Block an item¶
POST/
Endpoint API · Blocked Items
Block an item from exoneration.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
Request body¶
Content type: application/json
Request body fields
typestringrequiredProperty by which an item is blocked.
Must be one of:
Must be one of:
sha256.propertiesobjectrequiredBlocked item properties.
Show child attributesHide child attributes
fileNamestringFile name.
pathstringPath for the application.
sha256stringSha256 value for the application.
certificateSignerstringValue saved for the certificateSigner.
commentstringrequiredComment indicating why the item should be blocked.
Request samples¶
curl -X POST "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"type\": \"sha256\",
\"properties\": {
\"fileName\": \"filename.txt\",
\"path\": \"\$desktop/documents/filename.txt\",
\"sha256\": \"ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad\"
},
\"comment\": \"Item is a Malware\"
}"
import requests
response = requests.post(
"https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={ 'type': 'sha256',
'properties': { 'fileName': 'filename.txt',
'path': '$desktop/documents/filename.txt',
'sha256': 'ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad'},
'comment': 'Item is a Malware'},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"type": "sha256",
"properties": {
"fileName": "filename.txt",
"path": "$desktop/documents/filename.txt",
"sha256": "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
},
"comment": "Item is a Malware"
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items", strings.NewReader(`{
"type": "sha256",
"properties": {
"fileName": "filename.txt",
"path": "$desktop/documents/filename.txt",
"sha256": "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
},
"comment": "Item is a Malware"
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/blocked-items", {
method: "POST",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"type": "sha256",
"properties": {
"fileName": "filename.txt",
"path": "$desktop/documents/filename.txt",
"sha256": "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
},
"comment": "Item is a Malware"
}),
});
const data = await response.json();
console.log(data);
Responses¶
201 — Blocked item created.¶
Response fields
idstring (uuid)requiredBlocked item ID.
createdAtstring (date-time)requiredDate and time (UTC) when the blocked item was created.
updatedAtstring (date-time)Date and time (UTC) when the blocked item was updated.
propertiesobjectrequiredBlocked item properties.
Show child attributesHide child attributes
fileNamestringFile name.
pathstringPath for the application.
sha256stringSha256 value for the application.
certificateSignerstringValue saved for the certificateSigner.
commentstringrequiredComment indicating why the item was blocked.
typestringrequiredProperty by which an item is blocked.
Must be one of:
Must be one of:
sha256.createdByobjectUser.
Show child attributesHide child attributes
idstring (uuid)requiredUnique ID for the user.
namestringPerson's name.
originPersonobjectUser.
Show child attributesHide child attributes
idstring (uuid)requiredUnique ID for the user.
namestringPerson's name.
originEndpointobjectRepresents a referenced object.
Show child attributesHide child attributes
idstring (uuid)requiredThe ID of the referenced object.
Errors¶
| Status | Meaning |
|---|---|
400 | Bad request. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
201¶
{
"id": "00000000-0000-0000-0000-000000000000",
"createdAt": "2019-09-23T12:02:01.700Z",
"updatedAt": "2019-09-23T12:02:01.700Z",
"properties": {
"fileName": "string",
"path": "string",
"sha256": "string",
"certificateSigner": "string"
},
"comment": "string",
"type": "sha256",
"createdBy": {
"id": "00000000-0000-0000-0000-000000000000",
"name": "string"
},
"originPerson": {
"id": "00000000-0000-0000-0000-000000000000",
"name": "string"
},
"originEndpoint": {
"id": "00000000-0000-0000-0000-000000000000"
}
}
See the guide for a narrative walkthrough of this API.