WatchTowr API
The WatchTowr API connector allows for streamlined management of security threats by providing actions to interact with notes, hunts, findings, and assets.
WatchTowr is a cutting-edge security platform that specializes in identifying and managing digital risks across various assets. The WatchTowr API connector for Swimlane Turbine enables users to automate the retrieval of detailed information on findings, hunts, and suspicious domains, as well as manage notes and statuses for assets within the WatchTowr ecosystem. By integrating with Swimlane Turbine, security teams can enhance their threat intelligence and incident response capabilities, streamline security operations, and maintain a proactive security posture by leveraging real-time data and actionable insights from WatchTowr.
Limitations
None to date.
Supported Versions
This connector supports the latest version of WatchTowr API.
Prerequisites
To utilize the WatchTowr API connector within Swimlane, ensure you have the following prerequisites:
- HTTP Bearer Token Authentication with the following parameters:
- URL: Endpoint for the WatchTowr API.
- Token: A valid bearer token to authenticate API requests.
Capabilities
This Connector provides the following capabilities:
- Create Note
- Update Note
- Get Hunt Details
- List Hunts
- List Hunt Findings
- Get Finding Details
- List Finding Statuses
- Update Finding Status
- Reset Finding
- List Assets
- List Suspicious Domains
- Get Suspicious Domain Details
Create Note
Create a Note for a specific API Documentation asset.
WatchTowr's documentation for this action can be found here here.
Update Note
Update a Note of a specific API Documentation asset.
WatchTowr's documentation for this action can be found here here.
Get Hunt Details
Get the details of a specific hunt.
WatchTowr's documentation for this action can be found here here.
List Hunts
List all available hunt assets, ordered by creation date.
WatchTowr's documentation for this action can be found here here.
List Hunt Findings
List all findings for a specific hunt.
WatchTowr's documentation for this action can be found here here.
Get Finding Details
Get the details of a specific finding.
WatchTowr's documentation for this action can be found here here.
List Finding Statuses
List all available statuses for findings.
WatchTowr's documentation for this action can be found here here.
Update Finding Status
Update the status of a specific finding.
WatchTowr's documentation for this action can be found here here.
Reset Finding
Initiate a retest for a specific finding.
WatchTowr's documentation for this action can be found here here.
List Assets
Get a list of Assets for a specific Hunt.
WatchTowr's documentation for this action can be found here here.
List Suspicious Domains
List all discovered suspicious domain assets, ordered by discovery date.
WatchTowr's documentation for this action can be found here here.
Get Suspicious Domain Details
Get the details of a specific suspicious domain.
WatchTowr's documentation for this action can be found here here.
Configurations
HTTP Bearer Authentication
WatchTowr API authentication using Bearer token.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The Bearer token to authenticate with. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create Note
Creates a note for a specified API Documentation asset using the provided 'id' and 'note' content.
Endpoint
- URL: /api/client/assets/apiDocumentation/show/{{id}}/note
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | The asset ID of the API Documentation asset to create a new note for. |
note | string | Optional | Content of the note. |
title | string | Optional | Title of the note. |
Input Example
{"json_body":{"note":"Passed to the engineering team. Review on 01/07/2024","title":"Initial Review - 01/01/2024"},"path_parameters":{"id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.id | number | Response data |
data.note | string | Response data |
data.note_type | string | Response data |
data.note_id | number | Response data |
data.title | string | Response data |
data.author | object | Response data |
data.author.id | number | Response data |
data.author.name | string | Response data |
data.last_modified | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"id":1,"note":"Passed to the engineering team. Review on 01/07/2024","note_type":"Domain","note_id":2,"title":"Initial Review - 01/01/2024","author":{},"last_modified":"2022-02-13T02:10:00.000000Z"}}}
Get Finding Details
Retrieve detailed information for a specific finding in WatchTowr API using the unique identifier.
