Overview
This endpoint retrieves a paginated list of the individual detection events that constitute a specific threat. Target a threat by its threat_id in the path. The response is an array of detection objects, each containing granular data like trace IDs and MITRE ATT&CK tags. Use this API to conduct a deep-dive investigation of a threat. After a high-level threat is identified, call this endpoint to retrieve the specific, low-level events. This data is essential for understanding the root cause and the specific tactics, techniques, and procedures used.
Authentication
Authentication type: Bearer Token, API Key.
You can create a token using client credentials obtained through the developer portal. The API Key (x-api-key) is provided in your onboarding email or on the API Access Management page.
Path (or URL)
<HTTPS Method>
GET https://{Trellix EDR_gateway_URL}/edr/v2/threats/{threat_id}/detections
Request
Request headers
Authorization: Bearer <your_bearer_token> Content-Type: application/vnd.api+json x-api-key: <your_api_key> Accept-Encoding: gzip
Authorization: This header is used to authenticate your request. You need to replace
<your_bearer_token>with the actual token you generate.Content-Type: This header tells the server that the request body format is
json:api. Even though this specific call has no request body, the API requires this header.x-api-key: This is a custom header required by the Trellix API for authentication. You'll need to replace
<your_api_key>with the key from your onboarding email or the API Access Management page.Accept-Encoding: This is an optional header you can include to tell the server you can accept a compressed response (using gzip), which can make the data transfer faster.
Request parameters
Parameters | Data type/Values | Description |
|---|---|---|
sort | string | Specifies the order (ascending/descending) for the returned results. |
from | integer | Sets the start of the time frame to search, in epoch milliseconds. |
to | integer | Sets the end of the time frame to search, in epoch milliseconds. |
filter | string | Narrows down results based on criteria like severity, name, or rank. |
page[offset] | integer | Skips a specified number of records; used for pagination. |
page[limit] | integer | Sets the maximum number of records to return per page. |
Response
Response parameters
Parameter | Data Type | Description |
|---|---|---|
traceId | string | Correlation / distributed tracing ID associated with the execution path. |
sha256 | string | SHA-256 of the primary file payload involved in the detection. |
firstDetected | string (date-time) | Timestamp when the malicious behavior was first observed. |
lastDetected | string (date-time) | Timestamp of the most recent observation of this behavior. |
severity | string (enum: s0–s5) | Severity classification for this detection. For details, see Security levels. |
rank | integer | Computed analytics rank / priority sequence identifier. |
tags | array[string] | Collection of metadata tags / labels assigned to the detection event. |
host | object | Endpoint context (same structure as Affected Host host object above). |
Response example
{
"jsonapi": {
"version": "1.0"
},
"meta": {
"totalResourceCount": 1
},
"data": [
{
"type": "detections",
"id": "652404",
"attributes": {
"traceId": "9a718cc6-d8f6-46da-b3cc-fc4dbbd60151",
"firstDetected": "2023-08-27T05:34:29Z",
"lastDetected": "2023-08-27T05:34:29Z",
"severity": "s4",
"rank": 270,
"tags": [
"@ATA.Persistence",
"@ATE.T1112",
"@ATA.PrivilegeEscalation",
"@ATA.DefenseEvasion",
"@MSI._reg_ep0130_imageexecution_high",
"@ATE.T1546.012"
],
"host": {
"os": {},
"netInterfaces": [],
"traceExtendedVisibility": 0,
"hostOs": "",
"aGuid": "6D0A37A8-B5B7-4414-9444-A2B17721642B"
},
"sha256": "6E2918727CBB836F4D8E3404BDE9AEAF5D4DED5DD1F6916AAD3F3B956E6D8A17"
}
}
],
"links": {
"self": "/edr/v2/threats/182612/detections?page[offset]=0&page[limit]=20",
"first": "/edr/v2/threats/182612/detections?page[offset]=0&page[limit]=20",
"prev": "/edr/v2/threats/182612/detections?page[offset]=0&page[limit]=20",
"next": "/edr/v2/threats/182612/detections?page[offset]=0&page[limit]=20",
"last": "/edr/v2/threats/182612/detections?page[offset]=0&page[limit]=20"
}
}
Response codes
Status | Response | Description |
|---|---|---|
200 | OK | Your request was processed successfully. The server has returned the requested data. |
400 | Bad request | The server couldn't understand your request, likely due to a syntax error or an invalid parameter. |
401 | Access denied request | Your request was rejected because it lacks valid authentication credentials. Check your API key and token. |
403 | Forbidden | You are not authorized to access this resource. While your credentials may be valid, you don't have the necessary permissions. |
404 | Not Found | The specific resource or endpoint you requested does not exist. |
415 | Unsupported Media Type | The server rejected your request because the data format |
429 | Too Many Requests | You've exceeded the rate limit by sending too many requests in a short period. The |
500 | Internal Server Error | Something went wrong on the server's end. This is not an issue with your request. |