Get applications¶
GET/
Endpoint API · Exploit Mitigation
Get Exploit Mitigation settings for all protected applications.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
page | query | integer | No | The page number to fetch, starting with 1. |
pageSize | query | integer | No | The size of the page requested. |
pageTotal | query | boolean | No | Whether the number of pages should be calculated and returned in the response. |
type | query | string | No | Exploit Mitigation Application type. Must be one of: detected, custom. |
modified | query | boolean | No | Whether or not Exploit Mitigation Application has been customized. |
Request samples¶
curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"
import requests
response = requests.get(
"https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications" -Headers $headers
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications", nil)
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications", {
method: "GET",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
});
const data = await response.json();
console.log(data);
Responses¶
200 — List of Exploit Mitigation applications.¶
Response fields
itemsarray of objectrequiredShow child attributesHide child attributes
idstring (uuid)requiredID of an Exploit Mitigation application.
namestringrequiredName of this Exploit Mitigation application.
Must be 1–1000 characters long.
Must be 1–1000 characters long.
pathsarray of stringrequiredPaths included in this Exploit Mitigation application.
Must contain at most 100 items. Each item must be 1–260 characters long.
Must contain at most 100 items. Each item must be 1–260 characters long.
categorystringrequiredExploit Mitigation category ID.
Must be one of:
Must be one of:
browsers, exclude, java, media, office, plugins, test, other.typestringrequiredWhether the application was detected by the system or added by the user.
Must be one of:
Must be one of:
detected, custom.modificationsobjectModifications made to the detected Exploit Mitigation Application. This object does not apply to when type is
custom.Show child attributesHide child attributes
protectedbooleanrequiredWhether or not this Exploit Mitigation Application is protected.
settingsobjectpagesobjectrequiredShow child attributesHide child attributes
currentintegerrequiredThe 1-based page number being returned.
sizeintegerrequiredThe size of the page being returned.
totalinteger(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger(Optional) The total number of items across all pages.
maxSizeintegerrequiredThe maximum page size that can be requested.
Errors¶
| Status | Meaning |
|---|---|
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"items": [
{
"id": "00000000-0000-0000-0000-000000000000",
"name": "string",
"paths": [
"string"
],
"category": "browsers",
"type": "detected",
"modifications": {
"protected": true,
"settings": {
"ASLR": true,
"BannedAPI": true,
"BottomUpASLR": true,
"Caller": true,
"DEP": true,
"DeviceAndIoControl": true,
"HeapSpray": true,
"IAF": true,
"Intruder": true,
"KbdGuard": false,
"LoadLib": true,
"LockdownAutorun": true,
"LockdownLoadImage": false,
"LockdownNewFile": false,
"NullPage": true,
"PreventEtwTampering": true,
"SEHOP": true,
"StackExec": true,
"StackPivot": true
}
}
}
],
"pages": {
"current": 0,
"size": 0,
"total": 0,
"items": 0,
"maxSize": 0
}
}
See the guide for a narrative walkthrough of this API.