OpenAPI Specification
openapi: 3.2.0
info:
title: IROH-INT Response API
version: 1.0.107
license:
name: All Rights Reserved
url: https://www.cisco.com
contact:
name: Cisco Security Business Group -- Advanced Threat
email: cisco-intel-api-support@cisco.com
description: Manage Response from modules
x-provenance:
method: harvested
authored_by: Cisco XDR
harvested_by: API Evangelist
harvested_on: '2026-08-19'
first_party: true
note: Published by Cisco. Retrieved unmodified except for this x-provenance block.
provider_published: true
x-evidence:
- type: source
url: https://visibility.amp.cisco.com/iroh/iroh-response/index.html
- type: raw
url: https://visibility.amp.cisco.com/iroh/iroh-response/swagger.json
servers:
- url: https://visibility.amp.cisco.com/
security:
- iroh: []
- AuthorizationHeader: []
- oauth2:
- telemetry
- integration
- private-intel
- admin
- cognitive
- profile
- inspect
- asset
- event
- feedback
- sse
- registry
- users
- investigation
- invite
- casebook
- orbital
- enrich
- oauth
- vault
- response
- notification
- global-intel:read
- webhook
- ao
tags:
- name: Response
description: IROH Response
paths:
/iroh/iroh-response/respond/observables:
post:
x-no-doc: false
tags:
- Response
description: '[required scopes](/iroh/doc/iroh-auth/#scopes): `response/observables:read`
'
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/x-yaml:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/edn:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/transit+json:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/transit+msgpack:
schema:
$ref: '#/components/schemas/EnvelopedActions'
parameters:
- in: query
name: params
description: ''
required: false
allowEmptyValue: true
schema:
type: string
summary: List available actions for an observable
requestBody:
content:
application/json:
schema:
description: a list of observables
type: array
items:
$ref: '#/components/schemas/Observable'
application/x-yaml:
schema:
description: a list of observables
type: array
items:
$ref: '#/components/schemas/Observable'
application/edn:
schema:
description: a list of observables
type: array
items:
$ref: '#/components/schemas/Observable'
application/transit+json:
schema:
description: a list of observables
type: array
items:
$ref: '#/components/schemas/Observable'
application/transit+msgpack:
schema:
description: a list of observables
type: array
items:
$ref: '#/components/schemas/Observable'
description: A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might appear in a data feed of bad IPs, or bad Domains. These do not exist as objects within the CTIA storage model, so you never create an observable.
required: true
/iroh/iroh-response/respond/sighting:
post:
x-no-doc: false
tags:
- Response
description: '[required scopes](/iroh/doc/iroh-auth/#scopes): `response/sighting:read`
'
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/x-yaml:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/edn:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/transit+json:
schema:
$ref: '#/components/schemas/EnvelopedActions'
application/transit+msgpack:
schema:
$ref: '#/components/schemas/EnvelopedActions'
parameters:
- in: query
name: params
description: ''
required: false
allowEmptyValue: true
schema:
type: string
summary: List available actions for a sighting
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Sighting'
application/x-yaml:
schema:
$ref: '#/components/schemas/Sighting'
application/edn:
schema:
$ref: '#/components/schemas/Sighting'
application/transit+json:
schema:
$ref: '#/components/schemas/Sighting'
application/transit+msgpack:
schema:
$ref: '#/components/schemas/Sighting'
description: A Sighting
required: true
/iroh/iroh-response/respond/trigger/{module-instance-id}/{action-id}:
post:
x-no-doc: false
tags:
- Response
description: '[required scopes](/iroh/doc/iroh-auth/#scopes): `response/trigger:write`
'
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/EnvelopedActionResult'
application/x-yaml:
schema:
$ref: '#/components/schemas/EnvelopedActionResult'
application/edn:
schema:
$ref: '#/components/schemas/EnvelopedActionResult'
application/transit+json:
schema:
$ref: '#/components/schemas/EnvelopedActionResult'
