{"swagger":"2.0","info":{"description":"# Overview \n\nThis guide documents the InsightVM Application Programming Interface (API) Version 3. This API supports the\nRepresentation State Transfer (REST) design pattern. Unless noted otherwise this API accepts and produces the\n`application/json` media type. This API uses Hypermedia as the Engine of Application State (HATEOAS) and\nis hypermedia friendly. All API connections must be made to the security console using HTTPS.\n\n## Versioning\n\nVersioning is specified in the URL and the base path of this API is: `https:// Download the specification: Download OpenBSD OpenSSH 4.3 on Linux
|\n| `cvss-integrity-impact` | L
= LowM
= MediumH
= High
|\n| `cvss-confidentiality-impact` | N
= NoneP
= PartialC
= Complete
|\n| `cvss-availability-impact` | N
= NoneP
= PartialC
= Complete
|\n| `cvss-access-vector` | N
= NoneP
= PartialC
= Complete
|\n| `cvss-authentication-required` | L
= LocalA
= AdjacentN
= Network
|\n| `cvss-v3-confidentiality-impact` | N
= NoneS
= SingleM
= Multiple
|\n| `cvss-v3-integrity-impact` | L
= LocalL
= LowN
= NoneH
= High
|\n| `cvss-v3-availability-impact` | L
= LocalL
= LowN
= NoneH
= High
|\n| `cvss-v3-attack-vector` | N
= NoneL
= LowH
= High
|\n| `cvss-v3-attack-complexity` | N
= NetworkA
= AdjacentL
= LocalP
= Physical
|\n| `cvss-v3-user-interaction` | L
= LowH
= High
|\n| `cvss-v3-privileges-required` | N
= NoneR
= Required
|\n| `host-type` | 0=Unknown, 1=Guest, 2=Hypervisor, 3=Physical, 4=Mobile |\n| `ip-address-type` | 0=IPv4, 1=IPv6 |\n| `pci-compliance` | 0=fail, 1=pass |\n| `vulnerability-validated-status` | 0=present, 1=not present |\n\n##### Operator Properties \n\nThe following table outlines which properties are required for each operator and the appropriate data type(s):\n\n| Operator | `value` | `lower` | `upper` |\n| ----------------------|-----------------------|-----------------------|------------------------|\n| `are` | `string` | | |\n| `contains` | `string` | | |\n| `does-not-contain` | `string` | | |\n| `ends with` | `string` | | |\n| `in` | `Array[ string ]` | | |\n| `in-range` | | `numeric` | `numeric` |\n| `includes` | `Array[ string ]` | | |\n| `is` | `string` | | |\n| `is-applied` | | | |\n| `is-between` | | `string` (yyyy-MM-dd) | `numeric` (yyyy-MM-dd) |\n| `is-earlier-than` | `numeric` (days) | | |\n| `is-empty` | | | |\n| `is-greater-than` | `numeric` | | |\n| `is-on-or-after` | `string` (yyyy-MM-dd) | | |\n| `is-on-or-before` | `string` (yyyy-MM-dd) | | |\n| `is-not` | `string` | | |\n| `is-not-applied` | | | |\n| `is-not-empty` | | | |\n| `is-within-the-last` | `numeric` (days) | | |\n| `less-than` | `string` | | | \n| `like` | `string` | | |\n| `not-contains` | `string` | | |\n| `not-in` | `Array[ string ]` | | |\n| `not-in-range` | | `numeric` | `numeric` |\n| `not-like` | `string` | | |\n| `starts-with` | `string` | | |\n\n#### Discovery Connection Search Criteria \n\nDynamic sites make use of search criteria to match assets from a discovery connection. Search criteria is an array of search filters. \n\nEach search filter has a generic format of:\n\n```json\n{ \n \"field\": \"N
= NoneL
= LowH
= High
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge. ...
","description":"Textual representation of the content."}},"description":""},"CreateAuthenticationSource":{"type":"object","required":["type"],"properties":{"id":{"type":"integer","format":"int32","example":"","description":"The identifier of the authentication source to use to authenticate the user. The source with the specified identifier must be of the type specified by `type`. If `id` is omitted, then one source of the specified `type` is selected."},"type":{"type":"string","example":"","description":"The type of the authentication source to use to authenticate the user."}},"description":""},"CreatedOrUpdatedReference":{"type":"object","properties":{"id":{"type":"object","example":"3","description":"The identifier of the resource created or updated."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference":{"type":"object","properties":{"id":{"type":"object","example":"1","description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«AssetGroupID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«CredentialID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«DiscoveryQueryID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int64","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«EngineID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«PolicyOverrideID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int64","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«ScanID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int64","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«ScanTemplateID,Link»":{"type":"object","properties":{"id":{"type":"string","example":"1","description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«UserID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«VulnerabilityExceptionID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«VulnerabilityValidationID,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int64","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"CreatedReference«int,Link»":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":1,"description":"The identifier of the resource created."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"Criterion":{"type":"object","description":""},"Database":{"type":"object","required":["name"],"properties":{"description":{"type":"string","example":"Microsoft SQL Server","description":"The description of the database instance."},"id":{"type":"integer","format":"int32","example":13,"description":"The identifier of the database."},"name":{"type":"string","example":"MSSQL","description":"The name of the database instance."}},"description":""},"DatabaseConnectionSettings":{"type":"object","properties":{"maximumAdministrationPoolSize":{"type":"integer","format":"int32","example":-1,"description":"The maximum number of administrative connections in the connection pool. -1 means unlimited."},"maximumPoolSize":{"type":"integer","format":"int32","example":-1,"description":"The maximum number of connections in the connection pool. -1 means unlimited."},"maximumPreparedStatementPoolSize":{"type":"integer","format":"int32","example":256,"description":"The maximum number of prepared statements in the prepared statement pool. -1 means unlimited."}},"description":""},"DatabaseSettings":{"type":"object","properties":{"connection":{"example":"","description":"Details connection settings for the database.","$ref":"#/definitions/DatabaseConnectionSettings"},"host":{"type":"string","example":"127.0.0.1","description":"The database host."},"maintenanceThreadPoolSize":{"type":"integer","format":"int32","example":20,"description":"The maximum number of parallel tasks when executing maintenance tasks."},"port":{"type":"integer","format":"int32","example":5432,"description":"The database port."},"url":{"type":"string","example":"//127.0.0.1:5432/nexpose","description":"The database connection URL."},"user":{"type":"string","example":"nxpgsql","description":"The database user."},"vendor":{"type":"string","example":"postgresql","description":"The database vendor."}},"description":""},"DatabaseSize":{"type":"object","properties":{"bytes":{"type":"integer","format":"int64","example":5364047843,"description":"The raw value in bytes."},"formatted":{"type":"string","example":"5 GB","description":"The value formatted in human-readable notation (e.g. GB, MB, KB, bytes)."}},"description":""},"DiscoveryAsset":{"type":"object","properties":{"address":{"type":"string","example":"12.83.99.203","description":"The IP address of a discovered asset.","readOnly":true},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"desktop-27.acme.com","description":"The host name of a discovered asset.","readOnly":true}},"description":""},"DiscoveryConnection":{"type":"object","properties":{"accessKeyId":{"type":"string","example":"","description":"The AWS credential access key identifier (only used for the AWS connection)."},"address":{"type":"string","example":"","description":"The address used to connect to the discovery connection source."},"arn":{"type":"string","example":"","description":"The AWS credential ARN (only used for the AWS connection)."},"awsSessionName":{"type":"string","example":"","description":"The AWS credential session name (only used for the AWS connection)."},"connectionType":{"type":"string","example":"","description":"The type of the discovery connection."},"eventSource":{"type":"string","example":"","description":"The event source type to use."},"exchangeServerHostname":{"type":"string","example":"","description":"The hostname of the exchange server to connect to."},"exchangeUser":{"type":"string","example":"","description":"The username used to connect to the exchange server."},"folderPath":{"type":"string","example":"","description":"The folder path to pull logs from."},"id":{"type":"integer","format":"int64","example":"","description":"The identifier of the discovery connection.","readOnly":true},"ldapServer":{"type":"string","example":"","description":"The LDAP server to connect to."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"Connection 1","description":"The discovery connection name."},"port":{"type":"integer","format":"int32","example":"","description":"The port used to connect to the discovery connection source."},"protocol":{"type":"string","example":"","description":"The protocol used to connect to the discovery connection source."},"region":{"type":"string","example":"","description":"The AWS region (only used for the AWS connection)."},"scanEngineIsInsideAWS":{"type":"boolean","example":false,"description":"Flag denoting whether the scan engine is in AWS, this is used for AWS discovery connections for scanning purposes (only used for the AWS connection)."},"secretAccessKey":{"type":"string","example":"","description":"The AWS credential secret access key (only used for the AWS connection)."},"status":{"type":"string","example":"","description":"The status of the discovery connection."},"username":{"type":"string","example":"","description":"The username used to authenticate to the discovery connection source."},"winRMServer":{"type":"string","example":"","description":"The WinRM server to connect to. "}},"description":""},"DiscoverySearchCriteria":{"type":"object","properties":{"connectionType":{"type":"string","example":"","description":"The type of discovery connection configured for the site. This property only applies to dynamic sites.","enum":["activesync-ldap","activesync-office365","activesync-powershell","aws","dhcp","sonar","vsphere"]},"filters":{"type":"array","description":"Filters used to match assets from a discovery connection. See Discovery Connection Search Criteria for more information on the structure and format.","items":{"$ref":"#/definitions/SwaggerDiscoverySearchCriteriaFilter"}},"match":{"type":"string","example":"all","description":"Operator to determine how to match filters. `all` requires that all filters match for an asset to be included. `any` requires only one filter to match for an asset to be included.","enum":["any","all"]}},"description":""},"DiskFree":{"type":"object","properties":{"bytes":{"type":"integer","format":"int64","example":166532222976,"description":"The raw value in bytes."},"formatted":{"type":"string","example":"155.1 GB","description":"The value formatted in human-readable notation (e.g. GB, MB, KB, bytes)."}},"description":""},"DiskInfo":{"type":"object","properties":{"free":{"example":"","description":"Available disk space.","$ref":"#/definitions/DiskFree"},"installation":{"example":"","description":"Details regarding the size of disk used by the console installation.","$ref":"#/definitions/InstallSize"},"total":{"example":"","description":"Total disk space.","$ref":"#/definitions/DiskTotal"}},"description":""},"DiskTotal":{"type":"object","properties":{"bytes":{"type":"integer","format":"int64","example":499004735488,"description":"The raw value in bytes."},"formatted":{"type":"string","example":"464.7 GB","description":"The value formatted in human-readable notation (e.g. GB, MB, KB, bytes)."}},"description":""},"DynamicSite":{"type":"object","required":["id"],"properties":{"id":{"type":"integer","format":"int64","example":"","description":"The identifier of the discovery connection."}},"description":""},"EngineID":{"type":"object","properties":{"id":{"type":"integer","format":"int32"},"newScanEngine":{"type":"boolean"},"scope":{"type":"string","enum":["global","silo"]}},"description":""},"EnginePool":{"type":"object","required":["id","name"],"properties":{"engines":{"type":"array","description":"The identifiers of the scan engines in the engine pool.","items":{"type":"integer","format":"int32"}},"id":{"type":"integer","format":"int32","example":6,"description":"The identifier of the scan engine."},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"Corporate Scan Engine 001","description":"The name of the scan engine."},"sites":{"type":"array","description":"A list of identifiers of each site the scan engine is assigned to.","items":{"type":"integer","format":"int32"}}},"description":""},"EnvironmentProperties":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"properties":{"type":"object","example":"","description":"Key-value pairs for system and environment properties that are currently defined."}},"description":""},"Error":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"message":{"type":"string","example":"An error has occurred.","description":"The messages indicating the cause or reason for failure."},"status":{"type":"string","example":"","description":"The HTTP status code for the error (same as in the HTTP response).","enum":["100","101","102","103","200","201","202","203","204","205","206","207","208","226","300","301","302","303","304","305","307","308","400","401","402","403","404","405","406","407","408","409","410","411","412","413","414","415","416","417","418","419","420","421","422","423","424","426","428","429","431","500","501","502","503","504","505","506","507","508","509","510","511"]}},"description":""},"ExceptionScope":{"type":"object","properties":{"id":{"type":"integer","format":"int64","example":"","description":"The identifier of the scope type to which the exception applies. For example in a site scoped vulnerability exception this is the site id, in an asset group vulnerability exception this is the asset group id."},"key":{"type":"string","example":"","description":"If the scope type is `\"Instance\"`, an optional key to discriminate the instance the exception applies to."},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"port":{"type":"integer","format":"int32","example":"","description":"If the scope type is `\"Instance\"` and the vulnerability is detected on a service, the port on which the exception applies."},"type":{"type":"string","example":"","description":"The type of the exception scope. One of: `\"Global\"`, `\"Site\"`, `\"Asset\"`, `\"Asset Group\"`, `\"Instance\"`"},"vulnerability":{"type":"string","example":"","description":"The identifier of the vulnerability to which the exception applies."}},"description":""},"ExcludedAssetGroups":{"type":"object","properties":{"assetGroupIDs":{"type":"array","description":"List of asset group identifiers. Each element is an integer.","items":{"type":"integer","format":"int32"}},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}}},"description":""},"ExcludedScanTargets":{"type":"object","properties":{"addresses":{"type":"array","description":"List of addresses. Each address is a string that can represent either a hostname, ipv4 address, ipv4 address range, ipv6 address, or CIDR notation.","items":{"type":"string"}},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}}},"description":""},"Exploit":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":4924,"description":"The identifier of the exploit."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"skillLevel":{"type":"string","example":"expert","description":"The level of skill required to use the exploit.","enum":["novice","intermediate","expert"]},"source":{"example":"","description":"Details about where the exploit is defined.","$ref":"#/definitions/ExploitSource"},"title":{"type":"string","example":"Microsoft IIS WebDav ScStoragePathFromUrl Overflow","description":"The title (short summary) of the exploit."}},"description":""},"ExploitSource":{"type":"object","properties":{"key":{"type":"string","example":"exploit/windows/iis/iis_webdav_scstoragepathfromurl","description":"The identifier of the exploit in the source library."},"link":{"example":"","description":"Link to the source of the exploit.","$ref":"#/definitions/ExploitSourceLink"},"name":{"type":"string","example":"metasploit","description":"The source library of the exploit, typically the name of the vendor that maintains and/or defined the exploit.","enum":["metasploit","exploitdb"]}},"description":""},"ExploitSourceLink":{"type":"object","properties":{"href":{"type":"string","example":"http://www.metasploit.com/modules/exploit/windows/iis/iis_webdav_scstoragepathfromurl","description":"The hypertext reference for the exploit source."},"id":{"type":"string","example":"exploit/windows/iis/iis_webdav_scstoragepathfromurl","description":"Hypermedia link to the destination of the exploit source."},"rel":{"type":"string","example":"Source","description":"The relation of the hypermedia link, `\"Source\"`."}},"description":""},"Features":{"type":"object","properties":{"adaptiveSecurity":{"type":"boolean","example":false,"description":"Whether Adaptive Security features are available."},"agents":{"type":"boolean","example":true,"description":"Whether the use of agents is allowed."},"dynamicDiscovery":{"type":"boolean","example":true,"description":"Whether dynamic discovery sources may be used."},"earlyAccess":{"type":"boolean","example":false,"description":"Whether early-access features are available prior to general availability."},"enginePool":{"type":"boolean","example":true,"description":"Whether scan engine pools may be used."},"insightPlatform":{"type":"boolean","example":true,"description":"Whether the usage of the Insight platform is allowed."},"mobile":{"type":"boolean","example":true,"description":"Whether mobile features are allowed."},"multitenancy":{"type":"boolean","example":false,"description":"Whether multitenancy is allowed."},"policyEditor":{"type":"boolean","example":true,"description":"Whether the editing of policies is allowed."},"policyManager":{"type":"boolean","example":true,"description":"Whether the policy manager is allowed."},"remediationAnalytics":{"type":"boolean","example":true,"description":"Whether Remediation Analytics features are available."},"reporting":{"example":"","description":"The reporting features available in the license.","$ref":"#/definitions/LicenseReporting"},"scanning":{"example":"","description":"The scanning features available in the license.","$ref":"#/definitions/LicenseScanning"}},"description":""},"File":{"type":"object","required":["name","type"],"properties":{"attributes":{"type":"array","description":"Attributes detected on the file.","items":{"$ref":"#/definitions/Configuration"}},"name":{"type":"string","example":"ADMIN$","description":"The name of the file."},"size":{"type":"integer","format":"int64","example":-1,"description":"The size of the regular file (in bytes). If the file is a directory, no value is returned."},"type":{"type":"string","example":"directory","description":"The type of the file.","enum":["file","directory"]}},"description":""},"Fingerprint":{"type":"object","properties":{"description":{"type":"string","example":"Ubuntu libexpat1 2.1.0-4ubuntu1.2","description":"The description of the matched fingerprint."},"family":{"type":"string","example":"","description":"The family of the matched fingerprint."},"product":{"type":"string","example":"libexpat1","description":"The product of the matched fingerprint."},"vendor":{"type":"string","example":"Ubuntu","description":"The description of the matched fingerprint."},"version":{"type":"string","example":"2.1.0-4ubuntu1.2","description":"The version of the matched fingerprint."}},"description":""},"GlobalScan":{"type":"object","properties":{"assets":{"type":"integer","format":"int32","example":"","description":"The number of assets found in the scan."},"duration":{"type":"string","example":"","description":"The duration of the scan in ISO8601 format."},"endTime":{"type":"string","example":"","description":"The end time of the scan in ISO8601 format."},"engineId":{"type":"integer","format":"int32","example":"","description":"The identifier of the scan engine."},"engineIds":{"type":"array","description":"${scan.engine.ids}","items":{"$ref":"#/definitions/EngineID"}},"engineName":{"type":"string","example":"","description":"The name of the scan engine."},"id":{"type":"integer","format":"int64","example":"","description":"The identifier of the scan."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"message":{"type":"string","example":"","description":"The reason for the scan status."},"scanName":{"type":"string","example":"","description":"The user-driven scan name for the scan."},"scanType":{"type":"string","example":"","description":"The scan type (automated, manual, scheduled). "},"siteId":{"type":"integer","format":"int32"},"siteName":{"type":"string"},"startTime":{"type":"string","example":"","description":"The start time of the scan in ISO8601 format."},"startedBy":{"type":"string","example":"","description":"The name of the user that started the scan."},"startedByUsername":{"type":"string","example":"","description":"${scan.username}"},"status":{"type":"string","example":"","description":"The scan status.","enum":["aborted","unknown","running","finished","stopped","error","paused","dispatched","integrating"]},"vulnerabilities":{"example":"","description":"The vulnerability synopsis of the scan.","$ref":"#/definitions/Vulnerabilities"}},"description":""},"GroupAccount":{"type":"object","required":["name"],"properties":{"id":{"type":"integer","format":"int32","example":972,"description":"The identifier of the user group."},"name":{"type":"string","example":"Administrators","description":"The name of the user group."}},"description":""},"HostName":{"type":"object","required":["name"],"properties":{"name":{"type":"string","example":"corporate-workstation-1102DC.acme.com","description":"The host name (local or FQDN)."},"source":{"type":"string","example":"DNS","description":"The source used to detect the host name. `user` indicates the host name source is user-supplied (e.g. in a site target definition).","enum":["user","dns","netbios","dce","epsec","ldap","other"]}},"description":""},"IMetaData":{"type":"object","properties":{"fieldName":{"type":"string"},"supportedOperators":{"type":"array","items":{"type":"string","enum":["IS","IS_NOT","IS_APPLIED","IS_NOT_APPLIED","IN","NOT_IN","STARTS_WITH","ENDS_WITH","CONTAINS","NOT_CONTAINS","LESS_THAN","GREATER_THAN","IN_RANGE","NOT_IN_RANGE","INCLUDE","DO_NOT_INCLUDE","ON_OR_BEFORE","ON_OR_AFTER","BETWEEN","EARLIER_THAN","WITHIN_THE_LAST","IS_EMPTY","IS_NOT_EMPTY","ARE","LIKE","NOT_LIKE"]}},"type":{"type":"string","enum":["NUMERIC","STRING","SET","SET_STRING","SINGLE","DATE"]}},"description":""},"IncludedAssetGroups":{"type":"object","properties":{"assetGroupIDs":{"type":"array","description":"List of asset group identifiers. Each element is an integer.","items":{"type":"integer","format":"int32"}},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}}},"description":""},"IncludedScanTargets":{"type":"object","properties":{"addresses":{"type":"array","description":"List of addresses. Each address is a string that can represent either a hostname, ipv4 address, ipv4 address range, ipv6 address, or CIDR notation.","items":{"type":"string"}},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}}},"description":""},"Info":{"type":"object","properties":{"cpu":{"example":"","description":"Details regarding the host CPU.","$ref":"#/definitions/CPUInfo"},"disk":{"example":"","description":"Details regarding host disk usage.","$ref":"#/definitions/DiskInfo"},"distinguishedName":{"type":"string","example":"CN=Rapid7 Security Console/ O=Rapid7","description":"The distinguished name of the console."},"fqdn":{"type":"string","example":"server.acme.com","description":"The fully-qualified domain name of the local host the service is running on."},"host":{"type":"string","example":"SERVER","description":"The name of the local host the service is running on."},"ip":{"type":"string","example":"192.168.1.99","description":"The IP address of the local host the service is running on."},"jvm":{"example":"","description":"Details regarding the Java Virtual Machine.","$ref":"#/definitions/JVMInfo"},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"memory":{"example":"","description":"Details regarding host memory usage.","$ref":"#/definitions/MemoryInfo"},"operatingSystem":{"type":"string","example":"Ubuntu Linux 16.04","description":"The operating system of the host the service is running on."},"serial":{"type":"string","example":"729F31B1C92F3C91DFA8A649F4D5C883C269BD45","description":"The serial number of the console."},"superuser":{"type":"boolean","example":true,"description":"Whether the service is running a super-user."},"user":{"type":"string","example":"root","description":"The user running the service."},"version":{"example":"","description":"Details regarding the version of the installation.","$ref":"#/definitions/VersionInfo"}},"description":""},"InstallSize":{"type":"object","properties":{"backups":{"example":"","description":"The disk space used by backups.","$ref":"#/definitions/BackupsSize"},"database":{"example":"","description":"The disk space used by the database.","$ref":"#/definitions/DatabaseSize"},"directory":{"type":"string","example":"","description":"The installation directory."},"reports":{"example":"","description":"The disk space used by reports.","$ref":"#/definitions/ReportSize"},"scans":{"example":"","description":"The disk space used by scans.","$ref":"#/definitions/ScanSize"},"total":{"example":"","description":"Total disk space used by the installation.","$ref":"#/definitions/InstallationTotalSize"}},"description":""},"InstallationTotalSize":{"type":"object","properties":{"bytes":{"type":"integer","format":"int64","example":12125933077,"description":"The raw value in bytes."},"formatted":{"type":"string","example":"11.3 GB","description":"The value formatted in human-readable notation (e.g. GB, MB, KB, bytes)."}},"description":""},"InternalServerError":{"type":"object","required":["status"],"properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"message":{"type":"string","example":"An error has occurred.","description":"The messages indicating the cause or reason for failure."},"status":{"type":"string","example":"500","description":"The HTTP status code for the error (same as in the HTTP response).","enum":["500"]}},"description":""},"JVMInfo":{"type":"object","properties":{"name":{"type":"string","example":"OpenJDK 64-Bit Server VM","description":"The name of the Java Virtual Machine."},"startTime":{"type":"string","example":"2018-02-13T20:35:35.076Z","description":"The date and time the Java Virtual Machine last started."},"uptime":{"type":"string","example":"PT8H21M7.978S","description":"Total up-time of the Java Virtual Machine, in ISO 8601 format. For example: `\"PT1H4M24.214S\"`."},"vendor":{"type":"string","example":"Azul Systems, Inc.","description":"The vendor of the Java Virtual Machine."},"version":{"type":"string","example":"25.102-b14","description":"The version of the Java Virtual Machine."}},"description":""},"JsonNode":{"type":"object","properties":{"array":{"type":"boolean"},"bigDecimal":{"type":"boolean"},"bigInteger":{"type":"boolean"},"binary":{"type":"boolean"},"boolean":{"type":"boolean"},"containerNode":{"type":"boolean"},"double":{"type":"boolean"},"float":{"type":"boolean"},"floatingPointNumber":{"type":"boolean"},"int":{"type":"boolean"},"integralNumber":{"type":"boolean"},"long":{"type":"boolean"},"missingNode":{"type":"boolean"},"nodeType":{"type":"string","enum":["ARRAY","BINARY","BOOLEAN","MISSING","NULL","NUMBER","OBJECT","POJO","STRING"]},"null":{"type":"boolean"},"number":{"type":"boolean"},"object":{"type":"boolean"},"pojo":{"type":"boolean"},"short":{"type":"boolean"},"textual":{"type":"boolean"},"valueNode":{"type":"boolean"}},"description":""},"License":{"type":"object","properties":{"edition":{"type":"string","example":"InsightVM","description":"The edition of the product."},"evaluation":{"type":"boolean","example":false,"description":"Whether the license is a time-restricted evaluation."},"expires":{"type":"string","example":"2018-12-31T23:59:59.999Z","description":"The date and time the license expires."},"features":{"example":"","description":"The features available in the license.","$ref":"#/definitions/Features"},"limits":{"example":"","description":"The limits of the license.","$ref":"#/definitions/LicenseLimits"},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"perpetual":{"type":"boolean","example":false,"description":"Whether the license is perpetual."},"status":{"type":"string","example":"Activated","description":"The status of the license.","enum":["Activated","Unlicensed","Expired","Evaluation Mode","Revoked","Unknown"]}},"description":""},"LicenseLimits":{"type":"object","properties":{"assets":{"type":"integer","format":"int32","example":100000,"description":"The maximum number of assets that can be assessed."},"assetsWithHostedEngine":{"type":"integer","format":"int32","example":1000,"description":"The maximum number of assets that may be scanned with the hosted scan engine."},"scanEngines":{"type":"integer","format":"int32","example":100,"description":"The maximum number of scan engines that may be used."},"users":{"type":"integer","format":"int32","example":1000,"description":"The maximum number of users allowed."}},"description":""},"LicensePolicyScanning":{"type":"object","properties":{"benchmarks":{"example":"","description":"The benchmarks available to policy scan.","$ref":"#/definitions/LicensePolicyScanningBenchmarks"},"scanning":{"type":"boolean","example":true,"description":"Whether policy scanning is allowed."}},"description":""},"LicensePolicyScanningBenchmarks":{"type":"object","properties":{"cis":{"type":"boolean","example":true,"description":"Whether policy scanning for CIS benchmarks is allowed."},"custom":{"type":"boolean","example":true,"description":"Whether custom benchmarks can be used during scanning."},"disa":{"type":"boolean","example":true,"description":"Whether policy scanning for DISA benchmarks is allowed."},"fdcc":{"type":"boolean","example":true,"description":"Whether policy scanning for FDCC benchmarks is allowed."},"usgcb":{"type":"boolean","example":true,"description":"Whether policy scanning for USGCB benchmarks is allowed."}},"description":""},"LicenseReporting":{"type":"object","properties":{"advanced":{"type":"boolean","example":true,"description":"Whether advanced reporting is available."},"customizableCSVExport":{"type":"boolean","example":true,"description":"Whether customizable CSV Export is available."},"pci":{"type":"boolean","example":true,"description":"Whether PCI reporting is available."}},"description":""},"LicenseScanning":{"type":"object","properties":{"discovery":{"type":"boolean","example":true,"description":"Whether discovery scanning may be used."},"policy":{"example":"true","description":"Details as to whether policy scanning and what benchmarks are available.","$ref":"#/definitions/LicensePolicyScanning"},"scada":{"type":"boolean","example":true,"description":"Whether SCADA scanning may be used."},"virtual":{"type":"boolean","example":true,"description":"Whether virtual scanning may be used."},"webApplication":{"type":"boolean","example":true,"description":"Whether web scanning may be used."}},"description":""},"Link":{"type":"object","properties":{"href":{"type":"string","example":"https://hostname:3780/api/3/...","description":"A hypertext reference, which is either a URI (see RFC 3986) or URI template (see RFC 6570). "},"rel":{"type":"string","example":"self","description":"The link relation type. This value is one from the Link Relation Type Registry or is the type of resource being linked to."}},"description":""},"Links":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}}},"description":""},"LocalePreferences":{"type":"object","properties":{"default":{"type":"string","example":"","description":"The default language to use. The format is a IETF BCP 47 language tag."},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"reports":{"type":"string","example":"","description":"The language to use to generate reports. The format is a IETF BCP 47 language tag."}},"description":""},"MalwareKit":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":152,"description":"The identifier of the malware kit."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"Alpha Pack","description":"The name of the malware kit."},"popularity":{"type":"string","example":"Rare","description":"The name of the malware kit. One of: `\"Rare\"`, `\"Uncommon\"`, `\"Occasional\"`, `\"Common\"`, `\"Popular\"`, `\"Favored\"`, `\"Unknown\"`"}},"description":""},"MatchedSolution":{"type":"object","properties":{"additionalInformation":{"example":"","description":"Additional information or resources that can assist in applying the remediation.","$ref":"#/definitions/AdditionalInformation"},"appliesTo":{"type":"string","example":"libexpat1 on Ubuntu Linux","description":"The systems or software the solution applies to."},"confidence":{"type":"string","example":"","description":"The confidence of the matching process for the solution.","enum":["exact","partial","none"]},"estimate":{"type":"string","example":"PT10M","description":"The estimated duration to apply the solution, in ISO 8601 format. For example: `\"PT5M\"`."},"id":{"type":"string","example":"ubuntu-upgrade-libexpat1","description":"The identifier of the solution."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"matches":{"type":"array","description":"The raw matches that were performed in order to select the best solution(s).","items":{"$ref":"#/definitions/SolutionMatch"}},"steps":{"example":"","description":"The steps required to remediate the vulnerability.","$ref":"#/definitions/Steps"},"summary":{"example":"","description":"The summary of the solution.","$ref":"#/definitions/Summary"},"type":{"type":"string","example":"configuration","description":"The type of the solution. One of: `\"Configuration\"`, `\"Rollup patch\"`, `\"Patch\"`","enum":["configuration","rollup-patch","patch","unknown"]}},"description":""},"MemoryFree":{"type":"object","properties":{"bytes":{"type":"integer","format":"int64","example":45006848,"description":"The raw value in bytes."},"formatted":{"type":"string","example":"42.9 MB","description":"The value formatted in human-readable notation (e.g. GB, MB, KB, bytes)."}},"description":""},"MemoryInfo":{"type":"object","properties":{"free":{"example":"","description":"Free memory.","$ref":"#/definitions/MemoryFree"},"total":{"example":"","description":"Total memory usage.","$ref":"#/definitions/MemoryTotal"}},"description":""},"MemoryTotal":{"type":"object","properties":{"bytes":{"type":"integer","format":"int64","example":17179869184,"description":"The raw value in bytes."},"formatted":{"type":"string","example":"16 GB","description":"The value formatted in human-readable notation (e.g. GB, MB, KB, bytes)."}},"description":""},"NotFoundError":{"type":"object","required":["status"],"properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"message":{"type":"string","example":"An error has occurred.","description":"The messages indicating the cause or reason for failure."},"status":{"type":"string","example":"404","description":"The HTTP status code for the error (same as in the HTTP response).","enum":["404"]}},"description":""},"OperatingSystem":{"type":"object","properties":{"architecture":{"type":"string","example":"x86","description":"The architecture of the operating system."},"configurations":{"type":"array","description":"Configuration key-values pairs enumerated on the operating system.","items":{"$ref":"#/definitions/Configuration"}},"cpe":{"example":"","description":"The Common Platform Enumeration (CPE) of the operating system.","$ref":"#/definitions/OperatingSystemCpe"},"description":{"type":"string","example":"Microsoft Windows Server 2008 Enterprise Edition SP1","description":"The description of the operating system (containing vendor, family, product, version and architecture in a single string)."},"family":{"type":"string","example":"Windows","description":"The family of the operating system."},"id":{"type":"integer","format":"int64","example":35,"description":"The identifier of the operating system."},"product":{"type":"string","example":"Windows Server 2008 Enterprise Edition","description":"The name of the operating system."},"systemName":{"type":"string","example":"Microsoft Windows","description":"A combination of vendor and family (with redundancies removed), suitable for grouping."},"type":{"type":"string","example":"Workstation","description":"The type of operating system."},"vendor":{"type":"string","example":"Microsoft","description":"The vendor of the operating system."},"version":{"type":"string","example":"SP1","description":"The version of the operating system."}},"description":""},"OperatingSystemCpe":{"type":"object","required":["part"],"properties":{"edition":{"type":"string","example":"enterprise","description":"Edition-related terms applied by the vendor to the product. "},"language":{"type":"string","example":"","description":"Defines the language supported in the user interface of the product being described. The format is of the language tag adheres to RFC5646."},"other":{"type":"string","example":"","description":"Captures any other general descriptive or identifying information which is vendor- or product-specific and which does not logically fit in any other attribute value. "},"part":{"type":"string","example":"o","description":"A single letter code that designates the particular platform part that is being identified.","enum":["o","a","h"]},"product":{"type":"string","example":"windows_server_2008","description":"the most common and recognizable title or name of the product."},"swEdition":{"type":"string","example":"","description":"Characterizes how the product is tailored to a particular market or class of end users. "},"targetHW":{"type":"string","example":"","description":"Characterize the instruction set architecture on which the product operates. "},"targetSW":{"type":"string","example":"","description":"Characterize the software computing environment within which the product operates."},"update":{"type":"string","example":"sp1","description":"Vendor-specific alphanumeric strings characterizing the particular update, service pack, or point release of the product."},"v2.2":{"type":"string","example":"cpe:/o:microsoft:windows_server_2008:-:sp1:enterprise","description":"The full CPE string in the CPE 2.2 format."},"v2.3":{"type":"string","example":"cpe:2.3:o:microsoft:windows_server_2008:-:sp1:enterprise:*:*:*:*:*","description":"The full CPE string in the CPE 2.3 format."},"vendor":{"type":"string","example":"microsoft","description":"The person or organization that manufactured or created the product."},"version":{"type":"string","example":"-","description":"Vendor-specific alphanumeric strings characterizing the particular release version of the product."}},"description":""},"PCI":{"type":"object","properties":{"adjustedCVSSScore":{"type":"integer","format":"int32","example":4,"description":"The CVSS score of the vulnerability, adjusted for PCI rules and exceptions, on a scale of 0-10."},"adjustedSeverityScore":{"type":"integer","format":"int32","example":3,"description":"The severity score of the vulnerability, adjusted for PCI rules and exceptions, on a scale of 0-10."},"fail":{"type":"boolean","example":true,"description":"Whether if present on a host this vulnerability would cause a PCI failure. `true` if \"status\" is `\"Fail\"`, `false` otherwise."},"specialNotes":{"type":"string","example":"","description":"Any special notes or remarks about the vulnerability that pertain to PCI compliance."},"status":{"type":"string","example":"Fail","description":"The PCI compliance status of the vulnerability. One of: `\"Pass\"`, `\"Fail\"`."}},"description":""},"PageInfo":{"type":"object","properties":{"number":{"type":"integer","format":"int64","example":6,"description":"The index (zero-based) of the current page returned."},"size":{"type":"integer","format":"int64","example":10,"description":"The maximum size of the page returned."},"totalPages":{"type":"integer","format":"int64","example":13,"description":"The total number of pages available."},"totalResources":{"type":"integer","format":"int64","example":123,"description":"The total number of resources available across all pages."}},"description":""},"PageOf«Agent»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Agent"}}},"description":""},"PageOf«AssetGroup»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/AssetGroup"}}},"description":""},"PageOf«AssetPolicyItem»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/AssetPolicyItem"}}},"description":""},"PageOf«AssetPolicy»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/AssetPolicy"}}},"description":""},"PageOf«Asset»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Asset"}}},"description":""},"PageOf«DiscoveryConnection»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/DiscoveryConnection"}}},"description":""},"PageOf«Exploit»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Exploit"}}},"description":""},"PageOf«GlobalScan»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/GlobalScan"}}},"description":""},"PageOf«MalwareKit»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/MalwareKit"}}},"description":""},"PageOf«OperatingSystem»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/OperatingSystem"}}},"description":""},"PageOf«PolicyAsset»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/PolicyAsset"}}},"description":""},"PageOf«PolicyControl»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/PolicyControl"}}},"description":""},"PageOf«PolicyGroup»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/PolicyGroup"}}},"description":""},"PageOf«PolicyItem»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/PolicyItem"}}},"description":""},"PageOf«PolicyOverride»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/PolicyOverride"}}},"description":""},"PageOf«PolicyRule»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/PolicyRule"}}},"description":""},"PageOf«Policy»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Policy"}}},"description":""},"PageOf«Report»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Report"}}},"description":""},"PageOf«Scan»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Scan"}}},"description":""},"PageOf«Site»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Site"}}},"description":""},"PageOf«Software»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Software"}}},"description":""},"PageOf«Tag»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Tag"}}},"description":""},"PageOf«User»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/User"}}},"description":""},"PageOf«VulnerabilityCategory»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/VulnerabilityCategory"}}},"description":""},"PageOf«VulnerabilityCheck»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/VulnerabilityCheck"}}},"description":""},"PageOf«VulnerabilityException»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/VulnerabilityException"}}},"description":""},"PageOf«VulnerabilityFinding»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/VulnerabilityFinding"}}},"description":""},"PageOf«VulnerabilityReference»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/VulnerabilityReference"}}},"description":""},"PageOf«Vulnerability»":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"page":{"example":"","description":"The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.","$ref":"#/definitions/PageInfo"},"resources":{"type":"array","description":"The page of resources returned.","items":{"$ref":"#/definitions/Vulnerability"}}},"description":""},"PasswordResource":{"type":"object","properties":{"password":{"type":"string"}},"description":""},"Policy":{"type":"object","properties":{"enabled":{"type":"array","description":"The identifiers of the policies enabled to be checked during a scan. No policies are enabled by default.","items":{"type":"integer","format":"int64"}},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"recursiveWindowsFSSearch":{"type":"boolean","example":false,"description":"Whether recursive windows file searches are enabled, if your internal security practices require this capability. Recursive file searches can increase scan times by several hours, depending on the number of files and other factors, so this setting is disabled for Windows systems by default. Defaults to `false`."},"storeSCAP":{"type":"boolean","example":false,"description":"Whether Asset Reporting Format (ARF) results are stored. If you are required to submit reports of your policy scan results to the U.S. government in ARF for SCAP certification, you will need to store SCAP data so that it can be exported in this format. Note that stored SCAP data can accumulate rapidly, which can have a significant impact on file storage. Defaults to `false`."}},"description":""},"PolicyAsset":{"type":"object","properties":{"hostname":{"type":"string","example":"","description":"The primary host name (local or FQDN) of the asset."},"id":{"type":"integer","format":"int64","example":"","description":"The identifier of the asset."},"ip":{"type":"string","example":"","description":"The primary IPv4 or IPv6 address of the asset."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"os":{"example":"","description":"The full description of the operating system of the asset.","$ref":"#/definitions/OperatingSystem"},"status":{"type":"string","example":"","description":"The overall compliance status of the asset. ","enum":["passed","failed","notApplicable"]}},"description":""},"PolicyBenchmark":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The name of the policy's benchmark."},"title":{"type":"string","example":"","description":"The title of the policy benchmark."},"version":{"type":"string","example":"","description":"The version number of the benchmark that includes the policy."}},"description":""},"PolicyControl":{"type":"object","properties":{"cceItemId":{"type":"string","example":"","description":"The identifier of the CCE item."},"ccePlatform":{"type":"string","example":"","description":"The platform of the CCE."},"controlName":{"type":"string","example":"","description":"The name of the control mapping."},"id":{"type":"string","example":"","description":"The textual representation of the control identifier."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"publishedDate":{"type":"integer","format":"int64","example":"","description":"The published date of the control mapping."}},"description":""},"PolicyGroup":{"type":"object","properties":{"assets":{"example":"","description":"A summary of asset compliance.","$ref":"#/definitions/AssetPolicyAssessment"},"benchmark":{"example":"","description":"Information about the policy benchmark.","$ref":"#/definitions/PolicyBenchmark"},"description":{"type":"string","example":"","description":"A description of the policy group."},"id":{"type":"string","example":"","description":"The textual representation of the policy group identifier."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The name of the policy group."},"policy":{"example":"","description":"Information about the policy.","$ref":"#/definitions/PolicyMetadataResource"},"scope":{"type":"string","example":"","description":"The textual representation of the policy group scope. Policy groups that are automatically available have `\"Built-in\"` scope, whereas policy groups created by users have scope as `\"Custom\"`."},"status":{"type":"string","example":"","description":"The overall compliance status of the policy group.","enum":["PASS","FAIL","NOT_APPLICABLE"]},"surrogateId":{"type":"integer","format":"int64","example":"","description":"The identifier of the policy group."},"title":{"type":"string","example":"","description":"The title of the policy group as visible to the user."}},"description":""},"PolicyItem":{"type":"object","properties":{"assets":{"example":"","description":"A summary of asset compliance.","$ref":"#/definitions/AssetPolicyAssessment"},"description":{"type":"string","example":"","description":"A description of the policy rule or group."},"hasOverride":{"type":"boolean","example":false,"description":"A flag indicating whether the policy rule has an active override applied to it. This field only applies to resources representing policy rules. "},"id":{"type":"integer","format":"int64","example":"","description":"The identifier of the policy rule or group."},"isUnscored":{"type":"boolean","example":false,"description":"A flag indicating whether the policy rule has a role of `\"unscored\"`. This field only applies to resources representing policy rules."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The name of the policy rule or group."},"policy":{"example":"","description":"Information about the policy.","$ref":"#/definitions/PolicyMetadataResource"},"rules":{"example":"","description":"A summary of rule compliance for multiple policy rules. This field only applies to resources representing policy groups.","$ref":"#/definitions/PolicyRuleAssessmentResource"},"scope":{"type":"string","example":"","description":"The textual representation of the policy rule/group scope. Policy rules or groups that are automatically available have `\"Built-in\"` scope, whereas policy rules or groups created by users have scope as `\"Custom\"`."},"status":{"type":"string","example":"","description":"The overall compliance status of the policy rule or group.","enum":["PASS","FAIL","NOT_APPLICABLE"]},"title":{"type":"string","example":"","description":"The title of the policy rule, or group, as visible to the user."},"type":{"type":"string","example":"","description":"Indicates whether the resource represents either a policy rule or group.","enum":["rule","group"]}},"description":""},"PolicyMetadataResource":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The name of the policy."},"title":{"type":"string","example":"","description":"The title of the policy as visible to the user."},"version":{"type":"string","example":"","description":"The version of the policy."}},"description":""},"PolicyOverride":{"type":"object","required":["scope","state","submit"],"properties":{"expires":{"type":"string","example":"","description":"The date the policy override is set to expire. Date is represented in ISO 8601 format."},"id":{"type":"integer","format":"int64","example":"","description":"The identifier of the policy override.","readOnly":true},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"review":{"example":"","description":"Details regarding the review and/or approval of the policy override.","readOnly":true,"$ref":"#/definitions/PolicyOverrideReviewer"},"scope":{"example":"","description":"The scope of the policy override. Indicates which assets' policy compliance results are to be affected by the override.","$ref":"#/definitions/PolicyOverrideScope"},"state":{"type":"string","example":"","description":"The state of the policy override. Can be one of the following values: \n| Value | Description | Affects Compliance Results | \n| ---------------- | ----------------------------------------------------------------------------------- |:--------------------------:| \n| `\"deleted\"` | The policy override has been deleted. | | \n| `\"expired\"` | The policy override had an expiration date and it has expired. | | \n| `\"approved\"` | The policy override was submitted and approved. | ✓ | \n| `\"rejected\"` | The policy override was rejected by the reviewer. | | \n| `\"under-review\"` | The policy override was submitted but not yet approved or rejected by the reviewer. | | \n"},"submit":{"example":"","description":"Details regarding the submission of the policy override.","$ref":"#/definitions/PolicyOverrideSubmitter"}},"description":""},"PolicyOverrideReviewer":{"type":"object","properties":{"comment":{"type":"string","example":"","description":"A comment from the reviewer detailing the review. Cannot exceed 1024 characters.","readOnly":true},"date":{"type":"string","example":"","description":"The date the review took place.","readOnly":true},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The identifier of the user that reviewed the policy override.","readOnly":true},"user":{"type":"integer","format":"int32","example":"","description":"The login name of the user that reviewed the policy override.","readOnly":true}},"description":""},"PolicyOverrideScope":{"type":"object","required":["newResult","rule","type"],"properties":{"asset":{"type":"integer","format":"int64","example":"","description":"The identifier of the asset whose compliance results are to be overridden. Property is required if the property `scope` is set to either `\"specific-asset\"` or `\"specific-asset-until-next-scan\"`."},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"newResult":{"type":"string","example":"","description":"The new policy rule result after the override is applied.","enum":["pass","fail","not-applicable","fixed"]},"originalResult":{"type":"string","example":"","description":"The original policy rule result before the override was applied. This property only applies to overrides with a scope of either `\"specific-asset\"` or `\"specific-asset-until-next-scan\"`.","readOnly":true,"enum":["pass","fail","error","unknown","not-applicable","not-checked","not-selected","informational","fixed"]},"rule":{"type":"integer","format":"int64","example":"","description":"The identifier of the policy rule whose compliance results are to be overridden."},"type":{"type":"string","example":"","description":"The scope of assets affected by the policy override. Can be one of the following values: \n| Value | Description | \n| ---------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | \n| `\"all-assets\"` | Overrides the compliance result of all assets evaluated with the specified policy rule. | \n| `\"specific-asset\"` | Overrides the compliance result of a single asset evaluated with the specified policy rule. | \n| `\"specific-asset-until-next-scan\"` | Overrides the compliance result of a single asset evaluated with the specified policy rule until the next time asset is evaluated against that policy rule. | \n"}},"description":""},"PolicyOverrideSubmitter":{"type":"object","required":["comment"],"properties":{"comment":{"type":"string","example":"","description":"A comment from the submitter as to why the policy override was submitted. Cannot exceed 1024 characters."