[ { "title":"Security", "url":"/site/security/" }, { "title":"Security API Docs" } ]
Explore Cisco Security APIs
Go straight to the Cisco Security API that fits your use case.
API Docs
Description
Product
Cisco Defense Orchestrator (CDO) is a cloud-based multi-device manager that facilitates management of security policies in highly distributed environments to achieve consistent policy implementation.
Allows users to expedite their investigations by identifying which endpoints have seen a file, create custom file lists, and move endpoints in and out of triage groups.
Cisco empowers DevSecOps with end-to-end insight and control for every component of your applications - cloud and on-prem infrastructure, Kubernetes, Docker, microservices, and end users.
STIX-TAXII API to export events and localized security intelligence from Cognitive Intelligence (CTA) into STIX format. This can then be used to integrate CTA with SIEMs.
The deeper integration between IT, cloud and industrial control networks (ICS) is exposing your industrial operations to cyber threats. Cisco Cyber Vision has been specifically developed for OT and IT teams to work together to ensure production continuity, resilience and safety. You can now deploy Industrial Internet of Things (IIoT) technologies and capture the benefits of your industry digitization efforts.
Duo offers web services accessible via REST APIs, allowing you to customize the two-factor authentication user interface for your mobile, web or desktop app.
Context-rich APIs for exchange of network and endpoint security event data and host information across Firepower Management Center (FMC), Firepower Threat Defense (FTD) and Firepower Chassis Manager.
Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE) is an identity and access control policy platform enabling enterprises to enforce compliance, enhance infrastructure security, and streamline their user network access operations. pxGrid and pxGrid Cloud use the publish-subscribe model to publish ISE contextual information.
Open Source
Immunet is a malware and antivirus protection system that utilizes cloud computing and social networking to provide enhanced community-based security. Snort is an open-source, free and lightweight network intrusion detection system (NIDS) software for Linux and Windows to detect emerging threats. Joy is a BSD-licensed libpcap-based software package for extracting data features from live network traffic or packet capture (pcap) files, using a flow-oriented model similar to that of IPFIX or Netflow, and then representing these data features in JSON
The Cisco Product Security Incident Response Team (PSIRT) openVuln API is a RESTful API that allows technical staff and programmers to build tools that help them do their job more effectively
Content Security
The Cisco Content Security Management Appliance (SMA) centralizes management and reporting functions across multiple Cisco Secure Email and Secure Web appliances. It simplifies administration and planning, improves compliance monitoring, helps to enable consistent enforcement of policy, and enhances threat protection
Secure Network and Cloud Analytics provide comprehensive visibility and network traffic security analytics solution that uses enterprise telemetry from the existing network infrastructure. The Cisco Stealthwatch Data Exporter allows users to take flow data from the Stealthwatch system to be processed and stored by their own application.
SecureX threat response is built upon a collection of APIs which; can be used to integrate your Cisco and third-party security products, automate the incident response process, and manage threat intelligence and security context data in a single location.
Secure Malware Analytics combines advanced sandboxing with threat intelligence into one unified solution to protect organizations from malware. With a robust, context-rich malware knowledge base, you will understand what malware is doing, or attempting to do, how large a threat it poses, and how to defend against it.
Secure Workload (formerly Tetration)
Automate micro-segmentation and gain better threat detection and protection with Cisco Secure Workload. Leverage SecureX integration for broad visibility across your environment for faster, more intelligent detection and response.
CloudLock API
Umbrella APIs
The Cloud Security APIs connect you to services that manage and secure your network elements. Create automated workflows to provision your networks, manage destination lists, research security events, and generate security reports.