openapi: 3.1.0 info: title: Entries version: '1.0' servers: - url: https://api.feedly.com/v3/entries/ components: securitySchemes: sec0: type: apiKey name: Authorization in: header x-bearer-format: bearer security: - sec0: [] paths: /prediction: post: summary: Ask AI with structured outputs description: The Feedly Ask AI API allows developers to leverage the power of Large Language Models (LLMs) to ask questions and gather insights from a set of articles. operationId: ai-actions-experimental requestBody: content: application/json: schema: type: object properties: entryIds: type: array description: An array of article IDs to perform AI actions on items: type: string prompt: type: string description: The user-generated prompt to ask questions or gather insights from the articles responses: '200': description: '200' content: application/json: examples: Result: value: '{}' schema: type: object properties: {} '400': description: '400' content: application/json: examples: Result: value: '{}' schema: type: object properties: {} deprecated: false /{entryId}: get: summary: Get article metadata description: '' operationId: get-article-metadata parameters: - name: entryId in: path description: entryId of article schema: type: string required: true responses: '200': description: '200' content: application/json: examples: Result: value: "[\n {\n \"fingerprint\": \"c392b42\",\n \"id\": \"UybWZO8Gre9MphC4ZSsEQwKCOEGrCNXcYdJXbwlpiMI=_19a0d0d8f78:497f7ef:752f71fa\"\ ,\n \"language\": \"en\",\n \"originId\": \"https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/\"\ ,\n \"origin\": {\n \"streamId\": \"feed/https://detection.fyi/index.xml\"\ ,\n \"title\": \"Detection.FYI\",\n \"htmlUrl\": \"https://detection.fyi/\"\ \n },\n \"title\": \"AWS ConsoleLogin Failed Authentication\",\n \"published\"\ : 1761136602000,\n \"crawled\": 1761155583864,\n \"summary\": {\n \"content\"\ : \"Detects failed AWS console login attempts due to authentication failures. Monitoring\ \ these events is crucial for identifying potential brute-force attacks or unauthorized\ \ access attempts to AWS accounts.\",\n \"direction\": \"ltr\"\n },\n \"\ alternate\": [\n {\n \"href\": \"https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/\"\ ,\n \"type\": \"text/html\"\n }\n ],\n \"canonicalUrl\": \"https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/\"\ ,\n \"snippet\": \"\\n
\\n

Detects failed AWS console\ \ login attempts due to authentication failures. Monitoring these events is crucial\ \ for identifying potential brute-force attacks or unauthorized access attempts to\ \ AWS accounts.

\\n
 1title:\
                    \ AWS ConsoleLogin Failed Authentication\\n\
                    \ 2id: 6393e346-1977-46ef-8987-ad414a145fad\\\
                    n 3
\"\ ,\n \"originContentType\": \"text/html\",\n \"fullContent\": \"\\n
\\\ n

Detects failed AWS console login attempts due to authentication failures. Monitoring\ \ these events is crucial for identifying potential brute-force attacks or unauthorized\ \ access attempts to AWS accounts.

\\n
\
                    \ 1title: AWS ConsoleLogin\
                    \ Failed Authentication\\n 2id:\
                    \ 6393e346-1977-46ef-8987-ad414a145fad\\n\
                    \ 3status: experimental\\\
                    n 4description:\
                    \ |\\n 5\
                    \  Detects failed AWS console login attempts due to authentication\
                    \ failures. Monitoring these events is crucial for identifying potential brute-force\
                    \ attacks or unauthorized access attempts to AWS accounts.\\n\
                    \ 6references:\\n\
                    \ 7 - https://naikordian.github.io/blog/posts/brute-force-aws-console/\\\
                    n 8 - https://help.fortinet.com/fsiem/Public_Resource_Access/7_2_1/rules/PH_RULE_AWS_Management_Console_Brute_Force_of_Root_User_Identity.htm\\\
                    n 9 - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/aws_login_failure/aws_cloudtrail_events.json\\\
                    n10author:\
                    \ Ivan Saakov, Nasreddine Bencherchali\\n11date:\
                    \ 2025-10-19\\n12tags:\\\
                    n13 - attack.credential-access\\\
                    n14 - attack.t1110\\\
                    n15logsource:\\\
                    n16 product:\
                    \ aws\\n17\
                    \ service: cloudtrail\\\
                    n18detection:\\\
                    n19 selection:\\\
                    n20 eventName:\
                    \ 'ConsoleLogin'\\n21\
                    \ errorMessage: 'Failed authentication'\\\
                    n22 condition:\
                    \ selection\\n23falsepositives:\\\
                    n24 - Legitimate\
                    \ failed login attempts by authorized users. Investigate the source of repeated failed\
                    \ login attempts.\\n25level:\
                    \ medium\\n
\\n
\\\ n
\",\n \"unread\": true,\n \"categories\": [\n \ \ {\n \"id\": \"enterprise/christeam/category/a1b9d077-7806-4b29-8f1c-d17ebc172ea3\"\ ,\n \"label\": \"AI: Ad-Hoc Research\"\n }\n ],\n \"commonTopics\"\ : [\n {\n \"type\": \"detectionRule\",\n \"label\": \"Sigma rules\"\ ,\n \"id\": \"nlp/f/topic/7010\",\n \"score\": 1,\n \"salienceLevel\"\ : \"about\"\n }\n ],\n \"entities\": [\n {\n \"type\": \"org\"\ ,\n \"disambiguated\": true,\n \"label\": \"Amazon Web Services\",\n\ \ \"id\": \"nlp/f/entity/gz:org:amazon-web-services\",\n \"mentions\"\ : [\n {\n \"text\": \"AWS\"\n }\n ],\n \ \ \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"mitreAttack\"\ ,\n \"disambiguated\": true,\n \"label\": \"Brute Force (Enterprise\ \ T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\ ,\n \"mentions\": [\n {\n \"text\": \"brute-force\"\n \ \ },\n {\n \"text\": \"t1110\"\n }\n ],\n\ \ \"salienceLevel\": \"mention\"\n },\n {\n \"type\": \"mitreAttack\"\ ,\n \"disambiguated\": true,\n \"label\": \"Credential Access (Enterprise\ \ TA0006)\",\n \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\"\ ,\n \"causes\": [\n {\n \"label\": \"Brute Force (Enterprise\ \ T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\ \n }\n ],\n \"mentions\": [\n {\n \"text\"\ : \"credential-access\"\n }\n ],\n \"salienceLevel\": \"mention\"\ \n },\n {\n \"type\": \"mitreAttack\",\n \"disambiguated\"\ : true,\n \"label\": \"Tactics and Techniques\",\n \"id\": \"nlp/f/entity/gz:mi-any\"\ ,\n \"causes\": [\n {\n \"label\": \"Brute Force (Enterprise\ \ T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\ \n },\n {\n \"label\": \"Credential Access (Enterprise\ \ TA0006)\",\n \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\"\ \n }\n ],\n \"mentions\": [],\n \"salienceLevel\": \"\ mention\"\n }\n ],\n \"leoSummary\": {\n \"sentences\": []\n },\n\ \ \"indicatorsOfCompromise\": {\n \"mentions\": [],\n \"exports\": [],\n\ \ \"sigmaRules\": {\n \"count\": 1,\n \"url\": \"https://exports.feedly.com/sigma/sigma-342359ad452d13341f73665ef05c1f60.yaml\"\ \n }\n },\n \"attackNavigator\": {\n \"url\": \"https://exports.feedly.com/attacks/a322aeb98ff575dbc66b638386190651/feedly-ai-aws-consolelogin-failed-authentication.json\"\ ,\n \"ttpCount\": 1\n },\n \"sources\": [\n {\n \"streamId\"\ : \"feed/https://feedly.com/f/alert/278c354e-67ae-4509-b708-a354b8a41f9c\",\n \ \ \"title\": \"Detection rules\",\n \"feedlyFeedType\": \"WebAlert\",\n\ \ \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/225a0035-48b9-407b-b2bb-853f005cb2ce\"\ ,\n \"title\": \"Sigma Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n\ \ \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": false\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/6f87a1f0-f3cc-4738-a006-11ee08d9347a\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/0022a78d-2857-4f9a-b3d1-ed323bfd3265\"\ ,\n \"title\": \"PIR5.4 What new detection rules have been published?\",\n\ \ \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \ \ \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \ \ \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\"\ : true\n }\n },\n {\n \"streamId\": \"feed/https://feedly.com/f/alert/2c25ced4-db7a-400b-a711-802391d9089e\"\ ,\n \"title\": \"Sigma rules\",\n \"feedlyFeedType\": \"WebAlert\",\n\ \ \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": false\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/78ab8692-fa50-4ed7-954c-fadc12cba288\"\ ,\n \"title\": \"MITRE Tactics\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\"\ ,\n \"label\": \"Credential Access (Enterprise TA0006)\",\n \ \ \"type\": \"mitreAttack\"\n }\n ],\n \"isComplexFilter\"\ : true\n }\n },\n {\n \"streamId\": \"feed/https://feedly.com/f/alert/6c001996-3191-4cfb-918f-7ad1482a8999\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/d25940c2-348f-4f2f-8bcd-e1b9a4dcc990\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/28239608-5466-42b5-bc81-c29166fd46a8\"\ ,\n \"title\": \"Sigma rules and hunting queries\",\n \"feedlyFeedType\"\ : \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n\ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\ \n }\n ],\n \"isComplexFilter\": true\n }\n \ \ },\n {\n \"streamId\": \"feed/https://feedly.com/f/alert/af41b13b-f3a2-4cff-be47-b60f605a6c4c\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/3579d95a-7561-4017-8744-5518b125f475\"\ ,\n \"title\": \"Troubleshooting\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/entity/gz:org:amazon-web-services\",\n \"label\"\ : \"Amazon Web Services\",\n \"type\": \"org\"\n }\n \ \ ],\n \"isComplexFilter\": true\n }\n },\n {\n \ \ \"streamId\": \"feed/https://feedly.com/f/alert/1bb46cb3-0465-4a06-aaf7-795b5d062aca\"\ ,\n \"title\": \"DT Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \ \ \"searchTerms\": {\n \"parts\": [\n {\n \"\ id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n }\n ]\n\ \ }\n]" schema: type: array items: type: object properties: fingerprint: type: string example: c392b42 id: type: string example: UybWZO8Gre9MphC4ZSsEQwKCOEGrCNXcYdJXbwlpiMI=_19a0d0d8f78:497f7ef:752f71fa language: type: string example: en originId: type: string example: https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/ origin: type: object properties: streamId: type: string example: feed/https://detection.fyi/index.xml title: type: string example: Detection.FYI htmlUrl: type: string example: https://detection.fyi/ title: type: string example: AWS ConsoleLogin Failed Authentication published: type: integer example: 1761136602000 default: 0 crawled: type: integer example: 1761155583864 default: 0 summary: type: object properties: content: type: string example: Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts. direction: type: string example: ltr alternate: type: array items: type: object properties: href: type: string example: https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/ type: type: string example: text/html canonicalUrl: type: string example: https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/ snippet: type: string example: '

Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.

 1title:
                        AWS ConsoleLogin Failed Authentication

                         2id:
                        6393e346-1977-46ef-8987-ad414a145fad

                         3
' originContentType: type: string example: text/html fullContent: type: string example: '

Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.

 1title:
                        AWS ConsoleLogin Failed Authentication

                         2id:
                        6393e346-1977-46ef-8987-ad414a145fad

                         3status:
                        experimental

                         4description:
                        |

                         5  Detects
                        failed AWS console login attempts due to authentication failures. Monitoring these
                        events is crucial for identifying potential brute-force attacks or unauthorized
                        access attempts to AWS accounts.

                         6references:

                         7 - https://naikordian.github.io/blog/posts/brute-force-aws-console/

                         8 - https://help.fortinet.com/fsiem/Public_Resource_Access/7_2_1/rules/PH_RULE_AWS_Management_Console_Brute_Force_of_Root_User_Identity.htm

                         9 - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/aws_login_failure/aws_cloudtrail_events.json

                        10author:
                        Ivan Saakov, Nasreddine Bencherchali

                        11date:
                        2025-10-19

                        12tags:

                        13 - attack.credential-access

                        14 - attack.t1110

                        15logsource:

                        16 product:
                        aws

                        17 service:
                        cloudtrail

                        18detection:

                        19 selection:

                        20 eventName:
                        ''ConsoleLogin''

                        21 errorMessage:
                        ''Failed authentication''

                        22 condition:
                        selection

                        23falsepositives:

                        24 - Legitimate
                        failed login attempts by authorized users. Investigate the source of repeated
                        failed login attempts.

                        25level:
                        medium

                        
' unread: type: boolean example: true default: true categories: type: array items: type: object properties: id: type: string example: enterprise/christeam/category/a1b9d077-7806-4b29-8f1c-d17ebc172ea3 label: type: string example: 'AI: Ad-Hoc Research' commonTopics: type: array items: type: object properties: type: type: string example: detectionRule label: type: string example: Sigma rules id: type: string example: nlp/f/topic/7010 score: type: integer example: 1 default: 0 salienceLevel: type: string example: about entities: type: array items: type: object properties: type: type: string example: org disambiguated: type: boolean example: true default: true label: type: string example: Amazon Web Services id: type: string example: nlp/f/entity/gz:org:amazon-web-services mentions: type: array items: type: object properties: text: type: string example: AWS salienceLevel: type: string example: about leoSummary: type: object properties: sentences: type: array items: type: object properties: {} indicatorsOfCompromise: type: object properties: mentions: type: array items: type: object properties: {} exports: type: array items: type: object properties: {} sigmaRules: type: object properties: count: type: integer example: 1 default: 0 url: type: string example: https://exports.feedly.com/sigma/sigma-342359ad452d13341f73665ef05c1f60.yaml attackNavigator: type: object properties: url: type: string example: https://exports.feedly.com/attacks/a322aeb98ff575dbc66b638386190651/feedly-ai-aws-consolelogin-failed-authentication.json ttpCount: type: integer example: 1 default: 0 sources: type: array items: type: object properties: streamId: type: string example: feed/https://feedly.com/f/alert/278c354e-67ae-4509-b708-a354b8a41f9c title: type: string example: Detection rules feedlyFeedType: type: string example: WebAlert searchTerms: type: object properties: parts: type: array items: type: object properties: id: type: string example: nlp/f/topic/7010 label: type: string example: Sigma rules isComplexFilter: type: boolean example: true default: true '400': description: '400' content: application/json: examples: Result: value: '{}' schema: type: object properties: {} deprecated: false /.mget: post: summary: Get multiple article metadata description: '' operationId: get-multiple-article-metadata requestBody: content: application/json: schema: type: object properties: RAW_BODY: type: array description: Limit 1,000 entries per call items: type: string responses: '200': description: '200' content: application/json: examples: Result: value: "[\n {\n \"fingerprint\": \"c392b42\",\n \"id\": \"UybWZO8Gre9MphC4ZSsEQwKCOEGrCNXcYdJXbwlpiMI=_19a0d0d8f78:497f7ef:752f71fa\"\ ,\n \"language\": \"en\",\n \"originId\": \"https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/\"\ ,\n \"origin\": {\n \"streamId\": \"feed/https://detection.fyi/index.xml\"\ ,\n \"title\": \"Detection.FYI\",\n \"htmlUrl\": \"https://detection.fyi/\"\ \n },\n \"title\": \"AWS ConsoleLogin Failed Authentication\",\n \"published\"\ : 1761136602000,\n \"crawled\": 1761155583864,\n \"summary\": {\n \"content\"\ : \"Detects failed AWS console login attempts due to authentication failures. Monitoring\ \ these events is crucial for identifying potential brute-force attacks or unauthorized\ \ access attempts to AWS accounts.\",\n \"direction\": \"ltr\"\n },\n \"\ alternate\": [\n {\n \"href\": \"https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/\"\ ,\n \"type\": \"text/html\"\n }\n ],\n \"canonicalUrl\": \"https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/\"\ ,\n \"snippet\": \"\\n
\\n

Detects failed AWS console\ \ login attempts due to authentication failures. Monitoring these events is crucial\ \ for identifying potential brute-force attacks or unauthorized access attempts to\ \ AWS accounts.

\\n
 1title:\
                    \ AWS ConsoleLogin Failed Authentication\\n\
                    \ 2id: 6393e346-1977-46ef-8987-ad414a145fad\\\
                    n 3
\"\ ,\n \"originContentType\": \"text/html\",\n \"fullContent\": \"\\n
\\\ n

Detects failed AWS console login attempts due to authentication failures. Monitoring\ \ these events is crucial for identifying potential brute-force attacks or unauthorized\ \ access attempts to AWS accounts.

\\n
\
                    \ 1title: AWS ConsoleLogin\
                    \ Failed Authentication\\n 2id:\
                    \ 6393e346-1977-46ef-8987-ad414a145fad\\n\
                    \ 3status: experimental\\\
                    n 4description:\
                    \ |\\n 5\
                    \  Detects failed AWS console login attempts due to authentication\
                    \ failures. Monitoring these events is crucial for identifying potential brute-force\
                    \ attacks or unauthorized access attempts to AWS accounts.\\n\
                    \ 6references:\\n\
                    \ 7 - https://naikordian.github.io/blog/posts/brute-force-aws-console/\\\
                    n 8 - https://help.fortinet.com/fsiem/Public_Resource_Access/7_2_1/rules/PH_RULE_AWS_Management_Console_Brute_Force_of_Root_User_Identity.htm\\\
                    n 9 - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/aws_login_failure/aws_cloudtrail_events.json\\\
                    n10author:\
                    \ Ivan Saakov, Nasreddine Bencherchali\\n11date:\
                    \ 2025-10-19\\n12tags:\\\
                    n13 - attack.credential-access\\\
                    n14 - attack.t1110\\\
                    n15logsource:\\\
                    n16 product:\
                    \ aws\\n17\
                    \ service: cloudtrail\\\
                    n18detection:\\\
                    n19 selection:\\\
                    n20 eventName:\
                    \ 'ConsoleLogin'\\n21\
                    \ errorMessage: 'Failed authentication'\\\
                    n22 condition:\
                    \ selection\\n23falsepositives:\\\
                    n24 - Legitimate\
                    \ failed login attempts by authorized users. Investigate the source of repeated failed\
                    \ login attempts.\\n25level:\
                    \ medium\\n
\\n
\\\ n
\",\n \"unread\": true,\n \"categories\": [\n \ \ {\n \"id\": \"enterprise/christeam/category/a1b9d077-7806-4b29-8f1c-d17ebc172ea3\"\ ,\n \"label\": \"AI: Ad-Hoc Research\"\n }\n ],\n \"commonTopics\"\ : [\n {\n \"type\": \"detectionRule\",\n \"label\": \"Sigma rules\"\ ,\n \"id\": \"nlp/f/topic/7010\",\n \"score\": 1,\n \"salienceLevel\"\ : \"about\"\n }\n ],\n \"entities\": [\n {\n \"type\": \"org\"\ ,\n \"disambiguated\": true,\n \"label\": \"Amazon Web Services\",\n\ \ \"id\": \"nlp/f/entity/gz:org:amazon-web-services\",\n \"mentions\"\ : [\n {\n \"text\": \"AWS\"\n }\n ],\n \ \ \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"mitreAttack\"\ ,\n \"disambiguated\": true,\n \"label\": \"Brute Force (Enterprise\ \ T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\ ,\n \"mentions\": [\n {\n \"text\": \"brute-force\"\n \ \ },\n {\n \"text\": \"t1110\"\n }\n ],\n\ \ \"salienceLevel\": \"mention\"\n },\n {\n \"type\": \"mitreAttack\"\ ,\n \"disambiguated\": true,\n \"label\": \"Credential Access (Enterprise\ \ TA0006)\",\n \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\"\ ,\n \"causes\": [\n {\n \"label\": \"Brute Force (Enterprise\ \ T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\ \n }\n ],\n \"mentions\": [\n {\n \"text\"\ : \"credential-access\"\n }\n ],\n \"salienceLevel\": \"mention\"\ \n },\n {\n \"type\": \"mitreAttack\",\n \"disambiguated\"\ : true,\n \"label\": \"Tactics and Techniques\",\n \"id\": \"nlp/f/entity/gz:mi-any\"\ ,\n \"causes\": [\n {\n \"label\": \"Brute Force (Enterprise\ \ T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\ \n },\n {\n \"label\": \"Credential Access (Enterprise\ \ TA0006)\",\n \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\"\ \n }\n ],\n \"mentions\": [],\n \"salienceLevel\": \"\ mention\"\n }\n ],\n \"leoSummary\": {\n \"sentences\": []\n },\n\ \ \"indicatorsOfCompromise\": {\n \"mentions\": [],\n \"exports\": [],\n\ \ \"sigmaRules\": {\n \"count\": 1,\n \"url\": \"https://exports.feedly.com/sigma/sigma-342359ad452d13341f73665ef05c1f60.yaml\"\ \n }\n },\n \"attackNavigator\": {\n \"url\": \"https://exports.feedly.com/attacks/a322aeb98ff575dbc66b638386190651/feedly-ai-aws-consolelogin-failed-authentication.json\"\ ,\n \"ttpCount\": 1\n },\n \"sources\": [\n {\n \"streamId\"\ : \"feed/https://feedly.com/f/alert/278c354e-67ae-4509-b708-a354b8a41f9c\",\n \ \ \"title\": \"Detection rules\",\n \"feedlyFeedType\": \"WebAlert\",\n\ \ \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/225a0035-48b9-407b-b2bb-853f005cb2ce\"\ ,\n \"title\": \"Sigma Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n\ \ \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": false\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/6f87a1f0-f3cc-4738-a006-11ee08d9347a\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/0022a78d-2857-4f9a-b3d1-ed323bfd3265\"\ ,\n \"title\": \"PIR5.4 What new detection rules have been published?\",\n\ \ \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \ \ \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \ \ \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\"\ : true\n }\n },\n {\n \"streamId\": \"feed/https://feedly.com/f/alert/2c25ced4-db7a-400b-a711-802391d9089e\"\ ,\n \"title\": \"Sigma rules\",\n \"feedlyFeedType\": \"WebAlert\",\n\ \ \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": false\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/78ab8692-fa50-4ed7-954c-fadc12cba288\"\ ,\n \"title\": \"MITRE Tactics\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\"\ ,\n \"label\": \"Credential Access (Enterprise TA0006)\",\n \ \ \"type\": \"mitreAttack\"\n }\n ],\n \"isComplexFilter\"\ : true\n }\n },\n {\n \"streamId\": \"feed/https://feedly.com/f/alert/6c001996-3191-4cfb-918f-7ad1482a8999\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/d25940c2-348f-4f2f-8bcd-e1b9a4dcc990\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/28239608-5466-42b5-bc81-c29166fd46a8\"\ ,\n \"title\": \"Sigma rules and hunting queries\",\n \"feedlyFeedType\"\ : \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n\ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\ \n }\n ],\n \"isComplexFilter\": true\n }\n \ \ },\n {\n \"streamId\": \"feed/https://feedly.com/f/alert/af41b13b-f3a2-4cff-be47-b60f605a6c4c\"\ ,\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n },\n\ \ {\n \"streamId\": \"feed/https://feedly.com/f/alert/3579d95a-7561-4017-8744-5518b125f475\"\ ,\n \"title\": \"Troubleshooting\",\n \"feedlyFeedType\": \"WebAlert\"\ ,\n \"searchTerms\": {\n \"parts\": [\n {\n \ \ \"id\": \"nlp/f/entity/gz:org:amazon-web-services\",\n \"label\"\ : \"Amazon Web Services\",\n \"type\": \"org\"\n }\n \ \ ],\n \"isComplexFilter\": true\n }\n },\n {\n \ \ \"streamId\": \"feed/https://feedly.com/f/alert/1bb46cb3-0465-4a06-aaf7-795b5d062aca\"\ ,\n \"title\": \"DT Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \ \ \"searchTerms\": {\n \"parts\": [\n {\n \"\ id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n \ \ }\n ],\n \"isComplexFilter\": true\n }\n }\n ]\n\ \ },\n {\n \"language\": \"en\",\n \"id\": \"9SoZXMyUC2YuPYM5lOZapZAqx/84/0Bi+Qgx7L3rclM=_186099a7824:d77052:6d2d67a6\"\ ,\n \"createdBy\": {\n \"userAgent\": \"Mozilla/5.0 (Windows NT 10.0; Win64;\ \ x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36\",\n\ \ \"application\": \"feedly\"\n },\n \"origin\": {\n \"title\": \"\ The Cyber Express\",\n \"streamId\": \"feed/https://thecyberexpress.com/feed/\"\ ,\n \"htmlUrl\": \"https://thecyberexpress.com\"\n },\n \"content\": {\n\ \ \"content\": \"
\\n

