idempotent. **Required permissions** - `modify taxonomies` - [Create taxonomy nodes by specifying a single node or a node path.](https://developers.eclecticiq.com/reference/put_taxonomies.md): The taxonomy endpoint allows you to create: Create a single taxonomy node by sending as a request payload:
Taxonomy node names: Taxonomy node names must be unique for their parents.

Create all the nodes along a taxonomy node path by sending a list of taxonomy nodes in these formats: When sending a list of taxonomy nodes, the **first item in the list** must be one of these: **Required permissions** - `modify taxonomies` - [Delete a taxonomy node or a sub-tree.](https://developers.eclecticiq.com/reference/delete_taxonomies-id.md): **Required permissions** - `modify taxonomies` - [Get a taxonomy node by ID.](https://developers.eclecticiq.com/reference/get_taxonomies-id.md): **Required permissions** - `read taxonomies` - [Update a taxonomy node.](https://developers.eclecticiq.com/reference/patch_taxonomies-id.md): **Required permissions** - `modify taxonomies` - [Get a ticket comment by ID.](https://developers.eclecticiq.com/reference/get_tickets-comments-id.md): **Required permissions** - `read ticket-comments` **Optional permissions** - `read tickets` To access the tickets a comment is associated to - `read users` To access the users associated to a ticket comment - [Create a comment on a ticket.](https://developers.eclecticiq.com/reference/post_tickets-id-comments.md): **Required permissions** - `modify ticket-comments` **Optional permissions** - `read tickets` To access the tickets a comment is associated to - `read users` To access the users associated to a ticket comment - [Delete a set of tickets referenced by IDs.](https://developers.eclecticiq.com/reference/delete_tickets.md): **Required permissions** - `modify tickets` - [Get a list of all tickets.](https://developers.eclecticiq.com/reference/get_tickets.md): **Required permissions** - `read tickets` **Optional permissions** - `read ticket-comments` To access the comments associated to a ticket - `read entities` To access the entities attached to a ticket - `read users` To access the users associated to a ticket - `read workspaces` To access the workspaces a ticket is attached to - [Create a ticket.](https://developers.eclecticiq.com/reference/post_tickets.md): **Required permissions** - `modify tickets` **Optional permissions** - `read ticket-comments` To access the comments associated to a ticket - `read entities` To access the entities attached to a ticket - `read users` To access the users associated to a ticket - `read workspaces` To access the workspaces a ticket is attached to - [Delete a ticket by ID.](https://developers.eclecticiq.com/reference/delete_tickets-id.md): **Required permissions** - `modify tickets` - [Get a ticket by ID.](https://developers.eclecticiq.com/reference/get_tickets-id.md): **Required permissions** - `read tickets` **Optional permissions** - `read ticket-comments` To access the comments associated to a ticket - `read entities` To access the entities attached to a ticket - `read users` To access the users associated to a ticket - `read workspaces` To access the workspaces a ticket is attached to - [Update a ticket by ID.](https://developers.eclecticiq.com/reference/patch_tickets-id.md): **Required permissions** - `modify tickets` **Optional permissions** - `read ticket-comments` To access the comments associated to a ticket - `read entities` To access the entities attached to a ticket - `read users` To access the users associated to a ticket - `read workspaces` To access the workspaces a ticket is attached to - [Get a list of uploaded blobs.](https://developers.eclecticiq.com/reference/get_uploaded-blobs.md): **Required permissions** - `read blob-uploads` - [Upload a new blob.](https://developers.eclecticiq.com/reference/post_uploaded-blobs.md): The request body contains uploaded blob data in `application/octet-stream` format. The blob details are passed in the header 'x-platformapi-metadata', representing a dump of `UploadedBlobAPISchema`. **Required permissions** - `modify blob-uploads` - [Delete blobs referenced by IDs.](https://developers.eclecticiq.com/reference/post_uploaded-blobs-delete-tasks.md): **Required permissions** - `modify blob-uploads` - `read tasks` - [Get an uploaded blob by ID.](https://developers.eclecticiq.com/reference/get_uploaded-blobs-id.md): **Required permissions** - `read blob-uploads` - [Returns a list of users on the platform.](https://developers.eclecticiq.com/reference/get_users.md): **Required permissions** - `read users` **Optional permissions** - `read groups` Required to access the groups associated with a user - `read permissions` Required to access the permissions associated with a user - `read roles` Required to access the roles associated with a user - `read sources` Required to access the sources associated with a user - [Create a user.](https://developers.eclecticiq.com/reference/post_users.md): **Required permissions** - `modify users` **Optional permissions** - `modify user-groups` Required if you want to modify the groups associated to a user - `modify user-roles` Required if you want to modify the roles associated to a user - `read permissions` Required to access the permissions associated with a user - `read sources` Required to access the sources associated with a user - [Create (or update if the name already exists) one or more users.](https://developers.eclecticiq.com/reference/put_users.md): **Required permissions** - `modify users` **Optional permissions** - `modify user-groups` Required if you want to modify the groups associated to a user - `modify user-roles` Required if you want to modify the roles associated to a user - `read permissions` Required to access the permissions associated with a user - `read sources` Required to access the sources associated with a user - [Get a user by ID.](https://developers.eclecticiq.com/reference/get_users-id.md): Use `id=self` to get information about the user associated to the current API token. **Optional permissions** - `read users` Required to access the information of any user other than `self` - `read groups` Required to access the groups associated with a user - `read permissions` Required to access the permissions associated with a user - `read roles` Required to access the roles associated with a user - `read sources` Required to access the sources associated with a user - [Update a user.](https://developers.eclecticiq.com/reference/patch_users-id.md): Use `id=self` to reference the user associated to the current API token. **Optional permissions** - `modify users` Required if you want to modify any user other than yourself - `modify user-groups` Required if you want to modify the groups associated to a user, unless you are a group admin - `modify user-roles` Required if you want to modify the roles associated to a user - `read permissions` Required to access the permissions associated with a user - `read sources` Required to access the sources associated with a user - [Delete a set of workspace comments referenced by IDs.](https://developers.eclecticiq.com/reference/delete_workspaces-comments.md): **Required permissions** - `modify workspace-comments` - `read workspaces` - [Delete a workspace comment by ID.](https://developers.eclecticiq.com/reference/delete_workspaces-comments-id.md): On top of the required permissions, modifying workspace comments is allowed only if: - The user is a collaborator of the workspace and the creator of the comment, or - The user is a platform admin **Required permissions** - `modify workspace-comments` - `read workspaces` - [Get a workspace comment by ID.](https://developers.eclecticiq.com/reference/get_workspaces-comments-id.md): On top of the required permissions, reading workspace comments is allowed only if: - The user is a collaborator of the workspace, or - The user is a platform admin **Required permissions** - `read workspace-comments` - `read workspaces` - [Modify a workspace comment by ID.](https://developers.eclecticiq.com/reference/patch_workspaces-comments-id.md): On top of the required permissions, modifying workspace comments is allowed only if: - The user is a collaborator of the workspace and the creator of the comment, or - The user is a platform admin **Required permissions** - `modify workspace-comments` - `read workspaces` - [Get the content of the comments of a workspace.](https://developers.eclecticiq.com/reference/get_workspaces-id-comments.md): On top of the required permissions, reading workspace comments is allowed only if: - The user is a collaborator of the workspace, or - The user is a platform admin **Required permissions** - `read workspace-comments` - `read workspaces` - [Create a new workspace comment.](https://developers.eclecticiq.com/reference/post_workspaces-id-comments.md): On top of the required permissions, comment creation is allowed only if: - The user is a collaborator of the workspace, or - The user is a platform admin **Required permissions** - `modify workspace-comments` - `read workspaces` - [Delete a set of workspaces referenced by IDs.](https://developers.eclecticiq.com/reference/delete_workspaces.md): **Required permissions** - `modify workspaces` - [Get a list of workspaces.](https://developers.eclecticiq.com/reference/get_workspaces.md): Workspaces have three levels of access: - **Unlisted workspace:** ``is_public=False`` Only collaborators can see and modify this workspace. - **Listed workspace:** ``is_public=True`` This workspace has its public attributes (public description, "pinned" objects) visible to all users who have at least ``read workspaces`` permissions. Only collaborators can see the full workspace and modify it. - **Public workspace:** ``is_shared_with_all=True`` This is only set to ``True`` for