Skip to content

All Operations

A complete alphabetical index of all CrowdStrike API operations across every service collection. Each Operation ID is a unique, case-sensitive identifier used by the Falcon SDKs to reference a specific API call. Use this page as a quick-lookup reference when you know the operation name but not which collection it belongs to.

action_get_v1IOC
Get Actions by ids.
action_query_v1IOC
Query Actions.
ActionUpdateCountQuarantine
Returns count of potentially affected quarantined files for each action.
addCIDGroupMembersMSSP (Flight Control)
Add new CID Group member.
addRoleMSSP (Flight Control)
Assign new MSSP Role(s) between User Group and CID Group. It does not revoke existing role(s) between User Group and CID Group. User Group ID and CID Group ID have to be specified in request.
addUserGroupMembersMSSP (Flight Control)
Add new User Group member. Maximum 500 members allowed per User Group.
admission_control_add_host_groupsAdmission Control Policies
Add one or more host groups to an admission control policy.
admission_control_add_rule_group_custom_ruleAdmission Control Policies
Add one or more custom Rego rules to a rule group in an admission control policy.
admission_control_create_policyAdmission Control Policies
Create an admission control policy.
admission_control_create_rule_groupsAdmission Control Policies
Create one or more rule groups and add them to an existing admission control policy.
admission_control_delete_policiesAdmission Control Policies
Delete an admission control policy.
admission_control_delete_rule_groupsAdmission Control Policies
Delete rule groups.
admission_control_get_policiesAdmission Control Policies
Get admission control policies.
admission_control_query_policiesAdmission Control Policies
Search admission control policies.
admission_control_remove_host_groupsAdmission Control Policies
Remove one or more host groups from an admission control policy.
admission_control_remove_rule_group_custom_ruleAdmission Control Policies
Delete one or more custom Rego rules from all rule groups in an admission control policy.
admission_control_replace_rule_group_selectorsAdmission Control Policies
Replace labels and/or namespaces of a rule group within an admission control policy.
admission_control_set_rule_group_precedenceAdmission Control Policies
Change precedence of rule groups within an admission control policy.
admission_control_update_policyAdmission Control Policies
Update an admission control policy.
admission_control_update_policy_precedenceAdmission Control Policies
Update admission control policy precedence.
admission_control_update_rule_groupsAdmission Control Policies
Update a rule group.
aggregate_eventsFirewall Management
Aggregate events for customer
aggregate_external_assetsExposure Management
Returns external assets aggregates.
aggregate_networksNetwork Scan Networks
Returns “networks” aggregations
aggregate_policy_rulesFirewall Management
Aggregate rules within a policy for customer
aggregate_query_scan_host_metadataODS (On Demand Scan)
Get aggregates on ODS scan-hosts data.
aggregate_rule_groupsFirewall Management
Aggregate rule groups for customer
aggregate_rulesFirewall Management
Aggregate rules for customer
aggregate_scan_runsNetwork Scan Scan Runs
Returns “scan-runs” aggregations
aggregate_scannersNetwork Scan Scanners
Returns “scanners” aggregations
aggregate_scansODS (On Demand Scan)
Get aggregates on ODS scan data.
aggregate_scansMixin0Network Scan Scans
Returns “scans” aggregations
aggregate_scheduled_scansODS (On Demand Scan)
Get aggregates on ODS scheduled-scan data.
aggregate_zonesNetwork Scan Zones
Returns “zones” aggregations
AggregateAlertsFalcon Complete Dashboard
Retrieve aggregate alerts values based on the matched filter
AggregateAllowListFalcon Complete Dashboard
Retrieve aggregate allowlist ticket values based on the matched filter
AggregateAssessmentsGroupedByClustersV2Kubernetes Container Compliance
Returns cluster details along with aggregated assessment results organized by cluster, including pass/fail assessment counts for various asset types.
AggregateAssessmentsGroupedByRulesV2Kubernetes Container Compliance
Returns rule details along with aggregated assessment results organized by compliance rule, including pass/fail assessment counts.
AggregateBlockListFalcon Complete Dashboard
Retrieve aggregate blocklist ticket values based on the matched filter
AggregateCasesMessage Center
Retrieve aggregate case values based on the matched filter
AggregateComplianceByAssetTypeKubernetes Container Compliance
Provides aggregated compliance assessment metrics and rule status information, organized by asset type.
AggregateComplianceByClusterTypeKubernetes Container Compliance
Provides aggregated compliance assessment metrics and rule status information, organized by Kubernetes cluster type.
AggregateComplianceByFrameworkKubernetes Container Compliance
Provides aggregated compliance assessment metrics and rule status information, organized by compliance framework.
AggregateDeviceCountCollectionFalcon Complete Dashboard
Retrieve aggregate host/devices count based on the matched filter
AggregateEscalationsFalcon Complete Dashboard
Retrieve aggregate escalation ticket values based on the matched filter
AggregateFailedRulesByClustersV3Kubernetes Container Compliance
Retrieves the most non-compliant clusters, ranked in descending order based on the number of failed compliance rules across severity levels (critical, high, medium, and low).
AggregateFCIncidentsFalcon Complete Dashboard
Retrieve aggregate incident values based on the matched filter
AggregateHuntingGuidesCAO Hunting
Aggregate Hunting Guides
AggregateImageAssessmentHistoryContainer Images
Image assessment history
AggregateImageCountContainer Images
Aggregate count of images
AggregateImageCountByBaseOSContainer Images
Aggregate count of images grouped by Base OS distribution
AggregateImageCountByStateContainer Images
Aggregate count of images grouped by state
AggregateIntelligenceQueriesCAO Hunting
Aggregate intelligence queries.
AggregateNotificationsExposedDataRecordsV1Recon
Get notification exposed data record aggregates as specified via JSON in request body.
AggregateNotificationsV1Recon
Get notification aggregates as specified via JSON in request body.
AggregatePreventionPolicyFalcon Complete Dashboard
Retrieve aggregate prevention policy values based on the matched filter
AggregateRemediationsFalcon Complete Dashboard
Retrieve aggregate remediation ticket values based on the matched filter
aggregates_access_tags_post_v1Case Management
Get access tag aggregates.
aggregates_file_details_post_v1Case Management
Get file details aggregates as specified via json in the request body.
aggregates_knowledge_base_audit_events_v1Knowledge Base Audit Events
Aggregate knowledge base audit events based on the provided msa criteria.
aggregates_knowledge_bases_v1Knowledge Bases
Aggregate knowledge bases based on the provided msa criteria.
aggregates_notification_groups_post_v1Case Management
Get notification groups aggregations
aggregates_notification_groups_post_v2Case Management
Get notification groups aggregations
aggregates_rule_versions_post_v1Correlation Rules
Get rules aggregates as specified via json in the request body.
aggregates_slas_post_v1Case Management
Get SLA aggregations
aggregates_templates_post_v1Case Management
Get templates aggregations
AggregatesDetectionsGlobalCountsOverwatch Dashboard
Get the total number of detections pushed across all customers.
AggregateSensorUpdatePolicyFalcon Complete Dashboard
Retrieve aggregate sensor update policy values based on the matched filter
AggregatesEventsOverwatch Dashboard
Get aggregate OverWatch detection event info by providing an aggregate query.
AggregatesEventsCollectionsOverwatch Dashboard
Get OverWatch detection event collection info by providing an aggregate query.
AggregatesIncidentsGlobalCountsOverwatch Dashboard
Get the total number of incidents pushed across all customers.
AggregatesOWEventsGlobalCountsOverwatch Dashboard
Get the total number of OverWatch events across all customers.
AggregateSupportIssuesFalcon Complete Dashboard
Retrieve aggregate support issue values based on the matched filter
AggregateTopFailedImagesKubernetes Container Compliance
Retrieves the most non-compliant container images, ranked in descending order based on the number of failed assessments across severity levels (critical, high, medium, and low).
AggregateTotalDeviceCountsFalcon Complete Dashboard
Retrieve aggregate total host/devices based on the matched filter
aggregateUsersV1User Management
Get user aggregates as specified via json in request body.
api_preempt_proxy_post_graphqlIdentity Protection
Identity Protection GraphQL API. Allows to retrieve entities, timeline activities, identity-based incidents and security assessment. Allows to perform actions on entities and identity-based incidents.
ArchiveDeleteV1Sample Uploads
Delete an archive that was uploaded previously.
ArchiveGetV1Sample Uploads
Retrieves the archives upload operation statuses. Status done means that archive was processed successfully. Status error means that archive was not processed successfully.
ArchiveListV1Sample Uploads
Retrieves the archives files in chunks.
ArchiveUploadV1Sample Uploads
Uploads an archive and extracts files list from it. Operation is asynchronous.
ArchiveUploadV2Sample Uploads
Uploads an archive and extracts files list from it. Operation is asynchronous.
audit_events_queryInstallation Tokens
Search for audit events by providing a FQL filter and paging details.
audit_events_readInstallation Tokens
Gets the details of one or more audit events by id.
AzureDownloadCertificateCSPM Registration
Returns JSON object(s) that contain the base64 encoded certificate for a service principal.
AzureRefreshCertificateCSPM Registration
Refresh certificate and returns JSON object(s) that contain the base64 encoded certificate for a service principal.
BatchActiveResponderCmdReal Time Response
Batch executes a RTR active-responder command across the hosts mapped to the given batch ID.
BatchAdminCmdReal Time Response Admin
Batch executes a RTR administrator command across the hosts mapped to the given batch ID.
BatchCmdReal Time Response
Batch executes a RTR read-only command across the hosts mapped to the given batch ID.
BatchGetCmdReal Time Response
Batch executes get command across hosts to retrieve files. After this call is made BatchGetCmdStatus is used to query for the results.
BatchGetCmdStatusReal Time Response
Retrieves the status of the specified batch get command. Will return successful files when they are finished processing.
BatchInitSessionsReal Time Response
Batch initialize a RTR session on multiple hosts. Before any RTR commands can be used, an active session is needed on the host.
BatchRefreshSessionsReal Time Response
Batch refresh a RTR session on multiple hosts. RTR sessions will expire after 5 minutes unless refreshed.
blob_download_external_assetsExposure Management
Download the entire contents of the blob. The relative link to this endpoint is returned in the GET /entities/external-assets/v1 request.
blob_preview_external_assetsExposure Management
Download a preview of the blob. The relative link to this endpoint is returned in the GET /entities/external-assets/v1 request.
BulkInstallParsersNGSIEM
Install multiple CrowdStrike-managed out-of-the-box (OOTB) parsers.
cancel_scansODS (On Demand Scan)
Cancel ODS scans for the given scan ids.
CaseAddActivityMessage Center
Add an activity to case. Only activities of type comment are allowed via API
CaseAddAttachmentMessage Center
Upload an attachment for the case.
CaseDownloadAttachmentMessage Center
retrieves an attachment for the case, given the attachment id
cb_exclusions_create_v1Certificate Based Exclusions
Create new Certificate Based Exclusions.
cb_exclusions_delete_v1Certificate Based Exclusions
Delete the exclusions by id.
cb_exclusions_get_v1Certificate Based Exclusions
Find all exclusion IDs matching the query with filter.
cb_exclusions_query_v1Certificate Based Exclusions
Search for cert-based exclusions.
cb_exclusions_update_v1Certificate Based Exclusions
Updates existing Certificate Based Exclusions.
certificates_get_v1Certificate Based Exclusions
Retrieves certificate signing information for a file.
cloud_compliance_framework_posture_summariesCloud Security Compliance
Get sections and requirements with scores for benchmarks.
cloud_compliance_rule_posture_summariesCloud Security Compliance
Get compliance score and counts for rules.
cloud_registration_aws_create_accountCloud AWS Registration
Creates a new account in our system for a customer.
cloud_registration_aws_delete_accountCloud AWS Registration
Deletes an existing AWS account or organization in our system.
cloud_registration_aws_get_accountsCloud AWS Registration
Retrieve existing AWS accounts by account IDs.
cloud_registration_aws_query_accountsCloud AWS Registration
Retrieve existing AWS accounts by account IDs.
cloud_registration_aws_trigger_health_checkCloud AWS Registration
Trigger health check scan for AWS accounts.
cloud_registration_aws_update_accountCloud AWS Registration
Patches a existing account in our system for a customer.
cloud_registration_aws_validate_accountsCloud AWS Registration
Validates the AWS account registration status, and discover organization child accounts if organization is specified.
cloud_registration_azure_create_registrationCloud Azure Registration
Create an Azure registration for a tenant.
cloud_registration_azure_delete_legacy_subscriptionCloud Azure Registration
Delete existing legacy Azure subscriptions.
cloud_registration_azure_delete_registrationCloud Azure Registration
Deletes existing Azure registrations.
cloud_registration_azure_download_scriptCloud Azure Registration
Retrieve script to create resources.
cloud_registration_azure_get_registrationCloud Azure Registration
Retrieve existing Azure registration for a tenant.
cloud_registration_azure_trigger_health_checkCloud Azure Registration
Trigger health check scan for Azure registrations.
cloud_registration_azure_update_registrationCloud Azure Registration
Update an existing Azure registration for a tenant.
cloud_registration_azure_validate_registrationCloud Azure Registration
Validate an Azure registration by checking service principal, role assignments and deployment stack (if the deployment method is Bicep)
cloud_registration_gcp_create_registrationCloud GCP Registration
Create a Google Cloud Registration.
cloud_registration_gcp_create_registrationCloud Google Cloud Registration
Create a Google Cloud Registration.
cloud_registration_gcp_delete_registrationCloud GCP Registration
Deletes a Google Cloud Registration and returns the deleted registration in the response body.
cloud_registration_gcp_delete_registrationCloud Google Cloud Registration
Deletes a Google Cloud Registration and returns the deleted registration in the response body.
cloud_registration_gcp_get_entitiesCloud GCP Registration
Retrieve all GCP entities (organizations, folders, projects) grouped by type with support for FQL filtering, sorting, and pagination.
cloud_registration_gcp_get_entitiesCloud Google Cloud Registration
Retrieve all GCP entities (organizations, folders, projects) grouped by type with support for FQL filtering, sorting, and pagination.
cloud_registration_gcp_get_registrationCloud GCP Registration
Retrieve a Google Cloud Registration.
cloud_registration_gcp_get_registrationCloud Google Cloud Registration
Retrieve a Google Cloud Registration.
cloud_registration_gcp_put_registrationCloud GCP Registration
Creates/Updates a Google Cloud Registration.
cloud_registration_gcp_put_registrationCloud Google Cloud Registration
Creates/Updates a Google Cloud Registration.
cloud_registration_gcp_trigger_health_checkCloud GCP Registration
Trigger health check scan for GCP registrations
cloud_registration_gcp_trigger_health_checkCloud Google Cloud Registration
Trigger health check scan for GCP registrations
cloud_registration_gcp_update_registrationCloud GCP Registration
Update a Google Cloud Registration.
cloud_registration_gcp_update_registrationCloud Google Cloud Registration
Update a Google Cloud Registration.
cloud_security_assets_combined_application_findingsCloud Security Assets
Get findings for an application resource with pagination.
cloud_security_assets_combined_compliance_by_accountCloud Security Assets
Get combined compliance by account.
cloud_security_assets_entities_getCloud Security Assets
Gets raw resources based on the provided IDs param. Maximum of 100 resources can be requested with this method. Use POST method with same path if more are required.
cloud_security_assets_queriesCloud Security Assets
Query cloud security assets.
cloud_security_registration_oci_create_accountCloud OCI Registration
Create OCI tenancy account in CSPM
cloud_security_registration_oci_delete_accountCloud OCI Registration
Delete an existing OCI tenancy in CSPM.
cloud_security_registration_oci_download_scriptCloud OCI Registration
Retrieve script to create resources in tenancy OCID
cloud_security_registration_oci_get_accountCloud OCI Registration
Retrieve a list of OCI tenancies with support for FQL filtering, sorting, and pagination
cloud_security_registration_oci_rotate_keyCloud OCI Registration
Refresh key for the OCI Tenancy
cloud_security_registration_oci_update_accountCloud OCI Registration
Update an existing OCI account.
cloud_security_registration_oci_validate_tenancyCloud OCI Registration
Validate the OCI account in CSPM for a provided CID. For internal clients only.
cloud_security_timeline_risks_enrichedCloud Security Risks
Returns the enriched asset timeline. Rate limited to 500 requests per minute per CID. Exceeding this limit returns HTTP 429 (Too Many Requests).
combined_applicationsDiscover
Search for applications in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns details on applications which match the filter criteria.
combined_cloud_risksCloud Security
Get cloud risks with full details based on filters and sort criteria.
combined_ecosystem_subsidiariesExposure Management
Retrieves a list of ecosystem subsidiaries with their detailed information.
combined_edges_getThreatGraph
Retrieve edges for a given vertex id. One edge type must be specified.
combined_file_details_get_v1Case Management
Query file details
combined_hostsDiscover
Search for assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns details on assets which match the filter criteria.
combined_knowledge_base_audit_events_v1Knowledge Base Audit Events
Get knowledge base audit events with full event details and pagination.
combined_ran_on_getThreatGraph
Look up instances of indicators such as hashes, domain names, and ip addresses that have been seen on devices in your environment.
combined_rules_get_v1Correlation Rules
Find all rules matching the query and filter.
combined_rules_get_v2Correlation Rules
Find all rules matching the query and filter.
combined_summary_getThreatGraph
Retrieve summary for a given vertex ID.
combined_zonesNetwork Scan Zones
Get “zones” by filter
CombinedBaseImagesContainer Images
Retrieve base images identified by the provided filter criteria
CombinedDetectionsCloud Snapshots
Search IaC Detections using a query in Falcon Query Language.
