{
  "name": "threatintelligence",
  "basePath": "",
  "schemas": {
    "Evidence": {
      "properties": {
        "commonThemes": {
          "type": "array",
          "description": "A list of semantic themes or concepts found to be common, related, or aligned between the sources, supporting the verdict.",
          "items": {
            "type": "string"
          }
        },
        "distinctThemes": {
          "description": "A list of semantic themes or descriptions unique to one source or semantically distant.",
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      },
      "id": "Evidence",
      "description": "Details the evidence used to determine the relevance verdict.",
      "type": "object"
    },
    "MarkAlertAsResolvedRequest": {
      "description": "Request message for MarkAlertAsResolved.",
      "properties": {},
      "id": "MarkAlertAsResolvedRequest",
      "type": "object"
    },
    "CustomerProfileSecurityConsiderations": {
      "id": "CustomerProfileSecurityConsiderations",
      "description": "Security considerations for the customer profile.",
      "type": "object",
      "properties": {
        "note": {
          "description": "Optional. A note about the security considerations.",
          "type": "string"
        },
        "considerations": {
          "type": "array",
          "description": "Optional. A series of considerations for the security of the organization, such as \"high risk of compromise\" or \"vulnerable to cyberbullying\".",
          "items": {
            "type": "string"
          }
        }
      }
    },
    "Infrastructure": {
      "properties": {
        "urlResponse": {
          "description": "Optional. The raw URL response string.",
          "type": "string"
        },
        "certificateDetails": {
          "$ref": "CertificateDetails",
          "description": "Optional. SSL certificate details."
        }
      },
      "id": "Infrastructure",
      "type": "object",
      "description": "Core infrastructure observations associated with the URL or Domain."
    },
    "DataLeakAlertDetail": {
      "id": "DataLeakAlertDetail",
      "type": "object",
      "description": "Captures the specific details of Data Leak alert.",
      "properties": {
        "discoveryDocuments": {
          "type": "array",
          "description": "Output only. New structured metadata payload.",
          "items": {
            "$ref": "DiscoveryDocument"
          },
          "readOnly": true
        },
        "discoveryDocumentIds": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Optional. Deprecated: Use `discovery_documents` instead. Array of ids to accommodate multiple discovery documents.",
          "deprecated": true
        },
        "severity": {
          "type": "string",
          "description": "Required. The severity of the Data Leak alert. Allowed values are: * `LOW` * `MEDIUM` * `HIGH` * `CRITICAL`"
        }
      }
    },
    "AlertDetail": {
      "properties": {
        "detailType": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union."
        },
        "dataLeak": {
          "description": "Data Leak alert detail type.",
          "$ref": "DataLeakAlertDetail"
        },
        "targetTechnology": {
          "description": "Technology Watchlist alert detail type.",
          "$ref": "TargetTechnologyAlertDetail"
        },
        "insiderThreat": {
          "$ref": "InsiderThreatAlertDetail",
          "description": "Insider Threat alert detail type."
        },
        "initialAccessBroker": {
          "$ref": "InitialAccessBrokerAlertDetail",
          "description": "Initial Access Broker alert detail type."
        },
        "domainMonitoring": {
          "description": "Domain Monitoring alert detail type.",
          "$ref": "DomainMonitoringAlertDetail"
        }
      },
      "description": "Container for different types of alert details.",
      "type": "object",
      "id": "AlertDetail"
    },
    "CustomerProfileCitedString": {
      "type": "object",
      "properties": {
        "value": {
          "type": "string",
          "description": "Required. The value of the string."
        },
        "citationIds": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Optional. The citation ids for the string."
        }
      },
      "id": "CustomerProfileCitedString",
      "description": "A string with citation ids."
    },
    "InsiderThreatAlertDetail": {
      "properties": {
        "discoveryDocumentIds": {
          "items": {
            "type": "string"
          },
          "description": "Optional. Deprecated: Use `discovery_documents` instead. Array of ids to accommodate multiple discovery documents.",
          "type": "array",
          "deprecated": true
        },
        "severity": {
          "description": "Required. The severity of the Insider Threat alert. Allowed values are: * `LOW` * `MEDIUM` * `HIGH` * `CRITICAL`",
          "type": "string"
        },
        "discoveryDocuments": {
          "type": "array",
          "items": {
            "$ref": "DiscoveryDocument"
          },
          "description": "Output only. New structured metadata payload.",
          "readOnly": true
        }
      },
      "type": "object",
      "description": "Captures the specific details of InsiderThreat alert.",
      "id": "InsiderThreatAlertDetail"
    },
    "MarkAlertAsDuplicateRequest": {
      "type": "object",
      "properties": {
        "duplicateOf": {
          "type": "string",
          "description": "Optional. Name of the alert to mark as a duplicate of. Format: projects/{project}/alerts/{alert}"
        }
      },
      "id": "MarkAlertAsDuplicateRequest",
      "description": "Request message for MarkAlertAsDuplicate."
    },
    "Status": {
      "id": "Status",
      "properties": {
        "code": {
          "description": "The status code, which should be an enum value of google.rpc.Code.",
          "format": "int32",
          "type": "integer"
        },
        "message": {
          "description": "A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the google.rpc.Status.details field, or localized by the client.",
          "type": "string"
        },
        "details": {
          "type": "array",
          "items": {
            "additionalProperties": {
              "description": "Properties of the object. Contains field @type with type URL.",
              "type": "any"
            },
            "type": "object"
          },
          "description": "A list of messages that carry the error details. There is a common set of message types for APIs to use."
        }
      },
      "type": "object",
      "description": "The `Status` type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by [gRPC](https://github.com/grpc). Each `Status` message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the [API Design Guide](https://cloud.google.com/apis/design/errors)."
    },
    "MarkAlertAsBenignRequest": {
      "id": "MarkAlertAsBenignRequest",
      "type": "object",
      "properties": {},
      "description": "Request message for MarkAlertAsBenign."
    },
    "InitialAccessBrokerFindingDetail": {
      "id": "InitialAccessBrokerFindingDetail",
      "properties": {
        "discoveryDocument": {
          "$ref": "DiscoveryDocument",
          "description": "Optional. The discovery document associated with the IAB finding."
        },
        "matchScore": {
          "description": "Required. Reference to the match score of the IAB finding. This is a float value between 0 and 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.",
          "type": "number",
          "format": "float"
        },
        "documentId": {
          "description": "Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the IAB finding. This ID can be used to retrieve the content of the document for further analysis.",
          "deprecated": true,
          "type": "string"
        },
        "severity": {
          "enum": [
            "SEVERITY_UNSPECIFIED",
            "LOW",
            "MEDIUM",
            "HIGH",
            "CRITICAL"
          ],
          "description": "Required. The severity of the IAB finding. This indicates the potential impact of the threat.",
          "type": "string",
          "enumDescriptions": [
            "Default value, should never be set.",
            "Low severity.",
            "Medium severity.",
            "High severity.",
            "Critical severity."
          ]
        }
      },
      "description": "A detail object for an Initial Access Broker (IAB) finding.",
      "type": "object"
    },
    "Association": {
      "properties": {
        "id": {
          "type": "string",
          "description": "Required. The ID of the association."
        },
        "type": {
          "enum": [
            "THREAT_INTEL_OBJECT_TYPE_UNSPECIFIED",
            "THREAT_INTEL_OBJECT_TYPE_THREAT_ACTOR",
            "THREAT_INTEL_OBJECT_TYPE_MALWARE",
            "THREAT_INTEL_OBJECT_TYPE_REPORT",
            "THREAT_INTEL_OBJECT_TYPE_CAMPAIGN",
            "THREAT_INTEL_OBJECT_TYPE_IOC_COLLECTION",
            "THREAT_INTEL_OBJECT_TYPE_SOFTWARE_AND_TOOLKITS",
            "THREAT_INTEL_OBJECT_TYPE_VULNERABILITY"
          ],
          "description": "Required. The type of the association.",
          "type": "string",
          "enumDescriptions": [
            "Unspecified object type.",
            "Threat actor object type.",
            "Malware object type.",
            "Report object type.",
            "Campaign object type.",
            "IoC Collection object type.",
            "Software and toolkits object type.",
            "Vulnerability object type."
          ]
        }
      },
      "description": "Represents an association with a vulnerability.",
      "type": "object",
      "id": "Association"
    },
    "CustomerProfileWebPresence": {
      "type": "object",
      "id": "CustomerProfileWebPresence",
      "description": "Web presence information for the customer profile.",
      "properties": {
        "domain": {
          "description": "Required. The domain name of the web presence.",
          "type": "string"
        },
        "citationIds": {
          "items": {
            "type": "string"
          },
          "description": "Optional. The citation ids for the web presence.",
          "type": "array"
        }
      }
    },
    "DomainMonitoringUrlDetails": {
      "properties": {
        "url": {
          "description": "Required. The URL to match against.",
          "type": "string"
        }
      },
      "type": "object",
      "description": "Details specific to a monitored URL.",
      "id": "DomainMonitoringUrlDetails"
    },
    "GenerateOrgProfileConfigurationRequest": {
      "properties": {
        "domain": {
          "description": "Required. The domain of the organization to generate the profile for.",
          "type": "string"
        },
        "displayName": {
          "description": "Required. The display name of the organization to generate the profile for.",
          "type": "string"
        }
      },
      "type": "object",
      "id": "GenerateOrgProfileConfigurationRequest",
      "description": "Request message for GenerateOrgProfileConfiguration."
    },
    "CustomerProfileCitation": {
      "description": "Citation information for the customer profile.",
      "type": "object",
      "id": "CustomerProfileCitation",
      "properties": {
        "source": {
          "type": "string",
          "description": "Required. The source of the citation."
        },
        "citationId": {
          "type": "string",
          "description": "Required. The citation id for the citation. Should be unique within the profile."
        },
        "retrievalTime": {
          "type": "string",
          "format": "google-datetime",
          "description": "The time the citation was retrieved."
        },
        "uri": {
          "type": "string",
          "description": "Optional. The url of the citation."
        },
        "document": {
          "type": "string",
          "description": "Required. The name of the document the citation is from."
        }
      }
    },
    "DomainConfiguration": {
      "id": "DomainConfiguration",
      "type": "object",
      "description": "Configuration holding settings for one or more monitored domains.",
      "properties": {
        "domainSettings": {
          "description": "Optional. A list of settings for individual domains.",
          "type": "array",
          "items": {
            "$ref": "DomainSetting"
          }
        }
      }
    },
    "Operation": {
      "type": "object",
      "id": "Operation",
      "description": "This resource represents a long-running operation that is the result of a network API call.",
      "properties": {
        "done": {
          "description": "If the value is `false`, it means the operation is still in progress. If `true`, the operation is completed, and either `error` or `response` is available.",
          "type": "boolean"
        },
        "name": {
          "type": "string",
          "description": "The server-assigned name, which is only unique within the same service that originally returns it. If you use the default HTTP mapping, the `name` should be a resource name ending with `operations/{unique_id}`."
        },
        "metadata": {
          "type": "object",
          "additionalProperties": {
            "type": "any",
            "description": "Properties of the object. Contains field @type with type URL."
          },
          "description": "Service-specific metadata associated with the operation. It typically contains progress information and common metadata such as create time. Some services might not provide such metadata. Any method that returns a long-running operation should document the metadata type, if any."
        },
        "response": {
          "type": "object",
          "additionalProperties": {
            "description": "Properties of the object. Contains field @type with type URL.",
            "type": "any"
          },
          "description": "The normal, successful response of the operation. If the original method returns no data on success, such as `Delete`, the response is `google.protobuf.Empty`. If the original method is standard `Get`/`Create`/`Update`, the response should be the resource. For other methods, the response should have the type `XxxResponse`, where `Xxx` is the original method name. For example, if the original method name is `TakeSnapshot()`, the inferred response type is `TakeSnapshotResponse`."
        },
        "error": {
          "$ref": "Status",
          "description": "The error result of the operation in case of failure or cancellation."
        }
      }
    },
    "ListConfigurationsResponse": {
      "type": "object",
      "description": "Response message for ListConfigurations.",
      "id": "ListConfigurationsResponse",
      "properties": {
        "nextPageToken": {
          "type": "string",
          "description": "Page token."
        },
        "configurations": {
          "description": "List of configurations.",
          "items": {
            "$ref": "Configuration"
          },
          "type": "array"
        }
      }
    },
    "TechnologyWatchListConfig": {
      "id": "TechnologyWatchListConfig",
      "type": "object",
      "properties": {
        "alertThreshold": {
          "description": "Optional. Alert thresholds to effectively reduce noise.",
          "$ref": "TechnologyWatchListAlertThreshold"
        },
        "technologies": {
          "description": "Optional. List of vendor, technology or cpe fingerprint. example: Microsoft office 360 Apache Server 3.5 cpe:2.3:a:microsoft:outlook:*:*:*:*:*:*:*:*",
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      },
      "description": "TechnologyWatchListConfig is the configuration for the technology watchlist."
