Cisco XDR Response API

IROH Response

OpenAPI Specification

cisco-xdr-response-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: IROH-INT Response API
  version: 1.0.107
  license:
    name: All Rights Reserved
    url: https://www.cisco.com
  contact:
    name: Cisco Security Business Group -- Advanced Threat
    email: cisco-intel-api-support@cisco.com
  description: Manage Response from modules
  x-provenance:
    method: harvested
    authored_by: Cisco XDR
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    note: Published by Cisco. Retrieved unmodified except for this x-provenance block.
    provider_published: true
  x-evidence:
  - type: source
    url: https://visibility.amp.cisco.com/iroh/iroh-response/index.html
  - type: raw
    url: https://visibility.amp.cisco.com/iroh/iroh-response/swagger.json
servers:
- url: https://visibility.amp.cisco.com/
security:
- iroh: []
- AuthorizationHeader: []
- oauth2:
  - telemetry
  - integration
  - private-intel
  - admin
  - cognitive
  - profile
  - inspect
  - asset
  - event
  - feedback
  - sse
  - registry
  - users
  - investigation
  - invite
  - casebook
  - orbital
  - enrich
  - oauth
  - vault
  - response
  - notification
  - global-intel:read
  - webhook
  - ao
tags:
- name: Response
  description: IROH Response
paths:
  /iroh/iroh-response/respond/observables:
    post:
      x-no-doc: false
      tags:
      - Response
      description: '[required scopes](/iroh/doc/iroh-auth/#scopes): `response/observables:read`


        '
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/x-yaml:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/edn:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/transit+json:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/transit+msgpack:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
      parameters:
      - in: query
        name: params
        description: ''
        required: false
        allowEmptyValue: true
        schema:
          type: string
      summary: List available actions for an observable
      requestBody:
        content:
          application/json:
            schema:
              description: a list of observables
              type: array
              items:
                $ref: '#/components/schemas/Observable'
          application/x-yaml:
            schema:
              description: a list of observables
              type: array
              items:
                $ref: '#/components/schemas/Observable'
          application/edn:
            schema:
              description: a list of observables
              type: array
              items:
                $ref: '#/components/schemas/Observable'
          application/transit+json:
            schema:
              description: a list of observables
              type: array
              items:
                $ref: '#/components/schemas/Observable'
          application/transit+msgpack:
            schema:
              description: a list of observables
              type: array
              items:
                $ref: '#/components/schemas/Observable'
        description: A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature.  This is the classic 'indicator' which might appear in a data feed of bad IPs, or bad Domains.  These do not exist as objects within the CTIA storage model, so you never create an observable.
        required: true
  /iroh/iroh-response/respond/sighting:
    post:
      x-no-doc: false
      tags:
      - Response
      description: '[required scopes](/iroh/doc/iroh-auth/#scopes): `response/sighting:read`


        '
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/x-yaml:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/edn:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/transit+json:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
            application/transit+msgpack:
              schema:
                $ref: '#/components/schemas/EnvelopedActions'
      parameters:
      - in: query
        name: params
        description: ''
        required: false
        allowEmptyValue: true
        schema:
          type: string
      summary: List available actions for a sighting
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Sighting'
          application/x-yaml:
            schema:
              $ref: '#/components/schemas/Sighting'
          application/edn:
            schema:
              $ref: '#/components/schemas/Sighting'
          application/transit+json:
            schema:
              $ref: '#/components/schemas/Sighting'
          application/transit+msgpack:
            schema:
              $ref: '#/components/schemas/Sighting'
        description: A Sighting
        required: true
  /iroh/iroh-response/respond/trigger/{module-instance-id}/{action-id}:
    post:
      x-no-doc: false
      tags:
      - Response
      description: '[required scopes](/iroh/doc/iroh-auth/#scopes): `response/trigger:write`


        '
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EnvelopedActionResult'
            application/x-yaml:
              schema:
                $ref: '#/components/schemas/EnvelopedActionResult'
            application/edn:
              schema:
                $ref: '#/components/schemas/EnvelopedActionResult'
            application/transit+json:
              schema:
                $ref: '#/components/schemas/EnvelopedActionResult'
            application/transit+msgpack:
              schema:
                $ref: '#/components/schemas/EnvelopedActionResult'
      parameters:
      - in: path
        name: module-instance-id
        description: ''
        required: true
        schema:
          type: string
      - in: path
        name: action-id
        description: ''
        required: true
        schema:
          type: string
      - in: query
        name: observable_type
        description: Observable type names
        required: false
        example: acudid
        schema:
          type: string
          enum:
          - file_path
          - mac_address
          - trend_micro_id
          - cybereason_id
          - process_args
          - s1_agent_id
          - device
          - hostname
          - certificate_common_name
          - serial_number
          - meraki_network_id
          - url
          - jamf_management_id
          - certificate_serial
          - intune_id
          - meraki_org_id
          - cisco_cm_id
          - registry_key
          - process_path
          - darktrace_id
          - process_username
          - cortex_agent_id
          - orbital_node_id
          - process_uid
          - ngfw_name
          - user
          - certificate_issuer
          - ipv6
          - email
          - cisco_uc_id
          - cvm_id
          - sha256
          - crowdstrike_id
          - google_cloud_id
          - google_chromebook_id
          - acudid
          - sha1
          - registry_name
          - md5
          - service_now_id
          - ip
          - domain
          - email_subject
          - imei
          - ngfw_id
          - amp_computer_guid
          - ms_machine_id
          - secure_access_id
          - mutex
          - processor_id
          - swc_device_id
          - registry_path
          - odns_identity
          - odns_identity_label
          - cisco_mid
          - process_name
          - pki_serial
          - meraki_node_sn
          - email_messageid
          - imsi
          - user_agent
          - process_hash
          - file_name
      - in: query
        name: observable_value
        description: ''
        required: false
        schema:
          type: string
      summary: Trigger an Action
components:
  schemas:
    ActionResult:
      type: object
      properties:
        status:
          type: string
          enum:
          - failure
          - success
      additionalProperties: false
      required:
      - status
    EnvelopedActionResult:
      type: object
      properties:
        data:
          $ref: '#/components/schemas/ActionResult'
        errors:
          type: array
          items:
            $ref: '#/components/schemas/ErrorMessage'
      additionalProperties: false
    LibraryLoadType:
      example:
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        process_id: 10
        process_name: string
        process_guid: 10
        process_username: string
        type: LibraryLoadEvent
        dll_library_name: string
        dll_library_path: string
      type: object
      properties:
        time:
          $ref: '#/components/schemas/ObservedTime'
        process_id:
          example: 10
          type: integer
          format: int64
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_guid:
          example: 10
          type: integer
          format: int64
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        type:
          example: LibraryLoadEvent
          type: string
          enum:
          - LibraryLoadEvent
        dll_library_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        dll_library_path:
          example: string
          description: String with at most 2048 characters.
          type: string
      additionalProperties: false
      required:
      - time
      - process_id
      - process_name
      - type
      - dll_library_name
      - dll_library_path
    FileDeleteType:
      example:
        file_name: string
        process_guid: 10
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        type: FileDeleteEvent
        file_path: string
        process_name: string
        process_id: 10
        process_username: string
        failed: false
      type: object
      properties:
        file_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_guid:
          example: 10
          type: integer
          format: int64
        time:
          $ref: '#/components/schemas/ObservedTime'
        type:
          example: FileDeleteEvent
          type: string
          enum:
          - FileDeleteEvent
        file_path:
          example: string
          description: String with at most 2048 characters.
          type: string
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_id:
          example: 10
          type: integer
          format: int64
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        failed:
          example: false
          type: boolean
      additionalProperties: false
      required:
      - file_name
      - time
      - type
      - file_path
      - process_name
      - process_id
    RegistryCreateType:
      example:
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        process_id: 10
        process_name: string
        process_guid: 10
        process_username: string
        registry_key: string
        type: RegistryCreateEvent
      type: object
      properties:
        time:
          $ref: '#/components/schemas/ObservedTime'
        process_id:
          example: 10
          type: integer
          format: int64
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_guid:
          example: 10
          type: integer
          format: int64
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        registry_key:
          example: string
          description: String with at most 1024 characters.