},"date":{"type":"string","example":"","description":"The date the policy override was submitted.","readOnly":true},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The login name of the user that submitted the policy override.","readOnly":true},"user":{"type":"integer","format":"int32","example":"","description":"The identifier of the user that submitted the policy override.","readOnly":true}},"description":""},"PolicyRule":{"type":"object","properties":{"assets":{"example":"","description":"A summary of asset compliance.","$ref":"#/definitions/AssetPolicyAssessment"},"benchmark":{"example":"","description":"Information about the policy benchmark.","$ref":"#/definitions/PolicyBenchmark"},"description":{"type":"string","example":"","description":"A description of the rule."},"id":{"type":"string","example":"","description":"The textual representation of the policy rule identifier."},"isCustom":{"type":"boolean","example":false,"description":"A flag indicating whether the policy rule is custom."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The name of the rule."},"role":{"type":"string","example":"","description":"The role of the policy rule. It's value determines how it's results affect compliance.","enum":["full","unscored","unchecked"]},"scope":{"type":"string","example":"","description":"The textual representation of the policy rule scope. Policy rules that are automatically available have `\"Built-in\"` scope, whereas policy rules created by users have scope as `\"Custom\"`."},"status":{"type":"string","example":"","description":"The overall compliance status of the policy rule.","enum":["PASS","FAIL","NOT_APPLICABLE"]},"surrogateId":{"type":"integer","format":"int64","example":"","description":"The identifier of the policy rule."},"title":{"type":"string","example":"","description":"The title of the policy rule as visible to the user."}},"description":""},"PolicyRuleAssessmentResource":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"total":{"type":"integer","format":"int32","example":"","description":"The total number of policy rules."},"totalFailed":{"type":"integer","format":"int32","example":"","description":"The total number of policy rules that are not compliant against all assets."},"totalNotApplicable":{"type":"integer","format":"int32","example":"","description":"The total number of policy rules that are not applicable against all assets."},"totalPassed":{"type":"integer","format":"int32","example":"","description":"The total number of policy rules that are compliant against all assets."},"unscored":{"type":"integer","format":"int32","example":"","description":"The total number of policy rules that have a role of `\"unscored\"`."}},"description":""},"PolicySummaryResource":{"type":"object","properties":{"decreasedCompliance":{"type":"integer","format":"int32","example":"","description":"The total number of policies whose overall compliance has decreased between the last two scans of all assets. The list of scanned policies is based on the user's list of accessible assets."},"increasedCompliance":{"type":"integer","format":"int32","example":"","description":"The total number of policies whose overall compliance has increased between the last two scans of all assets. The list of scanned policies is based on the user's list of accessible assets."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"numberOfPolicies":{"type":"integer","format":"int32","example":"","description":"The total number of policies available in the Security Console."},"overallCompliance":{"type":"number","format":"float","example":"","description":"The ratio of compliant rules to the total number of rules across all policies."},"scannedPolicies":{"type":"integer","format":"int32","example":"","description":"The total number of policies that were evaluated against assets and have applicable results. The assets considered in the calculation are based on the user's list of accessible assets."}},"description":""},"Privileges":{"type":"object","properties":{"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"resources":{"type":"array","items":{"type":"string","enum":["all-permissions","create-reports","configure-global-settings","manage-sites","manage-tags","manage-static-asset-groups","manage-dynamic-asset-groups","manage-scan-templates","manage-report-templates","manage-scan-engines","submit-vulnerability-exceptions","approve-vulnerability-exceptions","delete-vulnerability-exceptions","manage-vuln-investigations","view-vuln-investigations","create-tickets","close-tickets","assign-ticket-assignee","manage-site-access","manage-asset-group-access","manage-report-access","use-restricted-report-sections","manage-policies","manage-advpolicies","view-asset-group-asset-data","manage-asset-group-assets","view-site-asset-data","specify-site-metadata","purge-site-asset-data","specify-scan-targets","assign-scan-engine","assign-scan-template","manage-site-credentials","manage-scan-alerts","schedule-automatic-scans","start-unscheduled-scans"]}}},"description":""},"RangeResource":{"type":"object","properties":{"every":{"type":"string","example":"day","description":"If `from` is a custom date the interval amount between reporting periods.","enum":["day","month","year"]},"from":{"type":"string","example":"","description":"The start date of the trend, which can either be a duration or a specific date and time.","enum":["P1Y","P6M","P3M","P1M","\"vulnerable-and-validated\"
is selected \nno other values can be specified.\nThe following is a specification of supported credential properties for each type of service. These properties are to be specified within the account
object.
The address of the domain.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The address of the domain.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The address of the domain.
The user name for the account that will be used for authenticating.
The NTLM password hash. Note: This property is not returned in responses for security.
The address of the domain.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The realm.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
\nBoolean flag signaling whether to connect to the database using Windows authentication. When set to true
, Windows authentication is attempted; when set to false
, SQL authentication is attempted.
The address of the domain. This property cannot be specified unless property useWindowsAuthentication
is set to true
.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
The user name for the account that will be used for authenticating.
The Notes ID password. Note: This property is not returned in responses for security.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
\nBoolean flag instructing the scan engine to attempt to enumerate SIDs from your environment. If set to true
, set the Oracle Net Listener password in property oracleListenerPassword
.
The Oracle Net Listener password. Used to enumerate SIDs from your environment.
The service name of the database. If not specified, a default database name will be used during authentication.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The community name that will be used for authenticating. Note: This property is not returned in responses for security.
The authentication protocols available to use in SNMP v3.
The user name for the account that will be used for authenticating.
\nThe password for the account that will be used for authenticating. Is required when the property authenticationType
is set to valid value other than \"no-authentication\"
. Note: This property is not returned in responses for security.
The privacy protocols available to use in SNMP v3.
\nThe privacy password for the account that will be used for authenticating. Is required when the property authenticationType
is set to valid value other than \"no-authentication\"
and when the privacyType
is set to a valid value other than code>\"no-privacy\". Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
\nElevate scan engine permissions to administrative or root access, which is necessary to obtain certain data during the scan. Defaults to \"none\"
if not specified.
\nThe user name for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.
\nThe password for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for private key. Note: This property is not returned in responses for security.
The PEM-format private key. Note: This property is not returned in responses for security.
\nElevate scan engine permissions to administrative or root access, which is necessary to obtain certain data during the scan. Defaults to \"none\"
if not specified.
\nThe user name for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.
\nThe password for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
\nBoolean flag signaling whether to connect to the database using Windows authentication. When set to true
, Windows authentication is attempted; when set to false
, SQL authentication is attempted.
The address of the domain. This property cannot be specified unless property useWindowsAuthentication
is set to true
.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The following is a specification of supported credential properties for each type of service. These properties are to be specified within the account
object.
The address of the domain.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The address of the domain.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The address of the domain.
The user name for the account that will be used for authenticating.
The NTLM password hash. Note: This property is not returned in responses for security.
The address of the domain.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The realm.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
\nBoolean flag signaling whether to connect to the database using Windows authentication. When set to true
, Windows authentication is attempted; when set to false
, SQL authentication is attempted.
The address of the domain. This property cannot be specified unless property useWindowsAuthentication
is set to true
.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
The user name for the account that will be used for authenticating.
The Notes ID password. Note: This property is not returned in responses for security.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
\nBoolean flag instructing the scan engine to attempt to enumerate SIDs from your environment. If set to true
, set the Oracle Net Listener password in property oracleListenerPassword
.
The Oracle Net Listener password. Used to enumerate SIDs from your environment.
The service name of the database. If not specified, a default database name will be used during authentication.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The name of the database.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The community name that will be used for authenticating. Note: This property is not returned in responses for security.
The authentication protocols available to use in SNMP v3.
The user name for the account that will be used for authenticating.
\nThe password for the account that will be used for authenticating. Is required when the property authenticationType
is set to valid value other than \"no-authentication\"
. Note: This property is not returned in responses for security.
The privacy protocols available to use in SNMP v3.
\nThe privacy password for the account that will be used for authenticating. Is required when the property authenticationType
is set to valid value other than \"no-authentication\"
and when the privacyType
is set to a valid value other than code>\"no-privacy\". Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
\nElevate scan engine permissions to administrative or root access, which is necessary to obtain certain data during the scan. Defaults to \"none\"
if not specified.
\nThe user name for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.
\nThe password for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for private key. Note: This property is not returned in responses for security.
The PEM-format private key. Note: This property is not returned in responses for security.
\nElevate scan engine permissions to administrative or root access, which is necessary to obtain certain data during the scan. Defaults to \"none\"
if not specified.
\nThe user name for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.
\nThe password for the account with elevated permissions. This property must not be specified when the property permissionElevation
is set to either \"none\"
or \"pbrun\"
; otherwise the property is required.Note: This property is not returned in responses for security.
The name of the database. If not specified, a default database name will be used during authentication.
\nBoolean flag signaling whether to connect to the database using Windows authentication. When set to true
, Windows authentication is attempted; when set to false
, SQL authentication is attempted.
The address of the domain. This property cannot be specified unless property useWindowsAuthentication
is set to true
.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
The user name for the account that will be used for authenticating.
The password for the account that will be used for authenticating. Note: This property is not returned in responses for security.
\n Use `apt-get upgrade` to upgrade libexpat1 to the latest version.\n
","description":"Textual representation of the content."},"text":{"type":"string","example":"Use `apt-get upgrade` to upgrade libexpat1 to the latest version.","description":"Textual representation of the content."}},"description":""},"Submission":{"type":"object","properties":{"comment":{"type":"string","example":"","description":"A comment from the submitter as to why the exception was submitted."},"date":{"type":"string","example":"","description":"The date and time the vulnerability exception was submitted.","readOnly":true},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"","description":"The login name of the user that submitted the vulnerability exception.","readOnly":true},"reason":{"type":"string","example":"","description":"The reason the vulnerability exception was submitted. One of: `\"False Positive\"`, `\"Compensating Control\"`, `\"Acceptable Use\"`, `\"Acceptable Risk\"`, `\"Other\"`"},"user":{"type":"integer","format":"int32","example":"","description":"The identifier of the user that submitted the vulnerability exception.","readOnly":true}},"description":""},"Summary":{"type":"object","properties":{"html":{"type":"string","example":"Upgrade libexpat1","description":"Textual representation of the content."},"text":{"type":"string","example":"Upgrade libexpat1","description":"Textual representation of the content."}},"description":""},"SwaggerDiscoverySearchCriteriaFilter":{"type":"object","properties":{"field":{"type":"string","example":"","description":"The filter field for the search criteria."},"lower":{"type":"object","example":"","description":"The lower value to match in a range criteria."},"operator":{"type":"string","example":"","description":"The operator on how to match the search criteria."},"upper":{"type":"object","example":"","description":"The upper value to match in a range criteria."},"value":{"type":"object","example":"","description":"The single value to match using the operator."},"values":{"type":"array","description":"An array of values to match using the operator.","items":{"type":"object"}}},"description":""},"SwaggerSearchCriteriaFilter":{"type":"object","properties":{"field":{"type":"string","example":"","description":"The filter field for the search criteria."},"lower":{"type":"object","example":"","description":"The lower value to match in a range criteria."},"operator":{"type":"string","example":"","description":"The operator on how to match the search criteria."},"upper":{"type":"object","example":"","description":"The upper value to match in a range criteria."},"value":{"type":"object","example":"","description":"The single value to match using the operator."},"values":{"type":"array","description":"An array of values to match using the operator.","items":{"type":"object"}}},"description":""},"SyslogAlert":{"type":"object","required":["enabled","name","notification","server"],"properties":{"enabled":{"type":"boolean","example":false,"description":"Flag indicating the alert is enabled."},"enabledScanEvents":{"example":"","description":"Allows the user to specify which scan events generate an alert. Default values will be chosen if property is not specified as apart of the request. The default values are documented in the properties of `enabledScanEvents`.","$ref":"#/definitions/ScanEvents"},"enabledVulnerabilityEvents":{"example":"","description":"Allows the user to specify which vulnerability result events generate an alert. Default values will be chosen if property is not specified as apart of the request. The default values are documented in the properties of `enabledVulnerabilityEvents`.","$ref":"#/definitions/VulnerabilityEvents"},"id":{"type":"integer","format":"int32","example":"","description":"The identifier of the alert."},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"maximumAlerts":{"type":"integer","format":"int32","example":"","description":"The maximum number of alerts that will be issued. To disable maximum alerts, omit the property in the request or specify the property with a value of `null`.","minimum":1},"name":{"type":"string","example":"","description":"The name of the alert."},"notification":{"type":"string","example":"","description":"The type of alert.","enum":["SMTP","SNMP","Syslog"]},"server":{"type":"string","example":"","description":"The Syslog server to send messages to."}},"description":""},"Tag":{"type":"object","required":["name","type"],"properties":{"color":{"type":"string","example":"default","description":"The color to use when rendering the tag in a user interface."},"created":{"type":"string","example":"2017-10-07T23:50:01.205Z","description":"The date and time the tag was created."},"id":{"type":"integer","format":"int32","example":6,"description":"The identifier of the tag.","readOnly":true},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"My Custom Tag","description":"The name (label) of the tab."},"riskModifier":{"type":"number","format":"double","example":2.0,"description":"The amount to adjust risk of an asset tagged with this tag. "},"searchCriteria":{"$ref":"#/definitions/SearchCriteria"},"source":{"type":"string","example":"custom","description":"The source of the tag.","readOnly":true,"enum":["built-in","custom"]},"type":{"type":"string","example":"custom","description":"The type of the tag."}},"description":""},"TagAssetSource":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":92,"description":"If the `source` is `\"asset-group\"` or `\"site\"` the identifier of the asset group or site that causes the tag to apply to the asset."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"source":{"type":"string","example":"site","description":"The source by which a tag applies to an asset.","enum":["site","asset-group","criteria","tag","unknown"]}},"description":""},"TagLink":{"type":"object","properties":{"id":{"type":"integer","format":"int64","example":78,"description":"The identifier of the tagged asset."},"sources":{"type":"array","description":"The source(s) by which a tag is-applied to an asset.","items":{"type":"string","enum":["site","asset-group","criteria","tag","unknown"]}}},"description":""},"TaggedAssetReferences":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"resources":{"type":"array","description":"The identifiers of the associated resources.","items":{"$ref":"#/definitions/TagLink"}}},"description":""},"Telnet":{"type":"object","properties":{"characterSet":{"type":"string","example":"ASCII","description":"The character set to use."},"failedLoginRegex":{"type":"string","example":"(?:[i,I]ncorrect|[u,U]nknown|[f,F]ail|[i,I]nvalid|[l,L]ogin|[p,P]assword|[p,P]asswd|[u,U]sername|[u,U]nable|[e,E]rror|[d,D]enied|[r,R]eject|[r,R]efuse|[c,C]lose|[c,C]losing|Not on system console|% Bad)","description":"Regular expression to match a failed login response."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"loginRegex":{"type":"string","example":"(?:[l,L]ogin|[u,U]ser.?[nN]ame) *\\:","description":"Regular expression to match a login response."},"passwordPromptRegex":{"type":"string","example":"(?:[p,P]assword|[p,P]asswd) *\\:","description":"Regular expression to match a password prompt."},"questionableLoginRegex":{"type":"string","example":"(?:[l,L]ast [l,L]ogin *\\:|allows only .* Telnet Client License)","description":"Regular expression to match a potential false negative login response."}},"description":""},"TokenResource":{"type":"object","properties":{"key":{"type":"string","example":"","description":"The two-factor authentication token seed (key)."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}}},"description":""},"UnauthorizedError":{"type":"object","required":["status"],"properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","items":{"$ref":"#/definitions/Link"}},"message":{"type":"string","example":"An error has occurred.","description":"The messages indicating the cause or reason for failure."},"status":{"type":"string","example":"401","description":"The HTTP status code for the error (same as in the HTTP response).","enum":["401"]}},"description":""},"UniqueId":{"type":"object","required":["id"],"properties":{"id":{"type":"string","example":"c56b2c59-4e9b-4b89-85e2-13f8146eb071","description":"The unique identifier."},"source":{"type":"string","example":"WQL","description":"The source of the unique identifier."}},"description":""},"UpdateId":{"type":"object","properties":{"productId":{"type":"string","example":"281474976711146","description":"Product update identifier."},"versionId":{"type":"string","example":"490","description":"Version update identifier."}},"description":""},"UpdateInfo":{"type":"object","properties":{"content":{"type":"string","example":"3192129162","description":"The most recent content update."},"contentPartial":{"type":"string","example":"723680177","description":"The most recent, partially-applied (in-memory), content update."},"id":{"example":"","description":"Details of update identifiers.","$ref":"#/definitions/UpdateId"},"product":{"type":"string","example":"2200922472","description":"The most recent product update."}},"description":""},"UpdateSettings":{"type":"object","properties":{"contentAutoUpdate":{"type":"boolean","example":true,"description":"Whether automatic content updates are enabled."},"enabled":{"type":"boolean","example":true,"description":"Whether updates are enabled."},"productAutoUpdate":{"type":"boolean","example":true,"description":"Whether automatic product updates are enabled."}},"description":""},"User":{"type":"object","required":["login","name"],"properties":{"authentication":{"example":"","description":"The authentication source used to authenticate the user.","readOnly":true,"$ref":"#/definitions/AuthenticationSource"},"email":{"type":"string","example":"","description":"The email address of the user."},"enabled":{"type":"boolean","example":false,"description":"Whether the user account is enabled."},"id":{"type":"integer","format":"int32","example":"","description":"The identifier of the user.","readOnly":true},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"locale":{"example":"","description":"The locale and language preferences for the user.","$ref":"#/definitions/LocalePreferences"},"locked":{"type":"boolean","example":false,"description":"Whether the user account is locked (exceeded maximum password retry attempts).","readOnly":true},"login":{"type":"string","example":"","description":"The login name of the user."},"name":{"type":"string","example":"","description":"The full name of the user."},"role":{"example":"","description":"The privileges and role the user is assigned.","$ref":"#/definitions/UserRole"}},"description":""},"UserAccount":{"type":"object","properties":{"fullName":{"type":"string","example":"Smith, John","description":"The full name of the user account."},"id":{"type":"integer","format":"int32","example":8952,"description":"The identifier of the user account."},"name":{"type":"string","example":"john_smith","description":"The name of the user account."}},"description":""},"UserCreateRole":{"type":"object","required":["id"],"properties":{"allAssetGroups":{"type":"boolean","example":false,"description":"Whether to grant the user access to all asset groups. Defaults to `false`."},"allSites":{"type":"boolean","example":false,"description":"Whether to grant the user access to all sites. Defaults to `false`."},"id":{"type":"string","example":"","description":"The identifier of the role the user is assigned to."},"superuser":{"type":"boolean","example":false,"description":"Whether the user is a superuser. Defaults to `false`."}},"description":""},"UserEdit":{"type":"object","required":["login","name","password","role"],"properties":{"authentication":{"example":"","description":"The details of the authentication source used to authenticate the user.","$ref":"#/definitions/CreateAuthenticationSource"},"email":{"type":"string","example":"","description":"The email address of the user."},"enabled":{"type":"boolean","example":false,"description":"Whether the user account is enabled. Defaults to `true`."},"id":{"type":"integer","format":"int32","example":"","description":"The identifier of the user.","readOnly":true},"locale":{"example":"","description":"The locale and language preferences for the user.","$ref":"#/definitions/LocalePreferences"},"locked":{"type":"boolean","example":false,"description":"Whether the user account is locked (exceeded maximum password retry attempts).","readOnly":true},"login":{"type":"string","example":"","description":"The login name of the user."},"name":{"type":"string","example":"","description":"The full name of the user."},"password":{"type":"string","example":"","description":"The password to use for the user."},"passwordResetOnLogin":{"type":"boolean","example":false,"description":"Whether to require a reset of the user's password upon first login. Defaults to `false`."},"role":{"example":"","description":"The privileges and role to assign the user.","$ref":"#/definitions/UserCreateRole"}},"description":""},"UserRole":{"type":"object","properties":{"allAssetGroups":{"type":"boolean","example":false,"description":"Whether the user has access to all asset groups."},"allSites":{"type":"boolean","example":false,"description":"Whether the user has access to all sites."},"id":{"type":"string","example":"","description":"The identifier of the role the user is assigned to."},"name":{"type":"string","example":"","description":"The name of the role the user is assigned to."},"privileges":{"type":"array","description":"The privileges granted to the user by their role.","items":{"type":"string","enum":["all-permissions","create-reports","configure-global-settings","manage-sites","manage-tags","manage-static-asset-groups","manage-dynamic-asset-groups","manage-scan-templates","manage-report-templates","manage-scan-engines","submit-vulnerability-exceptions","approve-vulnerability-exceptions","delete-vulnerability-exceptions","manage-vuln-investigations","view-vuln-investigations","create-tickets","close-tickets","assign-ticket-assignee","manage-site-access","manage-asset-group-access","manage-report-access","use-restricted-report-sections","manage-policies","manage-advpolicies","view-asset-group-asset-data","manage-asset-group-assets","view-site-asset-data","specify-site-metadata","purge-site-asset-data","specify-scan-targets","assign-scan-engine","assign-scan-template","manage-site-credentials","manage-scan-alerts","schedule-automatic-scans","start-unscheduled-scans"]}},"superuser":{"type":"boolean","example":false,"description":"Whether the user is a superuser."}},"description":""},"VersionInfo":{"type":"object","properties":{"build":{"type":"string","example":"2017-12-10-14-11","description":"The build number."},"changeset":{"type":"string","example":"7061fb4e7c355160df79a77d8983bed2af01f2bf","description":"The changeset of the source build."},"platform":{"type":"string","example":"Linux64","description":"The platform of the build."},"semantic":{"type":"string","example":"6.4.65","description":"The semantic version number of the installation."},"update":{"example":"","description":"Version update details.","$ref":"#/definitions/UpdateInfo"}},"description":""},"Vulnerabilities":{"type":"object","properties":{"critical":{"type":"integer","format":"int64","example":16,"description":"The number of critical vulnerabilities.","readOnly":true},"moderate":{"type":"integer","format":"int64","example":3,"description":"The number of moderate vulnerabilities.","readOnly":true},"severe":{"type":"integer","format":"int64","example":76,"description":"The number of severe vulnerabilities.","readOnly":true},"total":{"type":"integer","format":"int64","example":95,"description":"The total number of vulnerabilities.","readOnly":true}},"description":""},"Vulnerability":{"type":"object","properties":{"added":{"type":"string","example":"2017-10-10","description":"The date the vulnerability coverage was added. The format is an ISO 8601 date, `YYYY-MM-DD`."},"categories":{"type":"array","description":"All vulnerability categories assigned to this vulnerability.","items":{"type":"string"}},"cves":{"type":"array","description":"All CVEs assigned to this vulnerability.","items":{"type":"string"}},"cvss":{"example":"","description":"The CVSS vector(s) for the vulnerability.","$ref":"#/definitions/VulnerabilityCvss"},"denialOfService":{"type":"boolean","example":false,"description":"Whether the vulnerability can lead to Denial of Service (DoS)."},"description":{"example":"","description":"The description of the vulnerability.","$ref":"#/definitions/ContentDescription"},"exploits":{"type":"integer","format":"int32","example":"","description":"The exploits that can be used to exploit a vulnerability."},"id":{"type":"string","example":"msft-cve-2017-11804","description":"The identifier of the vulnerability."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"malwareKits":{"type":"integer","format":"int32","example":"","description":"The malware kits that are known to be used to exploit the vulnerability."},"modified":{"type":"string","example":"2017-10-10","description":"The last date the vulnerability was modified. The format is an ISO 8601 date, `YYYY-MM-DD`."},"pci":{"example":"","description":"Details the Payment Card Industry (PCI) details of the vulnerability.","$ref":"#/definitions/PCI"},"published":{"type":"string","example":"2017-10-10","description":"The date the vulnerability was first published or announced. The format is an ISO 8601 date, `YYYY-MM-DD`."},"riskScore":{"type":"number","format":"double","example":123.69,"description":"The risk score of the vulnerability, rounded to a maximum of to digits of precision. If using the default Rapid7 Real Risk™ model, this value ranges from 0-1000."},"severity":{"type":"string","example":"Severe","description":"The severity of the vulnerability, one of: `\"Moderate\"`, `\"Severe\"`, `\"Critical\"`."},"severityScore":{"type":"integer","format":"int32","example":4,"description":"The severity score of the vulnerability, on a scale of 0-10."},"title":{"type":"string","example":"Microsoft CVE-2017-11804: Scripting Engine Memory Corruption Vulnerability","description":"The title (summary) of the vulnerability."}},"description":""},"VulnerabilityCategory":{"type":"object","properties":{"id":{"type":"integer","format":"int32","example":23,"description":"The identifier of the vulnerability category."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"name":{"type":"string","example":"Microsoft","description":"The name of the category."}},"description":""},"VulnerabilityCheck":{"type":"object","properties":{"id":{"type":"string","example":"WINDOWS-HOTFIX-MS14-009-01123281-bac0-44d8-a729-cd31c19d6bd1","description":"The identifier of the vulnerability check."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"plugin":{"type":"string","example":"WindowsHotfixScanner","description":"The name of the plugin (module) the check belongs to."},"potential":{"type":"boolean","example":false,"description":"Whether the check results in potential vulnerabilities."},"requiresCredentials":{"type":"boolean","example":true,"description":"Whether the check requires credentials in order to run."},"safe":{"type":"boolean","example":true,"description":"Whether the checked is deemed to be \"safe\" to run. A safe check is one that can be run without negatively impacting the host it is run against."},"service":{"type":"boolean","example":false,"description":"Whether the check operates against a service, or false it it is a local check."},"unique":{"type":"boolean","example":false,"description":"Whether the check may only register a result once during a scan of host. Otherwise, the tests in the check can run multiple times, possibly registering multiple results."},"vulnerability":{"type":"string","example":"windows-hotfix-ms14-009","description":"The identifier of the vulnerability the check results in."}},"description":""},"VulnerabilityCheckType":{"type":"object","properties":{"disabled":{"type":"array","description":"The types of vulnerability checks to disable during a scan.","items":{"type":"string"}},"enabled":{"type":"array","description":"The types of vulnerability checks to enable during a scan.","items":{"type":"string"}},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}}},"description":""},"VulnerabilityCvss":{"type":"object","properties":{"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"v2":{"example":"","description":"The Common Vulnerability Scoring System (CVSS v2) information for the vulnerability.","$ref":"#/definitions/VulnerabilityCvssV2"},"v3":{"example":"","description":"The Common Vulnerability Scoring System (CVSS v3) information for the vulnerability.","$ref":"#/definitions/VulnerabilityCvssV3"}},"description":""},"VulnerabilityCvssV2":{"type":"object","properties":{"accessComplexity":{"type":"string","example":"M","description":"Access Complexity (AC) component which measures the complexity of the attack required to exploit the vulnerability once an attacker has gained access to the target system. \n| Access Complexity | Description | \n| ----------------------- | ------------------------------------------------------------------------ | \n| High (`\"H\"`) | Specialized access conditions exist. | \n| Medium (`\"M\"`) | The access conditions are somewhat specialized. | \n| Low (`\"L\"`) | Specialized access conditions or extenuating circumstances do not exist. |","enum":["L","M","H"]},"accessVector":{"type":"string","example":"L","description":"Access Vector (Av) component which reflects how the vulnerability is exploited. \n| Access Vector | Description | \n| -------------------------- | ----------- | \n| Local (`\"L\"`) | A vulnerability exploitable with only local access requires the attacker to have either physical access to the vulnerable system or a local (shell) account. | \n| Adjacent Network (`\"A\"`) | A vulnerability exploitable with adjacent network access requires the attacker to have access to either the broadcast or collision domain of the vulnerable software. | \n| Network (`\"N\"`) | A vulnerability exploitable with network access means the vulnerable software is bound to the network stack and the attacker does not require local network access or local access. Such a vulnerability is often termed \"remotely exploitable\". | \n","enum":["L","A","N"]},"authentication":{"type":"string","example":"N","description":"Authentication (Au) component which measures the number of times an attacker must authenticate to a target in order to exploit a vulnerability. \n| Authentication | Description | \n| -------------------- | ----------- | \n| Multiple (`\"M\"`) | Exploiting the vulnerability requires that the attacker authenticate two or more times, even if the same credentials are used each time. | \n| Single (`\"S\"`) | The vulnerability requires an attacker to be logged into the system. | \n| None (`\"N\"`) | Authentication is not required to exploit the vulnerability. |","enum":["N","S","M"]},"availabilityImpact":{"type":"string","example":"P","description":"Availability Impact (A) component which measures the impact to availability of a successfully exploited vulnerability. \n| Availability Impact | Description | \n| -------------------------- | ------------ | \n| None (`\"N\"`) | There is no impact to the availability of the system. | \n| Partial (`\"P\"`) | There is reduced performance or interruptions in resource availability. | \n| Complete (`\"C\"`) | There is a total shutdown of the affected resource. The attacker can render the resource completely unavailable. |","enum":["N","P","C"]},"confidentialityImpact":{"type":"string","example":"P","description":"Confidentiality Impact (C) component which measures the impact on confidentiality of a successfully exploited vulnerability. \n| Confidentiality Impact | Description | \n| -------------------------- | ------------ | \n| None (`\"N\"`) | There is no impact to the confidentiality of the system. | \n| Partial (`\"P\"`) | There is considerable informational disclosure. Access to some system files is possible, but the attacker does not have control over what is obtained, or the scope of the loss is constrained. | \n| Complete (`\"C\"`) | There is total information disclosure, resulting in all system files being revealed. The attacker is able to read all of the system's data (memory, files, etc.) | ","enum":["N","P","C"]},"exploitScore":{"type":"number","format":"double","example":3.3926,"description":"The CVSS exploit score."},"impactScore":{"type":"number","format":"double","example":6.443,"description":"The CVSS impact score."},"integrityImpact":{"type":"string","example":"P","description":"Integrity Impact (I) component measures the impact to integrity of a successfully exploited vulnerability. \n| Integrity Impact | Description | \n| -------------------------- | ------------ | \n| None (`\"N\"`) | There is no impact to the integrity of the system. | \n| Partial (`\"P\"`) | Modification of some system files or information is possible, but the attacker does not have control over what can be modified, or the scope of what the attacker can affect is limited. | \n| Complete (`\"C\"`) | There is a total compromise of system integrity. There is a complete loss of system protection, resulting in the entire system being compromised. The attacker is able to modify any files on the target system. |","enum":["N","P","C"]},"score":{"type":"number","format":"double","example":4.4,"description":"The CVSS score, which ranges from 0-10."},"vector":{"type":"string","example":"AV:L/AC:M/Au:N/C:P/I:P/A:P","description":"The CVSS v2 vector."}},"description":""},"VulnerabilityCvssV3":{"type":"object","properties":{"attackComplexity":{"type":"string","example":"H","description":"Access Complexity (AC) component with measures the conditions beyond the attacker's control that must exist in order to exploit the vulnerability. \n| Access Complexity | Description | \n| ---------------------- | ------------------------------------------------------------------------ | \n| Low (`\"L\"`) | Specialized access conditions or extenuating circumstances do not exist. | \n| High (`\"H\"`) | A successful attack depends on conditions beyond the attacker's control. |","enum":["L","H"]},"attackVector":{"type":"string","example":"N","description":"Attack Vector (AV) component which measures context by which vulnerability exploitation is possible. \n| Access Vector | Description | \n| ---------------------- | ------------------------------------------------------------------------ | \n| Local (`\"L\"`) | A vulnerability exploitable with only local access requires the attacker to have either physical access to the vulnerable system or a local (shell) account. | \n| Adjacent (`\"A\"`) | A vulnerability exploitable with adjacent network access requires the attacker to have access to either the broadcast or collision domain of the vulnerable software. | \n| Network (`\"N\"`) | A vulnerability exploitable with network access means the vulnerable software is bound to the network stack and the attacker does not require local network access or local access. Such a vulnerability is often termed \"remotely exploitable\". | \n","enum":["N","A","L","P"]},"availabilityImpact":{"type":"string","example":"H","description":"Availability Impact (A) measures the impact to the availability of the impacted component resulting from a successfully exploited vulnerability. \n| Availability Impact | Description | \n| -------------------------- | ------------ | \n| High (`\"H\"`) | There is total loss of availability, resulting in the attacker being able to fully deny access to resources in the impacted component; this loss is either sustained (while the attacker continues to deliver the attack) or persistent (the condition persists even after the attack has completed). | \n| Low (`\"L\"`) | There is reduced performance or interruptions in resource availability. Even if repeated exploitation of the vulnerability is possible, the attacker does not have the ability to completely deny service to legitimate users. | \n| None (`\"N\"`) | There is no impact to availability within the impacted component. |","enum":["N","L","H"]},"confidentialityImpact":{"type":"string","example":"H","description":"Confidentiality Impact (C) component which measures the impact on confidentiality of a successfully exploited vulnerability. \n| Confidentiality Impact | Description | \n| -------------------------- | ------------ | \n| High (`\"H\"`) | There is total loss of confidentiality, resulting in all resources within the impacted component being divulged to the attacker. | \n| Low (`\"L\"`) | There is some loss of confidentiality. Access to some restricted information is obtained, but the attacker does not have control over what information is obtained, or the amount or kind of loss is constrained. | \n| None (`\"N\"`) | There is no loss of confidentiality within the impacted component. |","enum":["N","L","H"]},"exploitScore":{"type":"number","format":"double","example":1.6201,"description":"The CVSS impact score."},"impactScore":{"type":"number","format":"double","example":5.8731,"description":"The CVSS exploit score."},"integrityImpact":{"type":"string","example":"H","description":"Integrity Impact (I) measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and veracity of information. \n| Integrity Impact | Description | \n| ------------------- | ------------ | \n| High (`\"H\"`) | There is a total loss of integrity, or a complete loss of protection. | \n| Low (`\"L\"`) | Modification of data is possible, but the attacker does not have control over the consequence of a modification, or the amount of modification is constrained. | \n| None (`\"N\"`) | There is no loss of integrity within the impacted component. |","enum":["N","L","H"]},"privilegeRequired":{"type":"string","example":"N","description":"Privileges Required (PR) measures the level of privileges an attacker must possess before successfully exploiting the vulnerability. \n| Privileges Required (PR) | Description | \n| ---------------------------- | ------------------------------------------------------------------------ | \n| None (`\"N\"`) | The attacker is unauthorized prior to attack, and therefore does not require any access to settings or files to carry out an attack. | \n| Low (`\"L\"`) | The attacker is authorized with (i.e. requires) privileges that provide basic user capabilities that could normally affect only settings and files owned by a user. | \n| High (`\"H\"`) | The attacker is authorized with (i.e. requires) privileges that provide significant (e.g. administrative) control over the vulnerable component that could affect component-wide settings and files. |","enum":["N","L","H"]},"scope":{"type":"string","example":"U","description":"Scope (S) measures the collection of privileges defined by a computing authority (e.g. an application, an operating system, or a sandbox environment) when granting access to computing resources (e.g. files, CPU, memory, etc). These privileges are assigned based on some method of identification and authorization. \n| Scope (S) | Description | \n| -------------------- | ------------------------------------------------------------------------ | \n| Unchanged (`\"U\"`) | An exploited vulnerability can only affect resources managed by the same authority. In this case the vulnerable component and the impacted component are the same. | \n| Changed (`\"C\"`) | An exploited vulnerability can affect resources beyond the authorization privileges intended by the vulnerable component. In this case the vulnerable component and the impacted component are different. |","enum":["U","C"]},"score":{"type":"number","format":"double","example":7.5,"description":"The CVSS score, which ranges from 0-10."},"userInteraction":{"type":"string","example":"R","description":"User Interaction (UI) measures the requirement for a user, other than the attacker, to participate in the successful compromise of the vulnerable component. \n| User Interaction (UI) | Description | \n| ---------------------------- | ------------------------------------------------------------------------- | \n| None (`\"N\"`) | The vulnerable system can be exploited without interaction from any user. | \n| Required (`\"R\"`) | Successful exploitation of this vulnerability requires a user to take some action before the vulnerability can be exploited. |","enum":["N","R"]},"vector":{"type":"string","example":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","description":"The CVSS v3 vector."}},"description":""},"VulnerabilityEvents":{"type":"object","required":["confirmedVulnerabilities","potentialVulnerabilities","unconfirmedVulnerabilities","vulnerabilitySeverity"],"properties":{"confirmedVulnerabilities":{"type":"boolean","example":false,"description":"Generates an alert for vulnerability results of confirmed vulnerabilties. A vulnerability is \"confirmed\" when asset-specific vulnerability tests, such as exploits, produce positive results. Default value is `true`."},"potentialVulnerabilities":{"type":"boolean","example":false,"description":"Generates an alert for vulnerability results of potential vulnerabilties. A vulnerability is \"potential\" if a check for a potential vulnerabilty is positive. Default value is `true`."},"unconfirmedVulnerabilities":{"type":"boolean","example":false,"description":"Generates an alert for vulnerability results of unconfirmed vulnerabilties. A vulnerability is \"unconfirmed\" when a version of a scanned service or software is known to be vulnerable, but there is no positive verification. Default value is `true`."},"vulnerabilitySeverity":{"type":"string","example":"","description":"Generates an alert for vulnerability results of the selected vulnerability severity. Default value is `\"any_severity\"`.","enum":["any_severity","severe_and_critical","only_critical"]}},"description":""},"VulnerabilityException":{"type":"object","properties":{"expires":{"type":"string","example":"","description":"The date and time the vulnerability exception is set to expire."},"id":{"type":"integer","format":"int32","example":"","description":"The identifier of the vulnerability exception.","readOnly":true},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"review":{"example":"","description":"Details regarding the review and/or approval of the exception.","readOnly":true,"$ref":"#/definitions/Review"},"scope":{"example":"","description":"The scope of the vulnerability exception, indicating the results it applies to.","$ref":"#/definitions/ExceptionScope"},"state":{"type":"string","example":"","description":"The state of the vulnerability exception. One of: `\"Deleted\"`, `\"Expired\"`, `\"Approved\"`, `\"Rejected\"`, `\"Under Review\"."},"submit":{"example":"","description":"Details regarding the submission of the exception.","readOnly":true,"$ref":"#/definitions/Submission"}},"description":""},"VulnerabilityFinding":{"type":"object","required":["id","instances","status"],"properties":{"id":{"type":"string","example":"ssh-openssh-x11uselocalhost-x11-forwarding-session-hijack","description":"The identifier of the vulnerability."},"instances":{"type":"integer","format":"int32","example":1,"description":"The number of vulnerable occurrences of the vulnerability. This does not include `invulnerable` instances."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"results":{"type":"array","description":"The vulnerability check results for the finding. Multiple instances may be present if one or more checks fired, or a check has multiple independent results.","items":{"$ref":"#/definitions/AssessmentResult"}},"since":{"type":"string","example":"2017-08-09T11:32:33.658Z","description":"The date and time the finding was was first recorded, in the ISO8601 format. If the result changes status this value is the date and time of the status change."},"status":{"type":"string","example":"vulnerable","description":"The status of the finding.","enum":["vulnerable","invulnerable","no-results"]}},"description":""},"VulnerabilityReference":{"type":"object","properties":{"advisory":{"example":"","description":"Hypermedia link to the destination of the vulnerability reference.","$ref":"#/definitions/AdvisoryLink"},"id":{"type":"integer","format":"int32","example":157986,"description":"The identifier of the vulnerability reference."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"reference":{"type":"string","example":"4041689","description":"The contents of the reference, typically an identifier or hyperlink. Example: `\"CVE-2011-0762\"`"},"source":{"type":"string","example":"mskb","description":"The originating source of the reference. Examples: `\"url\"`, `\"cve\"`, `\"bid\"`, `\"redhat\"`"}},"description":""},"VulnerabilityValidationResource":{"type":"object","properties":{"date":{"type":"string","example":"2017-12-21T04:54:32.314Z","description":"The date and time the vulnerability was validated, in the ISO8601 format."},"id":{"type":"integer","format":"int64","example":46,"description":"The identifier of the vulnerability validation.","readOnly":true},"links":{"type":"array","items":{"$ref":"#/definitions/Link"}},"source":{"example":"","description":"The source used to validate the vulnerability.","$ref":"#/definitions/VulnerabilityValidationSource"}},"description":""},"VulnerabilityValidationSource":{"type":"object","properties":{"key":{"type":"string","example":"exploit/windows/iis/iis_webdav_scstoragepathfromurl","description":"The identifier or name of the exploit that was used to validate the vulnerability."},"name":{"type":"string","example":"metasploit","description":"The name of the source used to validate the vulnerability.","enum":["metasploit","other"]}},"description":""},"WebApplication":{"type":"object","properties":{"id":{"type":"integer","format":"int64","example":30712,"description":"The identifier of the web application."},"pages":{"type":"array","description":"The pages discovered on the web application.","items":{"$ref":"#/definitions/WebPage"}},"root":{"type":"string","example":"/","description":"The web root of the web application."},"virtualHost":{"type":"string","example":"102.89.22.253","description":"The virtual host of the web application."}},"description":""},"WebFormAuthentication":{"type":"object","properties":{"baseURL":{"type":"string","example":"","description":"The base URL is the main address from which all paths in the target Web site begin. Includes the protocol. Example: http://acme.com."},"enabled":{"type":"boolean","example":false,"description":"Flag indicating whether the HTML form web authentication is enabled for the site's scans."},"id":{"type":"integer","format":"int32","example":"","description":"The identifier of the HTML form web authentication."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"loginRegularExpression":{"type":"string","example":"","description":"The regular expression matches the message that the Web server returns if the login attempt fails."},"loginURL":{"type":"string","example":"","description":"The login page URL contains form for logging on. Include the base URL. Example: http://acme.com/login."},"name":{"type":"string","example":"","description":"The HTML form web authentication name."},"service":{"type":"string","example":"","description":"Value indicating whether this web authentication configuration is for HTML form authentication or HTTP header authentication.","enum":["html-form","http-header"]}},"description":""},"WebHeaderAuthentication":{"type":"object","properties":{"baseURL":{"type":"string","example":"","description":"The base URL is the main address from which all paths in the target Web site begin. Includes the protocol. Example: http://acme.com."},"enabled":{"type":"boolean","example":false,"description":"Flag indicating whether the HTTP header web authentication is enabled for the site's scans."},"headers":{"type":"object","example":"","description":"A map of HTTP headers the scan engine will use when negotiating with the Web server for an \"authenticated\" page. Make sure that the session ID is valid between the time you save this ID for the site and when you start the scan. Note: This property is not returned in responses for security.","additionalProperties":{"type":"string"}},"id":{"type":"integer","format":"int32","example":"","description":"The identifier of the HTTP header web authentication."},"links":{"type":"array","description":"Hypermedia links to corresponding or related resources.","readOnly":true,"items":{"$ref":"#/definitions/Link"}},"loginRegularExpression":{"type":"string","example":"","description":"The regular expression matches the message that the Web server returns if the login attempt fails."},"name":{"type":"string","example":"","description":"The HTTP header web authentication name."},"service":{"type":"string","example":"","description":"Value indicating whether this web authentication configuration is for HTML form authentication or HTTP header authentication.","enum":["html-form","http-header"]}},"description":""},"WebPage":{"type":"object","properties":{"linkType":{"type":"string","example":"html-ref","description":"The type of link used to traverse or detect the page.","enum":["seed","html-ref","robots","js-string","query-param","pdf","css","implied-dir","rss","redirection","sitemap","backup","vck-rewrite","non-ref-guess","soft-404"]},"path":{"type":"string","example":"/docs/config/index.html","description":"The path to the page (URI)."},"response":{"type":"integer","format":"int32","example":200,"description":"The HTTP response code observed with retrieving the page."}},"description":""},"WebSettings":{"type":"object","properties":{"maxThreads":{"type":"integer","format":"int32","example":100,"description":"The maximum number of request handling threads."},"minThreads":{"type":"integer","format":"int32","example":10,"description":"The minimum number of request handling threads."},"port":{"type":"integer","format":"int32","example":3780,"description":"The port the web server is accepting requests."},"sessionTimeout":{"type":"string","example":"PT10M","description":"Session timeout duration, in ISO 8601 format. For example: `\"PT10M\"`."}},"description":""}}}