Get Threat Context
get_threat_contextRetrieve a threat's timeline and the custom rule that triggered it, ensuring verdicts rely on evidence rather than misleading threat names.
Instructions
Get timeline of a threat — reveals the custom rule name that triggered it. ALWAYS call before verdict. If Custom Rule, the threat name is a label not evidence.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tenant | No | ||
| threat_id | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||