# Wirespeed - [Introduction](https://docs.wirespeed.co/introduction.md): Getting started with Wirespeed - [Service Providers](https://docs.wirespeed.co/service-provider.md): Your guide to managing your clients on Wirespeed - [Frequently Asked Questions](https://docs.wirespeed.co/faq.md): Answers to common questions from Wirespeed users - [Introduction to Chat Ops](https://docs.wirespeed.co/chat-ops/introduction.md): What is it and how to get started - [Communication Plan](https://docs.wirespeed.co/chat-ops/communication-plan.md): Introduce your company to chat operations - [I received a message from Wirespeed](https://docs.wirespeed.co/chat-ops/received-message.md): What should I do now? - [Introduction to Remediation](https://docs.wirespeed.co/remediation/introduction.md): Automatic and manual isolation of compromised assets - [User Remediation](https://docs.wirespeed.co/remediation/users.md): Automatically remediate compromised users - [Endpoint Remediation](https://docs.wirespeed.co/remediation/endpoints.md): Isolate servers and workstations - [File Remediation](https://docs.wirespeed.co/remediation/files.md): Quarantine malicious files - [Introduction to Verdicts](https://docs.wirespeed.co/verdicts/introduction.md): Customize how Wirespeed automatically handles your detections - [Introduction to Groups](https://docs.wirespeed.co/groups/introduction.md): Organize assets and control automation behavior with groups and rules - [Introduction to Exclusions](https://docs.wirespeed.co/exclusions/introduction.md): Auto-close detections with exclusions created by Ask Wirespeed and refined by you - [Introduction to Events](https://docs.wirespeed.co/events/introduction.md): Ingest events, logs, and more from your source system into Wirespeed's SIEM - [Advanced Queries](https://docs.wirespeed.co/events/advanced-queries.md): Advanced queries and filtering - [Custom Detections](https://docs.wirespeed.co/events/custom-detections.md): Create detections for activity in your SIEM data - [Off-Platform Detections](https://docs.wirespeed.co/events/automated-custom-edr-detections.md): Review detection rules imported from connected EDR, XDR, and SIEM providers - [Billable Assets](https://docs.wirespeed.co/assets/billable-assets.md): How Wirespeed calculates billable users and endpoints - [Users](https://docs.wirespeed.co/assets/users.md): Users are ingested from your directory integrations and enable ChatOps, VIP identification, and technical user identification. - [Endpoints](https://docs.wirespeed.co/assets/endpoints.md): All endpoints available in your detection integrations are ingested into Wirespeed and correlated across cases. This allows you to identify repeat offenders over time, add special handling for critical assets, and provide Wirespeed more context for case triaging. - [Files](https://docs.wirespeed.co/assets/files.md): Files from your detection integrations are analyzed to determine their nature—malicious or benign. Detection of malicious files considers factors such as the targeted endpoint or user, exclusion status, and findings from our threat intelligence sources. - [IPs](https://docs.wirespeed.co/assets/ips.md): IP addresses are ingested from alerts on your detection integrations that have been previously identified by your detections vendor. Some may be benign and others may be malicious. Malicious IP addresses are determined by their usage of privacy-protecting services like Tor or VPNs and their countrie… - [Locations](https://docs.wirespeed.co/assets/locations.md): A variety of alerts from your detection integrations include location information, usually related to the location of the asset or user triggering alerts. You may view all identified locations underneath Assets > Locations and investigate cases Wirespeed has triaged from each location. - [Processes](https://docs.wirespeed.co/assets/processes.md): Process information is taken from