    },
    "DomainMonitoringDnsDetails": {
      "properties": {
        "dnsRecords": {
          "description": "Optional. The DNS records of the domain.",
          "type": "array",
          "items": {
            "$ref": "DomainMonitoringDnsRecord"
          }
        },
        "retrievalTime": {
          "format": "google-datetime",
          "description": "Optional. The time the DNS details were retrieved.",
          "type": "string"
        }
      },
      "type": "object",
      "description": "The DNS details of the domain.",
      "id": "DomainMonitoringDnsDetails"
    },
    "AlertDocument": {
      "description": "A document that is associated with an alert.",
      "properties": {
        "source": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Source of the intel item, e.g. DarkMarket."
        },
        "sourceUpdateTime": {
          "readOnly": true,
          "description": "Output only. Time when the intel was last updated by the source.",
          "type": "string",
          "format": "google-datetime"
        },
        "name": {
          "type": "string",
          "description": "Identifier. Server generated name for the alert document. format is projects/{project}/alerts/{alert}/documents/{document}"
        },
        "collectionTime": {
          "type": "string",
          "readOnly": true,
          "format": "google-datetime",
          "description": "Output only. Time when the origin source collected the intel."
        },
        "author": {
          "type": "string",
          "description": "Output only. The author of the document.",
          "readOnly": true
        },
        "translation": {
          "$ref": "AlertDocumentTranslation",
          "readOnly": true,
          "description": "Output only. The translation of the document, if available."
        },
        "sourceUri": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. URI of the intel item from the source."
        },
        "title": {
          "readOnly": true,
          "description": "Output only. The title of the document, if available.",
          "type": "string"
        },
        "aiSummary": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. AI summary of the document."
        },
        "createTime": {
          "format": "google-datetime",
          "type": "string",
          "description": "Output only. The timestamp of the original external publication of the document.",
          "readOnly": true
        },
        "languageCode": {
          "readOnly": true,
          "description": "Output only. The language code of the document.",
          "type": "string"
        },
        "content": {
          "readOnly": true,
          "description": "Output only. The content of the document.",
          "type": "string"
        },
        "ingestTime": {
          "description": "Output only. Time when GTI received the intel.",
          "readOnly": true,
          "format": "google-datetime",
          "type": "string"
        }
      },
      "id": "AlertDocument",
      "type": "object"
    },
    "CustomerProfileProduct": {
      "properties": {
        "citationIds": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Optional. The citation ids for the product."
        },
        "product": {
          "type": "string",
          "description": "Required. The name of the product."
        },
        "brand": {
          "type": "string",
          "description": "Required. The brand of the product."
        }
      },
      "type": "object",
      "id": "CustomerProfileProduct",
      "description": "Product information for the customer profile."
    },
    "PriorityAnalysis": {
      "description": "Structured priority analysis for a threat.",
      "type": "object",
      "id": "PriorityAnalysis",
      "properties": {
        "priorityLevel": {
          "enumDescriptions": [
            "Default value, should never be set.",
            "Low Priority.",
            "Medium Priority.",
            "High Priority.",
            "Critical Priority."
          ],
          "description": "The level of Priority.",
          "type": "string",
          "enum": [
            "PRIORITY_LEVEL_UNSPECIFIED",
            "PRIORITY_LEVEL_LOW",
            "PRIORITY_LEVEL_MEDIUM",
            "PRIORITY_LEVEL_HIGH",
            "PRIORITY_LEVEL_CRITICAL"
          ]
        },
        "confidence": {
          "type": "string",
          "enum": [
            "CONFIDENCE_LEVEL_UNSPECIFIED",
            "CONFIDENCE_LEVEL_LOW",
            "CONFIDENCE_LEVEL_MEDIUM",
            "CONFIDENCE_LEVEL_HIGH"
          ],
          "description": "The level of confidence in the given verdict.",
          "enumDescriptions": [
            "Default value. Confidence level is not specified.",
            "Low confidence in the verdict.",
            "Medium confidence in the verdict.",
            "High confidence in the verdict."
          ]
        },
        "reasoning": {
          "type": "string",
          "description": "Human-readable explanation from the model, detailing why a particular result is considered to have a certain priority."
        }
      }
    },
    "DocumentQuery": {
      "type": "object",
      "properties": {
        "queryType": {
          "description": "Required. The type of query.",
          "enumDescriptions": [
            "Default value, should never be set.",
            "Structured JSON condition tree built via query builder.",
            "Raw search query string e.g., VTI search syntax."
          ],
          "type": "string",
          "enum": [
            "QUERY_TYPE_UNSPECIFIED",
            "JSON",
            "STRING"
          ]
        },
        "query": {
          "type": "string",
          "description": "Required. The query string."
        }
      },
      "id": "DocumentQuery",
      "description": "Represents a query to match documents."
    },
    "GetPasswordResponse": {
      "properties": {
        "password": {
          "type": "string",
          "description": "The decrypted cleartext password for the compromised credential."
        }
      },
      "description": "Response message for GetPassword.",
      "type": "object",
      "id": "GetPasswordResponse"
    },
    "EnumerateAlertFacetsResponse": {
      "id": "EnumerateAlertFacetsResponse",
      "type": "object",
      "description": "Response message for EnumerateAlertFacets.",
      "properties": {
        "facets": {
          "description": "List of facets and the counts.",
          "items": {
            "$ref": "Facet"
          },
          "type": "array"
        }
      }
    },
    "DomainMonitoringGtiDetails": {
      "properties": {
        "avDetections": {
          "description": "Optional. Detection counts across vendor feeds.",
          "$ref": "AVDetections"
        },
        "threatClassification": {
          "description": "Optional. The threat classification of the domain, obtained from the domain report (e.g. DomainMonitoring).",
          "type": "string"
        },
        "domainPermutation": {
          "type": "string",
          "description": "Optional. The permutation technique used for the domain (e.g., dictionary, homoglyph)."
        },
        "verdict": {
          "enum": [
            "DOMAIN_MONITORING_GTI_VERDICT_UNSPECIFIED",
            "DOMAIN_MONITORING_GTI_VERDICT_BENIGN",
            "DOMAIN_MONITORING_GTI_VERDICT_UNDETECTED",
            "DOMAIN_MONITORING_GTI_VERDICT_SUSPICIOUS",
            "DOMAIN_MONITORING_GTI_VERDICT_MALICIOUS",
            "DOMAIN_MONITORING_GTI_VERDICT_UNKNOWN"
          ],
          "enumDescriptions": [
            "Default value. The verdict is not set or unspecified.",
            "Verdict is clean; the entity is considered harmless.",
            "Verdict is undetected; no immediate evidence of malicious intent.",
            "Verdict is suspicious; possible malicious activity detected.",
            "Verdict is malicious; high confidence that the entity poses a threat.",
            "Verdict is not applicable; not able to generate a verdict for this entity."
          ],
          "type": "string",
          "readOnly": true,
          "description": "Output only. The verdict of the domain."
        },
        "gtiScore": {
          "type": "integer",
          "format": "int32",
          "description": "Optional. The GTI score of the domain. The threat score is a number between 0 and 100."
        },
        "gtiDomainUri": {
          "description": "Optional. The GTI link for the domain.",
          "type": "string"
        }
      },
      "description": "The GTI details of the domain.",
      "id": "DomainMonitoringGtiDetails",
      "type": "object"
    },
    "MarkAlertAsTriagedRequest": {
      "description": "Request message for MarkAlertAsTriaged.",
      "properties": {},
      "type": "object",
      "id": "MarkAlertAsTriagedRequest"
    },
    "MarkAlertAsTrackedExternallyRequest": {
      "id": "MarkAlertAsTrackedExternallyRequest",
      "type": "object",
      "description": "Request message for MarkAlertAsTrackedExternally.",
      "properties": {}
    },
    "DomainMonitoringDomain": {
      "description": "A Domain Monitoring \"domain\"",
      "id": "DomainMonitoringDomain",
      "type": "object",
      "properties": {
        "domain": {
          "type": "string",
          "description": "The domain name to match against."
        }
      }
    },
    "FacetCount": {
      "id": "FacetCount",
      "properties": {
        "value": {
          "type": "string",
          "description": "Value of the facet stringified. Timestamps will be formatted using RFC3339."
        },
        "count": {
          "description": "Count of records with the value.",
          "format": "int32",
          "type": "integer"
        }
      },
      "type": "object",
      "description": "FacetCount represents a count of records with each facet value."
    },
    "CustomerProfileIndustry": {
      "id": "CustomerProfileIndustry",
      "description": "Industry information for the customer profile.",
      "type": "object",
      "properties": {
        "industry": {
          "description": "Required. The name of the industry.",
          "type": "string"
        },
        "citationIds": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Optional. The citation ids for the industry."
        }
      }
    },
    "InsiderThreatFindingDetail": {
      "type": "object",
      "description": "A detail object for a InsiderThreat finding.",
      "properties": {
        "matchScore": {
          "description": "Required. Reference to the match score of the InsiderThreat finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.",
          "type": "number",
          "format": "float"
        },
        "documentId": {
          "deprecated": true,
          "description": "Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the InsiderThreat finding. This ID can be used to retrieve the content of the document for further analysis.",
          "type": "string"
        },
        "severity": {
          "enumDescriptions": [
            "Default value, should never be set.",
            "Low severity.",
            "Medium severity.",
            "High severity.",
            "Critical severity."
          ],
          "description": "Required. The severity of the InsiderThreat finding. This indicates the potential impact of the threat.",
          "enum": [
            "SEVERITY_UNSPECIFIED",
            "LOW",
            "MEDIUM",
            "HIGH",
            "CRITICAL"
          ],
          "type": "string"
        },
        "discoveryDocument": {
          "description": "Optional. The discovery document associated with the Insider Threat finding.",
          "$ref": "DiscoveryDocument"
        }
      },
      "id": "InsiderThreatFindingDetail"
    },
    "RelevanceAnalysis": {
      "description": "Structured relevance analysis for a threat.",
      "type": "object",
      "properties": {
        "relevanceLevel": {
          "enumDescriptions": [
            "Default value, should never be set.",
            "Low Relevance.",
            "Medium Relevance.",
            "High Relevance."
          ],
          "description": "The level of relevance.",
          "enum": [
            "RELEVANCE_LEVEL_UNSPECIFIED",
            "RELEVANCE_LEVEL_LOW",
            "RELEVANCE_LEVEL_MEDIUM",
            "RELEVANCE_LEVEL_HIGH"
          ],
          "type": "string"
        },
        "evidence": {
          "$ref": "Evidence",
          "description": "Evidence supporting the verdict, including matched and unmatched items."
        },
        "reasoning": {
          "description": "Human-readable explanation from the matcher, detailing why a particular result is considered relevant or not relevant.",
          "type": "string"
        },
        "relevant": {
          "type": "boolean",
          "description": "Indicates whether the threat is considered relevant."
        },
        "confidence": {
          "type": "string",
          "description": "The level of confidence in the given verdict.",
          "enumDescriptions": [
            "Default value. Confidence level is not specified.",
            "Low confidence in the verdict.",
            "Medium confidence in the verdict.",
            "High confidence in the verdict."
          ],
          "enum": [
            "CONFIDENCE_LEVEL_UNSPECIFIED",
            "CONFIDENCE_LEVEL_LOW",
            "CONFIDENCE_LEVEL_MEDIUM",
            "CONFIDENCE_LEVEL_HIGH"
          ]
        }
      },
      "id": "RelevanceAnalysis"
    },
    "ListFindingsResponse": {
      "description": "Response message for ListFindings.",
      "type": "object",
      "properties": {
        "findings": {
          "items": {
            "$ref": "Finding"
          },
          "type": "array",
          "description": "List of findings."
        },
        "nextPageToken": {
          "description": "Page token.",
          "type": "string"
        }
      },
      "id": "ListFindingsResponse"
    },
    "Facet": {
      "properties": {
        "totalCount": {
          "type": "string",
          "format": "int64",
          "description": "Total number of records that contain this facet with ANY value."
        },
        "facet": {
          "description": "Name of the facet. This is also the string that needs to be used in the filtering expression.",
          "type": "string"
        },
        "maxValue": {
          "description": "Max value of the facet stringified based on type. Will be populated and formatted the same as min_value.",
          "type": "string"
        },
        "facetType": {
          "type": "string",
          "description": "The type of the facet. Options include \"string\", \"int\", \"float\", \"bool\", \"enum\", \"timestamp\", \"user\" and are useful to show the right sort of UI controls when building a AIP-160 style filtering string."
