Threat Timeline GraphQL API¶
Search process lineage — the ancestry tree around a suspicious process, with its detections, key activities, child processes, and related events — over GraphQL.
See the guide for a narrative walkthrough of this API.
This is a GraphQL API: every request is a POST carrying a query (or mutation) document, rather than one endpoint per operation. See the guide above for the request shape and authentication.
Queries¶
- enrichmentJobs
Returns enrichment status for job IDs. - enrichmentQueries
Returns status for enrichment query IDs from EnrichmentQueryEntry.queryId. - lineageNodeTopRelatedEvents
Returns most recent related events across event families. Results are not paginated. - processLineageTreeSearch
Returns a process lineage as a flat list. - searchLineage
Returns lineage counts and selected process details for multiple processes.
Mutations¶
- enrichNode
Starts enrichment for one process and returns its job ID.
Types¶
DNSRelatedEventDataTimeRangeDetectionEnrichNodeInputEnrichmentJobEnrichmentJobStatusEnrichmentQueryEntryEnrichmentQueryTypeFieldFilterFieldFilterOperatorFieldHighlightFilemodRelatedEventHTTPRelatedEventInt64KeyActivityLineageNodeRelatedEventLineageNodeTopRelatedEventsInputLineageNodeTopRelatedEventsResultLineageProcessInputLineageProcessNodeLineageProcessResultNetflowRelatedEventOtherRelatedEventProcessHashesProcessInfoMitreAttackInfoRegistryRelatedEventRelatedEventIndexTypeRelatedEventSummaryScriptblockRelatedEventSearchLineageCountsSearchLineageInputSearchLineageItemSearchLineageNodeSearchLineageNodeChildProcessItemSearchLineageNodeChildProcessesResultSearchLineageNodeDetectionItemSearchLineageNodeDetectionsResultSearchLineageNodeKeyActivitiesResultSearchLineageNodeKeyActivityItemSearchLineageNodeRelatedEventItemSearchLineageNodeRelatedEventsResultSearchLineageNodeResultSearchLineageRelatedEventCountsSearchModeSortCriterionSortOrderUUID