your detection integrations when malicious commands are identified on your endpoints. Process information includes things like the command that was run, the SHA1 and SHA256 of the command, and any threat intelligence we are able to gather related to the process. - [Team](https://docs.wirespeed.co/settings/team.md): Managing your team and users - [Notifications](https://docs.wirespeed.co/settings/notifications.md): Understanding notification types and managing your notification preferences - [Team Roles & Permissions](https://docs.wirespeed.co/settings/roles.md): Understanding team member roles and access levels - [Introduction to Integrations](https://docs.wirespeed.co/integrations/introduction.md): Connect your security stack to enable automated detection and response - [Integration Plans & SKU Mapping](https://docs.wirespeed.co/integrations/sku-mappings.md): Which integrations are included with each Wirespeed plan - [Integration Health](https://docs.wirespeed.co/integrations/integration-health.md): Understanding integration health statuses and how Wirespeed monitors your connected integrations - [Log Forwarders](https://docs.wirespeed.co/integrations/log-forwarders.md): Send logs to Wirespeed using a dedicated forwarder - [1Password](https://docs.wirespeed.co/integrations/1password.md): Monitor sign-in attempts, audit events, and item usage across your 1Password account - [Acronis](https://docs.wirespeed.co/integrations/acronis.md): Import Alert Manager detections from Acronis Cyber Protect Cloud - [Admin By Request](https://docs.wirespeed.co/integrations/admin-by-request.md): Ingest endpoint privilege management security events from Admin By Request - [Agger Labs](https://docs.wirespeed.co/integrations/agger-labs.md): Import anti-ransomware incidents and endpoint inventory from Agger Labs - [Anthropic](https://docs.wirespeed.co/integrations/anthropic.md): Integrate with Anthropic for usage and security event ingestion - [AWS GuardDuty](https://docs.wirespeed.co/integrations/aws.md): Integrate with AWS Guard Duty - [Axonius](https://docs.wirespeed.co/integrations/axonius.md): Import endpoint and asset inventory from Axonius. - [Bitwarden](https://docs.wirespeed.co/integrations/bitwarden.md): Monitor organization events including logins, policy changes, and user activity across your Bitwarden organization - [Box](https://docs.wirespeed.co/integrations/box.md): Integrate with Box.com - [Check Point Firewall (Quantum)](https://docs.wirespeed.co/integrations/checkpoint-firewall.md): Integrate with Check Point Firewall - [Check Point Harmony (Avanan)](https://docs.wirespeed.co/integrations/checkpoint-harmony.md): Integrate with Check Point Harmony - [Cisco Duo](https://docs.wirespeed.co/integrations/cisco-duo.md): Sync users, ingest authentication and activity logs, and remediate users from Cisco Duo - [Cisco Meraki](https://docs.wirespeed.co/integrations/cisco-meraki.md): Forward Cisco Meraki logs to Wirespeed - [Cisco Catalyst](https://docs.wirespeed.co/integrations/cisco-catalyst.md): Forward Cisco Catalyst logs to Wirespeed - [Cisco Secure Access](https://docs.wirespeed.co/integrations/cisco-secure-access.md): Ingest DNS, Proxy, and ZTNA logs from Cisco Secure Access - [Cisco Umbrella](https://docs.wirespeed.co/integrations/cisco-umbrella.md): Ingest DNS records from Cisco Umbrella - [ConnectWise PSA](https://docs.wirespeed.co/integrations/connectwise-psa.md): Automate your MSSP interactions with Wirespeed and ConnectWise - [CrowdStrike](https://docs.wirespeed.co/integrations/crowdstrike-falcon.md): Integrate with CrowdStrike products including Falcon, NG-SIEM, and their identity platform - [Idira (formerly CyberArk)](https://docs.wirespeed.co/integrations/cyberark.md): Ingest audit events and sync users from Idira (formerly CyberArk) Privilege Cloud and Identity - [Darktrace](https://docs.wirespeed.co/integrations/darktrace.md): Ingest AI-powered network detections from Darktrace - [DFIR IRIS](https://docs.wirespeed.co/integrations/dfir-iris.md): Integrate with DFIR IRIS for incident response case management - [Email](https://docs.wirespeed.co/integrations/email.md): Integrate with Email - [Exium](https://docs.wirespeed.co/integrations/exium.md): Ingest Syslog logs from Exium - [Fleet](https://docs.wirespeed.co/integrations/fleet-dm.md): Sync Fleet host inventory and activity telemetry - [Freshservice](https://docs.wirespeed.co/integrations/freshservice.md): Create and sync Freshservice tickets from Wirespeed cases and detections - [Fortinet](https://docs.wirespeed.co/integrations/fortinet.md): Ingest firewall logs from Fortinet - [Fortinet FortiAnalyzer](https://docs.wirespeed.co/integrations/fortinet-fortianalyzer.md): Ingest firewall logs from FortiAnalyzer - [Generic JSON Logs](https://docs.wirespeed.co/integrations/generic-json.md): Ingest JSON logs from any source within your organization - [Generic Syslog Logs](https://docs.wirespeed.co/integrations/generic-syslog.md): Ingest Syslog logs from any source within your organization - [GitHub](https://docs.wirespeed.co/integrations/github.md): Integrate with GitHub for security and audit event ingestion - [Google Alert Center](https://docs.wirespeed.co/integrations/google-alert-center.md): Integrate with Google Alert Center - [Google SecOps](https://docs.wirespeed.co/integrations/google-chronicle.md): Integrate with Google Security Operations (Google Chronicle) to ingest custom and curated rule detections - [Google Workspace](https://docs.wirespeed.co/integrations/google-workspace.md): Integrate with Google Workspace - [Google Security Center](https://docs.wirespeed.co/integrations/google-security-center.md): Integrate with Google Cloud Security Command Center (SCC) to ingest findings - [Halcyon](https://docs.wirespeed.co/integrations/halcyon.md): Import anti-ransomware alerts, manage endpoints, and quarantine or release files from Halcyon - [Halo ITSM](https://docs.wirespeed.co/integrations/halo-itsm.md): Integrate with Halo ITSM to automatically create and manage tickets from Wirespeed cases and detections - [Have I Been Pwned](https://docs.wirespeed.co/integrations/have-i-been-pwned.md): Discover breached credentials for your team members - [Horizon3 NodeZero](https://docs.wirespeed.co/integrations/horizon3.md): Integrate with Horizon3 NodeZero to verify whether detections can be correlated to pentest activity - [Hyas Protect](https://docs.wirespeed.co/integrations/hyas-protect.md): Ingest DNS logs from Hyas Protect - [IPinfo](https://docs.wirespeed.co/integrations/ipinfo.md): Enrich IP information - [Jamf Internet Security](https://docs.wirespeed.co/integrations/jamf-internet-security.md): Integrate with Jamf Internet Security for DNS and web security event ingestion - [Jamf Pro](https://docs.wirespeed.co/integrations/jamf-pro.md): Integrate with Jamf Pro to identify devices in your organization - [Jamf Protect](https://docs.wirespeed.co/integrations/jamf-protect.md): Integrate with Jamf Protect to identify devices and detections in your organization - [Jira Cloud](https://docs.wirespeed.co/integrations/jira-cloud.md): Integrate with Jira Cloud to sync Wirespeed cases with your team - [Jira Data Center](https://docs.wirespeed.co/integrations/jira-data-center.md): Integrate with Jira Data Center to sync Wirespeed cases with your team - [JumpCloud](https://docs.wirespeed.co/integrations/jumpcloud.md): Ingest directory events and sync users and endpoints from JumpCloud - [Iru](https://docs.wirespeed.co/integrations/iru.md): Sync your devices and threats from Iru (formerly Kandji) - [ManageEngine ADAudit Plus](https://docs.wirespeed.co/integrations/manage-engine.md): Ingest syslog events from ManageEngine - [Microsoft 365](https://docs.wirespeed.co/integrations/microsoft.md): Defender for Endpoint, Identity, Cloud, Cloud Apps, Sentinel, and