        },
        "facetCounts": {
          "items": {
            "$ref": "FacetCount"
          },
          "description": "List of counts for the facet (if categorical).",
          "type": "array"
        },
        "minValue": {
          "description": "Min value of the facet stringified based on type. This is only populated for facets that have a clear ordering, for types like enum it will be left empty. Timestamps will be formatted using RFC3339.",
          "type": "string"
        }
      },
      "id": "Facet",
      "type": "object",
      "description": "Facet represents a sub element of a resource for filtering. The results from this method are used to populate the filterable facets in the UI."
    },
    "TargetTechnologyAlertDetail": {
      "type": "object",
      "properties": {
        "vulnerabilityMatch": {
          "description": "Optional. The vulnerability match details.",
          "$ref": "VulnerabilityMatch"
        }
      },
      "id": "TargetTechnologyAlertDetail",
      "description": "Contains details for a technology watchlist alert."
    },
    "DomainSetting": {
      "properties": {
        "domainMonitoringConfig": {
          "description": "Optional. If not present, Domain Monitoring is enabled.",
          "$ref": "DomainMonitoringFeatureConfig"
        },
        "domain": {
          "type": "string",
          "description": "Required. The domain name to match against."
        },
        "state": {
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Verification is pending. The customer needs to add the TXT record.",
            "Verification succeeded."
          ],
          "type": "string",
          "readOnly": true,
          "enum": [
            "STATE_UNSPECIFIED",
            "PENDING",
            "VERIFIED"
          ],
          "description": "Output only. The verification state of the domain."
        }
      },
      "description": "Feature settings and toggles for a single specific domain.",
      "id": "DomainSetting",
      "type": "object"
    },
    "CommunicationContext": {
      "properties": {
        "channelUrl": {
          "description": "Optional. URL of the communication channel.",
          "type": "string"
        },
        "threadId": {
          "description": "Optional. Conversation thread identifier.",
          "type": "string"
        },
        "channelPath": {
          "type": "string",
          "description": "Optional. Channel path (e.g. forum path or sub-channel)."
        },
        "channelName": {
          "description": "Optional. Name of the communication channel.",
          "type": "string"
        },
        "serviceName": {
          "type": "string",
          "description": "Optional. Service from the collection event origin (e.g. forum or chat service name)."
        },
        "channelDescription": {
          "type": "string",
          "description": "Optional. Description of the communication channel."
        }
      },
      "description": "Detailed communication context metadata for documents originating from deep and dark web communication channels.",
      "id": "CommunicationContext",
      "type": "object"
    },
    "DataLeakFindingDetail": {
      "properties": {
        "discoveryDocument": {
          "description": "Optional. The discovery document associated with the Data Leak finding.",
          "$ref": "DiscoveryDocument"
        },
        "severity": {
          "enum": [
            "SEVERITY_UNSPECIFIED",
            "LOW",
            "MEDIUM",
            "HIGH",
            "CRITICAL"
          ],
          "type": "string",
          "description": "Required. The severity of the Data Leak finding. This indicates the potential impact of the threat.",
          "enumDescriptions": [
            "Default value, should never be set.",
            "Low severity.",
            "Medium severity.",
            "High severity.",
            "Critical severity."
          ]
        },
        "matchScore": {
          "type": "number",
          "description": "Required. Reference to the match score of the Data Leak finding. This is a float value greater than 0 and less than or equal to 1 calculated by the matching engine based on the similarity of the document and the user provided configurations.",
          "format": "float"
        },
        "documentId": {
          "type": "string",
          "deprecated": true,
          "description": "Optional. Deprecated: Use `discovery_document` instead. The unique identifier of the document that triggered the Data Leak finding. This ID can be used to retrieve the content of the document for further analysis."
        }
      },
      "type": "object",
      "description": "A detail object for a Data Leak finding.",
      "id": "DataLeakFindingDetail"
    },
    "CustomerProfileCompany": {
      "id": "CustomerProfileCompany",
      "type": "object",
      "description": "Company information for the customer profile.",
      "properties": {
        "company": {
          "type": "string",
          "description": "Required. The name of the company."
        },
        "citationIds": {
          "description": "Optional. The citation ids for the company.",
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      }
    },
    "DomainMonitoringFindingDetail": {
      "id": "DomainMonitoringFindingDetail",
      "properties": {
        "dnsDetails": {
          "description": "Optional. The DNS details of the domain or URL.",
          "$ref": "DomainMonitoringDnsDetails"
        },
        "gtiDetails": {
          "description": "Optional. The GTI details of the domain or URL.",
          "$ref": "DomainMonitoringGtiDetails"
        },
        "protectedDomain": {
          "description": "The protected domain that triggered the alert.",
          "$ref": "DomainMonitoringDomainDetails"
        },
        "whoisDetails": {
          "$ref": "DomainMonitoringWhoIsDetails",
          "description": "Optional. The whois details of the domain or URL."
        },
        "protectedBrand": {
          "description": "The protected brand name that triggered the alert.",
          "type": "string"
        },
        "relationships": {
          "description": "Optional. The relationships of the domain or URL.",
          "$ref": "Relationships"
        },
        "threatAttributionDetails": {
          "$ref": "ThreatAttributionDetails",
          "description": "Optional. The threat attribution details of the domain or URL."
        },
        "infrastructure": {
          "description": "Optional. The infrastructure of the domain or URL.",
          "$ref": "Infrastructure"
        },
        "domainDetails": {
          "$ref": "DomainMonitoringDomainDetails",
          "description": "Details specific to a monitored domain."
        },
        "matchedDomain": {
          "type": "string",
          "description": "Optional. The matched domain."
        },
        "registrationDetails": {
          "description": "Optional. Extracted WHOIS and DNS registration details.",
          "$ref": "DnsRegistrationDetails"
        },
        "urlDetails": {
          "$ref": "DomainMonitoringUrlDetails",
          "description": "Details specific to a monitored URL."
        }
      },
      "description": "A detailed object for a Domain or URL finding.",
      "type": "object"
    },
    "ConfigurationDetail": {
      "description": "Wrapper class that contains the union struct for all the various configuration detail specific classes.",
      "id": "ConfigurationDetail",
      "type": "object",
      "properties": {
        "customerProfile": {
          "description": "Customer Profile detail config.",
          "$ref": "CustomerProfileConfig"
        },
        "domainConfiguration": {
          "$ref": "DomainConfiguration",
          "description": "Domain Configuration detail config."
        },
        "customThreatScenario": {
          "description": "Custom Threat Scenario detail config.",
          "$ref": "CustomThreatScenarioConfig"
        },
        "technologyWatchlist": {
          "$ref": "TechnologyWatchListConfig",
          "description": "Technology Watchlist detail config."
        },
        "detailType": {
          "type": "string",
          "description": "Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union.",
          "readOnly": true
        },
        "domainMonitoring": {
          "description": "Domain Monitoring detail config.",
          "$ref": "DomainMonitoringConfig"
        }
      }
    },
    "DiscoveryDocument": {
      "type": "object",
      "description": "Replaces the raw string ID to hold associated metadata.",
      "id": "DiscoveryDocument",
      "properties": {
        "documentId": {
          "description": "Output only. The identifier of the discovery document.",
          "readOnly": true,
          "type": "string"
        },
        "documentType": {
          "type": "string",
          "description": "Output only. The classification/type of the document (e.g. `COMMUNICATION`, `DDW_COMMUNICATION`, `message`).",
          "readOnly": true
        },
        "communicationContext": {
          "$ref": "CommunicationContext",
          "description": "Optional. Detailed communication context metadata for documents originating from deep and dark web communication channels."
        }
      }
    },
    "AlertDocumentTranslation": {
      "description": "The translation of an alert document.",
      "id": "AlertDocumentTranslation",
      "properties": {
        "translatedTitle": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. The translated title of the document."
        },
        "translatedContent": {
          "readOnly": true,
          "description": "Output only. The translated content of the document.",
          "type": "string"
        }
      },
      "type": "object"
    },
    "CustomerProfileSummary": {
      "id": "CustomerProfileSummary",
      "description": "A summarized version of the customer profile. Generated by the backend.",
      "type": "object",
      "properties": {
        "primaryWebsite": {
          "description": "Optional. The primary website of the customer.",
          "$ref": "CustomerProfileCitedString"
        },
        "title": {
          "description": "Optional. The official name of the customer.",
          "$ref": "CustomerProfileCitedString"
        },
        "industry": {
          "description": "Optional. The industry the customer is in.",
          "$ref": "CustomerProfileCitedString"
        },
        "servicesSummary": {
          "description": "Optional. A narrative summary of services.",
          "$ref": "CustomerProfileCitedString"
        },
        "areaServed": {
          "$ref": "CustomerProfileCitedString",
          "description": "Optional. The area the customer serves."
        },
        "parentCompany": {
          "description": "Optional. The parent company of the customer.",
          "$ref": "CustomerProfileCitedString"
        },
        "productsSummary": {
          "description": "Optional. A narrative summary of products.",
          "$ref": "CustomerProfileCitedString"
        },
        "brands": {
          "$ref": "CustomerProfileCitedString",
          "description": "Optional. A narrative summary of brands."
        },
        "founded": {
          "description": "Optional. The date the customer was founded.",
          "$ref": "CustomerProfileCitedString"
        },
        "keyPeopleSummary": {
          "$ref": "CustomerProfileCitedString",
          "description": "Optional. A narrative summary of key people."
        },
        "entityType": {
          "$ref": "CustomerProfileCitedString",
          "description": "Optional. The entity type of the customer."
        },
        "headquarters": {
          "description": "Optional. The headquarters of the customer.",
          "$ref": "CustomerProfileCitedString"
        }
      }
    },
    "CustomerProfileTechnology": {
      "type": "object",
      "id": "CustomerProfileTechnology",
      "description": "Technology information for the customer profile.",
      "properties": {
        "citationIds": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Optional. The citation ids for the technology."
        },
        "technology": {
          "type": "string",
          "description": "Required. The name of the technology."
        }
      }
    },
    "PublicExploit": {
      "description": "Contains details about a public exploit.",
      "type": "object",
      "id": "PublicExploit",
      "properties": {
        "exploitReliability": {
          "enumDescriptions": [
            "Unspecified exploit reliability.",
            "Confirmed exploit reliability.",
            "Uncorroborated exploit reliability.",
            "Unconfirmed exploit reliability."
          ],
          "type": "string",
          "description": "Optional. The reliability of the exploit. Ex: \"Unreviewed\".",
          "enum": [
            "EXPLOIT_RELIABILITY_UNSPECIFIED",
            "UNREVIEWED",
            "REVIEWED",
            "TESTED"
          ]
        },
        "sizeBytes": {
          "description": "Optional. The size of the exploit.",
          "type": "string",
          "format": "int64"
        },
        "releaseTime": {
          "format": "google-datetime",
          "description": "Optional. The release time of the exploit.",
          "type": "string"
        },
        "exploitGrade": {
          "description": "Optional. The grade of the exploit. Ex: \"non-weaponized\".",
          "enumDescriptions": [
            "Unspecified exploit grade.",
            "Unevaluated exploit grade.",
            "Proof-of-concept exploit grade.",
            "Non-weaponized exploit grade.",
            "Weaponized exploit grade.",
            "Scanner exploit grade.",
            "Fake exploit grade."
          ],
          "enum": [
            "EXPLOIT_GRADE_UNSPECIFIED",
            "UNEVALUATED",
            "PROOF_OF_CONCEPT",
            "NON_WEAPONIZED",
            "WEAPONIZED",
            "SCANNER",
            "FAKE"
          ],
          "type": "string"
        },
        "exploitName": {
          "description": "Required. The name of the exploit. Ex: \"Magentounauth.php.txt\".",
          "type": "string"
        },
        "uri": {
          "description": "Optional. The URI of the exploit.",
          "type": "string"
        }
      }
    },
    "MarkAlertAsFalsePositiveRequest": {
      "description": "Request message for MarkAlertAsFalsePositive.",
      "properties": {},
      "id": "MarkAlertAsFalsePositiveRequest",
      "type": "object"
    },
    "CustomerProfileLocation": {
      "properties": {
        "address": {
          "type": "string",
          "description": "Required. The address of the location."
        },
        "brand": {
          "description": "Required. The brand of the location.",
          "type": "string"
        },
        "facilityType": {
          "description": "Optional. The type of location.",
          "type": "string"
        },
        "citationIds": {
          "description": "Optional. The citation ids for the location.",
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      },
      "description": "Location information for the customer profile.",
      "type": "object",
      "id": "CustomerProfileLocation"
    },
    "CustomerProfileContactInfo": {
      "id": "CustomerProfileContactInfo",
      "description": "Contact information for the customer profile.",
      "properties": {
        "address": {
          "description": "The address of the contact.",
          "type": "string"
        },
        "email": {
          "description": "The email address of the contact.",
          "type": "string"
        },
        "citationIds": {
          "description": "Optional. The citation ids for the contact information.",
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "other": {
          "type": "string",
          "description": "The other contact information."
        },
        "label": {
          "description": "Optional. The name of the contact.",
          "type": "string"
        },
        "phone": {
          "description": "The phone number of the contact.",
          "type": "string"
        }
      },
      "type": "object"
    },
    "LegacyMetadata": {
      "id": "LegacyMetadata",
      "properties": {
        "conditionVersion": {
          "readOnly": true,
          "description": "Output only. Version of the condition schema.",
          "type": "integer",
          "format": "int32"
        },
        "legacyMonitorId": {
          "description": "Output only. Unique identifier of the legacy monitor.",
          "readOnly": true,
          "type": "string"
        },
        "version": {
          "format": "int32",
          "readOnly": true,
          "description": "Output only. Version of the monitor configuration.",
          "type": "integer"
        },
        "staleTime": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Time the legacy monitor was considered stale.",
          "format": "google-datetime"
        },
        "disabledReason": {
          "readOnly": true,
          "description": "Output only. Reason why the monitor is disabled (if applicable).",
          "type": "string"
        },
        "emailNotificationEnabled": {
          "deprecated": true,
          "description": "Output only. Deprecated: Whether email notifications are enabled. This field will not be used as email notifications are handled through the GTI Mail Hub.",
          "type": "boolean",
          "readOnly": true
        },
        "displayName": {
          "description": "Output only. Name of the legacy monitor.",
          "readOnly": true,
          "type": "string"
        },
        "description": {
          "type": "string",
          "description": "Output only. Description of the legacy monitor.",
          "readOnly": true
        },
        "templateId": {
          "type": "string",
          "description": "Output only. ID of the template this monitor was created from.",
          "readOnly": true
        },
        "disabledCode": {
          "type": "string",
          "description": "Output only. Code indicating why the monitor is disabled (if applicable).",
          "readOnly": true
        },
        "aggregationEnabled": {
          "type": "boolean",
          "readOnly": true,
          "description": "Output only. Whether aggregation is enabled for alerts from this monitor."
        },
        "aggregationSimilarity": {
          "format": "double",
          "description": "Output only. Similarity threshold for aggregation.",
          "type": "number",
          "readOnly": true
        },
        "tenantId": {
          "description": "Output only. ID of the tenant owning the monitor.",
          "type": "string",
          "readOnly": true
        },
        "creatorUserId": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. User ID who created the monitor."
        },
        "emailNotificationImmediate": {
          "type": "boolean",
          "description": "Output only. Deprecated: Whether email notifications are intermediate/immediate. This field will not be used as email notifications are handled through the GTI Mail Hub.",
          "deprecated": true,
          "readOnly": true
        },
        "updaterUserId": {
          "readOnly": true,
          "description": "Output only. User ID who last updated the monitor.",
          "type": "string"
        }
      },
      "type": "object",
      "description": "Legacy metadata associated with this scenario/monitor."
    },
    "ListConfigurationRevisionsResponse": {
      "type": "object",
      "id": "ListConfigurationRevisionsResponse",
      "description": "Response message for ListConfigurationRevisions.",
      "properties": {
        "nextPageToken": {
          "type": "string",
          "description": "A token, which can be sent as `page_token` to retrieve the next page. If this field is omitted, there are no subsequent pages."
        },
        "revisions": {
          "type": "array",
          "items": {
            "$ref": "ConfigurationRevision"
          },
          "description": "The Configuration Revisions associated with the specified Configuration"
        }
      }
    },
    "DomainMonitoringDnsRecord": {
      "properties": {
        "ipRegionCode": {
          "description": "Optional. The region code associated with the resolved IP. Use ISO 3166-1 alpha-2 codes.",
          "type": "string"
        },
        "resolvedIp": {
          "type": "string",
          "description": "Optional. The resolved IP address."
        },
        "asnHosting": {
          "description": "Optional. The ASN hosting the domain.",
          "type": "string"
        },
        "ttl": {
          "description": "Optional. The TTL of the DNS record.",
          "type": "integer",
          "format": "int32"
        },
        "asnRegionCode": {
          "description": "Optional. The region code of the ASN. Use ISO 3166-1 alpha-2 codes.",
          "type": "string"
        },
        "recordData": {
          "description": "Optional. The value of the DNS record.",
          "type": "string"
        },
        "type": {
          "description": "Optional. The type of the DNS record.",
          "type": "string"
        }
      },
      "id": "DomainMonitoringDnsRecord",
      "description": "The DNS record of the domain.",
      "type": "object"
    },
    "CustomerProfileConfig": {
      "id": "CustomerProfileConfig",
      "description": "CustomerProfileConfig is the configuration for the customer profile.",
      "properties": {
        "locations": {
          "type": "array",
          "description": "Optional. Locations the organization is present or conducts business in.",
          "items": {
            "$ref": "CustomerProfileLocation"
          }
        },
        "org": {
          "description": "Required. The name of the organization.",
          "type": "string"
        },
        "summary": {
          "description": "Optional. A summarized version of the customer profile.",
          "$ref": "CustomerProfileSummary"
        },
        "securityConsiderations": {
          "description": "Optional. Security considerations for the organization.",
          "$ref": "CustomerProfileSecurityConsiderations"
        },
        "technologyPresence": {
          "description": "Optional. Technology presence of the organization.",
          "type": "string"
        },
        "technologies": {
          "type": "array",
          "description": "Optional. Technologies associated with the organization.",
          "items": {
            "$ref": "CustomerProfileTechnology"
          }
        },
        "parentCompanies": {
          "type": "array",
          "items": {
            "$ref": "CustomerProfileCompany"
          },
          "description": "Optional. The parent companies of the organization."
        },
        "industries": {
          "type": "array",
          "description": "Optional. The industries the organization is involved in.",
          "items": {
            "$ref": "CustomerProfileIndustry"
          }
        },
        "products": {
          "items": {
            "$ref": "CustomerProfileProduct"
          },
          "type": "array",
          "description": "Optional. Product information for the organization."
        },
        "webPresences": {
          "description": "Optional. Web presence of the organization.",
          "items": {
            "$ref": "CustomerProfileWebPresence"
          },
          "type": "array"
        },
        "orgSummary": {
          "type": "string",
          "description": "Optional. A summary of the organization."
        },
        "citations": {
          "description": "Optional. Citations for the organization profile.",
          "type": "array",
          "items": {
            "$ref": "CustomerProfileCitation"
          }
        },
        "executives": {
          "items": {
            "$ref": "CustomerProfilePerson"
          },
          "description": "Optional. Executives of the organization.",
          "type": "array"
        },
        "contactInfo": {
          "items": {
            "$ref": "CustomerProfileContactInfo"
          },
          "description": "Optional. Contact information for the organization.",
          "type": "array"
        }
      },
      "type": "object"
    },
    "CertificateDetails": {
      "type": "object",
      "properties": {
        "issuer": {
          "description": "Optional. The SSL certificate issuer.",
          "type": "string"
        },
        "subjectAlternativeNames": {
          "items": {
            "type": "string"
          },
          "description": "Optional. The SSL subject alternative names.",
          "type": "array"
        }
      },
      "id": "CertificateDetails",
      "description": "Details regarding the SSL certificate configuration."
    },
    "MarkAlertAsEscalatedRequest": {
      "id": "MarkAlertAsEscalatedRequest",
      "description": "Request message for MarkAlertAsEscalated.",
      "type": "object",
      "properties": {}
    },
    "FindingDetail": {
      "type": "object",
      "description": "Wrapper class that contains the union struct for all the various findings detail specific classes.",
      "properties": {
        "detailType": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Name of the detail type. Will be set by the server during creation to the name of the field that is set in the detail union."
        },
        "domainMonitoring": {
          "$ref": "DomainMonitoringFindingDetail",
          "description": "Domain Monitoring finding detail type."
        },
        "dataLeak": {
          "description": "Data Leak finding detail type.",
          "$ref": "DataLeakFindingDetail"
        },
        "initialAccessBroker": {
          "description": "Initial Access Broker finding detail type.",
          "$ref": "InitialAccessBrokerFindingDetail"
        },
        "insiderThreat": {
          "$ref": "InsiderThreatFindingDetail",
          "description": "Insider Threat finding detail type."
        },
        "targetTechnology": {
          "description": "Technology Watchlist finding detail type.",
          "$ref": "TargetTechnologyFindingDetail"
        }
      },
      "id": "FindingDetail"
    },
    "DomainMonitoringFeatureConfig": {
      "type": "object",
      "id": "DomainMonitoringFeatureConfig",
      "properties": {
        "disabled": {
          "type": "boolean",
          "description": "Optional. Whether the Domain Monitoring feature is disabled for the domain."
        }
      },
      "description": "Specific configuration for the Domain Monitoring feature."
    },
    "UpsertConfigurationResponse": {
      "properties": {
        "configuration": {
          "description": "Output only. Created configuration ID with server assigned id.",
          "type": "string",
          "readOnly": true
        }
      },
      "description": "Response message for UpsertConfiguration.",
      "type": "object",
      "id": "UpsertConfigurationResponse"
    },
    "AVDetections": {
      "description": "Details about the detection vendors.",
      "properties": {
        "detectedVendorCount": {
          "description": "Optional. Number of vendors that detected the threat.",
          "format": "int32",
          "type": "integer"
        },
        "totalVendorCount": {
          "description": "Optional. Total number of vendors.",
          "format": "int32",
          "type": "integer"
        }
      },
      "id": "AVDetections",
      "type": "object"
    },
    "DomainMonitoringAlertDetail": {
      "type": "object",
      "description": "A detailed object for a Domain or URL alert.",
      "id": "DomainMonitoringAlertDetail",
      "properties": {
        "relationships": {
          "description": "Optional. The relationships of the domain or URL.",
          "$ref": "Relationships"
        },
        "whoisDetails": {
          "description": "Optional. The whois details of the domain or URL.",
          "$ref": "DomainMonitoringWhoIsDetails"
        },
        "infrastructure": {
          "description": "Optional. The infrastructure of the domain or URL.",
          "$ref": "Infrastructure"
        },
        "domainDetails": {
          "description": "Details specific to a monitored domain.",
          "$ref": "DomainMonitoringDomainDetails"
        },
        "protectedDomain": {
          "description": "The protected domain that triggered the alert.",
          "$ref": "DomainMonitoringDomainDetails"
        },
        "matchedDomain": {
          "type": "string",
          "description": "Optional. The matched domain."
        },
        "urlDetails": {
          "$ref": "DomainMonitoringUrlDetails",
          "description": "Details specific to a monitored URL."
        },
        "threatAttributionDetails": {
          "$ref": "ThreatAttributionDetails",
          "description": "Optional. The threat attribution details of the domain or URL."
        },
        "dnsDetails": {
          "$ref": "DomainMonitoringDnsDetails",
          "description": "Optional. The DNS details of the domain or URL."
        },
        "gtiDetails": {
          "$ref": "DomainMonitoringGtiDetails",
          "description": "Optional. The GTI details of the domain or URL."
        },
        "protectedBrand": {
          "description": "The protected brand name that triggered the alert.",
          "type": "string"
        },
        "registrationDetails": {
          "description": "Optional. Extracted WHOIS and DNS registration details.",
          "$ref": "DnsRegistrationDetails"
        }
      }
    },
    "Audit": {
      "id": "Audit",
      "properties": {
        "createTime": {
          "readOnly": true,
          "description": "Output only. Time of creation.",
          "type": "string",
          "format": "google-datetime"
        },
        "creator": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Agent that created or updated the record, could be a UserId or a JobId."
        },
        "updateTime": {
          "type": "string",
          "format": "google-datetime",
          "description": "Output only. Time of creation or last update.",
          "readOnly": true
        },
        "updater": {
          "type": "string",
          "description": "Output only. Agent that last updated the record, could be a UserId or a JobId.",
          "readOnly": true
        }
      },
      "type": "object",
      "description": "Tracks basic CRUD facts."
    },
    "CustomerProfilePerson": {
      "description": "Person information for the customer profile.",
      "properties": {
        "citationIds": {
          "type": "array",
          "description": "Optional. The citation ids for the person.",
          "items": {
            "type": "string"
          }
        },
        "name": {
          "type": "string",
          "description": "Required. The name of the person."
        },
        "title": {
          "description": "Optional. The title of the person.",
          "type": "string"
        }
      },
      "type": "object",
      "id": "CustomerProfilePerson"
    },
    "Relationships": {
      "properties": {
        "subdomains": {
          "description": "Optional. Subdomains associated with the target domain or URL.",
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "relatedUrls": {
          "type": "array",
          "description": "Optional. Related URLs associated with the domain.",
          "items": {
            "type": "string"
          }
        },
        "siblingDomains": {
          "items": {
            "type": "string"
          },
          "description": "Optional. Sibling domains sharing the same IP address.",
          "type": "array"
        }
      },
      "id": "Relationships",
      "type": "object",
      "description": "Related entities and domains observed for the target."
    },
    "TechnologyWatchListAlertThreshold": {
      "id": "TechnologyWatchListAlertThreshold",
      "type": "object",
      "properties": {
        "riskRatingMinimum": {
          "enumDescriptions": [
            "Unspecified risk rating. This is the default value when the risk rating is not set.",
            "Low risk rating.",
            "Medium risk rating.",
            "High risk rating.",
            "Critical risk rating.",
            "The vulnerability has been assessed, but a specific risk rating could not be determined or assigned."
          ],
          "enum": [
            "RISK_RATING_UNSPECIFIED",
            "LOW",
            "MEDIUM",
            "HIGH",
            "CRITICAL",
            "UNRATED"
          ],
          "description": "Optional. The minimum risk rating for the alert.",
          "type": "string"
        },
        "cvssScoreMinimum": {
          "format": "float",
          "description": "Optional. The minimum CVSS score for the alert. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Ex: 7.0. Valid range is [0.0, 10.0].",
          "type": "number"
        },
        "epssScoreMinimum": {
          "type": "number",
          "format": "float",
          "description": "Optional. The minimum epss score for the alert. Ex: 0.8. Valid range is [0.0, 1.0]."
        },
        "exploitationStates": {
          "description": "Optional. The exploitation states of the alert.",
          "type": "array",
          "items": {
            "enumDescriptions": [
              "Unspecified exploitation state.",
              "No known exploitation.",
              "Exploitation has been reported.",
              "Exploitation is suspected.",
              "Exploitation is confirmed.",
              "Widespread exploitation."
            ],
            "enum": [
              "EXPLOITATION_STATE_UNSPECIFIED",
              "EXPLOITATION_STATE_NO_KNOWN",
              "EXPLOITATION_STATE_REPORTED",
              "EXPLOITATION_STATE_SUSPECTED",
              "EXPLOITATION_STATE_CONFIRMED",
              "EXPLOITATION_STATE_WIDESPREAD"
            ],
            "type": "string"
          }
        },
        "priorityMinimum": {
          "enumDescriptions": [
            "Unspecified priority.",
            "Priority level 0.",
            "Priority level 1.",
            "Priority level 2.",
            "Priority level 3.",
            "Priority level 4."
          ],
          "description": "Optional. The minimum priority for the alert.",
          "type": "string",
          "enum": [
            "PRIORITY_UNSPECIFIED",
            "P0",
            "P1",
            "P2",
            "P3",
            "P4"
          ]
        }
      },
      "description": "TechnologyWatchListAlertThreshold contains the thresholds for alerting."
    },
    "DomainMonitoringWhoIsDetails": {
      "id": "DomainMonitoringWhoIsDetails",
      "properties": {
        "retrievalTime": {
          "format": "google-datetime",
          "type": "string",
          "description": "Optional. The time the whois details were retrieved."
        },
        "whois": {
          "type": "string",
          "description": "Optional. The whois details of the domain."
        }
      },
      "type": "object",
      "description": "The whois details of the domain."
    },
    "MarkAlertAsReadRequest": {
      "type": "object",
      "description": "Request message for MarkAlertAsRead.",
      "id": "MarkAlertAsReadRequest",
      "properties": {}
    },
    "MarkAlertAsNotActionableRequest": {
      "properties": {},
      "description": "Request message for MarkAlertAsNotActionable.",
      "id": "MarkAlertAsNotActionableRequest",
      "type": "object"
    },
    "VulnerabilityMatch": {
      "type": "object",
      "id": "VulnerabilityMatch",
      "description": "Contains details about a vulnerability match.",
      "properties": {
        "cvss3Score": {
          "type": "number",
          "description": "Required. The CVSS score of the vulnerability. Evaluates to CVSS v3 when available with a fallback to v2 and v4. Example: 6.4.",
          "format": "float"
        },
        "collectionId": {
          "type": "string",
          "description": "Required. The collection ID of the vulnerability. Ex: \"vulnerability--cve-2025-9876\"."
        },
        "cveId": {
          "description": "Required. The CVE ID of the vulnerability. Ex: \"CVE-2025-9876\". See https://www.cve.org/ for more information.",
          "type": "string"
        },
        "exploitationConsequences": {
          "items": {
            "enumDescriptions": [
              "Unspecified exploitation consequence.",
              "Code execution consequence.",
              "Command execution consequence.",
              "Data loss consequence.",
              "Data manipulation consequence.",
              "Denial-of-Service consequence.",
              "Information disclosure consequence.",
              "Unauthorized access consequence.",
              "Privilege escalation consequence.",
              "Sandbox escape consequence.",
              "Security bypass consequence.",
              "Container escape consequence.",
              "Spoofing consequence."
            ],
            "type": "string",
            "enum": [
              "EXPLOITATION_CONSEQUENCE_UNSPECIFIED",
              "CODE_EXECUTION",
              "COMMAND_EXECUTION",
              "DATA_LOSS",
              "DATA_MANIPULATION",
              "DENIAL_OF_SERVICE",
              "INFORMATION_DISCLOSURE",
              "UNAUTHORIZED_ACCESS",
              "PRIVILEGE_ESCALATION",
              "SANDBOX_ESCAPE",
              "SECURITY_BYPASS",
              "CONTAINER_ESCAPE",
              "SPOOFING"
            ]
          },
          "description": "Optional. List of exploitation consequences for the vulnerability.",
          "type": "array"
        },
        "description": {
          "type": "string",
          "description": "Required. A description of the vulnerability."
        },
        "exploitationState": {
          "enum": [
            "EXPLOITATION_STATE_UNSPECIFIED",
            "EXPLOITATION_STATE_NO_KNOWN",
            "EXPLOITATION_STATE_REPORTED",
            "EXPLOITATION_STATE_SUSPECTED",
            "EXPLOITATION_STATE_CONFIRMED",
            "EXPLOITATION_STATE_WIDESPREAD"
          ],
          "enumDescriptions": [
            "Unspecified exploitation state.",
            "No known exploitation.",
            "Exploitation has been reported.",
            "Exploitation is suspected.",
            "Exploitation is confirmed.",
            "Widespread exploitation."
          ],
          "description": "Required. The exploitation state of the vulnerability.",
          "type": "string"
        },
        "exploitationVectors": {
          "items": {
            "enum": [
              "EXPLOITATION_VECTOR_UNSPECIFIED",
              "ADMINISTRATIVE_INTERFACE",
              "BLUETOOTH_ACCESS",
              "BROWSER",
              "COMPROMISED_COMMUNICATION_CHANNEL",
              "EMAIL",
              "EXPOSED_WEB_APPLICATION",
              "LOCAL_NETWORK_ACCESS",
              "MALICIOUS_APPLICATION",
              "MALICIOUS_FILE",
              "MALICIOUS_SERVER",
              "OPEN_PORT",
              "PHYSICAL_ACCESS",
              "SHORT_RANGE_RADIO",
              "UNSPECIFIED_LOCAL_VECTOR",
              "UNSPECIFIED_REMOTE_VECTOR",
              "VPN_ACCESS",
              "WIFI_ACCESS"
            ],
            "type": "string",
            "enumDescriptions": [
              "Unspecified exploitation vector.",
              "Administrative interface vector.",
              "Bluetooth access vector.",
              "Browser vector.",
              "Compromised communication channel vector.",
              "Email vector.",
              "Exposed web application vector.",
              "Local network access vector.",
              "Malicious application vector.",
              "Malicious file vector.",
              "Malicious server vector.",
              "Open port vector.",
              "Physical access vector.",
              "Short range radio vector.",
              "Unspecified local vector.",
              "Unspecified remote vector.",
              "VPN access vector.",
              "WiFi access vector."
            ]
          },
          "type": "array",
          "description": "Optional. List of exploitation vectors for the vulnerability."
        },
        "matchedTechnologies": {
          "items": {
            "type": "string"
          },
          "type": "array",
          "description": "Optional. The specific technologies from the configured watchlist that triggered the match. Ex: \"Apache Struts\"."
        },
        "technologies": {
          "items": {
            "type": "string"
          },
          "description": "Required. All technologies affected by the vulnerability. Ex: \"Apache Struts\".",
          "type": "array"
        },
        "publiclyAvailableExploit": {
          "type": "boolean",
          "readOnly": true,
          "description": "Output only. Whether a publicly available exploit exists."
        },
        "priority": {
          "type": "string",
          "enum": [
            "PRIORITY_UNSPECIFIED",
            "P0",
            "P1",
            "P2",
            "P3",
            "P4"
          ],
          "enumDescriptions": [
            "Unspecified priority.",
            "Priority level 0.",
            "Priority level 1.",
            "Priority level 2.",
            "Priority level 3.",
            "Priority level 4."
          ],
          "description": "Optional. The priority level of the vulnerability data. Ex: \"P1\"."
        },
        "productFixes": {
          "items": {
            "$ref": "ProductFix"
          },
          "description": "Optional. List of product fixes for the vulnerability.",
          "type": "array"
        },
        "publicExploits": {
          "type": "array",
          "description": "Optional. List of public exploits.",
          "items": {
            "$ref": "PublicExploit"
          }
        },
        "epssScore": {
          "format": "float",
          "type": "number",
          "description": "Optional. The EPSS score, representing the probability of exploitation. Example: 0.87."
        },
        "disclosureTime": {
          "type": "string",
          "description": "Optional. The disclosure time of the vulnerability.",
          "format": "google-datetime"
        },
        "riskRating": {
          "enumDescriptions": [
            "Unspecified risk rating. This is the default value when the risk rating is not set.",
            "Low risk rating.",
            "Medium risk rating.",
            "High risk rating.",
            "Critical risk rating.",
            "The vulnerability has been assessed, but a specific risk rating could not be determined or assigned."
          ],
          "type": "string",
          "enum": [
            "RISK_RATING_UNSPECIFIED",
            "LOW",
            "MEDIUM",
            "HIGH",
            "CRITICAL",
            "UNRATED"
          ],
          "description": "Required. The risk rating of the vulnerability."
        },
        "associations": {
          "description": "Optional. Associated threat actors, malware, etc. This is embedded as a snapshot because the details of the association at the time of the vulnerability match are important for context and reporting.",
          "type": "array",
          "items": {
            "$ref": "Association"
          }
        }
      }
    },
    "SearchFindingsResponse": {
      "properties": {
        "findings": {
          "items": {
            "$ref": "Finding"
          },
          "description": "List of findings.",
          "type": "array"
        },
        "nextPageToken": {
          "type": "string",
          "description": "Page token."
        }
      },
      "type": "object",
      "id": "SearchFindingsResponse",
      "description": "Response message for SearchFindings."
    },
    "ProductFix": {
      "id": "ProductFix",
      "description": "Contains details about a product fix.",
      "properties": {
        "displayName": {
          "description": "Required. The name of the fix. Ex: \"Magento\".",
          "type": "string"
        },
        "sourceId": {
          "type": "string",
          "description": "Required. The source ID of the fix. Ex: \"APPSEC-1420\"."
        },
        "uri": {
          "type": "string",
          "description": "Optional. The URI of the fix."
        },
        "publishTime": {
          "description": "Optional. The published time of the fix.",
          "type": "string",
          "format": "google-datetime"
        }
      },
      "type": "object"
    },
    "DnsRegistrationDetails": {
      "id": "DnsRegistrationDetails",
      "type": "object",
      "description": "Extracted WHOIS and DNS registration details of the domain.",
      "properties": {
        "expireTime": {
          "description": "Optional. The specific timestamp when the current domain registration expires.",
          "type": "string",
          "format": "google-datetime"
        },
        "registrar": {
          "type": "string",
          "description": "Optional. The registrar where the domain was registered (e.g., NameCheap)."
        },
        "registrationTime": {
          "description": "Optional. The specific timestamp when the domain registration was created.",
          "format": "google-datetime",
          "type": "string"
        },
        "privateRegistration": {
          "type": "boolean",
          "description": "Optional. Indicates whether private registration is enabled on the WHOIS record."
        },
        "registrantCountry": {
          "description": "Optional. The country code of the registrant (e.g., US). Use ISO 3166-1 alpha-2 codes",
          "type": "string"
        }
      }
    },
    "ListAlertsResponse": {
      "type": "object",
      "id": "ListAlertsResponse",
      "description": "Response message for ListAlerts.",
      "properties": {
        "alerts": {
          "type": "array",
          "description": "List of alerts.",
          "items": {
            "$ref": "Alert"
          }
        },
        "nextPageToken": {
          "description": "Page token.",
          "type": "string"
        }
      }
    },
    "CustomThreatScenarioConfig": {
      "properties": {
        "legacyMonitorMetadata": {
          "readOnly": true,
          "$ref": "LegacyMetadata",
          "description": "Output only. Legacy metadata associated with this scenario/monitor."
        },
        "compiledLuceneQuery": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. The compiled Lucene query string."
        },
        "documentQuery": {
          "description": "Optional. The query used to match documents.",
          "$ref": "DocumentQuery"
        },
        "documentCondition": {
          "description": "Required. The condition driving the scenario, stored as a stringified JSON. This is used to query/filter documents.",
          "type": "string"
        },
        "scenarioType": {
          "description": "Optional. The custom threat scenario type used to create this configuration.",
          "enumDescriptions": [
            "Unspecified scenario type.",
            "Data Leaks.",
            "Deep & Dark Web.",
            "Domain Protection.",
            "Ransomware Threats.",
            "Initial Access Broker.",
            "Netblocks and Domain Mentions.",
            "Supply Chain Compromise.",
            "Card Shops.",
            "Custom Monitor (Non-templated legacy monitor)."
          ],
          "type": "string",
          "enum": [
            "CUSTOM_THREAT_SCENARIO_TYPE_UNSPECIFIED",
            "DATA_LEAKS",
            "DEEP_DARK_WEB",
            "DOMAIN_PROTECTION",
            "RANSOMWARE_THREATS",
            "INITIAL_ACCESS_BROKER",
            "NETBLOCKS_AND_DOMAIN_MENTIONS",
            "SUPPLY_CHAIN_COMPROMISE",
            "CARD_SHOPS",
            "CUSTOM_MONITOR"
          ]
        }
      },
      "description": "CustomThreatScenarioConfig represents a user-defined threat scenario configuration.",
      "id": "CustomThreatScenarioConfig",
      "type": "object"
    },
    "Finding": {
      "type": "object",
      "id": "Finding",
      "description": "A ‘stateless’ and a point in time event that a check produced a result of interest.",
      "properties": {
        "name": {
          "type": "string",
          "description": "Identifier. Server generated name for the finding (leave clear during creation). Format: projects/{project}/findings/{finding}"
        },
        "provider": {
          "description": "Required. Logical source of this finding (name of the sub-engine).",
          "type": "string"
        },
        "detail": {
          "description": "Required. Holder of the domain specific details of the finding.",
          "$ref": "FindingDetail"
        },
        "severityAnalysis": {
          "readOnly": true,
          "description": "Output only. High-Precision Severity Analysis verdict for the finding.",
          "$ref": "SeverityAnalysis"
        },
        "relevanceAnalysis": {
          "readOnly": true,
          "$ref": "RelevanceAnalysis",
          "description": "Output only. High-Precision Relevance Analysis verdict for the finding."
        },
        "displayName": {
          "description": "Required. A short descriptive title for the finding \u003c= 250 chars. EX: \"Actor 'baddy' offering $1000 for credentials of 'goodguy'\".",
          "type": "string"
        },
        "audit": {
          "description": "Output only. Audit data about the finding.",
          "readOnly": true,
          "$ref": "Audit"
        },
        "aiSummary": {
          "type": "string",
          "description": "Optional. AI summary of the finding."
        },
        "configurations": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Optional. Configuration names that are bound to this finding."
        },
        "reoccurrenceTimes": {
          "items": {
            "type": "string",
            "format": "google-datetime"
          },
          "readOnly": true,
          "description": "Output only. When identical finding (same labels and same details) has re-occurred.",
          "type": "array"
        },
        "severity": {
          "format": "float",
          "type": "number",
          "deprecated": true,
          "description": "Optional. Deprecated: Use the `severity_analysis` field instead. Base severity score from the finding source."
        },
        "alert": {
          "type": "string",
          "description": "Optional. Name of the alert that this finding is bound to."
        }
      }
    },
    "Configuration": {
      "properties": {
        "etag": {
          "type": "string",
          "description": "If included when updating a configuration, this should be set to the current etag of the configuration. If the etags do not match, the update will be rejected and an ABORTED error will be returned."
        },
        "state": {
          "enum": [
            "STATE_UNSPECIFIED",
            "ENABLED",
            "DISABLED",
            "DEPRECATED"
          ],
          "type": "string",
          "enumDescriptions": [
            "Configuration state is unspecified. This is not expected to occur.",
            "Configuration is enabled for the customer.",
            "Configuration is disabled for the customer.",
            "Configuration is deprecated, no new configs are allowed to be created."
          ],
          "description": "Optional. State of the configuration."
        },
        "version": {
          "description": "Optional. A user-manipulatable version. Does not adhere to a specific format",
          "type": "string"
        },
        "audit": {
          "readOnly": true,
          "description": "Output only. Audit information for the configuration.",
          "$ref": "Audit"
        },
        "name": {
          "description": "Identifier. Server generated name for the configuration. format is projects/{project}/configurations/{configuration}",
          "type": "string"
        },
        "detail": {
          "$ref": "ConfigurationDetail",
          "description": "Required. Domain specific details for the configuration."
        },
        "provider": {
          "description": "Required. Name of the service that provides the configuration.",
          "type": "string"
        },
        "displayName": {
          "type": "string",
          "description": "Output only. Human readable name for the configuration.",
          "readOnly": true
        },
        "description": {
          "type": "string",
          "description": "Optional. A description of the configuration."
        }
      },
      "description": "A configuration represents a behavior an engine should follow when producing new findings.",
      "type": "object",
      "id": "Configuration"
    },
    "SeverityAnalysis": {
      "description": "Structured severity analysis for a threat.",
      "id": "SeverityAnalysis",
      "properties": {
        "reasoning": {
          "description": "Human-readable explanation from the model, detailing why a particular result is considered to have a certain severity.",
          "type": "string"
        },
        "confidence": {
          "description": "The level of confidence in the given verdict.",
          "enum": [
            "CONFIDENCE_LEVEL_UNSPECIFIED",
            "CONFIDENCE_LEVEL_LOW",
            "CONFIDENCE_LEVEL_MEDIUM",
            "CONFIDENCE_LEVEL_HIGH"
          ],
          "enumDescriptions": [
            "Default value. Confidence level is not specified.",
            "Low confidence in the verdict.",
            "Medium confidence in the verdict.",
            "High confidence in the verdict."
          ],
          "type": "string"
        },
        "severityLevel": {
          "description": "The level of severity.",
          "enumDescriptions": [
            "Default value, should never be set.",
            "Low Severity.",
            "Medium Severity.",
            "High Severity."
          ],
          "enum": [
            "SEVERITY_LEVEL_UNSPECIFIED",
            "SEVERITY_LEVEL_LOW",
            "SEVERITY_LEVEL_MEDIUM",
            "SEVERITY_LEVEL_HIGH"
          ],
          "type": "string"
        }
      },
      "type": "object"
    },
    "InitialAccessBrokerAlertDetail": {
      "description": "Captures the specific details of InitialAccessBroker (IAB) alert.",
      "type": "object",
      "properties": {
        "discoveryDocuments": {
          "description": "Output only. New structured metadata payload.",
          "readOnly": true,
          "type": "array",
          "items": {
            "$ref": "DiscoveryDocument"
          }
        },
        "severity": {
          "description": "Required. The severity of the Initial Access Broker (IAB) alert. Allowed values are: * `LOW` * `MEDIUM` * `HIGH` * `CRITICAL`",
          "type": "string"
        },
        "discoveryDocumentIds": {
          "deprecated": true,
          "description": "Optional. Deprecated: Use `discovery_documents` instead. Array of ids to accommodate multiple discovery documents.",
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      },
      "id": "InitialAccessBrokerAlertDetail"
    },
    "DomainMonitoringConfig": {
      "description": "Any account-level configuration options will go here.",
      "type": "object",
      "properties": {
        "domains": {
          "items": {
            "$ref": "DomainMonitoringDomain"
          },
          "description": "The domains to use as \"seeds\" for Suspicious Domain Monitoring.",
          "type": "array"
        }
      },
      "id": "DomainMonitoringConfig"
    },
    "DomainMonitoringDomainDetails": {
      "properties": {
        "domain": {
          "type": "string",
          "description": "Required. The domain name to match against."
        }
      },
      "id": "DomainMonitoringDomainDetails",
      "description": "Details specific to a monitored domain.",
      "type": "object"
    },
    "ThreatAttributionDetails": {
      "type": "object",
      "description": "Threat attribution information (actor, campaign, etc.).",
      "properties": {
        "malware": {
          "description": "Optional. The malware associated with the threat.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "actors": {
          "description": "Optional. The threat actors associated with the target.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "collections": {
          "items": {
            "type": "string"
          },
          "description": "Optional. The threat collections detected.",
          "type": "array"
        }
      },
      "id": "ThreatAttributionDetails"
    },
    "ConfigurationRevision": {
      "id": "ConfigurationRevision",
      "type": "object",
      "properties": {
        "name": {
          "type": "string",
          "description": "Identifier. The name of the ConfigurationRevision Format: projects//configurations//revisions/"
        },
        "createTime": {
          "format": "google-datetime",
          "description": "Output only. The time the Revision was created",
          "type": "string",
          "readOnly": true
        },
        "snapshot": {
          "$ref": "Configuration",
          "description": "The snapshot of the configuration"
        }
      },
      "description": "A ConfigurationRevision is a snapshot of a Configuration at a point in time. It is immutable."
    },
    "Alert": {
      "properties": {
        "priorityAnalysis": {
          "$ref": "PriorityAnalysis",
          "description": "Output only. High-Precision Priority Analysis for the alert.",
          "readOnly": true
        },
        "externalId": {
          "description": "Output only. External ID for the alert. This is used internally to provide protection against out of order updates.",
          "type": "string",
          "readOnly": true
        },
        "duplicateOf": {
          "description": "Output only. alert name of the alert this alert is a duplicate of. Format: projects/{project}/alerts/{alert}",
          "type": "string",
          "readOnly": true
        },
        "name": {
          "description": "Identifier. Server generated name for the alert. format is projects/{project}/alerts/{alert}",
          "type": "string"
        },
        "relevanceAnalysis": {
          "$ref": "RelevanceAnalysis",
          "readOnly": true,
          "description": "Output only. High-Precision Relevance Analysis verdict for the alert."
        },
        "audit": {
          "$ref": "Audit",
          "description": "Output only. Audit information for the alert.",
          "readOnly": true
        },
        "severityAnalysis": {
          "description": "Output only. High-Precision Severity Analysis for the alert.",
          "readOnly": true,
          "$ref": "SeverityAnalysis"
        },
        "aiSummary": {
          "description": "Optional. AI summary of the alert.",
          "type": "string"
        },
        "etag": {
          "type": "string",
          "description": "Optional. If included when updating an alert, this should be set to the current etag of the alert. If the etags do not match, the update will be rejected and an ABORTED error will be returned."
        },
        "state": {
          "readOnly": true,
          "description": "Output only. State of the alert.",
          "enum": [
            "STATE_UNSPECIFIED",
            "NEW",
            "READ",
            "TRIAGED",
            "ESCALATED",
            "RESOLVED",
            "DUPLICATE",
            "FALSE_POSITIVE",
            "NOT_ACTIONABLE",
            "BENIGN",
            "TRACKED_EXTERNALLY"
          ],
          "enumDescriptions": [
            "Default value, should never be set.",
            "alert is new.",
            "alert was read by a human.",
            "alert has been triaged.",
            "alert has been escalated.",
            "alert has been resolved.",
            "alert is a duplicate of another alert.",
            "alert is a false positive and should be ignored.",
            "alert is not actionable.",
            "alert is benign.",
            "alert is tracked externally."
          ],
          "type": "string"
        },
        "findings": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Output only. Findings that are covered by this alert.",
          "readOnly": true
        },
        "detail": {
          "readOnly": true,
          "description": "Output only. Details object for the alert, not all alerts will have a details object.",
          "$ref": "AlertDetail"
        },
        "tags": {
          "type": "array",
          "items": {
            "enumDescriptions": [
              "Default value, should never be set.",
              "Password length is under 8 characters.",
              "Password length is between 8 and 11 characters inclusive.",
              "Password length is 12 or more characters.",
              "Password contains at least one lowercase letter.",
              "Password contains at least one uppercase letter.",
              "Password contains at least one numeric digit.",
              "Password contains at least one special character.",
              "Credential login email domain matches a customer domain.",
              "Credential service domain matches a customer domain."
