Cisco Secure Endpoint Connector
Cisco Secure Endpoint is an endpoint security solution that provides advanced threat protection and continuous monitoring.
Cisco Secure Endpoint is a comprehensive security solution that provides advanced threat protection and endpoint security. This connector allows seamless integration with Swimlane Turbine, enabling users to automate endpoint security tasks such as policy management, device control, and threat detection. By leveraging this integration, security teams can enhance their threat response capabilities, streamline operations, and ensure robust protection across their network.
Limitations
The asset uses HTTP Basic authentication with your API Client ID as the username and API Key as the password. This is application-style access to the AMP API on behalf of your integration, not an interactive user session. Capabilities depend on what your Cisco account and API credentials are entitled to (for example, regional API hosts, v3 organization APIs, and forensic endpoints).
API v1 / legacy endpoints (computers, groups, events, isolation, forensics, and related actions) use paths under the configured base URL (for example https://api.amp.cisco.com) as described in the v1 reference.
API v3 policy actions require a Secure Endpoint organization identifier in the path. That identifier is the v3 organization ID from your tenant, which may differ from identifiers used only in older v1 flows. Policy and device-control operations apply per organization and policy GUID as defined in the Policies API.
Supported Version
The connector is built against Cisco Secure Endpoint / Secure Endpoint HTTP APIs:
- v1 (and related) API β Used for computers, groups, events, isolation, move host, and forensic snapshot actions.
- v3 API β Used for organization policies, policy types, and policy device control (USB mass storage and Windows portable device) actions, against the same configurable API base URL when your deployment exposes v3 (for example North America: https://api.amp.cisco.com/v3 as the path prefix on the server documented in Ciscoβs OpenAPI).
Refer to Ciscoβs documentation for the exact base URL for your region (for example EU or other AMP cloud instances).
Configuration
Prerequisites
Before you can use the Cisco Secure Endpoint connector for Turbine, you'll need access to the Cisco Secure Endpoint API. This requires the following:
- HTTP Basic authentication using the following parameters:
- API URL: The base URL for accessing the Cisco Secure Endpoint API.
- API Client ID: A unique identifier for your API client.
- API Key: A secret key used to authenticate API requests.
Authentication Methods
HTTP Basic (API Client ID and API Key)
Setup instructions
- Sign in to the Cisco Secure Endpoint (AMP) management console for your organization.
- Create or open an API credential that exposes an API Client ID and API Key (naming may vary slightly by console version).
- Copy the Client ID and API Key into the connector asset: Client ID β username, API Key β password.
- Set URL to your tenantβs API base (for example https://api.amp.cisco.com or your regional equivalent).
The connector sends requests with Authorization: Basic β¦ encoding those two values per RFC 7617.
Document references
Troubleshoot tips
- A 401 response usually means the Client ID or API Key is wrong, expired, or not enabled for the API you are calling.
- If v3 policy calls fail with βnot foundβ or organization errors, confirm you are using the v3 organization identifier from your tenant, not a legacy-only identifier from older APIs.
- If v1 actions work but v3 actions do not, confirm your deployment and entitlements include the v3 API on the same or documented host.
Capabilities
- Apply an Exclusion Set to a Policy
- Assign Policy USB Mass Storage Device Control
- Assign Policy Windows Portable Device Control
- Create Host Firewall Configuration
- Create Organization Policy
- Create Rule for Host Firewall configuration
- Delete Host Firewall Rule
- Delete Host Firewall configuration
- Delete a Policy
- Display the XML for the Policy
- Find a Policy by ID
- Get Computer Information
- Get Computers
- Get Events
- Get Forensic Snapshot by ID ... and so on
Apply an Exclusion Set to a Policy
Assign Policy USB Mass Storage Device Control
Assign Policy Windows Portable Device Control
Create Host Firewall Configuration
Create Organization Policy
Create Rule for Host Firewall configuration
Delete Host Firewall Rule
Delete Host Firewall configuration
Delete a Policy
Display the XML for the Policy
Find a Policy by ID
Get Computer Information
Get Computers
Get Events
Get Forensic Snapshot by ID
Get Forensic Snapshots
Get Groups
Get Host Firewall configuration
Get Policy USB Mass Storage Device Control
Get Policy Windows Portable Device Control
Isolate Computer
List Computers Using a Policy
List Exclusion Sets Assigned to a Policy
List Host Firewall Configurations
List Organization Policies
List Organization Policy Types
List of Groups Used by a Policy
List the Network Control Lists for a Policy
List the Proxy Settings for a Policy
Move Host to Group
Remove Policy USB Mass Storage Device Control
Remove Policy Windows Portable Device Control
Remove an Exclusion Set from a Policy
Show Host Firewall configuration Rules
Unisolate Computer
Update Host Firewall Rule
Configurations
HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | Secure Endpoint API URL. | string | Required |
username | Secure Endpoint API Client ID. | string | Required |
password | Secure Endpoint API Key. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Apply an Exclusion Set to a Policy
Apply an exclusion set to a specified policy and organization in Cisco Secure Endpoint using organizationIdentifier, policyGuid, and exclusionSetGuid.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/exclusion_sets