Endpoint
- URL: /api/client/findings/show/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | The ID of the finding to retrieve. |
Input Example
{"path_parameters":{"id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.id | number | Response data |
data.title | string | Response data |
data.description | string | Response data |
data.impact | string | Response data |
data.finding_impact | string | Response data |
data.tags | array | Response data |
data.tags.id | number | Response data |
data.tags.name | string | Response data |
data.evidence | string | Response data |
data.recommendation | string | Response data |
data.severity | string | Response data |
data.cvssv3_score | number | Response data |
data.cvssv3_metrics | string | Response data |
data.status | string | Response data |
data.created_at | string | Response data |
data.affected | object | Response data |
data.cve_id | string | Response data |
data.epss_score | number | Response data |
data.retest | object | Response data |
data.retest.retest_remaining | number | Response data |
data.retest.current_retest | object | Response data |
data.retest.current_retest.requested_by | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"id":1,"title":"Valid Credentials Discovered In Business System","description":"Through watchTowr's Credential Stuffing capabilities, a valid set of credentials...","impact":"Depending on the system, if leveraged by an attacker it may be possible to:\n\n* G...","finding_impact":"Prioritised Findings","tags":[],"evidence":"URL: https://example.com/adfs/ls\n\nValid credentials discovered:\nUsername: user\nP...","recommendation":"As a priority, ...
Get Hunt Details
Retrieve detailed information for a specific hunt identified by its unique ID in the WatchTowr API.
Endpoint
- URL: /api/client/hunts/show/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Get Hunt Details action |
Input Example
{"path_parameters":{"id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.id | number | Response data |
data.priority | string | Response data |
data.type | string | Response data |
data.created_at | string | Response data |
data.updated_at | string | Response data |
data.total_findings | number | Response data |
data.total_assets | number | Response data |
data.hunt_request_type | string | Response data |
data.rapid_exposure_mechanism | string | Response data |
data.title | string | Response data |
data.description | string | Response data |
data.hypothesis | string | Response data |
data.references | array | Response data |
data.completed_at | string | Response data |
data.completed_by | string | Response data |
data.requested_by | string | Response data |
data.status | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"id":1,"priority":"high","type":"bespoke","created_at":"2023-06-28T02:22:36.000Z","updated_at":"2023-06-28T02:22:36.000Z","total_findings":1,"total_assets":10,"hunt_request_type":"Others","rapid_exposure_mechanism":"impactLessPoc","title":"Hunt for ITW Exploited Command Injection in Palo Alto Networks GlobalProtect Gat...","description":"\"watchTowr performed a PROACTIVE hunt to determine if there are any instances of...","hypothesis":"\"A se...
Get Suspicious Domain Details
Retrieve detailed information about a specific suspicious domain using its unique identifier.
Endpoint
- URL: /api/client/suspicious-domain/show/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | The ID of the suspicious domain to retrieve. |
Input Example
{"path_parameters":{"id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.id | number | Response data |
data.name | string | Response data |
data.discovery_reason | string | Response data |
data.status | string | Response data |
data.whoisData | array | Response data |
data.whoisData.id | number | Response data |
data.whoisData.data | object | Response data |
data.whoisData.data.org | string | Response data |
data.whoisData.data.city | string | Response data |
data.whoisData.data.name | string | Response data |
data.whoisData.data.state | string | Response data |
data.whoisData.data.dnssec | string | Response data |
data.whoisData.data.emails | array | Response data |
data.whoisData.data.status | array | Response data |
data.whoisData.data.address | string | Response data |
data.whoisData.data.country | string | Response data |
data.whoisData.data.zipcode | string | Response data |
data.whoisData.data.registrar | string | Response data |
data.whoisData.data.domain_name | string | Response data |
data.whoisData.data.name_servers | array | Response data |
data.whoisData.data.referral_url | string | Response data |
data.whoisData.data.whois_server | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"id":1,"name":"example.com","discovery_reason":"Example reason","status":"legitimate","whoisData":[],"created_at":"2022-02-22 22:00:00"}}}
List Assets
Retrieve a list of assets associated with a specific Hunt ID from the WatchTowr API.
