The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Attack Set Profile Configuration Details using Policy ID at Domain Level

Prev Next

This URL retrieves the rule set configuration details at domain level.

Resource URL

GET /domain/<domainId>/ attacksetprofile/rulesetdetails/<policyId>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domainId Domain id Number Yes
policyId Policy id Number Yes

Response Parameters

Following fields are returned if the operation was successful, otherwise error details are returned.

Field Name Description Data Type
policyName Policy name String
domainId Domain id Number
domainName Domain name String
policyId Policy id Number
description Policy description String
lastModifiedTime Last modified time String
enableRfSBExpoit RfSB exploit configuration Boolean
enableRfSBMalware RfSB malware configuration Boolean
enableRfSBRecon RfSB recon configuration Boolean
enableRfSBPolicy RfSB policy configuration Boolean
isEditable Attack set editable configuration Boolean
rules Rules of attack set profile Object

Details of rules:

Field Name Description Data Type
action Inclusion/exclusion of rules String
comment Comments String
isSpecificAttack Specific attack name Boolean
AttackList List of attacks String
minSeverity Severity level String
maxBTP BTP level String
attackType Type of attack String
attackCategory Attack category String
application Application list String
protocol Protocols String
operatingsystem Operating system String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/rulesetdetails/<policyId>

Response

{
"policyName": "Outside Firewall",
"domainId": 0,
"domainName": "My Company",
"policyId": 1,
"description": "Include all except for the RECONNAISSANCE category, and excluding known noisy signatures. ",
"lastModifiedTime": "2017-06-20 10:46:04",
"lastModifiedUser": "1",
"enableRfSBExpoit": false,
"enableRfSBMalware": false,
"enableRfSBRecon": false,
"enableRfSBPolicy": false,
"isEditable": false,
"rules": [
  {
"action": "INCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": "LOW(2)",
"maxBTP": "MEDIUM(4)",
"attackType": "ANY",
"attackCategory": [
  null
],
"application": [
  null
],
"protocol": [
  null
],
"operatingsystem": [
  null
],
},
  {
"action": "EXCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": null,
"maxBTP": null,
"attackType": "ANY",
"attackCategory": [
  "Reconnaissance"
],
"application": [
  null
],
"protocol": [
  null
],
"operatingsystem": [
  null
],
}
],
} 
 

Error Information

Following error codes are returned by this URL:

No SDK API errorId SDK API errorMessage
1 1105 Invalid domain
2 7001 Invalid policy id