package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.Finding.CreateFinding(ctx, nil)
if err != nil {
log.Fatal(err)
}
if res.CreateFindingResponse != nil {
// handle response
}
}curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/findings \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"annotations": {},
"appResourceTarget": {
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>"
},
"appUserTarget": {
"appId": "<string>",
"appUserId": "<string>"
},
"connectorTarget": {
"appId": "<string>",
"connectorId": "<string>"
},
"customSubType": "<string>",
"decoyTarget": {
"decoyId": "<string>"
},
"dedupKeyParts": [
"<string>"
],
"description": "<string>",
"identityUserTarget": {
"identityUserId": "<string>"
},
"remediationDescription": "<string>",
"tenantTarget": {}
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/findings"
payload = {
"annotations": {},
"appResourceTarget": {
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>"
},
"appUserTarget": {
"appId": "<string>",
"appUserId": "<string>"
},
"connectorTarget": {
"appId": "<string>",
"connectorId": "<string>"
},
"customSubType": "<string>",
"decoyTarget": { "decoyId": "<string>" },
"dedupKeyParts": ["<string>"],
"description": "<string>",
"identityUserTarget": { "identityUserId": "<string>" },
"remediationDescription": "<string>",
"tenantTarget": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
annotations: {},
appResourceTarget: {appId: '<string>', appResourceId: '<string>', appResourceTypeId: '<string>'},
appUserTarget: {appId: '<string>', appUserId: '<string>'},
connectorTarget: {appId: '<string>', connectorId: '<string>'},
customSubType: '<string>',
decoyTarget: {decoyId: '<string>'},
dedupKeyParts: ['<string>'],
description: '<string>',
identityUserTarget: {identityUserId: '<string>'},
remediationDescription: '<string>',
tenantTarget: {}
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'annotations' => [
],
'appResourceTarget' => [
'appId' => '<string>',
'appResourceId' => '<string>',
'appResourceTypeId' => '<string>'
],
'appUserTarget' => [
'appId' => '<string>',
'appUserId' => '<string>'
],
'connectorTarget' => [
'appId' => '<string>',
'connectorId' => '<string>'
],
'customSubType' => '<string>',
'decoyTarget' => [
'decoyId' => '<string>'
],
'dedupKeyParts' => [
'<string>'
],
'description' => '<string>',
'identityUserTarget' => [
'identityUserId' => '<string>'
],
'remediationDescription' => '<string>',
'tenantTarget' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/findings")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"annotations\": {},\n \"appResourceTarget\": {\n \"appId\": \"<string>\",\n \"appResourceId\": \"<string>\",\n \"appResourceTypeId\": \"<string>\"\n },\n \"appUserTarget\": {\n \"appId\": \"<string>\",\n \"appUserId\": \"<string>\"\n },\n \"connectorTarget\": {\n \"appId\": \"<string>\",\n \"connectorId\": \"<string>\"\n },\n \"customSubType\": \"<string>\",\n \"decoyTarget\": {\n \"decoyId\": \"<string>\"\n },\n \"dedupKeyParts\": [\n \"<string>\"\n ],\n \"description\": \"<string>\",\n \"identityUserTarget\": {\n \"identityUserId\": \"<string>\"\n },\n \"remediationDescription\": \"<string>\",\n \"tenantTarget\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"annotations\": {},\n \"appResourceTarget\": {\n \"appId\": \"<string>\",\n \"appResourceId\": \"<string>\",\n \"appResourceTypeId\": \"<string>\"\n },\n \"appUserTarget\": {\n \"appId\": \"<string>\",\n \"appUserId\": \"<string>\"\n },\n \"connectorTarget\": {\n \"appId\": \"<string>\",\n \"connectorId\": \"<string>\"\n },\n \"customSubType\": \"<string>\",\n \"decoyTarget\": {\n \"decoyId\": \"<string>\"\n },\n \"dedupKeyParts\": [\n \"<string>\"\n ],\n \"description\": \"<string>\",\n \"identityUserTarget\": {\n \"identityUserId\": \"<string>\"\n },\n \"remediationDescription\": \"<string>\",\n \"tenantTarget\": {}\n}"
response = http.request(request)
puts response.read_body{
"finding": {
"annotations": {},
"appId": "<string>",
"appResourceTarget": {
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>"
},
"appUserTarget": {
"appId": "<string>",
"appUserId": "<string>"
},
"assignedOwner": {
"appOwnerAppId": "<string>",
"identityUserId": "<string>",
"managerOfUserId": "<string>",
"userSetId": "<string>"
},
"computedOwner": {
"appOwnerAppId": "<string>",
"identityUserId": "<string>",
"managerOfUserId": "<string>",
"userSetId": "<string>"
},
"connectorAnomalyDetectionDisabled": {},
"connectorTarget": {
"appId": "<string>",
"connectorId": "<string>"
},
"createdAt": "2023-11-07T05:31:56Z",
"credentialExpiring": {
"credentialDisplayName": "<string>",
"userClientId": "<string>"
},
"credentialExpiringEvidence": {
"expired": true,
"expiresAt": "2023-11-07T05:31:56Z"
},
"credentialPubliclyExposed": {
"connectorClientId": "<string>",
"connectorManagedCredentialId": "<string>",
"credentialDisplayName": "<string>",
"functionClientId": "<string>",
"userClientId": "<string>"
},
"credentialPubliclyExposedEvidence": {
"credentialRevoked": true,
"fingerprintPrefix": "<string>",
"firstObservedAt": "2023-11-07T05:31:56Z",
"firstScannerId": "<string>",
"reportingScanners": [
"<string>"
],
"revokedAt": "2023-11-07T05:31:56Z",
"sourceKind": "<string>",
"sourceUrl": "<string>"
},
"custom": {},
"customSubType": "<string>",
"customTags": {},
"deactivatedOwner": {
"source": "DEACTIVATED_OWNER_SOURCE_UNSPECIFIED"
},
"deactivatedOwnerEvidence": {
"deactivatedOwners": [
{
"reason": "DEACTIVATED_OWNER_REASON_UNSPECIFIED",
"userId": "<string>"
}
]
},
"decoyCredentialUsed": {
"decoyId": "<string>",
"kind": "DECOY_CREDENTIAL_KIND_UNSPECIFIED"
},
"decoyPubliclyExposed": {
"decoyDisplayName": "<string>",
"decoyId": "<string>"
},
"decoyPubliclyExposedEvidence": {
"credentialRevoked": true,
"fingerprintPrefix": "<string>",
"firstObservedAt": "2023-11-07T05:31:56Z",
"firstScannerId": "<string>",
"reportingScanners": [
"<string>"
],
"revokedAt": "2023-11-07T05:31:56Z",
"sourceKind": "<string>",
"sourceUrl": "<string>"
},
"decoyTarget": {
"decoyId": "<string>"
},
"dedupKeyParts": [
"<string>"
],
"description": "<string>",
"fingerprint": "<string>",
"firstObservedAt": "2023-11-07T05:31:56Z",
"id": "<string>",
"identityUserTarget": {
"identityUserId": "<string>"
},
"lastAppearedAt": "2023-11-07T05:31:56Z",
"lastObservedAt": "2023-11-07T05:31:56Z",
"nhiUnowned": {},
"recurrenceCount": 123,
"remediationDescription": "<string>",
"resolvedAt": "2023-11-07T05:31:56Z",
"riskAcceptanceExpiresAt": "2023-11-07T05:31:56Z",
"riskAcceptanceJustification": "<string>",
"riskScore": {
"originalScore": 123,
"overrideByUserId": "<string>",
"overrideScore": 123,
"riskFactors": [
{
"description": "<string>",
"name": "<string>",
"severity": "FINDING_SEVERITY_UNSPECIFIED",
"weight": 123
}
],
"score": 123,
"systemScore": 123
},
"serviceAccountMisclassification": {
"currentAccountType": "APP_USER_TYPE_UNSPECIFIED",
"detectedAccountType": "APP_USER_TYPE_UNSPECIFIED"
},
"serviceAccountMisclassificationEvidence": {
"detectionReason": "<string>"
},
"serviceAccountUnowned": {},
"severity": "FINDING_SEVERITY_UNSPECIFIED",
"similarUsernameMatch": {
"proposedIdentityUserId": "<string>"
},
"similarUsernameMatchEvidence": {
"appUsername": "<string>",
"identityUsername": "<string>",
"similarityScore": 123
},
"snoozeReason": "<string>",
"snoozeUntil": "2023-11-07T05:31:56Z",
"sourceDetectorId": "<string>",
"sourceKind": "FINDING_SOURCE_KIND_UNSPECIFIED",
"state": "FINDING_STATE_UNSPECIFIED",
"stateUpdatedById": "<string>",
"suppressReason": "<string>",
"taskId": "<string>",
"tenantTarget": {},
"unusedSecret": {},
"unusedSecretEvidence": {
"lastUsedAt": "2023-11-07T05:31:56Z"
},
"updatedAt": "2023-11-07T05:31:56Z"
}
}Create Finding
Create a user-authored custom finding.
package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.Finding.CreateFinding(ctx, nil)
if err != nil {
log.Fatal(err)
}
if res.CreateFindingResponse != nil {
// handle response
}
}curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/findings \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"annotations": {},
"appResourceTarget": {
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>"
},
"appUserTarget": {
"appId": "<string>",
"appUserId": "<string>"
},
"connectorTarget": {
"appId": "<string>",
"connectorId": "<string>"
},
"customSubType": "<string>",
"decoyTarget": {
"decoyId": "<string>"
},
"dedupKeyParts": [
"<string>"
],
"description": "<string>",
"identityUserTarget": {
"identityUserId": "<string>"
},
"remediationDescription": "<string>",
"tenantTarget": {}
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/findings"
payload = {
"annotations": {},
"appResourceTarget": {
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>"
},
"appUserTarget": {
"appId": "<string>",
"appUserId": "<string>"
},
"connectorTarget": {
"appId": "<string>",
"connectorId": "<string>"
},
"customSubType": "<string>",
"decoyTarget": { "decoyId": "<string>" },
"dedupKeyParts": ["<string>"],
"description": "<string>",
"identityUserTarget": { "identityUserId": "<string>" },
"remediationDescription": "<string>",
"tenantTarget": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
annotations: {},
appResourceTarget: {appId: '<string>', appResourceId: '<string>', appResourceTypeId: '<string>'},
appUserTarget: {appId: '<string>', appUserId: '<string>'},
connectorTarget: {appId: '<string>', connectorId: '<string>'},
customSubType: '<string>',
decoyTarget: {decoyId: '<string>'},
dedupKeyParts: ['<string>'],
description: '<string>',
identityUserTarget: {identityUserId: '<string>'},
remediationDescription: '<string>',
tenantTarget: {}
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'annotations' => [
],
'appResourceTarget' => [
'appId' => '<string>',
'appResourceId' => '<string>',
'appResourceTypeId' => '<string>'
],
'appUserTarget' => [
'appId' => '<string>',
'appUserId' => '<string>'
],
'connectorTarget' => [
'appId' => '<string>',
'connectorId' => '<string>'
],
'customSubType' => '<string>',
'decoyTarget' => [
'decoyId' => '<string>'
],
'dedupKeyParts' => [
'<string>'
],
'description' => '<string>',
'identityUserTarget' => [
'identityUserId' => '<string>'
],
'remediationDescription' => '<string>',
'tenantTarget' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/findings")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"annotations\": {},\n \"appResourceTarget\": {\n \"appId\": \"<string>\",\n \"appResourceId\": \"<string>\",\n \"appResourceTypeId\": \"<string>\"\n },\n \"appUserTarget\": {\n \"appId\": \"<string>\",\n \"appUserId\": \"<string>\"\n },\n \"connectorTarget\": {\n \"appId\": \"<string>\",\n \"connectorId\": \"<string>\"\n },\n \"customSubType\": \"<string>\",\n \"decoyTarget\": {\n \"decoyId\": \"<string>\"\n },\n \"dedupKeyParts\": [\n \"<string>\"\n ],\n \"description\": \"<string>\",\n \"identityUserTarget\": {\n \"identityUserId\": \"<string>\"\n },\n \"remediationDescription\": \"<string>\",\n \"tenantTarget\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"annotations\": {},\n \"appResourceTarget\": {\n \"appId\": \"<string>\",\n \"appResourceId\": \"<string>\",\n \"appResourceTypeId\": \"<string>\"\n },\n \"appUserTarget\": {\n \"appId\": \"<string>\",\n \"appUserId\": \"<string>\"\n },\n \"connectorTarget\": {\n \"appId\": \"<string>\",\n \"connectorId\": \"<string>\"\n },\n \"customSubType\": \"<string>\",\n \"decoyTarget\": {\n \"decoyId\": \"<string>\"\n },\n \"dedupKeyParts\": [\n \"<string>\"\n ],\n \"description\": \"<string>\",\n \"identityUserTarget\": {\n \"identityUserId\": \"<string>\"\n },\n \"remediationDescription\": \"<string>\",\n \"tenantTarget\": {}\n}"
response = http.request(request)
puts response.read_body{
"finding": {
"annotations": {},
"appId": "<string>",
"appResourceTarget": {
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>"
},
"appUserTarget": {
"appId": "<string>",
"appUserId": "<string>"
},
"assignedOwner": {
"appOwnerAppId": "<string>",
"identityUserId": "<string>",
"managerOfUserId": "<string>",
"userSetId": "<string>"
},
"computedOwner": {
"appOwnerAppId": "<string>",
"identityUserId": "<string>",
"managerOfUserId": "<string>",
"userSetId": "<string>"
},
"connectorAnomalyDetectionDisabled": {},
"connectorTarget": {
"appId": "<string>",
"connectorId": "<string>"
},
"createdAt": "2023-11-07T05:31:56Z",
"credentialExpiring": {
"credentialDisplayName": "<string>",
"userClientId": "<string>"
},
"credentialExpiringEvidence": {
"expired": true,
"expiresAt": "2023-11-07T05:31:56Z"
},
"credentialPubliclyExposed": {
"connectorClientId": "<string>",
"connectorManagedCredentialId": "<string>",
"credentialDisplayName": "<string>",
"functionClientId": "<string>",
"userClientId": "<string>"
},
"credentialPubliclyExposedEvidence": {
"credentialRevoked": true,
"fingerprintPrefix": "<string>",
"firstObservedAt": "2023-11-07T05:31:56Z",
"firstScannerId": "<string>",
"reportingScanners": [
"<string>"
],
"revokedAt": "2023-11-07T05:31:56Z",
"sourceKind": "<string>",
"sourceUrl": "<string>"
},
"custom": {},
"customSubType": "<string>",
"customTags": {},
"deactivatedOwner": {
"source": "DEACTIVATED_OWNER_SOURCE_UNSPECIFIED"
},
"deactivatedOwnerEvidence": {
"deactivatedOwners": [
{
"reason": "DEACTIVATED_OWNER_REASON_UNSPECIFIED",
"userId": "<string>"
}
]
},
"decoyCredentialUsed": {
"decoyId": "<string>",
"kind": "DECOY_CREDENTIAL_KIND_UNSPECIFIED"
},
"decoyPubliclyExposed": {
"decoyDisplayName": "<string>",
"decoyId": "<string>"
},
"decoyPubliclyExposedEvidence": {
"credentialRevoked": true,
"fingerprintPrefix": "<string>",
"firstObservedAt": "2023-11-07T05:31:56Z",
"firstScannerId": "<string>",
"reportingScanners": [
"<string>"
],
"revokedAt": "2023-11-07T05:31:56Z",
"sourceKind": "<string>",
"sourceUrl": "<string>"
},
"decoyTarget": {
"decoyId": "<string>"
},
"dedupKeyParts": [
"<string>"
],
"description": "<string>",
"fingerprint": "<string>",
"firstObservedAt": "2023-11-07T05:31:56Z",
"id": "<string>",
"identityUserTarget": {
"identityUserId": "<string>"
},
"lastAppearedAt": "2023-11-07T05:31:56Z",
"lastObservedAt": "2023-11-07T05:31:56Z",
"nhiUnowned": {},
"recurrenceCount": 123,
"remediationDescription": "<string>",
"resolvedAt": "2023-11-07T05:31:56Z",
"riskAcceptanceExpiresAt": "2023-11-07T05:31:56Z",
"riskAcceptanceJustification": "<string>",
"riskScore": {
"originalScore": 123,
"overrideByUserId": "<string>",
"overrideScore": 123,
"riskFactors": [
{
"description": "<string>",
"name": "<string>",
"severity": "FINDING_SEVERITY_UNSPECIFIED",
"weight": 123
}
],
"score": 123,
"systemScore": 123
},
"serviceAccountMisclassification": {
"currentAccountType": "APP_USER_TYPE_UNSPECIFIED",
"detectedAccountType": "APP_USER_TYPE_UNSPECIFIED"
},
"serviceAccountMisclassificationEvidence": {
"detectionReason": "<string>"
},
"serviceAccountUnowned": {},
"severity": "FINDING_SEVERITY_UNSPECIFIED",
"similarUsernameMatch": {
"proposedIdentityUserId": "<string>"
},
"similarUsernameMatchEvidence": {
"appUsername": "<string>",
"identityUsername": "<string>",
"similarityScore": 123
},
"snoozeReason": "<string>",
"snoozeUntil": "2023-11-07T05:31:56Z",
"sourceDetectorId": "<string>",
"sourceKind": "FINDING_SOURCE_KIND_UNSPECIFIED",
"state": "FINDING_STATE_UNSPECIFIED",
"stateUpdatedById": "<string>",
"suppressReason": "<string>",
"taskId": "<string>",
"tenantTarget": {},
"unusedSecret": {},
"unusedSecretEvidence": {
"lastUsedAt": "2023-11-07T05:31:56Z"
},
"updatedAt": "2023-11-07T05:31:56Z"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Body
The CreateFindingRequest message.
This message contains a oneof named target. Only a single field of the following list may be set at a time:
- identityUserTarget
- appUserTarget
- decoyTarget
- appResourceTarget
- connectorTarget
- tenantTarget
Arbitrary metadata attached to the finding; filterable by routing rules.
Show child attributes
Show child attributes
AppResourceTarget points at the app resource the finding is about.
Show child attributes
Show child attributes
The AppUserTarget message.
Show child attributes
Show child attributes
ConnectorTarget points at the connector that produced this finding.
Show child attributes
Show child attributes
User-supplied sub-classification (e.g. "shadow_it"). Part of the dedup identity and filterable via FindingSearch.
DecoyTarget points at the planted decoy that produced this finding. Populated for findings whose subject is the decoy artifact itself (e.g. decoy_credential_used), giving the UI and routing rules a uniform handle to the decoy alongside the finding_type payload.
Show child attributes
Show child attributes
Caller-supplied dedup identity. The fingerprint is a domain-separated SHA-256 over ("custom", custom_sub_type, dedup_key_parts...) — see pkg/uhash; parts cannot collide regardless of their byte content. Two creates with the same parts collapse onto one finding. Must be non-empty and every part must be non-empty.
Optional finding body (markdown by convention).
The IdentityUserTarget message.
Show child attributes
Show child attributes
Optional remediation guidance, used as the body of any task created from this finding.
Severity of the finding. Must be a defined, non-unspecified value.
FINDING_SEVERITY_UNSPECIFIED, FINDING_SEVERITY_INFO, FINDING_SEVERITY_LOW, FINDING_SEVERITY_MEDIUM, FINDING_SEVERITY_HIGH, FINDING_SEVERITY_CRITICAL TenantTarget scopes a finding to the whole tenant. It carries no subject id; the finding's tenant is the scope.
Response
Successful response
The CreateFindingResponse message.
The Finding message.
This message contains a oneof named finding_type. Only a single field of the following list may be set at a time:
- similarUsernameMatch
- serviceAccountMisclassification
- nhiUnowned
- serviceAccountUnowned
- decoyCredentialUsed
- custom
- connectorAnomalyDetectionDisabled
- deactivatedOwner
- unusedSecret
- credentialPubliclyExposed
- decoyPubliclyExposed
- credentialExpiring
This message contains a oneof named target. Only a single field of the following list may be set at a time:
- identityUserTarget
- appUserTarget
- decoyTarget
- appResourceTarget
- tenantTarget
- connectorTarget
This message contains a oneof named evidence. Only a single field of the following list may be set at a time:
- similarUsernameMatchEvidence
- serviceAccountMisclassificationEvidence
- deactivatedOwnerEvidence
- unusedSecretEvidence
- credentialPubliclyExposedEvidence
- decoyPubliclyExposedEvidence
- credentialExpiringEvidence
Show child attributes
Show child attributes
Was this page helpful?