How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Cisco XDR Bundle API

The Bundle API from Cisco XDR — 2 operation(s) for bundle.

Cisco XDR Bundle API is one of 83 APIs that Cisco XDR publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Bundle, Security, XDR, and Threat Detection. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 3 operations across 2 paths, and defines 226 schemas. It is described by OpenAPI 3.2.0, at version 4178275a824512c2fd3a2acdb0e8277233919054 v2.71.0.

Requests are made against a single base URL, /.

3 operations 2 paths 226 schemas 1 GET2 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
4178275a824512c2fd3a2acdb0e8277233919054 v2.71.0
Base URL
https://private.intel.amp.cisco.com
Authentication
API Key, OAuth 2.0
License
All Rights Reserved
Resource Areas
1

Authentication & Security 2

Cisco XDR Bundle API declares 2 security schemes for authenticating requests. An API key is passed in the header as Authorization (JWT). It supports OAuth 2.0 (oauth2) using the authorizationCode flow, exposing 6 scopes. By default, every request must be authenticated.

  • JWT — Ex: Bearer \

Paths & Operations 3

Across 2 paths, the API surfaces 3 operations — 1 GET, 2 POST. Each is listed below with its method, path, parameters, and response codes.

Bundle 3
GET
/ctia/bundle/export
Export records with their local relationships. Ids are URIs (with port if specified).
5 params → 200
POST
/ctia/bundle/export
Export records with their local relationships. Ids are URIs (with port if specified).
4 params body → 200
POST
/ctia/bundle/import
POST many new entities using a single HTTP call
1 param body → 200

Schemas 226

The contract defines 226 schemas that model the data the API accepts and returns. The most detailed are NewBundleExport (66 properties), Body116683 (58 properties), NewSighting (37 properties), NewIncident (37 properties). Each schema is shown below with its type and property counts.

NewBundleExportAssetPropertiesProperties
object
2 properties 2 required
NewBundleExportNotesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
ValidTime
object
Period of time when a cyber observation is valid.
2 properties
ExternalReference
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportSightingsContextNetflowEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportAssetPropertiesValidTime
object
The time range during which the AssetProperties is considered valid.
2 properties
NewNote
object
a new Note
22 properties 3 required
NewBundleExportSightingsSensorCoordinates
object
Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
3 properties 2 required
RegistryRenameType
object
8 properties 6 required
NewBundleExportDataTablesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportIdentityAssertions
object
For submitting a new IdentityAssertion.
14 properties 2 required
NewBundleExportCampaignsActivity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
2 properties 2 required
NewBundleExportSightingsContextNetflowEvents
object
22 properties 5 required
HTTPType
object
12 properties 6 required
Identity
object
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties
NewBundleExportIdentityAssertionsValidTime
object
Period of time when a cyber observation is valid.
2 properties
NewBundleExportJudgementsObservable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewCOA
object
a new Coa
31 properties
NewBundleExportSightingsActivityInterval
object
The time interval during which the malicious activity occurred. For example, the time when a malware sample was executing, or the time range of a network intru…
2 properties 1 required
NewBundleExportIncidentsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportSightingsSensorCoordinatesObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewBundleExportIncidentsIncidentTime
object
Relevant time values associated with this Incident.
7 properties 1 required
ColumnDefinition
object
5 properties 2 required
OpenC2COA
object
6 properties 2 required
RegistrySetType
object
10 properties 6 required
NewActor
object
a new Actor
30 properties 4 required
NewBundleExportSightingsTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewBundleExportSightingsContextRegistryCreateEvents
object
7 properties 5 required
RelatedIdentity
object
Describes a related Identity
4 properties
Verdict
object
A Verdict is chosen from all of the Judgements on that Observable which have not yet expired. The highest priority Judgement becomes the active verdict. If the…
6 properties
NewBundleExportSightingsContextHttpEvents
object
12 properties 6 required
NewBundleExportWeaknessesParadigms
object
2 properties 1 required
NewAttackPattern
object
a new Attack-pattern
26 properties 3 required
NewBundleExportWeaknessesModesOfIntroduction
object
2 properties 1 required
CVE
object
1 property 1 required
NewBundleExportSightingsContextRegistryRenameEvents
object
8 properties 6 required
VulnerabilityImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
NewBundleExportCoasOpenC2CoaModifiersTime
object
Period of time when a cyber observation is valid.
2 properties
Activity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
2 properties 2 required
NewBundleExportIdentityAssertionsIdentityObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
FileMoveType
object
10 properties 8 required
BundleImportResult
object
1 property 1 required
NewBundleExportIncidents
object
For submitting a new Incident.
30 properties 3 required
NewBundleExportSightingsContextFileDeleteEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportSightingsRelationsSource
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewBundleExportSightingsDetectionInterval
object
The time interval during which the malicious activity was detected by the source engine or security tool. This may differ from the activityinterval if detectio…
2 properties 1 required
NewAsset
object
a new Asset
23 properties 3 required
NewBundleExportActorsValidTime
object
Period of time when a cyber observation is valid.
2 properties
NewBundleExportSightingsContextFileDeleteEvents
object
9 properties 6 required
NewTool
object
a new Tool
25 properties 4 required
NewBundleExportSightingsContextRegistryDeleteEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportIndicatorsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
SensorCoordinates
object
Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
3 properties 2 required
NewBundleExportSightingsRelationsRelated
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewBundleExportSightingsContextFileCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewSighting
object
a new Sighting
37 properties 1 required
LibraryLoadType
object
8 properties 6 required
NewBundleExportCampaigns
object
Schema for submitting new Campaigns
21 properties 4 required
NewBundleExportIdentityAssertionsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
IncidentScores
object
Used to indicate the severity or impact score of the threat represented by the incident.
NewBundleExportAttackPatternsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportIndicatorsSpecificationRequiredJudgements
object
4 properties 1 required
NewBundleExportIndicatorsSpecification
object
An indicator based on a list of judgements. If any of the Observables in it's judgements are encountered, than it may be matches against. If there are any requ…
3 properties 3 required
NewVulnerability
object
a new Vulnerability
26 properties 1 required
ModifierType
object
13 properties
NewCampaign
object
a new Campaign
28 properties 4 required
NewBundleExportDataTablesColumns
object
5 properties 2 required
NewBundleExportSightingsContextFileMoveEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportJudgementsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportSightingsContextRegistryRenameEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewTargetRecord
object
a new Target-record
22 properties 2 required
NewBundleExportCoasExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportIdentityAssertionsAssertions
object
2 properties 2 required
Context
object
Context including the event type that best fits the type of the sighting.
12 properties
AdditionalProperties
object
1 property 1 required
NewAssetProperties
object
a new Asset-properties
21 properties 3 required
CPELeafNode
object
3 properties 2 required
NewBundleExportVulnerabilities
object
For submitting a new vulnerability.
19 properties 1 required
NewBundleExportAssetMappingsObservable
object
An AssetMapping is a record that a specific Observable maps to an Asset for an indicated period of time.
2 properties 2 required
CVSSv3
object
31 properties 3 required
NewBundleExportWeaknessesTechnologies
object
2 properties 1 required
NewBundleExportTargetRecordsTargets
object
Schema for TargetRecord Targets
7 properties 3 required
NewBundleExportVulnerabilitiesImpactCvssV3
object
31 properties 3 required
NewBundleExportFeedbacks
object
Schema for submitting new Feedback.
14 properties 3 required
FileDeleteType
object
9 properties 6 required
NewBundleExportSightingsContextFileMoveEvents
object
10 properties 8 required
NewBundleExportMalwaresKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
NewBundleExportTargetRecordsTargetsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewBundleExportAssetPropertiesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportVulnerabilitiesConfigurationsNodes
object
4 properties 1 required
NewBundleExportCoasValidTime
object
Period of time when a cyber observation is valid.
2 properties
NewBundleExportIndicators
object
For submitting a new Indicator
26 properties 1 required
NewBundleExportWeaknessesAlternateTerms
object
2 properties 1 required
NewBundleExportSightingsRelations
object
A relation inside a Sighting.
6 properties 4 required
NewBundleExportVerdictsObservable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewBundleExportExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewIncidentScores
object
5 properties
Target
object
Schema for TargetRecord Targets
7 properties 3 required
ProcessCreateType
object
19 properties 4 required
NewBundleExportAssetsValidTime
object
Specifies the time range during which the asset is considered valid or accurate. For example, if an asset entity represents a device, the validtime field could…
2 properties
NewBundleExportWeaknessesOperatingSystems
object
5 properties 1 required
NewBundleExportNotes
object
Schema for submitting Notes
15 properties 3 required
NewBundleExportCoasOpenC2CoaActuator
object
2 properties 1 required
NewBundleExportWeaknessesLanguages
object
3 properties 1 required
ActuatorType
object
2 properties 1 required
NewBundleExportCoasOpenC2Coa
object
6 properties 2 required
NewMalware
object
a new Malware
25 properties 4 required
NewBundleExportCampaignsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportSightingsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportVulnerabilitiesConfigurationsNodesCpeMatch
object
6 properties 2 required
Body116683
object
Describes a Bundle of any set of CTIM entities.
58 properties 1 required
NewBundleExportIndicatorsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportMalwaresExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportSightingsContextLibraryLoadEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportCoasRelatedCoAs
object
4 properties 1 required
NewBundleExportActors
object
Schema for submitting new Actors
23 properties 4 required
CVSSv2
object
25 properties 3 required
NewBundleExportSightingsDataColumns
object
5 properties 2 required
NewBundleExportIndicatorsValidTime
object
Period of time when a cyber observation is valid.
2 properties
NewBundleExportVulnerabilitiesImpactCvssV2
object
25 properties 3 required
NewBundleExportCoasOpenC2CoaModifiersAdditionalProperties
object
1 property 1 required
NewBundleExportSightingsRelationsRelationInfo
object
NewBundleExportAssetProperties
object
Schema for submitting new AssetProperties
14 properties 3 required
NewBundleExportActorsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportAttackPatternsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
NewIncident
object
a new Incident
37 properties 3 required
NewBundleExportSightingsContextFileModifyEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExport
object
Describes a Bundle of any set of CTIM entities.
66 properties 1 required
MetaData
object
metadata associated to the incident.
NewBundleExportTargetRecordsTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportVerdictsValidTime
object
Period of time when a cyber observation is valid.
2 properties
NewBundleExportSightingsContextRegistryDeleteEvents
object
8 properties 5 required
CPEMatch
object
6 properties 2 required
NewBundleExportWeaknessesNotes
object
2 properties 2 required
NewBundleExportActorsIdentity
object
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties 2 required
NewBundleExportCoas
object
Schema for submitting new COAs
24 properties
NewBundleExportSightingsContextRegistrySetEvents
object
10 properties 6 required
IncidentTime
object
Relevant time values associated with this Incident.
7 properties 1 required
NewBundleExportWeaknessesCommonConsequences
object
4 properties 1 required
NewBundleExportSightings
object
For submitting a new Sighting.
30 properties 1 required
NewBundleExportTargetRecordsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportToolsKillChainPhases
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
FileCreateType
object
9 properties 6 required
NewBundleExportSightingsContextProcessCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportCoasOpenC2CoaTarget
object
2 properties 1 required
NoteRelatedEntity
object
2 properties 2 required
RelatedCOA
object
4 properties 1 required
NewBundleExportSightingsContextProcessCreateEvents
object
19 properties 4 required
NewBundleExportSightingsModificationInterval
object
The time interval during which the sighting record was created or last updated in the system.
2 properties 1 required
NewBundleExportDataTables
object
Schema for submitting a NewDataTable record.
18 properties 2 required
NewBundleExportSightingsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportCoasOpenC2CoaModifiers
object
13 properties
CompositeIndicatorExpression
object
2 properties 2 required
NewSightingRelationsRelationInfo
object
EntityImportResult
object
7 properties
RegistryCreateType
object
7 properties 5 required
NewBundleExportWeaknessesDetectionMethods
object
4 properties 2 required
NewBundleExportCampaignsValidTime
object
Period of time when a cyber observation is valid.
