APINHI

List NHI findings

List findings across the org's directories. Without `status`, every finding except resolved ones is returned.

GET
/nhi/findings

List findings across the org's directories. Without status, every finding except resolved ones is returned.

Authorization

ApiKeyAuth
headerAuthorizationBearer <token>

Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.

Required permission

view_nhi

Query Parameters

offset?integer

Number of items to skip before returning results.

Formatint32
Range0 <= value
Default0
limit?integer

Maximum number of items to return per page.

Formatint32
Range0 <= value <= 256
Default10
source_id?string
Formatuuid
external_id?string

Only findings about this directory object.

status?array<>
severity?array<>
rule?array<>
sort?string
Default"severity"
Value in"severity""recent"
sort_order?string

Direction to sort results.

Default"desc"
Value in"asc""desc"

Response Body

The request has succeeded.

application/json
  1. response

A page of results together with its paging information.

items*array<>

The items in this page.

meta*

Paging information for a list response.

curl -X GET "https://example.com/nhi/findings"
{  "items": [    {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "source_id": "ae50a35c-df42-4eff-ba26-f8bc28d2af81",      "rule": "secret_never_expires",      "severity": "low",      "kind": "application",      "external_id": "string",      "display_name": "string",      "first_seen_at": "2019-08-24T14:15:22Z",      "last_seen_at": "2019-08-24T14:15:22Z",      "status": "open",      "status_changed_at": "2019-08-24T14:15:22Z",      "evidence": {        "provider": "microsoft_entra",        "credentials": [          {            "key_id": "string",            "display_name": "string",            "type": "password",            "expires_at": "2019-08-24T14:15:22Z",            "years_out": 0          }        ],        "principal": {          "object_id": "string",          "account_enabled": true        },        "audience": {          "sign_in_audience": "string"        },        "sprawl": {          "count": 0,          "window_days": 0,          "threshold": 0        },        "orphan": {          "age_days": 0,          "grace_days": 0        }      }    }  ],  "meta": {    "total": 0,    "offset": 0,    "limit": 0  }}