Skip to content

All Operations

A complete alphabetical index of all CrowdStrike API operations across every service collection. Each Operation ID is a unique, case-sensitive identifier used by the Falcon SDKs to reference a specific API call. Use this page as a quick-lookup reference when you know the operation name but not which collection it belongs to.

action.get.v1IOC
Get Actions by ids.
action.query.v1IOC
Query Actions.
ActionUpdateCountQuarantine
Returns count of potentially affected quarantined files for each action.
addCIDGroupMembersMSSP (Flight Control)
Add new CID group member.
addDashboardLabelsNGSIEM
Add multiple labels to a single dashboard
addFileLabelsNGSIEM
Add multiple labels to a single file
addRoleMSSP (Flight Control)
Create a link between user group and CID group, with zero or more additional roles.
addSavedQueryLabelsNGSIEM
Add multiple labels to a saved query
addUserGroupMembersMSSP (Flight Control)
Add new user group member.
admission-control-add-host-groupsAdmission Control Policies
Add one or more host groups to an admission control policy.
admission-control-add-rule-group-custom-ruleAdmission Control Policies
Add one or more custom Rego rules to a rule group in an admission control policy.
admission-control-create-policyAdmission Control Policies
Create an admission control policy.
admission-control-create-rule-groupsAdmission Control Policies
Create one or more rule groups and add them to an existing admission control policy.
admission-control-delete-policiesAdmission Control Policies
Delete an admission control policy.
admission-control-delete-rule-groupsAdmission Control Policies
Delete rule groups.
admission-control-get-policiesAdmission Control Policies
Get admission control policies.
admission-control-query-policiesAdmission Control Policies
Search admission control policies.
admission-control-remove-host-groupsAdmission Control Policies
Remove one or more host groups from an admission control policy.
admission-control-remove-rule-group-custom-ruleAdmission Control Policies
Delete one or more custom Rego rules from all rule groups in an admission control policy.
admission-control-replace-rule-group-selectorsAdmission Control Policies
Replace labels and/or namespaces of a rule group within an admission control policy.
admission-control-set-rule-group-precedenceAdmission Control Policies
Change precedence of rule groups within an admission control policy.
admission-control-update-policyAdmission Control Policies
Update an admission control policy.
admission-control-update-policy-precedenceAdmission Control Policies
Update admission control policy precedence.
admission-control-update-rule-groupsAdmission Control Policies
Update a rule group.
aggregate-eventsFirewall Management
Aggregate events for customer
aggregate-external-assetsExposure Management
Returns external assets aggregates.
aggregate-networksNetwork Scan Networks
Returns “networks” aggregations
aggregate-policy-rulesFirewall Management
Aggregate rules within a policy for customer
aggregate-query-scan-host-metadataODS (On Demand Scan)
Get aggregates on ODS scan-hosts data.
aggregate-rule-groupsFirewall Management
Aggregate rule groups for customer
aggregate-rulesFirewall Management
Aggregate rules for customer
aggregate-scan-runsNetwork Scan Scan Runs
Returns “scan-runs” aggregations
aggregate-scannersNetwork Scan Scanners
Returns “scanners” aggregations
aggregate-scansODS (On Demand Scan)
Get aggregates on ODS scan data.
aggregate-scansMixin0Network Scan Scans
Returns “scans” aggregations
aggregate-scheduled-scansODS (On Demand Scan)
Get aggregates on ODS scheduled-scan data.
aggregate-zonesNetwork Scan Zones
Returns “zones” aggregations
AggregateAlertsFalcon Complete Dashboard
Retrieve aggregate epp alerts values based on the matched filter
AggregateAllowListFalcon Complete Dashboard
Retrieve aggregate allowlist ticket values based on the matched filter
AggregateAssessmentsGroupedByClustersV2Kubernetes Container Compliance
Returns cluster details along with aggregated assessment results organized by cluster, including pass/fail assessment counts for various asset types.
AggregateAssessmentsGroupedByRulesV2Kubernetes Container Compliance
Returns rule details along with aggregated assessment results organized by compliance rule, including pass/fail assessment counts.
AggregateBlockListFalcon Complete Dashboard
Retrieve aggregate blocklist ticket values based on the matched filter
AggregateCasesMessage Center
Retrieve aggregate case values based on the matched filter
AggregateComplianceByAssetTypeKubernetes Container Compliance
Provides aggregated compliance assessment metrics and rule status information, organized by asset type.
AggregateComplianceByClusterTypeKubernetes Container Compliance
Provides aggregated compliance assessment metrics and rule status information, organized by Kubernetes cluster type.
AggregateComplianceByFrameworkKubernetes Container Compliance
Provides aggregated compliance assessment metrics and rule status information, organized by compliance framework.
AggregateDeviceCountCollectionFalcon Complete Dashboard
Retrieve aggregate host/devices count based on the matched filter
AggregateEscalationsFalcon Complete Dashboard
Retrieve aggregate escalation ticket values based on the matched filter
AggregateFailedRulesByClustersV3Kubernetes Container Compliance
Retrieves the most non-compliant clusters, ranked in descending order based on the number of failed compliance rules across severity levels (critical, high, medium, and low).
AggregateHuntingGuidesCAO Hunting
Aggregate Hunting Guides
AggregateImageAssessmentHistoryContainer Images
Image assessment history
AggregateImageCountContainer Images
Aggregate count of images
AggregateImageCountByBaseOSContainer Images
Aggregate count of images grouped by Base OS distribution
AggregateImageCountByStateContainer Images
Aggregate count of images grouped by state
AggregateIntelligenceQueriesCAO Hunting
Aggregate intelligence queries
AggregateNotificationsExposedDataRecordsV1Recon
Get notification exposed data record aggregates as specified via JSON in request body.
AggregateNotificationsV1Recon
Get notification aggregates as specified via JSON in request body.
AggregatePreventionPolicyFalcon Complete Dashboard
Retrieve prevention policies aggregate values based on the matched filter
AggregateRemediationsFalcon Complete Dashboard
Retrieve aggregate remediation ticket values based on the matched filter
aggregates.access-tags.post.v1Case Management
Get access tag aggregates
aggregates.file-details.post.v1Case Management
Get file details aggregates as specified via json in the request body.
aggregates.notification-groups.post.v1Case Management
Get notification groups aggregations
aggregates.notification-groups.post.v2Case Management
Get notification groups aggregations
aggregates.rule-versions.post.v1Correlation Rules
Get rules aggregates as specified via json in the request body.
aggregates.slas.post.v1Case Management
Get SLA aggregations
aggregates.templates.post.v1Case Management
Get templates aggregations
AggregateSensorUpdatePolicyFalcon Complete Dashboard
Retrieve sensor update policies aggregate values
AggregateSupportIssuesFalcon Complete Dashboard
Retrieve aggregate support issue ticket values based on the matched filter
AggregateTopFailedImagesKubernetes Container Compliance
Retrieves the most non-compliant container images, ranked in descending order based on the number of failed assessments across severity levels (critical, high, medium, and low).
AggregateTotalDeviceCountsFalcon Complete Dashboard
Retrieve aggregate total host/devices based on the matched filter
aggregateUsersV1User Management
Get host aggregates as specified via json in request body.
api_preempt_proxy_post_graphqlIdentity Protection
Identity Protection GraphQL API.
ArchiveDeleteV1Sample Uploads
Delete an archive that was uploaded previously
ArchiveGetV1Sample Uploads
Retrieves the archives upload operation statuses.
ArchiveListV1Sample Uploads
Retrieves the archives files in chunks.
ArchiveUploadV1Sample Uploads
Uploads an archive and extracts files list from it.
ArchiveUploadV2Sample Uploads
Uploads an archive and extracts files list from it.
audit-events-queryInstallation Tokens
Search for audit events by providing an FQL filter and paging details.
audit-events-readInstallation Tokens
Gets the details of one or more audit events by id.
AzureRefreshCertificateCSPM Registration
Refresh certificate and returns JSON object(s) that contain the base64 encoded certificate for a service principal.
BatchActiveResponderCmdReal Time Response
Batch executes a RTR active-responder command across the hosts mapped to the given batch ID.
BatchAdminCmdReal Time Response Admin
Batch executes a RTR administrator command across the hosts mapped to the given batch ID.
BatchCmdReal Time Response
Batch executes a RTR read-only command across the hosts mapped to the given batch ID.
BatchGetCmdReal Time Response
Batch executes get command across hosts to retrieve files.
BatchGetCmdStatusReal Time Response
Retrieves the status of the specified batch get command.
BatchInitSessionsReal Time Response
Batch initialize a RTR session on multiple hosts.
BatchRefreshSessionsReal Time Response
Batch refresh a RTR session on multiple hosts.
blob-download-external-assetsExposure Management
Download the entire contents of the blob.
blob-preview-external-assetsExposure Management
Download a preview of the blob.
bulkAddDashboardLabelsNGSIEM
Add labels to multiple dashboards (max 100 items, non-transactional)
bulkAddLookupFileLabelsNGSIEM
Add labels to multiple lookup files (max 100 items, non-transactional)
bulkAddSavedQueryLabelsNGSIEM
Add labels to multiple saved queries (max 100 items, non-transactional)
BulkCreateDashboardsFromTemplateNGSIEM
Create Multiple Dashboards from YAML Templates.
BulkCreateLookupFilesNGSIEM
Create Multiple Lookup Files.
BulkCreateSavedQueriesFromTemplateNGSIEM
Create Multiple Saved Queries from LogScale YAML Templates.
BulkGetLookupFilesNGSIEM
Retrieve Multiple Lookup Files by Filenames in NGSIEM.
BulkInstallParsersNGSIEM
Installs multiple CrowdStrike-managed out-of-the-box (OOTB) parsers into the customer’s repository in a single operation.
bulkRemoveDashboardLabelsNGSIEM
Remove labels from multiple dashboards (max 100 items, non-transactional)
bulkRemoveLookupFileLabelsNGSIEM
Remove labels from multiple lookup files (max 100 items, non-transactional)
bulkRemoveSavedQueryLabelsNGSIEM
Remove labels from multiple saved queries (max 100 items, non-transactional)
bulkUpdateDashboardLabelsNGSIEM
Replace all labels on multiple dashboards (max 100 items, non-transactional)
BulkUpdateDashboardsFromTemplateNGSIEM
Update Multiple Dashboards from YAML Templates.
bulkUpdateLookupFileLabelsNGSIEM
Replace all labels on multiple lookup files (max 100 items, non-transactional)
BulkUpdateLookupFilesNGSIEM
Update Multiple Lookup Files.
BulkUpdateSavedQueriesFromTemplateNGSIEM
Update Multiple Saved Queries from LogScale YAML Templates.
bulkUpdateSavedQueryLabelsNGSIEM
Replace all labels on multiple saved queries (max 100 items, non-transactional)
cancel-scansODS (On Demand Scan)
Cancel ODS scans for the given scan ids.
cao_incidents_aggregates_v1Intel
Perform statistical aggregations over incident data.
cao_incidents_entities_v1Intel
Retrieve full details for one or more adversary incidents by their IDs.
cao_incidents_queries_v1Intel
Search for adversary incidents using FQL criteria and return a paginated list of matching incident IDs.
CaseAddActivityMessage Center
Add an activity to case.
CaseAddAttachmentMessage Center
Upload an attachment for the case.
CaseDownloadAttachmentMessage Center
retrieves an attachment for the case, given the attachment id
cb-exclusions.create.v1Certificate Based Exclusions
Create new Certificate Based Exclusions.
cb-exclusions.delete.v1Certificate Based Exclusions
Delete the exclusions by id
cb-exclusions.get.v1Certificate Based Exclusions
Find all exclusion IDs matching the query with filter
cb-exclusions.query.v1Certificate Based Exclusions
Search for cert-based exclusions.
cb-exclusions.update.v1Certificate Based Exclusions
Updates existing Certificate Based Exclusions
certificates.get.v1Certificate Based Exclusions
Retrieves certificate signing information for a file
CloneComplianceFrameworkCloud Policies
Clone an existing compliance framework to create a custom copy
CloneParserNGSIEM
Clone an existing parser with a new name
cloud-compliance-framework-posture-summariesCloud Security Compliance
Get sections and requirements with scores for benchmarks.
cloud-compliance-rule-posture-summariesCloud Security Compliance
Get compliance score and counts for rules.
cloud-registration-aws-create-accountCloud AWS Registration
Creates a new account in our system for a customer.
cloud-registration-aws-delete-accountCloud AWS Registration
Deletes an existing AWS account or organization in our system.
cloud-registration-aws-get-accountsCloud AWS Registration
Retrieve existing AWS accounts by account IDs or organization IDs
cloud-registration-aws-query-accountsCloud AWS Registration
Retrieve existing AWS accounts by account IDs
cloud-registration-aws-trigger-health-checkCloud AWS Registration
Trigger health check scan for AWS accounts
cloud-registration-aws-update-accountCloud AWS Registration
Patches a existing account in our system for a customer.
cloud-registration-aws-validate-accountsCloud AWS Registration
Validates the AWS account registration status, and discover organization child accounts if organization is specified
cloud-registration-azure-create-registrationCloud Azure Registration
Create an Azure registration for a tenant.
cloud-registration-azure-create-suppressionsCloud Azure Registration
Create new issue suppression rules
cloud-registration-azure-delete-legacy-subscriptionCloud Azure Registration
Delete existing legacy Azure subscriptions.
cloud-registration-azure-delete-registrationCloud Azure Registration
Deletes existing Azure registrations.
cloud-registration-azure-delete-suppressionsCloud Azure Registration
Remove/revoke suppression rules
cloud-registration-azure-download-scriptCloud Azure Registration
Retrieve script to create resources
cloud-registration-azure-get-issue-suppression-values-by-fieldCloud Azure Registration
Retrieve distinct filterable values for issue suppression fields
cloud-registration-azure-get-issue-values-by-fieldCloud Azure Registration
Retrieve distinct filterable values for issue fields
cloud-registration-azure-get-issuesCloud Azure Registration
Retrieve issues for Azure registrations
cloud-registration-azure-get-registrationCloud Azure Registration
Retrieve existing Azure registration for a tenant.
cloud-registration-azure-get-scriptCloud Azure Registration
Download Azure deployment script (Terraform or Bicep)
cloud-registration-azure-get-script-versionsCloud Azure Registration
Retrieve all available script versions with filtering and sorting
cloud-registration-azure-get-suppressionsCloud Azure Registration
Retrieve existing suppression rules with filtering
cloud-registration-azure-trigger-health-checkCloud Azure Registration
Trigger health check scan for Azure registrations
cloud-registration-azure-update-registrationCloud Azure Registration
Update an existing Azure registration for a tenant.
cloud-registration-azure-update-suppressionsCloud Azure Registration
Update existing suppression rules
cloud-registration-azure-validate-registrationCloud Azure Registration
Validate an Azure registration by checking service principal, role assignments and deployment stack (if the deployment method is Bicep)
cloud-registration-cross-provider-get-account-aggregatesCloud Security Registration Combined
Returns cross-provider account aggregates by status
cloud-registration-gcp-create-registrationCloud Google Cloud Registration
Create a Google Cloud Registration.
cloud-registration-gcp-delete-registrationCloud Google Cloud Registration
Deletes a Google Cloud Registration and returns the deleted registration in the response body.
cloud-registration-gcp-get-entitiesCloud Google Cloud Registration
Retrieve all GCP entities (organizations, folders, projects) grouped by type with support for FQL filtering, sorting, and pagination.
cloud-registration-gcp-get-registrationCloud Google Cloud Registration
Retrieve a Google Cloud Registration.
cloud-registration-gcp-post-terraform-scriptCloud Google Cloud Registration
Generate Google Cloud Terraform deployment scripts (zip files)
cloud-registration-gcp-put-registrationCloud Google Cloud Registration
Creates/Updates a Google Cloud Registration.
cloud-registration-gcp-trigger-health-checkCloud Google Cloud Registration
Trigger health check scan for GCP registrations
cloud-registration-gcp-update-registrationCloud Google Cloud Registration
Update a Google Cloud Registration.
cloud-security-assets-combined-application-findingsCloud Security Assets
Get findings for an application resource with pagination
cloud-security-assets-combined-compliance-by-accountCloud Security Assets
Gets combined compliance data aggregated by account and region.
cloud-security-assets-entities-getCloud Security Assets
Gets raw resources based on the provided IDs param.
cloud-security-assets-entities-postCloud Security Assets
Gets raw resources based on IDs in the request body.
cloud-security-assets-queriesCloud Security Assets
Gets a list of resource IDs for the given parameters, filters and sort criteria
cloud-security-registration-oci-create-accountCloud OCI Registration
Create OCI tenancy account in CSPM
cloud-security-registration-oci-delete-accountCloud OCI Registration
Delete an existing OCI tenancy in CSPM.
cloud-security-registration-oci-download-scriptCloud OCI Registration
Retrieve script to create resources in tenancy OCID
cloud-security-registration-oci-get-accountCloud OCI Registration
Retrieve a list of OCI tenancies with support for FQL filtering, sorting, and pagination
cloud-security-registration-oci-rotate-keyCloud OCI Registration
Refresh key for the OCI Tenancy
cloud-security-registration-oci-update-accountCloud OCI Registration
Patch an existing OCI account in our system for a customer.
cloud-security-registration-oci-validate-tenancyCloud OCI Registration
Validate the OCI account in CSPM for a provided CID.
cloud-security-timeline-risks-enrichedCloud Security Risks
Returns the enriched asset timeline.
combined-applicationsDiscover
Search for applications in your environment by providing an FQL filter and paging details.
combined-cloud-risksCloud Security
Gets cloud risks with full details based on filters and sort criteria
combined-ecosystem-subsidiariesExposure Management
Retrieves a list of ecosystem subsidiaries with their detailed information.
combined-hostsDiscover
Search for assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
combined-zonesNetwork Scan Zones
Get “zones” by filter
combined.file-details.get.v1Case Management
Query file details
combined.rules.get.v1Correlation Rules
Find all rules matching the query and filter.
combined.rules.get.v2Correlation Rules
Find all rules matching the query and filter.
combined_edges_getThreatGraph
Retrieve edges for a given vertex id.
combined_ran_on_getThreatGraph
Look up instances of indicators such as hashes, domain names, and ip addresses that have been seen on devices in your environment.
combined_summary_getThreatGraph
Retrieve summary for a given vertex ID
CombinedBaseImagesContainer Images
Retrieves a list of base images for the provided filter.
CombinedDetectionsCloud Snapshots
Search IaC Detections using a query in Falcon Query Language
CombinedDevicesByFilterHosts
Search for hosts in your environment by platform, hostname, IP, and other criteria.
CombinedHiddenDevicesByFilterHosts
Search for hidden hosts in your environment by platform, hostname, IP, and other criteria.
CombinedImageByVulnerabilityCountContainer Images
Retrieve top x images with the most vulnerabilities
CombinedImageDetailContainer Images
Retrieve image entities identified by the provided filter criteria
CombinedImageIssuesSummaryContainer Images
Retrieve image issues summary such as Image detections, Runtime detections, Policies, vulnerabilities
CombinedImagesFindingsKubernetes Container Compliance
Returns detailed compliance assessment results for container images, providing the information needed to identify compliance violations.
CombinedImageVulnerabilitySummaryContainer Images
aggregates information about vulnerabilities for an image
CombinedKnowledgeBaseAuditEventsV1Knowledge Base Audit Events
Get knowledge base audit events with full event details and pagination.
CombinedKnowledgeBasesV1Knowledge Bases
Search for knowledge bases with filtering and return full entity details in a single response.
CombinedNodesFindingsKubernetes Container Compliance
Returns detailed compliance assessment results for kubernetes nodes, providing the information needed to identify compliance violations.
combinedQueryEvaluationLogicSpotlight Evaluation Logic
Search for evaluation logic in your environment by providing a FQL filter and paging details.
combinedQueryVulnerabilitiesSpotlight Vulnerabilities
Search for Vulnerabilities in your environment by providing an FQL filter and paging details.
CombinedReleaseNotesV1Deployments
Queries for release-notes resources and returns details
CombinedReleasesV1Mixin0Deployments
Queries for releases resources and returns details
combinedSupportedEvaluationExtSpotlight Evaluation Logic
Performs a combined query and get operation for retrieving RiskSupportedEvaluation entities.
combinedUserRolesV1User Management
Deprecated : Please use GET /user-management/combined/user-roles/v2.
CombinedUserRolesV2User Management
Get User Grant(s).
combineVulnMetadataExtSpotlight Vulnerability Metadata
Performs a combined query and get operation for retrieving Risk (vulnerability metadata) entities.
ConnectCSPMGCPAccountCSPM Registration
Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id
ConnectD4CGCPAccountD4C Registration
Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id
create-network-locationsFirewall Management
Create new network locations provided, and return the ID.
create-networksNetwork Scan Networks
Create “networks” using provided specifications
create-ruleCustom IOA
Create a rule within a rule group.
create-rule-groupFirewall Management
Create new rule group on a platform for a customer with a name and description, and return the ID
create-rule-group-validationFirewall Management
Validates the request of creating a new rule group on a platform for a customer with a name and description
create-rule-groupMixin0Custom IOA
Create a rule group for a platform with a name and an optional description.
create-scanODS (On Demand Scan)
Create ODS scan and start or schedule scan for the given scan request.
create-scan-runsNetwork Scan Scan Runs
Create “scan-runs” using provided specifications
create-scansNetwork Scan Scans
Create “scans” using provided specifications
create-templatesNetwork Scan Templates
Create “templates” using provided specifications
create-zonesNetwork Scan Zones
Create “zones” using provided specifications
CreateActionsV1Recon
Create actions for a monitoring rule.
CreateAPIClientAPI Clients
Create new API Client.
CreateAWSAccountKubernetes Protection
Creates a new AWS account in our system for a customer and generates the installation script
CreateAzureSubscriptionKubernetes Protection
Creates a new Azure Subscription in our system
CreateBaseImagesEntitiesContainer Images
Creates base images using the provided details
CreateCaseV2Message Center
create a new case
createCIDGroupsMSSP (Flight Control)
Create new CID groups.
CreateCloudGroupExternalCloud Security
Create a Cloud Group.
CreateComplianceControlCloud Policies
Create a new custom compliance control
CreateComplianceFrameworkCloud Policies
Create a new custom compliance framework
createContentUpdatePoliciesContent Update Policies
Create Content Update Policies by specifying details about the policy to create
CreateCSPMAwsAccountCSPM Registration
Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
CreateCSPMAzureAccountCSPM Registration
Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
CreateCSPMAzureManagementGroupCSPM Registration
Creates a new management group in our system for a customer.
CreateCSPMGCPAccountCSPM Registration
Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
CreateD4CAwsAccountD4C Registration
Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
CreateD4CGCPAccountD4C Registration
Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
CreateDashboardFromTemplateNGSIEM
Create Dashboard from LogScale YAML Template in NGSIEM
CreateDeploymentEntityCloud Snapshots
Launch a snapshot scan for a given cloud asset
createDeviceControlPoliciesDevice Control Policies
Create Device Control Policies by specifying details about the policy to create
CreateDiscoverCloudAzureAccountD4C Registration
Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
CreateExecutorNodeASPM
Create a new relay node
CreateExportJobsV1Recon
Launch asynchronous export job.
CreateFileV1Foundry Lookup Files
Creates a lookup file within a foundry app
createFirewallPoliciesFirewall Policies
Create Firewall Policies by specifying details about the policy to create
CreateGroupV1Mixin0Profile Groups
Create a new profile group
createHostGroupsHost Group
Create Host Groups by specifying details about the group to create
CreateIntegrationASPM
Create a new integration
CreateIntegrationTaskASPM
Create new integration task.
createIOAExclusionsV1IOA Exclusions
Create the IOA exclusions
CreateIOCIOCs
Create a new IOC. *** Deprecated - Use the new IOC Management endpoint (POST /iocs/entities/indicators/v1). ***
CreateLookupFileNGSIEM
Create Lookup File in NGSIEM
CreateMigrationV1Host Migration
Create a device migration job.
createMLExclusionsV1ML Exclusions
Create the ML exclusions
CreateOrUpdateAWSSettingsCloud Connect AWS
Create or update Global Settings which are applicable to all provisioned AWS accounts
CreateParserNGSIEM
Create Parser in NGSIEM.
CreateParserExtensionNGSIEM
Create a Parser extension in NGSIEM for the provided base parser.
CreateParserFromTemplateNGSIEM
Create Parser from LogScale YAML Template in NGSIEM
createPoliciesFileVantage
Creates a new policy of the specified type.
CreatePoliciesImage Assessment Policies
Create Image Assessment policies
CreatePolicyGroupsImage Assessment Policies
Create Image Assessment Policy Group entities
createPreventionPoliciesPrevention Policies
Create Prevention Policies by specifying details about the policy to create
CreateRegistryEntitiesFalcon Container
Create a registry entity using the provided details
createRTResponsePoliciesResponse Policies
Create Response Policies by specifying details about the policy to create
createRuleGroupsFileVantage
Creates a new rule group of the specified type.
CreateRuleMixin0Cloud Policies
Create a new rule
CreateRuleOverrideCloud Policies
Create a new rule override
createRulesFileVantage
Creates a new rule configuration within the specified rule group.
CreateRulesV1Recon
Create monitoring rules.
CreateSavedQueryNGSIEM
Create Saved Query from LogScale YAML Template in NGSIEM
CreateSavedSearchesDynamicExecuteV1Foundry LogScale
Execute a dynamic saved search
CreateSavedSearchesExecuteV1Foundry LogScale
Execute a saved search
CreateSavedSearchesIngestV1Foundry LogScale
Populate a saved search
createScheduledExclusionsFileVantage
Creates a new scheduled exclusion configuration for the provided policy id.
createSensorUpdatePoliciesSensor Update Policy
Create Sensor Update Policies by specifying details about the policy to create
createSensorUpdatePoliciesV2Sensor Update Policy
Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection
CreateSuppressionRuleCloud Policies
Create a new suppression rule
createSVExclusionsV1Sensor Visibility Exclusions
Create the sensor visibility exclusions
CreateUserUser Management
Deprecated : Please use POST /user-management/entities/users/v1.
createUserGroupsMSSP (Flight Control)
Create new user groups.
createUserV1User Management
Create a new user.
cspm-evaluations-combined-iom-by-ruleCloud Security Detections
returns ioms grouped by rule
cspm-evaluations-iom-entitiesCloud Security Detections
Gets IOMs based on the provided IDs
cspm-evaluations-iom-entities-postCloud Security Detections
Gets IOMs based on IDs in the request body.
cspm-evaluations-iom-queriesCloud Security Detections
Gets a list of IOM IDs for the given parameters, filters and sort criteria.
customer-settings-readInstallation Tokens
Check current installation token settings.
customer-settings-updateInstallation Tokens
Update installation token settings.
delete-external-assetsExposure Management
Delete multiple external assets.
delete-network-locationsFirewall Management
Delete network location entities by ID.
delete-networksNetwork Scan Networks
Delete “networks” by their IDs
delete-rule-groupsFirewall Management
Delete rule group entities by ID
delete-rule-groupsMixin0Custom IOA
Delete rule groups by ID.
delete-rulesCustom IOA
Delete rules from a rule group by ID.
delete-scansNetwork Scan Scans
Delete “scans” by their IDs
delete-scheduled-scansODS (On Demand Scan)
Delete ODS scheduled-scans for the given scheduled-scan ids.
delete-templatesNetwork Scan Templates
Delete “templates” by their IDs
delete-zonesNetwork Scan Zones
Delete “zones” by their IDs
delete_policy_rulesIdentity Protection
Delete policy rules
delete_policy_rulesIdentity Protection
Delete policy rules
DeleteActionV1Recon
Delete an action from a monitoring rule based on the action ID.
