Cisco XDR V2 API
The v2 API from Cisco XDR — 75 operation(s) for v2.
Operations 85
GET
/v2/investigation/{investigation-id}/indicators
Returns a list of indicators attached to this investigation
#
GET
/v2/investigation/{investigation-id}/observables
Returns a list of observables attached to this investigation
#
GET
/v2/investigation/{investigation-id}/targets
Returns a list of targets attached to this investigation
#
POST
/v2/investigation/{investigation-id}/observable/remove
Remove observables from an investigation
#
DELETE
/v2/investigation/{investigation-id}/delete
Delete investigation by investigation id delete
#
POST
/v2/incident/{incident-id}/link/{entity-type}/{entity-id}
Link incident and entity (investigation | casebook | incident)
#
DELETE
/v2/incident/{incident-id}/link/{entity-type}/{entity-id}
Unlink incident and entity. (investigation | casebook | incident)
#
POST
/v2/incident/{incident-id}/update-context
Process an incident update by invalidating the cache and finding reputations as…
#
GET
/v2/incident/{incident-id}/summary
Full Incident Summary. Equivalent Data to v1 summary endpoints
#
GET
/v2/incident/{incident-id}/mitre
Mitre tactics, techniques, and subtechniques found in an incident
#
GET
/v2/incident/{incident-id}/status
Returns the underlying incident's investigation status with surrounding threat…
#
GET
/v2/incident/{incident-id}/event-filters
Returns the available filter params for this incident's events
#
GET
/v2/incident/{incident-id}/errors
Returns a list of errors reported by the attached investigations
#
POST
/v2/incident/{incident-id}/import
Import Incident and all its surrounding threat context from CTIA
#