All Products
Search
Document Center

Security Center:API overview

Last Updated:Jul 06, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (Sas/2018-12-03) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

Intelligent behavior analysis

API

Title

Description

UpdateUnknownThreatDetectStrategy UpdateUnknownThreatDetectStrategy Updates the unknown threat detection strategy.
UpdateUnknownThreatDetectProcess UpdateUnknownThreatDetectProcess Updates the remark for a specified unknown threat detection process.
OperateUnknownThreatDetectMachine OperateUnknownThreatDetectMachine Modifies the unknown threat detection settings for specified servers.
ListUnknownThreatDetectStrategy ListUnknownThreatDetectStrategy Lists the strategies for intelligent behavior analytics.
ListUnknownThreatDetectProcess ListUnknownThreatDetectProcess Retrieve the list of processes from unknown threat detections.
ListUnknownThreatDetectMachine Query machines for intelligent behavior analytics Queries the list of machines for intelligent behavior analytics.
ListUnknownThreatDetectEvent Query intelligent behavior analytics alerts Queries the list of intelligent behavior analytics alerting events.
HandleUnknownThreatDetectEvent Handle intelligent behavior analytics alerting Handles alerting from intelligent behavior analytics.
GetUnknownThreatDetectStatistic Retrieve intelligent behavior analytics statistics information Retrieves statistics information on intelligent behavior analytics.
DeleteUnknownThreatDetectStrategy Delete a behavior analytics policy Deletes a behavior analytics policy.
DeleteUnknownThreatDetectProcess DeleteUnknownThreatDetectProcess Deletes one or more Unknown Threat Detect processes.
CreateUnknownThreatDetectStrategy CreateUnknownThreatDetectStrategy Creates an intelligent behavior analysis strategy.
AddUnknownThreatDetectProcess AddUnknownThreatDetectProcess Adds one or more processes for intelligent behavior analysis.

Custom client upgrade

API

Title

Description

ListPublishBatch Query release batches Queries the custom upgrade and release batches of the current user.
UpdatePublishBatch Update a release batch Updates a release batch.
UpdatePublishGraySwitch UpdatePublishGraySwitch Updates the settings of the canary release feature for agent upgrade. If you want to use the feature, contact technical support.
UpdatePublishCron Modify client upgrade time Modifies the configuration of the client upgrade time. To use this feature, contact technical support.
UpgradeVersionByUuids Manually upgrade client Manually upgrades the client of an asset.
UpdatePublishAutoUpgrade Modify automatic upgrade switch Enables or disables automatic upgrade.

Proxy access

API

Title

Description

UpdateHybridProxy Upgrade a hybrid cloud proxy client Upgrades a hybrid cloud proxy client.
ModifyHybridProxyCluster Modify remarks of a proxy cluster Modifies the remarks of a proxy cluster.
ModifyHybridProxyPolicy ModifyHybridProxyPolicy Modify proxy policy.
UnBindHybridProxy UnBindHybridProxy Removes servers from a proxy cluster.
DescribeHybridProxyPolicy Query data collection configuration of a proxy cluster Queries the data collection configuration of a specified proxy cluster.
DescribeHybridProxyList Query proxy machines by paging Queries the list of proxy nodes that have been deployed in a specified proxy cluster by paging.
DescribeHybridProxyClusterList Query proxy clusters by using paging Queries proxy clusters by using paging.
DescribeHybridProxyLinkedClientList Query connected clients by paging Queries the list of clients connected to a specified hybrid cloud proxy by paging. This operation is part of the hybrid cloud proxy feature.
DeleteHybridProxyCluster Delete a cluster by cluster name Deletes a proxy cluster by cluster name.
DeleteHybridProxy Delete a proxy node Deletes a proxy node from a specified proxy cluster.
DescribeDefaultProxyInstallVersion Query the default installation version of the hybrid cloud proxy Queries the default installation version of the hybrid cloud proxy.

Security report

API

Title

Description

DescribeReportExport Query security report export information Queries the export information of a security report.
DescribeChartList Query statistical chart list Queries the charts supported for statistics in Security Center security reports.
DescribeReportRecipientStatus Query report contact status Queries the status of report contacts by using the system configuration and security report feature of Security Center.

Application whitelist

API

Title

Description

ModifyProcessWhiteList Modify process whitelist status Adds processes to or removes processes from the whitelist in the application whitelist feature.
UpdateWhiteListStrategyStatus Modify application whitelist policy status Modifies the status of an application whitelist policy.
DescribeWhiteListProcess DescribeWhiteListProcess Queries the information about the processes that are detected in an application whitelist policy.

Agentless detection

API

Title

Description

DeleteMaliciousFileWhitelistConfig Delete a whitelist rule for agentless detection of sensitive file alerts Deletes a whitelist rule for agentless detection of sensitive file alerts.
UpdateMaliciousFileWhitelistConfig Modify a whitelist rule for agentless sensitive file detection alerts Modifies a whitelist rule for agentless sensitive file detection alerts.
CreateMaliciousFileWhitelistConfig Create Sensitive File Alert Whitelist Rule of Agentless Detection Get alert whitelist configuration details
ListMaliciousFileWhitelistConfigs Query allowlist rules for agentless sensitive file detection alerts Queries the list of allowlist rules for agentless sensitive file detection alerts.
DeleteMaliciousNote Delete an agentless detection note Deletes a note for an agentless detection alert event.
RetryAgentlessTask Retry an agentless detection task Retries an agentless detection task.
ListAgentlessRegion Retrieve regions supported by agentless detection Retrieves the regions supported by agentless detection.

Core file monitoring

API

Title

Description

ListFileProtectPluginStatus ListFileProtectPluginStatus Retrieves information about the Security Center agent installed on servers on which core file monitoring rules take effect. The information includes the installation status of the Security Center agent and whether the core file monitoring feature is supported.
UpdateFileProtectEventStatus UpdateFileProtectEventStatus Modifies the status of core file monitoring events reported by the Security Center agent.
GetFileProtectDashboard GetFileProtectDashboard Retrieves information about the core file monitoring feature, including the number of effective rules and the installation status of the Security Center agent on servers.
ListFileProtectEvent Get core file protection alert event list Filters and retrieves a list of rules that match the specified conditions.
UpdateFileProtectRemark Modify Core File Monitoring Event Remarks Modify Alert Remarks
GetFileProtectEvent GetFileProtectEvent Retrieves information about core file monitoring events.

Alert settings

API

Title

Description

Non-Mirror Program Defense Non-Mirror Program Defense
ListContainerDefenseRuleClusters Retrieve all clusters associated with non-image-based program defense rules Retrieves all clusters associated with non-image-based program defense rules.
ListContainerDefenseRule Retrieve defense rules for non-image programs Retrieves the list of defense rules for non-image programs.
GetContainerDefenseRuleDetail Retrieve non-image process defense rule details Retrieves the details of a non-image process defense rule.
ModifyContainerDefenseRule ModifyContainerDefenseRule Modifies a rule for non-image program defense.
ModifyContainerDefenseRuleSwitch Modify non-image program defense rule switch Modifies the switch status of a non-image program defense rule.
Risk mirror blocking Risk mirror blocking
ListOpaClusterStrategyNew Retrieve risky image blocking policies Retrieves the list of risky image blocking policies.
CreateOpaStrategyNew CreateOpaStrategyNew Creates a rule to block at-risk images.
GetOpaStrategyDetailNew GetOpaStrategyDetailNew Retrieves the details of the rule that is used to block at-risk images.
UpdateOpaStrategyNew Update risky image blocking policy Updates the risky image blocking policy.
DeleteOpaStrategyNew Delete a risky image blocking policy Deletes a risky image blocking policy.
GetOpaClusterLabelList GetOpaClusterLabelList Retrieves information about the tags that are added to containers based on the feature of proactive defense for containers.
GetOpaClusterImageList Get Cluster Image Information Get cluster image information.
GetOpaClusterNamespaceList GetOpaClusterNamespaceList Retrieves information about the namespaces of clusters for which the rules of the at-risk image blocking type are configured in proactive defense for containers.
DescribeMatchedMaliciousNames Query malicious file types Queries the list of malicious file types.
Container Escape Prevention Container Escape Prevention
ListAegisContainerPluginRule ListAegisContainerPluginRule Query user configurations.

Container active defense

API

Title

Description

ListSasContainerWebDefenseRule List container file defense rules Queries container file defense rules.
GetSasContainerWebDefenseRule Retrieve container file defense rule details Retrieves a container file defense rule.
OperateSwitchStatus Change the status of a container file defense rule Changes the status of a container file defense rule.
ModifySasContainerWebDefenseRule Modify a container file defense rule Modifies a container file defense rule.

Container file defense

API

Title

Description

ListInterceptionTargetPage Query container firewall protection objects Queries the network objects protected by micro-segmentation (container firewall).
ModifyInterceptionTarget Modify container firewall network object Modifies the network object information of a container firewall.
ListClusterInterceptionConfig Query cluster interception rules Queries the list of cluster interception rules.
ListClusterCnnfStatusDetail Query container firewall status details Queries the status details of the container firewall.
ModifyInterceptionRule Modify a container proactive defense interception rule Modifies a container proactive defense interception rule.
ModifyInterceptionRuleSwitch Modify container proactive defense interception policy switch Modifies the switch status of container proactive defense interception policies.

Container firewall

API

Title

Description

DescribeClientConfStrategy Query client configuration policy Queries the machine configuration information for different client tags.
DescribeClientConfSetup Query client configuration steps Queries the resource configuration information of a client.
DescribeInstallCode Retrieve installation key Retrieves the installation verification key for the agent client installation command.
DeleteInstallCode Delete an installation code Deletes an installation code.
ListPluginForUuid Query asset plugin information Query plugin information of an asset.
UnbindAegis Unbind non-Alibaba Cloud servers from security center Unbinds non-Alibaba Cloud servers from Security Center.
DescribeAgentInstallStatus Query agent installation status Queries the Agent installation status after an Agent installation command is run by using Cloud Assistant. This operation supports querying the installation status only for installations initiated within the last 2 minutes.
DescribeInstallCaptcha Retrieve the installation verification code for manual agent installation Retrieves the installation verification code for manually installing the Agent.
DescribeInstallCodes Query the list of commands for manually installing the security center agent Queries the list of commands for manually installing the Security Center agent.
ListUninstallAegisMachines Query assets without the client installed Queries information about assets that do not have the client installed.
DescribeClientProblemType Query client issue list Retrieves the category list of client issue diagnostics.

Agent client

API

Title

Description

DeleteSearchCondition Delete a saved search condition Deletes a saved search condition from the Assets module of Security Center.
ModifySearchCondition Edit common filter conditions for assets Edits the common filter conditions for host assets.
DescribeGroupStruct Retrieve group structure Retrieves the group structure.
ListCloudAssetInstances Query the cloud service asset list Queries the list of cloud service assets.
DescribeImageInfoList Query Image List for Console Asset Management Query the image list.
DescribeLogShipperStatus Query log analysis feature status Queries the availability status of the log analysis feature.
GetCloudAssetSummary Retrieve cloud asset summary Retrieves the summary of cloud assets.
GetCloudAssetDetail GetCloudAssetDetail Obtains the details of cloud assets.
ModifyAssetImportant Set asset importance Sets the importance level of assets.
ModifyGroupProperty Modify the name of a server group Modifies the name of a server group.
DeleteGroup Delete a server group Deletes a server group.
DeleteTagWithUuid Delete asset labels Deletes custom labels bound to assets.
ModifyLoginBaseConfig Modify basic logon security settings for a single asset Modifies the basic configuration of logon security settings for a single asset.
ModifyPushAllTask Send a security check task with one click Sends a security check task to asset servers with one click.
DescribeAssetDetailByUuid Query server asset details and extended information Queries the details and extended information of a server asset by UUID.
DescribeGroupedInstances Query Asset Statistics Query asset statistics by specified aggregation dimensions.
QueryGroupIdByGroupName Query asset group ID Queries the ID of an asset group by group name.
DescribeAssetSummary Query core count statistics information of protected assets Queries the core count statistics information of assets that are protected by Security Center.
DescribeAllEntity Query all server asset list information Retrieves the list of all server assets, including asset group IDs and asset names.
DescribeFieldStatistics Query server statistics information in assets Queries the statistics information of servers in your assets.
DescribeGroupedTags Query label statistics information Queries the statistics information of asset labels.
DescribeAllGroups Query server group information Queries information about all server groups.
DescribeInstanceStatistics Query server statistics information Queries the statistics information of server asset instances.
DescribeDomainCount Query domain name asset count Queries the number of your domain name assets.
DescribeDomainList Query domain name asset information Queries information about your domain name assets.
DescribeDomainDetail Query domain name asset details Queries the details of your domain name assets.
DescribeCloudCenterInstances Query asset information Queries asset information that meets specified search conditions. For example, you can search for assets by instance name or region. Two pagination methods are supported: page-based pagination and NextToken-based pagination. We recommend that you use NextToken-based pagination.
DescribeSearchCondition DescribeSearchCondition Queries the filter conditions that are used to search for assets.
DescribeCriteria DescribeCriteria Queries the filter conditions that are used to search for assets in fuzzy match mode.
DescribeAssetDetailByUuids Query asset details Queries the details of an asset (ECS instance).
DescribeImageStatistics Query risk statistics information of container image assets Queries the risk statistics information of container image assets.
DescribeContainerStatistics Query alert statistics of container assets Queries the alert statistics of container assets.
ModifyAssetGroup Modify an asset group Modifies an asset group.
DescribeSasPmAgentList Query O&M plug-in status list Queries the status list of O&M plug-ins.
ModifyAssetCleanConfig Modify offline host cleanup configuration Modifies the cleanup configuration for offline hosts. Only non-Alibaba Cloud hosts are supported.
AddCloudVendorAccountAK AddCloudVendorAccountAK Adds the configuration information of multi-cloud assets.
DeleteCloudVendorAccountAK DeleteCloudVendorAccountAK Delete multi-cloud asset synchronization configuration.
DescribeCloudVendorAccountAKList DescribeCloudVendorAccountAKList Queries the multi-cloud assets added to Security Center.
ModifyCloudVendorAccountAK Modify multi-cloud asset authorization configuration Modifies the authorization and authentication configuration of multi-cloud assets.
AddCloudVendorTrialConfig AddCloudVendorTrialConfig Adds configurations of connecting the audit logs of a third-party cloud asset.
SetSyncRefreshRegion Set asset refresh and sync region list Sets the region list for asset refresh and synchronization.
GetSupportedModules Retrieve module information supported by multi-cloud vendors Retrieves the list of modules supported for authorization.

