API reference · schema
SyscallAuditRequest
6 fields · used by 0 operations
Last reviewed 2026-10-03
Fields
| Field | Type | Meaning |
|---|---|---|
tenant_id | string | Tenant identifier default "demo" |
subject_id required | string | Subject / Agent / Process identifier |
syscall required | string | Name of the system call (e.g. execve, connect, ptrace) |
target | string | Target path, destination address, or resource default "" |
args | array of string | Syscall arguments or flags |
authorized_capabilities | array of string | Granted capabilities |
Smallest valid example
{
"tenant_id": "demo",
"subject_id": "subject-id",
"syscall": "syscall",
"target": ""
}JSON Schema
Show the raw definition
{
"properties": {
"tenant_id": {
"type": "string",
"title": "Tenant Id",
"description": "Tenant identifier",
"default": "demo"
},
"subject_id": {
"type": "string",
"title": "Subject Id",
"description": "Subject / Agent / Process identifier"
},
"syscall": {
"type": "string",
"title": "Syscall",
"description": "Name of the system call (e.g. execve, connect, ptrace)"
},
"target": {
"type": "string",
"title": "Target",
"description": "Target path, destination address, or resource",
"default": ""
},
"args": {
"items": {
"type": "string"
},
"type": "array",
"title": "Args",
"description": "Syscall arguments or flags"
},
"authorized_capabilities": {
"items": {
"type": "string"
},
"type": "array",
"title": "Authorized Capabilities",
"description": "Granted capabilities"
}
},
"type": "object",
"required": [
"subject_id",
"syscall"
],
"title": "SyscallAuditRequest"
}Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem