This URL gets the list of executables running on your internal endpoints.
Resource URL
GET /<nbaid>/endpointintelligence?search=<search_string>&&confidencetype=<confidencetype>&&classificationtype=<classificationtype>&&duration=<duration>
Request Parameters
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| nbaId | NTBA monitors id | String | Yes |
| Search | Search string | String | No |
| confidencetype | Confidence type
|
String | No |
| classificationtype | Classification type
|
String | No |
| duration | Duration
|
String | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| EndpointExecutableList | List of endpoint executables | Array |
Details of EndpointExecutableList:
| Field Name | Description | Data Type |
|---|---|---|
| executableHash | Executable hash | String |
| executableName | Executable name | String |
| executableVersions | Executable versions | String |
| classification | Classification | String |
| fileSize | File size | String |
| firstseen | First seen | String |
| lastseen | Last seen | String |
| endpointsCount | Endpoints count | Int |
| connectionsCount | Connections count | Int |
| eventsCount | Events count | Int |
| comment | Comment | String |
Example
Request
Response
{
"endpointExecutableList":[
{"executableHash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"executableName":"abc.exe",
"executableVersions":"file_version",
"malwareConfidence":"Medium",
"classification":"unclassified",
"fileSize":2566795,
"firstSeen":"2013-09-10 00:00:00",
"lastSeen":"2013-09-10 12:45:00",
"endpointsCount":1,
"connectionsCount":4,
"eventsCount":12}]
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 3601 | Invalid duration |
| 3 | 400 | 3603 | Invalid confidence type |
| 4 | 400 | 3604 | Invalid classification type |
| 4 | 400 | 4904 | Failed to retrieve data |