This URL creates new attack set profile at domain level.
Resource URL
POST /domain/<domainId>/attacksetprofile/createruleset
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| domainId | Domain id | Number | Yes |
Payload Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| policyName | Policy name | String | Yes |
| description | Policy description | String | Yes |
| enableRfSBExpoit | RfSB exploit configuration | Boolean | Yes |
| enableRfSBMalware | RfSB malware configuration | Boolean | Yes |
| enableRfSBRecon | RfSB recon configuration | Boolean | Yes |
| enableRfSBPolicy | RfSB policy configuration | Boolean | Yes |
| isEditable | Attack set editable configuration | Boolean | No |
| action | Inclusion/exclusion of rules Values can be:
|
String | No |
| comment | Comments | String | No |
| isSpecificAttack | Specific attack name | Boolean | No |
| AttackList | List of attacks | String | No |
| minSeverity | Severity level values can be:
|
String | No |
| maxBTP | BTP level values can be:
|
String | No |
| attackType | Type of attack values can be:
|
String | No |
| attackCategory | Attack category | String | No |
| application | Application list | String | No |
| Protocol | Protocols | String | No |
| operatingsystem | Operating system | String | No |
Response Parameters
Following fields are returned.
| Field Name | Description | Data Type |
|---|---|---|
| createdResourceId | Unique id of the created policy | Number |
Example
Request
POST https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/createruleset
{
"policyName": "New Attackset_API",
"description": "Test creation ",
"enableRfSBExpoit": false,
"enableRfSBMalware": false,
"enableRfSBRecon": false,
"enableRfSBPolicy": false,
"rules": [
{
"action": "INCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": "LOW(2)",
"maxBTP": "MEDIUM(4)",
"attackType": "ANY",
"attackCategory": [
null
],
"application": [
null
],
"protocol": [
null
],
"operatingsystem": [
null
],
},
{
"action": "EXCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": null,
"maxBTP": null,
"attackType": "ANY",
"attackCategory": [
"Reconnaissance"
],
"application": [
null
],
"protocol": [
null
],
"operatingsystem": [
null
],
}
],
}
Response
{
createdResourceId :1
}
Error Information
Following error codes are returned by this URL:
| No | SDK API errorId | SDK API errorMessage |
|---|---|---|
| 1 | 1105 | Invalid domain |
| 2 | 7001 | Invalid policy id |
| 3 | 7001 | Duplicate name detected |
| 4 | 7001 | The first rule in the list must be an Include rule |
| 5 | 7001 | Invalid attack type input |
| 6 | 7001 | A rule cannot contain multiple items of multiple categories at the same time |