Endpoint
- URL: /api/client/hunts/show/{{id}}/assets
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | The page number for paginated results. |
parameters.pageSize | number | Optional | The number of items to be included on each page of paginated results. |
path_parameters.id | number | Required | Hunt ID of the hunt to retrieve assets from. |
Input Example
{"parameters":{"page":1,"pageSize":20},"path_parameters":{"id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.type | string | Response data |
data.source | string | Response data |
data.status | string | Response data |
data.created_at | string | Response data |
data.id | string | Response data |
data.country | object | Response data |
data.platform | object | Response data |
data.provider | object | Response data |
data.url | string | Response data |
data.name | string | Response data |
data.businessUnits | array | Response data |
data.businessUnits.file_name | string | Response data |
data.businessUnits.file | string | Response data |
data.discovery_reason | object | Response data |
data.owner | object | Response data |
data.live | boolean | Response data |
data.sub_type | string | Response data |
data.super_type | string | Response data |
data.metadata | object | Response data |
meta | object | Output field: meta |
meta.pagination | object | Output field: meta.pagination |
meta.pagination.total | number | Output field: meta.pagination.total |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[{"type":"repository","source":"Initial Data","status":"verified","created_at":"2021-11-22T22:17:12.000Z","id":"1","country":null,"platform":null,"provider":"test provider","url":null,"name":"test name","businessUnits":[],"discovery_reason":"discovery reason test data","owner":"test owner","live":null,"sub_type":null,"super_type":null,"metadata":{}},{"type":"repository","source":"module-github-enumeration-v0.1","status":"verified","created_at"...
List Finding Statuses
Retrieve a list of all available statuses for findings within the WatchTowr API.
Endpoint
- URL: /api/client/findings/statuses
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.0 | string | Response data |
data.1 | string | Response data |
data.2 | string | Response data |
data.3 | string | Response data |
data.4 | string | Response data |
data.5 | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[[]]}}
List Findings
Retrieve a list of all discovered findings from WatchTowr API, sorted by the date they were identified.
Endpoint
- URL: /api/client/findings/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | The page number for paginated results. |
parameters.pageSize | number | Optional | The number of items to be included on each page of paginated results. |
parameters.created_from | string | Optional | Filter findings created after a given date and time. |
parameters.created_to | string | Optional | Filter findings created before a given date and time. |
parameters.updated_from | string | Optional | Filter findings updated after a given date and time. |
parameters.updated_to | string | Optional | Filter findings updated before a given date and time. |
parameters.statuses | string | Optional | Filter findings by a list of comma separated statuses they're tagged with. |
parameters.businessUnitIds | string | Optional | Filter findings by a list of comma separated business unit IDs that they're related to. |
parameters.findingImpactThreshold | string | Optional | Filter findings by a finding impact threshold. |
parameters.findingTitle | string | Optional | Search findings by title contents. |
parameters.severities | string | Optional | Filter findings by a list of comma separated severities they're tagged with. |
parameters.assetTitle | string | Optional | Search by findings by affected asset. |
parameters.assetTypes | string | Optional | Filter findings by a comma separated list of affected asset types. |
parameters.tags | string | Optional | Filter findings by a comma separated list of tags. |
parameters.onlyValidatedExploitable | boolean | Optional | Filter to only show findings validated as exploitable. |
parameters.onlyUnacknowledged | boolean | Optional | Filter to only show unacknowledged findings. |
parameters.exploitationRiskLevel | string | Optional | Filter findings by a comma separated list of exploitation risk levels. |
Input Example
{"parameters":{"page":1,"pageSize":10,"created_from":"2022-02-22 22:00:00","created_to":"2022-02-23 22:00:00","updated_from":"2022-02-22 22:00:00","updated_to":"2022-02-23 22:00:00","statuses":"confirmed,unconfirmed,remediated,risk-accepted,closed,asset-no-longer-tracked","businessUnitIds":"1,2,3","findingImpactThreshold":"medium","findingTitle":"Critical vulnerability in your network","severities":"critical,high,medium,low"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.id | number | Response data |
data.title | string | Response data |
data.created_at | string | Response data |
data.cvssv3_score | number | Response data |
data.cvssv3_metrics | string | Response data |
data.description | string | Response data |
data.impact | string | Response data |
data.finding_impact | string | Response data |
data.tags | array | Response data |
data.tags.id | number | Response data |
data.tags.name | string | Response data |
data.evidence | string | Response data |
data.recommendation | string | Response data |
data.references | string | Response data |
data.severity | string | Response data |
data.status | string | Response data |
data.affected | object | Response data |
data.affected.data | object | Response data |
data.affected.data.type | string | Response data |
data.affected.data.source | string | Response data |
data.affected.data.status | string | Response data |
data.affected.data.created_at | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[{"id":2917,"title":"Valid Credentials Discovered In Business System","created_at":"2023-11-24T07:56:51.000Z","cvssv3_score":8.6,"cvssv3_metrics":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:F/RL:W/RC:C","description":"Through watchTowr's Credential Stuffing capabilities, a valid set of credentials have been identified to work to authenticate to a legitimately exposed business system. \n\nThese credentials have been confirmed as valid again...
List Hunt Findings
Retrieve a list of all findings associated with a specific hunt identified by its unique ID in the WatchTowr API.
Endpoint
- URL: /api/client/hunts/show/{{id}}/findings
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | The page number for paginated results. |
parameters.pageSize | number | Optional | The number of items to be included on each page of paginated results. |
path_parameters.id | number | Required | The ID of the hunt to retrieve findings from. |
Input Example
{"parameters":{"page":1,"pageSize":20},"path_parameters":{"id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.id | number | Response data |
data.title | string | Response data |
data.description | string | Response data |
data.impact | string | Response data |
data.finding_impact | string | Response data |
data.tags | array | Response data |
data.tags.id | number | Response data |
data.tags.name | string | Response data |
data.evidence | string | Response data |
data.recommendation | string | Response data |
data.severity | string | Response data |
data.cvssv3_score | number | Response data |
data.cvssv3_metrics | string | Response data |
data.status | string | Response data |
data.created_at | string | Response data |
data.affected | object | Response data |
data.cve_id | string | Response data |
data.epss_score | number | Response data |
data.retest | object | Response data |
data.retest.retest_remaining | number | Response data |
data.retest.current_retest | object | Response data |
data.retest.current_retest.requested_by | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[{}],"meta":{"pagination":{}}}}
List Hunts
Retrieve a list of all available hunt assets from WatchTowr API, sorted by their creation date.
Endpoint
- URL: /api/client/hunts/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | The page number for paginated results. |
parameters.pageSize | number | Optional | The number of items to be included on each page of paginated results. |
parameters.statuses | string | Optional | Filter hunts by hunt status. |
parameters.huntSearch | string | Optional | Search for hunts by text in hunt name. |
parameters.types | string | Optional | Filter hunts by hunt types. |
parameters.created_from | string | Optional | Filter hunts created after a given date and time. |
parameters.created_to | string | Optional | Filter hunts created before a given date and time. |
parameters.updated_from | string | Optional | Filter hunts updated after a given date and time. |
parameters.updated_to | string | Optional | Filter hunts updated before a given date and time. |
parameters.priorities | string | Optional | Filter hunts updated before a given date and time. |
parameters.resourceFilter | string | Optional | Filter hunts that have associated assets or findings. |
parameters.onlyResolved | boolean | Optional | Filter to only show resolved hunts. |
parameters.isUnacknowledged | boolean | Optional | Filter to only show hunts that are not acknowledged. |
Input Example
{"parameters":{"page":1,"pageSize":50,"statuses":"received,in-progress,completed,not-covered","huntSearch":"remote code execution","types":"bespoke,proactive","created_from":"2022-02-22 22:00:00","created_to":"2022-02-23 22:00:00","updated_from":"2022-02-22 22:00:00","updated_to":"2022-02-23 22:00:00","priorities":"high,medium,low","resourceFilter":"hasAssetsOrFindings","onlyResolved":false,"isUnacknowledged":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.id | number | Response data |
data.priority | string | Response data |
data.type | string | Response data |
data.created_at | string | Response data |
data.updated_at | string | Response data |
data.total_findings | number | Response data |
data.total_assets | number | Response data |
data.hunt_request_type | string | Response data |
data.rapid_exposure_mechanism | string | Response data |
data.title | string | Response data |
data.status | string | Response data |
meta | object | Output field: meta |
meta.pagination | object | Output field: meta.pagination |
meta.pagination.total | number | Output field: meta.pagination.total |
meta.pagination.count | number | Count value |
meta.pagination.per_page | number | Output field: meta.pagination.per_page |
meta.pagination.current_page | number | Output field: meta.pagination.current_page |
meta.pagination.total_pages | number | Output field: meta.pagination.total_pages |
meta.pagination.links | object | Output field: meta.pagination.links |
meta.pagination.links.previous | string | Output field: meta.pagination.links.previous |
meta.pagination.links.next | string | Output field: meta.pagination.links.next |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[{}],"meta":{"pagination":{}}}}
List Suspicious Domains
Retrieve a list of all suspicious domain assets detected by WatchTowr API, sorted by the date they were discovered.
Endpoint
- URL: /api/client/suspicious-domain/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | The page number for paginated results. |
parameters.pageSize | number | Optional | The number of items to be included on each page of paginated results. |
parameters.created_from | string | Optional | Filter suspicious domains created after a given date and time. |
parameters.created_to | string | Optional | Filter suspicious domains created before a given date and time. |
parameters.updated_from | string | Optional | Filter suspicious domains updated after a given date and time. |
parameters.updated_to | string | Optional | Filter suspicious domains updated before a given date and time. |
parameters.search | string | Optional | Search suspicious domains by text within the domain. |
parameters.discovery_reason | string | Optional | Search suspicious domains by discovery reason. |
parameters.whoisSearch | string | Optional | Search suspicious domains by contents of Whois data. |
parameters.statuses | string | Optional | Filter suspicious domains by a list of comma separated statuses that asset is tagged with. |
Input Example
{"parameters":{"page":1,"pageSize":50,"created_from":"2022-02-22 22:00:00","created_to":"2022-02-23 22:00:00","updated_from":"2022-02-22 22:00:00","updated_to":"2022-02-23 22:00:00","search":"watchtowr.com","discovery_reason":"suspicious-words","whoisSearch":"Name Server: malicious.ns.com","statuses":"pending,malicious,legitimate,benign"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.id | number | Response data |
data.name | string | Response data |
data.discovery_reason | string | Response data |
data.status | string | Response data |
data.whoisData | array | Response data |
data.whoisData.id | number | Response data |
data.whoisData.data | object | Response data |
data.whoisData.data.org | string | Response data |
data.whoisData.data.city | string | Response data |
data.whoisData.data.name | string | Response data |
data.whoisData.data.state | string | Response data |
data.whoisData.data.dnssec | string | Response data |
data.whoisData.data.emails | array | Response data |
data.whoisData.data.status | array | Response data |
data.whoisData.data.address | string | Response data |
data.whoisData.data.country | string | Response data |
data.whoisData.data.zipcode | string | Response data |
data.whoisData.data.registrar | string | Response data |
data.whoisData.data.domain_name | string | Response data |
data.whoisData.data.name_servers | array | Response data |
data.whoisData.data.referral_url | string | Response data |
data.whoisData.data.whois_server | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[{}],"meta":{"pagination":{}}}}
Retest Finding
Initiates a retest for a specific finding identified by the 'finding_id' in WatchTowr API.
Endpoint
- URL: /api/client/findings/retest/{{finding_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.finding_id | number | Required | The ID of the finding to retest. |
Input Example
{"path_parameters":{"finding_id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | number | Unique identifier |
title | string | Output field: title |
description | string | Output field: description |
impact | string | Output field: impact |
finding_impact | string | Output field: finding_impact |
tags | array | Output field: tags |
tags.id | number | Unique identifier |
tags.name | string | Name of the resource |
evidence | string | Unique identifier |
recommendation | string | Output field: recommendation |
severity | string | Output field: severity |
cvssv3_score | number | Score value |
cvssv3_metrics | string | Output field: cvssv3_metrics |
status | string | Status value |
created_at | string | Output field: created_at |
affected | object | Output field: affected |
cve_id | string | Unique identifier |
epss_score | number | Score value |
retest | object | Output field: retest |
retest.retest_remaining | number | Output field: retest.retest_remaining |
retest.current_retest | object | Output field: retest.current_retest |
retest.current_retest.requested_by | string | Output field: retest.current_retest.requested_by |
retest.current_retest.requested_at | string | Output field: retest.current_retest.requested_at |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":1,"title":"Valid Credentials Discovered In Business System","description":"Through watchTowr's Credential Stuffing capabilities, a valid set of credentials...","impact":"Depending on the system, if leveraged by an attacker it may be possible to:\n\n* G...","finding_impact":"Prioritised Findings","tags":[{}],"evidence":"URL: https://example.com/adfs/ls\n\nValid credentials discovered:\nUsername: user\nP...","recommendation":"As a priority, it is ...
Update Finding Status
Updates the status of a specific finding in WatchTowr API using the provided 'id' and 'status'.
Endpoint
- URL: /api/client/findings/status/{{id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | The ID of the finding to update. |
status | string | Optional | The new status for the finding. |
statusReason | string | Optional | The reason for the status change. |
Input Example
{"json_body":{"status":"confirmed","statusReason":"Reason for change"},"path_parameters":{"id":1234}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.id | number | Response data |
data.title | string | Response data |
data.description | string | Response data |
data.impact | string | Response data |
data.finding_impact | string | Response data |
data.tags | array | Response data |
data.tags.id | number | Response data |
data.tags.name | string | Response data |
data.evidence | string | Response data |
data.recommendation | string | Response data |
data.severity | string | Response data |
data.cvssv3_score | number | Response data |
data.cvssv3_metrics | string | Response data |
data.status | string | Response data |
data.created_at | string | Response data |
data.affected | object | Response data |
data.cve_id | string | Response data |
data.epss_score | number | Response data |
data.retest | object | Response data |
data.retest.retest_remaining | number | Response data |
data.retest.current_retest | object | Response data |
data.retest.current_retest.requested_by | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"id":1,"title":"Valid Credentials Discovered In Business System","description":"Through watchTowr's Credential Stuffing capabilities, a valid set of credentials...","impact":"Depending on the system, if leveraged by an attacker it may be possible to:\n\n* G...","finding_impact":"Prioritised Findings","tags":[],"evidence":"URL: https://example.com/adfs/ls\n\nValid credentials discovered:\nUsername: user\nP...","recommendation":"As a priority, ...
Update Note
Updates a specific note identified by asset and note IDs in the WatchTowr API, requiring the updated note content.
Endpoint
- URL: /api/client/assets/apiDocumentation/show/{{id}}/note/{{noteId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | The asset ID of an API Documentation asset with a note to update. |
path_parameters.noteId | number | Required | The ID of the note to update. |
note | string | Optional | Parameter for Update Note |
title | string | Optional | Parameter for Update Note |
Input Example
{"json_body":{"note":"Passed to the engineering team. Review on 01/07/2024","title":"Initial Review - 01/01/2024"},"path_parameters":{"id":123,"noteId":456}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.id | number | Response data |
data.note | string | Response data |
data.note_type | string | Response data |
data.note_id | number | Response data |
data.title | string | Response data |
data.author | object | Response data |
data.author.id | number | Response data |
data.author.name | string | Response data |
data.last_modified | string | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"id":1,"note":"Passed to the engineering team. Review on 01/07/2024","note_type":"Domain","note_id":2,"title":"Initial Review - 01/01/2024","author":{},"last_modified":"2022-02-13T02:10:00.000000Z"}}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |