openapi: 3.2.0 info: title: Palo Alto Networks Custom Rules API version: '1.0' description: 'Operations tagged Custom-Rules across 4 of this provider''s published API definitions: palo-alto-compute-34-03-openapi-34-03-138-sh-openapi.json, palo-alto-compute-openapi-34-04-145-sh-openapi.json, palo-alto-cwpp-34-03-openapi-34-03-138-saas-openapi.json, palo-alto-cwpp-openapi-34-04-145-saas-openapi.json. Each path carries the servers of the definition it was published in.' servers: - url: PATH_TO_CONSOLE tags: - name: Custom-Rules description: Custom-Rules. 3 operations in this definition. x-description-source: desc/custom-rules/custom-rules.md paths: /api/v34.03/custom-rules: get: description: 'Get Custom Rules. GET /api/v34.03/custom-rules on the Custom-Rules API. Documented responses: 200.' responses: '200': content: application/json: schema: $ref: '#/components/schemas/-_customrules.Rule' description: '' default: description: '' tags: - Custom-Rules x-prisma-cloud-target-env: permission: policyCustomRules operationId: get-custom-rules summary: Get Custom Rules x-description-source: desc/custom-rules/get.md /api/v34.03/custom-rules/{id}: delete: description: 'Delete a Custom Rule. DELETE /api/v34.03/custom-rules/{id} on the Custom-Rules API. Takes 1 path parameter. Documented responses: 200.' parameters: - in: path name: id required: true schema: type: string responses: '200': description: OK default: description: '' tags: - Custom-Rules x-prisma-cloud-target-env: permission: policyCustomRules operationId: delete-custom-rules-id summary: Delete a Custom Rule x-description-source: desc/custom-rules/id_delete.md put: description: 'Update a Custom Rule. PUT /api/v34.03/custom-rules/{id} on the Custom-Rules API. Takes 1 path parameter, an optional request body. Documented responses: 200.' parameters: - in: path name: id required: true schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/customrules.Rule' responses: '200': description: OK default: description: '' tags: - Custom-Rules x-prisma-cloud-target-env: permission: policyCustomRules operationId: put-custom-rules-id summary: Update a Custom Rule x-description-source: desc/custom-rules/id_put.md /api/v34.04/custom-rules: get: description: 'Get Custom Rules. GET /api/v34.04/custom-rules on the Custom-Rules API. Documented responses: 200.' responses: '200': content: application/json: schema: $ref: '#/components/schemas/-_customrules.Rule' description: '' default: description: '' tags: - Custom-Rules x-prisma-cloud-target-env: permission: policyCustomRules operationId: get-custom-rules summary: Get Custom Rules x-description-source: desc/custom-rules/get.md /api/v34.04/custom-rules/{id}: delete: description: 'Delete a Custom Rule. DELETE /api/v34.04/custom-rules/{id} on the Custom-Rules API. Takes 1 path parameter. Documented responses: 200.' parameters: - in: path name: id required: true schema: type: string responses: '200': description: OK default: description: '' tags: - Custom-Rules x-prisma-cloud-target-env: permission: policyCustomRules operationId: delete-custom-rules-id summary: Delete a Custom Rule x-description-source: desc/custom-rules/id_delete.md put: description: 'Update a Custom Rule. PUT /api/v34.04/custom-rules/{id} on the Custom-Rules API. Takes 1 path parameter, an optional request body. Documented responses: 200.' parameters: - in: path name: id required: true schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/customrules.Rule' responses: '200': description: OK default: description: '' tags: - Custom-Rules x-prisma-cloud-target-env: permission: policyCustomRules operationId: put-custom-rules-id summary: Update a Custom Rule x-description-source: desc/custom-rules/id_put.md components: schemas: mitre.Technique: description: Technique is the MITRE framework attack technique enum: - - exploitationForPrivilegeEscalation - exploitPublicFacingApplication - applicationExploitRCE - networkServiceScanning - endpointDenialOfService - exfiltrationGeneral - systemNetworkConfigurationDiscovery - unsecuredCredentials - credentialDumping - systemInformationDiscovery - systemNetworkConnectionDiscovery - systemUserDiscovery - accountDiscovery - cloudInstanceMetadataAPI - accessKubeletMainAPI - queryKubeletReadonlyAPI - accessKubernetesAPIServer - softwareDeploymentTools - ingressToolTransfer - lateralToolTransfer - commandAndControlGeneral - resourceHijacking - manInTheMiddle - nativeBinaryExecution - foreignBinaryExecution - createAccount - accountManipulation - abuseElevationControlMechanisms - supplyChainCompromise - obfuscatedFiles - hijackExecutionFlow - impairDefences - scheduledTaskJob - exploitationOfRemoteServices - eventTriggeredExecution - accountAccessRemoval - privilegedContainer - writableVolumes - execIntoContainer - softwareDiscovery - createContainer - kubernetesSecrets - fileAndDirectoryDiscovery - masquerading - webShell - compileAfterDelivery type: string customrules.Rule: description: Rule represents a custom rule properties: _id: description: 'Rule ID. Must be unique. ' type: integer attackTechniques: description: 'List of attack techniques. ' items: $ref: '#/components/schemas/mitre.Technique' type: array description: description: 'Description of the rule. ' type: string message: description: 'Macro that is printed as part of the audit/incident message. ' type: string minVersion: description: 'Minimum version required to support the rule. ' type: string modified: description: 'Datetime when the rule was created or last modified. ' format: int64 type: integer name: description: 'Name of the rule. ' type: string owner: description: 'User who created or modified the rule. ' type: string script: description: 'Custom script. ' type: string type: $ref: '#/components/schemas/customrules.Type' vulnIDs: $ref: '#/components/schemas/customrules.VulnIDs' type: object string: type: string -_customrules.Rule: items: $ref: '#/components/schemas/customrules.Rule' type: array customrules.VulnIDs: description: VulnIDs is the list of vulnerability IDs items: $ref: '#/components/schemas/string' type: array customrules.Type: description: Type is the type of the custom rule enum: - - processes - filesystem - network-outgoing - kubernetes-audit - waas-request - waas-response type: string x-refined-from: - palo-alto-compute-34-03-openapi-34-03-138-sh-openapi.json - palo-alto-compute-openapi-34-04-145-sh-openapi.json - palo-alto-cwpp-34-03-openapi-34-03-138-saas-openapi.json - palo-alto-cwpp-openapi-34-04-145-saas-openapi.json