v1
latestOpenAPI 3.0.12026-07-2491247233.8 KBValidate rule
Validate a rule (MQL, YAML fields, etc). When run against the sandbox or analyzer, no auth is needed but custom lists etc will not be available.
Request body
IDs of actions to run when the rule is triggered
Activate the rule immediately
Rule attack types
Whether auto-reviewed messages will be shared
The classification auto-reviewed messages will have, when an auto-review action is associated with the rule
Description of rule
Rule detection technologies
Descriptions of known false positives that could occur
For core feed only
Rule label
Rule maturity
Rule name
URL references
For Triage rules only, whether this rule will run even if the message matched a global exclusion.
Rule severity
Source
Rule tactics and techniques
Tags
For Triage rules only, whether this rule will run for reported messages. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages whose classification has just changed. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages that matched a DLP rule. For triage rules, one triage_ field must be true.
For Triage rules only, whether this rule will run for messages which flagged. For triage rules, one triage_ field must be true.
Type of the rule
User-provided tags
Response
OK
Function names found in the rule
Whether the rule uses org-specific fields, lists, or functions
List names found in the rule
Validation error message if the rule is invalid