Cisco XDR website screenshot

Cisco XDR

Cisco XDR is Cisco's extended detection and response platform, the successor to SecureX. It correlates telemetry from Cisco Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email and third-party sources into incidents, and exposes four distinct REST API families behind a single OAuth 2.0 authorization server: the IROH platform (inspect, enrich, response actions, integration modules, events, webhooks) at visibility.amp.cisco.com, the CTIA private-intelligence store at private.intel.amp.cisco.com, the Conure v2 incidents and investigations service at conure.us.security.cisco.com, and the Automation workflow engine at automate.us.security.cisco.com. All four publish anonymously fetchable machine-readable contracts — 52 documents, 581 operations, 1,176 schema definitions — and Cisco additionally ships a 27-tool MCP server through CiscoDevNet, stdio-only. There is no sandbox, no test mode and no idempotency key anywhere, including on the operation that blocks, isolates and quarantines.

Cisco XDR publishes 82 APIs on the APIs.io network, including Actor API, Asset API, Asset Mapping API, and 79 more. Tagged areas include Security, XDR, Threat Detection, Incident Response, and SOC.

The Cisco XDR catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Cisco XDR’s developer surface includes authentication, developer portal, documentation, API reference, changelog, getting-started guide, support, and 42 more developer resources.

62.9/100 strong ▬ flat Agent 39/100 agent ready saas Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessSelf serve
12 APIs 2 MCP Servers
SecurityXDRThreat DetectionIncident ResponseSOCThreat IntelligenceExtended Detection and ResponseAuthenticationWebhookAutomationMCP

What this lets a business do 2

Business capabilities this provider's published APIs can perform, derived from its own contracts. Browse all capabilities →

Cybersecurity Management
BC-620
ActorAsset PropertiesAttack PatternCOACampaignCasebook
POST /iroh/iroh-inspect/inspect
SaaS Tenant Management
BC-4230
Tenants
POST /v2/tenants

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/cisco-xdr: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 83

Individual APIs this provider publishes, each with its own machine-readable definition.

Cisco XDR Actor API

Actor operations

Cisco XDR Asset API

Asset operations

Cisco XDR Asset Mapping API

Asset Mapping operations

Cisco XDR Asset Properties API

Asset Properties operations

Cisco XDR Attack Pattern API

Attack Pattern operations

Cisco XDR Bulk API

The Bulk API from Cisco XDR — 1 operation(s) for bulk.

Cisco XDR Bundle API

The Bundle API from Cisco XDR — 2 operation(s) for bundle.

Cisco XDR Campaign API

Campaign operations

Cisco XDR Casebook API

Casebook operations

Cisco XDR COA API

COA operations

Cisco XDR Deliberate API

This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something...

Cisco XDR Event API

Events operations

Cisco XDR Feed API

Feed operations

Cisco XDR Feedback API

Feedback Routes

Cisco XDR Graph QL API

The GraphQL API from Cisco XDR — 1 operation(s) for graphql.

Cisco XDR Health API

This set of routes allow to check the health of your integrations setup Verify if your modules are setup correctly and if your credentials are correct.

Cisco XDR Incident API

Incident operations

Cisco XDR Indicator API

Indicator operations

Cisco XDR Inspect API

Inspect related routes

Cisco XDR Investigation API

The Investigation API from Cisco XDR — 8 operation(s) for investigation.

Cisco XDR INVITE API

The INVITE API from Cisco XDR — 2 operation(s) for invite.

Cisco XDR Iroh API

The Iroh API from Cisco XDR — 3 operation(s) for iroh.

Cisco XDR Judgement API

Judgement operations

Cisco XDR LOGIN API

The LOGIN API from Cisco XDR — 4 operation(s) for login.

Cisco XDR Malware API

Malware operations

Cisco XDR Metrics API

The Metrics API from Cisco XDR — 1 operation(s) for metrics.

