Threats
# Custom Action Keyword
Generates the detection keyword (query) for a custom action based on the given attack module and its related fields (file hashes, file name, play process ids, url or action id). The returned keyword can then be passed to the Create Action endpoint.
post/v1/threat-library/actions/custom-keyword
Request body
Response
CustomActionKeywordReturnResponse
Changes
No recorded changes to this endpoint across all 4 revisions of this API.