Sublime Security
The Sublime Security connector enables seamless integration with Swimlane Turbine, allowing users to manage email security rules and lists, and analyze message content for threats directly through the automation platform.
Sublime Security provides a robust platform for email threat detection and rule management. This connector enables Swimlane Turbine users to integrate with Sublime Security's services, allowing for the activation and deactivation of security rules, analysis of messages, and management of lists and rules within the organization. By leveraging this integration, users can automate complex security workflows, enhance email security, and streamline threat detection and response without the need for coding.
Limitations
- The connector requires a valid API key with appropriate permissions
- API rate limits may apply based on your Sublime Security subscription
Supported Version
The Sublime Security connector supports v0 version of the Sublime Security API.
Configuration
Prerequisites
To utilize the Sublime Security connector within Swimlane Turbine, ensure you have the following prerequisites:
- Sublime Security API Authentication:
- URL: Endpoint for the Sublime Security API.
- API Key: Unique identifier to authenticate requests to the Sublime Security API.
Authentication Methods
Sublime Security uses API Key authentication for secure access to its endpoints. When authenticating with the Sublime Security connector, provide your API key in the asset configuration. The connector will automatically include the key in the Authorization header of every request.
API Key Location:
- Header: Authorization: Bearer <your_api_key>
How to Retrieve API Key:
- Log into your Sublime Security admin portal.
- Go to the API section under account settings or integrations.
- Generate a new API key (or reuse an existing one with sufficient permissions).
- Copy this key and paste it into the API Key field during asset setup in Swimlane.
Capabilities
This connector provides the following capabilities:
- Activate Rule
- Analyze a Raw Message
- Create List
- Create Message
- Create Rule
- Deactivate Rule
- Delete List
- Delete Rule
- Get List
- List Rules
- Patch List
- Retrieve Message Data Model
- Retrieve Rule
- Retrieve lists
- Update Rule
Notes
- For detailed API documentation, refer to the Sublime Security API Reference
- Authentication documentation: Sublime Security Authentication Guide
- The API uses RESTful conventions with JSON request/response bodies
- All API requests require API key authentication using the x-apikey header
- Base URL format varies by deployment type (cloud, on-premises, etc.) and region
- Raw email messages must be base64 encoded before sending to the Create Message and Analyze Message endpoints
- For Triage rules, at least one triage_ field must be set to true
- For issues, questions, or contributions, please visit the connector repository.
Configurations
Sublime Security API Authentication
Sublime Security API Authentication
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
x-apikey | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Activate Rule
Activates a specified rule within your Sublime Security organization using the rule's unique identifier.
Endpoint
- URL: v0/rules/{{id}}/activate
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the rule to activate |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier |
active | boolean | Output field: active |
message | string | Response message |
Output Example
{"id":"string","active":true,"message":"string"}
Analyze a Raw Message
Analyzes a raw message using the active or specified rules within your Sublime Security organization.
Endpoint
- URL: v0/messages/analyze
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
raw_message | string | Optional | The full base64 encoded raw eml message. |
queries | array | Optional | Queries to analyze. |
queries.name | ['string', 'null'] | Optional | Query name. |
queries.severity | ['string', 'null'] | Optional | Severity associated with the query. |
queries.source | ['string', 'null'] | Required | The MQL source to run against the message. |
rules | array | Optional | Rules to analyze. |
run_active_detection_rules | boolean | Optional | Whether to analyze the message with all active detection rules in your organization. Defaults to false. |
run_all_detection_rules | boolean | Optional | Whether to analyze with all detection rules from all Feeds, including uninstalled/inactive Feed rules and your active rules. Defaults to false. |
run_all_insights | boolean | Optional | Whether to analyze with all insights. Defaults to false. |
Input Example
{"raw_message":"string","queries":[],"rules":[],"run_active_detection_rules":true,"run_all_detection_rules":true,"run_all_insights":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
query_results | array | Result of the operation |
query_results.error | string | Result of the operation |
query_results.execution_time | number | Result of the operation |
query_results.external_errors | array | Result of the operation |
query_results.query | object | Result of the operation |
query_results.query.name | string | Name of the resource |
query_results.query.severity | string | Result of the operation |
query_results.query.source | string | Result of the operation |
query_results.success | boolean | Result of the operation |
rule_results | array | Result of the operation |
rule_results.error | string | Result of the operation |
rule_results.execution_time | number | Result of the operation |
rule_results.external_errors | array | Result of the operation |
rule_results.matched | boolean | Result of the operation |
rule_results.rule | object | Result of the operation |
rule_results.rule.id | string | Unique identifier |
rule_results.rule.name | string | Name of the resource |
rule_results.rule.severity | string | Result of the operation |
rule_results.rule.source | string | Result of the operation |
rule_results.success | boolean | Result of the operation |
Output Example
{"json_body":{"query_results":[{}],"rule_results":[{}]},"status_code":200,"reason":"OK"}
Create List
Generates a new list within your Sublime Security organization using the specified name.
