How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Cisco XDR Bulk API

The Bulk API from Cisco XDR — 1 operation(s) for bulk.

Cisco XDR Bulk API is one of 83 APIs that Cisco XDR publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Bulk, Security, XDR, and Threat Detection. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 5 operations across 1 path, and defines 232 schemas. It is described by OpenAPI 3.2.0, at version 4178275a824512c2fd3a2acdb0e8277233919054 v2.71.0.

Requests are made against a single base URL, /.

5 operations 1 paths 232 schemas 1 DELETE1 GET1 PATCH1 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
4178275a824512c2fd3a2acdb0e8277233919054 v2.71.0
Base URL
https://private.intel.amp.cisco.com
Authentication
API Key, OAuth 2.0
License
All Rights Reserved
Resource Areas
1

Authentication & Security 2

Cisco XDR Bulk API declares 2 security schemes for authenticating requests. An API key is passed in the header as Authorization (JWT). It supports OAuth 2.0 (oauth2) using the authorizationCode flow, exposing 6 scopes. By default, every request must be authenticated.

  • JWT — Ex: Bearer \

Paths & Operations 5

Across 1 path, the API surfaces 5 operations — 1 DELETE, 1 GET, 1 PATCH, 1 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Bulk 5
POST
/ctia/bulk
POST many new entities using a single HTTP call
1 param body → 201
PUT
/ctia/bulk
UPDATE many entities at once
1 param body → 200
GET
/ctia/bulk
GET many entities at once
23 params → 200
PATCH
/ctia/bulk
PATCH many entities at once
1 param body → 200
DELETE
/ctia/bulk
DELETE many entities at once
1 param body → 200

Schemas 232

The contract defines 232 schemas that model the data the API accepts and returns. The most detailed are Bundle (59 properties), NewIncident (37 properties), NewSighting (37 properties), Body116661Incidents (37 properties). Each schema is shown below with its type and property counts.

