CAIN-42 CAIN Studio

API reference · schema

SyscallAuditRequest

6 fields · used by 0 operations

Last reviewed 2026-10-03

Fields

FieldTypeMeaning
tenant_idstringTenant identifier
default "demo"
subject_id requiredstringSubject / Agent / Process identifier
syscall requiredstringName of the system call (e.g. execve, connect, ptrace)
targetstringTarget path, destination address, or resource
default ""
argsarray of stringSyscall arguments or flags
authorized_capabilitiesarray of stringGranted capabilities

Smallest valid example

{
  "tenant_id": "demo",
  "subject_id": "subject-id",
  "syscall": "syscall",
  "target": ""
}

JSON Schema

Show the raw definition
{
  "properties": {
    "tenant_id": {
      "type": "string",
      "title": "Tenant Id",
      "description": "Tenant identifier",
      "default": "demo"
    },
    "subject_id": {
      "type": "string",
      "title": "Subject Id",
      "description": "Subject / Agent / Process identifier"
    },
    "syscall": {
      "type": "string",
      "title": "Syscall",
      "description": "Name of the system call (e.g. execve, connect, ptrace)"
    },
    "target": {
      "type": "string",
      "title": "Target",
      "description": "Target path, destination address, or resource",
      "default": ""
    },
    "args": {
      "items": {
        "type": "string"
      },
      "type": "array",
      "title": "Args",
      "description": "Syscall arguments or flags"
    },
    "authorized_capabilities": {
      "items": {
        "type": "string"
      },
      "type": "array",
      "title": "Authorized Capabilities",
      "description": "Granted capabilities"
    }
  },
  "type": "object",
  "required": [
    "subject_id",
    "syscall"
  ],
  "title": "SyscallAuditRequest"
}

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem