The Realize API for Druva Cyber Resilience. Accelerated Ransomware Recovery quarantine ranges and snapshots, curated snapshot jobs, threat hunting, threat intel IOC sets and lookup, threat watch, unusual data activity anomaly detection, restore scans and the Realize event stream.
Druva Cyber Resilience API is one of 21 APIs that Druva publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Cyber Resilience, Ransomware Recovery, Threat Hunting, Threat Intel, and Curated Snapshots. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.
This API exposes
62 operations
across 49 paths,
organized into 8 resource areas,
and defines 106 schemas.
It is described by OpenAPI 3.0.0, at version 3.0.0.
Requests are made against a single base URL, https://apis.druva.com/realize.
62 operations49 paths106 schemas6 DELETE42 GET1 PATCH7 POST6 PUT
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.0.0
API Version
3.0.0
Base URL
https://apis.druva.com/realize
Authentication
OAuth 2.0, API Key
Resource Areas
8
Authentication & Security 2
Druva Cyber Resilience API declares
2 security schemes
for authenticating requests.
It supports OAuth 2.0 (OAuth2) using the clientCredentials flow, exposing 1 scope.
An API key is passed in the header as Authorization (Bearer).
Paths & Operations 62
Across 49 paths, the API surfaces 62 operations — 6 DELETE, 42 GET, 1 PATCH, 7 POST, 6 PUT. They span 8 resource areas: Ransomware Recovery, Data Anomalies, Restore scans, Realize Events, Curated Snapshots, Threat Hunting, Threat Watch, Threat Intel. Each is listed below with its method, path, parameters, and response codes.
Ransomware Recovery 13
List of APIs to get information and perform operations on ransomware affected resources managed in Druva Cloud.
List of APIs that helps to retrieve information and perform operations on Threat Watch. Threat Watch is an automated continuous monitoring feature that scans resources for threats…
List of APIs to view details and manage IOC Sets in the IOC library.
GET
/threatintel/v1/ioc-sets
Listing of IOC Sets
ListIocSetRequest6 params→ 200400401404500
POST
/threatintel/v1/ioc-sets
Creates a new IOC Set
CreateIOCSetRequestbody→ 200400401404500
GET
/threatintel/v1/ioc-sets/iocs
Lists all the IOCs that matches the specified parameters
GetIOCsRequest7 params→ 200400401404500
GET
/threatintel/v1/ioc-sets/{iocsetid}
Details of IOC Set
IocSetDetailsRequest1 param→ 200400401404500
DELETE
/threatintel/v1/ioc-sets/{iocsetid}
Delete an existing IOC Set
DeleteIocSetRequest1 parambody→ 200400401404500
PATCH
/threatintel/v1/ioc-sets/{iocsetid}
Updates existing IOC Set
UpdateIocSetRequest1 parambody→ 200400401404500
DELETE
/threatintel/v1/ioc-sets/{iocsetid}/iocs
Deletes IOCs from IOC Set
DeleteIocsRequest1 parambody→ 200400401404500
GET
/threatintel/v1/ioc/lookup
Check if the specified IOC exists in any of the existing IOC Sets
IocLookupRequest1 param→ 200400401404500
Schemas 106
The contract defines 106 schemas that model the data the API accepts and returns. The most detailed are jobDetailsModel (43 properties), ThreatHunt (17 properties), listResourceCverStats (16 properties), ThreatHuntScanSummaryResponse (14 properties). Each schema is shown below with its type and property counts.