Asset management

API

Title

Description

DescribePropertyUsageTop Query asset fingerprints statistics by type Retrieves the top 5 statistics information for ports, processes, software, accounts, or middleware by occurrence count in your assets using the Asset Fingerprints feature.
DescribePropertyScaProcessDetail DescribePropertyScaProcessDetail Queries the Java processes that are collected by the asset fingerprints feature of Security Center in your assets.
GetAssetsPropertyItem Query asset fingerprints aggregated list Queries the aggregated list of Asset Fingerprints for startup items, kernel modules, or websites.
GetAssetsPropertyDetail Query asset fingerprints detail list Queries the details of Asset Fingerprints for startup items, kernel modules, or web sites.
DescribePropertyCronDetail Query Asset Fingerprint Investigation Task List Details Query Asset Fingerprint Scheduled Task Details
DescribePropertyCount DescribePropertyCount Queries the statistics of asset fingerprints. The assets include processes, ports, software, accounts, middleware, websites, web services, scheduled tasks, startup items, and databases.
DescribePropertyPortDetail Query Asset Fingerprint Information of Port Assets Query Details of Asset Fingerprint Port Collection
DescribePropertyProcDetail Query Asset Fingerprint of Process Assets Query Details of Asset Fingerprint Collection Process
DescribePropertyPortItem Retrieve all port information Retrieves information about all ports.
DescribePropertySoftwareDetail Retrieve detailed information of a software in the software list Query details of asset fingerprint software collection
DescribePropertyUserDetail Query account asset fingerprint information of a server Queries the Asset Fingerprints information of account assets on a server.
DescribeModuleConfig Retrieve asset fingerprints module settings Queries the settings of the Asset Fingerprints module.
DescribePropertyScaDetail Query middleware list details in asset fingerprints investigation Queries the details of the middleware list on the Asset Fingerprints investigation page.

Asset fingerprints

API

Title

Description

GetSecurityScoreRule Query custom security scoring rule details Queries the details of custom security scoring rules.
ChangeSecurityScoreRule ChangeSecurityScoreRule Modifies the details of the deduction modules of the security score feature, including custom settings.
DescribeSecureSuggestion Query Security Risk Handling Suggestions Details Query Security Risk Handling Suggestions Details

Security score

API

Title

Description

DescribeExposedInstanceCriteria Query conditions supported for querying exposed assets Retrieves the supported query conditions for querying exposed assets.
DescribeExposedInstanceList Query information about internet-exposed assets Queries information about assets exposed on the Internet.
DescribeExposedStatistics Query the statistics of asset exposure analysis Queries the statistics of asset exposure analysis.
DescribeExposedStatisticsDetail Details of exposed asset statistics Queries the list of gateway assets, ports, system components, or public IP addresses that are exposed on the Internet.

Exposed assets

API

Title

Description

ListUuidsByAppId Query serverless instance uUIDs by application ID Queries the list of Serverless instance UUIDs by application ID.
ListMachineApps Query SAE applications of a serverless instance Queries the Serverless Application Engine (SAE) applications of a serverless instance.
DescribeContainerTags DescribeContainerTags Retrieves the details of container assets by using an attribute.
DescribeAssetsSecurityEventSummary Query container asset risk statistics Queries risk statistics for container assets.
DescribeImage Query image digest Queries the digest of an image.
DescribeContainerCriteria Retrieve supported search criteria for the container list Retrieves the supported search criteria for the container list.
DescribeContainerInstances Retrieve container instance information list Retrieves the list of container instance information.
DescribeImageCriteria Retrieve image search criteria Retrieves image search criteria.
DescribeImageInstances Retrieve image information Retrieves a list of image information.
DescribeImageRepoDetailList Retrieve image repository list Retrieves a list of image repositories.
DescribeImageRepoCriteria Retrieve supported search criteria for image repositories Retrieves the supported search criteria for image repositories.
DescribeGroupedContainerInstances Query container list information Queries the list of containers based on the specified group type.
RefreshContainerAssets Refresh container asset data in the asset center Refreshes container asset data in the asset center.

Container management

API

Title

Description

DescribeClusterNetwork DescribeClusterNetwork Retrieves information about the network topology edge by cluster.
FindContainerNetworkConnect Query container network connectivity information Retrieves information about network connectivity between two nodes.

Container visualization

API

Title

Description

UpdateWhiteList Update the IP address whitelist of an image repository Updates the IP address whitelist of an image repository.
GetRegistryScanDayNum Query image security scan time range Queries the time range for image security scanning.
GetDockerhubImageRiskStatistic GetDockerhubImageRiskStatistic Queries the risk statistics of Docker Hub images.
ListImageRegistryExtra Query extra configuration information of an image repository Queries the extra configuration information of an image repository.
SetBuildRiskDefineRuleConfig Modify risk scan configuration for image build instructions Modifies the risk scan configuration for image build instructions.
ListPrivateRegistryType Query the number of image repositories of each type Queries the number of image repositories of each type.
ListPrivateRegistryList ListPrivateRegistryList Retrieves image repositories.
SaveImageBaselineStrategy SaveImageBaselineStrategy Creates or updates an image baseline strategy.
OperateImageBaselineWhitelist Manage image baseline whitelist Manages the whitelist of image baseline check items.
DescribeImageBaselineStrategy Query image baseline policy Queries the image baseline policy.
DescribeImageBaselineItemList Query baseline check items by image Queries the list of baseline check results by image.
DescribeImageBaselineDetail Query image baseline check result details Queries the details of baseline check results for image scanning.
DescribeImageBaselineCheckResult Query image baseline check results Queries the detection results of image security scans.
DescribeAllImageBaseline Retrieve all image baseline check items Retrieves the list of all image baseline check items.
DescribeImageListBySensitiveFile Query images with sensitive files Queries information about images affected by sensitive files.
OpenSensitiveFileScan Edit sensitive file scan switch Modifies the sensitive file scan switch.
DescribeImageSensitiveFileList Query sensitive files Queries sensitive file information.
DescribeImageSensitiveFileByKey Query sensitive files of an image Queries the sensitive files of an image.
DescribeAffectedMaliciousFileImages Query malicious file details in container images Queries the details of malicious files detected in container images.
DescribeGroupedMaliciousFiles Query malicious sample files in container images Queries the list of malicious sample files in container images.
DescribeImageVulList View container image vulnerability list Queries the details of vulnerabilities detected by image security scans and the list of container images affected by the vulnerabilities.
DescribeImageGroupedVulList Query image vulnerability information Queries the list of image vulnerabilities.
DescribeImageListWithBaselineName Query image baseline check result details Queries the details of image baseline check results.
DescribeImageFixTask Query the list of created image repair tasks Queries the list of created image repair tasks.
DescribeImageScanAuthCount Query image security scan authorization information Queries the authorization quota information for image security scanning.
DescribeImageBaselineCheckSummary Query image baseline check list for image security scans Queries the image baseline check list of image security scans.
PublicCreateImageScanTask Create an image scan task Creates an image scan task that is not limited by a single primary task.
DescribeCountScannedImage Query scanned image statistics Queries statistics on scanned image data.

Image security scan

API

Title

Description

CreateCheckPolicy Create Custom Check Policy Category Create Policy
CreateCheckItem Create Custom Check Item User creates a custom check item
DeleteCheckItem Delete custom check items Deletes user-defined check items in the Cloud Security Posture Management (CSPM) custom check item feature.
ListCheckItems Query Custom Check Items List custom check items for situational awareness
UpdateCheckPolicy Modify Custom Check Item Policy Classification Settings Update Custom Policy
GetCheckSale Retrieve cloud service configuration check sales information Retrieves the sales information of cloud service configuration check, including the number of authorized quotas and consumed quotas.
ModifyCheckRule Modify CSPM check rules Modifies the rule settings of Cloud Security Posture Management (CSPM).
VerifyCheckInstanceResult Verifies the instance dimensions under a check item Verifies the instance dimensions under a check item.
VerifyCheckResult Check item-level validation Performs check item-level validation.
RemoveCheckResultWhiteList RemoveCheckResultWhiteList Removes the check items of the configuration assessment feature from the whitelist.
AddCheckResultWhiteList AddCheckResultWhiteList Adds the check items of the configuration assessment feature to the whitelist.
RemoveCheckInstanceResultWhiteList Remove whitelist status at the instance dimension Removes the whitelist status at the instance dimension.
GetCheckSummary Retrieve cloud platform configuration check overview Retrieves the overview of cloud platform configuration checks.
ListInstanceCatalog ListInstanceCatalog Queries the asset types and asset subtypes for configuration assessment.
SubmitCheck Submit a cloud service configuration check Submits a cloud service configuration check.
ChangeCheckConfig Modify cloud platform configuration check items Modifies the check items for cloud platform configuration checks.
GetCheckConfig Retrieve check item configurations for cloud platform configuration checks Retrieves the check item configurations for cloud platform configuration checks.
GetCheckCountStatistic GetCheckCountStatistic Queries statistics on the number of risk items in cloud security posture management (CSPM) for cloud services.
ListCheckInstanceResult ListCheckInstanceResult Queries the instances that failed a specified check item of configuration assessment.
ListCheckResult ListCheckResult Retrieves the details of the risk items that are detected in the configuration checks on cloud services.
ListCheckStandard ListCheckStandard Queries the standards of configuration checks.
ListCheckItem ListCheckItem Queries the check items that can be customized.
StartBaselineSecurityCheck StartBaselineSecurityCheck Checks cloud service configurations. You can check all items or a specific item and verify whether an item is checked.
DescribeRiskItemType Query the types of all cloud service configuration check items Queries the types of all cloud service configuration check items.
DescribeRiskCheckSummary Query cloud service configuration check result summary Queries the summary of cloud service configuration check results, including the number of risk items, risk rate, number of affected assets, check time, and statistics by type.
DescribeRiskCheckResult DescribeRiskCheckResult Queries the check results of cloud service configurations by check item type or name.
DescribeRiskCheckItemResult DescribeRiskCheckItemResult Queries the assets that are affected by the risk item detected in configuration assessment based on a specified check item.
ListCheckRule Query Cloud Security Posture Management Check Rules Display cloud product configuration check rules
ListOperationTask Query Cloud Security Posture Management Operation Tasks Display the list of cloud product configuration check, repair, and rollback tasks
VerifyCheckCustomConfig Validate threat detection service custom configuration Authenticates whether the configuration information entered by a user is compliant with the requirements of the corresponding parameter settings.
ListCheckPolicies Query Custom Check Item Policy Classification List User Policies
UpdateCheckItem Update Custom Check Item User creates a custom check item
DeleteCheckPolicy DeleteCheckPolicy Delete custom scope directories in Cloud Security Posture Management (CSPM) custom checks. You can remove assigned standards, requirements, or sections.

Cloud platform configuration check

API

Title

Description

DeleteBackupSnapshot Delete backup snapshots Deletes snapshots of anti-ransomware backups in Security Center.
QueryPreCheckDatabase Query database pre-check task result Queries the task result of a database dry run node.
ModifyUniBackupPolicy Update anti-ransomware policy for databases Modifies an anti-ransomware backup policy for databases.
DescribeUniBackupPolicyDetail Query anti-ransomware policy details for databases Queries the details of an anti-ransomware backup policy for databases.
CreateUniRestorePlan Create a database anti-ransomware restoration task Creates a database anti-ransomware restoration task.
DescribeBackupMachineStatus Query backup server status Queries the backup status of servers that are associated with an anti-ransomware backup policy.
UpgradeBackupPolicyVersion Upgrade anti-ransomware backup policy version Upgrades the version of an anti-ransomware backup policy.
DescribeExcludeSystemPath Query anti-ransomware system excluded directories Queries the excluded directories of the anti-ransomware system.
DescribeBackupClients Query servers with the anti-ransomware client installed in a specified region Queries servers that have the anti-ransomware client installed in a specified region.
DescribeBackupPolicies Query Backup Policy List Query anti-ransomware protection policies.
DescribeSupportRegion Query regions supported by anti-ransomware Queries the regions supported by anti-ransomware.
DescribeBackupRestoreCount Query anti-ransomware restoration tasks Queries data of anti-ransomware restoration tasks.
ModifyBackupPolicyStatus Enable or shutdown an anti-ransomware policy Enables or shuts down an anti-ransomware policy.
DeleteBackupPolicy Delete ransomware mitigation policies Deletes ransomware mitigation policies.

