This URL gets the list of executables running on your internal endpoints.
Resource URL
GET /<nbaid>/endpointintelligence?search=<search_string>&&confidencetype=<confidencetype>&&classificationtype=<classificationtype>&&duration=<duration>
Request Parameters
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| NTBA monitors id | String | Yes |
| Search string | String | No |
| Confidence type
Default: any | String | No |
| Classification type
Default: any | String | No |
| Duration
| String | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of endpoint executables | Array |
Details of EndpointExecutableList:
Field Name | Description | Data Type |
|---|---|---|
| Executable hash | String |
| Executable name | String |
| Executable versions | String |
| Classification | String |
| File size | String |
| First seen | String |
| Last seen | String |
| Endpoints count | Int |
| Connections count | Int |
| Events count | Int |
| Comment | String |
Example
Request
Response
{
"endpointExecutableList":[
{"executableHash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"executableName":"abc.exe",
"executableVersions":"file_version",
"malwareConfidence":"Medium",
"classification":"unclassified",
"fileSize":2566795,
"firstSeen":"2013-09-10 00:00:00",
"lastSeen":"2013-09-10 12:45:00",
"endpointsCount":1,
"connectionsCount":4,
"eventsCount":12}]
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 3601 | Invalid duration |
3 | 400 | 3603 | Invalid confidence type |
4 | 400 | 3604 | Invalid classification type |
4 | 400 | 4904 | Failed to retrieve data |