Cisco XDR V3 API

The v3 API from Cisco XDR — 10 operation(s) for v3.

Business capability
Threat Detection & Response Management BC-620.30

Operations 12

GET /v3/incident/filters incident search filter values
POST /v3/incident/search Search incidents
GET /v3/incident/{incident-id}/events Incident Events
GET /v3/incident/{incident-id}/storyboard XDR 2.0 Output for Incidents
POST /v3/incident/{incident-id}/storyboard/feedback Submit storyboard feedback for an incident
GET /v3/incident/{incident-id}/graph Graph Endpoint from entities.
POST /v3/incident/{incident-id}/graph Graph Endpoint from entities.
GET /v3/incident/{incident-id}/entity/{entity-id} Get the attributes of an entity
GET /v3/investigation/{investigation-id}/events Events endpoint from compacted entities.
GET /v3/investigation/{investigation-id}/graph Graph Endpoint from entities.
POST /v3/investigation/{investigation-id}/graph Graph Endpoint from entities.
GET /v3/investigation/{investigation-id}/entity/{entity-id} Get the attributes of an entity

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-xdr-v3-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-xdr-v3-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Conure V3 API
  version: conure-218-1-ee422dee
  license:
    name: All Rights Reserved
    url: https://www.cisco.com
  contact:
    name: Cisco Security Business Group -- Advanced Threat
    email: cisco-intel-api-support@cisco.com
  description: XDR High Priority Incident and Investigation API
  x-provenance:
    method: harvested
    authored_by: Cisco XDR
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: visibility.amp.cisco.com
    note: Anonymously fetchable Swagger 2.0 for nine IROH services plus the CTIA threat-intelligence API. The host returns real 404s on invented paths, so the 200s are genuine.
  x-evidence:
  - type: source
    url: https://visibility.amp.cisco.com/iroh/iroh-int/swagger.json
  - type: source
    url: https://private.intel.amp.cisco.com/swagger.json
tags:
- name: v3
paths:
  /v3/incident/filters:
    get:
      responses:
        '405':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
        default:
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
        '429':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
        '401':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
        '500':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  detection_sources:
                    type: array
                    items:
                      type: string
                  tactics:
                    type: array
                    items:
                      type: string
                  techniques:
                    type: array
                    items:
                      type: string
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  detection_sources:
                    type: array
                    items:
                      type: string
                  tactics:
                    type: array
                    items:
                      type: string
                  techniques:
                    type: array
                    items:
                      type: string
            application/transit+json:
              schema:
                type: object
                properties:
                  detection_sources:
                    type: array
                    items:
                      type: string
                  tactics:
                    type: array
                    items:
                      type: string
                  techniques:
                    type: array
                    items:
                      type: string
            application/edn:
              schema:
                type: object
                properties:
                  detection_sources:
                    type: array
                    items:
                      type: string
                  tactics:
                    type: array
                    items:
                      type: string
                  techniques:
                    type: array
                    items:
                      type: string
        '404':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Found
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Found
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Found
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Found
                required:
                - message
        '400':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message: {}
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message: {}
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message: {}
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message: {}
                required:
                - message
        '403':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Forbidden
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Forbidden
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Forbidden
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Forbidden
                required:
                - message
        '406':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Acceptable
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Acceptable
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Acceptable
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Not Acceptable
                required:
                - message
      tags:
      - v3
      summary: incident search filter values
      security:
      - JWT-Bearer: []
      - oauth2: []
  /v3/incident/search:
    post:
      responses:
        '405':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Method Not Allowed
                required:
                - message
        default:
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - unspecified status
                required:
                - message
        '429':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Too many requests
                required:
                - message
        '401':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - Unauthorized
                required:
                - message
        '500':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
            application/transit+msgpack:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
            application/transit+json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
            application/edn:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    enum:
                    - exception
                    - default exception
                    - sql exception
                    - JSON too large
                    - schema
                    - external_request
                  exception:
                    type: string
                    example: SqlException
                  data:
                    example:
                      example: Bad Request
                    description: Any specific error information passed by custom errors.
                  uri:
                    type: string
                    example: /global/v1/incident/?/incident-summary
                    description: The URI the error was seen at
                required:
                - message
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
                  properties:
                    assignees:
                      type: array
                      items:
                        type: string
                    categories:
                      type: array
                      items:
                        type: string
                        enum:
                        - Attrition
                        - Denial of Service
                        - Exercise
                        - Exercise/Network Defense Testing
                        - Explained Anomaly
                        - Forensics
                        - Improper Usage
                        - Intelligence
                        - Investigating
                        - Investigation
                        - Malicious Code
                        - Malicious Logic
                        - Non-Compliant
                        - Reconnaissance
                        - Root Level
                        - Scans/Probes/Attempted Access
                        - Unauthorized Access
                        - Unsuccessful
                        - User Level
                        - eDiscovery
                    confidence:
                      type: string
                      enum:
                      - High
                      - Info
                      - Low
                      - Medium
                      - None
                      - Unknown
                    detection_sources:
                      type: array
                      items:
                        type: string
                    detection_status:
                      title: DetectionStatusType
                      type: string
                      enum:
                      - active
                      - inactive_merged
                      - inactive_expired
                      - inactive_oversized
                      - inactive_user_closed
                      description: Whether the incident is actively receiving detection data updates
                    discovery_method:
                      type: string
                      enum:
                      - SecureX Threat Hunting
                      - Agent Disclosure
                      - Antivirus
                      - Audit
                      - Customer
                      - External - Fraud Detection
                      - Financial Audit
                      - HIPS
                      - IT Audit
                      - Incident Response
                      - Internal - Fraud Detection
                      - Law Enforcement
                      - Log Review
                      - Monitoring Service
                      - NIDS
                      - Security Alarm
                      - Unknown
                      - Unrelated Party
                      - User
                    incident_time:
                      type: object
                      properties:
                        opened:
                          type: string
                        closed:
                          type: string
                        discovered:
                          type: string
                        rejected:
                          type: string
                        remediated:
                          type: string
                        reported:
                          type: string
                      required:
                      - opened
                    intended_effect:
                      type: string
                      enum:
                      - Account Takeover
                      - Advantage
                      - Advantage - Economic
                      - Advantage - Military
                      - Advantage - Political
                      - Brand Damage
                      - Competitive Advantage
                      - Degradation of Service
                      - Denial and Deception
                      - Destruction
                      - Disruption
                      - Embarrassment
                      - Exposure
                      - Extortion
                      - Fraud
                      - Harassment
                      - ICS Control
                      - Theft
                      - Theft - Credential Theft
                      - Theft - Identity Theft
                      - Theft - Intellectual Property
                      - Theft - Theft of Proprietary Information
                      - Traffic Diversion
                      - Unauthorized Access
                    last_activity:
                      type:
                      - string
                      - 'null'
                      x-anyOf:
                      - type: string
                      - type: string
                        format: date-time
                    meta:
                      type: object
                      properties:
                        ai_description:
                          type: boolean
                        helios_report_generated:
                          type: boolean
                    promotion_method:
                      type: string
                      enum:
                      - Automated
                      - Manual
                    scores:
                      type: object
                      properties:
                        asset:
                          type: integer
                          format: int64
                          minimum: 0
                          maximum: 10
                        global:
                          type: integer
                          format: int64
                          minimum: 0
                          maximum: 1000
                        ml_score:
                          type: number
                          format: double
                        ttp:
                          type: integer
                          format: int64
                          minimum: 0
                          maximum: 100
                    severity:
                      type: string
                      enum:
                      - Critical
                      - High
                      - Info
                      - Low
                      - Medium
                      - None
                      - Unknown
                    short_id:
                      type:
                      - string
                      - 'null'
                    status:
                      title: IncidentStatusType
                      type: string
                      enum:
                      - New
                      - Closed
                      - 'Open: Recovered'
                      - 'Closed: Other'
                      - 'Hold: Internal'
                      - 'Hold: Legal'
                      - 'Closed: Under Review'
                      - Rejected
                      - Open
                      - 'Closed: Merged'
                      - Restoration Achieved
                      - Incident Reported
                      - 'Closed: Suspected'
                      - Stalled
                      - 'Open: Contained'
                      - 'Closed: Near-Miss'
                      - 'Hold: External'
                      - Containment Achieved
                      - 'New: Processing'
                      - 'Closed: Confirmed Threat'
                      - 'Closed: False Positive'
                      - 'Open: Reported'
                      - 'Open: Investigating'
                      - 

# --- truncated at 32 KB (1350 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/openapi/cisco-xdr-v3-api-openapi.yml