openapi: 3.2.0 info: title: Cybereason Visual Search API version: 23.x description: Cybereason EDR/XDR REST API. contact: name: Cybereason Nest url: https://nest.cybereason.com/documentation/api-documentation license: name: Proprietary servers: - url: https://{tenant}.cybereason.net description: Cybereason tenant variables: tenant: default: example description: Your Cybereason tenant hostname prefix. security: - SessionCookie: [] tags: - name: Visual search paths: /rest/visualsearch/query/simple: post: tags: - Visual search summary: Hunt with a Visual Search query requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/VisualSearchRequest' responses: '200': description: Visual Search response content: application/json: schema: $ref: '#/components/schemas/VisualSearchResponse' operationId: postRestVisualsearchQuerySimple x-operation-id-source: derived components: schemas: VisualSearchResponse: type: object properties: data: type: object additionalProperties: true status: type: string VisualSearchRequest: type: object properties: queryPath: type: array items: type: object properties: requestedType: type: string filters: type: array items: type: object customFields: type: array items: type: string totalResultLimit: type: integer default: 1000 perGroupLimit: type: integer templateContext: type: string example: SPECIFIC securitySchemes: SessionCookie: type: apiKey in: cookie name: JSESSIONID description: Session cookie returned by POST /login.html. BearerAuth: type: http scheme: bearer bearerFormat: JWT description: Available on Cybereason 20.1+ for token-based access. externalDocs: description: Cybereason API documentation url: https://nest.cybereason.com/documentation/api-documentation