REST API Documentation
Basic Authorization header
A list of all currently added tags
A list of all currently added tags
Basic Authorization header
Password was successfully updated
Request validation failed
Configuration file is malformed
No content
Basic Authorization header
Updated file system events configuration
Controls the frequency of the execution of queries that access file system events, like all detection strategies
Indicates how often the events are saved to the database
Request validation failed
Basic Authorization header
Current file system events configuration
Controls the frequency of the execution of queries that access file system events, like all detection strategies
Indicates how often the events are saved to the database
Current file system events configuration
Basic Authorization header
Path to exclude
Username for which the path should be excluded from monitoring
An excluded path entry was created
Request validation failed
Excluded paths file was not found
Excluded path already exists in the file
Basic Authorization header
Excluded path identifier
Excluded path was removed
Excluded paths file was not found
No content
Basic Authorization header
Excluded path identifier
A single excluded path
Represents a path at which file system events will be ignored
Excluded path identifier
Path to exclude
Username for which the path should be excluded from monitoring
Excluded path was not found or excluded paths file was not found
Basic Authorization header
OK
OK
Basic Authorization header
OK
Bad Request
Basic Authorization header
OK
Bad Request
Conflict
Basic Authorization header
OK
Bad Request
Unprocessable Content
Basic Authorization header
OK
Represents a path at which file system events will be ignored
Excluded path identifier
Path to exclude
Username for which the path should be excluded from monitoring
OK
Basic Authorization header
Path to exclude
Username for which the path should be excluded from monitoring
Created
Bad Request
Conflict
Basic Authorization header
No Content
Bad Request
No content
Basic Authorization header
OK
Represents a path at which file system events will be tracked by file event reports
Included path identifier
Path to include
Username for which the path should be included in file event reports
OK
Basic Authorization header
Path to include
Username for which the path should be included in file event reports
Created
Bad Request
Conflict
Basic Authorization header
No Content
Bad Request
No content
Basic Authorization header
File integrity configuration
File integrity strategy configuration
Indicates if the file integrity strategy is enabled
File integrity configuration
Basic Authorization header
Request to add new monitored path to file integrity configuration
Path prefix to monitor
Indicates if the file contents are checked to reduce number of false positives
OK
File integrity strategy configuration
Indicates if the file integrity strategy is enabled
New path was successfully added
Request validation failed
Conflict
Basic Authorization header
Updates file integrity strategy configuration
Indicates if the file integrity strategy is enabled
OK
File integrity strategy configuration
Indicates if the file integrity strategy is enabled
Request validation failed
Basic Authorization header
ID of the path to be removed
Path was successfully removed
File integrity strategy configuration
Indicates if the file integrity strategy is enabled
No Content
Request validation failed
Basic Authorization header
ID of path to update
Indicates if the file contents are checked to reduce number of false positives
OK
File integrity strategy configuration
Indicates if the file integrity strategy is enabled
Not Found
Basic Authorization header
A collection of all file system event types
Represents enumeration values, defined by ID and name
ID of returned value
Descriptive name of this value
A collection of all file system event types
Basic Authorization header
A collection of file system events
Request validation failed
Basic Authorization header
A set of placement paths
Source path honeypot files
Updated honeypot configuration
Honeypot files source path
File placement path collection
Request validation failed
Basic Authorization header
Current honeypot configuration
Honeypot files source path
File placement path collection
Current honeypot configuration
Basic Authorization header
A set of placement paths
An updated honeypot configuration with the new placement path
Honeypot files source path
File placement path collection
Request validation failed
Basic Authorization header
Placement path
An updated honeypot configuration without the selected placement path
Honeypot files source path
File placement path collection
Request validation failed
Basic Authorization header
Incident identifier
Maximum number of entries to be returned
Cursor to filter out already returned entries
A list of affected files connected to an incident with a given identifier
Affected file response item
Path to affected file before the incident started
Last registered path to affected file
Time of the first suspicious modification of this affected file
Request validation failed
An incident with provided identifier was not found
Basic Authorization header
Incident identifier
A collection of events connected to an incident with a given identifier
Request validation failed
An incident with provided identifier was not found
Basic Authorization header
User name. Only includes the incidents which were created for a specific user
A list of all detected security incidents
Security incident response item
Identifier of the incident
User for whom the incident was opened
Incident start time
Incident end time, or null if it is still ongoing
A list of all detected security incidents
Basic Authorization header
A list of all possible values of affected file modification types
Represents enumeration values, defined by ID and name
ID of returned value
Descriptive name of this value
A list of all possible values of affected file modification types
Basic Authorization header
A request that registers an agent with a management server
Agent instance identifier
The Guard Mode management server address/host
API key identifier
API key secret
Registration response with an extra data about the node
Successful agent registration response
Fully qualified domain name of the registered agent
Agent's operating system
Request validation failed
Agent is already registered with a server instance
Basic Authorization header
Current block list data
A timestamp which indicates when the block list was last updated
Count of pattern/file groups
Current block list data
Basic Authorization header
The timestamp which will be set as the 'last update time' for the block list
Collection of path filters
["*.exe"]Block list patterns were updated
Block list was not modified because it is already up to date
Request validation failed
No content
Basic Authorization header
Collection of path filters
["*.exe"]Skip list patterns updated
Request validation failed
No content
Basic Authorization header
File path pattern
Skip pattern added
Request validation failed
Pattern already exists in the skip list
No content
Basic Authorization header
Skip list pattern identifier
Skip pattern was removed
Request validation failed
No content
Basic Authorization header
Maximum number of entries to be returned
Cursor to filter out already returned entries
Returns a list of all scans, both ended and ongoing
File system scan
Identifier of the scan
Scan start time
Scan end time if it has ended, or null otherwise
Last file path scanned by this scan, or null if no files were scanned yet
Number of files that were scanned
Number of suspicious files found
Bad Request
Basic Authorization header
Scan creation request
Paths that will be recursively scanned
Indicates if file names found during scan should be analyzed to find files with names often used by ransomware
Indicates if files should be scanned using YARA rules
If true, Agent will raise alert on suspicious file found
If present, causes exclusions to work as if filesystem root was at each of provided paths
Returns a newly created scan
No content
Accepted
Bad request was sent
No content
Basic Authorization header
Returns a scan with provided ID
File system scan
Identifier of the scan
Scan start time
Scan end time if it has ended, or null otherwise
Last file path scanned by this scan, or null if no files were scanned yet
Number of files that were scanned
Number of suspicious files found
There is no scan with a given ID
Basic Authorization header
Maximum number of entries to be returned
Cursor to filter out already returned entries
Returns a list of suspicious files found by this scan
File system scan
Identifier of the scan
Scan start time
Scan end time if it has ended, or null otherwise
Last file path scanned by this scan, or null if no files were scanned yet
Number of files that were scanned
Number of suspicious files found
Bad Request
There is no scan with a given ID
Basic Authorization header
Scan was successfully stopped
No content
Scan has already finished
Scan with provided ID doesn't exist
Scan with provided ID cannot be stopped
No content
Basic Authorization header
Current SMB monitoring configuration
Indicates whether the SMB listener is enabled or disabled
Current SMB monitoring configuration
Basic Authorization header
Updated SMB monitoring configuration
Indicates whether the SMB listener is enabled or disabled
Request validation failed
Basic Authorization header
Number of threshold buckets
Limit of data points to analyze
Updated threshold configuration
Number of threshold buckets
Limit of data points to analyze
Request validation failed
Basic Authorization header
Current threshold configuration
Number of threshold buckets
Limit of data points to analyze
Current threshold configuration
Basic Authorization header
OK
Timezone information
Timezone ID that can be used set this timezone in configuration
Base UTC offset of this timezone (current offset might be different, depending on daylight saving time, etc.)
List of all known timezones
Basic Authorization header
Timezone configuration update request
ID of a timezone that will be set
Configuration was successfully updated
Bad request was sent
No content
Last updated