Avalon provides a robust API to automate interacting with the platform.
Many actions, including graphing, can be done outside the website application with simple HTTP REST requests. Avalon also provides REST endpoints to allow combinations of tasks.
Workspaces can be populated by importing documents that contain indicators. Avalon supports:
For PDF files, Avalon will search the document for words that look like IoCs and automatically add hem to the workspace. For CSVs, Avalon will take the first column of the CSV as an IoC, and later columns as attributes to add to that IoC. With JSON, users can specify both the ICs to be uploaded and the relations between them to automatically import connctions between IoCs.
Making intelligence operational is critical. Avalon supports the following export formats.
Exports can cover an individiual workspace or multiple workspaces. Users can also share sets of workspaces within interest groups and exports these sets of workspaces as a group, effectively creating a threat feed from the collaboration that occurs within an interest group.