Trellix Ips
The Trellix IPS connector enables seamless integration between Trellix's Intrusion Prevention System and Swimlane Turbine, facilitating automated security workflows and enhanced threat management.
Trellix IPS is a robust security platform that specializes in intrusion prevention and detection. This connector enables seamless integration with third-party tools, allowing users to manage firewall policies, attack filters, and rule objects directly within Swimlane Turbine. By leveraging this connector, security teams can automate the enforcement of security policies, streamline threat response, and enhance overall security posture with minimal manual intervention.
Limitations
None to date.
Supported Versions
This Trellix IPS connector uses the latest Version API.
Additional Docs
Configuration
Prerequisites
To effectively utilize the Trellix IPS connector with Swimlane Turbine, ensure you have the following prerequisites:
- Trellix IPS Authentication with the following parameters:
- URL: The endpoint URL for the Trellix IPS API.
- Username: The username credential for Trellix IPS access.
- Password: The password credential for Trellix IPS access.
Authentication Methods
- URL: The endpoint URL for the Trellix IPS API.
- Username: Your Trellix IPS username with sufficient permissions.
- Password: The password associated with your Trellix IPS account.
Capabilities
This Trellix IPS connector provides the following capabilities:
- Add Firewall Policy
- Add Rule Object
- Add new Attack Filter
- Assign Attack Filter to Domain and Attack
- Assign Attack Filter to Interface and Attack
- Assign Attack Filter to Sensor and Attack
- Create New IPS Policy
- Create a New Scanning Exception at Sensor
- Create or Update Light Weight Policy
- Delete Attack Filter
- Delete Firewall Policy
- Delete IPS Policy
- Delete Light Weight Policy
- Delete Rule Object
- Delete Scanning Exception on a Sensor ... and so on
Configurations
Trellix IPS Authentication
Trellix IPS Authentication.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | url. | string | Required |
username | Username used to authenticate with the NSM API. | string | Required |
password | Password for the NSM user account. | string | Required |
verify_ssl | Verify SSL certificates when making requests to NSM. | boolean | Optional |
http_proxy | Proxy server to route requests through. | string | Optional |
Actions
Add Firewall Policy
Adds a new firewall policy to Trellix IPS with specified name, domain ID, visibility, editability, type, and member details.
Endpoint
- URL: /firewallpolicy
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
Name | string | Optional | Name of the resource |
DomainId | number | Optional | Unique identifier |
VisibleToChild | boolean | Optional | Parameter for Add Firewall Policy |
Description | string | Optional | Parameter for Add Firewall Policy |
LastModifiedTime | string | Optional | Time value |
IsEditable | boolean | Optional | Parameter for Add Firewall Policy |
PolicyType | string | Optional | Type of the resource |
PolicyVersion | number | Optional | Parameter for Add Firewall Policy |
LastModifiedUser | string | Optional | Parameter for Add Firewall Policy |
MemberDetails | object | Optional | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList | array | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.Description | string | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.Enabled | boolean | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.Response | string | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.IsLogging | boolean | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.Direction | string | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.SourceAddressObjectList | array | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.SourceAddressObjectList.RuleObjectId | string | Required | Unique identifier |
MemberDetails.MemberRuleList.SourceAddressObjectList.Name | string | Required | Name of the resource |
MemberDetails.MemberRuleList.SourceAddressObjectList.RuleObjectType | string | Required | Type of the resource |
MemberDetails.MemberRuleList.DestinationAddressObjectList | array | Required | Parameter for Add Firewall Policy |
MemberDetails.MemberRuleList.DestinationAddressObjectList.RuleObjectId | string | Required | Unique identifier |
MemberDetails.MemberRuleList.DestinationAddressObjectList.Name | string | Required | Name of the resource |
MemberDetails.MemberRuleList.DestinationAddressObjectList.RuleObjectType | string | Required | Type of the resource |
MemberDetails.MemberRuleList.SourceUserObjectList | array | Required | Parameter for Add Firewall Policy |
Input Example
{"json_body":{"Name":"TestFirewallPolicy","DomainId":0,"VisibleToChild":true,"Description":"test the firewallpolicy","LastModifiedTime":"2012-12-12 12:30:47","IsEditable":true,"PolicyType":"ADVANCED","PolicyVersion":1,"LastModifiedUser":"admin","MemberDetails":{"MemberRuleList":[{"Description":"Test Member Rule","Enabled":true,"Response":"SCAN","IsLogging":false,"Direction":"INBOUND","SourceAddressObjectList":[{"RuleObjectId":"AF","Name":"Afghanistan","RuleObjectType":"COUNTRY"}],"DestinationAddressObjectList":[{"RuleObjectId":"101","Name":"hostDNSRule","RuleObjectType":"HOST_DNS_NAME"},{"RuleObjectId":"102","Name":"hostIpv4","RuleObjectType":"HOST_IPV_4"},{"RuleObjectId":"103","Name":"ipv4Addressrange","RuleObjectType":"IPV_4_ADDRESS_RANGE"},{"RuleObjectId":"104","Name":"networkgroup","RuleObjectType":"NETWORK_GROUP"}],"SourceUserObjectList":[{"RuleObjectId":"-1","Name":"Any","RuleObjectType":"USER"}],"ServiceObjectList":[],"ApplicationObjectList":[{"RuleObjectId":"1308991488","Name":"100bao","RuleObjectType":"APPLICATION","ApplicationType":"DEFAULT"},{"RuleObjectId":"106","Name":"applicaionOncutomPort","RuleObjectType":"APPLICATION_ON_CUSTOM_PORT","ApplicationType":"CUSTOM"},{"RuleObjectId":"105","Name":"applicationgroup","RuleObjectType":"APPLICATION_GROUP","ApplicationType":"CUSTOM"}],"TimeObjectList":[{"RuleObjectId":"107","Name":"finiteTimePeriod","RuleObjectType":"FINITE_TIMING_PERIOD"},{"RuleObjectId":"108","Name":"recuringTimePeriod","RuleObjectType":"RECURRING_TIME_PERIOD"},{"RuleObjectId":"109","Name":"recurringTimeperiodGroup","RuleObjectType":"RECURRING_TIME_PERIOD_GROUP"}]}]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
createdResourceId | number | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"createdResourceId":120}}
Add new Attack Filter
Adds a new Attack Filter to Trellix IPS using Type, name, DomainId, and MatchCriteria as configuration parameters.
Endpoint
- URL: /attackfilter
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
DomainId | number | Optional | Id of domain to which this attack filter belongs to. |
Description | string | Optional | Description of the attack filter. |
MatchCriteria | object | Optional | Match criteria for the attack filter |
MatchCriteria.Exclusion | array | Required | List of IP - port exclusions. |
MatchCriteria.Exclusion.Ip | object | Optional | IPv4 or IPv6 IP. |
MatchCriteria.Exclusion.Ip.destEnd | string | Optional | Destination IP end range. |
MatchCriteria.Exclusion.Ip.destMode | string | Required | Destination IP mode. |
MatchCriteria.Exclusion.Ip.srcMode | string | Required | Source IP mode. |
MatchCriteria.Exclusion.Ip.srcStart | string | Optional | Source IP start range. |
MatchCriteria.Exclusion.Ip.destStart | string | Optional | Destination IP start range. |
MatchCriteria.Exclusion.Ip.srcEnd | string | Optional | Source IP end range. |
MatchCriteria.Exclusion.Port | object | Optional | TCP/UDP Port. |
MatchCriteria.Exclusion.Port.srcPortMode | string | Required | Source Port mode. |
MatchCriteria.Exclusion.Port.srcPort | string | Optional | Source Port. |
MatchCriteria.Exclusion.Port.destPort | string | Optional | Destination Port. |
MatchCriteria.Exclusion.Port.destPortMode | string | Required | Destination Port mode. |
Type | string | Optional | Attack filter type. |
name | string | Optional | Name of the attack filter. |
Input Example
{"json_body":{"DomainId":0,"Description":"try ","MatchCriteria":{"Exclusion":[{"Ip":{"destEnd":"1.1.1.18","destMode":"RANGE_IP","srcMode":"SINGLE_IP","srcStart":"1.1.1.1","destStart":"1.1.1.13","srcEnd":"1.1.1.11"},"Port":{"srcPortMode":"TCP","srcPort":"85","destPort":"89","destPortMode":"TCP"}}]},"Type":"IPV_4_AND_TCP_UDP_PORT","name":"test1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
createdResourceId | number | Unique identifier |
Output Example
{"status_code":200,"reason":"OK","json_body":{"createdResourceId":419}}
Add Rule Object
Adds a new rule object to Trellix IPS with specified ID, type, name, description, domain, and visibility settings.
