1. allowlist
Anzenna Public API
  • How To Use the Anzenna Public API
  • data exfiltration
    • Query database exfiltration events
      POST
    • List file delete events
      POST
    • List file movement activities
      POST
    • Get file movement activity by id
      GET
    • List files used with data exfiltration.
      POST
    • Get a specific data exfiltration file
      GET
    • List git events
      POST
    • Get a specific git event by id
      GET
    • List git repositories
      POST
    • Get a specific git repository
      GET
  • api key
    • Get API key information
      GET
  • login events
    • List login events
      POST
    • Get a login event by ID
      GET
  • browser applications
    • Query all browser applications
      POST
    • Get a browser application by id
      GET
    • List browser application instances
      POST
  • browser history
    • List browser history entries
      POST
  • data sharing
    • List file sharing instances
      POST
    • Query database share grants
      POST
    • Query database share user additions
      POST
    • List documents
      POST
    • Get document by id
      GET
  • devices
    • List devices
    • Get a device
    • List USB device connection events
    • Get a USB connection event
  • device policies
    • List device policies
    • Get a device policy
  • device applications
    • List device applications
    • Get a device application
    • Query device application instances.
  • device infections
    • List device infections
    • Get a device infection
  • ide applications
    • List IDE applications
    • Get an IDE application
  • ide application instances
    • Query IDE application instances.
  • mcp servers
    • List MCP servers
    • Get an MCP server
    • Query MCP server installations
  • mfa
    • Query all mfa statuses
    • Get an MFA status by id
  • oauth applications
    • Query all OAuth applications
    • Get an OAuth application by id
    • Query all OAuth application instances
  • passwords
    • Query all password reuse instances
  • people
    • Query all people
    • Get departure analysis for a person
    • Get a person by id
    • Add a category to multiple people
    • Remove a category from multiple people
  • account
    • List accounts
    • Get an account by id
  • phishing interactions
    • Query all phishing interactions
  • email flows
    • Query all outbound email events
    • Get an outbound email event by id
  • company wide risk trends
    • Get company risk trends
  • high risk organizations
    • Get number of high risk organizations
  • detections
    • Get key finding detections
    • Get detection details
    • List users associated with a given detection
  • events
    • List security events
  • shadow it
    • Query all Shadow IT instances
  • web host
    • Query all web host resources
    • Get a web host resource by id
  • advanced query
    • Execute an advanced query
  • sources
    • Query raw events
  • allowlist
    • Query all allowlists
      GET
    • Create a new allowlist
      POST
    • Delete an allowlist
      DELETE
    • Update an allowlist
      PUT
  • anomalies
    • Get an anomaly by ID
  • groups
    • List groups
  • investigations
    • Query all investigations
    • Get an investigation by id
    • Get detection investigation prompts
    • Get global investigation prompts
    • Get user investigation prompts
  • rdp connections
    • Query all remote machines
    • Get a remote machine by id
  • risk registers
    • Query all risk registers
    • Query all risk register catalog entries
  • shadow ai
    • Query all Shadow AI instances
    • Get a Shadow AI instance by id
  • training
    • List training campaigns
    • Create a training campaign
  • webhooks
    • Receive a webhook event
  • ai audits
    • Query all AI audit events
    • Get an AI audit event by id
  • dlp policies
    • List DLP policies
    • Get a DLP policy by id
    • List DLP policy detectors
  • remediations
    • Execute a remediation
  • dlp alerts
    • Query all DLP alerts
    • Get a DLP alert by id
  1. allowlist

Create a new allowlist

POST
/allowlists
Creates a new allowlist to exclude matching items from alerts and detections.
Allowlists can be configured with filtering rules and optional snooze duration.

Request

Authorization
Bearer Token
Provide your bearer token in the
Authorization
header when making requests to protected resources.
Example:
Authorization: Bearer ********************
or
Body Params application/jsonRequired

Examples

Responses

🟢200OK
application/json
Allowlist created successfully
Bodyapplication/json

🟠400Bad Request
🟠401Unauthorized
🟠403Forbidden
Request Request Example
Shell
JavaScript
Java
Swift
curl --location '/allowlists' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
    "entity": "unspecified",
    "name": "Company IP addresses",
    "query": "ip_address='\''192.168.1.0/24'\''"
}'
Response Response Example
200 - Example 1
{
    "entity": "unspecified",
    "id": "8CA67511-744C-4D74-B26E-7281CF88712F",
    "items_allowlisted": 42,
    "name": "Company IP addresses",
    "query": "ip_address='192.168.1.0/24'"
}
Modified at 2026-07-28 15:47:54
Previous
Query all allowlists
Next
Delete an allowlist
Built with