more. - [Microsoft On-Prem Active Directory](https://docs.wirespeed.co/integrations/microsoft-on-prem-active-directory.md): Active Directory integration when 100% on-premises - [Microsoft Entra Sign-in Logs](https://docs.wirespeed.co/integrations/microsoft-sign-in-logs.md): Ingest sign-in logs from Microsoft Entra ID - [Microsoft Teams](https://docs.wirespeed.co/integrations/microsoft-teams.md): Message users directly in Teams - [Microsoft Windows](https://docs.wirespeed.co/integrations/microsoft-windows.md): Centralizing and forwarding Microsoft Windows telemetry - [Mimecast](https://docs.wirespeed.co/integrations/mimecast.md): Integrate with Mimecast to pull email alerts into Wirespeed - [Netskope](https://docs.wirespeed.co/integrations/netskope.md): Ingest SSE alerts, web/SaaS/ZTNA/network events, and users from Netskope - [NinjaOne](https://docs.wirespeed.co/integrations/ninjaone.md): Ingest NinjaOne activities and devices - [Odoo Helpdesk](https://docs.wirespeed.co/integrations/odoo-helpdesk.md): Integrate with Odoo Helpdesk to automatically create and manage tickets from Wirespeed cases and detections - [OneLogin](https://docs.wirespeed.co/integrations/onelogin.md): Sync directory users and remediate compromised OneLogin accounts - [Okta](https://docs.wirespeed.co/integrations/okta.md): Ingest all users from your Okta directory - [OpenAI Platform](https://docs.wirespeed.co/integrations/openai.md): Monitor administrative, configuration, and authentication activity across your OpenAI API Platform organization - [Orca Security](https://docs.wirespeed.co/integrations/orca-security.md): Ingest cloud security alerts from Orca Security - [PagerDuty](https://docs.wirespeed.co/integrations/pager-duty.md): Integrate with PagerDuty to sync Wirespeed cases as incidents - [Palo Alto Networks Cortex](https://docs.wirespeed.co/integrations/palo-alto-networks-cortex.md): Import alerts, manage endpoints, and quarantine or restore files from Cortex XDR/XSIAM - [Palo Alto Networks NGFW](https://docs.wirespeed.co/integrations/palo-alto-ngfw.md): Forward PAN-OS firewall logs to Wirespeed over syslog - [FortiMail Workspace Security](https://docs.wirespeed.co/integrations/perception-point.md): Import email threat scans from FortiMail Workspace Security (formerly Perception Point) - [Picus Security](https://docs.wirespeed.co/integrations/picus.md): Integrate with Picus Security to verify whether detections are tied to attack simulation activity - [PingOne](https://docs.wirespeed.co/integrations/ping-one.md): Sync PingOne users, ingest audit activities, and remediate accounts - [Proofpoint](https://docs.wirespeed.co/integrations/proofpoint.md): Integrate with Proofpoint for email threat detection ingestion - [ReversingLabs](https://docs.wirespeed.co/integrations/reversing-labs.md): Automated file enrichment - [SafeBreach](https://docs.wirespeed.co/integrations/safebreach.md): Integrate with SafeBreach to determine whether detections are tied to simulated attacks - [Sandfly](https://docs.wirespeed.co/integrations/sandfly.md): Ingest Sandfly alert results and sync Linux host inventory for enrichment - [SentinelOne](https://docs.wirespeed.co/integrations/sentinel-one.md): Automatically respond to all S1 detections - [ServiceNow Change Requests](https://docs.wirespeed.co/integrations/service-now.md): Use ServiceNow change requests to automatically close endpoint detections tied to planned changes. - [Slack](https://docs.wirespeed.co/integrations/slack.md): Communicate with your users directly in Slack - [Custom SMTP](https://docs.wirespeed.co/integrations/smtp.md): Send ChatOps emails from your own domain - [SonicWall](https://docs.wirespeed.co/integrations/sonic-wall.md): Integrate with SonicWall - [Sophos Central](https://docs.wirespeed.co/integrations/sophos.md): Ingest Sophos Central alerts, events, and endpoints - [Splunk](https://docs.wirespeed.co/integrations/splunk.md): Integrate