          type: string
        type:
          example: RegistryCreateEvent
          type: string
          enum:
          - RegistryCreateEvent
      additionalProperties: false
      required:
      - time
      - process_id
      - process_name
      - registry_key
      - type
    EnvelopedActions:
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/Action'
        errors:
          type: array
          items:
            $ref: '#/components/schemas/ErrorMessage'
      additionalProperties: false
    HTTPType:
      example:
        process_guid: 10
        traffic:
          destination_host_name: string
          protocol: 10
          source_ip: string
          destination_subnet: string
          destination_ip: string
          source_subnet: string
          destination_port: 10
          direction: incoming
          source_port: 10
        method: CONNECT
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        type: HTTPEvent
        host: string
        process_name: string
        process_id: 10
        process_username: string
        query: string
        encrypted: true
        url_port: 10
      type: object
      properties:
        process_guid:
          example: 10
          type: integer
          format: int64
        traffic:
          $ref: '#/components/schemas/Traffic'
        method:
          example: CONNECT
          type: string
          enum:
          - OPTIONS
          - PATCH
          - TRACE
          - HEAD
          - POST
          - CONNECT
          - GET
          - PUT
        time:
          $ref: '#/components/schemas/ObservedTime'
        type:
          example: HTTPEvent
          type: string
          enum:
          - HTTPEvent
        host:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_id:
          example: 10
          type: integer
          format: int64
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        query:
          example: string
          description: String with at most 5000 characters.
          type: string
        encrypted:
          example: true
          type: boolean
        url_port:
          example: 10
          type: integer
          format: int64
      additionalProperties: false
      required:
      - traffic
      - time
      - type
      - host
      - process_name
      - process_id
    NetflowType:
      example:
        parent_process_name: string
        byte_count_in: 10
        process_guid: 10
        process_path: string
        traffic:
          destination_host_name: string
          protocol: 10
          source_ip: string
          destination_subnet: string
          destination_ip: string
          source_subnet: string
          destination_port: 10
          direction: incoming
          source_port: 10
        flow_time: '2016-01-01T01:01:01.000Z'
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        parent_process_account: string
        type: NetflowEvent
        process_account_type: string
        parent_process_path: string
        parent_process_id: 10
        parent_process_args: string
        process_name: string
        process_account: string
        parent_process_account_type: string
        process_hash: string
        process_id: 10
        parent_process_hash: string
        process_username: string
        byte_count_out: 10
        process_args: string
      type: object
      properties:
        parent_process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        byte_count_in:
          example: 10
          type: integer
          format: int64
        process_guid:
          example: 10
          type: integer
          format: int64
        process_path:
          example: string
          description: String with at most 1024 characters.
          type: string
        traffic:
          $ref: '#/components/schemas/Traffic'
        flow_time:
          example: '2016-01-01T01:01:01.000Z'
          description: Schema definition for all date or timestamp values.  Serialized as a string, the field should follow the rules of the [ISO8601](https://en.wikipedia.org/wiki/ISO_8601) standard.
          type: string
          format: date-time
        time:
          $ref: '#/components/schemas/ObservedTime'
        parent_process_account:
          example: string
          description: String with at most 1024 characters.
          type: string
        type:
          example: NetflowEvent
          type: string
          enum:
          - NetflowEvent
        process_account_type:
          example: string
          description: String with at most 1024 characters.
          type: string
        parent_process_path:
          example: string
          description: String with at most 1024 characters.
          type: string
        parent_process_id:
          example: 10
          type: integer
          format: int64
        parent_process_args:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_account:
          example: string
          description: String with at most 1024 characters.
          type: string
        parent_process_account_type:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_hash:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_id:
          example: 10
          type: integer
          format: int64
        parent_process_hash:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        byte_count_out:
          example: 10
          type: integer
          format: int64
        process_args:
          example: string
          description: String with at most 1024 characters.
          type: string
      additionalProperties: false
      required:
      - traffic
      - time
      - type
      - process_name
      - process_id
    SightingDataTable:
      example:
        columns:
        - name: string
          type: integer
          description: string
          required: true
          short_description: string
        rows:
        - - anything
        row_count: 10
      description: An embedded data table for the Sighting.
