Skip to content

Block an item

POST/settings/blocked-items

Endpoint API · Blocked Items

Block an item from exoneration.

Required permissionendpoint-state:update

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request body

Content type: application/json

Request body fields

typestringrequired
Property by which an item is blocked.
Must be one of: sha256.
propertiesobjectrequired
Blocked item properties.
Show child attributesHide child attributes
fileNamestring
File name.
pathstring
Path for the application.
sha256string
Sha256 value for the application.
certificateSignerstring
Value saved for the certificateSigner.
commentstringrequired
Comment indicating why the item should be blocked.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"type\": \"sha256\",
  \"properties\": {
    \"fileName\": \"filename.txt\",
    \"path\": \"\$desktop/documents/filename.txt\",
    \"sha256\": \"ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad\"
  },
  \"comment\": \"Item is a Malware\"
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'type': 'sha256',
    'properties': {   'fileName': 'filename.txt',
                      'path': '$desktop/documents/filename.txt',
                      'sha256': 'ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad'},
    'comment': 'Item is a Malware'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "type": "sha256",
  "properties": {
    "fileName": "filename.txt",
    "path": "$desktop/documents/filename.txt",
    "sha256": "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
  },
  "comment": "Item is a Malware"
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items", strings.NewReader(`{
  "type": "sha256",
  "properties": {
    "fileName": "filename.txt",
    "path": "$desktop/documents/filename.txt",
    "sha256": "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
  },
  "comment": "Item is a Malware"
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "type": "sha256",
  "properties": {
    "fileName": "filename.txt",
    "path": "$desktop/documents/filename.txt",
    "sha256": "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
  },
  "comment": "Item is a Malware"
}),
});
const data = await response.json();
console.log(data);

Responses

201 — Blocked item created.

Response fields

idstring (uuid)required
Blocked item ID.
createdAtstring (date-time)required
Date and time (UTC) when the blocked item was created.
updatedAtstring (date-time)
Date and time (UTC) when the blocked item was updated.
propertiesobjectrequired
Blocked item properties.
Show child attributesHide child attributes
fileNamestring
File name.
pathstring
Path for the application.
sha256string
Sha256 value for the application.
certificateSignerstring
Value saved for the certificateSigner.
commentstringrequired
Comment indicating why the item was blocked.
typestringrequired
Property by which an item is blocked.
Must be one of: sha256.
createdByobject
User.
Show child attributesHide child attributes
idstring (uuid)required
Unique ID for the user.
namestring
Person's name.
originPersonobject
User.
Show child attributesHide child attributes
idstring (uuid)required
Unique ID for the user.
namestring
Person's name.
originEndpointobject
Represents a referenced object.
Show child attributesHide child attributes
idstring (uuid)required
The ID of the referenced object.

Errors

Status Meaning
400 Bad request.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "id": "00000000-0000-0000-0000-000000000000",
  "createdAt": "2019-09-23T12:02:01.700Z",
  "updatedAt": "2019-09-23T12:02:01.700Z",
  "properties": {
    "fileName": "string",
    "path": "string",
    "sha256": "string",
    "certificateSigner": "string"
  },
  "comment": "string",
  "type": "sha256",
  "createdBy": {
    "id": "00000000-0000-0000-0000-000000000000",
    "name": "string"
  },
  "originPerson": {
    "id": "00000000-0000-0000-0000-000000000000",
    "name": "string"
  },
  "originEndpoint": {
    "id": "00000000-0000-0000-0000-000000000000"
  }
}

See the guide for a narrative walkthrough of this API.