All Products
Search
Document Center

Security Center:DescribeDomainSecureAlarmList

Last Updated:Jun 16, 2026

Queries security alert data from a website security report.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeDomainSecureAlarmList

list

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

139.227.*.*

Lang

string

No

The language type of the request and response messages. Valid values:

  • zh: Chinese

  • en: English.

zh

From

string

No

The identifier of the request source. Set this parameter to sas.

sas

Response elements

Element

Type

Description

Example

object

The response parameters.

TotalCount

integer

The total number of entries returned.

42

RequestId

string

The ID of the request. The ID is a unique identifier that Alibaba Cloud generates for the request and can be used to troubleshoot issues.

D03DD0FD-6041-5107-AC00-383E28F1****

AlarmList

array<object>

The list of security alerts for website assets.

object

The list of security alerts for website assets.

Dealed

boolean

Indicates whether the alert event has been handled. Valid values:

  • N: Pending.

  • Y: Handled.

y

Stages

string

The stage of the attack or intrusion.

[\"authority_maintenance\"]

InternetIp

string

The public IP address of the server.

95.214.*.*

SuspiciousEventCount

integer

The total number of security alerts for your website assets.

1

GmtModified

integer

The time when the alert event was last modified.

1656901794000

AlarmEventNameOriginal

string

The original parent name of the alert event.

login_common_location

AlarmUniqueInfo

string

The unique identifier of the alert event.

8df914418f4211fbf756efe7a6f4****

CanCancelFault

boolean

Indicates whether the alert event can be unmarked as a false positive. Valid values:

  • true: Can be unmarked.

  • false: Cannot be unmarked.

false

SecurityEventIds

string

The IDs of the alert events associated with the alert event.

270789

CanBeDealOnLine

boolean

Indicates whether the alert event can be handled online, such as blocking, adding to a whitelist, or ignoring. Valid values:

  • true: Can be handled online.

  • false: Cannot be handled online.

true

Description

string

The description of the alert event.

The detection model finds that there is a Trojan horse program on your server. The Trojan horse program is a program specially used to invade the user's host. Generally, it will download and release another malicious program after being implanted into the system through disguise.

ContainHwMode

boolean

Indicates whether the alert event contains the critical event protection mode.

true

InstanceName

string

The name of the asset instance affected by the alert event.

TestInstance

SaleVersion

string

The edition of Security Center that supports the detection of the alert event. Valid values:

  • 0: Basic edition.

  • 1: Advanced edition.

  • 2: Enterprise edition.

1

OperateErrorCode

string

The result code of the alert event handling.

kill_and_quara.Success

Solution

string

The solution for the alert event.

A malicious program implanted by hacker after intrusion will occupy your bandwidth and attack other servers, and may affect you own service. The malicious process may also have self-deleting behavior or disguise as a system service to evade detection.

DataSource

string

The data source of the alert event.

aegis_****

HasTraceInfo

boolean

Indicates whether the alert event has tracing information. Valid values:

  • true: Has tracing information.

  • false: Does not have tracing information.

true

OperateTime

integer

The timestamp when the alert event was handled. Unit: milliseconds.

1631699497000

InstanceId

string

The ID of the asset instance affected by the alert event.

i-e****

IntranetIp

string

The private IP address of the asset instance affected by the alert event.

192.168.XX.XX

EndTime

integer

The timestamp of the most recent occurrence of the alert event. Unit: milliseconds.

1543740301000

StartTime

integer

The start timestamp of the alert event. Unit: milliseconds.

1543740301000

Uuid

string

The unique identifier of the instance associated with the alert event.

47900178-885d-4fa4-9d77-****

AlarmEventType

string

The type of the alert event.

Malicious Software

AutoBreaking

boolean

Indicates whether automatic defense is enabled.

true

AlarmEventName

string

The name of the alert event.

Trojan

Level

string

The risk level of the alert event. Valid values:

  • serious: Critical.

  • suspicious: Suspicious.

  • remind: Reminder.

serious

Examples

Success response

JSON format

{
  "TotalCount": 42,
  "RequestId": "D03DD0FD-6041-5107-AC00-383E28F1****",
  "AlarmList": [
    {
      "Dealed": true,
      "Stages": "[\\\"authority_maintenance\\\"]\n",
      "InternetIp": "95.214.*.*",
      "SuspiciousEventCount": 1,
      "GmtModified": 1656901794000,
      "AlarmEventNameOriginal": "login_common_location",
      "AlarmUniqueInfo": "8df914418f4211fbf756efe7a6f4****",
      "CanCancelFault": false,
      "SecurityEventIds": "270789",
      "CanBeDealOnLine": true,
      "Description": "The detection model finds that there is a Trojan horse program on your server. The Trojan horse program is a program specially used to invade the user's host. Generally, it will download and release another malicious program after being implanted into the system through disguise.",
      "ContainHwMode": true,
      "InstanceName": "TestInstance",
      "SaleVersion": "1",
      "OperateErrorCode": "kill_and_quara.Success",
      "Solution": "A malicious program implanted by hacker after intrusion will occupy your bandwidth and attack other servers, and may affect you own service. The malicious process may also have self-deleting behavior or disguise as a system service to evade detection. ",
      "DataSource": "aegis_****",
      "HasTraceInfo": true,
      "OperateTime": 1631699497000,
      "InstanceId": "i-e****",
      "IntranetIp": "192.168.XX.XX",
      "EndTime": 1543740301000,
      "StartTime": 1543740301000,
      "Uuid": "47900178-885d-4fa4-9d77-****",
      "AlarmEventType": "Malicious Software",
      "AutoBreaking": true,
      "AlarmEventName": "Trojan",
      "Level": "serious"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

500 ServerError ServerError
403 NoPermission caller has no permission

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.