      type: object
      properties:
        columns:
          example:
          - name: string
            type: integer
            description: string
            required: true
            short_description: string
          description: an ordered list of column definitions
          type: array
          items:
            $ref: '#/components/schemas/ColumnDefinition'
        rows:
          example:
          - - anything
          description: an ordered list of rows
          type: array
          items:
            type: array
            items: {}
        row_count:
          example: 10
          description: The number of rows in the data table.
          type: integer
          format: int64
      additionalProperties: false
      required:
      - columns
      - rows
    ObservedTime:
      example:
        start_time: '2016-01-01T01:01:01.000Z'
        end_time: '2016-01-01T01:01:01.000Z'
      description: Period of time when a cyber observation is valid. `start_time` must come before `end_time` (if specified).
      type: object
      properties:
        start_time:
          example: '2016-01-01T01:01:01.000Z'
          description: Time of the observation. If the observation was made over a period of time, than this field indicates the start of that period.
          type: string
          format: date-time
        end_time:
          example: '2016-01-01T01:01:01.000Z'
          description: If the observation was made over a period of time, than this field indicates the end of that period.
          type: string
          format: date-time
      additionalProperties: false
      required:
      - start_time
    RegistrySetType:
      example:
        process_guid: 10
        registry_data: string
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        type: RegistrySetEvent
        registry_data_length: 10
        registry_value: string
        registry_key: string
        process_name: string
        process_id: 10
        process_username: string
      type: object
      properties:
        process_guid:
          example: 10
          type: integer
          format: int64
        registry_data:
          example: string
          description: String with at most 5000 characters.
          type: string
        time:
          $ref: '#/components/schemas/ObservedTime'
        type:
          example: RegistrySetEvent
          type: string
          enum:
          - RegistrySetEvent
        registry_data_length:
          example: 10
          type: integer
          format: int64
        registry_value:
          example: string
          description: String with at most 2048 characters.
          type: string
        registry_key:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_id:
          example: 10
          type: integer
          format: int64
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
      additionalProperties: false
      required:
      - time
      - type
      - registry_value
      - registry_key
      - process_name
      - process_id
    ProcessCreateType:
      example:
        parent_process_name: string
        process_guid: 10
        parent_process_guid: 10
        process_disposition: string
        parent_process_size: 10
        process_size: 10
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        parent_process_disposition: string
        type: ProcessCreateEvent
        parent_process_username: string
        parent_process_id: 10
        parent_process_args: string
        process_name: string
        process_hash: string
        process_id: 10
        parent_process_hash: string
        process_username: string
        parent_creation_time: '2016-01-01T01:01:01.000Z'
        process_args: string
      type: object
      properties:
        parent_process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_guid:
          example: 10
          type: integer
          format: int64
        parent_process_guid:
          example: 10
          type: integer
          format: int64
        process_disposition:
          example: string
          description: String with at most 1024 characters.
          type: string
        parent_process_size:
          example: 10
          type: integer
          format: int64
        process_size:
          example: 10
          type: integer
          format: int64
        time:
          $ref: '#/components/schemas/ObservedTime'
        parent_process_disposition:
          example: string
          description: String with at most 1024 characters.
          type: string
        type:
          example: ProcessCreateEvent
          type: string
          enum:
          - ProcessCreateEvent
        parent_process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        parent_process_id:
          example: 10
          type: integer
          format: int64
        parent_process_args:
          example: string
          description: String with at most 2048 characters.
          type: string
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_hash:
          example: string
          description: String with at most 2048 characters.
          type: string
        process_id:
          example: 10
          type: integer
          format: int64
        parent_process_hash:
          example: string
          description: String with at most 2048 characters.
          type: string
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        parent_creation_time:
          example: '2016-01-01T01:01:01.000Z'
          description: Schema definition for all date or timestamp values.  Serialized as a string, the field should follow the rules of the [ISO8601](https://en.wikipedia.org/wiki/ISO_8601) standard.
          type: string
          format: date-time
        process_args:
          example: string
          description: String with at most 2048 characters.
