Skip to content

Get applications

GET/settings/exploit-mitigation/applications

Endpoint API · Exploit Mitigation

Get Exploit Mitigation settings for all protected applications.

Required permissionendpoint-state:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
page query integer No The page number to fetch, starting with 1.
pageSize query integer No The size of the page requested.
pageTotal query boolean No Whether the number of pages should be calculated and returned in the response.
type query string No Exploit Mitigation Application type.
Must be one of: detected, custom.
modified query boolean No Whether or not Exploit Mitigation Application has been customized.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/applications", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — List of Exploit Mitigation applications.

Response fields

itemsarray of objectrequired
Show child attributesHide child attributes
idstring (uuid)required
ID of an Exploit Mitigation application.
namestringrequired
Name of this Exploit Mitigation application.
Must be 1–1000 characters long.
pathsarray of stringrequired
Paths included in this Exploit Mitigation application.
Must contain at most 100 items. Each item must be 1–260 characters long.
categorystringrequired
Exploit Mitigation category ID.
Must be one of: browsers, exclude, java, media, office, plugins, test, other.
typestringrequired
Whether the application was detected by the system or added by the user.
Must be one of: detected, custom.
modificationsobject
Modifications made to the detected Exploit Mitigation Application. This object does not apply to when type is custom.
Show child attributesHide child attributes
protectedbooleanrequired
Whether or not this Exploit Mitigation Application is protected.
settingsobject
pagesobjectrequired
Show child attributesHide child attributes
currentintegerrequired
The 1-based page number being returned.
sizeintegerrequired
The size of the page being returned.
totalinteger
(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger
(Optional) The total number of items across all pages.
maxSizeintegerrequired
The maximum page size that can be requested.

Errors

Status Meaning
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "name": "string",
      "paths": [
        "string"
      ],
      "category": "browsers",
      "type": "detected",
      "modifications": {
        "protected": true,
        "settings": {
          "ASLR": true,
          "BannedAPI": true,
          "BottomUpASLR": true,
          "Caller": true,
          "DEP": true,
          "DeviceAndIoControl": true,
          "HeapSpray": true,
          "IAF": true,
          "Intruder": true,
          "KbdGuard": false,
          "LoadLib": true,
          "LockdownAutorun": true,
          "LockdownLoadImage": false,
          "LockdownNewFile": false,
          "NullPage": true,
          "PreventEtwTampering": true,
          "SEHOP": true,
          "StackExec": true,
          "StackPivot": true
        }
      }
    }
  ],
  "pages": {
    "current": 0,
    "size": 0,
    "total": 0,
    "items": 0,
    "maxSize": 0
  }
}

See the guide for a narrative walkthrough of this API.