get_hunting_ruleset
Retrieve a hunting ruleset by identifier to access Yara rules and metadata including creation date, modification date, and tags.
Instructions
Get a Hunting Ruleset object from Google Threat Intelligence.
A Hunting Ruleset object describes a user's hunting ruleset. It may contain multiple Yara rules.
The content of the Yara rules is in the rules attribute.
Some important object attributes:
creation_date: creation date as UTC timestamp.
modification_date (int): last modification date as UTC timestamp.
name (str): ruleset name.
rule_names (list[str]): contains the names of all rules in the ruleset.
number_of_rules (int): number of rules in the ruleset.
rules (str): rule file contents.
tags (list[str]): ruleset's custom tags.
Args: ruleset_id (required): Hunting ruleset identifier.
Returns: Hunting Ruleset object.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ruleset_id | Yes | ||
| api_key | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |