How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Cisco XDR Casebook API

Casebook operations

Cisco XDR Casebook API is one of 83 APIs that Cisco XDR publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Casebook, Security, XDR, and Threat Detection. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 15 operations across 11 paths, and defines 98 schemas. It is described by OpenAPI 3.2.0, at version 4178275a824512c2fd3a2acdb0e8277233919054 v2.71.0.

Requests are made against a single base URL, /.

15 operations 11 paths 98 schemas 2 DELETE7 GET1 PATCH4 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
4178275a824512c2fd3a2acdb0e8277233919054 v2.71.0
Base URL
https://private.intel.amp.cisco.com
Authentication
API Key, OAuth 2.0
License
All Rights Reserved
Resource Areas
1

Authentication & Security 2

Cisco XDR Casebook API declares 2 security schemes for authenticating requests. An API key is passed in the header as Authorization (JWT). It supports OAuth 2.0 (oauth2) using the authorizationCode flow, exposing 6 scopes. By default, every request must be authenticated.

  • JWT — Ex: Bearer \

Paths & Operations 15

Across 11 paths, the API surfaces 15 operations — 2 DELETE, 7 GET, 1 PATCH, 4 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Casebook 15

Casebook operations

PATCH
/ctia/casebook/{id}
Partially Update a Casebook
2 params body → 200
PUT
/ctia/casebook/{id}
Update an existing Casebook
2 params body → 200
GET
/ctia/casebook/{id}
Get one Casebook by ID
2 params → 200
DELETE
/ctia/casebook/{id}
Delete one Casebook
2 params → 204
POST
/ctia/casebook/{id}/observables
Edit Observables on a casebook
2 params body → 200
POST
/ctia/casebook/{id}/texts
Edit Texts on a casebook
2 params body → 200
POST
/ctia/casebook/{id}/bundle
Edit a Bundle on a casebook
2 params body → 200
POST
/ctia/casebook
Adds a new Casebook
1 param body → 201
GET
/ctia/casebook/external_id/{external_id}
List Casebook by external id
7 params → 200
GET
/ctia/casebook/search
Search for Casebook entities using a ES query syntax and field filters
17 params → 200
DELETE
/ctia/casebook/search
Delete Casebook entities matching given Lucene/ES query string or/and field filters
13 params → 200
GET
/ctia/casebook/search/count
Count Casebook matching a Lucene/ES query string and field filters
11 params → 200
GET
/ctia/casebook/metric/histogram
Histogram for some Casebook field
15 params → 200
GET
/ctia/casebook/metric/topn
Topn for some Casebook field
15 params → 200
GET
/ctia/casebook/metric/cardinality
Cardinality for some Casebook field
12 params → 200

Schemas 98

The contract defines 98 schemas that model the data the API accepts and returns. The most detailed are CasebookBundleUpdateBundle (66 properties), Bundle (59 properties), Weakness (31 properties), CVSSv3 (31 properties). Each schema is shown below with its type and property counts.

