Queries the list of malicious file alerts.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:ListObjectScanEvent |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| CurrentPage |
integer |
Yes |
The page number of the current page in a paging query. |
1 |
| PageSize |
integer |
Yes |
The maximum number of entries to return on each page in a paging query. |
20 |
| RiskLevel |
string |
No |
The risk level. Valid values:
|
low |
| EventName |
string |
No |
The alert name. |
WebShell |
| Source |
string |
No |
The data source. Valid values:
|
OSS |
| OssKey |
string |
No |
The storage key of the file in the OSS bucket. |
1/2022/06/23/15/41/16559701077444693a0c6-33b2-4cc2-a99f-9f38b8b8**** |
| BucketName |
string |
No |
The bucket name. |
ltrbuck**** |
| Lang |
string |
No |
The language of the request and response. Default value: zh. Valid values:
|
zh |
| Md5 |
string |
No |
The MD5 hash of the file. |
0552c44e243abdea1729d4507bce**** |
| TimeStart |
integer |
No |
The start time of the time range during which the anomalous event occurred. |
1683603086000 |
| TimeEnd |
integer |
No |
The end time of the time range during which the anomalous event occurred. |
1683862286000 |
| ParentEventId |
integer |
No |
If the file is a sub-file within a compressed archive, ParentEventId specifies the event ID of the alert for the compressed archive itself. To retrieve and query alert events for sub-files within a compressed archive:
|
1 |
| Status |
integer |
No |
The event status. Valid values:
|
0 |
| EventId |
integer |
No |
The event ID. |
8925**** |
| BatchType |
string |
No |
The batch operation type. Valid values:
|
sha256 |
|
No |
Specifies whether the alert was detected by AI. Valid values:
|
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response data. |
||
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for this request. You can use it to troubleshoot issues. |
7BC55C8F-226E-5AF5-9A2C-2EC43864**** |
| PageInfo |
object |
The paging information for the paging query. |
|
| CurrentPage |
integer |
The page number of the current page in a paging query. |
1 |
| PageSize |
integer |
The maximum number of entries returned per page in a paging query. |
20 |
| TotalCount |
integer |
The total number of entries. |
253 |
| Data |
array<object> |
The data details. |
|
|
array<object> |
The data details. |
||
| OssKey |
string |
The storage key of the file in the OSS bucket. |
1/2023/07/21/10/18/16899059356518bcf6c64-a04e-492d-a421-4ae8b888**** |
| Md5 |
string |
The MD5 hash of the file. |
5b394b54ca632fe51c4ab4a6dbaf**** |
| BucketName |
string |
The bucket name. |
hz-new01**** |
| RiskLevel |
string |
The risk level of the detected alert. Valid values:
|
medium |
| Source |
string |
The data source. Valid values:
|
OSS |
| FilePath |
string |
The file path. |
/usr/local**** |
| EventName |
string |
The alert name. |
WebShell |
| EventId |
integer |
The event ID. |
911273 |
| FirstTime |
integer |
The timestamp when the alert first occurred. |
1694576692000 |
| LastTime |
integer |
The timestamp when the alert was last detected. |
1694576692000 |
| Sha256 |
string |
The SHA-256 hash of the file. |
3a6fed5fc11392b3ee9f81caf017b48640d7458766a8eb0382899a605b41**** |
| Sha1 |
string |
The SHA-1 hash of the file. |
3c01bdbb26f358bab27f267924aa2c9a03fc**** |
| DisplaySandboxResult |
string |
Indicates whether cloud sandbox detection is supported. Valid values:
|
true |
| Details |
array<object> |
The detailed information of the check item. |
|
|
object |
The details. |
||
| Name |
string |
The name of the detail item. |
DownloadUrl |
| NameDisplay |
string |
The display name of the alert event. |
DownloadUrl |
| Type |
string |
The type of the detail information. |
html |
| Value |
string |
The value of the detail item. |
http://gcx.cn-hangzhou.aliyuncs.com/**** |
| ValueDisplay |
string |
The display value of the detail item. |
http://gcx.cn-hangzhou.aliyuncs.com/**** |
| HasSubEvent |
boolean |
Indicates whether alerts exist for sub-files within a compressed archive. Valid values:
|
true |
| Status |
integer |
The event status. Valid values:
|
0 |
| ErrorMsg |
string |
The error message. |
connect timed out |
| OperateResult |
string |
The alert handling result. |
fail |
| MatchedWhiteListRuleI18nStr |
string |
The information about the matched whitelist rule. |
 md5 contains  23 |
| Remark |
string |
The remarks. |
test |
| AiDetect |
boolean |
Specifies whether the alert was detected by AI. Valid values:
|
Examples
Success response
JSON format
{
"RequestId": "7BC55C8F-226E-5AF5-9A2C-2EC43864****",
"PageInfo": {
"CurrentPage": 1,
"PageSize": 20,
"TotalCount": 253
},
"Data": [
{
"OssKey": "1/2023/07/21/10/18/16899059356518bcf6c64-a04e-492d-a421-4ae8b888****",
"Md5": "5b394b54ca632fe51c4ab4a6dbaf****",
"BucketName": "hz-new01****",
"RiskLevel": "medium",
"Source": "OSS",
"FilePath": "/usr/local****",
"EventName": "WebShell",
"EventId": 911273,
"FirstTime": 1694576692000,
"LastTime": 1694576692000,
"Sha256": "3a6fed5fc11392b3ee9f81caf017b48640d7458766a8eb0382899a605b41****",
"Sha1": "3c01bdbb26f358bab27f267924aa2c9a03fc****",
"DisplaySandboxResult": "true",
"Details": [
{
"Name": "DownloadUrl",
"NameDisplay": "DownloadUrl",
"Type": "html",
"Value": "http://gcx.cn-hangzhou.aliyuncs.com/****",
"ValueDisplay": "http://gcx.cn-hangzhou.aliyuncs.com/****"
}
],
"HasSubEvent": true,
"Status": 0,
"ErrorMsg": "connect timed out",
"OperateResult": "fail",
"MatchedWhiteListRuleI18nStr": "  md5 contains  23 ",
"Remark": "test",
"AiDetect": false
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.