DeleteAPIClientsAPI Clients
Delete existing API Client(s) based on API Client ID(s) provided as request parameter(s) ‘ids’.
DeleteAWSAccountsCloud Connect AWS
Delete a set of AWS Accounts by specifying their IDs
DeleteAWSAccountsMixin0Kubernetes Protection
Delete AWS accounts.
DeleteAzureSubscriptionKubernetes Protection
Deletes a new Azure Subscription in our system
DeleteBaseImagesContainer Images
Delete base images by base image uuid
deleteCIDGroupMembersV1MSSP (Flight Control)
Deprecated : Please use DELETE /entities/cid-group-members/v2.
deleteCIDGroupMembersV2MSSP (Flight Control)
Delete CID group members.
deleteCIDGroupsMSSP (Flight Control)
Delete CID groups by ID.
DeleteCloudGroupsExternalCloud Security
Delete Cloud Groups in batch
DeleteComplianceControlCloud Policies
Delete custom compliance controls
DeleteComplianceFrameworkCloud Policies
Delete a custom compliance framework and all associated controls and rule assignments
deleteContentUpdatePoliciesContent Update Policies
Delete a set of Content Update Policies by specifying their IDs
DeleteCSPMAwsAccountCSPM Registration
Deletes an existing AWS account or organization in our system.
DeleteCSPMAzureAccountCSPM Registration
Deletes an Azure subscription from the system.
DeleteCSPMAzureManagementGroupCSPM Registration
Deletes Azure management groups from the system.
DeleteCSPMGCPAccountCSPM Registration
Deletes a GCP account from the system.
DeleteD4CAwsAccountD4C Registration
Deletes an existing AWS account or organization in our system.
DeleteD4CGCPAccountD4C Registration
Deletes a GCP account from the system.
DeleteDashboardNGSIEM
Delete Dashboard in NGSIEM
deleteDeviceControlPoliciesDevice Control Policies
Delete a set of Device Control Policies by specifying their IDs
deletedRolesMSSP (Flight Control)
Delete links or additional roles between user groups and CID groups.
DeleteExecutorNodeASPM
Delete a relay node
DeleteExportJobsV1Recon
Delete export jobs (and their associated file(s)) based on their IDs.
DeleteFederatedConnectionsConfigFederated Connections
Delete configuration for a federated connection
DeleteFileQuick Scan Pro
Deletes file by its sha256 identifier.
deleteFirewallPoliciesFirewall Policies
Delete a set of Firewall Policies by specifying their IDs
DeleteGroupASPM
DeleteGroupsV1Profile Groups
Delete profile groups by IDs
deleteHostGroupsHost Group
Delete a set of Host Groups by specifying their IDs
DeleteImageDetailsFalcon Container
Delete Images by ids.
DeleteIntegrationASPM
Delete an existing integration by its ID
DeleteIntegrationTaskASPM
Delete an existing integration task by its ID
deleteIOAExclusionsV1IOA Exclusions
Delete the IOA exclusions by id
DeleteIOCIOCs
Delete an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (DELETE /iocs/entities/indicators/v1). ***
DeleteLookupFileNGSIEM
Delete Lookup File in NGSIEM
deleteMLExclusionsV1ML Exclusions
Delete the ML exclusions by id
DeleteNotificationsV1Recon
Delete notifications based on IDs.
DeleteObjectCustom Storage
Delete the specified object
DeleteParserNGSIEM
Delete Parser in NGSIEM
deletePoliciesFileVantage
Deletes 1 or more policies.
DeletePolicyImage Assessment Policies
Delete Image Assessment Policy by policy UUID
DeletePolicyGroupImage Assessment Policies
Delete Image Assessment Policy Group entities
deletePreventionPoliciesPrevention Policies
Delete a set of Prevention Policies by specifying their IDs
DeleteRegistryEntitiesFalcon Container
Delete the registry entity identified by the entity UUID
DeleteReportFalconx Sandbox
Delete report based on the report ID.
deleteRTResponsePoliciesResponse Policies
Delete a set of Response Policies by specifying their IDs
deleteRuleGroupsFileVantage
Deletes 1 or more rule groups
DeleteRuleMixin0Cloud Policies
Delete a rule
DeleteRuleOverrideCloud Policies
Delete a rule override
deleteRulesFileVantage
Deletes 1 or more rules from the specified rule group.
DeleteRulesV1Recon
Delete monitoring rules.
DeleteSampleV2Falconx Sandbox
Removes a sample, including file, meta and submissions from the collection
DeleteSampleV3Sample Uploads
Removes a sample, including file, meta and submissions from the collection
DeleteSavedQueryNGSIEM
Delete Saved Query in NGSIEM
DeleteScanResultQuick Scan Pro
Deletes the result of an QuickScan Pro scan.
deleteScheduledExclusionsFileVantage
Deletes 1 or more scheduled exclusions from the provided policy id.
deleteSensorUpdatePoliciesSensor Update Policy
Delete a set of Sensor Update Policies by specifying their IDs
deleteSensorVisibilityExclusionsV1Sensor Visibility Exclusions
Delete the sensor visibility exclusions by id
DeleteSuppressionRulesCloud Policies
Delete Suppression Rules by ID
DeleteTagsASPM
Remove existing tags
DeleteThirdPartyPasskeyRegistryFalcon ID
Deletes third party passkey registries
DeleteUserUser Management
Deprecated : Please use DELETE /user-management/entities/users/v1.
deleteUserGroupMembersMSSP (Flight Control)
Delete user group members entry.
deleteUserGroupsMSSP (Flight Control)
Delete user groups by ID.
deleteUserV1User Management
Delete a user permanently.
DeleteVersionedObjectCustom Storage
Delete the specified versioned object
DescribeCollectionCustom Storage
Fetch metadata about an existing collection
DescribeCollectionsCustom Storage
Fetch metadata about one or more existing collections
DevicesActionsDeleteV1Hosts
Permanently delete hosts from the system.
DevicesCountIOCs
Number of hosts in your customer account that have observed a given custom IOC
DevicesRanOnIOCs
Find hosts that have observed a given custom IOC.
DiscoverCloudAzureDownloadCertificateCSPM Registration
Returns JSON object(s) that contain the base64 encoded certificate for a service principal.
DismissAffectedEntityV3SaaS Security
POST Dismiss Affected Entity
DismissSecurityCheckV3SaaS Security
POST Dismiss Security Check by ID
DownloadExportFileFalcon Container
Download an export file
DownloadExportFileMixin0Serverless Exports
Download an export file
DownloadFeedArchiveIntelligence Feeds
Downloads the content as a zip archive for a given feed item ID
DownloadFileDownloads
Gets pre-signed URL for the file
DownloadSensorInstallerByIdSensor Download
Download sensor installer by SHA256 ID
DownloadSensorInstallerByIdV2Sensor Download
Download sensor installer by SHA256 ID
DownloadSensorInstallerByIdV3Sensor Download
Download sensor installer by SHA256 ID
entities.access-tags.get.v1Case Management
Get access tags
entities.alert-evidence.post.v1Case Management
Adds the given list of alert evidence to the specified case.
entities.case-tags.delete.v1Case Management
Removes the specified tags from the specified case.
entities.case-tags.post.v1Case Management
Adds the given list of tags to the specified case.
entities.cases.patch.v2Case Management
Updates given fields on the specified case.
entities.cases.post.v2Case Management
Retrieves all Cases given their IDs.
entities.cases.put.v2Case Management
Creates the given Case
entities.classification.delete.v2Data Protection Configuration
Deletes classifications that match the provided ids
entities.classification.get.v2Data Protection Configuration
Gets the classifications that match the provided ids
entities.classification.patch.v2Data Protection Configuration
Update classifications
entities.classification.post.v2Data Protection Configuration
Create classifications
entities.cloud-application.createData Protection Configuration
Persist the given cloud application for the provided entity instance
entities.cloud-application.deleteData Protection Configuration
Delete cloud application
entities.cloud-application.getData Protection Configuration
Get a particular cloud-application
entities.cloud-application.patchData Protection Configuration
Update a cloud application
entities.content-pattern.createData Protection Configuration
Persist the given content pattern for the provided entity instance
entities.content-pattern.deleteData Protection Configuration
Delete content pattern
entities.content-pattern.getData Protection Configuration
Get a particular content-pattern(s)
entities.content-pattern.patchData Protection Configuration
Update a content pattern
entities.enterprise-account.createData Protection Configuration
Persist the given enterprise account for the provided entity instance
entities.enterprise-account.deleteData Protection Configuration
Delete enterprise account
entities.enterprise-account.getData Protection Configuration
Get a particular enterprise-account(s)
entities.enterprise-account.patchData Protection Configuration
Update a enterprise account
entities.event-evidence.post.v1Case Management
Adds the given list of event evidence to the specified case.
entities.fields.get.v1Case Management
Get fields by ID
entities.file-details.get.v1Case Management
Get file details by id
entities.file-details.patch.v1Case Management
Update file details
entities.file-type.getData Protection Configuration
Get a particular file-type
entities.files.delete.v1Case Management
Delete file details by id
entities.files_bulk-download.post.v1Case Management
Download multiple existing file from case as a ZIP
entities.files_download.get.v1Case Management
Download existing file from case
entities.files_download.post.v1Case Management
Download existing files from case
entities.files_upload.post.v1Case Management
Upload file for case
entities.get-rtr-file-metadata.post.v1Case Management
gets metadata for a file via RTR without retrieving it
entities.latest-rules.get.v1Correlation Rules
Retrieve latest rule versions by rule IDs
entities.local-application-group.createData Protection Configuration
Persist the given local application group for the provided entity instance
entities.local-application-group.deleteData Protection Configuration
Soft Delete local application.
entities.local-application-group.getData Protection Configuration
Get specific local application groups
entities.local-application-group.patchData Protection Configuration
Update a local application group
entities.local-application.createData Protection Configuration
Persist the given local application for the provided entity instance
entities.local-application.deleteData Protection Configuration
Soft Delete local application.
entities.local-application.getData Protection Configuration
Get a particular local application
entities.local-application.patchData Protection Configuration
Update a local application
entities.merge.post.v1Case Management
Merges a source case into a destination case.
entities.notification-groups.delete.v1Case Management
Delete notification groups by ID
entities.notification-groups.delete.v2Case Management
Delete notification groups by ID
entities.notification-groups.get.v1Case Management
Get notification groups by ID
entities.notification-groups.get.v2Case Management
Get notification groups by ID
entities.notification-groups.patch.v1Case Management
Update notification group
entities.notification-groups.patch.v2Case Management
Update notification group
entities.notification-groups.post.v1Case Management
Create notification group
entities.notification-groups.post.v2Case Management
Create notification group
entities.perform_actionHosts
Performs the specified action on the provided group IDs.
entities.policy.delete.v2Data Protection Configuration
Deletes policies that match the provided ids
entities.policy.get.v2Data Protection Configuration
Gets policies that match the provided ids
entities.policy.patch.v2Data Protection Configuration
Update policies
entities.policy.post.v2Data Protection Configuration
Create policies
entities.policy.precedence.post.v1Data Protection Configuration
Update Policy Precedence
entities.processesIOCs
For the provided ProcessID retrieve the process details
entities.retrieve-rtr-file.post.v1Case Management
retrieves a file from host using RTR and adds it to a case
entities.retrieve-rtr-recent-file.post.v1Case Management
RetrieveRecentRTRFile retrieves a recently fetched RTR file and adds it to a case
entities.rule-versions.delete.v1Correlation Rules
Delete versions by IDs
entities.rule-versions_export.post.v1Correlation Rules
Export rule versions
entities.rule-versions_import.post.v1Correlation Rules
Import rule versions
entities.rule-versions_publish.patch.v1Correlation Rules
Publish existing rule version
entities.rules.delete.v1Correlation Rules
Delete rules by IDs
entities.rules.get.v1Correlation Rules
Retrieve rules by IDs
entities.rules.get.v2Correlation Rules
Retrieve rule versions by IDs
entities.rules.patch.v1Correlation Rules
Update rules
entities.rules.post.v1Correlation Rules
Create rule
entities.rules_ownership.put.v1Correlation Rules Admin
Change the owner of an existing Correlation Rule
entities.rules_ownership.put.v2Correlation Rules Admin
Bulk change the owner of existing Correlation Rules
entities.sensitivity-label.create-v2Data Protection Configuration
Create new sensitivity label (V2)
entities.sensitivity-label.delete-v2Data Protection Configuration
Delete sensitivity labels matching the IDs (V2)
entities.sensitivity-label.get-v2Data Protection Configuration
Get sensitivity label matching the IDs (V2)
entities.slas.delete.v1Case Management
Delete SLAs
entities.slas.get.v1Case Management
Get SLAs by ID
entities.slas.patch.v1Case Management
Update SLA
entities.slas.post.v1Case Management
Create SLA
entities.states.v1Device Content
Retrieve the host content state for a number of ids between 1 and 100.
entities.template-snapshots.get.v1Case Management
Get template snapshots
entities.templates.delete.v1Case Management
Delete templates
entities.templates.get.v1Case Management
Get templates by ID
entities.templates.get.v1Mixin0Correlation Rules
Retrieve rule templates by IDs
entities.templates.patch.v1Case Management
Update template
entities.templates.post.v1Case Management
Create template
entities.templates_export.get.v1Case Management
Export templates to files in a zip archive
entities.templates_import.post.v1Case Management
Import a template from a file
entities.templates_rules.post.v1Correlation Rules
Create rule from template
entities.web-location-group.createData Protection Configuration
Create a web location group
entities.web-location-group.deleteData Protection Configuration
Soft delete web location groups
entities.web-location-group.getData Protection Configuration
Get specific web location groups
entities.web-location-group.patchData Protection Configuration
Update a web location group
entities.web-location.create-v2Data Protection Configuration
Persist the given web-locations
entities.web-location.delete-v2Data Protection Configuration
Delete web-location
entities.web-location.get-v2Data Protection Configuration
Get web-location entities matching the provided ID(s)
entities.web-location.patch-v2Data Protection Configuration
Update a web-location
entities_vertices_getThreatGraph
Retrieve metadata for a given vertex ID.
entities_vertices_getv2ThreatGraph
Retrieve metadata for a given vertex ID
EntitiesAgentTemplatesV1Agent Templates
Retrieve agent template entities for the provided IDs
EntitiesKnowledgeBaseAuditEventsV1Knowledge Base Audit Events
Retrieve knowledge base audit event entities by their IDs.
