This URL creates new attack set profile at domain level.
Resource URL
POST /domain/<domainId>/attacksetprofile/createruleset
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
Payload Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Policy name | String | Yes |
| Policy description | String | Yes |
| RfSB exploit configuration | Boolean | Yes |
| RfSB malware configuration | Boolean | Yes |
| RfSB recon configuration | Boolean | Yes |
| RfSB policy configuration | Boolean | Yes |
| Attack set editable configuration | Boolean | No |
| Inclusion/exclusion of rules Values can be:
| String | No |
| Comments | String | No |
| Specific attack name | Boolean | No |
| List of attacks | String | No |
| Severity level values can be:
| String | No |
| BTP level values can be:
| String | No |
| Type of attack values can be:
| String | No |
| Attack category | String | No |
| Application list | String | No |
| Protocols | String | No |
| Operating system | String | No |
Response Parameters
Following fields are returned.
Field Name | Description | Data Type |
|---|---|---|
| Unique id of the created policy | Number |
Example
Request
POST https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/createruleset
{
"policyName": "New Attackset_API",
"description": "Test creation ",
"enableRfSBExpoit": false,
"enableRfSBMalware": false,
"enableRfSBRecon": false,
"enableRfSBPolicy": false,
"rules": [
{
"action": "INCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": "LOW(2)",
"maxBTP": "MEDIUM(4)",
"attackType": "ANY",
"attackCategory": [
null
],
"application": [
null
],
"protocol": [
null
],
"operatingsystem": [
null
],
},
{
"action": "EXCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": null,
"maxBTP": null,
"attackType": "ANY",
"attackCategory": [
"Reconnaissance"
],
"application": [
null
],
"protocol": [
null
],
"operatingsystem": [
null
],
}
],
}
Response
{
createdResourceId :1
}
Error Information
Following error codes are returned by this URL:
No | SDK API errorId | SDK API errorMessage |
|---|---|---|
1 | 1105 | Invalid domain |
2 | 7001 | Invalid policy id |
3 | 7001 | Duplicate name detected |
4 | 7001 | The first rule in the list must be an Include rule |
5 | 7001 | Invalid attack type input |
6 | 7001 | A rule cannot contain multiple items of multiple categories at the same time |