            ],
            "enum": [
              "ALERT_TAG_UNSPECIFIED",
              "ALERT_TAG_PASSWORD_LENGTH_UNDER_8",
              "ALERT_TAG_PASSWORD_LENGTH_8_TO_11",
              "ALERT_TAG_PASSWORD_LENGTH_12_PLUS",
              "ALERT_TAG_PASSWORD_HAS_LOWERCASE",
              "ALERT_TAG_PASSWORD_HAS_UPPERCASE",
              "ALERT_TAG_PASSWORD_HAS_NUMBER",
              "ALERT_TAG_PASSWORD_HAS_SPECIAL",
              "ALERT_TAG_MATCH_LOGIN_EMAIL_DOMAIN",
              "ALERT_TAG_MATCH_SERVICE_DOMAIN"
            ],
            "type": "string"
          },
          "description": "Output only. System taxonomy tags associated with this alert.",
          "readOnly": true
        },
        "findingCount": {
          "description": "Output only. The number of findings associated with this alert.",
          "format": "int64",
          "readOnly": true,
          "type": "string"
        },
        "displayName": {
          "readOnly": true,
          "description": "Output only. A short title for the alert.",
          "type": "string"
        },
        "duplicatedBy": {
          "type": "array",
          "readOnly": true,
          "items": {
            "type": "string"
          },
          "description": "Output only. alert names of the alerts that are duplicates of this alert. Format: projects/{project}/alerts/{alert}"
        },
        "configurations": {
          "type": "array",
          "description": "Output only. The resource names of the Configurations bound to this alert. Format: projects/{project}/configurations/{configuration}",
          "items": {
            "type": "string"
          },
          "readOnly": true
        }
      },
      "type": "object",
      "id": "Alert",
      "description": "Stateful object representing a group of Findings. Key feature to an Alert is that it expresses the user's intent towards the findings of that group, even those that haven't occurred yet."
    },
    "TargetTechnologyFindingDetail": {
      "description": "Contains details for a technology watchlist finding.",
      "type": "object",
      "properties": {
        "vulnerabilityMatch": {
          "description": "Optional. The vulnerability match details.",
          "$ref": "VulnerabilityMatch"
        }
      },
      "id": "TargetTechnologyFindingDetail"
    }
  },
  "fullyEncodeReservedExpansion": true,
  "baseUrl": "https://threatintelligence.googleapis.com/",
  "id": "threatintelligence:v1beta",
  "endpoints": [
    {
      "location": "us-central1",
      "endpointUrl": "https://threatintelligence.us-central1.rep.googleapis.com/",
      "description": "Regional Endpoint"
    }
  ],
  "discoveryVersion": "v1",
  "mtlsRootUrl": "https://threatintelligence.mtls.googleapis.com/",
  "revision": "20260927",
  "ownerDomain": "google.com",
  "documentationLink": "https://docs.cloud.google.com/threatintelligence/",
  "resources": {
    "projects": {
      "resources": {
        "configurations": {
          "resources": {
            "revisions": {
              "methods": {
                "list": {
                  "path": "v1beta/{+parent}/revisions",
                  "flatPath": "v1beta/projects/{projectsId}/configurations/{configurationsId}/revisions",
                  "response": {
                    "$ref": "ListConfigurationRevisionsResponse"
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameters": {
                    "orderBy": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. Specify ordering of response"
                    },
                    "filter": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. An AIP-160 filter string"
                    },
                    "parent": {
                      "pattern": "^projects/[^/]+/configurations/[^/]+$",
                      "location": "path",
                      "type": "string",
                      "description": "Required. The name of the Configuration to retrieve Revisions for",
                      "required": true
                    },
                    "pageSize": {
                      "description": "Optional. Page Size",
                      "location": "query",
                      "type": "integer",
                      "format": "int32"
                    },
                    "pageToken": {
                      "description": "Optional. A page token provided by the API",
                      "type": "string",
                      "location": "query"
                    }
                  },
                  "httpMethod": "GET",
                  "description": "List configuration revisions that meet the filter criteria.",
                  "parameterOrder": [
                    "parent"
                  ],
                  "id": "threatintelligence.projects.configurations.revisions.list"
                }
              }
            }
          },
          "methods": {
            "get": {
              "parameterOrder": [
                "name"
              ],
              "flatPath": "v1beta/projects/{projectsId}/configurations/{configurationsId}",
              "response": {
                "$ref": "Configuration"
              },
              "description": "Get a configuration by name.",
              "path": "v1beta/{+name}",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "httpMethod": "GET",
              "id": "threatintelligence.projects.configurations.get",
              "parameters": {
                "name": {
                  "location": "path",
                  "type": "string",
                  "description": "Required. Name of the configuration to get. Format: vaults/{vault}/configurations/{configuration}",
                  "pattern": "^projects/[^/]+/configurations/[^/]+$",
                  "required": true
                }
              }
            },
            "list": {
              "parameters": {
                "pageToken": {
                  "description": "Optional. Page token.",
                  "type": "string",
                  "location": "query"
                },
                "orderBy": {
                  "description": "Optional. Order by criteria in the csv format: \"field1,field2 desc\" or \"field1,field2\" or \"field1 asc, field2\".",
                  "location": "query",
                  "type": "string"
                },
                "filter": {
                  "type": "string",
                  "location": "query",
                  "description": "Optional. Filter criteria."
                },
                "parent": {
                  "location": "path",
                  "description": "Required. Parent of the configuration. Format: vaults/{vault}",
                  "pattern": "^projects/[^/]+$",
                  "required": true,
                  "type": "string"
                },
                "pageSize": {
                  "location": "query",
                  "type": "integer",
                  "format": "int32",
                  "description": "Optional. Page size."
                }
              },
              "parameterOrder": [
                "parent"
              ],
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "id": "threatintelligence.projects.configurations.list",
              "httpMethod": "GET",
              "path": "v1beta/{+parent}/configurations",
              "description": "Get a list of configurations that meet the filter criteria.",
              "flatPath": "v1beta/projects/{projectsId}/configurations",
              "response": {
                "$ref": "ListConfigurationsResponse"
              }
            },
            "upsert": {
              "id": "threatintelligence.projects.configurations.upsert",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "flatPath": "v1beta/projects/{projectsId}/configurations:upsert",
              "response": {
                "$ref": "UpsertConfigurationResponse"
              },
              "path": "v1beta/{+parent}/configurations:upsert",
              "request": {
                "$ref": "Configuration"
              },
              "parameters": {
                "parent": {
                  "required": true,
                  "type": "string",
                  "location": "path",
                  "description": "Required. Parent of the configuration.",
                  "pattern": "^projects/[^/]+$"
                },
                "publishTime": {
                  "description": "Optional. Time that the configuration should be considered to have been published. This is an advanced feature used when onboarding and bulk loading data from other systems. Do not set this field without consulting with the API team.",
                  "location": "query",
                  "type": "string",
                  "format": "google-datetime"
                }
              },
              "parameterOrder": [
                "parent"
              ],
              "httpMethod": "POST",
              "description": "Creates or updates a configuration."
            }
          }
        },
        "alerts": {
          "methods": {
            "triage": {
              "path": "v1beta/{+name}:triage",
              "request": {
                "$ref": "MarkAlertAsTriagedRequest"
              },
              "parameterOrder": [
                "name"
              ],
              "id": "threatintelligence.projects.alerts.triage",
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:triage",
              "response": {
                "$ref": "Alert"
              },
              "description": "Marks an alert as triaged - TRIAGED.",
              "parameters": {
                "name": {
                  "type": "string",
                  "location": "path",
                  "required": true,
                  "description": "Required. Name of the alert to mark as a triaged. Format: projects/{project}/alerts/{alert}",
                  "pattern": "^projects/[^/]+/alerts/[^/]+$"
                }
              },
              "httpMethod": "POST",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ]
            },
            "read": {
              "path": "v1beta/{+name}:read",
              "description": "Marks an alert as read - READ.",
              "request": {
                "$ref": "MarkAlertAsReadRequest"
              },
              "id": "threatintelligence.projects.alerts.read",
              "httpMethod": "POST",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "parameters": {
                "name": {
                  "required": true,
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "type": "string",
                  "description": "Required. Name of the alert to mark as read. Format: projects/{project}/alerts/{alert}",
                  "location": "path"
                }
              },
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:read",
              "response": {
                "$ref": "Alert"
              },
              "parameterOrder": [
                "name"
              ]
            },
            "escalate": {
              "id": "threatintelligence.projects.alerts.escalate",
              "request": {
                "$ref": "MarkAlertAsEscalatedRequest"
              },
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:escalate",
              "response": {
                "$ref": "Alert"
              },
              "path": "v1beta/{+name}:escalate",
              "description": "Marks an alert as escalated - ESCALATED.",
              "parameterOrder": [
                "name"
              ],
              "httpMethod": "POST",
              "parameters": {
                "name": {
                  "location": "path",
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "required": true,
                  "description": "Required. Name of the alert to mark as escalated. Format: projects/{project}/alerts/{alert}",
                  "type": "string"
                }
              }
            },
            "notActionable": {
              "request": {
                "$ref": "MarkAlertAsNotActionableRequest"
              },
              "parameters": {
                "name": {
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "type": "string",
                  "description": "Required. Name of the alert to mark as a not actionable. Format: projects/{project}/alerts/{alert}",
                  "required": true,
                  "location": "path"
                }
              },
              "description": "Marks an alert as not actionable - NOT_ACTIONABLE.",
              "httpMethod": "POST",
              "id": "threatintelligence.projects.alerts.notActionable",
              "parameterOrder": [
                "name"
              ],
              "path": "v1beta/{+name}:notActionable",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:notActionable",
              "response": {
                "$ref": "Alert"
              }
            },
            "resolve": {
              "description": "Marks an alert to closed state - RESOLVED.",
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:resolve",
              "response": {
                "$ref": "Alert"
              },
              "id": "threatintelligence.projects.alerts.resolve",
              "httpMethod": "POST",
              "parameters": {
                "name": {
                  "type": "string",
                  "description": "Required. Name of the alert to mark as resolved. Format: projects/{project}/alerts/{alert}",
                  "required": true,
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "location": "path"
                }
              },
              "request": {
                "$ref": "MarkAlertAsResolvedRequest"
              },
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "path": "v1beta/{+name}:resolve",
              "parameterOrder": [
                "name"
              ]
            },
            "duplicate": {
              "path": "v1beta/{+name}:duplicate",
              "parameterOrder": [
                "name"
              ],
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:duplicate",
              "response": {
                "$ref": "Alert"
              },
              "id": "threatintelligence.projects.alerts.duplicate",
              "description": "Marks an alert as a duplicate of another alert. - DUPLICATE.",
              "parameters": {
                "name": {
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "type": "string",
                  "location": "path",
                  "description": "Required. Name of the alert to mark as a duplicate. Format: projects/{project}/alerts/{alert}",
                  "required": true
                }
              },
              "request": {
                "$ref": "MarkAlertAsDuplicateRequest"
              },
              "httpMethod": "POST",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ]
            },
            "benign": {
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:benign",
              "response": {
                "$ref": "Alert"
              },
              "httpMethod": "POST",
              "parameterOrder": [
                "name"
              ],
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "request": {
                "$ref": "MarkAlertAsBenignRequest"
              },
              "description": "Marks an alert as benign - BENIGN.",
              "parameters": {
                "name": {
                  "description": "Required. Name of the alert to mark as a benign. Format: projects/{project}/alerts/{alert}",
                  "location": "path",
                  "type": "string",
                  "required": true,
                  "pattern": "^projects/[^/]+/alerts/[^/]+$"
                }
              },
              "id": "threatintelligence.projects.alerts.benign",
              "path": "v1beta/{+name}:benign"
            },
            "enumerateFacets": {
              "parameters": {
                "filter": {
                  "description": "Optional. Filter on what alerts will be enumerated.",
                  "location": "query",
                  "type": "string"
                },
                "parent": {
                  "type": "string",
                  "required": true,
                  "pattern": "^projects/[^/]+$",
                  "description": "Required. Parent of the alerts.",
                  "location": "path"
                }
              },
              "httpMethod": "GET",
              "description": "EnumerateAlertFacets returns the facets and the number of alerts that meet the filter criteria and have that value for each facet.",
              "id": "threatintelligence.projects.alerts.enumerateFacets",
              "path": "v1beta/{+parent}/alerts:enumerateFacets",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "flatPath": "v1beta/projects/{projectsId}/alerts:enumerateFacets",
              "response": {
                "$ref": "EnumerateAlertFacetsResponse"
              },
              "parameterOrder": [
                "parent"
              ]
            },
            "trackExternally": {
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "request": {
                "$ref": "MarkAlertAsTrackedExternallyRequest"
              },
              "parameterOrder": [
                "name"
              ],
              "path": "v1beta/{+name}:trackExternally",
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:trackExternally",
              "response": {
                "$ref": "Alert"
              },
              "id": "threatintelligence.projects.alerts.trackExternally",
              "parameters": {
                "name": {
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "description": "Required. Name of the alert to mark as tracked externally. Format: projects/{project}/alerts/{alert}",
                  "required": true,
                  "location": "path",
                  "type": "string"
                }
              },
              "httpMethod": "POST",
              "description": "Marks an alert as tracked externally - TRACKED_EXTERNALLY."
            },
            "falsePositive": {
              "parameterOrder": [
                "name"
              ],
              "description": "Marks an alert as a false positive - FALSE_POSITIVE.",
              "path": "v1beta/{+name}:falsePositive",
              "httpMethod": "POST",
              "parameters": {
                "name": {
                  "type": "string",
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "description": "Required. Name of the alert to mark as a false positive. Format: projects/{project}/alerts/{alert}",
                  "location": "path",
                  "required": true
                }
              },
              "id": "threatintelligence.projects.alerts.falsePositive",
              "request": {
                "$ref": "MarkAlertAsFalsePositiveRequest"
              },
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:falsePositive",
              "response": {
                "$ref": "Alert"
              }
            },
            "list": {
              "flatPath": "v1beta/projects/{projectsId}/alerts",
              "response": {
                "$ref": "ListAlertsResponse"
              },
              "path": "v1beta/{+parent}/alerts",
              "parameters": {
                "orderBy": {
                  "description": "Optional. Order by criteria in the csv format: \"field1, field2 desc\" or \"field1, field2\" or \"field1 asc, field2\". If a field is specified without `asc` or `desc`, ascending order is used by default. Supported fields for ordering are identical to those supported for filtering. Examples: * `audit.create_time desc` * `audit.update_time asc` * `audit.create_time desc, severity_analysis.severity_level desc`",
                  "location": "query",
                  "type": "string"
                },
                "pageSize": {
                  "description": "Optional. Page size. Default to 100 alerts per page. Maximum is 1000 alerts per page.",
                  "type": "integer",
                  "location": "query",
                  "format": "int32"
                },
                "parent": {
                  "description": "Required. Parent of the alerts. Format: projects/{project}",
                  "pattern": "^projects/[^/]+$",
                  "location": "path",
                  "type": "string",
                  "required": true
                },
                "filter": {
                  "location": "query",
                  "type": "string",
                  "description": "Optional. Filter criteria. Supported fields for filtering include: * `audit.create_time` * `audit.creator` * `audit.update_time` * `audit.updater` * `detail.data_leak.discovery_document_ids` * `detail.data_leak.severity` * `detail.detail_type` * `detail.initial_access_broker.discovery_document_ids` * `detail.initial_access_broker.severity` * `detail.insider_threat.discovery_document_ids` * `detail.insider_threat.severity` * `finding_count` * `priority_analysis.priority_level` * `relevance_analysis.confidence` * `relevance_analysis.relevance_level` * `relevance_analysis.relevant` * `severity_analysis.severity_level` * `state` Examples: * `detail.detail_type = \"initial_access_broker\"` * `detail.detail_type != \"data_leak\"` * `detail.insider_threat.severity = \"HIGH\"` * `audit.create_time \u003e= \"2026-04-03T00:00:00Z\" AND audit.create_time \u003c \"2026-04-06T00:00:00Z\"` * `state = \"NEW\" OR state = \"TRIAGED\"` * `severity_analysis.severity_level = \"SEVERITY_LEVEL_CRITICAL\"`"
                },
                "pageToken": {
                  "description": "Optional. Page token to retrieve the next page of results.",
                  "type": "string",
                  "location": "query"
                }
              },
              "id": "threatintelligence.projects.alerts.list",
              "httpMethod": "GET",
              "parameterOrder": [
                "parent"
              ],
              "description": "Get a list of alerts that meet the filter criteria.",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ]
            },
            "get": {
              "parameterOrder": [
                "name"
              ],
              "id": "threatintelligence.projects.alerts.get",
              "description": "Get an alert by name.",
              "httpMethod": "GET",
              "parameters": {
                "name": {
                  "pattern": "^projects/[^/]+/alerts/[^/]+$",
                  "required": true,
                  "location": "path",
                  "description": "Required. Name of the alert to get. Format: projects/{project}/alerts/{alert}",
                  "type": "string"
                }
              },
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "path": "v1beta/{+name}",
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}",
              "response": {
                "$ref": "Alert"
              }
            },
            "getPassword": {
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "id": "threatintelligence.projects.alerts.getPassword",
              "httpMethod": "GET",
              "parameters": {
                "name": {
                  "required": true,
                  "location": "path",
                  "type": "string",
                  "description": "Required. Name of the alert to get password for. Format: projects/{project}/alerts/{alert}",
                  "pattern": "^projects/[^/]+/alerts/[^/]+$"
                }
              },
              "parameterOrder": [
                "name"
              ],
              "path": "v1beta/{+name}:getPassword",
              "description": "Get the decrypted password of an alert.",
              "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}:getPassword",
              "response": {
                "$ref": "GetPasswordResponse"
              }
            }
          },
          "resources": {
            "documents": {
              "methods": {
                "get": {
                  "flatPath": "v1beta/projects/{projectsId}/alerts/{alertsId}/documents/{documentsId}",
                  "response": {
                    "$ref": "AlertDocument"
                  },
                  "path": "v1beta/{+name}",
                  "parameterOrder": [
                    "name"
                  ],
                  "parameters": {
                    "name": {
                      "location": "path",
                      "description": "Required. Name of the alert document to get. Format: projects/{project}/alerts/{alert}/documents/{document}",
                      "pattern": "^projects/[^/]+/alerts/[^/]+/documents/[^/]+$",
                      "required": true,
                      "type": "string"
                    }
                  },
                  "id": "threatintelligence.projects.alerts.documents.get",
                  "description": "Gets a specific document associated with an alert.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "GET"
                }
              }
            }
          }
        },
        "findings": {
          "methods": {
            "get": {
              "flatPath": "v1beta/projects/{projectsId}/findings/{findingsId}",
              "response": {
                "$ref": "Finding"
              },
              "id": "threatintelligence.projects.findings.get",
              "httpMethod": "GET",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "parameters": {
                "name": {
                  "pattern": "^projects/[^/]+/findings/[^/]+$",
                  "required": true,
                  "description": "Required. Name of the finding to get.",
                  "location": "path",
                  "type": "string"
                }
              },
              "parameterOrder": [
                "name"
              ],
              "path": "v1beta/{+name}",
              "description": "Get a finding by name. The `name` field should have the format: `projects/{project}/findings/{finding}`"
            },
            "search": {
              "parameterOrder": [
                "parent"
              ],
              "id": "threatintelligence.projects.findings.search",
              "parameters": {
                "parent": {
                  "type": "string",
                  "location": "path",
                  "pattern": "^projects/[^/]+$",
                  "description": "Required. Parent of the findings. Format: vaults/{vault}",
                  "required": true
                },
                "query": {
                  "description": "Optional. Query on what findings will be returned. This supports the same filter criteria as FindingService.ListFindings as well as the following relationship query `has_alert`. Example: - `has_alert(\"name=\\\"projects/gti-12345/alerts/alert-12345\\\"\")`",
                  "type": "string",
                  "location": "query"
                },
                "pageToken": {
                  "description": "Optional. Page token.",
                  "type": "string",
                  "location": "query"
                },
                "orderBy": {
                  "location": "query",
                  "type": "string",
                  "description": "Optional. Order by criteria in the csv format: \"field1,field2 desc\" or \"field1,field2\" or \"field1 asc, field2\"."
                },
                "pageSize": {
                  "location": "query",
                  "type": "integer",
                  "description": "Optional. Page size.",
                  "format": "int32"
                }
              },
              "httpMethod": "GET",
              "path": "v1beta/{+parent}/findings:search",
              "description": "SearchFindings is a more powerful version of ListFindings that supports complex queries like \"findings for alerts\" using functions such as `has_alert` in the query string. The `parent` field in SearchFindingsRequest should have the format: projects/{project} Example to search for findings for a specific issue: `has_alert(\"name=\\\"projects/gti-12345/alerts/alert-12345\\\"\")`",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "flatPath": "v1beta/projects/{projectsId}/findings:search",
              "response": {
                "$ref": "SearchFindingsResponse"
              }
            },
            "list": {
              "path": "v1beta/{+parent}/findings",
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "httpMethod": "GET",
              "description": "Get a list of findings that meet the filter criteria. The `parent` field in ListFindingsRequest should have the format: projects/{project}",
              "parameters": {
                "filter": {
                  "description": "Optional. Filter criteria.",
                  "location": "query",
                  "type": "string"
                },
                "pageToken": {
                  "location": "query",
                  "description": "Optional. Page token.",
                  "type": "string"
                },
                "pageSize": {
                  "description": "Optional. Page size.",
                  "format": "int32",
                  "location": "query",
                  "type": "integer"
                },
                "orderBy": {
                  "description": "Optional. Order by criteria in the csv format: \"field1,field2 desc\" or \"field1,field2\" or \"field1 asc, field2\".",
                  "location": "query",
                  "type": "string"
                },
                "parent": {
                  "required": true,
                  "type": "string",
                  "description": "Required. Parent of the findings.",
                  "location": "path",
                  "pattern": "^projects/[^/]+$"
                }
              },
              "parameterOrder": [
                "parent"
              ],
              "flatPath": "v1beta/projects/{projectsId}/findings",
              "response": {
                "$ref": "ListFindingsResponse"
              },
              "id": "threatintelligence.projects.findings.list"
            }
          }
        }
      },
      "methods": {
        "generateOrgProfile": {
          "scopes": [
            "https://www.googleapis.com/auth/cloud-platform"
          ],
          "request": {
            "$ref": "GenerateOrgProfileConfigurationRequest"
          },
          "description": "Triggers the generation of a Customer Profile for a project.",
          "parameters": {
            "name": {
              "type": "string",
              "pattern": "^projects/[^/]+$",
              "required": true,
              "description": "Required. The name of the project to generate the profile for. Format: projects/{project}",
              "location": "path"
            }
          },
          "httpMethod": "POST",
          "parameterOrder": [
            "name"
          ],
          "path": "v1beta/{+name}:generateOrgProfile",
          "flatPath": "v1beta/projects/{projectsId}:generateOrgProfile",
          "response": {
            "$ref": "Operation"
          },
          "id": "threatintelligence.projects.generateOrgProfile"
        }
      }
    }
  },
  "icons": {
    "x16": "http://www.google.com/images/icons/product/search-16.gif",
    "x32": "http://www.google.com/images/icons/product/search-32.gif"
  },
  "canonicalName": "Threat Intelligence Service",
  "parameters": {
    "callback": {
      "description": "JSONP",
      "location": "query",
      "type": "string"
    },
    "alt": {
      "enum": [
        "json",
        "media",
        "proto"
      ],
      "type": "string",
      "location": "query",
      "enumDescriptions": [
        "Responses with Content-Type of application/json",
        "Media download with context-dependent Content-Type",
        "Responses with Content-Type of application/x-protobuf"
      ],
      "default": "json",
      "description": "Data format for response."
    },
    "oauth_token": {
      "type": "string",
      "location": "query",
      "description": "OAuth 2.0 token for the current user."
    },
    "key": {
      "type": "string",
      "location": "query",
      "description": "API key. Your API key identifies your project and provides you with API access, quota, and reports. Required unless you provide an OAuth 2.0 token."
    },
    "fields": {
      "type": "string",
      "description": "Selector specifying which fields to include in a partial response.",
      "location": "query"
    },
    "$.xgafv": {
      "enum": [
        "1",
        "2"
      ],
      "type": "string",
      "description": "V1 error format.",
      "enumDescriptions": [
        "v1 error format",
        "v2 error format"
      ],
      "location": "query"
    },
    "quotaUser": {
      "type": "string",
      "description": "Available to use for quota purposes for server-side applications. Can be any arbitrary string assigned to a user, but should not exceed 40 characters.",
      "location": "query"
    },
    "prettyPrint": {
      "description": "Returns response with indentations and line breaks.",
      "default": "true",
      "location": "query",
      "type": "boolean"
    },
    "access_token": {
      "type": "string",
      "location": "query",
      "description": "OAuth access token."
    },
    "upload_protocol": {
      "type": "string",
      "description": "Upload protocol for media (e.g. \"raw\", \"multipart\").",
      "location": "query"
    },
    "uploadType": {
      "description": "Legacy upload protocol for media (e.g. \"media\", \"multipart\").",
      "type": "string",
      "location": "query"
    }
  },
  "version": "v1beta",
  "auth": {
    "oauth2": {
      "scopes": {
        "https://www.googleapis.com/auth/cloud-platform": {
          "description": "See, edit, configure, and delete your Google Cloud data and see the email address for your Google Account."
        }
      }
    }
  },
  "kind": "discovery#restDescription",
  "servicePath": "",
  "rootUrl": "https://threatintelligence.googleapis.com/",
  "ownerName": "Google",
  "title": "Threat Intelligence API",
  "version_module": true,
  "batchPath": "batch",
  "protocol": "rest",
  "description": "threatintelligence.googleapis.com API."
}
