Получение списка инцидентов

Пространство имен: microsoft.graph.security

Важно!

API версии /beta в Microsoft Graph могут быть изменены. Использование этих API в производственных приложениях не поддерживается. Чтобы определить, доступен ли API в версии 1.0, используйте селектор версий.

Получите список объектов инцидентов , созданных Microsoft 365 Defender для отслеживания атак в организации.

Атаки обычно осуществляются на различные типы объектов, таких как устройства, пользователи и почтовые ящики, в результате чего создается множество объектов оповещений . Microsoft 365 Defender сопоставляет оповещения с одними и теми же методами атаки или одним и тем же злоумышленником в инциденте.

Эта операция позволяет фильтровать и сортировать инциденты для создания обоснованных ответных мер кибербезопасности. Он предоставляет коллекцию инцидентов, которые были помечены в сети, в диапазоне времени, указанном в политике хранения среды. Самые последние инциденты отображаются в верхней части списка.

Этот API доступен в следующих национальных облачных развертываниях.

Глобальное обслуживание Правительство США L4 Правительство США L5 (DOD) Китай, обслуживаемый 21Vianet

Разрешения

Выберите разрешение или разрешения, помеченные как наименее привилегированные для этого API. Используйте более высокий уровень привилегий или разрешений, только если это требуется вашему приложению. Дополнительные сведения о делегированных разрешениях и разрешениях приложений см. в статье Типы разрешений. Дополнительные сведения об этих разрешениях см. в справочнике по разрешениям.

Тип разрешения Разрешения с наименьшим объемом привилегий Разрешения с более высоким уровнем привилегий
Делегированные (рабочая или учебная учетная запись) SecurityIncident.Read.All SecurityIncident.ReadWrite.All
Делегированные (личная учетная запись Майкрософт) Не поддерживается. Не поддерживается.
Приложение SecurityIncident.Read.All SecurityIncident.ReadWrite.All

Важно!

Для делегированного доступа с помощью рабочих или учебных учетных записей вошедшему пользователю должна быть назначена поддерживаемая роль Microsoft Entra или пользовательская роль, предоставляющая разрешения, необходимые для этой операции. Эта операция поддерживает следующие встроенные роли, которые предоставляют лишь наименьшее количество необходимых прав:

  • Читатель сведений о безопасности
  • Глобальный читатель
  • Оператор безопасности
  • Администратор безопасности

HTTP-запрос

GET /security/incidents

Необязательные параметры запросов

Этот метод поддерживает следующие параметры запроса OData, помогающие настроить ответ: $count, $filter, $skip, $top$expand, .

Следующие свойства поддерживают $filter : assignedTo, classification, createdDateTime, definition, lastUpdateDateTime, severity и status.

Использование @odata.nextLink для разбивки на страницы.

Ниже приведены примеры их использования:

GET /security/incidents?$count=true
GET /security/incidents?$filter={property}+eq+'{property-value}'
GET /security/incidents?$top=10

Общие сведения см. в статье Параметры запроса OData.

Заголовки запросов

Имя Описание
Авторизация Bearer {token}. Обязательно. Дополнительные сведения об аутентификации и авторизации.

Текст запроса

Не указывайте текст запроса для этого метода.

Отклик

В случае успеха этот метод возвращает код отклика 200 OK и коллекцию объектов инцидента в тексте ответа.

Примеры

Пример 1. Перечисление всех инцидентов

Запрос

Ниже показан пример запроса.

GET https://graph.microsoft.com/beta/security/incidents

Отклик

Ниже показан пример отклика.

Примечание. Объект отклика, показанный здесь, может быть сокращен для удобочитаемости.

HTTP/1.1 200 OK
Content-Type: application/json

{
    "value": [
        {
            "@odata.type": "#microsoft.graph.security.incident",
            "id": "2972395",
            "incidentWebUrl": "https://security.microsoft.com/incidents/2972395?tid=12f988bf-16f1-11af-11ab-1d7cd011db47",
            "redirectIncidentId": null,
            "tenantId": "b3c1b5fc-828c-45fa-a1e1-10d74f6d6e9c",
            "displayName": "Multi-stage incident involving Initial access & Command and control on multiple endpoints reported by multiple sources",
            "createdDateTime": "2021-08-13T08:43:35.5533333Z",
            "lastUpdateDateTime": "2021-09-30T09:35:45.1133333Z",
            "assignedTo": "KaiC@contoso.com",
            "classification": "TruePositive",
            "determination": "MultiStagedAttack",
            "status": "Active",
            "severity": "Medium",
            "customTags": [
                "Demo"
            ],
            "comments": [
                {
                    "comment": "Demo incident",
                    "createdBy": "DavidS@contoso.com",
                    "createdTime": "2021-09-30T12:07:37.2756993Z"
                }
            ],
            "systemTags": [
                "Defender Experts"
            ],
            "description": "Microsoft observed Raspberry Robin worm activity spreading through infected USB on multiple devices in your environment. From available intel, these infections could be a potential precursor activity to ransomware deployment. ...",
            "recommendedActions": "Immediate Recommendations: 1.    Block untrusted and unsigned processes that run from USB (ASR Rule) 2.    Verify if the ASR rule is turned on for the devices and evaluate whether the ASR . ...",
            "recommendedHuntingQueries": [
                {
                    "@odata.type": "#microsoft.graph.security.recommendedHuntingQuery",
                    "kqlText": "AlertInfo   | where Timestamp >= datetime(2022-10-20 06:00:52.9644915)   | where Title == 'Potential Raspberry Robin worm command'  | join AlertEvidence on AlertId   | distinct DeviceId"
                }
            ],
            "summary": "Defender Experts has identified some malicious activity. This incident has been raised for your awareness and should be investigated as normal."
        }
    ]
}

Пример 2. Перечислить все инциденты с их оповещениями

Запрос

Ниже показан пример запроса.

GET https://graph.microsoft.com/beta/security/incidents?$expand=alerts

Отклик

Ниже показан пример отклика.

Примечание. Объект отклика, показанный здесь, может быть сокращен для удобочитаемости.

HTTP/1.1 200 OK
Content-Type: application/json

{
    "value": [
        {
            "@odata.type": "#microsoft.graph.security.incident",
            "id": "2972395",
            "incidentWebUrl": "https://security.microsoft.com/incidents/2972395?tid=12f988bf-16f1-11af-11ab-1d7cd011db47",
            "redirectIncidentId": null,
            "tenantId": "b3c1b5fc-828c-45fa-a1e1-10d74f6d6e9c",
            "displayName": "Multi-stage incident involving Initial access & Command and control on multiple endpoints reported by multiple sources",
            "createdDateTime": "2021-08-13T08:43:35.5533333Z",
            "lastUpdateDateTime": "2021-09-30T09:35:45.1133333Z",
            "assignedTo": "KaiC@contoso.com",
            "classification": "truePositive",
            "determination": "multiStagedAttack",
            "status": "active",
            "severity": "medium",
            "tags": [
                "Demo"
            ],
            "comments": [
                {
                    "comment": "Demo incident",
                    "createdBy": "DavidS@contoso.com",
                    "createdTime": "2021-09-30T12:07:37.2756993Z"
                }
            ],
            "systemTags": [
                "Defender Experts"
            ],
            "description": "Microsoft observed Raspberry Robin worm activity spreading through infected USB on multiple devices in your environment. From available intel, these infections could be a potential precursor activity to ransomware deployment. ...",
            "recommendedActions": "Immediate Recommendations:  1.    Block untrusted and unsigned processes that run from USB (ASR Rule) 2.    Verify if the ASR rule is turned on for the devices and evaluate whether the ASR . ...",
            "recommendedHuntingQueries": [
                {
                    "@odata.type": "#microsoft.graph.security.recommendedHuntingQuery",
                    "kqlText": "//Run this query to identify the devices having Raspberry Robin worm alerts  AlertInfo   | where Timestamp >= datetime(2022-10-20 06:00:52.9644915)   | where Title == 'Potential Raspberry Robin worm command'  | join AlertEvidence on AlertId   | distinct DeviceId"
                }
            ],
            "alerts": [
                {
                    "@odata.type": "#microsoft.graph.security.alert",
                    "id": "da637551227677560813_-961444813",
                    "providerAlertId": "da637551227677560813_-961444813",
                    "incidentId": "28282",
                    "status": "new",
                    "severity": "low",
                    "classification": "unknown",
                    "determination": "unknown",
                    "serviceSource": "microsoftDefenderForEndpoint",
                    "detectionSource": "antivirus",
                    "detectorId": "e0da400f-affd-43ef-b1d5-afc2eb6f2756",
                    "tenantId": "b3c1b5fc-828c-45fa-a1e1-10d74f6d6e9c",
                    "title": "Suspicious execution of hidden file",
                    "description": "A hidden file has been launched. This activity could indicate a compromised host. Attackers often hide files associated with malicious tools to evade file system inspection and defenses.",
                    "recommendedActions": "Collect artifacts and determine scope\n�\tReview the machine timeline for suspicious activities that may have occurred before and after the time of the alert, and record additional related artifacts (files, IPs/URLs) \n�\tLook for the presence of relevant artifacts on other systems. Identify commonalities and differences between potentially compromised systems.\n�\tSubmit relevant files for deep analysis and review resulting detailed behavioral information.\n�\tSubmit undetected files to the MMPC malware portal\n\nInitiate containment & mitigation \n�\tContact the user to verify intent and initiate local remediation actions as needed.\n�\tUpdate AV signatures and run a full scan. The scan might reveal and remove previously-undetected malware components.\n�\tEnsure that the machine has the latest security updates. In particular, ensure that you have installed the latest software, web browser, and Operating System versions.\n�\tIf credential theft is suspected, reset all relevant users passwords.\n�\tBlock communication with relevant URLs or IPs at the organization�s perimeter.",
                    "category": "DefenseEvasion",
                    "assignedTo": null,
                    "alertWebUrl": "https://security.microsoft.com/alerts/da637551227677560813_-961444813?tid=b3c1b5fc-828c-45fa-a1e1-10d74f6d6e9c",
                    "incidentWebUrl": "https://security.microsoft.com/incidents/28282?tid=b3c1b5fc-828c-45fa-a1e1-10d74f6d6e9c",
                    "actorDisplayName": null,
                    "threatDisplayName": null,
                    "threatFamilyName": null,
                    "mitreTechniques": [
                        "T1564.001"
                    ],
                    "createdDateTime": "2021-04-27T12:19:27.7211305Z",
                    "lastUpdateDateTime": "2021-05-02T14:19:01.3266667Z",
                    "resolvedDateTime": null,
                    "firstActivityDateTime": "2021-04-26T07:45:50.116Z",
                    "lastActivityDateTime": "2021-05-02T07:56:58.222Z",
                    "comments": [],
                    "evidence": [
                        {
                            "@odata.type": "#microsoft.graph.security.deviceEvidence",
                            "createdDateTime": "2021-04-27T12:19:27.7211305Z",
                            "verdict": "unknown",
                            "remediationStatus": "none",
                            "remediationStatusDetails": null,
                            "firstSeenDateTime": "2020-09-12T07:28:32.4321753Z",
                            "mdeDeviceId": "73e7e2de709dff64ef64b1d0c30e67fab63279db",
                            "azureAdDeviceId": null,
                            "deviceDnsName": "yonif-lap3.middleeast.corp.microsoft.com",
                            "hostName": "yonif-lap3",
                            "ntDomain": null,
                            "dnsDomain": "middleeast.corp.microsoft.com",
                            "osPlatform": "Windows10",
                            "osBuild": 22424,
                            "version": "Other",
                            "healthStatus": "active",
                            "riskScore": "medium",
                            "rbacGroupId": 75,
                            "rbacGroupName": "UnassignedGroup",
                            "onboardingStatus": "onboarded",
                            "defenderAvStatus": "unknown",
                            "ipInterfaces": [
                                "1.1.1.1"
                            ],
                            "loggedOnUsers": [],
                            "roles": [
                                "compromised"
                            ],
                            "detailedRoles": [
                                "Main device"
                            ],
                            "tags": [
                                "Test Machine"
                            ],
                            "vmMetadata": {
                                "vmId": "ca1b0d41-5a3b-4d95-b48b-f220aed11d78",
                                "cloudProvider": "azure",
                                "resourceId": "/subscriptions/8700d3a3-3bb7-4fbe-a090-488a1ad04161/resourceGroups/WdatpApi-EUS-STG/providers/Microsoft.Compute/virtualMachines/NirLaviTests",
                                "subscriptionId": "8700d3a3-3bb7-4fbe-a090-488a1ad04161"
                            }
                        },
                        {
                            "@odata.type": "#microsoft.graph.security.fileEvidence",
                            "createdDateTime": "2021-04-27T12:19:27.7211305Z",
                            "verdict": "unknown",
                            "remediationStatus": "none",
                            "remediationStatusDetails": null,
                            "detectionStatus": "detected",
                            "mdeDeviceId": "73e7e2de709dff64ef64b1d0c30e67fab63279db",
                            "roles": [],
                            "detailedRoles": [
                                "Referred in command line"
                            ],
                            "tags": [],
                            "fileDetails": {
                                "sha1": "5f1e8acedc065031aad553b710838eb366cfee9a",
                                "sha256": "8963a19fb992ad9a76576c5638fd68292cffb9aaac29eb8285f9abf6196a7dec",
                                "fileName": "MsSense.exe",
                                "filePath": "C:\\Program Files\\temp",
                                "fileSize": 6136392,
                                "filePublisher": "Microsoft Corporation",
                                "signer": null,
                                "issuer": null
                            }
                        },
                        {
                            "@odata.type": "#microsoft.graph.security.processEvidence",
                            "createdDateTime": "2021-04-27T12:19:27.7211305Z",
                            "verdict": "unknown",
                            "remediationStatus": "none",
                            "remediationStatusDetails": null,
                            "processId": 4780,
                            "parentProcessId": 668,
                            "processCommandLine": "\"MsSense.exe\"",
                            "processCreationDateTime": "2021-08-12T12:43:19.0772577Z",
                            "parentProcessCreationDateTime": "2021-08-12T07:39:09.0909239Z",
                            "detectionStatus": "detected",
                            "mdeDeviceId": "73e7e2de709dff64ef64b1d0c30e67fab63279db",
                            "roles": [],
                            "detailedRoles": [],
                            "tags": [],
                            "imageFile": {
                                "sha1": "5f1e8acedc065031aad553b710838eb366cfee9a",
                                "sha256": "8963a19fb992ad9a76576c5638fd68292cffb9aaac29eb8285f9abf6196a7dec",
                                "fileName": "MsSense.exe",
                                "filePath": "C:\\Program Files\\temp",
                                "fileSize": 6136392,
                                "filePublisher": "Microsoft Corporation",
                                "signer": null,
                                "issuer": null
                            },
                            "parentProcessImageFile": {
                                "sha1": null,
                                "sha256": null,
                                "fileName": "services.exe",
                                "filePath": "C:\\Windows\\System32",
                                "fileSize": 731744,
                                "filePublisher": "Microsoft Corporation",
                                "signer": null,
                                "issuer": null
                            },
                            "userAccount": {
                                "accountName": "SYSTEM",
                                "domainName": "NT AUTHORITY",
                                "userSid": "S-1-5-18",
                                "azureAdUserId": null,
                                "userPrincipalName": null
                            }
                        },
                        {
                            "@odata.type": "#microsoft.graph.security.registryKeyEvidence",
                            "createdDateTime": "2021-04-27T12:19:27.7211305Z",
                            "verdict": "unknown",
                            "remediationStatus": "none",
                            "remediationStatusDetails": null,
                            "registryKey": "SYSTEM\\CONTROLSET001\\CONTROL\\WMI\\AUTOLOGGER\\SENSEAUDITLOGGER",
                            "registryHive": "HKEY_LOCAL_MACHINE",
                            "roles": [],
                            "detailedRoles": [],
                            "tags": []
                        }
                    ]
                }
            ],
            "summary": "Defender Experts has identified some malicious activity. This incident has been raised for your awareness and should be investigated as normal."
        }
    ]
}