Skip to content

Get categories

GET/settings/exploit-mitigation/categories

Endpoint API · Exploit Mitigation

Get Exploit Mitigation categories.

Required permissionendpoint-state:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/categories" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/categories",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/categories" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/categories", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exploit-mitigation/categories", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — List of Exploit Mitigation categories.

Response fields

itemsarray of objectrequired
Category of applications protected from exploits.
Show child attributesHide child attributes
idstringrequired
Exploit Mitigation category ID.
Must be one of: browsers, exclude, java, media, office, plugins, test, other.
namestringrequired
Category name.
Must match the pattern [a-zA-Z ]{1,50}.
settingsobjectrequired

Errors

Status Meaning
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "browsers",
      "name": "Browsers",
      "settings": {
        "ASLR": true,
        "BannedAPI": true,
        "BottomUpASLR": true,
        "Caller": true,
        "DEP": true,
        "DeviceAndIoControl": true,
        "HeapSpray": true,
        "IAF": true,
        "Intruder": true,
        "KbdGuard": false,
        "LoadLib": true,
        "LockdownAutorun": true,
        "LockdownLoadImage": false,
        "LockdownNewFile": false,
        "NullPage": true,
        "PreventEtwTampering": true,
        "SEHOP": true,
        "StackExec": true,
        "StackPivot": true
      }
    }
  ]
}

See the guide for a narrative walkthrough of this API.