Close httplib2 connections.
Get a finding by name. The `name` field should have the format: `projects/{project}/findings/{finding}`
list(parent, filter=None, orderBy=None, pageSize=None, pageToken=None, x__xgafv=None)
Get a list of findings that meet the filter criteria. The `parent` field in ListFindingsRequest should have the format: projects/{project}
list_next(previous_request, previous_response)
Retrieves the next page of results.
search(parent, orderBy=None, pageSize=None, pageToken=None, query=None, x__xgafv=None)
SearchFindings is a more powerful version of ListFindings that supports complex queries like "findings for alerts" using functions such as `has_alert` in the query string. The `parent` field in SearchFindingsRequest should have the format: projects/{project} Example to search for findings for a specific issue: `has_alert("name=\"projects/gti-12345/alerts/alert-12345\"")`
search_next(previous_request, previous_response)
Retrieves the next page of results.
close()
Close httplib2 connections.
get(name, x__xgafv=None)
Get a finding by name. The `name` field should have the format: `projects/{project}/findings/{finding}`
Args:
name: string, Required. Name of the finding to get. (required)
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # A ‘stateless’ and a point in time event that a check produced a result of interest.
"aiSummary": "A String", # Optional. AI summary of the finding.
"alert": "A String", # Optional. Name of the alert that this finding is bound to.
"audit": { # Tracks basic CRUD facts. # Output only. Audit data about the finding.
"createTime": "A String", # Output only. Time of creation.
"creator": "A String", # Output only. Agent that created or updated the record, could be a UserId or a JobId.
"updateTime": "A String", # Output only. Time of creation or last update.
"updater": "A String", # Output only. Agent that last updated the record, could be a UserId or a JobId.
},
"configurations": [ # Optional. Configuration names that are bound to this finding.
"A String",
],
"detail": { # Wrapper class that contains the union struct for all the various findings detail specific classes. # Required. Holder of the domain specific details of the finding.
"dataLeak": { # A detail object for a Data Leak finding. # Data Leak finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Data Leak finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the Data Leak finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the Data Leak finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the Data Leak finding. This indicates the potential impact of the threat.
},
"detailType": "A String", # Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union.
"domainMonitoring": { # A detailed object for a Domain or URL finding. # Domain Monitoring finding detail type.
"dnsDetails": { # The DNS details of the domain. # Optional. The DNS details of the domain or URL.
"dnsRecords": [ # Optional. The DNS records of the domain.
{ # The DNS record of the domain.
"asnHosting": "A String", # Optional. The ASN hosting the domain.
"asnRegionCode": "A String", # Optional. The region code of the ASN. Use ISO 3166-1 alpha-2 codes.
"ipRegionCode": "A String", # Optional. The region code associated with the resolved IP. Use ISO 3166-1 alpha-2 codes.
"recordData": "A String", # Optional. The value of the DNS record.
"resolvedIp": "A String", # Optional. The resolved IP address.
"ttl": 42, # Optional. The TTL of the DNS record.
"type": "A String", # Optional. The type of the DNS record.
},
],
"retrievalTime": "A String", # Optional. The time the DNS details were retrieved.
},
"domainDetails": { # Details specific to a monitored domain. # Details specific to a monitored domain.
"domain": "A String", # Required. The domain name to match against.
},
"gtiDetails": { # The GTI details of the domain. # Optional. The GTI details of the domain or URL.
"avDetections": { # Details about the detection vendors. # Optional. Detection counts across vendor feeds.
"detectedVendorCount": 42, # Optional. Number of vendors that detected the threat.
"totalVendorCount": 42, # Optional. Total number of vendors.
},
"domainPermutation": "A String", # Optional. The permutation technique used for the domain (e.g., dictionary, homoglyph).
"gtiDomainUri": "A String", # Optional. The GTI link for the domain.
"gtiScore": 42, # Optional. The GTI score of the domain. The threat score is a number between 0 and 100.
"threatClassification": "A String", # Optional. The threat classification of the domain, obtained from the domain report (e.g. DomainMonitoring).
"verdict": "A String", # Output only. The verdict of the domain.
},
"infrastructure": { # Core infrastructure observations associated with the URL or Domain. # Optional. The infrastructure of the domain or URL.
"certificateDetails": { # Details regarding the SSL certificate configuration. # Optional. SSL certificate details.
"issuer": "A String", # Optional. The SSL certificate issuer.
"subjectAlternativeNames": [ # Optional. The SSL subject alternative names.
"A String",
],
},
"urlResponse": "A String", # Optional. The raw URL response string.
},
"matchedDomain": "A String", # Optional. The matched domain.
"protectedBrand": "A String", # The protected brand name that triggered the alert.
"protectedDomain": { # Details specific to a monitored domain. # The protected domain that triggered the alert.
"domain": "A String", # Required. The domain name to match against.
},
"registrationDetails": { # Extracted WHOIS and DNS registration details of the domain. # Optional. Extracted WHOIS and DNS registration details.
"expireTime": "A String", # Optional. The specific timestamp when the current domain registration expires.
"privateRegistration": True or False, # Optional. Indicates whether private registration is enabled on the WHOIS record.
"registrantCountry": "A String", # Optional. The country code of the registrant (e.g., US). Use ISO 3166-1 alpha-2 codes
"registrar": "A String", # Optional. The registrar where the domain was registered (e.g., NameCheap).
"registrationTime": "A String", # Optional. The specific timestamp when the domain registration was created.
},
"relationships": { # Related entities and domains observed for the target. # Optional. The relationships of the domain or URL.
"relatedUrls": [ # Optional. Related URLs associated with the domain.
"A String",
],
"siblingDomains": [ # Optional. Sibling domains sharing the same IP address.
"A String",
],
"subdomains": [ # Optional. Subdomains associated with the target domain or URL.
"A String",
],
},
"threatAttributionDetails": { # Threat attribution information (actor, campaign, etc.). # Optional. The threat attribution details of the domain or URL.
"actors": [ # Optional. The threat actors associated with the target.
"A String",
],
"collections": [ # Optional. The threat collections detected.
"A String",
],
"malware": [ # Optional. The malware associated with the threat.
"A String",
],
},
"urlDetails": { # Details specific to a monitored URL. # Details specific to a monitored URL.
"url": "A String", # Required. The URL to match against.
},
"whoisDetails": { # The whois details of the domain. # Optional. The whois details of the domain or URL.
"retrievalTime": "A String", # Optional. The time the whois details were retrieved.
"whois": "A String", # Optional. The whois details of the domain.
},
},
"initialAccessBroker": { # A detail object for an Initial Access Broker (IAB) finding. # Initial Access Broker finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the IAB finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the IAB finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the IAB finding. This is a float value between 0 and 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the IAB finding. This indicates the potential impact of the threat.
},
"insiderThreat": { # A detail object for a InsiderThreat finding. # Insider Threat finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Insider Threat finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the InsiderThreat finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the InsiderThreat finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the InsiderThreat finding. This indicates the potential impact of the threat.
},
"targetTechnology": { # Contains details for a technology watchlist finding. # Technology Watchlist finding detail type.
"vulnerabilityMatch": { # Contains details about a vulnerability match. # Optional. The vulnerability match details.
"associations": [ # Optional. Associated threat actors, malware, etc. This is embedded as a snapshot because the details of the association at the time of the vulnerability match are important for context and reporting.
{ # Represents an association with a vulnerability.
"id": "A String", # Required. The ID of the association.
"type": "A String", # Required. The type of the association.
},
],
"collectionId": "A String", # Required. The collection ID of the vulnerability. Ex: "vulnerability--cve-2025-9876".
"cveId": "A String", # Required. The CVE ID of the vulnerability. Ex: "CVE-2025-9876". See https://www.cve.org/ for more information.
"cvss3Score": 3.14, # Required. The CVSS score of the vulnerability. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Example: 6.4.
"description": "A String", # Required. A description of the vulnerability.
"disclosureTime": "A String", # Optional. The disclosure time of the vulnerability.
"epssScore": 3.14, # Optional. The EPSS score, representing the probability of exploitation. Example: 0.87.
"exploitationConsequences": [ # Optional. List of exploitation consequences for the vulnerability.
"A String",
],
"exploitationState": "A String", # Required. The exploitation state of the vulnerability.
"exploitationVectors": [ # Optional. List of exploitation vectors for the vulnerability.
"A String",
],
"matchedTechnologies": [ # Optional. The specific technologies from the configured watchlist that triggered the match. Ex: "Apache Struts".
"A String",
],
"priority": "A String", # Optional. The priority level of the vulnerability data. Ex: "P1".
"productFixes": [ # Optional. List of product fixes for the vulnerability.
{ # Contains details about a product fix.
"displayName": "A String", # Required. The name of the fix. Ex: "Magento".
"publishTime": "A String", # Optional. The published time of the fix.
"sourceId": "A String", # Required. The source ID of the fix. Ex: "APPSEC-1420".
"uri": "A String", # Optional. The URI of the fix.
},
],
"publicExploits": [ # Optional. List of public exploits.
{ # Contains details about a public exploit.
"exploitGrade": "A String", # Optional. The grade of the exploit. Ex: "non-weaponized".
"exploitName": "A String", # Required. The name of the exploit. Ex: "Magentounauth.php.txt".
"exploitReliability": "A String", # Optional. The reliability of the exploit. Ex: "Unreviewed".
"releaseTime": "A String", # Optional. The release time of the exploit.
"sizeBytes": "A String", # Optional. The size of the exploit.
"uri": "A String", # Optional. The URI of the exploit.
},
],
"publiclyAvailableExploit": True or False, # Output only. Whether a publicly available exploit exists.
"riskRating": "A String", # Required. The risk rating of the vulnerability.
"technologies": [ # Required. All technologies affected by the vulnerability. Ex: "Apache Struts".
"A String",
],
},
},
},
"displayName": "A String", # Required. A short descriptive title for the finding <= 250 chars. EX: "Actor 'baddy' offering $1000 for credentials of 'goodguy'".
"name": "A String", # Identifier. Server generated name for the finding (leave clear during creation). Format: projects/{project}/findings/{finding}
"provider": "A String", # Required. Logical source of this finding (name of the sub-engine).
"relevanceAnalysis": { # Structured relevance analysis for a threat. # Output only. High-Precision Relevance Analysis verdict for the finding.
"confidence": "A String", # The level of confidence in the given verdict.
"evidence": { # Details the evidence used to determine the relevance verdict. # Evidence supporting the verdict, including matched and unmatched items.
"commonThemes": [ # A list of semantic themes or concepts found to be common, related, or aligned between the sources, supporting the verdict.
"A String",
],
"distinctThemes": [ # A list of semantic themes or descriptions unique to one source or semantically distant.
"A String",
],
},
"reasoning": "A String", # Human-readable explanation from the matcher, detailing why a particular result is considered relevant or not relevant.
"relevanceLevel": "A String", # The level of relevance.
"relevant": True or False, # Indicates whether the threat is considered relevant.
},
"reoccurrenceTimes": [ # Output only. When identical finding (same labels and same details) has re-occurred.
"A String",
],
"severity": 3.14, # Optional. Deprecated: Use the `severity_analysis` field instead. Base severity score from the finding source.
"severityAnalysis": { # Structured severity analysis for a threat. # Output only. High-Precision Severity Analysis verdict for the finding.
"confidence": "A String", # The level of confidence in the given verdict.
"reasoning": "A String", # Human-readable explanation from the model, detailing why a particular result is considered to have a certain severity.
"severityLevel": "A String", # The level of severity.
},
}
list(parent, filter=None, orderBy=None, pageSize=None, pageToken=None, x__xgafv=None)
Get a list of findings that meet the filter criteria. The `parent` field in ListFindingsRequest should have the format: projects/{project}
Args:
parent: string, Required. Parent of the findings. (required)
filter: string, Optional. Filter criteria.
orderBy: string, Optional. Order by criteria in the csv format: "field1,field2 desc" or "field1,field2" or "field1 asc, field2".
pageSize: integer, Optional. Page size.
pageToken: string, Optional. Page token.
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # Response message for ListFindings.
"findings": [ # List of findings.
{ # A ‘stateless’ and a point in time event that a check produced a result of interest.
"aiSummary": "A String", # Optional. AI summary of the finding.
"alert": "A String", # Optional. Name of the alert that this finding is bound to.
"audit": { # Tracks basic CRUD facts. # Output only. Audit data about the finding.
"createTime": "A String", # Output only. Time of creation.
"creator": "A String", # Output only. Agent that created or updated the record, could be a UserId or a JobId.
"updateTime": "A String", # Output only. Time of creation or last update.
"updater": "A String", # Output only. Agent that last updated the record, could be a UserId or a JobId.
},
"configurations": [ # Optional. Configuration names that are bound to this finding.
"A String",
],
"detail": { # Wrapper class that contains the union struct for all the various findings detail specific classes. # Required. Holder of the domain specific details of the finding.
"dataLeak": { # A detail object for a Data Leak finding. # Data Leak finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Data Leak finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the Data Leak finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the Data Leak finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the Data Leak finding. This indicates the potential impact of the threat.
},
"detailType": "A String", # Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union.
"domainMonitoring": { # A detailed object for a Domain or URL finding. # Domain Monitoring finding detail type.
"dnsDetails": { # The DNS details of the domain. # Optional. The DNS details of the domain or URL.
"dnsRecords": [ # Optional. The DNS records of the domain.
{ # The DNS record of the domain.
"asnHosting": "A String", # Optional. The ASN hosting the domain.
"asnRegionCode": "A String", # Optional. The region code of the ASN. Use ISO 3166-1 alpha-2 codes.
"ipRegionCode": "A String", # Optional. The region code associated with the resolved IP. Use ISO 3166-1 alpha-2 codes.
"recordData": "A String", # Optional. The value of the DNS record.
"resolvedIp": "A String", # Optional. The resolved IP address.
"ttl": 42, # Optional. The TTL of the DNS record.
"type": "A String", # Optional. The type of the DNS record.
},
],
"retrievalTime": "A String", # Optional. The time the DNS details were retrieved.
},
"domainDetails": { # Details specific to a monitored domain. # Details specific to a monitored domain.
"domain": "A String", # Required. The domain name to match against.
},
"gtiDetails": { # The GTI details of the domain. # Optional. The GTI details of the domain or URL.
"avDetections": { # Details about the detection vendors. # Optional. Detection counts across vendor feeds.
"detectedVendorCount": 42, # Optional. Number of vendors that detected the threat.
"totalVendorCount": 42, # Optional. Total number of vendors.
},
"domainPermutation": "A String", # Optional. The permutation technique used for the domain (e.g., dictionary, homoglyph).
"gtiDomainUri": "A String", # Optional. The GTI link for the domain.
"gtiScore": 42, # Optional. The GTI score of the domain. The threat score is a number between 0 and 100.
"threatClassification": "A String", # Optional. The threat classification of the domain, obtained from the domain report (e.g. DomainMonitoring).
"verdict": "A String", # Output only. The verdict of the domain.
},
"infrastructure": { # Core infrastructure observations associated with the URL or Domain. # Optional. The infrastructure of the domain or URL.
"certificateDetails": { # Details regarding the SSL certificate configuration. # Optional. SSL certificate details.
"issuer": "A String", # Optional. The SSL certificate issuer.
"subjectAlternativeNames": [ # Optional. The SSL subject alternative names.
"A String",
],
},
"urlResponse": "A String", # Optional. The raw URL response string.
},
"matchedDomain": "A String", # Optional. The matched domain.
"protectedBrand": "A String", # The protected brand name that triggered the alert.
"protectedDomain": { # Details specific to a monitored domain. # The protected domain that triggered the alert.
"domain": "A String", # Required. The domain name to match against.
},
"registrationDetails": { # Extracted WHOIS and DNS registration details of the domain. # Optional. Extracted WHOIS and DNS registration details.
"expireTime": "A String", # Optional. The specific timestamp when the current domain registration expires.
"privateRegistration": True or False, # Optional. Indicates whether private registration is enabled on the WHOIS record.
"registrantCountry": "A String", # Optional. The country code of the registrant (e.g., US). Use ISO 3166-1 alpha-2 codes
"registrar": "A String", # Optional. The registrar where the domain was registered (e.g., NameCheap).
"registrationTime": "A String", # Optional. The specific timestamp when the domain registration was created.
},
"relationships": { # Related entities and domains observed for the target. # Optional. The relationships of the domain or URL.
"relatedUrls": [ # Optional. Related URLs associated with the domain.
"A String",
],
"siblingDomains": [ # Optional. Sibling domains sharing the same IP address.
"A String",
],
"subdomains": [ # Optional. Subdomains associated with the target domain or URL.
"A String",
],
},
"threatAttributionDetails": { # Threat attribution information (actor, campaign, etc.). # Optional. The threat attribution details of the domain or URL.
"actors": [ # Optional. The threat actors associated with the target.
"A String",
],
"collections": [ # Optional. The threat collections detected.
"A String",
],
"malware": [ # Optional. The malware associated with the threat.
"A String",
],
},
"urlDetails": { # Details specific to a monitored URL. # Details specific to a monitored URL.
"url": "A String", # Required. The URL to match against.
},
"whoisDetails": { # The whois details of the domain. # Optional. The whois details of the domain or URL.
"retrievalTime": "A String", # Optional. The time the whois details were retrieved.
"whois": "A String", # Optional. The whois details of the domain.
},
},
"initialAccessBroker": { # A detail object for an Initial Access Broker (IAB) finding. # Initial Access Broker finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the IAB finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the IAB finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the IAB finding. This is a float value between 0 and 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the IAB finding. This indicates the potential impact of the threat.