CombinedDevicesByFilterHosts
Search for hosts. Returns full device records.
CombinedHiddenDevicesByFilterHosts
Search for hidden hosts. Returns full device records.
CombinedImageByVulnerabilityCountContainer Images
Retrieve top x images with the most vulnerabilities
CombinedImageDetailContainer Images
Retrieve image entities identified by the provided filter criteria
CombinedImageIssuesSummaryContainer Images
Retrieve image issues summary such as Image detections, Runtime detections, Policies, vulnerabilities
CombinedImagesFindingsKubernetes Container Compliance
Returns detailed compliance assessment results for container images, providing the information needed to identify compliance violations.
CombinedImageVulnerabilitySummaryContainer Images
aggregates information about vulnerabilities for an image
CombinedNodesFindingsKubernetes Container Compliance
Returns detailed compliance assessment results for kubernetes nodes, providing the information needed to identify compliance violations.
combinedQueryEvaluationLogicSpotlight Evaluation Logic
Search for evaluation logic in your environment by providing a FQL filter and paging details. Returns a set of evaluation logic entities which match the filter criteria.
combinedQueryVulnerabilitiesSpotlight Vulnerabilities
Search for Vulnerabilities in your environment by providing a FQL filter and paging details. Returns a set of Vulnerability entities which match the filter criteria.
CombinedReleaseNotesV1Deployments
Queries for releases resources and returns details.
CombinedReleasesV1Mixin0Deployments
Queries for releases resources and returns details.
combinedSupportedEvaluationExtSpotlight Evaluation Logic
Perform a combined query and get for RiskSupportedEvaluation entities.
combinedUserRolesV1User Management
Get user grant(s). This operation lists both direct as well as flight control grants between a User and a Customer.
CombinedUserRolesV2User Management
Get user grant(s). This operation lists both direct as well as flight control grants between a User and a Customer.
combineVulnMetadataExtSpotlight Vulnerability Metadata
Perform a combined query and get operation for retrieving Risk (vulnerability metadata) entities.
ConnectCSPMGCPAccountCSPM Registration
Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id
ConnectD4CGCPAccountD4C Registration
Creates a new GCP account with newly-uploaded service account or connects with existing service account.
create_network_locationsFirewall Management
Create new network locations provided, and return the ID.
create_networksNetwork Scan Networks
Create “networks” using provided specifications
create_ruleCustom IOA
Create a rule within a rule group. Returns the rule.
create_rule_groupFirewall Management
Create new rule group on a platform for a customer with a name and description, and return the ID
create_rule_group_validationFirewall Management
Validates the request of creating a new rule group on a platform for a customer with a name and description
create_rule_groupMixin0Custom IOA
Create a rule group for a platform with a name and an optional description. Returns the rule group.
create_scanODS (On Demand Scan)
Create ODS scan and start or schedule scan for the given scan request.
create_scan_runsNetwork Scan Scan Runs
Create “scan-runs” using provided specifications
create_scansNetwork Scan Scans
Create “scans” using provided specifications
create_templatesNetwork Scan Templates
Create “templates” using provided specifications
create_zonesNetwork Scan Zones
Create “zones” using provided specifications
CreateActionsV1Recon
Create actions for a monitoring rule. Accepts a list of actions that will be attached to the monitoring rule.
CreateAWSAccountKubernetes Protection
Creates a new AWS account in our system for a customer and generates the installation script
CreateAzureSubscriptionKubernetes Protection
Creates a new Azure Subscription in our system
CreateBaseImagesEntitiesContainer Images
Creates base images using the provided details
CreateCaseV2Message Center
create a new case
createCIDGroupsMSSP (Flight Control)
Create new CID Group(s). Maximum 500 CID Group(s) allowed.
CreateCloudGroupExternalCloud Security
Create a new Cloud Group with specified properties and selectors.
CreateComplianceControlCloud Policies
Create a new custom compliance control.
CreateComplianceFrameworkCloud Policies
Create a new custom compliance framework.
createContentUpdatePoliciesContent Update Policies
Create Content Update Policies by specifying details about the policy to create.
CreateCSPMAwsAccountCSPM Registration
Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
CreateCSPMAzureAccountCSPM Registration
Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
CreateCSPMAzureManagementGroupCSPM Registration
Creates a new management group in our system for a customer.
CreateCSPMGCPAccountCSPM Registration
Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
CreateD4CAwsAccountD4C Registration
Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
CreateD4CGCPAccountD4C Registration
Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
CreateDashboardFromTemplateNGSIEM
Create dashboard from template.
CreateDeploymentEntityCloud Snapshots
Launch a snapshot scan for a given cloud asset.
createDeviceControlPoliciesDevice Control Policies
Create Device Control Policies by specifying details about the policy to create.
CreateDiscoverCloudAzureAccountD4C Registration
Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
CreateExecutorNodeASPM
Create a new relay node
CreateExportJobsV1Recon
Launch asynchronous export job. Use the job ID to poll the status of the job using GetExportJobsV1.
CreateFileV1Foundry LogScale
Creates a lookup file.
createFirewallPoliciesFirewall Policies
Create Firewall Policies by specifying details about the policy to create
createHostGroupsHost Group
Create Host Groups by specifying details about the group to create
CreateIntegrationASPM
Create a new integration
CreateIntegrationTaskASPM
Create new integration task.
createIOAExclusionsV1IOA Exclusions
Create the IOA exclusions.
CreateIOCIOCs
This operation has been superseded by the IOC.indicator_create_v1 operation and is no longer used.
CreateLookupFileNGSIEM
Create lookup file.
CreateMigrationV1Host Migration
Create a device migration job.
createMLExclusionsV1ML Exclusions
Create the ML exclusions.
CreateOrUpdateAWSSettingsCloud Connect AWS
Create or update Global Settings which are applicable to all provisioned AWS accounts
CreateParserNGSIEM
Create Parser in NGSIEM.
CreateParserFromTemplateNGSIEM
Create Parser in NGSIEM from template.
createPoliciesFileVantage
Creates a new policy of the specified type. New policies are always added at the end of the precedence list for the provided policy type.
CreatePoliciesImage Assessment Policies
Create Image Assessment policies
CreatePolicyGroupsImage Assessment Policies
Create Image Assessment Policy Group entities
createPreventionPoliciesPrevention Policy
Create Prevention Policies by specifying details about the policy to create
CreateRegistryEntitiesFalcon Container
Create registry entities using the provided detail.
createRTResponsePoliciesResponse Policies
Create Response Policies by specifying details about the policy to create
createRuleGroupsFileVantage
Creates a new rule group of the specified type.
CreateRuleMixin0Cloud Policies
Create a new rule.
CreateRuleOverrideCloud Policies
Create a new rule override.
createRulesFileVantage
Creates a new rule configuration within the specified rule group.
CreateRulesV1Recon
Create monitoring rules.
CreateSavedQueryNGSIEM
Create Saved Query from LogScale YAML Template in NGSIEM.
CreateSavedSearchesDynamicExecuteV1Foundry LogScale
Execute a dynamic saved search
CreateSavedSearchesExecuteV1Foundry LogScale
Execute a saved search
CreateSavedSearchesIngestV1Foundry LogScale
Populate a saved search
createScheduledExclusionsFileVantage
Creates a new scheduled exclusion configuration for the provided policy id.
createSensorUpdatePoliciesSensor Update Policy
Create Sensor Update Policies by specifying details about the policy to create.
createSensorUpdatePoliciesV2Sensor Update Policy
Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection.
CreateSuppressionRuleCloud Policies
Create a new suppression rule.
createSVExclusionsV1Sensor Visibility Exclusions
Create a sensor visibility exclusion.
CreateUserUser Management
Create a new user. After creating a user, assign one or more roles with GrantUserRoleIds.
createUserGroupsMSSP (Flight Control)
Create new User Group(s). Maximum 500 User Group(s) allowed per customer.
createUserV1User Management
Create a new user. After creating a user, assign one or more roles with userRolesActionV1. Supports Flight Control.
cspm_evaluations_combined_iom_by_ruleCloud Security Detections
Return IOMs grouped by rule.
cspm_evaluations_iom_entitiesCloud Security Detections
Gets IOMs based on the provided IDs
cspm_evaluations_iom_queriesCloud Security Detections
Gets a list of IOM IDs for the given parameters, filters and sort criteria.
customer_settings_readInstallation Tokens
Check current installation token settings.
customer_settings_updateInstallation Tokens
Update installation token settings.
delete_external_assetsExposure Management
Delete multiple external assets.
delete_federated_connections_configFederated Connections
Delete configuration for a federated connection
delete_network_locationsFirewall Management
Delete network location entities by ID.
delete_networksNetwork Scan Networks
Delete “networks” by their IDs
delete_policy_rulesIdentity Protection
Delete policy rules.
delete_rule_groupsFirewall Management
Delete rule group entities by ID
delete_rule_groupsMixin0Custom IOA
Delete rule groups by ID.
delete_rulesCustom IOA
Delete rules from a rule group by ID.
delete_scansNetwork Scan Scans
Delete “scans” by their IDs
delete_scheduled_scansODS (On Demand Scan)
Delete ODS scheduled-scans for the given scheduled-scan ids.
delete_templatesNetwork Scan Templates
Delete “templates” by their IDs
delete_zonesNetwork Scan Zones
Delete “zones” by their IDs
DeleteActionV1Recon
Delete an action from a monitoring rule based on the action ID.
DeleteAWSAccountsCloud Connect AWS
Delete a set of AWS Accounts by specifying their IDs
DeleteAWSAccountsMixin0Kubernetes Protection
Delete AWS accounts.
DeleteAzureSubscriptionKubernetes Protection
Delete an Azure Subscription from the system.
DeleteBaseImagesContainer Images
Delete base images by base image UUID
deleteCIDGroupMembersMSSP (Flight Control)
Delete CID Group members entry.
deleteCIDGroupMembersV1MSSP (Flight Control)
Deprecated: Please use deleteCIDGroupMembersV2.
deleteCIDGroupsMSSP (Flight Control)
Delete CID Group(s) by ID(s).
DeleteCloudGroupsExternalCloud Security
Delete Cloud Groups in batch by their UUIDs.
DeleteComplianceControlCloud Policies
Delete custom compliance controls.
DeleteComplianceFrameworkCloud Policies
Delete a custom compliance framework and all associated controls and rule assignments.
deleteContentUpdatePoliciesContent Update Policies
Delete a set of Content Update Policies by specifying their IDs.
DeleteCSPMAwsAccountCSPM Registration
Deletes an existing AWS account or organization in our system.
DeleteCSPMAzureAccountCSPM Registration
Deletes an Azure subscription from the system.
DeleteCSPMAzureManagementGroupCSPM Registration
Deletes Azure management groups from the system.
DeleteCSPMGCPAccountCSPM Registration
Deletes a GCP account from the system.
DeleteD4CAwsAccountD4C Registration
Deletes an existing AWS account or organization in our system.
DeleteD4CGCPAccountD4C Registration
Deletes a GCP account from the system.
DeleteDashboardNGSIEM
Delete dashboard.
deleteDeviceControlPoliciesDevice Control Policies
Delete a set of Device Control Policies by specifying their IDs.
deletedRolesMSSP (Flight Control)
Delete MSSP Role assignment(s) between User Group and CID Group. User Group ID and CID Group ID have to be specified in request. Only specified roles are removed if specified in request payload, else association between User Group and CID Group is dissolved completely (if no roles specified).
DeleteExecutorNodeASPM
Delete a relay node
DeleteExportJobsV1Recon
Delete export jobs (and their associated file(s)) based on their IDs.
DeleteFileQuick Scan Pro
Deletes file by its sha256 identifier.
deleteFirewallPoliciesFirewall Policies
Delete a set of Firewall Policies by specifying their IDs
DeleteGroupASPM
deleteHostGroupsHost Group
Delete a set of Host Groups by specifying their IDs
DeleteImageDetailsFalcon Container
Delete image details from the CrowdStrike registry.
DeleteIntegrationASPM
Delete an existing integration by its ID
DeleteIntegrationTaskASPM
Delete an existing integration task by its ID
deleteIOAExclusionsV1IOA Exclusions
Delete the IOA exclusions by ID.
DeleteIOCIOCs
This operation has been superseded by the IOC.indicator_delete_v1 operation and is no longer used.
DeleteLookupFileNGSIEM
Delete lookup file.
deleteMLExclusionsV1ML Exclusions
Delete the ML exclusions by ID.
DeleteNotificationsV1Recon
Delete notifications based on IDs. Notifications cannot be recovered after they are deleted.
DeleteObjectCustom Storage
Delete the specified object.
DeleteParserNGSIEM
Delete Parser in NGSIEM.
deletePoliciesFileVantage
Deletes 1 or more policies.
DeletePolicyImage Assessment Policies
Delete Image Assessment Policy by policy UUID
DeletePolicyGroupImage Assessment Policies
Delete Image Assessment Policy Group entities
deletePreventionPoliciesPrevention Policy
Delete a set of Prevention Policies by specifying their IDs
DeleteRegistryEntitiesFalcon Container
Delete registry entities by UUID.
DeleteReportFalconx Sandbox
Delete report based on the report ID. Operation can be checked for success by polling for the report ID on the report-summaries endpoint.
deleteRTResponsePoliciesResponse Policies
Delete a set of Response Policies by specifying their IDs
deleteRuleGroupsFileVantage
Deletes 1 or more rule groups.
DeleteRuleMixin0Cloud Policies
Delete a rule.
DeleteRuleOverrideCloud Policies
Delete a rule override.
deleteRulesFileVantage
Deletes 1 or more rules from the specified rule group.
DeleteRulesV1Recon
Delete monitoring rules.
DeleteSampleV2Falconx Sandbox
Removes a sample, including file, meta and submissions from the collection
DeleteSampleV3Sample Uploads
Removes a sample, including file, meta and submissions from the collection.
DeleteSavedQueryNGSIEM
Delete Saved Query in NGSIEM.
DeleteScanResultQuick Scan Pro
Deletes the result of an QuickScan Pro scan.
deleteScheduledExclusionsFileVantage
Deletes 1 or more scheduled exclusions from the provided policy id.
deleteSensorUpdatePoliciesSensor Update Policy
Delete a set of Sensor Update Policies by specifying their IDs.
deleteSensorVisibilityExclusionsV1Sensor Visibility Exclusions
Delete the sensor visibility exclusions by ID.
DeleteSuppressionRulesCloud Policies
Delete Suppression Rules by ID.
DeleteTagsASPM
Remove existing tags
DeleteUserUser Management
Delete a user permanently.
deleteUserGroupMembersMSSP (Flight Control)
Delete User Group members entry.
deleteUserGroupsMSSP (Flight Control)
Delete User Group(s) by ID(s).
deleteUserV1User Management
Delete a user permanently. Supports Flight Control.
DeleteVersionedObjectCustom Storage
Delete the specified versioned object.
DescribeCollectionCustom Storage
Fetch metadata about an existing collection.
DescribeCollectionsCustom Storage
Fetch metadata about one or more existing collections.
DevicesCountIOC
Number of hosts in your customer account that have observed a given custom IOC
DevicesCountIOCs
Number of hosts in your customer account that have observed a given custom IOC.
DevicesRanOnIOC
Find hosts that have observed a given custom IOC. For details about those hosts, use GET /devices/entities/devices/v1
DevicesRanOnIOCs
Find hosts that have observed a given custom IOC. For details about those hosts, use GET /devices/entities/devices/v1.
DiscoverCloudAzureDownloadCertificateD4C Registration
Returns JSON object(s) that contain the base64 encoded certificate for a service principal.
DismissAffectedEntityV3SaaS Security
Dismiss affected entity.
DismissSecurityCheckV3SaaS Security
Dismiss security check.
download_azure_scriptCloud Azure Registration
Download Azure deployment script (Terraform or Bicep).
DownloadExportFileFalcon Container
Download an export file.
DownloadExportFileMixin0Serverless Exports
Download an export file.
DownloadFeedArchiveIntelligence Feeds
Download feed file contents as a zip archive.
DownloadFileDownloads
Gets pre-signed URL for the file.
DownloadSensorInstallerByIdSensor Download
Download sensor installer by SHA256 ID
DownloadSensorInstallerByIdV2Sensor Download
Download sensor installer by SHA256 ID
DownloadSensorInstallerByIdV3Sensor Download
Download sensor installer by SHA256 ID
entities_access_tags_get_v1Case Management
Get access tags.
entities_alert_evidence_post_v1Case Management
Adds the given list of alert evidence to the specified case.
entities_case_tags_delete_v1Case Management
Removes the specified tags from the specified case.
entities_case_tags_post_v1Case Management
Adds the given list of tags to the specified case.
entities_cases_patch_v2Case Management
Updates given fields on the specified case.
entities_cases_post_v2Case Management
Retrieves all Cases given their IDs.
entities_cases_put_v2Case Management
Creates the given Case
entities_classification_delete_v2Data Protection Configuration
Deletes classifications that match the provided ids
entities_classification_get_v2Data Protection Configuration
Gets the classifications that match the provided ids
entities_classification_patch_v2Data Protection Configuration
Update classifications
entities_classification_post_v2Data Protection Configuration
Create classifications
entities_cloud_application_createData Protection Configuration
Persist the given cloud application for the provided entity instance
entities_cloud_application_deleteData Protection Configuration
Delete cloud application.
entities_cloud_application_getData Protection Configuration
Get a particular cloud-application
entities_cloud_application_patchData Protection Configuration
Update a cloud application.
entities_content_pattern_createData Protection Configuration
Persist the given content pattern for the provided entity instance.
entities_content_pattern_deleteData Protection Configuration
Delete content pattern.
entities_content_pattern_getData Protection Configuration
Get a particular content-pattern(s).
entities_content_pattern_patchData Protection Configuration
Update a content pattern.
entities_enterprise_account_createData Protection Configuration
Persist the given enterprise account for the provided entity instance.
entities_enterprise_account_deleteData Protection Configuration
Delete enterprise account.
entities_enterprise_account_getData Protection Configuration
Get a particular enterprise-account(s).
entities_enterprise_account_patchData Protection Configuration
Update a enterprise account.
entities_event_evidence_post_v1Case Management
Adds the given list of event evidence to the specified case.
entities_fields_get_v1Case Management
Get fields by ID
entities_file_details_get_v1Case Management
Get file details by id
entities_file_details_patch_v1Case Management
Update file details
entities_file_type_getData Protection Configuration
Get a particular file-type.
entities_files_bulk_download_post_v1Case Management
Download multiple existing file from case as a ZIP
entities_files_delete_v1Case Management
Delete file details by id
entities_files_download_get_v1Case Management
Download existing file from case
entities_files_upload_post_v1Case Management
Upload file for case
entities_get_rtr_file_metadata_post_v1Case Management
Get metadata for a file via RTR without retrieving it.
entities_knowledge_base_audit_events_v1Knowledge Base Audit Events
Retrieve knowledge base audit event entities by their IDs.
entities_knowledge_base_files_create_v1Knowledge Base Files
Upload a file to a knowledge base.
entities_knowledge_base_files_delete_v1Knowledge Base Files
Delete document from knowledge base.
entities_knowledge_base_files_download_v1Knowledge Base Files
Download knowledge base file entities for the provided id.
entities_knowledge_base_files_update_v1Knowledge Base Files
Update an existing file in a knowledge base. Supports updating file content and optionally its description.
entities_knowledge_base_files_v1Knowledge Base Files
Retrieve knowledge base file entities for the provided id.
entities_knowledge_bases_create_v1Knowledge Bases
Create or update a knowledge base. For deletion, provide knowledge base with IsDeleted=true.
entities_knowledge_bases_update_v1Knowledge Bases
Update an existing knowledge base.
entities_knowledge_bases_v1Knowledge Bases
Retrieve knowledge base entities for the provided id.
entities_latest_rules_get_v1Correlation Rules
Retrieve latest rule versions by rule IDs.
entities_local_application_createData Protection Configuration
Persist the given local application for the provided entity instance.
entities_local_application_deleteData Protection Configuration
Soft Delete local application. The application wont be visible anymore, but will still be in the database.
entities_local_application_getData Protection Configuration
Get a particular local application.
entities_local_application_group_createData Protection Configuration
Persist the given local application group for the provided entity instance.
entities_local_application_group_deleteData Protection Configuration
Soft Delete local application. The application won’t be visible anymore, but will still be in the database.
entities_local_application_group_getData Protection Configuration
Get particular local application groups.
entities_local_application_group_patchData Protection Configuration
Update a local application group.
entities_local_application_patchData Protection Configuration
Update a local application.
entities_notification_groups_delete_v1Case Management
Delete notification groups by ID
entities_notification_groups_delete_v2Case Management
Delete notification groups by ID
entities_notification_groups_get_v1Case Management
Get notification groups by ID
entities_notification_groups_get_v2Case Management
Get notification groups by ID
entities_notification_groups_patch_v1Case Management
Update notification group
entities_notification_groups_patch_v2Case Management
Update notification group
entities_notification_groups_post_v1Case Management
Create notification group
entities_notification_groups_post_v2Case Management
Create notification group
entities_policy_delete_v2Data Protection Configuration
Delete policies that match the provided ids.
entities_policy_get_v2Data Protection Configuration
Get policies that match the provided ids.
entities_policy_patch_v2Data Protection Configuration
Update policies.
entities_policy_post_v2Data Protection Configuration
Create policies.
entities_policy_precedence_post_v1Data Protection Configuration
Update Policy Precedence.
entities_processesIOC
For the provided ProcessID retrieve the process details
entities_processesIOCs
For the provided ProcessID retrieve the process details.
entities_retrieve_rtr_file_post_v1Case Management
Retrieve a file from host using RTR and add it to a case.
entities_retrieve_rtr_recent_file_post_v1Case Management
Retrieve a recently fetched RTR file and add it to a case.
entities_rule_versions_delete_v1Correlation Rules
Delete versions by IDs.
entities_rule_versions_export_post_v1Correlation Rules
Export rule versions.
entities_rule_versions_import_post_v1Correlation Rules
Import rule versions.
entities_rule_versions_publish_patch_v1Correlation Rules
Publish existing rule version.
entities_rules_delete_v1Correlation Rules
Delete rules by IDs.
entities_rules_get_v1Correlation Rules
Retrieve rules by IDs.
entities_rules_get_v2Correlation Rules
Retrieve rule versions by IDs.
entities_rules_ownership_put_v1Correlation Rules Admin
Change the owner of an existing Correlation Rule
entities_rules_patch_v1Correlation Rules
Update a correlation rule.
entities_rules_post_v1Correlation Rules
Create a correlation rule.
entities_sensitivity_label_create_v2Data Protection Configuration
Create new sensitivity label (V2).
entities_sensitivity_label_delete_v2Data Protection Configuration
Delete sensitivity labels matching the IDs (V2).
entities_sensitivity_label_get_v2Data Protection Configuration
Get sensitivity label matching the IDs (V2).
entities_slas_delete_v1Case Management
Delete SLAs
entities_slas_get_v1Case Management
Get SLAs by ID
entities_slas_patch_v1Case Management
Update SLA
entities_slas_post_v1Case Management
Create SLA
entities_states_v1Device Content
Retrieve the host content state for a number of ids between 1 and 100.
entities_template_snapshots_get_v1Case Management
Get template snapshots
entities_templates_delete_v1Case Management
Delete templates
entities_templates_export_get_v1Case Management
Export templates to files in a zip archive
entities_templates_get_v1Case Management
Get templates by ID
entities_templates_get_v1Mixin0Correlation Rules
Retrieve rule templates by IDs.
entities_templates_import_post_v1Case Management
Import a template from a file
entities_templates_patch_v1Case Management
Update template
entities_templates_post_v1Case Management
Create template
entities_templates_rules_post_v1Correlation Rules
Create rule from template.
entities_vertices_getThreatGraph
Retrieve metadata for a given vertex ID.
entities_vertices_getv2ThreatGraph
Retrieve metadata for a given vertex ID.
entities_web_location_create_v2Data Protection Configuration
Persist the given web-locations.
entities_web_location_delete_v2Data Protection Configuration
Delete web-location.
entities_web_location_get_v2Data Protection Configuration
Get web-location entities matching the provided ID(s).
entities_web_location_patch_v2Data Protection Configuration
Update a web-location.
entitiesRolesGETV2User Management
Get info about a role.
entitiesRolesV1User Management
Get info about a role, supports Flight Control.
EnumerateFileDownloads
Enumerates a list of files available for CID.
exclusions_aggregates_v2ML Exclusions
Get exclusion aggregates as specified via json in request body.
exclusions_create_v2ML Exclusions
Create the exclusions, with ancestor fields.
exclusions_delete_v2ML Exclusions
Delete the exclusions by id, with ancestor fields.
exclusions_get_all_v2ML Exclusions
Get all exclusions.
exclusions_get_reports_v2ML Exclusions
Create a report of ML exclusions scoped by the given filters.
exclusions_get_v2ML Exclusions
Get the exclusions by id, with ancestor fields.
exclusions_perform_action_v2ML Exclusions
Actions used to manipulate the content of exclusions, with ancestor fields.
exclusions_search_v2ML Exclusions
Search for exclusions, with ancestor fields.
exclusions_update_v2ML Exclusions
Update the exclusions by id, with ancestor fields.
ExecuteCommandAPI Integrations
Execute a command.
ExecuteCommandProxyAPI Integrations
Execute a command and proxy the response directly.
ExecuteFunctionDataASPM
A selected list of queryLanguage queries.
ExecuteFunctionDataCountASPM
A selected list of queryLanguage count queries.
ExecuteFunctionDataQueryASPM
A selected list of queryLanguage queries.
ExecuteFunctionDataQueryCountASPM
A selected list of queryLanguage count queries.
ExecuteFunctionsASPM
A selected list of queryLanguage services queries.
ExecuteFunctionsCountASPM
A selected list of queryLanguage count queries.
ExecuteFunctionsOvertimeASPM
A selected list of queryLanguage overtime queries.
ExecuteFunctionsQueryASPM
A selected list of queryLanguage services queries.
ExecuteFunctionsQueryCountASPM
A selected list of queryLanguage count queries.
ExecuteFunctionsQueryOvertimeASPM
A selected list of queryLanguage overtime queries.
ExecuteQueryASPM
Execute a query. The syntax used is identical to that of the query page.
extAggregateClusterAssessmentsContainer Image Compliance
Get the assessments for each cluster.
extAggregateFailedContainersByRulesPathContainer Image Compliance
Get the containers grouped into rules on which they failed.
extAggregateFailedContainersCountBySeverityContainer Image Compliance
Get the failed containers count grouped into severity levels.
extAggregateFailedImagesByRulesPathContainer Image Compliance
Get the images grouped into rules on which they failed.
extAggregateFailedImagesCountBySeverityContainer Image Compliance
Get the failed images count grouped into severity levels.
extAggregateFailedRulesByClustersContainer Image Compliance
Get the failed rules for each cluster grouped into severity levels.
extAggregateFailedRulesByImagesContainer Image Compliance
Get images with failed rules, rule count grouped by severity for each image.
extAggregateFailedRulesCountBySeverityContainer Image Compliance
Get the failed rules count grouped into severity levels.
extAggregateImageAssessmentsContainer Image Compliance
Get the assessments for each image.
extAggregateRulesAssessmentsContainer Image Compliance
Get the assessments for each rule.
extAggregateRulesByStatusContainer Image Compliance
Get the rules grouped by their statuses.
ExternalCreateConnectorConfigNGSIEM
Create a new configuration for a data connector.
ExternalCreateDataConnectionNGSIEM
Create a new data connection.
ExternalDeleteConnectorConfigsNGSIEM
Delete data connection config.
ExternalDeleteDataConnectionNGSIEM
Delete a data connection.
ExternalGetDataConnectionByIDNGSIEM
Get data connection by ID.
ExternalGetDataConnectionStatusNGSIEM
Get data connection provisioning status.
ExternalGetDataConnectionTokenNGSIEM
Get Ingest token for data connection.
ExternalListConnectorConfigsNGSIEM
List configurations for a data connector.
ExternalListDataConnectionsNGSIEM
List and search data connections.
ExternalListDataConnectorsNGSIEM
List available data connectors.
ExternalPatchConnectorConfigNGSIEM
Patch configurations for a data connector.
ExternalRegenerateDataConnectionTokenNGSIEM
Regenerate Ingest token for data connection.
ExternalUpdateDataConnectionNGSIEM
Update a data connection.
ExternalUpdateDataConnectionStatusNGSIEM
Update data connection status.
ExtractionCreateV1Sample Uploads
Extracts files from an uploaded archive and copies them to internal storage making it available for content analysis.
ExtractionGetV1Sample Uploads
Retrieves the files extraction operation statuses.
ExtractionListV1Sample Uploads
Retrieves the files extractions in chunks.
fdrschema_combined_event_getFDR
Fetches the combined schema.
fdrschema_entities_event_getFDR
Fetch event schema by ID.
fdrschema_entities_field_getFDR
Fetch field schema by ID.
fdrschema_queries_event_getFDR
Get list of event IDs given a particular query.
fdrschema_queries_field_getFDR
Get list of field IDs given a particular query.
FetchFilesDownloadInfoDownloads
Get files info and pre-signed download URLs
FetchFilesDownloadInfoV2Downloads
Get cloud security tools info and pre-signed download URLs
FindContainersByContainerRunTimeVersionKubernetes Protection
Retrieve containers by container_runtime_version
FindContainersCountAffectedByZeroDayVulnerabilitiesKubernetes Protection
Retrieve containers count affected by zero day vulnerabilities
get_accountsDiscover
Get details on accounts by providing one or more IDs.
get_applicationsDiscover
Get details on applications by providing one or more IDs.
get_ecosystem_subsidiariesExposure Management
Retrieves detailed information about ecosystem subsidiaries by ID.
get_eventsFirewall Management
Get events entities by ID and optionally version
get_external_assetsExposure Management
Get details on external assets by providing one or more IDs.
get_firewall_fieldsFirewall Management
Get the firewall field specifications by ID
get_global_configsNetwork Scan Global Configs
Get “global-configs” for the CID
get_hostsDiscover
Get details on assets by providing one or more IDs.
get_iot_hostsDiscover
Get details on IoT assets by providing one or more IDs.
get_loginsDiscover
Get details on logins by providing one or more IDs.
get_malicious_files_by_idsODS (On Demand Scan)
Get malicious files by ids.
get_network_locationsFirewall Management
Get a summary of network locations entities by ID
get_network_locations_detailsFirewall Management
Get network locations entities by ID
get_networksNetwork Scan Networks
Get “networks” by their IDs
get_patternsCustom IOA
Get pattern severities by ID.
get_platformsFirewall Management
Get platforms by ID, e.g., windows or mac or droid
get_platformsMixin0Custom IOA
Get platforms by ID.
get_policy_containersFirewall Management
Get policy container entities by policy ID
get_policy_rulesIdentity Protection
Get policy rules.
get_policy_rules_queryIdentity Protection
Query policy rule IDs.
get_rule_groupsFirewall Management
Get rule group entities by ID. These groups do not contain their rule entites, just the rule IDs in precedence order.
get_rule_groupsMixin0Custom IOA
Get rule groups by ID.
get_rule_typesCustom IOA
Get rule types by ID.
get_rulesFirewall Management
Get rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string)
get_rules_getCustom IOA
Get rules by ID and optionally version in the following format: ID[:version].
get_rulesMixin0Custom IOA
Get rules by ID and optionally version in the following format: ID[:version]. The max number of IDs is constrained by URL size.
get_scan_host_metadata_by_idsODS (On Demand Scan)
Get scan hosts by ids.
get_scan_run_reportsNetwork Scan Scan Run Reports
Downloads scan run report in CSV format
get_scan_runsNetwork Scan Scan Runs
Get “scan-runs” by their IDs
get_scannersNetwork Scan Scanners
Get “scanners” by their IDs
get_scansNetwork Scan Scans
Get “scans” by their IDs
get_scans_by_scan_ids_v1ODS (On Demand Scan)
Get Scans by IDs.
get_scans_by_scan_ids_v2ODS (On Demand Scan)
Get Scans by IDs.
get_scheduled_scans_by_scan_idsODS (On Demand Scan)
Get ScheduledScans by IDs.
get_template_configsNetwork Scan Templates
Get details on the network scan template configurations
get_templatesNetwork Scan Templates
Get “templates” by their IDs
get_zonesNetwork Scan Zones
Get “zones” by their IDs
getActionsMixin0FileVantage
Retrieves the processing results for one or more actions.
GetActionsV1Recon
Get actions based on their IDs. IDs can be retrieved using the QueryActionsV1 operation.
GetActivityMonitorV3SaaS Security
Get activity monitor.
GetAggregateDetectsDetects
Get detect aggregates as specified via json in request body.
GetAggregateFilesQuarantine
Get quarantine file aggregates as specified via json in request body.
GetAlertsV3SaaS Security
Get alerts.
GetAppInventorySaaS Security
Get application inventory.
GetAppInventoryUsersSaaS Security
Get application inventory users.
GetArchiveExportCAO Hunting
Creates an Archive Export.
GetArtifactsFalconx Sandbox
Download IOC packs, PCAP files, and other analysis artifacts.
getAssessmentsByScoreV1Zero Trust Assessment
Get Zero Trust Assessment data for one or more hosts by providing a customer ID (CID) and a range of scores.
getAssessmentV1Zero Trust Assessment
Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID) and a customer ID (CID).
GetAssetInventoryV3SaaS Security
Get asset inventory.
getAuditV1Zero Trust Assessment
Get the Zero Trust Assessment audit report for one customer ID (CID).
GetAvailableRoleIdsUser Management
Show role IDs for all roles available in your customer account. For more information on each role, provide the role ID to GetRoles.
GetAWSAccountsCloud Connect AWS
Retrieve a set of AWS Accounts by specifying their IDs
GetAWSAccountsKubernetes Protection
Provides a list of AWS accounts.
GetAWSSettingsCloud Connect AWS
Retrieve a set of Global Settings which are applicable to all provisioned AWS accounts
GetAzureInstallScriptKubernetes Protection
Provide the script to run for a given tenant id and subscription IDs.
GetAzureTenantConfigKubernetes Protection
Returns the Azure tenant config.
GetAzureTenantIDsKubernetes Protection
Provides all the azure subscriptions and tenants IDs.
GetBehaviorDetectionsCSPM Registration
Retrieve a list of detected behaviors.
GetCaseActivityByIdsMessage Center
Retrieve activities for given id’s
GetCaseEntitiesByIDsMessage Center
Retrieve message center cases
getChangesFileVantage
Retrieve information on changes.
getChildrenMSSP (Flight Control)
Get link to child customer by child CID(s)
getChildrenV2MSSP (Flight Control)
Get link to child customer by child CID(s)
getCIDGroupByIdMSSP (Flight Control)
Get CID Groups by ID.
getCIDGroupByIdV1MSSP (Flight Control)
Get CID Group(s) by ID(s).
getCIDGroupMembersByMSSP (Flight Control)
Get CID group members by CID Group ID.
getCIDGroupMembersByV1MSSP (Flight Control)
Get CID Group members by CID Group IDs.
getCloudEventIDsCSPM Registration
Get list of related cloud event LogScale IDs for a given IOA
GetCloudSecurityIntegrationStateASPM
Get Cloud Security integration state.
GetClustersKubernetes Protection
Provides the clusters acknowledged by the Kubernetes Protection service
getCombinedAssessmentsQueryConfiguration Assessment
Search for assessments in your environment by providing an FQL filter and paging details. Returns a set of HostFinding entities which match the filter criteria
getCombinedAssessmentsQueryZero Trust Assessment
Search for assessments in your environment by providing an FQL filter and paging details. Returns a set of HostFinding entities which match the filter criteria
GetCombinedCloudClustersKubernetes Protection
Returns a combined list of provisioned cloud accounts and known kubernetes clusters.
GetCombinedImagesContainer Images
Get image assessment results by providing an FQL filter and paging details
GetCombinedImagesFalcon Container
Retrieve registry entities identified by the customer ID.
GetCombinedPluginConfigsAPI Integrations
Queries for config resources and returns details
GetCombinedSensorInstallersByQuerySensor Download
Get sensor installer details by provided query
GetCombinedSensorInstallersByQueryV2Sensor Download
Get sensor installer details by provided query
GetCombinedSensorInstallersByQueryV3Sensor Download
Get sensor installer details by provided query
GetCombinedVulnerabilitiesSARIFServerless Vulnerabilities
Retrieve all lambda vulnerabilities that match the given query and return in the SARIF format.
GetComplianceControlsCloud Policies
Get compliance controls by ID.
GetComplianceFrameworksCloud Policies
Get compliance frameworks by ID.
GetConfigurationDetectionEntitiesCSPM Registration
Get misconfigurations based on the ID - including custom policy detections in addition to default policy detections.
GetConfigurationDetectionIDsV2CSPM Registration
Get a list of active misconfiguration ids - including custom policy detections in addition to default policy detections.
GetConfigurationDetectionsCSPM Registration
Retrieve a list of active misconfigurations.
getContentsFileVantage
Retrieves the content captured for the provided change ID.
getContentUpdatePoliciesContent Update Policies
Retrieve a set of Content Update Policies by specifying their IDs.
GetCredentialsFalcon Container
Gets the registry credentials.
GetCredentialsIACCloud Snapshots
Gets the registry credentials (external endpoint).
GetCredentialsMixin0Cloud Snapshots
Gets the registry credentials.
GetCSPMAwsAccountCSPM Registration
Returns information about the current status of an AWS account.
GetCSPMAwsAccountScriptsAttachmentCSPM Registration
Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetCSPMAwsConsoleSetupURLsCSPM Registration
Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetCSPMAzureAccountCSPM Registration
Return information about Azure account registration
GetCSPMAzureManagementGroupCSPM Registration
Return information about Azure management group registration
GetCSPMAzureUserScriptsAttachmentCSPM Registration
Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment
GetCSPMCGPAccountCSPM Registration
Returns information about the current status of an GCP account.
GetCSPMGCPServiceAccountsExtCSPM Registration
Returns the service account id and client email for external clients.
GetCSPMGCPUserScriptsAttachmentCSPM Registration
Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment
GetCSPMGCPUserScriptsAttachmentD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment.
GetCSPMGCPValidateAccountsExtCSPM Registration
Run a synchronous health check.
GetCSPMPoliciesDetailsCSPM Registration
Given an array of policy IDs, returns detailed policies information.
GetCSPMPolicyCSPM Registration
Given a policy ID, returns detailed policy information.
GetCSPMPolicySettingsCSPM Registration
Returns information about current policy settings.
GetCSPMScanScheduleCSPM Registration
Returns scan schedule configuration for one or more cloud platforms.
GetD4CAwsAccountD4C Registration
Returns information about the current status of an AWS account.
GetD4CAWSAccountScriptsAttachmentD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetD4CAwsConsoleSetupURLsD4C Registration
Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetD4CCGPAccountD4C Registration
Returns information about the current status of an GCP account.
GetD4CGCPServiceAccountsExtD4C Registration
Returns the service account id and client email for external clients.
GetD4CGCPUserScriptsD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their GCP environment.
GetD4CGCPUserScriptsAttachmentD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment.
GetDashboardTemplateNGSIEM
Get dashboard template by ID.
getDefaultDeviceControlPoliciesDevice Control Policies
Retrieve the configuration for the Default Device Control Policy.
getDefaultDeviceControlSettingsDevice Control Policies
Get default device control settings (USB and Bluetooth).
GetDeliverySettingsDelivery Settings
Get Delivery Settings.
GetDeploymentsExternalV1Deployments
Get deployment resources by IDs.
GetDetectSummariesDetects
View information about detections.
getDeviceControlPoliciesDevice Control Policies
Retrieve a set of Device Control Policies by specifying their IDs.
getDeviceControlPoliciesV2Device Control Policies
Get device control policies for the given filter criteria. Supports USB and Bluetooth.
GetDeviceCountCollectionQueriesByFilterFalcon Complete Dashboard
Retrieve device count collection Ids that match the provided FQL filter, criteria with scrolling enabled
GetDeviceInventoryV3SaaS Security
Get device inventory.
GetDiscoverCloudAzureAccountD4C Registration
Return information about Azure account registration.
GetDiscoverCloudAzureTenantIDsD4C Registration
Return all available Azure tenant IDs.
GetDiscoverCloudAzureUserScriptsD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their Azure environment.
GetDiscoverCloudAzureUserScriptsAttachmentD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment.
GetDriftIndicatorsValuesByDateDrift Indicators
Returns the count of Drift Indicators by the date. by default it’s for 7 days.
GetEnrichedAssetCloud Policies
Get enriched assets that combine a primary resource with all its related resources.
GetEntityIDsByQueryPOSTDeployments
Returns the release notes for the IDs in the request.
GetEntityIDsByQueryPOSTV2Deployments
Get entity IDs by query (v2).
getEvaluationLogicSpotlight Evaluation Logic
Get details on evaluation logic items by providing one or more IDs.
getEvaluationLogicMixin0Configuration Assessment Evaluation Logic
Get details on evaluation logic items by providing one or more finding IDs.
GetEvaluationResultCloud Policies
Get evaluation results based on the provided rule.
GetEventsBodyTailored Intelligence
Get event body for the provided event ID
GetEventsEntitiesTailored Intelligence
Get events entities for specified ids.
GetExecutorNodesASPM
Get all the relay nodes
GetExecutorNodesMetadataASPM
Get metadata about all executor nodes.
GetExportJobsV1Recon
Get the status of export jobs based on their IDs. Export jobs can be launched by calling CreateExportJobsV1. When a job is complete, use the job ID to download the file(s) associated with it using GetFileContentForExportJobsV1.
GetFileContentForExportJobsV1Recon
Download the file associated with a job ID.
getFirewallPoliciesFirewall Policies
Retrieve a set of Firewall Policies by specifying their IDs
GetGroupHierarchyASPM
Get group hierarchy
GetGroupsV2ASPM
GetGroupV2ASPM
Get group details
GetHelmValuesYamlKubernetes Protection
Provides a sample Helm values.yaml file for a customer to install alongside the agent Helm chart
GetHorizonD4CScriptsD4C Registration
Returns static install scripts for Horizon.
getHostGroupsHost Group
Retrieve a set of Host Groups by specifying their IDs
GetHostMigrationIDsV1Host Migration
Query host migration IDs.
GetHostMigrationsV1Host Migration
Get host migration details.
GetHuntingGuidesCAO Hunting
Retrieves a list of Hunting Guides
GetImageAssessmentReportFalcon Container
Retrieve an assessment report for an image by specifying repository and tag.
GetIndicatorsReportIOC
Launch an indicators report creation job
GetIntegrationsASPM
Get a list of all the integrations
GetIntegrationsV2ASPM
Get a list of all the integrations.
GetIntegrationsV3SaaS Security
Get integrations.
GetIntegrationTasksASPM
Get all the integration tasks
GetIntegrationTasksAdminASPM
Get all the integration tasks, requires admin scope
GetIntegrationTasksMetadataASPM
Get metadata about all integration tasks.
GetIntegrationTasksV2ASPM
Get all the integration tasks.
GetIntegrationTypesASPM
Get all the integration types
GetIntelActorEntitiesIntel
Retrieve specific actors using their actor IDs.
GetIntelIndicatorEntitiesIntel
Retrieve specific indicators using their indicator IDs.
GetIntelligenceQueriesCAO Hunting
Retrieves a list of Intelligence queries.
GetIntelReportEntitiesIntel
Retrieve specific reports using their report IDs.
GetIntelReportPDFIntel
Return a Report PDF attachment
GetIntelRuleEntitiesIntel
Retrieve details for rule sets for the specified ids.
GetIntelRuleFileIntel
Download earlier rule sets.
getIOAExclusionsV1IOA Exclusions
Get a set of IOA Exclusions by specifying their IDs.
GetIOCIOCs
This operation has been superseded by the IOC.indicator_get_v1 operation and is no longer used.
GetLatestIntelRuleFileIntel
Download the latest rule set.
GetLocationsKubernetes Protection
Provides the cloud locations acknowledged by the Kubernetes Protection service
GetLookupFileNGSIEM
Get lookup file by ID.
GetLookupFromPackageV1NGSIEM
Download lookup file in package from NGSIEM.
GetLookupFromPackageWithNamespaceV1NGSIEM
Download lookup file in namespaced package from NGSIEM.
GetLookupV1NGSIEM
Download lookup file from NGSIEM.
GetMalQueryDownloadV1MalQuery
Download a file indexed by MalQuery. Specify the file using its SHA256. Only one file is supported at this time
GetMalQueryEntitiesSamplesFetchV1MalQuery
Fetch a zip archive with password ‘infected’ containing the samples. Call this once the /entities/samples-multidownload request has finished processing
GetMalQueryMetadataV1MalQuery
Retrieve indexed files metadata by their hash
GetMalQueryQuotasV1MalQuery
Get information about search and download quotas in your environment
GetMalQueryRequestV1MalQuery
Check the status and results of an asynchronous request, such as hunt or exact-search. Supports a single request id at this time.
GetMalwareEntitiesIntel
Get malware entities for specified IDs.
GetMalwareMitreReportIntel
Export Mitre ATT&CK information for a given malware family.
GetMemoryDumpFalconx Sandbox
Get memory dump content, as a binary.
GetMemoryDumpExtractedStringsFalconx Sandbox
Get extracted strings from a memory dump.
GetMemoryDumpHexDumpFalconx Sandbox
Get the hex view of a memory dump.
GetMetricsV3SaaS Security
Get metrics.
GetMigrationDestinationsV1Host Migration
Get destinations for a migration.
GetMigrationIDsV1Host Migration
Query migration jobs.
GetMigrationsV1Host Migration
Get migration job details.
GetMitreReportIntel
Export Mitre ATT&CK information for a given actor.
getMLExclusionsV1ML Exclusions
Get a set of ML Exclusions by specifying their IDs.
GetNotificationsDetailedTranslatedV1Recon
Get detailed notifications based on their IDs. These include the raw intelligence content that generated the match. This endpoint will return translated notification content. The only target language available is English. A single notification can be translated per request.
GetNotificationsDetailedV1Recon
Get detailed notifications based on their IDs. These include the raw intelligence content that generated the match.
GetNotificationsExposedDataRecordsV1Recon
Get notifications exposed data records based on their IDs. IDs can be retrieved using the QueryNotificationsExposedDataRecordsV1 operation. The associated notification can be fetched using the notifications operations.
GetNotificationsTranslatedV1Recon
Get notifications based on their IDs. IDs can be retrieved using the QueryNotificationsV1 operation. This endpoint will return translated notification content. The only target language available is English.
GetNotificationsV1Recon
Get notifications based on their IDs. IDs can be retrieved using the QueryNotificationsV1 operation.
GetObjectCustom Storage
Get the bytes for the specified object.
GetObjectMetadataCustom Storage
Get the metadata for the specified object.
GetOnlineState_V1Hosts
Get online status for one or more hosts.
GetParserNGSIEM
Get parser by ID.
GetParserTemplateNGSIEM
Get parser template by ID.
getPoliciesFileVantage
Retrieves the configuration for 1 or more policies.
getPreventionPoliciesPrevention Policy
Retrieve a set of Prevention Policies by specifying their IDs
GetQuarantineFilesQuarantine
Get quarantine file metadata for specified ids.
GetQueriesAlertsV1Alerts
Search for alert IDs that match a given query.
GetQueriesAlertsV2Alerts
Search for alert IDs that match a given query.
getRemediationsSpotlight Vulnerabilities
Get details on remediations by providing one or more IDs.
getRemediationsV2Spotlight Vulnerabilities
Get details on remediation by providing one or more IDs.
GetReportByReferenceFalcon Container
Retrieve a report by its reference.
GetReportByScanIDFalcon Container
Retrieve a report by scan ID.
GetReportsFalconx Sandbox
Get a full sandbox report.
GetRolesUser Management
Get info about a role.
getRolesByIDMSSP (Flight Control)
Get MSSP Role assignment(s). MSSP Role assignment is of the format: <user_group_id>.<cid_group_id>.
getRTResponsePoliciesResponse Policies
Retrieve a set of Response Policies by specifying their IDs
GetRuleCloud Policies
Get a rule by id.
getRuleDetailsConfiguration Assessment
Get rules details for provided one or more rule IDs
getRuleGroupsFileVantage
Retrieves the rule group details for 1 or more rule groups.
GetRuleInputSchemaCloud Policies
Get rule input schema for given resource type.
GetRuleOverrideCloud Policies
Get a rule override by ID.
getRulesFileVantage
Retrieves the configuration for 1 or more rules.
GetRulesEntitiesTailored Intelligence
Get rules entities for specified ids.
getRulesMetadataByIDKubernetes Container Compliance
Retrieve detailed compliance rule information by ID. Includes descriptions, remediation steps, and audit procedures by specifying rule identifiers.
GetRulesV1Recon
Get monitoring rules rules by provided IDs.
GetRuntimeDetectionsCombinedV2Container Detections
Retrieve image assessment detections identified by the provided filter criteria.
GetSampleV2Falconx Sandbox
Retrieves the file associated with the given ID (SHA256)
GetSampleV3Sample Uploads
Retrieves the file associated with the given ID (SHA256).
GetSavedQueryTemplateNGSIEM
Retrieve Saved Query in NGSIEM as LogScale YAML Template by ID.
GetSavedSearchesExecuteV1Foundry LogScale
Get the results of a saved search
GetSavedSearchesJobResultsDownloadV1Foundry LogScale
Get the results of a saved search as a file
GetScanReportCloud Snapshots
Retrieve the scan report for an instance.
GetScanResultQuick Scan Pro
Gets the result of an QuickScan Pro scan.
GetScansQuick Scan
Check the status of a volume scan. Time required for analysis increases with the number of samples in a volume but usually it should take less than 1 minute
GetScansAggregatesQuick Scan
Get scans aggregations as specified via json in request body.
getScheduledExclusionsFileVantage
Retrieves the configuration of 1 or more scheduled exclusions from the provided policy id.
GetSchemaCustom Storage
Get the bytes of the specified schema of the requested collection.
GetSchemaMetadataCustom Storage
Get the metadata for the specified schema of the requested collection.
GetSearchStatusV1NGSIEM
Get status of a NGSIEM search.
GetSecurityCheckAffectedV3SaaS Security
Get affected resources for security checks.
GetSecurityCheckComplianceV3SaaS Security
Get security check compliance.
GetSecurityChecksV3SaaS Security
Get security checks.
GetSensorAggregatesIdentity Protection
Get sensor aggregates as specified via json in request body.
GetSensorDetailsIdentity Protection
Get details on one or more sensors by providing device IDs in a POST body. Supports up to a maximum of 5000 IDs.
GetSensorInstallersByQuerySensor Download
Get sensor installer IDs by provided query
GetSensorInstallersByQueryV2Sensor Download
Get sensor installer IDs by provided query
GetSensorInstallersByQueryV3Sensor Download
Get sensor installer IDs by provided query
GetSensorInstallersCCIDByQuerySensor Download
Get CCID to use with sensor installers
GetSensorInstallersEntitiesSensor Download
Get sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV2Sensor Download
Get sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV3Sensor Download
Get sensor installer details by provided SHA256 IDs
getSensorUpdatePoliciesSensor Update Policy
Retrieve a set of Sensor Update Policies by specifying their IDs.
getSensorUpdatePoliciesV2Sensor Update Policy
Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs.
GetSensorUsageHourlySensor Usage
Fetches hourly average. Each data point represents the average of how many unique AIDs were seen per hour for the previous 28 days.
GetSensorUsageWeeklySensor Usage
Fetches weekly average. Each data point represents the average of how many unique AIDs were seen per week for the previous 28 days.
getSensorVisibilityExclusionsV1Sensor Visibility Exclusions
Get a set of Sensor Visibility Exclusions by specifying their IDs.
getServiceArtifactsASPM
Retrieve service artifacts.
GetServicesCountASPM
Get the total amount of existing services
GetServiceViolationTypesASPM
Get the different types of violation
GetStaticScriptsKubernetes Protection
Get static bash scripts that are used during registration.
GetSubmissionsFalconx Sandbox
Check the status of a sandbox analysis. Time required for analysis varies but is usually less than 15 minutes.
GetSummaryReportsFalconx Sandbox
Get a short summary version of a sandbox report.
GetSupportedSaasV3SaaS Security
Get supported SaaS applications.
GetSuppressionRulesCloud Policies
Get Suppression Rules by ID.
GetSystemLogsV3SaaS Security
Get system logs.
GetSystemUsersV3SaaS Security
Get system users.
GetTagsASPM
Get all the tags
getUserGroupMembersByIDMSSP (Flight Control)
Get User Group members by User Group ID(s).
getUserGroupMembersByIDV1MSSP (Flight Control)
Get User Group members by User Group ID(s).
getUserGroupsByIDMSSP (Flight Control)
Get User Group by ID(s).
getUserGroupsByIDV1MSSP (Flight Control)
Get user groups by ID.
getUserGroupsByIDV2MSSP (Flight Control)
Get user groups by ID.
GetUserInventoryV3SaaS Security
Get user inventory.
GetUserRoleIdsUser Management
Show role IDs of roles assigned to a user. For more information on each role, provide the role ID to GetRoles.
GetUsersV2ASPM
List users
GetVersionedObjectCustom Storage
Get the bytes for the specified object.
GetVersionedObjectMetadataCustom Storage
Get the metadata for the specified object.
GetVulnerabilitiesIntel
Get vulnerabilities
getVulnerabilitiesSpotlight Vulnerabilities
Get details on vulnerabilities by providing one or more IDs.
GrantUserRoleIdsUser Management
Assign one or more roles to a user.
GroupContainersByManagedKubernetes Protection
Group the containers by Managed
HeadImageScanInventoryFalcon Container
Get headers for POST request for image scan inventory.
highVolumeQueryChangesFileVantage
Returns 1 or more change ids.
HostMigrationAggregatesV1Host Migration
Get host migration aggregates as specified via json in request body.
HostMigrationsActionsV1Host Migration
Perform an action on host migrations.
ImageMatchesPolicyFalcon Container
Check if an image matches a policy by specifying repository and tag.
incrementUninstallTokenSensor Update Policy
Increment a bulk maintenance token.
indicator_aggregate_v1IOC
Get Indicators aggregates as specified via json in the request body.
indicator_combined_v1IOC
Get Combined for Indicators.
indicator_create_v1IOC
Create Indicators.
indicator_delete_v1IOC
Delete Indicators by ids.
indicator_get_device_count_v1IOC
Number of hosts in your customer account that have observed a given custom IOC
indicator_get_devices_ran_on_v1IOC
Find hosts that have observed a given custom IOC. For details about those hosts, use GET /devices/entities/devices/v1
indicator_get_processes_ran_on_v1IOC
Search for processes associated with a custom IOC
indicator_get_v1IOC
Get Indicators by ids.
indicator_search_v1IOC
Search for Indicators.
indicator_update_v1IOC
Update Indicators.
IngestDataAsyncV1Foundry LogScale
Ingest data into the application repository asynchronously
IngestDataV1Foundry LogScale
Ingest data into the application repository
InstallParserNGSIEM
Install a CrowdStrike-managed out-of-the-box (OOTB) parser.
IntegrationBuilderEndTransactionV3SaaS Security
End integration builder transaction.
IntegrationBuilderGetStatusV3SaaS Security
Get integration builder status.
IntegrationBuilderResetV3SaaS Security
Reset integration builder.
IntegrationBuilderUploadV3SaaS Security
Upload integration builder.
ioc_type_query_v1IOC
Query IOC Types.
ITAutomationCancelTaskExecutionIT Automation
Cancel a task execution
ITAutomationCombinedScheduledTasksIT Automation
Returns full details of scheduled tasks matching the filter query parameter
ITAutomationCreatePolicyIT Automation
Create a new policy of the specified type
ITAutomationCreateScheduledTaskIT Automation
Create a scheduled task from the given request
ITAutomationCreateTaskIT Automation
Create a task with details from the given request
ITAutomationCreateTaskGroupIT Automation
Create a task group
ITAutomationCreateUserGroupIT Automation
Creates a user group from the given request
ITAutomationDeletePolicyIT Automation
Delete a policy
ITAutomationDeleteScheduledTasksIT Automation
Delete scheduled tasks
ITAutomationDeleteTaskIT Automation
Delete a task
ITAutomationDeleteTaskGroupsIT Automation
Delete task groups
ITAutomationDeleteUserGroupIT Automation
Deletes user groups for each provided ids
ITAutomationGetAssociatedTasksIT Automation
Retrieve tasks associated with the provided file ID
ITAutomationGetExecutionResultsIT Automation
Retrieve execution results
ITAutomationGetExecutionResultsSearchStatusIT Automation
Retrieve execution results search status
ITAutomationGetPoliciesIT Automation
Retrieve policies
ITAutomationGetScheduledTasksIT Automation
Retrieve scheduled tasks
ITAutomationGetTaskExecutionIT Automation
Retrieve a task execution
ITAutomationGetTaskExecutionHostStatusIT Automation
Retrieve task execution host status
ITAutomationGetTaskExecutionsByQueryIT Automation
Retrieve task executions by query
ITAutomationGetTaskGroupsIT Automation
Retrieve task groups
ITAutomationGetTaskGroupsByQueryIT Automation
Retrieve task groups by query
ITAutomationGetTasksIT Automation
Retrieve tasks
ITAutomationGetTasksByQueryIT Automation
Retrieve tasks by query
ITAutomationGetUserGroupIT Automation
Returns user groups for each provided id
ITAutomationQueryPoliciesIT Automation
Query policies
ITAutomationRerunTaskExecutionIT Automation
Rerun the task execution specified in the request
ITAutomationRunLiveQueryIT Automation
Start a new task execution from the provided query data in the request and return the initiated task executions
ITAutomationSearchScheduledTasksIT Automation
Search scheduled tasks
ITAutomationSearchTaskExecutionsIT Automation
Search task executions
ITAutomationSearchTaskGroupsIT Automation
Search task groups
ITAutomationSearchTasksIT Automation
Search tasks
ITAutomationSearchUserGroupIT Automation
Returns the list of user group ids matching the filter query parameter. It can be used together with the entities endpoint to retrieve full information on user groups
ITAutomationStartExecutionResultsSearchIT Automation
Start an asynchronous task execution results search
ITAutomationStartTaskExecutionIT Automation
Start a new task execution from an existing task provided in the request and returns the initiated task executions
ITAutomationUpdatePoliciesIT Automation
Update a new policy of the specified type
ITAutomationUpdatePoliciesPrecedenceIT Automation
Update policies precedence
ITAutomationUpdatePolicyHostGroupsIT Automation
Update policy host groups
ITAutomationUpdateScheduledTaskIT Automation
Update an existing scheduled task with the supplied info
ITAutomationUpdateTaskIT Automation
Update a task with details from the given request
ITAutomationUpdateTaskGroupIT Automation
Update a task group for a given ID
ITAutomationUpdateUserGroupIT Automation
Update a user group for a given id
LaunchExportJobFalcon Container
Launch an export job of a Container Security resource. Maximum of 1 job in progress per resource.
LaunchExportJobMixin0Serverless Exports
Launch an export job of a Lambda Security resource.
LaunchScanQuick Scan Pro
Starts scanning a file uploaded through UploadFileQuickScanPro.
listAvailableStreamsOAuth2Event Streams
Discover all event streams in your environment
ListAzureAccountsKubernetes Protection
Provides the azure subscriptions registered to Kubernetes Protection.
ListCloudGroupIDsExternalCloud Security
Query Cloud Groups and return only their IDs.
ListCloudGroupsByIDExternalCloud Security
Retrieve Cloud Groups by their UUIDs.
ListCloudGroupsExternalCloud Security
Query Cloud Groups and return entities with full details.
ListCollectionsCustom Storage
List available collection names in alphabetical order.
ListDashboardsNGSIEM
List dashboards.
ListFeedTypesIntelligence Feeds
List the accessible feeds for a given customer.
ListLookupFilesNGSIEM
List lookup files.
ListObjectsCustom Storage
List the object keys in the specified collection in alphabetical order.
ListObjectsByVersionCustom Storage
List the object keys in the specified collection in alphabetical order.
ListParsersNGSIEM
List parsers.
ListReposV1Foundry LogScale
Lists available repositories and views
ListSavedQueriesNGSIEM
List saved queries.
ListSchemasCustom Storage
Get the list of schemas for the requested collection in reverse version order (latest first).
ListViewV1Foundry LogScale
List views
LookupIndicatorsIntelligence Indicator Graph
Get indicators based on their value.
MigrationAggregatesV1Host Migration
Get migration aggregates as specified via json in request body.
MigrationsActionsV1Host Migration
Perform an action on a migration job.
oauth2AccessTokenOAuth2
Generate an OAuth2 access token
oauth2RevokeTokenOAuth2
Revoke a previously issued OAuth2 access token before the end of its standard 30-minute lifespan.
patch_external_assetsExposure Management
Update the details of external assets.
patch_federated_connections_configFederated Connections
Update configuration for a federated connection
PatchAzureServicePrincipalKubernetes Protection
Adds the client ID for the given tenant ID to our system.
PatchCSPMAwsAccountCSPM Registration
Patches a existing account in our system for a customer.
patchDeviceControlPoliciesClassesV1Device Control Policies
Update device control policy’s classes (USB and Bluetooth).
patchDeviceControlPoliciesV2Device Control Policies
Update Device Control Policies by specifying the ID of the policy and details to update.
PatchEntitiesAlertsV2Alerts
Perform actions on alerts identified by alert ID(s) in request.
PatchEntitiesAlertsV3Alerts
Perform actions on alerts identified by alert ID(s) in request.
PerformActionV2Hosts
Contain, lift containment, delete, or restore a host.
performContentUpdatePoliciesActionContent Update Policies
Perform the specified action on the Content Update Policies specified in the request.
performDeviceControlPoliciesActionDevice Control Policies
Perform the specified action on the Device Control Policies specified in the request.
performFirewallPoliciesActionFirewall Policies
Perform the specified action on the Firewall Policies specified in the request
performGroupActionHost Group
Perform the specified action on the Host Groups specified in the request
performPreventionPoliciesActionPrevention Policy
Perform the specified action on the Prevention Policies specified in the request
performRTResponsePoliciesActionResponse Policies
Perform the specified action on the Response Policies specified in the request
performSensorUpdatePoliciesActionSensor Update Policy
Perform the specified action on the Sensor Update Policies specified in the request.
platform_query_v1IOC
Query Platforms.
PolicyChecksFalcon Container
Perform policy checks against container configurations.
post_external_assets_inventory_v1Exposure Management
Add external assets for external asset scanning.
post_federated_connections_configFederated Connections
Create configuration for a federated connection
post_policy_rulesIdentity Protection
Create policy rules.
PostAggregatesAlertsV1Alerts
Retrieve aggregates for alerts across all CIDs.
PostAggregatesAlertsV2Alerts
Retrieve aggregates for alerts across all CIDs.
PostCombinedAlertsV1Alerts
Retrieves all Alerts that match a particular FQL filter. This API is intended for retrieval of large amounts of Alerts(>10k) using a pagination based on a after token.
PostDeliverySettingsDelivery Settings
Create Delivery Settings.
postDeviceControlPoliciesV2Device Control Policies
Create Device Control Policies by specifying details about the policy to create.
PostDeviceDetailsV2Hosts
Get details on one or more hosts by AID.
PostEntitiesAlertsV1Alerts
Retrieve all alerts given their IDs.
PostEntitiesAlertsV2Alerts
Retrieve all alerts given their IDs.
PostGroupV2ASPM
Create group
PostImageScanInventoryFalcon Container
Post image scan inventory.
PostMalQueryEntitiesSamplesMultidownloadV1MalQuery
Schedule samples for download. Use the result id with the /request endpoint to check if the download is ready after which you can call the /entities/samples-fetch to get the zip
PostMalQueryExactSearchV1MalQuery
Search Falcon MalQuery for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity. You can filter results on criteria such as file type, file size and first seen date. Returns a request id which can be used with the /request endpoint
PostMalQueryFuzzySearchV1MalQuery
Search Falcon MalQuery quickly, but with more potential for false positives. Search for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity.
PostMalQueryHuntV1MalQuery
Schedule a YARA-based search for execution. Returns a request id which can be used with the /request endpoint
PostMitreAttacksIntel
Retrieves report and observable IDs associated with the given actor and attacks.
PostSearchKubernetesIOMEntitiesKubernetes Protection
Search Kubernetes IOM entities by filter criteria
PreviewRuleV1Recon
Preview rules notification count and distribution. This will return aggregations on: channel, count, site.
ProcessesRanOnIOC
Search for processes associated with a custom IOC (Deprecated)
ProcessesRanOnIOCs
Search for processes associated with a custom IOC.
ProvisionAWSAccountsCloud Connect AWS
Provision AWS Accounts by specifying details about the accounts to provision
PutObjectCustom Storage
Put the specified new object at the given key or overwrite an existing object at the given key.
PutObjectByVersionCustom Storage
Put the specified new object at the given key or overwrite an existing object at the given key.
queries_access_tags_get_v1Case Management
Query access tags.
queries_cases_get_v1Case Management
Retrieves all Cases IDs that match a given query.
queries_classification_get_v2Data Protection Configuration
Search for classifications that match the provided criteria.
queries_cloud_application_get_v2Data Protection Configuration
Get all cloud-application IDs matching the query with filter.
queries_content_pattern_get_v2Data Protection Configuration
Get all content-pattern IDs matching the query with filter.
queries_edgetypes_getThreatGraph
Show all available edge types.
queries_enterprise_account_get_v2Data Protection Configuration
Get all enterprise-account IDs matching the query with filter.
queries_fields_get_v1Case Management
Query fields
queries_file_details_get_v1Case Management
Query for ids of file details
queries_file_type_get_v2Data Protection Configuration
Get all file-type IDs matching the query with filter.
queries_knowledge_base_audit_events_v1Knowledge Base Audit Events
Query knowledge base audit event IDs with pagination and filtering.
queries_knowledge_base_files_v1Knowledge Base Files
Query knowledge base files based on the provided filters.
queries_knowledge_bases_v1Knowledge Bases
Query knowledge bases based on the provided filters.
queries_local_application_getData Protection Configuration
Get all local-application IDs matching the query with filter.
queries_local_application_group_getData Protection Configuration
Get all local application group IDs matching the query with filter.
queries_notification_groups_get_v1Case Management
Query notification groups
queries_notification_groups_get_v2Case Management
Query notification groups
queries_policy_get_v2Data Protection Configuration
Search for policies that match the provided criteria.
queries_rules_get_v1Correlation Rules
Find all rule IDs matching the query and filter.
queries_rules_get_v2Correlation Rules
Find all rule version IDs matching the query and filter.
queries_sensitivity_label_get_v2Data Protection Configuration
Get all sensitivity label IDs matching the query with filter.
queries_slas_get_v1Case Management
Query SLAs
queries_states_v1Device Content
Query for the content state of the host.
queries_template_snapshots_get_v1Case Management
Query template snapshots
queries_templates_get_v1Case Management
Query templates
queries_templates_get_v1Mixin0Correlation Rules
Search rule template IDs matching the filter.
queries_web_location_get_v2Data Protection Configuration
Get web-location IDs matching the query with filter.
queriesRolesV1User Management
Show role IDs for all roles available in your customer account. Supports Flight Control.
query_accountsDiscover
Search for accounts in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_applicationsDiscover
Search for applications in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of application IDs which match the filter criteria.
query_ecosystem_subsidiariesExposure Management
Retrieves a list of IDs for ecosystem subsidiaries.
query_eventsFirewall Management
Find all event IDs matching the query with filter
query_external_assetsExposure Management
Get a list of external asset IDs that match the provided filter conditions. Use these IDs with the /entities/external-assets/v1 endpoints
query_external_assets_v2Exposure Management
Query external assets (v2).
query_firewall_fieldsFirewall Management
Get the firewall field specification IDs for the provided platform
query_hostsDiscover
Search for assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_iot_hostsDiscover
Search for IoT assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_iot_hostsV2Discover
Search for IoT assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_loginsDiscover
Search for logins in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_malicious_filesODS (On Demand Scan)
Query malicious files.
query_network_locationsFirewall Management
Get a list of network location IDs
query_networksNetwork Scan Networks
Get “networks IDs” by filter
query_patternsCustom IOA
Get all pattern severity IDs.
query_platformsFirewall Management
Get the list of platform names
query_platformsMixin0Custom IOA
Get all platform IDs.
query_policy_rulesFirewall Management
Find all firewall rule IDs matching the query with filter, and return them in precedence order
query_rule_groupsFirewall Management
Find all rule group IDs matching the query with filter
query_rule_groups_fullCustom IOA
Find all rule groups matching the query with optional filter.
query_rule_groupsMixin0Custom IOA
Finds all rule group IDs matching the query with optional filter.
query_rule_typesCustom IOA
Get all rule type IDs.
query_rulesFirewall Management
Find all rule IDs matching the query with filter
query_rulesMixin0Custom IOA
Finds all rule IDs matching the query with optional filter.
query_scan_host_metadataODS (On Demand Scan)
Query scan hosts.
query_scan_runsNetwork Scan Scan Runs
Get “scan-runs IDs” by filter
query_scannersNetwork Scan Scanners
Get “scanners IDs” by filter
query_scansODS (On Demand Scan)
Query Scans.
query_scansMixin0Network Scan Scans
Get “scans IDs” by filter
query_scheduled_scansODS (On Demand Scan)
Query ScheduledScans.
query_templatesNetwork Scan Templates
Get “templates IDs” by filter
query_zonesNetwork Scan Zones
Get “zones IDs” by filter
queryActionsMixin0FileVantage
Returns one or more action IDs.
QueryActionsV1Recon
Query actions based on provided criteria. Use the IDs from this response to get the action entities on GetActionsV1.
QueryActivityByCaseIDMessage Center
Retrieve activities id’s for a case
QueryAlertIdsByFilterFalcon Complete Dashboard
Retrieve Alert IDs that match the provided FQL filter criteria with scrolling enabled
QueryAlertIdsByFilterV2Falcon Complete Dashboard
Retrieve Alert IDs that match the provided FQL filter criteria with scrolling enabled
QueryAllowListFilterFalcon Complete Dashboard
Retrieve allowlist tickets that match the provided filter criteria with scrolling enabled
QueryAWSAccountsCloud Connect AWS
Search for provisioned AWS Accounts by providing a FQL filter and paging details. Returns a set of AWS accounts which match the filter criteria
QueryAWSAccountsForIDsCloud Connect AWS
Search for provisioned AWS Accounts by providing a FQL filter and paging details. Returns a set of AWS account IDs which match the filter criteria
QueryBlockListFilterFalcon Complete Dashboard
Retrieve block listtickets that match the provided filter criteria with scrolling enabled
QueryCasesIdsByFilterMessage Center
Retrieve case id’s that match the provided filter criteria
queryChangesFileVantage
Returns 1 or more change ids.
queryChildrenMSSP (Flight Control)
Query for customers linked as children
queryCIDGroupMembersMSSP (Flight Control)
Query a CID Groups members by associated CID.
queryCIDGroupsMSSP (Flight Control)
Query CID Groups.
queryCombinedContentUpdatePoliciesContent Update Policies
Search for Content Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Content Update Policies which match the filter criteria.
queryCombinedContentUpdatePolicyMembersContent Update Policies
Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria.
queryCombinedDeviceControlPoliciesDevice Control Policies
Search for Device Control Policies in your environment by providing a FQL filter and paging details. Returns a set of Device Control Policies which match the filter criteria.
queryCombinedDeviceControlPolicyMembersDevice Control Policies
Search for members of a Device Control Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria.
queryCombinedFirewallPoliciesFirewall Policies
Search for Firewall Policies in your environment by providing a FQL filter and paging details. Returns a set of Firewall Policies which match the filter criteria
queryCombinedFirewallPolicyMembersFirewall Policies
Search for members of a Firewall Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedGroupMembersHost Group
Search for members of a Host Group in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedHostGroupsHost Group
Search for Host Groups in your environment by providing a FQL filter and paging details. Returns a set of Host Groups which match the filter criteria
queryCombinedPreventionPoliciesPrevention Policy
Search for Prevention Policies in your environment by providing a FQL filter and paging details. Returns a set of Prevention Policies which match the filter criteria
queryCombinedPreventionPolicyMembersPrevention Policy
Search for members of a Prevention Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedRTResponsePoliciesResponse Policies
Search for Response Policies in your environment by providing a FQL filter and paging details. Returns a set of Response Policies which match the filter criteria
queryCombinedRTResponsePolicyMembersResponse Policies
Search for members of a Response policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedSensorUpdateBuildsSensor Update Policy
Retrieve available builds for use with Sensor Update Policies.
queryCombinedSensorUpdateKernelsSensor Update Policy
Retrieve kernel compatibility info for Sensor Update Builds.
queryCombinedSensorUpdatePoliciesSensor Update Policy
Search for Sensor Update Policies in your environment by providing a FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria.
queryCombinedSensorUpdatePoliciesV2Sensor Update Policy
Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing a FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria.
queryCombinedSensorUpdatePolicyMembersSensor Update Policy
Search for members of a Sensor Update Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria.
QueryComplianceControlsCloud Policies
Query for compliance controls by various parameters.
QueryComplianceFrameworksCloud Policies
Query for compliance frameworks by various parameters.
queryContentUpdatePoliciesContent Update Policies
Search for Content Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Content Update Policy IDs which match the filter criteria.
queryContentUpdatePolicyMembersContent Update Policies
Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria.
QueryDetectsDetects
Search for detection IDs that match a given query.
queryDeviceControlPoliciesDevice Control Policies
Search for Device Control Policies in your environment by providing a FQL filter and paging details. Returns a set of Device Control Policy IDs which match the filter criteria.
queryDeviceControlPolicyMembersDevice Control Policies
Search for members of a Device Control Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria.
QueryDeviceLoginHistoryV2Hosts
Retrieve recent login sessions for devices.
QueryDevicesByFilterScrollHosts
Search for hosts with continuous pagination.
QueryEscalationsFilterFalcon Complete Dashboard
Retrieve escalation tickets that match the provided filter criteria with scrolling enabled
queryEvaluationLogicSpotlight Evaluation Logic
Search for evaluation logic in your environment by providing a FQL filter and paging details. Returns a set of evaluation logic IDs which match the filter criteria.
QueryEventsTailored Intelligence
Get events ids that match the provided filter criteria.
QueryExportJobsFalcon Container
Query export jobs entities.
QueryExportJobsMixin0Serverless Exports
Query export jobs entities.
QueryFeedArchivesIntelligence Feeds
Query the accessible feeds for a customer.
queryFirewallPoliciesFirewall Policies
Search for Firewall Policies in your environment by providing a FQL filter and paging details. Returns a set of Firewall Policy IDs which match the filter criteria
queryFirewallPolicyMembersFirewall Policies
Search for members of a Firewall Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
QueryGetNetworkAddressHistoryV1Hosts
Retrieve IP and MAC address history.
queryGroupMembersHost Group
Search for members of a Host Group in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
QueryHiddenDevicesHosts
Retrieve hidden hosts matching filter criteria.
queryHostGroupsHost Group
Search for Host Groups in your environment by providing a FQL filter and paging details. Returns a set of Host Group IDs which match the filter criteria
QueryIncidentIdsByFilterFalcon Complete Dashboard
Retrieve incidents that match the provided filter criteria with scrolling enabled
QueryIntelActorEntitiesIntel
Get info about actors that match provided FQL filters.
QueryIntelActorIdsIntel
Get actor IDs that match provided FQL filters.
QueryIntelIndicatorEntitiesIntel
Get info about indicators that match provided FQL filters.
QueryIntelIndicatorIdsIntel
Get indicators IDs that match provided FQL filters.
QueryIntelReportEntitiesIntel
Get info about reports that match provided FQL filters.
QueryIntelReportIdsIntel
Get report IDs that match provided FQL filters.
QueryIntelRuleIdsIntel
Search for rule IDs that match provided filter criteria.
queryIOAExclusionsV1IOA Exclusions
Search for IOA exclusions.
QueryIOCsIOCs
This operation has been superseded by the IOC.indicator_search_v1 operation and is no longer used.
QueryMalwareIntel
Get malware family names that match provided FQL filters.
QueryMalwareEntitiesIntel
Get malware entities that match provided FQL filters.
QueryMitreAttacksIntel
Gets MITRE tactics and techniques for the given actor.
QueryMitreAttacksForMalwareIntel
Gets MITRE tactics and techniques for the given malware.
queryMLExclusionsV1ML Exclusions
Search for ML exclusions.
QueryNotificationsExposedDataRecordsV1Recon
Query notifications exposed data records based on provided criteria. Use the IDs from this response to get the notification entities on GetNotificationsExposedDataRecordsV1.
QueryNotificationsV1Recon
Query notifications based on provided criteria. Use the IDs from this response to get the notification entities on GetNotificationsV1 or GetNotificationsDetailedV1.
queryPinnableContentVersionsContent Update Policies
Search for content versions available for pinning given the category.
queryPoliciesFileVantage
Retrieve the ids of all policies that are assigned the provided policy type.
queryPreventionPoliciesPrevention Policy
Search for Prevention Policies in your environment by providing a FQL filter and paging details. Returns a set of Prevention Policy IDs which match the filter criteria
queryPreventionPolicyMembersPrevention Policy
Search for members of a Prevention Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
QueryQuarantineFilesQuarantine
Get quarantine file ids that match the provided filter criteria.
QueryReleaseNotesV1Deployments
Queries for release-notes resources and returns IDs.
QueryRemediationsFilterFalcon Complete Dashboard
Retrieve remediation tickets that match the provided filter criteria with scrolling enabled
QueryReportsFalconx Sandbox
Find sandbox reports by providing a FQL filter and paging details. Returns a set of report IDs that match your criteria.
queryRolesMSSP (Flight Control)
Query links between user groups and CID groups. At least one of CID Group ID or User Group ID should also be provided. Role ID is optional.
queryRTResponsePoliciesResponse Policies
Search for Response Policies in your environment by providing a FQL filter with sort and/or paging details. This returns a set of Response Policy IDs that match the given criteria.
queryRTResponsePolicyMembersResponse Policies
Search for members of a Response policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
QueryRuleCloud Policies
Query for rules by various parameters.
queryRuleGroupsFileVantage
Retrieve the ids of all rule groups that are of the provided rule group type.
QueryRulesTailored Intelligence
Get rules ids that match the provided filter criteria.
QueryRulesV1Recon
Query monitoring rules based on provided criteria. Use the IDs from this response to fetch the rules on GetRulesV1.
QuerySampleV1Falconx Sandbox
Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200
QueryScanResultsQuick Scan Pro
Gets QuickScan Pro scan jobs for a given FQL filter.
queryScheduledExclusionsFileVantage
Retrieve the ids of all scheduled exclusions contained within the provided policy id.
QuerySensorsByFilterIdentity Protection
Search for sensors in your environment by hostname, IP, and other criteria.
querySensorUpdateKernelsDistinctSensor Update Policy
Retrieve kernel compatibility info for Sensor Update Builds.
querySensorUpdatePoliciesSensor Update Policy
Search for Sensor Update Policies in your environment by providing a FQL filter and paging details. Returns a set of Sensor Update Policy IDs which match the filter criteria.
querySensorUpdatePolicyMembersSensor Update Policy
Search for members of a Sensor Update Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria.
querySensorVisibilityExclusionsV1Sensor Visibility Exclusions
Search for sensor visibility exclusions.
QuerySubmissionsFalconx Sandbox
Find submission IDs for uploaded files by providing a FQL filter and paging details. Returns a set of submission IDs that match your criteria.
QuerySubmissionsMixin0Quick Scan
Find IDs for submitted scans by providing a FQL filter and paging details. Returns a set of volume IDs that match your criteria.
QuerySuppressionRulesCloud Policies
Query suppression rules with filtering, sorting and pagination.
queryUserGroupMembersMSSP (Flight Control)
Query User Group member by User UUID.
queryUserGroupsMSSP (Flight Control)
Query User Groups.
queryUserV1User Management
List user IDs for all users in your customer account.
QueryVulnerabilitiesIntel
Get vulnerabilities IDs
queryVulnerabilitiesSpotlight Vulnerabilities
Search for Vulnerabilities in your environment by providing a FQL filter and paging details. Returns a set of Vulnerability IDs which match the filter criteria.
ReadClusterCombinedKubernetes Protection
Retrieve kubernetes clusters identified by the provided filter criteria
ReadClusterCombinedV2Kubernetes Protection
Retrieve kubernetes clusters identified by the provided filter criteria
ReadClusterCountKubernetes Protection
Retrieve cluster counts
ReadClusterEnrichmentKubernetes Protection
Retrieve cluster enrichment data
ReadClustersByDateRangeCountKubernetes Protection
Retrieve clusters by date range counts
ReadClustersByKubernetesVersionCountKubernetes Protection
Bucket clusters by kubernetes version
ReadClustersByStatusCountKubernetes Protection
Bucket clusters by status
ReadCombinedDetectionsContainer Detections
Retrieve image assessment detections identified by the provided filter criteria.
ReadCombinedImagesExportContainer Images
Retrieve images with an option to expand aggregated vulnerabilities/detections
ReadCombinedVulnerabilitiesContainer Vulnerabilities
Retrieve vulnerability and aggregate data filtered by the provided FQL
ReadCombinedVulnerabilitiesDetailsContainer Vulnerabilities
Retrieve vulnerability details related to an image
ReadCombinedVulnerabilitiesInfoContainer Vulnerabilities
Retrieve vulnerability and package related info for this customer
ReadContainerAlertsCountContainer Alerts
Search Container Alerts by the provided search criteria.
ReadContainerAlertsCountBySeverityContainer Alerts
Get Container Alert counts by severity.
ReadContainerCombinedKubernetes Protection
Retrieve containers identified by the provided filter criteria
ReadContainerCountKubernetes Protection
Retrieve container counts
ReadContainerCountByRegistryKubernetes Protection
Retrieve top container image registries
ReadContainerEnrichmentKubernetes Protection
Retrieve container enrichment data
ReadContainerImageDetectionsCountByDateKubernetes Protection
Retrieve count of image assessment detections on running containers over a period of time
ReadContainerImagesByMostUsedKubernetes Protection
Bucket container by image-digest
ReadContainerImagesByStateKubernetes Protection
Retrieve count of image states running on containers
ReadContainersByDateRangeCountKubernetes Protection
Retrieve containers by date range counts
ReadContainersSensorCoverageKubernetes Protection
Bucket containers by agent type and calculate sensor coverage
ReadContainerVulnerabilitiesBySeverityCountKubernetes Protection
Retrieve container vulnerabilities by severity counts
ReadDeploymentCombinedKubernetes Protection
Retrieve kubernetes deployments identified by the provided filter criteria
ReadDeploymentCountKubernetes Protection
Retrieve deployment counts
ReadDeploymentEnrichmentKubernetes Protection
Retrieve deployment enrichment data
ReadDeploymentsByDateRangeCountKubernetes Protection
Retrieve deployments by date range counts
ReadDeploymentsCombinedCloud Snapshots
Search for snapshot jobs identified by the provided filter.
ReadDeploymentsEntitiesCloud Snapshots
Retrieve snapshot jobs identified by the provided IDs.
ReadDetectionsContainer Detections
Retrieve image assessment detection entities identified by the provided filter criteria.
ReadDetectionsCountContainer Detections
Aggregate count of detections.
ReadDetectionsCountBySeverityContainer Detections
Aggregate counts of detections by severity.
ReadDetectionsCountByTypeContainer Detections
Aggregate counts of detections by detection type.
ReadDistinctContainerImageCountKubernetes Protection
Retrieve count of distinct images running on containers
ReadDriftIndicatorEntitiesDrift Indicators
Retrieve Drift Indicator entities identified by the provided IDs
ReadDriftIndicatorsCountDrift Indicators
Returns the total count of Drift indicators over a time period
ReadExportJobsFalcon Container
Read export jobs entities.
ReadExportJobsMixin0Serverless Exports
Read export jobs entities.
ReadImageVulnerabilitiesFalcon Container
Retrieve an assessment report for an image by specifying repository and tag.
ReadKubernetesIomByDateRangeKubernetes Protection
Returns the count of Kubernetes IOMs by the date. by default it’s for 7 days.
ReadKubernetesIomCountKubernetes Protection
Returns the total count of Kubernetes IOMs over the past seven days
ReadKubernetesIomEntitiesKubernetes Protection
Retrieve Kubernetes IOM entities identified by the provided IDs
ReadNamespaceCountKubernetes Protection
Retrieve namespace counts
ReadNamespacesByDateRangeCountKubernetes Protection
Retrieve namespaces by date range counts
ReadNodeCombinedKubernetes Protection
Retrieve kubernetes nodes identified by the provided filter criteria
ReadNodeCountKubernetes Protection
Retrieve node counts
ReadNodeEnrichmentKubernetes Protection
Retrieve node enrichment data
ReadNodesByCloudCountKubernetes Protection
Bucket nodes by cloud providers
ReadNodesByContainerEngineVersionCountKubernetes Protection
Bucket nodes by their container engine version
ReadNodesByDateRangeCountKubernetes Protection
Retrieve nodes by date range counts
ReadPackagesByFixableVulnCountContainer Packages
Retrieve top x app packages with the most fixable vulnerabilities.
ReadPackagesByImageCountContainer Packages
Retrieves the N most frequently used packages across images.
ReadPackagesByVulnCountContainer Packages
Retrieve top x packages with the most vulnerabilities.
ReadPackagesCombinedContainer Packages
Retrieve packages identified by the provided filter criteria.
ReadPackagesCombinedExportContainer Packages
Retrieve packages identified by the provided filter criteria for the purpose of export.
ReadPackagesCombinedV2Container Packages
Retrieve packages identified by the provided filter criteria.
ReadPackagesCountByZeroDayContainer Packages
Retrieve packages count affected by zero day vulnerabilities.
ReadPodCombinedKubernetes Protection
Retrieve kubernetes pods identified by the provided filter criteria
ReadPodCountKubernetes Protection
Retrieve pod counts
ReadPodEnrichmentKubernetes Protection
Retrieve pod enrichment data
ReadPodsByDateRangeCountKubernetes Protection
Retrieve pods by date range counts
ReadPoliciesImage Assessment Policies
Get all Image Assessment policies
ReadPolicyExclusionsImage Assessment Policies
Retrieve Image Assessment Policy Exclusion entities
ReadPolicyGroupsImage Assessment Policies
Retrieve Image Assessment Policy Group entities
ReadRegistryEntitiesFalcon Container
Retrieve registry entities associated with the client ID.
ReadRegistryEntitiesByUUIDFalcon Container
Retrieve registry entities associated with a specific UUID.
ReadRequestBodyFaaS Execution
Retrieve a large request body, such as a file, that has spilled into object storage.
ReadRunningContainerImagesKubernetes Protection
Retrieve images on running containers
ReadUnidentifiedContainersByDateRangeCountUnidentified Containers
Returns the count of Unidentified Containers over the last 7 days
ReadUnidentifiedContainersCountUnidentified Containers
Returns the total count of Unidentified Containers over a time period
ReadVulnerabilitiesByImageCountContainer Vulnerabilities
Retrieve top x vulnerabilities with the most impacted images
ReadVulnerabilitiesPublicationDateContainer Vulnerabilities
Retrieve top x vulnerabilities with the most recent publication date
ReadVulnerabilityCountContainer Vulnerabilities
Aggregate count of vulnerabilities
ReadVulnerabilityCountByActivelyExploitedContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by actively exploited
ReadVulnerabilityCountByCPSRatingContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by csp_rating
ReadVulnerabilityCountByCVSSScoreContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by cvss score
ReadVulnerabilityCountBySeverityContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by severity
ReadVulnerableContainerImageCountKubernetes Protection
Retrieve count of vulnerable images running on containers
refreshActiveStreamSessionEvent Streams
Refresh an active event stream. Use the URL shown in a listAvailableStreamsOAuth2 response.
RegenerateAPIKeyKubernetes Protection
Regenerate API key for docker registry integrations.
RegisterCspmSnapshotAccountCloud Snapshots
Register customer cloud account for snapshot scanning.
RenameSectionComplianceFrameworkCloud Policies
Rename a section in a custom compliance framework.
ReplaceControlRulesCloud Policies
Assign rules to a compliance control (full replace).
report_executions_download_getReport Executions
Get report entity download
report_executions_getReport Executions
Retrieve report details for the provided report IDs.
report_executions_queryReport Executions
Find all report execution IDs matching the query with filter
report_executions_retryReport Executions
Retry the execution of a report by ID.
RequestDeviceEnrollmentV3Mobile Enrollment
Trigger on-boarding process for a mobile device
RequestDeviceEnrollmentV4Mobile Enrollment
Trigger on-boarding process for a mobile device
RetrieveEmailsByCIDUser Management
List the usernames (usually an email address) for all users in your customer account
RetrieveRelayInstancesASPM
Retrieve the relay instances in CSV format.
RetrieveUserUser Management
Get info about a user.
retrieveUsersGETV1User Management
Get info about users including their name, UID and CID by providing user UUIDs.
RetrieveUserUUIDUser Management
Get a user’s ID by providing a username (usually an email address)
RetrieveUserUUIDsByCIDUser Management
List user IDs for all users in your customer account. For more information on each user, provide the user ID to RetrieveUser.
revealUninstallTokenSensor Update Policy
Reveals an uninstall token for a specific device. To retrieve the bulk maintenance token pass the value ‘MAINTENANCE’ as the value for ‘device_id’.
RevokeUserRoleIdsUser Management
Revoke one or more roles from a user
RTR_AggregateSessionsReal Time Response
Get aggregates on session data.
RTR_CheckActiveResponderCommandStatusReal Time Response
Get status of an executed active-responder command on a single host.
RTR_CheckAdminCommandStatusReal Time Response Admin
Get status of an executed RTR administrator command on a single host.
RTR_CheckCommandStatusReal Time Response
Get status of an executed command on a single host.
RTR_CreatePut_FilesReal Time Response Admin
Upload a new put-file to use for the RTR put command.
RTR_CreatePut_FilesV2Real Time Response Admin
Upload a new put-file to use for the RTR put command.
RTR_CreateScriptsReal Time Response Admin
Upload a new custom-script to use for the RTR runscript command.
RTR_CreateScriptsV2Real Time Response Admin
Upload a new custom-script to use for the RTR runscript command.
RTR_DeleteFileReal Time Response
Delete a RTR session file.
RTR_DeleteFileV2Real Time Response
Delete a RTR session file. (Expanded output detail, use with RTR_ListFilesV2.)
RTR_DeletePut_FilesReal Time Response Admin
Delete a put-file based on the ID given. Can only delete one file at a time.
RTR_DeleteQueuedSessionReal Time Response
Delete a queued session command.
RTR_DeleteScriptsReal Time Response Admin
Delete a custom-script based on the ID given. Can only delete one script at a time.
RTR_DeleteSessionReal Time Response
Delete a session.
RTR_ExecuteActiveResponderCommandReal Time Response
Execute an active responder command on a single host.
RTR_ExecuteAdminCommandReal Time Response Admin
Execute a RTR administrator command on a single host.
RTR_ExecuteCommandReal Time Response
Execute a command on a single host.
RTR_GetExtractedFileContentsReal Time Response
Get RTR extracted file contents for specified session and sha256.
RTR_GetFalconScriptsReal Time Response Admin
Get Falcon scripts with metadata and content of script
RTR_GetPut_FilesReal Time Response Admin
Get put-files based on the ID’s given. These are used for the RTR put command.
RTR_GetPut_FilesV2Real Time Response Admin
Get put-files based on the ID’s given. These are used for the RTR put command.
RTR_GetPutFileContentsReal Time Response Admin
Get the contents of a put-file based on the ID given.
RTR_GetScriptsReal Time Response Admin
Get custom-scripts based on the ID’s given. These are used for the RTR runscript command.
RTR_GetScriptsV2Real Time Response Admin
Get custom-scripts based on the ID’s given. These are used for the RTR runscript command.
RTR_InitSessionReal Time Response
Initialize a new session with the RTR cloud.
RTR_ListAllSessionsReal Time Response
Get a list of session_ids.
RTR_ListFalconScriptsReal Time Response Admin
Get a list of Falcon script IDs available to the user to run
RTR_ListFilesReal Time Response
Get a list of files for the specified RTR session.
RTR_ListFilesV2Real Time Response
Get a list of files for the specified RTR session. (Expanded output detail.)
RTR_ListPut_FilesReal Time Response Admin
Get a list of put-file ID’s that are available to the user for the put command.
RTR_ListQueuedSessionsReal Time Response
Get queued session metadata by session ID.
RTR_ListScriptsReal Time Response Admin
Get a list of custom-script ID’s that are available to the user for the runscript command.
RTR_ListSessionsReal Time Response
Get session metadata by session id.
RTR_PulseSessionReal Time Response
Refresh a session timeout on a single host.
RTR_UpdateScriptsReal Time Response Admin
Upload a new scripts to replace an existing one.
RTR_UpdateScriptsV2Real Time Response Admin
Upload a new scripts to replace an existing one.
RTRAuditSessionsReal Time Response Audit
Get all the RTR sessions created for a customer in a specified duration
RunIntegrationTaskASPM
Run an integration task by its ID
RunIntegrationTaskAdminASPM
Run an integration task by its ID with admin scope.
RunIntegrationTaskV2ASPM
Run an integration task by its ID
ScanSamplesQuick Scan
Submit a volume of files for ml scanning. Time required for analysis increases with the number of samples in a volume but usually it should take less than 1 minute
schedule_scanODS (On Demand Scan)
Create ODS scan and start or schedule scan for the given scan request.
scheduled_reports_getScheduled Reports
Retrieve scheduled reports for the provided report IDs.
scheduled_reports_launchScheduled Reports
Launch scheduled report executions for the provided ID(s).
scheduled_reports_queryScheduled Reports
Find all report IDs matching the query with filter
SearchAndReadContainerAlertsContainer Alerts
Search Container Alerts by the provided search criteria.
SearchAndReadDriftIndicatorEntitiesDrift Indicators
Retrieve Drift Indicators by the provided search criteria
SearchAndReadKubernetesIomEntitiesKubernetes Protection
Search Kubernetes IOM by the provided search criteria
SearchAndReadUnidentifiedContainersUnidentified Containers
Search Unidentified Containers by the provided search criteria
SearchDetectionsContainer Detections
Retrieve image assessment detection entities identified by the provided filter criteria.
SearchDriftIndicatorsDrift Indicators
Retrieve all drift indicators that match the given query
SearchHuntingGuidesCAO Hunting
Search for Hunting Guides that match the provided conditions
SearchIndicatorsIntelligence Indicator Graph
Search indicators based on FQL filter.
SearchIntelligenceQueriesCAO Hunting
Search intelligence queries that match the provided conditions.
SearchKubernetesIomsKubernetes Protection
Search Kubernetes IOMs by the provided search criteria. this endpoint returns a list of Kubernetes IOM UUIDs matching the query
SearchObjectsCustom Storage
Search for objects that match the specified filter criteria (returns metadata, not actual objects).
SearchObjectsByVersionCustom Storage
Search for objects that match the specified filter criteria (returns metadata, not actual objects).
ServiceNowGetDeploymentsASPM
Retrieve ServiceNow deployments
ServiceNowGetServicesASPM
Retrieve ServiceNow services.
SetCloudSecurityIntegrationStateASPM
Set Cloud Security integration state.
setContentUpdatePoliciesPrecedenceContent Update Policies
Sets the precedence of Content Update Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies when updating precedence.
setDeviceControlPoliciesPrecedenceDevice Control Policies
Sets the precedence of Device Control Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence.
setFirewallPoliciesPrecedenceFirewall Policies
Sets the precedence of Firewall Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence
setPreventionPoliciesPrecedencePrevention Policy
Sets the precedence of Prevention Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence
setRTResponsePoliciesPrecedenceResponse Policies
Sets the precedence of Response Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence
setSensorUpdatePoliciesPrecedenceSensor Update Policy
Sets the precedence of Sensor Update Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence.
severity_query_v1IOC
Query Severities.
signalChangesExternalFileVantage
Initiates workflows for the provided change IDs.
ss_ioa_exclusions_aggregates_v2IOA Exclusions
Get Self Service IOA Exclusion aggregates as specified via json in the request body.
ss_ioa_exclusions_create_v2IOA Exclusions
Create new Self Service IOA Exclusions.
ss_ioa_exclusions_delete_v2IOA Exclusions
Delete the Self Service IOA Exclusions rule by id.
ss_ioa_exclusions_get_reports_v2IOA Exclusions
Create a report of Self Service IOA Exclusions scoped by the given filters.
ss_ioa_exclusions_get_v2IOA Exclusions
Get the Self Service IOA Exclusions rules by id.
ss_ioa_exclusions_matched_rule_v2IOA Exclusions
Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent.
ss_ioa_exclusions_new_rules_v2IOA Exclusions
Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent.
ss_ioa_exclusions_search_v2IOA Exclusions
Search for Self Service IOA Exclusions.
ss_ioa_exclusions_update_v2IOA Exclusions
Update the Self Service IOA Exclusions rule by id.
startActionsFileVantage
Initiates the specified action on the provided change IDs.
StartSearchV1NGSIEM
Initiate a NGSIEM search.
StopSearchV1NGSIEM
Stop a NGSIEM search.
SubmitFalconx Sandbox
Submit an uploaded file or a URL for sandbox analysis. Time required for analysis varies but is usually less than 15 minutes.
tokens_createInstallation Tokens
Creates a token.
tokens_deleteInstallation Tokens
Deletes a token immediately. To revoke a token, use tokens_update instead.
tokens_queryInstallation Tokens
Search for tokens by providing a FQL filter and paging details.
tokens_readInstallation Tokens
Gets the details of one or more tokens by id.
tokens_updateInstallation Tokens
Updates one or more tokens. Use this endpoint to edit labels, change expiration, revoke, or restore.
TriggerScanKubernetes Protection
Triggers a dry run or a full scan of a customer’s kubernetes footprint.
update_global_configsNetwork Scan Global Configs
Update “global-configs” using provided specifications
update_network_locationsFirewall Management
Updates the network locations provided, and return the ID.
update_network_locations_metadataFirewall Management
Updates the network locations metadata such as polling_intervals for the cid
update_network_locations_precedenceFirewall Management
Updates the network locations precedence according to the list of ids provided.
update_networksNetwork Scan Networks
Update “networks” using provided specifications
update_policy_containerFirewall Management
Update an identified policy container
update_policy_container_v1Firewall Management
Update an identified policy container
update_rule_groupFirewall Management
Update name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
update_rule_group_validationFirewall Management
Validates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
update_rule_groupMixin0Custom IOA
Update a rule group. The following properties can be modified: name, description, enabled.
update_rulesCustom IOA
Update rules within a rule group. Return the updated rules.
update_rules_v2Custom IOA
Update name, description, enabled or field_values for individual rules within a rule group.
update_scan_runsNetwork Scan Scan Runs
Update “scan-runs” using provided specifications
update_scannersNetwork Scan Scanners
Update “scanners” using provided specifications
update_scansNetwork Scan Scans
Update “scans” using provided specifications
update_templatesNetwork Scan Templates
Update “templates” using provided specifications
update_zonesNetwork Scan Zones
Update “zones” using provided specifications
UpdateActionV1Recon
Update an action for a monitoring rule.
UpdateAWSAccountKubernetes Protection
Updates the AWS account per the query parameters provided
UpdateAWSAccountsCloud Connect AWS
Update AWS Accounts by specifying the ID of the account and details to update
updateCIDGroupsMSSP (Flight Control)
Update existing CID Group(s). CID Group ID is expected for each CID Group definition provided in request body. CID Group member(s) remain unaffected.
UpdateCloudGroupExternalCloud Security
Update an existing Cloud Group’s properties.
UpdateComplianceControlCloud Policies
Update a custom compliance control.
UpdateComplianceFrameworkCloud Policies
Update a custom compliance framework.
updateContentUpdatePoliciesContent Update Policies
Update Content Update Policies by specifying the ID of the policy and details to update.
UpdateCSPMAzureAccountCSPM Registration
Patches a existing account in our system for a customer.
UpdateCSPMAzureAccountClientIDCSPM Registration
Update an Azure service account in our system by with the user-created client_id created with the public key we’ve provided
UpdateCSPMAzureTenantDefaultSubscriptionIDCSPM Registration
Update an Azure default subscription_id in our system for given tenant_id
UpdateCSPMGCPAccountCSPM Registration
Patches a existing account in our system for a customer.
UpdateCSPMGCPServiceAccountsExtCSPM Registration
Updates an existing GCP service account.
UpdateCSPMPolicySettingsCSPM Registration
Updates a policy setting - can be used to override policy severity or to disable a policy entirely.
UpdateCSPMScanScheduleCSPM Registration
Updates scan schedule configuration for one or more cloud platforms.
UpdateD4CGCPServiceAccountsExtD4C Registration
Updates an existing GCP service account.
UpdateDashboardFromTemplateNGSIEM
Update dashboard from template.
updateDefaultDeviceControlPoliciesDevice Control Policies
Update the configuration for the Default Device Control Policy.
updateDefaultDeviceControlSettingsDevice Control Policies
Update the configuration for Default Device Control Settings.
UpdateDefaultGroupASPM
Update default group
UpdateDetectsByIdsV2Detects
Modify the state, assignee, and visibility of detections.
updateDeviceControlPoliciesDevice Control Policies
Update Device Control Policies by specifying the ID of the policy and details to update.
UpdateDeviceTagsHosts
Append or remove Falcon Grouping Tags.
UpdateDiscoverCloudAzureAccountClientIDD4C Registration
Update an Azure service account in our system by with the user-created client_id created with the public key we’ve provided.
UpdateExecutorNodeASPM
Update an existing relay node
UpdateFileV1Foundry LogScale
Updates a lookup file.
updateFirewallPoliciesFirewall Policies
Update Firewall Policies by specifying the ID of the policy and details to update
UpdateGroupASPM
Update group
updateHostGroupsHost Group
Update Host Groups by specifying the ID of the group and details to update
UpdateIntegrationASPM
Update an existing integration by its ID
UpdateIntegrationTaskASPM
Update an existing integration task by its ID
updateIOAExclusionsV1IOA Exclusions
Update the IOA exclusions.
UpdateIOCIOCs
This operation has been superseded by the IOC.indicator_update_v1 operation and is no longer used.
UpdateLookupFileNGSIEM
Update lookup file.
UpdateLookupFileEntriesNGSIEM
Update entries in an existing Lookup File in NGSIEM.
updateMLExclusionsV1ML Exclusions
Update the ML exclusions.
UpdateNotificationsV1Recon
Update notification status or assignee. Accepts bulk requests.
UpdateParserNGSIEM
Update parser.
UpdateParserAutoUpdatePolicyNGSIEM
Update a parser auto update policy.
UpdateParserFromTemplateNGSIEM
Update Parser in NGSIEM from YAML Template. Please note that name changes are not supported, but rather should be created as a new parser.
updatePoliciesFileVantage
Updates the general information of the provided policy.
UpdatePoliciesImage Assessment Policies
Update Image Assessment Policy entities
UpdatePolicyExclusionsImage Assessment Policies
Update Image Assessment Policy Exclusion entities
UpdatePolicyGroupsImage Assessment Policies
Update Image Assessment Policy Group entities
updatePolicyHostGroupsFileVantage
Manage host groups assigned to a policy.
updatePolicyPrecedenceFileVantage
Updates the policy precedence for all policies of a specific type.
UpdatePolicyPrecedenceImage Assessment Policies
Update Image Assessment Policy precedence
updatePolicyRuleGroupsFileVantage
Manage the rule groups assigned to the policy or set the rule group precedence for all rule groups within the policy.
updatePreventionPoliciesPrevention Policy
Update Prevention Policies by specifying the ID of the policy and details to update
UpdateQfByQueryQuarantine
Apply quarantine file actions by query.
UpdateQuarantinedDetectsByIdsQuarantine
Apply action by quarantine file ids.
UpdateRegistryEntitiesFalcon Container
Update the registry entity, as identified by the entity UUID, using the provided details.
updateRTResponsePoliciesResponse Policies
Update Response Policies by specifying the ID of the policy and details to update
UpdateRuleCloud Policies
Update a rule.
updateRuleGroupPrecedenceFileVantage
Updates the rule precedence for all rules in the identified rule group.
updateRuleGroupsFileVantage
Updates the provided rule group.
UpdateRuleOverrideCloud Policies
Update a rule override.
updateRulesFileVantage
Updates the provided rule configuration within the specified rule group.
UpdateRulesV1Recon
Update monitoring rules.
UpdateSavedQueryFromTemplateNGSIEM
Update Saved Query from LogScale YAML Template in NGSIEM.
updateScheduledExclusionsFileVantage
Updates the provided scheduled exclusion configuration within the provided policy.
updateSensorUpdatePoliciesSensor Update Policy
Update Sensor Update Policies by specifying the ID of the policy and details to update.
updateSensorUpdatePoliciesV2Sensor Update Policy
Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection.
updateSensorVisibilityExclusionsV1Sensor Visibility Exclusions
Update a sensor visibility exclusion.
UpdateSuppressionRuleCloud Policies
Update a suppression rule.
UpdateUserUser Management
Modify an existing user’s first or last name
updateUserGroupsMSSP (Flight Control)
Update existing User Group(s). User Group ID is expected for each User Group definition provided in request body. User Group member(s) remain unaffected.
updateUserV1User Management
Modify an existing user’s first or last name. Supports Flight Control.
UploadFileQuickScanProQuick Scan Pro
Uploads a file to be further analyzed with QuickScan Pro. The samples expire after 90 days.
UploadLookupV1NGSIEM
Upload a lookup file to NGSIEM.
UploadSampleV2Falconx Sandbox
Upload a file for sandbox analysis. After uploading, use /falconx/entities/submissions/v1 to start analyzing the file.
UploadSampleV3Sample Uploads
Upload a file for further cloud analysis. After uploading, call the specific analysis API endpoint.
upsert_network_locationsFirewall Management
Updates the network locations provided, and return the ID.
UpsertBusinessApplicationsASPM
Create or Update Business Applications
UpsertTagsASPM
Create new or update existing tag. You can update unique tags table or regular tags table
userActionV1User Management
Apply actions to one or more users.
userRolesActionV1User Management
Grant or Revoke one or more role(s) to a user against a CID.
v1_child_executions_queryWorkflows
Search for child executions by providing a FQL filter and paging details.
validateCustom IOA
Validates field values and checks for matches if a test string is provided.
validate_filepath_patternFirewall Management
Validates that the test pattern matches the executable filepath glob pattern.
ValidateCSPMGCPServiceAccountExtCSPM Registration
Validates credentials for a service account
VerifyAWSAccountAccessCloud Connect AWS
Performs an Access Verification check on the specified AWS Account IDs
WorkflowActivitiesCombinedWorkflows
Search for activities by name. Returns all supported activities if no filter is specified.
WorkflowActivitiesContentCombinedWorkflows
Search for activities by name. Returns all supported activities if no filter specified.
WorkflowDefinitionsActionWorkflows
Enable or disable a workflow definition, or stop all executions for a definition.
WorkflowDefinitionsCombinedWorkflows
Search workflow definitions based on the provided filter
WorkflowDefinitionsExportWorkflows
Exports a workflow definition for the given definition ID
WorkflowDefinitionsImportWorkflows
Imports a workflow definition based on the provided model
WorkflowDefinitionsUpdateWorkflows
Updates a workflow definition based on the provided model.
WorkflowExecuteWorkflows
Executes an on-demand Workflow, the body is JSON used to trigger the execution, the response the execution ID(s)
WorkflowExecuteInternalWorkflows
Executes an on-demand Workflow, the body is JSON used to trigger the execution, the response the execution ID(s)
WorkflowExecutionResultsWorkflows
Get execution result of a given execution
WorkflowExecutionsActionWorkflows
Allows a user to resume/retry a failed workflow execution.
WorkflowExecutionsCombinedWorkflows
Search workflow executions based on the provided filter
WorkflowGetHumanInputV1Workflows
Gets one or more specific human inputs by their IDs.
WorkflowMockExecuteWorkflows
Executes an on-demand Workflow with mocks
WorkflowSystemDefinitionsDeProvisionWorkflows
Deprovisions a system definition that was previously provisioned on the target CID
WorkflowSystemDefinitionsPromoteWorkflows
Promote a version of a system definition
WorkflowSystemDefinitionsProvisionWorkflows
Provisions a system definition onto the target CID by using the template and provided parameters
WorkflowTriggersCombinedWorkflows
Search for triggers by namespaced identifier, i.e. FalconAudit, Detection, or FalconAudit/Detection/Status. Returns all triggers if no filter is specified.
WorkflowUpdateHumanInputV1Workflows
Provides an input in response to a human input action. Depending on action configuration, one or more of Approve, Decline, and/or Escalate are permitted.