Palo Alto Networks Cortex XSOAR (formerly Demisto) is a Security Orchestration, Automation and Response (SOAR) platform. The REST API provides endpoints for managing incidents, indicators of compromise (IOCs), playbooks, integrations, war rooms, evidence, users, roles, investigations, and automation scripts. The API supports incident lifecycle management from creation through investigation, enrichment, remediation, and closure, with playbook execution, indicator enrichment, and evidence tracking. Authentication uses API keys passed in the Authorization header.
27 endpointsJentic publishes the only available OpenAPI specification for Prisma Cloud CSPM API, keeping it validated and agent-ready. Monitor and enforce cloud security posture across AWS, Azure, and GCP environments through 91 endpoints covering alert management, compliance reporting, policy configuration, asset inventory, and cloud account onboarding. The API provides programmatic access to Prisma Cloud's risk scoring, compliance framework mapping (CIS, NIST, SOC 2, PCI-DSS), and multi-cloud asset visibility with bearer token authentication across three regional deployments.
91 endpointsStep 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.