Edit

Share via


malwareState resource type (deprecated)

Namespace: microsoft.graph

Note

The legacy alerts API is deprecated and will be removed by April 2026. We recommend that you migrate to the new alerts and incidents API.

Contains stateful information about the malware entity.

Properties

Property Type Description
category String Provider-generated malware category (for example, trojan, ransomware, etc.).
family String Provider-generated malware family (for example, 'wannacry,' 'notpetya,' etc.).
name String Provider-generated malware variant name (for example, Trojan:Win32/Powessere.H).
severity String Provider-determined severity of this malware.
wasRunning Boolean Indicates whether the detected file (malware/vulnerability) was running at the time of detection or was detected at rest on the disk.

JSON representation

The following JSON representation shows the resource type.

{
  "category": "String",
  "family": "String",
  "name": "String",
  "severity": "String",
  "wasRunning": true
}