the "Default public workspace", which is fully visible and can be modified by users who have at least ``read workspaces`` permissions. **Required permissions** - `read workspaces` **Optional permissions** - `read intel-sets` To read datasets attached to the workspaces - `read entities` To read entities pinned to the workspaces - `read tasks` To read discovery tasks associated to the workspaces - `read discovery-rules` To read discovery tasks associated to the workspaces - `read tickets` To read tickets attached to the workspaces - `read users` To read workspace collaborators - `read groups` To read workspace collaborator groups - `read files` To read workspace files - `read workspace-comments` To read workspace comments - [Create a new workspace.](https://developers.eclecticiq.com/reference/post_workspaces.md): **Required permissions** - `modify workspaces` **Optional permissions** - `read intel-sets` To attach datasets to the workspace - `read entities` To pin entities to the workspace - `read tasks` To associate discovery tasks to the workspace - `read discovery-rules` To read discovery tasks associated to the workspaces - `read tickets` To attach tickets to the workspace - `read users` To add workspace collaborators - `read groups` To add workspace collaborator groups - [Create (or update if the name already exists) one or more workspaces.](https://developers.eclecticiq.com/reference/put_workspaces.md): The workspace name is used as a unique key to identify whether the workspace already exists. **Required permissions** - `modify workspaces` **Optional permissions** - `read intel-sets` To attach datasets to the workspace - `read entities` To pin entities to the workspace - `read tasks` To associate discovery tasks to the workspace - `read discovery-rules` To read discovery tasks associated to the workspaces - `read tickets` To attach tickets to the workspace - `read users` To add workspace collaborators - `read groups` To add workspace collaborator groups - `read files` To read workspace files - `read workspace-comments` To read workspace comments - [Delete a workspace by ID.](https://developers.eclecticiq.com/reference/delete_workspaces-id.md): **Required permissions** - `modify workspaces` - [Get a workspace by ID.](https://developers.eclecticiq.com/reference/get_workspaces-id.md): **Required permissions** - `read workspaces` **Optional permissions** - `read intel-sets` To read datasets attached to the workspace - `read entities` To read entities pinned to the workspace - `read tasks` To read discovery tasks associated to the workspace - `read discovery-rules` To read discovery tasks associated to the workspaces - `read tickets` To read tickets attached to the workspace - `read users` To read workspace collaborators - `read groups` To read workspace collaborator groups - `read files` To read workspace files - `read workspace-comments` To read workspace comments - [Edit a workspace by ID.](https://developers.eclecticiq.com/reference/patch_workspaces-id.md): **Required permissions** - `modify workspaces` **Optional permissions** - `read intel-sets` To read/modify datasets attached to the workspace - `read entities` To read/modify entities pinned to the workspace - `read tasks` To read/modify discovery tasks associated to the workspace - `read discovery-rules` To read discovery tasks associated to the workspaces - `read tickets` To read/modify tickets attached to the workspace - `read users` To read/modify workspace collaborators - `read groups` To read/modify workspace collaborator groups - `read files` To read workspace files - `read workspace-comments` To read workspace comments - [Get a list of consolidation policies](https://developers.eclecticiq.com/reference/get_consolidation-policies.md): **Required permissions** - `read consolidation-policies` **Optional permissions** - `read tasks` Required to access the task attached to a policy - `read groups` Required to access the group assigned to a policy - [Get a consolidation policy by ID.](https://developers.eclecticiq.com/reference/get_consolidation-policies-policy-id.md): **Required permissions** - `read consolidation-policies` **Optional permissions** - `read tasks` Required to access the task attached to a policy - `read groups` Required to access the group assigned to a policy - [Edit a consolidation policy by ID.](https://developers.eclecticiq.com/reference/patch_consolidation-policies-policy-id.md): **Required permissions** - `modify consolidation-policies` **Optional permissions** - `read tasks` Required to access the task attached to a policy - `read groups` Required to access the group assigned to a policy - [Delete a set of consolidation policy configurations referenced by IDs.](https://developers.eclecticiq.com/reference/delete_consolidation-policies-policy-id-configurations.md): **Required permissions** - `modify consolidation-policies` - [Get a list of consolidation policy configurations](https://developers.eclecticiq.com/reference/get_consolidation-policies-policy-id-configurations.md): **Required permissions** - `read consolidation-policies` **Optional permissions** - `read sources` Required to access the sources attached to a policy configuration - [Create (or update if the name already exists) one or more consolidation policy configurations.](https://developers.eclecticiq.com/reference/post_consolidation-policies-policy-id-configurations.md): **Required permissions** - `modify consolidation-policies` **Optional permissions** - `read sources` Required to access the sources attached to a policy configuration - [Delete a consolidation policy configuration by ID.](https://developers.eclecticiq.com/reference/delete_consolidation-policies-policy-id-configurations-configuration-id.md): **Required permissions** - `modify consolidation-policies` - [Get a consolidation policy configuration by ID.](https://developers.eclecticiq.com/reference/get_consolidation-policies-policy-id-configurations-configuration-id.md): **Required permissions** - `read consolidation-policies` **Optional permissions** - `read sources` Required to access the sources attached to a policy configuration - [Edit a consolidation policy configuration by ID.](https://developers.eclecticiq.com/reference/patch_consolidation-policies-policy-id-configurations-configuration-id.md): **Required permissions** - `modify consolidation-policies` **Optional permissions** - `read sources` Required to access the sources attached to a policy configuration - [Delete a set of prompts referenced by IDs.](https://developers.eclecticiq.com/reference/delete_content-generation-prompts.md): **Required permissions** - `modify prompts` - [Get a list of content generation prompts.](https://developers.eclecticiq.com/reference/get_content-generation-prompts.md): **Required permissions** - `read prompts` - [Create a content generation prompt.](https://developers.eclecticiq.com/reference/post_content-generation-prompts.md): **Required permissions** - `modify prompts` - [Delete a prompt referenced by ID.](https://developers.eclecticiq.com/reference/delete_content-generation-prompts-id.md): **Required permissions** - `modify prompts` - [Get a content generation prompt by ID.](https://developers.eclecticiq.com/reference/get_content-generation-prompts-id.md): **Required permissions** - `read prompts` - [Update a content generation prompt.](https://developers.eclecticiq.com/reference/patch_content-generation-prompts-id.md): **Required permissions** - `modify prompts` - [Get a list of custom attributes.](https://developers.eclecticiq.com/reference/get_custom-attributes.md): **Required permissions** - `read custom-entities` - [Create new or update existing custom attributes.](https://developers.eclecticiq.com/reference/put_custom-attributes.md): **Required permissions** - `modify custom-entities` - [Get a list of custom attribute mappings.](https://developers.eclecticiq.com/reference/get_custom-attributes-mappings.md): **Required permissions** - `read custom-entities` - [Delete a custom attribute by ID.](https://developers.eclecticiq.com/reference/delete_custom-attributes-id.md): **Required permissions** - `modify custom-entities` - [Get custom attribute by ID.](https://developers.eclecticiq.com/reference/get_custom-attributes-id.md): **Required permissions** - `read custom-entities` - [Partially update a custom attribute by ID](https://developers.eclecticiq.com/reference/patch_custom-attributes-id.md): Only unassigned attributes (not linked to any CustomEntitySchema) can be edited. **Required permissions** - `modify custom-entities` - [Get a list of custom entity schemas](https://developers.eclecticiq.com/reference/get_custom-entity-schemas.md): Deprecated in favor of entity-schemas. **Required permissions** - `read custom-entities` - [Create a new custom entity schema](https://developers.eclecticiq.com/reference/post_custom-entity-schemas.md): Deprecated in favor of entity-schemas. **Required permissions** - `modify custom-entities` - [Get custom entity schema by ID](https://developers.eclecticiq.com/reference/get_custom-entity-schemas-id.md): Deprecated in favor of entity-schemas/{id}. **Required permissions** - `read custom-entities` - [Delete a set of dashboards referenced by IDs.](https://developers.eclecticiq.com/reference/delete_dashboards.md): **Required permissions** - `modify dashboard` - [Get a list of Dashboards.](https://developers.eclecticiq.com/reference/get_dashboards.md): **Required permissions** - `read dashboard` - [Create a dashboard.](https://developers.eclecticiq.com/reference/post_dashboards.md): **Required permissions** - `modify dashboard` - [Delete a dashboard.](https://developers.eclecticiq.com/reference/delete_dashboards-id.md): **Required permissions** - `modify dashboard` - [Get a dashboard by ID.](https://developers.eclecticiq.com/reference/get_dashboards-id.md): **Required