# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Threat Vault ATP API version: 1.0.0 extends: openapi/palo-alto-networks-atp-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 2 - target: $.paths['/atp/reports'].get update: x-apievangelist-phrasing: intent: Get Advanced Threat Prevention analysis reports effect: read questions: - What did inline cloud analysis find about a threat with a given SHA-256 hash? - Can I pull the indicators of compromise from an ATP report? instructions: - text: Get the ATP report for hash {sha256}. slots: sha256: query.sha256 - text: Show ATP analysis report {id}. slots: id: query.id method: generated generated: '2026-09-26' - target: $.paths['/atp/reports/pcaps'].get update: x-apievangelist-phrasing: intent: Download packet captures for an ATP report effect: read questions: - How do I download the PCAP recorded during a threat's analysis? - Is there network traffic I can inspect for an ATP threat sample? instructions: - text: Download the PCAP files for sample {sha256}. slots: sha256: query.sha256 - text: Get packet captures for hash {sha256} from ATP report {id}. slots: sha256: query.sha256 id: query.id method: generated generated: '2026-09-26'