Response Categories, Reasons, & Identifiers Index
Response Categories, Reasons, & Identifiers Index
Each response returns the following information. These help you evaluate and act on security risks.
- Context category: Groups the information by its source or nature (e.g., Request, Session, Device, Network, or Account). This allows you to pinpoint exactly what aspect of the interaction triggered a risk label. Based on the
request_categoryvalue provided in the request - Risk labels: Specifies the types of risks or behavioral markers detected within that category (e.g., volume, incident, malicious cluster, or profile deviation). These labels indicate the specific security concern found.
- Applicable identifiers: Lists the identifiers used to track or link the risk to a specific entity, such as a Visitor ID (vid), User ID, Email, or Socket IP. This helps connect the threat to a specific user or session. Returned as the
typeproperty in the response. - Evidence: Provides the supporting data or proof behind the assigned risk label. This includes detailed metrics like specific signature types, traffic volume thresholds, or historical incident patterns. This provides the “why” behind the risk assessment.
Each category also has their own unique risk reasons and risk identifiers. Refer to the tables below for all available categories, their associated risk reasons, and their risk identifiers.
Context Categories
The table below shows all possible context categories, their possible risk labels and identifiers, and any associated evidence. For details about what each risk label means, see Risk Reasons Reference.
Evidence is currently unavailable in this version, but will be included in future iterations. The intent is to use this evidence to understand and assign a trust score to the event, which is a combination of risk and evidence.