All Operations
A complete alphabetical index of all CrowdStrike API operations across every service collection. Each Operation ID is a unique, case-sensitive identifier used by the Falcon SDKs to reference a specific API call. Use this page as a quick-lookup reference when you know the operation name but not which collection it belongs to.
| action.get.v1 | IOC |
| Get Actions by ids. | |
| action.query.v1 | IOC |
| Query Actions. | |
| ActionUpdateCount | Quarantine |
| Returns count of potentially affected quarantined files for each action. | |
| addCIDGroupMembers | MSSP (Flight Control) |
| Add new CID group member. | |
| addDashboardLabels | NGSIEM |
| Add multiple labels to a single dashboard | |
| addFileLabels | NGSIEM |
| Add multiple labels to a single file | |
| addRole | MSSP (Flight Control) |
| Create a link between user group and CID group, with zero or more additional roles. | |
| addSavedQueryLabels | NGSIEM |
| Add multiple labels to a saved query | |
| addUserGroupMembers | MSSP (Flight Control) |
| Add new user group member. | |
| admission-control-add-host-groups | Admission Control Policies |
| Add one or more host groups to an admission control policy. | |
| admission-control-add-rule-group-custom-rule | Admission Control Policies |
| Add one or more custom Rego rules to a rule group in an admission control policy. | |
| admission-control-create-policy | Admission Control Policies |
| Create an admission control policy. | |
| admission-control-create-rule-groups | Admission Control Policies |
| Create one or more rule groups and add them to an existing admission control policy. | |
| admission-control-delete-policies | Admission Control Policies |
| Delete an admission control policy. | |
| admission-control-delete-rule-groups | Admission Control Policies |
| Delete rule groups. | |
| admission-control-get-policies | Admission Control Policies |
| Get admission control policies. | |
| admission-control-query-policies | Admission Control Policies |
| Search admission control policies. | |
| admission-control-remove-host-groups | Admission Control Policies |
| Remove one or more host groups from an admission control policy. | |
| admission-control-remove-rule-group-custom-rule | Admission Control Policies |
| Delete one or more custom Rego rules from all rule groups in an admission control policy. | |
| admission-control-replace-rule-group-selectors | Admission Control Policies |
| Replace labels and/or namespaces of a rule group within an admission control policy. | |
| admission-control-set-rule-group-precedence | Admission Control Policies |
| Change precedence of rule groups within an admission control policy. | |
| admission-control-update-policy | Admission Control Policies |
| Update an admission control policy. | |
| admission-control-update-policy-precedence | Admission Control Policies |
| Update admission control policy precedence. | |
| admission-control-update-rule-groups | Admission Control Policies |
| Update a rule group. | |
| aggregate-events | Firewall Management |
| Aggregate events for customer | |
| aggregate-external-assets | Exposure Management |
| Returns external assets aggregates. | |
| aggregate-networks | Network Scan Networks |
| Returns “networks” aggregations | |
| aggregate-policy-rules | Firewall Management |
| Aggregate rules within a policy for customer | |
| aggregate-query-scan-host-metadata | ODS (On Demand Scan) |
| Get aggregates on ODS scan-hosts data. | |
| aggregate-rule-groups | Firewall Management |
| Aggregate rule groups for customer | |
| aggregate-rules | Firewall Management |
| Aggregate rules for customer | |
| aggregate-scan-runs | Network Scan Scan Runs |
| Returns “scan-runs” aggregations | |
| aggregate-scanners | Network Scan Scanners |
| Returns “scanners” aggregations | |
| aggregate-scans | ODS (On Demand Scan) |
| Get aggregates on ODS scan data. | |
| aggregate-scansMixin0 | Network Scan Scans |
| Returns “scans” aggregations | |
| aggregate-scheduled-scans | ODS (On Demand Scan) |
| Get aggregates on ODS scheduled-scan data. | |
| aggregate-zones | Network Scan Zones |
| Returns “zones” aggregations | |
| AggregateAlerts | Falcon Complete Dashboard |
| Retrieve aggregate epp alerts values based on the matched filter | |
| AggregateAllowList | Falcon Complete Dashboard |
| Retrieve aggregate allowlist ticket values based on the matched filter | |
| AggregateAssessmentsGroupedByClustersV2 | Kubernetes Container Compliance |
| Returns cluster details along with aggregated assessment results organized by cluster, including pass/fail assessment counts for various asset types. | |
| AggregateAssessmentsGroupedByRulesV2 | Kubernetes Container Compliance |
| Returns rule details along with aggregated assessment results organized by compliance rule, including pass/fail assessment counts. | |
| AggregateBlockList | Falcon Complete Dashboard |
| Retrieve aggregate blocklist ticket values based on the matched filter | |
| AggregateCases | Message Center |
| Retrieve aggregate case values based on the matched filter | |
| AggregateComplianceByAssetType | Kubernetes Container Compliance |
| Provides aggregated compliance assessment metrics and rule status information, organized by asset type. | |
| AggregateComplianceByClusterType | Kubernetes Container Compliance |
| Provides aggregated compliance assessment metrics and rule status information, organized by Kubernetes cluster type. | |
| AggregateComplianceByFramework | Kubernetes Container Compliance |
| Provides aggregated compliance assessment metrics and rule status information, organized by compliance framework. | |
| AggregateDeviceCountCollection | Falcon Complete Dashboard |
| Retrieve aggregate host/devices count based on the matched filter | |
| AggregateEscalations | Falcon Complete Dashboard |
| Retrieve aggregate escalation ticket values based on the matched filter | |
| AggregateFailedRulesByClustersV3 | Kubernetes Container Compliance |
| Retrieves the most non-compliant clusters, ranked in descending order based on the number of failed compliance rules across severity levels (critical, high, medium, and low). | |
| AggregateHuntingGuides | CAO Hunting |
| Aggregate Hunting Guides | |
| AggregateImageAssessmentHistory | Container Images |
| Image assessment history | |
| AggregateImageCount | Container Images |
| Aggregate count of images | |
| AggregateImageCountByBaseOS | Container Images |
| Aggregate count of images grouped by Base OS distribution | |
| AggregateImageCountByState | Container Images |
| Aggregate count of images grouped by state | |
| AggregateIntelligenceQueries | CAO Hunting |
| Aggregate intelligence queries | |
| AggregateNotificationsExposedDataRecordsV1 | Recon |
| Get notification exposed data record aggregates as specified via JSON in request body. | |
| AggregateNotificationsV1 | Recon |
| Get notification aggregates as specified via JSON in request body. | |
| AggregatePreventionPolicy | Falcon Complete Dashboard |
| Retrieve prevention policies aggregate values based on the matched filter | |
| AggregateRemediations | Falcon Complete Dashboard |
| Retrieve aggregate remediation ticket values based on the matched filter | |
| aggregates.access-tags.post.v1 | Case Management |
| Get access tag aggregates | |
| aggregates.file-details.post.v1 | Case Management |
| Get file details aggregates as specified via json in the request body. | |
| aggregates.notification-groups.post.v1 | Case Management |
| Get notification groups aggregations | |
| aggregates.notification-groups.post.v2 | Case Management |
| Get notification groups aggregations | |
| aggregates.rule-versions.post.v1 | Correlation Rules |
| Get rules aggregates as specified via json in the request body. | |
| aggregates.slas.post.v1 | Case Management |
| Get SLA aggregations | |
| aggregates.templates.post.v1 | Case Management |
| Get templates aggregations | |
| AggregateSensorUpdatePolicy | Falcon Complete Dashboard |
| Retrieve sensor update policies aggregate values | |
| AggregateSupportIssues | Falcon Complete Dashboard |
| Retrieve aggregate support issue ticket values based on the matched filter | |
| AggregateTopFailedImages | Kubernetes Container Compliance |
| Retrieves the most non-compliant container images, ranked in descending order based on the number of failed assessments across severity levels (critical, high, medium, and low). | |
| AggregateTotalDeviceCounts | Falcon Complete Dashboard |
| Retrieve aggregate total host/devices based on the matched filter | |
| aggregateUsersV1 | User Management |
| Get host aggregates as specified via json in request body. | |
| api_preempt_proxy_post_graphql | Identity Protection |
| Identity Protection GraphQL API. | |
| ArchiveDeleteV1 | Sample Uploads |
| Delete an archive that was uploaded previously | |
| ArchiveGetV1 | Sample Uploads |
| Retrieves the archives upload operation statuses. | |
| ArchiveListV1 | Sample Uploads |
| Retrieves the archives files in chunks. | |
| ArchiveUploadV1 | Sample Uploads |
| Uploads an archive and extracts files list from it. | |
| ArchiveUploadV2 | Sample Uploads |
| Uploads an archive and extracts files list from it. | |
| audit-events-query | Installation Tokens |
| Search for audit events by providing an FQL filter and paging details. | |
| audit-events-read | Installation Tokens |
| Gets the details of one or more audit events by id. | |
| AzureRefreshCertificate | CSPM Registration |
| Refresh certificate and returns JSON object(s) that contain the base64 encoded certificate for a service principal. | |
| BatchActiveResponderCmd | Real Time Response |
| Batch executes a RTR active-responder command across the hosts mapped to the given batch ID. | |
| BatchAdminCmd | Real Time Response Admin |
| Batch executes a RTR administrator command across the hosts mapped to the given batch ID. | |
| BatchCmd | Real Time Response |
| Batch executes a RTR read-only command across the hosts mapped to the given batch ID. | |
| BatchGetCmd | Real Time Response |
| Batch executes get command across hosts to retrieve files. | |
| BatchGetCmdStatus | Real Time Response |
| Retrieves the status of the specified batch get command. | |
| BatchInitSessions | Real Time Response |
| Batch initialize a RTR session on multiple hosts. | |
| BatchRefreshSessions | Real Time Response |
| Batch refresh a RTR session on multiple hosts. | |
| blob-download-external-assets | Exposure Management |
| Download the entire contents of the blob. | |
| blob-preview-external-assets | Exposure Management |
| Download a preview of the blob. | |
| bulkAddDashboardLabels | NGSIEM |
| Add labels to multiple dashboards (max 100 items, non-transactional) | |
| bulkAddLookupFileLabels | NGSIEM |
| Add labels to multiple lookup files (max 100 items, non-transactional) | |
| bulkAddSavedQueryLabels | NGSIEM |
| Add labels to multiple saved queries (max 100 items, non-transactional) | |
| BulkCreateDashboardsFromTemplate | NGSIEM |
| Create Multiple Dashboards from YAML Templates. | |
| BulkCreateLookupFiles | NGSIEM |
| Create Multiple Lookup Files. | |
| BulkCreateSavedQueriesFromTemplate | NGSIEM |
| Create Multiple Saved Queries from LogScale YAML Templates. | |
| BulkGetLookupFiles | NGSIEM |
| Retrieve Multiple Lookup Files by Filenames in NGSIEM. | |
| BulkInstallParsers | NGSIEM |
| Installs multiple CrowdStrike-managed out-of-the-box (OOTB) parsers into the customer’s repository in a single operation. | |
| bulkRemoveDashboardLabels | NGSIEM |
| Remove labels from multiple dashboards (max 100 items, non-transactional) | |
| bulkRemoveLookupFileLabels | NGSIEM |
| Remove labels from multiple lookup files (max 100 items, non-transactional) | |
| bulkRemoveSavedQueryLabels | NGSIEM |
| Remove labels from multiple saved queries (max 100 items, non-transactional) | |
| bulkUpdateDashboardLabels | NGSIEM |
| Replace all labels on multiple dashboards (max 100 items, non-transactional) | |
| BulkUpdateDashboardsFromTemplate | NGSIEM |
| Update Multiple Dashboards from YAML Templates. | |
| bulkUpdateLookupFileLabels | NGSIEM |
| Replace all labels on multiple lookup files (max 100 items, non-transactional) | |
| BulkUpdateLookupFiles | NGSIEM |
| Update Multiple Lookup Files. | |
| BulkUpdateSavedQueriesFromTemplate | NGSIEM |
| Update Multiple Saved Queries from LogScale YAML Templates. | |
| bulkUpdateSavedQueryLabels | NGSIEM |
| Replace all labels on multiple saved queries (max 100 items, non-transactional) | |
| cancel-scans | ODS (On Demand Scan) |
| Cancel ODS scans for the given scan ids. | |
| cao_incidents_aggregates_v1 | Intel |
| Perform statistical aggregations over incident data. | |
| cao_incidents_entities_v1 | Intel |
| Retrieve full details for one or more adversary incidents by their IDs. | |
| cao_incidents_queries_v1 | Intel |
| Search for adversary incidents using FQL criteria and return a paginated list of matching incident IDs. | |
| CaseAddActivity | Message Center |
| Add an activity to case. | |
| CaseAddAttachment | Message Center |
| Upload an attachment for the case. | |
| CaseDownloadAttachment | Message Center |
| retrieves an attachment for the case, given the attachment id | |
| cb-exclusions.create.v1 | Certificate Based Exclusions |
| Create new Certificate Based Exclusions. | |
| cb-exclusions.delete.v1 | Certificate Based Exclusions |
| Delete the exclusions by id | |
| cb-exclusions.get.v1 | Certificate Based Exclusions |
| Find all exclusion IDs matching the query with filter | |
| cb-exclusions.query.v1 | Certificate Based Exclusions |
| Search for cert-based exclusions. | |
| cb-exclusions.update.v1 | Certificate Based Exclusions |
| Updates existing Certificate Based Exclusions | |
| certificates.get.v1 | Certificate Based Exclusions |
| Retrieves certificate signing information for a file | |
| CloneComplianceFramework | Cloud Policies |
| Clone an existing compliance framework to create a custom copy | |
| CloneParser | NGSIEM |
| Clone an existing parser with a new name | |
| cloud-compliance-framework-posture-summaries | Cloud Security Compliance |
| Get sections and requirements with scores for benchmarks. | |
| cloud-compliance-rule-posture-summaries | Cloud Security Compliance |
| Get compliance score and counts for rules. | |
| cloud-registration-aws-create-account | Cloud AWS Registration |
| Creates a new account in our system for a customer. | |
| cloud-registration-aws-delete-account | Cloud AWS Registration |
| Deletes an existing AWS account or organization in our system. | |
| cloud-registration-aws-get-accounts | Cloud AWS Registration |
| Retrieve existing AWS accounts by account IDs or organization IDs | |
| cloud-registration-aws-query-accounts | Cloud AWS Registration |
| Retrieve existing AWS accounts by account IDs | |
| cloud-registration-aws-trigger-health-check | Cloud AWS Registration |
| Trigger health check scan for AWS accounts | |
| cloud-registration-aws-update-account | Cloud AWS Registration |
| Patches a existing account in our system for a customer. | |
| cloud-registration-aws-validate-accounts | Cloud AWS Registration |
| Validates the AWS account registration status, and discover organization child accounts if organization is specified | |
| cloud-registration-azure-create-registration | Cloud Azure Registration |
| Create an Azure registration for a tenant. | |
| cloud-registration-azure-create-suppressions | Cloud Azure Registration |
| Create new issue suppression rules | |
| cloud-registration-azure-delete-legacy-subscription | Cloud Azure Registration |
| Delete existing legacy Azure subscriptions. | |
| cloud-registration-azure-delete-registration | Cloud Azure Registration |
| Deletes existing Azure registrations. | |
| cloud-registration-azure-delete-suppressions | Cloud Azure Registration |
| Remove/revoke suppression rules | |
| cloud-registration-azure-download-script | Cloud Azure Registration |
| Retrieve script to create resources | |
| cloud-registration-azure-get-issue-suppression-values-by-field | Cloud Azure Registration |
| Retrieve distinct filterable values for issue suppression fields | |
| cloud-registration-azure-get-issue-values-by-field | Cloud Azure Registration |
| Retrieve distinct filterable values for issue fields | |
| cloud-registration-azure-get-issues | Cloud Azure Registration |
| Retrieve issues for Azure registrations | |
| cloud-registration-azure-get-registration | Cloud Azure Registration |
| Retrieve existing Azure registration for a tenant. | |
| cloud-registration-azure-get-script | Cloud Azure Registration |
| Download Azure deployment script (Terraform or Bicep) | |
| cloud-registration-azure-get-script-versions | Cloud Azure Registration |
| Retrieve all available script versions with filtering and sorting | |
| cloud-registration-azure-get-suppressions | Cloud Azure Registration |
| Retrieve existing suppression rules with filtering | |
| cloud-registration-azure-trigger-health-check | Cloud Azure Registration |
| Trigger health check scan for Azure registrations | |
| cloud-registration-azure-update-registration | Cloud Azure Registration |
| Update an existing Azure registration for a tenant. | |
| cloud-registration-azure-update-suppressions | Cloud Azure Registration |
| Update existing suppression rules | |
| cloud-registration-azure-validate-registration | Cloud Azure Registration |
| Validate an Azure registration by checking service principal, role assignments and deployment stack (if the deployment method is Bicep) | |
| cloud-registration-cross-provider-get-account-aggregates | Cloud Security Registration Combined |
| Returns cross-provider account aggregates by status | |
| cloud-registration-gcp-create-registration | Cloud Google Cloud Registration |
| Create a Google Cloud Registration. | |
| cloud-registration-gcp-delete-registration | Cloud Google Cloud Registration |
| Deletes a Google Cloud Registration and returns the deleted registration in the response body. | |
| cloud-registration-gcp-get-entities | Cloud Google Cloud Registration |
| Retrieve all GCP entities (organizations, folders, projects) grouped by type with support for FQL filtering, sorting, and pagination. | |
| cloud-registration-gcp-get-registration | Cloud Google Cloud Registration |
| Retrieve a Google Cloud Registration. | |
| cloud-registration-gcp-post-terraform-script | Cloud Google Cloud Registration |
| Generate Google Cloud Terraform deployment scripts (zip files) | |
| cloud-registration-gcp-put-registration | Cloud Google Cloud Registration |
| Creates/Updates a Google Cloud Registration. | |
| cloud-registration-gcp-trigger-health-check | Cloud Google Cloud Registration |
| Trigger health check scan for GCP registrations | |
| cloud-registration-gcp-update-registration | Cloud Google Cloud Registration |
| Update a Google Cloud Registration. | |
| cloud-security-assets-combined-application-findings | Cloud Security Assets |
| Get findings for an application resource with pagination | |
| cloud-security-assets-combined-compliance-by-account | Cloud Security Assets |
| Gets combined compliance data aggregated by account and region. | |
| cloud-security-assets-entities-get | Cloud Security Assets |
| Gets raw resources based on the provided IDs param. | |
| cloud-security-assets-entities-post | Cloud Security Assets |
| Gets raw resources based on IDs in the request body. | |
| cloud-security-assets-queries | Cloud Security Assets |
| Gets a list of resource IDs for the given parameters, filters and sort criteria | |
| cloud-security-registration-oci-create-account | Cloud OCI Registration |
| Create OCI tenancy account in CSPM | |
| cloud-security-registration-oci-delete-account | Cloud OCI Registration |
| Delete an existing OCI tenancy in CSPM. | |
| cloud-security-registration-oci-download-script | Cloud OCI Registration |
| Retrieve script to create resources in tenancy OCID | |
| cloud-security-registration-oci-get-account | Cloud OCI Registration |
| Retrieve a list of OCI tenancies with support for FQL filtering, sorting, and pagination | |
| cloud-security-registration-oci-rotate-key | Cloud OCI Registration |
| Refresh key for the OCI Tenancy | |
| cloud-security-registration-oci-update-account | Cloud OCI Registration |
| Patch an existing OCI account in our system for a customer. | |
| cloud-security-registration-oci-validate-tenancy | Cloud OCI Registration |
| Validate the OCI account in CSPM for a provided CID. | |
| cloud-security-timeline-risks-enriched | Cloud Security Risks |
| Returns the enriched asset timeline. | |
| combined-applications | Discover |
| Search for applications in your environment by providing an FQL filter and paging details. | |
| combined-cloud-risks | Cloud Security |
| Gets cloud risks with full details based on filters and sort criteria | |
| combined-ecosystem-subsidiaries | Exposure Management |
| Retrieves a list of ecosystem subsidiaries with their detailed information. | |
| combined-hosts | Discover |
| Search for assets in your environment by providing an FQL (Falcon Query Language) filter and paging details. | |
| combined-zones | Network Scan Zones |
| Get “zones” by filter | |
| combined.file-details.get.v1 | Case Management |
| Query file details | |
| combined.rules.get.v1 | Correlation Rules |
| Find all rules matching the query and filter. | |
| combined.rules.get.v2 | Correlation Rules |
| Find all rules matching the query and filter. | |
| combined_edges_get | ThreatGraph |
| Retrieve edges for a given vertex id. | |
| combined_ran_on_get | ThreatGraph |
| Look up instances of indicators such as hashes, domain names, and ip addresses that have been seen on devices in your environment. | |
| combined_summary_get | ThreatGraph |
| Retrieve summary for a given vertex ID | |
| CombinedBaseImages | Container Images |
| Retrieves a list of base images for the provided filter. | |
| CombinedDetections | Cloud Snapshots |
| Search IaC Detections using a query in Falcon Query Language | |
| CombinedDevicesByFilter | Hosts |
| Search for hosts in your environment by platform, hostname, IP, and other criteria. | |
| CombinedHiddenDevicesByFilter | Hosts |
| Search for hidden hosts in your environment by platform, hostname, IP, and other criteria. | |
| CombinedImageByVulnerabilityCount | Container Images |
| Retrieve top x images with the most vulnerabilities | |
| CombinedImageDetail | Container Images |
| Retrieve image entities identified by the provided filter criteria | |
| CombinedImageIssuesSummary | Container Images |
| Retrieve image issues summary such as Image detections, Runtime detections, Policies, vulnerabilities | |
| CombinedImagesFindings | Kubernetes Container Compliance |
| Returns detailed compliance assessment results for container images, providing the information needed to identify compliance violations. | |
| CombinedImageVulnerabilitySummary | Container Images |
| aggregates information about vulnerabilities for an image | |
| CombinedKnowledgeBaseAuditEventsV1 | Knowledge Base Audit Events |
| Get knowledge base audit events with full event details and pagination. | |
| CombinedKnowledgeBasesV1 | Knowledge Bases |
| Search for knowledge bases with filtering and return full entity details in a single response. | |
| CombinedNodesFindings | Kubernetes Container Compliance |
| Returns detailed compliance assessment results for kubernetes nodes, providing the information needed to identify compliance violations. | |
| combinedQueryEvaluationLogic | Spotlight Evaluation Logic |
| Search for evaluation logic in your environment by providing a FQL filter and paging details. | |
| combinedQueryVulnerabilities | Spotlight Vulnerabilities |
| Search for Vulnerabilities in your environment by providing an FQL filter and paging details. | |
| CombinedReleaseNotesV1 | Deployments |
| Queries for release-notes resources and returns details | |
| CombinedReleasesV1Mixin0 | Deployments |
| Queries for releases resources and returns details | |
| combinedSupportedEvaluationExt | Spotlight Evaluation Logic |
| Performs a combined query and get operation for retrieving RiskSupportedEvaluation entities. | |
| combinedUserRolesV1 | User Management |
| Deprecated : Please use GET /user-management/combined/user-roles/v2. | |
| CombinedUserRolesV2 | User Management |
| Get User Grant(s). | |
| combineVulnMetadataExt | Spotlight Vulnerability Metadata |
| Performs a combined query and get operation for retrieving Risk (vulnerability metadata) entities. | |
| ConnectCSPMGCPAccount | CSPM Registration |
| Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id | |
| ConnectD4CGCPAccount | D4C Registration |
| Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id | |
| create-network-locations | Firewall Management |
| Create new network locations provided, and return the ID. | |
| create-networks | Network Scan Networks |
| Create “networks” using provided specifications | |
| create-rule | Custom IOA |
| Create a rule within a rule group. | |
| create-rule-group | Firewall Management |
| Create new rule group on a platform for a customer with a name and description, and return the ID | |
| create-rule-group-validation | Firewall Management |
| Validates the request of creating a new rule group on a platform for a customer with a name and description | |
| create-rule-groupMixin0 | Custom IOA |
| Create a rule group for a platform with a name and an optional description. | |
| create-scan | ODS (On Demand Scan) |
| Create ODS scan and start or schedule scan for the given scan request. | |
| create-scan-runs | Network Scan Scan Runs |
| Create “scan-runs” using provided specifications | |
| create-scans | Network Scan Scans |
| Create “scans” using provided specifications | |
| create-templates | Network Scan Templates |
| Create “templates” using provided specifications | |
| create-zones | Network Scan Zones |
| Create “zones” using provided specifications | |
| CreateActionsV1 | Recon |
| Create actions for a monitoring rule. | |
| CreateAPIClient | API Clients |
| Create new API Client. | |
| CreateAWSAccount | Kubernetes Protection |
| Creates a new AWS account in our system for a customer and generates the installation script | |
| CreateAzureSubscription | Kubernetes Protection |
| Creates a new Azure Subscription in our system | |
| CreateBaseImagesEntities | Container Images |
| Creates base images using the provided details | |
| CreateCaseV2 | Message Center |
| create a new case | |
| createCIDGroups | MSSP (Flight Control) |
| Create new CID groups. | |
| CreateCloudGroupExternal | Cloud Security |
| Create a Cloud Group. | |
| CreateComplianceControl | Cloud Policies |
| Create a new custom compliance control | |
| CreateComplianceFramework | Cloud Policies |
| Create a new custom compliance framework | |
| createContentUpdatePolicies | Content Update Policies |
| Create Content Update Policies by specifying details about the policy to create | |
| CreateCSPMAwsAccount | CSPM Registration |
| Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access. | |
| CreateCSPMAzureAccount | CSPM Registration |
| Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access. | |
| CreateCSPMAzureManagementGroup | CSPM Registration |
| Creates a new management group in our system for a customer. | |
| CreateCSPMGCPAccount | CSPM Registration |
| Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access. | |
| CreateD4CAwsAccount | D4C Registration |
| Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access. | |
| CreateD4CGCPAccount | D4C Registration |
| Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access. | |
| CreateDashboardFromTemplate | NGSIEM |
| Create Dashboard from LogScale YAML Template in NGSIEM | |
| CreateDeploymentEntity | Cloud Snapshots |
| Launch a snapshot scan for a given cloud asset | |
| createDeviceControlPolicies | Device Control Policies |
| Create Device Control Policies by specifying details about the policy to create | |
| CreateDiscoverCloudAzureAccount | D4C Registration |
| Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access. | |
| CreateExecutorNode | ASPM |
| Create a new relay node | |
| CreateExportJobsV1 | Recon |
| Launch asynchronous export job. | |
| CreateFileV1 | Foundry Lookup Files |
| Creates a lookup file within a foundry app | |
| createFirewallPolicies | Firewall Policies |
| Create Firewall Policies by specifying details about the policy to create | |
| CreateGroupV1Mixin0 | Profile Groups |
| Create a new profile group | |
| createHostGroups | Host Group |
| Create Host Groups by specifying details about the group to create | |
| CreateIntegration | ASPM |
| Create a new integration | |
| CreateIntegrationTask | ASPM |
| Create new integration task. | |
| createIOAExclusionsV1 | IOA Exclusions |
| Create the IOA exclusions | |
| CreateIOC | IOCs |
| Create a new IOC. *** Deprecated - Use the new IOC Management endpoint (POST /iocs/entities/indicators/v1). *** | |
| CreateLookupFile | NGSIEM |
| Create Lookup File in NGSIEM | |
| CreateMigrationV1 | Host Migration |
| Create a device migration job. | |
| createMLExclusionsV1 | ML Exclusions |
| Create the ML exclusions | |
| CreateOrUpdateAWSSettings | Cloud Connect AWS |
| Create or update Global Settings which are applicable to all provisioned AWS accounts | |
| CreateParser | NGSIEM |
| Create Parser in NGSIEM. | |
| CreateParserExtension | NGSIEM |
| Create a Parser extension in NGSIEM for the provided base parser. | |
| CreateParserFromTemplate | NGSIEM |
| Create Parser from LogScale YAML Template in NGSIEM | |
| createPolicies | FileVantage |
| Creates a new policy of the specified type. | |
| CreatePolicies | Image Assessment Policies |
| Create Image Assessment policies | |
| CreatePolicyGroups | Image Assessment Policies |
| Create Image Assessment Policy Group entities | |
| createPreventionPolicies | Prevention Policies |
| Create Prevention Policies by specifying details about the policy to create | |
| CreateRegistryEntities | Falcon Container |
| Create a registry entity using the provided details | |
| createRTResponsePolicies | Response Policies |
| Create Response Policies by specifying details about the policy to create | |
| createRuleGroups | FileVantage |
| Creates a new rule group of the specified type. | |
| CreateRuleMixin0 | Cloud Policies |
| Create a new rule | |
| CreateRuleOverride | Cloud Policies |
| Create a new rule override | |
| createRules | FileVantage |
| Creates a new rule configuration within the specified rule group. | |
| CreateRulesV1 | Recon |
| Create monitoring rules. | |
| CreateSavedQuery | NGSIEM |
| Create Saved Query from LogScale YAML Template in NGSIEM | |
| CreateSavedSearchesDynamicExecuteV1 | Foundry LogScale |
| Execute a dynamic saved search | |
| CreateSavedSearchesExecuteV1 | Foundry LogScale |
| Execute a saved search | |
| CreateSavedSearchesIngestV1 | Foundry LogScale |
| Populate a saved search | |
| createScheduledExclusions | FileVantage |
| Creates a new scheduled exclusion configuration for the provided policy id. | |
| createSensorUpdatePolicies | Sensor Update Policy |
| Create Sensor Update Policies by specifying details about the policy to create | |
| createSensorUpdatePoliciesV2 | Sensor Update Policy |
| Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection | |
| CreateSuppressionRule | Cloud Policies |
| Create a new suppression rule | |
| createSVExclusionsV1 | Sensor Visibility Exclusions |
| Create the sensor visibility exclusions | |
| CreateUser | User Management |
| Deprecated : Please use POST /user-management/entities/users/v1. | |
| createUserGroups | MSSP (Flight Control) |
| Create new user groups. | |
| createUserV1 | User Management |
| Create a new user. | |
| cspm-evaluations-combined-iom-by-rule | Cloud Security Detections |
| returns ioms grouped by rule | |
| cspm-evaluations-iom-entities | Cloud Security Detections |
| Gets IOMs based on the provided IDs | |
| cspm-evaluations-iom-entities-post | Cloud Security Detections |
| Gets IOMs based on IDs in the request body. | |
| cspm-evaluations-iom-queries | Cloud Security Detections |
| Gets a list of IOM IDs for the given parameters, filters and sort criteria. | |
| customer-settings-read | Installation Tokens |
| Check current installation token settings. | |
| customer-settings-update | Installation Tokens |
| Update installation token settings. | |
| delete-external-assets | Exposure Management |
| Delete multiple external assets. | |
| delete-network-locations | Firewall Management |
| Delete network location entities by ID. | |
| delete-networks | Network Scan Networks |
| Delete “networks” by their IDs | |
| delete-rule-groups | Firewall Management |
| Delete rule group entities by ID | |
| delete-rule-groupsMixin0 | Custom IOA |
| Delete rule groups by ID. | |
| delete-rules | Custom IOA |
| Delete rules from a rule group by ID. | |
| delete-scans | Network Scan Scans |
| Delete “scans” by their IDs | |
| delete-scheduled-scans | ODS (On Demand Scan) |
| Delete ODS scheduled-scans for the given scheduled-scan ids. | |
| delete-templates | Network Scan Templates |
| Delete “templates” by their IDs | |
| delete-zones | Network Scan Zones |
| Delete “zones” by their IDs | |
| delete_policy_rules | Identity Protection |
| Delete policy rules | |
| delete_policy_rules | Identity Protection |
| Delete policy rules | |
| DeleteActionV1 | Recon |
| Delete an action from a monitoring rule based on the action ID. | |
| DeleteAPIClients | API Clients |
| Delete existing API Client(s) based on API Client ID(s) provided as request parameter(s) ‘ids’. | |
| DeleteAWSAccounts | Cloud Connect AWS |
| Delete a set of AWS Accounts by specifying their IDs | |
| DeleteAWSAccountsMixin0 | Kubernetes Protection |
| Delete AWS accounts. | |
| DeleteAzureSubscription | Kubernetes Protection |
| Deletes a new Azure Subscription in our system | |
| DeleteBaseImages | Container Images |
| Delete base images by base image uuid | |
| deleteCIDGroupMembersV1 | MSSP (Flight Control) |
| Deprecated : Please use DELETE /entities/cid-group-members/v2. | |
| deleteCIDGroupMembersV2 | MSSP (Flight Control) |
| Delete CID group members. | |
| deleteCIDGroups | MSSP (Flight Control) |
| Delete CID groups by ID. | |
| DeleteCloudGroupsExternal | Cloud Security |
| Delete Cloud Groups in batch | |
| DeleteComplianceControl | Cloud Policies |
| Delete custom compliance controls | |
| DeleteComplianceFramework | Cloud Policies |
| Delete a custom compliance framework and all associated controls and rule assignments | |
| deleteContentUpdatePolicies | Content Update Policies |
| Delete a set of Content Update Policies by specifying their IDs | |
| DeleteCSPMAwsAccount | CSPM Registration |
| Deletes an existing AWS account or organization in our system. | |
| DeleteCSPMAzureAccount | CSPM Registration |
| Deletes an Azure subscription from the system. | |
| DeleteCSPMAzureManagementGroup | CSPM Registration |
| Deletes Azure management groups from the system. | |
| DeleteCSPMGCPAccount | CSPM Registration |
| Deletes a GCP account from the system. | |
| DeleteD4CAwsAccount | D4C Registration |
| Deletes an existing AWS account or organization in our system. | |
| DeleteD4CGCPAccount | D4C Registration |
| Deletes a GCP account from the system. | |
| DeleteDashboard | NGSIEM |
| Delete Dashboard in NGSIEM | |
| deleteDeviceControlPolicies | Device Control Policies |
| Delete a set of Device Control Policies by specifying their IDs | |
| deletedRoles | MSSP (Flight Control) |
| Delete links or additional roles between user groups and CID groups. | |
| DeleteExecutorNode | ASPM |
| Delete a relay node | |
| DeleteExportJobsV1 | Recon |
| Delete export jobs (and their associated file(s)) based on their IDs. | |
| DeleteFederatedConnectionsConfig | Federated Connections |
| Delete configuration for a federated connection | |
| DeleteFile | Quick Scan Pro |
| Deletes file by its sha256 identifier. | |
| deleteFirewallPolicies | Firewall Policies |
| Delete a set of Firewall Policies by specifying their IDs | |
| DeleteGroup | ASPM |
| DeleteGroupsV1 | Profile Groups |
| Delete profile groups by IDs | |
| deleteHostGroups | Host Group |
| Delete a set of Host Groups by specifying their IDs | |
| DeleteImageDetails | Falcon Container |
| Delete Images by ids. | |
| DeleteIntegration | ASPM |
| Delete an existing integration by its ID | |
| DeleteIntegrationTask | ASPM |
| Delete an existing integration task by its ID | |
| deleteIOAExclusionsV1 | IOA Exclusions |
| Delete the IOA exclusions by id | |
| DeleteIOC | IOCs |
| Delete an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (DELETE /iocs/entities/indicators/v1). *** | |
| DeleteLookupFile | NGSIEM |
| Delete Lookup File in NGSIEM | |
| deleteMLExclusionsV1 | ML Exclusions |
| Delete the ML exclusions by id | |
| DeleteNotificationsV1 | Recon |
| Delete notifications based on IDs. | |
| DeleteObject | Custom Storage |
| Delete the specified object | |
| DeleteParser | NGSIEM |
| Delete Parser in NGSIEM | |
| deletePolicies | FileVantage |
| Deletes 1 or more policies. | |
| DeletePolicy | Image Assessment Policies |
| Delete Image Assessment Policy by policy UUID | |
| DeletePolicyGroup | Image Assessment Policies |
| Delete Image Assessment Policy Group entities | |
| deletePreventionPolicies | Prevention Policies |
| Delete a set of Prevention Policies by specifying their IDs | |
| DeleteRegistryEntities | Falcon Container |
| Delete the registry entity identified by the entity UUID | |
| DeleteReport | Falconx Sandbox |
| Delete report based on the report ID. | |
| deleteRTResponsePolicies | Response Policies |
| Delete a set of Response Policies by specifying their IDs | |
| deleteRuleGroups | FileVantage |
| Deletes 1 or more rule groups | |
| DeleteRuleMixin0 | Cloud Policies |
| Delete a rule | |
| DeleteRuleOverride | Cloud Policies |
| Delete a rule override | |
| deleteRules | FileVantage |
| Deletes 1 or more rules from the specified rule group. | |
| DeleteRulesV1 | Recon |
| Delete monitoring rules. | |
| DeleteSampleV2 | Falconx Sandbox |
| Removes a sample, including file, meta and submissions from the collection | |
| DeleteSampleV3 | Sample Uploads |
| Removes a sample, including file, meta and submissions from the collection | |
| DeleteSavedQuery | NGSIEM |
| Delete Saved Query in NGSIEM | |
| DeleteScanResult | Quick Scan Pro |
| Deletes the result of an QuickScan Pro scan. | |
| deleteScheduledExclusions | FileVantage |
| Deletes 1 or more scheduled exclusions from the provided policy id. | |
| deleteSensorUpdatePolicies | Sensor Update Policy |
| Delete a set of Sensor Update Policies by specifying their IDs | |
| deleteSensorVisibilityExclusionsV1 | Sensor Visibility Exclusions |
| Delete the sensor visibility exclusions by id | |
| DeleteSuppressionRules | Cloud Policies |
| Delete Suppression Rules by ID | |
| DeleteTags | ASPM |
| Remove existing tags | |
| DeleteThirdPartyPasskeyRegistry | Falcon ID |
| Deletes third party passkey registries | |
| DeleteUser | User Management |
| Deprecated : Please use DELETE /user-management/entities/users/v1. | |
| deleteUserGroupMembers | MSSP (Flight Control) |
| Delete user group members entry. | |
| deleteUserGroups | MSSP (Flight Control) |
| Delete user groups by ID. | |
| deleteUserV1 | User Management |
| Delete a user permanently. | |
| DeleteVersionedObject | Custom Storage |
| Delete the specified versioned object | |
| DescribeCollection | Custom Storage |
| Fetch metadata about an existing collection | |
| DescribeCollections | Custom Storage |
| Fetch metadata about one or more existing collections | |
| DevicesActionsDeleteV1 | Hosts |
| Permanently delete hosts from the system. | |
| DevicesCount | IOCs |
| Number of hosts in your customer account that have observed a given custom IOC | |
| DevicesRanOn | IOCs |
| Find hosts that have observed a given custom IOC. | |
| DiscoverCloudAzureDownloadCertificate | CSPM Registration |
| Returns JSON object(s) that contain the base64 encoded certificate for a service principal. | |
| DismissAffectedEntityV3 | SaaS Security |
| POST Dismiss Affected Entity | |
| DismissSecurityCheckV3 | SaaS Security |
| POST Dismiss Security Check by ID | |
| DownloadExportFile | Falcon Container |
| Download an export file | |
| DownloadExportFileMixin0 | Serverless Exports |
| Download an export file | |
| DownloadFeedArchive | Intelligence Feeds |
| Downloads the content as a zip archive for a given feed item ID | |
| DownloadFile | Downloads |
| Gets pre-signed URL for the file | |
| DownloadSensorInstallerById | Sensor Download |
| Download sensor installer by SHA256 ID | |
| DownloadSensorInstallerByIdV2 | Sensor Download |
| Download sensor installer by SHA256 ID | |
| DownloadSensorInstallerByIdV3 | Sensor Download |
| Download sensor installer by SHA256 ID | |
| fdrschema.combined.event.get | FDR |
| Fetch combined schema | |
| fdrschema.entities.event.get | FDR |
| Fetch event schema by ID | |
| fdrschema.entities.field.get | FDR |
| Fetch field schema by ID | |
| fdrschema.queries.event.get | FDR |
| Get list of event IDs given a particular query. | |
| fdrschema.queries.field.get | FDR |
| Get list of field IDs given a particular query. | |
| FetchFilesDownloadInfo | Downloads |
| Get files info and pre-signed download URLs | |
| FetchFilesDownloadInfoV2 | Downloads |
| Get cloud security tools info and pre-signed download URLs | |
| FindContainersByContainerRunTimeVersion | Kubernetes Protection |
| Retrieve containers by container_runtime_version | |
| FindContainersCountAffectedByZeroDayVulnerabilities | Kubernetes Protection |
| Retrieve containers count affected by zero day vulnerabilities | |
| get-accounts | Discover |
| Get details on accounts by providing one or more IDs. | |
| get-applications | Discover |
| Get details on applications by providing one or more IDs. | |
| get-ecosystem-subsidiaries | Exposure Management |
| Retrieves detailed information about ecosystem subsidiaries by ID. | |
| get-events | Firewall Management |
| Get events entities by ID and optionally version | |
| get-external-assets | Exposure Management |
| Get details on external assets by providing one or more IDs. | |
| get-firewall-fields | Firewall Management |
| Get the firewall field specifications by ID | |
| get-global-configs | Network Scan Global Configs |
| Get “global-configs” for the CID | |
| get-hosts | Discover |
| Get details on assets by providing one or more IDs. | |
| get-iot-hosts | Discover |
| Get details on IoT assets by providing one or more IDs. | |
| get-logins | Discover |
| Get details on logins by providing one or more IDs. | |
| get-malicious-files-by-ids | ODS (On Demand Scan) |
| Get malicious files by ids. | |
| get-network-locations | Firewall Management |
| Get a summary of network locations entities by ID | |
| get-network-locations-details | Firewall Management |
| Get network locations entities by ID | |
| get-networks | Network Scan Networks |
| Get “networks” by their IDs | |
| get-patterns | Custom IOA |
| Get pattern severities by ID. | |
| get-platforms | Firewall Management |
| Get platforms by ID, e.g., windows or mac or droid | |
| get-platformsMixin0 | Custom IOA |
| Get platforms by ID. | |
| get-policy-containers | Firewall Management |
| Get policy container entities by policy ID | |
| get-rule-groups | Firewall Management |
| Get rule group entities by ID. | |
| get-rule-groupsMixin0 | Custom IOA |
| Get rule groups by ID. | |
| get-rule-types | Custom IOA |
| Get rule types by ID. | |
| get-rules | Firewall Management |
| Get rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string) | |
| get-rules-get | Custom IOA |
| Get rules by ID and optionally with cid and/or version in the following format: [cid:]ID[:version]. | |
| get-rulesMixin0 | Custom IOA |
| Get rules by ID and optionally with cid and/or version in the following format: [cid:]ID[:version]. | |
| get-scan-host-metadata-by-ids | ODS (On Demand Scan) |
| Get scan hosts by ids. | |
| get-scan-run-reports | Network Scan Scan Run Reports |
| Downloads scan run report in CSV format | |
| get-scan-runs | Network Scan Scan Runs |
| Get “scan-runs” by their IDs | |
| get-scanners | Network Scan Scanners |
| Get “scanners” by their IDs | |
| get-scans | Network Scan Scans |
| Get “scans” by their IDs | |
| get-scans-by-scan-ids | ODS (On Demand Scan) |
| Get Scans by IDs. | |
| get-scans-by-scan-ids-v2 | ODS (On Demand Scan) |
| Get Scans by IDs. | |
| get-scheduled-scans-by-scan-ids | ODS (On Demand Scan) |
| Get ScheduledScans by IDs. | |
| get-template-configs | Network Scan Templates |
| Get details on the network scan template configurations | |
| get-templates | Network Scan Templates |
| Get “templates” by their IDs | |
| get-zones | Network Scan Zones |
| Get “zones” by their IDs | |
| get_policy_rules | Identity Protection |
| Get policy rules | |
| get_policy_rules | Identity Protection |
| Get policy rules | |
| get_policy_rules_query | Identity Protection |
| Query policy rule IDs | |
| get_policy_rules_query | Identity Protection |
| Query policy rule IDs | |
| GetAccessibleScopes | API Clients |
| Get all available scopes for customer. | |
| getActionsMixin0 | FileVantage |
| Retrieves the processing results for 1 or more actions. | |
| GetActionsV1 | Recon |
| Get actions based on their IDs. | |
| GetActivityMonitorV3 | SaaS Security |
| GET Activity Monitor | |
| GetAgentVersionsV1 | Agent Versions |
| Retrieve agent version entities for the provided ids. | |
| GetAggregateDetects | Detects |
| Deprecated: This endpoint will be decommissioned on September 30, 2025. | |
| GetAggregateFiles | Quarantine |
| Get quarantine file aggregates as specified via json in request body. | |
| GetAlertsV3 | SaaS Security |
| GET Alert by ID or GET Alerts | |
| GetAllAPIClientIdsForCustomer | API Clients |
| Get All API client ID(s) for customer. | |
| GetAPIClients | API Clients |
| Get API Client(s) based on API Client ID(s) provided as request parameter(s) ‘ids’. | |
| GetAppInventory | SaaS Security |
| GET Applications Inventory | |
| GetAppInventoryUsers | SaaS Security |
| GET Application Users | |
| GetArchiveExport | CAO Hunting |
| Creates an Archive Export | |
| GetArtifacts | Falconx Sandbox |
| Download IOC packs, PCAP files, memory dumps, and other analysis artifacts. | |
| getAssessmentsByScoreV1 | Zero Trust Assessment |
| Get Zero Trust Assessment data for one or more hosts by providing a customer ID (CID) and a range of scores. | |
| getAssessmentV1 | Zero Trust Assessment |
| Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID) and a customer ID (CID). | |
| GetAssetInventoryV3 | SaaS Security |
| GET Data Inventory | |
| getAuditV1 | Zero Trust Assessment |
| Get the Zero Trust Assessment audit report for one customer ID (CID). | |
| GetAvailableRoleIds | User Management |
| Deprecated : Please use GET /user-management/queries/roles/v1. | |
| GetAWSAccounts | Cloud Connect AWS |
| Retrieve a set of AWS Accounts by specifying their IDs | |
| GetAWSAccountsMixin0 | Kubernetes Protection |
| Provides a list of AWS accounts. | |
| GetAWSSettings | Cloud Connect AWS |
| Retrieve a set of Global Settings which are applicable to all provisioned AWS accounts | |
| GetAzureInstallScript | Kubernetes Protection |
| Provides the script to run for a given tenant id and subscription IDs | |
| GetAzureTenantConfig | Kubernetes Protection |
| Gets the Azure tenant Config | |
| GetAzureTenantIDs | Kubernetes Protection |
| Provides all the azure subscriptions and tenants | |
| GetBehaviorDetections | CSPM Registration |
| Get list of detected behaviors | |
| GetCaseActivityByIds | Message Center |
| Retrieve activities for given id’s | |
| GetCaseEntitiesByIDs | Message Center |
| Retrieve message center cases | |
| getChanges | FileVantage |
| Retrieve information on changes | |
| getChildren | MSSP (Flight Control) |
| Get link to child customer by child CID(s) | |
| getChildrenV2 | MSSP (Flight Control) |
| Get link to child customer by child CID(s) | |
| getCIDGroupByIdV1 | MSSP (Flight Control) |
| Deprecated : Please use GET /mssp/entities/cid-groups/v2. | |
| getCIDGroupByIdV2 | MSSP (Flight Control) |
| Get CID Groups by ID. | |
| getCIDGroupMembersByV1 | MSSP (Flight Control) |
| Deprecated : Please use GET /mssp/entities/cid-group-members/v2. | |
| getCIDGroupMembersByV2 | MSSP (Flight Control) |
| Get CID group members by CID Group ID. | |
| getCloudEventIDs | CSPM Registration |
| Deprecated: use cdrapi entities/event-details/v1 ‘logscale_related_events_query’ instead. | |
| GetCloudSecurityIntegrationState | ASPM |
| Get Cloud Security integration state | |
| GetClusters | Kubernetes Protection |
| Provides the clusters acknowledged by the Kubernetes Protection service | |
| getCombinedAssessmentsQuery | Configuration Assessment |
| Search for assessments in your environment by providing an FQL filter and paging details. | |
| GetCombinedCloudClusters | Kubernetes Protection |
| Returns a combined list of provisioned cloud accounts and known kubernetes clusters | |
| GetCombinedImages | Container Images |
| Get image assessment results by providing an FQL filter and paging details | |
| GetCombinedPluginConfigs | API Integrations |
| Queries for config resources and returns details | |
| GetCombinedSensorInstallersByQuery | Sensor Download |
| Get sensor installer details by provided query | |
| GetCombinedSensorInstallersByQueryV2 | Sensor Download |
| Get sensor installer details by provided query | |
| GetCombinedSensorInstallersByQueryV3 | Sensor Download |
| Get sensor installer details by provided query | |
| GetCombinedVulnerabilitiesSARIF | Serverless Vulnerabilities |
| Retrieve all lambda vulnerabilities that match the given query and return in the SARIF format | |
| GetComplianceControls | Cloud Policies |
| Get compliance controls by ID | |
| GetComplianceFrameworks | Cloud Policies |
| Get compliance frameworks by ID | |
| GetConfigurationDetectionEntities | CSPM Registration |
| Get misconfigurations based on the ID - including custom policy detections in addition to default policy detections. | |
| GetConfigurationDetectionIDsV2 | CSPM Registration |
| Get list of active misconfiguration ids - including custom policy detections in addition to default policy detections. | |
| GetConfigurationDetections | CSPM Registration |
| Get list of active misconfigurations. | |
| getContents | FileVantage |
| Retrieves the content captured for the provided change id | |
| getContentUpdatePolicies | Content Update Policies |
| Retrieve a set of Content Update Policies by specifying their IDs | |
| GetCredentials | Falcon Container |
| Gets the registry credentials | |
| GetCredentialsIAC | Cloud Snapshots |
| Gets the registry credentials (external endpoint) | |
| GetCredentialsMixin0 | Cloud Snapshots |
| Gets the registry credentials | |
| GetCSPMAwsAccount | CSPM Registration |
| Returns information about the current status of an AWS account. | |
| GetCSPMAwsAccountScriptsAttachment | CSPM Registration |
| Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment. | |
| GetCSPMAwsConsoleSetupURLs | CSPM Registration |
| Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment. | |
| GetCSPMAzureAccount | CSPM Registration |
| Return information about Azure account registration | |
| GetCSPMAzureManagementGroup | CSPM Registration |
| Return information about Azure management group registration | |
| GetCSPMAzureUserScriptsAttachment | CSPM Registration |
| Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment | |
| GetCSPMGCPAccount | CSPM Registration |
| Returns information about the current status of an GCP account. | |
| GetCSPMGCPServiceAccountsExt | CSPM Registration |
| Returns the service account id and client email for external clients. | |
| GetCSPMGCPUserScriptsAttachment | CSPM Registration |
| Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment | |
| GetCSPMGCPValidateAccountsExt | CSPM Registration |
| Run a synchronous health check. | |
| GetCSPMPoliciesDetails | CSPM Registration |
| Given an array of policy IDs, returns detailed policies information. | |
| GetCSPMPolicy | CSPM Registration |
| Given a policy ID, returns detailed policy information. | |
| GetCSPMPolicySettings | CSPM Registration |
| Returns information about current policy settings. | |
| GetCSPMScanSchedule | CSPM Registration |
| Returns scan schedule configuration for one or more cloud platforms. | |
| GetD4CAwsAccount | D4C Registration |
| Returns information about the current status of an AWS account. | |
| GetD4CAWSAccountScriptsAttachment | D4C Registration |
| Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment. | |
| GetD4CAwsConsoleSetupURLs | D4C Registration |
| Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment. | |
| GetD4CCGPAccount | D4C Registration |
| Returns information about the current status of an GCP account. | |
| GetD4CGCPServiceAccountsExt | D4C Registration |
| Returns the service account id and client email for external clients. | |
| GetD4CGCPUserScripts | D4C Registration |
| Return a script for customer to run in their cloud environment to grant us access to their GCP environment | |
| GetD4CGCPUserScriptsAttachment | D4C Registration |
| Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment | |
| GetDashboardTemplate | NGSIEM |
| Retrieve Dashboard(s) in NGSIEM as LogScale YAML Template. | |
| getDefaultDeviceControlPolicies | Device Control Policies |
| Retrieve the configuration for a Default Device Control Policy | |
| getDefaultDeviceControlSettings | Device Control Policies |
| Get default device control settings (USB and Bluetooth) | |
| GetDeliverySettings | Delivery Settings |
| Get Delivery Settings | |
| GetDeploymentsExternalV1 | Deployments |
| Get deployment resources by ids | |
| GetDetectSummaries | Detects |
| Deprecated: This endpoint will be decommissioned on September 30, 2025. | |
| getDeviceControlPolicies | Device Control Policies |
| Retrieve a set of Device Control Policies by specifying their IDs | |
| getDeviceControlPoliciesV2 | Device Control Policies |
| Get device control policies for the given filter criteria. | |
| GetDeviceCountCollectionQueriesByFilter | Falcon Complete Dashboard |
| Retrieve device count collection Ids that match the provided FQL filter, criteria with scrolling enabled | |
| GetDeviceDetails | Hosts |
| Get details on one or more hosts by providing host IDs in a POST body. | |
| GetDeviceDetailsV1 | Hosts |
| Get details on one or more hosts by providing agent IDs (AID). | |
| GetDeviceDetailsV2 | Hosts |
| Get details on one or more hosts by providing host IDs as a query parameter. | |
| GetDeviceInventoryV3 | SaaS Security |
| GET Device Inventory | |
| GetDiscoverCloudAzureAccount | D4C Registration |
| Return information about Azure account registration | |
| GetDiscoverCloudAzureTenantIDs | D4C Registration |
| Return available tenant ids for discover for cloud | |
| GetDiscoverCloudAzureUserScripts | D4C Registration |
| Return a script for customer to run in their cloud environment to grant us access to their Azure environment | |
| GetDiscoverCloudAzureUserScriptsAttachment | D4C Registration |
| Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment | |
| GetDriftIndicatorsValuesByDate | Drift Indicators |
| Returns the count of Drift Indicators by the date. by default it’s for 7 days. | |
| GetEnrichedAsset | Cloud Policies |
| Gets enriched assets that combine a primary resource with all its related resources | |
| GetEntityIDsByQueryPOST | Deployments |
| returns the release notes for the IDs in the request | |
| GetEntityIDsByQueryPOSTV2 | Deployments |
| returns the release notes for the IDs in the request with EA and GA dates in ISO 8601 format | |
| getEvaluationLogic | Spotlight Evaluation Logic |
| Get details on evaluation logic items by providing one or more IDs. | |
| getEvaluationLogicMixin0 | Configuration Assessment Evaluation Logic |
| Get details on evaluation logic items by providing one or more finding IDs. | |
| GetEvaluationResult | Cloud Policies |
| Gets evaluation results based on the provided rule | |
| GetEventsBody | Tailored Intelligence |
| Get event body for the provided event ID | |
| GetEventsEntities | Tailored Intelligence |
| Get events entities for specified ids. | |
| GetExecutorNodes | ASPM |
| Get all the relay nodes | |
| GetExecutorNodesMetadata | ASPM |
| Get metadata about all executor nodes | |
| GetExportJobsV1 | Recon |
| Get the status of export jobs based on their IDs. | |
| GetFileContentForExportJobsV1 | Recon |
| Download the file associated with a job ID. | |
| getFirewallPolicies | Firewall Policies |
| Retrieve a set of Firewall Policies by specifying their IDs | |
| GetGroupHierarchy | ASPM |
| Get group hierarchy | |
| GetGroupsV1Mixin0 | Profile Groups |
| Get profile groups by IDs with full details | |
| GetGroupsV2 | ASPM |
| GetGroupUsersV1 | Profile Groups |
| Get a list of groups with users that belong to them | |
| GetGroupV2 | ASPM |
| Get group details | |
| GetHelmValuesYaml | Kubernetes Protection |
| Provides a sample Helm values.yaml file for a customer to install alongside the agent Helm chart | |
| GetHorizonD4CScripts | D4C Registration |
| Returns static install scripts for Horizon. | |
| getHostGroups | Host Group |
| Retrieve a set of Host Groups by specifying their IDs | |
| GetHostMigrationIDsV1 | Host Migration |
| Query host migration IDs. | |
| GetHostMigrationsV1 | Host Migration |
| Get host migration details. | |
| GetHuntingGuides | CAO Hunting |
| Retrieves a list of Hunting Guides | |
| GetImageAssessmentReport | Falcon Container |
| Retrieves the Assessment report for the Image ID provided. | |
| GetIndicatorsReport | IOC |
| Launch an indicators report creation job | |
| GetIntegrations | ASPM |
| Get a list of all the integrations | |
| GetIntegrationsV2 | ASPM |
| Get a list of all the integrations | |
| GetIntegrationsV3 | SaaS Security |
| GET Integrations | |
| GetIntegrationTasks | ASPM |
| Get all the integration tasks | |
| GetIntegrationTasksAdmin | ASPM |
| Get all the integration tasks, requires admin scope | |
| GetIntegrationTasksMetadata | ASPM |
| Get metadata about all integration tasks | |
| GetIntegrationTasksV2 | ASPM |
| Get all the integration tasks | |
| GetIntegrationTypes | ASPM |
| Get all the integration types | |
| GetIntelActorEntities | Intel |
| Retrieve specific actors using their actor IDs. | |
| GetIntelIndicatorEntities | Intel |
| Retrieve specific indicators using their indicator IDs. | |
| GetIntelligenceQueries | CAO Hunting |
| Retrieves the details of a list of Intelligence queries IDs | |
| GetIntelReportEntities | Intel |
| Retrieve specific reports using their report IDs. | |
| GetIntelReportPDF | Intel |
| Return a Report PDF attachment | |
| GetIntelRuleEntities | Intel |
| Retrieve details for rule sets for the specified ids. | |
| GetIntelRuleFile | Intel |
| Download earlier rule sets. | |
| GetIOAEvents | CSPM Registration |
| For CSPM IOA events, gets list of IOA events. | |
| getIOAExclusionsV1 | IOA Exclusions |
| Get a set of IOA Exclusions by specifying their IDs | |
| GetIOAUsers | CSPM Registration |
| For CSPM IOA users, gets list of IOA users. | |
| GetIOC | IOCs |
| Get an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (GET /iocs/entities/indicators/v1). *** | |
| GetLatestIntelRuleFile | Intel |
| Download the latest rule set. | |
| GetLocations | Kubernetes Protection |
| Provides the cloud locations acknowledged by the Kubernetes Protection service | |
| GetLookupFile | NGSIEM |
| Retrieve Lookup File in NGSIEM | |
| GetLookupFromPackageV1 | NGSIEM |
| Download lookup file in package from NGSIEM | |
| GetLookupFromPackageWithNamespaceV1 | NGSIEM |
| Download lookup file in namespaced package from NGSIEM | |
| GetLookupV1 | NGSIEM |
| Download lookup file from NGSIEM | |
| GetMalQueryDownloadV1 | MalQuery |
| Download a file indexed by MalQuery. | |
| GetMalQueryEntitiesSamplesFetchV1 | MalQuery |
| Fetch a zip archive with password ‘infected’ containing the samples. | |
| GetMalQueryMetadataV1 | MalQuery |
| Retrieve indexed files metadata by their hash | |
| GetMalQueryQuotasV1 | MalQuery |
| Get information about search and download quotas in your environment | |
| GetMalQueryRequestV1 | MalQuery |
| Check the status and results of an asynchronous request, such as hunt or exact-search. | |
| GetMalwareEntities | Intel |
| Get malware entities for specified ids. | |
| GetMalwareMitreReport | Intel |
| Export Mitre ATT&CK information for a given malware family. | |
| GetMemoryDump | Falconx Sandbox |
| Get memory dump content, as binary | |
| GetMemoryDumpExtractedStrings | Falconx Sandbox |
| Get extracted strings from a memory dump | |
| GetMemoryDumpHexDump | Falconx Sandbox |
| Get hex view of a memory dump | |
| GetMetricsV3 | SaaS Security |
| GET Metrics | |
| GetMigrationDestinationsV1 | Host Migration |
| Get destinations for a migration. | |
| GetMigrationIDsV1 | Host Migration |
| Query migration jobs. | |
| GetMigrationsV1 | Host Migration |
| Get migration job details. | |
| GetMitreReport | Intel |
| Export Mitre ATT&CK information for a given actor. | |
| getMLExclusionsV1 | ML Exclusions |
| Get a set of ML Exclusions by specifying their IDs | |
| GetNotificationsDetailedTranslatedV1 | Recon |
| Get detailed notifications based on their IDs. | |
| GetNotificationsDetailedV1 | Recon |
| Get detailed notifications based on their IDs. | |
| GetNotificationsExposedDataRecordsV1 | Recon |
| Get notifications exposed data records based on their IDs. | |
| GetNotificationsTranslatedV1 | Recon |
| Get notifications based on their IDs. | |
| GetNotificationsV1 | Recon |
| Get notifications based on their IDs. | |
| GetObject | Custom Storage |
| Get the bytes for the specified object | |
| GetObjectMetadata | Custom Storage |
| Get the metadata for the specified object | |
| GetOnlineState.V1 | Hosts |
| Get the online status for one or more hosts by specifying each host’s unique ID. | |
| GetParser | NGSIEM |
| Retrieve Parser in NGSIEM. | |
| GetParserTemplate | NGSIEM |
| Retrieve Parser in NGSIEM as LogScale YAML Template | |
| getPolicies | FileVantage |
| Retrieves the configuration for 1 or more policies. | |
| getPreventionPolicies | Prevention Policies |
| Retrieve a set of Prevention Policies by specifying their IDs | |
| GetQuarantineFiles | Quarantine |
| Get quarantine file metadata for specified ids. | |
| GetQueriesAlertsV1 | Alerts |
| Deprecated: please use version v2 of this endpoint. | |
| GetQueriesAlertsV2 | Alerts |
| Retrieves all Alerts ids that match a given query. | |
| getRemediations | Spotlight Vulnerabilities |
| Get details on remediations by providing one or more IDs | |
| getRemediationsV2 | Spotlight Vulnerabilities |
| Get details on remediation by providing one or more IDs | |
| GetReportByReference | Falcon Container |
| Get image assessment scan report by image reference (v2) | |
| GetReportByScanID | Falcon Container |
| Get image assessment scan report by scan UUID (v2) | |
| GetReports | Falconx Sandbox |
| Get a full sandbox report. | |
| GetRoles | User Management |
| Deprecated : Please use GET /user-management/entities/roles/v1. | |
| getRolesByID | MSSP (Flight Control) |
| Get link between user group and CID group by ID. | |
| getRTResponsePolicies | Response Policies |
| Retrieve a set of Response Policies by specifying their IDs | |
| GetRule | Cloud Policies |
| Get a rule by id | |
| getRuleDetails | Configuration Assessment |
| Get rules details for provided one or more rule IDs | |
| getRuleGroups | FileVantage |
| Retrieves the rule group details for 1 or more rule groups. | |
| GetRuleInputSchema | Cloud Policies |
| Get rule input schema for given resource type | |
| GetRuleOverride | Cloud Policies |
| Get a rule override | |
| getRules | FileVantage |
| Retrieves the configuration for 1 or more rules. | |
| GetRulesEntities | Tailored Intelligence |
| Get rules entities for specified ids. | |
| getRulesMetadataByID | Kubernetes Container Compliance |
| Retrieve detailed compliance rule information including descriptions, remediation steps, and audit procedures by specifying rule identifiers. | |
| GetRulesV1 | Recon |
| Get monitoring rules based on their IDs. | |
| GetRuntimeDetectionsCombinedV2 | Container Detections |
| Retrieve container runtime detections by the provided search criteria | |
| GetSampleV2 | Falconx Sandbox |
| Retrieves the file associated with the given ID (SHA256) | |
| GetSampleV3 | Sample Uploads |
| Retrieves the file associated with the given ID (SHA256) | |
| GetSavedQueryTemplate | NGSIEM |
| Retrieve Saved Quer(ies) in NGSIEM as LogScale YAML Template. | |
| GetSavedSearchesExecuteV1 | Foundry LogScale |
| Get the results of a saved search | |
| GetSavedSearchesJobResultsDownloadV1 | Foundry LogScale |
| Get the results of a saved search as a file | |
| GetScanReport | Cloud Snapshots |
| retrieve the scan report for an instance | |
| GetScanResult | Quick Scan Pro |
| Gets the result of an QuickScan Pro scan. | |
| GetScans | Quick Scan |
| Check the status of a volume scan. | |
| GetScansAggregates | Quick Scan |
| Get scans aggregations as specified via json in request body. | |
| getScheduledExclusions | FileVantage |
| Retrieves the configuration of 1 or more scheduled exclusions from the provided policy id. | |
| GetSchema | Custom Storage |
| Get the bytes of the specified schema of the requested collection | |
| GetSchemaMetadata | Custom Storage |
| Get the metadata for the specified schema of the requested collection | |
| GetSearchStatusV1 | NGSIEM |
| Get status of search | |
| GetSecurityCheckAffectedV3 | SaaS Security |
| GET Security Check Affected | |
| GetSecurityCheckComplianceV3 | SaaS Security |
| GET Compliance | |
| GetSecurityChecksV3 | SaaS Security |
| GET Security Check by ID or GET List Security Checks | |
| GetSensorAggregates | Identity Protection |
| Get sensor aggregates as specified via json in request body. | |
| GetSensorDetails | Identity Protection |
| Get details on one or more sensors by providing device IDs in a POST body. | |
| GetSensorInstallersByQuery | Sensor Download |
| Get sensor installer IDs by provided query | |
| GetSensorInstallersByQueryV2 | Sensor Download |
| Get sensor installer IDs by provided query | |
| GetSensorInstallersByQueryV3 | Sensor Download |
| Get sensor installer IDs by provided query | |
| GetSensorInstallersCCIDByQuery | Sensor Download |
| Get CCID to use with sensor installers | |
| GetSensorInstallersEntities | Sensor Download |
| Get sensor installer details by provided SHA256 IDs | |
| GetSensorInstallersEntitiesV2 | Sensor Download |
| Get sensor installer details by provided SHA256 IDs | |
| GetSensorInstallersEntitiesV3 | Sensor Download |
| Get sensor installer details by provided SHA256 IDs | |
| getSensorUpdatePolicies | Sensor Update Policy |
| Retrieve a set of Sensor Update Policies by specifying their IDs | |
| getSensorUpdatePoliciesV2 | Sensor Update Policy |
| Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs | |
| GetSensorUsageHourly | Sensor Usage |
| Fetches hourly average. | |
| GetSensorUsageWeekly | Sensor Usage |
| Fetches weekly average. | |
| getSensorVisibilityExclusionsV1 | Sensor Visibility Exclusions |
| Get a set of Sensor Visibility Exclusions by specifying their IDs | |
| getServiceArtifacts | ASPM |
| GetServicesCount | ASPM |
| Get the total amount of existing services | |
| GetServiceViolationTypes | ASPM |
| Get the different types of violation | |
| GetStaticScripts | Kubernetes Protection |
| Gets static bash scripts that are used during registration | |
| GetSubmissions | Falconx Sandbox |
| Check the status of a sandbox analysis. | |
| GetSummaryReports | Falconx Sandbox |
| Get a short summary version of a sandbox report. | |
| GetSupportedSaasV3 | SaaS Security |
| GET Supported SaaS | |
| GetSuppressionRules | Cloud Policies |
| Get Suppression Rules by ID | |
| GetSystemLogsV3 | SaaS Security |
| GET System Logs | |
| GetSystemUsersV3 | SaaS Security |
| GET System Users | |
| GetTags | ASPM |
| Get all the tags | |
| GetThirdPartyPasskeyRegistry | Falcon ID |
| Fetches third party passkey registries | |
| getUserGroupMembersByIDV1 | MSSP (Flight Control) |
| Deprecated : Please use GET /mssp/entities/user-group-members/v2. | |
| getUserGroupMembersByIDV2 | MSSP (Flight Control) |
| Get user group members by user group ID. | |
| getUserGroupsByIDV1 | MSSP (Flight Control) |
