curl --request POST \
--url https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation \
--header 'Content-Type: application/json' \
--data '
{
"comment": "<string>",
"classification_reason_comment": "<string>",
"malicious_score": 123,
"classification_sop": {
"id": "<string>",
"name": "<string>"
},
"response_sops": [
{
"id": "<string>",
"name": "<string>"
}
],
"gamebook_ids": [
"<string>"
],
"tool_calls": [
{
"name": "<string>",
"time": "2023-11-07T05:31:56Z",
"duration_ms": 123,
"target_entity": "<string>",
"kql": {
"query": "<string>",
"row_count": 123
}
}
]
}
'import requests
url = "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation"
payload = {
"comment": "<string>",
"classification_reason_comment": "<string>",
"malicious_score": 123,
"classification_sop": {
"id": "<string>",
"name": "<string>"
},
"response_sops": [
{
"id": "<string>",
"name": "<string>"
}
],
"gamebook_ids": ["<string>"],
"tool_calls": [
{
"name": "<string>",
"time": "2023-11-07T05:31:56Z",
"duration_ms": 123,
"target_entity": "<string>",
"kql": {
"query": "<string>",
"row_count": 123
}
}
]
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
comment: '<string>',
classification_reason_comment: '<string>',
malicious_score: 123,
classification_sop: {id: '<string>', name: '<string>'},
response_sops: [{id: '<string>', name: '<string>'}],
gamebook_ids: ['<string>'],
tool_calls: [
{
name: '<string>',
time: '2023-11-07T05:31:56Z',
duration_ms: 123,
target_entity: '<string>',
kql: {query: '<string>', row_count: 123}
}
]
})
};
fetch('https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'comment' => '<string>',
'classification_reason_comment' => '<string>',
'malicious_score' => 123,
'classification_sop' => [
'id' => '<string>',
'name' => '<string>'
],
'response_sops' => [
[
'id' => '<string>',
'name' => '<string>'
]
],
'gamebook_ids' => [
'<string>'
],
'tool_calls' => [
[
'name' => '<string>',
'time' => '2023-11-07T05:31:56Z',
'duration_ms' => 123,
'target_entity' => '<string>',
'kql' => [
'query' => '<string>',
'row_count' => 123
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation"
payload := strings.NewReader("{\n \"comment\": \"<string>\",\n \"classification_reason_comment\": \"<string>\",\n \"malicious_score\": 123,\n \"classification_sop\": {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n },\n \"response_sops\": [\n {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n }\n ],\n \"gamebook_ids\": [\n \"<string>\"\n ],\n \"tool_calls\": [\n {\n \"name\": \"<string>\",\n \"time\": \"2023-11-07T05:31:56Z\",\n \"duration_ms\": 123,\n \"target_entity\": \"<string>\",\n \"kql\": {\n \"query\": \"<string>\",\n \"row_count\": 123\n }\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation")
.header("Content-Type", "application/json")
.body("{\n \"comment\": \"<string>\",\n \"classification_reason_comment\": \"<string>\",\n \"malicious_score\": 123,\n \"classification_sop\": {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n },\n \"response_sops\": [\n {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n }\n ],\n \"gamebook_ids\": [\n \"<string>\"\n ],\n \"tool_calls\": [\n {\n \"name\": \"<string>\",\n \"time\": \"2023-11-07T05:31:56Z\",\n \"duration_ms\": 123,\n \"target_entity\": \"<string>\",\n \"kql\": {\n \"query\": \"<string>\",\n \"row_count\": 123\n }\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"comment\": \"<string>\",\n \"classification_reason_comment\": \"<string>\",\n \"malicious_score\": 123,\n \"classification_sop\": {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n },\n \"response_sops\": [\n {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n }\n ],\n \"gamebook_ids\": [\n \"<string>\"\n ],\n \"tool_calls\": [\n {\n \"name\": \"<string>\",\n \"time\": \"2023-11-07T05:31:56Z\",\n \"duration_ms\": 123,\n \"target_entity\": \"<string>\",\n \"kql\": {\n \"query\": \"<string>\",\n \"row_count\": 123\n }\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"success": true,
"summary": "<string>",
"previous_status": "<string>",
"new_status": "<string>",
"applied_classification": "<string>",
"applied_classification_reason": "<string>",
"comment_posted": true,
"status_updated": true
},
"meta": {
"requestId": "<string>",
"timestamp": "<string>"
}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}Agent tool submit investigation
curl --request POST \
--url https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation \
--header 'Content-Type: application/json' \
--data '
{
"comment": "<string>",
"classification_reason_comment": "<string>",
"malicious_score": 123,
"classification_sop": {
"id": "<string>",
"name": "<string>"
},
"response_sops": [
{
"id": "<string>",
"name": "<string>"
}
],
"gamebook_ids": [
"<string>"
],
"tool_calls": [
{
"name": "<string>",
"time": "2023-11-07T05:31:56Z",
"duration_ms": 123,
"target_entity": "<string>",
"kql": {
"query": "<string>",
"row_count": 123
}
}
]
}
'import requests
url = "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation"
payload = {
"comment": "<string>",
"classification_reason_comment": "<string>",
"malicious_score": 123,
"classification_sop": {
"id": "<string>",
"name": "<string>"
},
"response_sops": [
{
"id": "<string>",
"name": "<string>"
}
],
"gamebook_ids": ["<string>"],
"tool_calls": [
{
"name": "<string>",
"time": "2023-11-07T05:31:56Z",
"duration_ms": 123,
"target_entity": "<string>",
"kql": {
"query": "<string>",
"row_count": 123
}
}
]
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
comment: '<string>',
classification_reason_comment: '<string>',
malicious_score: 123,
classification_sop: {id: '<string>', name: '<string>'},
response_sops: [{id: '<string>', name: '<string>'}],
gamebook_ids: ['<string>'],
tool_calls: [
{
name: '<string>',
time: '2023-11-07T05:31:56Z',
duration_ms: 123,
target_entity: '<string>',
kql: {query: '<string>', row_count: 123}
}
]
})
};
fetch('https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'comment' => '<string>',
'classification_reason_comment' => '<string>',
'malicious_score' => 123,
'classification_sop' => [
'id' => '<string>',
'name' => '<string>'
],
'response_sops' => [
[
'id' => '<string>',
'name' => '<string>'
]
],
'gamebook_ids' => [
'<string>'
],
'tool_calls' => [
[
'name' => '<string>',
'time' => '2023-11-07T05:31:56Z',
'duration_ms' => 123,
'target_entity' => '<string>',
'kql' => [
'query' => '<string>',
'row_count' => 123
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation"
payload := strings.NewReader("{\n \"comment\": \"<string>\",\n \"classification_reason_comment\": \"<string>\",\n \"malicious_score\": 123,\n \"classification_sop\": {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n },\n \"response_sops\": [\n {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n }\n ],\n \"gamebook_ids\": [\n \"<string>\"\n ],\n \"tool_calls\": [\n {\n \"name\": \"<string>\",\n \"time\": \"2023-11-07T05:31:56Z\",\n \"duration_ms\": 123,\n \"target_entity\": \"<string>\",\n \"kql\": {\n \"query\": \"<string>\",\n \"row_count\": 123\n }\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation")
.header("Content-Type", "application/json")
.body("{\n \"comment\": \"<string>\",\n \"classification_reason_comment\": \"<string>\",\n \"malicious_score\": 123,\n \"classification_sop\": {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n },\n \"response_sops\": [\n {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n }\n ],\n \"gamebook_ids\": [\n \"<string>\"\n ],\n \"tool_calls\": [\n {\n \"name\": \"<string>\",\n \"time\": \"2023-11-07T05:31:56Z\",\n \"duration_ms\": 123,\n \"target_entity\": \"<string>\",\n \"kql\": {\n \"query\": \"<string>\",\n \"row_count\": 123\n }\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/incidents/{source}/{incidentId}/investigation")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"comment\": \"<string>\",\n \"classification_reason_comment\": \"<string>\",\n \"malicious_score\": 123,\n \"classification_sop\": {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n },\n \"response_sops\": [\n {\n \"id\": \"<string>\",\n \"name\": \"<string>\"\n }\n ],\n \"gamebook_ids\": [\n \"<string>\"\n ],\n \"tool_calls\": [\n {\n \"name\": \"<string>\",\n \"time\": \"2023-11-07T05:31:56Z\",\n \"duration_ms\": 123,\n \"target_entity\": \"<string>\",\n \"kql\": {\n \"query\": \"<string>\",\n \"row_count\": 123\n }\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"success": true,
"summary": "<string>",
"previous_status": "<string>",
"new_status": "<string>",
"applied_classification": "<string>",
"applied_classification_reason": "<string>",
"comment_posted": true,
"status_updated": true
},
"meta": {
"requestId": "<string>",
"timestamp": "<string>"
}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}Path Parameters
Sentinel, DefenderXDR, QRadar, Splunk, CrowdStrike, SentinelOne, SumoLogic Body
Request DTO for the agent's submit-investigation tool — the closeout call the agent makes after it has finished investigating an incident.
Final investigation summary. Posted on the incident as the agent's comment as-is — no server-side wrapping or section headers are applied. Write as a detailed security analyst would: cover initial hypothesis, indicators matched, tools called and why, evidence found, classification rationale, response actions, and recommended next steps. This is what a human analyst will read to learn from the agent's analysis.
Short rationale (1–2 sentences) shown on the incident's closure record when the status transition closes the incident. Surfaces in the closure dialog and audit log alongside the classification reason.
How malicious the agent judged the activity, 0 to 100, where 0 is clearly benign and 100 is clearly malicious. This is not confidence in the verdict: a False Positive the agent is certain about scores near zero, not near a hundred.
Final incident classification, identical for every security platform. Allowed values: TruePositive (confirmed malicious), FalsePositive (the detection was wrong; no suspicious activity occurred), BenignPositive (real activity confirmed benign, expected, or authorized), Undetermined (no firm verdict reached). Status transition follows from this via the per-severity agent settings.
BenignPositive, FalsePositive, TruePositive, Undetermined, null Reason corresponding to the classification; required on every classified closeout and identical for every security platform. TruePositive → MultistagedAttack | Malware | MaliciousUserActivity | UnwantedSoftware | Phishing | CompromisedUser | Apt | SuspiciousActivity | Other. FalsePositive → NotMalicious | NoEnoughDataToValidate | InaccurateData | IncorrectAlertLogic | Other. BenignPositive → SecurityTesting | ConfirmedUserActivity | LineOfBusinessApplication | SecurityPersonnel | SuspiciousButExpected | Other. Undetermined → Unknown | Other. Pick the most specific reason the evidence supports; a pairing outside this list is normalized server-side to Other.
InaccurateData, IncorrectAlertLogic, SuspiciousActivity, SuspiciousButExpected, Unknown, Apt, Malware, SecurityPersonnel, SecurityTesting, UnwantedSoftware, Other, MultistagedAttack, CompromisedUser, Phishing, MaliciousUserActivity, NotMalicious, NoEnoughDataToValidate, ConfirmedUserActivity, LineOfBusinessApplication, null The single classification SOP whose decision tree drove the classification. Null when no SOP applied to this incident type.
Show child attributes
Show child attributes
SOPs whose response steps the agent executed during the investigation. Empty when the agent decided no response action was warranted.
Show child attributes
Show child attributes
IDs of gamebooks the agent queued earlier via submit-gamebook during this investigation. Use the gamebook_id returned by each submit-gamebook call. Receive-only here — submit-investigation does NOT queue additional gamebooks.
Per-tool-call timeline the agent recorded during the investigation. Used to render the activity header on the comment so an analyst can see exactly which tools the agent invoked, on what target, in what order, and how long each took.
Show child attributes
Show child attributes