application/transit+msgpack:
schema:
$ref: '#/components/schemas/EnvelopedActionResult'
parameters:
- in: path
name: module-instance-id
description: ''
required: true
schema:
type: string
- in: path
name: action-id
description: ''
required: true
schema:
type: string
- in: query
name: observable_type
description: Observable type names
required: false
example: acudid
schema:
type: string
enum:
- file_path
- mac_address
- trend_micro_id
- cybereason_id
- process_args
- s1_agent_id
- device
- hostname
- certificate_common_name
- serial_number
- meraki_network_id
- url
- jamf_management_id
- certificate_serial
- intune_id
- meraki_org_id
- cisco_cm_id
- registry_key
- process_path
- darktrace_id
- process_username
- cortex_agent_id
- orbital_node_id
- process_uid
- ngfw_name
- user
- certificate_issuer
- ipv6
- email
- cisco_uc_id
- cvm_id
- sha256
- crowdstrike_id
- google_cloud_id
- google_chromebook_id
- acudid
- sha1
- registry_name
- md5
- service_now_id
- ip
- domain
- email_subject
- imei
- ngfw_id
- amp_computer_guid
- ms_machine_id
- secure_access_id
- mutex
- processor_id
- swc_device_id
- registry_path
- odns_identity
- odns_identity_label
- cisco_mid
- process_name
- pki_serial
- meraki_node_sn
- email_messageid
- imsi
- user_agent
- process_hash
- file_name
- in: query
name: observable_value
description: ''
required: false
schema:
type: string
summary: Trigger an Action
components:
schemas:
ActionResult:
type: object
properties:
status:
type: string
enum:
- failure
- success
additionalProperties: false
required:
- status
EnvelopedActionResult:
type: object
properties:
data:
$ref: '#/components/schemas/ActionResult'
errors:
type: array
items:
$ref: '#/components/schemas/ErrorMessage'
additionalProperties: false
LibraryLoadType:
example:
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
process_id: 10
process_name: string
process_guid: 10
process_username: string
type: LibraryLoadEvent
dll_library_name: string
dll_library_path: string
type: object
properties:
time:
$ref: '#/components/schemas/ObservedTime'
process_id:
example: 10
type: integer
format: int64
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_guid:
example: 10
type: integer
format: int64
process_username:
example: string
description: String with at most 1024 characters.
type: string
type:
example: LibraryLoadEvent
type: string
enum:
- LibraryLoadEvent
dll_library_name:
example: string
description: String with at most 1024 characters.
type: string
dll_library_path:
example: string
description: String with at most 2048 characters.
type: string
additionalProperties: false
required:
- time
- process_id
- process_name
- type
- dll_library_name
- dll_library_path
FileDeleteType:
example:
file_name: string
process_guid: 10
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
type: FileDeleteEvent
file_path: string
process_name: string
process_id: 10
process_username: string
failed: false
type: object
properties:
file_name:
example: string
description: String with at most 1024 characters.
type: string
process_guid:
example: 10
type: integer
format: int64
time:
$ref: '#/components/schemas/ObservedTime'
type:
example: FileDeleteEvent
type: string
enum:
- FileDeleteEvent
file_path:
example: string
description: String with at most 2048 characters.
type: string
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_id:
example: 10
type: integer
format: int64
process_username:
example: string
description: String with at most 1024 characters.
type: string
failed:
example: false
type: boolean
additionalProperties: false
required:
- file_name
- time
- type
- file_path
- process_name
- process_id
RegistryCreateType:
example:
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
process_id: 10
process_name: string
process_guid: 10
process_username: string
registry_key: string
type: RegistryCreateEvent
type: object
properties:
time:
$ref: '#/components/schemas/ObservedTime'
process_id:
example: 10
type: integer
format: int64
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_guid:
example: 10
type: integer
format: int64
process_username:
example: string
description: String with at most 1024 characters.
type: string
registry_key:
example: string
description: String with at most 1024 characters.