Cisco XDR Module Instance API

ModuleInstance Routes

Cisco XDR Module Type API

ModuleType Routes

Cisco XDR Module Type Patch API

ModuleTypePatch Routes

Cisco XDR Note API

The Note API from Cisco XDR — 8 operation(s) for note.

Cisco XDR Observe API

This set of routes allow to get in depth investigation data about a threat You might use them at the start of any investigation to get the full picture and get to know if someth...

Cisco XDR One Click API

One-click Routes

Cisco XDR Private Intel API

Access private-intel

Cisco XDR Properties API

The Properties API from Cisco XDR — 1 operation(s) for properties.

Cisco XDR Query API

This set of routes allow to query for records related to observable events.Results are returned in OCSF format.

Cisco XDR Refer API

This set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a specific product interface.

Cisco XDR Relationship API

Relationship operations

Cisco XDR Reputation API

The Reputation API from Cisco XDR — 1 operation(s) for reputation.

Cisco XDR Response API

IROH Response

Cisco XDR Session Cookie API

Cookie-based session validation

Cisco XDR Sighting API

Sighting operations

Cisco XDR Status API

The Status API from Cisco XDR — 1 operation(s) for status.

Cisco XDR Target Record API

Target Record operations

Cisco XDR Tool API

Tool operations

Cisco XDR Verdict API

The Verdict API from Cisco XDR — 1 operation(s) for verdict.

Cisco XDR Version API

The Version API from Cisco XDR — 1 operation(s) for version.

Cisco XDR Vulnerability API

The Vulnerability API from Cisco XDR — 9 operation(s) for vulnerability.

Cisco XDR Webhook API

Webhook Routes

Cisco XDR Webhook Result API

The WebhookResult API from Cisco XDR — 2 operation(s) for webhookresult.

Cisco XDR MCP Server

Model Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investigate, Incidents, Response Actions, Casebooks, Threat Intel, Workflows a...

Cisco XDR Calendars API

The Calendars API from Cisco XDR — 3 operation(s) for calendars.

Cisco XDR Categories API

The Categories API from Cisco XDR — 2 operation(s) for categories.

Cisco XDR Change Owner API

The ChangeOwner API from Cisco XDR — 1 operation(s) for changeowner.

Cisco XDR Comments API

The Comments API from Cisco XDR — 2 operation(s) for comments.

Cisco XDR Events API

The Events API from Cisco XDR — 2 operation(s) for events.

Cisco XDR Events Rate Limit API

The EventsRateLimit API from Cisco XDR — 1 operation(s) for eventsratelimit.

Cisco XDR Metadata API

The Metadata API from Cisco XDR — 1 operation(s) for metadata.

Cisco XDR Ratings API

The Ratings API from Cisco XDR — 3 operation(s) for ratings.

Cisco XDR References API

The References API from Cisco XDR — 1 operation(s) for references.

Cisco XDR Remote Meta API

The RemoteMeta API from Cisco XDR — 3 operation(s) for remotemeta.

Cisco XDR Rules API

The Rules API from Cisco XDR — 4 operation(s) for rules.

Cisco XDR Runtime Users API

The RuntimeUsers API from Cisco XDR — 2 operation(s) for runtimeusers.

Cisco XDR Schedules API

The Schedules API from Cisco XDR — 2 operation(s) for schedules.

Cisco XDR Schemas API

The Schemas API from Cisco XDR — 2 operation(s) for schemas.

Cisco XDR Share Object Permissions API

The ShareObjectPermissions API from Cisco XDR — 1 operation(s) for shareobjectpermissions.

Cisco XDR SXIROH Incident API

The SXIROHIncident API from Cisco XDR — 1 operation(s) for sxirohincident.

Cisco XDR Tables API

The Tables API from Cisco XDR — 2 operation(s) for tables.

Cisco XDR Table Types API

The TableTypes API from Cisco XDR — 2 operation(s) for tabletypes.

Cisco XDR Target Groups API

The TargetGroups API from Cisco XDR — 2 operation(s) for targetgroups.

Cisco XDR Targets API

The Targets API from Cisco XDR — 3 operation(s) for targets.

