Manually create a Malicious Sites Playbook Alert for the supplied attacker domain. The alert is created with the cause manual and the creator is taken from the authenticated request.
If the attacker matches the main attacker of an existing alert, the attacker is added to that alert instead of creating a new one.
Provide exactly one of rule or organization to select the use case configuration the alert is created under.
What this endpoint does
Manually creates a Malicious Sites Playbook Alert for an attacker domain you supply — useful when an analyst spots a phishing or brand-impersonation site that automated detection hasn't alerted on yet. The alert is created with cause manual and attributed to the authenticated caller. Provide exactly one of rule (the alert rule id) or organization (whose Malicious Sites use case configuration the alert is created under), and optionally set targets, assignee, status, priority, or a free-text description via options. If the attacker domain already matches the main attacker of an existing alert, the domain is added to that alert instead of creating a duplicate.
Response data
The outcome field tells you what happened — alert_created (a new alert), attacker_added (folded into an existing alert), or already_tracked (nothing new to do) — along with the playbook_alert_id of the created or matched alert, ready to pass to Playbook Alerts: Malicious Sites Detail.