Technology
object
2 properties
ValidTime
object
Period of time when a cyber observation is valid.
2 properties
ExternalReference
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
RegistryRenameType
object
8 properties 6 required
Identity
object
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties
HTTPType
object
12 properties 6 required
Weakness
object
A mistake or condition that, if left unaddressed, could under the proper conditions contribute to a cyber-enabled capability being vulnerable to attack, allowi…
31 properties
CasebookBundleUpdateBundle
object
Describes a Bundle of any set of CTIM entities.
66 properties
ModeOfIntroduction
object
2 properties
ColumnDefinition
object
5 properties 2 required
OpenC2COA
object
6 properties 2 required
RegistrySetType
object
10 properties 6 required
RelatedIdentity
object
Describes a related Identity
4 properties
Verdict
object
A Verdict is chosen from all of the Judgements on that Observable which have not yet expired. The highest priority Judgement becomes the active verdict. If the…
6 properties
Campaign
object
Represents a campaign by an [actor](actor.md) pursing an intent.
21 properties
AssetMapping
object
A record that maps a specific Observable to an asset for a specified period of time.
18 properties
CVE
object
1 property 1 required
VulnerabilityImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
Activity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
2 properties 2 required
Incident
object
Information about computer security incident response. A computer security incident is a violation or imminent threat of violation of computer security policie…
30 properties
FileMoveType
object
10 properties 8 required
Judgement
object
A judgement about the intent or nature of an observable. For example, is it malicious, meaning is is malware and subverts system operations? It could also be c…
20 properties
DataTable
object
A generic table of data, consisting of types and documented columns, and 1 or more rows of data.
18 properties
Asset
object
Describes a protected resource. It could be a Device, User, Network, Application or Data.
16 properties
OperatingSystem
object
5 properties
Actor
object
Describes malicious actors or adversaries related to a cyber attack.
23 properties
SensorCoordinates
object
Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
3 properties 2 required
PartialCasebook
object
Allows to gather and group observables and related analyst notes in one place from across multiple products for easy retrieval and further actions. Through Cas…
24 properties
LibraryLoadType
object
8 properties 6 required
Assertion
object
2 properties
IncidentScores
object
Used to indicate the severity or impact score of the threat represented by the incident.
Indicator
object
An indicator is a test, or a collection of judgements that define criteria for identifying the activity, or presence of malware, or other unwanted software. We…
26 properties
ModifierType
object
13 properties
Relationship
object
Represents a relationship between two entities.
17 properties
IdentityAssertion
object
Context attributes about the target or any of its observables. Providers could provide different types of assertions regarding a target depending on their own…
14 properties
Context
object
Context including the event type that best fits the type of the sighting.
12 properties
AdditionalProperties
object
1 property 1 required
Mitigation
object
5 properties
Language
object
3 properties
CPELeafNode
object
3 properties 2 required
CVSSv3
object
31 properties 3 required
FileDeleteType
object
9 properties 6 required
Consequence
object
4 properties
NewCasebook
object
an updated Casebook
24 properties
Sighting
object
A sighting indicates that a particular entity or [indicator](indicator.md) was observed in an environment and can be an indication of a current or potential th…
30 properties
Target
object
Schema for TargetRecord Targets
7 properties 3 required
ProcessCreateType
object
19 properties 4 required
AssetProperties
object
Assets do not have any product specific properties, those are represented in AssetProperties - which is a record that asserts one or more properties of an Asse…
14 properties
COA
object
Course of Action. A corrective or preventative action to be taken in response to a threat.
24 properties
ActuatorType
object
2 properties 1 required
Bundle
object
Describes a Bundle of any set of CTIM entities.
59 properties
MetricResultFilters
object
2 properties 2 required
CasebookBundleUpdate
object
A casebook Bundle operation
2 properties 2 required
CVSSv2
object
25 properties 3 required
PartialNewCasebook
object
a Casebook partial update
24 properties
Malware
object
Malware is a type of TTP that is also known as malicious code and malicious software, and refers to a program that is inserted into a system, usually covertly,…
18 properties
MetricResultData
object
MetaData
object
metadata associated to the incident.
CPEMatch
object
6 properties 2 required
IncidentTime
object
Relevant time values associated with this Incident.
7 properties 1 required
TargetRecord
object
A TargetRecord is a Sighting that has no threat or observables associated with it, it's a way of saying they saw a set of observables together as a Target.
15 properties
Note
object
A Note is intended to convey informative text to provide further context and/or to provide additional analysis not contained in the Objects, assigning Text/con…
15 properties
IdentityCoordinates
object
Attributes for which the assertion is being made.
1 property
FileCreateType
object
9 properties 6 required
AttackPattern
object
Attack Patterns are a type of TTP that describe ways that adversaries attempt to compromise targets.
19 properties
NoteRelatedEntity
object
2 properties 2 required
RelatedCOA
object
4 properties 1 required
Architecture
object
3 properties
AlternateTerm
object
2 properties
CompositeIndicatorExpression
object
2 properties 2 required
NewSightingRelationsRelationInfo
object
RegistryCreateType
object
7 properties 5 required
Configurations
object
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
2 properties 2 required
DetectionMethod
object
4 properties
Paradigm
object
2 properties
MetricResult
object
3 properties 3 required
Tool
object
Tools are legitimate software that can be used by threat actors to perform attacks. Knowing how and when threat actors use such tools can be important for unde…
18 properties
NetflowType
object
22 properties 5 required
RegistryDeleteType
object
8 properties 5 required
Feedback
object
Feedback on any entity. Is it wrong? If so why? Was it right-on, and worthy of confirmation?
14 properties
ActionType
object
1 property 1 required
Casebook
object
Allows to gather and group observables and related analyst notes in one place from across multiple products for easy retrieval and further actions. Through Cas…
24 properties 2 required
Vulnerability
object
Indicates weakness or flaw in the system that can be exploited by an attacker to gain unauthorized access or cause harm to the system. Vulnerabilities can exis…
19 properties
CPENode
object
4 properties 1 required
TargetType
object
2 properties 1 required
CVEDataMeta
object
2 properties
CasebookTextsUpdate
object
A casebook Texts operation
2 properties 1 required
Traffic
object
9 properties 6 required
ObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
FileModifyType
object
9 properties 6 required
AssetProperty
object
2 properties 2 required
Text
object
2 properties
SightingDataTable
object
An embedded data table for the Sighting.
3 properties 2 required
KillChainPhase
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
Observable
object
An AssetMapping is a record that a specific Observable maps to an Asset for an indicated period of time.
2 properties 2 required
CasebookObservablesUpdate
object
A casebook Observables operation
2 properties 1 required
ObservedRelation
object
A relation inside a Sighting.
6 properties 4 required
IdentitySpecification
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

cisco-xdr-casebook-api-openapi.yml Raw ↑

Other APIs Cisco XDR publishes across the network.

Cisco XDR Actor API
Cisco XDR Asset API
Cisco XDR Asset Mapping API
Cisco XDR Asset Properties API
Cisco XDR Attack Pattern API
Cisco XDR Bulk API
Cisco XDR Bundle API
Cisco XDR Campaign API
Cisco XDR COA API
Cisco XDR Deliberate API
Cisco XDR Event API
Cisco XDR Feed API
Where this information came from

This is an independent, third-party profile of Cisco XDR Casebook API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.