with Splunk for security detection ingestion - [Stairwell](https://docs.wirespeed.co/integrations/stairwell.md): Ingest Stairwell detection events via JSON webhook - [Sublime Security](https://docs.wirespeed.co/integrations/sublime-security.md): Integrate with Sublime Security for email threat detection ingestion - [Tenable Nessus](https://docs.wirespeed.co/integrations/tenable-nessus.md): Correlate detections with Tenable Vulnerability Management scan activity - [Thinkst Canary](https://docs.wirespeed.co/integrations/thinkst-canary.md): Identify deception triggers in your environment - [Tracebit](https://docs.wirespeed.co/integrations/tracebit.md): Import deception alerts from Tracebit - [Ubiquiti UniFi Network](https://docs.wirespeed.co/integrations/unifi.md): Forward UniFi Network syslog (SIEM CEF or classic gateway logging) - [Vectra](https://docs.wirespeed.co/integrations/vectra.md): Ingest detections from Vectra - [WatchGuard Firebox](https://docs.wirespeed.co/integrations/watchguard-firebox.md): Ingest logs from WatchGuard Firebox - [Wiz](https://docs.wirespeed.co/integrations/wiz.md): Ingest cloud security threat detections from Wiz - [Wordfence](https://docs.wirespeed.co/integrations/wordfence.md): Ingest alerts from Wordfence - [Zabbix](https://docs.wirespeed.co/integrations/zabbix.md): Integrate with Zabbix for monitoring alert ingestion - [Zscaler ZPA](https://docs.wirespeed.co/integrations/zscaler-zpa.md): Forward Zscaler ZPA logs to Wirespeed - [Authentication](https://docs.wirespeed.co/api-reference/authentication.md): Create a team API key and authenticate Wirespeed API requests - [Bulk replace the current team's shared-inbox email subscriptions and settings for a notification type](https://docs.wirespeed.co/api-reference/notification/bulk-replace-the-current-teams-shared-inbox-email-subscriptions-and-settings-for-a-notification-type.md): SP teams fan out each email to SELF + CLIENTS rows. When subjectLine or richNotifications are provided they are written to every affected row. - [Get case statistics by severity](https://docs.wirespeed.co/api-reference/cases/get-case-statistics-by-severity.md) - [Get case statistics by category class](https://docs.wirespeed.co/api-reference/cases/get-case-statistics-by-category-class.md) - [Get weekly case counts](https://docs.wirespeed.co/api-reference/cases/get-weekly-case-counts.md) - [Get case counts grouped by team](https://docs.wirespeed.co/api-reference/cases/get-case-counts-grouped-by-team.md) - [Get all detections for a case](https://docs.wirespeed.co/api-reference/cases/get-all-detections-for-a-case.md) - [Get all detections for a case without entities](https://docs.wirespeed.co/api-reference/cases/get-all-detections-for-a-case-without-entities.md) - [Get TTD/TTV/TTR/TTC metrics for a case](https://docs.wirespeed.co/api-reference/cases/get-ttdttvttrttc-metrics-for-a-case.md) - [Update case details](https://docs.wirespeed.co/api-reference/cases/update-case-details.md) - [Get related cases](https://docs.wirespeed.co/api-reference/cases/get-related-cases.md) - [Get threat indicators for a case](https://docs.wirespeed.co/api-reference/cases/get-threat-indicators-for-a-case.md) - [Search and list cases](https://docs.wirespeed.co/api-reference/cases/search-and-list-cases.md) - [Get cases search count](https://docs.wirespeed.co/api-reference/cases/get-cases-search-count.md): Returns total count of cases matching the same filters as the search endpoint. - [Get MTTD/MTTV/MTTR/MTTC for cases matching search filters](https://docs.wirespeed.co/api-reference/cases/get-mttdmttvmttrmttc-for-cases-matching-search-filters.md): Averages time-to-detect, time-to-verdict, time-to-remediate, and time-to-close across all cases matching the same filters as the search endpoint. Pagination and sort fields are ignored. - [Get case by ID or SID](https://docs.wirespeed.co/api-reference/cases/get-case-by-id-or-sid.md) - [Merged