Get detection result¶
GET/
Detections API · Detections
Return the results of the detections query run with the given ID.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
runId | path | string (uuid) | Yes | Run ID of a query. |
page | query | integer | No | The page number to fetch, starting with 1. |
pageSize | query | integer | No | The size of the page requested. |
Request samples¶
curl -X GET "https://api-<data-region>.central.sophos.com/detections/v1/queries/detections/<runId>/results" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"
import requests
response = requests.get(
"https://api-<data-region>.central.sophos.com/detections/v1/queries/detections/<runId>/results",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/detections/v1/queries/detections/<runId>/results" -Headers $headers
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/detections/v1/queries/detections/<runId>/results", nil)
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/detections/v1/queries/detections/<runId>/results", {
method: "GET",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
});
const data = await response.json();
console.log(data);
Responses¶
200 — Successful retrieval of a detections results page.¶
Response fields
itemsarray of objectPage of detection results.
The detection item.
Show child attributesHide child attributes
idstringrequiredThe Detection ID.
Must match the pattern
Must match the pattern
^[A-Fa-f0-9_-]+$. Must be at most 150 characters long.attackTypestringThe attack type of the detection.
caseDescriptionobjectDescription of case handler verdict.
Show child attributesHide child attributes
correlatedReasonIdstringID of the correlation reason used for associating the case with the detection.
createdReasonIdstringID of the reason for creating this case handler verdict.
detectionDescriptionobjectDescription of detection handler verdict.
Show child attributesHide child attributes
createdReasonIdstringID of the reason for creating this detection handler verdict.
significanceIdstringID of the significance of associated handler verdict.
detectionRulestringrequiredDetection Rule ID.
sensorGeneratedAtstring (date-time)Time when the event was created by the sensor.
sensorobjectrequiredThe sensor which generated the detection.
Show child attributesHide child attributes
idstringrequiredID of the sensor.
typestringrequiredSensor type where detection occurred.
Must be one of:
Must be one of:
cloud, endpoint, email, firewall, iam, network, compound, backupAndRecovery.sourcestringrequiredThe name of the sensor source.
versionstringrequiredThe version of the sensor provided by the vendor.
namestringThe name of the sensor.
deviceobjectrequiredDevice associated with a detection.
Show child attributesHide child attributes
idstring (uuid)ID of the device.
typestringDevice type where detection occurred.
Must be one of:
Must be one of:
computer, sensor, server.entitystringEntity of the device.
detectionSigmaobjectInformation about the detection method.
detectionEqlstringEQL instructions for performing the classification.
detectionAttackstringrequiredMITRE ATT&CK tactic category of the detection.
detectionLicensesstringLicenses required for the rule or process.
geolocationarray of objectList of geolocation of sensors associated with the detection.
Geolocation of the sensor.
Show child attributesHide child attributes
fieldNamestringName of the IP.
fieldValuestringValue of the IP.
citystringCity where the device is located.
statestringState where the device is located.
countrystringCountry where the device is located.
countryCodestringCountry code where the device is located, in ISO 3166-1 format.
postalstringPostal code where the device is located.
latitudenumberLatitude of device location.
longitudenumberLongitude of device location.
entitiesarray of objectList of impacted and observed entities associated with the detection.
Detection entity.
Show child attributesHide child attributes
idstringrequiredEntity ID.
typestringrequiredEntity type. Possible values are user, device, ipAddress, networkFlow, file, process.
namestringEntity name.
categorystringrequiredEntity Category.
Must be one of:
Must be one of:
impacted, observed.attributesobjectEntity attributes.
intelixFileReputationarray of objectList of Intelix file reputation objects associated with this detection.
Intelix file reputation of detection.
Show child attributesHide child attributes
fieldNamestringName of the file.
fieldValuestringValue of the file.
reputationScoreintegerReputation score of the file.
Must be ≥ 0 and ≤ 100.
Must be ≥ 0 and ≤ 100.
detectionNamestringName of the detection.
mitreAttacksarray of objectrequiredList of MITRE ATT&CK objects associated with this detection.
