get_detection
Retrieve a detection's full details by ID, including query logic, logsource, data sources, CVEs, and false positives, to extract conditions for kill-chain correlation.
Instructions
Get full details of a specific detection by ID. Returns query logic, logsource (product/category/service), data_sources, process_names, platforms, CVEs, and false_positives. Use this to extract detection conditions for kill-chain correlation.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | Detection ID |