cURL
Detections
Get detections overview
Unified detection-efficacy view across the whole detection suite: Cotool detection agents, the synced external rule inventory (detection_rules), and usable alert-reported detection labels active in the window that matched no inventory rule. Each item carries alert counts and dispositions (true positive / false positive / benign / escalated) over a rolling window, sorted noisiest-first.
GET
cURL
Authorizations
API Key authentication for programmatic access. Include your API key in the Authorization header as: Bearer your_api_key_here
Query Parameters
Rolling window in days for alert counts. Defaults to 30.
Required range:
1 <= x <= 365