# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Endpoints API version: 1.0.0 extends: openapi/palo-alto-networks-endpoints-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 4 - target: $.paths['/endpoints/get_endpoints'].post update: x-apievangelist-phrasing: intent: List enrolled endpoints effect: read questions: - Which endpoints are enrolled in Cortex XDR? - Can I filter endpoints by hostname, IP or protection status? instructions: - text: List endpoints matching {request_data}. slots: request_data: requestBody.request_data - text: Show all enrolled XDR endpoints. method: generated generated: '2026-09-26' - target: $.paths['/endpoints/isolate'].post update: x-apievangelist-phrasing: intent: Isolate endpoints from the network effect: write questions: - How do I cut a compromised laptop off from the network? - Can isolated endpoints still talk to the XDR service? instructions: - text: Isolate endpoints {request_data}. slots: request_data: requestBody.request_data - text: Quarantine the host {request_data} from the network during investigation. slots: request_data: requestBody.request_data method: generated generated: '2026-09-26' - target: $.paths['/endpoints/unisolate'].post update: x-apievangelist-phrasing: intent: Release endpoints from isolation effect: write questions: - How do I restore network access to an endpoint after an investigation? - Can I un-isolate several endpoints at once? instructions: - text: Unisolate endpoints {request_data}. slots: request_data: requestBody.request_data - text: Restore network connectivity for isolated host {request_data}. slots: request_data: requestBody.request_data method: generated generated: '2026-09-26' - target: $.paths['/endpoints/scan'].post update: x-apievangelist-phrasing: intent: Run a malware scan on endpoints effect: write questions: - Can I trigger a malware scan on specific endpoints? - What does the endpoint scan do with malicious files it finds? instructions: - text: Scan endpoints {request_data} for malware. slots: request_data: requestBody.request_data - text: Run a local-analysis malware scan on {request_data}. slots: request_data: requestBody.request_data method: generated generated: '2026-09-26'