# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Threat Prevention API version: 1.0.0 extends: openapi/palo-alto-networks-threat-prevention-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 8 - target: $.paths['/threats/cve-coverage'].get update: x-apievangelist-phrasing: intent: Check threat coverage for a CVE effect: read questions: - Does Palo Alto Networks threat prevention cover a specific CVE? - Which signatures protect against a given CVE ID? instructions: - text: Check coverage for CVE {cve_id}. slots: cve_id: query.cve_id - text: Show which protections exist for {cve_id}. slots: cve_id: query.cve_id method: generated generated: '2026-09-26' - target: $.paths['/release-notes'].get update: x-apievangelist-phrasing: intent: Get content release notes effect: read questions: - What changed in a particular content release version? - Are release notes available for content versions older than 8000? instructions: - text: Get release notes for {type} version {version}. slots: type: query.type version: query.version - text: Show the content release notes of type {type} for version {version}. slots: type: query.type version: query.version method: generated generated: '2026-09-26' - target: $.paths['/threats'].get update: x-apievangelist-phrasing: intent: Look up threat signatures effect: read questions: - Which Threat Vault signatures cover a given CVE? - Can I find signatures linked to a file's SHA-256 hash? - What antivirus signatures were released between two dates? instructions: - text: Find threat signatures for CVE {cve}. slots: cve: query.cve - text: Look up signatures matching hash {sha256}. slots: sha256: query.sha256 - text: List {type} signatures released from {fromReleaseDate} to {toReleaseDate}. slots: type: query.type fromReleaseDate: query.fromReleaseDate toReleaseDate: query.toReleaseDate method: generated generated: '2026-10-01' - target: $.paths['/threats'].post update: x-apievangelist-phrasing: intent: Batch look up threat signatures effect: read questions: - Can I look up up to 100 threat signatures at once by id or hash? - What's the batch limit when querying signature metadata by name? instructions: - text: Batch look up threat signatures with ids {id}. slots: id: requestBody.id - text: Get signature metadata in bulk for sample hashes {sha256}. slots: sha256: requestBody.sha256 method: generated generated: '2026-09-26' - target: $.paths['/threats/history'].get update: x-apievangelist-phrasing: intent: Get a signature's release history effect: read questions: - When was a threat signature first released and modified? - How far back does antivirus signature release history go? instructions: - text: Show the release history of signature {id} for package {type}. slots: id: query.id type: query.type - text: Get the {type} release history of threat {id} in {order} order. slots: type: query.type id: query.id order: query.order method: generated generated: '2026-09-26' - target: $.paths['/edl'].get update: x-apievangelist-phrasing: intent: Get predefined external dynamic list content effect: read questions: - What IPs are in a predefined external dynamic list? - Is a specific IP address included in a Palo Alto Networks predefined EDL? instructions: - text: Get the contents of predefined EDL {name}. slots: name: query.name - text: Check whether {ipaddr} is in EDL {name}. slots: ipaddr: query.ipaddr name: query.name method: generated generated: '2026-09-26' - target: $.paths['/ip-feed'].get update: x-apievangelist-phrasing: intent: Look up IP feed information effect: read questions: - Which IP feed is an address listed in? - Can I search the IP feed for a range of addresses? instructions: - text: Look up IP feed information for {ipaddr}. slots: ipaddr: query.ipaddr - text: Search the IP feed from {fromipaddr} to {toipaddr}. slots: fromipaddr: query.fromipaddr toipaddr: query.toipaddr method: generated generated: '2026-09-26' - target: $.paths['/ip-feed'].post update: x-apievangelist-phrasing: intent: Batch look up IP feed entries effect: read questions: - Can I check up to 100 IP addresses against the IP feed in one request? - What is the batch limit for IP feed lookups? instructions: - text: Batch check IP addresses {ipaddr} against the IP feed. slots: ipaddr: requestBody.ipaddr - text: Look up IP feed entries in bulk for {ipaddr}. slots: ipaddr: requestBody.ipaddr method: generated generated: '2026-09-26'