Queries the number of alert events in each attack phase.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:QueryAttackCount |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| From |
string |
No |
The ID of the request source. Set the value to sas. |
sas |
| Lang |
string |
No |
The language of the content within the request and response. Default value: zh. Valid values:
|
zh |
| SourceIp |
string |
No |
The source IP address of the request. |
175.0.XX.XX |
| Uuids |
string |
No |
The UUID of the asset. Note
You can call the DescribeCloudCenterInstances operation to query the UUIDs of assets. |
1587bedb-fdb4-48c4-9330-************ |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
ListResult |
||
| Data |
array<object> |
An array that consists of the numbers of alert events in different attack phases. |
|
|
object |
The information about alert events in the attack phase. |
||
| TacticId |
string |
The stage ID of the ATT&CK attack. |
TA0043 |
| TacticType |
string |
The type of stage of the ATT&CK attack. |
Data collection |
| EventCount |
integer |
The number of times that the alert is triggered. |
28 |
| Count |
integer |
The number of entries returned on the current page. |
0 |
| Success |
boolean |
Indicates whether exceptions are handled. Valid values:
|
true |
| Code |
string |
The HTTP status code returned. |
200 |
| Message |
string |
The error message returned. |
successful |
| RequestId |
string |
The ID of the request, which is used to locate and troubleshoot issues. |
D4BE7D77-5B02-5126-A684-A73F6CD3XXXX |
Examples
Success response
JSON format
{
"Data": [
{
"TacticId": "TA0043",
"TacticType": "Data collection",
"EventCount": 28
}
],
"Count": 0,
"Success": true,
"Code": "200",
"Message": "successful",
"RequestId": "D4BE7D77-5B02-5126-A684-A73F6CD3XXXX"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | NoPermission | no permission | |
| 400 | UnknownError | UnknownError | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.