Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
asc, desc Filter cases by status
NEW, PROCESSING, ESCALATED, HUNTING, MONITORING, CHATOPS, CLOSED Filter cases by verdict
MALICIOUS, SUSPICIOUS, BENIGN Filter cases involving a specific asset
Filter cases by severity
INFORMATIONAL, LOW, MEDIUM, HIGH, CRITICAL Filter cases by asset type
USER, PROCESS, USER_AGENT, FILE, ENDPOINT, LOCATION, IP, DOMAIN Filter cases by exclusion rule
Only include cases that were escalated
Only include cases that were contained
Only include cases that involve mobile devices
Only include cases that involved chat ops
Filter cases by integration platform
microsoft-teams, google-alert-center, reversing-labs, jamf-protect, jamf-pro, thinkst-canary, generic-json, box, hyas-protect, checkpoint-harmony, sms, safebreach, wirespeed, vectra, wiz, microsoft, ipinfo, cisco-umbrella, jira-data-center, windows-event-logs, crowdstrike-falcon, cisco-duo, cisco-meraki, fortianalyzer, jira-cloud, microsoft-entra, have-i-been-pwned, manage-engine-ad-audit-plus, google-directory, mimecast, okta, sentinel-one, slack, aws, kandji, wordfence, generic-syslog, cisco-catalyst, connectwise-psa, email, fortinet ENDPOINT, IDENTITY, CLOUD, EMAIL, NETWORK, DATA, POSTURE, OTHER OTHER__DIAGNOSTIC, OTHER__INFORMATIONAL_EVENT, OTHER__WARNING, OTHER__UNKNOWN, OTHER__DECEPTION, OTHER__CUSTOM_DETECTION, CLOUD__INVOCATION, CLOUD__DISCOVERY, CLOUD__DATA_TRANSFER, CLOUD__PERSISTENCE, ENDPOINT__DISCOVERY, ENDPOINT__EXECUTION, ENDPOINT__LIVE_OFF_THE_LAND, ENDPOINT__NUISANCE, ENDPOINT__MALWARE_DISCOVERY, ENDPOINT__MALWARE_EXECUTION, ENDPOINT__LATE_STAGE, ENDPOINT__PERSISTENCE, ENDPOINT__REMOTE_MANAGEMENT, ENDPOINT__LATERAL_MOVEMENT, ENDPOINT__IMPACT, ENDPOINT__EVASION, ENDPOINT__EXPLOITATION, ENDPOINT__SIMULATION, IDENTITY__LOGIN, IDENTITY__REJECTED_MFA, IDENTITY__DISCOVERY, IDENTITY__BRUTE_FORCE, IDENTITY__PUBLIC_CREDENTIAL_EXPOSURE, IDENTITY__PRIVATE_CREDENTIAL_EXPOSURE, IDENTITY__PERSISTENCE, IDENTITY__ACCOUNT_COMPROMISE, NETWORK__INBOUND_CONNECTION, NETWORK__OUTBOUND_CONNECTION, NETWORK__PHISHING, NETWORK__NOISY, EMAIL__PHISHING, EMAIL__PHISHING_REPORTED, EMAIL__EVASION, EMAIL__MALWARE, EMAIL__MALICIOUS_LINK, EMAIL__GRAYMAIL, EMAIL__SPAM, EMAIL__BUSINESS_EMAIL_COMPROMISE, DATA__DATA_TRANSFER, DATA__DATA_SHARE, POSTURE__POSTURE Filter by creation date