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
exclusionSetGuid | string | Optional | The GUID of the exclusion set. |
Input Example
{"json_body":{"exclusionSetGuid":"3b8b0233-bcdd-484f-8954-21d24a93544b"},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":201,"response_headers":{},"reason":"Created","json_body":{}}
Assign Policy USB Mass Storage Device Control
Assign a USB mass storage device control configuration to a policy in Cisco Secure Endpoint using organization identifier, policy GUID, and configuration GUID.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies/{{policy_guid}}/device_control_configuration/usb_mass_storage
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
path_parameters.policy_guid | string | Required | GUID of the policy to update device control on. |
configurationGuid | string | Optional | GUID of the device control configuration to assign. |
Input Example
{"json_body":{"configurationGuid":"8999990f-122c-4d40-a173-f124f5a323a2"},"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policy_guid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.errors | array | Error message if any |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content"}
Assign Policy Windows Portable Device Control
Assign a Windows Portable Device control configuration to a policy in Cisco Secure Endpoint using organization identifier, policy GUID, and configuration GUID.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies/{{policy_guid}}/device_control_configuration/windows_portable_device
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
path_parameters.policy_guid | string | Required | GUID of the policy to update WPD device control on. |
configurationGuid | string | Optional | GUID of the device control configuration to assign. |
Input Example
{"json_body":{"configurationGuid":"8999990f-122c-4d40-a173-f124f5a323a2"},"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policy_guid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.errors | array | Error message if any |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content"}
Create Host Firewall Configuration
Create a new host firewall configuration for an organization in Cisco Secure Endpoint. Requires organizationIdentifier, name, and defaultAction.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/configurations
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
name | string | Optional | Name of the configuration. |
description | string | Optional | Description of the configuration. |
defaultAction | string | Optional | Default action for the configuration. |
Input Example
{"json_body":{"name":"Configuration name","description":"Configuration description","defaultAction":"allow"},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
data | object | Response data |
data.id | number | Response data |
data.guid | string | Response data |
data.name | string | Response data |
data.description | string | Response data |
data.defaultAction | string | Response data |
data.updatedAt | string | Response data |
data.updatedBy | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{},"data":{"id":3345,"guid":"aa4d84e2-cfbe-4d35-ad96-44e57188a2ab","name":"Configuration name","description":"Configuration description","defaultAction":"allow","updatedAt":"2023-09-12T21:19:53.201Z","updatedBy":"Jane Doe"}}}
Create Organization Policy
Create a new policy from the default for an organization in Cisco Secure Endpoint. Requires organization identifier, name, policy type, and operating system.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
name | string | Optional | Display name for the new policy. |
description | string | Optional | Optional human-readable description of the policy. |
policyType | string | Optional | Policy type network, mobile, or workstation. |
operatingSystem | string | Optional | Target OS windows, mac, linux, android, or ios. |
Input Example
{"json_body":{"name":"Audit","description":"Report malicious files, but take no other action.","policyType":"workstation","operatingSystem":"windows"},"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.delete | string | Output field: meta.delete |
meta.proxy | string | Output field: meta.proxy |
meta.networkControlLists | string | Output field: meta.networkControlLists |
meta.exclusionSets | string | Output field: meta.exclusionSets |
meta.deviceControlConfiguration | string | Output field: meta.deviceControlConfiguration |
meta.hostFirewallConfiguration | string | Output field: meta.hostFirewallConfiguration |
data | object | Response data |
data.name | string | Response data |
data.guid | string | Response data |
data.description | string | Response data |
data.createdAt | string | Response data |
data.updatedAt | string | Response data |
data.serialNumber | number | Response data |
data.orbital | object | Response data |
data.orbital.enabled | boolean | Response data |
data.operatingSystem | string | Response data |
data.policyType | string | Response data |
data.default | boolean | Response data |
data.protectionSettings | object | Response data |
data.protectionSettings.files | string | Response data |
data.protectionSettings.network | string | Response data |
data.protectionSettings.maliciousActivityProtection | string | Response data |
Output Example
{"status_code":201,"response_headers":{"content-type":"application/json"},"reason":"Created","json_body":{"meta":{"delete":"/v3/organizations/MTIzNDU2Nzg5MDEyMzQ1Njc/policies/73c9a3a1-e97d-4bc2-8597-a11b5...","proxy":"/v3/organizations/MTIzNDU2Nzg5MDEyMzQ1Njc/policies/73c9a3a1-e97d-4bc2-8597-a11b5...","networkControlLists":"/v3/organizations/MTIzNDU2Nzg5MDEyMzQ1Njc/policies/73c9a3a1-e97d-4bc2-8597-a11b5...","exclusionSets":"/v3/organizations/MTIzNDU2Nzg5MDEyMzQ1Njc/policies/73c9a3a1-e97d-4bc2-85...
Create Rule for Host Firewall configuration
Create a new rule for a Host Firewall configuration in Cisco Secure Endpoint. Requires organizationIdentifier, configurationGuid, and JSON body parameters like name, action, direction, and more.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/configurations/{{configurationGuid}}/rules
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.configurationGuid | string | Required | The GUID of the configuration. |
name | string | Optional | Name of the configuration rule. |
action | string | Optional | Action to take when a request matches the rule. |
direction | string | Optional | Direction of the rule. |
protocol | string | Optional | Protocol of the rule. |
audit | boolean | Optional | Whether to audit the rule. |
localIp | string | Optional | Valid IPv4 addresses, CIDR blocks and comma or new line separated lists. |
localPorts | string | Optional | Local address port. |
remoteIp | string | Optional | Valid IPv4 addresses, CIDR blocks and comma or new line separated lists. |
remotePorts | string | Optional | Remote address port. |
ipFamily | string | Optional | IP family of the rule. |
applicationPaths | string | Optional | A comma separated list of absolute paths. |
Input Example
{"json_body":{"name":"Rule name","action":"block","direction":"any","protocol":"any","audit":false,"localIp":"any","localPorts":"any","remoteIp":"any","remotePorts":"any","ipFamily":"ipv4","applicationPaths":"any"},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","configurationGuid":"d44d84e2-cfbe-4d35-ad96-3de57188a2ad"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.self | string | Output field: meta.self |
data | object | Response data |
data.guid | string | Response data |
data.action | string | Response data |
data.name | string | Response data |
data.direction | string | Response data |
data.localIp | string | Response data |
data.localPorts | string | Response data |
data.remoteIp | string | Response data |
data.remotePorts | string | Response data |
data.protocol | string | Response data |
Output Example
{"status_code":201,"response_headers":{},"reason":"Created","json_body":{"meta":{"self":"https://api.amp.cisco.com/v3/organizations/vyjrlylfhqtwxfo1celzdpjk/host_firewal..."},"data":{"guid":"da6c4b7b-cbb5-4922-a443-2771f580eabe","action":"block","name":"Rule name","direction":"out","localIp":"10.0.0.0","localPorts":"3600","remoteIp":"0.0.0.0/0","remotePorts":"any","protocol":"any"}}}
Delete a Policy
Delete a specified policy from the organization in Cisco Secure Endpoint using organizationIdentifier and policyGuid as path parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Delete Host Firewall configuration
Delete a Host Firewall configuration and associated rules in Cisco Secure Endpoint using organizationIdentifier and configurationGuid.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/configurations/{{configurationGuid}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.configurationGuid | string | Required | The GUID of the configuration. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","configurationGuid":"d44d84e2-cfbe-4d35-ad96-3de57188a2ad"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Delete Host Firewall Rule
Remove a host firewall rule from its configuration in Cisco Secure Endpoint using organizationIdentifier and ruleGuid.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/rules/{{ruleGuid}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.ruleGuid | string | Required | The GUID of the rule. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","ruleGuid":"9ac85fb4-9f68-4c9b-b2b9-004ed167d912"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Display the XML for the Policy
Return the policy XML content for a specified policy and organization in Cisco Secure Endpoint using organizationIdentifier and policyGuid.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/xml
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Find a Policy by ID
Retrieve policy data for a specified policy and organization in Cisco Secure Endpoint using organizationIdentifier and policyGuid.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.delete | string | Output field: meta.delete |
meta.proxy | string | Output field: meta.proxy |
meta.networkControlLists | string | Output field: meta.networkControlLists |
meta.exclusionSets | string | Output field: meta.exclusionSets |
meta.deviceControlConfiguration | string | Output field: meta.deviceControlConfiguration |
data | object | Response data |
data.name | string | Response data |
data.guid | string | Response data |
data.description | string | Response data |
data.createdAt | string | Response data |
data.updatedAt | string | Response data |
data.serialNumber | number | Response data |
data.orbital | object | Response data |
data.orbital.enabled | boolean | Response data |
data.operatingSystem | string | Response data |
data.policyType | string | Response data |
data.default | boolean | Response data |
data.protectionSettings | object | Response data |
data.protectionSettings.files | string | Response data |
data.protectionSettings.network | string | Response data |
data.protectionSettings.maliciousActivityProtection | string | Response data |
data.protectionSettings.systemProcessProtection | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"delete":"/v3/organizations/nhA6c9DGEyFDEeiHE1hdAgAV/policies/d44d84e2-cfbe-4d35-ad96-3de5...","proxy":"/v3/organizations/nhA6c9DGEyFDEeiHE1hdAgAV/policies/d44d84e2-cfbe-4d35-ad96-3de5...","networkControlLists":"/v3/organizations/nhA6c9DGEyFDEeiHE1hdAgAV/policies/d44d84e2-cfbe-4d35-ad96-3de5...","exclusionSets":"/v3/organizations/nhA6c9DGEyFDEeiHE1hdAgAV/policies/d44d84e2-cfbe-4d35-ad96-3de5...","deviceControlConfigurati...
