mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-23 22:33:41 +00:00
user, files, ip
This commit is contained in:
@ -24,7 +24,7 @@ ms.topic: article
|
|||||||
|
|
||||||
|
|
||||||
## API description
|
## API description
|
||||||
Retrieves the prevalence for the given file.
|
Retrieves the statistics for the given file.
|
||||||
|
|
||||||
|
|
||||||
## Limitations
|
## Limitations
|
||||||
|
@ -18,12 +18,19 @@ ms.topic: article
|
|||||||
|
|
||||||
# Get IP related alerts API
|
# Get IP related alerts API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
|
|
||||||
|
## API description
|
||||||
Retrieves a collection of alerts related to a given IP address.
|
Retrieves a collection of alerts related to a given IP address.
|
||||||
|
|
||||||
|
|
||||||
|
## Limitations
|
||||||
|
1. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
|
||||||
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
||||||
|
|
||||||
@ -69,39 +76,4 @@ Here is an example of the request.
|
|||||||
|
|
||||||
```
|
```
|
||||||
GET https://api.securitycenter.windows.com/api/ips/10.209.67.177/alerts
|
GET https://api.securitycenter.windows.com/api/ips/10.209.67.177/alerts
|
||||||
```
|
```
|
||||||
|
|
||||||
**Response**
|
|
||||||
|
|
||||||
Here is an example of the response.
|
|
||||||
|
|
||||||
|
|
||||||
```
|
|
||||||
HTTP/1.1 200 OK
|
|
||||||
Content-type: application/json
|
|
||||||
{
|
|
||||||
"@odata.context": "https://api.securitycenter.windows.com/api/$metadata#Alerts",
|
|
||||||
"value": [
|
|
||||||
{
|
|
||||||
"id": "441688558380765161_2136280442",
|
|
||||||
"incidentId": 8633,
|
|
||||||
"assignedTo": "secop@contoso.com",
|
|
||||||
"severity": "Low",
|
|
||||||
"status": "InProgress",
|
|
||||||
"classification": "TruePositive",
|
|
||||||
"determination": "Malware",
|
|
||||||
"investigationState": "Running",
|
|
||||||
"category": "MalwareDownload",
|
|
||||||
"detectionSource": "WindowsDefenderAv",
|
|
||||||
"threatFamilyName": "Mikatz",
|
|
||||||
"title": "Windows Defender AV detected 'Mikatz', high-severity malware",
|
|
||||||
"description": "Some description",
|
|
||||||
"alertCreationTime": "2018-11-25T16:19:21.8409809Z",
|
|
||||||
"firstEventTime": "2018-11-25T16:17:50.0948658Z",
|
|
||||||
"lastEventTime": "2018-11-25T16:18:01.809871Z",
|
|
||||||
"resolvedTime": null,
|
|
||||||
"machineId": "9d80fbbc1bdbc5ce968f1d37c72384cbe17ee337"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
```
|
|
@ -18,11 +18,18 @@ ms.topic: article
|
|||||||
|
|
||||||
# Get IP statistics API
|
# Get IP statistics API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
|
|
||||||
|
## API description
|
||||||
|
Retrieves the statistics for the given IP.
|
||||||
|
|
||||||
|
|
||||||
|
## Limitations
|
||||||
|
1. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
|
||||||
|
|
||||||
Retrieves the prevalence for the given IP.
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -18,12 +18,19 @@ ms.topic: article
|
|||||||
|
|
||||||
# Get user related alerts API
|
# Get user related alerts API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
|
|
||||||
|
## API description
|
||||||
Retrieves a collection of alerts related to a given user ID.
|
Retrieves a collection of alerts related to a given user ID.
|
||||||
|
|
||||||
|
|
||||||
|
## Limitations
|
||||||
|
1. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
|
||||||
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
||||||
|
|
||||||
@ -70,59 +77,4 @@ Here is an example of the request.
|
|||||||
|
|
||||||
```
|
```
|
||||||
GET https://api.securitycenter.windows.com/api/users/user1/alerts
|
GET https://api.securitycenter.windows.com/api/users/user1/alerts
|
||||||
```
|
```
|
||||||
|
|
||||||
**Response**
|
|
||||||
|
|
||||||
Here is an example of the response.
|
|
||||||
|
|
||||||
|
|
||||||
```
|
|
||||||
HTTP/1.1 200 OK
|
|
||||||
Content-type: application/json
|
|
||||||
{
|
|
||||||
"@odata.context": "https://api.securitycenter.windows.com/api/$metadata#Alerts",
|
|
||||||
"value": [
|
|
||||||
{
|
|
||||||
"id": "441688558380765161_2136280442",
|
|
||||||
"incidentId": 8633,
|
|
||||||
"assignedTo": "secop@contoso.com",
|
|
||||||
"severity": "Low",
|
|
||||||
"status": "InProgress",
|
|
||||||
"classification": "TruePositive",
|
|
||||||
"determination": "Malware",
|
|
||||||
"investigationState": "Running",
|
|
||||||
"category": "MalwareDownload",
|
|
||||||
"detectionSource": "WindowsDefenderAv",
|
|
||||||
"threatFamilyName": "Mikatz",
|
|
||||||
"title": "Windows Defender AV detected 'Mikatz', high-severity malware",
|
|
||||||
"description": "Some description",
|
|
||||||
"alertCreationTime": "2018-11-25T16:19:21.8409809Z",
|
|
||||||
"firstEventTime": "2018-11-25T16:17:50.0948658Z",
|
|
||||||
"lastEventTime": "2018-11-25T16:18:01.809871Z",
|
|
||||||
"resolvedTime": null,
|
|
||||||
"machineId": "9d80fbbc1bdbc5ce968f1d37c72384cbe17ee337"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "121688558380765161_2136280442",
|
|
||||||
"incidentId": 4123,
|
|
||||||
"assignedTo": "secop@contoso.com",
|
|
||||||
"severity": "Low",
|
|
||||||
"status": "InProgress",
|
|
||||||
"classification": "TruePositive",
|
|
||||||
"determination": "Malware",
|
|
||||||
"investigationState": "Running",
|
|
||||||
"category": "MalwareDownload",
|
|
||||||
"detectionSource": "WindowsDefenderAv",
|
|
||||||
"threatFamilyName": "Mikatz",
|
|
||||||
"title": "Windows Defender AV detected 'Mikatz', high-severity malware",
|
|
||||||
"description": "Some description",
|
|
||||||
"alertCreationTime": "2018-11-24T16:19:21.8409809Z",
|
|
||||||
"firstEventTime": "2018-11-24T16:17:50.0948658Z",
|
|
||||||
"lastEventTime": "2018-11-24T16:18:01.809871Z",
|
|
||||||
"resolvedTime": null,
|
|
||||||
"machineId": "9d80fbbc1bdbc5ce968f1d37c72384cbe17ee337"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
```
|
|
@ -18,12 +18,19 @@ ms.topic: article
|
|||||||
|
|
||||||
# Get user related machines API
|
# Get user related machines API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
|
|
||||||
|
## API description
|
||||||
Retrieves a collection of machines related to a given user ID.
|
Retrieves a collection of machines related to a given user ID.
|
||||||
|
|
||||||
|
|
||||||
|
## Limitations
|
||||||
|
1. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
|
||||||
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
||||||
|
|
||||||
@ -72,54 +79,3 @@ Here is an example of the request.
|
|||||||
```
|
```
|
||||||
GET https://api.securitycenter.windows.com/api/users/user1/machines
|
GET https://api.securitycenter.windows.com/api/users/user1/machines
|
||||||
```
|
```
|
||||||
|
|
||||||
**Response**
|
|
||||||
|
|
||||||
Here is an example of the response.
|
|
||||||
|
|
||||||
|
|
||||||
```
|
|
||||||
HTTP/1.1 200 OK
|
|
||||||
Content-type: application/json
|
|
||||||
{
|
|
||||||
"@odata.context": "https://api.securitycenter.windows.com/api/$metadata#Machines",
|
|
||||||
"value": [
|
|
||||||
{
|
|
||||||
"id": "1e5bc9d7e413ddd7902c2932e418702b84d0cc07",
|
|
||||||
"computerDnsName": "mymachine1.contoso.com",
|
|
||||||
"firstSeen": "2018-08-02T14:55:03.7791856Z",
|
|
||||||
"lastSeen": "2018-08-02T14:55:03.7791856Z",
|
|
||||||
"osPlatform": "Windows10",
|
|
||||||
"osVersion": "10.0.0.0",
|
|
||||||
"lastIpAddress": "172.17.230.209",
|
|
||||||
"lastExternalIpAddress": "167.220.196.71",
|
|
||||||
"agentVersion": "10.5830.18209.1001",
|
|
||||||
"osBuild": 18209,
|
|
||||||
"healthStatus": "Active",
|
|
||||||
"rbacGroupId": 140,
|
|
||||||
"rbacGroupName": "The-A-Team",
|
|
||||||
"riskScore": "Low",
|
|
||||||
"aadDeviceId": "80fe8ff8-2624-418e-9591-41f0491218f9",
|
|
||||||
"machineTags": [ "test tag 1", "test tag 2" ]
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "7292e4b8cb74ff1cc3d8a495eb29dc8858b732f7",
|
|
||||||
"computerDnsName": "mymachine2.contoso.com",
|
|
||||||
"firstSeen": "2018-07-09T13:22:45.1250071Z",
|
|
||||||
"lastSeen": "2018-07-09T13:22:45.1250071Z",
|
|
||||||
"osPlatform": "Windows10",
|
|
||||||
"osVersion": "10.0.0.0",
|
|
||||||
"lastIpAddress": "192.168.12.225",
|
|
||||||
"lastExternalIpAddress": "79.183.65.82",
|
|
||||||
"agentVersion": "10.5820.17724.1000",
|
|
||||||
"osBuild": 17724,
|
|
||||||
"healthStatus": "Inactive",
|
|
||||||
"rbacGroupId": 140,
|
|
||||||
"rbacGroupName": "The-A-Team",
|
|
||||||
"riskScore": "Low",
|
|
||||||
"aadDeviceId": null,
|
|
||||||
"machineTags": [ "test tag 1" ]
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
@ -18,8 +18,9 @@ ms.topic: article
|
|||||||
|
|
||||||
# User resource type
|
# User resource type
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
|
||||||
|
- Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
Method|Return Type |Description
|
Method|Return Type |Description
|
||||||
:---|:---|:---
|
:---|:---|:---
|
||||||
|
Reference in New Issue
Block a user