All Products
Search
Document Center

Security Center:API overview

Last Updated:Sep 18, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (Sas/2018-12-03) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

API catalog

API

Title

Description

UpdateCheckScopeConfig Update check scope configuration Updates the check scope configuration.
GetCheckScopeConfig Query check scope configuration Queries the check scope configuration.
ChangeCheckScopeConfigInstance Modify check scope configuration instance Modifies the check scope configuration instance.

Intelligent behavior analysis

API

Title

Description

UpdateUnknownThreatDetectStrategy Update an intelligent behavior analytics policy Updates an intelligent behavior analytics policy.
UpdateUnknownThreatDetectProcess UpdateUnknownThreatDetectProcess Updates the remark for a specified unknown threat detection process.
OperateUnknownThreatDetectMachine OperateUnknownThreatDetectMachine Modifies the unknown threat detection settings for specified servers.
ListUnknownThreatDetectStrategy Query intelligent behavior analytics policies Queries the list of intelligent behavior analytics policies.
ListUnknownThreatDetectProcess Query intelligent behavior analytics process list Queries the process list of intelligent behavior analytics.
ListUnknownThreatDetectMachine Query intelligent behavior analytics machine list Queries the list of machines for intelligent behavior analytics.
ListUnknownThreatDetectEvent Query intelligent behavior analytics alerts Queries the list of intelligent behavior analytics alerting events.
HandleUnknownThreatDetectEvent Handle intelligent behavior analytics alerting Handles alerting from intelligent behavior analytics.
GetUnknownThreatDetectStatistic Retrieve intelligent behavior analytics statistics information Retrieves statistics information on intelligent behavior analytics.
DeleteUnknownThreatDetectStrategy Delete a behavior analytics policy Deletes a behavior analytics policy.
DeleteUnknownThreatDetectProcess DeleteUnknownThreatDetectProcess Deletes one or more Unknown Threat Detect processes.
CreateUnknownThreatDetectStrategy Create an intelligent behavior analytics policy Creates an intelligent behavior analytics policy.
AddUnknownThreatDetectProcess Add intelligent behavior analytics processes Adds processes for intelligent behavior analytics.

Custom client upgrade

API

Title

Description

ListPublishBatch Query release batches Queries the custom upgrade and release batches of the current user.
AddPublishBatch Create a release batch Creates a release batch for Security Center upgrades.
UpdatePublishBatch Update a release batch Updates a release batch.
GetPublishCron Retrieve client upgrade time configuration Retrieves the client upgrade time configuration.
UpdatePublishGraySwitch UpdatePublishGraySwitch Updates the settings of the canary release feature for agent upgrade. If you want to use the feature, contact technical support.
UpdatePublishCron Modify client upgrade time Modifies the configuration of the client upgrade time. To use this feature, contact technical support.
UpgradeVersionByUuids Manually upgrade client Manually upgrades the client of an asset.
UpdatePublishAutoUpgrade Modify automatic upgrade switch Enables or disables automatic upgrade.

Proxy access

API

Title

Description

UpdateHybridProxy Upgrade a hybrid cloud proxy client Upgrades a hybrid cloud proxy client.
ModifyHybridProxyCluster Modify remarks of a proxy cluster Modifies the remarks of a proxy cluster.
ModifyHybridProxyPolicy ModifyHybridProxyPolicy Modify proxy policy.
UnBindHybridProxy UnBindHybridProxy Removes servers from a proxy cluster.
DescribeHybridProxyPolicy Query data collection configuration of a proxy cluster Queries the data collection configuration of a specified proxy cluster.
DescribeHybridProxyList Query proxy machines by paging Queries the list of proxy nodes that have been deployed in a specified proxy cluster by paging.
DescribeHybridProxyClusterList Query proxy clusters by using paging Queries proxy clusters by using paging.
DescribeHybridProxyLinkedClientList Query connected clients by paging Queries the list of clients connected to a specified hybrid cloud proxy by paging. This operation is part of the hybrid cloud proxy feature.
DeleteHybridProxyCluster Delete a cluster by cluster name Deletes a proxy cluster by cluster name.
DeleteHybridProxy Delete a proxy node Deletes a proxy node from a specified proxy cluster.
CreateHybridProxyCluster CreateHybridProxyCluster Creates a hybrid-cloud proxy cluster.
BindHybridProxy BindHybridProxy Adds servers to Security Center over a proxy server. After you create a proxy cluster and deploy a proxy server, you can connect a server to the proxy cluster as a client. This way, the server is added to Security Center over the proxy server and is protected.
DescribeDefaultProxyInstallVersion Query the default installation version of the hybrid cloud proxy Queries the default installation version of the hybrid cloud proxy.
InstallHybridProxy InstallHybridProxy Installs the Security Center agent on a proxy server in a hybrid cloud.

Security report

API

Title

Description

DescribeCustomizeReportList Query security report list Queries the list of security reports.
DescribeReportExport Query security report export information Queries the export information of a security report.
CopyCustomizeReportConfig CopyCustomizeReportConfig Clones an existing security report. The new security report has the same configuration as the existing security report.
DescribeChartList Query statistical chart list Queries the charts supported for statistics in Security Center security reports.
DescribeReportRecipientStatus Query report contact status Queries the status of report contacts by using the system configuration and security report feature of Security Center.

Application whitelist

API

Title

Description

ModifyProcessWhiteList Modify process whitelist status Adds processes to or removes processes from the whitelist in the application whitelist feature.
UpdateWhiteListStrategyStatus Modify application whitelist policy status Modifies the status of an application whitelist policy.
SaveWhiteListStrategyAssets SaveWhiteListStrategyAssets Manages the servers to which an application whitelist policy is applied.
SaveWhiteListStrategy SaveWhiteListStrategy Creates an application whitelist policy.
DescribeWhiteListStrategyUuidCount DescribeWhiteListStrategyUuidCount Queries the number of the servers on which an application whitelist policy takes effect.
DescribeWhiteListStrategyStatistics Query policy statistics information Queries the statistics of application whitelist policy.
DescribeWhiteListStrategyList DescribeWhiteListStrategyList Queries a list of application whitelist policies.
DescribeWhiteListProcess DescribeWhiteListProcess Queries the information about the processes that are detected in an application whitelist policy.
DescribeWhiteListEffectiveAssets DescribeWhiteListEffectiveAssets Queries the servers on which an application whitelist policy takes effect.
DescribeWhiteListAuthorize Retrieve available authorization count Queries the number of available authorizations for the application whitelist.
DescribeWhiteListAsset DescribeWhiteListAsset Queries the information about servers that can be added or are added to application whitelist policies.

Agentless detection

API

Title

Description

DeleteMaliciousFileWhitelistConfig Delete a whitelist rule for agentless detection of sensitive file alerts Deletes a whitelist rule for agentless detection of sensitive file alerts.
BatchDeleteMaliciousFileWhitelistConfig BatchDeleteMaliciousFileWhitelistConfig Deletes whitelist rules for alerts generated for sensitive files that are detected by using the agentless detection feature in batches.
UpdateMaliciousFileWhitelistConfig Modify a whitelist rule for agentless sensitive file detection alerts Modifies a whitelist rule for agentless sensitive file detection alerts.
BatchUpdateMaliciousFileWhitelistConfig BatchUpdateMaliciousFileWhitelistConfig Modifies multiple alert whitelist rules of sensitive files that are detected by using the agentless detection feature at a time.
CreateMaliciousFileWhitelistConfig Create Sensitive File Alert Whitelist Rule of Agentless Detection Get alert whitelist configuration details
GetMaliciousFileWhitelistConfig GetMaliciousFileWhitelistConfig Queries an alert whitelist rule of sensitive files that are detected by using the agentless detection feature.
ListMaliciousFileWhitelistConfigs Query allowlist rules for agentless sensitive file detection alerts Queries the list of allowlist rules for agentless sensitive file detection alerts.
CreateAgentlessScanTask Create an agentless detection task Creates an agentless detection task.
DeleteMaliciousNote Delete an agentless detection note Deletes a note for an agentless detection alert event.
CreateMaliciousNote CreateMaliciousNote Adds remarks to alert events for agentless detection.
ListAgentlessMaliciousFiles Retrieve agentless-detected malicious file list Retrieves the list of malicious files detected by agentless detection.
RetryAgentlessTask Retry an agentless detection task Retries an agentless detection task.
ListAgentlessRelateMalicious Retrieve risks associated with agentless detection events Retrieves risks associated with agentless detection events.
ListAgentlessRegion Retrieve regions supported by agentless detection Retrieves the regions supported by agentless detection.
ListAgentlessTask Retrieve agentless detection task list Retrieves the list of agentless detection tasks.
GetAgentlessTaskCount GetAgentlessTaskCount Queries the number of agentless detection tasks.
ListAgentlessRiskUuid Get agentless detection vulnerable server list Retrieves the list of vulnerable servers detected by agentless detection.

Core file monitoring

API

Title

Description

ListFileProtectPluginStatus ListFileProtectPluginStatus Retrieves information about the Security Center agent installed on servers on which core file monitoring rules take effect. The information includes the installation status of the Security Center agent and whether the core file monitoring feature is supported.
UpdateFileProtectEventStatus Modify core file protection event status Modifies the status of core file monitoring events reported by the client.
GetFileProtectDashboard GetFileProtectDashboard Retrieves information about the core file monitoring feature, including the number of effective rules and the installation status of the Security Center agent on servers.
ListFileProtectEvent Query core file protection alert events Filters and retrieves a list of rules that match the specified conditions.
DeleteFileProtectRule DeleteFileProtectRule Deletes core file monitoring rules.
GetFileProtectEventCount Retrieve total count of core file monitoring events Queries the total number of monitoring events for core files of the current user based on specified filter conditions.
UpdateFileProtectRemark Modify core file monitoring event remarks Adds remarks to core file monitoring events reported by the client.
GetFileProtectEvent Retrieve core file monitoring event details Retrieves the details of a core file monitoring event.
UpdateFileProtectRule Modify a core file protection rule Modifies the content of a core file monitoring rule based on the rule ID.
ListFileProtectRule Retrieve core file protection rules Retrieves the list of rules for the core file protection feature.
CreateFileProtectRule Create a core file protection rule Creates a core file protection rule.
GetFileProtectRule GetFileProtectRule Queries the information about a core file monitoring rule based on the ID of the rule.

Alert settings

API

Title

Description

ListClientAlertMode Retrieve alert settings list Queries the alert settings of assets. The default alert setting for assets is balance mode. Only strict mode returns a detailed asset list.
UpdateClientAlertMode Alert settings Modifies the alert settings for servers.

Container proactive defense

API

Title

Description

Non-image program defense Non-image program defense
ListContainerDefenseRuleClusters Retrieve all clusters associated with non-image-based program defense rules Retrieves all clusters associated with non-image-based program defense rules.
ListContainerDefenseRule Retrieve defense rules for non-image programs Retrieves the list of defense rules for non-image programs.
GetContainerDefenseRuleDetail Retrieve non-image process defense rule details Retrieves the details of a non-image process defense rule.
ModifyContainerDefenseRule ModifyContainerDefenseRule Modifies a rule for non-image program defense.
ModifyContainerDefenseRuleSwitch Modify non-image program defense rule switch Modifies the switch status of a non-image program defense rule.
DeleteContainerDefenseRule DeleteContainerDefenseRule Deletes a rule for non-image program defense.
AddContainerDefenseRule Create a non-image process defense rule Creates a non-image process defense rule.
Risky image blocking Risky image blocking
ListOpaClusterStrategyNew Retrieve risky image blocking policies Retrieves the list of risky image blocking policies.
CreateOpaStrategyNew CreateOpaStrategyNew Creates a rule to block at-risk images.
GetOpaStrategyDetailNew GetOpaStrategyDetailNew Retrieves the details of the rule that is used to block at-risk images.
UpdateOpaStrategyNew Update risky image blocking policy Updates the risky image blocking policy.
DeleteOpaStrategyNew Delete a risky image blocking policy Deletes a risky image blocking policy.
GetOpaStrategyTemplateSummary Query usage statistics of risky image blocking policy templates Queries the usage statistics information of risky image blocking policy templates for container proactive defense.
CreateOpaClusterPlugin CreateOpaClusterPlugin Installs the components that are required by at-risk image blocking. The components are policy-template-controller, gatekeeper, and logtail-ds.
GetOpaPluginStatus GetOpaPluginStatus Queries the installation status of the components that are required for clusters protected by proactive defense for containers.
GetOpaClusterLabelList GetOpaClusterLabelList Retrieves information about the tags that are added to containers based on the feature of proactive defense for containers.
GetStrategyTemplateDetail Query rule template details for container proactive defense Queries the details of a rule template for container proactive defense.
ListCriteriaStrategy ListCriteriaStrategy Queries the IDs and names of rules configured for proactive defense for containers.
GetOpaClusterImageList Get Cluster Image Information Get cluster image information.
GetOpaClusterNamespaceList GetOpaClusterNamespaceList Retrieves information about the namespaces of clusters for which the rules of the at-risk image blocking type are configured in proactive defense for containers.
GetOpaClusterBaseLineList GetOpaClusterBaseLineList Queries the baselines that are supported by at-risk image blocking.
ListImageBuildRiskItem ListImageBuildRiskItem Queries the types of risky image build commands.
DescribeMatchedMaliciousNames Query malicious file types Queries the list of malicious file types.
Container escape prevention Container escape prevention
ListAegisContainerPluginRule ListAegisContainerPluginRule Query user configurations.

Container file defense

API

Title

Description

ListSasContainerWebDefenseRule List container file defense rules Queries container file defense rules.
GetSasContainerWebDefenseRule Retrieve container file defense rule details Retrieves a container file defense rule.
OperateSwitchStatus Change the status of a container file defense rule Changes the status of a container file defense rule.
AddSasContainerWebDefenseRule AddSasContainerWebDefenseRule Creates a rule for container tamper-proofing.
ModifySasContainerWebDefenseRule Modify a container file defense rule Modifies a container file defense rule.
GetSasContainerWebDefenseRuleApplication Retrieve application list for container file defense configurations Retrieves the application list for container file defense configurations.

Container firewall

API

Title

Description

ModifyClusterCnnfStatusUserConfirm ModifyClusterCnnfStatusUserConfirm Fixes the blocking status of clusters whose status is Normal to be confirmed.
GetInterceptionSummary Query micro-segmentation defense overview Queries the micro-segmentation defense overview.
ListInterceptionTargetPage Query container firewall protection objects Queries the network objects protected by micro-segmentation (container firewall).
ListRuleTargetAll ListRuleTargetAll Queries the network objects based on which a specified cluster is protected.
SetClusterInterceptionConfig SetClusterInterceptionConfig Configures the status of the container firewall feature.
ModifyInterceptionTarget Modify container firewall network object Modifies the network object information of a container firewall.
ListClusterInterceptionConfig Query cluster interception rules Queries the list of cluster interception rules.
ListClusterCnnfStatusDetail Query container firewall status details Queries the status details of the container firewall.
ModifyInterceptionRule Modify a container proactive defense interception rule Modifies a container proactive defense interception rule.
ModifyInterceptionRuleSwitch Modify container proactive defense interception policy switch Modifies the switch status of container proactive defense interception policies.

Agent client

API

Title

Description

GetClientRatioStatistic GetClientRatioStatistic Queries the installation rate and online rate of the agent.
ModifyClientConfStrategy Modify a client configuration policy Modifies a client configuration policy.
DescribeClientConfStrategy Query client configuration policy Queries the machine configuration information for different client tags.
ModifyClientConfSetup ModifyClientConfSetup Modifies the resource configurations of the Security Center agent.
DescribeClientConfSetup Query client configuration steps Queries the resource configuration information of a client.
DescribeInstallCode Retrieve installation key Retrieves the installation verification key for the agent client installation command.
DeleteInstallCode Delete an installation code Deletes an installation code.
ListPluginForUuid Query asset plugin information Query plugin information of an asset.
AddInstallCode AddInstallCode Creates a command that is used to install the Security Center agent.
OperateAgentClientInstall OperateAgentClientInstall Installs the Security Center agent on servers.
PauseClient PauseClient Enables or disables the Security Center agent.
UnbindAegis Unbind non-Alibaba Cloud servers from security center Unbinds non-Alibaba Cloud servers from Security Center.
DescribeAgentInstallStatus Query agent installation status Queries the Agent installation status after an Agent installation command is run by using Cloud Assistant. This operation supports querying the installation status only for installations initiated within the last 2 minutes.
DescribeVendorList Retrieve supported vendors Retrieves the supported vendor information for Security Center.
DescribeInstallCaptcha Retrieve the installation verification code for manual agent installation Retrieves the installation verification code for manually installing the Agent.
SasInstallCode SasInstallCode Queries the installation verification code that is used to run the installation command of the Security Center agent.
DescribeInstallCodes Query the list of commands for manually installing the security center agent Queries the list of commands for manually installing the Security Center agent.
ListUninstallAegisMachines Query assets without the client installed Queries information about assets that do not have the client installed.
DescribeClientProblemType Query client issue list Retrieves the category list of client issue diagnostics.

Asset management

API

Title

Description

DeleteSearchCondition Delete a saved search condition Deletes a saved search condition from the Assets module of Security Center.
StartIdcProbeScan StartIdcProbeScan Starts an IDC scan task.
ModifySearchCondition Edit common filter conditions for assets Edits the common filter conditions for host assets.
GetAssetDetailByUuid Query server asset details and extended information Queries the details and extended information of a server asset by UUID.
DescribeGroupStruct Retrieve group structure Retrieves the group structure.
ListCloudAssetInstances List cloud service assets Retrieves the list of cloud service assets.
DescribeImageInfoList Query image list for console asset management Queries the list of images.
DescribeLogShipperStatus Query log analysis feature status Queries the availability status of the log analysis feature.
AddUninstallClientsByUuids AddUninstallClientsByUuids Adds servers from which you want to uninstall the Security Center agent.
AddTagWithUuid AddTagWithUuid Adds a tag to assets.
GetCloudAssetSummary Retrieve cloud asset summary Retrieves the summary of cloud assets.
GetCloudAssetDetail GetCloudAssetDetail Obtains the details of cloud assets.
ModifyAssetImportant Set asset importance Sets the importance level of assets.
ModifyGroupProperty Modify the name of a server group Modifies the name of a server group.
DescribeOfflineMachines DescribeOfflineMachines Queries the information about the servers whose Security Center agent status is Offline.
CheckUserHasEcs CheckUserHasEcs Checks whether Elastic Compute Service (ECS) instances exist.
CreateOrUpdateAssetGroup CreateOrUpdateAssetGroup Modifies the mapping between an asset and an asset group. For example, you can call this operation to modify the server group to which the asset belongs or the asset list of the asset group.
RefreshAssets Synchronize assets Synchronizes asset data.
DeleteGroup Delete a server group Deletes a server group.
DeleteTagWithUuid Delete asset labels Deletes custom labels bound to assets.
DeleteLoginBaseConfig DeleteLoginBaseConfig Deletes the basic configuration information from the logon security configurations for a specific asset.
ModifyTagWithUuid ModifyTagWithUuid Modifies the names of the tags that are added to assets, or modifies the tags for assets.
ModifyLoginSwitchConfig ModifyLoginSwitchConfig Enables or disables the logon security settings for a specific asset.
ModifyLoginBaseConfig Modify basic logon security settings for a single asset Modifies the basic configuration of logon security settings for a single asset.
ModifyPushAllTask Send a security check task with one click Sends a security check task to asset servers with one click.
DescribeAssetDetailByUuid Query server asset details and extended information Queries the details and extended information of a server asset by UUID.
DescribeGroupedInstances Query asset statistics information Queries statistics information of assets based on specified aggregation dimensions.
QueryGroupIdByGroupName Query asset group ID Queries the ID of an asset group by group name.
DescribeAssetSummary Query core count statistics information of protected assets Queries the core count statistics information of assets that are protected by Security Center.
DescribeAllEntity Query all server asset list information Retrieves the list of all server assets, including asset group IDs and asset names.
DescribeFieldStatistics Query server statistics information in assets Queries the statistics information of servers in your assets.
DescribeGroupedTags Query label statistics information Queries the statistics information of asset labels.
DescribeAllGroups Query server group information Queries information about all server groups.
DescribeInstanceStatistics Query server statistics information Queries the statistics information of server asset instances.
DescribeCloudProductFieldStatistics DescribeCloudProductFieldStatistics Queries the statistics of cloud services whose instances are protected by Security Center.
DescribeDomainCount Query domain name asset count Queries the number of your domain name assets.
DescribeDomainList Query domain name asset information Queries information about your domain name assets.
DescribeDomainDetail Query domain name asset details Queries the details of your domain name assets.
DescribeCloudCenterInstances Query asset information Queries asset information by settings conditional query criteria, such as asset instance name or asset instance region. Both paging and NextToken methods are supported. The NextToken method is recommended.
DescribeSummaryInfo DescribeSummaryInfo Queries the security information about your assets. The information includes the security score and the numbers of protected and unprotected assets.
DescribeSearchCondition DescribeSearchCondition Queries the filter conditions that are used to search for assets.
DescribeCriteria Query conditions for asset queries Queries the fuzzy match conditions for asset properties that can be displayed when you query assets.
DescribeVpcList DescribeVpcList Queries the information about virtual private clouds (VPCs).
DescribeAssetDetailByUuids Query asset details Queries the details of an asset (ECS instance).
DescribeImageStatistics Query risk statistics information of container image assets Queries the risk statistics information of container image assets.
DescribeContainerStatistics Query alert statistics of container assets Queries the alert statistics of container assets.
ModifyAssetGroup Modify an asset group Modifies an asset group.
InstallCloudMonitor Install cloudMonitor agent Installs the CloudMonitor agent on a specified server.
DescribeSasPmAgentList Query O&M plug-in status list Queries the status list of O&M plug-ins.
ListAssetCleanConfig ListAssetCleanConfig Queries the configurations for cleaning offline hosts whose provider cannot be identified.
ModifyAssetCleanConfig Modify offline host cleanup configuration Modifies the cleanup configuration for offline hosts. Only non-Alibaba Cloud hosts are supported.
ListAssetRefreshTaskConfig Get asset refresh configuration Retrieves the asset refresh configuration.
ChangeAssetRefreshTaskConfig ChangeAssetRefreshTaskConfig Modifies the interval of asset synchronization configurations.
ListCloudVendorRegions ListCloudVendorRegions Queries the synchronization region configurations of other clouds on a site.
AddCloudVendorAccountAK Add multi-cloud asset authorization configuration Adds multi-cloud asset configuration information.
DeleteCloudVendorAccountAK DeleteCloudVendorAccountAK Delete multi-cloud asset synchronization configuration.
DescribeCloudVendorAccountAKList DescribeCloudVendorAccountAKList Queries the multi-cloud assets added to Security Center.
DescribeCloudVendorTrialConfig Query Third-Party Cloud Asset Audit Log Access Configuration Query the trail configuration attributes of the corresponding AK configuration
ModifyCloudVendorTrialConfig Modify the audit log configuration information for multi-cloud access Modify the Trail configuration information for the AK
ModifyCloudVendorAccountAK Modify multi-cloud asset authorization configuration Modifies the authorization and authentication configuration of multi-cloud assets.
AddCloudVendorTrialConfig Add audit log access configuration for third-party cloud assets Adds an audit log access configuration for third-party cloud assets.
GetLocalDefaultRegion Retrieve default local region Retrieves the default synchronization region for synchronizing off-cloud assets.
SetSyncRefreshRegion Set asset refresh and sync region list Sets the region list for asset refresh and synchronization.
GetSupportedModules Retrieve module information supported by multi-cloud vendors Retrieves the list of modules supported for authorization.

Asset fingerprints

API

Title

Description

DescribeAssetsScaProcessNum DescribeAssetsScaProcessNum Queries the number of Java processes in an asset by using the asset fingerprints feature of Security Center.
DescribePropertyUsageTop Query asset fingerprints statistics by type Retrieves the top 5 statistics information for ports, processes, software, accounts, or middleware by occurrence count in your assets using the Asset Fingerprints feature.
DescribePropertyScaProcessDetail DescribePropertyScaProcessDetail Queries the Java processes that are collected by the asset fingerprints feature of Security Center in your assets.
GetPropertyScheduleConfig Query asset fingerprints collection cycle configuration Queries the collection cycle configuration of Asset Fingerprints.
GetAssetsPropertyItem Query asset fingerprints aggregated list Queries the aggregated list of Asset Fingerprints for startup items, kernel modules, or websites.
GetAssetsPropertyDetail Query asset fingerprints detail list Queries the details of Asset Fingerprints for startup items, kernel modules, or web sites.
DescribePropertyTypeScaItem DescribePropertyTypeScaItem Queries middleware types.
DescribePropertyCronItem DescribePropertyCronItem Queries the scheduled tasks of your assets.
DescribePropertyScaItem DescribePropertyScaItem Queries middleware fingerprints.
DescribePropertyCronDetail Query asset fingerprints scheduled task list details Queries the details of scheduled tasks in the host asset fingerprint list.
DescribePropertyCount DescribePropertyCount Queries the statistics of asset fingerprints. The assets include processes, ports, software, accounts, middleware, websites, web services, scheduled tasks, startup items, and databases.
DescribePropertyPortDetail Query Asset Fingerprint Information of Port Assets Query Details of Asset Fingerprint Port Collection
DescribePropertyProcDetail Query asset fingerprints of process assets Queries the Asset Fingerprints information of process assets on a server.
DescribePropertyPortItem Retrieve all port information Retrieves information about all ports.
DescribePropertyProcItem DescribePropertyProcItem Queries information about all processes.
DescribePropertySoftwareDetail Retrieve detailed information of a software in the software list Query details of asset fingerprint software collection
DescribePropertySoftwareItem DescribePropertySoftwareItem Queries information about all software assets.
DescribePropertyUserDetail Query account asset fingerprint information of a server Queries the Asset Fingerprints information of account assets on a server.
DescribePropertyUserItem Retrieve account information of assets Retrieves the account information of assets.
DescribeModuleConfig Retrieve asset fingerprints module settings Queries the settings of the Asset Fingerprints module.
DescribePropertyScaDetail Query details of the middleware list in asset fingerprints investigation Queries the details of the middleware list on the Asset Fingerprints investigation page.
ModifyPropertyScheduleConfig ModifyPropertyScheduleConfig Modifies the collection frequency of asset fingerprints for an automatic periodic collection task.
DescribePropertyScheduleConfig DescribePropertyScheduleConfig Queries the configurations of scheduled tasks of asset fingerprint collection.

Security score

API

Title

Description

GetSecurityScoreRule Query custom security score rule details Queries the details of custom security score rules.
ChangeSecurityScoreRule Modify custom security score rules Modifies custom security score rules.
DescribeSecureSuggestion Query Security Risk Handling Suggestions Details Query Security Risk Handling Suggestions Details

Exposed assets

API

Title

Description

DescribeExposedInstanceCriteria Query conditions supported for querying exposed assets Retrieves the supported query conditions for querying exposed assets.
DescribeExposedInstanceDetail DescribeExposedInstanceDetail Queries the details of a specified server that is exposed on the Internet.
DescribeExposedInstanceList Query information about internet-exposed assets Queries information about assets exposed on the Internet.
DescribeExposedStatistics Query the statistics of asset exposure analysis Queries the statistics of asset exposure analysis.
DescribeExposedStatisticsDetail Details of exposed asset statistics Queries the list of gateway assets, ports, system components, or public IP addresses that are exposed on the Internet.

Container management

API

Title

Description

ListUuidsByAppId Query serverless instance uUIDs by application ID Queries the list of Serverless instance UUIDs by application ID.
ListMachineApps Query SAE applications of a serverless instance Queries the Serverless Application Engine (SAE) applications of a serverless instance.
DescribeContainerTags DescribeContainerTags Retrieves the details of container assets by using an attribute.
DescribeAssetsSecurityEventSummary Query container asset risk statistics Queries risk statistics for container assets.
DescribeImage Query image digest Queries the digest of an image.
DescribeClusterInfoList DescribeClusterInfoList Queries the information about a cluster.
DescribeContainerCriteria Retrieve supported search criteria for the container list Retrieves the supported search criteria for the container list.
DescribeContainerInstances Retrieve container instance information list Retrieves the list of container instance information.
DescribeImageCriteria Retrieve image search criteria Retrieves image search criteria.
DescribeImageInstances Retrieve image information Retrieves a list of image information.
DescribeImageRepoDetailList Retrieve image repository list Retrieves a list of image repositories.
DescribeImageRepoCriteria Retrieve supported search criteria for image repositories Retrieves the supported search criteria for image repositories.
GetClusterSuspEventStatistics Retrieve container security event statistics Retrieves statistics on container security events.
GetClusterCheckItemWarningStatistics Retrieve baseline check issue count for a container cluster Retrieves the number of baseline check issues for a container cluster.
DescribeGroupedContainerInstances Query container list information Queries the list of containers based on the specified group type.
RefreshContainerAssets Refresh container asset data in the asset center Refreshes container asset data in the asset center.

Container visualization

API

Title

Description

DescribeClusterNetwork Query network topology edge information at the cluster level Queries the network topology edge information at the cluster level.
FindContainerNetworkConnect Query container network connection information Retrieves information about network connectivity between two nodes.

Image security scan

API

Title

Description

UpdateWhiteList Update the IP address whitelist of an image repository Updates the IP address whitelist of an image repository.
GetRegistryScanDayNum Query image security scan time range Queries the time range for image security scanning.
GetDockerhubImageRiskStatistic GetDockerhubImageRiskStatistic Queries the risk statistics of Docker Hub images.
ListImageRegistryExtra Query extra configuration information of an image repository Queries the extra configuration information of an image repository.
RefreshRegistryToken RefreshRegistryToken Updates an image token.
SetBuildRiskDefineRuleConfig Modify risk scan configuration for image build instructions Modifies the risk scan configuration for image build instructions.
GetBuildRiskDefineRuleConfig Query risk scan configuration for image build commands Queries the risk scan configuration for image build commands.
ListPrivateRegistryType Query the number of image repositories of each type Queries the number of image repositories of each type.
ListPrivateRegistryList ListPrivateRegistryList Retrieves image repositories.
DescribeCountNotScannedImage DescribeCountNotScannedImage Queries the number of images that are not scanned.
GetImageScanNumInPeriod GetImageScanNumInPeriod Queries the number of image scans that are performed within the last several days.
SetRegistryScanDayNum SetRegistryScanDayNum Specifies a cycle to scan images for image repositories. Unit: days.
SaveImageBaselineStrategy SaveImageBaselineStrategy Creates or updates an image baseline strategy.
OperateImageBaselineWhitelist Manage image baseline whitelist Manages the whitelist of image baseline check items.
DescribeImageBaselineStrategy Query image baseline policy Queries the image baseline policy.
DescribeImageBaselineItemList Query baseline check items by image Queries the list of baseline check results by image.
DescribeImageBaselineDetail Query image baseline check result details Queries the details of baseline check results for image scanning.
DescribeImageBaselineCheckResult Query image baseline check results Queries the detection results of image security scans.
DescribeAllImageBaseline Retrieve all image baseline check items Retrieves the list of all image baseline check items.
DescribeImageListBySensitiveFile Query images with sensitive files Queries information about images affected by sensitive files.
OpenSensitiveFileScan Edit sensitive file scan switch Modifies the sensitive file scan switch.
DescribeImageSensitiveFileList Query sensitive files Queries sensitive file information.
DescribeImageSensitiveFileByKey Query sensitive files of an image Queries the sensitive files of an image.
DescribeAffectedMaliciousFileImages Query malicious file details in container images Queries the details of malicious files detected in container images.
DescribeGroupedMaliciousFiles Query malicious sample files in container images Queries the list of malicious sample files in container images.
DescribeImageVulList Query container image vulnerability list Queries the details of vulnerabilities detected by image security scans and the list of container images affected by the vulnerabilities.
DescribeImageGroupedVulList Query image vulnerability information Queries the list of image vulnerabilities.
DescribeImageListWithBaselineName Query image baseline check result details Queries the details of image baseline check results.
DescribeImageFixTask Query the list of created image repair tasks Queries the list of created image repair tasks.
DescribeImageScanAuthCount Query image security scan authorization information Queries the authorization quota information for image security scanning.
DescribeImageBaselineCheckSummary Query image baseline check list for image security scans Queries the image baseline check list of image security scans.
PublicPreCheckImageScanTask PublicPreCheckImageScanTask Queries the number of images to scan in an image scan task and the quota for container image scan to be consumed by the task.
PublicCreateImageScanTask Create an image scan task Creates an image scan task that is not limited by a single primary task.
PublicSyncAndCreateImageScanTask PublicSyncAndCreateImageScanTask Adds images to Security Center and creates an image scan task to scan the images.
DescribeCountScannedImage Query scanned image statistics Queries statistics on scanned image data.

Cloud platform configuration check

API

Title

Description

CreateCheckPolicy Create Custom Check Policy Category Create Policy
CreateCheckItem Create a custom check item Creates a custom check item in the Cloud Security Posture Management (CSPM) custom check item feature.
DeleteCheckItem Delete custom check items Deletes user-defined check items in the Cloud Security Posture Management (CSPM) custom check item feature.
ListCheckItems Query Custom Check Items List custom check items for situational awareness
UpdateCheckPolicy Modify Custom Check Item Policy Classification Settings Update Custom Policy
GetCheckSale Retrieve cloud service configuration check sales information Retrieves the sales information of cloud service configuration check, including the number of authorized quotas and consumed quotas.
ModifyCheckRule Modify CSPM check rules Modifies the rule settings of Cloud Security Posture Management (CSPM).
VerifyCheckInstanceResult Verify instances for a check item Performs instance-level verification for a check item.
VerifyCheckResult Validate check items Validates check items.
GetCloudAssetCriteria GetCloudAssetCriteria Queries the filter conditions that are used to search for cloud assets.
RemoveCheckResultWhiteList RemoveCheckResultWhiteList Removes the check items of the configuration assessment feature from the whitelist.
AddCheckResultWhiteList Add check items to whitelist Adds check items to the whitelist for cloud platform configuration checks.
RemoveCheckInstanceResultWhiteList Remove whitelist status at the instance dimension Removes the whitelist status at the instance dimension.
AddCheckInstanceResultWhiteList Add instances to whitelist for a check item Adds instances to the whitelist at the instance level for a specific check item in cloud platform configuration checks.
GetCheckSummary Retrieve cloud platform configuration check overview Retrieves the overview of cloud platform configuration checks.
ListInstanceCatalog ListInstanceCatalog Queries the asset types and asset subtypes for configuration assessment.
GetCheckProcess Query cloud platform configuration check task progress Queries the progress of a cloud platform configuration check task.
SubmitCheck Submit a cloud service configuration check Submits a cloud service configuration check.
ChangeCheckConfig Modify cloud platform configuration check items Modifies the configuration items for cloud platform configuration checks.
GetCheckConfig Retrieve check item configurations for cloud platform configuration checks Retrieves the check item configurations for cloud platform configuration checks.
GetCheckDetail GetCheckDetail Queries the details about a check item that is used for configuration assessment.
GetCheckCountStatistic GetCheckCountStatistic Queries statistics on the number of risk items in cloud security posture management (CSPM) for cloud services.
GetCheckTimeDimensionStatistic Retrieve time trend statistics for CSPM risk items Retrieves the time trend pass rate statistics for Cloud Security Posture Management (CSPM) risk items.
ListCheckInstanceResult Retrieve instances under a check item Retrieves instances that failed a cloud platform configuration check item.
ListCheckResult ListCheckResult Retrieves the details of the risk items that are detected in the configuration checks on cloud services.
ListCheckStandard ListCheckStandard Queries the standards of configuration checks.
ListCheckItem Retrieve the list of configurable custom check item templates Retrieves the list of check items that can be configured with custom settings.
StartBaselineSecurityCheck StartBaselineSecurityCheck Checks cloud service configurations. You can check all items or a specific item and verify whether an item is checked.
ModifySecurityCheckScheduleConfig Set automatic detection time for cloud platform configuration check items Sets the automatic detection time for cloud platform configuration check items.
DescribeRiskItemType Query the types of all cloud service configuration check items Queries the types of all cloud service configuration check items.
DescribeRiskCheckSummary Query cloud service configuration check result summary Queries the summary of cloud service configuration check results, including the number of risk items, risk rate, number of affected assets, check time, and statistics by type.
DescribeRiskCheckResult DescribeRiskCheckResult Queries the check results of cloud service configurations by check item type or name.
DescribeSecurityCheckScheduleConfig Query custom check cycle and time period Queries the custom check cycle and time period configured by the user.
DescribeRiskCheckItemResult DescribeRiskCheckItemResult Queries the assets that are affected by the risk item detected in configuration assessment based on a specified check item.
DescribeRiskListCheckResult DescribeRiskListCheckResult Queries the number of risk items detected in the configuration assessment of one or more cloud services by using the instance IDs of the cloud services.
ListCheckRule Query Cloud Security Posture Management Check Rules Display cloud product configuration check rules
ListCheckRuleInstance Query instances of a CSPM rule Queries all instances under a Cloud Security Posture Management (CSPM) rule.
ListOperationCheck View details of a fix or rollback task Queries the details of a one-click fix or rollback task for cloud platform configuration checks.
ListOperationTask Query Cloud Security Posture Management Operation Tasks Display the list of cloud product configuration check, repair, and rollback tasks
VerifyCheckCustomConfig Validate threat detection service custom configuration Authenticates whether the configuration information entered by a user is compliant with the requirements of the corresponding parameter settings.
ChangeCheckCustomConfig Modify custom configuration of a check item Modifies the custom configuration of a check item.
ListCheckPolicies Query Custom Check Item Policy Classification List User Policies
UpdateCheckItem Update a custom check item Updates a custom check item in the Cloud Security Posture Management (CSPM) custom check item feature.
DeleteCheckPolicy DeleteCheckPolicy Delete custom scope directories in Cloud Security Posture Management (CSPM) custom checks. You can remove assigned standards, requirements, or sections.

Anti-ransomware

API

Title

Description

DeleteBackupSnapshot Delete backup snapshots Deletes snapshots of anti-ransomware backups in Security Center.
CreateRestoreJob CreateRestoreJob Creates a restoration task.
UninstallUniBackupAgent UninstallUniBackupAgent Uninstalls the database backup agent.
StartPreCheckDatabase StartPreCheckDatabase Starts a database precheck task.
StartDiscoverDatabaseTask StartDiscoverDatabaseTask Starts a database scan task.
QueryPreCheckDatabase Query database pre-check task result Queries the result of a database pre-check node.
QueryDiscoverDatabase QueryDiscoverDatabase Queries the progress of a database scan task.
ModifyUniBackupPolicy Update anti-ransomware policy for databases Modifies an anti-ransomware backup policy for databases.
InstallUniBackupAgent Install anti-ransomware client for databases Installs the anti-ransomware client for databases.
DescribeUniSupportRegion DescribeUniSupportRegion Queries the region that is supported by anti-ransomware for databases.
DescribeUniRecoverableList Query recoverable database backups Queries the list of recoverable database backups.
DescribeUniBackupPolicyDetail Query anti-ransomware policy details for databases Queries the details of an anti-ransomware backup policy for databases.
DescribeUniBackupPolicies Query anti-ransomware policies for databases Queries the list of anti-ransomware policies for databases.
DescribeUniBackupDatabase Query anti-ransomware databases Queries the details of databases in database protection policies.
DescribeRestorePlans DescribeRestorePlans Queries restoration tasks.
DeleteUniBackupPolicy DeleteUniBackupPolicy Deletes anti-ransomware policies that are created for databases.
CreateUniRestorePlan Create a database anti-ransomware restoration task Creates a recovery task for database anti-ransomware.
CreateUniBackupPolicy Create a database anti-ransomware policy Creates a database anti-ransomware policy.
DescribeBackupMachineStatus Query backup server status Queries the backup status of servers associated with an anti-ransomware backup policy.
UpgradeBackupPolicyVersion Upgrade anti-ransomware backup policy version Upgrades the version of an anti-ransomware backup policy.
DescribeExcludeSystemPath Query anti-ransomware system excluded directories Queries the excluded directories of the anti-ransomware system.
CreateBackupPolicy Create an anti-ransomware policy Creates an anti-ransomware policy for servers.
InstallBackupClient Install anti-ransomware client Installs the anti-ransomware client.
GetBackupStorageCount Query used anti-ransomware storage capacity Queries the used anti-ransomware storage capacity.
DescribeBackupClients Query servers with the anti-ransomware client installed in a specified region Queries servers that have the anti-ransomware client installed in a specified region.
DescribeBackupPolicies Query anti-ransomware policies Queries anti-ransomware mitigation policies.
DescribeSupportRegion Query regions supported by anti-ransomware Queries the regions supported by anti-ransomware.
DescribeUserBackupMachines Query servers with anti-ransomware backup policies enabled Queries servers that have anti-ransomware backup policies enabled.
DescribeRestoreJobs DescribeRestoreJobs Queries the details about restoration tasks.
DescribeBackupRestoreCount Query anti-ransomware restoration tasks Queries data of anti-ransomware restoration tasks.
ModifyBackupPolicyStatus Enable or shutdown an anti-ransomware policy Enables or shuts down an anti-ransomware policy.
DeleteBackupPolicyMachine DeleteBackupPolicyMachine Deletes a server from a specified anti-ransomware policy.
DeleteBackupPolicy Delete ransomware mitigation policies Deletes ransomware mitigation policies.
UninstallBackupClient UninstallBackupClient Uninstalls the anti-ransomware agent.

Web tamper-proofing

API

Title

Description

DescribeWebLockStatus Query tamper-proofing protection status Queries the tamper-proofing protection status.
DescribeWebLockFileEvents DescribeWebLockFileEvents Queries events on web tamper proofing.
ModifyWebLockDeleteConfig Delete a protected directory from a specified server Deletes a protected directory from a specified server.
ModifyWebLockCreateConfig Add a protected directory for a specified server Adds a protected directory for a specified server.
ModifyWebLockUpdateConfig Modify the protection policy of a specified server Modifies the protection policy of a specified server.
ModifyWebLockStart Create web tamper proofing protection for a server and enable the protection Creates web tamper proofing protection for a specified server and enables the protection.
DescribeWebLockConfigList DescribeWebLockConfigList Queries the configurations of web tamper proofing for a specified server.
DescribeWebLockBindList Query web tamper-proofing server list Retrieves the list of servers that have web tamper-proofing protection enabled.
ModifyWebLockStatus Modify web tamper-proofing status Enables or shuts down web tamper-proofing for a server.
ModifyWebLockUnbind Remove web tamper proofing from a server Removes the web tamper proofing protection folder from a specified server.
OperateWebLockFileEvents Handle web tamper-proofing alerting events Handles web tamper-proofing alerting events.
ModifyWebLockProcessStatus Set tamper-proofing process status Sets the status of a tamper-proofing process.
JoinWebLockProcessWhiteList JoinWebLockProcessWhiteList Adds processes to the process whitelist of web tamper proofing.
DescribeWebLockTotalFileChangeCount DescribeWebLockTotalFileChangeCount Queries the number of times that the files protected by web tamper proofing are changed.
DescribeWebLockProcessList DescribeWebLockProcessList Queries the processes for web tamper proofing.
DescribeWebLockProcessBlockStatistics DescribeWebLockProcessBlockStatistics Queries the statistics on processes for web tamper proofing.
DescribeWebLockInclusiveFileType Query tamper-proofing file types Queries the file types supported by tamper-proofing protection.
DescribeWebLockFileTypeSummary Query WebLock File Type Summary Queries the WebLock file type summary.
DescribeWebLockFileChangeStatistics Query file change statistics for web tamper-proofing Queries the file change statistics for web tamper-proofing.
DescribeWebLockExclusiveFileType DescribeWebLockExclusiveFileType Queries the types of files that are excluded from web tamper proofing.

Virus scan

API

Title

Description

DescribeSuspiciousUUIDConfig DescribeSuspiciousUUIDConfig Queries the UUIDs of servers on which proactive defense of a specified type takes effect.
DescribeLatestScanTask Query latest virus scan Queries the progress of the most recent virus scan task.
CreateVirusScanOnceTask Create a one-time virus scan task Creates a one-time virus scan task.
ListVirusScanMachine Query alert hosts for virus scanning Queries the list of alert hosts for virus scanning.
GetVirusScanLatestTaskStatistic Retrieve the latest virus scan information Retrieves the scan information of the latest virus scan.
ListVirusScanMachineEvent Query alert events detected by server scan Queries virus alerts detected by a virus scan on a specific server.
ListVirusScanTask Query virus scan tasks Queries virus scan tasks that match specified conditions such as scan type, scan status, and scanned machine information.
GetVirusScanConfig Retrieve periodic virus scan configuration Retrieves the configuration of a periodic virus scan task.
OperateSuspiciousTargetConfig OperateSuspiciousTargetConfig Configures the scope on which proactive defense takes effect.
OperateVirusEvents Handle virus defense alerts Handles virus defense alerts in batches. The handling types include deep scan and removal, adding to whitelist, ignoring, and manual handling.

Security alert

API

Title

Description

DescribeGraph4InvestigationOnline Query the investigation and tracing graph of an alert event Queries the investigation and tracing graph of a Cloud Workload Protection Platform (CWPP) alert event to visually investigate and reconstruct the cyberattack process.
DescribeSecurityEventMarkMissList Query alert whitelist rules Queries the auto-whitelist rules for security alerts.
DeleteSecurityEventMarkMissList Delete alert whitelist configurations Deletes alert whitelist configurations in batches.
ExportSuspEvents Export anomaly alert information Exports anomaly alert information.
DeleteSuspEventNode Delete a security alert note Deletes a note from a security alert.
AdvanceSecurityEventOperations Query advanced whitelist editing information Queries the advanced whitelist editing information.
DescribeBackUpExportInfo Retrieve security alert archive data export list Retrieves the list of exported security alert archive data.
DescribeLoginSwitchConfigs DescribeLoginSwitchConfigs Queries the alerting status for unapproved logon IP addresses, unapproved logon time ranges, or unapproved logon accounts.
DescribeWebPath Query custom web directories for security alerts Queries custom web directories for security alerts.
ListUuidsByWebPath Query protected assets by web path Queries protected assets by web path.
ModifyWebPath ModifyWebPath Modifies a custom web directory.
GetAlarmMachineCount Retrieve the number of servers with alerts Retrieves the number of servers that currently have security alerts.
DescribeSuspEventExportInfo DescribeSuspEventExportInfo Queries the information about an export task of exceptions.
DescribeNsasSuspEventType Query security alerting Alarm Metric Queries security alerting Alarm Metric.
HandleMaliciousFiles Add or remove security alerts to or from the whitelist Adds or removes security alerts detected by the agentless detection feature to or from the whitelist.
DescribeStrictEventName Query Alarm Names in Strict Mode Strict mode supports alarm queries
UpdateStrictEventName Modify strict mode alert status Modifies the strict mode configuration, including whether to enable alerting in strict mode. This is a full-update operation.
CreateSuspEventNote Create a note for a security alert event Creates a note for a security alert event.
QueryGroupedSecurityEventMarkMissList QueryGroupedSecurityEventMarkMissList Queries whitelist rules.
OperationCancelIgnoreSuspEvent Unignore anomaly alerting events Settings the specified anomaly alerting events to unignored.
CreateSimilarSecurityEventsQueryTask Create a node to query alerting events triggered by the same rule or Alarm Metric Creates a node to query alerting events triggered by the same rule or Alarm Metric.
DescribeAlarmEventDetail Retrieve alert event details Retrieves the details of a security alert event. Alert events are categorized into alerts and exceptions. An alert event contains multiple exception events.
DescribeSuspEventDetail DescribeSuspEventDetail Queries the details of an exception. An alert event consists of an alert and exceptions. Each alert event is associated with multiple exceptions.
DescribeSimilarSecurityEvents DescribeSimilarSecurityEvents Queries alert events that are triggered by the same rule or of the same alert type.
DescribeSimilarEventScenarios Query handling scenarios for alerts with the same trigger Queries the handling scenarios for alerts triggered by the same rule or type.
DescribeSecurityStatInfo Query statistics and trend data of security check items Queries the statistics of each security check item and the daily statistics in the security check item trend chart.
DescribeLoginBaseConfigs Query unusual logon detection rule configurations Queries the configuration of unusual logon detection rules for servers.
GetSuspiciousStatistics Query security alert counts by asset group Queries the statistics on the number of security alerts in one or more asset groups.
CheckSecurityEventId CheckSecurityEventId Checks whether one or more alerts are generated on a specified server based on alert IDs.
DescribeAttackAnalysisData DescribeAttackAnalysisData Queries the statistics of attack analysis.
HandleSimilarSecurityEvents Batch process alert events based on the same IP rule or type Batch processes alert events based on the same IP rule or type.
OperationSuspEvents Handle alert events in batches Handles alert events in batches.

Brute-force attack prevention

API

Title

Description

ModifyCustomBlockRecord Modify custom rule for brute-force attacks IP blocking Modifies the rule record of a custom blocked IP address.
EnableCustomBlockRecord EnableCustomBlockRecord Enables a custom IP address blocking policy.
EnableBruteForceRecord EnableBruteForceRecord Enables an IP address blocking policy for a specified server.
DisableBruteForceRecord DisableBruteForceRecord Disables an IP address blocking policy that is in effect.
DisableCustomBlockRecord DisableCustomBlockRecord Disables a custom IP address blocking policy for servers.
DescribeBruteForceRecords DescribeBruteForceRecords Queries the IP addresses that are blocked by a defense rule against brute-force attacks.
DeleteCustomBlockRecord Delete a custom IP blocking policy Deletes the blocking records of specific IP addresses that are custom-defined on one or more servers.
CreateCustomBlockRecord Add custom IP blocking policies Adds custom IP blocking policies for one or more specific servers based on your requirements.
CreateAntiBruteForceRule CreateAntiBruteForceRule Creates a defense rule against brute-force attacks.
ModifyAntiBruteForceRule Modify a defense rule against brute-force attacks Modifies a defense rule against brute-force attacks.
ModifyInstanceAntiBruteForceRule Modify the anti-brute-force attacks rule for a specified server Modifies the anti-brute-force attacks rule for a specified server.
DescribeBruteForceSummary DescribeBruteForceSummary Queries the statistics of IP address blocking policies that are used to defend against brute-force attacks and trigger alerts.
DescribeInstanceAntiBruteForceRules Query servers on which brute-force attacks defense rules take effect Queries information about servers on which brute-force attacks defense rules take effect.
DescribeAntiBruteForceRules Query brute-force attacks prevention rules Queries the brute-force attacks prevention rules that you have created.
DeleteAntiBruteForceRule Delete an anti-brute-force rule Deletes a specified anti-brute-force attacks rule.

Vulnerability fix

API

Title

Description

ListVulGlobalConfig Query vulnerability global configuration Queries the global configuration of vulnerabilities.
ModifyRefreshProcessInfo ModifyRefreshProcessInfo Refreshes the list of processes that are associated with a Linux software vulnerability.
OperateImageVul Operate on image vulnerabilities Performs operations on image vulnerabilities. Supported operation types include fix, verify, ignore, and unignore.
ModifyVulTarget Modify machine-level toggle settings for vulnerability scanning Modifies the machine-level toggle settings for vulnerability scanning.
ModifyVulConfig Modify vulnerability scanning toggle configuration Modifies the vulnerability scanning toggle configuration.
ModifyConcernNecessity Set the urgency levels of vulnerabilities that the user is concerned about Sets the urgency levels of vulnerabilities that the user is concerned about.
ModifyAutoDelConfig Set automatic deletion time for expired vulnerabilities Sets the automatic deletion time for expired vulnerabilities.
ModifyAppVulScanCycle ModifyAppVulScanCycle Configures a scan cycle for application vulnerabilities.
DescribeVulTargetStatistics Retrieve vulnerability switch configurations Retrieves the list of vulnerability switch configurations.
DescribeVulTargetConfig DescribeVulTargetConfig Queries the configurations of the vulnerability scan feature for a server.
DescribeVulNumStatistics Get vulnerability statistics Get vulnerability statistics.
DescribeVulListPage DescribeVulListPage Queries the vulnerabilities that can be detected.
DescribeVulCheckTaskStatusDetail Query vulnerability scanning node status for a server Queries the status of a vulnerability scanning node for a specified server.
DescribeTaskErrorLog Query error logs of a failed image fix task Queries the error logs of a failed image fix task.
DescribeTarget Query vulnerability machine list Queries the machine list settings for vulnerability scanning.
DescribeMachineCanReboot Query whether a server can be restarted Checks whether a server can be restarted when a vulnerability fix requires a restart to take effect.
DescribeEmgUserAgreement Query emergency vulnerability user agreement Queries the emergency vulnerability user authorization agreement.
DescribeClusterVulStatistics Query cluster vulnerability statistics Queries cluster vulnerability statistics.
DescribeAppVulScanCycle Query application vulnerability scanning epoch Queries the application vulnerability scanning epoch.
DescribeVulConfig Query vulnerability management configuration Queries vulnerability management configuration information.
DescribeVulFixStatistics DescribeVulFixStatistics Queries the statistics of vulnerability fixes.
DescribeUuidsByVulNames Retrieve servers that support vulnerability fixing by vulnerability name Retrieves the list of servers that support vulnerability fixing based on vulnerability names.
ListVulAutoRepairConfig Query auto-fix vulnerability configurations Queries the configurations of vulnerabilities that can be automatically fixed.
CreateVulAutoRepairConfig Batch create auto-fixable vulnerability lists Creates a batch list of vulnerabilities that can be automatically fixed. After creation, the list is used for vulnerability selection in vulnerability fix tasks in the task center.
DescribeInstanceRebootStatus Query instance restart status Queries the restart status of instances.
RebootMachine Restart an instance Restarts an instance. Currently, only Windows instances are supported.
ModifyVulTargetConfig Configure vulnerability detection settings for a single server Configures the vulnerability detection settings for a single server.
ModifyStartVulScan Trigger one-click vulnerability scan Enables the one-click scan feature on the vulnerability management page of the console.
ModifyEmgVulSubmit Perform emergency vulnerability detection Performs emergency vulnerability detection.
ModifyCreateVulWhitelist Add a vulnerability whitelist Adds a vulnerability whitelist. Vulnerabilities added to the whitelist are no longer displayed in the alert list.
GetVulWhitelist GetVulWhitelist Retrieves information about a vulnerability whitelist.
DeleteVulWhitelist Delete a specified vulnerability whitelist Deletes a specified vulnerability whitelist.
DescribeEmgVulItem Query emergency vulnerability information Queries the details of emergency vulnerabilities.
DescribeAutoDelConfig DescribeAutoDelConfig Queries the number of days during which a detected vulnerability is retained before the vulnerability is automatically deleted.
DescribeConcernNecessity Query necessity information for fixing followed vulnerabilities Queries the necessity information for fixing vulnerabilities that you follow.
DescribeVulWhitelist Query vulnerability whitelist by page Queries vulnerability whitelist entries by paging.
ExportVul Export vulnerability list Exports a vulnerability list.
DescribeVulExportInfo Query the progress of a vulnerability export task Queries the progress of a vulnerability export task.
GetVulStatistics GetVulStatistics Queries the statistics on vulnerabilities in asset groups.
ModifyVulWhitelistTarget ModifyVulWhitelistTarget Modifies the servers that are added to a vulnerability whitelist.

Baseline check

API

Title

Description

ListBaselineCheckWhiteRecord Query baseline whitelist records Queries baseline whitelist records.
ListCheckItemWarningSummary Retrieve baseline check item risk statistics Queries statistics on risks generated by check items by paging.
ListCheckItemWarningMachine Get Warning Machines for a Specific Baseline Check Item Query the list of warning machines for a specific baseline check item.
DescribeWarningExportInfo DescribeWarningExportInfo Queries the progress of a export task for a baseline check result.
DescribeHcExportInfo Query baseline risk export information Queries information about a baseline risk export, such as the file name and download link.
DescribeRisks Query baseline details Queries baseline details by baseline ID or name.
DescribeCheckWarningMachines DescribeCheckWarningMachines Queries the servers on which the same risk item is detected by specifying a baseline and a check item.
DescribeCheckFixDetails Query check item fix details Queries the configurable parameters for fixing a specified check item.
IgnoreCheckItems IgnoreCheckItems Adds risk items to the whitelist or removes risk items from the whitelist by specifying servers and risk items.
DescribeExposedCheckWarning Query baseline weak password risks of exposed assets Queries the weak password risks of a specified exposed server.
GetCheckRiskStatistics GetCheckRiskStatistics Queries the statistics on risk scenarios and check items that are used in the risk scenarios, including the statistics on low-risk, medium-risk, and high-risk items by baseline type.
ModifyStrategy ModifyStrategy Modifies a baseline check policy.
ModifyStrategyTarget ModifyStrategyTarget Modifies the servers to which a baseline check policy is applied.
DescribeCheckWarningSummary Query baseline check result statistics Queries the statistics of baseline check results, such as the number of servers checked, the number of check items, and the latest check pass rate.
DescribeRiskType DescribeRiskType Queries baseline types.
DescribeCheckWarnings Query check item information Queries check item information for a specified risk item and a specified server.
DescribeCheckWarningDetail Query details of a specified check item Queries the details of a specified check item.
DescribeWarningMachines DescribeWarningMachines Queries information about servers on which a baseline check is performed. The information includes the IDs of the servers, the statistics of a risk item, and the status of the risk item.
DescribeStrategyExecDetail DescribeStrategyExecDetail Queries the results of the last baseline check by using a specified baseline check policy.
DescribeCheckEcsWarnings Query the number of high-risk weak password risks Queries the number of high-risk weak password risks that exist in your assets.
DescribeUserBaselineAuthorization Query cloud platform authorization status Queries the status of cloud platform authorization information for a user.
DescribeStrategyDetail Retrieve baseline check policy details Retrieves the details of a baseline check policy.
ExportWarning ExportWarning Exports baseline check results.
DescribeStrategy DescribeStrategy Queries the details about baseline check policies.
DescribeStrategyTarget DescribeStrategyTarget Queries the information about the assets to which a baseline check policy is applied.
DeleteStrategy Delete a policy Deletes a baseline check policy.
ValidateHcWarnings Verify baseline check risk items in batches Verifies existing baseline risks. If the verification passes, the status of the risk items is updated to passed.
FixCheckWarnings Fix baseline check risk items Fixes baseline check risk items.
AddBaselineCheckWhiteRecord AddBaselineCheckWhiteRecord Creates a whitelist rule for a baseline check item.
IgnoreHcCheckWarnings IgnoreHcCheckWarnings Ignores or cancels ignoring multiple baseline risk items at a time.
DescribeCustomizedStrategyTargets Query custom policy targets Queries the target machines included in a custom policy.
ListCheckTypes ListCheckTypes Queries the types of check items that meet the specified conditions based on the ID of a baseline.
CreateDynamicDict CreateDynamicDict Creates a dynamic dictionary of weak passwords.
UpdateBaselineCheckWhiteRecord Update a baseline whitelist record Updates a baseline whitelist record.
DeleteCustomizedDict Delete a custom weak password Deletes a custom weak password file.
DescribeDefaultKeyInfo Query default key information Retrieves the keywords used to generate a custom dictionary in custom weak password detection.
CreateUserSetting Save user baseline check settings Saves the risk level settings for baseline checks of a user.
ExecStrategy Execute a baseline check policy Performs a baseline check on machines within a specified policy.
DeleteBaselineCheckWhiteRecord DeleteBaselineCheckWhiteRecord Deletes the whitelist record for a baseline check item.

Malicious behavior defense

API

Title

Description

ListSystemRuleAggregationTypes Query aggregation types of system rules Queries the aggregation types of system defense rules.
ListClientUserDefineRules ListClientUserDefineRules Queries custom defense rules.
ListSystemClientRuleTypes Query system rule types effective for a user Queries the system rule types.
ListSystemClientRules ListSystemClientRules Queries system defense rules.
ListSystemAggregationRules Retrieve details of system rule clusters Retrieves the details of system rule clusters.
ModifyClientUserDefineRule Modify a client custom rule Modifies a custom rule for malicious behavior defense.
ListClientUserDefineRuleTypes ListClientUserDefineRuleTypes Queries the supported types of custom defense rules.
GetRulesCount Query the number of system defense rules and user-defined rules Queries the number of system defense rules and user-defined rules.
GetClientUserDefineRule Get client user-defined rules Queries custom rules for malicious behavior defense.
DeleteClientUserDefineRule DeleteClientUserDefineRule Deletes specified custom defense rules.
AddClientUserDefineRule Add a user-defined rule Creates a user-defined defense rule.

AK leak detection

API

Title

Description

ModifyAccessKeyLeakDeal Handle accessKey leak records Handles AccessKey leak records.
DescribeAccesskeyLeakList Query leaked accessKey information Queries information about leaked AccessKey pairs in your assets.
DescribeAccessKeyLeakDetail Query accessKey leak event details Queries the details of an AccessKey pair leak event.

Honeypot

API

Title

Description

DeleteHoneypotProbeBind DeleteHoneypotProbeBind Delete the probe service.
GetHoneypotAttackStatistics Query attack event statistics information of a honeypot attack source Queries the attack event statistics information of a honeypot attack source.
GetHoneypotStatistics GetHoneypotStatistics Get statistics on honey pot usage.
ListAvailableHoneypot Query available honeypot configuration templates Queries available honeypot configuration templates.
CreateHoneypotNode Create a honeypot management node Creates a honeypot management node.
UpdateHoneypotNode Update a honeypot management node Updates a specified honeypot management node.
ListHoneypotNode ListHoneypotNode Queries the information about management nodes.
DeleteHoneypotNode DeleteHoneypotNode Deletes a specified management node.
GetHoneypotNode GetHoneypotNode Retrieves the details of a specified management node.
CreateHoneypot Create a honeypot instance Creates a honeypot instance.
UpdateHoneypot Modify honeypot configuration Modifies the configuration of a specified honeypot.
DeleteHoneypot DeleteHoneypot Deletes a specified honeypot.
ListHoneypot Query honeypot list Queries a list of honeypots.
CreateHoneypotPreset CreateHoneypotPreset Creates a honeypot template.
UpdateHoneypotPreset Modify honeypot template configuration Modifies the configuration of a specified honeypot template.
GetHoneypotPreset GetHoneypotPreset Queries the configurations of a specified honeypot template.
ListHoneypotPreset ListHoneypotPreset Queries honeypot templates.
CreateHoneypotProbe Create a honeypot probe Creates a honeypot probe.
DeleteHoneypotProbe DeleteHoneypotProbe Deletes a specified probe.
UpdateHoneypotProbe Update probe properties Updates the properties of a specified probe.
ListHoneypotProbe Query honeypot probes Queries the list of honeypot probes.
GetHoneypotProbe GetHoneypotProbe Queries the details about a specified probe.
ListHoneypotAlarmEvents ListHoneypotAlarmEvents Queries the information about alert events that are generated.
DeleteHoneypotPreset Delete a honeypot template configuration Deletes a specified honeypot template configuration.
AddVpcHoneyPot AddVpcHoneyPot Creates a honeypot.
DeleteVpcHoneyPot Delete a honeypot Deletes a specified honeypot instance.
ModifyVpcHoneyPot ModifyVpcHoneyPot Enables or disables a honeypot.
DescribeHoneyPotAuth Query the number of authorized honeypot instances Queries the number of authorized honeypot instances.
DescribeHoneyPotSuspStatistics Query top 5 vPCs or assets by security alert count Queries information about the top 5 VPCs or assets ranked by the number of security alerts.
DescribeVpcHoneyPotCriteria DescribeVpcHoneyPotCriteria Queries the search conditions that can be used to query honeypots.
DescribeVpcHoneyPotList Query VPC honeypot probe list Queries the list of VPC honeypot probes.

Log analysis

API

Title

Description

GetLogMeta GetLogMeta Queries the status of a data shipping task of a log.
GetUserLang Query log analysis language settings Queries the log analysis language settings.
ChangeUserLang ChangeUserLang Modifies the language settings of log analysis. The modification on the language settings takes effect within 12 hours and affects only the language of the descriptions for security events in security logs.
ModifyLogMetaStatus Modify log analysis enabling status Modifies the enabling status of log analysis.
DescribeLogMeta Query security center log analysis configuration Queries the configuration information of log analysis in Security Center.
ModifyOpenLogShipper Activate simple log service Activates Simple Log Service.
DescribeLogstoreStorage Query log analysis storage capacity of security center Queries the log analysis storage capacity of Security Center.
ModifyClearLogstoreStorage Clear security center logs Clears the storage capacity space for log analysis.

Notification

API

Title

Description

DingTalkOnlineTest DingTalkOnlineTest Tests whether DingTalk notification configurations are valid.
DeleteDingTalk DeleteDingTalk Deletes a DingTalk chatbot on the DingTalk Chatbot tab of the Notification Settings page.
ModifyDingTalkStatus ModifyDingTalkStatus Changes the notification status of a DingTalk chatbot.
CreateOrUpdateDingTalk CreateOrUpdateDingTalk Creates or modifies a DingTalk chatbot that sends notifications.
ModifyNoticeConfig Modify notification configuration Modifies notification configuration information.
DescribeDingTalk Retrieve dingTalk notification list Retrieves the list of DingTalk notifications.
DescribeNoticeConfig DescribeNoticeConfig Queries notification settings.
DescribeDataSource Query data sources for dingTalk alert configurations Queries the data sources for DingTalk alert configurations. You can configure the scope of DingTalk alert notifications based on the data sources.

Feature settings

API

Title

Description

CreateOrUpdateAutoTagRule CreateOrUpdateAutoTagRule Creates an asset auto-tagging rule or modifies an asset auto-tagging rule that is created on the Asset Management Rule tab.
ListAutoTagRules Query asset tag rules Queries the list of asset tag rules by using the system configuration, feature settings, multi-cloud configuration management, and asset management rule features of Security Center.
DeleteAutoTagRules Delete an automatic asset tagging rule Deletes an automatic asset tagging rule. This operation is used with the system configuration, feature settings, multi-cloud configuration management, and asset management rule features of Security Center.
IgnoreIdcProbeScanResult Whitelist or ignore IDC probe scan results Adds scan results from IDC probes to the whitelist or ignores them.
AddIdcProbe AddIdcProbe Creates an IDC probe to add assets in a data center to Security Center and manage the assets by using the Security Center console.
DeleteIdcProbe Delete an IDC probe Deletes an IDC probe that is created in the IDC probe feature of Security Center.
ModifyIdcProbe ModifyIdcProbe Updates the configurations of an IDC probe.
DescribeCommonOverallConfigList DescribeCommonOverallConfigList Queries the configurations of features in proactive defense.
DescribeCommonTargetConfig DescribeCommonTargetConfig Queries the configurations of the proactive defense feature.
BatchOperateCommonOverallConfig BatchOperateCommonOverallConfig Enables or disables multiple features in proactive defense at a time.
DescribeCommonTargetResultList Query configured assets of a switch Queries the configured asset information for a specific switch type.
OperateSuspiciousOverallConfig Set the global configuration for abnormal events Sets the global configuration for abnormal events.
OperateCommonOverallConfig Set a global switch Configures a global switch based on the specified type.
DescribeCommonOverallConfig Master switch global configuration Queries the global configuration of the master switch.
OperateCommonTargetConfig Configure general switch for feature module Configures the general switch for a feature module by type, including image scanning, endpoint engine detection, container network visualization, and container escape prevention.
DescribeSuspiciousOverallConfig DescribeSuspiciousOverallConfig Queries the configuration of a specified feature.

Export detection results

API

Title

Description

DescribeExportInfo View export progress Queries the progress of an export task.
ExportRecord ExportRecord Exports detection results from various Cloud Security Center features, such as Asset Center, cloud platform configuration check, image security scan, attack analysis, and AK leakage detection, to an Excel file.

Service-linked role

API

Title

Description

DescribeServiceLinkedRoleStatus DescribeServiceLinkedRoleStatus Checks whether a service-linked role is created for Security Center.

Malicious file detection

API

Title

Description

ListCompressFileDetectResult Retrieve detection results of files within a compressed archive Retrieves the detection results of files within a compressed archive.
GetFileDetectResult Get file detection results Retrieves file detection results in batches by HashKey.
CreateFileDetect Push file for detection Pushes a file to the cloud for detection.
CreateFileDetectUploadUrl CreateFileDetectUploadUrl Queries the parameters that are required to upload a file for detection.
GetFileDetectApiInvokeInfo GetFileDetectApiInvokeInfo Obtains the usage information of the malicious file detection SDK.
DeleteOssScanConfig DeleteOssScanConfig Deletes the configuration of an Object Storage Service (OSS) file detection policy.
ListOssScanConfig Query OSS file scan policy configurations Queries the list of OSS file scan policy configurations.
CreateOssBucketScanTask Create a bucket scan task Creates a bucket scan task.
GetObjectScanEvent GetObjectScanEvent Retrieves the details of an alert event that is generated for a malicious object.
ListObjectScanEvent Query malicious file alerts Queries the list of malicious file alerts.
OperateBucketScanTask Operate a bucket scan task Operates on a bucket scan task.
GetOssBucketScanStatistic Retrieve OSS scan statistics Retrieves OSS scan statistics.
ListOssBucketScanInfo Query bucket risk information Queries the risk information list of buckets.
UpdateOssScanConfig Update scan policy configuration Updates the OSS file scan policy configuration for the malicious file detection feature.
ListOssBucket Query bucket list Queries the list of buckets.
CreateOssScanConfig Create a scan policy Creates a scan policy for detecting malicious files in OSS under the malicious file detection feature.
ListSupportObjectSuffix Query supported file type suffixes Queries the supported file type suffixes.
RefreshOssBucketScanInfo Refresh bucket list Refreshes the bucket list.
GetOssScanConfig Retrieve scan policy configuration Retrieves the scan policy configuration.

Task management

API

Title

Description

CreateCycleTask Create a general plan scan task Creates an epoch scan task, including image scans, emergency vulnerability scans, and virus scans.
GenerateOnceTask GenerateOnceTask Creates a one-time scan task.
DeleteCycleTask Delete a general scan plan task Deletes an epoch-based scan node, including image scans, emergency vulnerability scanning, and virus scans.
ModifyCycleTask Modify scheduled task cycle Modifies the run epoch of periodic nodes, including image scan, emergency vulnerability scanning, and virus scan nodes.
CancelOnceTask CancelOnceTask Cancels the main task.
DescribeOnceTask Query client tasks Queries a list of client tasks.
DescribeCycleTaskList Query general-purpose scheduled task list Queries the list of general-purpose scheduled nodes, including image scan, emergency vulnerability scanning, and virus scan nodes.
GetOnceTaskResultInfo GetOnceTaskResultInfo Queries the execution results of a one-time scan task, such as an asset fingerprint collection task, a vulnerability scan, or an image security scan.
GetLastOnceTaskInfo Query the running information of the latest scan task Queries the running information of the latest scan task to determine whether the task is complete.
DescribeOnceTaskLeafRecordPage Retrieve subtask information of a one-time task Retrieves the details of subtasks for a one-time scan task result, including image scanning and image asset synchronization.

Asset selection

API

Title

Description

UpdateSelectionKeyByType Update the key for an asset selection type Modifies the key that corresponds to a specified type.
CreateAssetSelectionConfig Create an asset selection configuration Creates an asset selection configuration.
ListAssetSelectionSelectedTarget Query selected assets from specified assets Queries the selected assets from the specified assets.
ListAssetSelectionTarget ListAssetSelectionTarget Queries the required asset.
GetAssetSelectionConfig Retrieve asset selection configuration Retrieves the asset selection configuration.
AddAssetSelectionCriteria Add assets to an asset selection operation Adds assets to an asset selection operation.

Task center

API

Title

Description

CreateSoarStrategyTask Create a policy task Creates a task under My Policies in Task Center.
DeleteSoarStrategyTask Delete a task center task Deletes a policy task that is in the waiting state from the task center.
DescribeSoarStrategies DescribeSoarStrategies Queries the policy templates on the Playbook page.
DescribeSoarStrategyParam DescribeSoarStrategyParam Queries the parameters of a policy on the Playbook page.
DescribeSoarStrategyTaskDetail Query policy task details in the task center Queries the details of a policy task in the task center, including the task execution status and the corresponding flowchart.
DescribeSoarStrategyTasks DescribeSoarStrategyTasks Queries a list of policy tasks on the Playbook page.
ModifySoarStrategySubscribe Add or remove a policy template to or from my policies Adds or removes a policy template to or from My Policies in the task center.
DescribeSoarSubscribedStrategy Query custom policies in the task center Queries the list of custom policies created in the task center of Security Center.
DescribeSyncAssetTaskList Query asset synchronization task list Queries the list of asset synchronization IDC scan tasks.
DescribeSyncAssetTaskLogDetail Query asset synchronization task details Queries the details of IDC scan tasks for asset synchronization.
DescribeSoarPlaybookTaskDetail Query Playbook Task Details Query the execution details of a remediation task playbook
DescribeSoarStrategyTaskParams Query policy task parameters in the task center Queries the parameters of a policy task in the task center.
ProcessSoarStrategyTask Execute a policy task in the task center Executes a policy task in the task center.
DescribeSoarStrategyTaskResult Query policy task execution results Queries the execution results of a policy task in the task center.

Website security

API

Title

Description

DescribeDomainSecureVulList Query vulnerability list in a website security report Queries the vulnerability list in a website security report.
DescribeDomainSecureRiskList Query risky websites in website security report Queries websites with risks and their associated security information from the website security report, including the number of vulnerabilities and alerts.
DescribeDomainSecureAlarmList Query security alert data from a website security report Queries security alert data from a website security report.
DescribeDomainSecureStatistics Query website security report statistics Queries the statistics of a website security report, including the number of websites and security events.
DescribeDomainSecureScore Query the security score of a website security report Queries the security score of a website security report. The maximum score is 100.

Attack analysis

API

Title

Description

GetAttackTypeList Retrieve attack type list Retrieves the list of attack types for the attack analysis event display.

Billing

API

Title

Description

GetAuthSummary Retrieve authorization statistics Retrieves authorization statistics.
GetServerlessAuthSummary Retrieve serverless authorization overview Retrieves the Serverless authorization overview.
GetServerlessAppAuthDetail Retrieve serverless application authorization details Retrieves the authorization details of a serverless application.
DescribeVersionConfig Query version details of a purchased security center instance Queries the version details of a purchased Security Center instance.
ModifyPostPayModuleSwitch Modify pay-as-you-go feature status Enables or disables pay-as-you-go billing for a specified feature.
UpdatePostPaidBindRel Change the protection edition of a pay-as-you-go service Changes the protection edition bound to a server after you enable the pay-as-you-go billing method for host and container security.
BindAuthToMachine Bind authorization to servers Binds authorization information to servers.

Others

API

Title

Description

GetModuleConfigStatus GetModuleConfigStatus Checks whether the purchased Security Center features are enabled and whether related configurations take effect.
FinishGuidTask FinishGuidTask Completes guidance tasks for beginners to earn rewards.
DescribeVolDingdingMessage DescribeVolDingdingMessage Queries the QR code address of a DingTalk group.
DescribeAllRegionsStatistics Retrieve global security event statistics Retrieves global security event statistics, including the number of unfixed vulnerabilities, baseline checks, and alerts.
InstallPmAgent Install O&M plugin Installs the CloudMonitor agent on non-Alibaba Cloud ECS servers.
GetModuleConfig GetModuleConfig Queries the configurations of a module.
DescribeClusterBasicInfo Query cluster information by cluster ID Queries cluster information by cluster ID.
DescribeQuaraFileDownloadInfo Query download link of a quarantined file Queries the download information of a quarantined file for a security alert.
DescribeAffectedAssets Query affected assets Queries the list of affected assets from virus defense check results.
DescribeEventOnStage Query platforms supported by threat detection Queries the platforms supported by threat detection.
DescribeScanTaskStatistics DescribeScanTaskStatistics Queries the statistics of virus detection tasks.
DescribeSuspEventUserSetting DescribeSuspEventUserSetting Queries the user settings for exceptions.
DescribeTraceInfoNode Query trace node information Queries the details of a trace node.
DescribeTraceInfoDetail Query tracing information Queries the tracing information of a security alert.
DescribeEventLevelCount Query total number of security alerts by severity level Queries the total number of security alerts by severity level.
SaveSuspEventUserSetting Save user settings Saves user security alert settings.
ConfirmVirusEvents Confirm a virus event Confirms the handling of a trojan scan alert.
ModifySecurityEventMarkMissIndividually Adjust advanced whitelisting rules for security alerts Adjusts advanced whitelisting rules for security alerts by asset dimension.
CreateContainerScanTask Create a container scan task Creates a container scan task.
DescribeTotalStatistics Retrieve event statistics Retrieves event statistics information.
DescribeImageLatestScanTask Query the most recent scan status of an image Queries the most recent image scan task.
DescribeImageRepoList Retrieve image defense switch configuration statistics information Retrieves statistics information on image defense switch configurations.
CreateJenkinsImageRegistry CreateJenkinsImageRegistry Creates a Jenkins image repository.
PageImageRegistry Query image repositories by page Queries a list of image repositories.
QueryJenkinsImageRegistryPersistenceDay Query jenkins image repository image retention duration Queries the image retention duration of a Jenkins image repository.
UpdateJenkinsImageRegistryName Modify jenkins image repository image name Modifies the image name in a Jenkins image repository.
UpdateJenkinsImageRegistryPersistenceDay Modify jenkins image repository image retention period Modifies the image retention period for a Jenkins image repository.
GetInterceptionTargetDetail GetInterceptionTargetDetail Queries the information about a specified network object that is protected by the container firewall feature.
DeleteInterceptionRule Delete an interception rule Deletes a microsegmentation interception rule.
DeleteInterceptionTarget Delete interception targets Deletes active network objects from the container firewall.
DescribeCustomBlockRecords Query custom interception policies Queries brute-force attacks interception records for custom blocked IP addresses defined on one or more servers.
ListInterceptionRulePage Query micro-segmentation defense rules Queries micro-segmentation defense rules.
ListInterceptionHistory Query container firewall interception records Queries container firewall interception records.
CreateInterceptionRule Create a blocking rule Creates a container firewall blocking rule.
CreateInterceptionTarget CreateInterceptionTarget Creates a defense object.
GetInterceptionRuleDetail GetInterceptionRuleDetail Retrieves the details of a microsegmentation defense rule.
ListImageRegistryRegion Query regions that support private image registry access Queries the regions that support private image registry access.
GetAppNetwork Retrieve network topology between container applications Retrieves the network topology between container applications.
AddPrivateRegistry AddPrivateRegistry Adds a self-managed image repository.
DeletePrivateRegistry Delete a private repository Deletes a private image repository by image repository ID.
GetClusterRuleSummary GetClusterRuleSummary Queries the overall information about cluster defense rules that are configured for the container firewall feature.
ListPodRisk Retrieve security risks of pod groups Retrieves the security risks of pod groups.
ListImageRisk Retrieve security information of container images Retrieves the security information of container images.
DeleteServiceTrail Delete actionTrail data delivery Deletes an ActionTrail data delivery configuration.
GetServiceTrail Retrieve audit trail delivery configuration Retrieves the audit trail delivery configuration.
CreateServiceTrail Create actionTrail data delivery Creates a service trail.
DeleteBinarySecurityPolicy DeleteBinarySecurityPolicy Deletes a binary security policy from the container signature feature.
DescribeMonitorAccounts Query multi-account management account list Queries the list of monitored accounts for multi-account management.
AddImageVulWhiteList AddImageVulWhiteList Adds image vulnerabilities to the whitelist.
DescribeImageVulWhiteList Query image vulnerability whitelist Queries the image vulnerability whitelist.
QueryAttackCount Query the number of alerts by attack stage Queries the number of security alert events that occurred in each attack stage.
GetSwitchRegionDetail Query service switchover progress Queries the progress of a service switchover. For example, when a server connection is being migrated from China to Singapore, you can retrieve the migration progress and status.
GetAuthVersionStatistic Query asset authorization quantity statistics Query asset authorization quantity statistics.
UpdateImageVulWhitelistTarget Update an image vulnerability whitelist Updates an image vulnerability whitelist.
DeleteImageVulWhitelist Delete image vulnerability whitelists Deletes image vulnerability whitelists.
DescribeContainerScanConfig Query container runtime scan configuration Queries the container runtime scan configuration.
ModifyContainerScanConfig Modify container runtime scan configuration Modifies the container runtime scan configuration.
DescribeCanFixVulList Query fixable vulnerabilities Queries the list of fixable vulnerabilities.
ModifyImageFixCycleConfig ModifyImageFixCycleConfig Updates the configurations of a scheduled image fix.
DescribeImageFixCycleConfig Query scheduled image fix configuration Queries the scheduled image fix configuration.
CreateContainerScanTaskByAppName Create a container runtime scan task by application name Creates a container runtime scan task in the appNames dimension.
GetCommonSwitchConfig GetCommonSwitchConfig Queries the configuration of a common switch.
CreateHoneypotProbeBind Create a probe service Creates a listener or forwarding service for a specified probe.
ListHoneypotProbeUuid Query probe iDs by probe type and node ID Queries probe IDs by probe type and node ID.
StopHoneypot Stop a honeypot Stops a honeypot.
UpdateHoneypotProbeBind Modify a probe service Modifies a probe service.
ListHoneypotEvents List honeypot attack events Retrieves intrusion events of a honeypot.
UpdateAlarmEvent Modify honeypot alert status Modifies the processing status of a honeypot alert event.
RetryInstallProbe RetryInstallProbe Retry installing the honeypot probe.
ListHoneypotAttackerPortrait ListHoneypotAttackerPortrait Queries the attacker profile based on the source IP address of the attack.
GetHoneypotEventTrend Obtain the attack volume trend of honeypot attack sources Obtain attack trend statistics for a single attack source.
ListHoneypotAttackerSource ListHoneypotAttackerSource Queries the attack source IP addresses that are used to attack a honeypot.
UpdateCommonSwitchConfig UpdateCommonSwitchConfig Updates the settings of common switches.
CreateFileUploadLimit CreateFileUploadLimit Specifies the queries per second (QPS) limit on the files uploaded from the client.
GetFileUploadLimit GetFileUploadLimit Queries the queries per second (QPS) limit on the files uploaded from the client.
UpdateFileUploadLimit Modify the QPS upper limit for client file uploads Modifies the QPS for client file uploads.
GetFileDetectReport GetFileDetectReport Queries the cloud sandbox check results of malicious files.
DescribeImageEventOperationPage Query alerting handling rules by paging Queries alerting handling rules by using paging.
GetImageEventOperation GetImageEventOperation Queries alert handling rules.
DescribeImageEventOperationCondition Query conditions for handling image events Queries the conditions for handling image events.
UpdateImageEventOperation Update an alert handling rule Updates an alert handling rule.
DeleteImageEventOperation Delete an alert disposal rule Deletes an alert disposal rule.
SetSensitiveDefineRuleConfig SetSensitiveDefineRuleConfig Configure the check rules of sensitive files.
SetImageSensitiveFileStatus SetImageSensitiveFileStatus Modifies the status of sensitive files in an image.
AddImageEventOperation AddImageEventOperation Creates an alert handling rule.
GetSensitiveDefineRuleConfig Query custom check items for sensitive file tampering Queries custom check items for sensitive file tampering.
GetHoneypotNodeMetricList GetHoneypotNodeMetricList Queries the monitoring data of management nodes to which the cloud honeypot belongs.
GetAegisContainerPluginRuleCriteria Get Container Escape Prevention Query Criteria Queries the query conditions of container anti-tamper rules.
OperateApplication OperateApplication Adds or deletes container applications for tamper proofing.
GetSasContainerWebDefenseRuleCriteria Retrieve query criteria for container tamper-proofing rules Retrieves the query criteria for container tamper-proofing rules.
DescribeContainerApps Retrieve the app list of a cluster Retrieves the list of apps in a cluster.
ListGroups Retrieve server group list Retrieves the list of server groups for the current user.
ListInstanceRiskNum ListInstanceRiskNum Queries the statistics about risks in instances.
ListInstanceRiskLevels ListInstanceRiskLevels Queries the risk levels of instances.
GetModuleTrialAuthInfo GetModuleTrialAuthInfo Queries the qualification information about the trial use of Security Center value-added features, including vulnerability fixing and threat analysis and response.
AddSasModuleTrial AddSasModuleTrial Enables the trial use of Security Center value-added features, including vulnerability fixing and threat analysis and response.
EnableCustomInstanceBlockRecord Enable a specific instance in a custom rule Enables the status of a specific instance in a custom rule.
DescribeCustomBlockInstances DescribeCustomBlockInstances Queries the list of servers on which the custom defense rule against brute-force attacks takes effect.
GetHoneyPotUploadPolicyInfo GetHoneyPotUploadPolicyInfo Obtains the URL that is used to upload a file to a honeypot.
UploadedHoneyPotFile Upload a honeypot file and register the record Registers and confirms a record after a honeypot file is uploaded.
ListHoneypotEventFlows Retrieve honeypot attack event timeline Retrieves the details of a honeypot attack event.
ModifyImageRegistry ModifyImageRegistry Modifies the configuration of an image registry.
DeleteK8sAccessInfo Delete kubernetes access information Deletes Kubernetes access information.
AddContainerPluginRule AddContainerPluginRule Creates a defense rule against container escapes.
DeleteContainerPluginRule Delete a container escape prevention rule Deletes a container escape prevention rule.
ModifyContainerPluginRule Modify a container escape prevention rule Modifies a container escape prevention rule.
DeleteSasContainerWebDefenseRule Delete a container tamper-proofing rule Deletes a container tamper-proofing rule.
ListK8sAccessInfo List k8s access information Lists K8s access information.
GenerateK8sAccessInfo Generate a self-managed kubernetes access command Generates an access command for a self-managed Kubernetes cluster.
ListClusterPluginInfo ListClusterPluginInfo Queries the status of plug-ins on clusters.
MarkMonitorAccounts Tag member accounts in multi-account management Tags member accounts in multi-account management. Tags selected member accounts as accounts of interest. Accounts of interest are displayed at the top of the drop-down list above the left-side navigation pane in the Security Center console.
UnMarkMonitorAccounts UnMarkMonitorAccounts Cancel marking for members. Remove followed members from the list. In the Security Center console, the drop-down list above the left-side navigation pane no longer displays the members.
GetClusterStrategyCount Query the number of policies in each cluster Queries the number of policies in each cluster.
ListUnfinishedOnceTask Query incomplete tasks Queries the list of incomplete tasks by task type.
ListBackupRecord Query backup records Queries a list of backup records.
ResetHoneypot ResetHoneypot Resets a honeypot.
StartHoneypot StartHoneypot Starts a honeypot.
DeleteVulAutoRepairConfig Delete automatic fix configurations from the vulnerability task center Deletes the configurations of vulnerabilities that can be automatically fixed in the vulnerability task center in batches.
DescribeFixUsedCount Query the number of vulnerability fixes used by a pay-as-you-go user Queries the number of vulnerability fixes used by a pay-as-you-go user.
CreateAttestor CreateAttestor Creates a witness.
CreateBinarySecurityPolicy CreateBinarySecurityPolicy Creates a binary security policy.
DeleteAttestor Delete an attestor Deletes an attestor.
DescribeAttestors DescribeAttestors Queries a list of witnesses.
DescribeBinarySecurityPolicies DescribeBinarySecurityPolicies Queries binary security policies.
DescribeClusterHostSecuritySummary Query host security statistics Queries the security statistics of a host.
DescribeClusterImageSecuritySummary Query image security statistics Queries the security statistics of container images.
DescribeContainerServiceK8sClusters DescribeContainerServiceK8sClusters Queries a list of Container Service for Kubernetes (ACK) clusters.
DescribeCustomizedDictUploadInfo View OSS details of custom weak password upload Queries the information about the OSS bucket that stores custom weak password files.
CheckStsTokenAuth CheckStsTokenAuth Checks a Security Token Service (STS) token and returns the ID of the Alibaba Cloud account.
DescribeVulDefendCountStatistics Query user vulnerability prevention statistics Queries the vulnerability prevention statistics of a Security Center user.
DescribeVulMetaCountStatistics DescribeVulMetaCountStatistics Queries the statistics of vulnerabilities in Security Center.
CreateCustomizedDict CreateCustomizedDict Creates custom weak password rules.
DescribeContainerFieldStatistics DescribeContainerFieldStatistics Queries the statistical information about containers.
DescribeContainerGroupedFieldDetail Query container property details Queries the details of container properties.
DescribeContainerServiceK8sClusterKritisStatus Query the kritis status of an ACK cluster Queries the Kritis status of a Container Service for Kubernetes (ACK) cluster.
DescribeContainerServiceK8sClusterNamespaces Query namespaces of an ACK cluster Queries the namespaces of a Container Service for Kubernetes (ACK) cluster.
CreateJenkinsImageScanTask Create a jenkins scan task Creates a Jenkins scan task.
UpgradeHoneypotNode Upgrade honeypot management node version Upgrades the version of a specified honeypot management node.
QueryGuidTaskList Query beginner task information Security Center provides rewards such as value-added service authorization quotas and log analysis storage capacity to users who complete tasks. Queries the completion status and reward information of configuration tasks.
CreateSasTrial Start a security center free trial Starts a free trial of Security Center.
GetCanTrySas GetCanTrySas Checks whether the current user is qualified for the trial use of Security Center.
ReceiveFunctionTrialRewardByAliUid Start cloud honeypot or malicious file detection SDK trial Claims a trial reward for the cloud honeypot or malicious file detection SDK feature after completing a task.
DescribeAgentlessSensitiveFileByKey Query sensitive file alerts by type Retrieves the list of assets that contain a specific type of sensitive file detected by the agentless detection feature.
GetCheckStructure Get cloud platform configuration check item structure Queries the directory structure of the check item list.
DescribeDynamicDictUploadInfo Query OSS upload details of dynamic weak passwords Queries the OSS upload details of user-defined dynamic weak passwords for baseline checks.
DeleteCustomizeReport Delete a custom security report Deletes a specified custom security report.
DescribeCustomizeReportConfigDetail Retrieve report sending configuration details Retrieves the details of a report sending configuration.
DescribeDynamicDict Query dynamic weak passwords Queries the user-defined dynamic weak password rules for baseline checks.
DescribeIdcProbeScanResultList Query IDC probe scan results Retrieves the list of assets discovered by IDC probes.
DescribeSupervisonInfo Query latest system vulnerability discovery time Queries the latest system vulnerability discovery time.
ExportCustomizeReport Export a security report Exports a security report.
GenerateDynamicDict GenerateDynamicDict Generates a custom dictionary of weak passwords for the baseline check feature.
GetDefenceCount Query security protection statistics Queries the number of alerting events handled by accurate access control and web tamper-proofing.
OperationCustomizeReportChart Modify security report statistical charts Modifies the statistical charts of a security report.
SaveCustomizeReportConfig Save custom security report configuration Saves the configuration of a custom security report.
SendCustomizeReport Send security report Sends a security daily report to a specified email address. Only security reports whose report period is set to a custom time range are supported.
UpdateCustomizeReportStatus Modify security report status Modifies the status of a security report.
DescribeUniBackupStatistics Query anti-ransomware backup statistics information for databases Queries the statistics information of anti-ransomware backup for databases.
DescribeUserSetting Query user-defined configurations Retrieves user-defined configurations for baseline checks.
GetDataTrend Query security operations trends Queries the security operations trends for vulnerabilities, alerts, and baselines.
ResetLogShipper ResetLogShipper Resets and upgrades the log analysis feature. You can call this operation only when the log analysis feature uses the pay-as-you-go billing method.
ListLogShipperRegions Query regions supported for log delivery in pay-as-you-go mode Queries the regions supported for log delivery in pay-as-you-go mode.
UpdateTargetListByBatch Update machines in a batch Updates the machines included in a batch.
DescribeScreenScoreThread Query security dashboard score trends Queries the security score trends on the security dashboard.
DescribeChartData Query security daily report chart statistics Queries the statistics of charts configured in a security report.
OpenBackupAutoConfig Enable anti-ransomware managed service configuration Enables the anti-ransomware managed service to configure server backup policies with one click. This operation can be called only after you purchase the anti-ransomware managed service.
GetBackupAutoConfigStatus Query anti-ransomware managed service status Queries whether the anti-ransomware managed service supports automatic configuration of anti-ransomware server backup policies.
GetAegisContainerPluginRule Query container anti-escape rule details Queries the details of a container anti-escape rule.
SubmitOperationTask Submit a remediation or rollback task for check items Submits a remediation task for risky check items in cloud product configuration checks, or rolls back a remediation task that has been executed.
CheckTrialFixCount CheckTrialFixCount Checks whether the remaining quota of the vulnerability fixing feature is sufficient for a free trial user of Security Center and queries the quota usage required for the current fix operation.
CreateMonitorAccount CreateMonitorAccount Creates a list of members of the account monitored by Security Center type by using the multi-account management feature.
DeleteMonitorAccount Delete a security center monitoring account from multi-account security management Deletes a Security Center monitoring account from the multi-account security management feature.
EnableServiceAccessResourceDirectory Enable the multi-account management feature of security center Enables the multi-account management feature of Security Center.
ListAccountsInResourceDirectory Consultation des comptes membres dans un répertoire de ressources. Obtient la liste des comptes gérés pour la gouvernance multi-comptes.
ModifyWebLockRefresh ModifyWebLockRefresh Refreshes the status of the web tamper proofing feature for a server.
DescribeCheckResult DescribeCheckResult Queries the result of the ISO 27001 compliance check.
TriggerCheck TriggerCheck Triggers ISO 27001 compliance checks of Security Center.
CreateRdDefaultSyncList Create an automatic control policy for new accounts in multi-account security management Creates an automatic control policy for new accounts in the multi-account security management feature of Security Center. Member accounts under the automatic control policy folder are automatically added to the monitored account list.
ListRdDefaultSyncList Query the automatic control policy for new accounts in multi-account security management Queries the automatic control policy for new accounts in Security Center under the multi-account security management feature. Member accounts under the automatic control policy folder are automatically added to the monitoring account list.
GetRdTree Query the directory structure of a resource organization under a resource directory Queries the directory structure of the resource organization under a resource directory by using the multi-account management feature.
DescribeIdcAssetCriteria IDC probe scan asset search conditions Queries the fuzzy match search conditions for asset properties that can be displayed when you query IDC assets discovered by scanning.
DescribeImageListByBuildRisk Query affected images by build risk with paging Queries affected images by build risk with paging.
DescribeImageBuildRiskList Query image build risk summary by page Queries the summary of image build risks by using paging.
DescribeImageBuildRiskByKey Query image build risks by page Queries the build risks of images by paging.
DescribeCanTrySas DescribeCanTrySas Checks the permissions on the trial use of Security Center.
DescribeNeedAsyncQuery DescribeNeedAsyncQuery Queries whether slow queries need to be optimized.
ListPrivateK8s Retrieve private kubernetes cluster information Retrieves information about self-managed Kubernetes clusters that are connected to Security Center.
ModifyAttestor ModifyAttestor Modifies the information about a witness that is created by using the container signature feature.
DescribeCheckWarningCount DescribeCheckWarningCount Queries the number of alerts that are triggered by a check item.
GetAccountLabel Retrieve account labels Retrieves account labels.
ListAssetInfoPublish Retrieve upgrade information for a specified asset Retrieves the list of custom upgrade information for a specified asset of the user.
GetCurrentVersionPublish Retrieve version release information Retrieves the release information of the current client version.
BatchCreateMaliciousNote BatchCreateMaliciousNote Adds alert description in batches.
DescribeInstanceVulStatistics Query vulnerability risk statistics for serverless asset instances Queries vulnerability statistics for a cluster.
SetImageBuildRiskStatus Set image build risk status Sets the risk status of image builds.
SubmitTenantCheck Submit a one-click scan task Submits a free one-click scan. The scan scope includes free vulnerability scanning categories and free Cloud Security Posture Management (CSPM) check items.
GetTenantCheckAvailable Query whether a one-click scan can be submitted Queries whether a free one-click scan can be submitted. The scan scope includes free vulnerability scanning categories and free CSPM check items.
ListOperationProcessDetail Query operation task subtasks Queries the subtask list of an operation task.
ListOperationProcess Query operation tasks Queries a list of operation tasks.
DescribeCanAccessVpcSale Check if the Asset Can be Sold by VPC Check if the asset can be sold by VPC
DescribeDomainSecureSuggests Query security suggestions in a website security report Queries the security suggestions in a website security report.
DescribeIdcProbeList Query IDC probe list for asset discovery Retrieves the list of IDC probe instances used for asset discovery in the multi-cloud configuration management feature.
DescribeImageRiskLevelStatistic Query image risk statistics Queries the number of images that have security risk alerts, including vulnerabilities, baselines, and malicious sample risks.
DescribeImageSecurityScanCount Retrieve image security event count Retrieves the number of image security events.
GetDockerhubImageRiskRankInfo Query image rankings by dimension Queries the rankings of images by various dimensions.
ListDockerhubImage Query docker hub images Queries the risk overview of official Docker Hub images.
ListUserVpc Retrieve VPC data by region Retrieves VPC data for the user in a specified region by using the third-party image repository integration feature of Container Asset in Security Center.
CreateBatchUploadUrl CreateBatchUploadUrl Queries the parameters that are required to upload a file for detection.
GetFunctionTrialStatus Get Function Trial Eligibility Status Get Trial Status
ListTargetByBatch Query targets by batch Queries the list of publish target information for a specified batch.
GetConsoleFuncGrayStatus Get the Gray Status of Console Function Modules Query whether the core function's gray switch is hit
GetInstanceAlarmStatistics Retrieve alerting statistics information for a server Retrieves the alerting statistics information for a server.
AddProtectVpcList Add or Update the Whitelist for VPC Purchases Add or update the whitelist for VPC purchases
GrantSwitchAgreement Grant authorization for feature migration Grants authorization for feature migration.
ListAgentlessAsset ListAgentlessAsset Query agentless detection assets.
ModifyServerlessAuthToMachine Manage serverless asset authorization Manages Serverless asset authorization.
ModifyBinarySecurityPolicy Modify container image signing security policy Modifies a container image signing security policy.
GetInstallCodeForUuid Query the agent installation code for a specified asset by UUID Queries the Security Center agent installation code for a specified asset by UUID.
UpdateAttackPathWhitelist UpdateAttackPathWhitelist Update Attack Path Whitelist.
DeleteAttackPathWhitelist Delete an attack path whitelist entry Deletes an attack path whitelist entry.
DeleteAttackPathSensitiveAssetConfig DeleteAttackPathSensitiveAssetConfig Delete attack path sensitive asset.
ListSupportAttackPathAsset Query cloud service asset types supported by attack path analysis Queries the cloud service asset types supported by attack path analysis.
GetAttackPathWhitelist Query attack path whitelist details Queries the details of an attack path whitelist.
ListAttackPathWhitelist Query attack path whitelist Queries the attack path whitelist.
CreateAttackPathWhitelist Create an attack path whitelist Creates an attack path whitelist.
CreateAttackPathSensitiveAssetConfig Create Attack Path Sensitive Asset Settings Create attack path sensitive asset configuration.
UpdateAttackPathSensitiveAssetConfig Update attack path sensitive asset settings Updates the sensitive asset configuration for attack path analysis.
GetAttackPathSensitiveAssetConfig Query attack path sensitive asset settings Queries the sensitive assets in an attack path.
ListAvailableAttackPath ListAvailableAttackPath Query Attack Path List.
GetAttackPathEventDetail Query attack path event details Queries the details of an attack path event.
ListAttackPathEvent Query attack path events Queries the list of attack path events.
GetAttackPathEventStatistics Query attack path event statistics Queries attack path event statistics.
InstallAegisForLingjun Install Security Center agent on Lingjun bare metal servers Installs the Security Center agent on Lingjun bare metal servers.
ListAegisForLingjunStatus Query the Aegis Client Installation Result for Lingjun Bare Metal Query the Aegis client installation result for Lingjun bare metal.
DescribeAIAssetSummary DescribeAIAssetSummary Queries the overview of user AI assets.
DescribePluginSummary DescribePluginSummary Queries statistics on the client plug-in installation status.
DescribeCustomizedDict Query custom weak passwords Queries the upload result of a custom weak password file.
ListUniBackupRecord List Database Backup Records List Database Backup Records
HandleSimilarMaliciousFiles Batch process malicious sample alerts Batch processes malicious sample alerts.
GenerateClusterScannerWebhookYaml Generate Cluster Scanner Component Access Configuration Generate K8s cluster scan access configuration.
DescribeClusterScannerList Query cluster scanner list Queries the scanner status information of a Kubernetes cluster.
GetClusterScannerYaml View cluster scan component access configuration Queries the scan access configuration of a Kubernetes cluster.
GetAgentlessTaskUsedSizeEstimate Retrieve estimated scan volume for agentless detection Retrieves the estimated scan volume for agentless detection.
ListCloudAssetMatchOperators Get cloud asset data operator list Gets the list of cloud product configuration rule operators.
ListCloudAssetSchemas Get the list of asset structure definitions. Get the list of cloud product asset structure
UpdateMultiUserInstances Manage authorization assignments Manages authorization assignments for member accounts in multi-account authorization management.
GetInstanceAuthRange Retrieve instance authorization value ranges Retrieves the valid value ranges for instance authorization.
ListMultiUserInstances Query multi-account authorization assignment list Queries the multi-account authorization assignment list under multi-account authorization management.
DescribeCloudVendorProductTemplateConfig Query Agentic SOC Supported Cloud Vendor Product Access Template Configuration Get the cloud product access template for vendors
GetValidDeductInstances Retrieve active resource plan instances Retrieves active resource plan instances.
ListAttackEventInfo Retrieve attack analysis event list Retrieves the list of attack analysis events.
GetAttackEventDetail Get attack analysis event details Retrieves the details of an attack analysis event.
GetAttackEventDashboard Retrieve attack analysis dashboard information Retrieves attack analysis dashboard information.
DescribeSuspiciousSecurityEventyStatistics Query Alarm Security Event Statistics Query Alarm Security Event Statistics
ListClusterCheckResult Query Cluster Check Item Scan Results Query Cluster Check Item Scan Results
GetClusterCheckSummary Query cluster check item risk count Queries the risk statistics of check items for a cluster.
ListKspmInstances Query kubernetes assets Queries Kubernetes asset information.
AddFileProtectBindMachine Add tamper-proofing server Creates a file protection rule.
CreateFileProtectClientRule Create a tamper-proofing rule Creates a file protection rule.
DeleteFileProtectClientRule Delete a tamper-proofing rule Deletes a web tamper-proofing rule.
DescribeAlarmEventStackInfo DescribeAlarmEventStackInfo Queries the stack information about an alert event.
DescribeBackupFiles DescribeBackupFiles Queries backup files.
DescribeFrontVulPatchList Query prerequisite patches for a specified windows system vulnerability Queries the list of prerequisite patches that must be installed for a specified Windows system vulnerability.
DescribeGroupedVul Query vulnerability information by group Queries vulnerability information by group.
DescribeScanTaskProgress Query virus scan task progress Queries the progress of a virus scan task.
DescribeSecurityEventOperationStatus DescribeSecurityEventOperationStatus Queries the alert events that are triggered by the same IP address rule or of the same alert type as a specific alert event if you want to handle the specific alert event in batch operation mode.
DescribeSecurityEventOperations DescribeSecurityEventOperations Queries the operations that you can perform to handle an alert.
DescribeSnapshots DescribeSnapshots Queries the backup snapshots that are created for anti-ransomware.
DescribeSuspEventQuaraFiles Query quarantined files by page Queries quarantined files in the file quarantine box by paging.
DescribeSuspEvents Query security alert events Queries a list of security alert events that have not been aggregated.
DescribeVulDetails Query vulnerability details Queries vulnerability details.
DescribeVulList DescribeVulList Queries vulnerabilities by type.
GetFileProtectClientEvent Get tamper-proofing alert event details Retrieves the details of a file protection event.
GetFileProtectClientEventDashboard Retrieve statistics on tamper-proofing events Retrieves the dashboard data of file tamper-proofing events.
GetFileProtectClientRule Retrieve file tamper-proofing rule details Retrieves the details of a file protection rule.
GetFileProtectClientRuleDashboard Retrieve web tamper-proofing overview information Retrieves the overview dashboard of file protection rules.
HandleObjectScanEvent Handle malicious file detection alerts Handles malicious file detection alerts.
HandleSecurityEvents HandleSecurityEvents Handles alert events.
ListFileProtectBindMachine Retrieve the list of servers associated with file tamper-proofing Retrieves the list of servers associated with tamper-proofing.
ListFileProtectClientEvent Retrieve tamper-proofing event list Retrieves the list of file protection events.
ListFileProtectClientRule Retrieve file tamper-proofing rules Retrieves the list of file protection rules.
ListFileProtectClientRuleFileType Retrieve file types for web tamper-proofing Retrieves all file types for file protection rules.
ModifyOperateVul Handle detected vulnerabilities Handles detected vulnerabilities. Supported operations include fix, verify, and ignore.
OperateVuls Fix Linux software vulnerabilities Fixes Linux software vulnerabilities.
RollbackSuspEventQuaraFile Restore a quarantined file from the quarantine Restores a quarantined file from the quarantine.
StartVirusScanTask StartVirusScanTask Performs a virus scan task on a server or multiple servers.
UpdateFileProtectClientEvent Update a web tamper-proofing protection event Updates the status of a file protection event.
UpdateFileProtectClientRule Modify a web tamper-proofing rule Updates a file protection rule.
UpdateFileProtectClientRuleStatus Update tamper-proofing rule status Updates the status of file tamper-proofing rules.
CreateServiceLinkedRole Create a service-linked role and authorize security center to access cloud resources Creates a service-linked role and authorizes Security Center to access cloud resources.
DescribeBackupPolicy Query anti-ransomware protection policy details for servers Queries the details of an anti-ransomware protection policy for servers.
ModifyBackupPolicy Modify an anti-ransomware policy Modifies an anti-ransomware policy.
DescribeUuidVulNumClassifyStatistic Query vulnerability category statistics Queries vulnerability count statistics by UUID.