EntitiesKnowledgeBaseFilesCreateV1Knowledge Base Files
Upload a file to a knowledge base.
EntitiesKnowledgeBaseFilesDeleteV1Knowledge Base Files
Delete document from knowledge base.
EntitiesKnowledgeBaseFilesDownloadV1Knowledge Base Files
Download knowledge base file entities for the provided id.
EntitiesKnowledgeBaseFilesUpdateV1Knowledge Base Files
Update an existing file in a knowledge base.
EntitiesKnowledgeBaseFilesV1Knowledge Base Files
Retrieve knowledge base file entities for the provided id.
EntitiesKnowledgeBasesCreateV1Knowledge Bases
Create or update a knowledge base.
EntitiesKnowledgeBasesUpdateV1Knowledge Bases
Update an existing knowledge base.
EntitiesKnowledgeBasesV1Knowledge Bases
Retrieve knowledge base entities for the provided id.
EntitiesModelsV1Models
Get Model Entities by IDs
entitiesRolesGETV2User Management
Get info about a role
entitiesRolesV1User Management
Get info about a role
EntitiesSpansV1Spans
Retrieve spans for the provided ids.
EntitiesToolsV1Tools
Retrieve tools entities for the provided id.
EnumerateFileDownloads
Enumerates a list of files available for CID
exclusions.aggregates.v2ML Exclusions
Get exclusion aggregates as specified via json in request body.
exclusions.create.v2ML Exclusions
Create the exclusions, with ancestor fields.
exclusions.delete.v2ML Exclusions
Delete the exclusions by id, with ancestor fields.
exclusions.get-all.v2ML Exclusions
Get all exclusions.
exclusions.get-reports.v2ML Exclusions
Create a report of ML exclusions scoped by the given filters
exclusions.get.v2ML Exclusions
Get the exclusions by id, with ancestor fields.
exclusions.perform-action.v2ML Exclusions
Actions used to manipulate the content of exclusions, with ancestor fields.
exclusions.sdmf-query.v1ML Exclusions
Executes an SDMF data frame query against exclusion entities
exclusions.search.v2ML Exclusions
Search for exclusions, with ancestor fields.
exclusions.update.v2ML Exclusions
Update the exclusions by id, with ancestor fields.
ExecuteCommandAPI Integrations
Execute a command.
ExecuteCommandProxyAPI Integrations
Execute a command and proxy the response directly.
ExecuteFunctionDataASPM
A selected list of queryLanguage queries. request & response are in MSA format
ExecuteFunctionDataCountASPM
A selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionDataQueryASPM
A selected list of queryLanguage queries. request & response are in MSA format
ExecuteFunctionDataQueryCountASPM
A selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionsASPM
A selected list of queryLanguage services queries. request & response are in MSA format
ExecuteFunctionsCountASPM
A selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionsOvertimeASPM
A selected list of queryLanguage overtime queries. request & response are in MSA format
ExecuteFunctionsQueryASPM
A selected list of queryLanguage services queries. request & response are in MSA format
ExecuteFunctionsQueryCountASPM
A selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionsQueryOvertimeASPM
A selected list of queryLanguage overtime queries. request & response are in MSA format
ExecuteQueryASPM
Execute a query.
extAggregateClusterAssessmentsContainer Image Compliance
get the assessments for each cluster
extAggregateFailedContainersByRulesPathContainer Image Compliance
get the containers grouped into rules on which they failed
extAggregateFailedContainersCountBySeverityContainer Image Compliance
get the failed containers count grouped into severity levels
extAggregateFailedImagesByRulesPathContainer Image Compliance
get the images grouped into rules on which they failed
extAggregateFailedImagesCountBySeverityContainer Image Compliance
get the failed images count grouped into severity levels
extAggregateFailedRulesByClustersContainer Image Compliance
get the failed rules for each cluster grouped into severity levels
extAggregateFailedRulesByImagesContainer Image Compliance
get images with failed rules, rule count grouped by severity for each image
extAggregateFailedRulesCountBySeverityContainer Image Compliance
get the failed rules count grouped into severity levels
extAggregateImageAssessmentsContainer Image Compliance
get the assessments for each image
extAggregateRulesAssessmentsContainer Image Compliance
get the assessments for each rule
extAggregateRulesByStatusContainer Image Compliance
get the rules grouped by their statuses
ExternalCreateConnectorConfigNGSIEM
Create a new configuration for a data connector
ExternalCreateDataConnectionNGSIEM
Create a new data connection
ExternalDeleteConnectorConfigsNGSIEM
Delete data connection config
ExternalDeleteDataConnectionNGSIEM
Delete a data connection
ExternalGetDataConnectionByIDNGSIEM
Get data connection by ID
ExternalGetDataConnectionStatusNGSIEM
Get data connection provisioning status
ExternalGetDataConnectionTokenNGSIEM
Get Ingest token for data connection
ExternalListConnectorConfigsNGSIEM
List configurations for a data connector
ExternalListDataConnectionsNGSIEM
List and search data connections
ExternalListDataConnectorsNGSIEM
List available data connectors
ExternalPatchConnectorConfigNGSIEM
Patch configurations for a data connector
ExternalRegenerateDataConnectionTokenNGSIEM
Regenerate Ingest token for data connection
ExternalUpdateDataConnectionNGSIEM
Update a data connection
ExternalUpdateDataConnectionStatusNGSIEM
Update data connection status
ExtractionCreateV1Sample Uploads
Extracts files from an uploaded archive and copies them to internal storage making it available for content analysis.
ExtractionGetV1Sample Uploads
Retrieves the files extraction operation statuses.
ExtractionListV1Sample Uploads
Retrieves the files extractions in chunks.
fdrschema.combined.event.getFDR
Fetch combined schema
fdrschema.entities.event.getFDR
Fetch event schema by ID
fdrschema.entities.field.getFDR
Fetch field schema by ID
fdrschema.queries.event.getFDR
Get list of event IDs given a particular query.
fdrschema.queries.field.getFDR
Get list of field IDs given a particular query.
FetchFilesDownloadInfoDownloads
Get files info and pre-signed download URLs
FetchFilesDownloadInfoV2Downloads
Get cloud security tools info and pre-signed download URLs
FindContainersByContainerRunTimeVersionKubernetes Protection
Retrieve containers by container_runtime_version
FindContainersCountAffectedByZeroDayVulnerabilitiesKubernetes Protection
Retrieve containers count affected by zero day vulnerabilities
get-accountsDiscover
Get details on accounts by providing one or more IDs.
get-applicationsDiscover
Get details on applications by providing one or more IDs.
get-ecosystem-subsidiariesExposure Management
Retrieves detailed information about ecosystem subsidiaries by ID.
get-eventsFirewall Management
Get events entities by ID and optionally version
get-external-assetsExposure Management
Get details on external assets by providing one or more IDs.
get-firewall-fieldsFirewall Management
Get the firewall field specifications by ID
get-global-configsNetwork Scan Global Configs
Get “global-configs” for the CID
get-hostsDiscover
Get details on assets by providing one or more IDs.
get-iot-hostsDiscover
Get details on IoT assets by providing one or more IDs.
get-loginsDiscover
Get details on logins by providing one or more IDs.
get-malicious-files-by-idsODS (On Demand Scan)
Get malicious files by ids.
get-network-locationsFirewall Management
Get a summary of network locations entities by ID
get-network-locations-detailsFirewall Management
Get network locations entities by ID
get-networksNetwork Scan Networks
Get “networks” by their IDs
get-patternsCustom IOA
Get pattern severities by ID.
get-platformsFirewall Management
Get platforms by ID, e.g., windows or mac or droid
get-platformsMixin0Custom IOA
Get platforms by ID.
get-policy-containersFirewall Management
Get policy container entities by policy ID
get-rule-groupsFirewall Management
Get rule group entities by ID.
get-rule-groupsMixin0Custom IOA
Get rule groups by ID.
get-rule-typesCustom IOA
Get rule types by ID.
get-rulesFirewall Management
Get rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string)
get-rules-getCustom IOA
Get rules by ID and optionally with cid and/or version in the following format: [cid:]ID[:version].
get-rulesMixin0Custom IOA
Get rules by ID and optionally with cid and/or version in the following format: [cid:]ID[:version].
get-scan-host-metadata-by-idsODS (On Demand Scan)
Get scan hosts by ids.
get-scan-run-reportsNetwork Scan Scan Run Reports
Downloads scan run report in CSV format
get-scan-runsNetwork Scan Scan Runs
Get “scan-runs” by their IDs
get-scannersNetwork Scan Scanners
Get “scanners” by their IDs
get-scansNetwork Scan Scans
Get “scans” by their IDs
get-scans-by-scan-idsODS (On Demand Scan)
Get Scans by IDs.
get-scans-by-scan-ids-v2ODS (On Demand Scan)
Get Scans by IDs.
get-scheduled-scans-by-scan-idsODS (On Demand Scan)
Get ScheduledScans by IDs.
get-template-configsNetwork Scan Templates
Get details on the network scan template configurations
get-templatesNetwork Scan Templates
Get “templates” by their IDs
get-zonesNetwork Scan Zones
Get “zones” by their IDs
get_policy_rulesIdentity Protection
Get policy rules
get_policy_rulesIdentity Protection
Get policy rules
get_policy_rules_queryIdentity Protection
Query policy rule IDs
get_policy_rules_queryIdentity Protection
Query policy rule IDs
GetAccessibleScopesAPI Clients
Get all available scopes for customer.
getActionsMixin0FileVantage
Retrieves the processing results for 1 or more actions.
GetActionsV1Recon
Get actions based on their IDs.
GetActivityMonitorV3SaaS Security
GET Activity Monitor
GetAgentVersionsV1Agent Versions
Retrieve agent version entities for the provided ids.
GetAggregateDetectsDetects
Deprecated: This endpoint will be decommissioned on September 30, 2025.
GetAggregateFilesQuarantine
Get quarantine file aggregates as specified via json in request body.
GetAlertsV3SaaS Security
GET Alert by ID or GET Alerts
GetAllAPIClientIdsForCustomerAPI Clients
Get All API client ID(s) for customer.
GetAPIClientsAPI Clients
Get API Client(s) based on API Client ID(s) provided as request parameter(s) ‘ids’.
GetAppInventorySaaS Security
GET Applications Inventory
GetAppInventoryUsersSaaS Security
GET Application Users
GetArchiveExportCAO Hunting
Creates an Archive Export
GetArtifactsFalconx Sandbox
Download IOC packs, PCAP files, memory dumps, and other analysis artifacts.
getAssessmentsByScoreV1Zero Trust Assessment
Get Zero Trust Assessment data for one or more hosts by providing a customer ID (CID) and a range of scores.
getAssessmentV1Zero Trust Assessment
Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID) and a customer ID (CID).
GetAssetInventoryV3SaaS Security
GET Data Inventory
getAuditV1Zero Trust Assessment
Get the Zero Trust Assessment audit report for one customer ID (CID).
GetAvailableRoleIdsUser Management
Deprecated : Please use GET /user-management/queries/roles/v1.
GetAWSAccountsCloud Connect AWS
Retrieve a set of AWS Accounts by specifying their IDs
GetAWSAccountsMixin0Kubernetes Protection
Provides a list of AWS accounts.
GetAWSSettingsCloud Connect AWS
Retrieve a set of Global Settings which are applicable to all provisioned AWS accounts
GetAzureInstallScriptKubernetes Protection
Provides the script to run for a given tenant id and subscription IDs
GetAzureTenantConfigKubernetes Protection
Gets the Azure tenant Config
GetAzureTenantIDsKubernetes Protection
Provides all the azure subscriptions and tenants
GetBehaviorDetectionsCSPM Registration
Get list of detected behaviors
GetCaseActivityByIdsMessage Center
Retrieve activities for given id’s
GetCaseEntitiesByIDsMessage Center
Retrieve message center cases
getChangesFileVantage
Retrieve information on changes
getChildrenMSSP (Flight Control)
Get link to child customer by child CID(s)
getChildrenV2MSSP (Flight Control)
Get link to child customer by child CID(s)
getCIDGroupByIdV1MSSP (Flight Control)
Deprecated : Please use GET /mssp/entities/cid-groups/v2.
getCIDGroupByIdV2MSSP (Flight Control)
Get CID Groups by ID.
getCIDGroupMembersByV1MSSP (Flight Control)
Deprecated : Please use GET /mssp/entities/cid-group-members/v2.
getCIDGroupMembersByV2MSSP (Flight Control)
Get CID group members by CID Group ID.
getCloudEventIDsCSPM Registration
Deprecated: use cdrapi entities/event-details/v1 ‘logscale_related_events_query’ instead.
GetCloudSecurityIntegrationStateASPM
Get Cloud Security integration state
GetClustersKubernetes Protection
Provides the clusters acknowledged by the Kubernetes Protection service
getCombinedAssessmentsQueryConfiguration Assessment
Search for assessments in your environment by providing an FQL filter and paging details.
