Skip to content

Detected exploits

GET/settings/exploit-mitigation/detected-exploits

Endpoint API · Exploit Mitigation

Get detected exploits and the number of each detected exploit.

Required permissionendpoint-state:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
page query integer No The page number to fetch, starting with 1.
pageSize query integer No The size of the page requested.
pageTotal query boolean No Whether the number of pages should be calculated and returned in the response.
thumbprintNotIn query array of string No Filter out detected exploits with these thumbprints.
Each item must match the pattern [0-9a-zA-Z]{64}.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/detected-exploits", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — List of detected exploits.

Response fields

itemsarray of objectrequired
List of detected exploits.
Exploit detected on one or more endpoints.
Show child attributesHide child attributes
idstring (uuid)required
Detected exploit ID.
thumbprintstringrequired
Must match the pattern [0-9a-zA-Z]{64}.
countintegerrequired
Number of times the same exploit has been detected, potentially across multiple endpoints.
Must be ≥ 1.
descriptionstringrequired
The English description of the exploit detected event.
Must be 1–2000 characters long.
firstSeenAtstring (date-time)
When the exploit was first seen.
lastSeenAtstring (date-time)
When the exploit was last seen.
lastUserobject
User.
Show child attributesHide child attributes
idstring (uuid)required
Unique ID for the user.
namestring
Person's name.
lastEndpointobject
Reference to an endpoint.
Show child attributesHide child attributes
idstring (uuid)required
Unique endpoint ID.
hostnamestring
Endpoint hostname.
pagesobjectrequired
Show child attributesHide child attributes
currentintegerrequired
The 1-based page number being returned.
sizeintegerrequired
The size of the page being returned.
totalinteger
(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger
(Optional) The total number of items across all pages.
maxSizeintegerrequired
The maximum page size that can be requested.

Errors

Status Meaning
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "thumbprint": "string",
      "count": 0,
      "description": "string",
      "firstSeenAt": "2026-07-28T00:00:00Z",
      "lastSeenAt": "2026-07-28T00:00:00Z",
      "lastUser": {
        "id": "00000000-0000-0000-0000-000000000000",
        "name": "string"
      },
      "lastEndpoint": {
        "id": "00000000-0000-0000-0000-000000000000",
        "hostname": "string"
      }
    }
  ],
  "pages": {
    "current": 0,
    "size": 0,
    "total": 0,
    "items": 0,
    "maxSize": 0
  }
}

See the guide for a narrative walkthrough of this API.