Skip to content

WdatpClient

Attributes

TRIGGER_OPERATIONS module-attribute

TRIGGER_OPERATIONS: Dict[str, Dict[str, Any]] = {'WebHooks_CreateWebHook': {'operation_id': 'WebHooks_CreateWebHook', 'path': '/{connectionId}/subscriptions', 'method': 'post', 'required_parameters': ['request'], 'callback_payload_type': 'WebHookSubscriptionTableEntity'}, 'OnNewRemediationActivity': {'operation_id': 'OnNewRemediationActivity', 'path': '/{connectionId}/trigger/api/remediationtasks', 'method': 'get', 'required_parameters': [], 'callback_payload_type': 'OnNewRemediationActivityResponse'}}

Classes

AdvancedHuntingInput dataclass

AdvancedHuntingInput(query: Optional[str] = None)

Advanced Hunting (Deprecated)

Attributes

query class-attribute instance-attribute
query: Optional[str] = field(default=None, metadata={'wire_name': 'Query'})

The query to run

AdvancedHuntingResponse dataclass

AdvancedHuntingResponse(stats: Optional[Dict[str, Any]] = None, results: Optional[List[Dict[str, Any]]] = None)

Response for Advanced Hunting (Deprecated)

Attributes

stats class-attribute instance-attribute
stats: Optional[Dict[str, Any]] = field(default=None, metadata={'wire_name': 'Stats'})

Stats

CreateAlertByReferenceInput dataclass

CreateAlertByReferenceInput(machine_id: Optional[str] = None, report_id: Optional[str] = None, event_time: Optional[str] = None, severity: Optional[str] = None, category: Optional[str] = None, title: Optional[str] = None, description: Optional[str] = None, recommended_action: Optional[str] = None)

Alerts - Create alert

Attributes

machine_id class-attribute instance-attribute
machine_id: Optional[str] = field(default=None, metadata={'wire_name': 'machineId'})

ID of the machine on which the event was identified

report_id class-attribute instance-attribute
report_id: Optional[str] = field(default=None, metadata={'wire_name': 'reportId'})

Report Id of the event

event_time class-attribute instance-attribute
event_time: Optional[str] = field(default=None, metadata={'wire_name': 'eventTime'})

Time of the event as string, e.g. 2018-08-03T16:45:21.7115183Z

severity class-attribute instance-attribute
severity: Optional[str] = None

Severity of the alert.

category class-attribute instance-attribute
category: Optional[str] = None

Category of the alert

title class-attribute instance-attribute
title: Optional[str] = None

Title of the Alert

description class-attribute instance-attribute
description: Optional[str] = None

Description of the Alert

recommended_action class-attribute instance-attribute
recommended_action: Optional[str] = field(default=None, metadata={'wire_name': 'recommendedAction'})

Recommended action for the Alert

Alert dataclass

Alert(id: Optional[str] = None, incident_id: Optional[int] = None, investigation_id: Optional[int] = None, severity: Optional[str] = None, status: Optional[str] = None, description: Optional[str] = None, alert_creation_time: Optional[str] = None, category: Optional[str] = None, title: Optional[str] = None, threat_family_name: Optional[str] = None, detection_source: Optional[str] = None, classification: Optional[str] = None, determination: Optional[str] = None, assigned_to: Optional[str] = None, resolved_time: Optional[str] = None, last_event_time: Optional[str] = None, first_event_time: Optional[str] = None, machine_id: Optional[str] = None)

Response for Alerts - Create alert

Attributes

id class-attribute instance-attribute
id: Optional[str] = None

Alert identifier

incident_id class-attribute instance-attribute
incident_id: Optional[int] = field(default=None, metadata={'wire_name': 'incidentId'})

The ID of the incident

investigation_id class-attribute instance-attribute
investigation_id: Optional[int] = field(default=None, metadata={'wire_name': 'investigationId'})

The Id of the investigation

severity class-attribute instance-attribute
severity: Optional[str] = None

Alert severity

status class-attribute instance-attribute
status: Optional[str] = None

Status of the alert

description class-attribute instance-attribute
description: Optional[str] = None

Alert description

alert_creation_time class-attribute instance-attribute
alert_creation_time: Optional[str] = field(default=None, metadata={'wire_name': 'alertCreationTime'})

The time at which the alert was created

category class-attribute instance-attribute
category: Optional[str] = None

Alert category

title class-attribute instance-attribute
title: Optional[str] = None

Alert title

threat_family_name class-attribute instance-attribute
threat_family_name: Optional[str] = field(default=None, metadata={'wire_name': 'threatFamilyName'})

Threat family name

detection_source class-attribute instance-attribute
detection_source: Optional[str] = field(default=None, metadata={'wire_name': 'detectionSource'})

Detection source

classification class-attribute instance-attribute
classification: Optional[str] = None

Alert classification

determination class-attribute instance-attribute
determination: Optional[str] = None

Alert determination

assigned_to class-attribute instance-attribute
assigned_to: Optional[str] = field(default=None, metadata={'wire_name': 'assignedTo'})

Person to whom the alert was assigned

resolved_time class-attribute instance-attribute
resolved_time: Optional[str] = field(default=None, metadata={'wire_name': 'resolvedTime'})

The time at which the alert was resolved

last_event_time class-attribute instance-attribute
last_event_time: Optional[str] = field(default=None, metadata={'wire_name': 'lastEventTime'})

The time of the last event related to the alert

first_event_time class-attribute instance-attribute
first_event_time: Optional[str] = field(default=None, metadata={'wire_name': 'firstEventTime'})

The time of the first event related to the alert

machine_id class-attribute instance-attribute
machine_id: Optional[str] = field(default=None, metadata={'wire_name': 'machineId'})

The identifier of the machine related to the alert

GetAlertsResponse dataclass

GetAlertsResponse(count: Optional[int] = None, value: Optional[List[Alert]] = None, next_link: Optional[str] = None)

Response for Alerts - Get list of alerts

Attributes

count class-attribute instance-attribute
count: Optional[int] = field(default=None, metadata={'wire_name': '@odata.count'})

The number of available alerts by this query

value class-attribute instance-attribute
value: Optional[List[Alert]] = None

The alerts returned

next_link: Optional[str] = field(default=None, metadata={'wire_name': '@odata.nextLink'})

A link to get the next results in case there are more results than requested

PatchAlertInput dataclass

PatchAlertInput(status: Optional[str] = None, assigned_to: Optional[str] = None, classification: Optional[str] = None, determination: Optional[str] = None)

Alerts - Update alert

Attributes

status class-attribute instance-attribute
status: Optional[str] = None

Status of the alert. One of 'New', 'InProgress' and 'Resolved'

assigned_to class-attribute instance-attribute
assigned_to: Optional[str] = field(default=None, metadata={'wire_name': 'assignedTo'})

Person to assign the alert to

classification class-attribute instance-attribute
classification: Optional[str] = None

Classification of the alert. One of 'Unknown', 'FalsePositive', 'TruePositive'

determination class-attribute instance-attribute
determination: Optional[str] = None

The determination of the alert. One of 'NotAvailable', 'Apt', 'Malware', 'SecurityPersonnel', 'SecurityTesting', 'UnwantedSoftware', 'Other'

InitiateInvestigationInput dataclass

InitiateInvestigationInput(comment: Optional[str] = None)

Actions - Initiate investigation on a machine (to be deprecated)

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the investigation

InitiateInvestigationResponse dataclass

InitiateInvestigationResponse(value: Optional[str] = None)

Response for Actions - Initiate investigation on a machine (to be deprecated)

Attributes

value class-attribute instance-attribute
value: Optional[str] = None

The ID of the investigation

StartInvestigationInput dataclass

StartInvestigationInput(comment: Optional[str] = None)

Actions - Start automated investigation on a machine

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the investigation

Investigation dataclass

Investigation(id: Optional[str] = None, state: Optional[str] = None, status_details: Optional[str] = None, computer_dns_name: Optional[str] = None, machine_id: Optional[str] = None, start_time: Optional[str] = None, end_time: Optional[str] = None)

Response for Actions - Start automated investigation on a machine

Attributes

id class-attribute instance-attribute
id: Optional[str] = None

The ID of the investigation

state class-attribute instance-attribute
state: Optional[str] = None

The state of the investigation (e.g. 'Benign', 'Running', etc..)

status_details class-attribute instance-attribute
status_details: Optional[str] = field(default=None, metadata={'wire_name': 'statusDetails'})

Details on the status

computer_dns_name class-attribute instance-attribute
computer_dns_name: Optional[str] = field(default=None, metadata={'wire_name': 'computerDnsName'})

The computer name

machine_id class-attribute instance-attribute
machine_id: Optional[str] = field(default=None, metadata={'wire_name': 'machineId'})

The machine ID

start_time class-attribute instance-attribute
start_time: Optional[str] = field(default=None, metadata={'wire_name': 'startTime'})

The UTC time at which investigation was started

end_time class-attribute instance-attribute
end_time: Optional[str] = field(default=None, metadata={'wire_name': 'endTime'})

The UTC time at which investigation was completed

MachineAction dataclass

MachineAction(id: Optional[str] = None, type_: Optional[str] = None, requestor: Optional[str] = None, requestor_comment: Optional[str] = None, status: Optional[str] = None, machine_id: Optional[str] = None, creation_date_time_utc: Optional[str] = None, last_update_date_time_utc: Optional[str] = None, related_file_info: Optional[Dict[str, Any]] = None, commands: Optional[List[LiveResponseCommandStatus]] = None)

Response for Actions - Get single machine action

Attributes

id class-attribute instance-attribute
id: Optional[str] = None

The ID of the machine action

type_ class-attribute instance-attribute
type_: Optional[str] = field(default=None, metadata={'wire_name': 'type'})

The type of the action (e.g. 'Isolate', 'CollectInvestigationPackage', ...)

requestor class-attribute instance-attribute
requestor: Optional[str] = None

The person that requested the machine action

requestor_comment class-attribute instance-attribute
requestor_comment: Optional[str] = field(default=None, metadata={'wire_name': 'requestorComment'})

The comment associated to the machine action

status class-attribute instance-attribute
status: Optional[str] = None

The status of the machine action (e.g., 'InProgress')

machine_id class-attribute instance-attribute
machine_id: Optional[str] = field(default=None, metadata={'wire_name': 'machineId'})

The ID of the machine on which the action has been performed

creation_date_time_utc class-attribute instance-attribute
creation_date_time_utc: Optional[str] = field(default=None, metadata={'wire_name': 'creationDateTimeUtc'})

The UTC time at which the action has been requested

last_update_date_time_utc class-attribute instance-attribute
last_update_date_time_utc: Optional[str] = field(default=None, metadata={'wire_name': 'lastUpdateDateTimeUtc'})

The last UTC time at which the action has been updated

related_file_info class-attribute instance-attribute
related_file_info: Optional[Dict[str, Any]] = field(default=None, metadata={'wire_name': 'relatedFileInfo'})

relatedFileInfo

commands class-attribute instance-attribute
commands: Optional[List[LiveResponseCommandStatus]] = None

Live response machine action commands

CancelSingleMachineActionInput dataclass

CancelSingleMachineActionInput(comment: Optional[str] = None)

Actions - Cancel a single machine action

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the machine action cancellation

GetLiveResponseDownloadLinkResponse dataclass

GetLiveResponseDownloadLinkResponse(value: Optional[str] = None)

Response for Actions - Get live response command result download URI

Attributes

value class-attribute instance-attribute
value: Optional[str] = None

The live response command download URI

GetMachineActionsResponse dataclass

GetMachineActionsResponse(count: Optional[int] = None, value: Optional[List[MachineAction]] = None, next_link: Optional[str] = None)

Response for Actions - Get list of machine actions

Attributes

count class-attribute instance-attribute
count: Optional[int] = field(default=None, metadata={'wire_name': '@odata.count'})

The number of available machine actions by this query

value class-attribute instance-attribute
value: Optional[List[MachineAction]] = None

The machine actions returned

next_link: Optional[str] = field(default=None, metadata={'wire_name': '@odata.nextLink'})

A link to get the next results in case there are more results than requested

FileStats dataclass

FileStats(sha1: Optional[str] = None, globally_prevalence: Optional[int] = None, global_first_observed: Optional[str] = None, global_last_observed: Optional[str] = None, organization_prevalence: Optional[int] = None, org_first_seen: Optional[str] = None, org_last_seen: Optional[str] = None, top_file_names: Optional[List[str]] = None)

Response for Files - Get the statistics for the given file

Attributes

sha1 class-attribute instance-attribute
sha1: Optional[str] = None

The sha1 of the file

globally_prevalence class-attribute instance-attribute
globally_prevalence: Optional[int] = field(default=None, metadata={'wire_name': 'globallyPrevalence'})

The file global prevalence.

global_first_observed class-attribute instance-attribute
global_first_observed: Optional[str] = field(default=None, metadata={'wire_name': 'globalFirstObserved'})

The first time the file was observed globally.

global_last_observed class-attribute instance-attribute
global_last_observed: Optional[str] = field(default=None, metadata={'wire_name': 'globalLastObserved'})

The Last time the file was observed.

organization_prevalence class-attribute instance-attribute
organization_prevalence: Optional[int] = field(default=None, metadata={'wire_name': 'organizationPrevalence'})

The file prevalence across organization

org_first_seen class-attribute instance-attribute
org_first_seen: Optional[str] = field(default=None, metadata={'wire_name': 'orgFirstSeen'})

The first time the file was observed in the organization.

org_last_seen class-attribute instance-attribute
org_last_seen: Optional[str] = field(default=None, metadata={'wire_name': 'orgLastSeen'})

The last time the file was observed in the organization.

top_file_names class-attribute instance-attribute
top_file_names: Optional[List[str]] = field(default=None, metadata={'wire_name': 'topFileNames'})

The file names that this file has been presented.

DomainStats dataclass

DomainStats(host: Optional[str] = None, organization_prevalence: Optional[int] = None, org_first_seen: Optional[str] = None, org_last_seen: Optional[str] = None)

Response for Domains - Get the statistics for the given domain name

Attributes

host class-attribute instance-attribute
host: Optional[str] = None

The domain host.

organization_prevalence class-attribute instance-attribute
organization_prevalence: Optional[int] = field(default=None, metadata={'wire_name': 'organizationPrevalence'})

The domain prevalence across organization

org_first_seen class-attribute instance-attribute
org_first_seen: Optional[str] = field(default=None, metadata={'wire_name': 'orgFirstSeen'})

The first time the domain was observed in the organization.

org_last_seen class-attribute instance-attribute
org_last_seen: Optional[str] = field(default=None, metadata={'wire_name': 'orgLastSeen'})

The last time the domain was observed in the organization.

IpStats dataclass

IpStats(ip_address: Optional[str] = None, organization_prevalence: Optional[int] = None, org_first_seen: Optional[str] = None, org_last_seen: Optional[str] = None)

Response for Ips - Get the statistics for the given ip address

Attributes

ip_address class-attribute instance-attribute
ip_address: Optional[str] = field(default=None, metadata={'wire_name': 'ipAddress'})

The ip address

organization_prevalence class-attribute instance-attribute
organization_prevalence: Optional[int] = field(default=None, metadata={'wire_name': 'organizationPrevalence'})

The ip address prevalence across organization

org_first_seen class-attribute instance-attribute
org_first_seen: Optional[str] = field(default=None, metadata={'wire_name': 'orgFirstSeen'})

The first time the ip address was observed in the organization.

org_last_seen class-attribute instance-attribute
org_last_seen: Optional[str] = field(default=None, metadata={'wire_name': 'orgLastSeen'})

The last time the ip address was observed in the organization.

GetInvestigationsResponse dataclass

GetInvestigationsResponse(count: Optional[int] = None, value: Optional[List[Investigation]] = None, next_link: Optional[str] = None)

Response for Actions - Get list of investigation

Attributes

count class-attribute instance-attribute
count: Optional[int] = field(default=None, metadata={'wire_name': '@odata.count'})

The number of available investigations by this query

value class-attribute instance-attribute
value: Optional[List[Investigation]] = None

The investigations returned

next_link: Optional[str] = field(default=None, metadata={'wire_name': '@odata.nextLink'})

A link to get the next results in case there are more results than requested

CollectInvestigationPackageInput dataclass

CollectInvestigationPackageInput(comment: Optional[str] = None)

Actions - Collect investigation package

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the collection

GetInvestigationPackageUriResponse dataclass

GetInvestigationPackageUriResponse(value: Optional[str] = None)

Response for Actions - Get investigation package download URI

Attributes

value class-attribute instance-attribute
value: Optional[str] = None

The investigation package SAS URI

IsolateMachineInput dataclass

IsolateMachineInput(comment: Optional[str] = None, isolation_type: Optional[str] = None)

Actions - Isolate machine

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the isolation

isolation_type class-attribute instance-attribute
isolation_type: Optional[str] = field(default=None, metadata={'wire_name': 'IsolationType'})

Type of the isolation. Allowed values are 'Full' (for full isolation) or 'Selective' (to restrict only limited set of applications from accessing the network)

UnisolateMachineInput dataclass

UnisolateMachineInput(comment: Optional[str] = None)

Actions - Unisolate machine

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the unisolation

RestrictAppExecutionInput dataclass

RestrictAppExecutionInput(comment: Optional[str] = None)

Actions - Restrict app execution

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the restriction

UnrestrictAppExecutionInput dataclass

UnrestrictAppExecutionInput(comment: Optional[str] = None)

Actions - Remove app execution restriction

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the restriction removal

RunAntivirusScanInput dataclass

RunAntivirusScanInput(comment: Optional[str] = None, scan_type: Optional[str] = None)

Actions - Run antivirus scan

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the scan request

scan_type class-attribute instance-attribute
scan_type: Optional[str] = field(default=None, metadata={'wire_name': 'ScanType'})

Type of scan to perform. Allowed values are 'Quick' or 'Full'

RunLiveResponseInput dataclass

RunLiveResponseInput(comment: Optional[str] = None, commands: Optional[List[LiveResponseCommand]] = None)

Actions - Run live response

Attributes

comment class-attribute instance-attribute
comment: Optional[str] = field(default=None, metadata={'wire_name': 'Comment'})

A comment to associate to the isolation

commands class-attribute instance-attribute
commands: Optional[List[LiveResponseCommand]] = field(default=None, metadata={'wire_name': 'Commands'})

The live response commands to execute

GetRemediationActivitiesResponse dataclass

GetRemediationActivitiesResponse(count: Optional[int] = None, value: Optional[List[RemediationActivity]] = None, next_link: Optional[str] = None)

Response for Remediation tasks - Get list of remediation activities (Preview)

Attributes

count class-attribute instance-attribute
count: Optional[int] = field(default=None, metadata={'wire_name': '@odata.count'})

The number of remediation activities by this query

value class-attribute instance-attribute
value: Optional[List[RemediationActivity]] = None

The remediation activities returned

next_link: Optional[str] = field(default=None, metadata={'wire_name': '@odata.nextLink'})

A link to get the next results in case there are more results than requested

RemediationActivity dataclass

RemediationActivity(id: Optional[str] = None, title: Optional[str] = None, created_on: Optional[str] = None, status_last_modified_on: Optional[str] = None, requester_id: Optional[str] = None, requester_email: Optional[str] = None, status: Optional[str] = None, description: Optional[str] = None, related_component: Optional[str] = None, target_devices: Optional[int] = None, rbac_group_names: Optional[List[str]] = None, fixed_devices: Optional[int] = None, requester_notes: Optional[str] = None, due_on: Optional[str] = None, category: Optional[str] = None, productivity_impact_remediation_type: Optional[str] = None, priority: Optional[str] = None, completion_method: Optional[str] = None, completer_id: Optional[str] = None, completer_email: Optional[str] = None, scid: Optional[str] = None, type_: Optional[str] = None, product_id: Optional[str] = None, vendor_id: Optional[str] = None, name_id: Optional[str] = None, recommended_version: Optional[str] = None, recommended_vendor: Optional[str] = None, recommended_program: Optional[str] = None, recommendation_reference: Optional[str] = None)

Response for RemediationActivities - Get single remediation activity (Preview)

Attributes

id class-attribute instance-attribute
id: Optional[str] = None

The remediation activity identifier

title class-attribute instance-attribute
title: Optional[str] = None

The title of the remediation activit

created_on class-attribute instance-attribute
created_on: Optional[str] = field(default=None, metadata={'wire_name': 'createdOn'})

The time when the remediation activity was created

status_last_modified_on class-attribute instance-attribute
status_last_modified_on: Optional[str] = field(default=None, metadata={'wire_name': 'statusLastModifiedOn'})

The time when the status was last modified

requester_id class-attribute instance-attribute
requester_id: Optional[str] = field(default=None, metadata={'wire_name': 'requesterId'})

The remediation activity creator id

requester_email class-attribute instance-attribute
requester_email: Optional[str] = field(default=None, metadata={'wire_name': 'requesterEmail'})

The remediation activity creator email address

status class-attribute instance-attribute
status: Optional[str] = None

the remediation activity status

description class-attribute instance-attribute
description: Optional[str] = None

The description of the remediation activity

related_component class-attribute instance-attribute
related_component: Optional[str] = field(default=None, metadata={'wire_name': 'relatedComponent'})

The remediation activity related component

target_devices class-attribute instance-attribute
target_devices: Optional[int] = field(default=None, metadata={'wire_name': 'targetDevices'})

The number of the remediation activity target machines

rbac_group_names class-attribute instance-attribute
rbac_group_names: Optional[List[str]] = field(default=None, metadata={'wire_name': 'rbacGroupNames'})

The rbac group names associated to the remediation activity

fixed_devices class-attribute instance-attribute
fixed_devices: Optional[int] = field(default=None, metadata={'wire_name': 'fixedDevices'})

The number of the remediation activity fixed machines

requester_notes class-attribute instance-attribute
requester_notes: Optional[str] = field(default=None, metadata={'wire_name': 'requesterNotes'})

The remediation activity creator notes

due_on class-attribute instance-attribute
due_on: Optional[str] = field(default=None, metadata={'wire_name': 'dueOn'})

The due time for the remediation activity

category class-attribute instance-attribute
category: Optional[str] = None

the remediation activity category

productivity_impact_remediation_type class-attribute instance-attribute
productivity_impact_remediation_type: Optional[str] = field(default=None, metadata={'wire_name': 'productivityImpactRemediationType'})

the remediation Productivity impact type

priority class-attribute instance-attribute
priority: Optional[str] = None

The remediation activity priority

completion_method class-attribute instance-attribute
completion_method: Optional[str] = field(default=None, metadata={'wire_name': 'completionMethod'})

The remediation activity completion method

completer_id class-attribute instance-attribute
completer_id: Optional[str] = field(default=None, metadata={'wire_name': 'completerId'})

The remediation activity completer object id

completer_email class-attribute instance-attribute
completer_email: Optional[str] = field(default=None, metadata={'wire_name': 'completerEmail'})

The remediation activity completer email address

scid class-attribute instance-attribute
scid: Optional[str] = None

The remediation activity security configuration id

type_ class-attribute instance-attribute
type_: Optional[str] = field(default=None, metadata={'wire_name': 'type'})

The remediation activity type

product_id class-attribute instance-attribute
product_id: Optional[str] = field(default=None, metadata={'wire_name': 'productId'})

Product Id

vendor_id class-attribute instance-attribute
vendor_id: Optional[str] = field(default=None, metadata={'wire_name': 'vendorId'})

Vendor id

name_id class-attribute instance-attribute
name_id: Optional[str] = field(default=None, metadata={'wire_name': 'nameId'})

Name id

recommended_version class-attribute instance-attribute
recommended_version: Optional[str] = field(default=None, metadata={'wire_name': 'recommendedVersion'})

Recommended version

recommended_vendor class-attribute instance-attribute
recommended_vendor: Optional[str] = field(default=None, metadata={'wire_name': 'recommendedVendor'})

Recommended vendor

recommended_program class-attribute instance-attribute
recommended_program: Optional[str] = field(default=None, metadata={'wire_name': 'recommendedProgram'})

Recommended program

recommendation_reference class-attribute instance-attribute
recommendation_reference: Optional[str] = field(default=None, metadata={'wire_name': 'RecommendationReference'})

Recommendation reference

GetRemediationActivityMachineListResponse dataclass

GetRemediationActivityMachineListResponse(count: Optional[int] = None, value: Optional[List[Machine]] = None, next_link: Optional[str] = None)

Response for Remediation activities - Get list of related machines (Preview)

Attributes

count class-attribute instance-attribute
count: Optional[int] = field(default=None, metadata={'wire_name': '@odata.count'})

The number of available machines by this query

value class-attribute instance-attribute
value: Optional[List[Machine]] = None

The machines returned

next_link: Optional[str] = field(default=None, metadata={'wire_name': '@odata.nextLink'})

A link to get the next results in case there are more results than requested

GetMachinesResponse dataclass

GetMachinesResponse(count: Optional[int] = None, value: Optional[List[Machine]] = None, next_link: Optional[str] = None)

Response for Machines - Get list of machines

Attributes

count class-attribute instance-attribute
count: Optional[int] = field(default=None, metadata={'wire_name': '@odata.count'})

The number of available machines by this query

value class-attribute instance-attribute
value: Optional[List[Machine]] = None

The machines returned

next_link: Optional[str] = field(default=None, metadata={'wire_name': '@odata.nextLink'})

A link to get the next results in case there are more results than requested

Machine dataclass

Machine(id: Optional[str] = None, computer_dns_name: Optional[str] = None, first_seen: Optional[str] = None, last_seen: Optional[str] = None, os_platform: Optional[str] = None, os_version: Optional[str] = None, system_product_name: Optional[str] = None, last_ip_address: Optional[str] = None, last_external_ip_address: Optional[str] = None, agent_version: Optional[str] = None, os_build: Optional[int] = None, health_status: Optional[str] = None, is_aad_joined: Optional[bool] = None, machine_tags: Optional[List[str]] = None, rbac_group_id: Optional[int] = None, rbac_group_name: Optional[str] = None, risk_score: Optional[str] = None, aad_device_id: Optional[str] = None)

