Cisco XDR
Cisco XDR is Cisco's extended detection and response platform, the successor to SecureX. It correlates telemetry from Cisco Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email and third-party sources into incidents, and exposes four distinct REST API families behind a single OAuth 2.0 authorization server: the IROH platform (inspect, enrich, response actions, integration modules, events, webhooks) at visibility.amp.cisco.com, the CTIA private-intelligence store at private.intel.amp.cisco.com, the Conure v2 incidents and investigations service at conure.us.security.cisco.com, and the Automation workflow engine at automate.us.security.cisco.com. All four publish anonymously fetchable machine-readable contracts — 52 documents, 581 operations, 1,176 schema definitions — and Cisco additionally ships a 27-tool MCP server through CiscoDevNet, stdio-only. There is no sandbox, no test mode and no idempotency key anywhere, including on the operation that blocks, isolates and quarantines.
Cisco XDR publishes 49 APIs on the APIs.io network, including Actor API, Asset API, Asset Mapping API, and 46 more. Tagged areas include Security, XDR, Threat Detection, Incident Response, and SOC.
The Cisco XDR catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Cisco XDR’s developer surface includes authentication, developer portal, documentation, API reference, changelog, getting-started guide, support, and 41 more developer resources.
Kin Score
APIs 50
Individual APIs this provider publishes, each with its own machine-readable definition.
Cisco XDR Actor API
Actor operations
Cisco XDR Asset API
Asset operations
Cisco XDR Asset Mapping API
Asset Mapping operations
Cisco XDR Asset Properties API
Asset Properties operations
Cisco XDR Attack Pattern API
Attack Pattern operations
Cisco XDR Bulk API
The Bulk API from Cisco XDR — 1 operation(s) for bulk.
Cisco XDR Bundle API
The Bundle API from Cisco XDR — 2 operation(s) for bundle.
Cisco XDR Campaign API
Campaign operations
Cisco XDR Casebook API
Casebook operations
Cisco XDR COA API
COA operations
Cisco XDR Deliberate API
This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something...
Cisco XDR Event API
Events operations
Cisco XDR Feed API
Feed operations
Cisco XDR Feedback API
Feedback Routes
Cisco XDR Graph QL API
The GraphQL API from Cisco XDR — 1 operation(s) for graphql.
Cisco XDR Health API
This set of routes allow to check the health of your integrations setup Verify if your modules are setup correctly and if your credentials are correct.
Cisco XDR Incident API
Incident operations
Cisco XDR Indicator API
Indicator operations
Cisco XDR Inspect API
Inspect related routes
Cisco XDR Investigation API
The Investigation API from Cisco XDR — 8 operation(s) for investigation.
Cisco XDR INVITE API
The INVITE API from Cisco XDR — 2 operation(s) for invite.
Cisco XDR Iroh API
The Iroh API from Cisco XDR — 3 operation(s) for iroh.
Cisco XDR Judgement API
Judgement operations
Cisco XDR LOGIN API
The LOGIN API from Cisco XDR — 4 operation(s) for login.
Cisco XDR Malware API
Malware operations
Cisco XDR Metrics API
The Metrics API from Cisco XDR — 1 operation(s) for metrics.
Cisco XDR Module Instance API
ModuleInstance Routes
Cisco XDR Module Type API
ModuleType Routes
Cisco XDR Module Type Patch API
ModuleTypePatch Routes
Cisco XDR Note API
The Note API from Cisco XDR — 8 operation(s) for note.
Cisco XDR Observe API
This set of routes allow to get in depth investigation data about a threat You might use them at the start of any investigation to get the full picture and get to know if someth...
Cisco XDR One Click API
One-click Routes
Cisco XDR Private Intel API
Access private-intel
Cisco XDR Properties API
The Properties API from Cisco XDR — 1 operation(s) for properties.
Cisco XDR Query API
This set of routes allow to query for records related to observable events.Results are returned in OCSF format.
Cisco XDR Refer API
This set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a specific product interface.
Cisco XDR Relationship API
Relationship operations
Cisco XDR Reputation API
The Reputation API from Cisco XDR — 1 operation(s) for reputation.
Cisco XDR Response API
IROH Response
Cisco XDR Session Cookie API
Cookie-based session validation
Cisco XDR Sighting API
Sighting operations
Cisco XDR Status API
The Status API from Cisco XDR — 1 operation(s) for status.
Cisco XDR Target Record API
Target Record operations
Cisco XDR Tool API
Tool operations
Cisco XDR Verdict API
The Verdict API from Cisco XDR — 1 operation(s) for verdict.
Cisco XDR Version API
The Version API from Cisco XDR — 1 operation(s) for version.
Cisco XDR Vulnerability API
The Vulnerability API from Cisco XDR — 9 operation(s) for vulnerability.
Cisco XDR Webhook API
Webhook Routes
Cisco XDR Webhook Result API
The WebhookResult API from Cisco XDR — 2 operation(s) for webhookresult.
Cisco XDR MCP Server
Model Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investigate, Incidents, Response Actions, Casebooks, Threat Intel, Workflows a...
Scroll for all 50
MCP Servers 2
Model Context Protocol servers that expose these APIs to AI agents.
Cisco XDR MCP Server
MCP SERVERCisco XDR MCP Server
MCP SERVERPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Cisco Xdr Rate Limits
RATE LIMITSEvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Cisco Xdr Webhooks
ASYNCAPISecurity Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Resources
Get Started 5
Portal, sign-up, and the first successful call
Documentation 4
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 8
Authentication, authorization, and security posture
Scroll for all 8
Operate 6
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 5
Properties that don't map to a standard resource type