timeline of comments, logs, and activity for an entity](https://docs.wirespeed.co/api-reference/timeline/merged-timeline-of-comments-logs-and-activity-for-an-entity.md) - [List comments for an entity](https://docs.wirespeed.co/api-reference/timeline/list-comments-for-an-entity.md) - [Create a comment with optional image attachments](https://docs.wirespeed.co/api-reference/timeline/create-a-comment-with-optional-image-attachments.md) - [Soft-delete a comment](https://docs.wirespeed.co/api-reference/timeline/soft-delete-a-comment.md) - [Edit comment text and optionally replace attachments](https://docs.wirespeed.co/api-reference/timeline/edit-comment-text-and-optionally-replace-attachments.md) - [Get integration health summary](https://docs.wirespeed.co/api-reference/integration/get-integration-health-summary.md): Returns counts by health status (healthy, unhealthy, unstable, unknown) for the attention banner and dashboards - [Search integrations](https://docs.wirespeed.co/api-reference/integration/search-integrations.md) - [Get integration search count](https://docs.wirespeed.co/api-reference/integration/get-integration-search-count.md): Returns total count of integrations matching the same filters as the search endpoint. - [Add other integration type](https://docs.wirespeed.co/api-reference/integration/add-other-integration-type.md) - [Get OAuth installation URL](https://docs.wirespeed.co/api-reference/integration/get-oauth-installation-url.md) - [Get all integration configurations](https://docs.wirespeed.co/api-reference/integration/get-all-integration-configurations.md) - [Get integration by ID](https://docs.wirespeed.co/api-reference/integration/get-integration-by-id.md) - [Delete integration](https://docs.wirespeed.co/api-reference/integration/delete-integration.md) - [Update integration](https://docs.wirespeed.co/api-reference/integration/update-integration.md) - [Get integration configuration by type](https://docs.wirespeed.co/api-reference/integration/get-integration-configuration-by-type.md) - [Get synced licenses for integration](https://docs.wirespeed.co/api-reference/integration/get-synced-licenses-for-integration.md) - [Set whether assigned directory users count toward billable users](https://docs.wirespeed.co/api-reference/integration/set-whether-assigned-directory-users-count-toward-billable-users.md) - [Check integration entitlements](https://docs.wirespeed.co/api-reference/integration/check-integration-entitlements.md) - [Search OCSF events](https://docs.wirespeed.co/api-reference/ocsf/search-ocsf-events.md) - [Get all verdict rules](https://docs.wirespeed.co/api-reference/verdict/get-all-verdict-rules.md) - [Get all assets for a case](https://docs.wirespeed.co/api-reference/asset/get-all-assets-for-a-case.md) - [Get asset counts by type](https://docs.wirespeed.co/api-reference/asset/get-asset-counts-by-type.md) - [Bulk contain multiple assets](https://docs.wirespeed.co/api-reference/asset/bulk-contain-multiple-assets.md): Accepts remediation for each selected asset and returns the accepted operation ids to poll until provider remediation completes. - [Bulk uncontain multiple assets](https://docs.wirespeed.co/api-reference/asset/bulk-uncontain-multiple-assets.md): Accepts release for each selected asset and returns the accepted operation ids to poll until provider remediation completes. - [Contain directory user](https://docs.wirespeed.co/api-reference/asset/contain-directory-user.md) - [Contain endpoint](https://docs.wirespeed.co/api-reference/asset/contain-endpoint.md) - [Uncontain endpoint](https://docs.wirespeed.co/api-reference/asset/uncontain-endpoint.md) - [Uncontain directory](https://docs.wirespeed.co/api-reference/asset/uncontain-directory.md) - [Contain file](https://docs.wirespeed.co/api-reference/asset/contain-file.md) - [Uncontain file](https://docs.wirespeed.co/api-reference/asset/uncontain-file.md) - [Get