Get Computer Information
Retrieve detailed information about a specific computer in Cisco AMP for Endpoints using the connector GUID.
Endpoint
- URL: /v1/computers/{{connector_guid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.connector_guid | string | Required | Parameters for the Get Computer Information action |
Input Example
{"path_parameters":{"connector_guid":"bad2c522-3052-4d75-93a0-832d6283c299"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
data | object | Response data |
data.connector_guid | string | Response data |
data.hostname | string | Response data |
data.windows_processor_id | string | Response data |
data.active | boolean | Response data |
data.links | object | Response data |
data.links.computer | string | Response data |
data.links.trajectory | string | Response data |
data.links.group | string | Response data |
data.connector_version | string | Response data |
data.operating_system | string | Response data |
data.os_version | string | Response data |
data.internal_ips | array | Response data |
data.external_ip | string | Response data |
data.group_guid | string | Response data |
data.install_date | string | Response data |
data.is_compromised | boolean | Response data |
data.demo | boolean | Response data |
data.csc_id | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{}},"data":{"connector_guid":"bad2c522-3052-4d75-93a0-832d6283c299","hostname":"Demo_AMP","windows_processor_id":"195b0d8736e2af4","active":true,"links":{},"connector_version":"99.0.99.20946","operating_system":"Windows 10","os_version":"10.0.19044.1466","internal_ips":[],"external_ip":"xxx.xxx.xx...
Get Computers
Fetch information about a specific computer in Cisco Secure Endpoint using the provided connector_guid.
Endpoint
- URL: /v1/computers
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.last_seen_over | number | Optional | Providing information by Last Seen Over number of days ago. |
parameters.last_seen_within | number | Optional | Providing information by Last Seen Within number of days. |
parameters.group_guid | string | Optional | Providing information by Group GUID. |
parameters.external_ip | string | Optional | Providing information by External IP. |
parameters.internal_ip | string | Optional | Providing information by Internal IP. |
parameters.hostname | string | Optional | Providing information by Hostname. |
parameters.kenna_risk_score | string | Optional | Providing information by Kenna Risk Score. |
parameters.processor_id | string | Optional | Providing information by Windows Processor ID or Mac Hardware ID. |
parameters.limit | number | Optional | To prevent the response from becoming too large, the number of items returned is limited by default to 5000. You can override this value by using the limit query parameter to specify a different number. |
parameters.offset | number | Optional | The number of items to skip before starting to collect the result set. |
Input Example
{"parameters":{"last_seen_over":25,"last_seen_within":30,"group_guid":"6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03","external_ip":"10.23.154.46","internal_ip":"192.168.100.101","hostname":"Connector_1657546677","kenna_risk_score":"low","processor_id":"b3sd42gb568s42n","limit":100,"offset":10}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
metadata.results | object | Response data |
metadata.results.total | number | Response data |
metadata.results.current_item_count | number | Response data |
metadata.results.index | number | Response data |
metadata.results.items_per_page | number | Response data |
data | array | Response data |
data.connector_guid | string | Response data |
data.hostname | string | Response data |
data.windows_processor_id | string | Response data |
data.active | boolean | Response data |
data.links | object | Response data |
data.links.computer | string | Response data |
data.links.trajectory | string | Response data |
data.links.group | string | Response data |
data.connector_version | string | Response data |
data.operating_system | string | Response data |
data.os_version | string | Response data |
data.internal_ips | array | Response data |
data.internal_ips.file_name | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{},"results":{}},"data":[{}]}}
Get Events
Fetch a list of security events from Cisco Secure Endpoint to monitor and analyze endpoint activities.
Endpoint
- URL: /v1/events
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.event_type | number | Optional | Parameters for the Get Events action |
parameters.limit | number | Optional | Parameters for the Get Events action |
parameters.start_date | string | Optional | Parameters for the Get Events action |
parameters.offset | number | Optional | Parameters for the Get Events action |
parameters.detection_sha256 | string | Optional | Parameters for the Get Events action |
parameters.application_sha256 | string | Optional | Parameters for the Get Events action |
parameters.group_guid | string | Optional | Parameters for the Get Events action |
parameters.connector_guid | string | Optional | Parameters for the Get Events action |
Input Example
{"parameters":{"event_type":10,"limit":9,"start_date":"2022-03-18T11:20:06+00:00","offset":3,"detection_sha256":"b4e5c2775de098946b4e11aba138b89d42b88c1dbd4d5ec879ef6919bf018132","application_sha256":"b630e72639cc7340620adb0cfc26332ec52fe8867b769695f2d25718d68b1b40","group_guid":"e766a0e9-96da-41b9-b1e8-87dd010d6b68","connector_guid":"538738f5-3a14-4449-933b-86142553de06"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
metadata.links.next | string | Response data |
metadata.results | object | Response data |
metadata.results.total | number | Response data |
metadata.results.current_item_count | number | Response data |
metadata.results.index | number | Response data |
metadata.results.items_per_page | number | Response data |
data | array | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{},"results":{}},"data":[{}]}}
Get Forensic Snapshot by ID
Retrieve details of a specific forensic snapshot in Cisco Secure Endpoint using the forensic_snapshot_id path parameter. The details are available under data.snapshot.
