This URL retrieves the rule set configuration details at domain level.
Resource URL
GET /domain/<domainId>/ attacksetprofile/rulesetdetails/<policyId>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
| Policy id | Number | Yes |
Response Parameters
Following fields are returned if the operation was successful, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Policy name | String |
| Domain id | Number |
| Domain name | String |
| Policy id | Number |
| Policy description | String |
| Last modified time | String |
| RfSB exploit configuration | Boolean |
| RfSB malware configuration | Boolean |
| RfSB recon configuration | Boolean |
| RfSB policy configuration | Boolean |
| Attack set editable configuration | Boolean |
| Rules of attack set profile | Object |
Details of rules:
Field Name | Description | Data Type |
|---|---|---|
| Inclusion/exclusion of rules | String |
| Comments | String |
| Specific attack name | Boolean |
| List of attacks | String |
| Severity level | String |
| BTP level | String |
| Type of attack | String |
| Attack category | String |
| Application list | String |
| Protocols | String |
| Operating system | String |
Example
Request
GET https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/rulesetdetails/<policyId>
Response
{
"policyName": "Outside Firewall",
"domainId": 0,
"domainName": "My Company",
"policyId": 1,
"description": "Include all except for the RECONNAISSANCE category, and excluding known noisy signatures. ",
"lastModifiedTime": "2017-06-20 10:46:04",
"lastModifiedUser": "1",
"enableRfSBExpoit": false,
"enableRfSBMalware": false,
"enableRfSBRecon": false,
"enableRfSBPolicy": false,
"isEditable": false,
"rules": [
{
"action": "INCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": "LOW(2)",
"maxBTP": "MEDIUM(4)",
"attackType": "ANY",
"attackCategory": [
null
],
"application": [
null
],
"protocol": [
null
],
"operatingsystem": [
null
],
},
{
"action": "EXCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": null,
"maxBTP": null,
"attackType": "ANY",
"attackCategory": [
"Reconnaissance"
],
"application": [
null
],
"protocol": [
null
],
"operatingsystem": [
null
],
}
],
}
Error Information
Following error codes are returned by this URL:
No | SDK API errorId | SDK API errorMessage |
|---|---|---|
1 | 1105 | Invalid domain |
2 | 7001 | Invalid policy id |