searchResponse
object
3 properties
quarantineRangeCreateRequest
object
4 properties1 required
quarantineRangeUpdateRequest
object
2 properties
quarantineRangeCreateResponse
object
1 property
quarantineRangeListResponse
object
4 properties
quarantineRangeGetResponse
object
12 properties
snapshotListResponse
object
3 properties
deleteSnapshotSchema
object
1 property
listResourceCverStats
object
16 properties
SettingsResponse
object
11 properties
SettingsRequest
object
11 properties
jobListModel
object
3 properties
jobDetailsModel
object
43 properties
jobFilesDetailsResponse
object
3 properties
getJobCount
object
2 properties
ListEventsResponse
object
2 properties2 required
ListEventsByTrackerResponse
object
2 properties2 required
EventFilters
object
1 property
CSJobCreationParams
object
10 properties3 required
CSJobCreationResponse
object
2 properties
JobCreationError
object
2 properties
Resource
object
6 properties
JobModelError
object
3 properties
CSJobCancelResponse
object
1 property
CSGetJobResponse
object
2 properties
CSListJobResponse
object
3 properties
CSListSnapshotsResponse
object
3 properties
CSExpireSnapshotsResponse
object
1 property
CSJobCancelParams
object
1 property
CSDeleteParams
object
2 properties1 required
CSReportResponse
object
3 properties
HTTP_400
object
4 properties
HTTP_404
object
4 properties
HTTP_422
object
4 properties
HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
4 properties
ErrorResponse
object
4 properties
RWC_HTTP_400
object
4 properties
RWC_HTTP_404
object
4 properties
RWC_HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
4 properties
CS_HTTP_400
object
4 properties
CS_HTTP_404
object
4 properties
CS_HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
4 properties
RR_HTTP_400
object
4 properties
RR_HTTP_404
object
4 properties
RR_HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
4 properties
ThreatHuntSearchBackupsetResponse
object
2 properties
ThreatHuntSearchBackupsetParams
object
5 properties
ThreatHuntDownloadReportResponse
object
1 property
ThreatHuntListImpactedSnapshotsResponse
object
6 properties
ThreatHuntGetDeviceStatsResponse
object
13 properties
ThreatHuntGetDeviceDetailsResponse
object
10 properties
ThreatHuntListDevicesStatsResponse
object
3 properties
ThreatHuntListDevicesResponse
object
4 properties
ThreatHuntCreateResponse
object
3 properties
ThreatHuntCreateParams
object
9 properties
ThreatHuntScanSummaryResponse
object
14 properties
ThreatHuntJobDeleteParams
object
1 property
ThreatHuntListResponse
object
3 properties
ThreatHunt
object
17 properties
ThreatHuntJobCancelResponse
object
2 properties
ThreatHuntGetResponse
object
13 properties
ThreatHunt_HTTP_400
object
4 properties
ThreatHunt_HTTP_404
object
4 properties
ThreatHunt_HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
4 properties
ThreatWatchConfigResponse
object
2 properties
ThreatWatchConfigUpdateParams
object
1 property1 required
ThreatWatchConfigUpdateResponse
object
2 properties
ThreatWatchDevicesResponse
object
3 properties
ThreatWatchDeviceDetailsResponse
object
10 properties
ThreatWatchDeviceStatsResponse
object
8 properties
ThreatWatchImpactedDevicesStatsResponse
object
4 properties
ThreatWatchIOCsResponse
object
3 properties
ThreatWatchReportResponse
object
1 property
ThreatWatchScansResponse
object
2 properties
ThreatWatch_HTTP_400
object
4 properties
ThreatWatch_HTTP_404
object
4 properties
ThreatWatch_HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
4 properties
SearchAWSAccountsResponse
array
ListResourceIDsResponse
array
SearchAWSResourcesParams
object
6 properties
SearchAWSResourcesResponse
object
2 properties
RealizeCommon_HTTP_400
object
4 properties
RealizeCommon_HTTP_404
object
4 properties
RealizeCommon_HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
4 properties
CreateIOCSetRequestBody
object
5 properties3 required
DeleteIocSetBody
object
1 property
DeleteIocSetResponse
object
DeleteIocsRequestBody
object
2 properties
DeleteIocsResponse
object
GetIOCsResponse
object
3 properties
IOCDetails
object
7 properties
IOCSetResponse
object
IOCSetResponse is the response structure of successful ioc create request
5 properties
IocLookupResponse
object
1 property
IocSetDetailsResponse
object
9 properties
IocSetForLookup
object
6 properties
ListIocSetDetails
object
11 properties
ListIocSetResponse
object
4 properties
UpdateIocSetRequestBody
object
UpdateIocSetRequestBody is the request structure to handle IOC set create request
4 properties
TI_HTTP_400
object
4 properties
TI_HTTP_404
object
4 properties
TI_HTTP_500
object
The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Druva Cyber Resilience API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.