MITRE ATT&CK name and description.
Show child attributesHide child attributes
tacticobjectTactic used in the MITRE ATT&CK.
Show child attributesHide child attributes
idstringID of the tactic.
namestringMITRE ATT&CK name.
techniquesarray of objectMITRE ATT&CK techniques.
Technique used in the MITRE ATT&CK.
Show child attributesHide child attributes
idstringID of the technique.
namestringName of the technique.
processedDatastringProcessed data for the detection.
rawDataobjectrequiredRaw data received from the source.
ruleDescriptionstringA description of the rule that produced the detection.
severityintegerrequiredSeverity of the detection. A higher score implies a more severe detection.
Must be ≥ 1 and ≤ 10.
Must be ≥ 1 and ≤ 10.
schemastringDescribes the schema for the detection.
suppressedstringIndicates whether a detection is marked as suppressed.
timestring (date-time)requiredCreation time of the detection.
typestringrequiredType of the detection.
pagesobjectShow child attributesHide child attributes
currentintegerrequiredThe 1-based page number being returned.
sizeintegerrequiredThe size of the page being returned.
totalinteger(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger(Optional) The total number of items across all pages.
maxSizeintegerrequiredThe maximum page size that can be requested.
Errors¶
| Status | Meaning |
|---|---|
400 | Bad request. |
401 | Unauthorized. |
403 | Forbidden. |
404 | Not found. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"items": [
{
"id": "string",
"attackType": "Security Event Service Detections",
"caseDescription": {
"correlatedReasonId": "XDR-fortinet-fortianalyzer-Application-Layer-Protocol",
"createdReasonId": "XDR-fortinet-fortianalyzer-Application-Layer-Protocol"
},
"detectionDescription": {
"createdReasonId": "XDR-fortinet-fortianalyzer-Application-Layer-Protocol",
"significanceId": "XDR-fortinet-fortianalyzer-Application-Layer-Protocol"
},
"detectionRule": "WIN-PER-PSH-ADD-SERVICE-REG-1",
"sensorGeneratedAt": "2023-11-18T12:01:21Z",
"sensor": {
"id": "SophosSensorID",
"type": "cloud",
"source": "Sophos",
"version": "1.18.1",
"name": "string"
},
"device": {
"id": "0569f2b7-756c-4d16-8804-798a6d0030cf",
"type": "computer",
"entity": "EC2AMAZ-HKOG4LG"
},
"detectionSigma": {},
"detectionEql": "string",
"detectionAttack": "Defense Evasion",
"detectionLicenses": "string",
"geolocation": [
{
"fieldName": "raw.meta_public_ip",
"fieldValue": "52.11.152.156",
"city": "Boardman",
"state": "Oregon",
"country": "United States",
"countryCode": "US",
"postal": "97818",
"latitude": 45.8234,
"longitude": -119.7257
}
],
"entities": [
{
"id": "string",
"type": "string",
"name": "string",
"category": "impacted",
"attributes": {}
}
],
"intelixFileReputation": [
{
"fieldName": "raw.sha256",
"fieldValue": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c",
"reputationScore": 95,
"detectionName": "WIN-EXE-DM-SUS-POWERSHELL-SCRIPT-BLOCK-1"
}
],
"mitreAttacks": [
{
"tactic": {
"id": "TA0002",
"name": "Execution",
"techniques": [
{
"id": "T1059",
"name": "Command and Scripting Interpreter"
}
]
}
}
],
"processedData": "The process 'C:\\Windows\\System32\\svchost.exe' was created by 'C:\\Windows\\System32\\services.exe'.",
"rawData": {},
"ruleDescription": "string",
"severity": 5,
"schema": "string",
"suppressed": "string",
"time": "2023-11-18T12:02:15.604Z",
"type": "Threat"
}
],
"pages": {
"current": 0,
"size": 0,
"total": 0,
"items": 0,
"maxSize": 0
}
}
See the guide for a narrative walkthrough of this API.