Cisco XDR Tasks API

The Tasks API from Cisco XDR — 5 operation(s) for tasks.

Cisco XDR Tenants API

The Tenants API from Cisco XDR — 3 operation(s) for tenants.

Cisco XDR Triggers API

The Triggers API from Cisco XDR — 2 operation(s) for triggers.

Cisco XDR V1 API

The v1 API from Cisco XDR — 4 operation(s) for v1.

Cisco XDR V2 API

The v2 API from Cisco XDR — 75 operation(s) for v2.

Cisco XDR V3 API

The v3 API from Cisco XDR — 10 operation(s) for v3.

Cisco XDR Variables API

The Variables API from Cisco XDR — 3 operation(s) for variables.

Cisco XDR Variable Types API

The VariableTypes API from Cisco XDR — 3 operation(s) for variabletypes.

Cisco XDR Webhooks API

The Webhooks API from Cisco XDR — 3 operation(s) for webhooks.

Cisco XDR Workflow Instances API

The WorkflowInstances API from Cisco XDR — 7 operation(s) for workflowinstances.

Cisco XDR Workflows API

The Workflows API from Cisco XDR — 20 operation(s) for workflows.

Cisco XDR Workflow Variable References API

The WorkflowVariableReferences API from Cisco XDR — 1 operation(s) for workflowvariablereferences.

Cisco XDR Xchange API

The Xchange API from Cisco XDR — 4 operation(s) for xchange.

Scroll for all 83

MCP Servers 2

Model Context Protocol servers that expose these APIs to AI agents.

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Cisco Xdr Rate Limits

5 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Cisco Xdr Authentication

apiKey/oauth2 · 4 schemes

SECURITY

Cisco Xdr Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Cisco Xdr Vulnerability Disclosure

security.txt · contact published

SECURITY

Cisco Xdr Trust Center

ISO 27001, FedRAMP, GDPR, SOC 2, BSI C5

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Cisco Xdr Scopes

41 scopes · authorizationCode/clientCredentials

41 scopes

SCOPES

Resources

Get Started 5

Portal, sign-up, and the first successful call

Documentation 4

Reference material describing how the API behaves

Agent Surfaces 5

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 8

Authentication, authorization, and security posture

Scroll for all 8

Operate 6

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 6

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: cisco-xdr
name: Cisco XDR
description: 'Cisco XDR is Cisco''s extended detection and response platform, the successor to SecureX. It correlates telemetry
  from Cisco Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email and third-party sources into incidents, and exposes
  four distinct REST API families behind a single OAuth 2.0 authorization server: the IROH platform (inspect, enrich, response
  actions, integration modules, events, webhooks) at visibility.amp.cisco.com, the CTIA private-intelligence store at private.intel.amp.cisco.com,
  the Conure v2 incidents and investigations service at conure.us.security.cisco.com, and the Automation workflow engine at
  automate.us.security.cisco.com. All four publish anonymously fetchable machine-readable contracts — 52 documents, 581 operations,
  1,176 schema definitions — and Cisco additionally ships a 27-tool MCP server through CiscoDevNet, stdio-only. There is no
  sandbox, no test mode and no idempotency key anywhere, including on the operation that blocks, isolates and quarantines.'
url: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/apis.yml
type: Index
access: 3rd-Party
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: true
  label: Hosted service · you call their endpoint
  confidence: high
  source:
  - openapi
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  - scopes
  - rate-limits
  - security
  - sandbox
  generated: '2026-09-02'
  method: derived
position: Consuming
x-type: company
x-source: cisco-family-buildout:2026-08-19
x-parent: cisco
x-relationship: product
x-contract-status: real
x-contract-note: Anonymously fetchable Swagger 2.0 for nine IROH services at visibility.amp.cisco.com plus the CTIA threat-intelligence
  API — 581 operations. The host returns real 404s on invented paths, so the 200s are genuine.
specificationVersion: '0.23'
created: '2026-08-19'
modified: '2026-08-19'
tags:
- Security
- XDR
- Threat Detection
- Incident Response
- SOC
- Threat Intelligence
- Extended Detection and Response
- Authentication
- Webhook
- Automation
- MCP
tags_raw:
- Security
- XDR
- Threat Detection
- Incident Response
- SOC
- Threat Intelligence
- Extended Detection and Response
- OAuth
- Webhooks
- Automation
- MCP
apis:
- aid: cisco-xdr:cisco-xdr-actor-api
  name: Cisco XDR Actor API
  description: Actor operations
  tags:
  - Actor
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-actor-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-asset-api
  name: Cisco XDR Asset API
  description: Asset operations
  tags:
  - Asset
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-asset-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-asset-mapping-api
  name: Cisco XDR Asset Mapping API
  description: Asset Mapping operations
  tags:
  - Asset Mapping
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-asset-mapping-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-asset-properties-api
  name: Cisco XDR Asset Properties API
  description: Asset Properties operations
  tags:
  - Asset Properties
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-asset-properties-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-attack-pattern-api
  name: Cisco XDR Attack Pattern API
  description: Attack Pattern operations
  tags:
  - Attack Pattern
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-attack-pattern-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-bulk-api
  name: Cisco XDR Bulk API
  description: The Bulk API from Cisco XDR — 1 operation(s) for bulk.
  tags:
  - Bulk
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-bulk-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-bundle-api
  name: Cisco XDR Bundle API
  description: The Bundle API from Cisco XDR — 2 operation(s) for bundle.
  tags:
  - Bundle
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-bundle-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-campaign-api
  name: Cisco XDR Campaign API
  description: Campaign operations
  tags:
  - Campaign
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-campaign-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-casebook-api
  name: Cisco XDR Casebook API
  description: Casebook operations
  tags:
  - Casebook
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-casebook-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-coa-api
  name: Cisco XDR COA API
  description: COA operations
  tags:
  - coa
  - Security
  - XDR
  - Threat Detection
  tags_raw:
  - COA
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-coa-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-deliberate-api
  name: Cisco XDR Deliberate API
  description: This set of routes allow to quickly get answers from your integrations You might use them at the start of any
    investigation to quickly get answers from your modules if something is bad.
  tags:
  - Deliberate
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-deliberate-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/enrich-api-guide/
- aid: cisco-xdr:cisco-xdr-event-api
  name: Cisco XDR Event API
  description: Events operations
  tags:
  - Event
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-event-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-feed-api
  name: Cisco XDR Feed API
  description: Feed operations
  tags:
  - Feed
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-feed-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-feedback-api
  name: Cisco XDR Feedback API
  description: Feedback Routes
  tags:
  - Feedback
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-feedback-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-graphql-api
  name: Cisco XDR Graph QL API
  description: The GraphQL API from Cisco XDR — 1 operation(s) for graphql.
  tags:
  - GraphQL
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-graphql-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-health-api
  name: Cisco XDR Health API
  description: This set of routes allow to check the health of your integrations setup Verify if your modules are setup correctly
    and if your credentials are correct.
  tags:
  - Health
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-health-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/enrich-api-guide/
- aid: cisco-xdr:cisco-xdr-incident-api
  name: Cisco XDR Incident API
  description: Incident operations
  tags:
  - Incident
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-incident-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/incident-management-api-guide/
- aid: cisco-xdr:cisco-xdr-indicator-api
  name: Cisco XDR Indicator API
  description: Indicator operations
  tags:
  - Indicator
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-indicator-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-inspect-api
  name: Cisco XDR Inspect API
  description: Inspect related routes
  tags:
  - Inspect
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-inspect-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/inspect-api-guide/
- aid: cisco-xdr:cisco-xdr-investigation-api
  name: Cisco XDR Investigation API
  description: The Investigation API from Cisco XDR — 8 operation(s) for investigation.
  tags:
  - Investigation
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-investigation-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-invite-api
  name: Cisco XDR INVITE API
  description: The INVITE API from Cisco XDR — 2 operation(s) for invite.
  tags:
  - invite
  - Security
  - XDR
  - Threat Detection
  tags_raw:
  - INVITE
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-invite-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-iroh-api
  name: Cisco XDR Iroh API
  description: The Iroh API from Cisco XDR — 3 operation(s) for iroh.
  tags:
  - Iroh
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-iroh-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-judgement-api
  name: Cisco XDR Judgement API
  description: Judgement operations
  tags:
  - Judgement
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-judgement-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-login-api
  name: Cisco XDR LOGIN API
  description: The LOGIN API from Cisco XDR — 4 operation(s) for login.
  tags:
  - Login
  - Security
  - XDR
  - Threat Detection
  tags_raw:
  - LOGIN
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-login-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-malware-api
  name: Cisco XDR Malware API
  description: Malware operations
  tags:
  - Malware
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-malware-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-metrics-api
  name: Cisco XDR Metrics API
  description: The Metrics API from Cisco XDR — 1 operation(s) for metrics.
  tags:
  - Metrics
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-metrics-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-moduleinstance-api
  name: Cisco XDR Module Instance API
  description: ModuleInstance Routes
  tags:
  - ModuleInstance
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-moduleinstance-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-moduletype-api
  name: Cisco XDR Module Type API
  description: ModuleType Routes
  tags:
  - ModuleType
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-moduletype-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-moduletypepatch-api
  name: Cisco XDR Module Type Patch API
  description: ModuleTypePatch Routes
  tags:
  - ModuleTypePatch
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-moduletypepatch-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-note-api
  name: Cisco XDR Note API
  description: The Note API from Cisco XDR — 8 operation(s) for note.
  tags:
  - Note
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-note-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-observe-api
  name: Cisco XDR Observe API
  description: This set of routes allow to get in depth investigation data about a threat You might use them at the start
    of any investigation to get the full picture and get to know if something has been seen in your environment.
  tags:
  - Observe
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-observe-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/enrich-api-guide/
- aid: cisco-xdr:cisco-xdr-one-click-api
  name: Cisco XDR One Click API
  description: One-click Routes
  tags:
  - One-Click
  - Security
  - XDR
  - Threat Detection
  tags_raw:
  - One-click
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-one-click-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-private-intel-api
  name: Cisco XDR Private Intel API
  description: Access private-intel
  tags:
  - Private Intel
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-private-intel-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/incident-management-api-guide/
- aid: cisco-xdr:cisco-xdr-properties-api
  name: Cisco XDR Properties API
  description: The Properties API from Cisco XDR — 1 operation(s) for properties.
  tags:
  - Properties
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-properties-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-query-api
  name: Cisco XDR Query API
  description: This set of routes allow to query for records related to observable events.Results are returned in OCSF format.
  tags:
  - Query
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-query-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/enrich-api-guide/
- aid: cisco-xdr:cisco-xdr-refer-api
  name: Cisco XDR Refer API
  description: This set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a
    specific product interface.
  tags:
  - Refer
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-refer-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/enrich-api-guide/
- aid: cisco-xdr:cisco-xdr-relationship-api
  name: Cisco XDR Relationship API
  description: Relationship operations
  tags:
  - Relationship
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-relationship-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-reputation-api
  name: Cisco XDR Reputation API
  description: The Reputation API from Cisco XDR — 1 operation(s) for reputation.
  tags:
  - Reputation
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-reputation-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/enrich-api-guide/
- aid: cisco-xdr:cisco-xdr-response-api
  name: Cisco XDR Response API
  description: IROH Response
  tags:
  - Response
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-response-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/response-api-guide/
- aid: cisco-xdr:cisco-xdr-session-cookie-api
  name: Cisco XDR Session Cookie API
  description: Cookie-based session validation
  tags:
  - Session Cookie
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-session-cookie-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-sighting-api
  name: Cisco XDR Sighting API
  description: Sighting operations
  tags:
  - Sighting
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-sighting-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-status-api
  name: Cisco XDR Status API
  description: The Status API from Cisco XDR — 1 operation(s) for status.
  tags:
  - Status
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-status-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-target-record-api
  name: Cisco XDR Target Record API
  description: Target Record operations
  tags:
  - Target Record
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-target-record-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-tool-api
  name: Cisco XDR Tool API
  description: Tool operations
  tags:
  - Tool
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-tool-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-verdict-api
  name: Cisco XDR Verdict API
  description: The Verdict API from Cisco XDR — 1 operation(s) for verdict.
  tags:
  - Verdict
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-verdict-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-version-api
  name: Cisco XDR Version API
  description: The Version API from Cisco XDR — 1 operation(s) for version.
  tags:
  - Version
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-version-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-vulnerability-api
  name: Cisco XDR Vulnerability API
  description: The Vulnerability API from Cisco XDR — 9 operation(s) for vulnerability.
  tags:
  - Vulnerability
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-vulnerability-api-openapi.yml
  baseURL: https://private.intel.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-webhook-api
  name: Cisco XDR Webhook API
  description: Webhook Routes
  tags:
  - Webhook
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-webhook-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-webhookresult-api
  name: Cisco XDR Webhook Result API
  description: The WebhookResult API from Cisco XDR — 2 operation(s) for webhookresult.
  tags:
  - WebhookResult
  - Security
  - XDR
  - Threat Detection
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-webhookresult-api-openapi.yml
  baseURL: https://visibility.amp.cisco.com
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
- aid: cisco-xdr:cisco-xdr-mcp-server
  name: Cisco XDR MCP Server
  description: Model Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investigate,
    Incidents, Response Actions, Casebooks, Threat Intel, Workflows and Admin, plus 5 resources and 6 prompts. Apache-2.0,
    TypeScript, stdio transport only — there is no hosted endpoint and the package is not on npm, so a human must clone and
    build it before any agent can reach Cisco XDR through it.
  humanURL: https://github.com/CiscoDevNet/xdr-mcp-community
  baseURL: https://visibility.amp.cisco.com
  tags:
  - Security
  - XDR
  - MCP
  - Agents
  - Threat Detection
  tags_raw:
  - Security
  - XDR
  - MCP
  - Agent
  - Threat Detection
  properties:
  - type: MCPServer
    url: mcp/cisco-xdr-mcp.yml
  - type: MCPServer
    url: https://github.com/CiscoDevNet/xdr-mcp-community
  - type: ToolCrosswalk
    url: mcp/cisco-xdr-tool-crosswalk.yml
  - type: AgentSkill
    url: skills/_index.yml
  - type: Documentation
    url: https://github.com/CiscoDevNet/xdr-mcp-community/blob/main/INSTALL.md
- aid: cisco-xdr:cisco-xdr-calendars-api
  name: Cisco XDR Calendars API
  description: The Calendars API from Cisco XDR — 3 operation(s) for calendars.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Calendars
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-calendars-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-categories-api
  name: Cisco XDR Categories API
  description: The Categories API from Cisco XDR — 2 operation(s) for categories.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Categories
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-categories-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-changeowner-api
  name: Cisco XDR Change Owner API
  description: The ChangeOwner API from Cisco XDR — 1 operation(s) for changeowner.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - ChangeOwner
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-changeowner-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-comments-api
  name: Cisco XDR Comments API
  description: The Comments API from Cisco XDR — 2 operation(s) for comments.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Comments
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-comments-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-events-api
  name: Cisco XDR Events API
  description: The Events API from Cisco XDR — 2 operation(s) for events.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Event
  tags_raw:
  - Events
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-events-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-eventsratelimit-api
  name: Cisco XDR Events Rate Limit API
  description: The EventsRateLimit API from Cisco XDR — 1 operation(s) for eventsratelimit.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - EventsRateLimit
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-eventsratelimit-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-metadata-api
  name: Cisco XDR Metadata API
  description: The Metadata API from Cisco XDR — 1 operation(s) for metadata.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Metadata
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-metadata-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-ratings-api
  name: Cisco XDR Ratings API
  description: The Ratings API from Cisco XDR — 3 operation(s) for ratings.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Ratings
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-ratings-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-references-api
  name: Cisco XDR References API
  description: The References API from Cisco XDR — 1 operation(s) for references.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - References
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-references-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-remotemeta-api
  name: Cisco XDR Remote Meta API
  description: The RemoteMeta API from Cisco XDR — 3 operation(s) for remotemeta.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - RemoteMeta
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-remotemeta-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-rules-api
  name: Cisco XDR Rules API
  description: The Rules API from Cisco XDR — 4 operation(s) for rules.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Rules
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-rules-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-runtimeusers-api
  name: Cisco XDR Runtime Users API
  description: The RuntimeUsers API from Cisco XDR — 2 operation(s) for runtimeusers.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - RuntimeUsers
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-runtimeusers-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-schedules-api
  name: Cisco XDR Schedules API
  description: The Schedules API from Cisco XDR — 2 operation(s) for schedules.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Schedules
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-schedules-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-schemas-api
  name: Cisco XDR Schemas API
  description: The Schemas API from Cisco XDR — 2 operation(s) for schemas.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Schemas
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-schemas-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-shareobjectpermissions-api
  name: Cisco XDR Share Object Permissions API
  description: The ShareObjectPermissions API from Cisco XDR — 1 operation(s) for shareobjectpermissions.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - ShareObjectPermissions
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-shareobjectpermissions-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-sxirohincident-api
  name: Cisco XDR SXIROH Incident API
  description: The SXIROHIncident API from Cisco XDR — 1 operation(s) for sxirohincident.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - SXIROHIncident
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-sxirohincident-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-tables-api
  name: Cisco XDR Tables API
  description: The Tables API from Cisco XDR — 2 operation(s) for tables.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Tables
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-tables-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-tabletypes-api
  name: Cisco XDR Table Types API
  description: The TableTypes API from Cisco XDR — 2 operation(s) for tabletypes.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - TableTypes
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-tabletypes-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-targetgroups-api
  name: Cisco XDR Target Groups API
  description: The TargetGroups API from Cisco XDR — 2 operation(s) for targetgroups.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Target Groups
  tags_raw:
  - TargetGroups
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-targetgroups-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-targets-api
  name: Cisco XDR Targets API
  description: The Targets API from Cisco XDR — 3 operation(s) for targets.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Targets
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-targets-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-tasks-api
  name: Cisco XDR Tasks API
  description: The Tasks API from Cisco XDR — 5 operation(s) for tasks.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Task
  tags_raw:
  - Tasks
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-tasks-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-tenants-api
  name: Cisco XDR Tenants API
  description: The Tenants API from Cisco XDR — 3 operation(s) for tenants.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Tenants
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-tenants-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-triggers-api
  name: Cisco XDR Triggers API
  description: The Triggers API from Cisco XDR — 2 operation(s) for triggers.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - Triggers
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-triggers-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-v1-api
  name: Cisco XDR V1 API
  description: The v1 API from Cisco XDR — 4 operation(s) for v1.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - v1
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-v1-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-v2-api
  name: Cisco XDR V2 API
  description: The v2 API from Cisco XDR — 75 operation(s) for v2.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - v2
  tags_raw:
  - v2
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-v2-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-v3-api
  name: Cisco XDR V3 API
  description: The v3 API from Cisco XDR — 10 operation(s) for v3.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.intel.amp.cisco.com
  tags:
  - v3
  tags_raw:
  - v3
  properties:
  - type: OpenAPI
    url: openapi/cisco-xdr-v3-api-openapi.yml
- aid: cisco-xdr:cisco-xdr-variables-api
  name: Cisco XDR Variables API
  description: The Variables API from Cisco XDR — 3 operation(s) for variables.
  humanURL: https://developer.cisco.com/docs/cisco-xdr/
  baseURL: https://private.int

# --- truncated at 32 KB (38 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/apis.yml

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/cisco-xdr"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/cisco-xdr/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/cisco-xdr/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.