Public API Reference

Overview

The EDR Public API allows you to integrate EDR security data with external applications and automate access to security findings such as alerts, incidents, and threat hunting alerts.

Note that the EDR Public APIs are accessible only to users with the SOC Manager role.

The complete API reference is available through the Scalar API documentation hosted on your EDR server.

API Workflow

Authenticate

↓

Get JWT access token (Valid for one hour)

↓

Retrieve alerts / incidents / threat hunting data (Security Findings APIs)

↓

Retrieve Filtered Data (Filters APIs)

↓

Access token expires?

→ Yes: Refresh token (Valid for 24 hours) → Continue API requests

→ No: Continue API requests

When the refresh token expires, use the Login API with your credentials to generate a new access token and refresh token.

What You Can Do with the APIs

The EDR Public APIs enable you to integrate security data and capabilities with your applications, workflows, and security tools. After you open the API reference in Scalar, you can:

  • Integrate and automate security operations: Retrieve security data through APIs and integrate it with external security, monitoring, analysis, reporting, dashboard, and workflow tools to automate security tasks and create customised views.

  • Authenticate API access: The Authentication API provides an access token required to securely access the Alerts, Incidents, and Threat Hunting APIs.

  • Retrieve security data: Available APIs provide access to alerts, incidents, and threat-hunting data from the EDR platform.

  • Filter security data: Provided filters enable refinement of API requests to retrieve alerts, incidents, and threat-hunting data based on specific criteria.

  • Build customised queries: Available filters allow API requests to be refined to retrieve only the relevant security data.

  • Use sample requests and responses: Refer to the available sample requests and responses to understand API usage and try out the APIs with supported parameters.

To explore the available APIs, request parameters, response formats, and integration options, refer Access the API Reference section to open the API’s in Scalar.

Access the API Reference

To access the API reference:

  1. Enter the following URL with your server details:
  2. https://< worker_IP/FQDN >/scalar

  3. The Scalar API Reference opens in a new tab in your browser, providing the available APIs and their documentation.
Was this page helpful?