TestsGet a test

Get a test

Returns one test including description, remediation, mapped controls, requirements, and Fix Required resources by default. Looks up CAT first, then Cloud Parser Curator when the id is a CSPM test. Optional expansions via fields: tickets, mappedRisks, testHistory. addedBy and lastModifiedBy are omitted. Timestamps map from CAT createdAt / updatedAt. Requires scope test:read or test:write.

curl -X GET "https://api.scrut.io/v1/tests/test_authorized-users-access-tracked-log-sinks-gcp?resourceStatus=fix_required%2Cpassing&fields=tickets%2CmappedRisks%2CtestHistory" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
{
  "data": {
    "testId": "test_authorized-users-access-tracked-log-sinks-gcp",
    "testName": "Authorized users' access to log sinks is tracked (GCP)",
    "status": "ignored",
    "applications": [
      {
        "name": "AWS"
      }
    ],
    "assignees": [
      {
        "name": "Alex Rivera",
        "email": "alex@example.com",
        "isPrimary": true
      }
    ],
    "mappedFrameworks": [
      {
        "frameworkId": "14c4c45d-6c31-4097-a02a-ad9cfd04850e",
        "frameworkName": "SOC 2"
      }
    ],
    "entities": [
      {
        "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
        "entityName": "Organization Wide"
      }
    ],
    "description": "Checks that authorized users' access to GCP log sinks is tracked.",
    "remediation": "Enable audit logging and access tracking for GCP log sinks.",
    "mappedControls": [
      {
        "controlId": "2aa1b21e-4705-47cd-b1a7-e74ed4808bc9",
        "controlCode": "CC6.1",
        "controlName": "Transfer Authorizations"
      }
    ],
    "mappedRequirements": [
      {
        "frameworkId": "14c4c45d-6c31-4097-a02a-ad9cfd04850e",
        "frameworkName": "SOC 2",
        "requirementId": "b7e1c4a2-6f30-4d8a-9c15-2a8e4f1b0d63",
        "requirementCode": "CC6.1",
        "requirementName": "Logical Access Security"
      }
    ],
    "lastScannedOn": 1704067200000,
    "effortEstimate": "low",
    "notes": "Reviewed during the Q1 access audit.",
    "ignoreReason": "A compensating control covers this check.",
    "addedOn": 1704067200000,
    "modifiedOn": 1704067200000,
    "resources": [
      {
        "resourceId": "arn:aws:s3:::example-logs",
        "name": "example-logs",
        "status": "ignored",
        "lastScannedAt": 1704067200000,
        "firstDetected": 1704067200000,
        "assignees": [
          {
            "name": "Alex Rivera",
            "email": "alex@example.com"
          }
        ],
        "tags": [
          "prod"
        ],
        "region": "us-east-1",
        "service": "s3",
        "accountID": "123456789012",
        "environment": "production",
        "entities": [
          {
            "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
            "entityName": "Organization Wide"
          }
        ],
        "link": "https://console.aws.amazon.com/s3/buckets/example-logs",
        "description": "Production log bucket."
      }
    ],
    "tickets": [
      {
        "ticketId": "SEC-104",
        "source": "jira",
        "url": "https://jira.example/browse/SEC-104"
      }
    ],
    "mappedRisks": [
      {
        "riskId": "c3d4e5f6-a7b8-4901-8c2d-3e4f5a6b7c8d",
        "riskName": "Unauthorized access to production systems"
      }
    ],
    "testHistory": [
      {
        "scannedOn": 1704067200000,
        "status": "ignored"
      }
    ]
  },
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
GET
/v1/tests/{testId}
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
path
testIdstring
Required

Test identifier returned by list and get endpoints.

query
resourceStatusstring

Filter flagged resources on get. Comma-separated values are a union. Defaults to Fix Required. affected has no resource-level equivalent. Pass a comma-separated list (no spaces required). Allowed values: ignored, fix_required, passing, affected.

query
fieldsstring

Optional expansions. Default get response already includes core metadata; use this to add tickets, mappedRisks, or testHistory. Pass a comma-separated list (no spaces required). Allowed values: tickets, mappedRisks, testHistory.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Path Parameters

testIdstring
Required

Test identifier returned by list and get endpoints.

Example:
test_authorized-users-access-tracked-log-sinks-gcp

Query Parameters

resourceStatusstring

Filter flagged resources on get. Comma-separated values are a union. Defaults to Fix Required. affected has no resource-level equivalent. Pass a comma-separated list (no spaces required). Allowed values: ignored, fix_required, passing, affected.

Example:
fix_required,passing
fieldsstring

Optional expansions. Default get response already includes core metadata; use this to add tickets, mappedRisks, or testHistory. Pass a comma-separated list (no spaces required). Allowed values: tickets, mappedRisks, testHistory.

Example:
tickets,mappedRisks,testHistory

Responses

dataobject
Required
metaobject
Required