EDR
Get Alert by ID
Retrieve an EDR alert by its ID (Leen’s UUID).
GET
Path Parameters
Response
200 - application/json
Active Directory domain
Active Directory user ID
Assigned user
Description of alert, provided by the upstream vendor
Device attached to the alert, include device groups with includeDeviceGroups query parameter
First event time
Last event time
MITRE Tactics associated with the alert
Parent process ID
Process ID
Process command line
Process created at
Process filename
Process filepath
Process MD5
Process SHA1
Process SHA256
Resolved time
Title of the alert, provided by the upstream vendor
User name
Source vendor
Available options:
crowdstrike
, ms_defender_endpoint
, sentinelone
Vendor's ID of the alert
Vendor's severity
Vendor's status
Windows SID
Observable data associated with the alert
Alert severity
Available options:
none
, low
, medium
, high
, critical
, info
Alert status
Available options:
unknown
, new
, in_progress
, unresolved
, resolved