Domain name for API request: csip.intl.tencentcloudapi.com.
This API is used to obtain EDR alert details, including complete information such as alert content JSON, asset enrichment, and intelligence enrichment.
A maximum of 20 requests can be initiated per second for this API.
The following request parameter list only provides API request parameters and some common parameters. For the complete common parameter list, see Common Request Parameters.
| Parameter Name | Required | Type | Description |
|---|---|---|---|
| Action | Yes | String | Common Params. The value used for this API: DescribeEdrAlertInfo. |
| Version | Yes | String | Common Params. The value used for this API: 2022-11-21. |
| Region | No | String | Common Params. This parameter is not required. |
| Target | Yes | EdrAlertTarget | Alarm location information (including cross-account AppID) |
| MemberId.N | No | Array of String | Group account member id |
| Parameter Name | Type | Description |
|---|---|---|
| Alert | EdrAlertDetail | Alert details |
| RequestId | String | The unique request ID, generated by the server, will be returned for every request (if the request fails to reach the server for other reasons, the request will not obtain a RequestId). RequestId is required for locating a problem. |
Retrieve EDR alert details
POST / HTTP/1.1
Host: cwp.tencentcloudapi.com
Content-Type: application/json
X-TC-Action: DescribeEdrAlertInfo
<Common request parameters>
{
"Target": {
"Id": 1000000000004319,
"AppId": 260108008,
"AlertId": "2e44dee79d7d98335f2c2ec5c33aaf0a",
"Quuid": "8a4eac2e-d5e0-4422-8ab1-5199ccffd9c0",
"InstanceId": "ins-llfob98q"
}
}
{
"Response": {
"Alert": {
"AlertCategory": "AI_LINK_ENGINE",
"AlertId": "2e44dee79d7d98335f2c2ec5c33aaf0a",
"AlertName": "Multi-Action Attack"
"AlertSource": "HOST",
"AlertSubType": "MULTI_BEHAVIOR_ATTACK",
"AppId": 260108008,
"AttackStage": "",
"CSIPTags": [],
"ClusterId": "",
"ContainerId": "",
"Content": "{\"alert_raw_id\":\"eql-333a7b877fc181df\",\"alert_raw_ids\":[\"eql-333a7b877fc181df\"],\"alert_source_engine\":\"AI-Link\",\"alert_source_rule_mode\":\"balanced\",\"alert_type_category\":\"command\",\"behaviors\":[{\"action\":\"process_snapshot\",\"behavior_description\":\"bash DNS process_snapshot a.qqmusic1.com\",\"behavior_description_en\":\"bash DNS process_snapshot a.qqmusic1.com\",\"dataset\":\"cwp.dns\",\"destination_ip\":\"13.158.37.189\",\"dns_question_name\":\"a.qqmusic1.com\",\"parent_process_cmdline\":\"\",\"parent_process_name\":\"\",\"process_command_line\":\"/bin/sh -c sleep 100\",\"process_executable\":\"bash\",\"process_md5\":\"4002e96f27590cee08ca6bf6d32db707\",\"process_name\":\"bash\",\"process_pid\":62635,\"process_start\":\"\",\"pstree\":\"[{\\\"exe\\\":\\\"bash\\\",\\\"cmdline\\\":\\\"/bin/sh -c sleep 100\\\",\\\"pid\\\":62635,\\\"name\\\":\\\"bash\\\"}]\",\"threat_intels\":[{\"field\":\"dns_question_name\",\"ioc_type\":\"domain\",\"ioc_value\":\"a.qqmusic1.com\",\"domain_detail\":{\"Result\":\"black\",\"Basis\":[\"Intelligence analysis\"],\"RegistrarName\":\"redacted for privacy\",\"DNSHistory\":[{\"IP\":\"47.238.142.66\",\"Tags\":[\"ValleyRAT remote-control Trojan\",\"Winos4.0 malware\",\"Shulang remote-control Trojan\",\"Silver Fox group\"],\"Location\":[\"China\",\"Hong Kong (China)\",\"Hong Kong (China)\"],\"ISP\":\"Alibaba Cloud\",\"FirstSeen\":\"2026-01-28 05:54:05\",\"LastSeen\":\"2026-05-31 17:06:04\"},{\"IP\":\"8.217.103.109\",\"Tags\":[\"Proxy rotation\"],\"Location\":[\"China\",\"Hong Kong (China)\",\"Hong Kong (China)\"],\"ISP\":\"Alibaba Cloud\",\"FirstSeen\":\"2026-04-14 15:48:00\",\"LastSeen\":\"2026-05-01 05:05:02\"},{\"IP\":\"47.75.116.189\",\"Tags\":[\"ValleyRAT remote-control Trojan\",\"Winos4.0 malware\",\"Silver Fox group\"],\"Location\":[\"China\",\"Hong Kong (China)\",\"Hong Kong (China)\"],\"ISP\":\"Alibaba Cloud\",\"FirstSeen\":\"2026-05-30 10:02:11\",\"LastSeen\":\"2026-05-30 10:02:11\"}]}},{\"field\":\"destination_ip\",\"ioc_type\":\"ip\",\"ioc_value\":\"13.158.37.189\",\"ip_detail\":{\"Result\":\"suspicious\",\"Tags\":[\"Silver Fox group\",\"Proxy rotation\"],\"Basis\":\"Intelligence analysis\",\"ISP\":\"Amazon\",\"Location\":[\"Japan\",\"Tokyo\",\"Tokyo\"],\"Family\":[\"Silver Fox\"],\"Purpose\":[\"IDC-IP\"],\"Referer\":[{\"Domain\":\"uu.goldeyeuu.io\",\"Tags\":[\"Zusy bank trojan\"],\"Time\":\"2026-05-27 00:00:00\"},{\"Domain\":\"wk.goldeyeuu.io\",\"Tags\":[\"Zusy bank trojan\"],\"Time\":\"2026-05-27 00:00:00\"}]}}],\"timestamp\":\"2026-05-26T06:06:47.134112932+08:00\",\"user_name\":\"root\",\"working_directory\":\"\"}],\"edr_rule_id\":\"rule-c24e613eff9b86d9\",\"edr_rule_name\":\"Multi-field test rule - horizontal scroll\",\"execute_user\":\"root\","harm_description": "After hacking the server, the hacker may perform operations such as downloading malicious files, connecting to a mining pool, adding public keys, and viewing sensitive files for further malicious actions.", "suggest_scheme": "1. Check for malicious processes and invalid ports, remove suspicious startup items and scheduled tasks; 2. Delete trojan files; 3. Conduct risk detection on the system and reinforce security"
"ContentType": "",
"DetectMode": "BALANCED",
"EventCount": 1,
"FirstDetectTime": "2026-05-25 14:52:56",
"HarmDesc": "After compromising the server, the hacker may download malicious files, connect to a mining pool, add public keys, and view sensitive files for further malicious actions.",
"HarmDescSource": "default",
"Id": 1000000000004319,
"ImageId": "",
"InstanceId": "ins-llfob98q",
"InstanceName": "",
"IntelSource": "",
"IsProVersion": 1,
"LatestDetectTime": "2026-05-25 14:52:56",
"Level": "MEDIUM",
"ModifyTime": "2026-05-28 17:38:45",
"MultiBehaviorDetectionMode": "command",
"PrivateIp": "",
"PublicIp": "",
"Quuid": "8a4eac2e-d5e0-4422-8ab1-5199ccffd9c0",
"RuleId": "908776",
"RuleName": "",
"RuleType": 0,
"SourceDesc": "Rule engine: AI-Link engine Rule 908776 Detection mode: Balanced"
"Status": "PENDING",
"SuggestScheme": "1. Check for malicious processes and invalid ports, and remove suspicious startup items and scheduled tasks; 2. Isolate or delete related Trojan files; 3. Conduct a risk detection on the system and reinforce security",
"ThreatTags": [],
"Verdict": "",
"VerdictBasis": "",
"ContainerName": "nginx-container",
"ImageName": "nginx:latest",
"ClusterName": "cls-demo",
"RunStatus": "RUNNING",
"PodName": "nginx-pod",
"PodIp": "10.0.0.5",
"Namespace": "default",
"PodWorkloadType": "Deployment",
"ClusterCaMD5": "d41d8cd98f00b204e9800998ecf8427e",
"PodUniqueId": "pod-uniq-001"
},
"RequestId": "f8998684-7376-4fcf-9c6d-4f20dd0591a0"
}
}
TencentCloud API 3.0 integrates SDKs that support various programming languages to make it easier for you to call APIs.
The following only lists the error codes related to the API business logic. For other error codes, see Common Error Codes.
| Error Code | Description |
|---|---|
| FailedOperation | Operation failed. |
| InternalError | Internal error. |
| InvalidParameter | Parameter error. |
Apakah halaman ini membantu?
Anda juga dapat Menghubungi Penjualan atau Mengirimkan Tiket untuk meminta bantuan.
masukan