Threat Intelligence API . projects . findings

Instance Methods

close()

Close httplib2 connections.

get(name, x__xgafv=None)

Get a finding by name. The `name` field should have the format: `projects/{project}/findings/{finding}`

list(parent, filter=None, orderBy=None, pageSize=None, pageToken=None, x__xgafv=None)

Get a list of findings that meet the filter criteria. The `parent` field in ListFindingsRequest should have the format: projects/{project}

list_next(previous_request, previous_response)

Retrieves the next page of results.

search(parent, orderBy=None, pageSize=None, pageToken=None, query=None, x__xgafv=None)

SearchFindings is a more powerful version of ListFindings that supports complex queries like "findings for alerts" using functions such as `has_alert` in the query string. The `parent` field in SearchFindingsRequest should have the format: projects/{project} Example to search for findings for a specific issue: `has_alert("name=\"projects/gti-12345/alerts/alert-12345\"")`

search_next(previous_request, previous_response)

Retrieves the next page of results.

Method Details

close()
Close httplib2 connections.
get(name, x__xgafv=None)
Get a finding by name. The `name` field should have the format: `projects/{project}/findings/{finding}`

Args:
  name: string, Required. Name of the finding to get. (required)
  x__xgafv: string, V1 error format.
    Allowed values
      1 - v1 error format
      2 - v2 error format

Returns:
  An object of the form:

    { # A ‘stateless’ and a point in time event that a check produced a result of interest.
  "aiSummary": "A String", # Optional. AI summary of the finding.
  "alert": "A String", # Optional. Name of the alert that this finding is bound to.
  "audit": { # Tracks basic CRUD facts. # Output only. Audit data about the finding.
    "createTime": "A String", # Output only. Time of creation.
    "creator": "A String", # Output only. Agent that created or updated the record, could be a UserId or a JobId.
    "updateTime": "A String", # Output only. Time of creation or last update.
    "updater": "A String", # Output only. Agent that last updated the record, could be a UserId or a JobId.
  },
  "configurations": [ # Optional. Configuration names that are bound to this finding.
    "A String",
  ],
  "detail": { # Wrapper class that contains the union struct for all the various findings detail specific classes. # Required. Holder of the domain specific details of the finding.
    "dataLeak": { # A detail object for a Data Leak finding. # Data Leak finding detail type.
      "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Data Leak finding.
        "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
          "channelDescription": "A String", # Optional. Description of the communication channel.
          "channelName": "A String", # Optional. Name of the communication channel.
          "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
          "channelUrl": "A String", # Optional. URL of the communication channel.
          "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
          "threadId": "A String", # Optional. Conversation thread identifier.
        },
        "documentId": "A String", # Output only. The identifier of the discovery document.
        "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
      },
      "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the Data Leak finding. This ID can be used to retrieve the content of the document for further analysis.
      "matchScore": 3.14, # Required. Reference to the match score of the Data Leak finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
      "severity": "A String", # Required. The severity of the Data Leak finding. This indicates the potential impact of the threat.
    },
    "detailType": "A String", # Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union.
    "domainMonitoring": { # A detailed object for a Domain or URL finding. # Domain Monitoring finding detail type.
      "dnsDetails": { # The DNS details of the domain. # Optional. The DNS details of the domain or URL.
        "dnsRecords": [ # Optional. The DNS records of the domain.
          { # The DNS record of the domain.
            "asnHosting": "A String", # Optional. The ASN hosting the domain.
            "asnRegionCode": "A String", # Optional. The region code of the ASN. Use ISO 3166-1 alpha-2 codes.
            "ipRegionCode": "A String", # Optional. The region code associated with the resolved IP. Use ISO 3166-1 alpha-2 codes.
            "recordData": "A String", # Optional. The value of the DNS record.
            "resolvedIp": "A String", # Optional. The resolved IP address.
            "ttl": 42, # Optional. The TTL of the DNS record.
            "type": "A String", # Optional. The type of the DNS record.
          },
        ],
        "retrievalTime": "A String", # Optional. The time the DNS details were retrieved.
      },
      "domainDetails": { # Details specific to a monitored domain. # Details specific to a monitored domain.
        "domain": "A String", # Required. The domain name to match against.
      },
      "gtiDetails": { # The GTI details of the domain. # Optional. The GTI details of the domain or URL.
        "avDetections": { # Details about the detection vendors. # Optional. Detection counts across vendor feeds.
          "detectedVendorCount": 42, # Optional. Number of vendors that detected the threat.
          "totalVendorCount": 42, # Optional. Total number of vendors.
        },
        "domainPermutation": "A String", # Optional. The permutation technique used for the domain (e.g., dictionary, homoglyph).
        "gtiDomainUri": "A String", # Optional. The GTI link for the domain.
        "gtiScore": 42, # Optional. The GTI score of the domain. The threat score is a number between 0 and 100.
        "threatClassification": "A String", # Optional. The threat classification of the domain, obtained from the domain report (e.g. DomainMonitoring).
        "verdict": "A String", # Output only. The verdict of the domain.
      },
      "infrastructure": { # Core infrastructure observations associated with the URL or Domain. # Optional. The infrastructure of the domain or URL.
        "certificateDetails": { # Details regarding the SSL certificate configuration. # Optional. SSL certificate details.
          "issuer": "A String", # Optional. The SSL certificate issuer.
          "subjectAlternativeNames": [ # Optional. The SSL subject alternative names.
            "A String",
          ],
        },
        "urlResponse": "A String", # Optional. The raw URL response string.
      },
      "matchedDomain": "A String", # Optional. The matched domain.
      "protectedBrand": "A String", # The protected brand name that triggered the alert.
      "protectedDomain": { # Details specific to a monitored domain. # The protected domain that triggered the alert.
        "domain": "A String", # Required. The domain name to match against.
      },
      "registrationDetails": { # Extracted WHOIS and DNS registration details of the domain. # Optional. Extracted WHOIS and DNS registration details.
        "expireTime": "A String", # Optional. The specific timestamp when the current domain registration expires.
        "privateRegistration": True or False, # Optional. Indicates whether private registration is enabled on the WHOIS record.
        "registrantCountry": "A String", # Optional. The country code of the registrant (e.g., US). Use ISO 3166-1 alpha-2 codes
        "registrar": "A String", # Optional. The registrar where the domain was registered (e.g., NameCheap).
        "registrationTime": "A String", # Optional. The specific timestamp when the domain registration was created.
      },
      "relationships": { # Related entities and domains observed for the target. # Optional. The relationships of the domain or URL.
        "relatedUrls": [ # Optional. Related URLs associated with the domain.
          "A String",
        ],
        "siblingDomains": [ # Optional. Sibling domains sharing the same IP address.
          "A String",
        ],
        "subdomains": [ # Optional. Subdomains associated with the target domain or URL.
          "A String",
        ],
      },
      "threatAttributionDetails": { # Threat attribution information (actor, campaign, etc.). # Optional. The threat attribution details of the domain or URL.
        "actors": [ # Optional. The threat actors associated with the target.
          "A String",
        ],
        "collections": [ # Optional. The threat collections detected.
          "A String",
        ],
        "malware": [ # Optional. The malware associated with the threat.
          "A String",
        ],
      },
      "urlDetails": { # Details specific to a monitored URL. # Details specific to a monitored URL.
        "url": "A String", # Required. The URL to match against.
      },
      "whoisDetails": { # The whois details of the domain. # Optional. The whois details of the domain or URL.
        "retrievalTime": "A String", # Optional. The time the whois details were retrieved.
        "whois": "A String", # Optional. The whois details of the domain.
      },
    },
    "initialAccessBroker": { # A detail object for an Initial Access Broker (IAB) finding. # Initial Access Broker finding detail type.
      "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the IAB finding.
        "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
          "channelDescription": "A String", # Optional. Description of the communication channel.
          "channelName": "A String", # Optional. Name of the communication channel.
          "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
          "channelUrl": "A String", # Optional. URL of the communication channel.
          "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
          "threadId": "A String", # Optional. Conversation thread identifier.
        },
        "documentId": "A String", # Output only. The identifier of the discovery document.
        "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
      },
      "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the IAB finding. This ID can be used to retrieve the content of the document for further analysis.
      "matchScore": 3.14, # Required. Reference to the match score of the IAB finding. This is a float value between 0 and 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
      "severity": "A String", # Required. The severity of the IAB finding. This indicates the potential impact of the threat.
    },
    "insiderThreat": { # A detail object for a InsiderThreat finding. # Insider Threat finding detail type.
      "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Insider Threat finding.
        "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
          "channelDescription": "A String", # Optional. Description of the communication channel.
          "channelName": "A String", # Optional. Name of the communication channel.
          "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
          "channelUrl": "A String", # Optional. URL of the communication channel.
          "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
          "threadId": "A String", # Optional. Conversation thread identifier.
        },
        "documentId": "A String", # Output only. The identifier of the discovery document.
        "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
      },
      "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the InsiderThreat finding. This ID can be used to retrieve the content of the document for further analysis.
      "matchScore": 3.14, # Required. Reference to the match score of the InsiderThreat finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
      "severity": "A String", # Required. The severity of the InsiderThreat finding. This indicates the potential impact of the threat.
    },
    "targetTechnology": { # Contains details for a technology watchlist finding. # Technology Watchlist finding detail type.
      "vulnerabilityMatch": { # Contains details about a vulnerability match. # Optional. The vulnerability match details.
        "associations": [ # Optional. Associated threat actors, malware, etc. This is embedded as a snapshot because the details of the association at the time of the vulnerability match are important for context and reporting.
          { # Represents an association with a vulnerability.
            "id": "A String", # Required. The ID of the association.
            "type": "A String", # Required. The type of the association.
          },
        ],
        "collectionId": "A String", # Required. The collection ID of the vulnerability. Ex: "vulnerability--cve-2025-9876".
        "cveId": "A String", # Required. The CVE ID of the vulnerability. Ex: "CVE-2025-9876". See https://www.cve.org/ for more information.
        "cvss3Score": 3.14, # Required. The CVSS score of the vulnerability. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Example: 6.4.
        "description": "A String", # Required. A description of the vulnerability.
        "disclosureTime": "A String", # Optional. The disclosure time of the vulnerability.
        "epssScore": 3.14, # Optional. The EPSS score, representing the probability of exploitation. Example: 0.87.
        "exploitationConsequences": [ # Optional. List of exploitation consequences for the vulnerability.
          "A String",
        ],
        "exploitationState": "A String", # Required. The exploitation state of the vulnerability.
        "exploitationVectors": [ # Optional. List of exploitation vectors for the vulnerability.
          "A String",
        ],
        "matchedTechnologies": [ # Optional. The specific technologies from the configured watchlist that triggered the match. Ex: "Apache Struts".
          "A String",
        ],
        "priority": "A String", # Optional. The priority level of the vulnerability data. Ex: "P1".
        "productFixes": [ # Optional. List of product fixes for the vulnerability.
          { # Contains details about a product fix.
            "displayName": "A String", # Required. The name of the fix. Ex: "Magento".
            "publishTime": "A String", # Optional. The published time of the fix.
            "sourceId": "A String", # Required. The source ID of the fix. Ex: "APPSEC-1420".
            "uri": "A String", # Optional. The URI of the fix.
          },
        ],
        "publicExploits": [ # Optional. List of public exploits.
          { # Contains details about a public exploit.
            "exploitGrade": "A String", # Optional. The grade of the exploit. Ex: "non-weaponized".
            "exploitName": "A String", # Required. The name of the exploit. Ex: "Magentounauth.php.txt".
            "exploitReliability": "A String", # Optional. The reliability of the exploit. Ex: "Unreviewed".
            "releaseTime": "A String", # Optional. The release time of the exploit.
            "sizeBytes": "A String", # Optional. The size of the exploit.
            "uri": "A String", # Optional. The URI of the exploit.
          },
        ],
        "publiclyAvailableExploit": True or False, # Output only. Whether a publicly available exploit exists.
        "riskRating": "A String", # Required. The risk rating of the vulnerability.
        "technologies": [ # Required. All technologies affected by the vulnerability. Ex: "Apache Struts".
          "A String",
        ],
      },
    },
  },
  "displayName": "A String", # Required. A short descriptive title for the finding <= 250 chars. EX: "Actor 'baddy' offering $1000 for credentials of 'goodguy'".
  "name": "A String", # Identifier. Server generated name for the finding (leave clear during creation). Format: projects/{project}/findings/{finding}
  "provider": "A String", # Required. Logical source of this finding (name of the sub-engine).
  "relevanceAnalysis": { # Structured relevance analysis for a threat. # Output only. High-Precision Relevance Analysis verdict for the finding.
    "confidence": "A String", # The level of confidence in the given verdict.
    "evidence": { # Details the evidence used to determine the relevance verdict. # Evidence supporting the verdict, including matched and unmatched items.
      "commonThemes": [ # A list of semantic themes or concepts found to be common, related, or aligned between the sources, supporting the verdict.
        "A String",
      ],
      "distinctThemes": [ # A list of semantic themes or descriptions unique to one source or semantically distant.
        "A String",
      ],
    },
    "reasoning": "A String", # Human-readable explanation from the matcher, detailing why a particular result is considered relevant or not relevant.
    "relevanceLevel": "A String", # The level of relevance.
    "relevant": True or False, # Indicates whether the threat is considered relevant.
  },
  "reoccurrenceTimes": [ # Output only. When identical finding (same labels and same details) has re-occurred.
    "A String",
  ],
  "severity": 3.14, # Optional. Deprecated: Use the `severity_analysis` field instead. Base severity score from the finding source.
  "severityAnalysis": { # Structured severity analysis for a threat. # Output only. High-Precision Severity Analysis verdict for the finding.
    "confidence": "A String", # The level of confidence in the given verdict.
    "reasoning": "A String", # Human-readable explanation from the model, detailing why a particular result is considered to have a certain severity.
    "severityLevel": "A String", # The level of severity.
  },
}
list(parent, filter=None, orderBy=None, pageSize=None, pageToken=None, x__xgafv=None)
Get a list of findings that meet the filter criteria. The `parent` field in ListFindingsRequest should have the format: projects/{project}

Args:
  parent: string, Required. Parent of the findings. (required)
  filter: string, Optional. Filter criteria.
  orderBy: string, Optional. Order by criteria in the csv format: "field1,field2 desc" or "field1,field2" or "field1 asc, field2".
  pageSize: integer, Optional. Page size.
  pageToken: string, Optional. Page token.
  x__xgafv: string, V1 error format.
    Allowed values
      1 - v1 error format
      2 - v2 error format

Returns:
  An object of the form:

    { # Response message for ListFindings.
  "findings": [ # List of findings.
    { # A ‘stateless’ and a point in time event that a check produced a result of interest.
      "aiSummary": "A String", # Optional. AI summary of the finding.
      "alert": "A String", # Optional. Name of the alert that this finding is bound to.
      "audit": { # Tracks basic CRUD facts. # Output only. Audit data about the finding.
        "createTime": "A String", # Output only. Time of creation.
        "creator": "A String", # Output only. Agent that created or updated the record, could be a UserId or a JobId.
        "updateTime": "A String", # Output only. Time of creation or last update.
        "updater": "A String", # Output only. Agent that last updated the record, could be a UserId or a JobId.
      },
      "configurations": [ # Optional. Configuration names that are bound to this finding.
        "A String",
      ],
      "detail": { # Wrapper class that contains the union struct for all the various findings detail specific classes. # Required. Holder of the domain specific details of the finding.
        "dataLeak": { # A detail object for a Data Leak finding. # Data Leak finding detail type.
          "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Data Leak finding.
            "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
              "channelDescription": "A String", # Optional. Description of the communication channel.
              "channelName": "A String", # Optional. Name of the communication channel.
              "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
              "channelUrl": "A String", # Optional. URL of the communication channel.
              "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
              "threadId": "A String", # Optional. Conversation thread identifier.
            },
            "documentId": "A String", # Output only. The identifier of the discovery document.
            "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
          },
          "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the Data Leak finding. This ID can be used to retrieve the content of the document for further analysis.
          "matchScore": 3.14, # Required. Reference to the match score of the Data Leak finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
          "severity": "A String", # Required. The severity of the Data Leak finding. This indicates the potential impact of the threat.
        },
        "detailType": "A String", # Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union.
        "domainMonitoring": { # A detailed object for a Domain or URL finding. # Domain Monitoring finding detail type.
          "dnsDetails": { # The DNS details of the domain. # Optional. The DNS details of the domain or URL.
            "dnsRecords": [ # Optional. The DNS records of the domain.
              { # The DNS record of the domain.
                "asnHosting": "A String", # Optional. The ASN hosting the domain.
                "asnRegionCode": "A String", # Optional. The region code of the ASN. Use ISO 3166-1 alpha-2 codes.
                "ipRegionCode": "A String", # Optional. The region code associated with the resolved IP. Use ISO 3166-1 alpha-2 codes.
                "recordData": "A String", # Optional. The value of the DNS record.
                "resolvedIp": "A String", # Optional. The resolved IP address.
                "ttl": 42, # Optional. The TTL of the DNS record.
                "type": "A String", # Optional. The type of the DNS record.
              },
            ],
            "retrievalTime": "A String", # Optional. The time the DNS details were retrieved.
          },
          "domainDetails": { # Details specific to a monitored domain. # Details specific to a monitored domain.
            "domain": "A String", # Required. The domain name to match against.
          },
          "gtiDetails": { # The GTI details of the domain. # Optional. The GTI details of the domain or URL.
            "avDetections": { # Details about the detection vendors. # Optional. Detection counts across vendor feeds.
              "detectedVendorCount": 42, # Optional. Number of vendors that detected the threat.
              "totalVendorCount": 42, # Optional. Total number of vendors.
            },
            "domainPermutation": "A String", # Optional. The permutation technique used for the domain (e.g., dictionary, homoglyph).
            "gtiDomainUri": "A String", # Optional. The GTI link for the domain.
            "gtiScore": 42, # Optional. The GTI score of the domain. The threat score is a number between 0 and 100.
            "threatClassification": "A String", # Optional. The threat classification of the domain, obtained from the domain report (e.g. DomainMonitoring).
            "verdict": "A String", # Output only. The verdict of the domain.
          },
          "infrastructure": { # Core infrastructure observations associated with the URL or Domain. # Optional. The infrastructure of the domain or URL.
            "certificateDetails": { # Details regarding the SSL certificate configuration. # Optional. SSL certificate details.
              "issuer": "A String", # Optional. The SSL certificate issuer.
              "subjectAlternativeNames": [ # Optional. The SSL subject alternative names.
                "A String",
              ],
            },
            "urlResponse": "A String", # Optional. The raw URL response string.
          },
          "matchedDomain": "A String", # Optional. The matched domain.
          "protectedBrand": "A String", # The protected brand name that triggered the alert.
          "protectedDomain": { # Details specific to a monitored domain. # The protected domain that triggered the alert.
            "domain": "A String", # Required. The domain name to match against.
          },
          "registrationDetails": { # Extracted WHOIS and DNS registration details of the domain. # Optional. Extracted WHOIS and DNS registration details.
            "expireTime": "A String", # Optional. The specific timestamp when the current domain registration expires.
            "privateRegistration": True or False, # Optional. Indicates whether private registration is enabled on the WHOIS record.
            "registrantCountry": "A String", # Optional. The country code of the registrant (e.g., US). Use ISO 3166-1 alpha-2 codes
            "registrar": "A String", # Optional. The registrar where the domain was registered (e.g., NameCheap).
            "registrationTime": "A String", # Optional. The specific timestamp when the domain registration was created.
          },
          "relationships": { # Related entities and domains observed for the target. # Optional. The relationships of the domain or URL.
            "relatedUrls": [ # Optional. Related URLs associated with the domain.
              "A String",
            ],
            "siblingDomains": [ # Optional. Sibling domains sharing the same IP address.
              "A String",
            ],
            "subdomains": [ # Optional. Subdomains associated with the target domain or URL.
              "A String",
            ],
          },
          "threatAttributionDetails": { # Threat attribution information (actor, campaign, etc.). # Optional. The threat attribution details of the domain or URL.
            "actors": [ # Optional. The threat actors associated with the target.
              "A String",
            ],
            "collections": [ # Optional. The threat collections detected.
              "A String",
            ],
            "malware": [ # Optional. The malware associated with the threat.
              "A String",
            ],
          },
          "urlDetails": { # Details specific to a monitored URL. # Details specific to a monitored URL.
            "url": "A String", # Required. The URL to match against.
          },
          "whoisDetails": { # The whois details of the domain. # Optional. The whois details of the domain or URL.
            "retrievalTime": "A String", # Optional. The time the whois details were retrieved.
            "whois": "A String", # Optional. The whois details of the domain.
          },
        },
        "initialAccessBroker": { # A detail object for an Initial Access Broker (IAB) finding. # Initial Access Broker finding detail type.
          "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the IAB finding.
            "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
              "channelDescription": "A String", # Optional. Description of the communication channel.
              "channelName": "A String", # Optional. Name of the communication channel.
              "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
              "channelUrl": "A String", # Optional. URL of the communication channel.
              "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
              "threadId": "A String", # Optional. Conversation thread identifier.
            },
            "documentId": "A String", # Output only. The identifier of the discovery document.
            "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
          },
          "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the IAB finding. This ID can be used to retrieve the content of the document for further analysis.
          "matchScore": 3.14, # Required. Reference to the match score of the IAB finding. This is a float value between 0 and 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
          "severity": "A String", # Required. The severity of the IAB finding. This indicates the potential impact of the threat.
        },
        "insiderThreat": { # A detail object for a InsiderThreat finding. # Insider Threat finding detail type.
          "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Insider Threat finding.
            "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
              "channelDescription": "A String", # Optional. Description of the communication channel.
              "channelName": "A String", # Optional. Name of the communication channel.
              "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
              "channelUrl": "A String", # Optional. URL of the communication channel.
              "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
              "threadId": "A String", # Optional. Conversation thread identifier.
            },
            "documentId": "A String", # Output only. The identifier of the discovery document.
            "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
          },
          "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the InsiderThreat finding. This ID can be used to retrieve the content of the document for further analysis.
          "matchScore": 3.14, # Required. Reference to the match score of the InsiderThreat finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
          "severity": "A String", # Required. The severity of the InsiderThreat finding. This indicates the potential impact of the threat.
        },
        "targetTechnology": { # Contains details for a technology watchlist finding. # Technology Watchlist finding detail type.
          "vulnerabilityMatch": { # Contains details about a vulnerability match. # Optional. The vulnerability match details.
            "associations": [ # Optional. Associated threat actors, malware, etc. This is embedded as a snapshot because the details of the association at the time of the vulnerability match are important for context and reporting.
              { # Represents an association with a vulnerability.
                "id": "A String", # Required. The ID of the association.
                "type": "A String", # Required. The type of the association.
              },
            ],
            "collectionId": "A String", # Required. The collection ID of the vulnerability. Ex: "vulnerability--cve-2025-9876".
            "cveId": "A String", # Required. The CVE ID of the vulnerability. Ex: "CVE-2025-9876". See https://www.cve.org/ for more information.
            "cvss3Score": 3.14, # Required. The CVSS score of the vulnerability. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Example: 6.4.
            "description": "A String", # Required. A description of the vulnerability.
            "disclosureTime": "A String", # Optional. The disclosure time of the vulnerability.
            "epssScore": 3.14, # Optional. The EPSS score, representing the probability of exploitation. Example: 0.87.
            "exploitationConsequences": [ # Optional. List of exploitation consequences for the vulnerability.
              "A String",
            ],
            "exploitationState": "A String", # Required. The exploitation state of the vulnerability.
            "exploitationVectors": [ # Optional. List of exploitation vectors for the vulnerability.
              "A String",
            ],
            "matchedTechnologies": [ # Optional. The specific technologies from the configured watchlist that triggered the match. Ex: "Apache Struts".
              "A String",
            ],
            "priority": "A String", # Optional. The priority level of the vulnerability data. Ex: "P1".
            "productFixes": [ # Optional. List of product fixes for the vulnerability.
              { # Contains details about a product fix.
                "displayName": "A String", # Required. The name of the fix. Ex: "Magento".
                "publishTime": "A String", # Optional. The published time of the fix.
                "sourceId": "A String", # Required. The source ID of the fix. Ex: "APPSEC-1420".
                "uri": "A String", # Optional. The URI of the fix.
              },
            ],
            "publicExploits": [ # Optional. List of public exploits.
              { # Contains details about a public exploit.
                "exploitGrade": "A String", # Optional. The grade of the exploit. Ex: "non-weaponized".
                "exploitName": "A String", # Required. The name of the exploit. Ex: "Magentounauth.php.txt".
                "exploitReliability": "A String", # Optional. The reliability of the exploit. Ex: "Unreviewed".
                "releaseTime": "A String", # Optional. The release time of the exploit.
                "sizeBytes": "A String", # Optional. The size of the exploit.
                "uri": "A String", # Optional. The URI of the exploit.
              },
            ],
            "publiclyAvailableExploit": True or False, # Output only. Whether a publicly available exploit exists.
            "riskRating": "A String", # Required. The risk rating of the vulnerability.
            "technologies": [ # Required. All technologies affected by the vulnerability. Ex: "Apache Struts".
              "A String",
            ],
          },
        },
      },
      "displayName": "A String", # Required. A short descriptive title for the finding <= 250 chars. EX: "Actor 'baddy' offering $1000 for credentials of 'goodguy'".
      "name": "A String", # Identifier. Server generated name for the finding (leave clear during creation). Format: projects/{project}/findings/{finding}
      "provider": "A String", # Required. Logical source of this finding (name of the sub-engine).
      "relevanceAnalysis": { # Structured relevance analysis for a threat. # Output only. High-Precision Relevance Analysis verdict for the finding.
        "confidence": "A String", # The level of confidence in the given verdict.
        "evidence": { # Details the evidence used to determine the relevance verdict. # Evidence supporting the verdict, including matched and unmatched items.
          "commonThemes": [ # A list of semantic themes or concepts found to be common, related, or aligned between the sources, supporting the verdict.
            "A String",
          ],
          "distinctThemes": [ # A list of semantic themes or descriptions unique to one source or semantically distant.
            "A String",
          ],
        },
        "reasoning": "A String", # Human-readable explanation from the matcher, detailing why a particular result is considered relevant or not relevant.
        "relevanceLevel": "A String", # The level of relevance.
        "relevant": True or False, # Indicates whether the threat is considered relevant.
      },
      "reoccurrenceTimes": [ # Output only. When identical finding (same labels and same details) has re-occurred.
        "A String",
      ],
      "severity": 3.14, # Optional. Deprecated: Use the `severity_analysis` field instead. Base severity score from the finding source.
      "severityAnalysis": { # Structured severity analysis for a threat. # Output only. High-Precision Severity Analysis verdict for the finding.
        "confidence": "A String", # The level of confidence in the given verdict.
        "reasoning": "A String", # Human-readable explanation from the model, detailing why a particular result is considered to have a certain severity.
        "severityLevel": "A String", # The level of severity.
      },
    },
  ],
  "nextPageToken": "A String", # Page token.
}
list_next(previous_request, previous_response)
Retrieves the next page of results.

Args:
  previous_request: The request for the previous page. (required)
  previous_response: The response from the request for the previous page. (required)

Returns:
  A request object that you can call 'execute()' on to request the next
  page. Returns None if there are no more items in the collection.
search(parent, orderBy=None, pageSize=None, pageToken=None, query=None, x__xgafv=None)
SearchFindings is a more powerful version of ListFindings that supports complex queries like "findings for alerts" using functions such as `has_alert` in the query string. The `parent` field in SearchFindingsRequest should have the format: projects/{project} Example to search for findings for a specific issue: `has_alert("name=\"projects/gti-12345/alerts/alert-12345\"")`

Args:
  parent: string, Required. Parent of the findings. Format: vaults/{vault} (required)
  orderBy: string, Optional. Order by criteria in the csv format: "field1,field2 desc" or "field1,field2" or "field1 asc, field2".
  pageSize: integer, Optional. Page size.
  pageToken: string, Optional. Page token.
  query: string, Optional. Query on what findings will be returned. This supports the same filter criteria as FindingService.ListFindings as well as the following relationship query `has_alert`. Example: - `has_alert("name=\"projects/gti-12345/alerts/alert-12345\"")`
  x__xgafv: string, V1 error format.
    Allowed values
      1 - v1 error format
      2 - v2 error format

Returns:
  An object of the form:

    { # Response message for SearchFindings.
  "findings": [ # List of findings.
    { # A ‘stateless’ and a point in time event that a check produced a result of interest.
      "aiSummary": "A String", # Optional. AI summary of the finding.
      "alert": "A String", # Optional. Name of the alert that this finding is bound to.
      "audit": { # Tracks basic CRUD facts. # Output only. Audit data about the finding.
        "createTime": "A String", # Output only. Time of creation.
        "creator": "A String", # Output only. Agent that created or updated the record, could be a UserId or a JobId.
        "updateTime": "A String", # Output only. Time of creation or last update.
        "updater": "A String", # Output only. Agent that last updated the record, could be a UserId or a JobId.
      },
      "configurations": [ # Optional. Configuration names that are bound to this finding.
        "A String",
      ],
      "detail": { # Wrapper class that contains the union struct for all the various findings detail specific classes. # Required. Holder of the domain specific details of the finding.
        "dataLeak": { # A detail object for a Data Leak finding. # Data Leak finding detail type.
          "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Data Leak finding.
            "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
              "channelDescription": "A String", # Optional. Description of the communication channel.
              "channelName": "A String", # Optional. Name of the communication channel.
              "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
              "channelUrl": "A String", # Optional. URL of the communication channel.
              "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
              "threadId": "A String", # Optional. Conversation thread identifier.
            },
            "documentId": "A String", # Output only. The identifier of the discovery document.
            "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
          },
          "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the Data Leak finding. This ID can be used to retrieve the content of the document for further analysis.
          "matchScore": 3.14, # Required. Reference to the match score of the Data Leak finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
          "severity": "A String", # Required. The severity of the Data Leak finding. This indicates the potential impact of the threat.
        },
        "detailType": "A String", # Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union.
        "domainMonitoring": { # A detailed object for a Domain or URL finding. # Domain Monitoring finding detail type.
          "dnsDetails": { # The DNS details of the domain. # Optional. The DNS details of the domain or URL.
            "dnsRecords": [ # Optional. The DNS records of the domain.
              { # The DNS record of the domain.
                "asnHosting": "A String", # Optional. The ASN hosting the domain.
                "asnRegionCode": "A String", # Optional. The region code of the ASN. Use ISO 3166-1 alpha-2 codes.
                "ipRegionCode": "A String", # Optional. The region code associated with the resolved IP. Use ISO 3166-1 alpha-2 codes.
                "recordData": "A String", # Optional. The value of the DNS record.
                "resolvedIp": "A String", # Optional. The resolved IP address.
                "ttl": 42, # Optional. The TTL of the DNS record.
                "type": "A String", # Optional. The type of the DNS record.
              },
            ],
            "retrievalTime": "A String", # Optional. The time the DNS details were retrieved.
          },
          "domainDetails": { # Details specific to a monitored domain. # Details specific to a monitored domain.
            "domain": "A String", # Required. The domain name to match against.
          },
          "gtiDetails": { # The GTI details of the domain. # Optional. The GTI details of the domain or URL.
            "avDetections": { # Details about the detection vendors. # Optional. Detection counts across vendor feeds.
              "detectedVendorCount": 42, # Optional. Number of vendors that detected the threat.
              "totalVendorCount": 42, # Optional. Total number of vendors.
            },
            "domainPermutation": "A String", # Optional. The permutation technique used for the domain (e.g., dictionary, homoglyph).
            "gtiDomainUri": "A String", # Optional. The GTI link for the domain.
            "gtiScore": 42, # Optional. The GTI score of the domain. The threat score is a number between 0 and 100.
            "threatClassification": "A String", # Optional. The threat classification of the domain, obtained from the domain report (e.g. DomainMonitoring).
            "verdict": "A String", # Output only. The verdict of the domain.
          },
          "infrastructure": { # Core infrastructure observations associated with the URL or Domain. # Optional. The infrastructure of the domain or URL.
            "certificateDetails": { # Details regarding the SSL certificate configuration. # Optional. SSL certificate details.
              "issuer": "A String", # Optional. The SSL certificate issuer.
              "subjectAlternativeNames": [ # Optional. The SSL subject alternative names.
                "A String",
              ],
            },
            "urlResponse": "A String", # Optional. The raw URL response string.
          },
          "matchedDomain": "A String", # Optional. The matched domain.
          "protectedBrand": "A String", # The protected brand name that triggered the alert.
          "protectedDomain": { # Details specific to a monitored domain. # The protected domain that triggered the alert.
            "domain": "A String", # Required. The domain name to match against.
          },
          "registrationDetails": { # Extracted WHOIS and DNS registration details of the domain. # Optional. Extracted WHOIS and DNS registration details.
            "expireTime": "A String", # Optional. The specific timestamp when the current domain registration expires.
            "privateRegistration": True or False, # Optional. Indicates whether private registration is enabled on the WHOIS record.
            "registrantCountry": "A String", # Optional. The country code of the registrant (e.g., US). Use ISO 3166-1 alpha-2 codes
            "registrar": "A String", # Optional. The registrar where the domain was registered (e.g., NameCheap).
            "registrationTime": "A String", # Optional. The specific timestamp when the domain registration was created.
          },
          "relationships": { # Related entities and domains observed for the target. # Optional. The relationships of the domain or URL.
            "relatedUrls": [ # Optional. Related URLs associated with the domain.
              "A String",
            ],
            "siblingDomains": [ # Optional. Sibling domains sharing the same IP address.
              "A String",
            ],
            "subdomains": [ # Optional. Subdomains associated with the target domain or URL.
              "A String",
            ],
          },
          "threatAttributionDetails": { # Threat attribution information (actor, campaign, etc.). # Optional. The threat attribution details of the domain or URL.
            "actors": [ # Optional. The threat actors associated with the target.
              "A String",
            ],
            "collections": [ # Optional. The threat collections detected.
              "A String",
            ],
            "malware": [ # Optional. The malware associated with the threat.
              "A String",
            ],
          },
          "urlDetails": { # Details specific to a monitored URL. # Details specific to a monitored URL.
            "url": "A String", # Required. The URL to match against.
          },
          "whoisDetails": { # The whois details of the domain. # Optional. The whois details of the domain or URL.
            "retrievalTime": "A String", # Optional. The time the whois details were retrieved.
            "whois": "A String", # Optional. The whois details of the domain.
          },
        },
        "initialAccessBroker": { # A detail object for an Initial Access Broker (IAB) finding. # Initial Access Broker finding detail type.
          "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the IAB finding.
            "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
              "channelDescription": "A String", # Optional. Description of the communication channel.
              "channelName": "A String", # Optional. Name of the communication channel.
              "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
              "channelUrl": "A String", # Optional. URL of the communication channel.
              "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
              "threadId": "A String", # Optional. Conversation thread identifier.
            },
            "documentId": "A String", # Output only. The identifier of the discovery document.
            "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
          },
          "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the IAB finding. This ID can be used to retrieve the content of the document for further analysis.
          "matchScore": 3.14, # Required. Reference to the match score of the IAB finding. This is a float value between 0 and 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
          "severity": "A String", # Required. The severity of the IAB finding. This indicates the potential impact of the threat.
        },
        "insiderThreat": { # A detail object for a InsiderThreat finding. # Insider Threat finding detail type.
          "discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Insider Threat finding.
            "communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
              "channelDescription": "A String", # Optional. Description of the communication channel.
              "channelName": "A String", # Optional. Name of the communication channel.
              "channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
              "channelUrl": "A String", # Optional. URL of the communication channel.
              "serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
              "threadId": "A String", # Optional. Conversation thread identifier.
            },
            "documentId": "A String", # Output only. The identifier of the discovery document.
            "documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
          },
          "documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the InsiderThreat finding. This ID can be used to retrieve the content of the document for further analysis.
          "matchScore": 3.14, # Required. Reference to the match score of the InsiderThreat finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
          "severity": "A String", # Required. The severity of the InsiderThreat finding. This indicates the potential impact of the threat.
        },
        "targetTechnology": { # Contains details for a technology watchlist finding. # Technology Watchlist finding detail type.
          "vulnerabilityMatch": { # Contains details about a vulnerability match. # Optional. The vulnerability match details.
            "associations": [ # Optional. Associated threat actors, malware, etc. This is embedded as a snapshot because the details of the association at the time of the vulnerability match are important for context and reporting.
              { # Represents an association with a vulnerability.
                "id": "A String", # Required. The ID of the association.
                "type": "A String", # Required. The type of the association.
              },
            ],
            "collectionId": "A String", # Required. The collection ID of the vulnerability. Ex: "vulnerability--cve-2025-9876".
            "cveId": "A String", # Required. The CVE ID of the vulnerability. Ex: "CVE-2025-9876". See https://www.cve.org/ for more information.
            "cvss3Score": 3.14, # Required. The CVSS score of the vulnerability. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Example: 6.4.
            "description": "A String", # Required. A description of the vulnerability.
            "disclosureTime": "A String", # Optional. The disclosure time of the vulnerability.
            "epssScore": 3.14, # Optional. The EPSS score, representing the probability of exploitation. Example: 0.87.
            "exploitationConsequences": [ # Optional. List of exploitation consequences for the vulnerability.
              "A String",
            ],
            "exploitationState": "A String", # Required. The exploitation state of the vulnerability.
            "exploitationVectors": [ # Optional. List of exploitation vectors for the vulnerability.
              "A String",
            ],
            "matchedTechnologies": [ # Optional. The specific technologies from the configured watchlist that triggered the match. Ex: "Apache Struts".
              "A String",
            ],
            "priority": "A String", # Optional. The priority level of the vulnerability data. Ex: "P1".
            "productFixes": [ # Optional. List of product fixes for the vulnerability.
              { # Contains details about a product fix.
                "displayName": "A String", # Required. The name of the fix. Ex: "Magento".
                "publishTime": "A String", # Optional. The published time of the fix.
                "sourceId": "A String", # Required. The source ID of the fix. Ex: "APPSEC-1420".
                "uri": "A String", # Optional. The URI of the fix.
              },
            ],
            "publicExploits": [ # Optional. List of public exploits.
              { # Contains details about a public exploit.
                "exploitGrade": "A String", # Optional. The grade of the exploit. Ex: "non-weaponized".
                "exploitName": "A String", # Required. The name of the exploit. Ex: "Magentounauth.php.txt".
                "exploitReliability": "A String", # Optional. The reliability of the exploit. Ex: "Unreviewed".
                "releaseTime": "A String", # Optional. The release time of the exploit.
                "sizeBytes": "A String", # Optional. The size of the exploit.
                "uri": "A String", # Optional. The URI of the exploit.
              },
            ],
            "publiclyAvailableExploit": True or False, # Output only. Whether a publicly available exploit exists.
            "riskRating": "A String", # Required. The risk rating of the vulnerability.
            "technologies": [ # Required. All technologies affected by the vulnerability. Ex: "Apache Struts".
              "A String",
            ],
          },
        },
      },
      "displayName": "A String", # Required. A short descriptive title for the finding <= 250 chars. EX: "Actor 'baddy' offering $1000 for credentials of 'goodguy'".
      "name": "A String", # Identifier. Server generated name for the finding (leave clear during creation). Format: projects/{project}/findings/{finding}
      "provider": "A String", # Required. Logical source of this finding (name of the sub-engine).
      "relevanceAnalysis": { # Structured relevance analysis for a threat. # Output only. High-Precision Relevance Analysis verdict for the finding.
        "confidence": "A String", # The level of confidence in the given verdict.
        "evidence": { # Details the evidence used to determine the relevance verdict. # Evidence supporting the verdict, including matched and unmatched items.
          "commonThemes": [ # A list of semantic themes or concepts found to be common, related, or aligned between the sources, supporting the verdict.
            "A String",
          ],
          "distinctThemes": [ # A list of semantic themes or descriptions unique to one source or semantically distant.
            "A String",
          ],
        },
        "reasoning": "A String", # Human-readable explanation from the matcher, detailing why a particular result is considered relevant or not relevant.
        "relevanceLevel": "A String", # The level of relevance.
        "relevant": True or False, # Indicates whether the threat is considered relevant.
      },
      "reoccurrenceTimes": [ # Output only. When identical finding (same labels and same details) has re-occurred.
        "A String",
      ],
      "severity": 3.14, # Optional. Deprecated: Use the `severity_analysis` field instead. Base severity score from the finding source.
      "severityAnalysis": { # Structured severity analysis for a threat. # Output only. High-Precision Severity Analysis verdict for the finding.
        "confidence": "A String", # The level of confidence in the given verdict.
        "reasoning": "A String", # Human-readable explanation from the model, detailing why a particular result is considered to have a certain severity.
        "severityLevel": "A String", # The level of severity.
      },
    },
  ],
  "nextPageToken": "A String", # Page token.
}
search_next(previous_request, previous_response)
Retrieves the next page of results.

Args:
  previous_request: The request for the previous page. (required)
  previous_response: The response from the request for the previous page. (required)

Returns:
  A request object that you can call 'execute()' on to request the next
  page. Returns None if there are no more items in the collection.