Skip to content

Get application

GET/settings/exploit-mitigation/applications/{exploitMitigationApplicationId}

Endpoint API · Exploit Mitigation

Get Exploit Mitigation settings for an application.

Required permissionendpoint-state:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
exploitMitigationApplicationId path string (uuid) Yes Exploit Mitigation application ID.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications/<exploitMitigationApplicationId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications/<exploitMitigationApplicationId>",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications/<exploitMitigationApplicationId>" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications/<exploitMitigationApplicationId>", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications/<exploitMitigationApplicationId>", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — Protected application.

Response fields

idstring (uuid)required
ID of an Exploit Mitigation application.
namestringrequired
Name of this Exploit Mitigation application.
Must be 1–1000 characters long.
pathsarray of stringrequired
Paths included in this Exploit Mitigation application.
Must contain at most 100 items. Each item must be 1–260 characters long.
categorystringrequired
Exploit Mitigation category ID.
Must be one of: browsers, exclude, java, media, office, plugins, test, other.
typestringrequired
Whether the application was detected by the system or added by the user.
Must be one of: detected, custom.
modificationsobject
Modifications made to the detected Exploit Mitigation Application. This object does not apply to when type is custom.
Show child attributesHide child attributes
protectedbooleanrequired
Whether or not this Exploit Mitigation Application is protected.
settingsobject

Errors

Status Meaning
404 Can't find protected application.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "paths": [
    "string"
  ],
  "category": "browsers",
  "type": "detected",
  "modifications": {
    "protected": true,
    "settings": {
      "ASLR": true,
      "BannedAPI": true,
      "BottomUpASLR": true,
      "Caller": true,
      "DEP": true,
      "DeviceAndIoControl": true,
      "HeapSpray": true,
      "IAF": true,
      "Intruder": true,
      "KbdGuard": false,
      "LoadLib": true,
      "LockdownAutorun": true,
      "LockdownLoadImage": false,
      "LockdownNewFile": false,
      "NullPage": true,
      "PreventEtwTampering": true,
      "SEHOP": true,
      "StackExec": true,
      "StackPivot": true
    }
  }
}

See the guide for a narrative walkthrough of this API.