          type: string
      additionalProperties: false
      required:
      - time
      - type
      - process_name
      - process_id
    Traffic:
      example:
        destination_host_name: string
        protocol: 10
        source_ip: string
        destination_subnet: string
        destination_ip: string
        source_subnet: string
        destination_port: 10
        direction: incoming
        source_port: 10
      type: object
      properties:
        destination_host_name:
          example: string
          type: string
        protocol:
          example: 10
          description: The IP [protocol id](https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml)
          type: integer
          format: int64
        source_ip:
          example: string
          type: string
        destination_subnet:
          example: string
          type: string
        destination_ip:
          example: string
          type: string
        source_subnet:
          example: string
          type: string
        destination_port:
          example: 10
          type: integer
          format: int64
        direction:
          example: incoming
          type: string
          enum:
          - incoming
          - outgoing
        source_port:
          example: 10
          type: integer
          format: int64
      additionalProperties: false
      required:
      - protocol
      - source_ip
      - destination_ip
      - destination_port
      - direction
      - source_port
    Observable:
      example:
        value: 1.2.3.4
        type: ip
      description: A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature.  This is the classic 'indicator' which might appear in a data feed of bad IPs, or bad Domains.  These do not exist as objects within the CTIA storage model, so you never create an observable.
      type: object
      properties:
        value:
          example: 1.2.3.4
          description: The value of the observable.
          type: string
        type:
          example: ip
          description: The type of observable.
          type: string
          enum:
          - file_path
          - mac_address
          - trend_micro_id
          - cybereason_id
          - process_args
          - s1_agent_id
          - device
          - hostname
          - certificate_common_name
          - serial_number
          - meraki_network_id
          - url
          - jamf_management_id
          - certificate_serial
          - intune_id
          - meraki_org_id
          - cisco_cm_id
          - registry_key
          - process_path
          - darktrace_id
          - process_username
          - cortex_agent_id
          - orbital_node_id
          - process_uid
          - ngfw_name
          - user
          - certificate_issuer
          - ipv6
          - email
          - cisco_uc_id
          - cvm_id
          - sha256
          - crowdstrike_id
          - google_cloud_id
          - google_chromebook_id
          - acudid
          - sha1
          - registry_name
          - md5
          - service_now_id
          - ip
          - domain
          - email_subject
          - imei
          - ngfw_id
          - amp_computer_guid
          - ms_machine_id
          - secure_access_id
          - mutex
          - processor_id
          - swc_device_id
          - registry_path
          - odns_identity
          - odns_identity_label
          - cisco_mid
          - process_name
          - pki_serial
          - meraki_node_sn
          - email_messageid
          - imsi
          - user_agent
          - process_hash
          - file_name
      additionalProperties: false
      required:
      - value
      - type
    RegistryRenameType:
      example:
        time:
          start_time: '2016-01-01T01:01:01.000Z'
          end_time: '2016-01-01T01:01:01.000Z'
        process_id: 10
        process_name: string
        process_guid: 10
        process_username: string
        registry_key: string
        type: RegistryRenameEvent
        registry_old_key: string
      type: object
      properties:
        time:
          $ref: '#/components/schemas/ObservedTime'
        process_id:
          example: 10
          type: integer
          format: int64
        process_name:
          example: string
          description: String with at most 1024 characters.
          type: string
        process_guid:
          example: 10
          type: integer
          format: int64
        process_username:
          example: string
          description: String with at most 1024 characters.
          type: string
        registry_key:
          example: string
          description: String with at most 1024 characters.
          type: string
        type:
          example: RegistryRenameEvent
          type: string
          enum:
          - RegistryRenameEvent
        registry_old_key:
          example: string
          description: String with at most 1024 characters.
          type: string
      additionalProperties: false
      required:
      - time
      - process_id
      - process_name
      - registry_key
      - type
      - registry_old_key
    SensorCoordinates:
      example:
        type: endpoint
        observables:
        - value: 1.2.3.4
          type: ip
        os: string
      description: Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
      type: object
      properties:
        type:
          example: endpoint
          description: The sensor/actuator name that best fits a device.
          type: string
        observables:
          example:
          - value: 1.2.3.4
            type: ip
          type: array
          items:
            $ref: '#/components/schemas/Observable'
        os:
          example: string
          type: string
      additionalProperties: false
      required:
      - type
      - observabl

# --- truncated at 32 KB (70 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/openapi/cisco-xdr-response-api-openapi.yml