GetCombinedCloudClustersKubernetes Protection
Returns a combined list of provisioned cloud accounts and known kubernetes clusters
GetCombinedImagesContainer Images
Get image assessment results by providing an FQL filter and paging details
GetCombinedPluginConfigsAPI Integrations
Queries for config resources and returns details
GetCombinedSensorInstallersByQuerySensor Download
Get sensor installer details by provided query
GetCombinedSensorInstallersByQueryV2Sensor Download
Get sensor installer details by provided query
GetCombinedSensorInstallersByQueryV3Sensor Download
Get sensor installer details by provided query
GetCombinedVulnerabilitiesSARIFServerless Vulnerabilities
Retrieve all lambda vulnerabilities that match the given query and return in the SARIF format
GetComplianceControlsCloud Policies
Get compliance controls by ID
GetComplianceFrameworksCloud Policies
Get compliance frameworks by ID
GetConfigurationDetectionEntitiesCSPM Registration
Get misconfigurations based on the ID - including custom policy detections in addition to default policy detections.
GetConfigurationDetectionIDsV2CSPM Registration
Get list of active misconfiguration ids - including custom policy detections in addition to default policy detections.
GetConfigurationDetectionsCSPM Registration
Get list of active misconfigurations.
getContentsFileVantage
Retrieves the content captured for the provided change id
getContentUpdatePoliciesContent Update Policies
Retrieve a set of Content Update Policies by specifying their IDs
GetCredentialsFalcon Container
Gets the registry credentials
GetCredentialsIACCloud Snapshots
Gets the registry credentials (external endpoint)
GetCredentialsMixin0Cloud Snapshots
Gets the registry credentials
GetCSPMAwsAccountCSPM Registration
Returns information about the current status of an AWS account.
GetCSPMAwsAccountScriptsAttachmentCSPM Registration
Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetCSPMAwsConsoleSetupURLsCSPM Registration
Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetCSPMAzureAccountCSPM Registration
Return information about Azure account registration
GetCSPMAzureManagementGroupCSPM Registration
Return information about Azure management group registration
GetCSPMAzureUserScriptsAttachmentCSPM Registration
Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment
GetCSPMGCPAccountCSPM Registration
Returns information about the current status of an GCP account.
GetCSPMGCPServiceAccountsExtCSPM Registration
Returns the service account id and client email for external clients.
GetCSPMGCPUserScriptsAttachmentCSPM Registration
Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment
GetCSPMGCPValidateAccountsExtCSPM Registration
Run a synchronous health check.
GetCSPMPoliciesDetailsCSPM Registration
Given an array of policy IDs, returns detailed policies information.
GetCSPMPolicyCSPM Registration
Given a policy ID, returns detailed policy information.
GetCSPMPolicySettingsCSPM Registration
Returns information about current policy settings.
GetCSPMScanScheduleCSPM Registration
Returns scan schedule configuration for one or more cloud platforms.
GetD4CAwsAccountD4C Registration
Returns information about the current status of an AWS account.
GetD4CAWSAccountScriptsAttachmentD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetD4CAwsConsoleSetupURLsD4C Registration
Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetD4CCGPAccountD4C Registration
Returns information about the current status of an GCP account.
GetD4CGCPServiceAccountsExtD4C Registration
Returns the service account id and client email for external clients.
GetD4CGCPUserScriptsD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their GCP environment
GetD4CGCPUserScriptsAttachmentD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment
GetDashboardTemplateNGSIEM
Retrieve Dashboard(s) in NGSIEM as LogScale YAML Template.
getDefaultDeviceControlPoliciesDevice Control Policies
Retrieve the configuration for a Default Device Control Policy
getDefaultDeviceControlSettingsDevice Control Policies
Get default device control settings (USB and Bluetooth)
GetDeliverySettingsDelivery Settings
Get Delivery Settings
GetDeploymentsExternalV1Deployments
Get deployment resources by ids
GetDetectSummariesDetects
Deprecated: This endpoint will be decommissioned on September 30, 2025.
getDeviceControlPoliciesDevice Control Policies
Retrieve a set of Device Control Policies by specifying their IDs
getDeviceControlPoliciesV2Device Control Policies
Get device control policies for the given filter criteria.
GetDeviceCountCollectionQueriesByFilterFalcon Complete Dashboard
Retrieve device count collection Ids that match the provided FQL filter, criteria with scrolling enabled
GetDeviceDetailsHosts
Get details on one or more hosts by providing host IDs in a POST body.
GetDeviceDetailsV1Hosts
Get details on one or more hosts by providing agent IDs (AID).
GetDeviceDetailsV2Hosts
Get details on one or more hosts by providing host IDs as a query parameter.
GetDeviceInventoryV3SaaS Security
GET Device Inventory
GetDiscoverCloudAzureAccountD4C Registration
Return information about Azure account registration
GetDiscoverCloudAzureTenantIDsD4C Registration
Return available tenant ids for discover for cloud
GetDiscoverCloudAzureUserScriptsD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their Azure environment
GetDiscoverCloudAzureUserScriptsAttachmentD4C Registration
Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment
GetDriftIndicatorsValuesByDateDrift Indicators
Returns the count of Drift Indicators by the date. by default it’s for 7 days.
GetEnrichedAssetCloud Policies
Gets enriched assets that combine a primary resource with all its related resources
GetEntityIDsByQueryPOSTDeployments
returns the release notes for the IDs in the request
GetEntityIDsByQueryPOSTV2Deployments
returns the release notes for the IDs in the request with EA and GA dates in ISO 8601 format
getEvaluationLogicSpotlight Evaluation Logic
Get details on evaluation logic items by providing one or more IDs.
getEvaluationLogicMixin0Configuration Assessment Evaluation Logic
Get details on evaluation logic items by providing one or more finding IDs.
GetEvaluationResultCloud Policies
Gets evaluation results based on the provided rule
GetEventsBodyTailored Intelligence
Get event body for the provided event ID
GetEventsEntitiesTailored Intelligence
Get events entities for specified ids.
GetExecutorNodesASPM
Get all the relay nodes
GetExecutorNodesMetadataASPM
Get metadata about all executor nodes
GetExportJobsV1Recon
Get the status of export jobs based on their IDs.
GetFileContentForExportJobsV1Recon
Download the file associated with a job ID.
getFirewallPoliciesFirewall Policies
Retrieve a set of Firewall Policies by specifying their IDs
GetGroupHierarchyASPM
Get group hierarchy
GetGroupsV1Mixin0Profile Groups
Get profile groups by IDs with full details
GetGroupsV2ASPM
GetGroupUsersV1Profile Groups
Get a list of groups with users that belong to them
GetGroupV2ASPM
Get group details
GetHelmValuesYamlKubernetes Protection
Provides a sample Helm values.yaml file for a customer to install alongside the agent Helm chart
GetHorizonD4CScriptsD4C Registration
Returns static install scripts for Horizon.
getHostGroupsHost Group
Retrieve a set of Host Groups by specifying their IDs
GetHostMigrationIDsV1Host Migration
Query host migration IDs.
GetHostMigrationsV1Host Migration
Get host migration details.
GetHuntingGuidesCAO Hunting
Retrieves a list of Hunting Guides
GetImageAssessmentReportFalcon Container
Retrieves the Assessment report for the Image ID provided.
GetIndicatorsReportIOC
Launch an indicators report creation job
GetIntegrationsASPM
Get a list of all the integrations
GetIntegrationsV2ASPM
Get a list of all the integrations
GetIntegrationsV3SaaS Security
GET Integrations
GetIntegrationTasksASPM
Get all the integration tasks
GetIntegrationTasksAdminASPM
Get all the integration tasks, requires admin scope
GetIntegrationTasksMetadataASPM
Get metadata about all integration tasks
GetIntegrationTasksV2ASPM
Get all the integration tasks
GetIntegrationTypesASPM
Get all the integration types
GetIntelActorEntitiesIntel
Retrieve specific actors using their actor IDs.
GetIntelIndicatorEntitiesIntel
Retrieve specific indicators using their indicator IDs.
GetIntelligenceQueriesCAO Hunting
Retrieves the details of a list of Intelligence queries IDs
GetIntelReportEntitiesIntel
Retrieve specific reports using their report IDs.
GetIntelReportPDFIntel
Return a Report PDF attachment
GetIntelRuleEntitiesIntel
Retrieve details for rule sets for the specified ids.
GetIntelRuleFileIntel
Download earlier rule sets.
GetIOAEventsCSPM Registration
For CSPM IOA events, gets list of IOA events.
getIOAExclusionsV1IOA Exclusions
Get a set of IOA Exclusions by specifying their IDs
GetIOAUsersCSPM Registration
For CSPM IOA users, gets list of IOA users.
GetIOCIOCs
Get an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (GET /iocs/entities/indicators/v1). ***
GetLatestIntelRuleFileIntel
Download the latest rule set.
GetLocationsKubernetes Protection
Provides the cloud locations acknowledged by the Kubernetes Protection service
GetLookupFileNGSIEM
Retrieve Lookup File in NGSIEM
GetLookupFromPackageV1NGSIEM
Download lookup file in package from NGSIEM
GetLookupFromPackageWithNamespaceV1NGSIEM
Download lookup file in namespaced package from NGSIEM
GetLookupV1NGSIEM
Download lookup file from NGSIEM
GetMalQueryDownloadV1MalQuery
Download a file indexed by MalQuery.
GetMalQueryEntitiesSamplesFetchV1MalQuery
Fetch a zip archive with password ‘infected’ containing the samples.
GetMalQueryMetadataV1MalQuery
Retrieve indexed files metadata by their hash
GetMalQueryQuotasV1MalQuery
Get information about search and download quotas in your environment
GetMalQueryRequestV1MalQuery
Check the status and results of an asynchronous request, such as hunt or exact-search.
GetMalwareEntitiesIntel
Get malware entities for specified ids.
GetMalwareMitreReportIntel
Export Mitre ATT&CK information for a given malware family.
GetMemoryDumpFalconx Sandbox
Get memory dump content, as binary
GetMemoryDumpExtractedStringsFalconx Sandbox
Get extracted strings from a memory dump
GetMemoryDumpHexDumpFalconx Sandbox
Get hex view of a memory dump
GetMetricsV3SaaS Security
GET Metrics
GetMigrationDestinationsV1Host Migration
Get destinations for a migration.
GetMigrationIDsV1Host Migration
Query migration jobs.
GetMigrationsV1Host Migration
Get migration job details.
GetMitreReportIntel
Export Mitre ATT&CK information for a given actor.
getMLExclusionsV1ML Exclusions
Get a set of ML Exclusions by specifying their IDs
GetNotificationsDetailedTranslatedV1Recon
Get detailed notifications based on their IDs.
GetNotificationsDetailedV1Recon
Get detailed notifications based on their IDs.
GetNotificationsExposedDataRecordsV1Recon
Get notifications exposed data records based on their IDs.
GetNotificationsTranslatedV1Recon
Get notifications based on their IDs.
GetNotificationsV1Recon
Get notifications based on their IDs.
GetObjectCustom Storage
Get the bytes for the specified object
GetObjectMetadataCustom Storage
Get the metadata for the specified object
GetOnlineState.V1Hosts
Get the online status for one or more hosts by specifying each host’s unique ID.
GetParserNGSIEM
Retrieve Parser in NGSIEM.
GetParserTemplateNGSIEM
Retrieve Parser in NGSIEM as LogScale YAML Template
getPoliciesFileVantage
Retrieves the configuration for 1 or more policies.
getPreventionPoliciesPrevention Policies
Retrieve a set of Prevention Policies by specifying their IDs
GetQuarantineFilesQuarantine
Get quarantine file metadata for specified ids.
GetQueriesAlertsV1Alerts
Deprecated: please use version v2 of this endpoint.
GetQueriesAlertsV2Alerts
Retrieves all Alerts ids that match a given query.
getRemediationsSpotlight Vulnerabilities
Get details on remediations by providing one or more IDs
getRemediationsV2Spotlight Vulnerabilities
Get details on remediation by providing one or more IDs
GetReportByReferenceFalcon Container
Get image assessment scan report by image reference (v2)
GetReportByScanIDFalcon Container
Get image assessment scan report by scan UUID (v2)
GetReportsFalconx Sandbox
Get a full sandbox report.
GetRolesUser Management
Deprecated : Please use GET /user-management/entities/roles/v1.
getRolesByIDMSSP (Flight Control)
Get link between user group and CID group by ID.
getRTResponsePoliciesResponse Policies
Retrieve a set of Response Policies by specifying their IDs
GetRuleCloud Policies
Get a rule by id
getRuleDetailsConfiguration Assessment
Get rules details for provided one or more rule IDs
getRuleGroupsFileVantage
Retrieves the rule group details for 1 or more rule groups.
GetRuleInputSchemaCloud Policies
Get rule input schema for given resource type
GetRuleOverrideCloud Policies
Get a rule override
getRulesFileVantage
Retrieves the configuration for 1 or more rules.
GetRulesEntitiesTailored Intelligence
Get rules entities for specified ids.
getRulesMetadataByIDKubernetes Container Compliance
Retrieve detailed compliance rule information including descriptions, remediation steps, and audit procedures by specifying rule identifiers.
GetRulesV1Recon
Get monitoring rules based on their IDs.
GetRuntimeDetectionsCombinedV2Container Detections
Retrieve container runtime detections by the provided search criteria
GetSampleV2Falconx Sandbox
Retrieves the file associated with the given ID (SHA256)
GetSampleV3Sample Uploads
Retrieves the file associated with the given ID (SHA256)
GetSavedQueryTemplateNGSIEM
Retrieve Saved Quer(ies) in NGSIEM as LogScale YAML Template.
GetSavedSearchesExecuteV1Foundry LogScale
Get the results of a saved search
GetSavedSearchesJobResultsDownloadV1Foundry LogScale
Get the results of a saved search as a file
GetScanReportCloud Snapshots
retrieve the scan report for an instance
GetScanResultQuick Scan Pro
Gets the result of an QuickScan Pro scan.
GetScansQuick Scan
Check the status of a volume scan.