Response116966
object
19 properties
Technology
object
2 properties
ValidTime
object
Period of time when a cyber observation is valid.
2 properties
ExternalReference
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
BulkErrors
object
3 properties
Response116945TargetRecordsError
object
4 properties 2 required
NewNote
object
a new Note
22 properties 3 required
RegistryRenameType
object
8 properties 6 required
Identity
object
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties
HTTPType
object
12 properties 6 required
Body116663AttackPatternsError
object
4 properties 2 required
Weakness
object
A mistake or condition that, if left unaddressed, could under the proper conditions contribute to a cyber-enabled capability being vulnerable to attack, allowi…
31 properties
Body116663AssetMappings
object
4 properties
NewCOA
object
a new Coa
31 properties
Response116945Investigations
object
4 properties
ModeOfIntroduction
object
2 properties
ColumnDefinition
object
5 properties 2 required
OpenC2COA
object
6 properties 2 required
RegistrySetType
object
10 properties 6 required
Body116650IncidentsScores
object
5 properties
Body116650Campaigns
object
Schema for submitting new Campaigns
28 properties 5 required
NewActor
object
a new Actor
30 properties 4 required
Body116663NotesError
object
4 properties 2 required
Body116663Malwares
object
4 properties
RelatedIdentity
object
Describes a related Identity
4 properties
Campaign
object
Represents a campaign by an [actor](actor.md) pursing an intent.
21 properties
Verdict
object
A Verdict is chosen from all of the Judgements on that Observable which have not yet expired. The highest priority Judgement becomes the active verdict. If the…
6 properties
Response116945Judgements
object
4 properties
AssetMapping
object
A record that maps a specific Observable to an asset for a specified period of time.
18 properties
Response116945RelationshipsError
object
4 properties 2 required
NewAttackPattern
object
a new Attack-pattern
26 properties 3 required
Response116945AttackPatterns
object
4 properties
Response116945NotesError
object
4 properties 2 required
CVE
object
1 property 1 required
Response116945AttackPatternsError
object
4 properties 2 required
Body116663Investigations
object
4 properties
Response116945SightingsError
object
4 properties 2 required
VulnerabilityImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
Response116945Notes
object
4 properties
Activity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
2 properties 2 required
Incident
object
Information about computer security incident response. A computer security incident is a violation or imminent threat of violation of computer security policie…
30 properties
Response116945IndicatorsError
object
4 properties 2 required
FileMoveType
object
10 properties 8 required
Judgement
object
A judgement about the intent or nature of an observable. For example, is it malicious, meaning is is malware and subverts system operations? It could also be c…
20 properties
DataTable
object
A generic table of data, consisting of types and documented columns, and 1 or more rows of data.
18 properties
Body116650Investigations
object
Schema for submitting new Investigations
25 properties 2 required
Body116650Judgements
object
Schema for submitting new Judgements.
27 properties 6 required
Body116663
object
a new Bulk Delete object
19 properties
NewAsset
object
a new Asset
23 properties 3 required
Asset
object
Describes a protected resource. It could be a Device, User, Network, Application or Data.
16 properties
Body116663Indicators
object
4 properties
Response116945AssetPropertiesError
object
4 properties 2 required
OperatingSystem
object
5 properties
Body116663CoasError
object
4 properties 2 required
NewInvestigation
object
a new Investigation
25 properties 1 required
NewTool
object
a new Tool
25 properties 4 required
Response116945AssetMappingsError
object
4 properties 2 required
Body116650Malwares
object
For submitting a new Malware.
25 properties 5 required
Actor
object
Describes malicious actors or adversaries related to a cyber attack.
23 properties
Body116650Notes
object
Schema for submitting Notes
22 properties 4 required
Body116650InvestigationsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
Body116639
object
a new Bulk object
19 properties
Response116945Vulnerabilities
object
4 properties
SensorCoordinates
object
Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
3 properties 2 required
Body116663Coas
object
4 properties
LibraryLoadType
object
8 properties 6 required
Body116663Casebooks
object
4 properties
NewSighting
object
a new Sighting
37 properties 1 required
Response116945Coas
object
4 properties
Assertion
object
2 properties
Body116650AssetMappings
object
Schema for submitting new AssetMapping.
25 properties 9 required
Body116650Indicators
object
For submitting a new Indicator
33 properties 2 required
IncidentScores
object
Used to indicate the severity or impact score of the threat represented by the incident.
Body116663AssetsError
object
4 properties 2 required
Indicator
object
An indicator is a test, or a collection of judgements that define criteria for identifying the activity, or presence of malware, or other unwanted software. We…
26 properties
Response116945ToolsError
object
4 properties 2 required
TempIDs
object
Response116945Campaigns
object
4 properties
NewVulnerability
object
a new Vulnerability
26 properties 1 required
ModifierType
object
13 properties
NewCampaign
object
a new Campaign
28 properties 4 required
Relationship
object
Represents a relationship between two entities.
17 properties
NewTargetRecord
object
a new Target-record
22 properties 2 required
InvestigationTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
IdentityAssertion
object
Context attributes about the target or any of its observables. Providers could provide different types of assertions regarding a target depending on their own…
14 properties
Context
object
Context including the event type that best fits the type of the sighting.
12 properties
Body116663Relationships
object
4 properties
AdditionalProperties
object
1 property 1 required
Body116663Actors
object
4 properties
Mitigation
object
5 properties
Language
object
3 properties
CPELeafNode
object
3 properties 2 required
InvestigationExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
Body116650Vulnerabilities
object
For submitting a new vulnerability.
26 properties 2 required
NewAssetProperties
object
a new Asset-properties
21 properties 3 required
Body116650Assets
object
Schema for submitting new Assets
23 properties 4 required
CVSSv3
object
31 properties 3 required
FileDeleteType
object
9 properties 6 required
Consequence
object
4 properties
Body116663ToolsError
object
4 properties 2 required
NewCasebook
object
an updated Casebook
24 properties
Response116945IncidentsError
object
4 properties 2 required
Response116945AssetProperties
object
4 properties
Response116945Malwares
object
4 properties
BulkActions
object
3 properties
Sighting
object
A sighting indicates that a particular entity or [indicator](indicator.md) was observed in an environment and can be an indication of a current or potential th…
30 properties
Body116663Assets
object
4 properties
Response116945AssetMappings
object
4 properties
NewIncidentScores
object
5 properties
Target
object
Schema for TargetRecord Targets
7 properties 3 required
ProcessCreateType
object
19 properties 4 required
Body116661IncidentsScores
object
5 properties
Body116663Incidents
object
4 properties
AssetProperties
object
Assets do not have any product specific properties, those are represented in AssetProperties - which is a record that asserts one or more properties of an Asse…
14 properties
Body116663AssetMappingsError
object
4 properties 2 required
Response116945ActorsError
object
4 properties 2 required
NewInvestigationTargets
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required
COA
object
Course of Action. A corrective or preventative action to be taken in response to a threat.
24 properties
ActuatorType
object
2 properties 1 required
NewMalware
object
a new Malware
25 properties 4 required
Body116650Actors
object
Schema for submitting new Actors
30 properties 5 required
Response116945Actors
object
4 properties
Body116663AssetPropertiesError
object
4 properties 2 required
Body116650Casebooks
object
Allows to gather and group observables and related analyst notes in one place from across multiple products for easy retrieval and further actions. Through Cas…
24 properties 1 required
Response116945AssetsError
object
4 properties 2 required
Bundle
object
Describes a Bundle of any set of CTIM entities.
59 properties
Body116650Tools
object
For submitting a new Tool.
25 properties 5 required
CVSSv2
object
25 properties 3 required
Body116650TargetRecords
object
Schema for submitting new TargetRecord.
22 properties 3 required
Malware
object
Malware is a type of TTP that is also known as malicious code and malicious software, and refers to a program that is inserted into a system, usually covertly,…
18 properties
Body116650Coas
object
Schema for submitting new COAs
31 properties 1 required
Body116663IncidentsError
object
4 properties 2 required
Body116663AttackPatterns
object
4 properties
Body116650InvestigationsTargets
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required
NewIncident
object
a new Incident
37 properties 3 required
Body116650AttackPatterns
object
For submitting a new AttackPattern
26 properties 4 required
MetaData
object
metadata associated to the incident.
Response116945Relationships
object
4 properties
CPEMatch
object
6 properties 2 required
Body116663RelationshipsError
object
4 properties 2 required
Body116663SightingsError
object
4 properties 2 required
Response116980
object
19 properties
IncidentTime
object
Relevant time values associated with this Incident.
7 properties 1 required
TargetRecord
object
A TargetRecord is a Sighting that has no threat or observables associated with it, it's a way of saying they saw a set of observables together as a Target.
15 properties
InvestigationTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
Body116650InvestigationsTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
Note
object
A Note is intended to convey informative text to provide further context and/or to provide additional analysis not contained in the Objects, assigning Text/con…
15 properties
IdentityCoordinates
object
Attributes for which the assertion is being made.
1 property
Response116945Casebooks
object
4 properties
Body116663Judgements
object
4 properties
Response116945Sightings
object
4 properties
Body116663Notes
object
4 properties
FileCreateType
object
9 properties 6 required
Body116650InvestigationsTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
AttackPattern
object
Attack Patterns are a type of TTP that describe ways that adversaries attempt to compromise targets.
19 properties
Body116650Incidents
object
For submitting a new Incident.
37 properties 4 required
NoteRelatedEntity
object
2 properties 2 required
Body116663Tools
object
4 properties
RelatedCOA
object
4 properties 1 required
Response116945InvestigationsError
object
4 properties 2 required
Architecture
object
3 properties
Response116945CoasError
object
4 properties 2 required
AlternateTerm
object
2 properties
CompositeIndicatorExpression
object
2 properties 2 required
NewSightingRelationsRelationInfo
object
Body116663CasebooksError
object
4 properties 2 required
RegistryCreateType
object
7 properties 5 required
NewInvestigationTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
Response116945VulnerabilitiesError
object
4 properties 2 required
Body116663Campaigns
object
4 properties
Body116650AssetProperties
object
Schema for submitting new AssetProperties
21 properties 4 required
Response116945Assets
object
4 properties
Configurations
object
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
2 properties 2 required
DetectionMethod
object
4 properties
Response116945CasebooksError
object
4 properties 2 required
Body116661
object
a new Bulk Patch object
2 properties
Paradigm
object
2 properties
Body116661Notes
object
A Note is intended to convey informative text to provide further context and/or to provide additional analysis not contained in the Objects, assigning Text/con…
22 properties 1 required
Response116979
object
19 properties
NewInvestigationExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
Tool
object
Tools are legitimate software that can be used by threat actors to perform attacks. Knowing how and when threat actors use such tools can be important for unde…
18 properties
Body116650Relationships
object
Schema for submitting new Relationships.
24 properties 4 required
Body116663Sightings
object
4 properties
Body116663TargetRecords
object
4 properties
Body116663IndicatorsError
object
4 properties 2 required
NetflowType
object
22 properties 5 required
Body116663CampaignsError
object
4 properties 2 required
Response116945
object
20 properties
Response116967
object
19 properties
NewIndicator
object
a new Indicator
33 properties 1 required
Investigation
object
Schema for an Investigation (a work in progress)
25 properties 3 required
Body116663MalwaresError
object
4 properties 2 required
Body116663TargetRecordsError
object
4 properties 2 required
Response116945JudgementsError
object
4 properties 2 required
RegistryDeleteType
object
8 properties 5 required
NewAssetMapping
object
a new Asset-mapping
25 properties 8 required
Body116663JudgementsError
object
4 properties 2 required
Feedback
object
Feedback on any entity. Is it wrong? If so why? Was it right-on, and worthy of confirmation?
14 properties
ActionType
object
1 property 1 required
Casebook
object
Allows to gather and group observables and related analyst notes in one place from across multiple products for easy retrieval and further actions. Through Cas…
24 properties 2 required
Body116663VulnerabilitiesError
object
4 properties 2 required
Vulnerability
object
Indicates weakness or flaw in the system that can be exploited by an attacker to gain unauthorized access or cause harm to the system. Vulnerabilities can exis…
19 properties
Response116945Indicators
object
4 properties
CPENode
object
4 properties 1 required
Response116945CampaignsError
object
4 properties 2 required
Body116663ActorsError
object
4 properties 2 required
TargetType
object
2 properties 1 required
CVEDataMeta
object
2 properties
NewJudgement
object
a new Judgement
27 properties 5 required
Traffic
object
9 properties 6 required
NewInvestigationTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
ObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewRelationship
object
a new Relationship
24 properties 3 required
FileModifyType
object
9 properties 6 required
Body116650
object
a Bulk Update object
19 properties
AssetProperty
object
2 properties 2 required
Response116945MalwaresError
object
4 properties 2 required
Body116650Sightings
object
For submitting a new Sighting.
37 properties 2 required
Body116663AssetProperties
object
4 properties
Response116945TargetRecords
object
4 properties
Response116945Tools
object
4 properties
Text
object
2 properties
InvestigationTargets
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required
SightingDataTable
object
An embedded data table for the Sighting.
3 properties 2 required
KillChainPhase
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
Observable
object
An AssetMapping is a record that a specific Observable maps to an Asset for an indicated period of time.
2 properties 2 required
Body116663InvestigationsError
object
4 properties 2 required
ObservedRelation
object
A relation inside a Sighting.
6 properties 4 required
Body116661Incidents
object
37 properties 1 required
Response116945Incidents
object
4 properties
IdentitySpecification
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required
Body116663Vulnerabilities
object
4 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

cisco-xdr-bulk-api-openapi.yml Raw ↑

Other APIs Cisco XDR publishes across the network.

Cisco XDR Actor API
Cisco XDR Asset API
Cisco XDR Asset Mapping API
Cisco XDR Asset Properties API
Cisco XDR Attack Pattern API
Cisco XDR Bundle API
Cisco XDR Campaign API
Cisco XDR Casebook API
Cisco XDR COA API
Cisco XDR Deliberate API
Cisco XDR Event API
Cisco XDR Feed API
Where this information came from

This is an independent, third-party profile of Cisco XDR Bulk API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.