cURL
curl -X POST "https://app.cotool.ai/api/detection-queries/generate-system-prompt" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"prompt":"string","siemType":"splunk","category":"baseline_anomaly"}'import requests
url = "https://app.cotool.ai/api/detection-queries/generate-system-prompt"
payload = { "prompt": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({prompt: '<string>'})
};
fetch('https://app.cotool.ai/api/detection-queries/generate-system-prompt', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://app.cotool.ai/api/detection-queries/generate-system-prompt")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"prompt\": \"<string>\"\n}")
.asString();package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.cotool.ai/api/detection-queries/generate-system-prompt"
payload := strings.NewReader("{\n \"prompt\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"systemPrompt": "<string>"
}{
"error": "<string>",
"issues": [
{}
]
}{
"error": "<string>"
}{
"error": "<string>",
"missingPerms": [
"<string>"
]
}{
"error": "<string>"
}Detections
Generate a detection system prompt
Generates a system prompt for a detection based on category and user objective (without generating a query)
POST
/
api
/
detection-queries
/
generate-system-prompt
cURL
curl -X POST "https://app.cotool.ai/api/detection-queries/generate-system-prompt" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"prompt":"string","siemType":"splunk","category":"baseline_anomaly"}'import requests
url = "https://app.cotool.ai/api/detection-queries/generate-system-prompt"
payload = { "prompt": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({prompt: '<string>'})
};
fetch('https://app.cotool.ai/api/detection-queries/generate-system-prompt', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://app.cotool.ai/api/detection-queries/generate-system-prompt")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"prompt\": \"<string>\"\n}")
.asString();package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.cotool.ai/api/detection-queries/generate-system-prompt"
payload := strings.NewReader("{\n \"prompt\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"systemPrompt": "<string>"
}{
"error": "<string>",
"issues": [
{}
]
}{
"error": "<string>"
}{
"error": "<string>",
"missingPerms": [
"<string>"
]
}{
"error": "<string>"
}Authorizations
API Key authentication for programmatic access. Include your API key in the Authorization header as: Bearer your_api_key_here
Body
application/json
Request body for generating a detection system prompt
Natural language description of the detection objective
Minimum string length:
1The detection tool platform (SIEM or endpoint tools like SentinelOne)
Available options:
splunk, sumologic, elastic, databricks, datadog, scanner, runreveal, microsoftsentinel, cotool, sentinelone, gadmin The detection category
Available options:
baseline_anomaly, first_occurrence, sequence_pattern, privilege_escalation, custom Response
Successful response
Generated system prompt for manual query mode
The customized system prompt for the detection agent
Was this page helpful?
⌘I