openapi: 3.2.0 info: title: Cybereason Threat Intel API version: 23.x description: Cybereason EDR/XDR REST API. contact: name: Cybereason Nest url: https://nest.cybereason.com/documentation/api-documentation license: name: Proprietary servers: - url: https://{tenant}.cybereason.net description: Cybereason tenant variables: tenant: default: example description: Your Cybereason tenant hostname prefix. security: - SessionCookie: [] tags: - name: Threat Intel paths: /rest/classification_v1/file: get: tags: - Threat Intel summary: Lookup file reputation parameters: - in: query name: hash required: true schema: type: string responses: '200': description: File reputation content: application/json: schema: type: object operationId: getRestClassificationV1File x-operation-id-source: derived /rest/classification_v1/domain: get: tags: - Threat Intel summary: Lookup domain reputation parameters: - in: query name: domain required: true schema: type: string responses: '200': description: Domain reputation content: application/json: schema: type: object operationId: getRestClassificationV1Domain x-operation-id-source: derived /rest/classification_v1/ip: get: tags: - Threat Intel summary: Lookup IP reputation parameters: - in: query name: ip required: true schema: type: string responses: '200': description: IP reputation content: application/json: schema: type: object operationId: getRestClassificationV1Ip x-operation-id-source: derived components: securitySchemes: SessionCookie: type: apiKey in: cookie name: JSESSIONID description: Session cookie returned by POST /login.html. BearerAuth: type: http scheme: bearer bearerFormat: JWT description: Available on Cybereason 20.1+ for token-based access. externalDocs: description: Cybereason API documentation url: https://nest.cybereason.com/documentation/api-documentation