This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something is bad.
Cisco XDR Deliberate API declares
3 security schemes
for authenticating requests.
An API key is passed in the header as authorization (iroh).
An API key is passed in the header as authorization (AuthorizationHeader).
It supports OAuth 2.0 (oauth2) using the authorizationCode flow, exposing 25 scopes.
By default, every request must be authenticated.
AuthorizationHeader — Ex: Bearer \
Paths & Operations 1
Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.
Deliberate 1
This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something i…
POST
/iroh/iroh-enrich/deliberate/observables
Get Observable verdicts
3 paramsbody→ 200401500
Schemas 109
The contract defines 109 schemas that model the data the API accepts and returns. The most detailed are Weakness (34 properties), Sighting (33 properties), Incident (33 properties), CVSSv3 (31 properties). Each schema is shown below with its type and property counts.
Technology
object
2 properties1 required
ValidTime
object
The time range during which this Indicator is considered valid.
2 properties
ExternalReference
object
External references are used to describe pointers to information represented outside of CTIM. For example, a Malware object could use an external reference to…
Can contain information such as the name of the attacker, the group or organization they belong to, or any other identifier that can help in the attribution pr…
2 properties2 required
Weakness
object
34 properties4 required
DeliberateEnvelopedObserveBundleDataDataCampaigns
object
2 properties2 required
ModeOfIntroduction
object
2 properties1 required
ColumnDefinition
object
5 properties2 required
OpenC2COA
object
6 properties2 required
RegistrySetType
object
10 properties6 required
RelatedIdentity
object
Describes a related Identity
4 properties1 required
Verdict
object
9 properties4 required
Campaign
object
24 properties8 required
CVE
object
1 property1 required
VulnerabilityImpact
object
Describes the potential impact of a vulnerability that is being tracked in the system. Provides information on the extent of damage that a vulnerability can ca…
2 properties
Activity
object
Captures the specific activities or tactics associated with the entity. Examples of activities may include malicious software delivery, command and control com…
Context including the event type that best fits the type of the sighting.
12 properties
ErrorMessage
object
7 properties5 required
AdditionalProperties
object
1 property1 required
Mitigation
object
5 properties1 required
Language
object
3 properties1 required
CPELeafNode
object
3 properties2 required
CVSSv3
object
31 properties3 required
FileDeleteType
object
9 properties6 required
Consequence
object
4 properties1 required
DeliberateEnvelopedObserveBundle
object
2 properties
DeliberateEnvelopedObserveBundleDataDataFeedbacks
object
2 properties2 required
Sighting
object
33 properties6 required
SIOCSpecification
object
An indicator which runs in snort...
2 properties2 required
ThreatBrainSpecification
object
An indicator which runs in threatbrain...
3 properties2 required
ProcessCreateType
object
19 properties4 required
JudgementSpecification
object
An indicator based on a list of judgements. If any of the Observables in it's judgements are encountered, than it may be matches against. If there are any requ…
Represents a list of affected versions or configurations of a software component that is impacted by a vulnerability. By tracking the affected software compone…
The kill-chain-phase represents a phase in a kill chain, which describes the various phases an attacker may undertake in order to achieve their objectives.
2 properties2 required
Observable
object
A simple, atomic value which has a consistent identity, and is stable enough to be attributed an intent or nature. This is the classic 'indicator' which might…
2 properties2 required
SnortSpecification
object
An indicator which runs in snort...
2 properties2 required
DeliberateEnvelopedObserveBundleDataDataNotes
object
2 properties2 required
ObservedRelation
object
A relation inside a Sighting.
6 properties4 required
IdentitySpecification
object
Describes the target of the sighting and contains identifying observables for the target.
4 properties3 required
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Cisco XDR Deliberate API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.