All Products
Search
Document Center

Security Center:DescribeSuspEventQuaraFiles

Last Updated:Sep 07, 2026

Queries quarantined files in the file quarantine box by paging.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeSuspEventQuaraFiles

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

59.82.XX.XX

PageSize

string

No

The maximum number of entries per page in a paged query.

20

Status

string

No

The status of the quarantined files to query. Valid values:

  • quaraFailed: Quarantine failed.

  • quaraDone: Quarantine succeeded.

  • quaraing: Quarantine in progress.

  • rollbackFailed: Quarantine rollback failed.

  • rollbackDone: Quarantine rollback succeeded.

  • rollbacking: Quarantine rollback in progress.

quaraDone

GroupId deprecated

string

No

The ID of the asset group.

10541428

QuaraTag

string

No

The unique identifier of the quarantined file.

a31337789f64d39b2219733ec99f9af7

CurrentPage

string

No

The page number of the file list to view.

1

From

string

No

The identifier of the request source. Set the value to sas.

sas

GroupingId

integer

No

The ID of the server group where the quarantined file is located.

11472451

Response elements

Element

Type

Description

Example

object

CurrentPage

integer

The current page number of the returned file list.

1

PageSize

integer

The maximum number of quarantined files displayed per page.

20

RequestId

string

The ID of this request, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

32A73759-4C0F-4801-BE98-901223ACEE9A

TotalCount

integer

The total number of quarantined files.

38

Count

integer

The number of quarantined files on the current page.

7

QuaraFiles

array<object>

The list of quarantined files.

object

The quarantined file object.

Status

string

The quarantine status. Valid values:

  • quaraFailed: Quarantine failed.

  • quaraDone: Quarantine succeeded.

  • quaraing: Quarantine in progress.

  • rollbackFailed: Quarantine rollback failed.

  • rollbackDone: Quarantine rollback succeeded.

  • rollbacking: Quarantine rollback in progress.

rollbackDone

EventName

string

The event name.

WEBSHELL

InternetIp

string

The public IP address of the server where the quarantined file is located.

47.XX.XX.131

Ip

string

The public IP address of the server where the quarantined file is located.

47.XX.XX.131

Tag

string

The unique identifier of the event.

228f890e56eae9eec6a42c7ea801b538

InstanceId

string

The instance ID of the asset.

i-2ze9t1qp36n1436m****

Uuid

string

The UUID of the server.

04a0e735-ad32-4835-b635-0458d77b****

EventType

string

The event type.

WebshellQuaraEventType

InstanceName

string

The name of the server where the quarantined file is located.

iZwz98dkiw3vbrtqrt5v****

Path

string

The storage path of the quarantined file on the server.

/var/www/html/webshell-sample-master/others/defc3e21bab59e2a2ab49f7eda99f65f83d4d349.jpg

Md5

string

The MD5 hash of the file.

5ddebe926acc7ed39a664409bfd0ec10

Id

integer

The ID of the quarantined file.

26918

ModifyTime

string

The update time. The value is in the YYYY-MM-DD HH:mm:ss format.

2020-06-11 20:37:08

IntranetIp

string

The private IP address of the server where the quarantined file is located.

192.168.XX.XX

Examples

Success response

JSON format

{
  "CurrentPage": 1,
  "PageSize": 20,
  "RequestId": "32A73759-4C0F-4801-BE98-901223ACEE9A",
  "TotalCount": 38,
  "Count": 7,
  "QuaraFiles": [
    {
      "Link": "https://xxx.xxx/xxx",
      "Status": "rollbackDone",
      "EventName": "WEBSHELL",
      "InternetIp": "47.XX.XX.131",
      "Ip": "47.XX.XX.131",
      "Tag": "228f890e56eae9eec6a42c7ea801b538",
      "InstanceId": "i-2ze9t1qp36n1436m****",
      "Uuid": "04a0e735-ad32-4835-b635-0458d77b****",
      "EventType": "WebshellQuaraEventType",
      "InstanceName": "iZwz98dkiw3vbrtqrt5v****",
      "Path": "/var/www/html/webshell-sample-master/others/defc3e21bab59e2a2ab49f7eda99f65f83d4d349.jpg",
      "Md5": "5ddebe926acc7ed39a664409bfd0ec10",
      "Id": 26918,
      "ModifyTime": "2020-06-11 20:37:08",
      "IntranetIp": "172.16.XX.XX"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 IllegalParameter Illegal parameter, please check the param. Parameter error, please check the input parameters.
500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.