Request a focus view
Request a focus view from a specified device.
Service endpoint | /foci/v2 |
Optional query string parameters | — |
Example | https://protectapi.cylance.com/foci/v2 |
Method | HTTP/1.1 POST |
Request headers |
|
Request
{ "device_id": "E378DACB9324453AB8C65A8406952195", "artifact_type": "Process", "artifact_subtype": "Uid", "value": "59F849F29BBE4F1F889AAF50F9153618", "threat_type": "THREAT", "description": "Focus View Example" }
Response
Please see the Response status codes for more information.
Request JSON schema
Field Name | Description |
---|---|
device_id | This is the unique device ID that the lockdown command was issued to. See About device ID for device ID formatting. |
artifact_type | This is the type of artifact for the focus view.
|
artifact_subtype | This field should always be "Uid" at this time. |
value | This is the UID of the artifact to gather a focus view about. This can be obtained from InstaQuery results, another focus view, the details/associated artifacts of a detection event, or anywhere else an artifact is referenced. |
threat_type | This is an optional field to use with a "Protect" artifact_type to denote the type of threat that a focus view is being generated for. |
description | This is the human-readable description for the focus view. |
Response JSON schema
Field Name | Description |
---|---|
device_id | This is the unique device ID that the lockdown command was issued to. See About device ID for device ID formatting. |
artifact_type | This is the type of artifact for the focus view.
|
artifact_subtype | This field should always be "Uid" at this time. |
value | This is the UID of the artifact to gather a focus view about. This can be obtained from InstaQuery results, another focus view, the details/associated artifacts of a detection event, or anywhere else an artifact is referenced. |
threat_type | This is an optional field to use with a "Protect" artifact_type to denote the type of threat that a focus view is being generated for. |
description | This is the human-readable description for the focus view. |
id | This is the unique ID of the focus view. |
tenant_id | This is the unique ID of the tenant associated with the focus view. |
create_at | This is the timestamp (in UTC) of when the focus view was created. |
hostname | This is the hostname of the device that the focus view was requested from. |
status | This is the status of the focus view result or request. Possible values are:
|
relations | This is a list of objects that are related to this focus view. The following fields can be contained:
|