Response for Machines - Get single machine

Attributes

id class-attribute instance-attribute
id: Optional[str] = None

The machine identifier

computer_dns_name class-attribute instance-attribute
computer_dns_name: Optional[str] = field(default=None, metadata={'wire_name': 'computerDnsName'})

The computer name

first_seen class-attribute instance-attribute
first_seen: Optional[str] = field(default=None, metadata={'wire_name': 'firstSeen'})

The time of the first event received by the machine

last_seen class-attribute instance-attribute
last_seen: Optional[str] = field(default=None, metadata={'wire_name': 'lastSeen'})

The time of the last event received by the machine

os_platform class-attribute instance-attribute
os_platform: Optional[str] = field(default=None, metadata={'wire_name': 'osPlatform'})

The OS platform of the machine

os_version class-attribute instance-attribute
os_version: Optional[str] = field(default=None, metadata={'wire_name': 'osVersion'})

The OS version of the machine

system_product_name class-attribute instance-attribute
system_product_name: Optional[str] = field(default=None, metadata={'wire_name': 'systemProductName'})

systemProductName

last_ip_address class-attribute instance-attribute
last_ip_address: Optional[str] = field(default=None, metadata={'wire_name': 'lastIpAddress'})

The last IP address of the machine

last_external_ip_address class-attribute instance-attribute
last_external_ip_address: Optional[str] = field(default=None, metadata={'wire_name': 'lastExternalIpAddress'})

The last external IP address of the machine

agent_version class-attribute instance-attribute
agent_version: Optional[str] = field(default=None, metadata={'wire_name': 'agentVersion'})

The agent version

os_build class-attribute instance-attribute
os_build: Optional[int] = field(default=None, metadata={'wire_name': 'osBuild'})

The OS build of the machine

health_status class-attribute instance-attribute
health_status: Optional[str] = field(default=None, metadata={'wire_name': 'healthStatus'})

The health status of the machine

is_aad_joined class-attribute instance-attribute
is_aad_joined: Optional[bool] = field(default=None, metadata={'wire_name': 'isAadJoined'})

A flag indicating whether the machine is joined to Microsoft Entra ID

machine_tags class-attribute instance-attribute
machine_tags: Optional[List[str]] = field(default=None, metadata={'wire_name': 'machineTags'})

The tags associated to the machine

rbac_group_id class-attribute instance-attribute
rbac_group_id: Optional[int] = field(default=None, metadata={'wire_name': 'rbacGroupId'})

The ID of the RBAC group to which the machine belongs

rbac_group_name class-attribute instance-attribute
rbac_group_name: Optional[str] = field(default=None, metadata={'wire_name': 'rbacGroupName'})

The name of the RBAC group to which the machine belongs

risk_score class-attribute instance-attribute
risk_score: Optional[str] = field(default=None, metadata={'wire_name': 'riskScore'})

A score indicating how much the machine is at risk

aad_device_id class-attribute instance-attribute
aad_device_id: Optional[str] = field(default=None, metadata={'wire_name': 'aadDeviceId'})

aadDeviceId

MachineTagInput dataclass

MachineTagInput(value: Optional[str] = None, action: Optional[str] = None)

Machines - Tag machine

Attributes

value class-attribute instance-attribute
value: Optional[str] = field(default=None, metadata={'wire_name': 'Value'})

The tag to add or remove

action class-attribute instance-attribute
action: Optional[str] = field(default=None, metadata={'wire_name': 'Action'})

The action to perform. Value should be one of 'Add' (to add a tag) or 'Remove' (to remove a tag)

WebHookSubscriptionTableEntity dataclass

WebHookSubscriptionTableEntity(id: Optional[str] = None, notification_url: Optional[str] = None, client_state: Optional[str] = None)

Response for Triggers - Trigger when new WDATP alert occurs

Attributes

notification_url class-attribute instance-attribute
notification_url: Optional[str] = field(default=None, metadata={'wire_name': 'notificationUrl'})

Gets or sets the web hook subscription notification URL.

OnNewRemediationActivityResponse dataclass

OnNewRemediationActivityResponse(count: Optional[int] = None, value: Optional[List[RemediationActivity]] = None, next_link: Optional[str] = None)

Response for Triggers when a new remediation activity is created (Preview)

Attributes

count class-attribute instance-attribute
count: Optional[int] = field(default=None, metadata={'wire_name': '@odata.count'})

The number of remediation activities by this query

value class-attribute instance-attribute
value: Optional[List[RemediationActivity]] = None

The remediation activities returned

next_link: Optional[str] = field(default=None, metadata={'wire_name': '@odata.nextLink'})

A link to get the next results in case there are more results than requested

AdvancedHuntingSchemaInput dataclass

AdvancedHuntingSchemaInput(query: Optional[str] = None)

Advanced Hunting Schema

Attributes

query class-attribute instance-attribute
query: Optional[str] = field(default=None, metadata={'wire_name': 'Query'})

The query to run

AdvancedHuntingSchemaResponse dataclass

AdvancedHuntingSchemaResponse(additional_properties: Dict[str, Any] = dict())

Response for Advanced Hunting Schema

Attributes

additional_properties class-attribute instance-attribute
additional_properties: Dict[str, Any] = field(default_factory=dict)

Dynamic properties determined at runtime (similar to .NET [JsonExtensionData])

LiveResponseCommandStatus dataclass

LiveResponseCommandStatus(index: Optional[int] = None, start_time: Optional[str] = None, end_time: Optional[str] = None, command_status: Optional[str] = None, errors: Optional[List[str]] = None, command: Optional[LiveResponseCommand] = None)

Definition: LiveResponseCommandStatus

Attributes

index class-attribute instance-attribute
index: Optional[int] = None

The index of the command

start_time class-attribute instance-attribute
start_time: Optional[str] = field(default=None, metadata={'wire_name': 'startTime'})

The command execution start time UTC

end_time class-attribute instance-attribute
end_time: Optional[str] = field(default=None, metadata={'wire_name': 'endTime'})

The command execution end time UTC

command_status class-attribute instance-attribute
command_status: Optional[str] = field(default=None, metadata={'wire_name': 'commandStatus'})

The status of the command execution (e.g., 'Completed')

errors class-attribute instance-attribute
errors: Optional[List[str]] = None

List of command execution errors. In case no errors reported this will be an empty list.

command class-attribute instance-attribute
command: Optional[LiveResponseCommand] = None

The live response command

LiveResponseCommand dataclass

LiveResponseCommand(type_: Optional[str] = None, params: Optional[List[Dict[str, Any]]] = None)

Definition: LiveResponseCommand

Attributes

type_ class-attribute instance-attribute
type_: Optional[str] = field(default=None, metadata={'wire_name': 'type'})

The type of the command

params class-attribute instance-attribute
params: Optional[List[Dict[str, Any]]] = None

List of command parameters.

WebHookSubscriptionRequest dataclass

WebHookSubscriptionRequest(client_state: Optional[str] = None, change_type: Optional[str] = None, resource: Optional[str] = None, expiration_date_time: Optional[str] = None, notification_url: Optional[str] = None)

Definition: WebHookSubscriptionRequest

Attributes

client_state class-attribute instance-attribute
client_state: Optional[str] = field(default=None, metadata={'wire_name': 'clientState'})

Gets or sets the client state.

change_type class-attribute instance-attribute
change_type: Optional[str] = field(default=None, metadata={'wire_name': 'changeType'})

Indicates the type of change in the subscribed resource that will raise a notification.

resource class-attribute instance-attribute
resource: Optional[str] = None

Specifies the resource that will be monitored for changes.

expiration_date_time class-attribute instance-attribute
expiration_date_time: Optional[str] = field(default=None, metadata={'wire_name': 'expirationDateTime'})

Specifies the date and time when the webhook subscription expires.

notification_url class-attribute instance-attribute
notification_url: Optional[str] = field(default=None, metadata={'wire_name': 'notificationUrl'})

Gets or sets the web hook callback URL.

WebHookNotification dataclass

WebHookNotification(id: Optional[str] = None, machine_id: Optional[str] = None)

Definition: WebHookNotification

WdatpClient

WdatpClient(connection_runtime_url: str, token_provider: Optional[TokenProvider] = None, options: Optional[ConnectorClientOptions] = None)

Bases: ConnectorClientBase

Typed client for wdatp connector.

Initialize a WdatpClient.

Parameters:

Name Type Description Default
connection_runtime_url str

The connection runtime URL from Azure Portal.

required
token_provider Optional[TokenProvider]

Optional token provider. Defaults to ManagedIdentityTokenProvider.

None
options Optional[ConnectorClientOptions]

Optional connector client options.

None

Methods:

advanced_hunting_async async
advanced_hunting_async(input: AdvancedHuntingInput) -> dict[str, Any] | None

Advanced Hunting (Deprecated)

Run a custom query over Microsoft Defender for Endpoint data. This action supports only queries over MDE tables. This action is deprecated and will be retired on February 1, 2027. Migrate to the Microsoft Graph Security API. For migration guidance, see: https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0#powerplatformflow-migrationpowerapps-power-automate-logic-apps

create_alert_by_reference_async async
create_alert_by_reference_async(input: CreateAlertByReferenceInput) -> dict[str, Any] | None

Alerts - Create alert

Create Alert based on specific Event

get_alerts_async async
get_alerts_async(expand: Optional[str] = None, filter: Optional[str] = None, select: Optional[str] = None, orderby: Optional[str] = None, top: Optional[int] = None, skip: Optional[int] = None, count: Optional[bool] = None) -> dict[str, Any] | None

Alerts - Get list of alerts

Retrieve from Windows Defender ATP the most recent alerts

get_single_alert_async async
get_single_alert_async(alert_id: str) -> dict[str, Any] | None

Alerts - Get single alert

Retrieve from Windows Defender ATP a specific alert

patch_alert_async async
patch_alert_async(input: PatchAlertInput, alert_id: str) -> dict[str, Any] | None

Alerts - Update alert

Update a Windows Defender ATP alert

initiate_investigation_async async
initiate_investigation_async(input: InitiateInvestigationInput, machine_id: str) -> dict[str, Any] | None

Actions - Initiate investigation on a machine (to be deprecated)

Initiate investigation on a machine

start_investigation_async async
start_investigation_async(input: StartInvestigationInput, machine_id: str) -> dict[str, Any] | None

Actions - Start automated investigation on a machine

Start automated investigation on a machine

get_single_machine_action_async async
get_single_machine_action_async(machine_action_id: str) -> dict[str, Any] | None

Actions - Get single machine action

Retrieve from Windows Defender ATP a specific machine action

cancel_single_machine_action_async async
cancel_single_machine_action_async(input: CancelSingleMachineActionInput, machine_action_id: str) -> dict[str, Any] | None

Actions - Cancel a single machine action

Cancel a specific machine action

get_live_response_download_link_async(machine_action_id: str, command_index: int) -> dict[str, Any] | None

Actions - Get live response command result download URI

Get result download URI for a completed live response command

get_machine_actions_async async
get_machine_actions_async(filter: Optional[str] = None, select: Optional[str] = None, orderby: Optional[str] = None, top: Optional[int] = None, skip: Optional[int] = None, count: Optional[bool] = None) -> dict[str, Any] | None

Actions - Get list of machine actions

Retrieve from Windows Defender ATP the most recent machine actions

get_file_stats_async async
get_file_stats_async(file_id: str, look_back_hours: Optional[int] = None) -> dict[str, Any] | None

Files - Get the statistics for the given file

Retrieve from Windows Defender ATP statistics for the given file to a given file by identifier Sha1, or Sha256

get_domain_stats_async async
get_domain_stats_async(domain_name: str, look_back_hours: Optional[int] = None) -> dict[str, Any] | None

Domains - Get the statistics for the given domain name

Retrieve from Windows Defender ATP statistics related to a given domain name

get_ip_stats_async async
get_ip_stats_async(ip_address: str, look_back_hours: Optional[int] = None) -> dict[str, Any] | None

Ips - Get the statistics for the given ip address

Retrieve from Windows Defender ATP statistics related to a given ip address - given in ipv4 or ipv6 format.

get_single_investigation_async async
get_single_investigation_async(investigation_id: str) -> dict[str, Any] | None

Actions - Get single investigation

Retrieve from Microsoft Defender ATP a specific investigation

get_investigations_async async
get_investigations_async(filter: Optional[str] = None, select: Optional[str] = None, orderby: Optional[str] = None, top: Optional[int] = None, skip: Optional[int] = None, count: Optional[bool] = None) -> dict[str, Any] | None

Actions - Get list of investigation

Retrieve from Microsoft Defender ATP the most recent investigations

collect_investigation_package_async async
collect_investigation_package_async(input: CollectInvestigationPackageInput, machine_id: str) -> dict[str, Any] | None

Actions - Collect investigation package

Collect investigation package from a machine

get_investigation_package_uri_async async
get_investigation_package_uri_async(machine_action_id: str) -> dict[str, Any] | None

Actions - Get investigation package download URI

Get a URI that allows downloading of an investigation package

isolate_machine_async async
isolate_machine_async(input: IsolateMachineInput, machine_id: str) -> dict[str, Any] | None

Actions - Isolate machine

Isolate a machine from network

unisolate_machine_async async
unisolate_machine_async(input: UnisolateMachineInput, machine_id: str) -> dict[str, Any] | None

Actions - Unisolate machine

Unisolate a machine from network

restrict_app_execution_async async
restrict_app_execution_async(input: RestrictAppExecutionInput, machine_id: str) -> dict[str, Any] | None

Actions - Restrict app execution

Restrict execution of all applications on the machine except a predefined set

unrestrict_app_execution_async async
unrestrict_app_execution_async(input: UnrestrictAppExecutionInput, machine_id: str) -> dict[str, Any] | None

Actions - Remove app execution restriction

Enable execution of any application on the machine

run_antivirus_scan_async async
run_antivirus_scan_async(input: RunAntivirusScanInput, machine_id: str) -> dict[str, Any] | None

Actions - Run antivirus scan

Initiate Windows Defender Antivirus scan on a machine

run_live_response_async async
run_live_response_async(input: RunLiveResponseInput, machine_id: str) -> dict[str, Any] | None

Actions - Run live response

Run live response api commands for a single machine

get_remediation_activities_async async
get_remediation_activities_async(filter: Optional[str] = None, select: Optional[str] = None, orderby: Optional[str] = None, top: Optional[int] = None, skip: Optional[int] = None, count: Optional[bool] = None) -> dict[str, Any] | None

Remediation tasks - Get list of remediation activities (Preview)

Retrieve from Windows Defender ATP the remediation activities

get_single_remediation_activity_async async
get_single_remediation_activity_async(remediation_id: str) -> dict[str, Any] | None

RemediationActivities - Get single remediation activity (Preview)

Retrieve from Windows Defender ATP a specific remediation activity

get_remediation_activity_machine_list_async async
get_remediation_activity_machine_list_async(remediation_id: str) -> dict[str, Any] | None

Remediation activities - Get list of related machines (Preview)

Retrieve from Windows Defender ATP the related machines to a specific remediation activity

get_machines_async async
get_machines_async(filter: Optional[str] = None, select: Optional[str] = None, orderby: Optional[str] = None, top: Optional[int] = None, skip: Optional[int] = None, count: Optional[bool] = None) -> dict[str, Any] | None

Machines - Get list of machines

Retrieve from Windows Defender ATP the most recent machines

get_single_machine_async async
get_single_machine_async(machine_id: str) -> dict[str, Any] | None

Machines - Get single machine

Retrieve from Windows Defender ATP a specific machine

machine_tag_async async
machine_tag_async(input: MachineTagInput, machine_id: str) -> dict[str, Any] | None

Machines - Tag machine

Add or remove a tag to/from a machine

advanced_hunting_schema_async async
advanced_hunting_schema_async(input: AdvancedHuntingSchemaInput) -> dict[str, Any] | None

Advanced Hunting Schema

Gets the schema for a Windows Defender ATP custom query