Get a single detection¶
GET/
Cases API · Cases
Get a detection associated with case.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
caseId | path | string | Yes | Case ID. The ID follows the pattern ^[A-Za-z0-9]+-[A-Za-z0-9]+$. |
detectionId | path | string | Yes | Detection ID. Must match the pattern ^[a-f0-9_-]+$. Must be at most 150 characters long. |
Request samples¶
curl -X GET "https://api-<data-region>.central.sophos.com/cases/v1/cases/<caseId>/detections/<detectionId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"
import requests
response = requests.get(
"https://api-<data-region>.central.sophos.com/cases/v1/cases/<caseId>/detections/<detectionId>",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/cases/v1/cases/<caseId>/detections/<detectionId>" -Headers $headers
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/cases/v1/cases/<caseId>/detections/<detectionId>", nil)
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/cases/v1/cases/<caseId>/detections/<detectionId>", {
method: "GET",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
});
const data = await response.json();
console.log(data);
Responses¶
200 — Requested case detection.¶
Response fields
idstringrequiredDetection ID.
Must match the pattern
Must match the pattern
^[a-f0-9_-]+$. Must be at most 150 characters long.attackTypestringThe attack type of the detection.
detectionRulestringrequiredDetection rule ID.
sensorGeneratedAtstring (date-time)Time when the event was created by the sensor.
sensorobjectrequiredThe sensor which generated the detection.
Show child attributesHide child attributes
idstringrequiredID of the sensor.
typestringrequiredSensor type where detection occurred.
Must be one of:
Must be one of:
cloud, endpoint, email, firewall, iam, network, compound, backupAndRecovery.sourcestringrequiredThe name of the sensor source.
versionstringrequiredThe version of the sensor provided by the vendor.
namestringThe name of the sensor.
deviceobjectrequiredDevice associated with a detection.
Show child attributesHide child attributes
idstring (uuid)ID of the device.
typestringDevice type where detection occurred.
Must be one of:
Must be one of:
computer, sensor, server.entitystringEntity of the device.
detectionSigmaobjectInformation about the detection method.
detectionEqlstringEQL instructions for performing the classification.
detectionAttackstringrequiredMITRE ATT&CK tactic category of the detection.
detectionLicensesstringLicenses required for the rule or process.
geolocationarray of objectList of geolocation of sensors associated with the detection.
Geolocation of the sensor.
Show child attributesHide child attributes
fieldNamestringName of the IP.
fieldValuestringValue of the IP.
citystringCity where the device is located.
statestringState where the device is located.
countrystringCountry where the device is located.
countryCodestringCountry code where the device is located, in ISO 3166-1 format.
postalstringPostal code where the device is located.
latitudenumberLatitude of device location.
longitudenumberLongitude of device location.
intelixFileReputationarray of objectList of Intelix file reputation objects associated with this detection.
Intelix file reputation of detection.
Show child attributesHide child attributes
fieldNamestringName of the file.
fieldValuestringValue of the file.
reputationScoreintegerReputation score of the file.
Must be ≥ 0 and ≤ 100.
Must be ≥ 0 and ≤ 100.
detectionNamestringName of the detection.
mitreAttacksarray of objectrequiredList of MITRE ATT&CK objects associated with this detection.
MITRE ATT&CK name and description.
Show child attributesHide child attributes
tacticobjectTactic used in the MITRE ATT&CK.
Show child attributesHide child attributes
idstringID of the tactic.
namestringMITRE ATT&CK name.
techniquesarray of objectMITRE ATT&CK techniques.
Technique used in the MITRE ATT&CK.
Show child attributesHide child attributes
idstringID of the technique.
namestringName of the technique.
rawDataobjectrequiredRaw data received from the source.
ruleDescriptionstringA description of the rule that produced the detection.
severityintegerrequiredSeverity of the detection. A higher score implies a more severe detection.
Must be ≥ 1 and ≤ 10.
Must be ≥ 1 and ≤ 10.
schemastringDescribes the schema for the detection.
timestring (date-time)requiredCreation time of the detection.
typestringrequiredType of the detection.
Errors¶
| Status | Meaning |
|---|---|
400 | Bad request. |
401 | Unauthorized. |
403 | Forbidden. |
404 | Not found. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"id": "2e0cdd5ffec_3bad8fb8f",
"attackType": "Security Event Service Detections",
"detectionRule": "WIN-PER-PSH-ADD-SERVICE-REG-1",
"sensorGeneratedAt": "2023-11-18T12:01:21Z",
"sensor": {
"id": "SophosSensorID",
"type": "cloud",
"source": "Sophos",
"version": "1.18.1",
"name": "string"
},
"device": {
"id": "0569f2b7-756c-4d16-8804-798a6d0030cf",
"type": "computer",
"entity": "EC2AMAZ-HKOG4LG"
},
"detectionSigma": {},
"detectionEql": "string",
"detectionAttack": "Defense Evasion",
"detectionLicenses": "string",
"geolocation": [
{
"fieldName": "raw.meta_public_ip",
"fieldValue": "52.11.152.156",
"city": "Boardman",
"state": "Oregon",
"country": "United States",
"countryCode": "US",
"postal": "97818",
"latitude": 45.8234,
"longitude": -119.7257
}
],
"intelixFileReputation": [
{
"fieldName": "raw.sha256",
"fieldValue": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c",
"reputationScore": 95,
"detectionName": "WIN-EXE-DM-SUS-POWERSHELL-SCRIPT-BLOCK-1"
}
],
"mitreAttacks": [
{
"tactic": {
"id": "TA0002",
"name": "Execution",
"techniques": [
{
"id": "T1059",
"name": "Command and Scripting Interpreter"
}
]
}
}
],
"rawData": {},
"ruleDescription": "string",
"severity": 5,
"schema": "string",
"time": "2023-11-18T12:02:15.604Z",
"type": "Threat"
}
See the guide for a narrative walkthrough of this API.