Downloads malware artifacts data for the specified alert ID as a zip file.
GET https://<address>/wsapis/v1.2.0/artifacts/<alert_type>/<alert_id>
Availability
This command is available on the following appliances:
Central Management System
Malware Analysis
Email Security — Server
File Protect
Network Security
Required header:
X-FeApi-Token: [API-Token]
Request content-type:
application/octet-stream
Parameters
address—This is the IP address of the appliance running the Web Services API.
API-Token—This token authenticates the session. By default, the session times out after 15 minutes of inactivity.
alert_type—Type of alert, for example,
malwareobject.alert_id—ID of the alert.
Example request
GET https://<address>/wsapis/v1.2.0/artifacts/<alert_type>/<alert_id>
List artifacts data by ID response
Response Code—A standard HTML response code.
200—Request successful.
500—Request unsuccessful because the server encountered a problem.
Response Message—A standard HTML response message.
OK—Request successful.
Internal Server Error—Request unsuccessful because the server encountered a problem.
cURL code sample: list artifacts data by ID
The following code sample can be copied and executed from any command-line interface that includes the cURL library.
Note
In this sample, line breaks are added for readability. Remove these line breaks before you paste the code sample into your command-line tool.
curl -qgsSk --header "X-FeApi-Token: IHAT75KulvFZ2fz7NqMJRIRRCmNYQFuXXX=" --header "Accept:application/octet-stream" "https://xxx.xxx.xxx.xxx/wsapis/v1.2.0/artifacts/malwareobject/1" -o file.zip
This cURL sample includes the following options:
-q—This option specifies that thecurlrcconfig file is not read or used. Although this is an optional setting, Trellix recommends that you include this option.-g—This option turns off the URL globbing parser. Although this is an optional setting, Trellix recommends that you include this option.-s—This option turns off the progress meter and error message. Although this is an optional setting, Trellix recommends that you include this option.-S—When used with the-soption, this option shows error messages if your cURL switch fails. Although this is an optional setting, Trellix recommends that you include this option.-k—This option explicitly allows cURL to perform insecure SSL connections and transfers. This allows you to test your SSL connection without installing a CA certificate.https://xxx.xxx.xxx.xxx/wsapis/v1.2.0/artifacts/malwareobject/1}—The fetch request URL. Replace the IP addressxxx.xxx.xxx.xxxwith the IP address of your appliance.-o file.zip—This option specifies the name of the output file.
Results
The specified alert's metadata is returned as a zip file called file.zip. It contains files which have details of malware artifacts as well as a screen capture video file.