Endpoint
- URL: sdkapi/ruleobject
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
ruleobjId | number | Optional | The ID of the rule object to add. |
ruleobjType | string | Optional | The type of the rule object to add. |
name | string | Optional | The name of the rule object to add. |
description | string | Optional | The description of the rule object to add. |
domain | number | Optional | ID of domain in which the rule object is defined. |
visibleToChild | boolean | Optional | Is rule object visible to child. |
ApplicationGroup | object | Optional | Application group object, should be defined if ruleobjType is APPLICATION_GROUP. |
ApplicationGroup.ApplicationIdentifier | array | Required | List of applications identifier. |
ApplicationGroup.ApplicationIdentifier.applicationRuleObjId | number | Required | ID of the application rule object. |
ApplicationGroup.ApplicationIdentifier.applicationType | string | Required | Type of the application. |
ApplicationOnCustomPort | object | Optional | Application defined on custom port object, should be defined if ruleobjType is APPLICATION_ON_CUSTOM_PORT. |
ApplicationOnCustomPort.applicationId | string | Required | ID of the application. |
ApplicationOnCustomPort.portsList | array | Required | List of ports. |
ApplicationOnCustomPort.portsList.IPProtocol | string | Required | IP protocol, can be "TCP" or "UDP". |
ApplicationOnCustomPort.portsList.port | number | Required | Port number. |
FiniteTimePeriod | object | Optional | Finite time period rule object, should be defined if ruleobjType is FINITE_TIME_PERIOD. |
FiniteTimePeriod.from | string | Required | Start time of the time period. |
FiniteTimePeriod.until | string | Required | End time of the time period. |
HostIPv4 | object | Optional | Host IPv4 rule object, should be defined if ruleobjType is HOST_IPV_4. |
HostIPv4.hostIPv4AddressList | array | Required | List of host IPv4 addresses. |
HostIPv4.hostIPv4AddressList.ruleObjID | number | Required | Rule object ID. |
HostIPv4.hostIPv4AddressList.state | number | Required | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. |
HostIPv4.hostIPv4AddressList.comment | string | Optional | Comment for the rule member. |
HostIPv4.hostIPv4AddressList.userID | number | Required | User ID of the rule member. |
HostIPv4.hostIPv4AddressList.value | string | Required | Value of the rule member. |
Input Example
{"ruleobjId":123,"ruleobjType":"string","name":"Example Name","description":"string","domain":123,"visibleToChild":true,"ApplicationGroup":{"ApplicationIdentifier":[{"applicationRuleObjId":123,"applicationType":"string"}]},"ApplicationOnCustomPort":{"applicationId":"string","portsList":[{"IPProtocol":"string","port":123}]},"FiniteTimePeriod":{"from":"string","until":"string"},"HostIPv4":{"hostIPv4AddressList":[{"ruleObjID":123,"state":123,"comment":"string","userID":123,"value":"string"}]},"HostIPv6":{"hostIPv6AddressList":[{"ruleObjID":123,"state":123,"comment":"string","userID":123,"value":"string"}]},"HostDNSName":{"hostDNSNameList":[{"ruleObjID":123,"state":123,"comment":"string","userID":123,"value":"string"}]},"IPv4AddressRange":{"IPV4RangeList":[{"ruleObjID":123,"state":123,"comment":"string","userID":123,"FromAddress":"string","ToAddress":"string"}]},"IPv6AddressRange":{"IPV6RangeList":[{"ruleObjID":123,"state":123,"comment":"string","userID":123,"FromAddress":"string","ToAddress":"string"}]},"NetworkIPv4":{"networkIPV4List":[{"ruleObjID":123,"state":123,"comment":"string","userID":123,"value":"string"}]},"NetworkIPv6":{"networkIPV6List":[{"ruleObjID":123,"state":123,"comment":"string","userID":123,"value":"string"}]},"NetworkGroup":{"NetworkGroupIdentifier":[{"RuleObjId":123,"type":"string"}]},"RecurringTimePeriod":{"entireDay":true,"day":["string"],"duration":{"from":"string","until":"string"}},"RecurringTimePeriodGroup":{"recurringTimePeriodsId":[123]},"Service":{"protocol":"string","portNumber":"string"},"ServiceRange":{"protocol":"string","From":"string","To":"string"},"ServiceGroup":{"ServiceIdentifier":[{"ServiceRuleObjId":123,"ServiceType":"string"}]},"NetworkGroupAF":{"NetworkGroupIdentifier":[{"RuleObjId":123,"type":"string"}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
createdResourceId | number | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"createdResourceId":235}}
Assign Attack Filter to Domain and Attack
Assign specific attack filters to a domain and attack within Trellix IPS using the provided domain ID and AssignAttackFilterRequest.
Endpoint
- URL: /domain/{{domain_id}}/attackfilter
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_id | number | Required | ID of the domain in which the attack filter is created. |
AssignAttackFilterRequest | array | Optional | List of attack filters. |
AssignAttackFilterRequest.Direction | string | Required | Attack direction |
AssignAttackFilterRequest.AttackId | string | Required | ID of the attack. |
AssignAttackFilterRequest.FilterId | array | Required | List of filter IDs to be assigned to the attack. |
AssignAttackFilterRequest.Overwrite | boolean | Required | Whether to overwrite existing filters assigned to the attack. |
Input Example
{"json_body":{"AssignAttackFilterRequest":[{"Direction":"INBOUND","AttackId":"0x40503900","FilterId":[419,420],"Overwrite":true},{"Direction":"INBOUND","AttackId":"0x48304e00","FilterId":[419],"Overwrite":true}]},"path_parameters":{"domain_id":12345}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Assign Attack Filter to Interface and Attack
Assigns specified attack filters to an interface or subinterface and attack in Trellix IPS, utilizing sensor_id, interface_id, and AssignAttackFilterRequest.
Endpoint
- URL: /sensor/{{sensor_id}}/interface/{{interface_id}}/attackfilter
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | ID of the sensor to which the attack filter is to be assigned. |
path_parameters.interface_id | number | Required | Interface/subinterface id to which the attack filter is to be assigned. |
AssignAttackFilterRequest | array | Optional | List of attack filters. |
AssignAttackFilterRequest.Direction | string | Required | Attack direction |
AssignAttackFilterRequest.AttackId | string | Required | ID of the attack. |
AssignAttackFilterRequest.FilterId | array | Required | List of filter IDs to be assigned. |
AssignAttackFilterRequest.Overwrite | boolean | Required | Whether to overwrite existing assignments. |
Input Example
{"json_body":{"AssignAttackFilterRequest":[{"Direction":"INBOUND","AttackId":"0x40503900","FilterId":[419,420],"Overwrite":true},{"Direction":"INBOUND","AttackId":"0x48304e00","FilterId":[419],"Overwrite":true}]},"path_parameters":{"sensor_id":121234,"interface_id":111223}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Assign Attack Filter to Sensor and Attack
Assigns specified attack filters to both a sensor and an attack within Trellix IPS, utilizing the sensor ID and AssignAttackFilterRequest.
Endpoint
- URL: /sensor/{{sensor_id}}/attackfilter
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | ID of the sensor to which the attack filter is to be assigned. |
AssignAttackFilterRequest | array | Optional | List of attack filters. |
AssignAttackFilterRequest.Direction | string | Required | Attack direction. |
AssignAttackFilterRequest.AttackId | string | Required | ID of the attack. |
AssignAttackFilterRequest.FilterId | array | Required | List of filter IDs. |
AssignAttackFilterRequest.Overwrite | boolean | Required | Overwrite filter. |
Input Example
{"json_body":{"AssignAttackFilterRequest":[{"Direction":"INBOUND","AttackId":"0x40503900","FilterId":[419,420],"Overwrite":true},{"Direction":"INBOUND","AttackId":"0x48304e00","FilterId":[419],"Overwrite":true}]},"path_parameters":{"sensor_id":12341}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Create a New Scanning Exception at Sensor
Creates a new scanning exception on a Trellix IPS sensor using the provided sensor_id and ScanningExceptionDetailsElement.
Endpoint
- URL: /sensor/{{sensor_id}}/scanningexception
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID |
ScanningExceptionDetailsElement | object | Optional | Object that contains the details of the field to be sent. |
ScanningExceptionDetailsElement.scanningExceptionDetails | object | Required | Object that contains the details of the field to be sent. |
ScanningExceptionDetailsElement.scanningExceptionDetails.forwardType | string | Optional | Can be one of these - TCP/UDP/VLAN |
ScanningExceptionDetailsElement.scanningExceptionDetails.portInfo | object | Optional | Contains the TCP/UDP port informations. |
ScanningExceptionDetailsElement.scanningExceptionDetails.portInfo.portRange | object | Optional | Contains the port range information. |
ScanningExceptionDetailsElement.scanningExceptionDetails.portInfo.portRange.from | object | Required | Start port value. |
ScanningExceptionDetailsElement.scanningExceptionDetails.portInfo.portRange.to | object | Required | End port value. |
ScanningExceptionDetailsElement.scanningExceptionDetails.portInfo.portNumber | object | Optional | Contains the port number information. |
ScanningExceptionDetailsElement.scanningExceptionDetails.portInfo.portNumber.value | number | Required | Specified port value. |
ScanningExceptionDetailsElement.scanningExceptionDetails.vlanInfo | object | Optional | Contains the VLAN information. |
ScanningExceptionDetailsElement.scanningExceptionDetails.vlanInfo.portPairName | object | Required | Name of the port pair on which scanning exception of VLAN type should be created. |
ScanningExceptionDetailsElement.scanningExceptionDetails.vlanInfo.vlanIds | object | Optional | Contains the VLAN information. |
ScanningExceptionDetailsElement.scanningExceptionDetails.vlanInfo.vlanIds.vlanRange | object | Optional | Contains the VLAN range information. |
ScanningExceptionDetailsElement.scanningExceptionDetails.vlanInfo.vlanIds.vlanId | object | Optional | Contains the VLAN id information. |
Input Example
{"path_parameters":{"sensor_id":123},"ScanningExceptionDetailsElement":{"scanningExceptionDetails":{"forwardType":"string","portInfo":{"portRange":{},"portNumber":{}},"vlanInfo":{"portPairName":{},"vlanIds":{}}}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Create New IPS Policy
Creates a new global Intrusion Prevention System policy in Trellix IPS with specified name, description, visibility, rule sets, and DOS sensitivity.
Endpoint
- URL: /sdkapi/domain/{{domain_id}}/ipspolicies/createips
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_id | number | Required | The unique identifier of the domain for which the IPS policy is being created. |
PolicyName | string | Optional | The name of the IPS policy to be created. |
Description | string | Optional | A brief description of the IPS policy. |
IsVisibleToChildren | boolean | Optional | Indicates if the policy is visible to child domains. |
InboundRuleSet | string | Optional | The rule set to apply for inbound traffic. |
OutboundRuleSet | string | Optional | The rule set to apply for outbound traffic. |
DosResponseSensitivityLevel | number | Optional | Sensitivity level for DoS response (e.g., 1 for low, 2 for medium, etc.). |
direction | number | Optional | The direction of the policy (e.g., 1 for inbound, 2 for outbound). |
Input Example
{"json_body":{"PolicyName":"IPS policytest1","Description":"test","IsVisibleToChildren":true,"InboundRuleSet":"Default Prevention","OutboundRuleSet":"DMZ","DosResponseSensitivityLevel":1,"direction":1},"path_parameters":{"domain_id":0}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
createdResourceId | number | Unique identifier |
Output Example
{"status_code":200,"reason":"OK","json_body":{"createdResourceId":105}}
Create or Update Light Weight Policy
Create or update a lightweight policy on Trellix IPS using sensor_id, interface_id, and PolicyDescriptor.
