Cisco XDR V2 API

The v2 API from Cisco XDR — 75 operation(s) for v2.

Business capability
Threat Detection & Response Management BC-620.30

Operations 85

POST /v2/casebook Adds a new Casebook #
GET /v2/casebook/external_id/{external-id} List Casebook by external id #
GET /v2/casebook/search Search casebooks #
GET /v2/casebook/{casebook-id} Get one casebook by id #
PUT /v2/casebook/{casebook-id} Updates a Casebook #
DELETE /v2/casebook/{casebook-id} Deletes a Casebook #
PATCH /v2/casebook/{casebook-id} Partially Update a Casebook #
GET /v2/casebook/{casebook-id}/summary Returns a casebook and it's related incidents #
POST /v2/casebook/{casebook-id}/observables Updates a casebook's observables #
POST /v2/casebook/{casebook-id}/bundle Updates a casebook's bundle #
POST /v2/casebook/{casebook-id}/texts Updates a casebook's texts #
POST /v2/investigation Create Investigation #
POST /v2/investigation/bundle Create Investigation from Snapshot #
POST /v2/investigation/snapshot Create Investigation from Snapshot #
GET /v2/investigation/{investigation-id}/snapshot Create Investigation from Investigation Id #
GET /v2/investigation/{investigation-id}/errors Investigation Errors #
GET /v2/investigation/{investigation-id}/entities Investigation Entities #
GET /v2/investigation/{investigation-id}/events Investigation Events #
GET /v2/investigation/{investigation-id}/verdicts Investigation Verdicts #
GET /v2/investigation/{investigation-id}/graph Investigation Relation Graph #
GET /v2/investigation/{investigation-id}/indicators Returns a list of indicators attached to this investigation #
GET /v2/investigation/{investigation-id}/observables Returns a list of observables attached to this investigation #
GET /v2/investigation/{investigation-id}/overview Returns metadata about the investigation #
GET /v2/investigation/{investigation-id}/status Investigation Status #
GET /v2/investigation/{investigation-id}/summary Returns a Summary of the Investigation #
GET /v2/investigation/{investigation-id}/targets Returns a list of targets attached to this investigation #
POST /v2/investigation/{investigation-id}/bundle Add Threat context to an investigation #
POST /v2/investigation/{investigation-id}/observable/add Add observables to an investigation #
POST /v2/investigation/{investigation-id}/observable/remove Remove observables from an investigation #
POST /v2/investigation/{investigation-id}/task Run a task #
PUT /v2/investigation/{investigation-id}/edit Saves an investigation in place #
POST /v2/investigation/{investigation-id}/copy Create a copy of an investigation #
DELETE /v2/investigation/{investigation-id}/delete Delete investigation by investigation id delete #
POST /v2/investigation/{investigation-id}/save-as Saves an investigation as a new entity #
POST /v2/incident Create New Incident #
POST /v2/incident/delete Delete Bulk Incidents #
GET /v2/incident/search Search incidents #
GET /v2/incident/search/count Get Count of Incidents by Search #
GET /v2/incident/{incident-id} Get one incident #
PUT /v2/incident/{incident-id} Update one incident #
DELETE /v2/incident/{incident-id} Delete one incident #
PATCH /v2/incident/{incident-id} Patch one incident #
POST /v2/incident/{incident-id}/actions-taken Post actions taken for an incident #
POST /v2/incident/{incident-id}/link/{entity-type}/{entity-id} Link incident and entity (investigation | casebook | incident) #
DELETE /v2/incident/{incident-id}/link/{entity-type}/{entity-id} Unlink incident and entity. (investigation | casebook | incident) #
POST /v2/incident/{incident-id}/update-context Process an incident update by invalidating the cache and finding reputations as… #
GET /v2/incident/{incident-id}/report Incident Report #
GET /v2/incident/{incident-id}/report/{section-id} Incident Report Section #
POST /v2/incident/{incident-id}/report/{section-id} Update Report Section #
POST /v2/incident/{incident-id}/report/{section-id}/regenerate Regenerate a Report Section #
GET /v2/incident/{incident-id}/summary Full Incident Summary. Equivalent Data to v1 summary endpoints #
GET /v2/incident/{incident-id}/mitre Mitre tactics, techniques, and subtechniques found in an incident #
GET /v2/incident/{incident-id}/targets Incident Assets #
GET /v2/incident/{incident-id}/observables Returns a list of observables linked to this incident #
GET /v2/incident/{incident-id}/indicators Returns a list of indicators linked to this incident #
GET /v2/incident/{incident-id}/entities Returns a list of entities associated with this incident #
GET /v2/incident/{incident-id}/events Returns a list of events linked to this incident #
POST /v2/incident/{incident-id}/events Returns a list of events linked to this incident #
GET /v2/incident/{incident-id}/status Returns the underlying incident's investigation status with surrounding threat… #
POST /v2/incident/{incident-id}/status Update an incident status #
GET /v2/incident/{incident-id}/event-filters Returns the available filter params for this incident's events #
GET /v2/incident/{incident-id}/verdicts Returns a list of events linked to this incident #
GET /v2/incident/{incident-id}/graph Returns a graph representation of this incident #
GET /v2/incident/{incident-id}/linked-casebooks Return Linked Casebooks #
GET /v2/incident/{incident-id}/linked-incidents Returns linked incidents #
GET /v2/incident/{incident-id}/primary-investigation Returns linked investigations #
GET /v2/incident/{incident-id}/errors Returns a list of errors reported by the attached investigations #
GET /v2/incident/{incident-id}/overview Returns baseline incident information #
GET /v2/incident/{incident-id}/recommend Recommend actions for an incident #
GET /v2/incident/{incident-id}/export Get a full summary of the incident, everything seen in XDR #
POST /v2/incident/{incident-id}/import Import Incident and all its surrounding threat context from CTIA #
GET /v2/sighting/{sighting-id}/findings Get the findings for a sighting ID #
GET /v2/report/incident-status-by-assignment Incident counts by status and assignment bucket #
GET /v2/report/mitre-attack-incidents Non-closed incident counts by MITRE tactic and technique #
GET /v2/report/top-seen-techniques Top seen techniques across incidents #
GET /v2/report/detection-sources-histogram Daily incident counts per detection source #
GET /v2/report/top-targeted-devices Top targeted devices across incidents #
GET /v2/report/top-targeted-users Top targeted users across incidents #
GET /v2/report/top-targeted-assets Top targeted assets across incidents #
GET /v2/report/team-mean-time-to-engage Team mean time to engage over the period #
GET /v2/report/user-mean-time-to-engage Requesting user's mean time to engage over the period #
GET /v2/report/team-mean-time-to-contain Team mean time to contain over the period #
GET /v2/report/user-mean-time-to-contain User mean time to contain over the period #
GET /v2/report/team-mean-time-to-resolve Team mean time to resolve over the period #
GET /v2/report/user-mean-time-to-resolve Requesting user's mean time to resolve over the period #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-xdr-v2-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-xdr-v2-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Conure V2 API
  version: conure-218-1-ee422dee
  license:
    name: All Rights Reserved
    url: https://www.cisco.com
  contact:
    name: Cisco Security Business Group -- Advanced Threat
    email: cisco-intel-api-support@cisco.com
  description: XDR High Priority Incident and Investigation API
  x-provenance:
    method: harvested
    authored_by: Cisco XDR
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: visibility.amp.cisco.com
    note: Anonymously fetchable Swagger 2.0 for nine IROH services plus the CTIA threat-intelligence API. The host returns real 404s on invented paths, so the 200s are genuine.
  x-evidence:
  - type: source
    url: https://visibility.amp.cisco.com/iroh/iroh-int/swagger.json
  - type: source
    url: https://private.intel.amp.cisco.com/swagger.json
tags:


# --- truncated at 32 KB (13955 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/openapi/cisco-xdr-v2-api-openapi.yml