Qodex.ai
Qodex.ai
Introduction
1-Secure Endpoint
Initialize Variables
Initialize: Set Variables
Check Status
Check Status
APIv1 - queries-Audit Logs
All Audit Log TypesAudit Log Type - AllowList
APIv1 - queries-Computers
Search computer by name and store additional valuesSearch computer by IPSpecific computer by GUID Trajectory
APIv1 - queries-Computer Activity (Hunting)-Query for Sightings
Which computer reported URL (Demo data)
APIv1 - queries-Computer Activity (Hunting)-Investigate
Computer ObjectGroup ObjectComputer Trajectory
APIv1 - queries-Endpoint Isolation
Isolation feature availability for endpointIsolation status for endpointIsolation StartIsolation Stop
APIv1 - queries-Events and Event Types-Events Per Computer
Event Type: Behavioral Protection for specific computer
APIv1 - queries-Events and Event Types
All Event TypesComputer Events by SHA256
APIv1 - queries-File List
Show Application Blocking List by nameShow all Simple Custom Detection Lists by name
APIv1 - queries-Forensic Snapshot (Hunting)
List Forensic Snapshots for Computer
APIv1 - queries-Indicators (Hunting)
List all available indicators with Event Count
APIv1 - queries-Vulnerabilities (Hunting)
Vulnerable Applications by GroupGUIDOS Vulnerabilities per ComputerVulnerable Applications by SHA256 and Computers
APIv1 - queries-Compromise Inbox (Hunting)
Compromises - Inbox
APIv1 - queries-Manage ORG-Event Streams
List Event StreamsList Event Stream by ID
APIv1 - queries-Manage ORG-Webhooks
List WebhooksDelete Webhook by ID
APIv1 - queries-Deployment Packages
Create Deployment packageCreate Deployment package Copy
Use Cases-Create and Delete Groups demo
Refill Sub-Group GUID if missing4-Generate Sub-Group5-Move Sub-Group under Top Group6-Delete Top group by GUID7-Delete Sub-group by GUID
APIv3 - queries-1-Generate Bearer Token first
APIv3 Generate Security Cloud API Access TokenAPIv3 Generate SE API Access TokenAPIv3 Access Secure Endpoint API - multiple ORGs
APIv3 - queries-Exclusions
List Exclusion Set Entries - WindowsList Cisco Maintained ExlcusionsCreate Exclusion ListList Exclusion List Property by GUIDChange Exclusion List Property by GUID (Name)Delete Exclusion List
APIv3 - queries-Device Control-DVC: List all configurations
List Device Control Configurations - ALL
APIv3 - queries-Device Control-DVC: Check if configuration exists
DVC: Check BaseRule and update variableDVC: Check exception rule is already there
APIv3 - queries-Device Control-DVC: Add configuration and exeption rule
1-Add a DVC ConfigurationAdd DVC Rule to given DVC configurationList DVC Rulses for given DVC configuration
APIv3 - queries-Device Control-DVC: remove configuration
1a-Update DVC ConfigurationRemove a DVC exeption ruleRemove a DVC Configuration
APIv3 - queries-IOCs
List IOCs
APIv3 - queries-Policies
List all Policy Objects (Search Parameters)List all Policy Types (dynamic Visualizer)Delete Policy Object
APIv3 - queries-Uninstall the connector
Uninstall the connector
APIv3 - queries-Firewall-FW: List all configurations
List Host Firewall Configurations
APIv3 - queries-Firewall-FW Get Host Firewall Configuration Properties by GUID
Get Host Firewall Configuration Properties by GUID
APIv3 - queries-Firewall-FW: List Firewall Configuration Rules
List Firewall Configuratin Rules
APIv3 - queries-Firewall-FW: Get Firewall Rule Details
Get Firewall Rule Details
APIv3 - queries-Firewall-FW: Create/Rename/Delete Firewall Configuration
Create Firewall ConfigurationUpdate Firewall Configuration - Default Action BlockDelete Firewall Configuration