active containment actions for an asset](https://docs.wirespeed.co/api-reference/asset/get-active-containment-actions-for-an-asset.md) - [Get containment action history for an asset](https://docs.wirespeed.co/api-reference/asset/get-containment-action-history-for-an-asset.md) - [Get current authenticated user information](https://docs.wirespeed.co/api-reference/authentication/get-current-authenticated-user-information.md): Resolves the identity behind the bearer token, including the role it grants. API keys authenticate as their service account user, so this is how a caller discovers the effective role of a key. - [Get current user information](https://docs.wirespeed.co/api-reference/users/get-current-user-information.md) - [Update user role](https://docs.wirespeed.co/api-reference/users/update-user-role.md) - [Get team detection statistics](https://docs.wirespeed.co/api-reference/team/get-team-detection-statistics.md) - [Get team billable resource statistics](https://docs.wirespeed.co/api-reference/team/get-team-billable-resource-statistics.md) - [Get team event statistics by integration](https://docs.wirespeed.co/api-reference/team/get-team-event-statistics-by-integration.md) - [Detections created over time](https://docs.wirespeed.co/api-reference/team/detections-created-over-time.md) - [Cases over time](https://docs.wirespeed.co/api-reference/team/cases-over-time.md) - [Noise reduction rate over time](https://docs.wirespeed.co/api-reference/team/noise-reduction-rate-over-time.md) - [Switch to a different team](https://docs.wirespeed.co/api-reference/team/switch-to-a-different-team.md) - [Get current team information](https://docs.wirespeed.co/api-reference/team/get-current-team-information.md) - [Create a new team](https://docs.wirespeed.co/api-reference/team/create-a-new-team.md) - [Search service provider teams](https://docs.wirespeed.co/api-reference/team/search-service-provider-teams.md) - [Delete the current team and all associated data](https://docs.wirespeed.co/api-reference/team/delete-the-current-team-and-all-associated-data.md): Teams with child teams (rows with parent_team_id pointing at this team) cannot be deleted. Empty service providers with no child teams may be deleted. - [Update team information](https://docs.wirespeed.co/api-reference/team/update-team-information.md) - [Get all teams with slim payload](https://docs.wirespeed.co/api-reference/team/get-all-teams-with-slim-payload.md) - [Search team members](https://docs.wirespeed.co/api-reference/team/search-team-members.md) - [Get team member search count](https://docs.wirespeed.co/api-reference/team/get-team-member-search-count.md) - [Search system logs](https://docs.wirespeed.co/api-reference/team/search-system-logs.md) - [Invite user to team](https://docs.wirespeed.co/api-reference/team/invite-user-to-team.md) - [Remove external user from team](https://docs.wirespeed.co/api-reference/team/remove-external-user-from-team.md) - [Get all team-level API keys](https://docs.wirespeed.co/api-reference/team/get-all-team-level-api-keys.md) - [Create a team-level API key](https://docs.wirespeed.co/api-reference/team/create-a-team-level-api-key.md) - [Delete a team-level API key](https://docs.wirespeed.co/api-reference/team/delete-a-team-level-api-key.md) - [Get directory user statistics](https://docs.wirespeed.co/api-reference/directory/get-directory-user-statistics.md) - [List logical directory user licenses](https://docs.wirespeed.co/api-reference/directory/list-logical-directory-user-licenses.md): Returns distinct provider license IDs across the current team integrations. - [Get directory user by ID](https://docs.wirespeed.co/api-reference/directory/get-directory-user-by-id.md) - [Update directory user](https://docs.wirespeed.co/api-reference/directory/update-directory-user.md) - [Get directory user search count](https://docs.wirespeed.co/api-reference/directory/get-directory-user-search-count.md): Returns total count of directory users matching the same filters as the search endpoint. Use this for pagination totalCount without running the count in the search query. - [Search directory users](https://docs.wirespeed.co/api-reference/directory/search-directory-users.md): Returns one page of users. For total row count for these filters, call POST /directory/count with the same body. - [Get VIP user count and change](https://docs.wirespeed.co/api-reference/directory/get-vip-user-count-and-change.md) - [Get detection statistics by severity](https://docs.wirespeed.co/api-reference/detection/get-detection-statistics-by-severity.md) - [Get detection statistics by category class](https://docs.wirespeed.co/api-reference/detection/get-detection-statistics-by-category-class.md) - [Get noise reduction summary statistics](https://docs.wirespeed.co/api-reference/detection/get-noise-reduction-summary-statistics.md) - [Calculate mean time to detect](https://docs.wirespeed.co/api-reference/detection/calculate-mean-time-to-detect.md) - [Calculate mean time to verdict](https://docs.wirespeed.co/api-reference/detection/calculate-mean-time-to-verdict.md) - [Calculate mean time to remediate for the team](https://docs.wirespeed.co/api-reference/detection/calculate-mean-time-to-remediate-for-the-team.md) - [Calculate mean time to close for the team](https://docs.wirespeed.co/api-reference/detection/calculate-mean-time-to-close-for-the-team.md) - [Search and list detections](https://docs.wirespeed.co/api-reference/detection/search-and-list-detections.md) - [Count detections matching search filters](https://docs.wirespeed.co/api-reference/detection/count-detections-matching-search-filters.md) - [Average MTTD and MTTV across detections matching search filters](https://docs.wirespeed.co/api-reference/detection/average-mttd-and-mttv-across-detections-matching-search-filters.md) - [Get time-to-detect and time-to-verdict metrics for a single detection](https://docs.wirespeed.co/api-reference/detection/get-time-to-detect-and-time-to-verdict-metrics-for-a-single-detection.md) - [Get detection by ID or SID](https://docs.wirespeed.co/api-reference/detection/get-detection-by-id-or-sid.md) - [Update detection details](https://docs.wirespeed.co/api-reference/detection/update-detection-details.md) - [Get endpoint by ID](https://docs.wirespeed.co/api-reference/endpoint/get-endpoint-by-id.md): Retrieves detailed information about a specific endpoint including its public IPs and integration data - [Search endpoints](https://docs.wirespeed.co/api-reference/endpoint/search-endpoints.md): Search and filter endpoints with pagination support. Can filter by Critical Asset status, IP, user, and managed status - [Get endpoint search count](https://docs.wirespeed.co/api-reference/endpoint/get-endpoint-search-count.md): Returns total count of endpoints matching the same filters as the search endpoint. Use this to get totalCount for pagination without running the count in the search query. - [Get Critical Asset count and change](https://docs.wirespeed.co/api-reference/endpoint/get-critical-asset-count-and-change.md): Returns the current count of Critical Assets and the change over time - [Create a custom group](https://docs.wirespeed.co/api-reference/group/create-a-custom-group.md) - [Search groups](https://docs.wirespeed.co/api-reference/group/search-groups.md) - [Update a group](https://docs.wirespeed.co/api-reference/group/update-a-group.md) - [Add a directory user to a group](https://docs.wirespeed.co/api-reference/group/add-a-directory-user-to-a-group.md) - [Remove a directory user from a group](https://docs.wirespeed.co/api-reference/group/remove-a-directory-user-from-a-group.md) - [Changelog](https://docs.wirespeed.co/changelog.md): Latest updates and improvements to Wirespeed ## OpenAPI Specs - [openapi](https://api.wirespeed.co/v1/openapi.json)