permissions** - `read dashboard` - [Update a dashboard.](https://developers.eclecticiq.com/reference/patch_dashboards-id.md) - [Get a list of Overview Dashboards.](https://developers.eclecticiq.com/reference/get_overview-dashboards.md): **Required permissions** - `read dashboard` - [Create overview dashboard.](https://developers.eclecticiq.com/reference/post_overview-dashboards.md) - [Delete an overview dashboard.](https://developers.eclecticiq.com/reference/delete_overview-dashboards-id.md) - [Update Overview dashboard.](https://developers.eclecticiq.com/reference/patch_overview-dashboards-id.md) - [Delete a set of widgets referenced by IDs.](https://developers.eclecticiq.com/reference/delete_widgets.md) - [Get a list of widgets.](https://developers.eclecticiq.com/reference/get_widgets.md) - [Create a widget.](https://developers.eclecticiq.com/reference/post_widgets.md) - [Delete a widget.](https://developers.eclecticiq.com/reference/delete_widgets-id.md) - [Get a widget by ID.](https://developers.eclecticiq.com/reference/get_widgets-id.md) - [Update a widget.](https://developers.eclecticiq.com/reference/patch_widgets-id.md) - [Get the widget dark thumbnail as binary.](https://developers.eclecticiq.com/reference/get_widgets-id-thumbnail-dark.md) - [Get the widget light thumbnail as binary.](https://developers.eclecticiq.com/reference/get_widgets-id-thumbnail-light.md) - [Get a list of Detonation Task](https://developers.eclecticiq.com/reference/get_detonator-tasks.md): **Required permissions** - `read detonation-vendors` - [Get a Detonator Task by an ID](https://developers.eclecticiq.com/reference/get_detonator-tasks-id.md): **Required permissions** - `read detonation-vendors` - [Update the detonation Task by an ID](https://developers.eclecticiq.com/reference/patch_detonator-tasks-id.md): **Required permissions** - `modify detonation-vendors` - [Delete a set of Sandbox Detonations referenced by IDs](https://developers.eclecticiq.com/reference/delete_sandbox-detonations.md): **Required permissions** - `modify detonations` - [Get a list of Sandbox Detonations](https://developers.eclecticiq.com/reference/get_sandbox-detonations.md): **Required permissions** - `read detonations` - [Create Sandbox Detonation](https://developers.eclecticiq.com/reference/post_sandbox-detonations.md): **Required permissions** - `modify detonations` - [Delete a Sandbox Detonations](https://developers.eclecticiq.com/reference/delete_sandbox-detonations-id.md): **Required permissions** - `modify detonations` - [Get a Sandbox Detonation details by an ID](https://developers.eclecticiq.com/reference/get_sandbox-detonations-id.md): **Required permissions** - `read detonations` - [Get the Detonation Result by sandbox detonation ID](https://developers.eclecticiq.com/reference/get_sandbox-detonations-id-result.md): **Required permissions** - `read detonations` - [Delete a set of matches between an entity and an intelligence requirement referenced by IDs.](https://developers.eclecticiq.com/reference/delete_entities-intel-requirement-matches.md): **Required permissions** - `modify entities` - [Get a list of intelligence requirement matches to an entity.](https://developers.eclecticiq.com/reference/get_entities-intel-requirement-matches.md): **Required permissions** - `read entities` - [Create a new match object between an enity and an intelligence requirement.](https://developers.eclecticiq.com/reference/post_entities-intel-requirement-matches.md): **Required permissions** - `modify entities` - [Create (or update if the (entity_id, intel_requirement_id) combination already exists) one or more Intelligence Requirement Match objects.](https://developers.eclecticiq.com/reference/put_entities-intel-requirement-matches.md): **Required permissions** - `modify entities` - [Delete a match between an entity and an intelligence requirement by ID.](https://developers.eclecticiq.com/reference/delete_entities-intel-requirement-matches-id.md): **Required permissions** - `modify entities` - [Get an intelligence requirement match by ID.](https://developers.eclecticiq.com/reference/get_entities-intel-requirement-matches-id.md): **Required permissions** - `read entities` - [Get a list of fonts.](https://developers.eclecticiq.com/reference/get_font-families.md): **Required permissions** - `read report-templates` - [Upload a new custom font (TTF or ZIP).](https://developers.eclecticiq.com/reference/post_font-families.md): Accepts either: - A single `.ttf`, `.otf` font file. - A `.zip` file containing one or more `.ttf` files. **Required permissions** - `modify report-templates` - [Delete a font by ID.](https://developers.eclecticiq.com/reference/delete_font-families-id.md): **Required permissions** - `modify report-templates` - [Delete a custom entity schema by ID](https://developers.eclecticiq.com/reference/delete_custom-entity-schemas-id.md): Only unassigned entity schemas can be deleted Deprecated in favor of entity-schemas/{id}. **Required permissions** - `modify custom-entities` - [Update an existing custom entity schema by ID](https://developers.eclecticiq.com/reference/patch_custom-entity-schemas-id.md): Deprecated in favor of entity-schemas/{id}. **Required permissions** - `modify custom-entities` - [Returns a list of notifications in the platform.](https://developers.eclecticiq.com/reference/get_notifications.md): Notifications are periodically removed from the system. There is a limit of most revent notifications per user that is controlled by ``NOTIFICATIONS_MAX_PER_USER`` value in platform settings. **Required permissions** - `read notifications` - [Get a user notification by ID.](https://developers.eclecticiq.com/reference/get_notifications-id.md): **Required permissions** - `read permissions` - [Modify a notification by ID. The only supported modification is marking a notification as ``is_read``.](https://developers.eclecticiq.com/reference/patch_notifications-id.md): **Required permissions** - `modify notifications` - [Upload a report template attachment.](https://developers.eclecticiq.com/reference/post_report-template-attachments.md): **Required permissions** - `modify report-templates` - [Delete report template attachment by ID.](https://developers.eclecticiq.com/reference/delete_report-template-attachments-id.md): **Required permissions** - `modify report-templates` - [Delete a set of report templates by IDs.](https://developers.eclecticiq.com/reference/delete_report-templates.md) - [Get a list of report templates.](https://developers.eclecticiq.com/reference/get_report-templates.md): **Required permissions** - `read report-templates` - [Create a report template.](https://developers.eclecticiq.com/reference/post_report-templates.md): **Required permissions** - `modify report-templates` - [Delete a report template by ID.](https://developers.eclecticiq.com/reference/delete_report-templates-id.md): **Required permissions** - `modify report-templates` - [Update report template by ID.](https://developers.eclecticiq.com/reference/patch_report-templates-id.md): **Required permissions** - `modify report-templates` - [Create a duplicate report template using existing report template ID.](https://developers.eclecticiq.com/reference/post_report-templates-id-duplicate.md): **Required permissions** - `modify report-templates` - [Get a list of risk score decay settings.](https://developers.eclecticiq.com/reference/get_risk-score-decay-settings.md): **Required permissions** - `read observable-risk-score-policy` - [Create or update (if a setting for such observable type already exists) one or more risk score decay settings.](https://developers.eclecticiq.com/reference/put_risk-score-decay-settings.md): **Required permissions** - `modify observable-risk-score-policy` - [Get a list of risk score policies.](https://developers.eclecticiq.com/reference/get_risk-score-policies.md): **Required permissions** - `read observable-risk-score-policy` - [Create a risk score policy.](https://developers.eclecticiq.com/reference/post_risk-score-policies.md): **Required permissions** - `modify observable-risk-score-policy` - [Create (or update if the name already exists) one or more policies.](https://developers.eclecticiq.com/reference/put_risk-score-policies.md): **Required permissions** - `modify observable-risk-score-policy` - [Delete a risk score policy by ID.](https://developers.eclecticiq.com/reference/delete_risk-score-policies-policy-id.md): **Required permissions** - `modify observable-risk-score-policy` - [Get a risk score policy by ID](https://developers.eclecticiq.com/reference/get_risk-score-policies-policy-id.md): **Required permissions** - `read observable-risk-score-policy` - [Edit a risk score policy by ID.](https://developers.eclecticiq.com/reference/patch_risk-score-policies-policy-id.md): **Required permissions** - `modify observable-risk-score-policy` - [Get a list of parameters for a policy.](https://developers.eclecticiq.com/reference/get_risk-score-policies-policy-id-parameters.md): **Required permissions** - `read observable-risk-score-policy` - [Get a policy parameter by ID.](https://developers.eclecticiq.com/reference/get_risk-score-policies-policy-id-parameters-parameter-id.md): **Required permissions** - `read observable-risk-score-policy` - [Edit a policy parameter by ID.](https://developers.eclecticiq.com/reference/patch_risk-score-policies-policy-id-parameters-parameter-id.md): **Required permissions** - `modify observable-risk-score-policy` - [Delete a set of parameter values by ID.](https://developers.eclecticiq.com/reference/delete_risk-score-policies-policy-id-parameters-parameter-id-values.md): **Required permissions** - `modify observable-risk-score-policy` - [Get a parameter values list.](https://developers.eclecticiq.com/reference/get_risk-score-policies-policy-id-parameters-parameter-id-values.md): **Required permissions** - `read observable-risk-score-policy` **Optional permissions** - `read sources` Required to access the sources associated to risk score parameter - `read entities` Required to access the entities associated to risk score parameter - `read observables` Required to access the observables associated to risk score parameter - `read taxonomies` Required to access the taxonomies associated to risk score parameter - [Create a new parameter value.](https://developers.eclecticiq.com/reference/post_risk-score-policies-policy-id-parameters-parameter-id-values.md): **Required permissions** - `modify observable-risk-score-policy` **Optional permissions** - `read sources` Required to access the sources associated to risk score parameter - `read entities` Required to access the entities associated to risk score parameter - `read observables` Required to access the observables associated to risk score parameter - `read taxonomies` Required to access the taxonomies associated to risk score parameter - [Create or update one or more parameter values.](https://developers.eclecticiq.com/reference/put_risk-score-policies-policy-id-parameters-parameter-id-values.md): **Required permissions** - `modify observable-risk-score-policy` **Optional permissions** - `read sources` Required to access the sources associated to risk score parameter - `read entities` Required to access the entities associated to risk score parameter - `read observables` Required to access the observables associated to risk score parameter - `read taxonomies` Required to access the taxonomies associated to risk score parameter - [Delete a parameter value by ID.](https://developers.eclecticiq.com/reference/delete_risk-score-policies-policy-id-parameters-parameter-id-values-parameter-value-id.md): **Required permissions** - `modify observable-risk-score-policy` - [Get a parameter value by ID.](https://developers.eclecticiq.com/reference/get_risk-score-policies-policy-id-parameters-parameter-id-values-parameter-value-id.md): **Required permissions** - `read observable-risk-score-policy` **Optional permissions** - `read sources` Required to access the sources associated to risk score parameter - `read entities` Required to access the entities associated to risk score parameter - `read observables` Required to access the observables associated to risk score parameter - `read taxonomies` Required to access the taxonomies associated to risk score parameter - [Edit a parameter value by ID.](https://developers.eclecticiq.com/reference/patch_risk-score-policies-policy-id-parameters-parameter-id-values-parameter-value-id.md): **Required permissions** - `modify observable-risk-score-policy` **Optional permissions** - `read sources` Required to access the sources associated to risk score parameter - `read entities` Required to access the entities associated to risk score parameter - `read observables` Required to access the observables associated to risk score parameter - `read taxonomies` Required to access the taxonomies associated to risk score parameter - [Preview a result of a risk score policy by ID run for a batch of up to 100 of extracts matching provided query.](https://developers.eclecticiq.com/reference/post_risk-score-policies-policy-id-score-previews.md): **Required permissions** - `read observable-risk-score-policy` - `read extracts` - [Delete a set of intelligence requirements referenced by IDs.](https://developers.eclecticiq.com/reference/delete_rules-intel-requirements.md): **Required permissions** - `modify intel-requirements` - [Get a list of intelligence requirements.](https://developers.eclecticiq.com/reference/get_rules-intel-requirements.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `read intel-requirements` **Optional permissions** - `read intel-sets` Required to access the datasets attached to intelligence requirements - `read users` Required to access the users attached to intelligence requirements - `read sources` Required to access sources attached to intelligence requirements - `read tasks` Required to access the tasks attached to intelligence requirements - `read taxonomies` Required to access the taxonomies attached to intelligence requirements - [Create a new intelligence requirement.](https://developers.eclecticiq.com/reference/post_rules-intel-requirements.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `modify intel-requirements` **Optional permissions** - `read intel-sets` Required to access the datasets attached to intelligence requirements - `read users` Required to access the users attached to intelligence requirements - `read sources` Required to access sources attached to intelligence requirements - `read tasks` Required to access the tasks attached to intelligence requirements - `read taxonomies` Required to access the taxonomies attached to intelligence requirements - [Create (or update if the name already exists) one or more intelligence requirements.](https://developers.eclecticiq.com/reference/put_rules-intel-requirements.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `modify intel-requirements` **Optional permissions** - `read intel-sets` Required to access the datasets attached to intelligence requirements - `read users` Required to access the users attached to intelligence requirements - `read sources` Required to access sources attached to intelligence requirements - `read tasks` Required to access the tasks attached to intelligence requirements - `read taxonomies` Required to access the taxonomies attached to intelligence requirements - [Delete an intelligence requirement by ID.](https://developers.eclecticiq.com/reference/delete_rules-intel-requirements-id.md): **Required permissions** - `modify intel-requirements` - [Get an intelligence requirement by ID.](https://developers.eclecticiq.com/reference/get_rules-intel-requirements-id.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `read intel-requirements` **Optional permissions** - `read intel-sets` Required to access the datasets attached to intelligence requirements - `read users` Required to access the users attached to intelligence requirements - `read sources` Required to access sources attached to intelligence requirements - `read tasks` Required to access the tasks attached to intelligence requirements - `read taxonomies` Required to access the taxonomies attached to intelligence requirements - [Edit an Intelligence requirement by ID.](https://developers.eclecticiq.com/reference/patch_rules-intel-requirements-id.md): Deprecated as it can only see/set the first list of matching keywords. Please use at least API v3. **Required permissions** - `modify intel-requirements` **Optional permissions** - `read intel-sets` Required to access the datasets attached to intelligence requirements - `read users` Required to access the users attached to intelligence requirements - `read sources` Required to access sources attached to intelligence requirements - `read tasks` Required to access the tasks attached to intelligence requirements - `read taxonomies` Required to access the taxonomies attached to intelligence requirements - [Delete a set of Property Propagations referenced by IDs.](https://developers.eclecticiq.com/reference/delete_rules-property-propagations.md): **Required permissions** - `modify property-propagations` - [Get a list of property propagations.](https://developers.eclecticiq.com/reference/get_rules-property-propagations.md): **Required permissions** - `read property-propagations` **Optional permissions** - `read sources` Required to access sources attached to property propagations - `read tasks` Required to access the tasks attached to property propagations - [Create a new property propagation.](https://developers.eclecticiq.com/reference/post_rules-property-propagations.md): **Required permissions** - `modify property-propagations` **Optional permissions** - `read sources` Required to access sources attached to property propagations - `read tasks` Required to access the tasks attached to property propagations - [Create (or update if the name already exists) one or more Property Propagations.](https://developers.eclecticiq.com/reference/put_rules-property-propagations.md): **Required permissions** - `modify property-propagations` **Optional permissions** - `read sources` Required to access sources attached to property propagations - `read tasks` Required to access the tasks attached to property propagations - [Delete an property propagation by ID.](https://developers.eclecticiq.com/reference/delete_rules-property-propagations-id.md): **Required permissions** - `modify property-propagations` - [Get an property propagation by ID.](https://developers.eclecticiq.com/reference/get_rules-property-propagations-id.md): **Required permissions** - `read property-propagations` **Optional permissions** - `read sources` Required to access sources attached to property propagations - `read tasks` Required to access the tasks attached to property propagations - [Edit an property propagation by ID.](https://developers.eclecticiq.com/reference/patch_rules-property-propagations-id.md): **Required permissions** - `modify property-propagations` **Optional permissions** - `read sources` Required to access sources attached to property propagations - `read tasks` Required to access the tasks attached to property propagations - [Get a list of Vendor API](https://developers.eclecticiq.com/reference/get_vendor-apis.md): **Required permissions** - `read vendor-apis` - [Get a Vendor API by an ID](https://developers.eclecticiq.com/reference/get_vendor-apis-id.md): **Required permissions** - `read vendor-apis` - [Update the Vendor API by an ID](https://developers.eclecticiq.com/reference/patch_vendor-apis-id.md): **Required permissions** - `modify vendor-apis`