Feed back a verdict from a SOAR playbook or SOC analyst.
Supply a single outcome describing what happened to the case.
An optional comment and list of supporting event_ids may be included.
Domain-scoped API key. Generate and manage keys from the API Keys
page in Settings. Pass via the X-API-Key header.
What happened to the case. One label, no ambiguity:
SAFE — Benign, no threatTRUE_POSITIVE — Confirmed threat, actionedFALSE_POSITIVE — Incorrectly flaggedDUPLICATE — Already handled under another caseESCALATED — Passed to investigation or SOC tierSAFE, TRUE_POSITIVE, FALSE_POSITIVE, DUPLICATE, ESCALATED 2000Optional event IDs supporting this verdict
200Verdict accepted and applied
What happened to the case. One label, no ambiguity:
SAFE — Benign, no threatTRUE_POSITIVE — Confirmed threat, actionedFALSE_POSITIVE — Incorrectly flaggedDUPLICATE — Already handled under another caseESCALATED — Passed to investigation or SOC tierSAFE, TRUE_POSITIVE, FALSE_POSITIVE, DUPLICATE, ESCALATED ID of the case version created by this verdict, if available