Azure.ResourceManager.SecurityInsights.Models Namespace
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Classes
AadCheckRequirements |
Represents AADIP (Azure Active Directory Identity Protection) requirements check request. |
AatpCheckRequirements |
Represents AATP (Azure Advanced Threat Protection) requirements check request. |
ActivityCustomEntityQuery |
Represents Activity entity query. |
ActivityEntityQuery |
Represents Activity entity query. |
ActivityEntityQueryDefinition |
The Activity query definitions. |
ActivityEntityQueryTemplate |
Represents Activity entity query. |
ActivityTimelineItem |
Represents Activity timeline item. |
AddIncidentTaskActionProperties |
The AddIncidentTaskActionProperties. |
AlertRuleTemplateDataSource |
alert rule template data sources. |
AnalyticsRuleRunTrigger |
Analytics Rule Run Trigger request. |
AnomalySecurityMLAnalyticsSettings |
Represents Anomaly Security ML Analytics Settings. |
AnomalyTimelineItem |
Represents anomaly timeline item. |
ArmSecurityInsightsModelFactory |
Model factory for models. |
AscCheckRequirements |
Represents ASC (Azure Security Center) requirements check request. |
AutomationRuleAddIncidentTaskAction |
Describes an automation rule action to add a task to an incident. |
AutomationRuleBooleanCondition |
The AutomationRuleBooleanCondition. |
AutomationRuleModifyPropertiesAction |
Describes an automation rule action to modify an object's properties. |
AutomationRulePropertyArrayChangedValuesCondition |
The AutomationRulePropertyArrayChangedValuesCondition. |
AutomationRulePropertyArrayValuesCondition |
The AutomationRulePropertyArrayValuesCondition. |
AutomationRulePropertyValuesChangedCondition |
The AutomationRulePropertyValuesChangedCondition. |
AutomationRulePropertyValuesCondition |
The AutomationRulePropertyValuesCondition. |
AutomationRuleRunPlaybookAction |
Describes an automation rule action to run a playbook. |
AutomationRuleRunPlaybookActionProperties |
The AutomationRuleRunPlaybookActionProperties. |
AwsAuthModel |
Model for API authentication with AWS. |
AwsCloudTrailCheckRequirements |
Amazon Web Services CloudTrail requirements check request. |
AwsS3CheckRequirements |
Amazon Web Services S3 requirements check request. |
AwsS3DataConnector |
Represents Amazon Web Services S3 data connector. |
AzureDevOpsResourceInfo |
Resources created in Azure DevOps repository. |
BasicAuthModel |
Model for API authentication with basic flow - user name + password. |
BookmarkConnectedEntity |
Expansion result connected entities. |
BookmarkEntityMappings |
Describes the entity mappings of a single entity. |
BookmarkExpandContent |
The parameters required to execute an expand operation on the given bookmark. |
BookmarkExpandResponseValue |
The expansion result values. |
BookmarkExpandResult |
The entity expansion result operation response. |
BookmarkTimelineItem |
Represents bookmark timeline item. |
BooleanConditionProperties |
Describes an automation rule condition that applies a boolean operator (e.g AND, OR) to conditions. |
CcpAuthConfig |
Base Model for API authentication. Please note CcpAuthConfig is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include SecurityInsightsApiKeyAuthModel, AwsAuthModel, BasicAuthModel, GcpAuthModel, GitHubAuthModel, JwtAuthModel, NoneAuthModel, OAuthModel, OracleAuthModel, GenericBlobSbsAuthModel and SessionAuthModel. |
CcpResponseConfig |
A custom response configuration for a rule. |
CodelessApiPollingDataConnector |
Represents Codeless API Polling data connector. |
CodelessConnectorPollingAuthProperties |
Describe the authentication properties needed to successfully authenticate with the server. |
CodelessConnectorPollingConfigProperties |
Config to describe the polling config for API poller connector. |
CodelessConnectorPollingPagingProperties |
Describe the properties needed to make a pagination call. |
CodelessConnectorPollingRequestProperties |
Describe the request properties needed to successfully pull from the server. |
CodelessConnectorPollingResponseProperties |
Describes the response from the external server. |
CodelessUiConnectorConfigProperties |
Config to describe the instructions blade. |
CodelessUiDataConnector |
Represents Codeless UI data connector. |
ConnectorAvailability |
Connector Availability Status. |
ConnectorConnectivityCriteria |
Setting for the connector check connectivity. |
ConnectorConnectivityCriterion |
The criteria by which we determine whether the connector is connected or not. For Example, use a KQL query to check if the expected data type is flowing). |
ConnectorCustoms |
Customs permissions required for the connector. |
ConnectorCustomsPermission |
Customs permissions required for the connector. |
ConnectorDataType |
The data type which is created by the connector, including a query indicated when was the last time that data type was received in the workspace. |
ConnectorDefinitionsAvailability |
The exposure status of the connector to the customers. |
ConnectorDefinitionsPermissions |
The required Permissions for the connector. |
ConnectorDefinitionsResourceProvider |
The resource provider details include the required permissions for the user to create connections. The user should have the required permissions(Read\Write, ..) in the specified scope ProviderPermissionsScope against the specified resource provider. |
ConnectorGraphQueries |
The graph query to show the current data status. |
ConnectorGraphQuery |
The graph query to show the volume of data arriving into the workspace over time. |
ConnectorInstructionModelBase |
Instruction step details. |
ConnectorPermissions |
Permissions required for the connector. |
ConnectorRequiredPermissions |
Required permissions for the connector. |
ConnectorResourceProvider |
Resource provider permissions required for the connector. |
ConnectorResourceProviderRequiredPermissions |
Required permissions for the connector resource provider that define in ResourceProviders. For more information about the permissions see <see href="https://docs.microsoft.com/en-us/azure/role-based-access-control/role-definitions#actions-format">here</see>. |
CustomizableConnectionsConfig |
The UiConfig for 'Customizable' connector definition kind. |
CustomizableConnectorDefinitionData |
Connector definition for kind 'Customizable'. |
CustomizableConnectorUiConfig |
The UiConfig for 'Customizable' connector definition kind. |
CustomPermissionDetails |
The Custom permissions required for the connector. |
DataConnectorConnectContent |
Represents Codeless API Polling data connector. |
DataConnectorDataTypeCommon |
Common field for data type in data connectors. |
DataConnectorRequirementsState |
Data connector requirements status. |
DataConnectorsCheckRequirements |
Data connector requirements properties. Please note DataConnectorsCheckRequirements is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include AwsCloudTrailCheckRequirements, AwsS3CheckRequirements, AadCheckRequirements, AatpCheckRequirements, AscCheckRequirements, Dynamics365CheckRequirements, IotCheckRequirements, McasCheckRequirements, MdatpCheckRequirements, MicrosoftPurviewInformationProtectionCheckRequirements, MstiCheckRequirements, MtpCheckRequirements, Office365ProjectCheckRequirements, OfficeAtpCheckRequirements, OfficeIrmCheckRequirements, OfficePowerBICheckRequirements, ThreatIntelligenceCheckRequirements and ThreatIntelligenceTaxiiCheckRequirements. |
DataTypeDefinitions |
The data type definition. |
DcrConfiguration |
The configuration of the destination of the data. |
Dynamics365CheckRequirements |
Represents Dynamics365 requirements check request. |
Dynamics365DataConnector |
Represents Dynamics365 data connector. |
EnrichmentDomainContent |
Domain name to be enriched. |
EnrichmentDomainWhois |
Whois information for a given domain and associated metadata. |
EnrichmentDomainWhoisContact |
An individual contact associated with this domain. |
EnrichmentDomainWhoisContacts |
The set of contacts associated with this domain. |
EnrichmentDomainWhoisDetails |
The whois record for a given domain. |
EnrichmentDomainWhoisRegistrarDetails |
The registrar associated with this domain. |
EnrichmentIPAddressContent |
IP address (v4 or v6) to be enriched. |
EnrichmentIPGeodata |
Geodata information for a given IP address. |
EntityAnalytics |
Settings with single toggle. |
EntityEdges |
The edge that connects the entity to the other entity. |
EntityExpandContent |
The parameters required to execute an expand operation on the given entity. |
EntityExpandResponseValue |
The expansion result values. |
EntityExpandResult |
The entity expansion result operation response. |
EntityFieldMapping |
Map identifiers of a single entity. |
EntityGetInsightsContent |
The parameters required to execute insights operation on the given entity. |
EntityInsightItem |
Entity insight Item. |
EntityInsightItemQueryTimeInterval |
The Time interval that the query actually executed on. |
EntityManualTriggerRequestContent |
Describes the request body for triggering a playbook on an entity. |
EntityQueryItem |
An abstract Query item for entity Please note EntityQueryItem is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include InsightQueryItem. |
EntityQueryItemProperties |
An properties abstract Query item for entity. |
EntityQueryItemPropertiesDataTypesItem |
The EntityQueryItemPropertiesDataTypesItem. |
EntityTimelineContent |
The parameters required to execute s timeline operation on the given entity. |
EntityTimelineItem |
Entity timeline Item. Please note EntityTimelineItem is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include ActivityTimelineItem, AnomalyTimelineItem, BookmarkTimelineItem and SecurityAlertTimelineItem. |
ExpansionEntityQuery |
Represents Expansion entity query. |
ExpansionResultAggregation |
Information of a specific aggregation in the expansion result. |
FusionScenarioExclusionPattern |
Represents a Fusion scenario exclusion patterns in Fusion detection. |
FusionSourceSettings |
Represents a supported source signal configuration in Fusion detection. |
FusionSourceSubTypeSetting |
Represents a supported source subtype configuration under a source signal in Fusion detection. |
FusionSubTypeSeverityFilter |
Represents severity configuration for a source subtype consumed in Fusion detection. |
FusionSubTypeSeverityFiltersItem |
Represents a Severity filter setting for a given source subtype consumed in Fusion detection. |
FusionTemplateSourceSetting |
Represents a source signal consumed in Fusion detection. |
FusionTemplateSourceSubType |
Represents a source subtype under a source signal consumed in Fusion detection. |
FusionTemplateSubTypeSeverityFilter |
Represents severity configurations available for a source subtype consumed in Fusion detection. |
GcpAuthModel |
Model for API authentication for all GCP kind connectors. |
GcpAuthProperties |
Google Cloud Platform auth section properties. |
GcpDataConnector |
Represents Google Cloud Platform data connector. |
GcpRequestProperties |
Google Cloud Platform request section properties. |
GenericBlobSbsAuthModel |
Model for API authentication for working with service bus or storage account. |
GitHubAuthModel |
Model for API authentication for GitHub. For this authentication first we need to approve the Router app (Microsoft Security DevOps) to access the GitHub account, Then we only need the InstallationId to get the access token from https://api.github.com/app/installations/{installId}/access_tokens. |
IndicatorObservablesItem |
An observable of this indicator. |
InsightQueryItem |
Represents Insight Query. |
InsightQueryItemProperties |
Represents Insight Query. |
InsightQueryItemPropertiesAdditionalQuery |
The activity query definitions. |
InsightQueryItemPropertiesDefaultTimeRange |
The insight chart query. |
InsightQueryItemPropertiesTableQuery |
The insight table query. |
InsightQueryItemPropertiesTableQueryColumnsDefinitionsItem |
The InsightQueryItemPropertiesTableQueryColumnsDefinitionsItem. |
InsightQueryItemPropertiesTableQueryQueriesDefinitionsItem |
The InsightQueryItemPropertiesTableQueryQueriesDefinitionsItem. |
InsightQueryItemPropertiesTableQueryQueriesDefinitionsPropertiesItemsItem |
The InsightQueryItemPropertiesTableQueryQueriesDefinitionsPropertiesItemsItem. |
InsightsTableResult |
Query results for table insights query. |
InsightsTableResultColumnsItem |
The InsightsTableResultColumnsItem. |
InstructionStep |
Instruction steps to enable the connector. |
InstructionStepDetails |
Instruction step details, to be displayed in the Instructions steps section in the connector's page in Sentinel Portal. |
InstructionSteps |
Instruction steps to enable the connector. |
IotCheckRequirements |
Represents IoT requirements check request. |
IotDataConnector |
Represents IoT data connector. |
JobItem |
An entity describing the publish status of a content item. |
JwtAuthModel |
Model for API authentication with JWT. Simple exchange between user name + password to access token. |
LastDataReceivedDataType |
Data type for last data received. |
ManualTriggerRequestBody |
The ManualTriggerRequestBody. |
McasCheckRequirements |
Represents MCAS (Microsoft Cloud App Security) requirements check request. |
McasDataConnector |
Represents MCAS (Microsoft Cloud App Security) data connector. |
McasDataConnectorDataTypes |
The available data types for MCAS (Microsoft Cloud App Security) data connector. |
MdatpCheckRequirements |
Represents MDATP (Microsoft Defender Advanced Threat Protection) requirements check request. |
MdatpDataConnector |
Represents MDATP (Microsoft Defender Advanced Threat Protection) data connector. |
MicrosoftPurviewInformationProtectionCheckRequirements |
Represents MicrosoftPurviewInformationProtection requirements check request. |
MicrosoftPurviewInformationProtectionDataConnector |
Represents Microsoft Purview Information Protection data connector. |
MicrosoftSecurityIncidentCreationAlertRule |
Represents MicrosoftSecurityIncidentCreation rule. |
MicrosoftSecurityIncidentCreationAlertRuleTemplate |
Represents MicrosoftSecurityIncidentCreation rule template. |
MLBehaviorAnalyticsAlertRule |
Represents MLBehaviorAnalytics alert rule. |
MLBehaviorAnalyticsAlertRuleTemplate |
Represents MLBehaviorAnalytics alert rule template. |
MstiCheckRequirements |
Represents Microsoft Threat Intelligence requirements check request. |
MstiDataConnector |
Represents Microsoft Threat Intelligence data connector. |
MtpCheckRequirements |
Represents MTP (Microsoft Threat Protection) requirements check request. |
MtpDataConnector |
Represents MTP (Microsoft Threat Protection) data connector. |
NicEntity |
Represents an network interface entity. |
NoneAuthModel |
Model for API authentication with no authentication method - public API. |
NrtAlertRule |
Represents NRT alert rule. |
NrtAlertRuleTemplate |
Represents NRT alert rule template. |
OAuthModel |
Model for API authentication with OAuth2. |
Office365ProjectCheckRequirements |
Represents Office365 Project requirements check request. |
Office365ProjectDataConnector |
Represents Office Microsoft Project data connector. |
OfficeAtpCheckRequirements |
Represents OfficeATP (Office 365 Advanced Threat Protection) requirements check request. |
OfficeAtpDataConnector |
Represents OfficeATP (Office 365 Advanced Threat Protection) data connector. |
OfficeIrmCheckRequirements |
Represents OfficeIRM (Microsoft Insider Risk Management) requirements check request. |
OfficeIrmDataConnector |
Represents OfficeIRM (Microsoft Insider Risk Management) data connector. |
OfficePowerBICheckRequirements |
Represents Office PowerBI requirements check request. |
OfficePowerBIDataConnector |
Represents Office Microsoft PowerBI data connector. |
OracleAuthModel |
Model for API authentication for Oracle. |
PropertyArrayConditionProperties |
Describes an automation rule condition that evaluates an array property's value. |
PublicationFailedError |
The error description for why a publication failed. |
PullRequestInfo |
Information regarding pull request for protected branches. |
RecommendedSuggestion |
What suggestions should be taken to complete the recommendation. |
ReevaluateResult |
Reevaluate response object. |
RelationshipHint |
An object used to help follow relationships from this object to other STIX objects. |
RepositoryAccess |
Credentials to access repository. |
RepositoryAccessProperties |
Credentials to access repository. |
RepositoryResourceInfo |
Resources created in user's repository for the source-control. |
RestApiPollerDataConnector |
Represents Rest Api Poller data connector. |
RestApiPollerRequestConfig |
The request configuration. |
RestApiPollerRequestPagingConfig |
The request paging configuration. |
SapSolutionUsageStatistic |
Billing statistic about the Microsoft Sentinel solution for SAP Usage. |
ScheduledAlertRuleTemplate |
Represents scheduled alert rule template. |
SecurityAlertTimelineItem |
Represents security alert timeline item. |
SecurityInsightsAadDataConnector |
Represents AADIP (Azure Active Directory Identity Protection) data connector. |
SecurityInsightsAatpDataConnector |
Represents AATP (Azure Advanced Threat Protection) data connector. |
SecurityInsightsAccountEntity |
Represents an account entity. |
SecurityInsightsAlert |
Represents a security alert entity. |
SecurityInsightsAlertConfidenceReason |
confidence reason item. |
SecurityInsightsAlertDetailsOverride |
Settings for how to dynamically override alert static details. |
SecurityInsightsAlertPropertyMapping |
A single alert property mapping to override. |
SecurityInsightsAlertRuleActionCreateOrUpdateContent |
Action for alert rule. |
SecurityInsightsAlertRuleEntityMapping |
Single entity mapping for the alert rule. |
SecurityInsightsAlertsDataTypeOfDataConnector |
Alerts data type for data connectors. |
SecurityInsightsApiKeyAuthModel |
Model for authentication with the API Key. Will result in additional header on the request (default behavior) to the remote server: 'ApiKeyName: ApiKeyIdentifier ApiKey'. If 'IsApiKeyInPostPayload' is true it will send it in the body of the request and not the header. |
SecurityInsightsAscDataConnector |
Represents ASC (Azure Security Center) data connector. |
SecurityInsightsAutomationRuleAction |
Describes an automation rule action. Please note SecurityInsightsAutomationRuleAction is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include AutomationRuleAddIncidentTaskAction, AutomationRuleModifyPropertiesAction and AutomationRuleRunPlaybookAction. |
SecurityInsightsAutomationRuleCondition |
Describes an automation rule condition. Please note SecurityInsightsAutomationRuleCondition is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include BooleanConditionProperties, SecurityInsightsPropertyConditionProperties, PropertyArrayConditionProperties, SecurityInsightsPropertyArrayChangedConditionProperties and SecurityInsightsPropertyChangedConditionProperties. |
SecurityInsightsAutomationRuleTriggeringLogic |
Describes automation rule triggering logic. |
SecurityInsightsAwsCloudTrailDataConnector |
Represents Amazon Web Services CloudTrail data connector. |
SecurityInsightsAzureResourceEntity |
Represents an azure resource entity. |
SecurityInsightsBookmarkIncidentInfo |
Describes related incident information for the bookmark. |
SecurityInsightsClientInfo |
Information on the client (user or application) that made some action. |
SecurityInsightsCloudApplicationEntity |
Represents a cloud application entity. |
SecurityInsightsDnsEntity |
Represents a dns entity. |
SecurityInsightsEntity |
A class representing the SecurityInsightsEntity data model. Specific entity. Please note SecurityInsightsEntity is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include SecurityInsightsAccountEntity, SecurityInsightsAzureResourceEntity, SecurityInsightsHuntingBookmark, SecurityInsightsCloudApplicationEntity, SecurityInsightsDnsEntity, SecurityInsightsFileEntity, SecurityInsightsFileHashEntity, SecurityInsightsHostEntity, SecurityInsightsIotDeviceEntity, SecurityInsightsIPEntity, SecurityInsightsMailboxEntity, SecurityInsightsMailClusterEntity, SecurityInsightsMailMessageEntity, SecurityInsightsMalwareEntity, NicEntity, SecurityInsightsProcessEntity, SecurityInsightsRegistryKeyEntity, SecurityInsightsRegistryValueEntity, SecurityInsightsAlert, SecurityInsightsGroupEntity, SecurityInsightsSubmissionMailEntity and SecurityInsightsUriEntity. |
SecurityInsightsEntityQueryCreateOrUpdateContent |
Specific entity query that supports put requests. Please note SecurityInsightsEntityQueryCreateOrUpdateContent is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include ActivityCustomEntityQuery. |
SecurityInsightsEyesOn |
Settings with single toggle. |
SecurityInsightsFieldMapping |
A single field mapping of the mapped entity. |
SecurityInsightsFileEntity |
Represents a file entity. |
SecurityInsightsFileHashEntity |
Represents a file hash entity. |
SecurityInsightsFileMetadata |
Represents a file. |
SecurityInsightsFileValidationError |
Describes an error encountered in the file during validation. |
SecurityInsightsFusionAlertRule |
Represents Fusion alert rule. |
SecurityInsightsFusionAlertRuleTemplate |
Represents Fusion alert rule template. |
SecurityInsightsGroupEntity |
Represents a security group entity. |
SecurityInsightsGroupingConfiguration |
Grouping configuration property bag. |
SecurityInsightsHostEntity |
Represents a host entity. |
SecurityInsightsHuntingBookmark |
Represents a Hunting bookmark entity. |
SecurityInsightsHuntOwner |
Describes a user that the hunt is assigned to. |
SecurityInsightsIncidentActionConfiguration |
The SecurityInsightsIncidentActionConfiguration. |
SecurityInsightsIncidentAdditionalInfo |
Incident additional data property bag. |
SecurityInsightsIncidentConfiguration |
Incident Configuration property bag. |
SecurityInsightsIncidentEntitiesMetadata |
Information of a specific aggregation in the incident related entities result. |
SecurityInsightsIncidentEntitiesResult |
The incident related entities response. |
SecurityInsightsIncidentLabel |
Represents an incident label. |
SecurityInsightsIncidentOwnerInfo |
Information on the user an incident is assigned to. |
SecurityInsightsIotDeviceEntity |
Represents an IoT device entity. |
SecurityInsightsIPEntity |
Represents an ip entity. |
SecurityInsightsIPEntityGeoLocation |
The geo-location context attached to the ip entity. |
SecurityInsightsMailboxEntity |
Represents a mailbox entity. |
SecurityInsightsMailClusterEntity |
Represents a mail cluster entity. |
SecurityInsightsMailMessageEntity |
Represents a mail message entity. |
SecurityInsightsMalwareEntity |
Represents a malware entity. |
SecurityInsightsMetadataAuthor |
Publisher or creator of the content item. |
SecurityInsightsMetadataCategories |
ies for the solution content item. |
SecurityInsightsMetadataDependencies |
Dependencies for the content item, what other content items it requires to work. Can describe more complex dependencies using a recursive/nested structure. For a single dependency an id/kind/version can be supplied or operator/criteria for complex dependencies. |
SecurityInsightsMetadataPatch |
Metadata patch request body. |
SecurityInsightsMetadataSource |
The original source of the content item, where it comes from. |
SecurityInsightsMetadataSupport |
Support information for the content item. |
SecurityInsightsOfficeDataConnector |
Represents office data connector. |
SecurityInsightsOfficeDataConnectorDataTypes |
The available data types for office data connector. |
SecurityInsightsPackageCollectionGetAllOptions |
The SecurityInsightsPackageCollectionGetAllOptions. |
SecurityInsightsProcessEntity |
Represents a process entity. |
SecurityInsightsProductTemplateCollectionGetAllOptions |
The SecurityInsightsProductTemplateCollectionGetAllOptions. |
SecurityInsightsPropertyArrayChangedConditionProperties |
Describes an automation rule condition that evaluates an array property's value change. |
SecurityInsightsPropertyChangedConditionProperties |
Describes an automation rule condition that evaluates a property's value change. |
SecurityInsightsPropertyConditionProperties |
Describes an automation rule condition that evaluates a property's value. |
SecurityInsightsRecommendationPatch |
Recommendation Fields to update. |
SecurityInsightsRegistryKeyEntity |
Represents a registry key entity. |
SecurityInsightsRegistryValueEntity |
Represents a registry value entity. |
SecurityInsightsScheduledAlertRule |
Represents scheduled alert rule. |
SecurityInsightsSettingAnomaliesKind |
Settings with single toggle. |
SecurityInsightsSubmissionMailEntity |
Represents a submission mail entity. |
SecurityInsightsTemplateCollectionGetAllOptions |
The SecurityInsightsTemplateCollectionGetAllOptions. |
SecurityInsightsThreatIntelligence |
ThreatIntelligence property bag. |
SecurityInsightsThreatIntelligenceIndicatorData |
Threat intelligence indicator entity. |
SecurityInsightsTIDataConnector |
Represents threat intelligence data connector. |
SecurityInsightsUriEntity |
Represents a url entity. |
SecurityInsightsUserInfo |
User information that made some action. |
SecurityMLAnalyticsSettingsDataSource |
security ml analytics settings data sources. |
SentinelEntityMapping |
A single sentinel entity mapping. |
SessionAuthModel |
Model for API authentication with session cookie. |
SourceControlDeployment |
Description about a deployment. |
SourceControlDeploymentInfo |
Information regarding a deployment. |
SourceControlOperationWarning |
Warning response structure. |
SourceControlOperationWarningBody |
Warning details. |
SourceControlRepo |
Represents a repository. |
SourceControlRepository |
metadata of a repository. |
SourceControlSampleQueries |
The sample queries for the connector. |
SourceControlServicePrincipal |
Service principal metadata. |
SourceControlWebhook |
Detail about the webhook object. |
TeamInformation |
Describes team information. |
TemplateBaseProperties |
Template property bag. |
TemplateProperties |
Template property bag. |
ThreatIntelligenceAlertRule |
Represents Threat Intelligence alert rule. |
ThreatIntelligenceAlertRuleTemplate |
Represents Threat Intelligence alert rule template. |
ThreatIntelligenceAppendTags |
Array of tags to be appended to the threat intelligence indicator. |
ThreatIntelligenceAttackPattern |
Represents an attack pattern in Azure Security Insights. |
ThreatIntelligenceCheckRequirements |
Threat Intelligence Platforms data connector check requirements. |
ThreatIntelligenceCount |
Count of all the threat intelligence objects on the workspace that match the provided query. |
ThreatIntelligenceCountQuery |
Represents a query to run on the TI objects in the workspace. |
ThreatIntelligenceExternalReference |
Describes external reference. |
ThreatIntelligenceFilteringCriteria |
Filtering criteria for querying threat intelligence indicators. |
ThreatIntelligenceGranularMarkingEntity |
Describes threat granular marking model entity. |
ThreatIntelligenceIdentity |
Represents an identity in Azure Security Insights. |
ThreatIntelligenceIndicator |
Represents an indicator in Azure Security Insights. |
ThreatIntelligenceKillChainPhase |
Describes threat kill chain phase entity. |
ThreatIntelligenceMetric |
Describes threat intelligence metric. |
ThreatIntelligenceMetricEntity |
Describes threat intelligence metric entity. |
ThreatIntelligenceMetrics |
Threat intelligence metrics. |
ThreatIntelligenceObject |
Represents a threat intelligence object in Azure Security Insights. Please note ThreatIntelligenceObject is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include ThreatIntelligenceAttackPattern, ThreatIntelligenceIdentity, ThreatIntelligenceIndicator, ThreatIntelligenceRelationship and ThreatIntelligenceThreatActor. |
ThreatIntelligenceParsedPattern |
Describes parsed pattern entity. |
ThreatIntelligenceParsedPatternTypeValue |
Describes threat kill chain phase entity. |
ThreatIntelligenceQuery |
Represents a query to run on the TI objects in the workspace. |
ThreatIntelligenceQueryCondition |
Represents a condition used to query for TI objects. |
ThreatIntelligenceQueryConditionClause |
Represents a single clause to be evaluated by a NormalizedCondition. |
ThreatIntelligenceQueryConditionProperties |
Represents a condition used to query for TI objects. |
ThreatIntelligenceQuerySortBy |
Specifies how to sort the query results. |
ThreatIntelligenceRelationship |
Represents a relationship in Azure Security Insights. |
ThreatIntelligenceSortingCriteria |
List of available columns for sorting. |
ThreatIntelligenceTaxiiCheckRequirements |
Threat Intelligence TAXII data connector check requirements. |
ThreatIntelligenceTaxiiDataConnector |
Data connector to pull Threat intelligence data from TAXII 2.0/2.1 server. |
ThreatIntelligenceThreatActor |
Represents a threat actor in Azure Security Insights. |
ThreatIntelligenceUserInfo |
Data about a user or client application. |
UebaSettings |
Settings with single toggle. |
WorkspaceEnrichmentIPGeodata |
Geodata information for a given IP address. |
WorkspaceManagerAssignmentItem |
An entity describing a content item. |
Structs
AnomalySecurityMLAnalyticsSettingsStatus |
The anomaly SecurityMLAnalyticsSettings status. |
AntispamMailDirection |
The directionality of this mail message. |
AutomationRuleBooleanConditionSupportedOperator |
The AutomationRuleBooleanConditionSupportedOperator. |
AutomationRulePropertyArrayChangedConditionSupportedArrayType |
The AutomationRulePropertyArrayChangedConditionSupportedArrayType. |
AutomationRulePropertyArrayChangedConditionSupportedChangeType |
The AutomationRulePropertyArrayChangedConditionSupportedChangeType. |
AutomationRulePropertyArrayConditionSupportedArrayConditionType |
The AutomationRulePropertyArrayConditionSupportedArrayConditionType. |
AutomationRulePropertyArrayConditionSupportedArrayType |
The AutomationRulePropertyArrayConditionSupportedArrayType. |
AutomationRulePropertyChangedConditionSupportedChangedType |
The AutomationRulePropertyChangedConditionSupportedChangedType. |
AutomationRulePropertyChangedConditionSupportedPropertyType |
The AutomationRulePropertyChangedConditionSupportedPropertyType. |
AutomationRulePropertyConditionSupportedOperator |
The AutomationRulePropertyConditionSupportedOperator. |
AutomationRulePropertyConditionSupportedProperty |
The property to evaluate in an automation rule property condition. |
ConnectAuthKind |
The authentication kind used to poll the data. |
ConnectorAvailabilityStatus |
The connector Availability Status. |
ConnectorConnectivityType |
type of connectivity. |
ConnectorHttpMethodVerb |
The HTTP method, default value GET. |
ConnectorProviderName |
Provider name. |
ConnectorSettingType |
The kind of the setting. |
DataConnectorAuthorizationState |
Describes the state of user's authorization for a connector kind. |
DataConnectorLicenseState |
Describes the state of user's license for a connector kind. |
DeviceImportance |
Device importance, determines if the device classified as 'crown jewel'. |
EnrichmentType |
The EnrichmentType. |
EntityItemQueryKind |
The EntityItemQueryKind. |
EntityProvider |
The entity provider that is synced. |
EntityQueryKind |
The EntityQueryKind. |
EntityTemplateQueryKind |
The EntityTemplateQueryKind. |
EntityTimelineKind |
The entity query kind. |
EventGroupingAggregationKind |
The event grouping aggregation kinds. |
HuntStatus |
The status of the hunt. |
HypothesisStatus |
The hypothesis status of the hunt. |
IncidentTaskStatus |
The IncidentTaskStatus. |
IngestionMode |
Describes how to ingest the records in the file. |
InsightsColumnOutputType |
Insights Column type. |
MicrosoftSecurityProductName |
The alerts' productName on which the cases will be generated. |
MtpProvider |
The available data providers. |
PermissionProviderScope |
Permission provider scope. |
PollingFrequency |
The polling frequency for the TAXII server. |
ProviderPermissionsScope |
The scope on which the user should have permissions, in order to be able to create connections. |
PublicationStatus |
Status of the item publication. |
RecommendationState |
State of recommendation. |
RepositoryAccessKind |
The kind of repository access credentials. |
RestApiPollerRequestPagingKind |
Type of paging. |
SecurityInsightsAlertConfidenceLevel |
The confidence level of this alert. |
SecurityInsightsAlertConfidenceScoreStatus |
The confidence score calculation status, i.e. indicating if score calculation is pending for this alert, not applicable or final. |
SecurityInsightsAlertDetail |
Alert detail. |
SecurityInsightsAlertProperty |
The V3 alert property. |
SecurityInsightsAlertRuleEntityMappingType |
The V3 type of the mapped entity. |
SecurityInsightsAlertRuleTemplateStatus |
The alert rule template status. |
SecurityInsightsAlertSeverity |
The severity of the alert. |
SecurityInsightsAlertStatus |
The lifecycle status of the alert. |
SecurityInsightsAttackTactic |
The severity for alerts created by this alert rule. |
SecurityInsightsDataTypeConnectionState |
Describe whether this data type connection is enabled or not. |
SecurityInsightsEntityKind |
The kind of the entity. |
SecurityInsightsEntityType |
The type of the entity. |
SecurityInsightsFileDeleteStatus |
Indicates whether the file was deleted from the storage account. |
SecurityInsightsFileFormat |
The format of the file. |
SecurityInsightsFileHashAlgorithm |
The hash algorithm type. |
SecurityInsightsFileImportContentType |
The content type of this file. |
SecurityInsightsFileImportState |
The state of the file import. |
SecurityInsightsGroupingMatchingMethod |
Grouping matching method. When method is Selected at least one of groupByEntities, groupByAlertDetails, groupByCustomDetails must be provided and not empty. |
SecurityInsightsIncidentClassification |
The reason the incident was closed. |
SecurityInsightsIncidentClassificationReason |
The classification reason the incident was closed with. |
SecurityInsightsIncidentLabelType |
The type of the label. |
SecurityInsightsIncidentOwnerType |
The type of the owner the hunt is assigned to. |
SecurityInsightsIncidentSeverity |
The severity of the incident. |
SecurityInsightsIncidentStatus |
The status of the incident. |
SecurityInsightsKillChainIntent |
The intent of the alert. |
SecurityInsightsKind |
The kind of content the metadata is for. |
SecurityInsightsMetadataFlag |
The boolean value the metadata is for. |
SecurityInsightsMetadataPackageKind |
The package kind. |
SecurityInsightsRegistryHive |
the hive that holds the registry key. |
SecurityInsightsRegistryValueKind |
Specifies the data types to use when storing values in the registry, or identifies the data type of a value in the registry. |
SecurityInsightsSourceKind |
Source type of the content. |
SecurityInsightsSupportTier |
Type of support for content item. |
Source |
The source of the watchlist. |
SourceControlContentType |
The content type of a source control path. |
SourceControlDeploymentFetchStatus |
Status while trying to fetch the deployment information. |
SourceControlDeploymentResult |
Status while trying to fetch the deployment information. |
SourceControlDeploymentState |
The current state of the deployment. |
SourceControlOperationWarningCode |
The type of repository. |
SourceControlRepoType |
The type of repository. |
SourceControlVersion |
The version of the source control. |
ThreatIntelligenceQueryConnective |
Represents boolean connectives used to join clauses in conditions. |
ThreatIntelligenceQueryOperator |
Represents an operator in a ConditionClause. |
ThreatIntelligenceQuerySortingDirection |
The direction to sort the results by. |
ThreatIntelligenceSortingOrder |
Sorting order (ascending/descending/unsorted). |
ThreatIntelligenceType |
The ThreatIntelligenceType. |
TriggeredAnalyticsRuleRunProvisioningState |
The triggered analytics rule run provisioning state. |
TriggersOn |
The TriggersOn. |
TriggersWhen |
The TriggersWhen. |
UebaDataSource |
The data source that enriched by ueba. |
WatchlistSourceType |
The sourceType of the watchlist. |
WorkspaceManagerConfigurationMode |
The current mode of the workspace manager configuration. |
Enums
SecurityInsightsAlertRuleTriggerOperator |
The operation against the threshold that triggers alert rule. |
SecurityInsightsHostOSFamily |
The operating system type. |
SecurityInsightsMailMessageDeliveryAction |
The delivery action of this mail message like Delivered, Blocked, Replaced etc. |
SecurityInsightsMailMessageDeliveryLocation |
The delivery location of this mail message like Inbox, JunkFolder etc. |
SecurityInsightsProcessElevationToken |
The elevation token associated with the process. |