SAFE Security · Example Payload

Safe Security Signal High Quality Edr Signal

A process gathered information about the operating system or hardware. Adversaries can use this to identify system vulnerabilities. Review the process tree.

CompanySecurityCyber Risk QuantificationThird-Party Risk ManagementContinuous Threat Exposure ManagementAI Security Posture ManagementRisk ManagementGovernance Risk and ComplianceFAIRVulnerability Management

Safe Security Signal High Quality Edr Signal is an example object payload from SAFE Security, with 12 top-level fields. It illustrates the shape of data this provider's APIs accept or return.

Top-level fields

versionidtypenamesourcedescriptionentitysecurityContextsfirstSeenlastSeenconfidencecreatedAt

Example Payload

safe-security-signal-high-quality-edr-signal.json Raw ↑
{
  "version": "1.2.13",
  "id": "aa332918-3319-470f-a18b-e75e326c9d7d",
  "type": "default",
  "name": "SystemInfoDiscovery",
  "source": {
    "name": "A-unique-signal-submitter-name"
  },
  "description": "A process gathered information about the operating system or hardware. Adversaries can use this to identify system vulnerabilities. Review the process tree.",
  "entity": {
    "type": "machine",
    "name": "MyVirtualMachine.acme.com",
    "entityAttributes": {
      "ipAddresses": [
        {
          "name": "Ip",
          "ipv4": "10.0.6.173"
        }
      ],
      "type": "Windows Server 2019 Datacenter 64 bit Edition Version 1809 Build 17763",
      "tags": {
        "hostname": [
          "MyVirtualMachine"
        ]
      }
    }
  },
  "securityContexts": [
    {
      "type": "edr",
      "status": {
        "complianceStatus": "fail",
        "workflowStatus": "new"
      },
      "evidence": {
        "observationText": "malware.exe tries to access system info"
      },
      "severity": {
        "type": "custom",
        "level": "high"
      },
      "attackPattern": [
        {
          "name": "Data from Local system",
          "mapping": {
            "techniqueName": "Data from Local system",
            "techniqueId": "T1005"
          },
          "sourceName": "ATT&CK"
        }
      ],
      "tags": {
        "detectionId": [
          "999e1e2a-effc-4317-b7b3-31e184d15481"
        ],
        "detectionTime": [
          "2023-03-09T11:42:28Z"
        ],
        "files": [
          "{\"name\":\"malware.exe\",\"checksumSha256\":\"550a68076cd1bade01da6e7a359d5642d1222934a1a862f5045e17374ef89539\",\"checksumMd5\":\"78979bd9288153580175da12d95f05b5\",\"filePath\":\"/usr/bin/malware.exe\",\"commandLine\":\"/usr/bin/malware.exe --systemd-watchdog\",\"parentchecksumSha256\":\"\",\"parentchecksumMd5\":\"\"}",
          "{\"name\":\"malwareSubProcess.exe\",\"checksumSha256\":\"9900a68076cd1bade01da6e7a359d5642d1222934a1a862f5045e17374ef89539\",\"checksumMd5\":\"87179bd9288153580175da12d95f05b5\",\"filePath\":\"/usr/bin/malwareSubProcess.exe\",\"commandLine\":\"/usr/bin/malwareSubProcess.exe --systemd-watchdog\",\"parentchecksumSha256\":\"\",\"parentchecksumMd5\":\"\"}"
        ]
      }
    },
    {
      "type": "edr",
      "status": {
        "complianceStatus": "fail",
        "workflowStatus": "new"
      },
      "evidence": {
        "observationText": "someothermalware.exe"
      },
      "severity": {
        "type": "custom",
        "level": "high"
      },
      "attackPattern": [
        {
          "name": "Data from Local system",
          "mapping": {
            "techniqueName": "Data from Local system",
            "techniqueId": "T1005"
          },
          "sourceName": "ATT&CK"
        }
      ],
      "tags": {
        "detectionId": [
          "111e1e2a-effc-4317-b7b3-31e184d15481"
        ],
        "detectionTime": [
          "2023-03-09T11:42:28Z"
        ],
        "files": [
          "{\"name\":\"someothermalware.exe\",\"checksumSha256\":\"550a68076cd1bade01da6e7a359d5642d1222934a1a862f5045e17374ef89539\",\"checksumMd5\":\"78979bd9288153580175da12d95f05b5\",\"filePath\":\"/usr/bin/someothermalware.exe\",\"commandLine\":\"/usr/bin/someothermalware.exe --systemd-watchdog\",\"parentchecksumSha256\":\"\",\"parentchecksumMd5\":\"\"}"
        ]
      }
    }
  ],
  "firstSeen": "2023-03-08T11:42:28.000Z",
  "lastSeen": "2023-03-09T11:42:28.000Z",
  "confidence": 100,
  "createdAt": "2023-03-09T11:42:28.000Z"
}

Work with this as data

Every example here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for examples

4 MCP tools reach this
  • find_examplesBrowse and filter every example in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This example
curl "https://apis.io/api/v1/examples/safe-security-signal-high-quality-edr-signal"
All examples
curl "https://apis.io/api/v1/examples?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.