v1

latestOpenAPI 3.1.12026-07-242899061.7 MB
Data Leakage on Code Repository

Bulk Code Repository Data Leakage alert lookup

Perform a detailed lookup of data panels for several alerts at once.

post/code_repo_leakage

Request body

playbook_alert_idsstring[] required

The unique ids of the triggered Playbook Alerts. Maximum number of ids in a single request is 250.

panelsstring[]

Request inclusion of detailed Case data, grouped into a set of panels. If left unset, all panels will be returned.

Example request

{
  "panels": [
    "summary",
    "details",
    "log"
  ]
}

Response

Data for the requested panels.

Example response

{
  "status": {
    "status_code": "Ok",
    "status_message": "Ok"
  },
  "data": [
    {
      "panel_status": {
        "status": "Resolved",
        "assignee_name": "Marty McFly",
        "assignee_id": "uhash:40wXmPVONA",
        "created": "2023-07-21T17:32:28Z",
        "updated": "2023-07-21T17:32:28Z",
        "creator_name": "Marty McFly",
        "creator_id": "uhash:40wXmPVONA",
        "owner_id": "uhash:3HX3rIn4Kv",
        "owner_name": "Recorded Future",
        "organisation_id": "uhash:3HX3rIn4Kv",
        "organisation_name": "Recorded Future",
        "owner_organisation_details": {
          "organisations": [
            {
              "organisation_id": "uhash:3HX3rIn4Kv",
              "organisation_name": "Recorded Future"
            }
          ],
          "enterprise_id": "uhash:1HX2qIn4Zy",
          "enterprise_name": "Recorded Future"
        },
        "targets": [
          {
            "id": "ip:8.8.8.8",
            "type": "IpAddress",
            "name": "8.8.8.8"
          }
        ],
        "actions_taken": [
          "cyber_vulnerability.patched",
          "brand_mentions_on_code_repository.keys_rotated",
          "domain_abuse.takedown",
          "malicious_sites.takedown",
          "third_party_risk.vendor_mitigated_findings",
          "identity_novel_exposures.enforced_password_reset"
        ]
      },
      "panel_evidence_summary": {
        "repository": {
          "id": "url:https://github.com/example-user/example-repo",
          "name": "https://github.com/example-user/example-repo",
          "owner": {
            "id": "ip:8.8.8.8",
            "type": "IpAddress",
            "name": "8.8.8.8"
          }
        },
        "evidence": [
          {
            "assessments": [
              {
                "id": "attr:possibleKeyLeak",
                "title": "Possible Key Leak",
                "value": "admin"
              }
            ],
            "targets": [
              {
                "id": "ip:8.8.8.8",
                "type": "IpAddress",
                "name": "8.8.8.8"
              }
            ],
            "url": "https://github.com/example-user/example-repo/README.md",
            "content": "text fragment from code repository",
            "published": "2023-02-14T09:48:54.082Z"
          }
        ]
      },
      "panel_log": [
        {
          "actor_name": "Marty McFly",
          "actor_id": "uhash:40wXmPVONA",
          "created": "2023-07-21T17:32:28Z",
          "modified": "2023-07-21T17:32:28Z",
          "message": "Sample log message.",
          "changes": {
            "assignee_change": {
              "old": "uhash:Ds92mDX",
              "new": "uhash:AbHGsX"
            },
            "status_change": {
              "old": "New",
              "new": "InProgress"
            },
            "priority_change": {
              "old": "Moderate",
              "new": "High"
            },
            "reopen_strategy_change": {
              "old": "SignificantUpdates",
              "new": "Never"
            },
            "actions_change": {
              "removed": [
                "task:4d65b0f8-8254-402c-8178-4a9f97afc9b2"
              ],
              "added": [
                "task:4d65b0f8-8254-402c-8178-4a9f97afc9b2"
              ]
            },
            "assessment_ids_change": {
              "removed": [
                "Active Mail Server"
              ],
              "added": [
                "C&C Server"
              ]
            }
          },
          "context": {
            "changes": [
              {
                "attacker": "mail.google.mail.pl",
                "manual_addition_user_id": "uhash:40wXmPVONA",
                "manual_addition_user_name": "User Name",
                "typosquat_targets": [
                  "google.com"
                ],
                "similar_domains_keywords": [
                  "*infix*"
                ]
              }
            ]
          }
        }
      ],
      "panel_log_v2": [
        {
          "id": "uuid:a3c4f8f0-8dd8-4940-8b0a-75a59764d068",
          "author_id": "uhash:40wXmPVONA",
          "author_name": "Marty McFly",
          "created": "2023-07-21T17:32:28Z",
          "changes": [
            {
              "old": {
                "id": "uhash:Ds92mDX",
                "name": "Marty"
              },
              "new": {
                "id": "uhash:Ds92mDX",
                "name": "Marty"
              }
            }
          ]
        }
      ]
    }
  ]
}