All Products
Search
Document Center

Security Center:DescribeRiskType

Last Updated:Aug 28, 2026

Queries the baseline check types and subtypes in Security Center.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeRiskType

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The source IP address of the request.

192.168.X.X

Lang

string

No

The language of the request and response. Default value: zh. Valid values:

  • zh: Chinese

  • en: English

zh

Source

string

No

The data source. Valid values:

  • default: host baseline

  • agentless: agentless baseline

agentless

Response elements

Element

Type

Description

Example

object

The returned data.

RequestId

string

The request ID.

F22037B5-FCE4-5178-A9E7-71798E1F9270

RiskTypes

array<object>

The baseline types.

array<object>

The information about the baseline type.

TypeName

string

The name of the baseline type.

hc_exploit

Alias

string

The alias of the baseline type.

Redis unauthorized access high exploit vulnerability risk

SubTypes

array<object>

The baseline subtypes.

array<object>

TypeName

string

The name of the baseline subtype.

hc_exploit_redis

Alias

string

The alias of the baseline subtype.

Redis unauthorized access high exploit vulnerability risk

CheckDetails

array<object>

The check details of the baseline subtype.

array<object>

CheckId

integer

The ID of the baseline.

1299

CheckItem

string

The baseline.

Ensure password expiration period is set.

CheckDesc

string

The description of the baseline.

Set password expiration time, force regular modification of password, reduce password leakage and guess risk.Use non-password login (e.g. key pair) please ignore this item.

Rules

array<object>

The rules of the baseline check item.

array<object>

Optional

integer

Specifies whether the baseline can be edited. Valid values:

  • 0: no

  • 1: yes

1

RuleDesc

string

The rule description.

Please customize the password expiration time detection standard as

RuleId

string

The rule ID.

audit.audit_policy.auditpolicychange.cus

ParamList

array<object>

The parameters of the rule.

object

ParamDefaultValue

string

The default value of the parameter.

7

ParamName

string

The name of the parameter.

range_val

MaxValue

integer

The maximum value of the parameter.

999

ParamType

integer

The configuration type of the parameter. Valid values:

  • 1: input

  • 2: selection

1

ParamDesc

string

The description of the parameter.

The setting value is 0 means no definition, 1 means success, 2 means failure, 3 means success and failure

MinValue

integer

The minimum value of the parameter.

1

EnumValue

string

The selectable values when ParamType is 2. This parameter is empty when ParamType is 1.

0,1,2,3

SupportedOs

string

The operating system type of the server. Valid values:

  • windows

  • linux

linux

AuthFlag

boolean

Specifies whether the current user version has access to this baseline subtype. Valid values:

  • true: has access

  • false: no access

true

AuthFlag

boolean

Specifies whether the current user version has access to this baseline type. Valid values:

  • true: has access

  • false: no access

true

Examples

Success response

JSON format

{
  "RequestId": "F22037B5-FCE4-5178-A9E7-71798E1F9270",
  "RiskTypes": [
    {
      "TypeName": "hc_exploit",
      "Alias": "Redis unauthorized access high exploit vulnerability risk",
      "SubTypes": [
        {
          "TypeName": "hc_exploit_redis",
          "Alias": "Redis unauthorized access high exploit vulnerability risk",
          "CheckDetails": [
            {
              "CheckId": 1299,
              "CheckItem": "Ensure password expiration period is set.",
              "CheckDesc": "Set password expiration time, force regular modification of password, reduce password leakage and guess risk.Use non-password login (e.g. key pair) please ignore this item.",
              "Rules": [
                {
                  "Optional": 1,
                  "RuleDesc": "Please customize the password expiration time detection standard as",
                  "RuleId": "audit.audit_policy.auditpolicychange.cus",
                  "ParamList": [
                    {
                      "ParamDefaultValue": "7",
                      "ParamName": "range_val",
                      "MaxValue": 999,
                      "ParamType": 1,
                      "ParamDesc": "The setting value is 0 means no definition, 1 means success, 2 means failure, 3 means success and failure",
                      "MinValue": 1,
                      "EnumValue": "0,1,2,3"
                    }
                  ]
                }
              ]
            }
          ],
          "SupportedOs": "linux",
          "AuthFlag": true
        }
      ],
      "AuthFlag": true
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 -101 %s %s
500 -100 The service is unavailable, please try again later. Service exception, please try again later.
500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.