Endpoint
- URL: /v1/forensic_snapshots/{{forensic_snapshot_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.forensic_snapshot_id | string | Required | Parameters for the Get Forensic Snapshot by ID action |
Input Example
{"path_parameters":{"forensic_snapshot_id":"sZ9uJIOQuDMAhslsq_r6OA"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Get Forensic Snapshots
Return details of a specific forensic snapshot in Cisco Secure Endpoint, with information available under data.snapshot.
Endpoint
- URL: /v1/forensic_snapshots
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.limit | number | Optional | Parameters for the Get Forensic Snapshots action |
Input Example
{"parameters":{"limit":10}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
metadata.results | object | Response data |
metadata.results.total | number | Response data |
metadata.results.current_item_count | number | Response data |
metadata.results.index | number | Response data |
metadata.results.items_per_page | number | Response data |
data | array | Response data |
data.connector_guid | string | Response data |
data.user_email | string | Response data |
data.url | string | Response data |
data.triggered_by | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{},"results":{}},"data":[{},{}]}}
Get Groups
Fetch a list of groups filtered by name in Cisco Secure Endpoint.
Endpoint
- URL: /v1/groups
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.name | string | Optional | Parameters for the Get Groups action |
parameters.limit | number | Optional | To prevent the response from becoming too large, the number of items returned is limited by default to 5000. You can override this value by using the limit query parameter to specify a different number. |
Input Example
{"parameters":{"name":"name","limit":20}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
metadata.results | object | Response data |
metadata.results.total | number | Response data |
metadata.results.current_item_count | number | Response data |
metadata.results.index | number | Response data |
metadata.results.items_per_page | number | Response data |
data | array | Response data |
data.name | string | Response data |
data.description | string | Response data |
data.guid | string | Response data |
data.source | string | Response data |
data.links | object | Response data |
data.links.group | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{},"results":{}},"data":[{}]}}
Get Host Firewall configuration
Get the details of a Host Firewall configuration in Cisco Secure Endpoint using organizationIdentifier and configurationGuid as path parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/configurations/{{configurationGuid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.configurationGuid | string | Required | The GUID of the configuration. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","configurationGuid":"d44d84e2-cfbe-4d35-ad96-3de57188a2ad"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.edit | string | Output field: meta.edit |
data | object | Response data |
data.id | number | Response data |
data.guid | string | Response data |
data.name | string | Response data |
data.description | string | Response data |
data.defaultAction | string | Response data |
data.updatedAt | string | Response data |
data.updatedBy | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"edit":"/v3/organizations/sdfvsdfkn5nj3kjhn3we/host_firewall/configurations/e2b62351-067..."},"data":{"id":3345,"guid":"aa4d84e2-cfbe-4d35-ad96-44e57188a2ab","name":"Configuration name","description":"Configuration description","defaultAction":"allow","updatedAt":"2023-09-12T21:19:53.201Z","updatedBy":"Jane Doe"}}}
Get Policy USB Mass Storage Device Control
Retrieve USB mass storage device control settings for a specific policy in Cisco Secure Endpoint using organization identifier and policy GUID.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies/{{policy_guid}}/device_control_configuration/usb_mass_storage
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
path_parameters.policy_guid | string | Required | GUID of the policy to read device control from. |
Input Example
{"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policy_guid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.canonical | string | Output field: meta.canonical |
meta.errors | array | Error message if any |
data | object | Response data |
data.guid | string | Response data |
data.name | string | Response data |
data.description | string | Response data |
data.permitted | boolean | Response data |
Output Example
{"status_code":200,"response_headers":{"content-type":"application/json"},"reason":"OK","json_body":{"meta":{"canonical":"/v3/organizations/nhA6c9DGEyFDEeiHE1hdAgAV/device_control/configurations/aa4d84e..."},"data":{"guid":"aa4d84e2-cfbe-4d35-ad96-44e57188a2ad","name":"Main Config","description":"Config description","permitted":true}}}
Get Policy Windows Portable Device Control
Get Windows portable device control configuration for a policy in Cisco Secure Endpoint using organization identifier and policy GUID.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies/{{policy_guid}}/device_control_configuration/windows_portable_device
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
path_parameters.policy_guid | string | Required | GUID of the policy to read WPD device control from. |
Input Example
{"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policy_guid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.canonical | string | Output field: meta.canonical |
meta.errors | array | Error message if any |
data | object | Response data |
data.guid | string | Response data |
data.name | string | Response data |
data.description | string | Response data |
data.permitted | boolean | Response data |
Output Example
{"status_code":200,"response_headers":{"content-type":"application/json"},"reason":"OK","json_body":{"meta":{"canonical":"/v3/organizations/nhA6c9DGEyFDEeiHE1hdAgAV/device_control/configurations/aa4d84e..."},"data":{"guid":"aa4d84e2-cfbe-4d35-ad96-44e57188a2ad","name":"Main Config","description":"Config description","permitted":true}}}
Isolate Computer
Request isolation for a computer in Cisco Secure Endpoint using the connector GUID as a path parameter.
