feat(search): ioc --with-artifacts returns the matching artifacts' metadata - #275
Merged
Merged
Conversation
…with_artifacts=) CI installs the SDK from the same-named branch archive, so the floor names the version the paired SDK change declares: 4.7.0, the next version above the 4.6.0 the SDK's develop already declares for refanging. It is mergeable once that change is on the SDK's develop, and releasable once 4.7.0 is on PyPI.
…tadata `search ioc <ip|domain|ttp|imphash> <value>` prints bare sha256s. With `--with-artifacts` it asks the server for each artifact's metadata-search row and renders it with the `metadata` formatter, the block `search metadata` prints, so the text, json and hash output formats all apply. `output.ioc` cannot render these rows (it indexes IOC keys a metadata row lacks). Without the flag the SDK call is unchanged. On the sha256/sha1/md5 forward lookup the flag is refused as a usage error rather than silently ignored. Tests mock at the SDK boundary with autospec, so each call is a signature check against the SDK the floor installs.
…rows Drive sha256, sha1 and md5 through the metadata formatter on an artifact row, and name the reverse search in the command's short help.
|
Clean against AGENTS.md and specs/: it targets |
mjbradford89
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
polyswarm search ioc ip|domain|ttp|imphash <value>gains a--with-artifactsflag. It callssearch_by_ioc(with_artifacts=True)and prints each row with the same formatter assearch metadata, so the text, json and hash output formats all work. Theshort_helpnow covers both directions: "Retrieve IOCs by artifact hash, or artifacts by IOC."Semantics
search ioc sha256 …), the flag is refused as a usage error (exit 2). It is not silently ignored.polyswarm_api>=4.7.0.Requires
with_artifacts). Deploy it first.search_by_ioc(with_artifacts=), version 4.7.0). CI resolves it from the same-named branch.Tests
tests/search_test.pymocks the SDK method, as the repo's testing spec allows. It covers: