openapi: 3.2.0 info: title: CTIA GraphQL API version: 4178275a824512c2fd3a2acdb0e8277233919054 v2.71.0 license: name: All Rights Reserved url: '' contact: name: 'Cisco Security Business Group -- Advanced Threat ' url: http://github.com/threatgrid/ctia email: cisco-intel-api-support@cisco.com description: 'A Threat Intelligence API service This API provides a mechanism for making Judgements on the Disposition of Observables, which are then distilled into a final Verdict.' x-provenance: method: harvested authored_by: Cisco XDR (CTIA) harvested_by: API Evangelist harvested_on: '2026-08-19' first_party: true note: Published by Cisco. Retrieved unmodified except for this x-provenance block. provider_published: true x-evidence: - type: source url: https://private.intel.amp.cisco.com/index.html - type: raw url: https://private.intel.amp.cisco.com/swagger.json servers: - url: / security: - JWT: [] - oauth2: - private-intel - private-intel:read - private-intel:write - casebook - casebook:read - casebook:write tags: - name: Graph QL paths: /ctia/graphql: post: tags: - Graph QL responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/RelayGraphQLResponse' application/x-yaml: schema: $ref: '#/components/schemas/RelayGraphQLResponse' application/edn: schema: $ref: '#/components/schemas/RelayGraphQLResponse' application/transit+json: schema: $ref: '#/components/schemas/RelayGraphQLResponse' application/transit+msgpack: schema: $ref: '#/components/schemas/RelayGraphQLResponse' summary: 'EXPERIMENTAL: Executes a Relay compatible GraphQL query' description: Requires capabilities list-actors, list-asset-mappings, list-asset-properties, list-assets, list-attack-patterns, list-campaigns, list-coas, list-data-tables, list-feedbacks, list-identity-assertions, list-incidents, list-indicators, list-investigations, list-judgements, list-malwares, list-relationships, list-sightings, list-target-records, list-tools, list-verdicts, list-vulnerabilities, list-weaknesses, read-actor, read-asset, read-asset-mapping, read-asset-properties, read-attack-pattern, read-campaign, read-coa, read-data-table, read-feedback, read-identity-assertion, read-incident, read-indicator, read-investigation, read-judgement, read-malware, read-relationship, read-sighting, read-target-record, read-tool, read-vulnerability, read-weakness. requestBody: content: application/json: schema: $ref: '#/components/schemas/RelayGraphQLQuery' application/x-yaml: schema: $ref: '#/components/schemas/RelayGraphQLQuery' application/edn: schema: $ref: '#/components/schemas/RelayGraphQLQuery' application/transit+json: schema: $ref: '#/components/schemas/RelayGraphQLQuery' application/transit+msgpack: schema: $ref: '#/components/schemas/RelayGraphQLQuery' description: a Relay compatible GraphQL body required: true operationId: postCtiaGraphql x-operation-id-source: derived components: schemas: RelayGraphQLResponse: type: object properties: data: {} errors: type: array items: {} additionalProperties: false required: - data RelayGraphQLQuery: description: a Relay compatible GraphQL body type: object properties: query: type: string operationName: type: - string - 'null' variables: {} additionalProperties: false required: - query securitySchemes: JWT: type: apiKey in: header name: Authorization description: 'Ex: Bearer \' oauth2: type: oauth2 flows: authorizationCode: scopes: private-intel: Private Intelligence Full Access private-intel:read: Private Intelligence Read Access private-intel:write: Private Intelligence Write Access casebook: Casebook Full Access casebook:read: Casebook Read Access casebook:write: Casebook Write Access authorizationUrl: https://visibility.amp.cisco.com/iroh/oauth2/authorize tokenUrl: https://visibility.amp.cisco.com/iroh/oauth2/token