API standards and multilingual preset SDKs
The OpenAPI of this product (Sas/2018-12-03) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.
Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.
Custom signature scenarios
If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.
Account and security preparation
Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.
Intelligent behavior analysis
|
API |
Title |
Description |
| UpdateUnknownThreatDetectStrategy | UpdateUnknownThreatDetectStrategy | Updates the unknown threat detection strategy. |
| UpdateUnknownThreatDetectProcess | UpdateUnknownThreatDetectProcess | Updates the remark for a specified unknown threat detection process. |
| OperateUnknownThreatDetectMachine | OperateUnknownThreatDetectMachine | Modifies the unknown threat detection settings for specified servers. |
| ListUnknownThreatDetectStrategy | ListUnknownThreatDetectStrategy | Lists the strategies for intelligent behavior analytics. |
| ListUnknownThreatDetectProcess | ListUnknownThreatDetectProcess | Retrieve the list of processes from unknown threat detections. |
| ListUnknownThreatDetectMachine | Query machines for intelligent behavior analytics | Queries the list of machines for intelligent behavior analytics. |
| ListUnknownThreatDetectEvent | Query intelligent behavior analytics alerts | Queries the list of intelligent behavior analytics alerting events. |
| HandleUnknownThreatDetectEvent | Handle intelligent behavior analytics alerting | Handles alerting from intelligent behavior analytics. |
| GetUnknownThreatDetectStatistic | Retrieve intelligent behavior analytics statistics information | Retrieves statistics information on intelligent behavior analytics. |
| DeleteUnknownThreatDetectStrategy | Delete a behavior analytics policy | Deletes a behavior analytics policy. |
| DeleteUnknownThreatDetectProcess | DeleteUnknownThreatDetectProcess | Deletes one or more Unknown Threat Detect processes. |
| CreateUnknownThreatDetectStrategy | CreateUnknownThreatDetectStrategy | Creates an intelligent behavior analysis strategy. |
| AddUnknownThreatDetectProcess | AddUnknownThreatDetectProcess | Adds one or more processes for intelligent behavior analysis. |
Custom client upgrade
|
API |
Title |
Description |
| ListPublishBatch | Query release batches | Queries the custom upgrade and release batches of the current user. |
| UpdatePublishBatch | Update a release batch | Updates a release batch. |
| UpdatePublishGraySwitch | UpdatePublishGraySwitch | Updates the settings of the canary release feature for agent upgrade. If you want to use the feature, contact technical support. |
| UpdatePublishCron | Modify client upgrade time | Modifies the configuration of the client upgrade time. To use this feature, contact technical support. |
| UpgradeVersionByUuids | Manually upgrade client | Manually upgrades the client of an asset. |
| UpdatePublishAutoUpgrade | Modify automatic upgrade switch | Enables or disables automatic upgrade. |
Proxy access
|
API |
Title |
Description |
| UpdateHybridProxy | Upgrade a hybrid cloud proxy client | Upgrades a hybrid cloud proxy client. |
| ModifyHybridProxyCluster | Modify remarks of a proxy cluster | Modifies the remarks of a proxy cluster. |
| ModifyHybridProxyPolicy | ModifyHybridProxyPolicy | Modify proxy policy. |
| UnBindHybridProxy | UnBindHybridProxy | Removes servers from a proxy cluster. |
| DescribeHybridProxyPolicy | Query data collection configuration of a proxy cluster | Queries the data collection configuration of a specified proxy cluster. |
| DescribeHybridProxyList | Query proxy machines by paging | Queries the list of proxy nodes that have been deployed in a specified proxy cluster by paging. |
| DescribeHybridProxyClusterList | Query proxy clusters by using paging | Queries proxy clusters by using paging. |
| DescribeHybridProxyLinkedClientList | Query connected clients by paging | Queries the list of clients connected to a specified hybrid cloud proxy by paging. This operation is part of the hybrid cloud proxy feature. |
| DeleteHybridProxyCluster | Delete a cluster by cluster name | Deletes a proxy cluster by cluster name. |
| DeleteHybridProxy | Delete a proxy node | Deletes a proxy node from a specified proxy cluster. |
| DescribeDefaultProxyInstallVersion | Query the default installation version of the hybrid cloud proxy | Queries the default installation version of the hybrid cloud proxy. |
Security report
|
API |
Title |
Description |
| DescribeReportExport | Query security report export information | Queries the export information of a security report. |
| DescribeChartList | Query statistical chart list | Queries the charts supported for statistics in Security Center security reports. |
| DescribeReportRecipientStatus | Query report contact status | Queries the status of report contacts by using the system configuration and security report feature of Security Center. |
Application whitelist
|
API |
Title |
Description |
| ModifyProcessWhiteList | Modify process whitelist status | Adds processes to or removes processes from the whitelist in the application whitelist feature. |
| UpdateWhiteListStrategyStatus | Modify application whitelist policy status | Modifies the status of an application whitelist policy. |
| DescribeWhiteListProcess | DescribeWhiteListProcess | Queries the information about the processes that are detected in an application whitelist policy. |
Agentless detection
|
API |
Title |
Description |
| DeleteMaliciousFileWhitelistConfig | Delete a whitelist rule for agentless detection of sensitive file alerts | Deletes a whitelist rule for agentless detection of sensitive file alerts. |
| UpdateMaliciousFileWhitelistConfig | Modify a whitelist rule for agentless sensitive file detection alerts | Modifies a whitelist rule for agentless sensitive file detection alerts. |
| CreateMaliciousFileWhitelistConfig | Create Sensitive File Alert Whitelist Rule of Agentless Detection | Get alert whitelist configuration details |
| ListMaliciousFileWhitelistConfigs | Query allowlist rules for agentless sensitive file detection alerts | Queries the list of allowlist rules for agentless sensitive file detection alerts. |
| DeleteMaliciousNote | Delete an agentless detection note | Deletes a note for an agentless detection alert event. |
| RetryAgentlessTask | Retry an agentless detection task | Retries an agentless detection task. |
| ListAgentlessRegion | Retrieve regions supported by agentless detection | Retrieves the regions supported by agentless detection. |
Core file monitoring
|
API |
Title |
Description |
| ListFileProtectPluginStatus | ListFileProtectPluginStatus | Retrieves information about the Security Center agent installed on servers on which core file monitoring rules take effect. The information includes the installation status of the Security Center agent and whether the core file monitoring feature is supported. |
| UpdateFileProtectEventStatus | UpdateFileProtectEventStatus | Modifies the status of core file monitoring events reported by the Security Center agent. |
| GetFileProtectDashboard | GetFileProtectDashboard | Retrieves information about the core file monitoring feature, including the number of effective rules and the installation status of the Security Center agent on servers. |
| ListFileProtectEvent | Get core file protection alert event list | Filters and retrieves a list of rules that match the specified conditions. |
| UpdateFileProtectRemark | Modify Core File Monitoring Event Remarks | Modify Alert Remarks |
| GetFileProtectEvent | GetFileProtectEvent | Retrieves information about core file monitoring events. |
Alert settings
|
API |
Title |
Description |
| Non-Mirror Program Defense | Non-Mirror Program Defense | |
| ListContainerDefenseRuleClusters | Retrieve all clusters associated with non-image-based program defense rules | Retrieves all clusters associated with non-image-based program defense rules. |
| ListContainerDefenseRule | Retrieve defense rules for non-image programs | Retrieves the list of defense rules for non-image programs. |
| GetContainerDefenseRuleDetail | Retrieve non-image process defense rule details | Retrieves the details of a non-image process defense rule. |
| ModifyContainerDefenseRule | ModifyContainerDefenseRule | Modifies a rule for non-image program defense. |
| ModifyContainerDefenseRuleSwitch | Modify non-image program defense rule switch | Modifies the switch status of a non-image program defense rule. |
| Risk mirror blocking | Risk mirror blocking | |
| ListOpaClusterStrategyNew | Retrieve risky image blocking policies | Retrieves the list of risky image blocking policies. |
| CreateOpaStrategyNew | CreateOpaStrategyNew | Creates a rule to block at-risk images. |
| GetOpaStrategyDetailNew | GetOpaStrategyDetailNew | Retrieves the details of the rule that is used to block at-risk images. |
| UpdateOpaStrategyNew | Update risky image blocking policy | Updates the risky image blocking policy. |
| DeleteOpaStrategyNew | Delete a risky image blocking policy | Deletes a risky image blocking policy. |
| GetOpaClusterLabelList | GetOpaClusterLabelList | Retrieves information about the tags that are added to containers based on the feature of proactive defense for containers. |
| GetOpaClusterImageList | Get Cluster Image Information | Get cluster image information. |
| GetOpaClusterNamespaceList | GetOpaClusterNamespaceList | Retrieves information about the namespaces of clusters for which the rules of the at-risk image blocking type are configured in proactive defense for containers. |
| DescribeMatchedMaliciousNames | Query malicious file types | Queries the list of malicious file types. |
| Container Escape Prevention | Container Escape Prevention | |
| ListAegisContainerPluginRule | ListAegisContainerPluginRule | Query user configurations. |
Container active defense
|
API |
Title |
Description |
| ListSasContainerWebDefenseRule | List container file defense rules | Queries container file defense rules. |
| GetSasContainerWebDefenseRule | Retrieve container file defense rule details | Retrieves a container file defense rule. |
| OperateSwitchStatus | Change the status of a container file defense rule | Changes the status of a container file defense rule. |
| ModifySasContainerWebDefenseRule | Modify a container file defense rule | Modifies a container file defense rule. |
Container file defense
|
API |
Title |
Description |
| ListInterceptionTargetPage | Query container firewall protection objects | Queries the network objects protected by micro-segmentation (container firewall). |
| ModifyInterceptionTarget | Modify container firewall network object | Modifies the network object information of a container firewall. |
| ListClusterInterceptionConfig | Query cluster interception rules | Queries the list of cluster interception rules. |
| ListClusterCnnfStatusDetail | Query container firewall status details | Queries the status details of the container firewall. |
| ModifyInterceptionRule | Modify a container proactive defense interception rule | Modifies a container proactive defense interception rule. |
| ModifyInterceptionRuleSwitch | Modify container proactive defense interception policy switch | Modifies the switch status of container proactive defense interception policies. |
Container firewall
|
API |
Title |
Description |
| DescribeClientConfStrategy | Query client configuration policy | Queries the machine configuration information for different client tags. |
| DescribeClientConfSetup | Query client configuration steps | Queries the resource configuration information of a client. |
| DescribeInstallCode | Retrieve installation key | Retrieves the installation verification key for the agent client installation command. |
| DeleteInstallCode | Delete an installation code | Deletes an installation code. |
| ListPluginForUuid | Query asset plugin information | Query plugin information of an asset. |
| UnbindAegis | Unbind non-Alibaba Cloud servers from security center | Unbinds non-Alibaba Cloud servers from Security Center. |
| DescribeAgentInstallStatus | Query agent installation status | Queries the Agent installation status after an Agent installation command is run by using Cloud Assistant. This operation supports querying the installation status only for installations initiated within the last 2 minutes. |
| DescribeInstallCaptcha | Retrieve the installation verification code for manual agent installation | Retrieves the installation verification code for manually installing the Agent. |
| DescribeInstallCodes | Query the list of commands for manually installing the security center agent | Queries the list of commands for manually installing the Security Center agent. |
| ListUninstallAegisMachines | Query assets without the client installed | Queries information about assets that do not have the client installed. |
| DescribeClientProblemType | Query client issue list | Retrieves the category list of client issue diagnostics. |
Agent client
|
API |
Title |
Description |
| DeleteSearchCondition | Delete a saved search condition | Deletes a saved search condition from the Assets module of Security Center. |
| ModifySearchCondition | Edit common filter conditions for assets | Edits the common filter conditions for host assets. |
| DescribeGroupStruct | Retrieve group structure | Retrieves the group structure. |
| ListCloudAssetInstances | Query the cloud service asset list | Queries the list of cloud service assets. |
| DescribeImageInfoList | Query Image List for Console Asset Management | Query the image list. |
| DescribeLogShipperStatus | Query log analysis feature status | Queries the availability status of the log analysis feature. |
| GetCloudAssetSummary | Retrieve cloud asset summary | Retrieves the summary of cloud assets. |
| GetCloudAssetDetail | GetCloudAssetDetail | Obtains the details of cloud assets. |
| ModifyAssetImportant | Set asset importance | Sets the importance level of assets. |
| ModifyGroupProperty | Modify the name of a server group | Modifies the name of a server group. |
| DeleteGroup | Delete a server group | Deletes a server group. |
| DeleteTagWithUuid | Delete asset labels | Deletes custom labels bound to assets. |
| ModifyLoginBaseConfig | Modify basic logon security settings for a single asset | Modifies the basic configuration of logon security settings for a single asset. |
| ModifyPushAllTask | Send a security check task with one click | Sends a security check task to asset servers with one click. |
| DescribeAssetDetailByUuid | Query server asset details and extended information | Queries the details and extended information of a server asset by UUID. |
| DescribeGroupedInstances | Query Asset Statistics | Query asset statistics by specified aggregation dimensions. |
| QueryGroupIdByGroupName | Query asset group ID | Queries the ID of an asset group by group name. |
| DescribeAssetSummary | Query core count statistics information of protected assets | Queries the core count statistics information of assets that are protected by Security Center. |
| DescribeAllEntity | Query all server asset list information | Retrieves the list of all server assets, including asset group IDs and asset names. |
| DescribeFieldStatistics | Query server statistics information in assets | Queries the statistics information of servers in your assets. |
| DescribeGroupedTags | Query label statistics information | Queries the statistics information of asset labels. |
| DescribeAllGroups | Query server group information | Queries information about all server groups. |
| DescribeInstanceStatistics | Query server statistics information | Queries the statistics information of server asset instances. |
| DescribeDomainCount | Query domain name asset count | Queries the number of your domain name assets. |
| DescribeDomainList | Query domain name asset information | Queries information about your domain name assets. |
| DescribeDomainDetail | Query domain name asset details | Queries the details of your domain name assets. |
| DescribeCloudCenterInstances | Query asset information | Queries asset information that meets specified search conditions. For example, you can search for assets by instance name or region. Two pagination methods are supported: page-based pagination and NextToken-based pagination. We recommend that you use NextToken-based pagination. |
| DescribeSearchCondition | DescribeSearchCondition | Queries the filter conditions that are used to search for assets. |
| DescribeCriteria | DescribeCriteria | Queries the filter conditions that are used to search for assets in fuzzy match mode. |
| DescribeAssetDetailByUuids | Query asset details | Queries the details of an asset (ECS instance). |
| DescribeImageStatistics | Query risk statistics information of container image assets | Queries the risk statistics information of container image assets. |
| DescribeContainerStatistics | Query alert statistics of container assets | Queries the alert statistics of container assets. |
| ModifyAssetGroup | Modify an asset group | Modifies an asset group. |
| DescribeSasPmAgentList | Query O&M plug-in status list | Queries the status list of O&M plug-ins. |
| ModifyAssetCleanConfig | Modify offline host cleanup configuration | Modifies the cleanup configuration for offline hosts. Only non-Alibaba Cloud hosts are supported. |
| AddCloudVendorAccountAK | AddCloudVendorAccountAK | Adds the configuration information of multi-cloud assets. |
| DeleteCloudVendorAccountAK | DeleteCloudVendorAccountAK | Delete multi-cloud asset synchronization configuration. |
| DescribeCloudVendorAccountAKList | DescribeCloudVendorAccountAKList | Queries the multi-cloud assets added to Security Center. |
| ModifyCloudVendorAccountAK | Modify multi-cloud asset authorization configuration | Modifies the authorization and authentication configuration of multi-cloud assets. |
| AddCloudVendorTrialConfig | AddCloudVendorTrialConfig | Adds configurations of connecting the audit logs of a third-party cloud asset. |
| SetSyncRefreshRegion | Set asset refresh and sync region list | Sets the region list for asset refresh and synchronization. |
| GetSupportedModules | Retrieve module information supported by multi-cloud vendors | Retrieves the list of modules supported for authorization. |
Asset management
|
API |
Title |
Description |
| DescribePropertyUsageTop | Query asset fingerprints statistics by type | Retrieves the top 5 statistics information for ports, processes, software, accounts, or middleware by occurrence count in your assets using the Asset Fingerprints feature. |
| DescribePropertyScaProcessDetail | DescribePropertyScaProcessDetail | Queries the Java processes that are collected by the asset fingerprints feature of Security Center in your assets. |
| GetAssetsPropertyItem | Query asset fingerprints aggregated list | Queries the aggregated list of Asset Fingerprints for startup items, kernel modules, or websites. |
| GetAssetsPropertyDetail | Query asset fingerprints detail list | Queries the details of Asset Fingerprints for startup items, kernel modules, or web sites. |
| DescribePropertyCronDetail | Query Asset Fingerprint Investigation Task List Details | Query Asset Fingerprint Scheduled Task Details |
| DescribePropertyCount | DescribePropertyCount | Queries the statistics of asset fingerprints. The assets include processes, ports, software, accounts, middleware, websites, web services, scheduled tasks, startup items, and databases. |
| DescribePropertyPortDetail | Query Asset Fingerprint Information of Port Assets | Query Details of Asset Fingerprint Port Collection |
| DescribePropertyProcDetail | Query Asset Fingerprint of Process Assets | Query Details of Asset Fingerprint Collection Process |
| DescribePropertyPortItem | Retrieve all port information | Retrieves information about all ports. |
| DescribePropertySoftwareDetail | Retrieve detailed information of a software in the software list | Query details of asset fingerprint software collection |
| DescribePropertyUserDetail | Query account asset fingerprint information of a server | Queries the Asset Fingerprints information of account assets on a server. |
| DescribeModuleConfig | Retrieve asset fingerprints module settings | Queries the settings of the Asset Fingerprints module. |
| DescribePropertyScaDetail | Query middleware list details in asset fingerprints investigation | Queries the details of the middleware list on the Asset Fingerprints investigation page. |
Asset fingerprints
|
API |
Title |
Description |
| GetSecurityScoreRule | Query custom security scoring rule details | Queries the details of custom security scoring rules. |
| ChangeSecurityScoreRule | ChangeSecurityScoreRule | Modifies the details of the deduction modules of the security score feature, including custom settings. |
| DescribeSecureSuggestion | Query Security Risk Handling Suggestions Details | Query Security Risk Handling Suggestions Details |
Security score
|
API |
Title |
Description |
| DescribeExposedInstanceCriteria | Query conditions supported for querying exposed assets | Retrieves the supported query conditions for querying exposed assets. |
| DescribeExposedInstanceList | Query information about internet-exposed assets | Queries information about assets exposed on the Internet. |
| DescribeExposedStatistics | Query the statistics of asset exposure analysis | Queries the statistics of asset exposure analysis. |
| DescribeExposedStatisticsDetail | Details of exposed asset statistics | Queries the list of gateway assets, ports, system components, or public IP addresses that are exposed on the Internet. |
Exposed assets
|
API |
Title |
Description |
| ListUuidsByAppId | Query serverless instance uUIDs by application ID | Queries the list of Serverless instance UUIDs by application ID. |
| ListMachineApps | Query SAE applications of a serverless instance | Queries the Serverless Application Engine (SAE) applications of a serverless instance. |
| DescribeContainerTags | DescribeContainerTags | Retrieves the details of container assets by using an attribute. |
| DescribeAssetsSecurityEventSummary | Query container asset risk statistics | Queries risk statistics for container assets. |
| DescribeImage | Query image digest | Queries the digest of an image. |
| DescribeContainerCriteria | Retrieve supported search criteria for the container list | Retrieves the supported search criteria for the container list. |
| DescribeContainerInstances | Retrieve container instance information list | Retrieves the list of container instance information. |
| DescribeImageCriteria | Retrieve image search criteria | Retrieves image search criteria. |
| DescribeImageInstances | Retrieve image information | Retrieves a list of image information. |
| DescribeImageRepoDetailList | Retrieve image repository list | Retrieves a list of image repositories. |
| DescribeImageRepoCriteria | Retrieve supported search criteria for image repositories | Retrieves the supported search criteria for image repositories. |
| DescribeGroupedContainerInstances | Query container list information | Queries the list of containers based on the specified group type. |
| RefreshContainerAssets | Refresh container asset data in the asset center | Refreshes container asset data in the asset center. |
Container management
|
API |
Title |
Description |
| DescribeClusterNetwork | DescribeClusterNetwork | Retrieves information about the network topology edge by cluster. |
| FindContainerNetworkConnect | Query container network connectivity information | Retrieves information about network connectivity between two nodes. |
Container visualization
|
API |
Title |
Description |
| UpdateWhiteList | Update the IP address whitelist of an image repository | Updates the IP address whitelist of an image repository. |
| GetRegistryScanDayNum | Query image security scan time range | Queries the time range for image security scanning. |
| GetDockerhubImageRiskStatistic | GetDockerhubImageRiskStatistic | Queries the risk statistics of Docker Hub images. |
| ListImageRegistryExtra | Query extra configuration information of an image repository | Queries the extra configuration information of an image repository. |
| SetBuildRiskDefineRuleConfig | Modify risk scan configuration for image build instructions | Modifies the risk scan configuration for image build instructions. |
| ListPrivateRegistryType | Query the number of image repositories of each type | Queries the number of image repositories of each type. |
| ListPrivateRegistryList | ListPrivateRegistryList | Retrieves image repositories. |
| SaveImageBaselineStrategy | SaveImageBaselineStrategy | Creates or updates an image baseline strategy. |
| OperateImageBaselineWhitelist | Manage image baseline whitelist | Manages the whitelist of image baseline check items. |
| DescribeImageBaselineStrategy | Query image baseline policy | Queries the image baseline policy. |
| DescribeImageBaselineItemList | Query baseline check items by image | Queries the list of baseline check results by image. |
| DescribeImageBaselineDetail | Query image baseline check result details | Queries the details of baseline check results for image scanning. |
| DescribeImageBaselineCheckResult | Query image baseline check results | Queries the detection results of image security scans. |
| DescribeAllImageBaseline | Retrieve all image baseline check items | Retrieves the list of all image baseline check items. |
| DescribeImageListBySensitiveFile | Query images with sensitive files | Queries information about images affected by sensitive files. |
| OpenSensitiveFileScan | Edit sensitive file scan switch | Modifies the sensitive file scan switch. |
| DescribeImageSensitiveFileList | Query sensitive files | Queries sensitive file information. |
| DescribeImageSensitiveFileByKey | Query sensitive files of an image | Queries the sensitive files of an image. |
| DescribeAffectedMaliciousFileImages | Query malicious file details in container images | Queries the details of malicious files detected in container images. |
| DescribeGroupedMaliciousFiles | Query malicious sample files in container images | Queries the list of malicious sample files in container images. |
| DescribeImageVulList | View container image vulnerability list | Queries the details of vulnerabilities detected by image security scans and the list of container images affected by the vulnerabilities. |
| DescribeImageGroupedVulList | Query image vulnerability information | Queries the list of image vulnerabilities. |
| DescribeImageListWithBaselineName | Query image baseline check result details | Queries the details of image baseline check results. |
| DescribeImageFixTask | Query the list of created image repair tasks | Queries the list of created image repair tasks. |
| DescribeImageScanAuthCount | Query image security scan authorization information | Queries the authorization quota information for image security scanning. |
| DescribeImageBaselineCheckSummary | Query image baseline check list for image security scans | Queries the image baseline check list of image security scans. |
| PublicCreateImageScanTask | Create an image scan task | Creates an image scan task that is not limited by a single primary task. |
| DescribeCountScannedImage | Query scanned image statistics | Queries statistics on scanned image data. |
Image security scan
|
API |
Title |
Description |
| CreateCheckPolicy | Create Custom Check Policy Category | Create Policy |
| CreateCheckItem | Create Custom Check Item | User creates a custom check item |
| DeleteCheckItem | Delete custom check items | Deletes user-defined check items in the Cloud Security Posture Management (CSPM) custom check item feature. |
| ListCheckItems | Query Custom Check Items | List custom check items for situational awareness |
| UpdateCheckPolicy | Modify Custom Check Item Policy Classification Settings | Update Custom Policy |
| GetCheckSale | Retrieve cloud service configuration check sales information | Retrieves the sales information of cloud service configuration check, including the number of authorized quotas and consumed quotas. |
| ModifyCheckRule | Modify CSPM check rules | Modifies the rule settings of Cloud Security Posture Management (CSPM). |
| VerifyCheckInstanceResult | Verifies the instance dimensions under a check item | Verifies the instance dimensions under a check item. |
| VerifyCheckResult | Check item-level validation | Performs check item-level validation. |
| RemoveCheckResultWhiteList | RemoveCheckResultWhiteList | Removes the check items of the configuration assessment feature from the whitelist. |
| AddCheckResultWhiteList | AddCheckResultWhiteList | Adds the check items of the configuration assessment feature to the whitelist. |
| RemoveCheckInstanceResultWhiteList | Remove whitelist status at the instance dimension | Removes the whitelist status at the instance dimension. |
| GetCheckSummary | Retrieve cloud platform configuration check overview | Retrieves the overview of cloud platform configuration checks. |
| ListInstanceCatalog | ListInstanceCatalog | Queries the asset types and asset subtypes for configuration assessment. |
| SubmitCheck | Submit a cloud service configuration check | Submits a cloud service configuration check. |
| ChangeCheckConfig | Modify cloud platform configuration check items | Modifies the check items for cloud platform configuration checks. |
| GetCheckConfig | Retrieve check item configurations for cloud platform configuration checks | Retrieves the check item configurations for cloud platform configuration checks. |
| GetCheckCountStatistic | GetCheckCountStatistic | Queries statistics on the number of risk items in cloud security posture management (CSPM) for cloud services. |
| ListCheckInstanceResult | ListCheckInstanceResult | Queries the instances that failed a specified check item of configuration assessment. |
| ListCheckResult | ListCheckResult | Retrieves the details of the risk items that are detected in the configuration checks on cloud services. |
| ListCheckStandard | ListCheckStandard | Queries the standards of configuration checks. |
| ListCheckItem | ListCheckItem | Queries the check items that can be customized. |
| StartBaselineSecurityCheck | StartBaselineSecurityCheck | Checks cloud service configurations. You can check all items or a specific item and verify whether an item is checked. |
| DescribeRiskItemType | Query the types of all cloud service configuration check items | Queries the types of all cloud service configuration check items. |
| DescribeRiskCheckSummary | Query cloud service configuration check result summary | Queries the summary of cloud service configuration check results, including the number of risk items, risk rate, number of affected assets, check time, and statistics by type. |
| DescribeRiskCheckResult | DescribeRiskCheckResult | Queries the check results of cloud service configurations by check item type or name. |
| DescribeRiskCheckItemResult | DescribeRiskCheckItemResult | Queries the assets that are affected by the risk item detected in configuration assessment based on a specified check item. |
| ListCheckRule | Query Cloud Security Posture Management Check Rules | Display cloud product configuration check rules |
| ListOperationTask | Query Cloud Security Posture Management Operation Tasks | Display the list of cloud product configuration check, repair, and rollback tasks |
| VerifyCheckCustomConfig | Validate threat detection service custom configuration | Authenticates whether the configuration information entered by a user is compliant with the requirements of the corresponding parameter settings. |
| ListCheckPolicies | Query Custom Check Item Policy Classification | List User Policies |
| UpdateCheckItem | Update Custom Check Item | User creates a custom check item |
| DeleteCheckPolicy | DeleteCheckPolicy | Delete custom scope directories in Cloud Security Posture Management (CSPM) custom checks. You can remove assigned standards, requirements, or sections. |
Cloud platform configuration check
|
API |
Title |
Description |
| DeleteBackupSnapshot | Delete backup snapshots | Deletes snapshots of anti-ransomware backups in Security Center. |
| QueryPreCheckDatabase | Query database pre-check task result | Queries the task result of a database dry run node. |
| ModifyUniBackupPolicy | Update anti-ransomware policy for databases | Modifies an anti-ransomware backup policy for databases. |
| DescribeUniBackupPolicyDetail | Query anti-ransomware policy details for databases | Queries the details of an anti-ransomware backup policy for databases. |
| CreateUniRestorePlan | Create a database anti-ransomware restoration task | Creates a database anti-ransomware restoration task. |
| DescribeBackupMachineStatus | Query backup server status | Queries the backup status of servers that are associated with an anti-ransomware backup policy. |
| UpgradeBackupPolicyVersion | Upgrade anti-ransomware backup policy version | Upgrades the version of an anti-ransomware backup policy. |
| DescribeExcludeSystemPath | Query anti-ransomware system excluded directories | Queries the excluded directories of the anti-ransomware system. |
| DescribeBackupClients | Query servers with the anti-ransomware client installed in a specified region | Queries servers that have the anti-ransomware client installed in a specified region. |
| DescribeBackupPolicies | Query Backup Policy List | Query anti-ransomware protection policies. |
| DescribeSupportRegion | Query regions supported by anti-ransomware | Queries the regions supported by anti-ransomware. |
| DescribeBackupRestoreCount | Query anti-ransomware restoration tasks | Queries data of anti-ransomware restoration tasks. |
| ModifyBackupPolicyStatus | Enable or shutdown an anti-ransomware policy | Enables or shuts down an anti-ransomware policy. |
| DeleteBackupPolicy | Delete ransomware mitigation policies | Deletes ransomware mitigation policies. |
Tamper protection
|
API |
Title |
Description |
| ModifyWebLockDeleteConfig | Delete a protected directory from a specified server | Deletes a protected directory from a specified server. |
| ModifyWebLockCreateConfig | Add a protected directory for a specified server | Adds a protected directory for a specified server. |
| ModifyWebLockUpdateConfig | Modify the protection policy of a specified server | Modifies the protection policy of a specified server. |
| ModifyWebLockStart | Create web tamper proofing protection for a server and enable the protection | Creates web tamper proofing protection for a specified server and enables the protection. |
| ModifyWebLockStatus | Modify web tamper-proofing status | Enables or shuts down web tamper-proofing for a server. |
| ModifyWebLockUnbind | Remove web tamper proofing from a server | Removes the web tamper proofing protection folder from a specified server. |
| OperateWebLockFileEvents | Handle web tamper-proofing alerting events | Handles web tamper-proofing alerting events. |
| ModifyWebLockProcessStatus | Set tamper-proofing process status | Sets the status of a tamper-proofing process. |
| DescribeWebLockExclusiveFileType | DescribeWebLockExclusiveFileType | Queries the types of files that are excluded from web tamper proofing. |
Virus detection
|
API |
Title |
Description |
| DescribeLatestScanTask | Query latest virus scan | Queries the progress of the most recent virus scan task. |
| CreateVirusScanOnceTask | CreateVirusScanOnceTask | Creates a one-time virus scan task that is immediately executed. |
| ListVirusScanMachine | Query alert hosts for virus scanning | Queries the list of alert hosts for virus scanning. |
| ListVirusScanMachineEvent | Query alert events detected by server scan | Queries virus alerts detected by a virus scan on a specific server. |
| ListVirusScanTask | Query virus scan tasks | Queries virus scan tasks that match specified conditions such as scan type, scan status, and scanned machine information. |
| GetVirusScanConfig | Retrieve periodic virus scan configuration | Retrieves the configuration of a periodic virus scan task. |
| OperateVirusEvents | Handle virus defense alerts | Handles virus defense alerts in batches. The handling types include deep scan and removal, adding to whitelist, ignoring, and manual handling. |
Alerts
|
API |
Title |
Description |
| DescribeGraph4InvestigationOnline | Query the investigation and tracing graph of alert events | Queries the investigation and tracing graph of Cloud Workload Protection Platform (CWPP) alert events to visually investigate and reconstruct cyberattack processes. |
| DescribeSecurityEventMarkMissList | Query alert whitelist rules | Queries the auto-whitelist rules for security alerts. |
| DescribeBackUpExportInfo | Retrieve security alert archive data export list | Retrieves the list of exported security alert archive data. |
| ListUuidsByWebPath | Query protected assets by web path | Queries protected assets by web path. |
| DescribeNsasSuspEventType | Query security alerting Alarm Metric | Queries security alerting Alarm Metric. |
| UpdateStrictEventName | Modify strict mode alert status | Modifies the strict mode configuration, including whether to enable alerting in strict mode. This is a full-update operation. |
| CreateSuspEventNote | Create a note for a security alert event | Creates a note for a security alert event. |
| CreateSimilarSecurityEventsQueryTask | Create a node to query alert events triggered by the same rule or Alarm Metric | Creates a node to query alert events triggered by the same rule or Alarm Metric through alerting. |
| DescribeSuspEventDetail | DescribeSuspEventDetail | Queries the details of an exception. An alert event consists of an alert and exceptions. Each alert event is associated with multiple exceptions. |
| DescribeSimilarEventScenarios | Query handling scenarios for alerts with the same trigger | Queries the handling scenarios for alerts triggered by the same rule or type. |
| DescribeSecurityStatInfo | Query statistics and trend data of security check items | Queries the statistics of each security check item and the daily statistics in the security check item trend chart. |
| DescribeLoginBaseConfigs | Query unusual logon detection rule configurations | Queries the configuration of unusual logon detection rules for servers. |
| DescribeAttackAnalysisData | DescribeAttackAnalysisData | Queries the statistics of attack analysis. |
| OperationSuspEvents | Handle alert events in batches | Handles alert events in batches. |
Anti-ransomware
|
API |
Title |
Description |
| ModifyCustomBlockRecord | Modify custom rule for brute-force attacks IP blocking | Modifies the rule record of a custom blocked IP address. |
| DeleteCustomBlockRecord | Delete a custom IP blocking policy | Deletes the blocking records of specific IP addresses that are custom-defined on one or more servers. |
| ModifyAntiBruteForceRule | Modify a defense rule against brute-force attacks | Modifies a defense rule against brute-force attacks. |
| ModifyInstanceAntiBruteForceRule | Modify the anti-brute-force attacks rule for a specified server | Modifies the anti-brute-force attacks rule for a specified server. |
| DescribeInstanceAntiBruteForceRules | Query servers on which brute-force attacks defense rules take effect | Queries information about servers on which brute-force attacks defense rules take effect. |
| DescribeAntiBruteForceRules | Query brute-force attacks prevention rules | Queries the brute-force attacks prevention rules that you have created. |
| DeleteAntiBruteForceRule | Delete an anti-brute-force rule | Deletes a specified anti-brute-force attacks rule. |
Web tamper-proofing
|
API |
Title |
Description |
| ListVulGlobalConfig | Query vulnerability global configuration | Queries the global configuration of vulnerabilities. |
| OperateImageVul | Operate on image vulnerabilities | Performs operations on image vulnerabilities. Supported operation types include fix, verify, ignore, and unignore. |
| ModifyVulTarget | Modify machine-level toggle settings for vulnerability scanning | Modifies the machine-level toggle settings for vulnerability scanning. |
| ModifyVulConfig | Modify vulnerability scanning switch configuration | Modifies the vulnerability scanning switch configuration. |
| ModifyConcernNecessity | Set the urgency levels of vulnerabilities that the user is concerned about | Sets the urgency levels of vulnerabilities that the user is concerned about. |
| ModifyAutoDelConfig | Set automatic deletion time for expired vulnerabilities | Sets the automatic deletion time for expired vulnerabilities. |
| DescribeVulNumStatistics | Get vulnerability statistics | Get vulnerability statistics. |
| DescribeVulListPage | DescribeVulListPage | Queries the vulnerabilities that can be detected. |
| DescribeMachineCanReboot | Query whether a server can be restarted | Checks whether a server can be restarted when a vulnerability fix requires a restart to take effect. |
| DescribeEmgUserAgreement | Query emergency vulnerability user agreement | Queries the emergency vulnerability user authorization agreement. |
| DescribeClusterVulStatistics | Query cluster vulnerability statistics | Queries cluster vulnerability statistics. |
| DescribeAppVulScanCycle | Query application vulnerability scanning epoch | Queries the application vulnerability scanning epoch. |
| ListVulAutoRepairConfig | Query auto-fix vulnerability configurations | Queries the configurations of vulnerabilities that can be automatically fixed. |
| DescribeInstanceRebootStatus | Query instance restart status | Queries the restart status of instances. |
| RebootMachine | Restart an instance | Restarts an instance. Currently, only Windows instances are supported. |
| ModifyVulTargetConfig | Configure vulnerability detection settings for a single server | Configures the vulnerability detection settings for a single server. |
| ModifyStartVulScan | Trigger one-click vulnerability scan | Enables the one-click scan feature on the vulnerability management page of the console. |
| ModifyEmgVulSubmit | Perform emergency vulnerability detection | Performs emergency vulnerability detection. |
| ModifyCreateVulWhitelist | ModifyCreateVulWhitelist | Adds vulnerabilities to the whitelist. After you add the vulnerabilities to the whitelist, Security Center no longer generates alerts for the vulnerabilities. |
| GetVulWhitelist | GetVulWhitelist | Retrieves information about a vulnerability whitelist. |
| DeleteVulWhitelist | Delete a specified vulnerability whitelist | Deletes a specified vulnerability whitelist. |
| DescribeEmgVulItem | Query emergency vulnerability information | Queries the details of emergency vulnerabilities. |
| DescribeConcernNecessity | Query necessity information for fixing followed vulnerabilities | Queries the necessity information for fixing vulnerabilities that you follow. |
| DescribeVulWhitelist | Query vulnerability whitelists by page | Queries vulnerability whitelists by paging. |
| ExportVul | ExportVul | Export vulnerability list |
| DescribeVulExportInfo | Query the progress of a vulnerability export task | Queries the progress of a vulnerability export task. |
| GetVulStatistics | GetVulStatistics | Queries the statistics on vulnerabilities in asset groups. |
Virus scan
|
API |
Title |
Description |
| ListBaselineCheckWhiteRecord | Query baseline whitelist records | Queries baseline whitelist records. |
| ListCheckItemWarningSummary | ListCheckItemWarningSummary | Queries the risk statistics of check items by page. |
| ListCheckItemWarningMachine | Get Warning Machines for a Specific Baseline Check Item | Query the list of warning machines for a specific baseline check item. |
| DescribeHcExportInfo | Query baseline risk export information | Queries information about a baseline risk export, such as the file name and download link. |
| DescribeRisks | Query baseline details | Queries baseline details by baseline ID or name. |
| DescribeCheckFixDetails | Query check item fix details | Queries the configurable parameters for fixing a specified check item. |
| IgnoreCheckItems | IgnoreCheckItems | Adds risk items to the whitelist or removes risk items from the whitelist by specifying servers and risk items. |
| DescribeExposedCheckWarning | Query baseline weak password risks of exposed assets | Queries the weak password risks of a specified exposed server. |
| DescribeCheckWarningSummary | Query baseline check result statistics | Queries the statistics of baseline check results, such as the number of servers checked, the number of check items, and the latest check pass rate. |
| DescribeCheckWarnings | Query check item information | Queries check item information for a specified risk item and a specified server. |
| DescribeCheckWarningDetail | Query details of a specified check item | Queries the details of a specified check item. |
| DescribeWarningMachines | DescribeWarningMachines | Queries information about servers on which a baseline check is performed. The information includes the IDs of the servers, the statistics of a risk item, and the status of the risk item. |
| DescribeCheckEcsWarnings | Query the number of high-risk weak password risks | Queries the number of high-risk weak password risks that exist in your assets. |
| DescribeStrategyDetail | Retrieve baseline check policy details | Retrieves the details of a baseline check policy. |
| ExportWarning | ExportWarning | Exports baseline check results. |
| DescribeStrategy | DescribeStrategy | Queries the details about baseline check policies. |
| DeleteStrategy | Delete a policy | Deletes a baseline check policy. |
| ValidateHcWarnings | Batch verify baseline check risk items | Verifies existing baseline risks. If the verification passes, the status of the risk items is updated to passed. |
| DescribeCustomizedStrategyTargets | Query custom policy targets | Queries the target machines included in a custom policy. |
| UpdateBaselineCheckWhiteRecord | Update a baseline whitelist record | Updates a baseline whitelist record. |
| DeleteCustomizedDict | Delete a custom weak password | Deletes a custom weak password file. |
| DescribeDefaultKeyInfo | Query default key information | Retrieves the keywords used to generate a custom dictionary in custom weak password detection. |
| CreateUserSetting | Save user baseline check settings | Saves the risk level settings for baseline checks of a user. |
| ExecStrategy | Execute a baseline check policy | Performs a baseline check on machines within a specified policy. |
Security alert
|
API |
Title |
Description |
| ListSystemRuleAggregationTypes | Query aggregation types of system rules | Queries the aggregation types of system defense rules. |
| ListClientUserDefineRules | ListClientUserDefineRules | Queries custom defense rules. |
| ListSystemClientRuleTypes | Query system rule types effective for a user | Queries the system rule types. |
| ListSystemClientRules | ListSystemClientRules | Queries system defense rules. |
| ListSystemAggregationRules | Retrieve details of system rule clusters | Retrieves the details of system rule clusters. |
| ModifyClientUserDefineRule | Modify a client custom rule | Modifies a custom rule for malicious behavior defense. |
| ListClientUserDefineRuleTypes | ListClientUserDefineRuleTypes | Queries the supported types of custom defense rules. |
| GetClientUserDefineRule | Get client user-defined rules | Queries custom rules for malicious behavior defense. |
| DeleteClientUserDefineRule | DeleteClientUserDefineRule | Deletes specified custom defense rules. |
| AddClientUserDefineRule | Add a custom rule | Create a custom defense rule. |
Brute-force attack prevention
|
API |
Title |
Description |
| ModifyAccessKeyLeakDeal | Handle accessKey pair leak records | Handles an AccessKey pair leak record. |
| DescribeAccesskeyLeakList | Query leaked accessKey information | Queries information about leaked AccessKey pairs in your assets. |
| DescribeAccessKeyLeakDetail | Query accessKey pair leak event details | Queries the details of an AccessKey pair leak event. |
Vulnerability fix
|
API |
Title |
Description |
| GetHoneypotAttackStatistics | Query attack event statistics information of a honeypot attack source | Queries the attack event statistics information of a honeypot attack source. |
| UpdateHoneypotNode | Update a honeypot management node | Updates a specified honeypot management node. |
| GetHoneypotNode | GetHoneypotNode | Retrieves the details of a specified management node. |
| UpdateHoneypot | Modify honeypot configuration | Modifies the configuration of a specified honeypot. |
| ListHoneypot | Query honeypot list | Queries a list of honeypots. |
| UpdateHoneypotPreset | Modify honeypot template configuration | Modifies the configuration of a specified honeypot template. |
| UpdateHoneypotProbe | Update probe properties | Updates the properties of a specified probe. |
| ListHoneypotProbe | Query honeypot probes | Queries the list of honeypot probes. |
| DeleteHoneypotPreset | Delete a honeypot template configuration | Deletes a specified honeypot template configuration. |
| DeleteVpcHoneyPot | Delete a honeypot | Deletes a specified honeypot instance. |
| DescribeHoneyPotAuth | Query the number of authorized honeypot instances | Queries the number of authorized honeypot instances. |
| DescribeHoneyPotSuspStatistics | Query top 5 vPCs or assets by security alert count | Queries information about the top 5 VPCs or assets ranked by the number of security alerts. |
Baseline check
|
API |
Title |
Description |
| ModifyLogMetaStatus | Modify log analysis enabling status | Modifies the enabling status of log analysis. |
| DescribeLogMeta | Query security center log analysis configuration | Queries the configuration information of log analysis in Security Center. |
| ModifyOpenLogShipper | Activate simple log service | Activates Simple Log Service. |
| DescribeLogstoreStorage | Query log analysis storage capacity of security center | Queries the log analysis storage capacity of Security Center. |
| ModifyClearLogstoreStorage | Clear security center logs | Clears the storage capacity space for log analysis. |
Malicious behavior defense
|
API |
Title |
Description |
| ModifyNoticeConfig | Modify notification configuration | Modifies notification configuration information. |
| DescribeDingTalk | Retrieve dingTalk notification list | Retrieves the list of DingTalk notifications. |
| DescribeNoticeConfig | DescribeNoticeConfig | Queries notification settings. |
| DescribeDataSource | Query data sources for dingTalk alert configurations | Queries the data sources for DingTalk alert configurations. You can configure the scope of DingTalk alert notifications based on the data sources. |
AK leak detection
|
API |
Title |
Description |
| DeleteAutoTagRules | Delete an automatic asset tagging rule | Deletes an automatic asset tagging rule. This operation is used with the system configuration, feature settings, multi-cloud configuration management, and asset management rule features of Security Center. |
| DeleteIdcProbe | Delete an IDC probe | Deletes an IDC probe that is created in the IDC probe feature of Security Center. |
| ModifyIdcProbe | ModifyIdcProbe | Updates the configurations of an IDC probe. |
| DescribeCommonTargetResultList | Query configured assets of a switch | Queries the configured asset information for a specific switch type. |
| OperateSuspiciousOverallConfig | Set the global configuration for abnormal events | Sets the global configuration for abnormal events. |
| DescribeCommonOverallConfig | Master switch global configuration | Queries the global configuration of the master switch. |
| OperateCommonTargetConfig | Configure general switch for feature module | Configures the general switch for a feature module by type, including image scanning, endpoint engine detection, container network visualization, and container escape prevention. |
Honeypot
|
API |
Title |
Description |
| DescribeExportInfo | View export progress | Queries the progress of an export task. |
| ExportRecord | ExportRecord | Exports detection results from various Cloud Security Center features, such as Asset Center, cloud platform configuration check, image security scan, attack analysis, and AK leakage detection, to an Excel file. |
Log analysis
|
API |
Title |
Description |
| GetFileDetectApiInvokeInfo | GetFileDetectApiInvokeInfo | Obtains the usage information of the malicious file detection SDK. |
| CreateFileDetect | CreateFileDetect | Submits a file to the cloud for detection. |
| GetFileDetectResult | GetFileDetectResult | Retrieves file detection results in batches using `HashKey` values. |
| ListCompressFileDetectResult | ListCompressFileDetectResult | Retrieves a list of file detection results from an archive. |
Notification
|
API |
Title |
Description |
| ListOssScanConfig | ListOssScanConfig | Queries the configuration of an Object Storage Service (OSS) file detection policy. |
| GetObjectScanEvent | GetObjectScanEvent | Retrieves the details of an alert event that is generated for a malicious object. |
| ListObjectScanEvent | Query malicious file alerts | Queries the list of malicious file alerts. |
| GetOssBucketScanStatistic | Retrieve OSS scan statistics | Retrieves OSS scan statistics. |
| ListOssBucketScanInfo | Query risk information list of buckets | Queries the risk information list of buckets. |
| UpdateOssScanConfig | Update scan policy configuration | Updates the scan policy configuration for OSS file detection under the malicious file detection feature. |
| ListOssBucket | Query bucket list | Queries the list of buckets. |
| CreateOssScanConfig | CreateOssScanConfig | Creates a policy for detecting malicious Object Storage Service (OSS) objects by using the SDK for malicious file detection feature. |
| ListSupportObjectSuffix | Query supported file type suffixes | Queries the supported file type suffixes. |
| RefreshOssBucketScanInfo | Refresh bucket list | Refreshes the bucket list. |
| GetOssScanConfig | Retrieve scan policy configuration | Retrieves the scan policy configuration. |
Feature settings
|
API |
Title |
Description |
| GenerateOnceTask | GenerateOnceTask | Creates a one-time scan task. |
| DeleteCycleTask | Delete a general scan plan task | Deletes an epoch-based scan node, including image scans, emergency vulnerability scanning, and virus scans. |
| ModifyCycleTask | Modify scheduled task cycle | Modifies the run epoch of periodic nodes, including image scan, emergency vulnerability scanning, and virus scan nodes. |
| DescribeOnceTask | Query client tasks | Queries a list of client tasks. |
| DescribeCycleTaskList | Query general-purpose scheduled task list | Queries the list of general-purpose scheduled nodes, including image scan, emergency vulnerability scanning, and virus scan nodes. |
| GetOnceTaskResultInfo | GetOnceTaskResultInfo | Queries the execution results of a one-time scan task, such as an asset fingerprint collection task, a vulnerability scan, or an image security scan. |
| GetLastOnceTaskInfo | GetLastOnceTaskInfo | Retrieves runtime information for the latest scan task to check its completion status. |
| DescribeOnceTaskLeafRecordPage | Retrieve subtask information of a one-time task | Retrieves the details of subtasks for a one-time scan task result, including image scanning and image asset synchronization. |
Export detection results
|
API |
Title |
Description |
| UpdateSelectionKeyByType | Update the key for an asset selection type | Modifies the key that corresponds to a specified type. |
Service-linked role
|
API |
Title |
Description |
| CreateSoarStrategyTask | Create a policy task | Creates a task under My Policies in Task Center. |
| DeleteSoarStrategyTask | Delete a task center task | Deletes a policy task that is in the waiting state from the task center. |
| DescribeSoarStrategyTaskDetail | Query policy task details in the task center | Queries the details of a policy task in the task center, including the task execution status and the corresponding flowchart. |
| ModifySoarStrategySubscribe | Add or remove a policy template to or from my policies | Adds or removes a policy template to or from My Policies in the task center. |
| DescribeSoarSubscribedStrategy | Query custom policies in the task center | Queries the list of custom policies created in the task center of Security Center. |
| DescribeSyncAssetTaskLogDetail | Query asset synchronization task details | Queries the details of IDC scan tasks for asset synchronization. |
| DescribeSoarStrategyTaskParams | Query policy task parameters in the task center | Queries the parameters of a policy task in the task center. |
| ProcessSoarStrategyTask | Execute a policy task in the task center | Executes a policy task in the task center. |
| DescribeSoarStrategyTaskResult | Query policy task execution results | Queries the execution results of a policy task in the task center. |
Malicious file detection SDK
|
API |
Title |
Description |
| DescribeDomainSecureVulList | Query vulnerability list in a website security report | Queries the vulnerability list in a website security report. |
| DescribeDomainSecureRiskList | Query risky websites in website security report | Queries websites with risks and their associated security information from the website security report, including the number of vulnerabilities and alerts. |
| DescribeDomainSecureAlarmList | Query security alert data from a website security report | Queries security alert data from a website security report. |
| DescribeDomainSecureStatistics | Query website security report statistics | Queries the statistics of a website security report, including the number of websites and security events. |
| DescribeDomainSecureScore | Query the security score of a website security report | Queries the security score of a website security report. The maximum score is 100. |
Malicious file detection OSS
|
API |
Title |
Description |
| GetAuthSummary | Retrieve authorization statistics | Retrieves authorization statistics. |
| DescribeVersionConfig | Query edition details of a purchased security center instance | Queries the edition details of a purchased Security Center instance. |
| ModifyPostPayModuleSwitch | Modify pay-as-you-go feature status | Enables or disables pay-as-you-go billing for a specified feature. |
| UpdatePostPaidBindRel | Change Pay-As-You-Go Service Protection Version | Change Postpaid Asset Authorization Version |
| BindAuthToMachine | Bind authorization to servers | Binds authorization information to servers. |
Task management
|
API |
Title |
Description |
| DescribeClusterBasicInfo | Query cluster information by cluster ID | Queries cluster information by cluster ID. |
| DescribeQuaraFileDownloadInfo | Query download link for a quarantined file | Queries the download information of a quarantined file for a security alert. |
| DescribeAffectedAssets | Query affected assets | Queries the list of affected assets from virus defense check results. |
| DescribeEventOnStage | Query platforms supported by threat detection | Queries the platforms supported by threat detection. |
| DescribeTraceInfoDetail | Query tracing information | Queries the tracing information of a security alert. |
| DescribeImageLatestScanTask | Query the most recent scan status of an image | Queries the most recent scan task for an image. |
| DescribeImageRepoList | Retrieve image defense switch configuration statistics information | Retrieves statistics information on image defense switch configurations. |
| PageImageRegistry | Query image repositories by page | Queries a list of image repositories. |
| QueryJenkinsImageRegistryPersistenceDay | Query jenkins image repository image retention duration | Queries the image retention duration of a Jenkins image repository. |
| UpdateJenkinsImageRegistryName | Modify jenkins image repository image name | Modifies the image name in a Jenkins image repository. |
| UpdateJenkinsImageRegistryPersistenceDay | Modify jenkins image repository image retention period | Modifies the image retention period for a Jenkins image repository. |
| DeleteInterceptionRule | Delete an interception rule | Deletes a microsegmentation interception rule. |
| DeleteInterceptionTarget | Delete interception targets | Deletes active network objects from the container firewall. |
| DescribeCustomBlockRecords | Query custom interception policies | Queries brute-force attacks interception records for custom blocked IP addresses defined on one or more servers. |
| ListInterceptionHistory | Query container firewall interception records | Queries container firewall interception records. |
| GetInterceptionRuleDetail | GetInterceptionRuleDetail | Retrieves the details of a microsegmentation defense rule. |
| ListImageRegistryRegion | Query regions that support private image registry access | Queries the regions that support private image registry access. |
| DeletePrivateRegistry | Delete a private repository | Deletes a private image repository by image repository ID. |
| ListPodRisk | Retrieve security risks of pod groups | Retrieves the security risks of pod groups. |
| ListImageRisk | Retrieve security information of container images | Retrieves the security information of container images. |
| DeleteServiceTrail | Delete actionTrail data delivery | Deletes an ActionTrail data delivery configuration. |
| CreateServiceTrail | Create actionTrail data delivery | Creates a service trail. |
| DescribeMonitorAccounts | DescribeMonitorAccounts | Queries the list of accounts that are added to the multi-account management feature as members. |
| DescribeImageVulWhiteList | Query image vulnerability whitelist | Queries the image vulnerability whitelist. |
| QueryAttackCount | Query security alert counts by attack phase | Queries the number of security alert events that occurred in each attack phase. |
| GetSwitchRegionDetail | Query service switchover progress | Queries the progress of a service switchover. For example, when a server connection is being migrated from China to Singapore, this operation retrieves the migration progress and status. |
| UpdateImageVulWhitelistTarget | Update an image vulnerability whitelist | Updates an image vulnerability whitelist. |
| DeleteImageVulWhitelist | Delete image vulnerability whitelist | Deletes an image vulnerability whitelist. |
| DescribeContainerScanConfig | Query container runtime scan configuration | Queries the container runtime scan configuration. |
| ModifyContainerScanConfig | Modify container runtime scan configuration | Modifies the container runtime scan configuration. |
| DescribeCanFixVulList | Query fixable vulnerabilities | Queries the list of fixable vulnerabilities. |
| ModifyImageFixCycleConfig | ModifyImageFixCycleConfig | Updates the configurations of a scheduled image fix. |
| DescribeImageFixCycleConfig | Query scheduled image fix configuration | Queries the scheduled image fix configuration. |
| ListHoneypotProbeUuid | Query probe iDs by probe type and node ID | Queries probe IDs by probe type and node ID. |
| UpdateHoneypotProbeBind | Modify a probe service | Modifies a probe service. |
| ListHoneypotEvents | List honeypot attack events | Retrieves intrusion events of a honeypot. |
| ListHoneypotAttackerPortrait | ListHoneypotAttackerPortrait | Queries the attacker profile based on the source IP address of the attack. |
| ListHoneypotAttackerSource | ListHoneypotAttackerSource | Queries the attack source IP addresses that are used to attack a honeypot. |
| UpdateCommonSwitchConfig | UpdateCommonSwitchConfig | Updates the settings of common switches. |
| UpdateFileUploadLimit | Modify the QPS upper limit for client file uploads | Modifies the QPS for client file uploads. |
| GetFileDetectReport | GetFileDetectReport | Queries the cloud sandbox check results of malicious files. |
| DescribeImageEventOperationPage | Query alerting handling rules by paging | Queries alerting handling rules by using paging. |
| DescribeImageEventOperationCondition | Query conditions for handling image events | Queries the conditions for handling image events. |
| UpdateImageEventOperation | Update an alert handling rule | Updates an alert handling rule. |
| DeleteImageEventOperation | Delete an alert disposal rule | Deletes an alert disposal rule. |
| ListGroups | Retrieve server group list | Retrieves the list of server groups for the current user. |
| UploadedHoneyPotFile | Upload a honeypot file and create a confirmed record | Creates and confirms a record after a honeypot file is uploaded. |
| ListHoneypotEventFlows | Retrieve honeypot attack event timeline | Retrieves the details of a honeypot attack event. |
| ModifyImageRegistry | ModifyImageRegistry | Modifies the configuration of an image registry. |
| DeleteK8sAccessInfo | Delete kubernetes access information | Deletes Kubernetes access information. |
| DeleteContainerPluginRule | Delete a container escape prevention rule | Deletes a container escape prevention rule. |
| ModifyContainerPluginRule | Modify a container escape prevention rule | Modifies a container escape prevention rule. |
| DeleteSasContainerWebDefenseRule | Delete a container tamper-proofing rule | Deletes a container tamper-proofing rule. |
| ListK8sAccessInfo | List k8s access information | Lists K8s access information. |
| GenerateK8sAccessInfo | Generate commands for connecting self-built Kubernetes clusters | Generate commands for connecting self-built Kubernetes clusters. |
| MarkMonitorAccounts | Tag member accounts in multi-account management | Tags member accounts in multi-account management. Tags selected member accounts as accounts of interest. Accounts of interest are displayed at the top of the drop-down list above the left-side navigation pane in the Security Center console. |
| UnMarkMonitorAccounts | UnMarkMonitorAccounts | Cancel marking for members. Remove followed members from the list. In the Security Center console, the drop-down list above the left-side navigation pane no longer displays the members. |
| ListUnfinishedOnceTask | Query incomplete tasks | Queries the list of incomplete tasks by task type. |
| DeleteVulAutoRepairConfig | Delete automatic fix configurations from the vulnerability task center | Deletes the configurations of vulnerabilities that can be automatically fixed in the vulnerability task center in batches. |
| DescribeFixUsedCount | Query the number of vulnerability fixes used by a pay-as-you-go user | Queries the number of vulnerability fixes used by a pay-as-you-go user. |
| DeleteAttestor | Delete an attestor | Deletes an attestor. |
| DescribeClusterHostSecuritySummary | Query host security statistics | Queries the security statistics of a host. |
| DescribeClusterImageSecuritySummary | Query image security statistics | Queries the security statistics of container images. |
| DescribeCustomizedDictUploadInfo | View OSS details of custom weak password upload | Queries the information about the OSS bucket that stores custom weak password files. |
| CreateCustomizedDict | CreateCustomizedDict | Creates custom weak password rules. |
| DescribeContainerServiceK8sClusterKritisStatus | Query the kritis status of an ACK cluster | Queries the Kritis status of a Container Service for Kubernetes (ACK) cluster. |
| UpgradeHoneypotNode | Upgrade honeypot management node version | Upgrades the version of a specified honeypot management node. |
| QueryGuidTaskList | Query beginner task information | Security Center provides rewards such as value-added service authorization quotas and log analysis storage capacity to users who complete tasks. Queries the completion status and reward information of configuration tasks. |
| ReceiveFunctionTrialRewardByAliUid | Start cloud honeypot or malicious file detection SDK trial | Claims a trial reward for the cloud honeypot or malicious file detection SDK feature after completing a task. |
| DescribeAgentlessSensitiveFileByKey | Query sensitive file alerts by type | Retrieves the list of assets that contain a specific type of sensitive file detected by the agentless detection feature. |
| GetCheckStructure | Get cloud platform configuration check item structure | Queries the directory structure of the check item list. |
| DescribeDynamicDictUploadInfo | Query OSS upload details of dynamic weak passwords | Queries the OSS upload details of user-defined dynamic weak passwords for baseline checks. |
| DeleteCustomizeReport | Delete a custom security report | Deletes a specified custom security report. |
| DescribeCustomizeReportConfigDetail | Retrieve report delivery configuration details | Retrieves the details of a report delivery configuration. |
| DescribeDynamicDict | Query dynamic weak passwords | Queries the user-defined dynamic weak password rules for baseline checks. |
| DescribeIdcProbeScanResultList | Query IDC probe scan results | Retrieves the list of assets discovered by IDC probes. |
| DescribeSupervisonInfo | Query latest system vulnerability discovery time | Queries the latest system vulnerability discovery time. |
| GetDefenceCount | Query security protection statistics | Queries the number of alerting events handled by accurate access control and web tamper-proofing. |
| OperationCustomizeReportChart | Modify security report statistical charts | Modifies the statistical charts of a security report. |
| SaveCustomizeReportConfig | SaveCustomizeReportConfig | Saves the configurations of a custom security report. |
| SendCustomizeReport | Send a security report | Sends a security daily report to a specified email address. Only security reports with a custom time period as the report cycle are supported. |
| UpdateCustomizeReportStatus | Modify security report status | Modifies the status of a security report. |
| ListLogShipperRegions | Query regions supported for log delivery in pay-as-you-go mode | Queries the regions supported for log delivery in pay-as-you-go mode. |
| UpdateTargetListByBatch | Update machines in a batch | Updates the machines included in a batch. |
| DescribeScreenScoreThread | Query security dashboard score trend | Queries the security score trend on the security dashboard. |
| DescribeChartData | Query security daily report chart statistics | Queries the statistics of charts configured in a security report. |
| OpenBackupAutoConfig | Enable anti-ransomware managed service configuration | Enables the anti-ransomware managed service to configure server backup policies with one click. This operation can be called only after you purchase the anti-ransomware managed service. |
| GetAegisContainerPluginRule | Query container escape prevention rule details | Queries the details of a container escape prevention rule. |
| SubmitOperationTask | SubmitOperationTask | Submits a repair task of risk items detected in configuration assessment or rolls back a repair task that is executed. |
| CheckTrialFixCount | CheckTrialFixCount | Checks whether the remaining quota of the vulnerability fixing feature is sufficient for a free trial user of Security Center and queries the quota usage required for the current fix operation. |
| CreateMonitorAccount | CreateMonitorAccount | Creates a list of members of the account monitored by Security Center type by using the multi-account management feature. |
| DeleteMonitorAccount | Delete a security center monitoring account from multi-account security management | Deletes a Security Center monitoring account from the multi-account security management feature. |
| ListAccountsInResourceDirectory | Query member accounts in a resource directory | Retrieves the list of managed accounts for multi-account governance. |
| CreateRdDefaultSyncList | Create an automatic control policy for new accounts in multi-account security management | Creates an automatic control policy for new accounts in the multi-account security management feature of Security Center. Member accounts under the automatic control policy folder are automatically added to the monitoring account list. |
| DescribeIdcAssetCriteria | IDC probe scan asset search conditions | Queries the fuzzy match search conditions for asset properties that can be displayed when you query IDC assets discovered by scanning. |
| DescribeImageListByBuildRisk | Query affected images by build risk with paging | Queries affected images by build risk with paging. |
| DescribeImageBuildRiskList | Query image build risk summary by page | Queries the summary of image build risks by using paging. |
| DescribeImageBuildRiskByKey | Query image build risks by page | Queries the build risks of images by paging. |
| DescribeNeedAsyncQuery | DescribeNeedAsyncQuery | Queries whether slow queries need to be optimized. |
| ListPrivateK8s | Retrieve private kubernetes cluster information | Retrieves information about self-managed Kubernetes clusters that are connected to Security Center. |
| DescribeCheckWarningCount | DescribeCheckWarningCount | Queries the number of alerts that are triggered by a check item. |
| GetCurrentVersionPublish | Retrieve version release information | Retrieves the release information of the current client version. |
| DescribeInstanceVulStatistics | Query vulnerability risk statistics for serverless asset instances | Queries vulnerability statistics for a cluster. |
| SetImageBuildRiskStatus | Set image build risk status | Sets the risk status of image builds. |
| ListOperationProcessDetail | Query operation task subtasks | Queries the subtask list of an operation task. |
| ListOperationProcess | Query operation tasks | Queries a list of operation tasks. |
| DescribeDomainSecureSuggests | Query security suggestions in a website security report | Queries the security suggestions in a website security report. |
| DescribeIdcProbeList | Query IDC probe list for asset discovery | Retrieves the list of IDC probe instances used for asset discovery in the multi-cloud configuration management feature. |
| DescribeImageRiskLevelStatistic | Query image risk statistics | Queries the number of images that have security risk alerts, including vulnerabilities, baselines, and malicious sample risks. |
| DescribeImageSecurityScanCount | Retrieve image security event count | Retrieves the number of image security events. |
| GetDockerhubImageRiskRankInfo | Query image rankings by dimension | Queries the rankings of images by various dimensions. |
| ListDockerhubImage | Query docker hub images | Queries the risk overview of official Docker Hub images. |
| ListUserVpc | Retrieve VPC data by region | Retrieves VPC data for the user in a specified region by using the third-party image repository integration feature of Container Asset in Security Center. |
| ListTargetByBatch | Query targets by batch | Queries the list of publish target information for a specified batch. |
| GetInstanceAlarmStatistics | Get Server Alarm Statistics | Count the number of security events for a single instance |
| GrantSwitchAgreement | Grant authorization for feature migration | Grants authorization for feature migration. |
| ModifyServerlessAuthToMachine | Manage serverless asset authorization | Manages Serverless asset authorization. |
| ModifyBinarySecurityPolicy | Modify container image signing security policy | Modifies a container image signing security policy. |
| DeleteAttackPathWhitelist | Delete an attack path whitelist entry | Deletes an attack path whitelist entry. |
| ListSupportAttackPathAsset | Query cloud service asset types supported by attack path analysis | Queries the cloud service asset types supported by attack path analysis. |
| UpdateAttackPathSensitiveAssetConfig | Update attack path sensitive asset settings | Updates the sensitive asset configuration for attack path analysis. |
| GetAttackPathEventDetail | Query attack path event details | Queries the details of an attack path event. |
| InstallAegisForLingjun | Install Security Center agent on Lingjun bare metal servers | Installs the Security Center agent on Lingjun bare metal servers. |
| ListAegisForLingjunStatus | Query the Aegis Client Installation Result for Lingjun Bare Metal | Query the Aegis client installation result for Lingjun bare metal. |
| DescribeAIAssetSummary | DescribeAIAssetSummary | Queries the overview of user AI assets. |
| DescribePluginSummary | DescribePluginSummary | Queries statistics on the client plug-in installation status. |
| DescribeCustomizedDict | Query custom weak passwords | Queries the upload result of a custom weak password file. |
| ListUniBackupRecord | List Database Backup Records | List Database Backup Records |
| HandleSimilarMaliciousFiles | Batch process malicious sample alerts | Batch processes malicious sample alerts. |
| GenerateClusterScannerWebhookYaml | Generate Cluster Scanner Component Access Configuration | Generate K8s cluster scan access configuration. |
| DescribeClusterScannerList | View cluster scanner list | Queries the scanner status information for a Kubernetes cluster. |
| GetClusterScannerYaml | View cluster scan component access configuration | Queries the scan access configuration of a Kubernetes cluster. |
| GetAgentlessTaskUsedSizeEstimate | Retrieve estimated scan volume for agentless detection | Retrieves the estimated scan volume for agentless detection. |
| ListCloudAssetMatchOperators | Get cloud asset data operator list | Gets the list of cloud product configuration rule operators. |
| ListCloudAssetSchemas | Get the list of asset structure definitions. | Get the list of cloud product asset structure |
| UpdateMultiUserInstances | Authorization Allocation Management | Modify Multi-Account Instance Configuration |
| GetInstanceAuthRange | Get Instance Authorization Value Range | Get Instance Authorization Value Range |
| ListMultiUserInstances | Query Multi-Account Authorization Allocation List | Query Multi-Account Authorization Allocation List |
| DescribeCloudVendorProductTemplateConfig | Query Agentic SOC Supported Cloud Vendor Product Access Template Configuration | Get the cloud product access template for vendors |
| GetValidDeductInstances | Get Valid Resource Package Instances | Get Valid Resource Package Instances |
| ListAttackEventInfo | Retrieve the list of attack analysis events | Retrieve the list of attack analysis events |
| GetAttackEventDetail | Retrieve attack analysis event details | Retrieves the details of an attack analysis event. |
| GetAttackEventDashboard | Retrieve attack analysis dashboard information | Retrieves attack analysis dashboard information. |
| DescribeSuspiciousSecurityEventyStatistics | Query Alarm Security Event Statistics | Query Alarm Security Event Statistics |
| ListClusterCheckResult | Query Cluster Check Item Scan Results | Query Cluster Check Item Scan Results |
| GetClusterCheckSummary | Query cluster check item risk count | Queries the risk statistics of check items for a cluster. |
| ListKspmInstances | Query kubernetes assets | Queries Kubernetes asset information. |
| AddFileProtectBindMachine | Add tamper-proofing server | Creates a file protection rule. |
| CreateFileProtectClientRule | Create a tamper-proofing rule | Creates a file protection rule. |
| DeleteFileProtectClientRule | Delete a tamper-proofing rule | Deletes a file protection rule. |
| DescribeFrontVulPatchList | Query prerequisite patches for a specified windows system vulnerability | Queries the list of prerequisite patches that must be installed for a specified Windows system vulnerability. |
| DescribeGroupedVul | Query vulnerability information by group | Queries vulnerability information by group. |
| DescribeScanTaskProgress | Query virus scan task progress | Queries the progress of a virus scan task. |
| DescribeSnapshots | DescribeSnapshots | Queries the backup snapshots that are created for anti-ransomware. |
| DescribeSuspEvents | DescribeSuspEvents | Queries a list of alert events that are generated without aggregation. |
| DescribeVulDetails | Query vulnerability details | Queries vulnerability details. |
| DescribeVulList | DescribeVulList | Queries vulnerabilities by type. |
| GetFileProtectClientEvent | Get tamper-proofing alert event details | Retrieves the details of a file protection event. |
| GetFileProtectClientEventDashboard | Retrieve statistics on tamper-proofing events | Retrieves the dashboard data of file tamper-proofing events. |
| GetFileProtectClientRule | Retrieve file tamper-proofing rule details | Retrieves the details of a file protection rule. |
| GetFileProtectClientRuleDashboard | Retrieve web tamper-proofing overview information | Retrieves the overview dashboard of file protection rules. |
| HandleObjectScanEvent | Handle malicious file detection alerts | Handles malicious file detection alerts. |
| ListFileProtectBindMachine | Retrieve the list of servers associated with file tamper-proofing | Retrieves the list of servers associated with tamper-proofing. |
| ListFileProtectClientEvent | Retrieve web tamper-proofing event list | Retrieves the list of file protection events. |
| ListFileProtectClientRule | Retrieve web tamper-proofing rules | Retrieves a list of file protection rules. |
| ListFileProtectClientRuleFileType | Retrieve file types for web tamper-proofing | Retrieves all file types for file protection rules. |
| OperateVuls | Fix a Linux software vulnerability | Fixes a Linux software vulnerability. |
| UpdateFileProtectClientEvent | Update a web tamper-proofing protection event | Updates the status of a file protection event. |
| UpdateFileProtectClientRule | Modify a web tamper-proofing rule | Updates a file protection rule. |
| UpdateFileProtectClientRuleStatus | Update tamper-proofing rule status | Updates the status of file tamper-proofing rules in batches. |
| CreateServiceLinkedRole | Create a service-linked role and grant security center access to cloud resources | Creates a service-linked role and grants Security Center access to cloud resources. |
| DescribeBackupPolicy | Query anti-ransomware protection policy details for servers | Queries the details of an anti-ransomware protection policy for servers. |
| ModifyBackupPolicy | Modify an anti-ransomware policy | Modifies an anti-ransomware mitigation policy. |
Asset selection
|
API |
Title |
Description |
| AddAssetSelectionCriteria | AddAssetSelectionCriteria | Select an operation for assets. |
| AddBaselineCheckWhiteRecord | AddBaselineCheckWhiteRecord | Creates a whitelist rule for a baseline check item. |
| AddCheckInstanceResultWhiteList | AddCheckInstanceResultWhiteList | Adds instances on which risks are detected based on check items of the configuration assessment feature to a whitelist. |
| AddContainerDefenseRule | AddContainerDefenseRule | Creates a rule for non-image program defense. |
| AddContainerPluginRule | AddContainerPluginRule | Creates a defense rule against container escapes. |
| AddIdcProbe | AddIdcProbe | Creates an IDC probe to add assets in a data center to Security Center and manage the assets by using the Security Center console. |
| AddImageEventOperation | AddImageEventOperation | Creates an alert handling rule. |
| AddImageVulWhiteList | AddImageVulWhiteList | Adds image vulnerabilities to the whitelist. |
| AddInstallCode | AddInstallCode | Creates a command that is used to install the Security Center agent. |
| AddPrivateRegistry | AddPrivateRegistry | Adds a self-managed image repository. |
| AddProtectVpcList | Add or Update the Whitelist for VPC Purchases | Add or update the whitelist for VPC purchases |
| AddPublishBatch | AddPublishBatch | Upgrades the Security Center agent in batches. |
| AddSasContainerWebDefenseRule | AddSasContainerWebDefenseRule | Creates a rule for container tamper-proofing. |
| AddSasModuleTrial | AddSasModuleTrial | Enables the trial use of Security Center value-added features, including vulnerability fixing and threat analysis and response. |
| AddTagWithUuid | AddTagWithUuid | Adds a tag to assets. |
| AddUninstallClientsByUuids | AddUninstallClientsByUuids | Adds servers from which you want to uninstall the Security Center agent. |
| AddVpcHoneyPot | AddVpcHoneyPot | Creates a honeypot. |
| AdvanceSecurityEventOperations | AdvanceSecurityEventOperations | Queries the configurations of an advanced whitelist rule. |
| BatchCreateMaliciousNote | BatchCreateMaliciousNote | Adds alert description in batches. |
| BatchDeleteMaliciousFileWhitelistConfig | BatchDeleteMaliciousFileWhitelistConfig | Deletes whitelist rules for alerts generated for sensitive files that are detected by using the agentless detection feature in batches. |
| BatchOperateCommonOverallConfig | BatchOperateCommonOverallConfig | Enables or disables multiple features in proactive defense at a time. |
| BatchUpdateMaliciousFileWhitelistConfig | BatchUpdateMaliciousFileWhitelistConfig | Modifies multiple alert whitelist rules of sensitive files that are detected by using the agentless detection feature at a time. |
| BindHybridProxy | BindHybridProxy | Adds servers to Security Center over a proxy server. After you create a proxy cluster and deploy a proxy server, you can connect a server to the proxy cluster as a client. This way, the server is added to Security Center over the proxy server and is protected. |
| CancelOnceTask | CancelOnceTask | Cancels the main task. |
| ChangeAssetRefreshTaskConfig | ChangeAssetRefreshTaskConfig | Modifies the interval of asset synchronization configurations. |
| ChangeCheckCustomConfig | ChangeCheckCustomConfig | Modifies the custom configuration items of a check item. |
| ChangeCheckScopeConfigInstance | Modify check scope configuration instance | Modifies the configuration instance of a check scope. |
| ChangeUserLang | ChangeUserLang | Modifies the language settings of log analysis. The modification on the language settings takes effect within 12 hours and affects only the language of the descriptions for security events in security logs. |
| CheckSecurityEventId | CheckSecurityEventId | Checks whether one or more alerts are generated on a specified server based on alert IDs. |
| CheckStsTokenAuth | CheckStsTokenAuth | Checks a Security Token Service (STS) token and returns the ID of the Alibaba Cloud account. |
| CheckUserHasEcs | CheckUserHasEcs | Checks whether Elastic Compute Service (ECS) instances exist. |
| ConfirmVirusEvents | ConfirmVirusEvents | Confirms the alert events that you want to handle. |
| CopyCustomizeReportConfig | CopyCustomizeReportConfig | Clones an existing security report. The new security report has the same configuration as the existing security report. |
| CreateAgentlessScanTask | CreateAgentlessScanTask | Creates an agentless detection task. |
| CreateAntiBruteForceRule | CreateAntiBruteForceRule | Creates a defense rule against brute-force attacks. |
| CreateAssetSelectionConfig | CreateAssetSelectionConfig | Create asset selection configurations. |
| CreateAttackPathSensitiveAssetConfig | Create Attack Path Sensitive Asset Settings | Create attack path sensitive asset configuration. |
| CreateAttackPathWhitelist | CreateAttackPathWhitelist | Create Attack Path Whitelist. |
| CreateAttestor | CreateAttestor | Creates a witness. |
| CreateBackupPolicy | CreateBackupPolicy | Creates an anti-ransomware policy for servers. |
| CreateBatchUploadUrl | CreateBatchUploadUrl | Queries the parameters that are required to upload a file for detection. |
| CreateBinarySecurityPolicy | CreateBinarySecurityPolicy | Creates a binary security policy. |
| CreateContainerScanTask | CreateContainerScanTask | Creates a container scan task. |
| CreateContainerScanTaskByAppName | CreateContainerScanTaskByAppName | Creates a scan task for a running container application based on the application name. |
| CreateCustomBlockRecord | CreateCustomBlockRecord | Creates an IP address blocking policy for one or more servers. |
| CreateCycleTask | CreateCycleTask | Creates a periodic scan task. The task can be an image scan task, urgent vulnerability scan task, or virus scan task. |
| CreateDynamicDict | CreateDynamicDict | Creates a dynamic dictionary of weak passwords. |
| CreateFileDetectUploadUrl | CreateFileDetectUploadUrl | Queries the parameters that are required to upload a file for detection. |
| CreateFileProtectRule | CreateFileProtectRule | Creates a core file monitoring rule. |
| CreateFileUploadLimit | CreateFileUploadLimit | Specifies the queries per second (QPS) limit on the files uploaded from the client. |
| CreateHoneypot | CreateHoneypot | Creates a honeypot. |
| CreateHoneypotNode | CreateHoneypotNode | Creates a management node. |
| CreateHoneypotPreset | CreateHoneypotPreset | Creates a honeypot template. |
| CreateHoneypotProbe | CreateHoneypotProbe | Creates a probe. |
| CreateHoneypotProbeBind | CreateHoneypotProbeBind | Creates a monitoring or forwarding service for a probe. |
| CreateHybridProxyCluster | CreateHybridProxyCluster | Creates a hybrid-cloud proxy cluster. |
| CreateInterceptionRule | CreateInterceptionRule | Creates a defense rule in the container firewall module. |
| CreateInterceptionTarget | CreateInterceptionTarget | Creates a defense object. |
| CreateJenkinsImageRegistry | CreateJenkinsImageRegistry | Creates a Jenkins image repository. |
| CreateJenkinsImageScanTask | CreateJenkinsImageScanTask | Creates a Jenkins scan task. |
| CreateMaliciousNote | CreateMaliciousNote | Adds remarks to alert events for agentless detection. |
| CreateOpaClusterPlugin | CreateOpaClusterPlugin | Installs the components that are required by at-risk image blocking. The components are policy-template-controller, gatekeeper, and logtail-ds. |
| CreateOrUpdateAssetGroup | CreateOrUpdateAssetGroup | Modifies the mapping between an asset and an asset group. For example, you can call this operation to modify the server group to which the asset belongs or the asset list of the asset group. |
| CreateOrUpdateAutoTagRule | CreateOrUpdateAutoTagRule | Creates an asset auto-tagging rule or modifies an asset auto-tagging rule that is created on the Asset Management Rule tab. |
| CreateOrUpdateDingTalk | CreateOrUpdateDingTalk | Creates or modifies a DingTalk chatbot that sends notifications. |
| CreateOssBucketScanTask | CreateOssBucketScanTask | Creates a bucket check task. |
| CreateRestoreJob | CreateRestoreJob | Creates a restoration task. |
| CreateSasTrial | CreateSasTrial | Applies for a trial of Security Center. |
| CreateUniBackupPolicy | CreateUniBackupPolicy | Creates an anti-ransomware policy for a database. |
| CreateVulAutoRepairConfig | CreateVulAutoRepairConfig | Creates a list of vulnerabilities that can be automatically fixed. After the list is created, you can select the list when you create a vulnerability fixing task on the Playbook page. |
| DeleteAttackPathSensitiveAssetConfig | DeleteAttackPathSensitiveAssetConfig | Delete attack path sensitive asset. |
| DeleteBackupPolicyMachine | DeleteBackupPolicyMachine | Deletes a server from a specified anti-ransomware policy. |
| DeleteBaselineCheckWhiteRecord | DeleteBaselineCheckWhiteRecord | Deletes the whitelist record for a baseline check item. |
| DeleteBinarySecurityPolicy | DeleteBinarySecurityPolicy | Deletes a binary security policy from the container signature feature. |
| DeleteContainerDefenseRule | DeleteContainerDefenseRule | Deletes a rule for non-image program defense. |
| DeleteDingTalk | DeleteDingTalk | Deletes a DingTalk chatbot on the DingTalk Chatbot tab of the Notification Settings page. |
| DeleteFileProtectRule | DeleteFileProtectRule | Deletes core file monitoring rules. |
| DeleteHoneypot | DeleteHoneypot | Deletes a specified honeypot. |
| DeleteHoneypotNode | DeleteHoneypotNode | Deletes a specified management node. |
| DeleteHoneypotProbe | DeleteHoneypotProbe | Deletes a specified probe. |
| DeleteHoneypotProbeBind | DeleteHoneypotProbeBind | Delete the probe service. |
| DeleteLoginBaseConfig | DeleteLoginBaseConfig | Deletes the basic configuration information from the logon security configurations for a specific asset. |
| DeleteOssScanConfig | DeleteOssScanConfig | Deletes the configuration of an Object Storage Service (OSS) file detection policy. |
| DeleteSecurityEventMarkMissList | DeleteSecurityEventMarkMissList | Deletes multiple custom defense rules at a time. The custom defense rules are used to add false positive alerts to the whitelist. |
| DeleteSuspEventNode | DeleteSuspEventNode | Deletes the description of an alert. |
| DeleteUniBackupPolicy | DeleteUniBackupPolicy | Deletes anti-ransomware policies that are created for databases. |
| DescribeAlarmEventDetail | DescribeAlarmEventDetail | Queries the details about an alert event. An alert event consists of an alert and exceptions. Each alert event is associated with multiple exceptions. |
| DescribeAlarmEventStackInfo | DescribeAlarmEventStackInfo | Queries the stack information about an alert event. |
| DescribeAllRegionsStatistics | DescribeAllRegionsStatistics | Queries the statistics on global security events, including the numbers of unfixed vulnerabilities, baseline risks, and alerts. |
| DescribeAssetsScaProcessNum | DescribeAssetsScaProcessNum | Queries the number of Java processes in an asset by using the asset fingerprints feature of Security Center. |
| DescribeAttestors | DescribeAttestors | Queries a list of witnesses. |
| DescribeAutoDelConfig | DescribeAutoDelConfig | Queries the number of days during which a detected vulnerability is retained before the vulnerability is automatically deleted. |
| DescribeBackupFiles | DescribeBackupFiles | Queries backup files. |
| DescribeBinarySecurityPolicies | DescribeBinarySecurityPolicies | Queries binary security policies. |
| DescribeBruteForceRecords | DescribeBruteForceRecords | Queries the IP addresses that are blocked by a defense rule against brute-force attacks. |
| DescribeBruteForceSummary | DescribeBruteForceSummary | Queries the statistics of IP address blocking policies that are used to defend against brute-force attacks and trigger alerts. |
| DescribeCanAccessVpcSale | Check if the Asset Can be Sold by VPC | Check if the asset can be sold by VPC |
| DescribeCanTrySas | DescribeCanTrySas | Checks the permissions on the trial use of Security Center. |
| DescribeCheckResult | DescribeCheckResult | Queries the result of the ISO 27001 compliance check. |
| DescribeCheckWarningMachines | DescribeCheckWarningMachines | Queries the servers on which the same risk item is detected by specifying a baseline and a check item. |
| DescribeCloudProductFieldStatistics | DescribeCloudProductFieldStatistics | Queries the statistics of cloud services whose instances are protected by Security Center. |
| DescribeCloudVendorTrialConfig | Query Third-Party Cloud Asset Audit Log Access Configuration | Query the trail configuration attributes of the corresponding AK configuration |
| DescribeClusterInfoList | DescribeClusterInfoList | Queries the information about a cluster. |
| DescribeCommonOverallConfigList | DescribeCommonOverallConfigList | Queries the configurations of features in proactive defense. |
| DescribeCommonTargetConfig | DescribeCommonTargetConfig | Queries the configurations of the proactive defense feature. |
| DescribeContainerApps | DescribeContainerApps | Queries the information about a containerized application. |
| DescribeContainerFieldStatistics | DescribeContainerFieldStatistics | Queries the statistical information about containers. |
| DescribeContainerGroupedFieldDetail | DescribeContainerGroupedFieldDetail | Queries the attribute details of containers. |
| DescribeContainerServiceK8sClusterNamespaces | DescribeContainerServiceK8sClusterNamespaces | Queries the namespace of a Container Service for Kubernetes (ACK) cluster. |
| DescribeContainerServiceK8sClusters | DescribeContainerServiceK8sClusters | Queries a list of Container Service for Kubernetes (ACK) clusters. |
| DescribeCountNotScannedImage | DescribeCountNotScannedImage | Queries the number of images that are not scanned. |
| DescribeCustomBlockInstances | DescribeCustomBlockInstances | Queries the list of servers on which the custom defense rule against brute-force attacks takes effect. |
| DescribeCustomizeReportList | DescribeCustomizeReportList | Queries security reports. |
| DescribeEventLevelCount | DescribeEventLevelCount | Queries the statistics of alert events by risk level. |
| DescribeExposedInstanceDetail | DescribeExposedInstanceDetail | Queries the details of a specified server that is exposed on the Internet. |
| DescribeLoginSwitchConfigs | DescribeLoginSwitchConfigs | Queries the alerting status for unapproved logon IP addresses, unapproved logon time ranges, or unapproved logon accounts. |
| DescribeOfflineMachines | DescribeOfflineMachines | Queries the information about the servers whose Security Center agent status is Offline. |
| DescribePropertyCronItem | DescribePropertyCronItem | Queries the scheduled tasks of your assets. |
| DescribePropertyProcItem | DescribePropertyProcItem | Queries information about all processes. |
| DescribePropertyScaItem | DescribePropertyScaItem | Queries middleware fingerprints. |
| DescribePropertyScheduleConfig | DescribePropertyScheduleConfig | Queries the configurations of scheduled tasks of asset fingerprint collection. |
| DescribePropertySoftwareItem | DescribePropertySoftwareItem | Queries information about all software assets. |
| DescribePropertyTypeScaItem | DescribePropertyTypeScaItem | Queries middleware types. |
| DescribePropertyUserItem | Retrieve account information of assets | Retrieves the account information of assets. |
| DescribeRestoreJobs | DescribeRestoreJobs | Queries the details about restoration tasks. |
| DescribeRestorePlans | DescribeRestorePlans | Queries restoration tasks. |
| DescribeRiskListCheckResult | DescribeRiskListCheckResult | Queries the number of risk items detected in the configuration assessment of one or more cloud services by using the instance IDs of the cloud services. |
| DescribeRiskType | DescribeRiskType | Queries baseline types. |
| DescribeScanTaskStatistics | DescribeScanTaskStatistics | Queries the statistics of virus detection tasks. |
| DescribeSecurityCheckScheduleConfig | DescribeSecurityCheckScheduleConfig | Queries the day of a week when custom check tasks are performed and the time range during which the custom check tasks are performed. |
| DescribeSecurityEventOperationStatus | DescribeSecurityEventOperationStatus | Queries the alert events that are triggered by the same IP address rule or of the same alert type as a specific alert event if you want to handle the specific alert event in batch operation mode. |
| DescribeSecurityEventOperations | DescribeSecurityEventOperations | Queries the operations that you can perform to handle an alert. |
| DescribeServiceLinkedRoleStatus | DescribeServiceLinkedRoleStatus | Checks whether a service-linked role is created for Security Center. |
| DescribeSimilarSecurityEvents | DescribeSimilarSecurityEvents | Queries alert events that are triggered by the same rule or of the same alert type. |
| DescribeSoarPlaybookTaskDetail | Query Playbook Task Details | Query the execution details of a remediation task playbook |
| DescribeSoarStrategies | DescribeSoarStrategies | Queries the policy templates on the Playbook page. |
| DescribeSoarStrategyParam | DescribeSoarStrategyParam | Queries the parameters of a policy on the Playbook page. |
| DescribeSoarStrategyTasks | DescribeSoarStrategyTasks | Queries a list of policy tasks on the Playbook page. |
| DescribeStrategyExecDetail | DescribeStrategyExecDetail | Queries the results of the last baseline check by using a specified baseline check policy. |
| DescribeStrategyTarget | DescribeStrategyTarget | Queries the information about the assets to which a baseline check policy is applied. |
| DescribeStrictEventName | Query Alarm Names in Strict Mode | Strict mode supports alarm queries |
| DescribeSummaryInfo | DescribeSummaryInfo | Queries the security information about your assets. The information includes the security score and the numbers of protected and unprotected assets. |
| DescribeSuspEventExportInfo | DescribeSuspEventExportInfo | Queries the information about an export task of exceptions. |
| DescribeSuspEventQuaraFiles | DescribeSuspEventQuaraFiles | Queries quarantined files by page. |
| DescribeSuspEventUserSetting | DescribeSuspEventUserSetting | Queries the user settings for exceptions. |
| DescribeSuspiciousOverallConfig | DescribeSuspiciousOverallConfig | Queries the configuration of a specified feature. |
| DescribeSuspiciousUUIDConfig | DescribeSuspiciousUUIDConfig | Queries the UUIDs of servers on which proactive defense of a specified type takes effect. |
| DescribeSyncAssetTaskList | Query asset synchronization task list | Queries the list of asset synchronization IDC scan tasks. |
| DescribeTarget | Query vulnerability machine list | Queries the machine list settings for vulnerability scanning. |
| DescribeTaskErrorLog | Query error logs of a failed image fix task | Queries the error logs of a failed image fix task. |
| DescribeTotalStatistics | Retrieve event statistics | Retrieves event statistics information. |
| DescribeTraceInfoNode | Query trace node information | Queries the details of a trace node. |
| DescribeUniBackupDatabase | Query anti-ransomware databases | Queries the details of databases in database protection policies. |
| DescribeUniBackupPolicies | Query anti-ransomware policies | Queries the list of database anti-ransomware policies. |
| DescribeUniBackupStatistics | Query anti-ransomware backup statistics information for databases | Queries the statistics information of anti-ransomware backup for databases. |
| DescribeUniRecoverableList | Query recoverable database backups | Queries the list of recoverable database backups. |
| DescribeUniSupportRegion | DescribeUniSupportRegion | Queries the region that is supported by anti-ransomware for databases. |
| DescribeUserBackupMachines | Query servers with anti-ransomware backup policies enabled | Queries servers that have anti-ransomware backup policies enabled. |
| DescribeUserBaselineAuthorization | Query cloud platform authorization status | Queries the status of cloud platform authorization information for a user. |
| DescribeUserSetting | Query user-defined configurations | Retrieves user-defined configurations for baseline checks. |
| DescribeUuidsByVulNames | Retrieve servers that support vulnerability fixing by vulnerability name | Retrieves the list of servers that support vulnerability fixing based on vulnerability names. |
| DescribeVendorList | Retrieve supported vendors | Retrieves the supported vendor information for Security Center. |
| DescribeVolDingdingMessage | DescribeVolDingdingMessage | Queries the QR code address of a DingTalk group. |
| DescribeVpcHoneyPotCriteria | DescribeVpcHoneyPotCriteria | Queries the search conditions that can be used to query honeypots. |
| DescribeVpcHoneyPotList | Query VPC honeypot probe list | Queries the list of VPC honeypot probes. |
| DescribeVpcList | DescribeVpcList | Queries the information about virtual private clouds (VPCs). |
| DescribeVulCheckTaskStatusDetail | DescribeVulCheckTaskStatusDetail | Queries the status information about vulnerability scan tasks on a server. |
| DescribeVulConfig | Query vulnerability management configuration | Queries vulnerability management configuration information. |
| DescribeVulDefendCountStatistics | Query user vulnerability prevention statistics | Queries the vulnerability prevention statistics of a Security Center user. |
| DescribeVulFixStatistics | DescribeVulFixStatistics | Queries the statistics of vulnerability fixes. |
| DescribeVulMetaCountStatistics | DescribeVulMetaCountStatistics | Queries the statistics of vulnerabilities in Security Center. |
| DescribeVulTargetConfig | DescribeVulTargetConfig | Queries the configurations of the vulnerability scan feature for a server. |
| DescribeVulTargetStatistics | Retrieve vulnerability switch configurations | Retrieves the list of vulnerability switch configurations. |
| DescribeWarningExportInfo | DescribeWarningExportInfo | Queries the progress of a export task for a baseline check result. |
| DescribeWebLockBindList | Query web tamper-proofing server list | Retrieves the list of servers that have web tamper-proofing protection enabled. |
| DescribeWebLockConfigList | DescribeWebLockConfigList | Queries the configurations of web tamper proofing for a specified server. |
| DescribeWebLockFileChangeStatistics | Query file change statistics for web tamper-proofing | Queries the file change statistics for web tamper-proofing. |
| DescribeWebLockFileEvents | DescribeWebLockFileEvents | Queries events on web tamper proofing. |
| DescribeWebLockFileTypeSummary | Query WebLock File Type Summary | Queries the WebLock file type summary. |
| DescribeWebLockInclusiveFileType | Query tamper-proofing file types | Queries the file types supported by tamper-proofing protection. |
| DescribeWebLockProcessBlockStatistics | DescribeWebLockProcessBlockStatistics | Queries the statistics on processes for web tamper proofing. |
| DescribeWebLockProcessList | DescribeWebLockProcessList | Queries the processes for web tamper proofing. |
| DescribeWebLockStatus | Query tamper-proofing protection status | Queries the tamper-proofing protection status. |
| DescribeWebLockTotalFileChangeCount | DescribeWebLockTotalFileChangeCount | Queries the number of times that the files protected by web tamper proofing are changed. |
| DescribeWebPath | Query custom web directories for security alerts | Queries custom web directories for security alerts. |
| DescribeWhiteListAsset | DescribeWhiteListAsset | Queries the information about servers that can be added or are added to application whitelist policies. |
| DescribeWhiteListAuthorize | Retrieve available authorization count | Queries the number of available authorizations for the application whitelist. |
| DescribeWhiteListEffectiveAssets | DescribeWhiteListEffectiveAssets | Queries the servers on which an application whitelist policy takes effect. |
| DescribeWhiteListStrategyList | DescribeWhiteListStrategyList | Queries a list of application whitelist policies. |
| DescribeWhiteListStrategyStatistics | Query policy statistics information | Queries the statistics of application whitelist policy. |
| DescribeWhiteListStrategyUuidCount | DescribeWhiteListStrategyUuidCount | Queries the number of the servers on which an application whitelist policy takes effect. |
| DingTalkOnlineTest | DingTalkOnlineTest | Tests whether DingTalk notification configurations are valid. |
| DisableBruteForceRecord | DisableBruteForceRecord | Disables an IP address blocking policy that is in effect. |
| DisableCustomBlockRecord | DisableCustomBlockRecord | Disables a custom IP address blocking policy for servers. |
| EnableBruteForceRecord | EnableBruteForceRecord | Enables an IP address blocking policy for a specified server. |
| EnableCustomBlockRecord | EnableCustomBlockRecord | Enables a custom IP address blocking policy. |
| EnableCustomInstanceBlockRecord | EnableCustomInstanceBlockRecord | Enables a custom rule for an instance. |
| EnableServiceAccessResourceDirectory | Enable the multi-account management feature of security center | Enables the multi-account management feature of Security Center. |
| ExportCustomizeReport | ExportCustomizeReport | Exports a security report. |
| ExportSuspEvents | ExportSuspEvents | Exports the information about exceptions to a file. |
| FinishGuidTask | FinishGuidTask | Completes guidance tasks for beginners to earn rewards. |
| FixCheckWarnings | Fix baseline check risk items | Fixes baseline check risk items. |
| GenerateDynamicDict | GenerateDynamicDict | Generates a custom dictionary of weak passwords for the baseline check feature. |
| GetAccountLabel | GetAccountLabel | Obtains account tags. |
| GetAegisContainerPluginRuleCriteria | Get Container Escape Prevention Query Criteria | Queries the query conditions of container anti-tamper rules. |
| GetAgentlessTaskCount | GetAgentlessTaskCount | Queries the number of agentless detection tasks. |
| GetAlarmMachineCount | Retrieve the number of servers with alerts | Retrieves the number of servers that currently have security alerts. |
| GetAppNetwork | Retrieve network topology between container applications | Retrieves the network topology between container applications. |
| GetAssetDetailByUuid | Query server asset details and extended information | Queries the details and extended information of a server asset by UUID. |
| GetAssetSelectionConfig | Retrieve asset selection configuration | Retrieves the asset selection configuration. |
| GetAttackPathEventStatistics | Query attack path event statistics | Queries attack path event statistics. |
| GetAttackPathSensitiveAssetConfig | Query attack path sensitive asset settings | Queries the sensitive assets in an attack path. |
| GetAttackPathWhitelist | Query attack path whitelist details | Queries the details of an attack path whitelist. |
| GetAttackTypeList | Retrieve attack type list | Retrieves the list of attack types for the attack analysis event display. |
| GetAuthVersionStatistic | Query asset authorization quantity statistics | Query asset authorization quantity statistics. |
| GetBackupAutoConfigStatus | Query anti-ransomware managed service status | Queries whether the anti-ransomware managed service supports automatic configuration of anti-ransomware server backup policies. |
| GetBackupStorageCount | Query used anti-ransomware storage capacity | Queries the used anti-ransomware storage capacity. |
| GetBuildRiskDefineRuleConfig | Query risk scan configuration for image build commands | Queries the risk scan configuration for image build commands. |
| GetCanTrySas | GetCanTrySas | Checks whether the current user is qualified for the trial use of Security Center. |
| GetCheckDetail | GetCheckDetail | Queries the details about a check item that is used for configuration assessment. |
| GetCheckProcess | Query cloud platform configuration check task progress | Queries the progress of a cloud platform configuration check task. |
| GetCheckRiskStatistics | GetCheckRiskStatistics | Queries the statistics on risk scenarios and check items that are used in the risk scenarios, including the statistics on low-risk, medium-risk, and high-risk items by baseline type. |
| GetCheckScopeConfig | Query check scope configuration | Queries the check scope configuration. |
| GetCheckTimeDimensionStatistic | Retrieve time trend statistics for CSPM risk items | Retrieves the time trend pass rate statistics for Cloud Security Posture Management (CSPM) risk items. |
| GetClientRatioStatistic | GetClientRatioStatistic | Queries the installation rate and online rate of the agent. |
| GetCloudAssetCriteria | GetCloudAssetCriteria | Queries the filter conditions that are used to search for cloud assets. |
| GetClusterCheckItemWarningStatistics | Retrieve baseline check issue count for a container cluster | Retrieves the number of baseline check issues for a container cluster. |
| GetClusterRuleSummary | GetClusterRuleSummary | Queries the overall information about cluster defense rules that are configured for the container firewall feature. |
| GetClusterStrategyCount | Query the number of policies in each cluster | Queries the number of policies in each cluster. |
| GetClusterSuspEventStatistics | Retrieve container security event statistics | Retrieves statistics on container security events. |
| GetCommonSwitchConfig | GetCommonSwitchConfig | Queries the configuration of a common switch. |
| GetConsoleFuncGrayStatus | Get the Gray Status of Console Function Modules | Query whether the core function's gray switch is hit |
| GetDataTrend | Query security operations trends | Queries the security operations trends for vulnerabilities, alerts, and baselines. |
| GetFileProtectEventCount | GetFileProtectEventCount | Queries the total number of core file monitoring events by filter condition. |
| GetFileProtectRule | GetFileProtectRule | Queries the information about a core file monitoring rule based on the ID of the rule. |
| GetFileUploadLimit | GetFileUploadLimit | Queries the queries per second (QPS) limit on the files uploaded from the client. |
| GetFunctionTrialStatus | Get Function Trial Eligibility Status | Get Trial Status |
| GetHoneyPotUploadPolicyInfo | GetHoneyPotUploadPolicyInfo | Obtains the URL that is used to upload a file to a honeypot. |
| GetHoneypotEventTrend | Obtain the attack volume trend of honeypot attack sources | Obtain attack trend statistics for a single attack source. |
| GetHoneypotNodeMetricList | GetHoneypotNodeMetricList | Queries the monitoring data of management nodes to which the cloud honeypot belongs. |
| GetHoneypotPreset | GetHoneypotPreset | Queries the configurations of a specified honeypot template. |
| GetHoneypotProbe | GetHoneypotProbe | Queries the details about a specified probe. |
| GetHoneypotStatistics | GetHoneypotStatistics | Get statistics on honey pot usage. |
| GetImageEventOperation | GetImageEventOperation | Queries alert handling rules. |
| GetImageScanNumInPeriod | GetImageScanNumInPeriod | Queries the number of image scans that are performed within the last several days. |
| GetInstallCodeForUuid | Query the agent installation code for a specified asset by UUID | Queries the Security Center agent installation code for a specified asset by UUID. |
| GetInterceptionSummary | GetInterceptionSummary | Queries the statistics of the container firewall feature. |
| GetInterceptionTargetDetail | GetInterceptionTargetDetail | Queries the information about a specified network object that is protected by the container firewall feature. |
| GetLocalDefaultRegion | Retrieve default local region | Retrieves the default synchronization region for external asset synchronization. |
| GetLogMeta | GetLogMeta | Queries the status of a data shipping task of a log. |
| GetMaliciousFileWhitelistConfig | GetMaliciousFileWhitelistConfig | Queries an alert whitelist rule of sensitive files that are detected by using the agentless detection feature. |
| GetModuleConfig | GetModuleConfig | Queries the configurations of a module. |
| GetModuleConfigStatus | GetModuleConfigStatus | Checks whether the purchased Security Center features are enabled and whether related configurations take effect. |
| GetModuleTrialAuthInfo | GetModuleTrialAuthInfo | Queries the qualification information about the trial use of Security Center value-added features, including vulnerability fixing and threat analysis and response. |
| GetOpaClusterBaseLineList | GetOpaClusterBaseLineList | Queries the baselines that are supported by at-risk image blocking. |
| GetOpaPluginStatus | GetOpaPluginStatus | Queries the installation status of the components that are required for clusters protected by proactive defense for containers. |
| GetOpaStrategyTemplateSummary | Query usage statistics of risky image blocking policy templates | Queries the usage statistics information of risky image blocking policy templates for container proactive defense. |
| GetPropertyScheduleConfig | Query asset fingerprints collection cycle configuration | Queries the collection cycle configuration of Asset Fingerprints. |
| GetPublishCron | Retrieve client upgrade time configuration | Retrieves the client upgrade time configuration. |
| GetRdTree | Query the directory structure of a resource organization under a resource directory | Queries the directory structure of the resource organization under a resource directory by using the multi-account management feature. |
| GetRulesCount | Query the number of system defense rules and user-defined rules | Queries the number of system defense rules and user-defined rules. |
| GetSasContainerWebDefenseRuleApplication | Retrieve the application list for container file defense configurations | Retrieves the list of applications for container file defense configurations. |
| GetSasContainerWebDefenseRuleCriteria | Retrieve query criteria for container tamper-proofing rules | Retrieves the query criteria for container tamper-proofing rules. |
| GetSensitiveDefineRuleConfig | Query custom check items for sensitive file tampering | Queries custom check items for sensitive file tampering. |
| GetServerlessAppAuthDetail | Retrieve serverless application authorization details | Retrieves the authorization details of a serverless application. |
| GetServerlessAuthSummary | Retrieve serverless authorization overview | Retrieves the Serverless authorization overview. |
| GetServiceTrail | Retrieve audit trail delivery configuration | Retrieves the audit trail delivery configuration. |
| GetStrategyTemplateDetail | Query rule template details for container proactive defense | Queries the details of a rule template for container proactive defense. |
| GetSuspiciousStatistics | Query security alert counts by asset group | Queries the statistics on the number of security alerts in one or more asset groups. |
| GetTenantCheckAvailable | Query whether a one-click scan can be submitted | Queries whether a free one-click scan can be submitted. The scan scope includes free vulnerability scanning categories and free CSPM check items. |
| GetUserLang | Query log analysis language settings | Queries the log analysis language settings. |
| GetVirusScanLatestTaskStatistic | Retrieve the latest virus scan information | Retrieves the scan information of the latest virus scan. |
| HandleMaliciousFiles | Add or remove security alerts to or from the whitelist | Adds or removes security alerts detected by the agentless detection feature to or from the whitelist. |
| HandleSecurityEvents | HandleSecurityEvents | Handles alert events. |
| HandleSimilarSecurityEvents | Batch process alert events based on the same IP rule or type | Batch processes alert events based on the same IP rule or type. |
| IgnoreHcCheckWarnings | IgnoreHcCheckWarnings | Ignores or cancels ignoring multiple baseline risk items at a time. |
| IgnoreIdcProbeScanResult | Whitelist or ignore IDC probe scan results | Adds scan results from IDC probes to the whitelist or ignores them. |
| InstallBackupClient | Install anti-ransomware client | Installs the anti-ransomware client. |
| InstallCloudMonitor | Install cloudMonitor agent | Installs the CloudMonitor agent on a specified server. |
| InstallHybridProxy | InstallHybridProxy | Installs the Security Center agent on a proxy server in a hybrid cloud. |
| InstallPmAgent | InstallPmAgent | Installs the CloudMonitor agent on a server that is not deployed on Alibaba Cloud. |
| InstallUniBackupAgent | Install the anti-ransomware agent for databases | Installs the anti-ransomware agent for databases. |
| JoinWebLockProcessWhiteList | JoinWebLockProcessWhiteList | Adds processes to the process whitelist of web tamper proofing. |
| ListAgentlessAsset | ListAgentlessAsset | Query agentless detection assets. |
| ListAgentlessMaliciousFiles | Retrieve agentless detection malicious file list | Retrieves the list of malicious files detected by agentless detection. |
| ListAgentlessRelateMalicious | Retrieve risks associated with agentless detection events | Retrieves risks associated with agentless detection events. |
| ListAgentlessRiskUuid | Retrieve agentless detection vulnerable server list | Retrieves the list of vulnerable servers detected by agentless detection. |
| ListAgentlessTask | Retrieve agentless detection task list | Retrieves the list of agentless detection tasks. |
| ListAssetCleanConfig | ListAssetCleanConfig | Queries the configurations for cleaning offline hosts whose provider cannot be identified. |
| ListAssetInfoPublish | ListAssetInfoPublish | Queries the custom upgrade information about assets. |
| ListAssetRefreshTaskConfig | Get asset refresh configuration | Retrieves the asset refresh configuration. |
| ListAssetSelectionSelectedTarget | Query selected assets from specified assets | Queries the selected assets from the specified assets. |
| ListAssetSelectionTarget | ListAssetSelectionTarget | Queries the required asset. |
| ListAttackPathEvent | Query attack path events | Queries the list of attack path events. |
| ListAttackPathWhitelist | Query attack path whitelist | Queries the attack path whitelist. |
| ListAutoTagRules | Query asset tag rules | Queries the list of asset tag rules by using the system configuration, feature settings, multi-cloud configuration management, and asset management rule features of Security Center. |
| ListAvailableAttackPath | ListAvailableAttackPath | Query Attack Path List. |
| ListAvailableHoneypot | Query available honeypot configuration templates | Queries available honeypot configuration templates. |
| ListBackupRecord | Query backup records | Queries a list of backup records. |
| ListCheckRuleInstance | Query instances of a CSPM rule | Queries all instances under a Cloud Security Posture Management (CSPM) rule. |
| ListCheckTypes | ListCheckTypes | Queries the types of check items that meet the specified conditions based on the ID of a baseline. |
| ListClientAlertMode | Query alert settings | Queries the alert settings of assets. The default alert setting for assets is balance mode. The detailed asset list is returned only in strict mode. |
| ListCloudVendorRegions | ListCloudVendorRegions | Queries the synchronization region configurations of other clouds on a site. |
| ListClusterPluginInfo | ListClusterPluginInfo | Queries the status of plug-ins on clusters. |
| ListCriteriaStrategy | ListCriteriaStrategy | Queries the IDs and names of rules configured for proactive defense for containers. |
| ListFileProtectRule | ListFileProtectRule | Queries core file monitoring rules. |
| ListHoneypotAlarmEvents | ListHoneypotAlarmEvents | Queries the information about alert events that are generated. |
| ListHoneypotNode | ListHoneypotNode | Queries the information about management nodes. |
| ListHoneypotPreset | ListHoneypotPreset | Queries honeypot templates. |
| ListImageBuildRiskItem | ListImageBuildRiskItem | Queries the types of risky image build commands. |
| ListInstanceRiskLevels | ListInstanceRiskLevels | Queries the risk levels of instances. |
| ListInstanceRiskNum | ListInstanceRiskNum | Queries the statistics about risks in instances. |
| ListInterceptionRulePage | ListInterceptionRulePage | Queries defense rules that are configured for the container firewall feature. |
| ListOperationCheck | View details of repair or rollback tasks | Query the list of instance results under the operation check item |
| ListRdDefaultSyncList | ListRdDefaultSyncList | Queries the automatic management policies of members that are added to Security Center for multi-account management. The members in the automatic control management directory are automatically added to the member list of Security Center. |
| ListRuleTargetAll | ListRuleTargetAll | Queries the network objects based on which a specified cluster is protected. |
| ModifyAppVulScanCycle | ModifyAppVulScanCycle | Configures a scan cycle for application vulnerabilities. |
| ModifyAttestor | ModifyAttestor | Modifies the information about a witness that is created by using the container signature feature. |
| ModifyClientConfSetup | ModifyClientConfSetup | Modifies the resource configurations of the Security Center agent. |
| ModifyClientConfStrategy | ModifyClientConfStrategy | Modifies an agent configuration policy. |
| ModifyCloudVendorTrialConfig | Modify the audit log configuration information for multi-cloud access | Modify the Trail configuration information for the AK |
| ModifyClusterCnnfStatusUserConfirm | ModifyClusterCnnfStatusUserConfirm | Fixes the blocking status of clusters whose status is Normal to be confirmed. |
| ModifyDingTalkStatus | ModifyDingTalkStatus | Changes the notification status of a DingTalk chatbot. |
| ModifyLoginSwitchConfig | ModifyLoginSwitchConfig | Enables or disables the logon security settings for a specific asset. |
| ModifyOperateVul | ModifyOperateVul | Handles detected vulnerabilities. You can fix, check, or ignore the vulnerabilities. |
| ModifyPropertyScheduleConfig | ModifyPropertyScheduleConfig | Modifies the collection frequency of asset fingerprints for an automatic periodic collection task. |
| ModifyRefreshProcessInfo | ModifyRefreshProcessInfo | Refreshes the list of processes that are associated with a Linux software vulnerability. |
| ModifySecurityCheckScheduleConfig | ModifySecurityCheckScheduleConfig | Specifies the time when an automatic configuration check on cloud services runs. |
| ModifySecurityEventMarkMissIndividually | ModifySecurityEventMarkMissIndividually | Modifies the alert handling rule for alerts that are added to the whitelist by asset. |
| ModifyStrategy | ModifyStrategy | Modifies a baseline check policy. |
| ModifyStrategyTarget | ModifyStrategyTarget | Modifies the servers to which a baseline check policy is applied. |
| ModifyTagWithUuid | ModifyTagWithUuid | Modifies the names of the tags that are added to assets, or modifies the tags for assets. |
| ModifyVpcHoneyPot | ModifyVpcHoneyPot | Enables or disables a honeypot. |
| ModifyVulWhitelistTarget | ModifyVulWhitelistTarget | Modifies the servers that are added to a vulnerability whitelist. |
| ModifyWebLockRefresh | ModifyWebLockRefresh | Refreshes the status of the web tamper proofing feature for a server. |
| ModifyWebPath | ModifyWebPath | Modifies a custom web directory. |
| OperateAgentClientInstall | OperateAgentClientInstall | Installs the Security Center agent on servers. |
| OperateApplication | OperateApplication | Adds or deletes container applications for tamper proofing. |
| OperateBucketScanTask | OperateBucketScanTask | Manages an Object Storage Service (OSS) bucket check task. |
| OperateCommonOverallConfig | OperateCommonOverallConfig | Enables or disables a feature by type. |
| OperateSuspiciousTargetConfig | OperateSuspiciousTargetConfig | Configures the scope on which proactive defense takes effect. |
| OperationCancelIgnoreSuspEvent | OperationCancelIgnoreSuspEvent | Cancels ignoring alert events. |
| PauseClient | PauseClient | Enables or disables the Security Center agent. |
| PublicPreCheckImageScanTask | PublicPreCheckImageScanTask | Queries the number of images to scan in an image scan task and the quota for container image scan to be consumed by the task. |
| PublicSyncAndCreateImageScanTask | PublicSyncAndCreateImageScanTask | Adds images to Security Center and creates an image scan task to scan the images. |
| QueryDiscoverDatabase | QueryDiscoverDatabase | Queries the progress of a database scan task. |
| QueryGroupedSecurityEventMarkMissList | QueryGroupedSecurityEventMarkMissList | Queries whitelist rules. |
| RefreshAssets | RefreshAssets | Synchronizes assets. |
| RefreshRegistryToken | RefreshRegistryToken | Updates an image token. |
| ResetHoneypot | ResetHoneypot | Resets a honeypot. |
| ResetLogShipper | ResetLogShipper | Resets and upgrades the log analysis feature. You can call this operation only when the log analysis feature uses the pay-as-you-go billing method. |
| RetryInstallProbe | RetryInstallProbe | Retry installing the honeypot probe. |
| RollbackSuspEventQuaraFile | RollbackSuspEventQuaraFile | Restores a quarantined file. |
| SasInstallCode | SasInstallCode | Queries the installation verification code that is used to run the installation command of the Security Center agent. |
| SaveSuspEventUserSetting | SaveSuspEventUserSetting | Saves alert settings. |
| SaveWhiteListStrategy | SaveWhiteListStrategy | Creates an application whitelist policy. |
| SaveWhiteListStrategyAssets | SaveWhiteListStrategyAssets | Manages the servers to which an application whitelist policy is applied. |
| SetClusterInterceptionConfig | SetClusterInterceptionConfig | Configures the status of the container firewall feature. |
| SetImageSensitiveFileStatus | SetImageSensitiveFileStatus | Modifies the status of sensitive files in an image. |
| SetRegistryScanDayNum | SetRegistryScanDayNum | Specifies a cycle to scan images for image repositories. Unit: days. |
| SetSensitiveDefineRuleConfig | SetSensitiveDefineRuleConfig | Configure the check rules of sensitive files. |
| StartDiscoverDatabaseTask | StartDiscoverDatabaseTask | Starts a database scan task. |
| StartHoneypot | StartHoneypot | Starts a honeypot. |
| StartIdcProbeScan | StartIdcProbeScan | Starts an IDC scan task. |
| StartPreCheckDatabase | StartPreCheckDatabase | Starts a database precheck task. |
| StartVirusScanTask | StartVirusScanTask | Performs a virus scan task on a server or multiple servers. |
| StopHoneypot | StopHoneypot | Stops a honeypot. |
| SubmitTenantCheck | SubmitTenantCheck | Submits a free quick scan task, which includes vulnerability detection in the free category and free check items of Cloud Security Posture Management (CSPM). |
| TriggerCheck | TriggerCheck | Triggers ISO 27001 compliance checks of Security Center. |
| UninstallBackupClient | UninstallBackupClient | Uninstalls the anti-ransomware agent. |
| UninstallUniBackupAgent | UninstallUniBackupAgent | Uninstalls the database backup agent. |
| UpdateAlarmEvent | UpdateAlarmEvent | Updates the status of the honeypot installation time. |
| UpdateAttackPathWhitelist | UpdateAttackPathWhitelist | Update Attack Path Whitelist. |
| UpdateCheckScopeConfig | Update check scope configuration | Updates the check scope configuration. |
| UpdateClientAlertMode | UpdateClientAlertMode | Modifies alerting settings for servers. |
| UpdateFileProtectRule | UpdateFileProtectRule | Modifies the content of a core file monitoring rule based on the ID of the rule. |