| Deprecated : Please use GET /entities/user-groups/v2. | |
| getUserGroupsByIDV2 | MSSP (Flight Control) |
| Get user groups by ID. | |
| GetUserGroupsV1 | Profile Groups |
| Get a list of users with the groups that they belong to | |
| GetUserInventoryV3 | SaaS Security |
| GET User Inventory | |
| GetUserRoleIds | User Management |
| Deprecated : Please use GET /user-management/combined/user-roles/v1. | |
| GetUsersV2 | ASPM |
| List users | |
| GetVersionedObject | Custom Storage |
| Get the bytes for the specified object | |
| GetVersionedObjectMetadata | Custom Storage |
| Get the metadata for the specified object | |
| GetVulnerabilities | Intel |
| Get vulnerabilities | |
| getVulnerabilities | Spotlight Vulnerabilities |
| Get details on vulnerabilities by providing one or more IDs | |
| GrantUserRoleIds | User Management |
| Deprecated : Please use POST /user-management/entities/user-role-actions/v1. | |
| GroupActionsV1Mixin0 | Profile Groups |
| Perform actions on profile groups (add/remove roles, user groups, FGA objects) | |
| GroupContainersByManaged | Kubernetes Protection |
| Group the containers by Managed | |
| GroupUsersActionsV1Mixin0 | Profile Groups |
| Add or remove users from profile groups | |
| HeadImageScanInventory | Falcon Container |
| Get headers for POST request for image scan inventory | |
| highVolumeQueryChanges | FileVantage |
| Returns 1 or more change ids | |
| HostMigrationAggregatesV1 | Host Migration |
| Get host migration aggregates as specified via json in request body. | |
| HostMigrationsActionsV1 | Host Migration |
| Perform an action on host migrations. | |
| ImageMatchesPolicy | Falcon Container |
| After an image scan, use this operation to see if any images match a policy. | |
| incrementUninstallToken | Sensor Update Policy |
| Increments a bulk maintenance token. | |
| indicator.aggregate.v1 | IOC |
| Get Indicators aggregates as specified via json in the request body. | |
| indicator.combined.v1 | IOC |
| Get Combined for Indicators. | |
| indicator.create.v1 | IOC |
| Create Indicators. | |
| indicator.delete.v1 | IOC |
| Delete Indicators by ids. | |
| indicator.get.device_count.v1 | IOC |
| Get the number of devices the indicator has run on | |
| indicator.get.devices_ran_on.v1 | IOC |
| Get the IDs of devices the indicator has run on | |
| indicator.get.processes_ran_on.v1 | IOC |
| Get the number of processes the indicator has run on | |
| indicator.get.v1 | IOC |
| Get Indicators by ids. | |
| indicator.sdmf-query.v1 | IOC |
| Executes an SDMF data frame query against IOC indicators | |
| indicator.search.v1 | IOC |
| Search for Indicators. | |
| indicator.update.v1 | IOC |
| Update Indicators. | |
| IngestDataAsyncV1 | Foundry LogScale |
| Asynchronously ingest data into the application repository | |
| IngestDataV1 | Foundry LogScale |
| Synchronously ingest data into the application repository | |
| InstallParser | NGSIEM |
| Installs a CrowdStrike-managed out-of-the-box (OOTB) parser into the customer’s repository. | |
| IntegrationBuilderEndTransactionV3 | SaaS Security |
| POST Data Upload Transaction Completion | |
| IntegrationBuilderGetStatusV3 | SaaS Security |
| GET Status | |
| IntegrationBuilderResetV3 | SaaS Security |
| Reset | |
| IntegrationBuilderUploadV3 | SaaS Security |
| POST Upload | |
| ioc_type.query.v1 | IOC |
| Query IOC Types. | |
| ITAutomationCancelTaskExecution | IT Automation |
| Cancel a task execution specified in the request | |
| ITAutomationCombinedScheduledTasks | IT Automation |
| Returns full details of scheduled tasks matching the filter query parameter. | |
| ITAutomationCreatePolicy | IT Automation |
| Creates a new policy of the specified type. | |
| ITAutomationCreateScheduledTask | IT Automation |
| Creates a scheduled task from the given request | |
| ITAutomationCreateTask | IT Automation |
| Creates a task with details from the given request. | |
| ITAutomationCreateTaskGroup | IT Automation |
| Creates a task group from the given request | |
| ITAutomationCreateUserGroup | IT Automation |
| Creates a user group from the given request | |
| ITAutomationDeletePolicy | IT Automation |
| Deletes 1 or more policies. | |
| ITAutomationDeleteScheduledTasks | IT Automation |
| Delete one or more scheduled tasks by providing the scheduled tasks IDs | |
| ITAutomationDeleteTask | IT Automation |
| Deletes tasks for each provided ID | |
| ITAutomationDeleteTaskGroups | IT Automation |
| Delete one or more task groups by providing the task group IDs | |
| ITAutomationDeleteUserGroup | IT Automation |
| Deletes user groups for each provided ids | |
| ITAutomationGetAssociatedTasks | IT Automation |
| Retrieve tasks associated with the provided file id | |
| ITAutomationGetExecutionResults | IT Automation |
| Get the task execution results from an async search. | |
| ITAutomationGetExecutionResultsSearchStatus | IT Automation |
| Get the status of an async task execution results. | |
| ITAutomationGetPolicies | IT Automation |
| Retrieves the configuration for 1 or more policies. | |
| ITAutomationGetScheduledTasks | IT Automation |
| Returns scheduled tasks for each provided id | |
| ITAutomationGetTaskExecution | IT Automation |
| Get the task execution for the provided task execution IDs | |
| ITAutomationGetTaskExecutionHostStatus | IT Automation |
| Get the status of host executions by providing the execution IDs | |
| ITAutomationGetTaskExecutionsByQuery | IT Automation |
| Returns the list of task executions (and their details) matching the filter query parameter. | |
| ITAutomationGetTaskGroups | IT Automation |
| Returns task groups for each provided id | |
| ITAutomationGetTaskGroupsByQuery | IT Automation |
| Returns full details of task groups matching the filter query parameter. | |
| ITAutomationGetTasks | IT Automation |
| Returns tasks for each provided ID | |
| ITAutomationGetTasksByQuery | IT Automation |
| Returns full details of tasks matching the filter query parameter. | |
| ITAutomationGetUserGroup | IT Automation |
| Returns user groups for each provided id | |
| ITAutomationQueryPolicies | IT Automation |
| Returns the list of policy ids matching the filter query parameter. | |
| ITAutomationRerunTaskExecution | IT Automation |
| Rerun the task execution specified in the request | |
| ITAutomationRunLiveQuery | IT Automation |
| Starts a new task execution from the provided query data in the request and returns the initiated task executions | |
| ITAutomationSearchScheduledTasks | IT Automation |
| Returns the list of scheduled task IDs matching the filter query parameter | |
| ITAutomationSearchTaskExecutions | IT Automation |
| Returns the list of task execution IDs matching the filter query parameter. | |
| ITAutomationSearchTaskGroups | IT Automation |
| Returns the list of task group ids matching the filter query parameter | |
| ITAutomationSearchTasks | IT Automation |
| Returns the list of task IDs matching the filter query parameter. | |
| ITAutomationSearchUserGroup | IT Automation |
| Returns the list of user group ids matching the filter query parameter. | |
| ITAutomationStartExecutionResultsSearch | IT Automation |
| Starts an async task execution results search. | |
| ITAutomationStartTaskExecution | IT Automation |
| Starts a new task execution from an existing task provided in the request and returns the initiated task executions | |
| ITAutomationUpdatePolicies | IT Automation |
| Updates a new policy of the specified type. | |
| ITAutomationUpdatePoliciesPrecedence | IT Automation |
| Updates the policy precedence for all policies of a specific platform. | |
| ITAutomationUpdatePolicyHostGroups | IT Automation |
| Manage host groups assigned to a policy. | |
| ITAutomationUpdateScheduledTask | IT Automation |
| Update an existing scheduled task with the supplied info | |
| ITAutomationUpdateTask | IT Automation |
| Update a task with details from the given request. | |
| ITAutomationUpdateTaskGroup | IT Automation |
| Update a task group for a given id | |
| ITAutomationUpdateUserGroup | IT Automation |
| Update a user group for a given id | |
| LaunchExportJob | Falcon Container |
| Launch an export job of a Container Security resource. | |
| LaunchExportJobMixin0 | Serverless Exports |
| Launch an export job of a Lambda Security resource. | |
| LaunchScan | Quick Scan Pro |
| Starts scanning a file uploaded through ‘/quickscanpro/entities/files/v1’. | |
| ListAccessScopesExternal | Access Scopes |
| List Access Scopes By ID | |
| listAvailableStreamsOAuth2 | Event Streams |
| Discover all event streams in your environment | |
| ListAzureAccounts | Kubernetes Protection |
| Provides the azure subscriptions registered to Kubernetes Protection | |
| ListCloudGroupIDsExternal | Cloud Security |
| Query Cloud Groups and returns IDs | |
| ListCloudGroupsByIDExternal | Cloud Security |
| List Cloud Groups By ID | |
| ListCloudGroupsExternal | Cloud Security |
| Query Cloud Groups and returns entities | |
| ListCollections | Custom Storage |
| List available collection names in alphabetical order | |
| ListDashboards | NGSIEM |
| List Dashboards in NGSIEM with Pagination and Filtering. | |
| ListFeedTypes | Intelligence Feeds |
| Lists the accessible feed types for a given customer | |
| ListLookupFiles | NGSIEM |
| List Lookup Files in NGSIEM with Pagination and Filtering. | |
| ListObjects | Custom Storage |
| List the object keys in the specified collection in alphabetical order | |
| ListObjectsByVersion | Custom Storage |
| List the object keys in the specified collection in alphabetical order | |
| ListParsers | NGSIEM |
| List Parsers in NGSIEM | |
| ListReposV1 | Foundry LogScale |
| Lists available repositories | |
| ListSavedQueries | NGSIEM |
| List Saved Queries in NGSIEM with Pagination and Filtering. | |
| ListSchemas | Custom Storage |
| Get the list of schemas for the requested collection in reverse version order (latest first) | |
| ListViewV1 | Foundry LogScale |
| List available views | |
| LookupIndicators | Intelligence Indicator Graph |
| Get indicators based on their value. | |
| MigrationAggregatesV1 | Host Migration |
| Get migration aggregates as specified via json in request body. | |
| MigrationsActionsV1 | Host Migration |
| Perform an action on a migration job. | |
| oauth2AccessToken | OAuth2 |
| Generate an OAuth2 access token | |
| oauth2RevokeToken | OAuth2 |
| Revoke a previously issued OAuth2 access token before the end of its standard 30-minute lifespan. | |
| patch-external-assets | Exposure Management |
| Update the details of external assets. | |
| PatchAzureServicePrincipal | Kubernetes Protection |
| Adds the client ID for the given tenant ID to our system | |
| PatchCSPMAwsAccount | CSPM Registration |
| Patches a existing account in our system for a customer. | |
| patchDeviceControlPoliciesClassesV1 | Device Control Policies |
| Update device control policy’s classes (USB and Bluetooth) | |
| patchDeviceControlPoliciesV2 | Device Control Policies |
| Update device control policy base (USB and Bluetooth) | |
| PatchEntitiesAlertsV1 | Alerts |
| Perform actions on detections identified by detection ID(s) in request. | |
| PatchEntitiesAlertsV2 | Alerts |
| Deprecated: Please use version v3 of this endpoint. | |
| PatchEntitiesAlertsV3 | Alerts |
| Perform actions on Alerts identified by composite ID(s) in request. | |
| PatchFederatedConnectionsConfig | Federated Connections |
| Update configuration for a federated connection | |
| PerformActionV2 | Hosts |
| Take various actions on the hosts in your environment. | |
| performContentUpdatePoliciesAction | Content Update Policies |
| Perform the specified action on the Content Update Policies specified in the request | |
| performDeviceControlPoliciesAction | Device Control Policies |
| Perform the specified action on the Device Control Policies specified in the request | |
| performFirewallPoliciesAction | Firewall Policies |
| Perform the specified action on the Firewall Policies specified in the request | |
| performGroupAction | Host Group |
| Perform the specified action on the Host Groups specified in the request | |
| performPreventionPoliciesAction | Prevention Policies |
| Perform the specified action on the Prevention Policies specified in the request | |
| performRTResponsePoliciesAction | Response Policies |
| Perform the specified action on the Response Policies specified in the request | |
| performSensorUpdatePoliciesAction | Sensor Update Policy |
| Perform the specified action on the Sensor Update Policies specified in the request | |
| platform.query.v1 | IOC |
| Query Platforms. | |
| PolicyChecks | Falcon Container |
| Check image prevention policies | |
| post-external-assets-inventory-v1 | Exposure Management |
| Add external assets for external asset scanning. | |
| post_policy_rules | Identity Protection |
| Create policy rule | |
| post_policy_rules | Identity Protection |
| Create policy rule | |
| PostAggregatesAlertsV1 | Alerts |
| Deprecated: Please use version v2 of this endpoint. | |
| PostAggregatesAlertsV2 | Alerts |
| Retrieves aggregate values for Alerts across all CIDs. | |
| PostAggregatesPods | Kubernetes Protection |
| Get aggregate query result for pods | |
| PostCombinedAlertsV1 | Alerts |
| Retrieves all Alerts that match a particular FQL filter. | |
| PostDeliverySettings | Delivery Settings |
| Create Delivery Settings | |
| postDeviceControlPoliciesV2 | Device Control Policies |
| Create/clone a device control policy (USB and Bluetooth) | |
| PostDeviceDetailsV2 | Hosts |
| Get details on one or more hosts by providing host IDs in a POST body. | |
| PostEntitiesAlertsV1 | Alerts |
| Deprecated: please use version v2 of this endpoint. | |
| PostEntitiesAlertsV2 | Alerts |
| Retrieves all Alerts given their composite ids. | |
| PostFederatedConnectionsConfig | Federated Connections |
| Create configuration for a federated connection | |
| PostGroupV2 | ASPM |
| Create group | |
| PostImageScanInventory | Falcon Container |
| Post image scan inventory | |
| PostMalQueryEntitiesSamplesMultidownloadV1 | MalQuery |
| Schedule samples for download. | |
| PostMalQueryExactSearchV1 | MalQuery |
| Search Falcon MalQuery for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity. | |
| PostMalQueryFuzzySearchV1 | MalQuery |
| Search Falcon MalQuery quickly, but with more potential for false positives. | |
| PostMalQueryHuntV1 | MalQuery |
| Schedule a YARA-based search for execution. | |
| PostMitreAttacks | Intel |
| Retrieves report and observable IDs associated with the given actor and attacks | |
| PostSearchKubernetesIOMEntities | Kubernetes Protection |
| Search for Kubernetes IOMs with filtering options.Pagination is supported via Elasticsearch’s search_after search param and point in time. | |
| PreviewRuleV1 | Recon |
| Preview rules notification count and distribution. | |
| ProcessesRanOn | IOCs |
| Search for processes associated with a custom IOC | |
| ProvisionAWSAccounts | Cloud Connect AWS |
| Provision AWS Accounts by specifying details about the accounts to provision | |
| PutObject | Custom Storage |
| Put the specified new object at the given key or overwrite an existing object at the given key | |
| PutObjectByVersion | Custom Storage |
| Put the specified new object at the given key or overwrite an existing object at the given key | |
| queries.access-tags.get.v1 | Case Management |
| Query access tags | |
| queries.cases.get.v1 | Case Management |
| Retrieves all Cases IDs that match a given query. | |
| queries.classification.get.v2 | Data Protection Configuration |
| Search for classifications that match the provided criteria | |
| queries.cloud-application.get-v2 | Data Protection Configuration |
| Get all cloud-application IDs matching the query with filter | |
| queries.content-pattern.get-v2 | Data Protection Configuration |
| Get all content-pattern IDs matching the query with filter | |
| queries.enterprise-account.get-v2 | Data Protection Configuration |
| Get all enterprise-account IDs matching the query with filter | |
| queries.fields.get.v1 | Case Management |
| Query fields | |
| queries.file-details.get.v1 | Case Management |
| Query for ids of file details | |
| queries.file-type.get-v2 | Data Protection Configuration |
| Get all file-type IDs matching the query with filter | |
| queries.local-application-group.get | Data Protection Configuration |
| Get all local application group IDs matching the query with filter | |
| queries.local-application.get | Data Protection Configuration |
| Get all local-application IDs matching the query with filter | |
| queries.notification-groups.get.v1 | Case Management |
| Query notification groups | |
| queries.notification-groups.get.v2 | Case Management |
| Query notification groups | |
| queries.policy.get.v2 | Data Protection Configuration |
| Search for policies that match the provided criteria | |
| queries.rules.get.v1 | Correlation Rules |
| Find all rule IDs matching the query and filter. | |
| queries.rules.get.v2 | Correlation Rules |
| Find all rule version IDs matching the query and filter. | |
| queries.sensitivity-label.get-v2 | Data Protection Configuration |