type: string
type:
example: RegistryCreateEvent
type: string
enum:
- RegistryCreateEvent
additionalProperties: false
required:
- time
- process_id
- process_name
- registry_key
- type
EnvelopedActions:
type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/Action'
errors:
type: array
items:
$ref: '#/components/schemas/ErrorMessage'
additionalProperties: false
HTTPType:
example:
process_guid: 10
traffic:
destination_host_name: string
protocol: 10
source_ip: string
destination_subnet: string
destination_ip: string
source_subnet: string
destination_port: 10
direction: incoming
source_port: 10
method: CONNECT
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
type: HTTPEvent
host: string
process_name: string
process_id: 10
process_username: string
query: string
encrypted: true
url_port: 10
type: object
properties:
process_guid:
example: 10
type: integer
format: int64
traffic:
$ref: '#/components/schemas/Traffic'
method:
example: CONNECT
type: string
enum:
- OPTIONS
- PATCH
- TRACE
- HEAD
- POST
- CONNECT
- GET
- PUT
time:
$ref: '#/components/schemas/ObservedTime'
type:
example: HTTPEvent
type: string
enum:
- HTTPEvent
host:
example: string
description: String with at most 1024 characters.
type: string
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_id:
example: 10
type: integer
format: int64
process_username:
example: string
description: String with at most 1024 characters.
type: string
query:
example: string
description: String with at most 5000 characters.
type: string
encrypted:
example: true
type: boolean
url_port:
example: 10
type: integer
format: int64
additionalProperties: false
required:
- traffic
- time
- type
- host
- process_name
- process_id
NetflowType:
example:
parent_process_name: string
byte_count_in: 10
process_guid: 10
process_path: string
traffic:
destination_host_name: string
protocol: 10
source_ip: string
destination_subnet: string
destination_ip: string
source_subnet: string
destination_port: 10
direction: incoming
source_port: 10
flow_time: '2016-01-01T01:01:01.000Z'
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
parent_process_account: string
type: NetflowEvent
process_account_type: string
parent_process_path: string
parent_process_id: 10
parent_process_args: string
process_name: string
process_account: string
parent_process_account_type: string
process_hash: string
process_id: 10
parent_process_hash: string
process_username: string
byte_count_out: 10
process_args: string
type: object
properties:
parent_process_name:
example: string
description: String with at most 1024 characters.
type: string
byte_count_in:
example: 10
type: integer
format: int64
process_guid:
example: 10
type: integer
format: int64
process_path:
example: string
description: String with at most 1024 characters.
type: string
traffic:
$ref: '#/components/schemas/Traffic'
flow_time:
example: '2016-01-01T01:01:01.000Z'
description: Schema definition for all date or timestamp values. Serialized as a string, the field should follow the rules of the [ISO8601](https://en.wikipedia.org/wiki/ISO_8601) standard.
type: string
format: date-time
time:
$ref: '#/components/schemas/ObservedTime'
parent_process_account:
example: string
description: String with at most 1024 characters.
type: string
type:
example: NetflowEvent
type: string
enum:
- NetflowEvent
process_account_type:
example: string
description: String with at most 1024 characters.
type: string
parent_process_path:
example: string
description: String with at most 1024 characters.
type: string
parent_process_id:
example: 10
type: integer
format: int64
parent_process_args:
example: string
description: String with at most 1024 characters.
type: string
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_account:
example: string
description: String with at most 1024 characters.
type: string
parent_process_account_type:
example: string
description: String with at most 1024 characters.
type: string
process_hash:
example: string
description: String with at most 1024 characters.
type: string
process_id:
example: 10
type: integer
format: int64
parent_process_hash:
example: string
description: String with at most 1024 characters.
type: string
process_username:
example: string
description: String with at most 1024 characters.
type: string
byte_count_out:
example: 10
type: integer
format: int64
process_args:
example: string
description: String with at most 1024 characters.
type: string
additionalProperties: false
required:
- traffic
- time
- type
- process_name
- process_id
SightingDataTable:
example:
columns:
- name: string
type: integer
description: string
required: true
short_description: string
rows:
- - anything
row_count: 10
description: An embedded data table for the Sighting.
type: object
properties:
columns:
example:
- name: string
type: integer
description: string
required: true
short_description: string
description: an ordered list of column definitions
type: array
items:
$ref: '#/components/schemas/ColumnDefinition'
rows:
example:
- - anything
description: an ordered list of rows
type: array
items:
type: array
items: {}
row_count:
example: 10
description: The number of rows in the data table.
type: integer
format: int64
additionalProperties: false
required:
- columns
- rows
ObservedTime:
example:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
description: Period of time when a cyber observation is valid. `start_time` must come before `end_time` (if specified).
type: object
properties:
start_time:
example: '2016-01-01T01:01:01.000Z'
description: Time of the observation. If the observation was made over a period of time, than this field indicates the start of that period.
type: string
format: date-time
end_time:
example: '2016-01-01T01:01:01.000Z'
description: If the observation was made over a period of time, than this field indicates the end of that period.
type: string
format: date-time
additionalProperties: false
required:
- start_time
RegistrySetType:
example:
process_guid: 10
registry_data: string
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
type: RegistrySetEvent
registry_data_length: 10
registry_value: string
registry_key: string
process_name: string
process_id: 10
process_username: string
type: object
properties:
process_guid:
example: 10
type: integer
format: int64
registry_data:
example: string
description: String with at most 5000 characters.
type: string
time:
$ref: '#/components/schemas/ObservedTime'
type:
example: RegistrySetEvent
type: string
enum:
- RegistrySetEvent
registry_data_length:
example: 10
type: integer
format: int64
registry_value:
example: string
description: String with at most 2048 characters.
type: string
registry_key:
example: string
description: String with at most 1024 characters.
type: string
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_id:
example: 10
type: integer
format: int64
process_username:
example: string
description: String with at most 1024 characters.
type: string
additionalProperties: false
required:
- time
- type
- registry_value
- registry_key
- process_name
- process_id
ProcessCreateType:
example:
parent_process_name: string
process_guid: 10
parent_process_guid: 10
process_disposition: string
parent_process_size: 10
process_size: 10
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
parent_process_disposition: string
type: ProcessCreateEvent
parent_process_username: string
parent_process_id: 10
parent_process_args: string
process_name: string
process_hash: string
process_id: 10
parent_process_hash: string
process_username: string
parent_creation_time: '2016-01-01T01:01:01.000Z'
process_args: string
type: object
properties:
parent_process_name:
example: string
description: String with at most 1024 characters.
type: string
process_guid:
example: 10
type: integer
format: int64
parent_process_guid:
example: 10
type: integer
format: int64
process_disposition:
example: string
description: String with at most 1024 characters.
type: string
parent_process_size:
example: 10
type: integer
format: int64
process_size:
example: 10
type: integer
format: int64
time:
$ref: '#/components/schemas/ObservedTime'
parent_process_disposition:
example: string
description: String with at most 1024 characters.
type: string
type:
example: ProcessCreateEvent
type: string
enum:
- ProcessCreateEvent
parent_process_username:
example: string
description: String with at most 1024 characters.
type: string
parent_process_id:
example: 10
type: integer
format: int64
parent_process_args:
example: string
description: String with at most 2048 characters.
type: string
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_hash:
example: string
description: String with at most 2048 characters.
type: string
process_id:
example: 10
type: integer
format: int64
parent_process_hash:
example: string
description: String with at most 2048 characters.
type: string
process_username:
example: string
description: String with at most 1024 characters.
type: string
parent_creation_time:
example: '2016-01-01T01:01:01.000Z'
description: Schema definition for all date or timestamp values. Serialized as a string, the field should follow the rules of the [ISO8601](https://en.wikipedia.org/wiki/ISO_8601) standard.
type: string
format: date-time
process_args:
example: string
description: String with at most 2048 characters.
type: string
additionalProperties: false
required:
- time
- type
- process_name
- process_id
Traffic:
example:
destination_host_name: string
protocol: 10
source_ip: string
destination_subnet: string
destination_ip: string
source_subnet: string
destination_port: 10
direction: incoming
source_port: 10
type: object
properties:
destination_host_name:
example: string
type: string
protocol:
example: 10
description: The IP [protocol id](https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml)
type: integer
format: int64
source_ip:
example: string
type: string
destination_subnet:
example: string
type: string
destination_ip:
example: string
type: string
source_subnet:
example: string
type: string
destination_port:
example: 10
type: integer
format: int64
direction:
example: incoming
type: string
enum:
- incoming
- outgoing
source_port:
example: 10
type: integer
format: int64
additionalProperties: false
required:
- protocol
- source_ip
- destination_ip
- destination_port
- direction
- source_port
Observable:
example:
value: 1.2.3.4
type: ip
description: A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might appear in a data feed of bad IPs, or bad Domains. These do not exist as objects within the CTIA storage model, so you never create an observable.
type: object
properties:
value:
example: 1.2.3.4
description: The value of the observable.
type: string
type:
example: ip
description: The type of observable.
type: string
enum:
- file_path
- mac_address
- trend_micro_id
- cybereason_id
- process_args
- s1_agent_id
- device
- hostname
- certificate_common_name
- serial_number
- meraki_network_id
- url
- jamf_management_id
- certificate_serial
- intune_id
- meraki_org_id
- cisco_cm_id
- registry_key
- process_path
- darktrace_id
- process_username
- cortex_agent_id
- orbital_node_id
- process_uid
- ngfw_name
- user
- certificate_issuer
- ipv6
- email
- cisco_uc_id
- cvm_id
- sha256
- crowdstrike_id
- google_cloud_id
- google_chromebook_id
- acudid
- sha1
- registry_name
- md5
- service_now_id
- ip
- domain
- email_subject
- imei
- ngfw_id
- amp_computer_guid
- ms_machine_id
- secure_access_id
- mutex
- processor_id
- swc_device_id
- registry_path
- odns_identity
- odns_identity_label
- cisco_mid
- process_name
- pki_serial
- meraki_node_sn
- email_messageid
- imsi
- user_agent
- process_hash
- file_name
additionalProperties: false
required:
- value
- type
RegistryRenameType:
example:
time:
start_time: '2016-01-01T01:01:01.000Z'
end_time: '2016-01-01T01:01:01.000Z'
process_id: 10
process_name: string
process_guid: 10
process_username: string
registry_key: string
type: RegistryRenameEvent
registry_old_key: string
type: object
properties:
time:
$ref: '#/components/schemas/ObservedTime'
process_id:
example: 10
type: integer
format: int64
process_name:
example: string
description: String with at most 1024 characters.
type: string
process_guid:
example: 10
type: integer
format: int64
process_username:
example: string
description: String with at most 1024 characters.
type: string
registry_key:
example: string
description: String with at most 1024 characters.
type: string
type:
example: RegistryRenameEvent
type: string
enum:
- RegistryRenameEvent
registry_old_key:
example: string
description: String with at most 1024 characters.
type: string
additionalProperties: false
required:
- time
- process_id
- process_name
- registry_key
- type
- registry_old_key
SensorCoordinates:
example:
type: endpoint
observables:
- value: 1.2.3.4
type: ip
os: string
description: Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
type: object
properties:
type:
example: endpoint
description: The sensor/actuator name that best fits a device.
type: string
observables:
example:
- value: 1.2.3.4
type: ip
type: array
items:
$ref: '#/components/schemas/Observable'
os:
example: string
type: string
additionalProperties: false
required:
- type
- observabl
# --- truncated at 32 KB (70 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/openapi/cisco-xdr-response-api-openapi.yml