2 properties
Configurations
object
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
2 properties 2 required
NewBundleExportAssetMappings
object
Schema for submitting new AssetMapping.
18 properties 8 required
BundleExportIds
object
1 property 1 required
NewBundleExportSightingsContextLibraryLoadEvents
object
8 properties 6 required
NewBundleExportSightingsContextFileCreateEvents
object
9 properties 6 required
NewBundleExportTools
object
For submitting a new Tool.
18 properties 4 required
NetflowType
object
22 properties 5 required
NewBundleExportToolsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportJudgements
object
Schema for submitting new Judgements.
20 properties 5 required
NewBundleExportSightingsTargetsObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportVulnerabilitiesImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
NewBundleExportValidTime
object
Period of time when a cyber observation is valid.
2 properties
NewIndicator
object
a new Indicator
33 properties 1 required
NewBundleExportSightingsContextFileModifyEvents
object
9 properties 6 required
NewBundleExportWeaknessesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportSightingsContextNetflowEventsTraffic
object
9 properties 6 required
NewBundleExportActorsIdentityRelatedIdentities
object
Describes a related Identity
4 properties 1 required
NewBundleExportDataTablesValidTime
object
Period of time when a cyber observation is valid.
2 properties
RegistryDeleteType
object
8 properties 5 required
NewAssetMapping
object
a new Asset-mapping
25 properties 8 required
NewBundleExportNotesRelatedEntities
object
2 properties 2 required
NewBundleExportVulnerabilitiesConfigurations
object
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
2 properties 2 required
NewBundleExportWeaknessesPotentialMitigations
object
5 properties 1 required
NewBundleExportSightingsContextRegistryCreateEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
ActionType
object
1 property 1 required
NewBundleExportRelationshipsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportSightingsContextHttpEventsTraffic
object
9 properties 6 required
NewBundleExportSightingsData
object
An embedded data table for the Sighting.
3 properties 2 required
NewBundleExportJudgementsValidTime
object
Period of time when a cyber observation is valid.
2 properties
NewBundleExportAttackPatterns
object
For submitting a new AttackPattern
19 properties 3 required
NewBundleExportAssets
object
Schema for submitting new Assets
16 properties 3 required
NewBundleExportAssetMappingsValidTime
object
For each asset, we allow for the assertion of time bound properties.This gives us both a record of the current state of the asset,as well as history.
2 properties
NewBundleExportSightingsContextHttpEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
CPENode
object
4 properties 1 required
NewBundleExportVulnerabilitiesConfigurationsNodesChildrenCpeMatch
object
6 properties 2 required
NewRelationship
object
a new Relationship
24 properties 3 required
TargetType
object
2 properties 1 required
CVEDataMeta
object
2 properties
Traffic
object
9 properties 6 required
NewJudgement
object
a new Judgement
27 properties 5 required
ObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
NewBundleExportTargetRecords
object
Schema for submitting new TargetRecord.
15 properties 2 required
FileModifyType
object
9 properties 6 required
NewBundleExportWeaknesses
object
For submitting a new weakness.
31 properties 1 required
NewBundleExportSightingsTargets
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required
NewBundleExportIndicatorsCompositeIndicatorExpression
object
2 properties 2 required
AssetProperty
object
2 properties 2 required
NewBundleExportSightingsObservables
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
NewBundleExportVulnerabilitiesConfigurationsNodesChildren
object
3 properties 2 required
NewBundleExportRelationships
object
Schema for submitting new Relationships.
17 properties 3 required
NewBundleExportAssetMappingsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportVerdicts
object
A Verdict is chosen from all of the Judgements on that Observable which have not yet expired. The highest priority Judgement becomes the active verdict. If the…
6 properties 4 required
NewBundleExportSightingsContext
object
Context including the event type that best fits the type of the sighting.
12 properties
NewBundleExportCoasOpenC2CoaAction
object
1 property 1 required
NewBundleExportVulnerabilitiesCve
object
1 property 1 required
SightingDataTable
object
An embedded data table for the Sighting.
3 properties 2 required
NewBundleExportAssetsExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
KillChainPhase
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
NewBundleExportSightingsContextRegistrySetEventsTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
Observable
object
An AssetMapping is a record that a specific Observable maps to an Asset for an indicated period of time.
2 properties 2 required
NewBundleExportVulnerabilitiesExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
NewBundleExportVulnerabilitiesCveCveDataMeta
object
2 properties
NewBundleExportWeaknessesArchitectures
object
3 properties 1 required
NewBundleExportFeedbacksExternalReferences
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
ObservedRelation
object
A relation inside a Sighting.
6 properties 4 required
NewBundleExportIdentityAssertionsIdentity
object
Attributes for which the assertion is being made.
1 property 1 required
IdentitySpecification
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required
NewBundleExportMalwares
object
For submitting a new Malware.
18 properties 4 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

cisco-xdr-bundle-api-openapi.yml Raw ↑

Other APIs Cisco XDR publishes across the network.

Cisco XDR Actor API
Cisco XDR Asset API
Cisco XDR Asset Mapping API
Cisco XDR Asset Properties API
Cisco XDR Attack Pattern API
Cisco XDR Bulk API
Cisco XDR Campaign API
Cisco XDR Casebook API
Cisco XDR COA API
Cisco XDR Deliberate API
Cisco XDR Event API
Cisco XDR Feed API
Where this information came from

This is an independent, third-party profile of Cisco XDR Bundle API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.