Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
asc, desc Filter by case ID or case SID
Filter detections by status
NEW, PROCESSING, ESCALATED, HUNTING, MONITORING, CHATOPS, CLOSED Filter detections by verdict
MALICIOUS, SUSPICIOUS, BENIGN Filter detections involving a specific asset
Filter detections by asset type involved
USER, PROCESS, USER_AGENT, FILE, ENDPOINT, LOCATION, IP, DOMAIN Hide detections that have been excluded
Only show detections that were escalated
Only show detections that were escalated
Only show detections that resulted in containment
Hide detections from demo client teams
Filter detections by category class
ENDPOINT, IDENTITY, CLOUD, EMAIL, NETWORK, DATA, POSTURE, OTHER Filter detections by specific category
OTHER__DIAGNOSTIC, OTHER__INFORMATIONAL_EVENT, OTHER__WARNING, OTHER__UNKNOWN, OTHER__DECEPTION, OTHER__CUSTOM_DETECTION, CLOUD__INVOCATION, CLOUD__DISCOVERY, CLOUD__DATA_TRANSFER, CLOUD__PERSISTENCE, ENDPOINT__DISCOVERY, ENDPOINT__EXECUTION, ENDPOINT__LIVE_OFF_THE_LAND, ENDPOINT__NUISANCE, ENDPOINT__MALWARE_DISCOVERY, ENDPOINT__MALWARE_EXECUTION, ENDPOINT__LATE_STAGE, ENDPOINT__PERSISTENCE, ENDPOINT__REMOTE_MANAGEMENT, ENDPOINT__LATERAL_MOVEMENT, ENDPOINT__IMPACT, ENDPOINT__EVASION, ENDPOINT__EXPLOITATION, ENDPOINT__SIMULATION, IDENTITY__LOGIN, IDENTITY__REJECTED_MFA, IDENTITY__DISCOVERY, IDENTITY__BRUTE_FORCE, IDENTITY__PUBLIC_CREDENTIAL_EXPOSURE, IDENTITY__PRIVATE_CREDENTIAL_EXPOSURE, IDENTITY__PERSISTENCE, IDENTITY__ACCOUNT_COMPROMISE, NETWORK__INBOUND_CONNECTION, NETWORK__OUTBOUND_CONNECTION, NETWORK__PHISHING, NETWORK__NOISY, EMAIL__PHISHING, EMAIL__PHISHING_REPORTED, EMAIL__EVASION, EMAIL__MALWARE, EMAIL__MALICIOUS_LINK, EMAIL__GRAYMAIL, EMAIL__SPAM, EMAIL__BUSINESS_EMAIL_COMPROMISE, DATA__DATA_TRANSFER, DATA__DATA_SHARE, POSTURE__POSTURE Filter detections by exclusion rule ID
Filter detections by severity
INFORMATIONAL, LOW, MEDIUM, HIGH, CRITICAL Filter detections by integration platform
microsoft-teams, google-alert-center, reversing-labs, jamf-protect, jamf-pro, thinkst-canary, generic-json, box, hyas-protect, checkpoint-harmony, sms, safebreach, wirespeed, vectra, wiz, microsoft, ipinfo, cisco-umbrella, jira-data-center, windows-event-logs, crowdstrike-falcon, cisco-duo, cisco-meraki, fortianalyzer, jira-cloud, microsoft-entra, have-i-been-pwned, manage-engine-ad-audit-plus, google-directory, mimecast, okta, sentinel-one, slack, aws, kandji, wordfence, generic-syslog, cisco-catalyst, connectwise-psa, email, fortinet Filter by creation date