get_endpoint_threat_alerts
Retrieve Threat Response alerts for a specific endpoint, showing performance and anomaly detection events from the last 24 hours. Use to investigate zero-day or unusual activity history.
Instructions
특정 엔드포인트의 Threat Response 알림(성능/이상 탐지 alert)을 조회합니다. 내부적으로 Direct Connect 연결을 연 뒤 최근 24시간 alert를 가져옵니다. (업무요건: 제로데이/이상탐지 이력)
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| endpointId | Yes | 대상 엔드포인트 ID (EID). get_all_assets 등으로 얻은 computerID를 사용하세요. |