cases
post/cases
Request body
descriptionstring nullable
entityTypestring nullable
entityValuestring nullable
evidenceobject nullable
Initial evidence payload attached to the case at creation
linkedAlertIdstring nullable
linkedCveFindingIdstring nullable
linkedReportIdstring nullable
prioritystring nullable
sourceIdstring nullable
Identifier of the originating record
sourceTypestring nullable
Origin surface of the case (e.g. report, alert) — used with sourceId to resolve the linked record and seed initial evidence
titlestring required
Response
Created case
createdAtstring required
descriptionstring nullable
entityTypestring nullable
entityValuestring nullable
idstring required
linkedAlertIdstring nullable
linkedCveFindingIdstring nullable
linkedReportIdstring nullable
organizationIdstring nullable
prioritystring required
statusstring required
titlestring required
updatedAtstring required
userIdstring required