APIv3 - queries-Firewall-FW: Create/Delete Firewall Rule
Create Firewall RuleDelete Firewall Rule
APIv3 - queries-Firewall-FW: My personal FW Test Ruleset
APIv3 Generate Security Cloud API Access Token CopyAPIv3 Generate SE API Access Token CopyCreate Firewall ConfigurationInternetbadguys - Demo Site
2-Orbital
Authorize with Token
1-Orbital Generate Token2-Orbital Check Status
Query Catalog entries
Get public stock query catalogueGet Organization catalog queries
Queries-3-Generate Queries-3a-Probe Endpoints
Probe Linux
Queries-3-Generate Queries-3b-StockQueries
Query by catalog ID: installed_programs_monitoring (Win)
Queries-4-Review Result
4-Orbital Job Status4-Orbital Show Result
Queries-5-Manage ORG
4-List WebhooksDelete Webhook
Scripts-Script Catalog entries
Get all catalog stock queriesGet Organization catalog scripts
Scripts-Get Script Details
Get Script Details by scriptID
Scripts-Script Live Execution
Live execution of a script - os:windows
3-Private Intelligence
1-Generate Bearer Token first
APIv3 Generate SecureX API Access Token
2-My Casebook
Create CasebookShows Casebook ContentDelete Casebook by ID
DemoData_CozyDuke_Casebook
Check: CozyDukeCreate: CozyDukeDelete: CozyDuke
Infos about observable
SHA256: get verdictsSHA256: get judgementsSHA256: get indicatorsIP: get verdictsIP: get judgementsIP: get indicatorsDomain: get verdictsDomain: get judgementsDomain: get indictors
List All CasebooksSearch Casebooks: all contentSearch Casebooks: title onlySearch Casebooks: descriptionCTIA: MetricsCTIA: PropertiesCTIA: StatusCTIA: Version
Introduction
1-Secure Endpoint
Initialize Variables
Initialize: Set Variables
Check Status
Check Status
APIv1 - queries-Audit Logs
All Audit Log TypesAudit Log Type - AllowList
APIv1 - queries-Computers
Search computer by name and store additional valuesSearch computer by IPSpecific computer by GUID Trajectory
APIv1 - queries-Computer Activity (Hunting)-Query for Sightings
Which computer reported URL (Demo data)
APIv1 - queries-Computer Activity (Hunting)-Investigate
Computer ObjectGroup ObjectComputer Trajectory
APIv1 - queries-Endpoint Isolation
Isolation feature availability for endpointIsolation status for endpointIsolation StartIsolation Stop
APIv1 - queries-Events and Event Types-Events Per Computer
Event Type: Behavioral Protection for specific computer
APIv1 - queries-Events and Event Types
All Event TypesComputer Events by SHA256
APIv1 - queries-File List
Show Application Blocking List by nameShow all Simple Custom Detection Lists by name
APIv1 - queries-Forensic Snapshot (Hunting)
List Forensic Snapshots for Computer
APIv1 - queries-Indicators (Hunting)
List all available indicators with Event Count
APIv1 - queries-Vulnerabilities (Hunting)
Vulnerable Applications by GroupGUIDOS Vulnerabilities per ComputerVulnerable Applications by SHA256 and Computers
APIv1 - queries-Compromise Inbox (Hunting)
Compromises - Inbox
APIv1 - queries-Manage ORG-Event Streams
List Event StreamsList Event Stream by ID
APIv1 - queries-Manage ORG-Webhooks
List WebhooksDelete Webhook by ID
APIv1 - queries-Deployment Packages
Create Deployment packageCreate Deployment package Copy
Use Cases-Create and Delete Groups demo
Refill Sub-Group GUID if missing4-Generate Sub-Group5-Move Sub-Group under Top Group6-Delete Top group by GUID7-Delete Sub-group by GUID
APIv3 - queries-1-Generate Bearer Token first
APIv3 Generate Security Cloud API Access TokenAPIv3 Generate SE API Access TokenAPIv3 Access Secure Endpoint API - multiple ORGs
APIv3 - queries-Exclusions
List Exclusion Set Entries - WindowsList Cisco Maintained ExlcusionsCreate Exclusion ListList Exclusion List Property by GUIDChange Exclusion List Property by GUID (Name)Delete Exclusion List
APIv3 - queries-Device Control-DVC: List all configurations
List Device Control Configurations - ALL
APIv3 - queries-Device Control-DVC: Check if configuration exists
DVC: Check BaseRule and update variableDVC: Check exception rule is already there
APIv3 - queries-Device Control-DVC: Add configuration and exeption rule
1-Add a DVC ConfigurationAdd DVC Rule to given DVC configurationList DVC Rulses for given DVC configuration
APIv3 - queries-Device Control-DVC: remove configuration
1a-Update DVC ConfigurationRemove a DVC exeption ruleRemove a DVC Configuration
APIv3 - queries-IOCs
List IOCs
APIv3 - queries-Policies
List all Policy Objects (Search Parameters)List all Policy Types (dynamic Visualizer)Delete Policy Object
APIv3 - queries-Uninstall the connector
Uninstall the connector
APIv3 - queries-Firewall-FW: List all configurations
List Host Firewall Configurations
APIv3 - queries-Firewall-FW Get Host Firewall Configuration Properties by GUID
Get Host Firewall Configuration Properties by GUID
APIv3 - queries-Firewall-FW: List Firewall Configuration Rules
List Firewall Configuratin Rules
APIv3 - queries-Firewall-FW: Get Firewall Rule Details
Get Firewall Rule Details
APIv3 - queries-Firewall-FW: Create/Rename/Delete Firewall Configuration
Create Firewall ConfigurationUpdate Firewall Configuration - Default Action BlockDelete Firewall Configuration
APIv3 - queries-Firewall-FW: Create/Delete Firewall Rule
Create Firewall RuleDelete Firewall Rule
APIv3 - queries-Firewall-FW: My personal FW Test Ruleset
APIv3 Generate Security Cloud API Access Token CopyAPIv3 Generate SE API Access Token CopyCreate Firewall ConfigurationInternetbadguys - Demo Site
2-Orbital
Authorize with Token
1-Orbital Generate Token2-Orbital Check Status
Query Catalog entries
Get public stock query catalogueGet Organization catalog queries
Queries-3-Generate Queries-3a-Probe Endpoints
Probe Linux
Queries-3-Generate Queries-3b-StockQueries
Query by catalog ID: installed_programs_monitoring (Win)
Queries-4-Review Result
4-Orbital Job Status4-Orbital Show Result
Queries-5-Manage ORG
4-List WebhooksDelete Webhook
Scripts-Script Catalog entries
Get all catalog stock queriesGet Organization catalog scripts
Scripts-Get Script Details
Get Script Details by scriptID
Scripts-Script Live Execution
Live execution of a script - os:windows
3-Private Intelligence
1-Generate Bearer Token first
APIv3 Generate SecureX API Access Token
2-My Casebook
Create CasebookShows Casebook ContentDelete Casebook by ID
DemoData_CozyDuke_Casebook
Check: CozyDukeCreate: CozyDukeDelete: CozyDuke
Infos about observable
SHA256: get verdictsSHA256: get judgementsSHA256: get indicatorsIP: get verdictsIP: get judgementsIP: get indicatorsDomain: get verdictsDomain: get judgementsDomain: get indictors
List All CasebooksSearch Casebooks: all contentSearch Casebooks: title onlySearch Casebooks: descriptionCTIA: MetricsCTIA: PropertiesCTIA: StatusCTIA: Version
Home1-Secure EndpointAPIv3 - queries-1-Generate Bearer Token firstAPIv3 Generate SE API Access Token

APIv3 Generate SE API Access Token

POST https://api.amp.cisco.com/v3/access_tokens

Previous
APIv3 Generate Security Cloud API Access Token
Next
APIv3 Access Secure Endpoint API - multiple ORGs