---
title: "Changes to Find Attack discoveries that match the search criteria"
method: GET
path: "/api/attack_discovery/_find"
---

# Changes to Find Attack discoveries that match the search criteria

`GET /api/attack_discovery/_find`

> Every recorded change to this endpoint, newest first.
> 176 revisions in range; 20 not diffed.

## Timeline

Changed in 1 of 176 revisions.

- **2026-09-09** `887252c0434a` — 1 info

## Changes

- **2026-09-09** `887252c0434a` — 1 info
  - added the optional property `data/items/alert_workflow_reason` to the response with the `200` status

---

[Operation](https://skmtc.dev/elastic/apis/kibana-apis/docs/api/attack_discovery/_find/get.md) · [API](https://skmtc.dev/elastic/apis/kibana-apis.md) · [Page](https://skmtc.dev/elastic/apis/kibana-apis/changes/api/attack_discovery/_find/get)