Tamper protection

API

Title

Description

ModifyWebLockDeleteConfig Delete a protected directory from a specified server Deletes a protected directory from a specified server.
ModifyWebLockCreateConfig Add a protected directory for a specified server Adds a protected directory for a specified server.
ModifyWebLockUpdateConfig Modify the protection policy of a specified server Modifies the protection policy of a specified server.
ModifyWebLockStart Create web tamper proofing protection for a server and enable the protection Creates web tamper proofing protection for a specified server and enables the protection.
ModifyWebLockStatus Modify web tamper-proofing status Enables or shuts down web tamper-proofing for a server.
ModifyWebLockUnbind Remove web tamper proofing from a server Removes the web tamper proofing protection folder from a specified server.
OperateWebLockFileEvents Handle web tamper-proofing alerting events Handles web tamper-proofing alerting events.
ModifyWebLockProcessStatus Set tamper-proofing process status Sets the status of a tamper-proofing process.
DescribeWebLockExclusiveFileType DescribeWebLockExclusiveFileType Queries the types of files that are excluded from web tamper proofing.

Virus detection

API

Title

Description

DescribeLatestScanTask Query latest virus scan Queries the progress of the most recent virus scan task.
CreateVirusScanOnceTask CreateVirusScanOnceTask Creates a one-time virus scan task that is immediately executed.
ListVirusScanMachine Query alert hosts for virus scanning Queries the list of alert hosts for virus scanning.
ListVirusScanMachineEvent Query alert events detected by server scan Queries virus alerts detected by a virus scan on a specific server.
ListVirusScanTask Query virus scan tasks Queries virus scan tasks that match specified conditions such as scan type, scan status, and scanned machine information.
GetVirusScanConfig Retrieve periodic virus scan configuration Retrieves the configuration of a periodic virus scan task.
OperateVirusEvents Handle virus defense alerts Handles virus defense alerts in batches. The handling types include deep scan and removal, adding to whitelist, ignoring, and manual handling.

Alerts

API

Title

Description

DescribeGraph4InvestigationOnline Query the investigation and tracing graph of alert events Queries the investigation and tracing graph of Cloud Workload Protection Platform (CWPP) alert events to visually investigate and reconstruct cyberattack processes.
DescribeSecurityEventMarkMissList Query alert whitelist rules Queries the auto-whitelist rules for security alerts.
DescribeBackUpExportInfo Retrieve security alert archive data export list Retrieves the list of exported security alert archive data.
ListUuidsByWebPath Query protected assets by web path Queries protected assets by web path.
DescribeNsasSuspEventType Query security alerting Alarm Metric Queries security alerting Alarm Metric.
UpdateStrictEventName Modify strict mode alert status Modifies the strict mode configuration, including whether to enable alerting in strict mode. This is a full-update operation.
CreateSuspEventNote Create a note for a security alert event Creates a note for a security alert event.
CreateSimilarSecurityEventsQueryTask Create a node to query alert events triggered by the same rule or Alarm Metric Creates a node to query alert events triggered by the same rule or Alarm Metric through alerting.
DescribeSuspEventDetail DescribeSuspEventDetail Queries the details of an exception. An alert event consists of an alert and exceptions. Each alert event is associated with multiple exceptions.
DescribeSimilarEventScenarios Query handling scenarios for alerts with the same trigger Queries the handling scenarios for alerts triggered by the same rule or type.
DescribeSecurityStatInfo Query statistics and trend data of security check items Queries the statistics of each security check item and the daily statistics in the security check item trend chart.
DescribeLoginBaseConfigs Query unusual logon detection rule configurations Queries the configuration of unusual logon detection rules for servers.
DescribeAttackAnalysisData DescribeAttackAnalysisData Queries the statistics of attack analysis.
OperationSuspEvents Handle alert events in batches Handles alert events in batches.

Anti-ransomware

API

Title

Description

ModifyCustomBlockRecord Modify custom rule for brute-force attacks IP blocking Modifies the rule record of a custom blocked IP address.
DeleteCustomBlockRecord Delete a custom IP blocking policy Deletes the blocking records of specific IP addresses that are custom-defined on one or more servers.
ModifyAntiBruteForceRule Modify a defense rule against brute-force attacks Modifies a defense rule against brute-force attacks.
ModifyInstanceAntiBruteForceRule Modify the anti-brute-force attacks rule for a specified server Modifies the anti-brute-force attacks rule for a specified server.
DescribeInstanceAntiBruteForceRules Query servers on which brute-force attacks defense rules take effect Queries information about servers on which brute-force attacks defense rules take effect.
DescribeAntiBruteForceRules Query brute-force attacks prevention rules Queries the brute-force attacks prevention rules that you have created.
DeleteAntiBruteForceRule Delete an anti-brute-force rule Deletes a specified anti-brute-force attacks rule.

Web tamper-proofing

API

Title

Description

ListVulGlobalConfig Query vulnerability global configuration Queries the global configuration of vulnerabilities.
OperateImageVul Operate on image vulnerabilities Performs operations on image vulnerabilities. Supported operation types include fix, verify, ignore, and unignore.
ModifyVulTarget Modify machine-level toggle settings for vulnerability scanning Modifies the machine-level toggle settings for vulnerability scanning.
ModifyVulConfig Modify vulnerability scanning switch configuration Modifies the vulnerability scanning switch configuration.
ModifyConcernNecessity Set the urgency levels of vulnerabilities that the user is concerned about Sets the urgency levels of vulnerabilities that the user is concerned about.
ModifyAutoDelConfig Set automatic deletion time for expired vulnerabilities Sets the automatic deletion time for expired vulnerabilities.
DescribeVulNumStatistics Get vulnerability statistics Get vulnerability statistics.
DescribeVulListPage DescribeVulListPage Queries the vulnerabilities that can be detected.
DescribeMachineCanReboot Query whether a server can be restarted Checks whether a server can be restarted when a vulnerability fix requires a restart to take effect.
DescribeEmgUserAgreement Query emergency vulnerability user agreement Queries the emergency vulnerability user authorization agreement.
DescribeClusterVulStatistics Query cluster vulnerability statistics Queries cluster vulnerability statistics.
DescribeAppVulScanCycle Query application vulnerability scanning epoch Queries the application vulnerability scanning epoch.
ListVulAutoRepairConfig Query auto-fix vulnerability configurations Queries the configurations of vulnerabilities that can be automatically fixed.
DescribeInstanceRebootStatus Query instance restart status Queries the restart status of instances.
RebootMachine Restart an instance Restarts an instance. Currently, only Windows instances are supported.
ModifyVulTargetConfig Configure vulnerability detection settings for a single server Configures the vulnerability detection settings for a single server.
ModifyStartVulScan Trigger one-click vulnerability scan Enables the one-click scan feature on the vulnerability management page of the console.
ModifyEmgVulSubmit Perform emergency vulnerability detection Performs emergency vulnerability detection.
ModifyCreateVulWhitelist ModifyCreateVulWhitelist Adds vulnerabilities to the whitelist. After you add the vulnerabilities to the whitelist, Security Center no longer generates alerts for the vulnerabilities.
GetVulWhitelist GetVulWhitelist Retrieves information about a vulnerability whitelist.
DeleteVulWhitelist Delete a specified vulnerability whitelist Deletes a specified vulnerability whitelist.
DescribeEmgVulItem Query emergency vulnerability information Queries the details of emergency vulnerabilities.
DescribeConcernNecessity Query necessity information for fixing followed vulnerabilities Queries the necessity information for fixing vulnerabilities that you follow.
DescribeVulWhitelist Query vulnerability whitelists by page Queries vulnerability whitelists by paging.
ExportVul ExportVul Export vulnerability list
DescribeVulExportInfo Query the progress of a vulnerability export task Queries the progress of a vulnerability export task.
GetVulStatistics GetVulStatistics Queries the statistics on vulnerabilities in asset groups.

Virus scan

API

Title

Description

ListBaselineCheckWhiteRecord Query baseline whitelist records Queries baseline whitelist records.
ListCheckItemWarningSummary ListCheckItemWarningSummary Queries the risk statistics of check items by page.
ListCheckItemWarningMachine Get Warning Machines for a Specific Baseline Check Item Query the list of warning machines for a specific baseline check item.
DescribeHcExportInfo Query baseline risk export information Queries information about a baseline risk export, such as the file name and download link.
DescribeRisks Query baseline details Queries baseline details by baseline ID or name.
DescribeCheckFixDetails Query check item fix details Queries the configurable parameters for fixing a specified check item.
IgnoreCheckItems IgnoreCheckItems Adds risk items to the whitelist or removes risk items from the whitelist by specifying servers and risk items.
DescribeExposedCheckWarning Query baseline weak password risks of exposed assets Queries the weak password risks of a specified exposed server.
DescribeCheckWarningSummary Query baseline check result statistics Queries the statistics of baseline check results, such as the number of servers checked, the number of check items, and the latest check pass rate.
DescribeCheckWarnings Query check item information Queries check item information for a specified risk item and a specified server.
DescribeCheckWarningDetail Query details of a specified check item Queries the details of a specified check item.
DescribeWarningMachines DescribeWarningMachines Queries information about servers on which a baseline check is performed. The information includes the IDs of the servers, the statistics of a risk item, and the status of the risk item.
DescribeCheckEcsWarnings Query the number of high-risk weak password risks Queries the number of high-risk weak password risks that exist in your assets.
DescribeStrategyDetail Retrieve baseline check policy details Retrieves the details of a baseline check policy.
ExportWarning ExportWarning Exports baseline check results.
DescribeStrategy DescribeStrategy Queries the details about baseline check policies.
DeleteStrategy Delete a policy Deletes a baseline check policy.
ValidateHcWarnings Batch verify baseline check risk items Verifies existing baseline risks. If the verification passes, the status of the risk items is updated to passed.
DescribeCustomizedStrategyTargets Query custom policy targets Queries the target machines included in a custom policy.
UpdateBaselineCheckWhiteRecord Update a baseline whitelist record Updates a baseline whitelist record.
DeleteCustomizedDict Delete a custom weak password Deletes a custom weak password file.
DescribeDefaultKeyInfo Query default key information Retrieves the keywords used to generate a custom dictionary in custom weak password detection.
CreateUserSetting Save user baseline check settings Saves the risk level settings for baseline checks of a user.
ExecStrategy Execute a baseline check policy Performs a baseline check on machines within a specified policy.

Security alert

API

Title

Description

ListSystemRuleAggregationTypes Query aggregation types of system rules Queries the aggregation types of system defense rules.
ListClientUserDefineRules ListClientUserDefineRules Queries custom defense rules.
ListSystemClientRuleTypes Query system rule types effective for a user Queries the system rule types.
ListSystemClientRules ListSystemClientRules Queries system defense rules.
ListSystemAggregationRules Retrieve details of system rule clusters Retrieves the details of system rule clusters.
ModifyClientUserDefineRule Modify a client custom rule Modifies a custom rule for malicious behavior defense.
ListClientUserDefineRuleTypes ListClientUserDefineRuleTypes Queries the supported types of custom defense rules.
GetClientUserDefineRule Get client user-defined rules Queries custom rules for malicious behavior defense.
DeleteClientUserDefineRule DeleteClientUserDefineRule Deletes specified custom defense rules.
AddClientUserDefineRule Add a custom rule Create a custom defense rule.

Brute-force attack prevention

API

Title

Description

ModifyAccessKeyLeakDeal Handle accessKey pair leak records Handles an AccessKey pair leak record.
DescribeAccesskeyLeakList Query leaked accessKey information Queries information about leaked AccessKey pairs in your assets.
DescribeAccessKeyLeakDetail Query accessKey pair leak event details Queries the details of an AccessKey pair leak event.

Vulnerability fix

API

Title

Description

GetHoneypotAttackStatistics Query attack event statistics information of a honeypot attack source Queries the attack event statistics information of a honeypot attack source.
UpdateHoneypotNode Update a honeypot management node Updates a specified honeypot management node.
GetHoneypotNode GetHoneypotNode Retrieves the details of a specified management node.
UpdateHoneypot Modify honeypot configuration Modifies the configuration of a specified honeypot.
ListHoneypot Query honeypot list Queries a list of honeypots.
UpdateHoneypotPreset Modify honeypot template configuration Modifies the configuration of a specified honeypot template.
UpdateHoneypotProbe Update probe properties Updates the properties of a specified probe.
ListHoneypotProbe Query honeypot probes Queries the list of honeypot probes.
DeleteHoneypotPreset Delete a honeypot template configuration Deletes a specified honeypot template configuration.
DeleteVpcHoneyPot Delete a honeypot Deletes a specified honeypot instance.
DescribeHoneyPotAuth Query the number of authorized honeypot instances Queries the number of authorized honeypot instances.
DescribeHoneyPotSuspStatistics Query top 5 vPCs or assets by security alert count Queries information about the top 5 VPCs or assets ranked by the number of security alerts.

Baseline check

API

Title

Description

ModifyLogMetaStatus Modify log analysis enabling status Modifies the enabling status of log analysis.
DescribeLogMeta Query security center log analysis configuration Queries the configuration information of log analysis in Security Center.
ModifyOpenLogShipper Activate simple log service Activates Simple Log Service.
DescribeLogstoreStorage Query log analysis storage capacity of security center Queries the log analysis storage capacity of Security Center.
ModifyClearLogstoreStorage Clear security center logs Clears the storage capacity space for log analysis.

Malicious behavior defense

API

Title

Description

ModifyNoticeConfig Modify notification configuration Modifies notification configuration information.
DescribeDingTalk Retrieve dingTalk notification list Retrieves the list of DingTalk notifications.
DescribeNoticeConfig DescribeNoticeConfig Queries notification settings.
DescribeDataSource Query data sources for dingTalk alert configurations Queries the data sources for DingTalk alert configurations. You can configure the scope of DingTalk alert notifications based on the data sources.

AK leak detection

API

Title

Description

DeleteAutoTagRules Delete an automatic asset tagging rule Deletes an automatic asset tagging rule. This operation is used with the system configuration, feature settings, multi-cloud configuration management, and asset management rule features of Security Center.
DeleteIdcProbe Delete an IDC probe Deletes an IDC probe that is created in the IDC probe feature of Security Center.
ModifyIdcProbe ModifyIdcProbe Updates the configurations of an IDC probe.
DescribeCommonTargetResultList Query configured assets of a switch Queries the configured asset information for a specific switch type.
OperateSuspiciousOverallConfig Set the global configuration for abnormal events Sets the global configuration for abnormal events.
DescribeCommonOverallConfig Master switch global configuration Queries the global configuration of the master switch.
OperateCommonTargetConfig Configure general switch for feature module Configures the general switch for a feature module by type, including image scanning, endpoint engine detection, container network visualization, and container escape prevention.

Honeypot

API

Title

Description

DescribeExportInfo View export progress Queries the progress of an export task.
ExportRecord ExportRecord Exports detection results from various Cloud Security Center features, such as Asset Center, cloud platform configuration check, image security scan, attack analysis, and AK leakage detection, to an Excel file.

Log analysis

API

Title

Description

GetFileDetectApiInvokeInfo GetFileDetectApiInvokeInfo Obtains the usage information of the malicious file detection SDK.
CreateFileDetect CreateFileDetect Submits a file to the cloud for detection.
GetFileDetectResult GetFileDetectResult Retrieves file detection results in batches using `HashKey` values.
ListCompressFileDetectResult ListCompressFileDetectResult Retrieves a list of file detection results from an archive.

Notification

API

Title

Description

ListOssScanConfig ListOssScanConfig Queries the configuration of an Object Storage Service (OSS) file detection policy.
GetObjectScanEvent GetObjectScanEvent Retrieves the details of an alert event that is generated for a malicious object.
ListObjectScanEvent Query malicious file alerts Queries the list of malicious file alerts.
GetOssBucketScanStatistic Retrieve OSS scan statistics Retrieves OSS scan statistics.
ListOssBucketScanInfo Query risk information list of buckets Queries the risk information list of buckets.
UpdateOssScanConfig Update scan policy configuration Updates the scan policy configuration for OSS file detection under the malicious file detection feature.
ListOssBucket Query bucket list Queries the list of buckets.
CreateOssScanConfig CreateOssScanConfig Creates a policy for detecting malicious Object Storage Service (OSS) objects by using the SDK for malicious file detection feature.
ListSupportObjectSuffix Query supported file type suffixes Queries the supported file type suffixes.
RefreshOssBucketScanInfo Refresh bucket list Refreshes the bucket list.
GetOssScanConfig Retrieve scan policy configuration Retrieves the scan policy configuration.

Feature settings

API

Title

Description

GenerateOnceTask GenerateOnceTask Creates a one-time scan task.
DeleteCycleTask Delete a general scan plan task Deletes an epoch-based scan node, including image scans, emergency vulnerability scanning, and virus scans.
ModifyCycleTask Modify scheduled task cycle Modifies the run epoch of periodic nodes, including image scan, emergency vulnerability scanning, and virus scan nodes.
DescribeOnceTask Query client tasks Queries a list of client tasks.
DescribeCycleTaskList Query general-purpose scheduled task list Queries the list of general-purpose scheduled nodes, including image scan, emergency vulnerability scanning, and virus scan nodes.
GetOnceTaskResultInfo GetOnceTaskResultInfo Queries the execution results of a one-time scan task, such as an asset fingerprint collection task, a vulnerability scan, or an image security scan.
GetLastOnceTaskInfo GetLastOnceTaskInfo Retrieves runtime information for the latest scan task to check its completion status.
DescribeOnceTaskLeafRecordPage Retrieve subtask information of a one-time task Retrieves the details of subtasks for a one-time scan task result, including image scanning and image asset synchronization.

Export detection results

API

Title

Description

UpdateSelectionKeyByType Update the key for an asset selection type Modifies the key that corresponds to a specified type.

Service-linked role

API

Title

Description

CreateSoarStrategyTask Create a policy task Creates a task under My Policies in Task Center.
DeleteSoarStrategyTask Delete a task center task Deletes a policy task that is in the waiting state from the task center.
DescribeSoarStrategyTaskDetail Query policy task details in the task center Queries the details of a policy task in the task center, including the task execution status and the corresponding flowchart.
ModifySoarStrategySubscribe Add or remove a policy template to or from my policies Adds or removes a policy template to or from My Policies in the task center.
DescribeSoarSubscribedStrategy Query custom policies in the task center Queries the list of custom policies created in the task center of Security Center.
DescribeSyncAssetTaskLogDetail Query asset synchronization task details Queries the details of IDC scan tasks for asset synchronization.
DescribeSoarStrategyTaskParams Query policy task parameters in the task center Queries the parameters of a policy task in the task center.
ProcessSoarStrategyTask Execute a policy task in the task center Executes a policy task in the task center.
DescribeSoarStrategyTaskResult Query policy task execution results Queries the execution results of a policy task in the task center.

Malicious file detection SDK

API

Title

Description

DescribeDomainSecureVulList Query vulnerability list in a website security report Queries the vulnerability list in a website security report.
DescribeDomainSecureRiskList Query risky websites in website security report Queries websites with risks and their associated security information from the website security report, including the number of vulnerabilities and alerts.
DescribeDomainSecureAlarmList Query security alert data from a website security report Queries security alert data from a website security report.
DescribeDomainSecureStatistics Query website security report statistics Queries the statistics of a website security report, including the number of websites and security events.
DescribeDomainSecureScore Query the security score of a website security report Queries the security score of a website security report. The maximum score is 100.

Malicious file detection OSS

API

Title

Description

GetAuthSummary Retrieve authorization statistics Retrieves authorization statistics.
DescribeVersionConfig Query edition details of a purchased security center instance Queries the edition details of a purchased Security Center instance.
ModifyPostPayModuleSwitch Modify pay-as-you-go feature status Enables or disables pay-as-you-go billing for a specified feature.
UpdatePostPaidBindRel Change Pay-As-You-Go Service Protection Version Change Postpaid Asset Authorization Version
BindAuthToMachine Bind authorization to servers Binds authorization information to servers.

Task management

API

Title

Description

DescribeClusterBasicInfo Query cluster information by cluster ID Queries cluster information by cluster ID.
DescribeQuaraFileDownloadInfo Query download link for a quarantined file Queries the download information of a quarantined file for a security alert.
DescribeAffectedAssets Query affected assets Queries the list of affected assets from virus defense check results.
DescribeEventOnStage Query platforms supported by threat detection Queries the platforms supported by threat detection.
DescribeTraceInfoDetail Query tracing information Queries the tracing information of a security alert.
DescribeImageLatestScanTask Query the most recent scan status of an image Queries the most recent scan task for an image.
DescribeImageRepoList Retrieve image defense switch configuration statistics information Retrieves statistics information on image defense switch configurations.
PageImageRegistry Query image repositories by page Queries a list of image repositories.
QueryJenkinsImageRegistryPersistenceDay Query jenkins image repository image retention duration Queries the image retention duration of a Jenkins image repository.
UpdateJenkinsImageRegistryName Modify jenkins image repository image name Modifies the image name in a Jenkins image repository.
UpdateJenkinsImageRegistryPersistenceDay Modify jenkins image repository image retention period Modifies the image retention period for a Jenkins image repository.
DeleteInterceptionRule Delete an interception rule Deletes a microsegmentation interception rule.
DeleteInterceptionTarget Delete interception targets Deletes active network objects from the container firewall.
DescribeCustomBlockRecords Query custom interception policies Queries brute-force attacks interception records for custom blocked IP addresses defined on one or more servers.
ListInterceptionHistory Query container firewall interception records Queries container firewall interception records.
GetInterceptionRuleDetail GetInterceptionRuleDetail Retrieves the details of a microsegmentation defense rule.
ListImageRegistryRegion Query regions that support private image registry access Queries the regions that support private image registry access.
DeletePrivateRegistry Delete a private repository Deletes a private image repository by image repository ID.
ListPodRisk Retrieve security risks of pod groups Retrieves the security risks of pod groups.
ListImageRisk Retrieve security information of container images Retrieves the security information of container images.
DeleteServiceTrail Delete actionTrail data delivery Deletes an ActionTrail data delivery configuration.
CreateServiceTrail Create actionTrail data delivery Creates a service trail.
DescribeMonitorAccounts DescribeMonitorAccounts Queries the list of accounts that are added to the multi-account management feature as members.
DescribeImageVulWhiteList Query image vulnerability whitelist Queries the image vulnerability whitelist.
QueryAttackCount Query security alert counts by attack phase Queries the number of security alert events that occurred in each attack phase.
GetSwitchRegionDetail Query service switchover progress Queries the progress of a service switchover. For example, when a server connection is being migrated from China to Singapore, this operation retrieves the migration progress and status.
UpdateImageVulWhitelistTarget Update an image vulnerability whitelist Updates an image vulnerability whitelist.
DeleteImageVulWhitelist Delete image vulnerability whitelist Deletes an image vulnerability whitelist.
DescribeContainerScanConfig Query container runtime scan configuration Queries the container runtime scan configuration.
ModifyContainerScanConfig Modify container runtime scan configuration Modifies the container runtime scan configuration.
DescribeCanFixVulList Query fixable vulnerabilities Queries the list of fixable vulnerabilities.
ModifyImageFixCycleConfig ModifyImageFixCycleConfig Updates the configurations of a scheduled image fix.
DescribeImageFixCycleConfig Query scheduled image fix configuration Queries the scheduled image fix configuration.
ListHoneypotProbeUuid Query probe iDs by probe type and node ID Queries probe IDs by probe type and node ID.
UpdateHoneypotProbeBind Modify a probe service Modifies a probe service.
ListHoneypotEvents List honeypot attack events Retrieves intrusion events of a honeypot.
ListHoneypotAttackerPortrait ListHoneypotAttackerPortrait Queries the attacker profile based on the source IP address of the attack.
ListHoneypotAttackerSource ListHoneypotAttackerSource Queries the attack source IP addresses that are used to attack a honeypot.
UpdateCommonSwitchConfig UpdateCommonSwitchConfig Updates the settings of common switches.
UpdateFileUploadLimit Modify the QPS upper limit for client file uploads Modifies the QPS for client file uploads.
GetFileDetectReport GetFileDetectReport Queries the cloud sandbox check results of malicious files.
DescribeImageEventOperationPage Query alerting handling rules by paging Queries alerting handling rules by using paging.
DescribeImageEventOperationCondition Query conditions for handling image events Queries the conditions for handling image events.
UpdateImageEventOperation Update an alert handling rule Updates an alert handling rule.
DeleteImageEventOperation Delete an alert disposal rule Deletes an alert disposal rule.
ListGroups Retrieve server group list Retrieves the list of server groups for the current user.
UploadedHoneyPotFile Upload a honeypot file and create a confirmed record Creates and confirms a record after a honeypot file is uploaded.
ListHoneypotEventFlows Retrieve honeypot attack event timeline Retrieves the details of a honeypot attack event.
ModifyImageRegistry ModifyImageRegistry Modifies the configuration of an image registry.
DeleteK8sAccessInfo Delete kubernetes access information Deletes Kubernetes access information.
DeleteContainerPluginRule Delete a container escape prevention rule Deletes a container escape prevention rule.
ModifyContainerPluginRule Modify a container escape prevention rule Modifies a container escape prevention rule.
DeleteSasContainerWebDefenseRule Delete a container tamper-proofing rule Deletes a container tamper-proofing rule.
ListK8sAccessInfo List k8s access information Lists K8s access information.
GenerateK8sAccessInfo Generate commands for connecting self-built Kubernetes clusters Generate commands for connecting self-built Kubernetes clusters.
MarkMonitorAccounts Tag member accounts in multi-account management Tags member accounts in multi-account management. Tags selected member accounts as accounts of interest. Accounts of interest are displayed at the top of the drop-down list above the left-side navigation pane in the Security Center console.
UnMarkMonitorAccounts UnMarkMonitorAccounts Cancel marking for members. Remove followed members from the list. In the Security Center console, the drop-down list above the left-side navigation pane no longer displays the members.
ListUnfinishedOnceTask Query incomplete tasks Queries the list of incomplete tasks by task type.
DeleteVulAutoRepairConfig Delete automatic fix configurations from the vulnerability task center Deletes the configurations of vulnerabilities that can be automatically fixed in the vulnerability task center in batches.
DescribeFixUsedCount Query the number of vulnerability fixes used by a pay-as-you-go user Queries the number of vulnerability fixes used by a pay-as-you-go user.
DeleteAttestor Delete an attestor Deletes an attestor.
DescribeClusterHostSecuritySummary Query host security statistics Queries the security statistics of a host.
DescribeClusterImageSecuritySummary Query image security statistics Queries the security statistics of container images.
DescribeCustomizedDictUploadInfo View OSS details of custom weak password upload Queries the information about the OSS bucket that stores custom weak password files.
CreateCustomizedDict CreateCustomizedDict Creates custom weak password rules.
DescribeContainerServiceK8sClusterKritisStatus Query the kritis status of an ACK cluster Queries the Kritis status of a Container Service for Kubernetes (ACK) cluster.
UpgradeHoneypotNode Upgrade honeypot management node version Upgrades the version of a specified honeypot management node.
QueryGuidTaskList Query beginner task information Security Center provides rewards such as value-added service authorization quotas and log analysis storage capacity to users who complete tasks. Queries the completion status and reward information of configuration tasks.
ReceiveFunctionTrialRewardByAliUid Start cloud honeypot or malicious file detection SDK trial Claims a trial reward for the cloud honeypot or malicious file detection SDK feature after completing a task.
DescribeAgentlessSensitiveFileByKey Query sensitive file alerts by type Retrieves the list of assets that contain a specific type of sensitive file detected by the agentless detection feature.
GetCheckStructure Get cloud platform configuration check item structure Queries the directory structure of the check item list.
DescribeDynamicDictUploadInfo Query OSS upload details of dynamic weak passwords Queries the OSS upload details of user-defined dynamic weak passwords for baseline checks.
DeleteCustomizeReport Delete a custom security report Deletes a specified custom security report.
DescribeCustomizeReportConfigDetail Retrieve report delivery configuration details Retrieves the details of a report delivery configuration.
DescribeDynamicDict Query dynamic weak passwords Queries the user-defined dynamic weak password rules for baseline checks.
DescribeIdcProbeScanResultList Query IDC probe scan results Retrieves the list of assets discovered by IDC probes.
DescribeSupervisonInfo Query latest system vulnerability discovery time Queries the latest system vulnerability discovery time.
GetDefenceCount Query security protection statistics Queries the number of alerting events handled by accurate access control and web tamper-proofing.
OperationCustomizeReportChart Modify security report statistical charts Modifies the statistical charts of a security report.
SaveCustomizeReportConfig SaveCustomizeReportConfig Saves the configurations of a custom security report.
SendCustomizeReport Send a security report Sends a security daily report to a specified email address. Only security reports with a custom time period as the report cycle are supported.
UpdateCustomizeReportStatus Modify security report status Modifies the status of a security report.
ListLogShipperRegions Query regions supported for log delivery in pay-as-you-go mode Queries the regions supported for log delivery in pay-as-you-go mode.
UpdateTargetListByBatch Update machines in a batch Updates the machines included in a batch.
DescribeScreenScoreThread Query security dashboard score trend Queries the security score trend on the security dashboard.
DescribeChartData Query security daily report chart statistics Queries the statistics of charts configured in a security report.
OpenBackupAutoConfig Enable anti-ransomware managed service configuration Enables the anti-ransomware managed service to configure server backup policies with one click. This operation can be called only after you purchase the anti-ransomware managed service.
GetAegisContainerPluginRule Query container escape prevention rule details Queries the details of a container escape prevention rule.
SubmitOperationTask SubmitOperationTask Submits a repair task of risk items detected in configuration assessment or rolls back a repair task that is executed.
CheckTrialFixCount CheckTrialFixCount Checks whether the remaining quota of the vulnerability fixing feature is sufficient for a free trial user of Security Center and queries the quota usage required for the current fix operation.
CreateMonitorAccount CreateMonitorAccount Creates a list of members of the account monitored by Security Center type by using the multi-account management feature.
DeleteMonitorAccount Delete a security center monitoring account from multi-account security management Deletes a Security Center monitoring account from the multi-account security management feature.
ListAccountsInResourceDirectory Query member accounts in a resource directory Retrieves the list of managed accounts for multi-account governance.
CreateRdDefaultSyncList Create an automatic control policy for new accounts in multi-account security management Creates an automatic control policy for new accounts in the multi-account security management feature of Security Center. Member accounts under the automatic control policy folder are automatically added to the monitoring account list.
DescribeIdcAssetCriteria IDC probe scan asset search conditions Queries the fuzzy match search conditions for asset properties that can be displayed when you query IDC assets discovered by scanning.
DescribeImageListByBuildRisk Query affected images by build risk with paging Queries affected images by build risk with paging.
DescribeImageBuildRiskList Query image build risk summary by page Queries the summary of image build risks by using paging.
DescribeImageBuildRiskByKey Query image build risks by page Queries the build risks of images by paging.
DescribeNeedAsyncQuery DescribeNeedAsyncQuery Queries whether slow queries need to be optimized.
ListPrivateK8s Retrieve private kubernetes cluster information Retrieves information about self-managed Kubernetes clusters that are connected to Security Center.
DescribeCheckWarningCount DescribeCheckWarningCount Queries the number of alerts that are triggered by a check item.
GetCurrentVersionPublish Retrieve version release information Retrieves the release information of the current client version.
DescribeInstanceVulStatistics Query vulnerability risk statistics for serverless asset instances Queries vulnerability statistics for a cluster.
SetImageBuildRiskStatus Set image build risk status Sets the risk status of image builds.
ListOperationProcessDetail Query operation task subtasks Queries the subtask list of an operation task.
ListOperationProcess Query operation tasks Queries a list of operation tasks.
DescribeDomainSecureSuggests Query security suggestions in a website security report Queries the security suggestions in a website security report.
DescribeIdcProbeList Query IDC probe list for asset discovery Retrieves the list of IDC probe instances used for asset discovery in the multi-cloud configuration management feature.
DescribeImageRiskLevelStatistic Query image risk statistics Queries the number of images that have security risk alerts, including vulnerabilities, baselines, and malicious sample risks.
DescribeImageSecurityScanCount Retrieve image security event count Retrieves the number of image security events.
GetDockerhubImageRiskRankInfo Query image rankings by dimension Queries the rankings of images by various dimensions.
ListDockerhubImage Query docker hub images Queries the risk overview of official Docker Hub images.
ListUserVpc Retrieve VPC data by region Retrieves VPC data for the user in a specified region by using the third-party image repository integration feature of Container Asset in Security Center.
ListTargetByBatch Query targets by batch Queries the list of publish target information for a specified batch.
GetInstanceAlarmStatistics Get Server Alarm Statistics Count the number of security events for a single instance
GrantSwitchAgreement Grant authorization for feature migration Grants authorization for feature migration.
ModifyServerlessAuthToMachine Manage serverless asset authorization Manages Serverless asset authorization.
ModifyBinarySecurityPolicy Modify container image signing security policy Modifies a container image signing security policy.
DeleteAttackPathWhitelist Delete an attack path whitelist entry Deletes an attack path whitelist entry.
ListSupportAttackPathAsset Query cloud service asset types supported by attack path analysis Queries the cloud service asset types supported by attack path analysis.
UpdateAttackPathSensitiveAssetConfig Update attack path sensitive asset settings Updates the sensitive asset configuration for attack path analysis.
GetAttackPathEventDetail Query attack path event details Queries the details of an attack path event.
InstallAegisForLingjun Install Security Center agent on Lingjun bare metal servers Installs the Security Center agent on Lingjun bare metal servers.
ListAegisForLingjunStatus Query the Aegis Client Installation Result for Lingjun Bare Metal Query the Aegis client installation result for Lingjun bare metal.
DescribeAIAssetSummary DescribeAIAssetSummary Queries the overview of user AI assets.
DescribePluginSummary DescribePluginSummary Queries statistics on the client plug-in installation status.
DescribeCustomizedDict Query custom weak passwords Queries the upload result of a custom weak password file.
ListUniBackupRecord List Database Backup Records List Database Backup Records
HandleSimilarMaliciousFiles Batch process malicious sample alerts Batch processes malicious sample alerts.
GenerateClusterScannerWebhookYaml Generate Cluster Scanner Component Access Configuration Generate K8s cluster scan access configuration.
DescribeClusterScannerList View cluster scanner list Queries the scanner status information for a Kubernetes cluster.
GetClusterScannerYaml View cluster scan component access configuration Queries the scan access configuration of a Kubernetes cluster.
GetAgentlessTaskUsedSizeEstimate Retrieve estimated scan volume for agentless detection Retrieves the estimated scan volume for agentless detection.
ListCloudAssetMatchOperators Get cloud asset data operator list Gets the list of cloud product configuration rule operators.
ListCloudAssetSchemas Get the list of asset structure definitions. Get the list of cloud product asset structure
UpdateMultiUserInstances Authorization Allocation Management Modify Multi-Account Instance Configuration
GetInstanceAuthRange Get Instance Authorization Value Range Get Instance Authorization Value Range
ListMultiUserInstances Query Multi-Account Authorization Allocation List Query Multi-Account Authorization Allocation List
DescribeCloudVendorProductTemplateConfig Query Agentic SOC Supported Cloud Vendor Product Access Template Configuration Get the cloud product access template for vendors
GetValidDeductInstances Get Valid Resource Package Instances Get Valid Resource Package Instances
ListAttackEventInfo Retrieve the list of attack analysis events Retrieve the list of attack analysis events
GetAttackEventDetail Retrieve attack analysis event details Retrieves the details of an attack analysis event.
GetAttackEventDashboard Retrieve attack analysis dashboard information Retrieves attack analysis dashboard information.
DescribeSuspiciousSecurityEventyStatistics Query Alarm Security Event Statistics Query Alarm Security Event Statistics
ListClusterCheckResult Query Cluster Check Item Scan Results Query Cluster Check Item Scan Results
GetClusterCheckSummary Query cluster check item risk count Queries the risk statistics of check items for a cluster.
ListKspmInstances Query kubernetes assets Queries Kubernetes asset information.
AddFileProtectBindMachine Add tamper-proofing server Creates a file protection rule.
CreateFileProtectClientRule Create a tamper-proofing rule Creates a file protection rule.
DeleteFileProtectClientRule Delete a tamper-proofing rule Deletes a file protection rule.
DescribeFrontVulPatchList Query prerequisite patches for a specified windows system vulnerability Queries the list of prerequisite patches that must be installed for a specified Windows system vulnerability.
DescribeGroupedVul Query vulnerability information by group Queries vulnerability information by group.
DescribeScanTaskProgress Query virus scan task progress Queries the progress of a virus scan task.
DescribeSnapshots DescribeSnapshots Queries the backup snapshots that are created for anti-ransomware.
DescribeSuspEvents DescribeSuspEvents Queries a list of alert events that are generated without aggregation.
DescribeVulDetails Query vulnerability details Queries vulnerability details.
DescribeVulList DescribeVulList Queries vulnerabilities by type.
GetFileProtectClientEvent Get tamper-proofing alert event details Retrieves the details of a file protection event.
GetFileProtectClientEventDashboard Retrieve statistics on tamper-proofing events Retrieves the dashboard data of file tamper-proofing events.
GetFileProtectClientRule Retrieve file tamper-proofing rule details Retrieves the details of a file protection rule.
GetFileProtectClientRuleDashboard Retrieve web tamper-proofing overview information Retrieves the overview dashboard of file protection rules.
HandleObjectScanEvent Handle malicious file detection alerts Handles malicious file detection alerts.
ListFileProtectBindMachine Retrieve the list of servers associated with file tamper-proofing Retrieves the list of servers associated with tamper-proofing.
ListFileProtectClientEvent Retrieve web tamper-proofing event list Retrieves the list of file protection events.
ListFileProtectClientRule Retrieve web tamper-proofing rules Retrieves a list of file protection rules.
ListFileProtectClientRuleFileType Retrieve file types for web tamper-proofing Retrieves all file types for file protection rules.
OperateVuls Fix a Linux software vulnerability Fixes a Linux software vulnerability.
UpdateFileProtectClientEvent Update a web tamper-proofing protection event Updates the status of a file protection event.
UpdateFileProtectClientRule Modify a web tamper-proofing rule Updates a file protection rule.
UpdateFileProtectClientRuleStatus Update tamper-proofing rule status Updates the status of file tamper-proofing rules in batches.
CreateServiceLinkedRole Create a service-linked role and grant security center access to cloud resources Creates a service-linked role and grants Security Center access to cloud resources.
DescribeBackupPolicy Query anti-ransomware protection policy details for servers Queries the details of an anti-ransomware protection policy for servers.
ModifyBackupPolicy Modify an anti-ransomware policy Modifies an anti-ransomware mitigation policy.

Asset selection

API

Title

Description

AddAssetSelectionCriteria AddAssetSelectionCriteria Select an operation for assets.
AddBaselineCheckWhiteRecord AddBaselineCheckWhiteRecord Creates a whitelist rule for a baseline check item.
AddCheckInstanceResultWhiteList AddCheckInstanceResultWhiteList Adds instances on which risks are detected based on check items of the configuration assessment feature to a whitelist.
AddContainerDefenseRule AddContainerDefenseRule Creates a rule for non-image program defense.
AddContainerPluginRule AddContainerPluginRule Creates a defense rule against container escapes.
AddIdcProbe AddIdcProbe Creates an IDC probe to add assets in a data center to Security Center and manage the assets by using the Security Center console.
AddImageEventOperation AddImageEventOperation Creates an alert handling rule.
AddImageVulWhiteList AddImageVulWhiteList Adds image vulnerabilities to the whitelist.
AddInstallCode AddInstallCode Creates a command that is used to install the Security Center agent.
AddPrivateRegistry AddPrivateRegistry Adds a self-managed image repository.
AddProtectVpcList Add or Update the Whitelist for VPC Purchases Add or update the whitelist for VPC purchases
AddPublishBatch AddPublishBatch Upgrades the Security Center agent in batches.
AddSasContainerWebDefenseRule AddSasContainerWebDefenseRule Creates a rule for container tamper-proofing.
AddSasModuleTrial AddSasModuleTrial Enables the trial use of Security Center value-added features, including vulnerability fixing and threat analysis and response.
AddTagWithUuid AddTagWithUuid Adds a tag to assets.
AddUninstallClientsByUuids AddUninstallClientsByUuids Adds servers from which you want to uninstall the Security Center agent.
AddVpcHoneyPot AddVpcHoneyPot Creates a honeypot.
AdvanceSecurityEventOperations AdvanceSecurityEventOperations Queries the configurations of an advanced whitelist rule.
BatchCreateMaliciousNote BatchCreateMaliciousNote Adds alert description in batches.
BatchDeleteMaliciousFileWhitelistConfig BatchDeleteMaliciousFileWhitelistConfig Deletes whitelist rules for alerts generated for sensitive files that are detected by using the agentless detection feature in batches.
BatchOperateCommonOverallConfig BatchOperateCommonOverallConfig Enables or disables multiple features in proactive defense at a time.
BatchUpdateMaliciousFileWhitelistConfig BatchUpdateMaliciousFileWhitelistConfig Modifies multiple alert whitelist rules of sensitive files that are detected by using the agentless detection feature at a time.
BindHybridProxy BindHybridProxy Adds servers to Security Center over a proxy server. After you create a proxy cluster and deploy a proxy server, you can connect a server to the proxy cluster as a client. This way, the server is added to Security Center over the proxy server and is protected.
CancelOnceTask CancelOnceTask Cancels the main task.
ChangeAssetRefreshTaskConfig ChangeAssetRefreshTaskConfig Modifies the interval of asset synchronization configurations.
ChangeCheckCustomConfig ChangeCheckCustomConfig Modifies the custom configuration items of a check item.
ChangeCheckScopeConfigInstance Modify check scope configuration instance Modifies the configuration instance of a check scope.
ChangeUserLang ChangeUserLang Modifies the language settings of log analysis. The modification on the language settings takes effect within 12 hours and affects only the language of the descriptions for security events in security logs.
CheckSecurityEventId CheckSecurityEventId Checks whether one or more alerts are generated on a specified server based on alert IDs.
CheckStsTokenAuth CheckStsTokenAuth Checks a Security Token Service (STS) token and returns the ID of the Alibaba Cloud account.
CheckUserHasEcs CheckUserHasEcs Checks whether Elastic Compute Service (ECS) instances exist.
ConfirmVirusEvents ConfirmVirusEvents Confirms the alert events that you want to handle.
CopyCustomizeReportConfig CopyCustomizeReportConfig Clones an existing security report. The new security report has the same configuration as the existing security report.
CreateAgentlessScanTask CreateAgentlessScanTask Creates an agentless detection task.
CreateAntiBruteForceRule CreateAntiBruteForceRule Creates a defense rule against brute-force attacks.
CreateAssetSelectionConfig CreateAssetSelectionConfig Create asset selection configurations.
CreateAttackPathSensitiveAssetConfig Create Attack Path Sensitive Asset Settings Create attack path sensitive asset configuration.
CreateAttackPathWhitelist CreateAttackPathWhitelist Create Attack Path Whitelist.
CreateAttestor CreateAttestor Creates a witness.
CreateBackupPolicy CreateBackupPolicy Creates an anti-ransomware policy for servers.
CreateBatchUploadUrl CreateBatchUploadUrl Queries the parameters that are required to upload a file for detection.
CreateBinarySecurityPolicy CreateBinarySecurityPolicy Creates a binary security policy.
CreateContainerScanTask CreateContainerScanTask Creates a container scan task.
CreateContainerScanTaskByAppName CreateContainerScanTaskByAppName Creates a scan task for a running container application based on the application name.
CreateCustomBlockRecord CreateCustomBlockRecord Creates an IP address blocking policy for one or more servers.
CreateCycleTask CreateCycleTask Creates a periodic scan task. The task can be an image scan task, urgent vulnerability scan task, or virus scan task.
CreateDynamicDict CreateDynamicDict Creates a dynamic dictionary of weak passwords.
CreateFileDetectUploadUrl CreateFileDetectUploadUrl Queries the parameters that are required to upload a file for detection.
CreateFileProtectRule CreateFileProtectRule Creates a core file monitoring rule.
CreateFileUploadLimit CreateFileUploadLimit Specifies the queries per second (QPS) limit on the files uploaded from the client.
CreateHoneypot CreateHoneypot Creates a honeypot.
CreateHoneypotNode CreateHoneypotNode Creates a management node.
CreateHoneypotPreset CreateHoneypotPreset Creates a honeypot template.
CreateHoneypotProbe CreateHoneypotProbe Creates a probe.
CreateHoneypotProbeBind CreateHoneypotProbeBind Creates a monitoring or forwarding service for a probe.
CreateHybridProxyCluster CreateHybridProxyCluster Creates a hybrid-cloud proxy cluster.
CreateInterceptionRule CreateInterceptionRule Creates a defense rule in the container firewall module.
CreateInterceptionTarget CreateInterceptionTarget Creates a defense object.
CreateJenkinsImageRegistry CreateJenkinsImageRegistry Creates a Jenkins image repository.
CreateJenkinsImageScanTask CreateJenkinsImageScanTask Creates a Jenkins scan task.
CreateMaliciousNote CreateMaliciousNote Adds remarks to alert events for agentless detection.
CreateOpaClusterPlugin CreateOpaClusterPlugin Installs the components that are required by at-risk image blocking. The components are policy-template-controller, gatekeeper, and logtail-ds.
CreateOrUpdateAssetGroup CreateOrUpdateAssetGroup Modifies the mapping between an asset and an asset group. For example, you can call this operation to modify the server group to which the asset belongs or the asset list of the asset group.
CreateOrUpdateAutoTagRule CreateOrUpdateAutoTagRule Creates an asset auto-tagging rule or modifies an asset auto-tagging rule that is created on the Asset Management Rule tab.
CreateOrUpdateDingTalk CreateOrUpdateDingTalk Creates or modifies a DingTalk chatbot that sends notifications.
CreateOssBucketScanTask CreateOssBucketScanTask Creates a bucket check task.
CreateRestoreJob CreateRestoreJob Creates a restoration task.
CreateSasTrial CreateSasTrial Applies for a trial of Security Center.
CreateUniBackupPolicy CreateUniBackupPolicy Creates an anti-ransomware policy for a database.
CreateVulAutoRepairConfig CreateVulAutoRepairConfig Creates a list of vulnerabilities that can be automatically fixed. After the list is created, you can select the list when you create a vulnerability fixing task on the Playbook page.
DeleteAttackPathSensitiveAssetConfig DeleteAttackPathSensitiveAssetConfig Delete attack path sensitive asset.
DeleteBackupPolicyMachine DeleteBackupPolicyMachine Deletes a server from a specified anti-ransomware policy.
DeleteBaselineCheckWhiteRecord DeleteBaselineCheckWhiteRecord Deletes the whitelist record for a baseline check item.
DeleteBinarySecurityPolicy DeleteBinarySecurityPolicy Deletes a binary security policy from the container signature feature.
DeleteContainerDefenseRule DeleteContainerDefenseRule Deletes a rule for non-image program defense.
DeleteDingTalk DeleteDingTalk Deletes a DingTalk chatbot on the DingTalk Chatbot tab of the Notification Settings page.
DeleteFileProtectRule DeleteFileProtectRule Deletes core file monitoring rules.
DeleteHoneypot DeleteHoneypot Deletes a specified honeypot.
DeleteHoneypotNode DeleteHoneypotNode Deletes a specified management node.
DeleteHoneypotProbe DeleteHoneypotProbe Deletes a specified probe.
DeleteHoneypotProbeBind DeleteHoneypotProbeBind Delete the probe service.
DeleteLoginBaseConfig DeleteLoginBaseConfig Deletes the basic configuration information from the logon security configurations for a specific asset.
DeleteOssScanConfig DeleteOssScanConfig Deletes the configuration of an Object Storage Service (OSS) file detection policy.
DeleteSecurityEventMarkMissList DeleteSecurityEventMarkMissList Deletes multiple custom defense rules at a time. The custom defense rules are used to add false positive alerts to the whitelist.
DeleteSuspEventNode DeleteSuspEventNode Deletes the description of an alert.
DeleteUniBackupPolicy DeleteUniBackupPolicy Deletes anti-ransomware policies that are created for databases.
DescribeAlarmEventDetail DescribeAlarmEventDetail Queries the details about an alert event. An alert event consists of an alert and exceptions. Each alert event is associated with multiple exceptions.
DescribeAlarmEventStackInfo DescribeAlarmEventStackInfo Queries the stack information about an alert event.
DescribeAllRegionsStatistics DescribeAllRegionsStatistics Queries the statistics on global security events, including the numbers of unfixed vulnerabilities, baseline risks, and alerts.
DescribeAssetsScaProcessNum DescribeAssetsScaProcessNum Queries the number of Java processes in an asset by using the asset fingerprints feature of Security Center.
DescribeAttestors DescribeAttestors Queries a list of witnesses.
DescribeAutoDelConfig DescribeAutoDelConfig Queries the number of days during which a detected vulnerability is retained before the vulnerability is automatically deleted.
DescribeBackupFiles DescribeBackupFiles Queries backup files.
DescribeBinarySecurityPolicies DescribeBinarySecurityPolicies Queries binary security policies.
DescribeBruteForceRecords DescribeBruteForceRecords Queries the IP addresses that are blocked by a defense rule against brute-force attacks.
DescribeBruteForceSummary DescribeBruteForceSummary Queries the statistics of IP address blocking policies that are used to defend against brute-force attacks and trigger alerts.
DescribeCanAccessVpcSale Check if the Asset Can be Sold by VPC Check if the asset can be sold by VPC
DescribeCanTrySas DescribeCanTrySas Checks the permissions on the trial use of Security Center.
DescribeCheckResult DescribeCheckResult Queries the result of the ISO 27001 compliance check.
DescribeCheckWarningMachines DescribeCheckWarningMachines Queries the servers on which the same risk item is detected by specifying a baseline and a check item.
DescribeCloudProductFieldStatistics DescribeCloudProductFieldStatistics Queries the statistics of cloud services whose instances are protected by Security Center.
DescribeCloudVendorTrialConfig Query Third-Party Cloud Asset Audit Log Access Configuration Query the trail configuration attributes of the corresponding AK configuration
DescribeClusterInfoList DescribeClusterInfoList Queries the information about a cluster.
DescribeCommonOverallConfigList DescribeCommonOverallConfigList Queries the configurations of features in proactive defense.
DescribeCommonTargetConfig DescribeCommonTargetConfig Queries the configurations of the proactive defense feature.
DescribeContainerApps DescribeContainerApps Queries the information about a containerized application.
DescribeContainerFieldStatistics DescribeContainerFieldStatistics Queries the statistical information about containers.
DescribeContainerGroupedFieldDetail DescribeContainerGroupedFieldDetail Queries the attribute details of containers.
DescribeContainerServiceK8sClusterNamespaces DescribeContainerServiceK8sClusterNamespaces Queries the namespace of a Container Service for Kubernetes (ACK) cluster.
DescribeContainerServiceK8sClusters DescribeContainerServiceK8sClusters Queries a list of Container Service for Kubernetes (ACK) clusters.
DescribeCountNotScannedImage DescribeCountNotScannedImage Queries the number of images that are not scanned.
DescribeCustomBlockInstances DescribeCustomBlockInstances Queries the list of servers on which the custom defense rule against brute-force attacks takes effect.
DescribeCustomizeReportList DescribeCustomizeReportList Queries security reports.
DescribeEventLevelCount DescribeEventLevelCount Queries the statistics of alert events by risk level.
DescribeExposedInstanceDetail DescribeExposedInstanceDetail Queries the details of a specified server that is exposed on the Internet.
DescribeLoginSwitchConfigs DescribeLoginSwitchConfigs Queries the alerting status for unapproved logon IP addresses, unapproved logon time ranges, or unapproved logon accounts.
DescribeOfflineMachines DescribeOfflineMachines Queries the information about the servers whose Security Center agent status is Offline.
DescribePropertyCronItem DescribePropertyCronItem Queries the scheduled tasks of your assets.
DescribePropertyProcItem DescribePropertyProcItem Queries information about all processes.
DescribePropertyScaItem DescribePropertyScaItem Queries middleware fingerprints.
DescribePropertyScheduleConfig DescribePropertyScheduleConfig Queries the configurations of scheduled tasks of asset fingerprint collection.
DescribePropertySoftwareItem DescribePropertySoftwareItem Queries information about all software assets.
DescribePropertyTypeScaItem DescribePropertyTypeScaItem Queries middleware types.
DescribePropertyUserItem Retrieve account information of assets Retrieves the account information of assets.
DescribeRestoreJobs DescribeRestoreJobs Queries the details about restoration tasks.
DescribeRestorePlans DescribeRestorePlans Queries restoration tasks.
DescribeRiskListCheckResult DescribeRiskListCheckResult Queries the number of risk items detected in the configuration assessment of one or more cloud services by using the instance IDs of the cloud services.
DescribeRiskType DescribeRiskType Queries baseline types.
DescribeScanTaskStatistics DescribeScanTaskStatistics Queries the statistics of virus detection tasks.
DescribeSecurityCheckScheduleConfig DescribeSecurityCheckScheduleConfig Queries the day of a week when custom check tasks are performed and the time range during which the custom check tasks are performed.
DescribeSecurityEventOperationStatus DescribeSecurityEventOperationStatus Queries the alert events that are triggered by the same IP address rule or of the same alert type as a specific alert event if you want to handle the specific alert event in batch operation mode.
DescribeSecurityEventOperations DescribeSecurityEventOperations Queries the operations that you can perform to handle an alert.
DescribeServiceLinkedRoleStatus DescribeServiceLinkedRoleStatus Checks whether a service-linked role is created for Security Center.
DescribeSimilarSecurityEvents DescribeSimilarSecurityEvents Queries alert events that are triggered by the same rule or of the same alert type.
DescribeSoarPlaybookTaskDetail Query Playbook Task Details Query the execution details of a remediation task playbook
DescribeSoarStrategies DescribeSoarStrategies Queries the policy templates on the Playbook page.
DescribeSoarStrategyParam DescribeSoarStrategyParam Queries the parameters of a policy on the Playbook page.
DescribeSoarStrategyTasks DescribeSoarStrategyTasks Queries a list of policy tasks on the Playbook page.
DescribeStrategyExecDetail DescribeStrategyExecDetail Queries the results of the last baseline check by using a specified baseline check policy.
DescribeStrategyTarget DescribeStrategyTarget Queries the information about the assets to which a baseline check policy is applied.
DescribeStrictEventName Query Alarm Names in Strict Mode Strict mode supports alarm queries
DescribeSummaryInfo DescribeSummaryInfo Queries the security information about your assets. The information includes the security score and the numbers of protected and unprotected assets.
DescribeSuspEventExportInfo DescribeSuspEventExportInfo Queries the information about an export task of exceptions.
DescribeSuspEventQuaraFiles DescribeSuspEventQuaraFiles Queries quarantined files by page.
DescribeSuspEventUserSetting DescribeSuspEventUserSetting Queries the user settings for exceptions.
DescribeSuspiciousOverallConfig DescribeSuspiciousOverallConfig Queries the configuration of a specified feature.
DescribeSuspiciousUUIDConfig DescribeSuspiciousUUIDConfig Queries the UUIDs of servers on which proactive defense of a specified type takes effect.
DescribeSyncAssetTaskList Query asset synchronization task list Queries the list of asset synchronization IDC scan tasks.
DescribeTarget Query vulnerability machine list Queries the machine list settings for vulnerability scanning.
DescribeTaskErrorLog Query error logs of a failed image fix task Queries the error logs of a failed image fix task.
DescribeTotalStatistics Retrieve event statistics Retrieves event statistics information.
DescribeTraceInfoNode Query trace node information Queries the details of a trace node.
DescribeUniBackupDatabase Query anti-ransomware databases Queries the details of databases in database protection policies.
DescribeUniBackupPolicies Query anti-ransomware policies Queries the list of database anti-ransomware policies.
DescribeUniBackupStatistics Query anti-ransomware backup statistics information for databases Queries the statistics information of anti-ransomware backup for databases.
DescribeUniRecoverableList Query recoverable database backups Queries the list of recoverable database backups.
DescribeUniSupportRegion DescribeUniSupportRegion Queries the region that is supported by anti-ransomware for databases.
DescribeUserBackupMachines Query servers with anti-ransomware backup policies enabled Queries servers that have anti-ransomware backup policies enabled.
DescribeUserBaselineAuthorization Query cloud platform authorization status Queries the status of cloud platform authorization information for a user.
DescribeUserSetting Query user-defined configurations Retrieves user-defined configurations for baseline checks.
DescribeUuidsByVulNames Retrieve servers that support vulnerability fixing by vulnerability name Retrieves the list of servers that support vulnerability fixing based on vulnerability names.
DescribeVendorList Retrieve supported vendors Retrieves the supported vendor information for Security Center.
DescribeVolDingdingMessage DescribeVolDingdingMessage Queries the QR code address of a DingTalk group.
DescribeVpcHoneyPotCriteria DescribeVpcHoneyPotCriteria Queries the search conditions that can be used to query honeypots.
DescribeVpcHoneyPotList Query VPC honeypot probe list Queries the list of VPC honeypot probes.
DescribeVpcList DescribeVpcList Queries the information about virtual private clouds (VPCs).
DescribeVulCheckTaskStatusDetail DescribeVulCheckTaskStatusDetail Queries the status information about vulnerability scan tasks on a server.
DescribeVulConfig Query vulnerability management configuration Queries vulnerability management configuration information.
DescribeVulDefendCountStatistics Query user vulnerability prevention statistics Queries the vulnerability prevention statistics of a Security Center user.
DescribeVulFixStatistics DescribeVulFixStatistics Queries the statistics of vulnerability fixes.
DescribeVulMetaCountStatistics DescribeVulMetaCountStatistics Queries the statistics of vulnerabilities in Security Center.
DescribeVulTargetConfig DescribeVulTargetConfig Queries the configurations of the vulnerability scan feature for a server.
DescribeVulTargetStatistics Retrieve vulnerability switch configurations Retrieves the list of vulnerability switch configurations.
DescribeWarningExportInfo DescribeWarningExportInfo Queries the progress of a export task for a baseline check result.
DescribeWebLockBindList Query web tamper-proofing server list Retrieves the list of servers that have web tamper-proofing protection enabled.
DescribeWebLockConfigList DescribeWebLockConfigList Queries the configurations of web tamper proofing for a specified server.
DescribeWebLockFileChangeStatistics Query file change statistics for web tamper-proofing Queries the file change statistics for web tamper-proofing.
DescribeWebLockFileEvents DescribeWebLockFileEvents Queries events on web tamper proofing.
DescribeWebLockFileTypeSummary Query WebLock File Type Summary Queries the WebLock file type summary.
DescribeWebLockInclusiveFileType Query tamper-proofing file types Queries the file types supported by tamper-proofing protection.
DescribeWebLockProcessBlockStatistics DescribeWebLockProcessBlockStatistics Queries the statistics on processes for web tamper proofing.
DescribeWebLockProcessList DescribeWebLockProcessList Queries the processes for web tamper proofing.
DescribeWebLockStatus Query tamper-proofing protection status Queries the tamper-proofing protection status.
DescribeWebLockTotalFileChangeCount DescribeWebLockTotalFileChangeCount Queries the number of times that the files protected by web tamper proofing are changed.
DescribeWebPath Query custom web directories for security alerts Queries custom web directories for security alerts.
DescribeWhiteListAsset DescribeWhiteListAsset Queries the information about servers that can be added or are added to application whitelist policies.
DescribeWhiteListAuthorize Retrieve available authorization count Queries the number of available authorizations for the application whitelist.
DescribeWhiteListEffectiveAssets DescribeWhiteListEffectiveAssets Queries the servers on which an application whitelist policy takes effect.
DescribeWhiteListStrategyList DescribeWhiteListStrategyList Queries a list of application whitelist policies.
DescribeWhiteListStrategyStatistics Query policy statistics information Queries the statistics of application whitelist policy.
DescribeWhiteListStrategyUuidCount DescribeWhiteListStrategyUuidCount Queries the number of the servers on which an application whitelist policy takes effect.
DingTalkOnlineTest DingTalkOnlineTest Tests whether DingTalk notification configurations are valid.
DisableBruteForceRecord DisableBruteForceRecord Disables an IP address blocking policy that is in effect.
DisableCustomBlockRecord DisableCustomBlockRecord Disables a custom IP address blocking policy for servers.
EnableBruteForceRecord EnableBruteForceRecord Enables an IP address blocking policy for a specified server.
EnableCustomBlockRecord EnableCustomBlockRecord Enables a custom IP address blocking policy.
EnableCustomInstanceBlockRecord EnableCustomInstanceBlockRecord Enables a custom rule for an instance.
EnableServiceAccessResourceDirectory Enable the multi-account management feature of security center Enables the multi-account management feature of Security Center.
ExportCustomizeReport ExportCustomizeReport Exports a security report.
ExportSuspEvents ExportSuspEvents Exports the information about exceptions to a file.
FinishGuidTask FinishGuidTask Completes guidance tasks for beginners to earn rewards.
FixCheckWarnings Fix baseline check risk items Fixes baseline check risk items.
GenerateDynamicDict GenerateDynamicDict Generates a custom dictionary of weak passwords for the baseline check feature.
GetAccountLabel GetAccountLabel Obtains account tags.
GetAegisContainerPluginRuleCriteria Get Container Escape Prevention Query Criteria Queries the query conditions of container anti-tamper rules.
GetAgentlessTaskCount GetAgentlessTaskCount Queries the number of agentless detection tasks.
GetAlarmMachineCount Retrieve the number of servers with alerts Retrieves the number of servers that currently have security alerts.
GetAppNetwork Retrieve network topology between container applications Retrieves the network topology between container applications.
GetAssetDetailByUuid Query server asset details and extended information Queries the details and extended information of a server asset by UUID.
GetAssetSelectionConfig Retrieve asset selection configuration Retrieves the asset selection configuration.
GetAttackPathEventStatistics Query attack path event statistics Queries attack path event statistics.
GetAttackPathSensitiveAssetConfig Query attack path sensitive asset settings Queries the sensitive assets in an attack path.
GetAttackPathWhitelist Query attack path whitelist details Queries the details of an attack path whitelist.
GetAttackTypeList Retrieve attack type list Retrieves the list of attack types for the attack analysis event display.
GetAuthVersionStatistic Query asset authorization quantity statistics Query asset authorization quantity statistics.
GetBackupAutoConfigStatus Query anti-ransomware managed service status Queries whether the anti-ransomware managed service supports automatic configuration of anti-ransomware server backup policies.
GetBackupStorageCount Query used anti-ransomware storage capacity Queries the used anti-ransomware storage capacity.
GetBuildRiskDefineRuleConfig Query risk scan configuration for image build commands Queries the risk scan configuration for image build commands.
GetCanTrySas GetCanTrySas Checks whether the current user is qualified for the trial use of Security Center.
GetCheckDetail GetCheckDetail Queries the details about a check item that is used for configuration assessment.
GetCheckProcess Query cloud platform configuration check task progress Queries the progress of a cloud platform configuration check task.
GetCheckRiskStatistics GetCheckRiskStatistics Queries the statistics on risk scenarios and check items that are used in the risk scenarios, including the statistics on low-risk, medium-risk, and high-risk items by baseline type.
GetCheckScopeConfig Query check scope configuration Queries the check scope configuration.
GetCheckTimeDimensionStatistic Retrieve time trend statistics for CSPM risk items Retrieves the time trend pass rate statistics for Cloud Security Posture Management (CSPM) risk items.
GetClientRatioStatistic GetClientRatioStatistic Queries the installation rate and online rate of the agent.
GetCloudAssetCriteria GetCloudAssetCriteria Queries the filter conditions that are used to search for cloud assets.
GetClusterCheckItemWarningStatistics Retrieve baseline check issue count for a container cluster Retrieves the number of baseline check issues for a container cluster.
GetClusterRuleSummary GetClusterRuleSummary Queries the overall information about cluster defense rules that are configured for the container firewall feature.
GetClusterStrategyCount Query the number of policies in each cluster Queries the number of policies in each cluster.
GetClusterSuspEventStatistics Retrieve container security event statistics Retrieves statistics on container security events.
GetCommonSwitchConfig GetCommonSwitchConfig Queries the configuration of a common switch.
GetConsoleFuncGrayStatus Get the Gray Status of Console Function Modules Query whether the core function's gray switch is hit
GetDataTrend Query security operations trends Queries the security operations trends for vulnerabilities, alerts, and baselines.
GetFileProtectEventCount GetFileProtectEventCount Queries the total number of core file monitoring events by filter condition.
GetFileProtectRule GetFileProtectRule Queries the information about a core file monitoring rule based on the ID of the rule.
GetFileUploadLimit GetFileUploadLimit Queries the queries per second (QPS) limit on the files uploaded from the client.
GetFunctionTrialStatus Get Function Trial Eligibility Status Get Trial Status
GetHoneyPotUploadPolicyInfo GetHoneyPotUploadPolicyInfo Obtains the URL that is used to upload a file to a honeypot.
GetHoneypotEventTrend Obtain the attack volume trend of honeypot attack sources Obtain attack trend statistics for a single attack source.
GetHoneypotNodeMetricList GetHoneypotNodeMetricList Queries the monitoring data of management nodes to which the cloud honeypot belongs.
GetHoneypotPreset GetHoneypotPreset Queries the configurations of a specified honeypot template.
GetHoneypotProbe GetHoneypotProbe Queries the details about a specified probe.
GetHoneypotStatistics GetHoneypotStatistics Get statistics on honey pot usage.
GetImageEventOperation GetImageEventOperation Queries alert handling rules.
GetImageScanNumInPeriod GetImageScanNumInPeriod Queries the number of image scans that are performed within the last several days.
GetInstallCodeForUuid Query the agent installation code for a specified asset by UUID Queries the Security Center agent installation code for a specified asset by UUID.
GetInterceptionSummary GetInterceptionSummary Queries the statistics of the container firewall feature.
GetInterceptionTargetDetail GetInterceptionTargetDetail Queries the information about a specified network object that is protected by the container firewall feature.
GetLocalDefaultRegion Retrieve default local region Retrieves the default synchronization region for external asset synchronization.
GetLogMeta GetLogMeta Queries the status of a data shipping task of a log.
GetMaliciousFileWhitelistConfig GetMaliciousFileWhitelistConfig Queries an alert whitelist rule of sensitive files that are detected by using the agentless detection feature.
GetModuleConfig GetModuleConfig Queries the configurations of a module.
GetModuleConfigStatus GetModuleConfigStatus Checks whether the purchased Security Center features are enabled and whether related configurations take effect.
GetModuleTrialAuthInfo GetModuleTrialAuthInfo Queries the qualification information about the trial use of Security Center value-added features, including vulnerability fixing and threat analysis and response.
GetOpaClusterBaseLineList GetOpaClusterBaseLineList Queries the baselines that are supported by at-risk image blocking.
GetOpaPluginStatus GetOpaPluginStatus Queries the installation status of the components that are required for clusters protected by proactive defense for containers.
GetOpaStrategyTemplateSummary Query usage statistics of risky image blocking policy templates Queries the usage statistics information of risky image blocking policy templates for container proactive defense.
GetPropertyScheduleConfig Query asset fingerprints collection cycle configuration Queries the collection cycle configuration of Asset Fingerprints.
GetPublishCron Retrieve client upgrade time configuration Retrieves the client upgrade time configuration.
GetRdTree Query the directory structure of a resource organization under a resource directory Queries the directory structure of the resource organization under a resource directory by using the multi-account management feature.
GetRulesCount Query the number of system defense rules and user-defined rules Queries the number of system defense rules and user-defined rules.
GetSasContainerWebDefenseRuleApplication Retrieve the application list for container file defense configurations Retrieves the list of applications for container file defense configurations.
GetSasContainerWebDefenseRuleCriteria Retrieve query criteria for container tamper-proofing rules Retrieves the query criteria for container tamper-proofing rules.
GetSensitiveDefineRuleConfig Query custom check items for sensitive file tampering Queries custom check items for sensitive file tampering.
GetServerlessAppAuthDetail Retrieve serverless application authorization details Retrieves the authorization details of a serverless application.
GetServerlessAuthSummary Retrieve serverless authorization overview Retrieves the Serverless authorization overview.
GetServiceTrail Retrieve audit trail delivery configuration Retrieves the audit trail delivery configuration.
GetStrategyTemplateDetail Query rule template details for container proactive defense Queries the details of a rule template for container proactive defense.
GetSuspiciousStatistics Query security alert counts by asset group Queries the statistics on the number of security alerts in one or more asset groups.
GetTenantCheckAvailable Query whether a one-click scan can be submitted Queries whether a free one-click scan can be submitted. The scan scope includes free vulnerability scanning categories and free CSPM check items.
GetUserLang Query log analysis language settings Queries the log analysis language settings.
GetVirusScanLatestTaskStatistic Retrieve the latest virus scan information Retrieves the scan information of the latest virus scan.
HandleMaliciousFiles Add or remove security alerts to or from the whitelist Adds or removes security alerts detected by the agentless detection feature to or from the whitelist.
HandleSecurityEvents HandleSecurityEvents Handles alert events.
HandleSimilarSecurityEvents Batch process alert events based on the same IP rule or type Batch processes alert events based on the same IP rule or type.
IgnoreHcCheckWarnings IgnoreHcCheckWarnings Ignores or cancels ignoring multiple baseline risk items at a time.
IgnoreIdcProbeScanResult Whitelist or ignore IDC probe scan results Adds scan results from IDC probes to the whitelist or ignores them.
InstallBackupClient Install anti-ransomware client Installs the anti-ransomware client.
InstallCloudMonitor Install cloudMonitor agent Installs the CloudMonitor agent on a specified server.
InstallHybridProxy InstallHybridProxy Installs the Security Center agent on a proxy server in a hybrid cloud.
InstallPmAgent InstallPmAgent Installs the CloudMonitor agent on a server that is not deployed on Alibaba Cloud.
InstallUniBackupAgent Install the anti-ransomware agent for databases Installs the anti-ransomware agent for databases.
JoinWebLockProcessWhiteList JoinWebLockProcessWhiteList Adds processes to the process whitelist of web tamper proofing.
ListAgentlessAsset ListAgentlessAsset Query agentless detection assets.
ListAgentlessMaliciousFiles Retrieve agentless detection malicious file list Retrieves the list of malicious files detected by agentless detection.
ListAgentlessRelateMalicious Retrieve risks associated with agentless detection events Retrieves risks associated with agentless detection events.
ListAgentlessRiskUuid Retrieve agentless detection vulnerable server list Retrieves the list of vulnerable servers detected by agentless detection.
ListAgentlessTask Retrieve agentless detection task list Retrieves the list of agentless detection tasks.
ListAssetCleanConfig ListAssetCleanConfig Queries the configurations for cleaning offline hosts whose provider cannot be identified.
ListAssetInfoPublish ListAssetInfoPublish Queries the custom upgrade information about assets.
ListAssetRefreshTaskConfig Get asset refresh configuration Retrieves the asset refresh configuration.
ListAssetSelectionSelectedTarget Query selected assets from specified assets Queries the selected assets from the specified assets.
ListAssetSelectionTarget ListAssetSelectionTarget Queries the required asset.
ListAttackPathEvent Query attack path events Queries the list of attack path events.
ListAttackPathWhitelist Query attack path whitelist Queries the attack path whitelist.
ListAutoTagRules Query asset tag rules Queries the list of asset tag rules by using the system configuration, feature settings, multi-cloud configuration management, and asset management rule features of Security Center.
ListAvailableAttackPath ListAvailableAttackPath Query Attack Path List.
ListAvailableHoneypot Query available honeypot configuration templates Queries available honeypot configuration templates.
ListBackupRecord Query backup records Queries a list of backup records.
ListCheckRuleInstance Query instances of a CSPM rule Queries all instances under a Cloud Security Posture Management (CSPM) rule.
ListCheckTypes ListCheckTypes Queries the types of check items that meet the specified conditions based on the ID of a baseline.
ListClientAlertMode Query alert settings Queries the alert settings of assets. The default alert setting for assets is balance mode. The detailed asset list is returned only in strict mode.
ListCloudVendorRegions ListCloudVendorRegions Queries the synchronization region configurations of other clouds on a site.
ListClusterPluginInfo ListClusterPluginInfo Queries the status of plug-ins on clusters.
ListCriteriaStrategy ListCriteriaStrategy Queries the IDs and names of rules configured for proactive defense for containers.
ListFileProtectRule ListFileProtectRule Queries core file monitoring rules.
ListHoneypotAlarmEvents ListHoneypotAlarmEvents Queries the information about alert events that are generated.
ListHoneypotNode ListHoneypotNode Queries the information about management nodes.
ListHoneypotPreset ListHoneypotPreset Queries honeypot templates.
ListImageBuildRiskItem ListImageBuildRiskItem Queries the types of risky image build commands.
ListInstanceRiskLevels ListInstanceRiskLevels Queries the risk levels of instances.
ListInstanceRiskNum ListInstanceRiskNum Queries the statistics about risks in instances.
ListInterceptionRulePage ListInterceptionRulePage Queries defense rules that are configured for the container firewall feature.
ListOperationCheck View details of repair or rollback tasks Query the list of instance results under the operation check item
ListRdDefaultSyncList ListRdDefaultSyncList Queries the automatic management policies of members that are added to Security Center for multi-account management. The members in the automatic control management directory are automatically added to the member list of Security Center.
ListRuleTargetAll ListRuleTargetAll Queries the network objects based on which a specified cluster is protected.
ModifyAppVulScanCycle ModifyAppVulScanCycle Configures a scan cycle for application vulnerabilities.
ModifyAttestor ModifyAttestor Modifies the information about a witness that is created by using the container signature feature.
ModifyClientConfSetup ModifyClientConfSetup Modifies the resource configurations of the Security Center agent.
ModifyClientConfStrategy ModifyClientConfStrategy Modifies an agent configuration policy.
ModifyCloudVendorTrialConfig Modify the audit log configuration information for multi-cloud access Modify the Trail configuration information for the AK
ModifyClusterCnnfStatusUserConfirm ModifyClusterCnnfStatusUserConfirm Fixes the blocking status of clusters whose status is Normal to be confirmed.
ModifyDingTalkStatus ModifyDingTalkStatus Changes the notification status of a DingTalk chatbot.
ModifyLoginSwitchConfig ModifyLoginSwitchConfig Enables or disables the logon security settings for a specific asset.
ModifyOperateVul ModifyOperateVul Handles detected vulnerabilities. You can fix, check, or ignore the vulnerabilities.
ModifyPropertyScheduleConfig ModifyPropertyScheduleConfig Modifies the collection frequency of asset fingerprints for an automatic periodic collection task.
ModifyRefreshProcessInfo ModifyRefreshProcessInfo Refreshes the list of processes that are associated with a Linux software vulnerability.
ModifySecurityCheckScheduleConfig ModifySecurityCheckScheduleConfig Specifies the time when an automatic configuration check on cloud services runs.
ModifySecurityEventMarkMissIndividually ModifySecurityEventMarkMissIndividually Modifies the alert handling rule for alerts that are added to the whitelist by asset.
ModifyStrategy ModifyStrategy Modifies a baseline check policy.
ModifyStrategyTarget ModifyStrategyTarget Modifies the servers to which a baseline check policy is applied.
ModifyTagWithUuid ModifyTagWithUuid Modifies the names of the tags that are added to assets, or modifies the tags for assets.
ModifyVpcHoneyPot ModifyVpcHoneyPot Enables or disables a honeypot.
ModifyVulWhitelistTarget ModifyVulWhitelistTarget Modifies the servers that are added to a vulnerability whitelist.
ModifyWebLockRefresh ModifyWebLockRefresh Refreshes the status of the web tamper proofing feature for a server.
ModifyWebPath ModifyWebPath Modifies a custom web directory.
OperateAgentClientInstall OperateAgentClientInstall Installs the Security Center agent on servers.
OperateApplication OperateApplication Adds or deletes container applications for tamper proofing.
OperateBucketScanTask OperateBucketScanTask Manages an Object Storage Service (OSS) bucket check task.
OperateCommonOverallConfig OperateCommonOverallConfig Enables or disables a feature by type.
OperateSuspiciousTargetConfig OperateSuspiciousTargetConfig Configures the scope on which proactive defense takes effect.
OperationCancelIgnoreSuspEvent OperationCancelIgnoreSuspEvent Cancels ignoring alert events.
PauseClient PauseClient Enables or disables the Security Center agent.
PublicPreCheckImageScanTask PublicPreCheckImageScanTask Queries the number of images to scan in an image scan task and the quota for container image scan to be consumed by the task.
PublicSyncAndCreateImageScanTask PublicSyncAndCreateImageScanTask Adds images to Security Center and creates an image scan task to scan the images.
QueryDiscoverDatabase QueryDiscoverDatabase Queries the progress of a database scan task.
QueryGroupedSecurityEventMarkMissList QueryGroupedSecurityEventMarkMissList Queries whitelist rules.
RefreshAssets RefreshAssets Synchronizes assets.
RefreshRegistryToken RefreshRegistryToken Updates an image token.
ResetHoneypot ResetHoneypot Resets a honeypot.
ResetLogShipper ResetLogShipper Resets and upgrades the log analysis feature. You can call this operation only when the log analysis feature uses the pay-as-you-go billing method.
RetryInstallProbe RetryInstallProbe Retry installing the honeypot probe.
RollbackSuspEventQuaraFile RollbackSuspEventQuaraFile Restores a quarantined file.
SasInstallCode SasInstallCode Queries the installation verification code that is used to run the installation command of the Security Center agent.
SaveSuspEventUserSetting SaveSuspEventUserSetting Saves alert settings.
SaveWhiteListStrategy SaveWhiteListStrategy Creates an application whitelist policy.
SaveWhiteListStrategyAssets SaveWhiteListStrategyAssets Manages the servers to which an application whitelist policy is applied.
SetClusterInterceptionConfig SetClusterInterceptionConfig Configures the status of the container firewall feature.
SetImageSensitiveFileStatus SetImageSensitiveFileStatus Modifies the status of sensitive files in an image.
SetRegistryScanDayNum SetRegistryScanDayNum Specifies a cycle to scan images for image repositories. Unit: days.
SetSensitiveDefineRuleConfig SetSensitiveDefineRuleConfig Configure the check rules of sensitive files.
StartDiscoverDatabaseTask StartDiscoverDatabaseTask Starts a database scan task.
StartHoneypot StartHoneypot Starts a honeypot.
StartIdcProbeScan StartIdcProbeScan Starts an IDC scan task.
StartPreCheckDatabase StartPreCheckDatabase Starts a database precheck task.
StartVirusScanTask StartVirusScanTask Performs a virus scan task on a server or multiple servers.
StopHoneypot StopHoneypot Stops a honeypot.
SubmitTenantCheck SubmitTenantCheck Submits a free quick scan task, which includes vulnerability detection in the free category and free check items of Cloud Security Posture Management (CSPM).
TriggerCheck TriggerCheck Triggers ISO 27001 compliance checks of Security Center.
UninstallBackupClient UninstallBackupClient Uninstalls the anti-ransomware agent.
UninstallUniBackupAgent UninstallUniBackupAgent Uninstalls the database backup agent.
UpdateAlarmEvent UpdateAlarmEvent Updates the status of the honeypot installation time.
UpdateAttackPathWhitelist UpdateAttackPathWhitelist Update Attack Path Whitelist.
UpdateCheckScopeConfig Update check scope configuration Updates the check scope configuration.
UpdateClientAlertMode UpdateClientAlertMode Modifies alerting settings for servers.
UpdateFileProtectRule UpdateFileProtectRule Modifies the content of a core file monitoring rule based on the ID of the rule.