Authorizations
Bearer authentication header of the form Bearer <token>
, where <token>
is your auth token.
Path Parameters
Custom detection identifier
Body
application/json
Name of the custom detection
Query of the custom detection
Description of the custom detection
Whether the custom detection is enabled
Category of the custom detection
Available options:
OTHER__DIAGNOSTIC
, OTHER__INFORMATIONAL_EVENT
, OTHER__WARNING
, OTHER__UNKNOWN
, OTHER__DECEPTION
, OTHER__CUSTOM_DETECTION
, CLOUD__INVOCATION
, CLOUD__DISCOVERY
, CLOUD__DATA_TRANSFER
, CLOUD__PERSISTENCE
, ENDPOINT__DISCOVERY
, ENDPOINT__EXECUTION
, ENDPOINT__LIVE_OFF_THE_LAND
, ENDPOINT__NUISANCE
, ENDPOINT__MALWARE_DISCOVERY
, ENDPOINT__MALWARE_EXECUTION
, ENDPOINT__LATE_STAGE
, ENDPOINT__PERSISTENCE
, ENDPOINT__REMOTE_MANAGEMENT
, ENDPOINT__LATERAL_MOVEMENT
, ENDPOINT__IMPACT
, ENDPOINT__EVASION
, IDENTITY__LOGIN
, IDENTITY__REJECTED_MFA
, IDENTITY__DISCOVERY
, IDENTITY__BRUTE_FORCE
, IDENTITY__PUBLIC_CREDENTIAL_EXPOSURE
, IDENTITY__PRIVATE_CREDENTIAL_EXPOSURE
, IDENTITY__PERSISTENCE
, IDENTITY__ACCOUNT_COMPROMISE
, NETWORK__INBOUND_CONNECTION
, NETWORK__OUTBOUND_CONNECTION
, NETWORK__PHISHING
, NETWORK__NOISY
, EMAIL__PHISHING
, EMAIL__PHISHING_REPORTED
, EMAIL__MALWARE
, EMAIL__MALICIOUS_LINK
, EMAIL__GRAYMAIL
, EMAIL__SPAM
, EMAIL__BUSINESS_EMAIL_COMPROMISE
, DATA__DATA_TRANSFER
, DATA__DATA_SHARE
, POSTURE__POSTURE
Response
Unique identifier for the custom detection
Name of the custom detection
Category of the custom detection
Query of the custom detection
Timestamp when the custom detection was last run
Timestamp when the custom detection was created
Whether the custom detection is enabled
Email or ID of the user who created the custom detection
Description of the custom detection