---
name: azion-raise-the-sensitivity-of-one-threat-family
description: >-
  Set a higher sensitivity on one WAF threat family from the API, and keep the other seven where they are.
---

# Raise the sensitivity of one threat family

You can raise the sensitivity of one threat family from the API and leave the other seven where they are. The body below raises `sql_injection` to `high` and keeps the other seven families at `medium`.

---

## Prerequisites

- An existing rule set, such as `storefront-waf`. To create one, refer to [Create a rule set at medium sensitivity](/en/documentation/guides/application-security/firewall-and-waf/rule-set-medium/).
- A personal token.

---

## Raise the family

Send a `PATCH` request to the rule set endpoint, with all eight families in `thresholds`:

```bash
curl --request PATCH \
  --url https://api.azion.com/v4/workspace/wafs/<waf-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "engine_settings": {
    "engine_version": "2021-Q3",
    "type": "score",
    "attributes": {
      "rulesets": [1],
      "thresholds": [
        { "threat": "cross_site_scripting", "sensitivity": "medium" },
        { "threat": "directory_traversal", "sensitivity": "medium" },
        { "threat": "evading_tricks", "sensitivity": "medium" },
        { "threat": "file_upload", "sensitivity": "medium" },
        { "threat": "identified_attack", "sensitivity": "medium" },
        { "threat": "remote_file_inclusion", "sensitivity": "medium" },
        { "threat": "sql_injection", "sensitivity": "high" },
        { "threat": "unwanted_access", "sensitivity": "medium" }
      ]
    }
  }
}'
```

The API answers `202`, and the rule set reads back carrying exactly the eight entries you sent.

A `PATCH` replaces the whole `thresholds` array rather than merging it entry by entry. Send all eight families, including the seven you are not changing: a body carrying only `sql_injection` leaves the rule set scoring that family alone. Send each family once: a repeated `threat` is answered with `500` and the error `10067 Internal Server Error` rather than a validation message. The array holds at most eight entries, one per family, and `sensitivity` takes `highest`, `high`, `medium`, `low`, or `lowest`.

For what a level changes in the score a family blocks on, refer to [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes/) and [WAF Rule Sets](/en/documentation/platform/firewall/waf/rules-set/#sensitivity-levels).

---

## Next steps

- [Create a rule set at medium sensitivity](/en/documentation/guides/application-security/firewall-and-waf/rule-set-medium.md): The body this request edits, with every family at the level it starts on.
- [WAF Rule Sets](/en/documentation/platform/firewall/waf/rules-set.md): The eight threat families, the five sensitivity levels, and what each level changes.
