# Custom Action Keyword

Generates the detection keyword (query) for a custom action based on the given attack module
and its related fields (file hashes, file name, play process ids, url or action id).
The returned keyword can then be passed to the Create Action endpoint.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
uint64

Action id (data exfiltration / email modules)

string

File name (file-based modules)

string

MD5 hash of the file

string

Attack module the action belongs to

play_process
array of uint64s

Play process ids (endpoint modules)

play_process
string

SHA1 hash of the file

string

SHA256 hash of the file

string

URL (URL Filtering module)

Responses

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json