A BreachForums user under the alias IntelBroker\ \ claims to have posted the customer data of Verizon Communications on the forum.\ \ The threat actor has claimed to have access to a database of 7.5 million Verizon\ \ customer records. Verizon has verified the data on the request from The Cyber Express.

\\\ n

According to their initial review of this matter, the data appears\ \ to be obtained approximately two weeks ago when a Verizon vendor experienced a security\ \ breach, Verizon spokesperson Richard Young told The Cyber Express.

\\\ n

“This vendor creates videos for Verizon to assist customers with billing-related\ \ questions. The vendor had access to customer first names, device types, and service\ \ plans. The vendor did not have access to Social Security numbers, credit card numbers, or other personally\ \ identifiable customer information,” Young said.

\\n

We have severed this vendor’s\ \ access to our systems and suspended use of their services. Our review of this\ \ matter continues.”

\\n

Commonly known as Verizon, the American\ \ multinational telecommunications conglomerate is a corporate component of the Dow\ \ Jones Industrial Average. According to Statista, Verizon has a retail customer\ \ base of approximately 143 million subscribers in 2021.

\\n

“In January 2023,\ \ a database of 7.5 million customers belonging to the Verizon was stolen by hackers,”\ \ claimed the post by IntelBroker. A sample of the hashed data posted indicates mobile and online subscription details.

\\n

The\ \ post, made on Friday, had the link to download the entire data tranche. IntelBroker’s\ \ present avatar has been active on the forum since October 2022. Its previous targets\ \ include Autotrader, Volvo, Hilton Hotels, and AT&T.

\\n

\\\"\\\"

\\n

Verizon and data breaches

\\n

Independent researchers\ \ were analysing the sample data at the time of publishing this report. If the tranche turns out to be\ \ authentic, this would be the company’s second major data breach in the past 12 months.

\\n

Verizon in May 2022 confirmed a\ \ data breach where the full names, email addresses, corporate ID numbers, and phone\ \ numbers of Verizon employees were compromised. According to a report from Motherboard, the data was shared with the\ \ publication by the hacker who reached out to them.

\\n

The company popped up\ \ in cybersecurity news over a data\ \ breach five years before that.

\\n

In 2017, the telecommunication company conceded that the personal data of 6 million customers\ \ had been leaked online. The leak was caused by a misconfigured security setting on a cloud server, which was the result of “human error.

\\\ n

The data, which included customer phone numbers, names, and some PIN codes, was publicly available online due\ \ to a mistake made by NICE Systems, an Israel-based company that Verizon was working\ \ with to facilitate customer service calls.

\\n

The data of telecommunication users was collected over a period of six months,\ \ and Verizon closed the security hole on June 22.

\\n
Update: The article was updated on January 27, 2023, with confirmations,\ \ and analysis from Verizon.
\\n
\",\n \"\ direction\": \"ltr\"\n },\n \"title\": \"Verizon Investigates Customer Data\ \ Breach, Says No PII Compromised\",\n \"author\": \"Editorial\",\n \"crawled\"\ : 1675198363684,\n \"published\": 1675198363684,\n \"updated\": 1675198363684,\n\ \ \"alternate\": [\n {\n \"href\": \"https://thecyberexpress.com/verizon-customer-data-for-sale-on-dark-web/\"\ \n }\n ],\n \"canonical\": [\n {\n \"type\": \"text/html\"\ ,\n \"href\": \"https://thecyberexpress.com/verizon-customer-data-for-sale-on-dark-web/\"\ \n }\n ],\n \"visual\": {\n \"width\": 746,\n \"processor\":\ \ \"feedly-nikon-v3.1\",\n \"url\": \"https://i0.wp.com/thecyberexpress.com/wp-content/uploads/2023/01/verison.jpg?resize=746%2C373&is-pending-load=1#038;ssl=1\"\ ,\n \"height\": 373,\n \"contentType\": \"image/jpeg\"\n },\n \"canonicalUrl\"\ : \"https://thecyberexpress.com/verizon-customer-data-for-sale-on-dark-web/\",\n \ \ \"unread\": false,\n \"commonTopics\": [\n {\n \"type\": \"topic\"\ ,\n \"id\": \"nlp/f/topic/3003\",\n \"label\": \"Cyber Security\",\n\ \ \"score\": 1,\n \"causes\": [\n {\n \"id\": \"\ nlp/f/topic/4009\",\n \"label\": \"Cyber Attacks\"\n }\n \ \ ],\n \"salienceLevel\": \"about\"\n },\n {\n \"type\"\ : \"cyberEvent\",\n \"targets\": [\n {\n \"text\": \"Verizon\ \ Communications\",\n \"id\": \"nlp/f/entity/gz:org:verizon\",\n \ \ \"confidence\": 0.9280639886856079\n }\n ],\n \"id\"\ : \"nlp/f/topic/4009\",\n \"label\": \"Cyber Attacks\",\n \"score\"\ : 0.998,\n \"salienceLevel\": \"about\"\n },\n {\n \"type\"\ : \"technology\",\n \"id\": \"nlp/f/topic/2256\",\n \"label\": \"Tech\"\ ,\n \"score\": 0.692,\n \"salienceLevel\": \"about\"\n },\n \ \ {\n \"type\": \"topic\",\n \"id\": \"nlp/f/topic/603\",\n \ \ \"label\": \"Cyber Crime\",\n \"score\": 0.931,\n \"salienceLevel\"\ : \"about\"\n },\n {\n \"type\": \"topic\",\n \"id\": \"nlp/f/topic/1025\"\ ,\n \"label\": \"Hacking\",\n \"score\": 0.97,\n \"salienceLevel\"\ : \"about\"\n },\n {\n \"type\": \"topic\",\n \"id\": \"nlp/f/topic/4004\"\ ,\n \"label\": \"Data Breach\",\n \"score\": 0.997,\n \"salienceLevel\"\ : \"about\"\n },\n {\n \"type\": \"industryTopic\",\n \"id\"\ : \"nlp/f/topic/4027\",\n \"label\": \"Telecom Industry\",\n \"score\"\ : 1,\n \"salienceLevel\": \"about\"\n }\n ],\n \"entities\": [\n\ \ {\n \"disambiguated\": true,\n \"type\": \"org\",\n \"\ id\": \"nlp/f/entity/gz:org:verizon\",\n \"label\": \"Verizon\",\n \"\ salienceLevel\": \"about\",\n \"mentions\": [\n {\n \"\ text\": \"Verizon Communications\"\n },\n {\n \"text\"\ : \"Verizon\"\n }\n ]\n },\n {\n \"disambiguated\"\ : true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:at-t\"\ ,\n \"label\": \"AT&T\",\n \"salienceLevel\": \"mention\",\n \ \ \"mentions\": [\n {\n \"text\": \"AT&T\"\n }\n \ \ ]\n },\n {\n \"disambiguated\": true,\n \"type\": \"\ org\",\n \"id\": \"nlp/f/entity/gz:org:hilton-worldwide\",\n \"label\"\ : \"Hilton Worldwide\",\n \"salienceLevel\": \"mention\",\n \"mentions\"\ : [\n {\n \"text\": \"Hilton Hotels\"\n }\n ]\n\ \ },\n {\n \"disambiguated\": true,\n \"type\": \"org\",\n\ \ \"id\": \"nlp/f/entity/gz:org:travel-and-hospitality-industry-companies\"\ ,\n \"label\": \"Travel & Hospitality Companies\",\n \"causes\": [\n\ \ {\n \"id\": \"nlp/f/entity/gz:org:hilton-worldwide\",\n \ \ \"label\": \"Hilton Worldwide\"\n }\n ],\n \"salienceLevel\"\ : \"mention\",\n \"mentions\": []\n },\n {\n \"disambiguated\"\ : true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:telecom-industry-companies\"\ ,\n \"label\": \"Telecom Companies\",\n \"causes\": [\n {\n\ \ \"id\": \"nlp/f/entity/gz:org:verizon\",\n \"label\": \"Verizon\"\ \n },\n {\n \"id\": \"nlp/f/entity/gz:org:at-t\",\n \ \ \"label\": \"AT&T\"\n }\n ],\n \"salienceLevel\"\ : \"about\",\n \"mentions\": []\n },\n {\n \"disambiguated\"\ : true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:fortune-500-companies\"\ ,\n \"label\": \"Fortune 500 Companies\",\n \"causes\": [\n \ \ {\n \"id\": \"nlp/f/entity/gz:org:verizon\",\n \"label\"\ : \"Verizon\"\n },\n {\n \"id\": \"nlp/f/entity/gz:org:at-t\"\ ,\n \"label\": \"AT&T\"\n }\n ],\n \"salienceLevel\"\ : \"about\",\n \"mentions\": []\n }\n ],\n \"leoSummary\": {\n \ \ \"sentences\": [\n {\n \"text\": \"According to their initial\ \ review of this matter, the data appears to be obtained approximately two weeks ago\ \ when a Verizon vendor experienced a security breach, Verizon spokesperson Richard\ \ Young told The Cyber Express.\"\n },\n {\n \"text\": \"A\ \ BreachForums user under the alias IntelBroker claims to have posted the customer\ \ data of Verizon Communications on the forum.\"\n }\n ]\n },\n \ \ \"indicatorsOfCompromise\": {\n \"exports\": [],\n \"mentions\": []\n\ \ }\n }\n]" schema: type: array items: type: object properties: fingerprint: type: string example: c392b42 id: type: string example: UybWZO8Gre9MphC4ZSsEQwKCOEGrCNXcYdJXbwlpiMI=_19a0d0d8f78:497f7ef:752f71fa language: type: string example: en originId: type: string example: https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/ origin: type: object properties: streamId: type: string example: feed/https://detection.fyi/index.xml title: type: string example: Detection.FYI htmlUrl: type: string example: https://detection.fyi/ title: type: string example: AWS ConsoleLogin Failed Authentication published: type: integer example: 1761136602000 default: 0 crawled: type: integer example: 1761155583864 default: 0 summary: type: object properties: content: type: string example: Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts. direction: type: string example: ltr alternate: type: array items: type: object properties: href: type: string example: https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/ type: type: string example: text/html canonicalUrl: type: string example: https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication/ snippet: type: string example: '

Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.

 1title:
                        AWS ConsoleLogin Failed Authentication

                         2id:
                        6393e346-1977-46ef-8987-ad414a145fad

                         3
' originContentType: type: string example: text/html fullContent: type: string example: '

Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.

 1title:
                        AWS ConsoleLogin Failed Authentication

                         2id:
                        6393e346-1977-46ef-8987-ad414a145fad

                         3status:
                        experimental

                         4description:
                        |

                         5  Detects
                        failed AWS console login attempts due to authentication failures. Monitoring these
                        events is crucial for identifying potential brute-force attacks or unauthorized
                        access attempts to AWS accounts.

                         6references:

                         7 - https://naikordian.github.io/blog/posts/brute-force-aws-console/

                         8 - https://help.fortinet.com/fsiem/Public_Resource_Access/7_2_1/rules/PH_RULE_AWS_Management_Console_Brute_Force_of_Root_User_Identity.htm

                         9 - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/aws_login_failure/aws_cloudtrail_events.json

                        10author:
                        Ivan Saakov, Nasreddine Bencherchali

                        11date:
                        2025-10-19

                        12tags:

                        13 - attack.credential-access

                        14 - attack.t1110

                        15logsource:

                        16 product:
                        aws

                        17 service:
                        cloudtrail

                        18detection:

                        19 selection:

                        20 eventName:
                        ''ConsoleLogin''

                        21 errorMessage:
                        ''Failed authentication''

                        22 condition:
                        selection

                        23falsepositives:

                        24 - Legitimate
                        failed login attempts by authorized users. Investigate the source of repeated
                        failed login attempts.

                        25level:
                        medium

                        
' unread: type: boolean example: true default: true categories: type: array items: type: object properties: id: type: string example: enterprise/christeam/category/a1b9d077-7806-4b29-8f1c-d17ebc172ea3 label: type: string example: 'AI: Ad-Hoc Research' commonTopics: type: array items: type: object properties: type: type: string example: detectionRule label: type: string example: Sigma rules id: type: string example: nlp/f/topic/7010 score: type: integer example: 1 default: 0 salienceLevel: type: string example: about entities: type: array items: type: object properties: type: type: string example: org disambiguated: type: boolean example: true default: true label: type: string example: Amazon Web Services id: type: string example: nlp/f/entity/gz:org:amazon-web-services mentions: type: array items: type: object properties: text: type: string example: AWS salienceLevel: type: string example: about leoSummary: type: object properties: sentences: type: array items: type: object properties: {} indicatorsOfCompromise: type: object properties: mentions: type: array items: type: object properties: {} exports: type: array items: type: object properties: {} sigmaRules: type: object properties: count: type: integer example: 1 default: 0 url: type: string example: https://exports.feedly.com/sigma/sigma-342359ad452d13341f73665ef05c1f60.yaml attackNavigator: type: object properties: url: type: string example: https://exports.feedly.com/attacks/a322aeb98ff575dbc66b638386190651/feedly-ai-aws-consolelogin-failed-authentication.json ttpCount: type: integer example: 1 default: 0 sources: type: array items: type: object properties: streamId: type: string example: feed/https://feedly.com/f/alert/278c354e-67ae-4509-b708-a354b8a41f9c title: type: string example: Detection rules feedlyFeedType: type: string example: WebAlert searchTerms: type: object properties: parts: type: array items: type: object properties: id: type: string example: nlp/f/topic/7010 label: type: string example: Sigma rules isComplexFilter: type: boolean example: true default: true '400': description: '400' content: application/json: examples: Result: value: '{}' schema: type: object properties: {} deprecated: false x-readme: headers: [] explorer-enabled: true proxy-enabled: true x-readme-fauxas: true