Skip to content

SOC API reference (generated)

Auto-generated from the live SOC OpenAPI spec by scripts/sync-api-refs.ts (DOCS-160). Do not hand-edit. Complements the semantic reference in this section.

Title: Cirius SOC · version: 1.0.0 · endpoints: 144

MethodPathSummary
DELETE/api/agents/runsDelete Runs
DELETE/api/incidents/{incident_id}/links/{linked_id}Delete Link
DELETE/api/maintenance/{window_id}Delete Window
DELETE/api/rules/{rule_id}Delete Rule
DELETE/api/webhooks/{webhook_id}Delete Webhook
GET/Root
GET/agents/healthAgent Health Ui
GET/api/agent-decisionsList Decisions
GET/api/agents/healthGet Health
GET/api/agents/runsList Runs
GET/api/assets/by-ip/{ip}Get Asset By Ip Api
GET/api/assets/{system}Get Asset Api
GET/api/assetsList Assets Api
GET/api/attack-team/campaignsList Campaign Summaries
GET/api/changes/List Changes
GET/api/changes/recentGet Recent Changes
GET/api/changes/{change_id}Get Change
GET/api/detections/{detection_id}Get Detection
GET/api/detectionsList Detections
GET/api/events/statsEvents Stats
GET/api/incidents/List Incidents
GET/api/incidents/actor-summaryActor Summary
GET/api/incidents/closed-patternsClosed Patterns
GET/api/incidents/detection-efficacyDetection Efficacy
GET/api/incidents/exportExport Incidents
GET/api/incidents/kg-queueKg Queue
GET/api/incidents/newly-openedList Newly Opened
GET/api/incidents/openList Open Incidents
GET/api/incidents/pending-analystList Pending Analyst
GET/api/incidents/prior-verdictsPrior Verdicts
GET/api/incidents/resolvedList Resolved Incidents
GET/api/incidents/summaryIncident Summary
GET/api/incidents/suppression-effectivenessSuppression Effectiveness
GET/api/incidents/type-summaryIncident Type Summary
GET/api/incidents/unenriched-openList Unenriched Open
GET/api/incidents/{incident_id}/adjacentGet Adjacent Incidents
GET/api/incidents/{incident_id}/auditList Audit
GET/api/incidents/{incident_id}/commentsList Comments
GET/api/incidents/{incident_id}/ioc-matchesIoc Matches
GET/api/incidents/{incident_id}/linksList Links
GET/api/incidents/{incident_id}Get Incident
GET/api/known-good/staleList Stale Rules
GET/api/known-good/statsKnown Good Stats
GET/api/known-goodList Rules Api
GET/api/maintenance/List Windows
GET/api/maintenance/activeGet Active Windows
GET/api/metrics/Get Metrics
GET/api/metrics/analyst-workloadAnalyst Workload
GET/api/metrics/environment-breakdownEnvironment Breakdown
GET/api/metrics/exportExport Metrics
GET/api/metrics/phi-exposurePhi Exposure
GET/api/metrics/severity-breakdownSeverity Breakdown
GET/api/metrics/soc-on-call-handoffSoc On Call Handoff
GET/api/metrics/weekly-trendWeekly Trend
GET/api/mini-trigger/latestGet Latest
GET/api/playbooks/runs/{run_id}Get Run
GET/api/playbooks/runsList Runs
GET/api/playbooks/{playbook_id}Get Playbook
GET/api/playbooksList Playbooks
GET/api/rules/{rule_id}/hitsGet Rule Hits
GET/api/rules/{rule_id}Get Rule
GET/api/rulesList Rules
GET/api/search/facetsSearch Facets
GET/api/search/savedList Saved Searches
GET/api/tenants/List Tenants
GET/api/tenants/{tenant_id}Get Tenant
GET/api/threat-intel/cacheGet Cache
GET/api/threat-intel/{intel_id}Get Threat Intel
GET/api/threat-intelList Threat Intel
GET/api/webhooks/List Webhooks
GET/changes/Changes List
GET/changes/{change_id}Change Detail
GET/dashboardDashboard Redirect
GET/detections/Detections List
GET/healthHealth
GET/incidents/Incidents List
GET/incidents/{incident_id}Incident Detail
GET/known-good/List Rules Ui
GET/known-good/partialList Rules Partial
GET/maintenance/Maintenance Index
GET/metrics/Metrics Ui
GET/playbooks/Playbooks List
GET/playbooks/partialPlaybooks Partial
GET/playbooks/{playbook_id}Playbook Detail
GET/robots.txtRobots
GET/rulesRules Page
GET/threat-intel/Threat Intel List
GET/webhooks/Webhooks Ui
PATCH/api/assets/{system}/classifyClassify Asset Api
PATCH/api/assets/{system}/reclassifyReclassify Asset Api
PATCH/api/changes/{change_id}Update Change
PATCH/api/incidents/{incident_id}Patch Incident
PATCH/api/known-good/{rule_id}Patch Rule Api
PATCH/api/maintenance/{window_id}Update Window
PATCH/api/rules/{rule_id}Patch Rule
PATCH/api/tenants/{tenant_id}Update Tenant
PATCH/api/webhooks/{webhook_id}Update Webhook
POST/api/agent-decisionsCreate Decision
POST/api/agents/runsReport Run
POST/api/agents/self-checkSelf Check
POST/api/assets/{system}/sources/{source}Write Source Bucket
POST/api/attack-team/campaignsRecord Campaign Summary
POST/api/changes/Create Change
POST/api/detection/queries/naMark Not Applicable
POST/api/detection/queriesRegister Agent Queries
POST/api/detections/{detection_id}/toggleToggle Detection
POST/api/detectionsCreate Detection
POST/api/incidents/Create Incident
POST/api/incidents/bulk-reset-newBulk Reset To New
POST/api/incidents/bulk-resolveBulk Resolve
POST/api/incidents/refresh-slaRefresh Sla
POST/api/incidents/{incident_id}/analyst-decisionAnalyst Decision
POST/api/incidents/{incident_id}/commentsAdd Comment
POST/api/incidents/{incident_id}/detection-enrichmentDetection Enrichment
POST/api/incidents/{incident_id}/linksCreate Link
POST/api/incidents/{incident_id}/playbook/{playbook_id}/step/{step_index}Toggle Step
POST/api/incidents/{incident_id}/resolveResolve Incident
POST/api/ingest/findingsIngest Findings
POST/api/known-good/prune-stalePrune Stale Rules
POST/api/known-good/reset-weekly-countersReset Weekly Counters
POST/api/known-good/{rule_id}/hitRecord Hit
POST/api/known-goodCreate Rule Api
POST/api/maintenance/Create Window
POST/api/mini-triggerPost Trigger
POST/api/playbooks/runs/{run_id}/approveApprove Run
POST/api/playbooks/{playbook_id}/toggleToggle Playbook
POST/api/playbooksCreate Playbook
POST/api/rules/{rule_id}/toggleToggle Rule
POST/api/rulesCreate Rule
POST/api/search/eventsSearch Events
POST/api/search/saveSave Search
POST/api/tenants/Create Tenant
POST/api/threat-intel/cacheUpsert Cache
POST/api/threat-intel/{intel_id}/toggleToggle Threat Intel
POST/api/threat-intelCreate Threat Intel
POST/api/webhooks/Create Webhook
POST/known-good/newCreate Rule Ui
POST/known-good/suggestSuggest Rule Ui
POST/known-good/{rule_id}/approveApprove Rule
POST/known-good/{rule_id}/deleteDelete Rule
POST/known-good/{rule_id}/rejectReject Rule
POST/known-good/{rule_id}/toggleToggle Rule
POST/maintenance/Maintenance Create
POST/maintenance/{window_id}/deleteMaintenance Delete

Internal use only — Cirius Group