| Get all sensitivity label IDs matching the query with filter | |
| queries.slas.get.v1 | Case Management |
| Query SLAs | |
| queries.states.v1 | Device Content |
| Query for the content state of the host. | |
| queries.template-snapshots.get.v1 | Case Management |
| Query template snapshots | |
| queries.templates.get.v1 | Case Management |
| Query templates | |
| queries.templates.get.v1Mixin0 | Correlation Rules |
| Search rule template IDs matching the filter. | |
| queries.web-location-group.get | Data Protection Configuration |
| Get all web location group IDs matching the query with filter | |
| queries.web-location.get-v2 | Data Protection Configuration |
| Get web-location IDs matching the query with filter | |
| queries_edgetypes_get | ThreatGraph |
| Show all available edge types | |
| QueriesAgentTemplatesV1 | Agent Templates |
| Query agent template IDs with pagination | |
| QueriesKnowledgeBaseAuditEventsV1 | Knowledge Base Audit Events |
| Query knowledge base audit event IDs with pagination and filtering. | |
| QueriesKnowledgeBaseFilesV1 | Knowledge Base Files |
| Query knowledge base files based on the provided filters. | |
| QueriesKnowledgeBasesV1 | Knowledge Bases |
| Query knowledge bases based on the provided filters. | |
| QueriesModelsV1 | Models |
| Query models based on the provided filters. | |
| queriesRolesV1 | User Management |
| Show role IDs for all roles available in your customer account. | |
| QueriesSpansV1 | Spans |
| Query spans based on the provided filters. | |
| QueriesToolsV1 | Tools |
| Query tools based on the provided filters. | |
| query-accounts | Discover |
| Search for accounts in your environment by providing an FQL (Falcon Query Language) filter and paging details. | |
| query-applications | Discover |
| Search for applications in your environment by providing an FQL filter and paging details. returns a set of application IDs which match the filter criteria. | |
| query-ecosystem-subsidiaries | Exposure Management |
| Retrieves a list of IDs for ecosystem subsidiaries. | |
| query-events | Firewall Management |
| Find all event IDs matching the query with filter | |
| query-external-assets | Exposure Management |
| Get a list of external asset IDs that match the provided filter conditions. | |
| query-external-assets-v2 | Exposure Management |
| Get a list of external asset IDs that match the provided filter conditions. | |
| query-firewall-fields | Firewall Management |
| Get the firewall field specification IDs for the provided platform | |
| query-hosts | Discover |
| Search for assets in your environment by providing an FQL (Falcon Query Language) filter and paging details. | |
| query-iot-hosts | Discover |
| Search for IoT assets in your environment by providing an FQL (Falcon Query Language) filter and paging details. | |
| query-iot-hostsV2 | Discover |
| Search for IoT assets in your environment by providing an FQL (Falcon Query Language) filter and paging details. | |
| query-logins | Discover |
| Search for logins in your environment by providing an FQL (Falcon Query Language) filter and paging details. | |
| query-malicious-files | ODS (On Demand Scan) |
| Query malicious files. | |
| query-network-locations | Firewall Management |
| Get a list of network location IDs | |
| query-networks | Network Scan Networks |
| Get “networks IDs” by filter | |
| query-patterns | Custom IOA |
| Get all pattern severity IDs. | |
| query-platforms | Firewall Management |
| Get the list of platform names | |
| query-platformsMixin0 | Custom IOA |
| Get all platform IDs. | |
| query-policy-rules | Firewall Management |
| Find all firewall rule IDs matching the query with filter, and return them in precedence order | |
| query-rule-groups | Firewall Management |
| Find all rule group IDs matching the query with filter | |
| query-rule-groups-full | Custom IOA |
| Find all rule groups matching the query with optional filter. | |
| query-rule-groupsMixin0 | Custom IOA |
| Finds all rule group IDs matching the query with optional filter. | |
| query-rule-types | Custom IOA |
| Get all rule type IDs. | |
| query-rules | Firewall Management |
| Find all rule IDs matching the query with filter | |
| query-rulesMixin0 | Custom IOA |
| Finds all rule IDs matching the query with optional filter. | |
| query-scan-host-metadata | ODS (On Demand Scan) |
| Query scan hosts. | |
| query-scan-runs | Network Scan Scan Runs |
| Get “scan-runs IDs” by filter | |
| query-scanners | Network Scan Scanners |
| Get “scanners IDs” by filter | |
| query-scans | ODS (On Demand Scan) |
| Query Scans. | |
| query-scansMixin0 | Network Scan Scans |
| Get “scans IDs” by filter | |
| query-scheduled-scans | ODS (On Demand Scan) |
| Query ScheduledScans. | |
| query-templates | Network Scan Templates |
| Get “templates IDs” by filter | |
| query-zones | Network Scan Zones |
| Get “zones IDs” by filter | |
| QueryAccessScopesExternal | Access Scopes |
| Query Access Scopes and returns IDs | |
| queryActionsMixin0 | FileVantage |
| Returns one or more action ids | |
| QueryActionsV1 | Recon |
| Query actions based on provided criteria. | |
| QueryActivityByCaseID | Message Center |
| Retrieve activities id’s for a case | |
| QueryAgentVersionsV1 | Agent Versions |
| Query agent versions based on the provided filters. | |
| QueryAlertIdsByFilter | Falcon Complete Dashboard |
| Retrieve Alerts Ids for epp that match the provided FQL filter criteria with scrolling enabled | |
| QueryAlertIdsByFilterV2 | Falcon Complete Dashboard |
| Retrieve Alerts Ids for epp, idp and ngsiem that match the provided FQL filter criteria with scrolling enabled | |
| QueryAllowListFilter | Falcon Complete Dashboard |
| Retrieve allowlist tickets that match the provided filter criteria with scrolling enabled | |
| QueryAWSAccounts | Cloud Connect AWS |
| Search for provisioned AWS Accounts by providing an FQL filter and paging details. | |
| QueryAWSAccountsForIDs | Cloud Connect AWS |
| Search for provisioned AWS Accounts by providing an FQL filter and paging details. | |
| QueryBlockListFilter | Falcon Complete Dashboard |
| Retrieve block listtickets that match the provided filter criteria with scrolling enabled | |
| QueryCasesIdsByFilter | Message Center |
| Retrieve case id’s that match the provided filter criteria | |
| queryChanges | FileVantage |
| Returns 1 or more change ids | |
| queryChildren | MSSP (Flight Control) |
| Query for customers linked as children | |
| queryCIDGroupMembers | MSSP (Flight Control) |
| Query a CID groups members by associated CID. | |
| queryCIDGroups | MSSP (Flight Control) |
| Query CID groups. | |
| queryCombinedContentUpdatePolicies | Content Update Policies |
| Search for Content Update Policies in your environment by providing an FQL filter and paging details. | |
| queryCombinedContentUpdatePolicyMembers | Content Update Policies |
| Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. | |
| queryCombinedDeviceControlPolicies | Device Control Policies |
| Search for Device Control Policies in your environment by providing an FQL filter and paging details. | |
| queryCombinedDeviceControlPolicyMembers | Device Control Policies |
| Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. | |
| queryCombinedFirewallPolicies | Firewall Policies |
| Search for Firewall Policies in your environment by providing an FQL filter and paging details. | |
| queryCombinedFirewallPolicyMembers | Firewall Policies |
| Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. | |
| queryCombinedGroupMembers | Host Group |
| Search for members of a Host Group in your environment by providing an FQL filter and paging details. | |
| queryCombinedHostGroups | Host Group |
| Search for Host Groups in your environment by providing an FQL filter and paging details. | |
| queryCombinedPreventionPolicies | Prevention Policies |
| Search for Prevention Policies in your environment by providing an FQL filter and paging details. | |
| queryCombinedPreventionPolicyMembers | Prevention Policies |
| Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. | |
| queryCombinedRTResponsePolicies | Response Policies |
| Search for Response Policies in your environment by providing an FQL filter and paging details. | |
| queryCombinedRTResponsePolicyMembers | Response Policies |
| Search for members of a Response policy in your environment by providing an FQL filter and paging details. | |
| queryCombinedSensorUpdateBuilds | Sensor Update Policy |
| Retrieve available builds for use with Sensor Update Policies | |
| queryCombinedSensorUpdateKernels | Sensor Update Policy |
| Retrieve kernel compatibility info for Sensor Update Builds | |
| queryCombinedSensorUpdatePolicies | Sensor Update Policy |
| Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. | |
| queryCombinedSensorUpdatePoliciesV2 | Sensor Update Policy |
| Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details. | |
| queryCombinedSensorUpdatePolicyMembers | Sensor Update Policy |
| Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. | |
| QueryComplianceControls | Cloud Policies |
| Query for compliance controls by various parameters | |
| QueryComplianceFrameworks | Cloud Policies |
| Query for compliance frameworks by various parameters | |
| queryContentUpdatePolicies | Content Update Policies |
| Search for Content Update Policies in your environment by providing an FQL filter and paging details. | |
| queryContentUpdatePolicyMembers | Content Update Policies |
| Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. | |
| QueryDetects | Detects |
| Deprecated: This endpoint will be decommissioned on September 30, 2025. | |
| queryDeviceControlPolicies | Device Control Policies |
| Search for Device Control Policies in your environment by providing an FQL filter and paging details. | |
| queryDeviceControlPolicyMembers | Device Control Policies |
| Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. | |
| QueryDeviceLoginHistory | Hosts |
| Retrieve details about recent login sessions for a set of devices. | |
| QueryDeviceLoginHistoryV2 | Hosts |
| Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline. | |
| QueryDevicesByFilter | Hosts |
| Search for hosts in your environment by platform, hostname, IP, and other criteria. | |
| QueryDevicesByFilterScroll | Hosts |
| Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit) | |
| QueryEscalationsFilter | Falcon Complete Dashboard |
| Retrieve escalation tickets that match the provided filter criteria with scrolling enabled | |
| queryEvaluationLogic | Spotlight Evaluation Logic |
| Search for evaluation logic in your environment by providing a FQL filter and paging details. | |
| QueryEvents | Tailored Intelligence |
| Get events ids that match the provided filter criteria. | |
| QueryExportJobs | Falcon Container |
| Query export jobs entities | |
| QueryExportJobsMixin0 | Serverless Exports |
| Query export jobs entities | |
| QueryFeedArchives | Intelligence Feeds |
| Queries the accessible feed types for a customer. | |
| queryFirewallPolicies | Firewall Policies |
| Search for Firewall Policies in your environment by providing an FQL filter and paging details. | |
| queryFirewallPolicyMembers | Firewall Policies |
| Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. | |
| QueryGetNetworkAddressHistoryV1 | Hosts |
| Retrieve history of IP and MAC addresses of devices. | |
| queryGroupMembers | Host Group |
| Search for members of a Host Group in your environment by providing an FQL filter and paging details. | |
| QueryGroupsV1Mixin0 | Profile Groups |
| Query profile group IDs with FQL filtering, pagination, and sorting | |
| QueryHiddenDevices | Hosts |
| Retrieve hidden hosts that match the provided filter criteria. | |
| queryHostGroups | Host Group |
| Search for Host Groups in your environment by providing an FQL filter and paging details. | |
| QueryIntelActorEntities | Intel |
| Get info about actors that match provided FQL filters. | |
| QueryIntelActorIds | Intel |
| Get actor IDs that match provided FQL filters. | |
| QueryIntelIndicatorEntities | Intel |
| Get info about indicators that match provided FQL filters. | |
| QueryIntelIndicatorIds | Intel |
| Get indicators IDs that match provided FQL filters. | |
| QueryIntelReportEntities | Intel |
| Get info about reports that match provided FQL filters. | |
| QueryIntelReportIds | Intel |
| Get report IDs that match provided FQL filters. | |
| QueryIntelRuleIds | Intel |
| Search for rule IDs that match provided filter criteria. | |
| queryIOAExclusionsV1 | IOA Exclusions |
| Search for IOA exclusions. | |
| QueryIOCs | IOCs |
| Search the custom IOCs in your customer account. *** Deprecated - Use the new IOC Management endpoint (GET /iocs/queries/indicators/v1). *** | |
| QueryMalware | Intel |
| Get malware family names that match provided FQL filters. | |
| QueryMalwareEntities | Intel |
| Get malware entities that match provided FQL filters. | |
| QueryMitreAttacks | Intel |
| Gets MITRE tactics and techniques for the given actor, returning concatenation of id and tactic and technique ids, example: fancy-bear_TA0011_T1071 | |
| QueryMitreAttacksForMalware | Intel |
| Gets MITRE tactics and techniques for the given malware | |
| queryMLExclusionsV1 | ML Exclusions |
| Search for ML exclusions. | |
| QueryNotificationsExposedDataRecordsV1 | Recon |
| Query notifications exposed data records based on provided criteria. | |
| QueryNotificationsV1 | Recon |
| Query notifications based on provided criteria. | |
| queryPinnableContentVersions | Content Update Policies |
| Search for content versions available for pinning given the category. | |
| queryPolicies | FileVantage |
| Retrieve the ids of all policies that are assigned the provided policy type. | |
| queryPreventionPolicies | Prevention Policies |
| Search for Prevention Policies in your environment by providing an FQL filter and paging details. | |
| queryPreventionPolicyMembers | Prevention Policies |
| Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. | |
| QueryQuarantineFiles | Quarantine |
| Get quarantine file ids that match the provided filter criteria. | |
| QueryReleaseNotesV1 | Deployments |
| Queries for release-notes resources and returns ids | |
| QueryRemediationsFilter | Falcon Complete Dashboard |
| Retrieve remediation tickets that match the provided filter criteria with scrolling enabled | |
| QueryReports | Falconx Sandbox |
| Find sandbox reports by providing an FQL filter and paging details. | |
| queryRoles | MSSP (Flight Control) |
| Query links between user groups and CID groups. | |
| queryRTResponsePolicies | Response Policies |
| Search for Response Policies in your environment by providing an FQL filter with sort and/or paging details. | |
| queryRTResponsePolicyMembers | Response Policies |
| Search for members of a Response policy in your environment by providing an FQL filter and paging details. | |
| QueryRule | Cloud Policies |
| Query for rules by various parameters | |
| queryRuleGroups | FileVantage |
| Retrieve the ids of all rule groups that are of the provided rule group type. | |
| QueryRules | Tailored Intelligence |
| Get rules ids that match the provided filter criteria. | |
| QueryRulesV1 | Recon |
| Query monitoring rules based on provided criteria. | |
| QuerySampleV1 | Falconx Sandbox |
| Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200 | |
| QueryScanResults | Quick Scan Pro |
| FQL query specifying the filter parameters | |
| queryScheduledExclusions | FileVantage |
| Retrieve the ids of all scheduled exclusions contained within the provided policy id. | |
| QuerySensorsByFilter | Identity Protection |
| Search for sensors in your environment by hostname, IP, and other criteria. | |
| querySensorUpdateKernelsDistinct | Sensor Update Policy |
| Retrieve kernel compatibility info for Sensor Update Builds | |
| querySensorUpdatePolicies | Sensor Update Policy |
| Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. | |
| querySensorUpdatePolicyMembers | Sensor Update Policy |
| Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. | |
| querySensorVisibilityExclusionsV1 | Sensor Visibility Exclusions |
| Search for sensor visibility exclusions. | |
| QuerySubmissions | Falconx Sandbox |
| Find submission IDs for uploaded files by providing an FQL filter and paging details. | |
| QuerySubmissionsMixin0 | Quick Scan |
| Find IDs for submitted scans by providing an FQL filter and paging details. | |
| QuerySuppressionRules | Cloud Policies |
| Query suppression rules with filtering, sorting and pagination | |
| QueryThirdPartyPasskeyRegistry | Falcon ID |
| Query third party passkey registries | |
| queryUserGroupMembers | MSSP (Flight Control) |
| Query user group member by user UUID. | |
| queryUserGroups | MSSP (Flight Control) |
| Query user groups. | |
| queryUserV1 | User Management |
| List user IDs for all users in your customer account. | |
| QueryVulnerabilities | Intel |
| Get vulnerabilities IDs | |
| queryVulnerabilities | Spotlight Vulnerabilities |
| Search for Vulnerabilities in your environment by providing an FQL filter and paging details. | |
| ReadClusterCombined | Kubernetes Protection |
| Retrieve kubernetes clusters identified by the provided filter criteria | |
| ReadClusterCombinedV2 | Kubernetes Protection |
| Retrieve Kubernetes cluster data | |
| ReadClusterCount | Kubernetes Protection |
| Retrieve cluster counts | |
| ReadClusterEnrichment | Kubernetes Protection |
| Retrieve cluster enrichment data | |
| ReadClustersByDateRangeCount | Kubernetes Protection |
| Retrieve clusters by date range counts | |
| ReadClustersByKubernetesVersionCount | Kubernetes Protection |
| Bucket clusters by kubernetes version | |
| ReadClustersByStatusCount | Kubernetes Protection |
| Bucket clusters by status | |
| ReadCombinedDetections | Container Detections |
| Retrieve image assessment detections identified by the provided filter criteria | |
| ReadCombinedImagesExport | Container Images |
| Retrieves a paginated list of images, with an option to expand aggregated vulnerabilities/detections. | |
| ReadCombinedVulnerabilities | Container Vulnerabilities |
| Retrieves a paginated list of vulnerabilities filtered by the provided FQL. | |
| ReadCombinedVulnerabilitiesDetails | Container Vulnerabilities |
| Retrieve vulnerability details related to an image | |
| ReadCombinedVulnerabilitiesInfo | Container Vulnerabilities |
| Retrieve vulnerability and package related info for this customer | |
| ReadContainerAlertsCount | Container Alerts |
| Search Container Alerts by the provided search criteria | |
| ReadContainerAlertsCountBySeverity | Container Alerts |
| Get Container Alerts counts by severity | |
| ReadContainerCombined | Kubernetes Protection |
| Retrieves a paginated list of containers identified by the provided filter criteria. | |
| ReadContainerCount | Kubernetes Protection |
| Retrieve container counts | |
| ReadContainerCountByRegistry | Kubernetes Protection |
| Retrieves a list with the top container image registries. | |
| ReadContainerEnrichment | Kubernetes Protection |
| Retrieve container enrichment data | |
| ReadContainerImageDetectionsCountByDate | Kubernetes Protection |
| Retrieve count of image assessment detections on running containers over a period of time | |
| ReadContainerImagesByMostUsed | Kubernetes Protection |
| Bucket container by image-digest | |
| ReadContainerImagesByState | Kubernetes Protection |
| Retrieve count of image states running on containers | |
| ReadContainersByDateRangeCount | Kubernetes Protection |
| Retrieve containers by date range counts | |
| ReadContainersSensorCoverage | Kubernetes Protection |
| Bucket containers by agent type and calculate sensor coverage | |
| ReadContainerVulnerabilitiesBySeverityCount | Kubernetes Protection |
| Retrieve container vulnerabilities by severity counts | |
| ReadDeploymentCombined | Kubernetes Protection |
| Retrieve kubernetes deployments identified by the provided filter criteria | |
| ReadDeploymentCount | Kubernetes Protection |
| Retrieve deployment counts | |
| ReadDeploymentEnrichment | Kubernetes Protection |
| Retrieve deployment enrichment data | |
| ReadDeploymentsByDateRangeCount | Kubernetes Protection |
| Retrieve deployments by date range counts | |
| ReadDeploymentsCombined | Cloud Snapshots |
| Retrieve snapshot jobs identified by the provided IDs | |
| ReadDeploymentsEntities | Cloud Snapshots |
| Retrieve snapshot jobs identified by the provided IDs | |
| ReadDetections | Container Detections |
| Retrieve image assessment detection entities identified by the provided filter criteria | |
| ReadDetectionsCount | Container Detections |
| Aggregate count of detections | |
| ReadDetectionsCountBySeverity | Container Detections |
| Aggregate counts of detections by severity | |
| ReadDetectionsCountByType | Container Detections |
| Aggregate counts of detections by detection type | |
| ReadDistinctContainerImageCount | Kubernetes Protection |
| Retrieve count of distinct images running on containers | |
| ReadDriftIndicatorEntities | Drift Indicators |
| Retrieve Drift Indicator entities identified by the provided IDs | |
| ReadDriftIndicatorsCount | Drift Indicators |
| Returns the total count of Drift indicators over a time period | |
| ReadExportJobs | Falcon Container |
| Read export jobs entities | |
| ReadExportJobsMixin0 | Serverless Exports |
| Read export jobs entities | |
| ReadImageVulnerabilities | Falcon Container |
| Retrieve known vulnerabilities for the provided image | |
| ReadKubernetesIomByDateRange | Kubernetes Protection |
| Returns the count of Kubernetes IOMs by the date. by default it’s for 7 days. | |
| ReadKubernetesIomCount | Kubernetes Protection |
| Returns the total count of Kubernetes IOMs over the past seven days | |
| ReadKubernetesIomEntities | Kubernetes Protection |
| Retrieve Kubernetes IOM entities identified by the provided IDs | |
| ReadNamespaceCount | Kubernetes Protection |
| Retrieve namespace counts | |
| ReadNamespacesByDateRangeCount | Kubernetes Protection |
| Retrieve namespaces by date range counts | |
| ReadNodeCombined | Kubernetes Protection |
| Retrieve kubernetes nodes identified by the provided filter criteria | |
| ReadNodeCount | Kubernetes Protection |
| Retrieve node counts | |
| ReadNodeEnrichment | Kubernetes Protection |
| Retrieve node enrichment data | |
| ReadNodesByCloudCount | Kubernetes Protection |
| Bucket nodes by cloud providers | |
| ReadNodesByContainerEngineVersionCount | Kubernetes Protection |
| Bucket nodes by their container engine version | |
| ReadNodesByDateRangeCount | Kubernetes Protection |
| Retrieve nodes by date range counts | |
| ReadPackagesByFixableVulnCount | Container Packages |
| Retrieve top x app packages with the most fixable vulnerabilities | |
| ReadPackagesByImageCount | Container Packages |
| Retrieves the N most frequently used packages across images | |
| ReadPackagesByVulnCount | Container Packages |
| Retrieve top x packages with the most vulnerabilities | |
| ReadPackagesCombined | Container Packages |
| Retrieve packages identified by the provided filter criteria | |
| ReadPackagesCombinedExport | Container Packages |
| Retrieves a paginated list of packages identified by the provided filter criteria,used for export.Maximum page size: 100. | |
| ReadPackagesCombinedV2 | Container Packages |
| Retrieve packages identified by the provided filter criteria | |
| ReadPackagesCountByZeroDay | Container Packages |
| Retrieve packages count affected by zero day vulnerabilities | |
| ReadPodCombined | Kubernetes Protection |
| Retrieve kubernetes pods identified by the provided filter criteria | |
| ReadPodCount | Kubernetes Protection |
| Retrieve pod counts | |
| ReadPodEnrichment | Kubernetes Protection |
| Retrieve pod enrichment data | |
| ReadPodsByDateRangeCount | Kubernetes Protection |
| Retrieve pods by date range counts | |
| ReadPolicies | Image Assessment Policies |
| Get all Image Assessment policies | |
| ReadPolicyExclusions | Image Assessment Policies |
| Retrieve Image Assessment Policy Exclusion entities | |
| ReadPolicyGroups | Image Assessment Policies |
| Retrieve Image Assessment Policy Group entities | |
| ReadRegistryEntities | Falcon Container |
| Retrieves a list of registry entities identified by the customer id. | |
| ReadRegistryEntitiesByUUID | Falcon Container |
| Retrieves a list of registry entities by the provided UUIDs. | |
| ReadRequestBody | FaaS Execution |
| retrieve a large request body, such as a file, that has spilled into object storage | |
| ReadRunningContainerImages | Kubernetes Protection |
| Retrieve images on running containers | |
| ReadUnidentifiedContainersByDateRangeCount | Unidentified Containers |
| Returns the count of Unidentified Containers over the last 7 days | |
| ReadUnidentifiedContainersCount | Unidentified Containers |
| Returns the total count of Unidentified Containers over a time period | |
| ReadVulnerabilitiesByImageCount | Container Vulnerabilities |
| Retrieve top x vulnerabilities with the most impacted images | |
| ReadVulnerabilitiesPublicationDate | Container Vulnerabilities |
| Retrieve top x vulnerabilities with the most recent publication date | |
| ReadVulnerabilityCount | Container Vulnerabilities |
| Aggregate count of vulnerabilities | |
| ReadVulnerabilityCountByActivelyExploited | Container Vulnerabilities |
| Aggregate count of vulnerabilities grouped by actively exploited | |
| ReadVulnerabilityCountByCPSRating | Container Vulnerabilities |
| Aggregate count of vulnerabilities grouped by csp_rating | |
| ReadVulnerabilityCountByCVSSScore | Container Vulnerabilities |
| Aggregate count of vulnerabilities grouped by CVSS score | |
| ReadVulnerabilityCountBySeverity | Container Vulnerabilities |
| Aggregate count of vulnerabilities grouped by severity | |
| ReadVulnerableContainerImageCount | Kubernetes Protection |
| Retrieve count of vulnerable images running on containers | |
| refreshActiveStreamSession | Event Streams |
| Refresh an active event stream. | |
| RegenerateAPIKey | Kubernetes Protection |
| Regenerate API key for docker registry integrations | |
| RegisterCspmSnapshotAccount | Cloud Snapshots |
| Register customer cloud account for snapshot scanning | |
| removeDashboardLabels | NGSIEM |
| Remove multiple labels from a single dashboard | |
| removeFileLabels | NGSIEM |
| Remove multiple labels from a single file | |
| removeSavedQueryLabels | NGSIEM |
| Remove multiple labels from a saved query | |
| RenameSectionComplianceFramework | Cloud Policies |
| Rename a section in a custom compliance framework | |
| ReplaceControlRules | Cloud Policies |
| Assign rules to a compliance control (full replace) | |
| report-executions-download.get | Report Executions |
| Get report entity download | |
| report-executions.get | Report Executions |
| Retrieve report details for the provided report IDs. | |
| report-executions.query | Report Executions |
| Find all report execution IDs matching the query with filter | |
| report-executions.retry | Report Executions |
| This endpoint will be used to retry report executions | |
| RequestDeviceEnrollmentV3 | Mobile Enrollment |
| Trigger on-boarding process for a mobile device | |
| RequestDeviceEnrollmentV4 | Mobile Enrollment |
| Trigger on-boarding process for a mobile device | |
| ResetAPIClientSecret | API Clients |
| Reset existing API Client(s)‘s secret based on API Client ID(s) provided as request parameter(s) ‘ids’. | |
| RetrieveEmailsByCID | User Management |
| Deprecated : Please use POST /user-management/entities/users/GET/v1. | |
| RetrieveRelayInstances | ASPM |
| Retrieve the relay instances in CSV format | |
| retrieveUser | User Management |
| Deprecated : Please use POST /user-management/entities/users/GET/v1. | |
| RetrieveUser | User Management |
| Deprecated : Please use retrieveUsersGETV1. | |
| retrieveUsersGETV1 | User Management |
| Get info about users including their name, UID and CID by providing user UUIDs | |
| RetrieveUserUUID | User Management |
| Deprecated : Please use GET /user-management/queries/users/v1. | |
| RetrieveUserUUIDsByCID | User Management |
| Deprecated : Please use GET /user-management/queries/users/v1. | |
| revealUninstallToken | Sensor Update Policy |
| Reveals an uninstall token for a specific device. | |
| RevokeUserRoleIds | User Management |
| Deprecated : Please use POST /user-management/entities/user-role-actions/v1. | |
| RTR-AggregateSessions | Real Time Response |
| Get aggregates on session data. | |
| RTR-CheckActiveResponderCommandStatus | Real Time Response |
| Get status of an executed active-responder command on a single host. | |
| RTR-CheckAdminCommandStatus | Real Time Response Admin |
| Get status of an executed RTR administrator command on a single host. | |
| RTR-CheckCommandStatus | Real Time Response |
| Get status of an executed command on a single host. | |
| RTR-CreatePut-Files | Real Time Response Admin |
| Upload a new put-file to use for the RTR put command. | |
| RTR-CreatePut-FilesV2 | Real Time Response Admin |
| Upload a new put-file to use for the RTR put command. | |
| RTR-CreateScripts | Real Time Response Admin |
| Upload a new custom-script to use for the RTR runscript command. | |
| RTR-CreateScriptsV2 | Real Time Response Admin |
| Upload a new custom-script to use for the RTR runscript command. | |
| RTR-DeleteFile | Real Time Response |
| Delete a RTR session file. | |
| RTR-DeleteFileV2 | Real Time Response |
| Delete a RTR session file. | |
| RTR-DeletePut-Files | Real Time Response Admin |
| Delete a put-file based on the ID given. | |
| RTR-DeleteQueuedSession | Real Time Response |
| Delete a queued session command | |
| RTR-DeleteScripts | Real Time Response Admin |
| Delete a custom-script based on the ID given. | |
| RTR-DeleteSession | Real Time Response |
| Delete a session. | |
| RTR-ExecuteActiveResponderCommand | Real Time Response |
| Execute an active responder command on a single host. | |
| RTR-ExecuteAdminCommand | Real Time Response Admin |
| Execute a RTR administrator command on a single host. | |
| RTR-ExecuteCommand | Real Time Response |
| Execute a command on a single host. | |
| RTR-GetExtractedFileContents | Real Time Response |
| Get RTR extracted file contents for specified session and sha256. | |
| RTR-GetFalconScripts | Real Time Response Admin |
| Get Falcon scripts with metadata and content of script | |
| RTR-GetPut-Files | Real Time Response Admin |
| Get put-files based on the ID’s given. | |
| RTR-GetPut-FilesV2 | Real Time Response Admin |
| Get put-files based on the ID’s given. | |
| RTR-GetPutFileContents | Real Time Response Admin |
| Get RTR put file contents for a given file ID | |
| RTR-GetScripts | Real Time Response Admin |
| Get custom-scripts based on the ID’s given. | |
| RTR-GetScriptsV2 | Real Time Response Admin |
| Get custom-scripts based on the ID’s given. | |
| RTR-InitSession | Real Time Response |
| Initialize a new session with the RTR cloud. | |
| RTR-ListAllSessions | Real Time Response |
| Get a list of session_ids. | |
| RTR-ListFalconScripts | Real Time Response Admin |
| Get a list of Falcon script IDs available to the user to run | |
| RTR-ListFiles | Real Time Response |
| Get a list of files for the specified RTR session. | |
| RTR-ListFilesV2 | Real Time Response |
| Get a list of files for the specified RTR session. | |
| RTR-ListPut-Files | Real Time Response Admin |
| Get a list of put-file ID’s that are available to the user for the put command. | |
| RTR-ListQueuedSessions | Real Time Response |
| Get queued session metadata by session ID. | |
| RTR-ListScripts | Real Time Response Admin |
| Get a list of custom-script ID’s that are available to the user for the runscript command. | |
| RTR-ListSessions | Real Time Response |
| Get session metadata by session id. | |
| RTR-PulseSession | Real Time Response |
| Refresh a session timeout on a single host. | |
| RTR-UpdateScripts | Real Time Response Admin |
| Upload a new scripts to replace an existing one. | |
| RTR-UpdateScriptsV2 | Real Time Response Admin |
| Upload a new scripts to replace an existing one. | |
| RTRAuditSessions | Real Time Response Audit |
| Get all the RTR sessions created for a customer in a specified duration | |
| RunIntegrationTask | ASPM |
| Run an integration task by its ID | |
| RunIntegrationTaskAdmin | ASPM |
| Run an integration task by its ID - for admin scope | |
| RunIntegrationTaskV2 | ASPM |
| Run an integration task by its ID | |
| scans-report | ODS (On Demand Scan) |
| Launch a scans report creation job | |
| ScanSamples | Quick Scan |
| Submit a volume of files for ml scanning. | |
| schedule-scan | ODS (On Demand Scan) |
| Create ODS scan and start or schedule scan for the given scan request. | |
| scheduled-reports.get | Scheduled Reports |
| Retrieve scheduled reports for the provided report IDs. | |
| scheduled-reports.launch | Scheduled Reports |
| Launch scheduled reports executions for the provided report IDs. | |
| scheduled-reports.query | Scheduled Reports |
| Find all report IDs matching the query with filter | |
| SearchAndReadContainerAlerts | Container Alerts |
| Search Container Alerts by the provided search criteria | |
| SearchAndReadDriftIndicatorEntities | Drift Indicators |
| Retrieve Drift Indicators by the provided search criteria | |
| SearchAndReadKubernetesIomEntities | Kubernetes Protection |
| Retrieves a list of Kubernetes IOMs identified by the provided search criteria. | |
| SearchAndReadUnidentifiedContainers | Unidentified Containers |
| Search Unidentified Containers by the provided search criteria | |
| SearchDetections | Container Detections |
| Retrieve image assessment detection entities identified by the provided filter criteria | |
| SearchDriftIndicators | Drift Indicators |
| Retrieve all drift indicators that match the given query | |
| SearchHuntingGuides | CAO Hunting |
| Search for Hunting Guides that match the provided conditions | |
| SearchIndicators | Intelligence Indicator Graph |
| Search indicators based on FQL filter. | |
| SearchIntelligenceQueries | CAO Hunting |
| Search for a list of intelligence queries IDs that match the provided conditions | |
