Authorizations
Bearer authentication header of the form Bearer <token>
, where <token>
is your auth token.
Response
Unique identifier for the case
Short identifier for the case
Team ID that owns this case
Timestamp when the case was last notified to the client
Current status of the case
NEW
, PROCESSING
, ESCALATED
, HUNTING
, MONITORING
, CLOSED
Timestamp when the case was created
Array of detection SIDs associated with this case
Whether this case is in test mode
Timestamp when first detection was ingested
Timestamp when first detection was detected by source
Array of log entries for this case
Whether the threat has been contained
Whether the case has been reingested
Verdict assigned to the case
MALICIOUS
, SUSPICIOUS
, BENIGN
Title of the case based on categories and verdict
Array of categories assigned to this case
Whether to exclude this case from mean calculations
Whether this is the first run of the detection
Whether case involves VIP users
Whether case involves high-value assets
Whether case involves mobile devices
Severity level of the case
Numeric value of severity for sorting
Custom name for the case
Timestamp when the case was last updated
Timestamp when the case was closed
Timestamp when verdict was assigned
Number of detections in this case
Mean time to respond in seconds
Name of the team that owns this case
External ticket ID from ticketing system integration
ID of integration used for external ticket
Whether threat was automatically contained
Timestamp when case was responded to
Array of integration platforms involved
Notes or comments about the case
Whether client has been notified about this case
AI-generated summary of the case