This URL retrieves the list of top executables.
Resource URL
GET /domain/<domain_id>/threatexplorer/alerts/TopN/<count>/direction/<direction>/duration/<duration>/executables?includeChildDomain=<includeChildDomain>&&action=<action>&&value=<value>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
| Number of top attacks to display. Values allowed are: 5,10,15,20 or 25 | Boolean | No |
| Direction of the attack. Values allowed are: ANY, INBOUND & OUTBOUND | String | No |
| Duration can be:
| String | Yes |
| Include the child domains. Default is true | Boolean | No |
| Should the data be filtered or grouped. Values allowed are:
| String | No |
| If action is group, the values allowed are:
If the action is filter, we can give multiple filters separated by ":::". The format of value will be <filter_name1>=<filter_value>::: <filter_name2>=<filter_value> . The filter_name's and filter_values allowed are:
| String | No |
Response Parameters
Following fields are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of top executables. It contains TE top executables list. | Object |
Details of fields in TETopMalwareDownloadsList:
Field Name | Description | Data Type |
|---|---|---|
| Executable hash value | String |
| Confidence level of executable | String |
| Name of the executable | String |
| Classification of the executable | String |
| Numbers of the attack | Number |
Example
Request
Response
{
"TETopExecutablesList":
[
{
"executableHash": "6691f88cbd9122d990fe9e17197e2771",
"executableConfidence": "veryLow",
"executableName": "BitTorrent.exe",
"executableClassification": "Allowed",
"attackCount": 327
},
{
"executableHash": "fb104d17018b4ca9f0c1a9bed02d15fc",
"executableConfidence": "veryLow",
"executableName": "firefox.exe",
"executableClassification": "Allowed",
"attackCount": 13
},
{
"executableHash": "f71d97b6b631d565af7c6e0bdf9d49f4",
"executableConfidence": "veryLow",
"executableName": "IEXPLORE.EXE.MUI",
"executableClassification": "Allowed",
"attackCount": 6
},
{
"executableHash": "bcd9cbf0621f9a6767276a2e0bf1dd15",
"executableConfidence": "veryLow",
"executableName": "googletalk.exe",
"executableClassification": "Allowed",
"attackCount": 5
}
]
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1105 | Invalid domain |
2 | 400 | 3707 | Top count should be 5,10,15,20 or 25 |
3 | 400 | 3702 | Invalid action |
4 | 400 | 3701 | Invalid "GroupBy" string specified |
5 | 400 | 3704 | Invalid filters specified |
6 | 400 | 3703 | Invalid direction |
7 | 400 | 3601 | Invalid duration |