List Host Findings For Alert
GET/resource/external_finding
Get a list of all host findings for a specific alert.
Request
Query Parameters
Responses
- 200
- 400
successful operation
- application/json; charset=UTF-8
- Schema
- Example (from schema)
Schema
- Array [
- ]
Possible values: [CRITICAL_SEVERITY
, HIGH_SEVERITY
, MEDIUM_SEVERITY
, HAS_FIX
, REMOTE_EXECUTION
, DOS
, RECENT_VULNERABILITY
, EXPLOIT_EXISTS
, ATTACK_COMPLEXITY_LOW
, ATTACK_VECTOR_NETWORK
, REACHABLE_FROM_THE_INTERNET
, LISTENING_PORTS
, CONTAINER_IS_RUNNING_AS_ROOT
, NO_MANDATORY_SECURITY_PROFILE_APPLIED
, RUNNING_AS_PRIVILEGED_CONTAINER
, PACKAGE_IN_USE
]
Possible values: [INFORMATIONAL
, LOW
, MEDIUM
, HIGH
, CRITICAL
]
Possible values: [AWS_INSPECTOR
, AWS_GUARD_DUTY
, TENABLE
, QUALYS
, PRISMA_CLOUD
, AZURE_SECURITY_CENTER
]
sourceData object
Possible values: [PENDING
, NO_ERROR
, ERROR
, ENABLED
, DISABLED
, OPEN
, DISMISSED
, RESOLVED
, DESCOPED
, RISK_SCORING_ERROR
, ACTIVE
, CLOSED
, SUPPRESSED
]
Possible values: [HOST_VULNERABILITY_CVE
, COMPLIANCE_ISSUE_CIS
, AWS_INSPECTOR_SECURITY_BEST_PRACTICES
, AWS_INSPECTOR_RUNTIME_BEHAVIOR_ANALYSIS
, AWS_GUARD_DUTY_HOST_FINDING
, AWS_GUARD_DUTY_IAM_FINDING
, SERVERLESS_VULNERABILITY
, AZURE_SECURITY_CENTER_ALERTS
, PACKAGE_VULNERABILITY
, NETWORK_REACHABILITY
, AWS_GUARD_DUTY_EKS_FINDING
, AWS_GUARD_DUTY_ECS_FINDING
, AWS_GUARD_DUTY_CONTAINER_FINDING
]
[
{
"accountId": "string",
"apiId": 0,
"count": "string",
"createdOn": 0,
"customerId": 0,
"cveId": "string",
"description": "string",
"externalFindingId": 0,
"findingId": "string",
"normalizedName": "string",
"normalizedNames": [
"string"
],
"nvdUrl": "string",
"rawData": "string",
"regionId": "string",
"resourceCloudId": "string",
"resourceId": 0,
"resourceUrl": "string",
"riskFactors": [
"CRITICAL_SEVERITY"
],
"rlUpdatedOn": 0,
"scanId": "string",
"score": {},
"severity": "INFORMATIONAL",
"source": "AWS_INSPECTOR",
"sourceData": {},
"status": "PENDING",
"title": "string",
"type": "HOST_VULNERABILITY_CVE",
"updatedOn": 0
}
]
bad_request / invalid_parameter_value