Endpoint
- URL: /sensor/{{sensor_id}}/interface/{{interface_id}}/localipspolicy
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | The unique identifier of the sensor for which the policy is being created or updated. |
path_parameters.interface_id | number | Required | The unique identifier of the interface for which the policy is being created or updated. |
PolicyDescriptor | object | Optional | The policy descriptor containing the configuration details for the light weight policy. |
PolicyDescriptor.PolicyName | string | Required | The name of the policy. |
PolicyDescriptor.Description | string | Required | A brief description of the policy. |
PolicyDescriptor.IsVisibleToChildren | boolean | Required | Indicates whether this policy is visible to child entities in the hierarchy. |
PolicyDescriptor.InboundRuleSet | string | Required | The name of the inbound rule set associated with this policy. |
PolicyDescriptor.OutboundRuleSet | string | Required | The name of the outbound rule set associated with this policy. |
PolicyDescriptor.AttackCategory | object | Required | The category of attacks that this policy is configured to handle. |
PolicyDescriptor.AttackCategory.ExpolitAttackList | array | Required | List of exploits and attacks for the policy. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.attackName | string | Required | The name of the attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.nspId | string | Required | The unique identifier for the attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.severity | number | Required | The severity level of the attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isSeverityCustomized | boolean | Required | Indicates whether the severity level has been customized for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isEnabled | boolean | Required | Indicates whether this attack is enabled in the policy. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isAlertCustomized | boolean | Required | Indicates whether the alert settings for this attack have been customized. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isRecommendedForSmartBlocking | boolean | Required | Indicates whether this attack is recommended for smart blocking. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse | object | Required | The response actions to be taken for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.TCPReset | string | Required | The TCP reset action to be taken for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isTcpResetCustomized | boolean | Required | Indicates whether the TCP reset action has been customized for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSend | boolean | Required | Indicates whether an ICMP send action is configured for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSendCustomized | boolean | Required | Indicates whether the ICMP send action has been customized for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.mcAfeeNACNotification | string | Required | The McAfee NAC notification setting for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isMcAfeeNACNotificationEnabled | boolean | Required | Indicates whether the McAfee NAC notification is enabled for this attack. |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isQuarantineCustomized | boolean | Required | Indicates whether the quarantine settings for this attack have been customized. |
Input Example
{"path_parameters":{"sensor_id":123,"interface_id":123},"PolicyDescriptor":{"PolicyName":"Example Name","Description":"string","IsVisibleToChildren":true,"InboundRuleSet":"string","OutboundRuleSet":"string","AttackCategory":{"ExpolitAttackList":[{"attackName":"Example Name","nspId":"string","severity":123,"isSeverityCustomized":true,"isEnabled":true,"isAlertCustomized":true,"isRecommendedForSmartBlocking":true,"AttackResponse":{},"notification":{},"protocolList":["string"],"benignTriggerProbability":"string","blockingType":"string","subCategory":"string","direction":"string","isAttackCustomized":true}]},"OutboundAttackCategory":{},"DosPolicy":{"LearningAttack":[{"attackName":"Example Name","nspId":"string","isSeverityCustomized":true,"severity":123,"isBlockingSettingCustomized":true,"isDropPacket":true,"IsAlertCustomized":true,"isSendAlertToManager":true,"direction":"string","notification":{},"isAttackCustomized":true}],"ThresholdAttack":[{"attackName":"Example Name","nspId":"string","isSeverityCustomized":true,"severity":123,"isThresholdValueCustomized":true,"isThresholdDurationCustomized":true,"ThresholdValue":123,"ThresholdDuration":123,"isAlertCustomized":true,"isSendAlertToManager":true,"Notification":{},"direction":"string","isAttackCustomized":true}],"TimeStamp":"2024-01-01T00:00:00Z"},"ReconPolicy":{"TimeStamp":{},"ReconAttackList":[{"IsAlertCustomized":true,"isSeverityCustomized":true,"direction":{},"severity":123,"isThresholdDurationCustomized":true,"isSendAlertToManager":true,"isQuarantineCustomized":true,"attackName":"Example Name","ThresholdDuration":123,"alertSuppressionTimer":123,"isAlertSuppressionTimerCustomized":true,"isAttackCustomized":true,"isMcAfeeNACNotificationEnabled":true,"isThresholdValueCustomized":true,"nspId":"string","mcAfeeNACNotification":"string","isRemediateEnabled":true,"timeStamp":{},"ThresholdValue":123,"notification":{}}]},"DosResponseSensitivityLevel":123,"IsEditable":true,"Timestamp":"2024-01-01T00:00:00Z","VersionNum":123,"IsLightWeightPolicy":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
createdResourceId | number | Unique identifier |
Output Example
{"status_code":200,"reason":"OK","json_body":{"createdResourceId":105}}
Delete Attack Filter
Deletes a specified attack filter from Trellix IPS using the provided unique attackfilter_id.
Endpoint
- URL: /attackfilter/{{attackfilter_id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.attackfilter_id | number | Required | ID of the attack filter to be deleted. |
Input Example
{"path_parameters":{"attackfilter_id":12345}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Delete Firewall Policy
Removes a specified firewall policy from Trellix IPS using the provided unique policy ID.
Endpoint
- URL: /firewallpolicy/{{policy_id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.policy_id | number | Required | The unique identifier of the firewall policy to be deleted. |
Input Example
{"path_parameters":{"policy_id":120}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Delete IPS Policy
Removes a specified Intrusion Prevention System policy from Trellix IPS using the provided policy ID.
Endpoint
- URL: /ipspolicy/{{policyid}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.policyid | number | Required | The unique identifier of the IPS policy to be deleted. |
Input Example
{"path_parameters":{"policyid":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
createdResourceId | number | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"createdResourceId":120}}
Delete Light Weight Policy
Removes a local Intrusion Prevention System policy from a specified sensor interface in Trellix IPS using sensor and interface IDs.
Endpoint
- URL: /sensor/{{sensor_id}}/interface/{{interface_id}}/localipspolicy
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | The unique identifier of the sensor for which the policy is being created or updated. |
path_parameters.interface_id | number | Required | The unique identifier of the interface for which the policy is being created or updated. |
Input Example
{"path_parameters":{"sensor_id":1001,"Interface_id":501}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Delete Rule Object
Removes a specified rule object from Trellix IPS; fails if the object is currently in use.
Endpoint
- URL: sdkapi/ruleobject/{{ruleobject_id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ruleobject_id | number | Required | The ID of the rule object to delete. |
Input Example
{"path_parameters":{"ruleobject_id":21}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Delete Scanning Exception on a Sensor
Removes a specified scanning exception from a Trellix IPS sensor using the sensor ID and ScanningExceptionDeleteElement.
Endpoint
- URL: /sensor/{{sensor_id}}/scanningexception
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID |
ScanningExceptionDeleteElement | string | Optional | Object that contains the details of the field to be sent. |
Input Example
{"path_parameters":{"sensor_id":123},"ScanningExceptionDeleteElement":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Download Invalid Rule Members CSV file
Downloads a CSV file with invalid rule members from Trellix IPS using the specified rule object ID.
Endpoint
- URL: /sdkapi/ruleobject/downloadInvalidROMembers
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ruleObjectId | number | Required | The ID of the rule object to download the invalid rule members from. |
Input Example
{"parameters":{"ruleobject_id":121}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
file | object | Attachments |
file.file | string | Output field: file.file |
file.file_name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{},"file":{"file_name":"invalid_rule_members.csv","file":"data:application/vnd.ms-excel;base64,..."}}
Enable or Disable Scanning Exception on a Sensor
Enable or disable a scanning exception for a Trellix IPS sensor by specifying the sensor ID and status element.
Endpoint
- URL: /sensor/{{sensor_id}}/scanningexception/status
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID |
ScanningExceptionStatusElement | object | Optional | Object that contains the details of the field to be sent |
ScanningExceptionStatusElement.enabled | boolean | Required | Indicates if scanning exception is enabled on the sensor. |
Input Example
{"path_parameters":{"sensor_id":123},"ScanningExceptionStatusElement":{"enabled":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Export Rule Members to a CSV file
Downloads a CSV file with rule members from Trellix IPS using the specified ruleObjectId.
Endpoint
- URL: sdkapi/ruleobject/exportROMembers
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ruleObjectId | number | Required | The ID of the rule object to export the rule members from. |
Input Example
{"parameters":{"ruleObjectId":0}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
file | object | Attachments |
file.file | string | Output field: file.file |
file.file_name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{},"file":{"file_name":"invalid_rule_members.csv","file":"data:application/vnd.ms-excel;base64,..."}}
Get an Attack Filter
Retrieve detailed information for a specified Attack Filter in Trellix IPS using the unique attackfilter_id.
Endpoint
- URL: /attackfilter/{{attackfilter_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.attackfilter_id | number | Required | ID of the attack filter to be retrieved. |
Input Example
{"path_parameters":{"attackfilter_id":12345}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
DomainId | number | Unique identifier |
MatchCriteria | object | Output field: MatchCriteria |
MatchCriteria.Exclusion | array | Output field: MatchCriteria.Exclusion |
MatchCriteria.Exclusion.Ip | object | Output field: MatchCriteria.Exclusion.Ip |
MatchCriteria.Exclusion.Port | object | Output field: MatchCriteria.Exclusion.Port |
MatchCriteria.Exclusion.Port.srcPortMode | string | Output field: MatchCriteria.Exclusion.Port.srcPortMode |
MatchCriteria.Exclusion.Port.srcPort | string | Output field: MatchCriteria.Exclusion.Port.srcPort |
MatchCriteria.Exclusion.Port.destPort | string | Output field: MatchCriteria.Exclusion.Port.destPort |
MatchCriteria.Exclusion.Port.destPortMode | string | Output field: MatchCriteria.Exclusion.Port.destPortMode |
LastModTs | string | Output field: LastModTs |
attackFilterId | number | Unique identifier |
Type | string | Type of the resource |
name | string | Name of the resource |
Output Example
{"status_code":200,"reason":"OK","json_body":{"DomainId":0,"MatchCriteria":{"Exclusion":[]},"LastModTs":"2012-07-24 00:19:00","attackFilterId":420,"Type":"TCP_UDP_PORT","name":"test2"}}
Get Attack Filters Assigned to Domain and Attack
Retrieves all attack filters assigned to a specific domain and attack in Trellix IPS, requiring domain_id and attack_id as parameters.
Endpoint
- URL: /domain/{{domain_id}}/attackfilter/{{attack_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_id | number | Required | ID of domain in which the attack filter is created. |
path_parameters.attack_id | string | Required | Attack ID to which attack filters are assigned. |
Input Example
{"path_parameters":{"domain_id":12345,"attack_id":"123ekpp"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
AttackFilterDescriptor | array | Output field: AttackFilterDescriptor |
AttackFilterDescriptor.VisibleToChild | boolean | Output field: AttackFilterDescriptor.VisibleToChild |
AttackFilterDescriptor.name | string | Name of the resource |
AttackFilterDescriptor.IsEditable | boolean | Output field: AttackFilterDescriptor.IsEditable |
AttackFilterDescriptor.filterId | number | Unique identifier |
AttackFilterDescriptor.DomainId | number | Unique identifier |
AttackFilterDescriptor.LastModTs | string | Output field: AttackFilterDescriptor.LastModTs |
Output Example
{"status_code":200,"reason":"OK","json_body":{"AttackFilterDescriptor":[{},{}]}}
Get Attack Filters Assigned to Interface
Retrieves all attack filters assigned to a specified interface or subinterface within Trellix IPS for a given attack, requiring sensor_id, interface_id, and attack_id.
Endpoint
- URL: /sensor/{{sensor_id}}/interface/{{interface_id}}/attackfilter/{{attack_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | ID of the sensor to which the attack filter is assigned. |
path_parameters.interface_id | number | Required | Interface/subinterface id to which the attack filter is assigned. |
path_parameters.attack_id | string | Required | Attack ID to which attack filters are assigned. |
Input Example
{"path_parameters":{"sensor_id":12123,"interface_id":14321,"attack_id":"13edfp"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
AttackFilterDescriptor | array | Output field: AttackFilterDescriptor |
AttackFilterDescriptor.VisibleToChild | boolean | Output field: AttackFilterDescriptor.VisibleToChild |
AttackFilterDescriptor.name | string | Name of the resource |
AttackFilterDescriptor.IsEditable | boolean | Output field: AttackFilterDescriptor.IsEditable |
AttackFilterDescriptor.filterId | number | Unique identifier |
AttackFilterDescriptor.DomainId | number | Unique identifier |
AttackFilterDescriptor.LastModTs | string | Output field: AttackFilterDescriptor.LastModTs |
Output Example
{"status_code":200,"reason":"OK","json_body":{"AttackFilterDescriptor":[{},{}]}}
Get Attack Filters Assigned to Sensor and Attack
Retrieves all attack filters assigned to a specific sensor and attack in Trellix IPS, using sensor_id and attack_id.
Endpoint
- URL: /sensor/{{sensor_id}}/attackfilter/{{attack_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | ID of the sensor to which the attack filter is assigned. |
path_parameters.attack_id | string | Required | Attack ID to which attack filters are assigned. |
Input Example
{"path_parameters":{"sensor_id":1234,"attack_id":"12wepq"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
AttackFilterDescriptor | array | Output field: AttackFilterDescriptor |
AttackFilterDescriptor.VisibleToChild | boolean | Output field: AttackFilterDescriptor.VisibleToChild |
AttackFilterDescriptor.name | string | Name of the resource |
AttackFilterDescriptor.IsEditable | boolean | Output field: AttackFilterDescriptor.IsEditable |
AttackFilterDescriptor.filterId | number | Unique identifier |
AttackFilterDescriptor.DomainId | number | Unique identifier |
AttackFilterDescriptor.LastModTs | string | Output field: AttackFilterDescriptor.LastModTs |
Output Example
{"status_code":200,"reason":"OK","json_body":{"AttackFilterDescriptor":[{},{}]}}
Get Attack Filters Assignments
Retrieve assignments for a specific attack filter by ID in Trellix IPS, encompassing all attacks and resources.
Endpoint
- URL: /attackfilter/{{attackfilter_id}}/assignments
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.attackfilter_id | number | Required | ID of the attack filter whose assignments are to be retrieved. |
Input Example
{"path_parameters":{"attackfilter_id":12351}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
AssignmentDetails | array | Output field: AssignmentDetails |
AssignmentDetails.resourceName | string | Name of the resource |
AssignmentDetails.attackId | string | Unique identifier |
Output Example
{"status_code":200,"reason":"OK","json_body":{"AssignmentDetails":[{},{}]}}
Get Attack Filters Defined in a Domain
Retrieves all attack filters within a specified domain in Trellix IPS, using the provided domain ID.
Endpoint
- URL: /attackfilters?domain={{domain_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_id | number | Required | ID of the domain in which the attack filter has been created. |
Input Example
{"path_parameters":{"domain_id":12345}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
AttackFilterDescriptor | array | Output field: AttackFilterDescriptor |
AttackFilterDescriptor.VisibleToChild | boolean | Output field: AttackFilterDescriptor.VisibleToChild |
AttackFilterDescriptor.name | string | Name of the resource |
AttackFilterDescriptor.IsEditable | boolean | Output field: AttackFilterDescriptor.IsEditable |
AttackFilterDescriptor.filterId | number | Unique identifier |
AttackFilterDescriptor.DomainId | number | Unique identifier |
AttackFilterDescriptor.LastModTs | string | Output field: AttackFilterDescriptor.LastModTs |
Output Example
{"status_code":200,"reason":"OK","json_body":{"AttackFilterDescriptor":[{},{}]}}
Get Firewall Policies in Domain
Retrieve all firewall policies within a specified domain in Trellix IPS using the provided domain ID.
Endpoint
- URL: /domain/{{domain_id}}/firewallpolicy
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_id | number | Required | The unique identifier of the domain for which firewall policies are being retrieved. |
Input Example
{"path_parameters":{"domain_id":120}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
FirewallPoliciesForDomainResponseList | array | Output field: FirewallPoliciesForDomainResponseList |
FirewallPoliciesForDomainResponseList.policyId | number | Unique identifier |
FirewallPoliciesForDomainResponseList.policyName | string | Name of the resource |
FirewallPoliciesForDomainResponseList.domainId | number | Unique identifier |
FirewallPoliciesForDomainResponseList.visibleToChild | boolean | Output field: FirewallPoliciesForDomainResponseList.visibleToChild |
FirewallPoliciesForDomainResponseList.description | string | Output field: FirewallPoliciesForDomainResponseList.description |
FirewallPoliciesForDomainResponseList.isEditable | boolean | Output field: FirewallPoliciesForDomainResponseList.isEditable |
FirewallPoliciesForDomainResponseList.policyType | string | Type of the resource |
FirewallPoliciesForDomainResponseList.policyVersion | number | Output field: FirewallPoliciesForDomainResponseList.policyVersion |
FirewallPoliciesForDomainResponseList.lastModUser | string | Output field: FirewallPoliciesForDomainResponseList.lastModUser |
Output Example
{"status_code":200,"reason":"OK","json_body":{"FirewallPoliciesForDomainResponseList":[{"policyId":107,"policyName":"Port_FirewallPolicy","domainId":0,"visibleToChild":false,"description":"Firewall Policy for Port","isEditable":true,"policyType":"CLASSIC","policyVersion":1,"lastModUser":"admin"},{"policyId":105,"policyName":"Interface_FirewallPolicy","domainId":0,"visibleToChild":true,"description":"Firewall Policy for Interface","isEditable":true,"policyType":"ADVANCED","policyVersion":1,"lastM...
Get Firewall Policy
Retrieve details of a specific firewall policy in Trellix IPS using the provided policy ID.
Endpoint
- URL: /firewallpolicy/{{policy_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.policy_id | number | Required | The unique identifier of the firewall policy to be deleted. |
Input Example
{"path_parameters":{"policy_id":120}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
FirewallPolicyId | number | Unique identifier |
Name | string | Name of the resource |
DomainId | number | Unique identifier |
VisibleToChild | boolean | Output field: VisibleToChild |
Description | string | Output field: Description |
LastModifiedTime | string | Time value |
IsEditable | boolean | Output field: IsEditable |
PolicyType | string | Type of the resource |
PolicyVersion | number | Output field: PolicyVersion |
LastModifiedUser | string | Output field: LastModifiedUser |
MemberDetails | object | Output field: MemberDetails |
MemberDetails.MemberRuleList | array | Output field: MemberDetails.MemberRuleList |
MemberDetails.MemberRuleList.Description | string | Output field: MemberDetails.MemberRuleList.Description |
MemberDetails.MemberRuleList.Enabled | boolean | Output field: MemberDetails.MemberRuleList.Enabled |
MemberDetails.MemberRuleList.Response | string | Output field: MemberDetails.MemberRuleList.Response |
MemberDetails.MemberRuleList.IsLogging | boolean | Output field: MemberDetails.MemberRuleList.IsLogging |
MemberDetails.MemberRuleList.Direction | string | Output field: MemberDetails.MemberRuleList.Direction |
MemberDetails.MemberRuleList.SourceAddressObjectList | array | Output field: MemberDetails.MemberRuleList.SourceAddressObjectList |
MemberDetails.MemberRuleList.SourceAddressObjectList.RuleObjectId | string | Unique identifier |
MemberDetails.MemberRuleList.SourceAddressObjectList.Name | string | Name of the resource |
MemberDetails.MemberRuleList.SourceAddressObjectList.RuleObjectType | string | Type of the resource |
MemberDetails.MemberRuleList.DestinationAddressObjectList | array | Output field: MemberDetails.MemberRuleList.DestinationAddressObjectList |
MemberDetails.MemberRuleList.DestinationAddressObjectList.RuleObjectId | string | Unique identifier |
Output Example
{"status_code":200,"reason":"OK","json_body":{"FirewallPolicyId":120,"Name":"TestFirewallPolicy","DomainId":0,"VisibleToChild":true,"Description":"test the firewallpolicy","LastModifiedTime":"2012-12-12 12:43:54","IsEditable":true,"PolicyType":"ADVANCED","PolicyVersion":1,"LastModifiedUser":"admin","MemberDetails":{"MemberRuleList":[]}}}
Get IPS Policies in a Domain
Retrieves all Intrusion Prevention System policies within a specified domain in Trellix IPS using the provided domain ID.
Endpoint
- URL: /domain/{{domain_id}}/ipspolicies
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain_id | number | Required | The unique identifier of the domain for which IPS policies are being retrieved. |
Input Example
{"path_parameters":{"domain_id":0}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
PolicyDescriptorDetailsList | array | Output field: PolicyDescriptorDetailsList |
PolicyDescriptorDetailsList.name | string | Name of the resource |
PolicyDescriptorDetailsList.DomainId | string | Unique identifier |
PolicyDescriptorDetailsList.policyId | string | Unique identifier |
PolicyDescriptorDetailsList.IsEditable | string | Output field: PolicyDescriptorDetailsList.IsEditable |
PolicyDescriptorDetailsList.VisibleToChild | string | Output field: PolicyDescriptorDetailsList.VisibleToChild |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"PolicyDescriptorDetailsList":[{"name":"Default IPS Attack Settings","DomainId":"0","policyId":"-1","IsEditable":"true","VisibleToChild":"true"},{"name":"Default IDS","DomainId":"0","policyId":"0","IsEditable":"true","VisibleToChild":"true"},{"name":"All-Inclusive Without Audit","DomainId":"0","policyId":"16","IsEditable":"true","VisibleToChild":"true"}]}}
Get IPS Policy Details
Retrieve detailed information for a specific Trellix IPS policy, including attack sets and response actions, using the policy ID.
Endpoint
- URL: /ipspolicy/{{policy_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.policy_id | number | Required | The unique identifier of the IPS policy for which details are being retrieved. |
Input Example
{"path_parameters":{"policy_id":0}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
PolicyDescriptor | object | Output field: PolicyDescriptor |
PolicyDescriptor.PolicyName | string | Name of the resource |
PolicyDescriptor.Description | string | Output field: PolicyDescriptor.Description |
PolicyDescriptor.IsVisibleToChildren | boolean | Output field: PolicyDescriptor.IsVisibleToChildren |
PolicyDescriptor.InboundRuleSet | string | Output field: PolicyDescriptor.InboundRuleSet |
PolicyDescriptor.OutboundRuleSet | string | Output field: PolicyDescriptor.OutboundRuleSet |
PolicyDescriptor.AttackCategory | object | Output field: PolicyDescriptor.AttackCategory |
PolicyDescriptor.AttackCategory.ExpolitAttackList | array | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList |
PolicyDescriptor.AttackCategory.ExpolitAttackList.attackName | string | Name of the resource |
PolicyDescriptor.AttackCategory.ExpolitAttackList.nspId | string | Unique identifier |
PolicyDescriptor.AttackCategory.ExpolitAttackList.severity | number | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.severity |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isSeverityCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isSeverityCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isEnabled | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isEnabled |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isAlertCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isAlertCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isRecommendedForSmartBlocking | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isRecommendedForSmartBlocking |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse | object | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.TCPReset | string | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.TCPReset |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isTcpResetCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isTcpResetCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSend | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSend |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSendCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSendCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.mcAfeeNACNotification | string | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.mcAfeeNACNotification |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isMcAfeeNACNotificationEnabled | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isMcAfeeNACNotificationEnabled |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isQuarantineCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isQuarantineCustomized |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"PolicyDescriptor":{"PolicyName":"IpsPolicy","Description":"To test the IPS policy","IsVisibleToChildren":true,"InboundRuleSet":"TestIPS","OutboundRuleSet":"Null","AttackCategory":{},"OutboundAttackCategory":{},"DosPolicy":{},"DosResponseSensitivityLevel":0,"IsEditable":false,"Timestamp":"2012-06-20 18:44:55.000","VersionNum":1,"IsLightWeightPolicy":false}}}
Get Light Weight Policy details
Retrieve lightweight policy details for a specified sensor and interface in Trellix IPS, using sensor_id and interface_id.
Endpoint
- URL: /sensor/{{sensor_id}}/interface/{{interface_id}}/localipspolicy
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | The unique identifier of the sensor for which the policy is being created or updated. |
path_parameters.interface_id | number | Required | The unique identifier of the interface for which the policy is being created or updated. |
Input Example
{"path_parameters":{"sensor_id":1001,"Interface_id":501,"subinterface_id":105}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
PolicyDescriptor | object | Output field: PolicyDescriptor |
PolicyDescriptor.PolicyName | string | Name of the resource |
PolicyDescriptor.Description | string | Output field: PolicyDescriptor.Description |
PolicyDescriptor.IsVisibleToChildren | boolean | Output field: PolicyDescriptor.IsVisibleToChildren |
PolicyDescriptor.InboundRuleSet | string | Output field: PolicyDescriptor.InboundRuleSet |
PolicyDescriptor.OutboundRuleSet | string | Output field: PolicyDescriptor.OutboundRuleSet |
PolicyDescriptor.AttackCategory | object | Output field: PolicyDescriptor.AttackCategory |
PolicyDescriptor.AttackCategory.ExpolitAttackList | array | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList |
PolicyDescriptor.AttackCategory.ExpolitAttackList.attackName | string | Name of the resource |
PolicyDescriptor.AttackCategory.ExpolitAttackList.nspId | string | Unique identifier |
PolicyDescriptor.AttackCategory.ExpolitAttackList.severity | number | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.severity |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isSeverityCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isSeverityCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isEnabled | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isEnabled |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isAlertCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isAlertCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.isRecommendedForSmartBlocking | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.isRecommendedForSmartBlocking |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse | object | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.TCPReset | string | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.TCPReset |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isTcpResetCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isTcpResetCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSend | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSend |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSendCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isICMPSendCustomized |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.mcAfeeNACNotification | string | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.mcAfeeNACNotification |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isMcAfeeNACNotificationEnabled | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isMcAfeeNACNotificationEnabled |
PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isQuarantineCustomized | boolean | Output field: PolicyDescriptor.AttackCategory.ExpolitAttackList.AttackResponse.isQuarantineCustomized |
Output Example
{"status_code":200,"reason":"OK","json_body":{"PolicyDescriptor":{"PolicyName":"Local Policy - /My Company/IPS_NS9200/G3/1-G3/2/interface-1","Description":"To test the policies","IsVisibleToChildren":true,"InboundRuleSet":"testRuleSet","OutboundRuleSet":"Null","AttackCategory":{},"OutboundAttackCategory":{},"DosPolicy":{},"ReconPolicy":{},"DosResponseSensitivityLevel":0,"IsEditable":false,"Timestamp":"2012-08-31 15:20:55.000","VersionNum":1,"IsLightWeightPolicy":true}}}
Get Quarantined Host Details
Retrieve details of hosts quarantined by Trellix IPS using the specified sensor ID.
Endpoint
- URL: /sensor/{{sensor_id}}/action/quarantinehost/details
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID. |
Input Example
{"path_parameters":{"sensor_id":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
quarantineHostDetail | array | Output field: quarantineHostDetail |
quarantineHostDetail.ipAddress | string | Output field: quarantineHostDetail.ipAddress |
quarantineHostDetail.quarantineDetails | object | Output field: quarantineHostDetail.quarantineDetails |
quarantineHostDetail.quarantineDetails.device | string | Output field: quarantineHostDetail.quarantineDetails.device |
quarantineHostDetail.quarantineDetails.quarantineZone | string | Output field: quarantineHostDetail.quarantineDetails.quarantineZone |
quarantineHostDetail.addedToQuarantine | object | Output field: quarantineHostDetail.addedToQuarantine |
quarantineHostDetail.addedToQuarantine.by | string | Output field: quarantineHostDetail.addedToQuarantine.by |
quarantineHostDetail.addedToQuarantine.time | string | Time value |
quarantineHostDetail.remediate | boolean | Output field: quarantineHostDetail.remediate |
quarantineHostDetail.pendingRelease | string | Output field: quarantineHostDetail.pendingRelease |
Output Example
{"status_code":200,"reason":"OK","json_body":{"quarantineHostDetail":[{}]}}
Get Quarantined Hosts
Retrieve a list of hosts quarantined by a specific sensor in Trellix IPS using the sensor's ID.
Endpoint
- URL: /sensor/{{sensor_id}}/action/quarantinehost
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID. |
Input Example
{"path_parameters":{"sensor_id":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
QuarantineHostDescriptor | array | Output field: QuarantineHostDescriptor |
QuarantineHostDescriptor.IPAddress | string | Output field: QuarantineHostDescriptor.IPAddress |
QuarantineHostDescriptor.Duration | number | Output field: QuarantineHostDescriptor.Duration |
Output Example
{"status_code":200,"reason":"OK","json_body":{"QuarantineHostDescriptor":[{},{}]}}
Get Rule Object
Retrieves detailed information for a specified rule object in Trellix IPS using the ruleobject_id.
Endpoint
- URL: sdkapi/ruleobject/{{ruleobject_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ruleobject_id | number | Required | The ID of the rule object to get. |
Input Example
{"path_parameters":{"ruleobject_id":121}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
RuleObjDef | object | Output field: RuleObjDef |
RuleObjDef.ruleobjId | string | Unique identifier |
RuleObjDef.ruleobjType | string | Type of the resource |
RuleObjDef.name | string | Name of the resource |
RuleObjDef.description | string | Output field: RuleObjDef.description |
RuleObjDef.domain | number | Output field: RuleObjDef.domain |
RuleObjDef.visibleToChild | boolean | Output field: RuleObjDef.visibleToChild |
RuleObjDef.hostCriticality | string | Output field: RuleObjDef.hostCriticality |
RuleObjDef.ApplicationGroup | object | Output field: RuleObjDef.ApplicationGroup |
RuleObjDef.ApplicationOnCustomPort | object | Output field: RuleObjDef.ApplicationOnCustomPort |
RuleObjDef.FiniteTimePeriod | object | Output field: RuleObjDef.FiniteTimePeriod |
RuleObjDef.HostIPv4 | object | Output field: RuleObjDef.HostIPv4 |
RuleObjDef.HostIPv4.hostIPv4AddressList | array | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList |
RuleObjDef.HostIPv4.hostIPv4AddressList.ruleObjectID | number | Unique identifier |
RuleObjDef.HostIPv4.hostIPv4AddressList.value | string | Value for the parameter |
RuleObjDef.HostIPv4.hostIPv4AddressList.state | number | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList.state |
RuleObjDef.HostIPv4.hostIPv4AddressList.comment | string | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList.comment |
RuleObjDef.HostIPv4.hostIPv4AddressList.userID | number | Unique identifier |
RuleObjDef.HostIPv4.hostIPv4AddressList.changedState | number | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList.changedState |
RuleObjDef.HostIPv6 | object | Output field: RuleObjDef.HostIPv6 |
RuleObjDef.HostDNSName | object | Name of the resource |
RuleObjDef.IPv4AddressRange | object | Output field: RuleObjDef.IPv4AddressRange |
RuleObjDef.IPv6AddressRange | object | Output field: RuleObjDef.IPv6AddressRange |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"RuleObjDef":{"ruleobjId":"234","ruleobjType":"HOST_IPV_4","name":"test_SDK3","description":"try","domain":0,"visibleToChild":true,"hostCriticality":"HIGH","ApplicationGroup":null,"ApplicationOnCustomPort":null,"FiniteTimePeriod":null,"HostIPv4":{},"HostIPv6":null,"HostDNSName":null,"IPv4AddressRange":null,"IPv6AddressRange":null}}}
Get Rule Object Associations
Retrieve associations of a specific rule object across all modules in Trellix IPS using the ruleobject_id.
Endpoint
- URL: sdkapi/ruleobject/{{ruleobject_id}}/assignments
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ruleobject_id | number | Required | The ID of the rule object to get the associations for. |
Input Example
{"path_parameters":{"ruleobject_id":121}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
RuleObjectAssociationResponseList | array | Output field: RuleObjectAssociationResponseList |
RuleObjectAssociationResponseList.usagePath | string | Output field: RuleObjectAssociationResponseList.usagePath |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"RuleObjectAssociationResponseList":[{},{}]}}
Get Rule Objects in a Domain
Retrieves a list of rule objects within a specified domain in Trellix IPS, requiring the domain ID and object type.
Endpoint
- URL: sdkapi/domain/{{domain_id}}/ruleobject
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.type | string | Required | Rule object type, can be application, applicationgroup, applicationoncustomport, country, finitetimeperiod, hostdnsname, hostipv4, hostipv6, ipv4addressrange, ipv6addressrange, network ipv4, networkipv6, networkgroup, recurringtimeperiod, recurringtimeperiodgroup, service, servicerange, servicegroup. |
path_parameters.domain_id | number | Required | Parameters for the Get Rule Objects in a Domain action |
Input Example
{"parameters":{"type":"application,applicationgroup"},"path_parameters":{"domain_id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
RuleObjDef | array | Output field: RuleObjDef |
RuleObjDef.ruleobjId | string | Unique identifier |
RuleObjDef.ruleobjType | string | Type of the resource |
RuleObjDef.name | string | Name of the resource |
RuleObjDef.description | string | Output field: RuleObjDef.description |
RuleObjDef.domain | number | Output field: RuleObjDef.domain |
RuleObjDef.visibleToChild | boolean | Output field: RuleObjDef.visibleToChild |
RuleObjDef.hostCriticality | string | Output field: RuleObjDef.hostCriticality |
RuleObjDef.ApplicationGroup | object | Output field: RuleObjDef.ApplicationGroup |
RuleObjDef.ApplicationOnCustomPort | object | Output field: RuleObjDef.ApplicationOnCustomPort |
RuleObjDef.FiniteTimePeriod | object | Output field: RuleObjDef.FiniteTimePeriod |
RuleObjDef.HostIPv4 | object | Output field: RuleObjDef.HostIPv4 |
RuleObjDef.HostIPv4.hostIPv4AddressList | array | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList |
RuleObjDef.HostIPv4.hostIPv4AddressList.ruleObjectID | number | Unique identifier |
RuleObjDef.HostIPv4.hostIPv4AddressList.value | string | Value for the parameter |
RuleObjDef.HostIPv4.hostIPv4AddressList.state | number | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList.state |
RuleObjDef.HostIPv4.hostIPv4AddressList.comment | string | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList.comment |
RuleObjDef.HostIPv4.hostIPv4AddressList.userID | number | Unique identifier |
RuleObjDef.HostIPv4.hostIPv4AddressList.changedState | number | Output field: RuleObjDef.HostIPv4.hostIPv4AddressList.changedState |
RuleObjDef.HostIPv6 | object | Output field: RuleObjDef.HostIPv6 |
RuleObjDef.HostDNSName | object | Name of the resource |
RuleObjDef.IPv4AddressRange | object | Output field: RuleObjDef.IPv4AddressRange |
RuleObjDef.IPv6AddressRange | object | Output field: RuleObjDef.IPv6AddressRange |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"RuleObjDef":[{}]}}
Get Scanning Exception details on a Sensor
Retrieve scanning exception details for a specified sensor in Trellix IPS using the provided sensor ID.
Endpoint
- URL: /sensor/{{sensor_id}}/scanningexception
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID |
ScanningExceptionResponseElement | object | Optional | Object that contains the details of the field to be sent. |
ScanningExceptionResponseElement.tcpRules | object | Optional | Object containing TCP rule settings. |
ScanningExceptionResponseElement.tcpRules.tcpPortRangeList | object | Optional | List of objects containing TCP port range setting. |
ScanningExceptionResponseElement.tcpRules.tcpPortRangeList.tcpPortRange | string | Optional | TCP port range in format "from-to". |
ScanningExceptionResponseElement.udpRules | object | Optional | Object containing UDP rule settings. |
ScanningExceptionResponseElement.udpRules.udpPortRangeList | object | Optional | List of objects containing UDP port range setting. |
ScanningExceptionResponseElement.udpRules.udpPortRangeList.udpPortRange | string | Optional | UDP port range in format "from-to". |
ScanningExceptionResponseElement.vlanRules | object | Optional | Object containing VLAN rule settings. |
ScanningExceptionResponseElement.vlanRules.vlanIdRangeList | object | Optional | List of objects containing VLAN id range setting. |
ScanningExceptionResponseElement.vlanRules.vlanIdRangeList.vlanIdRange | string | Optional | Vlan Id range in format "from-to". |
ScanningExceptionResponseElement.vlanRules.vlanIdRangeList.portPairName | string | Optional | Name of the port pair. |
Input Example
{"path_parameters":{"sensor_id":123},"ScanningExceptionResponseElement":{"tcpRules":{"tcpPortRangeList":{"tcpPortRange":"string"}},"udpRules":{"udpPortRangeList":{"udpPortRange":"string"}},"vlanRules":{"vlanIdRangeList":{"vlanIdRange":"string","portPairName":"Example Name"}}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Get Scanning Exception Status on a Sensor
Retrieve the scanning exception status on a specific sensor in Trellix IPS using the provided sensor_id and ScanningExceptionStatusElement.
Endpoint
- URL: /sensor/{{sensor_id}}/scanningexception/status
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID |
ScanningExceptionStatusElement | object | Optional | Object that contains the details of the field to be sent |
ScanningExceptionStatusElement.enabled | boolean | Required | Indicates if scanning exception is enabled on the sensor. |
Input Example
{"path_parameters":{"sensor_id":123},"ScanningExceptionStatusElement":{"enabled":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Get User Group
Retrieves user group rule objects from Trellix IPS, providing an overview of group configurations.
Endpoint
- URL: sdkapi/ruleobject/usergroup
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
userGroupRuleObjectResponseList | array | Output field: userGroupRuleObjectResponseList |
userGroupRuleObjectResponseList.ruleObjectId | string | Unique identifier |
userGroupRuleObjectResponseList.ruleObjectName | string | Name of the resource |
userGroupRuleObjectResponseList.ruleObjectType | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"userGroupRuleObjectResponseList":[{},{}]}}
Get User Rule Objects
Retrieves a list of user-defined rule objects from Trellix IPS for further analysis or modification.
Endpoint
- URL: sdkapi/ruleobject/user
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | The filter to apply to the user rule objects. |
parameters.max_entries_expected | number | Optional | The maximum number of entries expected. |
Input Example
{"parameters":{"filter":"user","max_entries_expected":100}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
userRuleObjectResponseList | array | Output field: userRuleObjectResponseList |
userRuleObjectResponseList.ruleObjectId | string | Unique identifier |
userRuleObjectResponseList.ruleObjectName | string | Name of the resource |
userRuleObjectResponseList.ruleObjectType | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"userRuleObjectResponseList":[{},{}]}}
Import Rule Members to existing rule obj from file
Imports rule members from a CSV file to an existing Trellix IPS rule object, requiring 'importOption' and 'ruleObjId'.
Endpoint
- URL: sdkapi/ruleobject/importEditROMembers
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.importOption | number | Required | Import option ID, should be 1 to append and 2 to replace the existing rule members. |
parameters.ruleObjId | number | Required | The ID of the rule object to import the rule members to. |
files | object | Required | CSV file containing the rule members to import. |
files.file | string | Optional | Parameter for Import Rule Members to existing rule obj from file |
files.file_name | string | Optional | Name of the resource |
Input Example
{"parameters":{"importOption_id":2,"ruleObjId":0},"files":{"file_name":"rule_members.csv","file":"data:application/vnd.ms-excel;base64,..."}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
ruleObjectId | number | Unique identifier |
errorCode | number | Error message if any |
errorMsg | object | Error message if any |
invalidEntriesExist | boolean | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"ruleObjectId":238,"errorCode":0,"errorMsg":null,"invalidEntriesExist":true}}
Import Rule Members to new rule object from file
Imports rule members to a new Trellix IPS rule object from a specified CSV file, requiring files, data body, and import options.
Endpoint
- URL: sdkapi/ruleobject/importROMembers
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.importOption | number | Required | Import option ID, should be 1 to append and 2 to replace the existing rule members. |
parameters.ruleObjId | number | Optional | The ID of the rule object to import the rule members to. |
data_body | object | Required | Response data |
data_body.roPropertiesJson | object | Required | Response data |
data_body.roPropertiesJson.RuleObjDef | object | Required | Response data |
data_body.roPropertiesJson.RuleObjDef.ruleobjId | number | Required | The ID of the rule object to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.ruleobjType | string | Required | The type of the rule object to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.name | string | Required | The name of the rule object to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.description | string | Required | The description of the rule object to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.domain | number | Required | The domain of the rule object to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.visibleToChild | boolean | Required | Is rule object visible to child. |
data_body.roPropertiesJson.RuleObjDef.HostIPv4 | object | Optional | The list of host IPv4 addresses to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.HostIPv4.hostIPv4AddressList | array | Required | The list of host IPv4 addresses to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.HostIPv6 | object | Optional | The list of host IPv6 addresses to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.HostIPv6.hostIPv6AddressList | array | Required | The list of host IPv6 addresses to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.NetworkIPv4 | object | Optional | The list of network IPv4 addresses to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.NetworkIPv4.networkIPV4List | array | Required | The list of network IPv4 addresses to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.NetworkIPv6 | object | Optional | The list of network IPv6 addresses to import the rule members to. |
data_body.roPropertiesJson.RuleObjDef.NetworkIPv6.networkIPv6List | array | Required | The list of network IPv6 addresses to import the rule members to. |
files | object | Required | CSV file containing the rule members to import. |
files.file | string | Optional | Parameter for Import Rule Members to new rule object from file |
files.file_name | string | Optional | Name of the resource |
Input Example
{"parameters":{"importOption_id":2,"ruleObjId":0},"data_body":{"roPropertiesJson":{"RuleObjDef":{"ruleobjId":0,"ruleobjType":"HOST_IPV_4","name":"test_SDK6","description":"try","domain":0,"visibleToChild":true,"HostIPv4":{"hostIPv4AddressList":[]},"HostIPv6":{"hostIPv6AddressList":[]},"NetworkIPv4":{"networkIPV4List":[]},"NetworkIPv6":{"networkIPv6List":[]}}}},"files":{"file_name":"rule_members.csv","file":"data:application/vnd.ms-excel;base64,..."}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
ruleObjectId | number | Unique identifier |
errorCode | number | Error message if any |
errorMsg | object | Error message if any |
invalidEntriesExist | boolean | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"success":true,"ruleObjectId":238,"errorCode":0,"errorMsg":null,"invalidEntriesExist":true}}
Quarantine Host
Isolates a host for a specified duration using the Trellix IPS sensor, requiring both sensor ID and IP address.
Endpoint
- URL: /sensor/{{sensor_id}}/action/quarantinehost
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID. |
IPAddress | string | Optional | IPv4/IPv6 to be quarantined. |
Duration | string | Optional | Duration for which the IP is to be quarantined. |
remediate | boolean | Optional | Remediate the IP along with quarantine. |
Input Example
{"path_parameters":{"sensor_id":123},"IPAddress":"string","Duration":"string","remediate":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Release Quarantined Host
Releases a quarantined host in Trellix IPS using the specified sensor ID and IP address.
Endpoint
- URL: /sensor/{{sensor_id}}/action/quarantinehost/{{IPAddress}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID |
path_parameters.IPAddress | string | Required | IPv4/IPv6 to be released from quarantine. |
Input Example
{"path_parameters":{"sensor_id":123,"IPAddress":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Unassign Attack Filter to Sensor and Attack
Removes specified attack filters from a Sensor and attack in Trellix IPS, using sensor_id, attack_id, and direction.
Endpoint
- URL: /sensor/{{sensor_id}}/attackfilter/{{attack_id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.direction | string | Required | Attack direction |
path_parameters.sensor_id | number | Required | ID of the sensor from which attack filters are to be unassigned. |
path_parameters.attack_id | string | Required | Attack ID from which attack filters are to be unassigned. |
Input Example
{"parameters":{"direction":"INBOUND"},"path_parameters":{"sensor_id":1234,"attack_id":"12edw"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Unassign Attack Filters Assigned to Domain
Removes all attack filters linked to a specific attack from a domain in Trellix IPS, using domain and attack IDs, plus direction.
Endpoint
- URL: /domain/{{domain_id}}/attackfilter/{{attack_id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.direction | string | Required | Attack direction |
path_parameters.domain_id | number | Required | ID of the domain in which the attack filter is created. |
path_parameters.attack_id | string | Required | Attack ID from which attack filters are to be unassigned. |
Input Example
{"parameters":{"direction":"INBOUND"},"path_parameters":{"domain_id":1234,"attack_id":"12efpq"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Unassign Attack Filters to Interface
Removes specific attack filters from an interface or subinterface on a Trellix IPS sensor by utilizing sensor, interface, and attack IDs.
Endpoint
- URL: /sensor/{{sensor_id}}/interface/{{interface_id}}/attackfilter/{{attack_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.direction | string | Required | Attack direction. |
path_parameters.sensor_id | number | Required | ID of the sensor from which the attack filter is to be unassigned. |
path_parameters.interface_id | number | Required | Interface/subinterface id from which the attack filter is to be unassigned. |
path_parameters.attack_id | string | Required | ID of the attack from which attack filters are to be unassigned. |
Input Example
{"parameters":{"direction":"INBOUND"},"path_parameters":{"sensor_id":1212345,"interface_id":124567,"attack_id":"132efji"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Update Attack Filter
Updates an existing attack filter in Trellix IPS with details like DomainId, MatchCriteria, and other specified criteria.
Endpoint
- URL: /attackfilter/{{attackfilter_id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.attackfilter_id | number | Required | ID of the attack filter to be updated. |
DomainId | number | Optional | Id of domain to which this attack filter belongs to. |
Description | string | Optional | Description of the attack filter. |
MatchCriteria | object | Optional | Match criteria for the attack filter. |
MatchCriteria.Exclusion | array | Required | List of exclusion criteria. |
MatchCriteria.Exclusion.Ip | object | Optional | IP exclusion criteria. |
MatchCriteria.Exclusion.Ip.destEnd | string | Optional | Destination IP end range. |
MatchCriteria.Exclusion.Ip.destMode | string | Required | Destination IP mode. |
MatchCriteria.Exclusion.Ip.srcMode | string | Required | Source IP mode. |
MatchCriteria.Exclusion.Ip.srcStart | string | Optional | Source IP start range. |
MatchCriteria.Exclusion.Ip.destStart | string | Optional | Destination IP start range. |
MatchCriteria.Exclusion.Ip.srcEnd | string | Optional | Source IP end range. |
MatchCriteria.Exclusion.Port | object | Optional | TCP/UDP Port. |
MatchCriteria.Exclusion.Port.srcPortMode | string | Required | Source Port mode. |
MatchCriteria.Exclusion.Port.srcPort | string | Optional | Source Port. |
MatchCriteria.Exclusion.Port.destPort | string | Optional | Destination Port. |
MatchCriteria.Exclusion.Port.destPortMode | string | Required | Destination Port mode. |
LastModTs | string | Optional | Last modified timestamp of the attack filter. |
attackFilterId | number | Optional | ID of the attack filter. |
Type | string | Optional | Attack filter type. |
name | string | Optional | Name of the attack filter. |
Input Example
{"json_body":{"DomainId":0,"Description":"try","MatchCriteria":{"Exclusion":[{"Ip":{"destEnd":"1.1.1.17","destMode":"RANGE_IP","srcMode":"SINGLE_IP","srcStart":"1.1.1.1","destStart":"1.1.1.13","srcEnd":"1.1.1.11"},"Port":{"srcPortMode":"TCP","srcPort":"85","destPort":"89","destPortMode":"TCP"}}]},"LastModTs":"2012-07-24 00:19:00","attackFilterId":419,"Type":"IPV_4_AND_TCP_UDP_PORT","name":"test1"},"path_parameters":{"attackfilter_id":12345}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Update Firewall Policy
Updates a Trellix IPS firewall policy with specific configurations like name, domain, and member details using the given policy ID.
Endpoint
- URL: /firewallpolicy/{{policy_id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.policy_id | number | Required | The unique identifier of the firewall policy to be updated. |
FirewallPolicyId | number | Optional | Unique identifier |
Name | string | Optional | Name of the resource |
DomainId | number | Optional | Unique identifier |
VisibleToChild | boolean | Optional | Parameter for Update Firewall Policy |
Description | string | Optional | Parameter for Update Firewall Policy |
LastModifiedTime | string | Optional | Time value |
IsEditable | boolean | Optional | Parameter for Update Firewall Policy |
PolicyType | string | Optional | Type of the resource |
PolicyVersion | number | Optional | Parameter for Update Firewall Policy |
LastModifiedUser | string | Optional | Parameter for Update Firewall Policy |
MemberDetails | object | Optional | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList | array | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.Description | string | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.Enabled | boolean | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.Response | string | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.IsLogging | boolean | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.Direction | string | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.SourceAddressObjectList | array | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.SourceAddressObjectList.RuleObjectId | string | Required | Unique identifier |
MemberDetails.MemberRuleList.SourceAddressObjectList.Name | string | Required | Name of the resource |
MemberDetails.MemberRuleList.SourceAddressObjectList.RuleObjectType | string | Required | Type of the resource |
MemberDetails.MemberRuleList.DestinationAddressObjectList | array | Required | Parameter for Update Firewall Policy |
MemberDetails.MemberRuleList.DestinationAddressObjectList.RuleObjectId | string | Required | Unique identifier |
MemberDetails.MemberRuleList.DestinationAddressObjectList.Name | string | Required | Name of the resource |
Input Example
{"json_body":{"Name":"TestFirewallPolicy","DomainId":0,"VisibleToChild":true,"Description":"test the firewallpolicy","LastModifiedTime":"2012-12-12 12:30:47","IsEditable":true,"PolicyType":"ADVANCED","PolicyVersion":1,"LastModifiedUser":"admin","MemberDetails":{"MemberRuleList":[{"Description":"Test Member Rule","Enabled":true,"Response":"SCAN","IsLogging":false,"Direction":"INBOUND","SourceAddressObjectList":[{"RuleObjectId":"AF","Name":"Afghanistan","RuleObjectType":"COUNTRY"}],"DestinationAddressObjectList":[{"RuleObjectId":"101","Name":"hostDNSRule","RuleObjectType":"HOST_DNS_NAME"},{"RuleObjectId":"102","Name":"hostIpv4","RuleObjectType":"HOST_IPV_4"},{"RuleObjectId":"103","Name":"ipv4Addressrange","RuleObjectType":"IPV_4_ADDRESS_RANGE"},{"RuleObjectId":"104","Name":"networkgroup","RuleObjectType":"NETWORK_GROUP"}],"SourceUserObjectList":[{"RuleObjectId":"-1","Name":"Any","RuleObjectType":"USER"}],"ServiceObjectList":[],"ApplicationObjectList":[{"RuleObjectId":"1308991488","Name":"100bao","RuleObjectType":"APPLICATION","ApplicationType":"DEFAULT"},{"RuleObjectId":"106","Name":"applicaionOncutomPort","RuleObjectType":"APPLICATION_ON_CUSTOM_PORT","ApplicationType":"CUSTOM"},{"RuleObjectId":"105","Name":"applicationgroup","RuleObjectType":"APPLICATION_GROUP","ApplicationType":"CUSTOM"}],"TimeObjectList":[{"RuleObjectId":"107","Name":"finiteTimePeriod","RuleObjectType":"FINITE_TIMING_PERIOD"},{"RuleObjectId":"108","Name":"recuringTimePeriod","RuleObjectType":"RECURRING_TIME_PERIOD"},{"RuleObjectId":"109","Name":"recurringTimeperiodGroup","RuleObjectType":"RECURRING_TIME_PERIOD_GROUP"}]}]}},"path_parameters":{"policy_id":120}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Update IPS Policy
Updates a specified Trellix IPS policy using the provided policy ID and OutboundAttackCategory.
Endpoint
- URL: /ipspolicy/{{policyid}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.policyid | number | Required | The unique identifier of the IPS policy to update. |
DosResponseSensitivityLevel | number | Optional | The sensitivity level for DoS response in the policy. |
direction | number | Optional | The direction of the policy (e.g., inbound or outbound). |
Description | string | Optional | A brief description of the IPS policy. |
IsEditable | boolean | Optional | Indicates if the policy is editable. |
PolicyName | string | Optional | The name of the IPS policy. |
ReconPolicy | object | Optional | The reconnaissance policy configuration. |
ReconPolicy.ReconAttackList | array | Optional | List of reconnaissance attacks for the policy. |
ReconPolicy.ReconAttackList.IsAlertCustomized | boolean | Optional | Indicates if alert settings are customized for this recon attack. |
ReconPolicy.ReconAttackList.isQuarantineCustomized | boolean | Optional | Indicates if quarantine settings are customized for this recon attack. |
ReconPolicy.ReconAttackList.severity | number | Optional | The severity level of the recon attack. |
ReconPolicy.ReconAttackList.isThresholdDurationCustomized | boolean | Optional | Indicates if the threshold duration is customized for this recon attack. |
ReconPolicy.ReconAttackList.isSendAlertToManager | boolean | Optional | Indicates if alerts should be sent to the manager for this recon attack. |
ReconPolicy.ReconAttackList.nspId | string | Optional | The unique identifier for the recon attack. |
ReconPolicy.ReconAttackList.ThresholdDuration | number | Optional | The duration for the threshold in seconds for this recon attack. |
ReconPolicy.ReconAttackList.alertSuppressionTimer | number | Optional | The timer for alert suppression for this recon attack. |
ReconPolicy.ReconAttackList.isAlertSuppressionTimerCustomized | boolean | Optional | Indicates if the alert suppression timer is customized for this recon attack. |
ReconPolicy.ReconAttackList.isMcAfeeNACNotificationEnabled | boolean | Optional | Indicates if McAfee NAC notification is enabled for this recon attack. |
ReconPolicy.ReconAttackList.ThresholdValue | number | Optional | The threshold value for the recon attack. |
ReconPolicy.ReconAttackList.notification | object | Required | Notification settings for this recon attack, including email, pager, script, auto-acknowledgment, SNMP, and syslog. |
ReconPolicy.ReconAttackList.notification.isAutoAckCustomized | boolean | Optional | Indicates if auto-acknowledgment setting is customized. |
ReconPolicy.ReconAttackList.notification.isPager | boolean | Optional | Indicates if pager notifications are enabled. |
ReconPolicy.ReconAttackList.notification.isSyslogCustomized | boolean | Optional | Indicates if syslog notification setting is customized. |
ReconPolicy.ReconAttackList.notification.isPagerCustomized | boolean | Optional | Indicates if pager notification setting is customized. |
ReconPolicy.ReconAttackList.notification.isEmail | boolean | Optional | Indicates if email notifications are enabled. |
Input Example
{"path_parameters":{"policyid":123},"DosResponseSensitivityLevel":123,"direction":123,"Description":"string","IsEditable":true,"PolicyName":"Example Name","ReconPolicy":{"ReconAttackList":[{"IsAlertCustomized":true,"isQuarantineCustomized":true,"severity":123,"isThresholdDurationCustomized":true,"isSendAlertToManager":true,"nspId":"string","ThresholdDuration":123,"alertSuppressionTimer":123,"isAlertSuppressionTimerCustomized":true,"isMcAfeeNACNotificationEnabled":true,"ThresholdValue":123,"notification":{"isAutoAckCustomized":true,"isPager":true,"isSyslogCustomized":true,"isPagerCustomized":true,"isEmail":true,"isScriptCustomized":true,"isSnmpCustomized":true,"isScript":true,"isSnmp":true,"isEmailCustomized":true,"isAutoAck":true,"isSyslog":true},"mcAfeeNACNotification":"string","isRemediateEnabled":true,"isSeverityCustomized":true,"isThresholdValueCustomized":true}]},"DosPolicy":{"LearningAttack":[{"IsAlertCustomized":true,"direction":"string","severity":123,"isDropPacket":true,"isSendAlertToManager":true,"nspId":"string","isBlockingSettingCustomized":true,"attackName":"Example Name","isSeverityCustomized":true,"notification":{"isAutoAckCustomized":true,"isPager":true,"isSyslogCustomized":true,"isPagerCustomized":true,"isEmail":true,"isScriptCustomized":true,"isSnmpCustomized":true,"isScript":true,"isSnmp":true,"isEmailCustomized":true,"isAutoAck":true,"isSyslog":true}}],"ThresholdAttack":[{"isAlertCustomized":true,"direction":"string","severity":123,"isThresholdDurationCustomized":true,"isSendAlertToManager":true,"nspId":"string","ThresholdDuration":123,"isSeverityCustomized":true,"Notification":{"isAutoAckCustomized":true,"isPager":true,"isSyslogCustomized":true,"isPagerCustomized":true,"isEmail":true,"isScriptCustomized":true,"isSnmpCustomized":true,"isScript":true,"isSnmp":true,"isEmailCustomized":true,"isAutoAck":true,"isSyslog":true},"attackName":"Example Name","ThresholdValue":123,"isThresholdValueCustomized":true}]},"IsVisibleToChildren":true,"OutboundAttackCategory":{"ExpolitAttackList":[{"isAlertCustomized":true,"blockingType":"string","direction":"string","severity":123,"AttackResponse":{"isFlowCustomized":true,"isICMPSend":true,"blockingOption":"string","mcAfeeNACNotification":"string","isAlertCustomized":true,"isCapturedPrior":true,"numberOfBytesInEachPacket":{},"isICMPSendCustomized":true,"isCapturedPriorCustomized":true,"TimeStamp":"2024-01-01T00:00:00Z","isQuarantineCustomized":true,"TCPReset":"string","isLogCustomized":true,"isTcpResetCustomized":true,"isNbytesCustomized":true,"flow":"string","isMcAfeeNACNotificationEnabled":true,"isAlert":true,"action":"string","loggingDuration":{},"isRemediateEnabled":true,"isBlockingOptionCustomized":true},"nspId":"string","isEnabled":true,"benignTriggerProbability":"string","notification":{"isAutoAckCustomized":true,"isPager":true,"isSyslogCustomized":true,"isPagerCustomized":true,"isEmail":true,"isScriptCustomized":true,"isSnmpCustomized":true,"isScript":true,"isSnmp":true,"isEmailCustomized":true,"isAutoAck":true,"isSyslog":true},"isRecommendedForSmartBlocking":true,"isSeverityCustomized":true,"subCategory":"string"}]},"AttackCategory":{"ExpolitAttackList":[{"isAlertCustomized":true,"blockingType":"string","direction":"string","severity":123,"AttackResponse":{"isFlowCustomized":true,"isICMPSend":true,"blockingOption":"string","mcAfeeNACNotification":"string","isAlertCustomized":true,"isCapturedPrior":true,"numberOfBytesInEachPacket":{},"isICMPSendCustomized":true,"isCapturedPriorCustomized":true,"TimeStamp":"2024-01-01T00:00:00Z","isQuarantineCustomized":true,"TCPReset":"string","isLogCustomized":true,"isTcpResetCustomized":true,"isNbytesCustomized":true,"flow":"string","isMcAfeeNACNotificationEnabled":true,"isAlert":true,"action":"string","loggingDuration":{},"isRemediateEnabled":true,"isBlockingOptionCustomized":true},"nspId":"string","isEnabled":true,"benignTriggerProbability":"string","notification":{"isAutoAckCustomized":true,"isPager":true,"isSyslogCustomized":true,"isPagerCustomized":true,"isEmail":true,"isScriptCustomized":true,"isSnmpCustomized":true,"isScript":true,"isSnmp":true,"isEmailCustomized":true,"isAutoAck":true,"isSyslog":true},"isRecommendedForSmartBlocking":true,"isSeverityCustomized":true,"subCategory":"string"}]},"OutboundRuleSet":"string","InboundRuleSet":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Update IPS Quarantine Duration for a Host
Modifies the quarantine duration for a host in Trellix IPS using the provided sensor ID, IP address, and duration.
Endpoint
- URL: /sensor/{{sensor_id}}/action/quarantinehost
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sensor_id | number | Required | Sensor ID |
IPAddress | string | Optional | IPv4/IPv6 to be quarantined. |
Duration | string | Optional | Duration for which the IP is to be quarantined. |
remediate | boolean | Optional | Remediate the IP along with quarantine |
IsOverride | boolean | Optional | Override the previous data if present for the IP provided. |
Input Example
{"path_parameters":{"sensor_id":123},"IPAddress":"string","Duration":"string","remediate":true,"IsOverride":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"reason":"OK","json_body":{"status":1}}
Update Rule Object
Updates a specified rule object in Trellix IPS with details like type, name, and visibility settings. Requires ruleobject_id and JSON body.
Endpoint
- URL: sdkapi/ruleobject/{{ruleobject_id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ruleobject_id | number | Required | The ID of the rule object to update. |
ruleobjId | number | Optional | The ID of the rule object to add. |
ruleobjType | string | Optional | The type of the rule object to add. |
name | string | Optional | The name of the rule object to add. |
description | string | Optional | The description of the rule object to add. |
domain | number | Optional | ID of domain in which the rule object is defined. |
visibleToChild | boolean | Optional | Is rule object visible to child. |
ApplicationGroup | object | Optional | Application group object, should be defined if ruleobjType is APPLICATION_GROUP. |
ApplicationGroup.ApplicationIdentifier | array | Required | List of applications identifier. |
ApplicationGroup.ApplicationIdentifier.applicationRuleObjId | number | Required | ID of the application rule object. |
ApplicationGroup.ApplicationIdentifier.applicationType | string | Required | Type of the application. |
ApplicationOnCustomPort | object | Optional | Application defined on custom port object, should be defined if ruleobjType is APPLICATION_ON_CUSTOM_PORT. |
ApplicationOnCustomPort.applicationId | string | Required | ID of the application. |
ApplicationOnCustomPort.portsList | array | Required | List of ports. |
ApplicationOnCustomPort.portsList.IPProtocol | string | Required | IP protocol, can be "TCP" or "UDP". |
ApplicationOnCustomPort.portsList.port | number | Required | Port number. |
FiniteTimePeriod | object | Optional | Finite time period rule object, should be defined if ruleobjType is FINITE_TIME_PERIOD. |
FiniteTimePeriod.from | string | Required | Start time of the time period. |
FiniteTimePeriod.until | string | Required | End time of the time period. |
HostIPv4 | object | Optional | Host IPv4 rule object, should be defined if ruleobjType is HOST_IPV_4. |
HostIPv4.hostIPv4AddressList | array | Required | List of host IPv4 addresses. |
HostIPv4.hostIPv4AddressList.ruleObjID | number | Required | Rule object ID. |
HostIPv4.hostIPv4AddressList.state | number | Required | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. |
HostIPv4.hostIPv4AddressList.comment | string | Optional | Comment for the rule member. |
HostIPv4.hostIPv4AddressList.userID | number | Required | User ID of the rule member. |
Input Example
{"path_parameters":{"ruleobject_id":21}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | number | Status value |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"status":1}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |