Demisto Evidence API
The Evidence API from Demisto — 3 operation(s) for evidence.
The Evidence API from Demisto — 3 operation(s) for evidence.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/demisto-evidence-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: This is the public REST API to integrate with the demisto server.
title: Demisto Evidence API
version: 2.0.0
servers:
- url: https://hostname:443
security:
- api_key: []
- csrf_token: []
- x-xdr-auth-id: []
tags:
- name: Evidence
paths:
/evidence:
post:
description: 'Save an evidence entity
To update evidence custom fields you should lowercase them and remove all spaces. For example: Scan IP -> scanip'
summary: Save evidence
operationId: saveEvidence
responses:
'200':
description: The new / updated Evidence
content:
application/json:
schema:
$ref: '#/components/schemas/Evidence'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Evidence'
application/xml:
schema:
$ref: '#/components/schemas/Evidence'
tags:
- Evidence
/evidence/delete:
post:
description: Delete an evidence entity
summary: delete evidence
operationId: deleteEvidenceOp
responses:
'200':
description: Deleted evidence ID
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/deleteEvidence'
application/xml:
schema:
$ref: '#/components/schemas/deleteEvidence'
tags:
- Evidence
/evidence/search:
post:
description: Search for an evidence entutiy by filter
summary: Search evidence
operationId: searchEvidence
responses:
'200':
description: EvidencesSearchResponse
content:
application/json:
schema:
$ref: '#/components/schemas/EvidencesSearchResponse'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/evidencesFilterWrapper'
application/xml:
schema:
$ref: '#/components/schemas/evidencesFilterWrapper'
tags:
- Evidence
components:
schemas:
Period:
type: object
title: Period holds the 'Period' query, such as last 3 days, last 6 hours, between 6 days from now until 3 days from now.
properties:
by:
description: By is used for legacty, and if exists it will override ByTo and ByFrom
type: string
x-go-name: By
byFrom:
type: string
x-go-name: ByFrom
byTo:
type: string
x-go-name: ByTo
field:
type: string
x-go-name: Field
fromValue:
type: string
format: duration
x-go-name: FromValue
toValue:
type: string
format: duration
x-go-name: ToValue
x-go-package: github.com/demisto/server/domain
Evidence:
type: object
title: Evidence details.
properties:
ShardID:
type: integer
format: int64
description:
description: The description for the resolve
type: string
x-go-name: Description
entryId:
description: The entry ID
type: string
x-go-name: EntryID
fetched:
description: when the evidence entry was fetched
type: string
format: date-time
x-go-name: Fetched
hasRole:
description: Internal field to make queries on role faster
type: boolean
x-go-name: HasRole
id:
type: string
x-go-name: ID
incidentId:
description: The incident ID
type: string
x-go-name: IncidentID
markedBy:
description: the user that marked this evidence
type: string
x-go-name: MarkedBy
markedDate:
description: when this evidence was marked
type: string
format: date-time
x-go-name: MarkedDate
modified:
type: string
format: date-time
x-go-name: Modified
occurred:
description: When this evidence has occurred
type: string
format: date-time
x-go-name: Occurred
previousRoles:
description: PreviousRoleName - do not change this field manually
type: array
items:
type: string
x-go-name: PreviousRoleName
roles:
description: The role assigned to this investigation
type: array
items:
type: string
x-go-name: RoleName
sortValues:
type: array
items:
type: string
x-go-name: SortValues
tags:
description: Tags
type: array
items:
type: string
x-go-name: Tags
tagsRaw:
description: TagsRaw
type: array
items:
type: string
x-go-name: TagsRaw
taskId:
description: when the evidence entry was fetched
type: string
x-go-name: TaskID
version:
type: integer
format: int64
x-go-name: Versn
additionalProperties:
type: object
x-go-package: github.com/demisto/server/domain
evidencesFilterWrapper:
type: object
properties:
filter:
$ref: '#/components/schemas/GenericStringDateFilter'
incidentID:
type: string
x-go-name: IncidentID
x-go-package: github.com/demisto/server/web
deleteEvidence:
type: object
properties:
evidenceID:
type: string
x-go-name: EvidenceID
x-go-package: github.com/demisto/server/web
Duration:
description: 'A Duration represents the elapsed time between two instants
as an int64 nanosecond count. The representation limits the
largest representable duration to approximately 290 years.'
type: integer
format: int64
x-go-package: time
Evidences:
description: Evidences is a list of evidence entities
type: array
items:
$ref: '#/components/schemas/Evidence'
x-go-package: github.com/demisto/server/domain
Order:
description: Order struct holds a sort field and the direction of sorting
type: object
properties:
asc:
type: boolean
x-go-name: Asc
field:
type: string
x-go-name: Field
fieldType:
type: string
x-go-name: FieldType
x-go-package: github.com/demisto/server/domain
EvidencesSearchResponse:
description: EvidencesSearchResponse returns the response from the evidences search
type: object
properties:
evidences:
$ref: '#/components/schemas/Evidences'
total:
type: integer
format: int64
x-go-name: Total
x-go-package: github.com/demisto/server/repo/entities
GenericStringDateFilter:
description: GenericStringDateFilter is a general filter that will fetch entities using the Query value and a date filter
type: object
properties:
Cache:
description: Cache of join functions
type: object
additionalProperties:
type: array
items:
type: string
fromDate:
type: string
format: date-time
x-go-name: FromDate
fromDateLicense:
type: string
format: date-time
x-go-name: FromDateLicenseVal
page:
description: 0-based page
type: integer
format: int64
x-go-name: Page
period:
$ref: '#/components/schemas/Period'
query:
type: string
x-go-name: Query
searchAfter:
description: Efficient next page, pass max sort value from previous page
type: array
items:
type: string
x-go-name: SearchAfter
searchBefore:
description: Efficient prev page, pass min sort value from next page
type: array
items:
type: string
x-go-name: SearchBefore
size:
description: Size is limited to 1000, if not passed it defaults to 0, and no results will return
type: integer
format: int64
x-go-name: Size
sort:
description: The sort order
type: array
items:
$ref: '#/components/schemas/Order'
x-go-name: Sort
timeFrame:
$ref: '#/components/schemas/Duration'
toDate:
type: string
format: date-time
x-go-name: ToDate
x-go-package: github.com/demisto/server/repo/entities
securitySchemes:
api_key:
type: apiKey
name: Authorization
in: header
csrf_token:
type: apiKey
name: X-XSRF-TOKEN
in: header
x-xdr-auth-id:
type: apiKey
name: x-xdr-auth-id
in: header