The identity and technical contract details declared by the specification.
AlibabaCloudResourceTypes
string
MetadataPolicy
object
4 properties
4 required
KubernetesResourceTypes
string
ConnectionQuery
object
4 properties
4 required
AndQuery
object
1 property
AccountData
object
2 properties
2 required
PolicyCode
object
1 property
1 required
PolicyPreviewBody
object
5 properties
PoliciesTableData
object
7 properties
7 required
PolicyDefinition
object
3 properties
2 required
CloudFormationResourceTypes
string
PreviewDataResults
object
10 properties
10 required
OrQuery
object
1 property
1 required
ErrorsReturn
object
1 property
1 required
ResourceType
object
2 properties
2 required
QueryPreview
object
3 properties
1 required
PoliciesTable
object
2 properties
2 required
PolicyRes
object
1 property
1 required
ComplexQuery
object
3 properties
filters
object
7 properties
7 required
SecretsQuery
object
2 properties
1 required
ClonePolicy
object
11 properties
ScopePolicy
object
1 property
1 required
FilterQuery
object
4 properties
4 required
Amount
object
6 properties
6 required
ErrorMessage
object
1 property
1 required
AzureResourceTypes
string
policyPreviewResult
object
2 properties
1 required
BaseAttributeOperator
string
ErrorResponse
object
2 properties
PolicyPreviewDetails
object
1 property
1 required
AttributeQuery
object
5 properties
4 required
waas.ParamStyle
string
ParamStyle is a param format style, defined by OpenAPI specification It describes how the parameter value will be serialized depending on the type of the param…
waas.KnownBotProtectionsSpec
object
KnownBotProtectionsSpec is the known bot protections spec
9 properties
vulnerability.ExploitType
string
ExploitType represents the source of an exploit
shared.ImageTag
object
ImageTag represents an image repository and its associated tag or registry digest
5 properties
common.NetworkDeviceIP
object
NetworkDeviceIP represents a network device name and address pair
2 properties
common.HostForensicSettings
object
HostForensicSettings indicates how to perform host forensic
6 properties
waas.ParamType
string
ParamType is the type of a parameter, defined by OpenAPI specification Ref: https://github.com/OAI/OpenAPI-Specification/blob/master/versions/2.0.mddata-types
common.ACIMetadata
object
1 property
shared.Port
object
Port is a container port
3 properties
shared.FileDetails
object
FileDetails contains file details as the file path, hash checksum
5 properties
vuln.SecretType
string
SecretType represents a secret type
vulnerability.RiskFactors
object
RiskFactors maps the existence of vulnerability risk factors
runtime.ContainerNetworkRule
object
ContainerNetworkRule represents the restrictions/suppression for networking
10 properties
shared.ImageInstance
object
ImageInstance represents an image on a single host
6 properties
shared.PkgsTimes
object
PkgsTimes are the compressed layer times for pkgs of the specific type
2 properties
trust.Status
string
Status is the trust status for an image
shared.Conditions
object
Conditions contains rule conditions. Conditions apply only for their respective policy type
3 properties
waas.VPCConfigStatus
string
VPCConfigStatus is the status of a VPC configuration deployment
waas.DoSRates
object
DoSRates specifies dos requests rates (thresholds)
2 properties
waas.RequestAnomalyThreshold
integer
RequestAnomalyThreshold is the score threshold for which request anomaly violation is triggered
agentless.ImageScanResultErrCode
integer
ImageScanResultErrCode represents the asset status error
customrules.Action
string
Action is the action to perform if the custom rule applies
runtime.HostPolicy
object
HostPolicy represents a host runtime policy enforced for a given running resource
3 properties
runtime.ContainerPolicy
object
ContainerPolicy represents a runtime policy enforced for a given running resource
3 properties
waas.UnknownBotProtectionSpec
object
UnknownBotProtectionSpec is the unknown bot protection spec
8 properties
customrules.Ref
object
Ref represents a custom rule that is referenced by a policy rule
3 properties
shared.BlockThreshold
object
BlockThreshold is the vulnerability policy block threshold Threshold values typically vary between 0 and 10 (noninclusive)
2 properties
waas.MaliciousUploadConfig
object
MaliciousUploadConfig is the configuration for file upload protection
3 properties
common.PortRange
object
PortRange represents a port range
3 properties
runtime.PortListRule
object
PortListRule represents a rule containing ports to allowed/denied and the required effect
3 properties
shared.ImageHosts
object
ImageHosts is a fast index for image scan results metadata per host
runtime.AntiMalwareRule
object
AntiMalwareRule represents restrictions/suppression for suspected anti-malware
16 properties
runtime.ContainerDNSRule
object
ContainerDNSRule is the DNS runtime rule for container
3 properties
runtime.DenyListRule
object
DenyListRule represents a rule containing paths of files and processes to alert/prevent and the required effect
2 properties
vulnerability.RiskFactor
string
RiskFactor represents a vulnerability risk factor, used in determining a vulnerability risk score
common.ClusterType
string
ClusterType is the cluster type
shared.LicenseConfig
object
LicenseConfig is the compliance policy license configuration
6 properties
waas.FeatureExceptions
object
FeatureExceptions represents subnets that should bypass WAAS features
1 property
shared.CompressedLayerTimes
object
CompressedLayerTimes represent the compressed layer times of the image apps and pkgs
2 properties
shared.ImageHistory
object
ImageHistory represent a layer in the image's history
8 properties
types.ImpactedOutOfBandEntity
object
ImpactedOutOfBandEntity holds the info of an impacted out of band entity
3 properties
waas.OutOfBandMode
string
OutOfBandMode holds the app firewall out-of-band mode
runtime.FileIntegrityRule
object
FileIntegrityRule represents a single file integrity monitoring rule
8 properties
shared.ContainerPort
object
ContainerPort represents the state of a port in a given container
5 properties
waas.CustomBlockResponseConfig
object
CustomBlockResponseConfig is a custom block message config for a policy
3 properties
shared.InstalledProducts
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
24 properties
runtime.ServerlessPolicy
object
ServerlessPolicy represents a serverless runtime policy enforced for a given running resource
3 properties
runtime.HostDNSRule
object
HostDNSRule represents a host DNS runtime rule
4 properties
common.AzureMetadata
object
2 properties
waas.DoSConfig
object
DoSConfig is a dos policy specification
6 properties
cnnf.RuleID
integer
RuleID represents the ID of each container network firewall policy rule
runtime.ContainerFilesystemRule
object
ContainerFilesystemRule represents restrictions/suppression for filesystem changes
8 properties
vulnerability.ExploitKind
string
ExploitKind represents the kind of the exploit
types.BaseImage
object
BaseImage represents an image which is defined as a base image
3 properties
waas.Param
object
Param contains a parameter information
10 properties
shared.ScanResultType
string
ScanResultType represents a cloud scan result type
-_waas.VPCConfigMirroredResource
array
runtime.ContainerPolicyRule
object
ContainerPolicyRule represents a single rule in the runtime policy
17 properties
collection.Collection
object
Collection is a collection of resources
16 properties
waas.VPCConfigMirroredResource
object
VPCConfigMirroredResource is a resource(vm or LB) mirrored by a VPC configuration deployment
2 properties
common.CloudProvider
string
CloudProvider specifies the cloud provider name
vuln.AllCompliance
object
AllCompliance contains data regarding passed compliance checks
2 properties
cnnf.RuleEntityType
string
RuleEntityType is the network firewall rule entity type
vuln.Secret
object
Secret represents a secret found on the scanned workload
12 properties
vuln.WildFireMalware
object
WildFireMalware holds the data for WildFire malicious MD5
3 properties
waas.OutOfBandRuleScope
string
OutOfBandRuleScope represents the Out-of-Band Rule Scope
vuln.Vulnerability
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
waas.UserDefinedBot
object
UserDefinedBot indicates a user-defined bot and its effect
5 properties
vuln.Distribution
object
Distribution counts the number of vulnerabilities per type
5 properties
waas.IntelGatheringConfig
object
IntelGatheringConfig is the configuration for intelligence gathering protections
2 properties
shared.ContainerScanResult
object
ContainerScanResult contains the result of a scanning a container
11 properties
common.ExternalLabelSourceType
string
ExternalLabelSourceType indicates the source of the labels
shared.Binary
object
Binary represents a detected binary file (ELF)
12 properties
runtime.NetworkRule
object
NetworkRule represents the restrictions/suppression for networking
7 properties
waas.Endpoint
object
Endpoint is an application endpoint
7 properties
waas.FileType
string
FileType is the type of an uploaded file
waas.CertificateMeta
object
CertificateMeta is the certificate metadata
3 properties
waas.AutoApplyPatchesSpec
object
AutoApplyPatchesSpec is the configuration for automation apply patches protection
1 property
runtime.HostPolicyRule
object
HostPolicyRule represents a single rule in the runtime policy
14 properties
shared.RiskFactorEffect
object
RiskFactorEffect represents the effect which is applied by a risk factor
2 properties
waas.VPCConfigState
object
VPCConfigState is the state of a VPC configuration This includes only the state needed by the frontend bson bindings do not omit empty as the structure is upda…
4 properties
trust.ImageResult
object
ImageResult represents an aggregated image trust result
2 properties
vuln.Condition
object
Condition are extended options for vulnerability assessment in authorization flows
2 properties
cnnf.Policy
object
Policy holds the data for firewall policies (host and container)
8 properties
shared.ImageHost
object
ImageHost holds information about image scan result per host
9 properties
shared.ContainerProcess
object
ContainerProcess represents a process inside a container
1 property
waas.ParamLocation
string
ParamLocation is the location of a parameter
vuln.ExpirationDate
object
ExpirationDate is the vulnerability expiration date
2 properties
vuln.Application
object
Application represents a detected application
10 properties
runtime.LogInspectionRule
object
LogInspectionRule represents a single log inspection rule
2 properties
waas.NetworkControls
object
NetworkControls contains the network controls config (e.g., access controls for IPs and countries)
5 properties
-_types.BaseImagesRule
array
-_types.ImpactedOutOfBandEntity
array
waas.StatusCodeRange
object
StatusCodeRange represents a status code range
2 properties
waas.RemoteHostForwardingConfig
object
RemoteHostForwardingConfig defines a remote host to forward requests to
2 properties
waas.Rule
object
Rule details for an application firewall
15 properties
runtime.ContainerProcessesRule
object
ContainerProcessesRule represents restrictions/suppression for running processes
10 properties
waas.SameSite
string
SameSite allows a server to define a cookie attribute making it impossible for the browser to send this cookie along with cross-site requests. The main goal is…
shared.LicenseThreshold
object
LicenseThreshold is the license severity threshold to indicate whether to perform an action (alert/block) Threshold values typically vary between 0 and 10 (non…
2 properties
secrets.SecretScanMetrics
object
SecretScanMetrics represents metrics collected during secret scan
10 properties
common.CloudRunMetadata
object
2 properties
vuln.ComplianceTemplate
string
ComplianceTemplate represents the compliance template
waas.AgentlessPolicyState
object
AgentlessPolicyState is the state of the agentless policy
2 properties
vulnerability.Type
string
Type represents the vulnerability type
common.ExternalLabel
object
ExternalLabel holds an external label with a source and timestamp
5 properties
vulnerability.ExploitData
object
ExploitData holds information about an exploit
3 properties
cnnf.Rule
object
Rule contains the properties common to both host and container network firewall
11 properties
common.Secret
object
Secret Stores the plain and encrypted version of a value. The plain version is not stored in a database
2 properties
shared.CVERule
object
CVERule is a vuln rule for specific vulnerability
4 properties
shared.GraceDaysPolicy
object
GraceDaysPolicy indicates the grace days policy by severity
5 properties
waas.Policy
object
Policy representation details
4 properties
waas.ExceptionField
object
ExceptionField is used to perform the protection exception fields
5 properties
common.Effect
string
Effect is the effect that is used in the CNNF rule
common.PolicyEffect
string
PolicyEffect state the effect of evaluating the given policy
shared.Policy
object
Policy represents a policy that should be enforced by the Auditor
3 properties
waas.ProtectionConfig
object
ProtectionConfig represents a WAAS protection config
2 properties
shared.ScanType
string
ScanType displays the components for an ongoing scan
cnnf.Subnet
object
Subnet is a network firewall subnet
2 properties
waas.ProtectionStatus
object
ProtectionStatus describes the status of the WAAS protection
6 properties
shared.TagRule
object
TagRule is a tag rule for specific vulnerabilities
4 properties
cnnf.NetworkEntities
array
NetworkEntities represents a list of network firewall entities
waas.AccessControls
object
AccessControls contains the access controls config (e.g., denied/allowed sources)
6 properties
waas.TLSConfig
object
TLSConfig holds the user TLS configuration and the certificate data
3 properties
trust.Group
object
Group represents a group of images
9 properties
packages.Type
string
Type describes the package type
shared.PkgTypeThreshold
object
PkgTypeThreshold represents specific vulnerability alert and block thresholds for a package type
3 properties
waas.BotProtectionSpec
object
BotProtectionSpec is the bot protections spec
7 properties
waas.CustomReCAPTCHAPageSpec
object
CustomReCAPTCHAPageSpec is the custom reCAPTCHA page spec
2 properties
runtime.RuleEffect
string
RuleEffect is the effect that will be used in the runtime rule
runtime.HostNetworkRule
object
HostNetworkRule represents the restrictions/suppression for host networking
7 properties
waas.ReCAPTCHASpec
object
ReCAPTCHASpec is the reCAPTCHA spec
7 properties
vuln.TagInfo
object
TagInfo is the tag info in a specific vulnerability context
3 properties
waas.ReCAPTCHAType
string
ReCAPTCHAType is the reCAPTCHA configured type
runtime.AppEmbeddedPolicyRule
object
AppEmbeddedPolicyRule represents a single rule in the app embedded runtime policy
14 properties
shared.ContainerInfo
object
ContainerInfo contains all information gathered on a specific container
25 properties
shared.DockerNetworkInfo
object
DockerNetworkInfo contains network-related information about a container
4 properties
common.PolicyType
string
PolicyType represents the type of the policy
vulnerability.Exploits
array
Exploits represents the exploits data found for a CVE
waas.JSInjectionSpec
object
JSInjectionSpec is the js injection protection spec
2 properties
runtime.ServerlessPolicyRule
object
ServerlessPolicyRule represents a single rule in the serverless runtime policy
17 properties
wildfire.Usage
object
Usage holds wildfire usage stats, period for the usage varies with context
3 properties
runtime.FilesystemRule
object
FilesystemRule represents restrictions/suppression for filesystem changes
7 properties
common.CloudMetadata
object
CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)
15 properties
waas.VPCConfigResource
object
VPCConfigResource is a resource created by a VPC configuration deployment
3 properties
shared.PolicyRule
object
PolicyRule is a single rule in the policy
28 properties
waas.UnprotectedProcess
object
UnprotectedProcess holds unprotected processes alongside the port
3 properties
-_waas.VPCConfigResource
array
common.Color
string
Color is a hexadecimal representation of color code value
customrules.Effect
string
Effect is the effect that will be used for custom rule
runtime.DNSRule
object
DNSRule is the DNS runtime rule
3 properties
shared.Packages
object
Packages is a collection of packages
2 properties
types.BaseImagesRule
object
BaseImagesRule holds the base images defined by a single scope
3 properties
common.GCPCloudMetadata
object
1 property
waas.ApplicationSpec
object
ApplicationSpec is an application of a firewall instance
32 properties
cnnf.AllowAllConnections
object
AllowAllConnections indicates if connections are allowed to/from any entity of the specified types e.g. if inbound contains the type subnet, the entity is allo…
2 properties
waas.BodyConfig
object
BodyConfig represents app configuration related to HTTP Body
3 properties
shared.NetworkInfo
object
NetworkInfo contains data about a container regarding a specific network
3 properties
common.PolicyBlockMsg
string
PolicyBlockMsg represent the block message in a Policy
waas.NetworkList
object
NetworkList represent network list of IP/CIDR in waas
9 properties
runtime.DNSListRule
object
DNSListRule represents an explicitly allowed/denied domains list rule
3 properties
waas.Effect
string
Effect is the effect that will be used in the rule
trust.HostStatus
object
HostStatus represents an image trust status on a host
2 properties
shared.ImageScanResult
object
ImageScanResult holds the result of an image scan
87 properties
waas.MinTLSVersion
string
MinTLSVersion is the list of acceptable TLS versions
waas.ExceptionLocation
string
ExceptionLocation indicates exception http field location
waas.APISpec
object
APISpec is an API specification
6 properties
waas.RequestAnomalies
object
RequestAnomalies is the request anomalies spec
2 properties
shared.ContainerNetwork
object
ContainerNetwork contains details about the container network (ports, IPs, type etc...)
1 property
waas.Path
object
Path is an API path information
2 properties
waas.HSTSConfig
object
HSTSConfig is the HTTP Strict Transport Security configuration in order to enforce HSTS header see: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/S…
4 properties
shared.AlertThreshold
object
AlertThreshold is the vulnerability policy alert threshold Threshold values typically vary between 0 and 10 (noninclusive)
2 properties
waas.DoSMatchCondition
object
DoSMatchCondition is used for matching a request for tracking
3 properties
vuln.Effect
string
Effect specifies relevant action for a vulnerability
waas.TrafficMirroringConfig
object
TrafficMirroringConfig specifies the traffic mirroring configuration is fine in that case
3 properties
shared.Image
object
Image represents a container image
13 properties
-_shared.ContainerScanResult
array
waas.VPCConfig
object
VPCConfig is the VPC configuration (there is a 1-to-1 relation with the rule, only one configuration per rule)
15 properties
waas.HeaderSpec
object
HeaderSpec is specification for a single header and its allowed or blocked values
5 properties
waas.Method
object
Method is a method information
2 properties
shared.Package
object
Package stores relevant package information
22 properties
runtime.ProcessesRule
object
ProcessesRule represents restrictions/suppression for running processes
8 properties
runtime.AppEmbeddedPolicy
object
AppEmbeddedPolicy represents a runtime policy enforced for a given running resource
2 properties
waas.ResponseHeaderSpec
object
ResponseHeaderSpec is specification for a single response header to modify
3 properties
cnnf.EntityID
integer
EntityID represents the ID of each network firewall entity. 20 bits are used. Max legal value: 2^20-1
-_shared.ImageScanResult
array
cnnf.NetworkEntity
object
NetworkEntity represents a network firewall entity
7 properties
shared.InstalledProducts_2
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
vuln.Vulnerability_2
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
vulnerability.VulnerabilityDataSource
object
VulnerabilityDataSource identifies the source of a specific vulnerability attribute. Example: CVSS from NVD, Severity from RedHat.
2 properties
vulnerability.VulnerabilitySource
integer
VulnerabilitySource represents the authority that provided vulnerability-related data (severity, CVSS, links).
vulnerability.VulnerabilityAttribute
integer
VulnerabilityAttribute represents a specific vulnerability property whose value may come from different sources
shared.ImageScanResult_2
object
ImageScanResult holds the result of an image scan
89 properties
vulnerability.VulnerabilityDataSources
array
VulnerabilityDataSources is a slice of VulnerabilityDataSource that implements the sql.Scanner and driver.Valuer interfaces
shared.Package_2
object
Package stores relevant package information
21 properties
shared.InstalledProducts_3
object
InstalledProducts contains data regarding products running in environment TODO 34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean…
25 properties
vuln.Vulnerability_3
object
Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
37 properties
shared.ImageScanResult_3
object
ImageScanResult holds the result of an image scan
89 properties
shared.Package_3
object
Package stores relevant package information
21 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Palo Alto Networks publishes across the network.