GetScansAggregatesQuick Scan
Get scans aggregations as specified via json in request body.
getScheduledExclusionsFileVantage
Retrieves the configuration of 1 or more scheduled exclusions from the provided policy id.
GetSchemaCustom Storage
Get the bytes of the specified schema of the requested collection
GetSchemaMetadataCustom Storage
Get the metadata for the specified schema of the requested collection
GetSearchStatusV1NGSIEM
Get status of search
GetSecurityCheckAffectedV3SaaS Security
GET Security Check Affected
GetSecurityCheckComplianceV3SaaS Security
GET Compliance
GetSecurityChecksV3SaaS Security
GET Security Check by ID or GET List Security Checks
GetSensorAggregatesIdentity Protection
Get sensor aggregates as specified via json in request body.
GetSensorDetailsIdentity Protection
Get details on one or more sensors by providing device IDs in a POST body.
GetSensorInstallersByQuerySensor Download
Get sensor installer IDs by provided query
GetSensorInstallersByQueryV2Sensor Download
Get sensor installer IDs by provided query
GetSensorInstallersByQueryV3Sensor Download
Get sensor installer IDs by provided query
GetSensorInstallersCCIDByQuerySensor Download
Get CCID to use with sensor installers
GetSensorInstallersEntitiesSensor Download
Get sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV2Sensor Download
Get sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV3Sensor Download
Get sensor installer details by provided SHA256 IDs
getSensorUpdatePoliciesSensor Update Policy
Retrieve a set of Sensor Update Policies by specifying their IDs
getSensorUpdatePoliciesV2Sensor Update Policy
Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs
GetSensorUsageHourlySensor Usage
Fetches hourly average.
GetSensorUsageWeeklySensor Usage
Fetches weekly average.
getSensorVisibilityExclusionsV1Sensor Visibility Exclusions
Get a set of Sensor Visibility Exclusions by specifying their IDs
getServiceArtifactsASPM
GetServicesCountASPM
Get the total amount of existing services
GetServiceViolationTypesASPM
Get the different types of violation
GetStaticScriptsKubernetes Protection
Gets static bash scripts that are used during registration
GetSubmissionsFalconx Sandbox
Check the status of a sandbox analysis.
GetSummaryReportsFalconx Sandbox
Get a short summary version of a sandbox report.
GetSupportedSaasV3SaaS Security
GET Supported SaaS
GetSuppressionRulesCloud Policies
Get Suppression Rules by ID
GetSystemLogsV3SaaS Security
GET System Logs
GetSystemUsersV3SaaS Security
GET System Users
GetTagsASPM
Get all the tags
GetThirdPartyPasskeyRegistryFalcon ID
Fetches third party passkey registries
getUserGroupMembersByIDV1MSSP (Flight Control)
Deprecated : Please use GET /mssp/entities/user-group-members/v2.
getUserGroupMembersByIDV2MSSP (Flight Control)
Get user group members by user group ID.
getUserGroupsByIDV1MSSP (Flight Control)
Deprecated : Please use GET /entities/user-groups/v2.
getUserGroupsByIDV2MSSP (Flight Control)
Get user groups by ID.
GetUserGroupsV1Profile Groups
Get a list of users with the groups that they belong to
GetUserInventoryV3SaaS Security
GET User Inventory
GetUserRoleIdsUser Management
Deprecated : Please use GET /user-management/combined/user-roles/v1.
GetUsersV2ASPM
List users
GetVersionedObjectCustom Storage
Get the bytes for the specified object
GetVersionedObjectMetadataCustom Storage
Get the metadata for the specified object
GetVulnerabilitiesIntel
Get vulnerabilities
getVulnerabilitiesSpotlight Vulnerabilities
Get details on vulnerabilities by providing one or more IDs
GrantUserRoleIdsUser Management
Deprecated : Please use POST /user-management/entities/user-role-actions/v1.
GroupActionsV1Mixin0Profile Groups
Perform actions on profile groups (add/remove roles, user groups, FGA objects)
GroupContainersByManagedKubernetes Protection
Group the containers by Managed
GroupUsersActionsV1Mixin0Profile Groups
Add or remove users from profile groups
HeadImageScanInventoryFalcon Container
Get headers for POST request for image scan inventory
highVolumeQueryChangesFileVantage
Returns 1 or more change ids
HostMigrationAggregatesV1Host Migration
Get host migration aggregates as specified via json in request body.
HostMigrationsActionsV1Host Migration
Perform an action on host migrations.
ImageMatchesPolicyFalcon Container
After an image scan, use this operation to see if any images match a policy.
incrementUninstallTokenSensor Update Policy
Increments a bulk maintenance token.
indicator.aggregate.v1IOC
Get Indicators aggregates as specified via json in the request body.
indicator.combined.v1IOC
Get Combined for Indicators.
indicator.create.v1IOC
Create Indicators.
indicator.delete.v1IOC
Delete Indicators by ids.
indicator.get.device_count.v1IOC
Get the number of devices the indicator has run on
indicator.get.devices_ran_on.v1IOC
Get the IDs of devices the indicator has run on
indicator.get.processes_ran_on.v1IOC
Get the number of processes the indicator has run on
indicator.get.v1IOC
Get Indicators by ids.
indicator.sdmf-query.v1IOC
Executes an SDMF data frame query against IOC indicators
indicator.search.v1IOC
Search for Indicators.
indicator.update.v1IOC
Update Indicators.
IngestDataAsyncV1Foundry LogScale
Asynchronously ingest data into the application repository
IngestDataV1Foundry LogScale
Synchronously ingest data into the application repository
InstallParserNGSIEM
Installs a CrowdStrike-managed out-of-the-box (OOTB) parser into the customer’s repository.
IntegrationBuilderEndTransactionV3SaaS Security
POST Data Upload Transaction Completion
IntegrationBuilderGetStatusV3SaaS Security
GET Status
IntegrationBuilderResetV3SaaS Security
Reset
IntegrationBuilderUploadV3SaaS Security
POST Upload
ioc_type.query.v1IOC
Query IOC Types.
ITAutomationCancelTaskExecutionIT Automation
Cancel a task execution specified in the request
ITAutomationCombinedScheduledTasksIT Automation
Returns full details of scheduled tasks matching the filter query parameter.
ITAutomationCreatePolicyIT Automation
Creates a new policy of the specified type.
ITAutomationCreateScheduledTaskIT Automation
Creates a scheduled task from the given request
ITAutomationCreateTaskIT Automation
Creates a task with details from the given request.
ITAutomationCreateTaskGroupIT Automation
Creates a task group from the given request
ITAutomationCreateUserGroupIT Automation
Creates a user group from the given request
ITAutomationDeletePolicyIT Automation
Deletes 1 or more policies.
ITAutomationDeleteScheduledTasksIT Automation
Delete one or more scheduled tasks by providing the scheduled tasks IDs
ITAutomationDeleteTaskIT Automation
Deletes tasks for each provided ID
ITAutomationDeleteTaskGroupsIT Automation
Delete one or more task groups by providing the task group IDs
ITAutomationDeleteUserGroupIT Automation
Deletes user groups for each provided ids
ITAutomationGetAssociatedTasksIT Automation
Retrieve tasks associated with the provided file id
ITAutomationGetExecutionResultsIT Automation
Get the task execution results from an async search.
ITAutomationGetExecutionResultsSearchStatusIT Automation
Get the status of an async task execution results.
ITAutomationGetPoliciesIT Automation
Retrieves the configuration for 1 or more policies.
ITAutomationGetScheduledTasksIT Automation
Returns scheduled tasks for each provided id
ITAutomationGetTaskExecutionIT Automation
Get the task execution for the provided task execution IDs
ITAutomationGetTaskExecutionHostStatusIT Automation
Get the status of host executions by providing the execution IDs
ITAutomationGetTaskExecutionsByQueryIT Automation
Returns the list of task executions (and their details) matching the filter query parameter.
ITAutomationGetTaskGroupsIT Automation
Returns task groups for each provided id
ITAutomationGetTaskGroupsByQueryIT Automation
Returns full details of task groups matching the filter query parameter.
ITAutomationGetTasksIT Automation
Returns tasks for each provided ID
ITAutomationGetTasksByQueryIT Automation
Returns full details of tasks matching the filter query parameter.
ITAutomationGetUserGroupIT Automation
Returns user groups for each provided id
ITAutomationQueryPoliciesIT Automation
Returns the list of policy ids matching the filter query parameter.
ITAutomationRerunTaskExecutionIT Automation
Rerun the task execution specified in the request
ITAutomationRunLiveQueryIT Automation
Starts a new task execution from the provided query data in the request and returns the initiated task executions
ITAutomationSearchScheduledTasksIT Automation
Returns the list of scheduled task IDs matching the filter query parameter
ITAutomationSearchTaskExecutionsIT Automation
Returns the list of task execution IDs matching the filter query parameter.
ITAutomationSearchTaskGroupsIT Automation
Returns the list of task group ids matching the filter query parameter
ITAutomationSearchTasksIT Automation
Returns the list of task IDs matching the filter query parameter.
ITAutomationSearchUserGroupIT Automation
Returns the list of user group ids matching the filter query parameter.
ITAutomationStartExecutionResultsSearchIT Automation
Starts an async task execution results search.
ITAutomationStartTaskExecutionIT Automation
Starts a new task execution from an existing task provided in the request and returns the initiated task executions
ITAutomationUpdatePoliciesIT Automation
Updates a new policy of the specified type.
ITAutomationUpdatePoliciesPrecedenceIT Automation
Updates the policy precedence for all policies of a specific platform.
ITAutomationUpdatePolicyHostGroupsIT Automation
Manage host groups assigned to a policy.
ITAutomationUpdateScheduledTaskIT Automation
Update an existing scheduled task with the supplied info
ITAutomationUpdateTaskIT Automation
Update a task with details from the given request.
ITAutomationUpdateTaskGroupIT Automation
Update a task group for a given id
ITAutomationUpdateUserGroupIT Automation
Update a user group for a given id
LaunchExportJobFalcon Container
Launch an export job of a Container Security resource.
LaunchExportJobMixin0Serverless Exports
Launch an export job of a Lambda Security resource.
LaunchScanQuick Scan Pro
Starts scanning a file uploaded through ‘/quickscanpro/entities/files/v1’.
ListAccessScopesExternalAccess Scopes
List Access Scopes By ID
listAvailableStreamsOAuth2Event Streams
Discover all event streams in your environment
ListAzureAccountsKubernetes Protection
Provides the azure subscriptions registered to Kubernetes Protection
ListCloudGroupIDsExternalCloud Security
Query Cloud Groups and returns IDs
ListCloudGroupsByIDExternalCloud Security
List Cloud Groups By ID
ListCloudGroupsExternalCloud Security
Query Cloud Groups and returns entities
ListCollectionsCustom Storage
List available collection names in alphabetical order
ListDashboardsNGSIEM
List Dashboards in NGSIEM with Pagination and Filtering.
ListFeedTypesIntelligence Feeds
Lists the accessible feed types for a given customer
ListLookupFilesNGSIEM
List Lookup Files in NGSIEM with Pagination and Filtering.
ListObjectsCustom Storage
List the object keys in the specified collection in alphabetical order
ListObjectsByVersionCustom Storage
List the object keys in the specified collection in alphabetical order
ListParsersNGSIEM
List Parsers in NGSIEM
ListReposV1Foundry LogScale
Lists available repositories
ListSavedQueriesNGSIEM
List Saved Queries in NGSIEM with Pagination and Filtering.
ListSchemasCustom Storage
Get the list of schemas for the requested collection in reverse version order (latest first)
ListViewV1Foundry LogScale
List available views
LookupIndicatorsIntelligence Indicator Graph
Get indicators based on their value.
MigrationAggregatesV1Host Migration
Get migration aggregates as specified via json in request body.
MigrationsActionsV1Host Migration
Perform an action on a migration job.
oauth2AccessTokenOAuth2
Generate an OAuth2 access token
oauth2RevokeTokenOAuth2
Revoke a previously issued OAuth2 access token before the end of its standard 30-minute lifespan.
patch-external-assetsExposure Management
Update the details of external assets.
PatchAzureServicePrincipalKubernetes Protection
Adds the client ID for the given tenant ID to our system
PatchCSPMAwsAccountCSPM Registration
Patches a existing account in our system for a customer.
patchDeviceControlPoliciesClassesV1Device Control Policies
Update device control policy’s classes (USB and Bluetooth)
patchDeviceControlPoliciesV2Device Control Policies
Update device control policy base (USB and Bluetooth)
PatchEntitiesAlertsV1Alerts
Perform actions on detections identified by detection ID(s) in request.
PatchEntitiesAlertsV2Alerts
Deprecated: Please use version v3 of this endpoint.
PatchEntitiesAlertsV3Alerts
Perform actions on Alerts identified by composite ID(s) in request.
PatchFederatedConnectionsConfigFederated Connections
Update configuration for a federated connection
PerformActionV2Hosts
Take various actions on the hosts in your environment.
performContentUpdatePoliciesActionContent Update Policies
Perform the specified action on the Content Update Policies specified in the request
performDeviceControlPoliciesActionDevice Control Policies
Perform the specified action on the Device Control Policies specified in the request
performFirewallPoliciesActionFirewall Policies
Perform the specified action on the Firewall Policies specified in the request
performGroupActionHost Group
Perform the specified action on the Host Groups specified in the request
performPreventionPoliciesActionPrevention Policies
Perform the specified action on the Prevention Policies specified in the request
performRTResponsePoliciesActionResponse Policies
Perform the specified action on the Response Policies specified in the request
performSensorUpdatePoliciesActionSensor Update Policy
Perform the specified action on the Sensor Update Policies specified in the request
platform.query.v1IOC
Query Platforms.