| SearchKubernetesIoms | Kubernetes Protection |
| Search Kubernetes IOMs by the provided search criteria. this endpoint returns a list of Kubernetes IOM UUIDs matching the query | |
| SearchObjects | Custom Storage |
| Search for objects that match the specified filter criteria (returns metadata, not actual objects) | |
| SearchObjectsByVersion | Custom Storage |
| Search for objects that match the specified filter criteria (returns metadata, not actual objects) | |
| ServiceNowGetDeployments | ASPM |
| ServiceNowGetServices | ASPM |
| SetCloudSecurityIntegrationState | ASPM |
| Set Cloud Security integration state | |
| setContentUpdatePoliciesPrecedence | Content Update Policies |
| Sets the precedence of Content Update Policies based on the order of IDs specified in the request. | |
| setDeviceControlPoliciesPrecedence | Device Control Policies |
| Sets the precedence of Device Control Policies based on the order of IDs specified in the request. | |
| setFirewallPoliciesPrecedence | Firewall Policies |
| Sets the precedence of Firewall Policies based on the order of IDs specified in the request. | |
| setPreventionPoliciesPrecedence | Prevention Policies |
| Sets the precedence of Prevention Policies based on the order of IDs specified in the request. | |
| setRTResponsePoliciesPrecedence | Response Policies |
| Sets the precedence of Response Policies based on the order of IDs specified in the request. | |
| setSensorUpdatePoliciesPrecedence | Sensor Update Policy |
| Sets the precedence of Sensor Update Policies based on the order of IDs specified in the request. | |
| severity.query.v1 | IOC |
| Query Severities. | |
| signalChangesExternal | FileVantage |
| Initiates workflows for the provided change ids | |
| ss-ioa-exclusions.aggregates.v2 | IOA Exclusions |
| Get Self Service IOA Exclusion aggregates as specified via json in the request body. | |
| ss-ioa-exclusions.create.v2 | IOA Exclusions |
| Create new Self Service IOA Exclusions. | |
| ss-ioa-exclusions.delete.v2 | IOA Exclusions |
| Delete the Self Service IOA Exclusions rule by id. | |
| ss-ioa-exclusions.get-reports.v2 | IOA Exclusions |
| Create a report of Self Service IOA Exclusions scoped by the given filters | |
| ss-ioa-exclusions.get.v2 | IOA Exclusions |
| Get the Self Service IOA Exclusions rules by id. | |
| ss-ioa-exclusions.matched-rule.v2 | IOA Exclusions |
| Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent | |
| ss-ioa-exclusions.new-rules.v2 | IOA Exclusions |
| Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent. | |
| ss-ioa-exclusions.search.v2 | IOA Exclusions |
| Search for Self Service IOA Exclusions. | |
| ss-ioa-exclusions.update.v2 | IOA Exclusions |
| Update the Self Service IOA Exclusions rule by id. | |
| startActions | FileVantage |
| Initiates the specified action on the provided change ids | |
| StartSearchV1 | NGSIEM |
| Initiate search | |
| StopSearchV1 | NGSIEM |
| Stop search | |
| Submit | Falconx Sandbox |
| Submit an uploaded file or a URL for sandbox analysis. | |
| TestParserFromTemplate | NGSIEM |
| Test Parser from LogScale YAML Template in NGSIEM | |
| tokens-create | Installation Tokens |
| Creates a token. | |
| tokens-delete | Installation Tokens |
| Deletes a token immediately. | |
| tokens-query | Installation Tokens |
| Search for tokens by providing an FQL filter and paging details. | |
| tokens-read | Installation Tokens |
| Gets the details of one or more tokens by id. | |
| tokens-update | Installation Tokens |
| Updates one or more tokens. | |
| TriggerScan | Kubernetes Protection |
| Triggers a dry run or a full scan of a customer’s kubernetes footprint | |
| update-global-configs | Network Scan Global Configs |
| Update “global-configs” using provided specifications | |
| update-network-locations | Firewall Management |
| Updates the network locations provided, and return the ID. | |
| update-network-locations-metadata | Firewall Management |
| Updates the network locations metadata such as polling_intervals for the cid | |
| update-network-locations-precedence | Firewall Management |
| Updates the network locations precedence according to the list of ids provided. | |
| update-networks | Network Scan Networks |
| Update “networks” using provided specifications | |
| update-policy-container | Firewall Management |
| Update an identified policy container, including local logging functionality. | |
| update-policy-container-v1 | Firewall Management |
| Update an identified policy container. | |
| update-rule-group | Firewall Management |
| Update name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules | |
| update-rule-group-validation | Firewall Management |
| Validates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules | |
| update-rule-groupMixin0 | Custom IOA |
| Update a rule group. | |
| update-rules | Custom IOA |
| Update rules within a rule group. | |
| update-rules-v2 | Custom IOA |
| Update name, description, enabled or field_values for individual rules within a rule group. | |
| update-scan-runs | Network Scan Scan Runs |
| Update “scan-runs” using provided specifications | |
| update-scanners | Network Scan Scanners |
| Update “scanners” using provided specifications | |
| update-scans | Network Scan Scans |
| Update “scans” using provided specifications | |
| update-templates | Network Scan Templates |
| Update “templates” using provided specifications | |
| update-zones | Network Scan Zones |
| Update “zones” using provided specifications | |
| UpdateActionV1 | Recon |
| Update an action for a monitoring rule. | |
| UpdateAPIClient | API Clients |
| Update existing API Client based on API Client ID provided as request parameter ‘ids’. | |
| UpdateAWSAccount | Kubernetes Protection |
| Updates the AWS account per the query parameters provided | |
| UpdateAWSAccounts | Cloud Connect AWS |
| Update AWS Accounts by specifying the ID of the account and details to update | |
| UpdateCase | Message Center |
| update an existing case | |
| updateCIDGroups | MSSP (Flight Control) |
| Update existing CID groups. | |
| UpdateCloudGroupExternal | Cloud Security |
| Update Cloud Group | |
| UpdateComplianceControl | Cloud Policies |
| Update a custom compliance control | |
| UpdateComplianceFramework | Cloud Policies |
| Update a custom compliance framework | |
| updateContentUpdatePolicies | Content Update Policies |
| Update Content Update Policies by specifying the ID of the policy and details to update | |
| UpdateCSPMAzureAccount | CSPM Registration |
| Patches a existing account in our system for a customer. | |
| UpdateCSPMAzureAccountClientID | CSPM Registration |
| Update an Azure service account in our system by with the user-created client_id created with the public key we’ve provided | |
| UpdateCSPMAzureTenantDefaultSubscriptionID | CSPM Registration |
| Update an Azure default subscription_id in our system for given tenant_id | |
| UpdateCSPMGCPAccount | CSPM Registration |
| Patches a existing account in our system for a customer. | |
| UpdateCSPMGCPServiceAccountsExt | CSPM Registration |
| Patches the service account key for external clients. | |
| UpdateCSPMPolicySettings | CSPM Registration |
| Updates a policy setting - can be used to override policy severity or to disable a policy entirely. | |
| UpdateCSPMScanSchedule | CSPM Registration |
| Updates scan schedule configuration for one or more cloud platforms. | |
| UpdateD4CGCPServiceAccountsExt | D4C Registration |
| Patches the service account key for external clients. | |
| UpdateDashboardFromTemplate | NGSIEM |
| Update Dashboard from LogScale YAML Template in NGSIEM. | |
| updateDashboardLabels | NGSIEM |
| Replace all labels on a single dashboard | |
| updateDefaultDeviceControlPolicies | Device Control Policies |
| Update the configuration for a Default Device Control Policy | |
| updateDefaultDeviceControlSettings | Device Control Policies |
| Update the configuration for Default Device Control Settings | |
| UpdateDefaultGroup | ASPM |
| Update default group | |
| UpdateDetectsByIdsV2 | Detects |
| Deprecated: This endpoint will be decommissioned on September 30, 2025. | |
| updateDeviceControlPolicies | Device Control Policies |
| Update Device Control Policies by specifying the ID of the policy and details to update | |
| UpdateDeviceTags | Hosts |
| Append or remove one or more Falcon Grouping Tags on one or more hosts. | |
| UpdateDiscoverCloudAzureAccountClientID | D4C Registration |
| Update an Azure service account in our system by with the user-created client_id created with the public key we’ve provided | |
| UpdateExecutorNode | ASPM |
| Update an existing relay node | |
| updateFileLabels | NGSIEM |
| Replace all labels on a single file | |
| UpdateFileV1 | Foundry Lookup Files |
| Updates a lookup file within a Foundry app | |
| updateFirewallPolicies | Firewall Policies |
| Update Firewall Policies by specifying the ID of the policy and details to update | |
| UpdateGroup | ASPM |
| Update group | |
| UpdateGroupV1Mixin0 | Profile Groups |
| Update profile group metadata (name, description) | |
| updateHostGroups | Host Group |
| Update Host Groups by specifying the ID of the group and details to update | |
| UpdateIntegration | ASPM |
| Update an existing integration by its ID | |
| UpdateIntegrationTask | ASPM |
| Update an existing integration task by its ID | |
| updateIOAExclusionsV1 | IOA Exclusions |
| Update the IOA exclusions | |
| UpdateIOC | IOCs |
| Update an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (PATCH /iocs/entities/indicators/v1). *** | |
| UpdateLookupFile | NGSIEM |
| Update an entire Lookup File in NGSIEM | |
| UpdateLookupFileEntries | NGSIEM |
| Update entries in an existing Lookup File in NGSIEM | |
| updateMLExclusionsV1 | ML Exclusions |
| Update the ML exclusions | |
| UpdateNotificationsV1 | Recon |
| Update notification status or assignee. | |
| UpdateParser | NGSIEM |
| Update Parser in NGSIEM. | |
| UpdateParserAutoUpdatePolicy | NGSIEM |
| Updates a parser auto update policy - ‘on’ enables auto-updates, ‘off’ disables them | |
| UpdateParserExtension | NGSIEM |
| Update an existing Parser extension in NGSIEM. | |
| UpdateParserFromTemplate | NGSIEM |
| Update Parser in NGSIEM from YAML Template. | |
| updatePolicies | FileVantage |
| Updates the general information of the provided policy. | |
| UpdatePolicies | Image Assessment Policies |
| Update Image Assessment Policy entities | |
| UpdatePolicyExclusions | Image Assessment Policies |
| Update Image Assessment Policy Exclusion entities | |
| UpdatePolicyGroups | Image Assessment Policies |
| Update Image Assessment Policy Group entities | |
| updatePolicyHostGroups | FileVantage |
| Manage host groups assigned to a policy. | |
| updatePolicyPrecedence | FileVantage |
| Updates the policy precedence for all policies of a specific type. | |
| UpdatePolicyPrecedence | Image Assessment Policies |
| Update Image Assessment Policy precedence | |
| updatePolicyRuleGroups | FileVantage |
| Manage the rule groups assigned to the policy or set the rule group precedence for all rule groups within the policy. | |
| updatePreventionPolicies | Prevention Policies |
| Update Prevention Policies by specifying the ID of the policy and details to update | |
| UpdateQfByQuery | Quarantine |
| Apply quarantine file actions by query. | |
| UpdateQuarantinedDetectsByIds | Quarantine |
| Apply action by quarantine file ids | |
| UpdateRegistryEntities | Falcon Container |
| Update the registry entity, as identified by the entity UUID, using the provided details | |
| updateRTResponsePolicies | Response Policies |
| Update Response Policies by specifying the ID of the policy and details to update | |
| UpdateRule | Cloud Policies |
| Update a rule | |
| updateRuleGroupPrecedence | FileVantage |
| Updates the rule precedence for all rules in the identified rule group. | |
| updateRuleGroups | FileVantage |
| Updates the provided rule group. | |
| UpdateRuleOverride | Cloud Policies |
| Update a rule override | |
| updateRules | FileVantage |
| Updates the provided rule configuration within the specified rule group. | |
| UpdateRulesV1 | Recon |
| Update monitoring rules. | |
| UpdateSavedQueryFromTemplate | NGSIEM |
| Update Saved Query from LogScale YAML Template in NGSIEM. | |
| updateSavedQueryLabels | NGSIEM |
| Replace all labels on a single saved query | |
| updateScheduledExclusions | FileVantage |
| Updates the provided scheduled exclusion configuration within the provided policy. | |
| updateSensorUpdatePolicies | Sensor Update Policy |
| Update Sensor Update Policies by specifying the ID of the policy and details to update | |
| updateSensorUpdatePoliciesV2 | Sensor Update Policy |
| Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection | |
| updateSensorVisibilityExclusionsV1 | Sensor Visibility Exclusions |
| Update the sensor visibility exclusions | |
| UpdateSuppressionRule | Cloud Policies |
| Update a suppression rule | |
| UpdateThirdPartyPasskeyRegistry | Falcon ID |
| Updates third party passkey registries | |
| UpdateUser | User Management |
| Deprecated : Please use PATCH /user-management/entities/users/v1. | |
| updateUserGroups | MSSP (Flight Control) |
| Update existing user group(s). | |
| updateUserV1 | User Management |
| Modify an existing user’s first or last name. | |
| UploadFileMixin0Mixin94 | Quick Scan Pro |
| Uploads a file to be further analyzed with QuickScan Pro. | |
| UploadFileQuickScanPro | Quick Scan Pro |
| Uploads a file to be further analyzed with QuickScan Pro. | |
| UploadLookupV1 | NGSIEM |
| Upload file to NGSIEM | |
| UploadSampleV2 | Falconx Sandbox |
| Upload a file for sandbox analysis. | |
| UploadSampleV3 | Sample Uploads |
| Upload a file for further cloud analysis. | |
| upsert-network-locations | Firewall Management |
| Updates the network locations provided, and return the ID. | |
| UpsertBusinessApplications | ASPM |
| Create or Update Business Applications | |
| UpsertTags | ASPM |
| Create new or update existing tag. | |
| userActionV1 | User Management |
| Apply actions to one or more User. | |
| userRolesActionV1 | User Management |
| Grant or Revoke one or more role(s) to a user against a CID. | |
| v1.child-executions.query | Workflows |
| Search for child executions by providing a FQL filter and paging details. | |
| validate | Custom IOA |
| Validates field values and checks for matches if a test string is provided. | |
| validate-filepath-pattern | Firewall Management |
| Validates that the test pattern matches the executable filepath glob pattern. | |
| ValidateCSPMGCPServiceAccountExt | CSPM Registration |
| Validates credentials for a service account | |
| VerifyAWSAccountAccess | Cloud Connect AWS |
| Performs an Access Verification check on the specified AWS Account IDs | |
| WorkflowActivitiesCombined | Workflows |
| Search for activities by name. | |
| WorkflowActivitiesContentCombined | Workflows |
| Search for activities by name. | |
| WorkflowDefinitionsAction | Workflows |
| Enable or disable a workflow definition, or stop all executions for a definition. | |
| WorkflowDefinitionsCombined | Workflows |
| Search workflow definitions based on the provided filter. | |
| WorkflowDefinitionsDelete | Workflows |
| Accepts a list of workflow definition IDs and deletes those definitions and all their associated versions. | |
| WorkflowDefinitionsExport | Workflows |
| Exports a workflow definition for the given definition ID | |
| WorkflowDefinitionsImport | Workflows |
| Imports a workflow definition based on the provided model | |
| WorkflowDefinitionsUpdate | Workflows |
| Updates a workflow definition based on the provided model | |
| WorkflowExecute | Workflows |
| Executes an on-demand Workflow, the body is JSON used to trigger the execution, the response the execution ID(s) | |
| WorkflowExecuteSingleNodeV1 | Workflows |
| Executes a single activity node, resulting in an execution where test_mode=true and single_node_execution=true, associated with a definition ID if provided | |
| WorkflowExecutionResults | Workflows |
| Get execution result of a given execution | |
| WorkflowExecutionsAction | Workflows |
| Allows a user to resume/retry a failed workflow execution, or cancel/stop a currently running workflow execution | |
| WorkflowExecutionsCombined | Workflows |
| Search workflow executions based on the provided filter | |
| WorkflowGetHumanInputV1 | Workflows |
| Gets one or more specific human inputs by their IDs. | |
| WorkflowMockExecute | Workflows |
| Executes a workflow definition with mocks | |
| WorkflowSystemDefinitionsDeProvision | Workflows |
| Deprovisions a system definition that was previously provisioned on the target CID | |
| WorkflowSystemDefinitionsPromote | Workflows |
| Promotes a version of a system definition for a customer. | |
| WorkflowSystemDefinitionsProvision | Workflows |
| Provisions a system definition onto the target CID by using the template and provided parameters | |
| WorkflowTriggersCombined | Workflows |
| Search for triggers by namespaced identifier, i.e. | |
| WorkflowUpdateHumanInputV1 | Workflows |
| Provides an input in response to a human input action. | |