All Products
Search
Document Center

Security Center:OperateCommonOverallConfig

Last Updated:Sep 15, 2026

Configures a global switch based on the specified type.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:OperateCommonOverallConfig

update

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

223.79.XX.XX

Type

string

Yes

The configuration type. Valid values:

  • kdump_switch: proactive defense optimization

  • threat_detect: adaptive threat detection

  • suspicious_aggregation: alert association

  • alidetect: file detection

  • USER-ENABLE-SWITCH-TYPE_38857: Linux entry service performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_50858: Linux web service performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_50859: Linux entry service performs suspicious operations

  • USER-ENABLE-SWITCH-TYPE_50862: Linux Cloud Assistant advanced protection

  • USER-ENABLE-SWITCH-TYPE_50867: Linux malicious file implantation

  • USER-ENABLE-SWITCH-TYPE_50868: Linux suspicious file implantation

  • USER-ENABLE-SWITCH-TYPE_64025: Linux entry service executes commands [enhanced mode]

  • USER-ENABLE-SWITCH-TYPE_51229: Windows browser service performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_51230: Windows entry service performs suspicious operations

  • USER-ENABLE-SWITCH-TYPE_51232: Windows system process performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_51233: Windows Java service performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_51234: Windows Office component performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_51235: Windows web service performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_52820: Windows malicious file implantation

  • USER-ENABLE-SWITCH-TYPE_52826: Windows entry service performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_55251: Windows database service performs high-risk operations

  • USER-ENABLE-SWITCH-TYPE_63725: Windows entry service implants suspicious scripts or binary files

  • USER-ENABLE-SWITCH-TYPE_3277: Linux suspicious process startup

  • USER-ENABLE-SWITCH-TYPE_50983: Linux obfuscated commands

  • USER-ENABLE-SWITCH-TYPE_51200: Linux command line downloads and runs malicious files

  • USER-ENABLE-SWITCH-TYPE_71131: Linux entry service performs suspicious behavior sequence

  • USER-ENABLE-SWITCH-TYPE_51225: Windows PowerShell executes high-risk commands

  • USER-ENABLE-SWITCH-TYPE_51226: Windows PowerShell executes suspicious commands

  • USER-ENABLE-SWITCH-TYPE_52821: Windows suspicious process startup

  • USER-ENABLE-SWITCH-TYPE_57242: Windows malicious command execution

  • USER-ENABLE-SWITCH-TYPE_57340: Windows command line downloads and runs malicious files

  • USER-ENABLE-SWITCH-TYPE_39659: Windows sensitive registry key protection

  • USER-ENABLE-SWITCH-TYPE_52816: Windows high-risk account manipulation

  • USER-ENABLE-SWITCH-TYPE_54365: Windows creates service auto-start items

  • USER-ENABLE-SWITCH-TYPE_54366: Windows creates high-risk auto-start items

  • USER-ENABLE-SWITCH-TYPE_54367: Windows creates scheduled task auto-start items

  • USER-ENABLE-SWITCH-TYPE_54368: Windows creates registry auto-start items

  • USER-ENABLE-SWITCH-TYPE_54369: Windows creates WMI auto-start items

  • USER-ENABLE-SWITCH-TYPE_50869: Linux privilege escalation to execute high-risk commands

  • USER-ENABLE-SWITCH-TYPE_53272: Linux kernel vulnerability exploitation for privilege escalation

  • USER-ENABLE-SWITCH-TYPE_54395: Linux privilege escalation to read or write sensitive files

  • USER-ENABLE-SWITCH-TYPE_57897: Linux suspected privilege escalation

  • USER-ENABLE-SWITCH-TYPE_52825: Windows privilege escalation to execute high-risk commands

  • USER-ENABLE-SWITCH-TYPE_5507: Linux malicious driver

  • USER-ENABLE-SWITCH-TYPE_50876: Linux anti-security software

  • USER-ENABLE-SWITCH-TYPE_53168: Linux process debugging

  • USER-ENABLE-SWITCH-TYPE_54699: Linux dynamic-link library hijacking

  • USER-ENABLE-SWITCH-TYPE_62981: Linux security monitoring bypass

  • USER-ENABLE-SWITCH-TYPE_52815: Windows loads high-risk drivers

  • USER-ENABLE-SWITCH-TYPE_52823: Windows runs high-risk ARK tools

  • USER-ENABLE-SWITCH-TYPE_54373: Windows anti-security software

  • USER-ENABLE-SWITCH-TYPE_54374: Windows intrusion trace cleanup

  • USER-ENABLE-SWITCH-TYPE_54265: Linux PAM module hijacking

  • USER-ENABLE-SWITCH-TYPE_54953: Linux HashDump attack

  • USER-ENABLE-SWITCH-TYPE_54383: Windows MimiKatz credential theft

  • USER-ENABLE-SWITCH-TYPE_54384: Windows HashDump attack

  • USER-ENABLE-SWITCH-TYPE_50861: Linux information reconnaissance

  • USER-ENABLE-SWITCH-TYPE_52818: Windows information reconnaissance

  • USER-ENABLE-SWITCH-TYPE_54034: Linux internal network scanning

  • USER-ENABLE-SWITCH-TYPE_51228: Windows high-risk lateral movement tools

  • USER-ENABLE-SWITCH-TYPE_50870: Linux reverse shell

  • USER-ENABLE-SWITCH-TYPE_50873: WebShell command execution

  • USER-ENABLE-SWITCH-TYPE_51236: Windows reverse shell

  • USER-ENABLE-SWITCH-TYPE_50877: Linux malicious program communication

  • USER-ENABLE-SWITCH-TYPE_50884: Linux suspicious worm script behavior

  • USER-ENABLE-SWITCH-TYPE_50885: Linux malicious script behavior

  • USER-ENABLE-SWITCH-TYPE_51201: Linux ransomware

  • USER-ENABLE-SWITCH-TYPE_51202: Linux suspicious ransomware behavior

  • USER-ENABLE-SWITCH-TYPE_52827: Windows ransomware

  • USER-ENABLE-SWITCH-TYPE_52828: Windows suspicious ransomware behavior

  • USER-ENABLE-SWITCH-TYPE_52829: Windows system backup deletion behavior

kdump_switch

Config

string

Yes

The switch status. Valid values:

  • on: enabled

  • off: disabled

on

NoTargetAsOn

boolean

No

Specifies whether asset configuration is required. Default value: false. Valid values:

  • true: Required.

  • false: Not required.

Note

This parameter takes effect only when config is set to on.

true

ClientToken

string

No

The client token that is used to ensure the idempotence of the request. Use a different token for each request. The token supports only ASCII characters and cannot exceed 64 characters in length.

No

Specifies whether to perform only a dry run, without performing the actual request. Valid values: true: performs only a dry run without performing the actual request. false: performs the actual request. Default value: false.

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

7E0618A9-D5EF-4220-9471-C42B5E92719F

Examples

Success response

JSON format

{
  "RequestId": "7E0618A9-D5EF-4220-9471-C42B5E92719F"
}

Error codes

HTTP status code

Error code

Error message

Description

400 IdempotentParameterMismatch 相同的 ClientToken 被用于不同的请求参数。
500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.
409 IdempotentRequestInProgress 使用相同 ClientToken 的请求正在处理中。

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.