Endpoint
- URL: v0/lists
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
name | string | Optional | Name of the list |
description | string | Optional | Description of the list (optional) |
Input Example
{"name":"Example Name","description":"string"}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier for the list. |
name | string | Name of the created list. |
description | string | Description of the list. |
created_at | string | Creation timestamp of the list. |
updated_at | string | Last updated timestamp for the list. |
editable | boolean | Indicates if the list is editable. |
entry_type | string | Entry type of the list. |
Output Example
{"id":"string","name":"string","description":"string","created_at":"string","updated_at":"string","editable":true,"entry_type":"string"}
Create Message
Generates a new message data model in Sublime Security from a base64 encoded raw message.
Endpoint
- URL: v0/messages/create
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
raw_message | string | Optional | The full base64 encoded raw eml message |
canonical_id | string | Optional | The canonical ID of the message, if known (optional) |
external_created_at | string | Optional | Timestamp the message created at according to the external source (optional) |
external_message_id | string | Optional | ID of the message according to the external source (optional) |
external_thread_id | string | Optional | ID of the thread the message belongs to according to the external source (optional) |
folder | string | Optional | The mailbox folder the message is in (optional) |
labels | array | Optional | Labels applied to the message by the mailbox (optional) |
mailbox_email_address | string | Optional | The email address of the mailbox containing this message (optional) |
message_type | object | Optional | Override on message types, defined from the perspective of your organization (optional) |
message_type.inbound | boolean | Optional | Message was sent from someone outside your organization, to at least one recipient inside your organization |
message_type.internal | boolean | Optional | Message was sent from someone inside your organization, to at least one recipient inside your organization. Messages must be authenticated by either SPF or DKIM to be treated as internal. |
message_type.outbound | boolean | Optional | Message was sent from someone inside your organization, to at least one recipient outside your organization |
route_type | string | Optional | The directional route type of the message (optional) |
Input Example
{"raw_message":"string","canonical_id":"string","external_created_at":"string","external_message_id":"string","external_thread_id":"string","folder":"string","labels":["string"],"mailbox_email_address":"string","message_type":{"inbound":true,"internal":true,"outbound":true},"route_type":"string"}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier |
message_id | string | Unique identifier |
created_at | string | Output field: created_at |
Output Example
{"id":"string","message_id":"string","created_at":"string"}
Create Rule
Generates a new detection rule in Sublime Security using the specified 'name' and 'source'. A JSON body input is required.
Endpoint
- URL: v0/rules
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
name | string | Optional | Rule name |
source | string | Optional | Source |
type | string | Optional | Type of the rule |
description | string | Optional | Description of rule |
active | boolean | Optional | Activate the rule immediately |
action_ids | array | Optional | IDs of actions to run when the rule is triggered |
attack_types | array | Optional | Rule attack types |
authors | array | Optional | Rule authors. Defaults to the user that made the request |
authors.name | string | Optional | Name of a rule author |
authors.twitter | string | Optional | Twitter handle for a rule author |
auto_review_auto_share | boolean | Optional | Whether auto-reviewed messages will be shared |
auto_review_classification | string | Optional | The classification auto-reviewed messages will have, when an auto-review action is associated with the rule |
detection_methods | array | Optional | Rule detection technologies |
false_positives | array | Optional | Descriptions of known false positives that could occur |
label | string | Optional | Rule label |
maturity | string | Optional | Rule maturity |
references | array | Optional | URL references |
severity | string | Optional | Rule severity |
tactics_and_techniques | array | Optional | Rule tactics and techniques |
tags | array | Optional | Tags |
triage_abuse_reports | boolean | Optional | For Triage rules only, whether this rule will run for reported messages. For triage rules, one triage_ field must be true. |
triage_classification_changes | boolean | Optional | For Triage rules only, whether this rule will run for messages whose classification has just changed. For triage rules, one triage_ field must be true. |
triage_flagged_messages | boolean | Optional | For Triage rules only, whether this rule will run for messages which flagged. For triage rules, one triage_ field must be true. |
user_provided_tags | array | Optional | User-provided tags |
Input Example
{"name":"Example Name","source":"string","type":"string","description":"string","active":true,"action_ids":["string"],"attack_types":["string"],"authors":[{"name":"Example Name","twitter":"string"}],"auto_review_auto_share":true,"auto_review_classification":"string","detection_methods":["string"],"false_positives":["string"],"label":"string","maturity":"string","references":["string"],"severity":"string","tactics_and_techniques":["string"],"tags":["string"],"triage_abuse_reports":true,"triage_classification_changes":true,"triage_flagged_messages":true,"user_provided_tags":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier for the rule |
name | string | Name of the rule |
source | string | MQL source code of the rule |
type | string | Type of the rule |
description | string | Description of the rule |
active | boolean | Whether the rule is active |
passive | boolean | Whether the rule is passive |
action_ids | array | IDs of actions associated with the rule |
attack_types | array | Attack types associated with the rule |
authors | array | Authors of the rule |
authors.name | string | Name of the resource |
authors.twitter | string | Output field: authors.twitter |
auto_review_auto_share | boolean | Whether auto-reviewed messages will be shared |
auto_review_classification | string | Classification for auto-reviewed messages |
detection_methods | array | Detection methods used by the rule |
false_positives | array | Known false positives |
label | string | Rule label |
maturity | string | Rule maturity |
references | array | URL references |
severity | string | Rule severity |
tactics_and_techniques | array | Tactics and techniques |
tags | array | Tags associated with the rule |
triage_abuse_reports | boolean | Whether rule runs for reported messages (Triage rules only) |
triage_classification_changes | boolean | Whether rule runs for classification changes (Triage rules only) |
triage_flagged_messages | boolean | Whether rule runs for flagged messages (Triage rules only) |
Output Example
{"id":"string","name":"string","source":"string","type":"string","description":"string","active":true,"passive":true,"action_ids":[],"attack_types":[],"authors":[],"auto_review_auto_share":true,"auto_review_classification":"string","detection_methods":[],"false_positives":[],"label":"string"}
Deactivate Rule
Deactivates a specified rule within your Sublime Security organization using the rule's unique identifier.
Endpoint
- URL: v0/rules/{{id}}/deactivate
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the rule to deactivate |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier |
active | boolean | Output field: active |
message | string | Response message |
Output Example
{"id":"string","active":true,"message":"string"}
Delete List
Remove a specified list from your organization in Sublime Security by providing the unique identifier.
Endpoint
- URL: v0/lists/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the list to delete |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
success | boolean | Whether the operation was successful |
message | string | Response message |
Output Example
{"success":true,"message":"string"}
Delete Rule
Remove a specified rule from your organization in Sublime Security by providing the unique identifier.
Endpoint
- URL: v0/rules/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the rule to delete |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
success | boolean | Whether the operation was successful |
message | string | Response message |
Output Example
{"success":true,"message":"string"}
Get List
Retrieves detailed information for a specific list in Sublime Security using the provided list ID.
Endpoint
- URL: v0/lists/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the list to retrieve |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier for the list. |
name | string | Name of the list. |
description | string | Description of the list. |
created_at | string | Creation timestamp of the list. |
updated_at | string | Last updated timestamp for the list. |
editable | boolean | Indicates if the list is editable. |
entry_type | string | Entry type of the list. |
Output Example
{"id":"string","name":"string","description":"string","created_at":"string","updated_at":"string","editable":true,"entry_type":"string"}
List Rules
Retrieve a list of all active security rules from Sublime Security for further analysis or management.
Endpoint
- URL: v0/rules
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.in_feed | boolean | Optional | Restrict to rules that are explicitly in or not in a feed |
parameters.limit | integer | Optional | The maximum number of entries to return. Maximum value is 500. |
parameters.offset | integer | Optional | The (zero-based) offset of the first rule to return |
parameters.search | string | Optional | Search for matching case-insensitive substring across rule name, description, and MQL source |
Input Example
{"parameters":{"in_feed":true,"limit":50,"offset":123,"search":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
count | integer | Number of rules returned in this response |
rules | array | Output field: rules |
rules.id | string | Unique identifier for the rule |
rules.name | string | Name of the rule |
rules.description | string | Description of the rule |
rules.active | boolean | Whether the rule is active |
rules.severity | string | Severity level of the rule |
rules.source | string | MQL source code of the rule |
rules.references | array | List of references used by the rule |
rules.tags | array | Tags associated with the rule |
rules.created_at | string | ISO timestamp when the rule was created |
rules.updated_at | string | ISO timestamp when the rule was last updated |
total | integer | Total number of rules matching the query |
Output Example
{"count":123,"rules":[],"total":123}
Patch List
Updates an existing list identified by 'id' in Sublime Security with a new 'description'. Required inputs include path parameters and JSON body.
Endpoint
- URL: v0/lists/{{id}}
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the list to update |
description | string | Optional | Updated description of the list. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"description":"string"}
Output
Parameter | Type | Description |
|---|---|---|
id | string | The unique identifier for the list. |
name | string | Name of the list. |
description | string | Updated description of the list. |
created_at | string | ISO timestamp when the list was created. |
updated_at | string | ISO timestamp when the list was last updated. |
editable | boolean | Indicates if the list can be edited. |
entry_type | string | The type of entries contained in the list. |
Output Example
{"id":"string","name":"string","description":"string","created_at":"string","updated_at":"string","editable":true,"entry_type":"string"}
Retrieve lists
Retrieve filtered lists from Sublime Security based on the specified entry type parameter.
Endpoint
- URL: v0/lists
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.entry_type | string | Required | List type to filter by. Currently must be set to 'string' |
parameters.id | string | Optional | Optional ID (exact match) to filter by |
parameters.name | string | Optional | Optional name (exact match) to filter by |
Input Example
{"parameters":{"entry_type":"string","id":"12345678-1234-1234-1234-123456789abc","name":"Example Name"}}
Output
Parameter | Type | Description |
|---|---|---|
lists | array | Output field: lists |
lists.id | string | Unique identifier |
lists.name | string | Name of the resource |
lists.description | string | Output field: lists.description |
lists.entry_type | string | Type of the resource |
lists.editable | boolean | Output field: lists.editable |
lists.created_at | string | Output field: lists.created_at |
lists.updated_at | string | Output field: lists.updated_at |
Output Example
{"lists":[]}
Retrieve Message Data Model
Retrieve the data model for a specific message in Sublime Security using the message's unique identifier.
Endpoint
- URL: v0/messages/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the message to retrieve. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
_errors | array | Error message if any |
_errors.additionalProp | string | Error message if any |
_meta | object | Output field: _meta |
_meta.canonical_id | string | Unique identifier |
_meta.created_at | string | Output field: _meta.created_at |
_meta.effective_at | string | Output field: _meta.effective_at |
_meta.id | string | Unique identifier |
attachments | array | Output field: attachments |
attachments.content_id | string | Unique identifier |
attachments.content_transfer_encoding | string | Response content |
attachments.content_type | string | Type of the resource |
attachments.file_extension | string | Output field: attachments.file_extension |
attachments.file_name | string | Name of the resource |
attachments.file_type | string | Type of the resource |
attachments.md5 | string | Output field: attachments.md5 |
attachments.raw | string | Output field: attachments.raw |
attachments.sha1 | string | Output field: attachments.sha1 |
attachments.sha256 | string | Output field: attachments.sha256 |
attachments.size | integer | Output field: attachments.size |
body | object | Request body data |
body.current_thread | object | Request body data |
body.current_thread.links | array | Request body data |
body.current_thread.links.display_text | string | Request body data |
body.current_thread.links.display_url | string | Display URL |
body.current_thread.links.href_url | string | Href URL |
Output Example
{"_errors":[],"_meta":{"canonical_id":"string","created_at":"string","effective_at":"string","id":"12345678-1234-1234-1234-123456789abc"},"attachments":[],"body":{"current_thread":{"links":[],"text":"string"},"html":{"charset":"string","content_transfer_encoding":"string","display_text":"string","inner_text":"string","raw":"string"},"ips":[{}],"links":[{}],"plain":{"charset":"string","content_transfer_encoding":"string","raw":"string"},"previous_threads":[{}]},"external":{"created_at":"string","...
Retrieve Rule
Retrieve details of a specific rule in Sublime Security using the unique identifier provided as a path parameter.
Endpoint
- URL: v0/rules/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the rule to retrieve |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier for the rule. |
name | string | Name of the rule. |
description | string | Description of the rule. |
action_ids | array | IDs of actions to run when the rule is triggered. |
active | boolean | Whether the rule is active. |
attack_types | array | Rule attack types. |
authors | array | Rule authors. |
authors.name | string | Name of a rule author. |
authors.twitter | string | Twitter handle for a rule author. |
auto_review_auto_share | boolean | Whether auto-reviewed messages will be shared. |
auto_review_classification | string | The classification for auto-reviewed messages. |
created_at | string | Creation timestamp of the rule. |
detection_methods | array | Rule detection technologies. |
false_positives | array | Known false positives that could occur. |
label | string | Label of the rule. |
last_activated_at | string | Last time the rule was activated. |
maturity | string | Maturity of the rule. |
passive | boolean | Whether the rule runs passively. |
references | array | Rule references. |
severity | string | Severity level of the rule. |
source | string | MQL source of the rule. |
tactics_and_techniques | array | MITRE ATT&CK tactics and techniques. |
tags | array | Tags associated with the rule. |
triage_abuse_reports | boolean | Whether to triage abuse reports. |
triage_classification_changes | boolean | Whether to triage classification changes. |
Output Example
{"id":"string","name":"string","description":"string","action_ids":[],"active":true,"attack_types":[],"authors":[],"auto_review_auto_share":true,"auto_review_classification":"string","created_at":"string","detection_methods":[],"false_positives":[],"label":"string","last_activated_at":"string","maturity":"string"}
Update Rule
Updates an existing rule in Sublime Security with a new definition, requiring the rule's ID, name, and source.
Endpoint
- URL: v0/rules/{{id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Rule ID |
name | string | Optional | Rule name |
source | string | Optional | Source |
description | string | Optional | Description of rule |
action_ids | array | Optional | IDs of actions to run when the rule is triggered |
attack_types | array | Optional | Rule attack types |
authors | array | Optional | Rule authors. Defaults to the user that made the request |
authors.name | string | Optional | Name of a rule author |
authors.twitter | string | Optional | Twitter handle for a rule author |
auto_review_auto_share | boolean | Optional | Whether auto-reviewed messages will be shared |
auto_review_classification | string | Optional | The classification auto-reviewed messages will have, when an auto-review action is associated with the rule |
detection_methods | array | Optional | Rule detection technologies |
false_positives | array | Optional | Descriptions of known false positives that could occur |
label | string | Optional | Rule label |
maturity | string | Optional | Rule maturity |
references | array | Optional | URL references |
severity | string | Optional | Rule severity |
tactics_and_techniques | array | Optional | Rule tactics and techniques |
tags | array | Optional | Tags |
triage_abuse_reports | boolean | Optional | For Triage rules only, whether this rule will run for reported messages. For triage rules, one triage_ field must be true. |
triage_classification_changes | boolean | Optional | For Triage rules only, whether this rule will run for messages whose classification has just changed. For triage rules, one triage_ field must be true. |
triage_flagged_messages | boolean | Optional | For Triage rules only, whether this rule will run for messages which flagged. For triage rules, one triage_ field must be true. |
user_provided_tags | array | Optional | User-provided tags |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"name":"Example Name","source":"string","description":"string","action_ids":["string"],"attack_types":["string"],"authors":[{"name":"Example Name","twitter":"string"}],"auto_review_auto_share":true,"auto_review_classification":"string","detection_methods":["string"],"false_positives":["string"],"label":"string","maturity":"string","references":["string"],"severity":"string","tactics_and_techniques":["string"],"tags":["string"],"triage_abuse_reports":true,"triage_classification_changes":true,"triage_flagged_messages":true,"user_provided_tags":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier for the rule |
name | string | Name of the rule |
source | string | MQL source code of the rule |
type | string | Type of the rule |
description | string | Description of the rule |
active | boolean | Whether the rule is active |
passive | boolean | Whether the rule is passive |
action_ids | array | IDs of actions associated with the rule |
attack_types | array | Attack types associated with the rule |
authors | array | Authors of the rule |
authors.name | string | Name of the resource |
authors.twitter | string | Output field: authors.twitter |
auto_review_auto_share | boolean | Whether auto-reviewed messages will be shared |
auto_review_classification | string | Classification for auto-reviewed messages |
detection_methods | array | Detection methods used by the rule |
false_positives | array | Known false positives |
label | string | Rule label |
maturity | string | Rule maturity |
references | array | URL references |
severity | string | Rule severity |
tactics_and_techniques | array | Tactics and techniques |
tags | array | Tags associated with the rule |
triage_abuse_reports | boolean | Whether rule runs for reported messages (Triage rules only) |
triage_classification_changes | boolean | Whether rule runs for classification changes (Triage rules only) |
triage_flagged_messages | boolean | Whether rule runs for flagged messages (Triage rules only) |
Output Example
{"id":"string","name":"string","source":"string","type":"string","description":"string","active":true,"passive":true,"action_ids":[],"attack_types":[],"authors":[],"auto_review_auto_share":true,"auto_review_classification":"string","detection_methods":[],"false_positives":[],"label":"string"}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |