openapi: 3.2.0 info: description: List of APIs that helps to retrieve information and perform operations on Threat Watch. Threat Watch is an automated continuous monitoring feature that scans resources for threats every 8 hours. version: 3.0.0 title: Cyber Resilience Threat Watch API servers: - url: https://apis.druva.com/realize tags: - name: Threat Watch description: List of APIs that helps to retrieve information and perform operations on Threat Watch. Threat Watch is an automated continuous monitoring feature that scans resources for threats every 8 hours. paths: /threathunting/v1/threatwatch/config: get: description: Retrieves the Threat Watch auto-quarantine configuration for the authenticated organization. Returns default values if no configuration exists. tags: - Threat Watch security: - Bearer: [] summary: Get Threat Watch configuration details responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchConfigResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchConfig x-operation-id-source: derived put: description: Creates or updates the Threat Watch auto-quarantine configuration for the authenticated organization. tags: - Threat Watch security: - Bearer: [] summary: Update Threat Watch configuration requestBody: content: application/json: schema: $ref: '#/components/schemas/ThreatWatchConfigUpdateParams' responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchConfigUpdateResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: putThreathuntingV1ThreatwatchConfig x-operation-id-source: derived /threathunting/v1/threatwatch/devices: get: description: 'The Threat Watch API provides a paginated list of devices affected by matches against Indicators of Compromise (IOC) sets identified during Threat Watch scans over the past 30 days. For each impacted device, the results include: Resource type, Count of file matches, Count of impacted snapshots, Matched IOC Sets, Timestamp of the first match, and Timestamp of the last match.' tags: - Threat Watch security: - Bearer: [] summary: Lists Threat Watch impacted devices parameters: - name: resourceTypes[] in: query description: 'Devices can be filtered based on their resource type (lowercase workload names: vmware, ec2, azurevm, onedrive, sharepoint, exchangeonline).' style: form explode: false schema: type: array items: type: string enum: - vmware - ec2 - azurevm - onedrive - sharepoint - exchangeonline - name: iocSetIds[] in: query description: Filters devices based on IOC set IDs. You can specify multiple IOC Set IDs. style: form explode: false schema: type: array items: type: integer - name: pageToken in: query description: The token to access the next page of results. Use the token value received in the previous response's parameter 'nextPageToken'. schema: type: string responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchDevicesResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchDevices x-operation-id-source: derived /threathunting/v1/threatwatch/devices/{deviceID}: get: description: Provides comprehensive details on impacted devices for Threat Watch. This API displays all details similar to the Threat Hunt API. tags: - Threat Watch security: - Bearer: [] summary: Get Threat Watch device details parameters: - name: deviceID in: path description: Specify the device ID. You can obtain the device ID using the 'List Threat Watch Device Results API'. required: true schema: type: integer - name: resourceType in: query description: Specify the resource type. required: true schema: type: string enum: - vmware - ec2 - azurevm - onedrive - sharepoint - exchangeonline responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchDeviceDetailsResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchDevicesByDeviceID x-operation-id-source: derived /threathunting/v1/threatwatch/devices/{deviceID}/stats: get: description: 'Provides comprehensive, device-level statistics for a specified device. The data includes: impacted snapshot counts; Total files impacted across all snapshots; Timestamps for the first and last impacted snapshots; Indicator of Compromise (IOC) sets that matched on the device.' tags: - Threat Watch security: - Bearer: [] summary: Get Threat Watch device statistics parameters: - name: deviceID in: path description: Specify the device ID. You can obtain the device ID using the 'List Threat Watch Device Results API'. required: true schema: type: integer - name: resourceType in: query description: Specify the resource type. required: true schema: type: string enum: - vmware - ec2 - azurevm - onedrive - sharepoint - exchangeonline responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchDeviceStatsResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchDevicesByDeviceIDStats x-operation-id-source: derived /threathunting/v1/threatwatch/impacteddevices/stats: get: description: Get aggregated statistics for impacted devices showing breakdown by resource type and IOC set. This API provides total number of impacted resources and file matches, breakdown of impacted devices by resource type (VMware, EC2, AzureVM, OneDrive, SharePoint, Exchange Online), and breakdown of impacted devices by IOC set name (sorted by impact count in descending order). tags: - Threat Watch security: - Bearer: [] summary: Get Impacted Devices Statistics parameters: - name: minTime in: query description: The start date for the statistics query is a required parameter and must be provided in YYYY-MM-DD format. required: true schema: type: string - name: maxTime in: query description: The statistics query's end date should be specified in YYYY-MM-DD format. If omitted, the current time is used by default. schema: type: string responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchImpactedDevicesStatsResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchImpacteddevicesStats x-operation-id-source: derived /threathunting/v1/threatwatch/iocs: get: description: 'Retrieves a paginated list of IOC Sets, including their threat impact metrics and daily trends, with a breakdown by resource type. Parameters include: - minTime (required): The start date for the data range, in YYYY-MM-DD format. - maxTime (optional): The end date, in YYYY-MM-DD format. Defaults to the current time. Constraint: If provided, maxTime must be on or after minTime. - pageToken (optional): Used to support pagination for navigating results. Returns: - IOC Set metadata - Threat impact metrics - Daily trends, broken down by resource type.' tags: - Threat Watch security: - Bearer: [] summary: Lists IOC Sets and impacted details for each IOC Set parameters: - name: minTime in: query description: Specifies the start date in YYYY-MM-DD format. required: true schema: type: string - name: maxTime in: query description: Optional end date in YYYY-MM-DD format. If omitted, the current time is used as the default. schema: type: string - name: pageToken in: query description: Used to support pagination for navigating results. schema: type: string responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchIOCsResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchIocs x-operation-id-source: derived /threathunting/v1/threatwatch/reports/{snapshotID}: get: description: Allows download of Threat Watch report for only impacted snapshots. Requires snapshotID (path), deviceID (query), and resourceType (query) to identify the resource. tags: - Threat Watch security: - Bearer: [] summary: Downloads Threat Watch snapshot report parameters: - name: snapshotID in: path description: The unique snapshot identifier. required: true schema: type: string - name: deviceID in: query description: Device identifier for the impacted resource. Obtain from List Threat Watch Device Results API. required: true schema: type: integer - name: resourceType in: query description: 'Workload type (lowercase). Required with deviceID. Values: vmware, ec2, azurevm, onedrive, sharepoint, exchangeonline.' required: true schema: type: string enum: - vmware - ec2 - azurevm - onedrive - sharepoint - exchangeonline responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchReportResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchReportsBySnapshotID x-operation-id-source: derived /threathunting/v1/threatwatch/scans: get: description: Retrieves Threat Watch automated scan details with pagination support. tags: - Threat Watch security: - Bearer: [] summary: List Threat Watch Scans parameters: - name: jobType in: query description: 'Filters by scan type: ''Scheduled'' or ''Retrospective''.' schema: type: string enum: - Scheduled - Retrospective - name: pageToken in: query description: The token to access the next page of results. Use the token value received in the previous response's parameter 'nextPageToken'. schema: type: string responses: '200': description: Success content: '*/*': schema: $ref: '#/components/schemas/ThreatWatchScansResponse' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_400' '401': description: The request either did not include an authentication token, or you have provided an expired authentication token. '404': description: The requested resource was not found. content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_404' '500': description: Internal Server Error content: '*/*': schema: $ref: '#/components/schemas/ThreatWatch_HTTP_500' operationId: getThreathuntingV1ThreatwatchScans x-operation-id-source: derived components: schemas: ThreatWatchReportResponse: type: object properties: downloadLink: type: string description: Download the Threat Watch snapshot report using this URL. ThreatWatch_HTTP_500: type: object description: The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time. properties: code: type: string enum: - THMaster-1006 message: type: string enum: - The request was not processed due to an internal error in Druva Cloud. Kindly try again after some time. data: type: object retryable: type: boolean enum: - false - true ThreatWatchDeviceDetailsResponse: type: object properties: deviceID: type: integer description: Device identifier. resourceIDs: type: array items: type: integer description: List of resource IDs. resourceName: type: string description: Resource name. resourceURL: type: string description: URL to resource in console. resourceType: type: string description: Resource type (VMware, EC2, AzureVM, OneDrive, SharePoint, ExchangeOnline). orgID: type: integer description: Organization ID. orgName: type: string description: Organization name. resourceParentID: type: integer description: Parent resource ID (e.g., vCenter, AWS Account). resourceParentName: type: string description: Parent resource name. payload: type: object description: Additional resource metadata. ThreatWatch_HTTP_404: type: object properties: code: type: string enum: - THMaster-1003 message: type: string enum: - The requested resource was not found. data: type: object retryable: type: boolean enum: - false - true ThreatWatchImpactedDevicesStatsResponse: type: object properties: totalImpactedResources: type: integer description: Total number of impacted resources. totalFileMatches: type: integer description: Total number of file matches across all impacted devices. impactByResourceType: type: array items: type: object properties: resourceType: type: string description: Resource type (VMware, EC2, AzureVM, OneDrive, SharePoint, ExchangeOnline). impactedDevices: type: integer description: Number of impacted devices for this resource type. description: Breakdown by resource type. impactByIoC: type: array items: type: object properties: iocSetID: type: integer description: IOC set identifier. iocSetName: type: string description: IOC set name. impactedDevices: type: integer description: Number of devices impacted by this IOC set. description: Breakdown by IOC set (sorted by impact count in descending order). ThreatWatchIOCsResponse: type: object properties: nextPageToken: type: string description: Token for pagination to next page. iocSet: type: array items: type: object properties: iocSetName: type: string description: IOC set name. iocSetType: type: string description: Type of IOC set - 'hash' or 'extension'. iocSetId: type: integer description: IOC set identifier. totalIOCsInSet: type: integer description: Total number of IOCs in the set. source: type: string description: Source of the IOC set (e.g., 'CISA', 'Druva', 'Custom'). lastUpdated: type: string description: ISO 8601 timestamp of last update. createdBy: type: string description: Creator of the IOC set. isDruvaPublished: type: boolean description: Indicates if the IOC Set is a Druva-published entity. threatImpact: type: object properties: devicesImpacted: type: integer description: Total devices impacted by this IOC Set. snapshotsImpacted: type: integer description: Total snapshots impacted by this IOC Set. filesImpacted: type: integer description: Total files impacted by this IOC Set. uniqueIOCMatches: type: integer description: Number of unique IOCs that matched. firstMatchedOn: type: string description: ISO 8601 timestamp of first match. lastMatchedOn: type: string description: ISO 8601 timestamp of last match. description: Overall threat impact metrics. impactTrend: type: array description: Trends in daily impact over the specified period. items: type: object properties: date: type: string description: Use the YYYY-MM-DD format for the date. devicesImpacted: type: integer description: The devices affected as of this date. snapshotsImpacted: type: integer description: The snapshots affected as of this date. filesImpacted: type: integer description: The files affected as of this date. impactByResourceType: type: array items: type: object properties: resourceType: type: string description: The resource type (VMware, EC2, AzureVM, OneDrive, SharePoint, ExchangeOnline) affected as of this date. impactedDevices: type: integer description: The devices affected for the resource type. description: Breakdown by resource type. description: The list of Indicators of Compromise (IOC) sets, along with their associated impact metrics, has been compiled. totalImpactedIOCSets: type: integer description: The total count of affected IOC sets. ThreatWatch_HTTP_400: type: object properties: code: type: string enum: - THMaster-1002 message: type: string enum: - Invalid API Syntax data: type: object retryable: type: boolean enum: - false - true ThreatWatchScansResponse: type: object properties: nextPageToken: type: string description: Next page pagination token. threatWatchScans: type: array items: type: object properties: devicesScanned: type: integer description: Number of devices scanned. filesScanned: type: integer description: Total files scanned. lastScannedOn: type: string description: ISO 8601 timestamp of scan start time. nextScheduledOn: type: string description: ISO 8601 timestamp of next scheduled scan. jobType: type: string description: 'Type of scan: ''Scheduled'' or ''Retrospective''.' enum: - Scheduled - Retrospective iocsUsedForScan: type: integer description: Number of IOCs used in the scan. iocsAddedInLastSevenDays: type: integer description: Number of IOCs added in last 7 days. scanStatus: type: string description: 'Status of the scan: ''Running'', ''Completed'', or ''Failed''.' description: List of scan records. ThreatWatchConfigUpdateResponse: type: object properties: message: type: string description: Response message indicating the result of the configuration update. validationFailures: type: array items: type: string description: List of validation failures, if any. ThreatWatchConfigResponse: type: object properties: autoQuarantineEnabled: type: boolean description: Indicates whether auto-quarantine is enabled for Threat Watch. lastUpdated: type: string description: Timestamp of the last configuration update. Format - YYYY-MM-DDTHH:MM:SSZ example: '2024-01-02T15:04:05Z' ThreatWatchDeviceStatsResponse: type: object properties: deviceID: type: integer description: Device identifier. resourceIDs: type: array items: type: integer description: List of resource IDs associated with the device. resourceType: type: string description: Resource type (VMware, EC2, AzureVM, OneDrive, SharePoint, ExchangeOnline). impactedSnapshots: type: integer description: Number of impacted snapshots. totalFilesImpacted: type: integer description: Total files impacted across all snapshots. firstImpactedSnapshot: type: string description: ISO 8601 timestamp of first impacted snapshot. lastImpactedSnapshot: type: string description: ISO 8601 timestamp of last impacted snapshot. iocSetsMatched: type: array items: type: object properties: iocSetID: type: integer description: IOC set identifier. iocSetName: type: string description: IOC set name. description: List of IOC sets that matched on the device. ThreatWatchDevicesResponse: type: object properties: nextPageToken: type: string description: The token to access the next page of results. This parameter will be empty for the last page of results. impactedDevices: type: array items: type: object properties: deviceID: type: integer description: Device identifier. resourceIDs: type: array items: type: integer description: List of resource IDs. resourceName: type: string description: Resource name. resourceType: type: string description: Resource type. The resource types can be 'VMware', 'EC2', 'AzureVM', 'OneDrive', 'SharePoint', and 'ExchangeOnline'. orgID: type: integer description: Organization ID. payload: type: object description: Additional resource metadata. fileMatches: type: integer description: Total file matches for the device. snapshotsImpacted: type: integer description: Number of infected snapshots. iocSetsMatched: type: array items: type: string description: List of IOC set names that matched. firstMatchedOn: type: string description: ISO 8601 timestamp of first match. lastMatchedOn: type: string description: ISO 8601 timestamp of last match. description: List of impacted devices. totalImpactedDevices: type: integer description: Total number of impacted devices. ThreatWatchConfigUpdateParams: type: object required: - autoQuarantineEnabled properties: autoQuarantineEnabled: type: boolean description: Enable or disable auto-quarantine for Threat Watch. Requires Premium SKU license and admin privileges. securitySchemes: OAuth2: type: oauth2 flows: clientCredentials: tokenUrl: https://apis.druva.com/token scopes: read: Grants read access Bearer: type: apiKey name: Authorization in: header