v1
latestOpenAPI 3.0.12026-07-2491247233.8 KBUpdate rule
Update a rule to a new definition
Path parameters
Rule ID
Rule ID
Request body
IDs of actions to run when the rule is triggered
Rule attack types
Whether auto-reviewed messages will be shared
The classification auto-reviewed messages will have, when an auto-review action is associated with the rule
Description of rule
Rule detection technologies
Descriptions of known false positives that could occur
For core feed only
Rule label
Rule maturity
Rule name
URL references
For Triage rules only, whether this rule will run even if the message matched a global exclusion.
Rule severity
Source
Rule tactics and techniques
Tags
For Triage rules only, whether this rule will run for reported messages. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages whose classification has just changed. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages that matched a DLP rule. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages which flagged. For triage rules, one triage_ field must be true.
User-provided tags
Response
OK
IDs of actions to run when the rule is triggered
Indicates whether or not the rule is active and will flag matching messages
Rule attack types
Whether auto-reviewed messages will be shared
The classification auto-reviewed messages will have, when an auto-review action is associated with the rule
Rule creation time
Description of rule
Rule detection technologies
Descriptions of known false positives that could occur
Rule ID
Rule label
When the rule was last activated
Rule maturity
Rule name
Indicates whether or not the rule is in passive mode
URLs of reference resources for this rule
For Triage rules only, whether this rule will run even if the message matched a global exclusion.
Rule severity
Rule MQL (Message Query Language) source
Rule tactics and techniques
Freeform tags for this rule (for example, "Executive Impersonation")
For Triage rules only, whether this rule will run for reported messages. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages whose classification has just changed. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages that matched a DLP rule. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages which flagged. For triage rules, one triage_ field must be true.
Rule type
Rule last updated time