Package-level declarations
Types
The Activity query definitions
Describes an automation rule action to add a task to an incident.
Describes the configuration of a system inside the agent.
Settings for how to dynamically override alert static details
A single alert property mapping to override
Alerts data type for data connectors.
Represents anomaly timeline item.
Model for authentication with the API Key. Will result in additional header on the request (default behavior) to the remote server: 'ApiKeyName: ApiKeyIdentifier ApiKey'. If 'IsApiKeyInPostPayload' is true it will send it in the body of the request and not the header.
An entity describing a content item.
Describes an automation rule action to add a task to an incident
Describes an automation rule condition with boolean operators.
Describes an automation rule action to modify an object's properties
Describes an automation rule condition on array properties.
Describes an automation rule action to run a playbook
Model for API authentication with AWS.
The available data types for Amazon Web Services CloudTrail data connector.
Logs data type.
Resources created in Azure DevOps repository.
Model for API authentication with basic flow - user name + password.
Represents bookmark timeline item.
Describes an automation rule condition that applies a boolean operator (e.g AND, OR) to conditions
A custom response configuration for a rule.
Information on the client (user or application) that made some action
The criteria by which we determine whether the connector is connected or not. For Example, use a KQL query to check if the expected data type is flowing).
The data type which is created by the connector, including a query indicated when was the last time that data type was received in the workspace.
The exposure status of the connector to the customers.
The required Permissions for the connector.
The resource provider details include the required permissions for the user to create connections. The user should have the required permissions(Read\Write, ..) in the specified scope ProviderPermissionsScope against the specified resource provider.
The mapping of content type to a repo path.
The UiConfig for 'Customizable' connector definition kind.
The UiConfig for 'Customizable' connector definition kind.
The Custom permissions required for the connector.
Common field for data type in data connectors.
The configuration of the destination of the data.
Information regarding a deployment.
An individual contact associated with this domain
The set of contacts associated with this domain
The whois record for a given domain
Entity insight Item.
The Time interval that the query actually executed on.
Single entity mapping for the alert rule
Event grouping settings property bag.
A single field mapping of the mapped entity
Model for API authentication for all GCP kind connectors.
Represents AAD (Azure Active Directory) data connector.
Represents AATP (Azure Advanced Threat Protection) data connector.
Action for alert rule.
Represents Activity entity query.
Settings with single toggle.
Represents Anomaly Security ML Analytics Settings
Represents ASC (Azure Security Center) data connector.
Represents Amazon Web Services CloudTrail data connector.
Represents a relation between two resources
Represents a bookmark in Azure Security Insights.
Describes the configuration of a Business Application Agent.
Represents a Package in Azure Security Insights.
Template resource definition.
Connector definition for kind 'Customizable'.
The entity timeline result operation response.
Settings with single toggle.
The Get Insights result operation response.
Settings with single toggle.
Represents a file import in Azure Security Insights.
Represents Fusion alert rule.
Represents a Hunt Comment in Azure Security Insights
Represents a Hunt Relation in Azure Security Insights.
Represents a Hunt in Azure Security Insights.
Represents an incident comment
Represents a relation between two resources
Represents an incident in Azure Security Insights.
Describes incident task properties
GetInsights Query Errors.
Get Insights result metadata.
Represents MCAS (Microsoft Cloud App Security) data connector.
Represents MDATP (Microsoft Defender Advanced Threat Protection) data connector.
Metadata resource definition.
Represents MicrosoftSecurityIncidentCreation rule.
Represents Microsoft Threat Intelligence data connector.
Represents office data connector.
Represents Premium Microsoft Defender for Threat Intelligence data connector.
Represents Rest Api Poller data connector.
Represents scheduled alert rule.
Sentinel onboarding state
Represents a SourceControl in Azure Security Insights.
Describes the system within the agent.
Threat intelligence information object.
Represents threat intelligence data connector.
Settings with single toggle.
Represents a Watchlist Item in Azure Security Insights.
Represents a Watchlist in Azure Security Insights.
The workspace manager assignment
The workspace manager configuration
The workspace manager group
The workspace manager member
Model for API authentication for GitHub. For this authentication first we need to approve the Router app (Microsoft Security DevOps) to access the GitHub account, Then we only need the InstallationId to get the access token from https://api.github.com/app/installations/{installId}/access_tokens.
Resources created in GitHub repository.
The graph query to show the volume of data arriving into the workspace over time.
Grouping configuration property bag.
Incident Configuration property bag.
Describes related incident information for the bookmark
Represents an incident label
Query results for table insights query.
Instruction step details, to be displayed in the Instructions steps section in the connector's page in Sentinel Portal.
Instruction steps to enable the connector.
Model for API authentication with JWT. Simple exchange between user name + password to access token.
Geodata information for a given IP address
List all the source controls.
List all actions for a system to perform.
Whois information for a given domain and associated metadata
Represents lock user action.
The available data types for MCAS (Microsoft Cloud App Security) data connector.
Publisher or creator of the content item.
ies for the solution content item
Dependencies for the content item, what other content items it requires to work. Can describe more complex dependencies using a recursive/nested structure. For a single dependency an id/kind/version can be supplied or operator/criteria for complex dependencies.
The original source of the content item, where it comes from.
Support information for the content item.
The available data types for Microsoft Threat Intelligence data connector.
Data type for Microsoft Threat Intelligence data connector.
Model for API authentication with no authentication method - public API.
Model for API authentication with OAuth2.
The available data types for office data connector.
Exchange data type connection.
SharePoint data type connection.
Teams data type connection.
The available data types for Premium Microsoft Defender for Threat Intelligence data connector.
Data type for Premium Microsoft Defender for Threat Intelligence data connector.
Describes an automation rule condition that evaluates an array property's value change
Describes an automation rule condition that evaluates an array property's value
Describes an automation rule condition that evaluates a property's value change
Describes an automation rule condition that evaluates a property's value
Resources created in user's repository for the source-control.
metadata of a repository.
Required permissions for the connector resource provider that define in ResourceProviders. For more information about the permissions see
The request configuration.
The request paging configuration.
Describes the Rfc connector.
Describes the configuration of a SAP Docker agent.
Describes the SAP configuration.
Represents security alert timeline item.
security ml analytics settings data sources
Model for API authentication with session cookie.
Metadata pertaining to creation and last modification of the resource.
Template property bag.
The available data types for TI (Threat Intelligence) data connector.
Data type for indicators connection.
timeline aggregation information per kind
Timeline Query Errors.
Expansion result metadata.
Represents an unlock user action.
User information that made some action
Describes an error encountered in the file during validation.
User information that made some action
Detail about the webhook object.