Skip to content

Detected exploit

GET/settings/exploit-mitigation/detected-exploits/{detectedExploitId}

Endpoint API · Exploit Mitigation

Get a detected exploit by ID.

Required permissionendpoint-state:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
detectedExploitId path string (uuid) Yes ID of a previously detected exploit.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits/<detectedExploitId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits/<detectedExploitId>",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits/<detectedExploitId>" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits/<detectedExploitId>", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits/<detectedExploitId>", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — Previously detected exploit.

Response fields

idstring (uuid)required
Detected exploit ID.
thumbprintstringrequired
Must match the pattern [0-9a-zA-Z]{64}.
countintegerrequired
Number of times the same exploit has been detected, potentially across multiple endpoints.
Must be ≥ 1.
descriptionstringrequired
The English description of the exploit detected event.
Must be 1–2000 characters long.
firstSeenAtstring (date-time)
When the exploit was first seen.
lastSeenAtstring (date-time)
When the exploit was last seen.
lastUserobject
User.
Show child attributesHide child attributes
idstring (uuid)required
Unique ID for the user.
namestring
Person's name.
lastEndpointobject
Reference to an endpoint.
Show child attributesHide child attributes
idstring (uuid)required
Unique endpoint ID.
hostnamestring
Endpoint hostname.

Errors

Status Meaning
404 Can't find previously detected exploit.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "id": "00000000-0000-0000-0000-000000000000",
  "thumbprint": "string",
  "count": 0,
  "description": "string",
  "firstSeenAt": "2026-07-28T00:00:00Z",
  "lastSeenAt": "2026-07-28T00:00:00Z",
  "lastUser": {
    "id": "00000000-0000-0000-0000-000000000000",
    "name": "string"
  },
  "lastEndpoint": {
    "id": "00000000-0000-0000-0000-000000000000",
    "hostname": "string"
  }
}

See the guide for a narrative walkthrough of this API.