},
"insiderThreat": { # A detail object for a InsiderThreat finding. # Insider Threat finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Insider Threat finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the InsiderThreat finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the InsiderThreat finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the InsiderThreat finding. This indicates the potential impact of the threat.
},
"targetTechnology": { # Contains details for a technology watchlist finding. # Technology Watchlist finding detail type.
"vulnerabilityMatch": { # Contains details about a vulnerability match. # Optional. The vulnerability match details.
"associations": [ # Optional. Associated threat actors, malware, etc. This is embedded as a snapshot because the details of the association at the time of the vulnerability match are important for context and reporting.
{ # Represents an association with a vulnerability.
"id": "A String", # Required. The ID of the association.
"type": "A String", # Required. The type of the association.
},
],
"collectionId": "A String", # Required. The collection ID of the vulnerability. Ex: "vulnerability--cve-2025-9876".
"cveId": "A String", # Required. The CVE ID of the vulnerability. Ex: "CVE-2025-9876". See https://www.cve.org/ for more information.
"cvss3Score": 3.14, # Required. The CVSS score of the vulnerability. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Example: 6.4.
"description": "A String", # Required. A description of the vulnerability.
"disclosureTime": "A String", # Optional. The disclosure time of the vulnerability.
"epssScore": 3.14, # Optional. The EPSS score, representing the probability of exploitation. Example: 0.87.
"exploitationConsequences": [ # Optional. List of exploitation consequences for the vulnerability.
"A String",
],
"exploitationState": "A String", # Required. The exploitation state of the vulnerability.
"exploitationVectors": [ # Optional. List of exploitation vectors for the vulnerability.
"A String",
],
"matchedTechnologies": [ # Optional. The specific technologies from the configured watchlist that triggered the match. Ex: "Apache Struts".
"A String",
],
"priority": "A String", # Optional. The priority level of the vulnerability data. Ex: "P1".
"productFixes": [ # Optional. List of product fixes for the vulnerability.
{ # Contains details about a product fix.
"displayName": "A String", # Required. The name of the fix. Ex: "Magento".
"publishTime": "A String", # Optional. The published time of the fix.
"sourceId": "A String", # Required. The source ID of the fix. Ex: "APPSEC-1420".
"uri": "A String", # Optional. The URI of the fix.
},
],
"publicExploits": [ # Optional. List of public exploits.
{ # Contains details about a public exploit.
"exploitGrade": "A String", # Optional. The grade of the exploit. Ex: "non-weaponized".
"exploitName": "A String", # Required. The name of the exploit. Ex: "Magentounauth.php.txt".
"exploitReliability": "A String", # Optional. The reliability of the exploit. Ex: "Unreviewed".
"releaseTime": "A String", # Optional. The release time of the exploit.
"sizeBytes": "A String", # Optional. The size of the exploit.
"uri": "A String", # Optional. The URI of the exploit.
},
],
"publiclyAvailableExploit": True or False, # Output only. Whether a publicly available exploit exists.
"riskRating": "A String", # Required. The risk rating of the vulnerability.
"technologies": [ # Required. All technologies affected by the vulnerability. Ex: "Apache Struts".
"A String",
],
},
},
},
"displayName": "A String", # Required. A short descriptive title for the finding <= 250 chars. EX: "Actor 'baddy' offering $1000 for credentials of 'goodguy'".
"name": "A String", # Identifier. Server generated name for the finding (leave clear during creation). Format: projects/{project}/findings/{finding}
"provider": "A String", # Required. Logical source of this finding (name of the sub-engine).
"relevanceAnalysis": { # Structured relevance analysis for a threat. # Output only. High-Precision Relevance Analysis verdict for the finding.
"confidence": "A String", # The level of confidence in the given verdict.
"evidence": { # Details the evidence used to determine the relevance verdict. # Evidence supporting the verdict, including matched and unmatched items.
"commonThemes": [ # A list of semantic themes or concepts found to be common, related, or aligned between the sources, supporting the verdict.
"A String",
],
"distinctThemes": [ # A list of semantic themes or descriptions unique to one source or semantically distant.
"A String",
],
},
"reasoning": "A String", # Human-readable explanation from the matcher, detailing why a particular result is considered relevant or not relevant.
"relevanceLevel": "A String", # The level of relevance.
"relevant": True or False, # Indicates whether the threat is considered relevant.
},
"reoccurrenceTimes": [ # Output only. When identical finding (same labels and same details) has re-occurred.
"A String",
],
"severity": 3.14, # Optional. Deprecated: Use the `severity_analysis` field instead. Base severity score from the finding source.
"severityAnalysis": { # Structured severity analysis for a threat. # Output only. High-Precision Severity Analysis verdict for the finding.
"confidence": "A String", # The level of confidence in the given verdict.
"reasoning": "A String", # Human-readable explanation from the model, detailing why a particular result is considered to have a certain severity.
"severityLevel": "A String", # The level of severity.
},
},
],
"nextPageToken": "A String", # Page token.
}
list_next(previous_request, previous_response)
Retrieves the next page of results. Args: previous_request: The request for the previous page. (required) previous_response: The response from the request for the previous page. (required) Returns: A request object that you can call 'execute()' on to request the next page. Returns None if there are no more items in the collection.
search(parent, orderBy=None, pageSize=None, pageToken=None, query=None, x__xgafv=None)
SearchFindings is a more powerful version of ListFindings that supports complex queries like "findings for alerts" using functions such as `has_alert` in the query string. The `parent` field in SearchFindingsRequest should have the format: projects/{project} Example to search for findings for a specific issue: `has_alert("name=\"projects/gti-12345/alerts/alert-12345\"")`
Args:
parent: string, Required. Parent of the findings. Format: vaults/{vault} (required)
orderBy: string, Optional. Order by criteria in the csv format: "field1,field2 desc" or "field1,field2" or "field1 asc, field2".
pageSize: integer, Optional. Page size.
pageToken: string, Optional. Page token.
query: string, Optional. Query on what findings will be returned. This supports the same filter criteria as FindingService.ListFindings as well as the following relationship query `has_alert`. Example: - `has_alert("name=\"projects/gti-12345/alerts/alert-12345\"")`
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # Response message for SearchFindings.
"findings": [ # List of findings.
{ # A ‘stateless’ and a point in time event that a check produced a result of interest.
"aiSummary": "A String", # Optional. AI summary of the finding.
"alert": "A String", # Optional. Name of the alert that this finding is bound to.
"audit": { # Tracks basic CRUD facts. # Output only. Audit data about the finding.
"createTime": "A String", # Output only. Time of creation.
"creator": "A String", # Output only. Agent that created or updated the record, could be a UserId or a JobId.
"updateTime": "A String", # Output only. Time of creation or last update.
"updater": "A String", # Output only. Agent that last updated the record, could be a UserId or a JobId.
},
"configurations": [ # Optional. Configuration names that are bound to this finding.
"A String",
],
"detail": { # Wrapper class that contains the union struct for all the various findings detail specific classes. # Required. Holder of the domain specific details of the finding.
"dataLeak": { # A detail object for a Data Leak finding. # Data Leak finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Data Leak finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the Data Leak finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the Data Leak finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the Data Leak finding. This indicates the potential impact of the threat.
},
"detailType": "A String", # Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union.
"domainMonitoring": { # A detailed object for a Domain or URL finding. # Domain Monitoring finding detail type.
"dnsDetails": { # The DNS details of the domain. # Optional. The DNS details of the domain or URL.
"dnsRecords": [ # Optional. The DNS records of the domain.
{ # The DNS record of the domain.
"asnHosting": "A String", # Optional. The ASN hosting the domain.
"asnRegionCode": "A String", # Optional. The region code of the ASN. Use ISO 3166-1 alpha-2 codes.
"ipRegionCode": "A String", # Optional. The region code associated with the resolved IP. Use ISO 3166-1 alpha-2 codes.
"recordData": "A String", # Optional. The value of the DNS record.
"resolvedIp": "A String", # Optional. The resolved IP address.
"ttl": 42, # Optional. The TTL of the DNS record.
"type": "A String", # Optional. The type of the DNS record.
},
],
"retrievalTime": "A String", # Optional. The time the DNS details were retrieved.
},
"domainDetails": { # Details specific to a monitored domain. # Details specific to a monitored domain.
"domain": "A String", # Required. The domain name to match against.
},
"gtiDetails": { # The GTI details of the domain. # Optional. The GTI details of the domain or URL.
"avDetections": { # Details about the detection vendors. # Optional. Detection counts across vendor feeds.
"detectedVendorCount": 42, # Optional. Number of vendors that detected the threat.
"totalVendorCount": 42, # Optional. Total number of vendors.
},
"domainPermutation": "A String", # Optional. The permutation technique used for the domain (e.g., dictionary, homoglyph).
"gtiDomainUri": "A String", # Optional. The GTI link for the domain.
"gtiScore": 42, # Optional. The GTI score of the domain. The threat score is a number between 0 and 100.
"threatClassification": "A String", # Optional. The threat classification of the domain, obtained from the domain report (e.g. DomainMonitoring).
"verdict": "A String", # Output only. The verdict of the domain.
},
"infrastructure": { # Core infrastructure observations associated with the URL or Domain. # Optional. The infrastructure of the domain or URL.
"certificateDetails": { # Details regarding the SSL certificate configuration. # Optional. SSL certificate details.
"issuer": "A String", # Optional. The SSL certificate issuer.
"subjectAlternativeNames": [ # Optional. The SSL subject alternative names.
"A String",
],
},
"urlResponse": "A String", # Optional. The raw URL response string.
},
"matchedDomain": "A String", # Optional. The matched domain.
"protectedBrand": "A String", # The protected brand name that triggered the alert.
"protectedDomain": { # Details specific to a monitored domain. # The protected domain that triggered the alert.
"domain": "A String", # Required. The domain name to match against.
},
"registrationDetails": { # Extracted WHOIS and DNS registration details of the domain. # Optional. Extracted WHOIS and DNS registration details.
"expireTime": "A String", # Optional. The specific timestamp when the current domain registration expires.
"privateRegistration": True or False, # Optional. Indicates whether private registration is enabled on the WHOIS record.
"registrantCountry": "A String", # Optional. The country code of the registrant (e.g., US). Use ISO 3166-1 alpha-2 codes
"registrar": "A String", # Optional. The registrar where the domain was registered (e.g., NameCheap).
"registrationTime": "A String", # Optional. The specific timestamp when the domain registration was created.
},
"relationships": { # Related entities and domains observed for the target. # Optional. The relationships of the domain or URL.
"relatedUrls": [ # Optional. Related URLs associated with the domain.
"A String",
],
"siblingDomains": [ # Optional. Sibling domains sharing the same IP address.
"A String",
],
"subdomains": [ # Optional. Subdomains associated with the target domain or URL.
"A String",
],
},
"threatAttributionDetails": { # Threat attribution information (actor, campaign, etc.). # Optional. The threat attribution details of the domain or URL.
"actors": [ # Optional. The threat actors associated with the target.
"A String",
],
"collections": [ # Optional. The threat collections detected.
"A String",
],
"malware": [ # Optional. The malware associated with the threat.
"A String",
],
},
"urlDetails": { # Details specific to a monitored URL. # Details specific to a monitored URL.
"url": "A String", # Required. The URL to match against.
},
"whoisDetails": { # The whois details of the domain. # Optional. The whois details of the domain or URL.
"retrievalTime": "A String", # Optional. The time the whois details were retrieved.
"whois": "A String", # Optional. The whois details of the domain.
},
},
"initialAccessBroker": { # A detail object for an Initial Access Broker (IAB) finding. # Initial Access Broker finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the IAB finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the IAB finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the IAB finding. This is a float value between 0 and 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the IAB finding. This indicates the potential impact of the threat.
},
"insiderThreat": { # A detail object for a InsiderThreat finding. # Insider Threat finding detail type.
"discoveryDocument": { # Replaces the raw string ID to hold associated metadata. # Optional. The discovery document associated with the Insider Threat finding.
"communicationContext": { # Detailed communication context metadata for documents originating from deep and dark web communication channels. # Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels.
"channelDescription": "A String", # Optional. Description of the communication channel.
"channelName": "A String", # Optional. Name of the communication channel.
"channelPath": "A String", # Optional. Channel path (e.g. forum path or sub-channel).
"channelUrl": "A String", # Optional. URL of the communication channel.
"serviceName": "A String", # Optional. Service from the collection event origin (e.g. forum or chat service name).
"threadId": "A String", # Optional. Conversation thread identifier.
},
"documentId": "A String", # Output only. The identifier of the discovery document.
"documentType": "A String", # Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).
},
"documentId": "A String", # Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the InsiderThreat finding. This ID can be used to retrieve the content of the document for further analysis.
"matchScore": 3.14, # Required. Reference to the match score of the InsiderThreat finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.
"severity": "A String", # Required. The severity of the InsiderThreat finding. This indicates the potential impact of the threat.
},
"targetTechnology": { # Contains details for a technology watchlist finding. # Technology Watchlist finding detail type.
"vulnerabilityMatch": { # Contains details about a vulnerability match. # Optional. The vulnerability match details.
"associations": [ # Optional. Associated threat actors, malware, etc. This is embedded as a snapshot because the details of the association at the time of the vulnerability match are important for context and reporting.
{ # Represents an association with a vulnerability.
"id": "A String", # Required. The ID of the association.
"type": "A String", # Required. The type of the association.
},
],
"collectionId": "A String", # Required. The collection ID of the vulnerability. Ex: "vulnerability--cve-2025-9876".
"cveId": "A String", # Required. The CVE ID of the vulnerability. Ex: "CVE-2025-9876". See https://www.cve.org/ for more information.
"cvss3Score": 3.14, # Required. The CVSS score of the vulnerability. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Example: 6.4.
"description": "A String", # Required. A description of the vulnerability.
"disclosureTime": "A String", # Optional. The disclosure time of the vulnerability.
"epssScore": 3.14, # Optional. The EPSS score, representing the probability of exploitation. Example: 0.87.
"exploitationConsequences": [ # Optional. List of exploitation consequences for the vulnerability.
"A String",
],
"exploitationState": "A String", # Required. The exploitation state of the vulnerability.
"exploitationVectors": [ # Optional. List of exploitation vectors for the vulnerability.
"A String",
],
"matchedTechnologies": [ # Optional. The specific technologies from the configured watchlist that triggered the match. Ex: "Apache Struts".
"A String",
],
"priority": "A String", # Optional. The priority level of the vulnerability data. Ex: "P1".
"productFixes": [ # Optional. List of product fixes for the vulnerability.
{ # Contains details about a product fix.
"displayName": "A String", # Required. The name of the fix. Ex: "Magento".
"publishTime": "A String", # Optional. The published time of the fix.
"sourceId": "A String", # Required. The source ID of the fix. Ex: "APPSEC-1420".
"uri": "A String", # Optional. The URI of the fix.
},
],
"publicExploits": [ # Optional. List of public exploits.
{ # Contains details about a public exploit.
"exploitGrade": "A String", # Optional. The grade of the exploit. Ex: "non-weaponized".
"exploitName": "A String", # Required. The name of the exploit. Ex: "Magentounauth.php.txt".
"exploitReliability": "A String", # Optional. The reliability of the exploit. Ex: "Unreviewed".
"releaseTime": "A String", # Optional. The release time of the exploit.
"sizeBytes": "A String", # Optional. The size of the exploit.
"uri": "A String", # Optional. The URI of the exploit.
},
],
"publiclyAvailableExploit": True or False, # Output only. Whether a publicly available exploit exists.
"riskRating": "A String", # Required. The risk rating of the vulnerability.
"technologies": [ # Required. All technologies affected by the vulnerability. Ex: "Apache Struts".
"A String",
],
},
},
},
"displayName": "A String", # Required. A short descriptive title for the finding <= 250 chars. EX: "Actor 'baddy' offering $1000 for credentials of 'goodguy'".
"name": "A String", # Identifier. Server generated name for the finding (leave clear during creation). Format: projects/{project}/findings/{finding}
"provider": "A String", # Required. Logical source of this finding (name of the sub-engine).
"relevanceAnalysis": { # Structured relevance analysis for a threat. # Output only. High-Precision Relevance Analysis verdict for the finding.
"confidence": "A String", # The level of confidence in the given verdict.
"evidence": { # Details the evidence used to determine the relevance verdict. # Evidence supporting the verdict, including matched and unmatched items.
"commonThemes": [ # A list of semantic themes or concepts found to be common, related, or aligned between the sources, supporting the verdict.
"A String",
],
"distinctThemes": [ # A list of semantic themes or descriptions unique to one source or semantically distant.
"A String",
],
},
"reasoning": "A String", # Human-readable explanation from the matcher, detailing why a particular result is considered relevant or not relevant.
"relevanceLevel": "A String", # The level of relevance.
"relevant": True or False, # Indicates whether the threat is considered relevant.
},
"reoccurrenceTimes": [ # Output only. When identical finding (same labels and same details) has re-occurred.
"A String",
],
"severity": 3.14, # Optional. Deprecated: Use the `severity_analysis` field instead. Base severity score from the finding source.
"severityAnalysis": { # Structured severity analysis for a threat. # Output only. High-Precision Severity Analysis verdict for the finding.
"confidence": "A String", # The level of confidence in the given verdict.
"reasoning": "A String", # Human-readable explanation from the model, detailing why a particular result is considered to have a certain severity.
"severityLevel": "A String", # The level of severity.
},
},
],
"nextPageToken": "A String", # Page token.
}
search_next(previous_request, previous_response)
Retrieves the next page of results. Args: previous_request: The request for the previous page. (required) previous_response: The response from the request for the previous page. (required) Returns: A request object that you can call 'execute()' on to request the next page. Returns None if there are no more items in the collection.