How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Acronis Endpoint Detection and Response API

The Acronis Endpoint Detection and Response API is a comprehensive security solution that helps organizations detect and respond to cybersecurity threats in real-time.

Acronis Endpoint Detection and Response API is one of 21 APIs that Acronis publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Acronis, EDR, and Endpoint Security. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 6 operations across 5 paths, and defines 30 schemas. It is described by OpenAPI 3.0.0, at version 1.0.

Requests are made against a single base URL, https://dev-cloud.acronis.com/api/mdr/v1.

6 operations 5 paths 30 schemas 3 GET3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
1.0
Base URL
https://{datacenter}.acronis.com/api/mdr/v1
Authentication
OAuth 2.0
Resource Areas
1

Authentication & Security 1

Acronis Endpoint Detection and Response API declares 1 security scheme for authenticating requests. It supports OAuth 2.0 (security_schemes.oauth2) using the clientCredentials flow, exposing 14 scopes.

Paths & Operations 6

Across 5 paths, the API surfaces 6 operations — 3 GET, 3 POST. Each is listed below with its method, path, parameters, and response codes.

Operations 6
GET
/incidents
Returns a list of incidents. The endpoint is is designed for use by MDR vendors to retrieve incidents for their customers and store them on their backend for future use. It is not intended for buildi…
18 params → 200400401403429500
POST
/incidents/investigation_state
Post update for an investigation state accompanied with comment or post a new comment for multiple incidents by MDR vendor.
4 params body → 200207400401403429500
GET
/incidents/{incident_id}
Returns incident detailed info.
9 params → 200304400401403404410429
POST
/incidents/{incident_id}/investigation_state
Post update for an investigation state accompanied with comment or post a new comment for an incident by MDR vendor.
5 params body → 200201400401403404429500
POST
/incidents/{incident_id}/response_action
Perform a response action listed in Get IncidentDetails reply.
21 params → 200201400401403404429500
GET
/incidents/{incident_id}/response_action
Get Detailed status of initiated action.
4 params → 200400401403404429500

Schemas 30

The contract defines 30 schemas that model the data the API accepts and returns. The most detailed are Incident (29 properties), IncidentBrief (26 properties), Activity (16 properties), ResponseAction (8 properties). Each schema is shown below with its type and property counts.

UUID
string
Universally Unique Identifier.
IncidentID
string
Incident ID.
MitigationState
string
Determines whether the threat was mitigated.
InvestigationState
string
Incident investigation state.
Severity
string
Incident severity.
PositivityLevel
number
Positivity level.
ThreatCategory
string
threat category.
WorkloadID
string
Workload ID.
IncidentBrief
object
Incident information.
26 properties 9 required
Error
object
Describes an error.
3 properties 3 required
UpdateInvestigationState
object
The investigation state update by a MDR vendor.
7 properties
debugInfo
object
Error debug information (map type)
kbLinkInfo
object
Components for kblink
6 properties 6 required
Incident
object
Complete Incident object.
29 properties 9 required
EntityID
string
Unique identifier of an entity in the EDR system.
ResponseActionPredefined
string
Predefined Response Action type.
ResponseActionDetails
object
Detailed status of initiated action.
4 properties 1 required
WorkloadInfo
object
Workload specific information. All fields are optional and can be omitted for host-less incident.
5 properties
Detection
object
8 properties 4 required
ResponseAction
object
Definition of available Response Action and its status if it's already initiated.
8 properties 1 required
Activity
object
Activity (includes comments, response actions and user incident actions).
16 properties 6 required
InProgressState
string
State of the activity that is in progress.
CompletionStatus
string
Execution state of the activity.
QueryParameters
object
Query Parameters definition modeled after RAML spec.
ActivityID
string
Activity ID.
ActivityOrigin
string
The origin of the activity.
ActivityStatus
Activity status.
IncidentActivityType
string
Incident activity type.
ResponseActionType
string
Response action type.
ParameterProperty
object
Parameter definition modeled after RAML spec.
4 properties 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

acronis-mdr-v1-openapi.json Raw ↑

Other APIs Acronis publishes across the network.

Acronis Resource and Policy Management API
Acronis Advanced Automation API
Acronis Event Manager API
Acronis Disaster Recovery Service API
Acronis Vault Manager REST API
Acronis Activities API
Acronis Agent Updates API
Acronis Agents API
Acronis Authentication API
Acronis Clients API
Acronis Hardware Nodes API
Acronis Licensing API
Where this information came from

This is an independent, third-party profile of Acronis Endpoint Detection and Response API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.