Detection Rules: Search

Search Insikt Group detection rules with deployable YARA, Sigma, and Snort source code.

Body Params
filter
object

Filters Insikt Notes and the associated detection rules.

boolean
Defaults to false

If set to true, the entity ID of tagged entities in the title and body of the Insikt Note associated with the detection rule will be included.

int32
≥ 1
Defaults to 10

Sets the limit of total number of rules that will be returned in the result set. If the search has more results than the specified limit, the next_offset value in the response can be used in the offset value of the next request to get the next set of results.

string

This value, if specified with the next_offset value of a prior result, will indicate where to start showing results from. To see the first set of results of the search, this parameter should be omitted.

Responses

400

Bad Request

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json