How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Cisco XDR Deliberate API

This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something is bad.

Cisco XDR Deliberate API is one of 83 APIs that Cisco XDR publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Deliberate, Security, XDR, and Threat Detection. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 1 operation across 1 path, and defines 109 schemas. It is described by OpenAPI 3.2.0, at version 1.0.107.

Requests are made against a single base URL, https://visibility.amp.cisco.com/.

1 operations 1 paths 109 schemas 1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.107
Base URL
https://visibility.amp.cisco.com
Authentication
API Key, API Key, OAuth 2.0
Resource Areas
1

Authentication & Security 3

Cisco XDR Deliberate API declares 3 security schemes for authenticating requests. An API key is passed in the header as authorization (iroh). An API key is passed in the header as authorization (AuthorizationHeader). It supports OAuth 2.0 (oauth2) using the authorizationCode flow, exposing 25 scopes. By default, every request must be authenticated.

  • AuthorizationHeader — Ex: Bearer \

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.

Deliberate 1

This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something i…

POST
/iroh/iroh-enrich/deliberate/observables
Get Observable verdicts
3 params body → 200401500

Schemas 109

The contract defines 109 schemas that model the data the API accepts and returns. The most detailed are Weakness (34 properties), Sighting (33 properties), Incident (33 properties), CVSSv3 (31 properties). Each schema is shown below with its type and property counts.

Technology
object
2 properties 1 required
ValidTime
object
The time range during which this Indicator is considered valid.
2 properties
ExternalReference
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
5 properties 1 required
DeliberateEnvelopedObserveBundleDataDataRelationships
object
2 properties 2 required
DeliberateEnvelopedObserveBundleDataDataIdentityAssertions
object
2 properties 2 required
RegistryRenameType
object
8 properties 6 required
HTTPType
object
12 properties 6 required
Identity
object
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties 2 required
Weakness
object
34 properties 4 required
DeliberateEnvelopedObserveBundleDataDataCampaigns
object
2 properties 2 required
ModeOfIntroduction
object
2 properties 1 required
ColumnDefinition
object
5 properties 2 required
OpenC2COA
object
6 properties 2 required
RegistrySetType
object
10 properties 6 required
RelatedIdentity
object
Describes a related Identity
4 properties 1 required
Verdict
object
9 properties 4 required
Campaign
object
24 properties 8 required
CVE
object
1 property 1 required
VulnerabilityImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
Activity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
2 properties 2 required
Incident
object
33 properties 6 required
FileMoveType
object
10 properties 8 required
Judgement
object
23 properties 11 required
DeliberateEnvelopedObserveBundleDataDataAttackPatterns
object
2 properties 2 required
DataTable
object
21 properties 5 required
DeliberateEnvelopedObserveBundleDataDataIncidents
object
2 properties 2 required
OperatingSystem
object
5 properties 1 required
Actor
object
26 properties 8 required
SensorCoordinates
object
Describes the device that made the sighting (sensor) and contains identifying observables for the sensor.
3 properties 2 required
LibraryLoadType
object
8 properties 6 required
Assertion
object
2 properties 2 required
DeliberateEnvelopedObserveBundleDataDataSightings
object
2 properties 2 required
IncidentScores
object
Used to indicate the severity or impact score of the threat represented by the incident.
Indicator
object
29 properties 5 required
DeliberateEnvelopedObserveBundleDataDataIndicators
object
2 properties 2 required
ModifierType
object
13 properties
Relationship
object
20 properties 6 required
IdentityAssertion
object
17 properties 5 required
Context
object
Context including the event type that best fits the type of the sighting.
12 properties
ErrorMessage
object
7 properties 5 required
AdditionalProperties
object
1 property 1 required
Mitigation
object
5 properties 1 required
Language
object
3 properties 1 required
CPELeafNode
object
3 properties 2 required
CVSSv3
object
31 properties 3 required
FileDeleteType
object
9 properties 6 required
Consequence
object
4 properties 1 required
DeliberateEnvelopedObserveBundle
object
2 properties
DeliberateEnvelopedObserveBundleDataDataFeedbacks
object
2 properties 2 required
Sighting
object
33 properties 6 required
SIOCSpecification
object
An indicator which runs in snort...
2 properties 2 required
ThreatBrainSpecification
object
An indicator which runs in threatbrain...
3 properties 2 required
ProcessCreateType
object
19 properties 4 required
JudgementSpecification
object
An indicator based on a list of judgements. If any of the Observables in it's judgements are encountered, than it may be matches against. If there are any requ…
3 properties 3 required
DeliberateEnvelopedObserveBundleDataDataMalwares
object
2 properties 2 required
COA
object
27 properties 4 required
ActuatorType
object
2 properties 1 required
DeliberateEnvelopedObserveBundleDataDataTools
object
2 properties 2 required
CVSSv2
object
25 properties 3 required
Malware
object
21 properties 7 required
DeliberateEnvelopedObserveBundleDataDataJudgements
object
2 properties 2 required
RelatedJudgement
object
4 properties 1 required
MetaData
object
metadata associated to the incident.
CPEMatch
object
6 properties 2 required
IncidentTime
object
Relevant time values associated with this Incident.
7 properties 1 required
Note
object
18 properties 6 required
IdentityCoordinates
object
Attributes for which the assertion is being made.
1 property 1 required
FileCreateType
object
9 properties 6 required
AttackPattern
object
22 properties 6 required
NoteRelatedEntity
object
2 properties 2 required
RelatedCOA
object
4 properties 1 required
Architecture
object
3 properties 1 required
DeliberateEnvelopedObserveBundleDataDataWeaknesses
object
2 properties 2 required
AlternateTerm
object
2 properties 1 required
CompositeIndicatorExpression
object
2 properties 2 required
RegistryCreateType
object
7 properties 5 required
DeliberateEnvelopedObserveBundleDataDataActors
object
2 properties 2 required
Configurations
object
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
2 properties 2 required
DetectionMethod
object
4 properties 2 required
NormalizedError-500
object
6 properties
Paradigm
object
2 properties 1 required
Tool
object
21 properties 7 required
NetflowType
object
22 properties 5 required
DeliberateEnvelopedObserveBundleDataDataVerdicts
object
2 properties 2 required
DeliberateEnvelopedObserveBundleDataDataDataTables
object
2 properties 2 required
ModuleObserveBundle
object
18 properties
RegistryDeleteType
object
8 properties 5 required
Feedback
object
17 properties 6 required
DeliberateEnvelopedObserveBundleDataDataCoas
object
2 properties 2 required
ActionType
object
1 property 1 required
Vulnerability
object
22 properties 4 required
CPENode
object
4 properties 1 required
TargetType
object
2 properties 1 required
CVEDataMeta
object
2 properties
OpenIOCSpecification
object
An indicator which contains an XML blob of an openIOC indicator.
2 properties 2 required
Traffic
object
9 properties 6 required
ObservedTime
object
Period of time when a cyber observation is valid. starttime must come before endtime (if specified).
2 properties 1 required
DeliberateEnvelopedObserveBundleDataDataSightingsDocsRelationsRelationInfo
object
FileModifyType
object
9 properties 6 required
DeliberateEnvelopedObserveBundleDataDataVulnerabilities
object
2 properties 2 required
NormalizedError-401
object
6 properties
DeliberateEnvelopedObserveBundleData
object
5 properties 4 required
SightingDataTable
object
An embedded data table for the Sighting.
3 properties 2 required
KillChainPhase
object
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties 2 required
Observable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties 2 required
SnortSpecification
object
An indicator which runs in snort...
2 properties 2 required
DeliberateEnvelopedObserveBundleDataDataNotes
object
2 properties 2 required
ObservedRelation
object
A relation inside a Sighting.
6 properties 4 required
IdentitySpecification
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties 3 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

cisco-xdr-deliberate-api-openapi.yml Raw ↑

Other APIs Cisco XDR publishes across the network.

Cisco XDR Actor API
Cisco XDR Asset API
Cisco XDR Asset Mapping API
Cisco XDR Asset Properties API
Cisco XDR Attack Pattern API
Cisco XDR Bulk API
Cisco XDR Bundle API
Cisco XDR Campaign API
Cisco XDR Casebook API
Cisco XDR COA API
Cisco XDR Event API
Cisco XDR Feed API
Where this information came from

This is an independent, third-party profile of Cisco XDR Deliberate API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.