Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks Threat Vault ATP API

3 actions 3 updates phrasing extends openapi/palo-alto-networks-atp-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 3

$.info
$.paths['/atp/reports'].get
$.paths['/atp/reports/pcaps'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks Threat Vault ATP API
  version: 1.0.0
extends: openapi/palo-alto-networks-atp-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 2
- target: $.paths['/atp/reports'].get
  update:
    x-apievangelist-phrasing:
      intent: Get Advanced Threat Prevention analysis reports
      effect: read
      questions:
      - What did inline cloud analysis find about a threat with a given SHA-256 hash?
      - Can I pull the indicators of compromise from an ATP report?
      instructions:
      - text: Get the ATP report for hash {sha256}.
        slots:
          sha256: query.sha256
      - text: Show ATP analysis report {id}.
        slots:
          id: query.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/atp/reports/pcaps'].get
  update:
    x-apievangelist-phrasing:
      intent: Download packet captures for an ATP report
      effect: read
      questions:
      - How do I download the PCAP recorded during a threat's analysis?
      - Is there network traffic I can inspect for an ATP threat sample?
      instructions:
      - text: Download the PCAP files for sample {sha256}.
        slots:
          sha256: query.sha256
      - text: Get packet captures for hash {sha256} from ATP report {id}.
        slots:
          sha256: query.sha256
          id: query.id
      method: generated
      generated: '2026-09-26'