EDR
Get Alert by ID
Retrieve an EDR alert by its ID (Leen’s UUID).
GET
Path Parameters
Response
200
application/json
Successful Response
Vendor's ID of the alert
Title of the alert, provided by the upstream vendor
Description of alert, provided by the upstream vendor
Assigned user
Vendor's severity
Vendor's status
First event time
Last event time
Resolved time
Source vendor
Available options:
crowdstrike
, ms_defender_endpoint
, sentinelone
Process ID
Process created at
Process filename
Process command line
Process filepath
Process SHA1
Process SHA256
Process MD5
Parent process ID
User name
Windows SID
Active Directory user ID
Active Directory domain
Device attached to the alert, include device groups with includeDeviceGroups query parameter
MITRE Tactics associated with the alert
Alert severity
Available options:
none
, low
, medium
, high
, critical
, info
Alert status
Available options:
unknown
, new
, in_progress
, unresolved
, resolved
Observable data associated with the alert
OCSF Observable object