# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Security Endpoint Management API version: 1.0.0 extends: openapi/elk-stack-security-endpoint-management-api-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 29 - target: $.paths['/api/endpoint/action'].get update: x-apievangelist-phrasing: intent: List endpoint response actions effect: read questions: - What response actions have been run against my endpoints? - Can I filter response action history by user or date range? - Which isolate or kill-process commands were issued on a given agent? instructions: - text: List all endpoint response actions. - text: Show response actions run on agents {agent_ids}. slots: agent_ids: query.agentIds - text: List {commands} response actions issued between {start} and {end}. slots: commands: query.commands start: query.startDate end: query.endDate method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action_status'].get update: x-apievangelist-phrasing: intent: Get pending response action status for agents effect: read questions: - Do any of my agents have response actions still pending? - What is the response action status for a set of endpoint agents? instructions: - text: Check the response action status for agents {agent_ids}. slots: agent_ids: query.agent_ids - text: Show pending action counts for agent {agent_ids}. slots: agent_ids: query.agent_ids method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/{action_id}'].get update: x-apievangelist-phrasing: intent: Get details of a response action effect: read questions: - Did a specific response action complete successfully? - What output did one particular response action return? instructions: - text: Show the details of response action {action_id}. slots: action_id: path.action_id - text: Check whether action {action_id} finished. slots: action_id: path.action_id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/{action_id}/file/{file_id}'].get update: x-apievangelist-phrasing: intent: Get info about a response action file effect: read questions: - What file was collected by a get-file response action, and how big is it? - Is a retrieved endpoint file ready for download yet? instructions: - text: Show information for file {file_id} from action {action_id}. slots: file_id: path.file_id action_id: path.action_id - text: Check the status of file {file_id} retrieved by action {action_id}. slots: file_id: path.file_id action_id: path.action_id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/{action_id}/file/{file_id}/download'].get update: x-apievangelist-phrasing: intent: Download a file from a response action effect: read questions: - How can I download a file that was pulled from an endpoint? - What password opens the zip archive of a retrieved endpoint file? instructions: - text: Download file {file_id} from response action {action_id}. slots: file_id: path.file_id action_id: path.action_id - text: Save the zipped file {file_id} collected by action {action_id}. slots: file_id: path.file_id action_id: path.action_id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/cancel'].post update: x-apievangelist-phrasing: intent: Cancel a pending response action effect: destructive questions: - Can I cancel a response action that is still pending on a host? - Is cancelling a running response action supported for every agent type? instructions: - text: Cancel the pending response action on endpoint {endpoint_ids}. slots: endpoint_ids: requestBody.endpoint_ids - text: Cancel the running action on {endpoint_ids} with comment {comment}. slots: endpoint_ids: requestBody.endpoint_ids comment: requestBody.comment method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/execute'].post update: x-apievangelist-phrasing: intent: Run a shell command on an endpoint effect: write questions: - Can I run a shell command remotely on a compromised host? - How do I execute a command on an endpoint and capture its output? instructions: - text: Run the shell command {parameters} on endpoint {endpoint_ids}. slots: parameters: requestBody.parameters endpoint_ids: requestBody.endpoint_ids - text: Execute a command on {endpoint_ids} and link it to case {case_ids}. slots: endpoint_ids: requestBody.endpoint_ids case_ids: requestBody.case_ids method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/get_file'].post update: x-apievangelist-phrasing: intent: Retrieve a file from an endpoint effect: write questions: - Can I pull a suspicious file off a host for analysis? - What do I need to collect a file from an endpoint by path? instructions: - text: Retrieve the file at {parameters} from endpoint {endpoint_ids}. slots: parameters: requestBody.parameters endpoint_ids: requestBody.endpoint_ids - text: Collect a file from host {endpoint_ids} for alert {alert_ids}. slots: endpoint_ids: requestBody.endpoint_ids alert_ids: requestBody.alert_ids method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/isolate'].post update: x-apievangelist-phrasing: intent: Isolate an endpoint from the network effect: write questions: - How do I cut a compromised host off from the network? - Does an isolated endpoint stay isolated until someone releases it? instructions: - text: Isolate endpoint {endpoint_ids} from the network. slots: endpoint_ids: requestBody.endpoint_ids - text: Network-isolate host {endpoint_ids} with the note {comment}. slots: endpoint_ids: requestBody.endpoint_ids comment: requestBody.comment method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/kill_process'].post update: x-apievangelist-phrasing: intent: Terminate a process on an endpoint effect: destructive questions: - Can I kill a malicious process running on a host? - What details do I need to terminate a process by PID on an endpoint? instructions: - text: Kill process {parameters} on endpoint {endpoint_ids}. slots: parameters: requestBody.parameters endpoint_ids: requestBody.endpoint_ids - text: Terminate the running process on {endpoint_ids} tied to alert {alert_ids}. slots: endpoint_ids: requestBody.endpoint_ids alert_ids: requestBody.alert_ids method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/memory_dump'].post update: x-apievangelist-phrasing: intent: Capture a memory dump from a host effect: write questions: - Can I capture a memory dump from a host under investigation? - Is a memory dump taken of the whole machine or a single process? instructions: - text: Generate a memory dump on endpoint {endpoint_ids}. slots: endpoint_ids: requestBody.endpoint_ids - text: Capture memory from {endpoint_ids} using options {parameters}. slots: endpoint_ids: requestBody.endpoint_ids parameters: requestBody.parameters method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/run_script'].post update: x-apievangelist-phrasing: intent: Run a script on a host effect: write questions: - Can I run a remediation script on a host remotely? - Which agent types support running a script as a response action? instructions: - text: Run script {parameters} on endpoint {endpoint_ids}. slots: parameters: requestBody.parameters endpoint_ids: requestBody.endpoint_ids - text: Run a script on {endpoint_ids} for agent type {agent_type}. slots: endpoint_ids: requestBody.endpoint_ids agent_type: requestBody.agent_type method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/running_procs'].post update: x-apievangelist-phrasing: intent: List processes running on an endpoint effect: write questions: - What processes are running on a suspicious host right now? - Can I pull a live process list from an endpoint? instructions: - text: Get the running processes on endpoint {endpoint_ids}. slots: endpoint_ids: requestBody.endpoint_ids - text: Pull a process list from {endpoint_ids} for case {case_ids}. slots: endpoint_ids: requestBody.endpoint_ids case_ids: requestBody.case_ids method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/scan'].post update: x-apievangelist-phrasing: intent: Scan a file or folder for malware effect: write questions: - Can I trigger a malware scan of a folder on a host? - Is it possible to scan one specific file on an endpoint? instructions: - text: Scan the path {parameters} on endpoint {endpoint_ids} for malware. slots: parameters: requestBody.parameters endpoint_ids: requestBody.endpoint_ids - text: Run a malware scan on {endpoint_ids}. slots: endpoint_ids: requestBody.endpoint_ids method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/state'].get update: x-apievangelist-phrasing: intent: Check whether response action encryption is on effect: read questions: - Is encryption enabled for endpoint response actions? - What is the overall state of the response actions feature? instructions: - text: Check the response actions state. - text: Tell me if response action encryption is enabled. method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/suspend_process'].post update: x-apievangelist-phrasing: intent: Suspend a process on an endpoint effect: write questions: - Can I pause a suspicious process without killing it? - What do I need to suspend a running process on a host? instructions: - text: Suspend process {parameters} on endpoint {endpoint_ids}. slots: parameters: requestBody.parameters endpoint_ids: requestBody.endpoint_ids - text: Freeze the running process on {endpoint_ids} with note {comment}. slots: endpoint_ids: requestBody.endpoint_ids comment: requestBody.comment method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/unisolate'].post update: x-apievangelist-phrasing: intent: Release an isolated endpoint effect: write questions: - How do I bring an isolated host back onto the network? - Can I release several isolated endpoints at once? instructions: - text: Release endpoint {endpoint_ids} from isolation. slots: endpoint_ids: requestBody.endpoint_ids - text: Unisolate host {endpoint_ids} and note {comment}. slots: endpoint_ids: requestBody.endpoint_ids comment: requestBody.comment method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/action/upload'].post update: x-apievangelist-phrasing: intent: Upload a file to an endpoint effect: write questions: - Can I push a file onto a host during an investigation? - Where does a file uploaded to an endpoint end up? instructions: - text: Upload {file} to endpoint {endpoint_ids}. slots: file: requestBody.file endpoint_ids: requestBody.endpoint_ids - text: Send the file {file} to host {endpoint_ids} with options {parameters}. slots: file: requestBody.file endpoint_ids: requestBody.endpoint_ids parameters: requestBody.parameters method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/metadata'].get update: x-apievangelist-phrasing: intent: List endpoint host metadata effect: read questions: - Which endpoints are enrolled and what is their host status? - Can I list only unhealthy or offline endpoints? instructions: - text: List endpoint hosts with status {host_statuses}. slots: host_statuses: query.hostStatuses - text: Show endpoints matching {kuery} with status {host_statuses}. slots: kuery: query.kuery host_statuses: query.hostStatuses method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/metadata/{id}'].get update: x-apievangelist-phrasing: intent: Get host metadata for one endpoint effect: read questions: - What OS and agent version is a specific endpoint running? - Which policy is applied to one particular host? instructions: - text: Show host metadata for endpoint {id}. slots: id: path.id - text: Get the details of endpoint {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/policy_response'].get update: x-apievangelist-phrasing: intent: Get an endpoint's latest policy response effect: read questions: - Did the endpoint security policy apply successfully on a host? - Why is a policy failing on a particular agent? instructions: - text: Show the latest policy response for agent {agent_id}. slots: agent_id: query.agentId - text: Check policy application status on agent {agent_id}. slots: agent_id: query.agentId method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/protection_updates_note/{package_policy_id}'].get update: x-apievangelist-phrasing: intent: Get a protection updates note effect: read questions: - What note is recorded about protection updates for a policy? - Why were protection updates pinned on a package policy? instructions: - text: Show the protection updates note for policy {package_policy_id}. slots: package_policy_id: path.package_policy_id - text: Read the protection note on {package_policy_id}. slots: package_policy_id: path.package_policy_id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/protection_updates_note/{package_policy_id}'].post update: x-apievangelist-phrasing: intent: Write the protection updates note for a policy effect: write questions: - Can I record why protection updates were paused on a policy? - How do I change the protection updates note on a package policy? instructions: - text: Set the protection updates note on policy {package_policy_id} to {note}. slots: package_policy_id: path.package_policy_id note: requestBody.note - text: Save the note {note} for protection updates on {package_policy_id}. slots: note: requestBody.note package_policy_id: path.package_policy_id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/scripts_library'].get update: x-apievangelist-phrasing: intent: List scripts in the script library effect: read questions: - What scripts are in my endpoint script library? - Can I search the script library by name or platform? instructions: - text: List all scripts in the script library. - text: Find library scripts matching {kuery}. slots: kuery: query.kuery method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/scripts_library'].post update: x-apievangelist-phrasing: intent: Add a script to the script library effect: write questions: - How do I add a new script to the endpoint script library? - Which platforms can a library script target? instructions: - text: Upload {file} as script {name} for platform {platform} as {file_type}. slots: file: requestBody.file name: requestBody.name platform: requestBody.platform file_type: requestBody.fileType - text: Create library script {name} from {file} ({file_type}) for {platform}, tagged {tags}. slots: name: requestBody.name file: requestBody.file file_type: requestBody.fileType platform: requestBody.platform tags: requestBody.tags method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/scripts_library/{script_id}'].get update: x-apievangelist-phrasing: intent: Get a script from the library effect: read questions: - What does a specific script in the library do and which platform is it for? - Does one library script require input when it runs? instructions: - text: Show library script {script_id}. slots: script_id: path.script_id - text: Get the details and instructions of script {script_id}. slots: script_id: path.script_id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/scripts_library/{script_id}'].delete update: x-apievangelist-phrasing: intent: Delete a script from the library effect: destructive questions: - Can I remove an outdated script from the script library? - Is deleting a library script permanent? instructions: - text: Delete library script {script_id}. slots: script_id: path.script_id - text: Remove script {script_id} from the script library. slots: script_id: path.script_id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/scripts_library/{script_id}'].patch update: x-apievangelist-phrasing: intent: Update a script in the library effect: write questions: - Can I change just the description of a library script? - How do I replace the file behind an existing library script? instructions: - text: Rename library script {script_id} to {name}. slots: script_id: path.script_id name: requestBody.name - text: Replace the file of script {script_id} with {file}. slots: script_id: path.script_id file: requestBody.file method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint/scripts_library/{script_id}/download'].get update: x-apievangelist-phrasing: intent: Download a library script file effect: read questions: - Can I download the file behind a script in the library? - Where do I get the source of a library script to review it? instructions: - text: Download the file for library script {script_id}. slots: script_id: path.script_id - text: Fetch the script source of {script_id}. slots: script_id: path.script_id method: generated generated: '2026-09-26'