Endpoint
- URL: /v1/computers/{{connector_guid}}/isolation
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.connector_guid | string | Required | Parameters for the Isolate Computer action |
comment | string | Optional | Parameter for Isolate Computer |
Input Example
{"json_body":{"comment":"A comment"},"path_parameters":{"connector_guid":"bad2c522-3052-4d75-93a0-832d6283c299"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
data | object | Response data |
data.available | boolean | Response data |
data.status | string | Response data |
data.unlock_code | string | Response data |
data.comment | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{}},"data":{"available":true,"status":"pending_start","unlock_code":"unlockme","comment":"this is a comment about locking the computer"}}}
List Computers Using a Policy
Retrieve a list of computers associated with a specified policy and organization in Cisco Secure Endpoint. Requires organizationIdentifier, policyGuid, and size parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/exclusion_sets
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.size | number | Required | Limits the number of computers returned. |
parameters.start | number | Optional | Zero-based index of first computer to include (API default 0). |
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"parameters":{"size":50,"start":0},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.start | number | Output field: meta.start |
meta.size | number | Output field: meta.size |
meta.total | number | Output field: meta.total |
data | array | Response data |
data.hostname | string | Response data |
data.guid | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"start":0,"size":10,"total":11},"data":[{"hostname":"Demo_SFEicar","guid":"c47e67f4-acc9-42da-8af7-16ed2c990f7d"},{"hostname":"Demo_Tinba","guid":"84e4216a-4aee-484b-920d-78c6ae04321b"},{"hostname":"Demo_Command_Line_Arguments_Meterpreter","guid":"8cd2efa5-4fd6-4b3a-9d67-963b5238899a"}]}}
List Exclusion Sets Assigned to a Policy
Retrieve a list of exclusion sets assigned to a specified policy and organization in Cisco Secure Endpoint. Requires organizationIdentifier, policyGuid, and size parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/exclusion_sets
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.size | number | Required | Number of exclusion sets to include (API default 50). |
parameters.start | number | Optional | Zero-based index of first exclusion set to include (API default 0). |
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"parameters":{"size":50,"start":0},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.start | number | Output field: meta.start |
meta.size | number | Output field: meta.size |
meta.total | number | Output field: meta.total |
data | array | Response data |
data.name | string | Response data |
data.guid | string | Response data |
data.operatingSystem | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"start":0,"size":1,"total":40},"data":[{}]}}
List Host Firewall Configurations
Retrieve a list of host firewall configurations for a specified organization in Cisco Secure Endpoint. Requires organizationIdentifier and size parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/configurations
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.size | number | Required | Desired number of returned entries. |
parameters.start | number | Optional | Starting position or offset of the desired first entry. |
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
Input Example
{"parameters":{"size":2,"start":0},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.start | number | Output field: meta.start |
meta.size | number | Output field: meta.size |
meta.total | number | Output field: meta.total |
meta.create | string | Output field: meta.create |
data | array | Response data |
data.id | number | Response data |
data.guid | string | Response data |
data.name | string | Response data |
data.description | string | Response data |
data.defaultAction | string | Response data |
data.updatedAt | string | Response data |
data.updatedBy | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"start":0,"size":2,"total":10,"create":"/v3/organizations/<organizationIdentifier>/host_firewall/configurations"},"data":[{},{}]}}
List of Groups Used by a Policy
Retrieve a list of groups associated with a specified policy and organization in Cisco Secure Endpoint. Requires organizationIdentifier, policyGuid, and size parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/groups
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.size | number | Required | Number of groups to include (API default 50). |
parameters.start | number | Optional | Zero-based index of first group to include (API default 0). |
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"parameters":{"size":50,"start":0},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.start | number | Output field: meta.start |
meta.size | number | Output field: meta.size |
meta.total | number | Output field: meta.total |
data | array | Response data |
data.name | string | Response data |
data.guid | string | Response data |
data.permitted | boolean | Response data |
data.parentGuid | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"start":0,"size":10,"total":2},"data":[{},{}]}}
List Organization Policies
List policies for an organization in Cisco Secure Endpoint using optional filters like organization identifier and size.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
parameters.size | number | Required | Maximum number of policies to return (API default 50). |
parameters.start | number | Optional | Zero-based index of first policy to include (API default 0). |
parameters.sortBy | string | Optional | Sort field name, product, or modified. |
parameters.direction | string | Optional | Sort direction asc or desc (API default asc). |
parameters.policyType | string | Optional | Filter by policy type network, mobile, or workstation. |
parameters.operatingSystem | string | Optional | Filter by windows, mac, linux, android, or ios. |
parameters.orbital | string | Optional | Filter by orbital enabled or disabled. |
parameters.search | string | Optional | Filter policies matching the search string. |
parameters.filter | string | Optional | Filter by device control GUID (e.g. deviceControl==guid). |
Input Example
{"parameters":{"size":50,"start":0,"sortBy":"name","direction":"asc"},"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.start | number | Output field: meta.start |
meta.size | number | Output field: meta.size |
meta.total | number | Output field: meta.total |
meta.create | string | Output field: meta.create |
data | array | Response data |
data.name | string | Response data |
data.guid | string | Response data |
data.description | string | Response data |
data.createdAt | string | Response data |
data.updatedAt | string | Response data |
data.serialNumber | number | Response data |
data.operatingSystem | string | Response data |
data.policyType | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-type":"application/json"},"reason":"OK","json_body":{"meta":{"start":0,"size":1,"total":100,"create":"/v3/organizations/nhA6c9DGEyFDEeiHE1hdAgAV/policies"},"data":[{}]}}
List Organization Policy Types
List available policy types and operating systems for a specified organization in Cisco Secure Endpoint using the organization identifier.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policy_types
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
Input Example
{"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
data | array | Response data |
data.name | string | Response data |
data.operatingSystems | array | Response data |
data.operatingSystems.name | string | Response data |
data.operatingSystems.hasConnectorSupport | boolean | Response data |
data.operatingSystems.distributions | array | Response data |
data.operatingSystems.distributions.guid | string | Response data |
data.operatingSystems.distributions.name | string | Response data |
data.operatingSystems.distributions.version | string | Response data |
data.operatingSystems.distributions.organization | string | Response data |
data.operatingSystems.distributions.minimumSupportVersion | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-type":"application/json"},"reason":"OK","json_body":{"meta":{},"data":[{},{},{}]}}
List the Network Control Lists for a Policy
Return a list of network control lists for a specified policy and organization in Cisco Secure Endpoint. Requires organizationIdentifier, policyGuid, and size parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/network_control_lists
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.size | number | Required | Number of network control lists to include (API default 50). |
parameters.start | number | Optional | Zero-based index of first network control list to include (API default 0). |
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"parameters":{"size":50,"start":0},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.start | number | Output field: meta.start |
meta.size | number | Output field: meta.size |
meta.total | number | Output field: meta.total |
data | array | Response data |
data.guid | string | Response data |
data.name | string | Response data |
data.type | string | Response data |
data.permitted | boolean | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"start":0,"size":5,"total":2},"data":[{},{}]}}
List the Proxy Settings for a Policy
Retrieve proxy settings for a specified policy and organization in Cisco Secure Endpoint. Requires organizationIdentifier and policyGuid as path parameters.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/proxy
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.proxyType | string | Response data |
data.hostname | string | Response data |
data.port | number | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"proxyType":"http_proxy","hostname":"exampleHostname","port":1234}}}
Move Host to Group
Move a host to a specified group in Cisco Secure Endpoint using connector_guid and group_guid.
Endpoint
- URL: /v1/computers/{{connector_guid}}
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.connector_guid | string | Required | Parameters for the Move Host to Group action |
parameters.group_guid | string | Required | Parameters for the Move Host to Group action |
Input Example
{"parameters":{"group_guid":"6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"},"path_parameters":{"connector_guid":"bad2c522-3052-4d75-93a0-832d6283c299"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
data | object | Response data |
data.connector_guid | string | Response data |
data.hostname | string | Response data |
data.windows_processor_id | string | Response data |
data.active | boolean | Response data |
data.links | object | Response data |
data.links.computer | string | Response data |
data.links.trajectory | string | Response data |
data.links.group | string | Response data |
data.connector_version | string | Response data |
data.operating_system | string | Response data |
data.os_version | string | Response data |
data.internal_ips | array | Response data |
data.external_ip | string | Response data |
data.group_guid | string | Response data |
data.install_date | string | Response data |
data.is_compromised | boolean | Response data |
data.demo | boolean | Response data |
data.csc_id | string | Response data |
Output Example
{"status_code":202,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{}},"data":{"connector_guid":"bad2c522-3052-4d75-93a0-832d6283c299","hostname":"Demo_AMP","windows_processor_id":"195b0d8736e2af4","active":true,"links":{},"connector_version":"99.0.99.20946","operating_system":"Windows 10","os_version":"10.0.19044.1466","internal_ips":[],"external_ip":"xxx.xxx.xx...
Remove an Exclusion Set from a Policy
Remove an exclusion set from a specified policy and organization in Cisco Secure Endpoint using organizationIdentifier, policyGuid, and exclusionSetGuid.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/policies/{{policyGuid}}/exclusion_sets/{{exclusionSetGuid}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.policyGuid | string | Required | The GUID of the policy. |
path_parameters.exclusionSetGuid | string | Required | The GUID of the exclusion set. |
Input Example
{"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policyGuid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8","exclusionSetGuid":"3b8b0233-bcdd-484f-8954-21d24a93544b"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Remove Policy USB Mass Storage Device Control
Remove USB mass storage device control configuration from a policy in Cisco Secure Endpoint using organization identifier and policy GUID.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies/{{policy_guid}}/device_control_configuration/usb_mass_storage
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
path_parameters.policy_guid | string | Required | GUID of the policy to clear device control from. |
Input Example
{"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policy_guid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.errors | array | Error message if any |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content"}
Remove Policy Windows Portable Device Control
Remove Windows Portable Device control configuration from a policy in Cisco Secure Endpoint using organization identifier and policy GUID.
Endpoint
- URL: /v3/organizations/{{organization_identifier}}/policies/{{policy_guid}}/device_control_configuration/windows_portable_device
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organization_identifier | string | Required | Organization identifier for the Secure Endpoint tenant. |
path_parameters.policy_guid | string | Required | GUID of the policy to clear WPD device control from. |
Input Example
{"path_parameters":{"organization_identifier":"nhA6c9DGEyFDEeiHE1hdAgAV","policy_guid":"dcbdc51f-5482-4add-8c33-ac7f161fc5e8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.errors | array | Error message if any |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content"}
Show Host Firewall configuration Rules
Retrieve a paginated list of host firewall configuration rules in Cisco Secure Endpoint using organizationIdentifier, configurationGuid, and size.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/configurations/{{configurationGuid}}/rules
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.size | number | Required | Desired number of returned entries. |
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.configurationGuid | string | Required | The GUID of the configuration. |
Input Example
{"parameters":{"size":2},"path_parameters":{"organizationIdentifier":"nhA6c9DGEyFDEeiHE1hdAgAV","configurationGuid":"d44d84e2-cfbe-4d35-ad96-3de57188a2ad"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.start | number | Output field: meta.start |
meta.size | number | Output field: meta.size |
meta.total | number | Output field: meta.total |
data | array | Response data |
data.0 | object | Response data |
data.0.name | string | Response data |
data.0.guid | string | Response data |
data.1 | object | Response data |
data.1.name | string | Response data |
data.1.guid | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"start":0,"size":2,"total":10},"data":[[]]}}
Unisolate Computer
Stop isolation on a computer in Cisco Secure Endpoint using the connector GUID.
Endpoint
- URL: /v1/computers/{{connector_guid}}/isolation
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.connector_guid | string | Required | Parameters for the Unisolate Computer action |
comment | string | Optional | Parameter for Unisolate Computer |
Input Example
{"json_body":{"comment":"A comment"},"path_parameters":{"connector_guid":"bad2c522-3052-4d75-93a0-832d6283c299"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
metadata | object | Response data |
metadata.links | object | Response data |
metadata.links.self | string | Response data |
data | object | Response data |
data.available | boolean | Response data |
data.status | string | Response data |
data.unlock_code | string | Response data |
data.comment | string | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 09 Nov 2023 20:37:23 GMT"},"reason":"OK","json_body":{"version":"v1.2.0","metadata":{"links":{}},"data":{"available":true,"status":"pending_stop","unlock_code":"unlockme","comment":"this is a comment about unlocking"}}}
Update Host Firewall Rule
Update a Host Firewall rule in Cisco Secure Endpoint using organizationIdentifier, ruleGuid, and parameters like name, action, direction, protocol, and more.
Endpoint
- URL: /organizations/{{organizationIdentifier}}/host_firewall/rules/{{ruleGuid}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.organizationIdentifier | string | Required | The identifier of the organization. |
path_parameters.ruleGuid | string | Required | The GUID of the rule. |
name | string | Optional | Name of the configuration rule. |
action | string | Optional | Action to take when a request matches the rule. |
direction | string | Optional | Direction of the rule. |
protocol | string | Optional | Protocol of the rule. |
audit | boolean | Optional | Whether to audit the rule. |
localIp | string | Optional | Valid IPv4 addresses, CIDR blocks and comma or new line separated lists. |
localPorts | string | Optional | Local address port. |
remoteIp | string | Optional | Valid IPv4 addresses, CIDR blocks and comma or new line separated lists. |
remotePorts | string | Optional | Remote address port. |
ipFamily | string | Optional | IP family of the rule. |
applicationPaths | string | Optional | A comma separated list of absolute paths. |
Input Example
{"json_body":{"name":"Rule name","action":"block","direction":"any","protocol":"any","audit":false,"localIp":"any","localPorts":"any","remoteIp":"any","remotePorts":"any","ipFamily":"ipv4","applicationPaths":"any"},"path_parameters":{"organizationIdentifier":"string","ruleGuid":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Response Headers
Header | Description | Example |
|---|---|---|
content-length | The length of the response body in bytes | 140 |
content-type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 09 Nov 2023 20:37:23 GMT |