Skip to content

Machine-Readable Data & CTI Endpoints


All endpoints are served with Content-Type: application/json and standard HTTP caching headers.

EndpointMethodDescriptionSize
/api/entities/index.jsonGETMaster searchable catalog of all 556 canonical entities.~65 KB
/api/features.jsonGETUnified Feature Registry across 7-step intelligence lifecycle (Section 54).~23 KB
/api/graph.jsonGETComplete Knowledge Graph (556 nodes, 575 relationships).~210 KB
/api/stats.jsonGETGlobal corpus metrics, evidence counts, and confidence health.~2 KB
/api/methodology/index.jsonGETActive methodology versions (HTS-3.1, HTR-2.0, etc.).~8 KB
/api/decisions/index.jsonGETPrescriptive operational directives linked to risk trajectories.~18 KB

2. OASIS STIX 2.1 & TAXII 2.1 Server Feeds (Section 38)

Section titled β€œ2. OASIS STIX 2.1 & TAXII 2.1 Server Feeds (Section 38)”

Hermes compiles all intelligence into standardized OASIS STIX 2.1 Domain Objects (SDOs) and Relationship Objects (SROs).

Feed EndpointStandardTarget Systems
/api/stix2/bundle.jsonSTIX 2.1OpenCTI, MISP, Sentinel (Complete Knowledge Bundle - 531 SDOs)
/api/stix2/latest.jsonSTIX 2.1Daily Threat Delta & Newly Accelerated Weaponizations
/api/taxii2/taxii2/index.jsonTAXII 2.1TAXII Server Discovery Endpoint
/api/taxii2/root/index.jsonTAXII 2.1TAXII API Root Specification
/api/taxii2/root/collections/index.jsonTAXII 2.1Collections Manifest (hermes-all, hermes-vulnerabilities)

EndpointFrequencyDescription
/api/daily-brief/latest.jsonDailyComplete 8-section synthesized threat brief and stack index.
/api/trajectories/index.jsonContinuousRisk curves $R(t)$, velocities $\Delta R/\Delta t$, and archetypes.
/api/snapshots/index.jsonDailyHistorical archive of immutable daily state snapshots.
/api/forecast/index.jsonWeeklyFalsifiable forecast registry and Brier score tracking.