Authorizations
Bearer authentication header of the form Bearer <token>
, where <token>
is your auth token.
Body
application/json
Name of the custom detection
Category of the custom detection
Available options:
OTHER__DIAGNOSTIC
, OTHER__INFORMATIONAL_EVENT
, OTHER__WARNING
, OTHER__UNKNOWN
, OTHER__DECEPTION
, OTHER__CUSTOM_DETECTION
, CLOUD__INVOCATION
, CLOUD__DISCOVERY
, CLOUD__DATA_TRANSFER
, CLOUD__PERSISTENCE
, ENDPOINT__DISCOVERY
, ENDPOINT__EXECUTION
, ENDPOINT__LIVE_OFF_THE_LAND
, ENDPOINT__NUISANCE
, ENDPOINT__MALWARE_DISCOVERY
, ENDPOINT__MALWARE_EXECUTION
, ENDPOINT__LATE_STAGE
, ENDPOINT__PERSISTENCE
, ENDPOINT__REMOTE_MANAGEMENT
, ENDPOINT__LATERAL_MOVEMENT
, ENDPOINT__IMPACT
, ENDPOINT__EVASION
, IDENTITY__LOGIN
, IDENTITY__REJECTED_MFA
, IDENTITY__DISCOVERY
, IDENTITY__BRUTE_FORCE
, IDENTITY__PUBLIC_CREDENTIAL_EXPOSURE
, IDENTITY__PRIVATE_CREDENTIAL_EXPOSURE
, IDENTITY__PERSISTENCE
, IDENTITY__ACCOUNT_COMPROMISE
, NETWORK__INBOUND_CONNECTION
, NETWORK__OUTBOUND_CONNECTION
, NETWORK__PHISHING
, NETWORK__NOISY
, EMAIL__PHISHING
, EMAIL__PHISHING_REPORTED
, EMAIL__MALWARE
, EMAIL__MALICIOUS_LINK
, EMAIL__GRAYMAIL
, EMAIL__SPAM
, EMAIL__BUSINESS_EMAIL_COMPROMISE
, DATA__DATA_TRANSFER
, DATA__DATA_SHARE
, POSTURE__POSTURE
Query of the custom detection
Description of the custom detection
Response
Unique identifier for the custom detection
Name of the custom detection
Category of the custom detection
Query of the custom detection
Timestamp when the custom detection was last run
Timestamp when the custom detection was created
Whether the custom detection is enabled
Email or ID of the user who created the custom detection
Description of the custom detection