Associated Entity Types

List entity type categories that appear across Insikt Group detection rules.

What this endpoint does

Returns the taxonomy of entity type categories (~37 types) that appear across Insikt Group detection rules — including Hash, IpAddress, URL, Malware, MitreAttackIdentifier, CyberVulnerability, and others. This is a discovery/reference tool: use it to understand what kinds of entities the detection rule library covers before querying Detection Rules: Associated Entities for specific entity IDs.

Important: the id values returned here (e.g., type:Hash) are type identifiers, not entity IDs. They cannot be passed to filter.entities in Detection Rules: Search — that endpoint requires individual entity IDs from the Associated Entities list. No parameters required.

Response data

Returns a flat JSON array (no data envelope) of type objects with machine-readable names and human-friendly display names — use these to understand the breadth of entity coverage before drilling into specific entities.

Responses

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json