Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Threat Prevention API
9 actions
9 updates
phrasing
extends
openapi/palo-alto-networks-threat-prevention-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 9
$.info
$.paths['/threats/cve-coverage'].get
$.paths['/release-notes'].get
$.paths['/threats'].get
$.paths['/threats'].post
$.paths['/threats/history'].get
$.paths['/edl'].get
$.paths['/ip-feed'].get
$.paths['/ip-feed'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Threat Prevention API
version: 1.0.0
extends: openapi/palo-alto-networks-threat-prevention-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 8
- target: $.paths['/threats/cve-coverage'].get
update:
x-apievangelist-phrasing:
intent: Check threat coverage for a CVE
effect: read
questions:
- Does Palo Alto Networks threat prevention cover a specific CVE?
- Which signatures protect against a given CVE ID?
instructions:
- text: Check coverage for CVE {cve_id}.
slots:
cve_id: query.cve_id
- text: Show which protections exist for {cve_id}.
slots:
cve_id: query.cve_id
method: generated
generated: '2026-09-26'
- target: $.paths['/release-notes'].get
update:
x-apievangelist-phrasing:
intent: Get content release notes
effect: read
questions:
- What changed in a particular content release version?
- Are release notes available for content versions older than 8000?
instructions:
- text: Get release notes for {type} version {version}.
slots:
type: query.type
version: query.version
- text: Show the content release notes of type {type} for version {version}.
slots:
type: query.type
version: query.version
method: generated
generated: '2026-09-26'
- target: $.paths['/threats'].get
update:
x-apievangelist-phrasing:
intent: Look up threat signatures
effect: read
questions:
- Which Threat Vault signatures cover a given CVE?
- Can I find signatures linked to a file's SHA-256 hash?
- What antivirus signatures were released between two dates?
instructions:
- text: Find threat signatures for CVE {cve}.
slots:
cve: query.cve
- text: Look up signatures matching hash {sha256}.
slots:
sha256: query.sha256
- text: List {type} signatures released from {fromReleaseDate} to {toReleaseDate}.
slots:
type: query.type
fromReleaseDate: query.fromReleaseDate
toReleaseDate: query.toReleaseDate
method: generated
generated: '2026-10-01'
- target: $.paths['/threats'].post
update:
x-apievangelist-phrasing:
intent: Batch look up threat signatures
effect: read
questions:
- Can I look up up to 100 threat signatures at once by id or hash?
- What's the batch limit when querying signature metadata by name?
instructions:
- text: Batch look up threat signatures with ids {id}.
slots:
id: requestBody.id
- text: Get signature metadata in bulk for sample hashes {sha256}.
slots:
sha256: requestBody.sha256
method: generated
generated: '2026-09-26'
- target: $.paths['/threats/history'].get
update:
x-apievangelist-phrasing:
intent: Get a signature's release history
effect: read
questions:
- When was a threat signature first released and modified?
- How far back does antivirus signature release history go?
instructions:
- text: Show the release history of signature {id} for package {type}.
slots:
id: query.id
type: query.type
- text: Get the {type} release history of threat {id} in {order} order.
slots:
type: query.type
id: query.id
order: query.order
method: generated
generated: '2026-09-26'
- target: $.paths['/edl'].get
update:
x-apievangelist-phrasing:
intent: Get predefined external dynamic list content
effect: read
questions:
- What IPs are in a predefined external dynamic list?
- Is a specific IP address included in a Palo Alto Networks predefined EDL?
instructions:
- text: Get the contents of predefined EDL {name}.
slots:
name: query.name
- text: Check whether {ipaddr} is in EDL {name}.
slots:
ipaddr: query.ipaddr
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/ip-feed'].get
update:
x-apievangelist-phrasing:
intent: Look up IP feed information
effect: read
questions:
- Which IP feed is an address listed in?
- Can I search the IP feed for a range of addresses?
instructions:
- text: Look up IP feed information for {ipaddr}.
slots:
ipaddr: query.ipaddr
- text: Search the IP feed from {fromipaddr} to {toipaddr}.
slots:
fromipaddr: query.fromipaddr
toipaddr: query.toipaddr
method: generated
generated: '2026-09-26'
- target: $.paths['/ip-feed'].post
update:
x-apievangelist-phrasing:
intent: Batch look up IP feed entries
effect: read
questions:
- Can I check up to 100 IP addresses against the IP feed in one request?
- What is the batch limit for IP feed lookups?
instructions:
- text: Batch check IP addresses {ipaddr} against the IP feed.
slots:
ipaddr: requestBody.ipaddr
- text: Look up IP feed entries in bulk for {ipaddr}.
slots:
ipaddr: requestBody.ipaddr
method: generated
generated: '2026-09-26'