This URL updates the attack set profile configuration details at domain level.
Resource URL
PUT /domain/<domainId>/ attacksetprofile/updateruleset/<policyId>
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| domainId | Domain id | Number | Yes |
| policyId | Policy id | Number | Yes |
Payload parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| policyName | Policy name | String | Yes |
| description | Policy description | String | Yes |
| enableRfSBExpoit | RfSB exploit configuration | Boolean | Yes |
| enableRfSBMalware | RfSB malware configuration | Boolean | Yes |
| enableRfSBRecon | RfSB recon configuration | Boolean | Yes |
| enableRfSBPolicy | RfSB policy configuration | Boolean | Yes |
| isEditable | AttackSet editable configuration | Boolean | No |
| action | Inclusion/exclusion of rules Values can be:
|
String | No |
| comment | Comments | String | No |
| isSpecificAttack | Specific attack name | Boolean | No |
| AttackList | List of attacks | String | No |
| minSeverity | Severity level values can be:
|
String | No |
| maxBTP | BTP level values can be:
|
String | No |
| attackType | Type of attack values can be:
|
String | No |
| attackCategory | Attack category | String | No |
| Application | Application list | String | No |
| Protocol | Protocols | String | No |
| operatingsystem | Operating system | String | No |
Response Parameters
Following fields are returned if the operation was successful, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| status | Set to 1 if the operation was successful | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/updateruleset/<policyId>
Payload
{"policyName":"API new create2",
"description":"Include all except for the RECONNAISSANCE\ncategory, and excluding known noisy signatures.",
"enableRfSBExpoit":false,
"enableRfSBMalware":false,
"enableRfSBRecon":false,
"enableRfSBPolicy":false,
"rules":[{"action":"INCLUDE",
"comment":null,"isSpecificAttack":false,"AttackList":[],"minSeverity":"LOW(2)","maxBTP":"MEDIUM(4)","attackType":"ANY","attackCategory":[null],"application":[null],"protocol":[null],"operatingsystem":[null]}]}
Response
{
status:1
}
Error Information
Following error codes are returned by this URL:
| No | SDK API errorId | SDK API errorMessage |
|---|---|---|
| 1 | 1105 | Invalid domain |
| 2 | 7001 | Invalid policy id |
| 3 | 7001 | Duplicate name detected |
| 4 | 7001 | The first rule in the list must be an Include rule |
| 5 | 7001 | Invalid attack type input |
| 6 | 7001 | A rule cannot contain multiple items of multiple categories at the same time |