{"openapi":"3.0.0","info":{"title":"Web Application Scanning","version":"1.0.0"},"security":[{"cloud":[]}],"servers":[{"url":"https://cloud.tenable.com"}],"components":{"securitySchemes":{"cloud":{"type":"apiKey","in":"header","name":"X-ApiKeys","description":"Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY"}}},"x-samples-languages":["python","curl","node","powershell","ruby","javascript","objectivec","java","php","csharp","go","swift","kotlin"],"paths":{"/assets":{"get":{"summary":"List assets","description":"Lists up to 5000 assets, including non-WAS assets.

Requires ADMINISTRATOR [64] user permissions. See Permissions.

","operationId":"was-assets-list-assets","tags":["Assets"],"responses":{"200":{"description":"Returns a list of assets.","content":{"application/json":{"schema":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","description":"The unique ID of the asset."},"bios_uuid":{"type":"string","description":"BIOS UUID of the asset."},"ipv4":{"description":"A list of ipv4 addresses for the asset.","type":"array","items":{"type":"string"}},"ipv6":{"description":"A list of ipv6 addresses for the asset.","type":"array","items":{"type":"string"}},"hostname":{"description":"A list of hostnames for the asset.","type":"array","items":{"type":"string"}},"fqdn":{"description":"A list of FQDNs for the asset.","type":"array","items":{"type":"string"}},"ssh_fingerprint":{"type":"string","description":"The SSH fingerprint for the asset."},"mac_address":{"description":"A list of MAC addresses for the asset.","type":"array","items":{"type":"string"}},"netbios_name":{"type":"string","description":"The NetBIOS name for the asset."},"operating_system":{"type":"string","description":"The operating system installed on the asset."},"system_type":{"type":"string","description":"The system architecture (x86) of the asset."}}}},"examples":{"response":{"value":{"assets":[{"id":"31e37f64-cf0f-4ba0-9359-f5094a92352b","has_agent":false,"last_seen":"2018-11-28T17:28:28.000Z","sources":[{"name":"NESSUS_SCAN","first_seen":"2018-11-28T15:00:25.000Z","last_seen":"2018-11-28T17:28:28.000Z"}],"ipv4":["172.204.81.57"],"ipv6":[],"fqdn":[],"netbios_name":["S11C"],"operating_system":["Microsoft Windows Server 2008 R2 Datacenter Service Pack 1"],"agent_name":[],"aws_ec2_name":[],"mac_address":[]},{"id":"7e35af00-a3f0-4d43-a354-0638ba2b05ae","has_agent":false,"last_seen":"2018-11-28T17:28:28.000Z","sources":[{"name":"NESSUS_SCAN","first_seen":"2018-11-28T15:00:25.000Z","last_seen":"2018-11-28T17:28:28.000Z"}],"ipv4":["172.204.81.57"],"ipv6":[],"fqdn":["freebsd11.dc.demo.io"],"netbios_name":[],"operating_system":["FreeBSD 11.1"],"agent_name":[],"aws_ec2_name":[],"mac_address":[]},{"id":"466934be-abb4-4fa9-b8b8-27ace85e5523","has_agent":false,"last_seen":"2018-11-28T17:28:28.000Z","sources":[{"name":"NESSUS_SCAN","first_seen":"2018-11-28T15:00:25.000Z","last_seen":"2018-11-28T17:28:28.000Z"}],"ipv4":["172.204.81.57"],"ipv6":[],"fqdn":["fedorawork27.dc.demo.io"],"netbios_name":[],"operating_system":["Linux Kernel 4.13.9-300.fc27.x86_64 on Fedora release 27 (Twenty Seven)"],"agent_name":[],"aws_ec2_name":[],"mac_address":[]}],"total":3}}}}}},"403":{"description":"Returned if the user does not have permission to list assets."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"\n\n\n 429 Too Many Requests\n\n\n\n
\n

429 Too Many Requests

\n
\n
\n
nginx
\n\n\n"}}}}}},"security":[{"cloud":[]}]}},"/assets/{asset_uuid}":{"get":{"summary":"Get asset information","description":"Gets information about the specified asset.

Requires ADMINISTRATOR [64] user permissions. See Permissions.

","operationId":"was-assets-asset-info","tags":["Assets"],"parameters":[{"description":"The UUID of the asset.","required":true,"name":"asset_uuid","in":"path","schema":{"type":"string"}}],"responses":{"200":{"description":"Returns a list of assets.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string","description":"The unique ID of the asset."},"bios_uuid":{"type":"string","description":"BIOS UUID of the asset."},"ipv4":{"description":"A list of ipv4 addresses for the asset.","type":"array","items":{"type":"string"}},"ipv6":{"description":"A list of ipv6 addresses for the asset.","type":"array","items":{"type":"string"}},"hostname":{"description":"A list of hostnames for the asset.","type":"array","items":{"type":"string"}},"fqdn":{"description":"A list of FQDNs for the asset.","type":"array","items":{"type":"string"}},"ssh_fingerprint":{"type":"string","description":"The SSH fingerprint for the asset."},"mac_address":{"description":"A list of MAC addresses for the asset.","type":"array","items":{"type":"string"}},"netbios_name":{"type":"string","description":"The NetBIOS name for the asset."},"operating_system":{"type":"string","description":"The operating system installed on the asset."},"system_type":{"type":"string","description":"The system architecture (x86) of the asset."}}},"examples":{"response":{"value":{"id":"f56168ed-b719-4273-b58c-a340a09ffbce","has_agent":false,"created_at":"2018-11-28T15:01:01.618Z","updated_at":"2018-11-28T15:01:01.618Z","first_seen":"2018-11-28T15:00:57.000Z","last_seen":"2018-11-28T15:00:57.000Z","last_authenticated_scan_date":"2018-11-28T15:00:57.000Z","last_licensed_scan_date":"2018-11-28T15:00:57.000Z","sources":[{"name":"NESSUS_SCAN","first_seen":"2018-11-28T15:00:57.000Z","last_seen":"2018-11-28T15:00:57.000Z"}],"tags":[],"network_id":["00000000-0000-0000-0000-000000000000"],"ipv4":["172.204.81.57"],"ipv6":[],"fqdn":["kubernetes.ad.demo.io"],"mac_address":["aa:e6:57:2f:b3:13","ca:0f:69:8b:c8:ff","8a:83:e4:13:69:96","1e:1f:92:66:12:63","02:42:97:86:cb:b3","46:eb:64:68:6d:7d","6a:7b:e7:9e:a2:0e","f6:27:2f:17:12:bd","00:50:56:a6:6a:a4","a6:8c:f1:b7:2d:1d","16:dd:64:f9:12:6e"],"netbios_name":["kubernetes.ad.demo.io"],"operating_system":["Linux Kernel 3.10.0-862.14.4.el7.x86_64 on CentOS Linux release 7.5.1804 (Core)"],"system_type":["general-purpose"],"tenable_uuid":["dea43dad16684f8a93e88bbd6b30a35a"],"hostname":["kubernetes.ad.demo.io"],"agent_name":[],"bios_uuid":["42263460-6fee-53cb-7e3e-44c8304da18e"],"aws_ec2_instance_id":[],"aws_ec2_instance_ami_id":[],"aws_owner_id":[],"aws_availability_zone":[],"aws_region":[],"aws_vpc_id":[],"aws_ec2_instance_group_name":[],"aws_ec2_instance_state_name":[],"aws_ec2_instance_type":[],"aws_subnet_id":[],"aws_ec2_product_code":[],"aws_ec2_name":[],"azure_vm_id":[],"azure_resource_id":[],"gcp_project_id":[],"gcp_zone":[],"gcp_instance_id":[],"ssh_fingerprint":[],"mcafee_epo_guid":[],"mcafee_epo_agent_guid":[],"qualys_asset_id":[],"qualys_host_id":[],"servicenow_sysid":[]}}}}}},"403":{"description":"Returned if the user does not have permission to view information about an asset."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"\n\n\n 429 Too Many Requests\n\n\n\n
\n

429 Too Many Requests

\n
\n
\n
nginx
\n\n\n"}}}}}},"security":[{"cloud":[]}]}},"/import/assets":{"post":{"summary":"Import asset list","description":"Imports a list of assets in JSON format. The request cannot exceed 5 MB. Each asset object requires a value for at least one of the following properties: fqdn, ipv4, netbios_name, mac_address.

Requires CAN CONFIGURE [64] scan permissions. See Permissions.

","operationId":"was-assets-import","tags":["Assets"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"assets":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","description":"The unique ID of the asset."},"bios_uuid":{"type":"string","description":"BIOS UUID of the asset."},"ipv4":{"description":"A list of ipv4 addresses for the asset.","type":"array","items":{"type":"string"}},"ipv6":{"description":"A list of ipv6 addresses for the asset.","type":"array","items":{"type":"string"}},"hostname":{"description":"A list of hostnames for the asset.","type":"array","items":{"type":"string"}},"fqdn":{"description":"A list of FQDNs for the asset.","type":"array","items":{"type":"string"}},"ssh_fingerprint":{"type":"string","description":"The SSH fingerprint for the asset."},"mac_address":{"description":"A list of MAC addresses for the asset.","type":"array","items":{"type":"string"}},"netbios_name":{"type":"string","description":"The NetBIOS name for the asset."},"operating_system":{"type":"string","description":"The operating system installed on the asset."},"system_type":{"type":"string","description":"The system architecture (x86) of the asset."}}},"description":"An array of asset objects to import. Each asset object requires a value for at least one of the following properties: fqdn, ipv4, netbios\\_name, mac\\_address. Each asset object may also optionally contain additional properties for each property of was-assets. If any asset fails to be imported, an error message is returned indicating the cause of the failure.","example":"[{\"ipv4\":\"172.204.81.57\",\"operating_system\":\"Windows 7 x64\"}]"},"source":{"type":"string","description":"An identifier for the script used to upload the assets.","example":"Custom Import"}},"required":["assets","source"]}}}},"responses":{"200":{"description":"Returns the import job UUID.","content":{"application/json":{"schema":{"type":"object","properties":{"asset_import_job_uuid":{"type":"string","description":"The asset import job UUID."}}},"examples":{"response":{"value":{"asset_import_job_uuid":"fd7646b5-2c7a-433e-8f2b-f3281b7726ef"}}}}}},"400":{"description":"Returned if the user submitted a bad request."},"403":{"description":"Returned if the user does not have permission to import assets."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"\n\n\n 429 Too Many Requests\n\n\n\n
\n

429 Too Many Requests

\n
\n
\n
nginx
\n\n\n"}}}}}},"security":[{"cloud":[]}]}},"/import/asset-jobs":{"get":{"summary":"List asset import jobs","description":"Lists asset import jobs.

Requires ADMINISTRATOR [64] user permissions. See Permissions.

","operationId":"was-assets-list-import-jobs","tags":["Assets"],"responses":{"200":{"description":"Returns a list of asset import jobs.","content":{"application/json":{"schema":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","description":"The unique ID of the job."},"user_uuid":{"type":"string","description":"The unique ID of the user who started the import job."},"start_time":{"type":"string","description":"The start time of the job."},"end_time":{"type":"string","description":"The end time of the job."},"asset_count":{"type":"integer","description":"The total number of assets uploaded for import."},"imported_asset_count":{"type":"integer","description":"The number of assets successfully imported."},"failed_asset_count":{"type":"integer","description":"The number of assets that failed to import."},"status":{"type":"string","description":"The status of the job."},"error_message":{"type":"string","description":"The description of why a job failed."}}}},"examples":{"response":{"value":{"asset_import_jobs":[{"job_id":"fd7646b5-2c7a-433e-8f2b-f3281b7726ef","container_id":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","source":"gabbytest","batches":1,"uploaded_assets":0,"failed_assets":0,"start_time":1544480303548,"last_update_time":1544484511492,"end_time":1544484511492,"status":"ERROR","status_message":"Job failed by exceeding time limit"},{"job_id":"15759fd1-3483-4467-b04f-1bff11141c37","container_id":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","source":"readmeio","batches":1,"uploaded_assets":0,"failed_assets":0,"start_time":1544480429785,"last_update_time":1544484511496,"end_time":1544484511496,"status":"ERROR","status_message":"Job failed by exceeding time limit"}]}}}}}},"403":{"description":"Returned if the user does not have permission to list asset import jobs."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"\n\n\n 429 Too Many Requests\n\n\n\n
\n

429 Too Many Requests

\n
\n
\n
nginx
\n\n\n"}}}}}},"security":[{"cloud":[]}]}},"/import/asset-jobs/{asset_import_job_uuid}":{"get":{"summary":"Get import job information","description":"Gets information about the specified import job.

Requires ADMINISTRATOR [64] user permissions. See Permissions.

","operationId":"was-assets-import-job-info","tags":["Assets"],"parameters":[{"description":"The UUID of the asset import job.","required":true,"name":"asset_import_job_uuid","in":"path","schema":{"type":"string"}}],"responses":{"200":{"description":"Returns information about the specified import job.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string","description":"The unique ID of the job."},"user_uuid":{"type":"string","description":"The unique ID of the user who started the import job."},"start_time":{"type":"string","description":"The start time of the job."},"end_time":{"type":"string","description":"The end time of the job."},"asset_count":{"type":"integer","description":"The total number of assets uploaded for import."},"imported_asset_count":{"type":"integer","description":"The number of assets successfully imported."},"failed_asset_count":{"type":"integer","description":"The number of assets that failed to import."},"status":{"type":"string","description":"The status of the job."},"error_message":{"type":"string","description":"The description of why a job failed."}}},"examples":{"response":{"value":{"job_id":"fd7646b5-2c7a-433e-8f2b-f3281b7726ef","container_id":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","source":"gabbytest","batches":1,"uploaded_assets":0,"failed_assets":0,"start_time":1544480303548,"last_update_time":1544484511492,"end_time":1544484511492,"status":"ERROR","status_message":"Job failed by exceeding time limit"}}}}}},"403":{"description":"Returned if the user does not have permission to list asset import jobs."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"\n\n\n 429 Too Many Requests\n\n\n\n
\n

429 Too Many Requests

\n
\n
\n
nginx
\n\n\n"}}}}}},"security":[{"cloud":[]}]}},"/editor/{type}/{id}":{"get":{"summary":"Get configuration details","description":"Gets the configuration details for the scan or policy.

Requires STANDARD [32] user permissions. See Permissions.

","operationId":"was-editor-details","tags":["Editor"],"parameters":[{"description":"The type of object (scan or policy).","required":true,"name":"type","in":"path","schema":{"type":"string","enum":["scan","policy"]}},{"description":"The unique ID of the object.","required":true,"name":"id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returns the object data.","content":{"application/json":{"schema":{"type":"object","properties":{"uuid":{"type":"string"},"user_permissions":{"type":"integer"},"settings":{"type":"object"},"credentials":{"type":"object"},"plugins":{"type":"object"}}},"examples":{"response":{"value":{"credentials":{"data":[{"types":[{"inputs":[{"id":"username","placeholer":"admin","name":"Username","type":"entry","required":true},{"id":"password","name":"Password","type":"password","required":true},{"id":"type","name":"Authentication Type","type":"radio","default":"auto","options":["auto","ntlm"],"optionsLabels":["Basic / Digest","NTLM"]}],"max":1,"name":"HTTP Server Authentication","instances":[],"settings":null},{"inputs":[{"id":"was_auth_method","name":"Authentication method","type":"ui_radio","options":[{"inputs":[{"id":"login_page","name":"Login Page","type":"entry","required":true},{"id":"login_parameters","name":"Login Parameters","type":"entry"},{"id":"login_check","name":"Regex to verify successful auth","type":"entry","required":true},{"id":"login_check_url","name":"Page to verify active session","type":"entry","required":true},{"id":"login_check_pattern","name":"Regex to verify active session","type":"entry","required":true}],"name":"Login Form"},{"inputs":[{"id":"cookies","name":"Cookies","type":"entry"},{"id":"cookie_check_url","name":"Page to verify active session","type":"entry","required":true},{"id":"cookie_check_pattern","name":"Regex to verify active session","type":"entry","required":true}],"name":"Cookie Authentication"},{"inputs":[{"id":"selenium_script","name":"Selenium script (.side)","type":"file","required":true},{"id":"login_check_url","name":"Page to verify active session","type":"entry","required":true},{"id":"login_check_pattern","name":"Regex to verify active session","type":"entry","required":true}],"name":"Selenium Authentication"}],"default":"Login Form","required":true}],"max":1,"name":"Web Application Authentication","instances":[],"settings":null}],"name":"Web Authentication","default_expand":1}]},"is_was":true,"user_permissions":128,"owner":"admin@api.demo","title":"Web App Scan","is_agent":false,"uuid":"09805055-a034-4088-8986-aac5e1c57d5f0d44f09d736969bf","plugins":{"families":{"Injection":{"count":8,"id":8,"status":"enabled"},"File Inclusion":{"count":2,"id":10,"status":"enabled"},"Cross Site Request Forgery":{"count":1,"id":7,"status":"enabled"},"Data Exposure":{"count":7,"id":5,"status":"enabled"},"Cross Site Scripting":{"count":8,"id":6,"status":"enabled"},"Authentication & Session":{"count":4,"id":2,"status":"enabled"},"Web Servers":{"count":13,"id":4,"status":"enabled"},"Code Execution":{"count":5,"id":9,"status":"enabled"},"Component Vulnerability":{"count":502,"id":11,"status":"enabled"},"Web Applications":{"count":42,"id":3,"status":"enabled"}}},"filter_attributes":[],"settings":{"basic":{"inputs":[{"type":"entry","name":"Name","id":"name","default":"test","required":true},{"type":"textarea","name":"Description","id":"description","default":""},{"type":"select","id":"include_aggregate","name":"Scan results","default":true,"options":[{"name":"Keep private","value":"false"},{"name":"Show in dashboard","value":"true"}]},{"type":"select","id":"folder_id","name":"Folder","default":9,"options":[{"name":"My Scans","id":19},{"name":"Trash","id":18}]},{"type":"select","id":"scanner_id","name":"Scanner","default":"00000000-0000-0000-0000-00000000000000000000000000001","options":[{"id":"00000000-0000-0000-0000-00000000000000000000000000001","name":"US Cloud Scanner","type":"local","environment_name":null,"linked":true,"status":"on"},{"id":"1b895828-62a9-5084-8bc5-d4864a927fb10523d1e84e3fef44","name":"AP Singapore Cloud Scanners","type":"local","environment_name":null,"linked":true,"status":"on"},{"id":"cdf44a84-b547-b66c-d997-920aa1e897cc7165fe2e344196bb","name":"Demo Scanner","type":"local","environment_name":null,"linked":true,"status":"on"},{"id":"06ab826a-301d-7829-d2c4-37f400c0f949ea8cce60f523eeef","name":"EU Frankfurt Cloud Scanners","type":"local","environment_name":null,"linked":true,"status":"on"},{"id":"15e29fb5-c378-4803-37f7-67752912247e812e6cf942b4fd2e","name":"US East Cloud Scanners","type":"local","environment_name":null,"linked":true,"status":"on"},{"id":"37b315c1-f31f-cc8e-7e78-585c609fc1d7eba88f8d1e7d24b3","name":"US West Cloud Scanners","type":"local","environment_name":null,"linked":true,"status":"on"}]},{"type":"entry","id":"text_targets","name":"Target","default":"http://172.204.81.57","placeholder":"Example: https://www.tenable.com/","required":true,"regex":"^https?://\\S+$"}],"title":"Basic","groups":[{"title":"Schedule","name":"schedule","enabled":false,"rrules":null,"timezone":null,"starttime":null},{"filter_type":"and","inputs":[{"type":"textarea","name":"Email Recipient(s)","placeholder":"Example: me@example.com, you@example.com"}],"title":"Notifications","name":"email","emails":"","filters":null},{"title":"Permissions","name":"permissions","acls":[{"permissions":0,"owner":null,"display_name":null,"name":null,"id":null,"type":"default"},{"permissions":128,"owner":1,"display_name":"admin@api.demo","name":"admin@api.demo","id":2,"type":"user"}]}],"sections":[]},"assessment":{"inputs":null,"modes":{"id":"assessment_mode","name":"mode","type":"ui_radio","default":"Quick","options":[{"desc":"","name":"None"},{"desc":"