PolicyChecksFalcon Container
Check image prevention policies
post-external-assets-inventory-v1Exposure Management
Add external assets for external asset scanning.
post_policy_rulesIdentity Protection
Create policy rule
post_policy_rulesIdentity Protection
Create policy rule
PostAggregatesAlertsV1Alerts
Deprecated: Please use version v2 of this endpoint.
PostAggregatesAlertsV2Alerts
Retrieves aggregate values for Alerts across all CIDs.
PostAggregatesPodsKubernetes Protection
Get aggregate query result for pods
PostCombinedAlertsV1Alerts
Retrieves all Alerts that match a particular FQL filter.
PostDeliverySettingsDelivery Settings
Create Delivery Settings
postDeviceControlPoliciesV2Device Control Policies
Create/clone a device control policy (USB and Bluetooth)
PostDeviceDetailsV2Hosts
Get details on one or more hosts by providing host IDs in a POST body.
PostEntitiesAlertsV1Alerts
Deprecated: please use version v2 of this endpoint.
PostEntitiesAlertsV2Alerts
Retrieves all Alerts given their composite ids.
PostFederatedConnectionsConfigFederated Connections
Create configuration for a federated connection
PostGroupV2ASPM
Create group
PostImageScanInventoryFalcon Container
Post image scan inventory
PostMalQueryEntitiesSamplesMultidownloadV1MalQuery
Schedule samples for download.
PostMalQueryExactSearchV1MalQuery
Search Falcon MalQuery for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity.
PostMalQueryFuzzySearchV1MalQuery
Search Falcon MalQuery quickly, but with more potential for false positives.
PostMalQueryHuntV1MalQuery
Schedule a YARA-based search for execution.
PostMitreAttacksIntel
Retrieves report and observable IDs associated with the given actor and attacks
PostSearchKubernetesIOMEntitiesKubernetes Protection
Search for Kubernetes IOMs with filtering options.Pagination is supported via Elasticsearch’s search_after search param and point in time.
PreviewRuleV1Recon
Preview rules notification count and distribution.
ProcessesRanOnIOCs
Search for processes associated with a custom IOC
ProvisionAWSAccountsCloud Connect AWS
Provision AWS Accounts by specifying details about the accounts to provision
PutObjectCustom Storage
Put the specified new object at the given key or overwrite an existing object at the given key
PutObjectByVersionCustom Storage
Put the specified new object at the given key or overwrite an existing object at the given key
queries.access-tags.get.v1Case Management
Query access tags
queries.cases.get.v1Case Management
Retrieves all Cases IDs that match a given query.
queries.classification.get.v2Data Protection Configuration
Search for classifications that match the provided criteria
queries.cloud-application.get-v2Data Protection Configuration
Get all cloud-application IDs matching the query with filter
queries.content-pattern.get-v2Data Protection Configuration
Get all content-pattern IDs matching the query with filter
queries.enterprise-account.get-v2Data Protection Configuration
Get all enterprise-account IDs matching the query with filter
queries.fields.get.v1Case Management
Query fields
queries.file-details.get.v1Case Management
Query for ids of file details
queries.file-type.get-v2Data Protection Configuration
Get all file-type IDs matching the query with filter
queries.local-application-group.getData Protection Configuration
Get all local application group IDs matching the query with filter
queries.local-application.getData Protection Configuration
Get all local-application IDs matching the query with filter
queries.notification-groups.get.v1Case Management
Query notification groups
queries.notification-groups.get.v2Case Management
Query notification groups
queries.policy.get.v2Data Protection Configuration
Search for policies that match the provided criteria
queries.rules.get.v1Correlation Rules
Find all rule IDs matching the query and filter.
queries.rules.get.v2Correlation Rules
Find all rule version IDs matching the query and filter.
queries.sensitivity-label.get-v2Data Protection Configuration
Get all sensitivity label IDs matching the query with filter
queries.slas.get.v1Case Management
Query SLAs
queries.states.v1Device Content
Query for the content state of the host.
queries.template-snapshots.get.v1Case Management
Query template snapshots
queries.templates.get.v1Case Management
Query templates
queries.templates.get.v1Mixin0Correlation Rules
Search rule template IDs matching the filter.
queries.web-location-group.getData Protection Configuration
Get all web location group IDs matching the query with filter
queries.web-location.get-v2Data Protection Configuration
Get web-location IDs matching the query with filter
queries_edgetypes_getThreatGraph
Show all available edge types
QueriesAgentTemplatesV1Agent Templates
Query agent template IDs with pagination
QueriesKnowledgeBaseAuditEventsV1Knowledge Base Audit Events
Query knowledge base audit event IDs with pagination and filtering.
QueriesKnowledgeBaseFilesV1Knowledge Base Files
Query knowledge base files based on the provided filters.
QueriesKnowledgeBasesV1Knowledge Bases
Query knowledge bases based on the provided filters.
QueriesModelsV1Models
Query models based on the provided filters.
queriesRolesV1User Management
Show role IDs for all roles available in your customer account.
QueriesSpansV1Spans
Query spans based on the provided filters.
QueriesToolsV1Tools
Query tools based on the provided filters.
query-accountsDiscover
Search for accounts in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-applicationsDiscover
Search for applications in your environment by providing an FQL filter and paging details. returns a set of application IDs which match the filter criteria.
query-ecosystem-subsidiariesExposure Management
Retrieves a list of IDs for ecosystem subsidiaries.
query-eventsFirewall Management
Find all event IDs matching the query with filter
query-external-assetsExposure Management
Get a list of external asset IDs that match the provided filter conditions.
query-external-assets-v2Exposure Management
Get a list of external asset IDs that match the provided filter conditions.
query-firewall-fieldsFirewall Management
Get the firewall field specification IDs for the provided platform
query-hostsDiscover
Search for assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-iot-hostsDiscover
Search for IoT assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-iot-hostsV2Discover
Search for IoT assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-loginsDiscover
Search for logins in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-malicious-filesODS (On Demand Scan)
Query malicious files.
query-network-locationsFirewall Management
Get a list of network location IDs
query-networksNetwork Scan Networks
Get “networks IDs” by filter
query-patternsCustom IOA
Get all pattern severity IDs.
query-platformsFirewall Management
Get the list of platform names
query-platformsMixin0Custom IOA
Get all platform IDs.
query-policy-rulesFirewall Management
Find all firewall rule IDs matching the query with filter, and return them in precedence order
query-rule-groupsFirewall Management
Find all rule group IDs matching the query with filter
query-rule-groups-fullCustom IOA
Find all rule groups matching the query with optional filter.
query-rule-groupsMixin0Custom IOA
Finds all rule group IDs matching the query with optional filter.
query-rule-typesCustom IOA
Get all rule type IDs.
query-rulesFirewall Management
Find all rule IDs matching the query with filter
query-rulesMixin0Custom IOA
Finds all rule IDs matching the query with optional filter.
query-scan-host-metadataODS (On Demand Scan)
Query scan hosts.
query-scan-runsNetwork Scan Scan Runs
Get “scan-runs IDs” by filter
query-scannersNetwork Scan Scanners
Get “scanners IDs” by filter
query-scansODS (On Demand Scan)
Query Scans.
query-scansMixin0Network Scan Scans
Get “scans IDs” by filter
query-scheduled-scansODS (On Demand Scan)
Query ScheduledScans.
query-templatesNetwork Scan Templates
Get “templates IDs” by filter
query-zonesNetwork Scan Zones
Get “zones IDs” by filter
QueryAccessScopesExternalAccess Scopes
Query Access Scopes and returns IDs
queryActionsMixin0FileVantage
Returns one or more action ids
QueryActionsV1Recon
Query actions based on provided criteria.
QueryActivityByCaseIDMessage Center
Retrieve activities id’s for a case
QueryAgentVersionsV1Agent Versions
Query agent versions based on the provided filters.
QueryAlertIdsByFilterFalcon Complete Dashboard
Retrieve Alerts Ids for epp that match the provided FQL filter criteria with scrolling enabled
QueryAlertIdsByFilterV2Falcon Complete Dashboard
Retrieve Alerts Ids for epp, idp and ngsiem that match the provided FQL filter criteria with scrolling enabled
QueryAllowListFilterFalcon Complete Dashboard
Retrieve allowlist tickets that match the provided filter criteria with scrolling enabled
QueryAWSAccountsCloud Connect AWS
Search for provisioned AWS Accounts by providing an FQL filter and paging details.
QueryAWSAccountsForIDsCloud Connect AWS
Search for provisioned AWS Accounts by providing an FQL filter and paging details.
QueryBlockListFilterFalcon Complete Dashboard
Retrieve block listtickets that match the provided filter criteria with scrolling enabled
QueryCasesIdsByFilterMessage Center
Retrieve case id’s that match the provided filter criteria
queryChangesFileVantage
Returns 1 or more change ids
queryChildrenMSSP (Flight Control)
Query for customers linked as children
queryCIDGroupMembersMSSP (Flight Control)
Query a CID groups members by associated CID.
queryCIDGroupsMSSP (Flight Control)
Query CID groups.
queryCombinedContentUpdatePoliciesContent Update Policies
Search for Content Update Policies in your environment by providing an FQL filter and paging details.
queryCombinedContentUpdatePolicyMembersContent Update Policies
Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
queryCombinedDeviceControlPoliciesDevice Control Policies
Search for Device Control Policies in your environment by providing an FQL filter and paging details.
queryCombinedDeviceControlPolicyMembersDevice Control Policies
Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
queryCombinedFirewallPoliciesFirewall Policies
Search for Firewall Policies in your environment by providing an FQL filter and paging details.
queryCombinedFirewallPolicyMembersFirewall Policies
Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
queryCombinedGroupMembersHost Group
Search for members of a Host Group in your environment by providing an FQL filter and paging details.
queryCombinedHostGroupsHost Group
Search for Host Groups in your environment by providing an FQL filter and paging details.
queryCombinedPreventionPoliciesPrevention Policies
Search for Prevention Policies in your environment by providing an FQL filter and paging details.
queryCombinedPreventionPolicyMembersPrevention Policies
Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
queryCombinedRTResponsePoliciesResponse Policies
Search for Response Policies in your environment by providing an FQL filter and paging details.
queryCombinedRTResponsePolicyMembersResponse Policies
Search for members of a Response policy in your environment by providing an FQL filter and paging details.
queryCombinedSensorUpdateBuildsSensor Update Policy
Retrieve available builds for use with Sensor Update Policies
queryCombinedSensorUpdateKernelsSensor Update Policy
Retrieve kernel compatibility info for Sensor Update Builds
queryCombinedSensorUpdatePoliciesSensor Update Policy
Search for Sensor Update Policies in your environment by providing an FQL filter and paging details.
queryCombinedSensorUpdatePoliciesV2Sensor Update Policy
Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details.
queryCombinedSensorUpdatePolicyMembersSensor Update Policy
Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
QueryComplianceControlsCloud Policies
Query for compliance controls by various parameters
QueryComplianceFrameworksCloud Policies
Query for compliance frameworks by various parameters
queryContentUpdatePoliciesContent Update Policies
Search for Content Update Policies in your environment by providing an FQL filter and paging details.
queryContentUpdatePolicyMembersContent Update Policies
Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
QueryDetectsDetects
Deprecated: This endpoint will be decommissioned on September 30, 2025.
queryDeviceControlPoliciesDevice Control Policies
Search for Device Control Policies in your environment by providing an FQL filter and paging details.
queryDeviceControlPolicyMembersDevice Control Policies
Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
QueryDeviceLoginHistoryHosts
Retrieve details about recent login sessions for a set of devices.
QueryDeviceLoginHistoryV2Hosts
Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline.
QueryDevicesByFilterHosts
Search for hosts in your environment by platform, hostname, IP, and other criteria.
QueryDevicesByFilterScrollHosts
Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit)
QueryEscalationsFilterFalcon Complete Dashboard
Retrieve escalation tickets that match the provided filter criteria with scrolling enabled
queryEvaluationLogicSpotlight Evaluation Logic
Search for evaluation logic in your environment by providing a FQL filter and paging details.
QueryEventsTailored Intelligence
Get events ids that match the provided filter criteria.
QueryExportJobsFalcon Container
Query export jobs entities
QueryExportJobsMixin0Serverless Exports
Query export jobs entities
QueryFeedArchivesIntelligence Feeds
Queries the accessible feed types for a customer.
queryFirewallPoliciesFirewall Policies
Search for Firewall Policies in your environment by providing an FQL filter and paging details.
queryFirewallPolicyMembersFirewall Policies
Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
QueryGetNetworkAddressHistoryV1Hosts
Retrieve history of IP and MAC addresses of devices.
queryGroupMembersHost Group
Search for members of a Host Group in your environment by providing an FQL filter and paging details.
QueryGroupsV1Mixin0Profile Groups
Query profile group IDs with FQL filtering, pagination, and sorting
QueryHiddenDevicesHosts
Retrieve hidden hosts that match the provided filter criteria.
queryHostGroupsHost Group
Search for Host Groups in your environment by providing an FQL filter and paging details.
QueryIntelActorEntitiesIntel
Get info about actors that match provided FQL filters.
QueryIntelActorIdsIntel
Get actor IDs that match provided FQL filters.
QueryIntelIndicatorEntitiesIntel
Get info about indicators that match provided FQL filters.
QueryIntelIndicatorIdsIntel
Get indicators IDs that match provided FQL filters.
QueryIntelReportEntitiesIntel
Get info about reports that match provided FQL filters.
QueryIntelReportIdsIntel
Get report IDs that match provided FQL filters.
QueryIntelRuleIdsIntel
Search for rule IDs that match provided filter criteria.
queryIOAExclusionsV1IOA Exclusions
Search for IOA exclusions.
QueryIOCsIOCs
Search the custom IOCs in your customer account. *** Deprecated - Use the new IOC Management endpoint (GET /iocs/queries/indicators/v1). ***
QueryMalwareIntel
Get malware family names that match provided FQL filters.
QueryMalwareEntitiesIntel
Get malware entities that match provided FQL filters.
QueryMitreAttacksIntel
Gets MITRE tactics and techniques for the given actor, returning concatenation of id and tactic and technique ids, example: fancy-bear_TA0011_T1071
QueryMitreAttacksForMalwareIntel
Gets MITRE tactics and techniques for the given malware
queryMLExclusionsV1ML Exclusions
Search for ML exclusions.
QueryNotificationsExposedDataRecordsV1Recon
Query notifications exposed data records based on provided criteria.
QueryNotificationsV1Recon
Query notifications based on provided criteria.
queryPinnableContentVersionsContent Update Policies
Search for content versions available for pinning given the category.
queryPoliciesFileVantage
Retrieve the ids of all policies that are assigned the provided policy type.
queryPreventionPoliciesPrevention Policies
Search for Prevention Policies in your environment by providing an FQL filter and paging details.
queryPreventionPolicyMembersPrevention Policies
Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
QueryQuarantineFilesQuarantine
Get quarantine file ids that match the provided filter criteria.
QueryReleaseNotesV1Deployments
Queries for release-notes resources and returns ids
QueryRemediationsFilterFalcon Complete Dashboard
Retrieve remediation tickets that match the provided filter criteria with scrolling enabled
QueryReportsFalconx Sandbox
Find sandbox reports by providing an FQL filter and paging details.
queryRolesMSSP (Flight Control)
Query links between user groups and CID groups.
queryRTResponsePoliciesResponse Policies
Search for Response Policies in your environment by providing an FQL filter with sort and/or paging details.
queryRTResponsePolicyMembersResponse Policies
Search for members of a Response policy in your environment by providing an FQL filter and paging details.
QueryRuleCloud Policies
Query for rules by various parameters
queryRuleGroupsFileVantage
Retrieve the ids of all rule groups that are of the provided rule group type.
QueryRulesTailored Intelligence
Get rules ids that match the provided filter criteria.
QueryRulesV1Recon
Query monitoring rules based on provided criteria.
QuerySampleV1Falconx Sandbox
Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200
QueryScanResultsQuick Scan Pro
FQL query specifying the filter parameters
queryScheduledExclusionsFileVantage
Retrieve the ids of all scheduled exclusions contained within the provided policy id.
QuerySensorsByFilterIdentity Protection
Search for sensors in your environment by hostname, IP, and other criteria.
querySensorUpdateKernelsDistinctSensor Update Policy
Retrieve kernel compatibility info for Sensor Update Builds
querySensorUpdatePoliciesSensor Update Policy
Search for Sensor Update Policies in your environment by providing an FQL filter and paging details.
querySensorUpdatePolicyMembersSensor Update Policy
Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
querySensorVisibilityExclusionsV1Sensor Visibility Exclusions
Search for sensor visibility exclusions.
QuerySubmissionsFalconx Sandbox
Find submission IDs for uploaded files by providing an FQL filter and paging details.
QuerySubmissionsMixin0Quick Scan
Find IDs for submitted scans by providing an FQL filter and paging details.
QuerySuppressionRulesCloud Policies
Query suppression rules with filtering, sorting and pagination
QueryThirdPartyPasskeyRegistryFalcon ID
Query third party passkey registries
queryUserGroupMembersMSSP (Flight Control)
Query user group member by user UUID.
queryUserGroupsMSSP (Flight Control)
Query user groups.
queryUserV1User Management
List user IDs for all users in your customer account.
QueryVulnerabilitiesIntel
Get vulnerabilities IDs
queryVulnerabilitiesSpotlight Vulnerabilities
Search for Vulnerabilities in your environment by providing an FQL filter and paging details.
ReadClusterCombinedKubernetes Protection
Retrieve kubernetes clusters identified by the provided filter criteria
ReadClusterCombinedV2Kubernetes Protection
Retrieve Kubernetes cluster data
ReadClusterCountKubernetes Protection
Retrieve cluster counts
ReadClusterEnrichmentKubernetes Protection
Retrieve cluster enrichment data
ReadClustersByDateRangeCountKubernetes Protection
Retrieve clusters by date range counts
ReadClustersByKubernetesVersionCountKubernetes Protection
Bucket clusters by kubernetes version
ReadClustersByStatusCountKubernetes Protection
Bucket clusters by status
ReadCombinedDetectionsContainer Detections
Retrieve image assessment detections identified by the provided filter criteria
ReadCombinedImagesExportContainer Images
Retrieves a paginated list of images, with an option to expand aggregated vulnerabilities/detections.
ReadCombinedVulnerabilitiesContainer Vulnerabilities
Retrieves a paginated list of vulnerabilities filtered by the provided FQL.
ReadCombinedVulnerabilitiesDetailsContainer Vulnerabilities
Retrieve vulnerability details related to an image
ReadCombinedVulnerabilitiesInfoContainer Vulnerabilities
Retrieve vulnerability and package related info for this customer
ReadContainerAlertsCountContainer Alerts
Search Container Alerts by the provided search criteria
ReadContainerAlertsCountBySeverityContainer Alerts
Get Container Alerts counts by severity
ReadContainerCombinedKubernetes Protection
Retrieves a paginated list of containers identified by the provided filter criteria.
ReadContainerCountKubernetes Protection
Retrieve container counts
ReadContainerCountByRegistryKubernetes Protection
Retrieves a list with the top container image registries.
ReadContainerEnrichmentKubernetes Protection
Retrieve container enrichment data
ReadContainerImageDetectionsCountByDateKubernetes Protection
Retrieve count of image assessment detections on running containers over a period of time
ReadContainerImagesByMostUsedKubernetes Protection
Bucket container by image-digest
ReadContainerImagesByStateKubernetes Protection
Retrieve count of image states running on containers
ReadContainersByDateRangeCountKubernetes Protection
Retrieve containers by date range counts
ReadContainersSensorCoverageKubernetes Protection
Bucket containers by agent type and calculate sensor coverage
ReadContainerVulnerabilitiesBySeverityCountKubernetes Protection
Retrieve container vulnerabilities by severity counts
ReadDeploymentCombinedKubernetes Protection
Retrieve kubernetes deployments identified by the provided filter criteria
ReadDeploymentCountKubernetes Protection
Retrieve deployment counts
ReadDeploymentEnrichmentKubernetes Protection
Retrieve deployment enrichment data
ReadDeploymentsByDateRangeCountKubernetes Protection
Retrieve deployments by date range counts
ReadDeploymentsCombinedCloud Snapshots
Retrieve snapshot jobs identified by the provided IDs
ReadDeploymentsEntitiesCloud Snapshots
Retrieve snapshot jobs identified by the provided IDs
ReadDetectionsContainer Detections
Retrieve image assessment detection entities identified by the provided filter criteria
ReadDetectionsCountContainer Detections
Aggregate count of detections
ReadDetectionsCountBySeverityContainer Detections
Aggregate counts of detections by severity
ReadDetectionsCountByTypeContainer Detections
Aggregate counts of detections by detection type
ReadDistinctContainerImageCountKubernetes Protection
Retrieve count of distinct images running on containers
ReadDriftIndicatorEntitiesDrift Indicators
Retrieve Drift Indicator entities identified by the provided IDs
ReadDriftIndicatorsCountDrift Indicators
Returns the total count of Drift indicators over a time period
ReadExportJobsFalcon Container
Read export jobs entities
ReadExportJobsMixin0Serverless Exports
Read export jobs entities
ReadImageVulnerabilitiesFalcon Container
Retrieve known vulnerabilities for the provided image
ReadKubernetesIomByDateRangeKubernetes Protection
Returns the count of Kubernetes IOMs by the date. by default it’s for 7 days.
ReadKubernetesIomCountKubernetes Protection
Returns the total count of Kubernetes IOMs over the past seven days
ReadKubernetesIomEntitiesKubernetes Protection
Retrieve Kubernetes IOM entities identified by the provided IDs
ReadNamespaceCountKubernetes Protection
Retrieve namespace counts
ReadNamespacesByDateRangeCountKubernetes Protection
Retrieve namespaces by date range counts
ReadNodeCombinedKubernetes Protection
Retrieve kubernetes nodes identified by the provided filter criteria
ReadNodeCountKubernetes Protection
Retrieve node counts
ReadNodeEnrichmentKubernetes Protection
Retrieve node enrichment data
ReadNodesByCloudCountKubernetes Protection
Bucket nodes by cloud providers
ReadNodesByContainerEngineVersionCountKubernetes Protection
Bucket nodes by their container engine version
ReadNodesByDateRangeCountKubernetes Protection
Retrieve nodes by date range counts
ReadPackagesByFixableVulnCountContainer Packages
Retrieve top x app packages with the most fixable vulnerabilities
ReadPackagesByImageCountContainer Packages
Retrieves the N most frequently used packages across images
ReadPackagesByVulnCountContainer Packages
Retrieve top x packages with the most vulnerabilities
ReadPackagesCombinedContainer Packages
Retrieve packages identified by the provided filter criteria
ReadPackagesCombinedExportContainer Packages
Retrieves a paginated list of packages identified by the provided filter criteria,used for export.Maximum page size: 100.
ReadPackagesCombinedV2Container Packages
Retrieve packages identified by the provided filter criteria
ReadPackagesCountByZeroDayContainer Packages
Retrieve packages count affected by zero day vulnerabilities
ReadPodCombinedKubernetes Protection
Retrieve kubernetes pods identified by the provided filter criteria
ReadPodCountKubernetes Protection
Retrieve pod counts
ReadPodEnrichmentKubernetes Protection
Retrieve pod enrichment data
ReadPodsByDateRangeCountKubernetes Protection
Retrieve pods by date range counts
ReadPoliciesImage Assessment Policies
Get all Image Assessment policies
ReadPolicyExclusionsImage Assessment Policies
Retrieve Image Assessment Policy Exclusion entities
ReadPolicyGroupsImage Assessment Policies
Retrieve Image Assessment Policy Group entities
ReadRegistryEntitiesFalcon Container
Retrieves a list of registry entities identified by the customer id.
ReadRegistryEntitiesByUUIDFalcon Container
Retrieves a list of registry entities by the provided UUIDs.
ReadRequestBodyFaaS Execution
retrieve a large request body, such as a file, that has spilled into object storage
ReadRunningContainerImagesKubernetes Protection
Retrieve images on running containers
ReadUnidentifiedContainersByDateRangeCountUnidentified Containers
Returns the count of Unidentified Containers over the last 7 days
ReadUnidentifiedContainersCountUnidentified Containers
Returns the total count of Unidentified Containers over a time period
ReadVulnerabilitiesByImageCountContainer Vulnerabilities
Retrieve top x vulnerabilities with the most impacted images
ReadVulnerabilitiesPublicationDateContainer Vulnerabilities
Retrieve top x vulnerabilities with the most recent publication date
ReadVulnerabilityCountContainer Vulnerabilities
Aggregate count of vulnerabilities
ReadVulnerabilityCountByActivelyExploitedContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by actively exploited
ReadVulnerabilityCountByCPSRatingContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by csp_rating
ReadVulnerabilityCountByCVSSScoreContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by CVSS score
ReadVulnerabilityCountBySeverityContainer Vulnerabilities
Aggregate count of vulnerabilities grouped by severity
ReadVulnerableContainerImageCountKubernetes Protection
Retrieve count of vulnerable images running on containers
refreshActiveStreamSessionEvent Streams
Refresh an active event stream.
RegenerateAPIKeyKubernetes Protection
Regenerate API key for docker registry integrations
RegisterCspmSnapshotAccountCloud Snapshots
Register customer cloud account for snapshot scanning
removeDashboardLabelsNGSIEM
Remove multiple labels from a single dashboard
removeFileLabelsNGSIEM
Remove multiple labels from a single file
removeSavedQueryLabelsNGSIEM
Remove multiple labels from a saved query
RenameSectionComplianceFrameworkCloud Policies
Rename a section in a custom compliance framework
ReplaceControlRulesCloud Policies
Assign rules to a compliance control (full replace)
report-executions-download.getReport Executions
Get report entity download
report-executions.getReport Executions
Retrieve report details for the provided report IDs.
report-executions.queryReport Executions
Find all report execution IDs matching the query with filter
report-executions.retryReport Executions
This endpoint will be used to retry report executions
RequestDeviceEnrollmentV3Mobile Enrollment
Trigger on-boarding process for a mobile device
RequestDeviceEnrollmentV4Mobile Enrollment
Trigger on-boarding process for a mobile device
ResetAPIClientSecretAPI Clients
Reset existing API Client(s)‘s secret based on API Client ID(s) provided as request parameter(s) ‘ids’.
RetrieveEmailsByCIDUser Management
Deprecated : Please use POST /user-management/entities/users/GET/v1.
RetrieveRelayInstancesASPM
Retrieve the relay instances in CSV format
retrieveUserUser Management
Deprecated : Please use POST /user-management/entities/users/GET/v1.
RetrieveUserUser Management
Deprecated : Please use retrieveUsersGETV1.
retrieveUsersGETV1User Management
Get info about users including their name, UID and CID by providing user UUIDs
RetrieveUserUUIDUser Management
Deprecated : Please use GET /user-management/queries/users/v1.
RetrieveUserUUIDsByCIDUser Management
Deprecated : Please use GET /user-management/queries/users/v1.
revealUninstallTokenSensor Update Policy
Reveals an uninstall token for a specific device.
RevokeUserRoleIdsUser Management
Deprecated : Please use POST /user-management/entities/user-role-actions/v1.
RTR-AggregateSessionsReal Time Response
Get aggregates on session data.
RTR-CheckActiveResponderCommandStatusReal Time Response
Get status of an executed active-responder command on a single host.
RTR-CheckAdminCommandStatusReal Time Response Admin
Get status of an executed RTR administrator command on a single host.
RTR-CheckCommandStatusReal Time Response
Get status of an executed command on a single host.
RTR-CreatePut-FilesReal Time Response Admin
Upload a new put-file to use for the RTR put command.
RTR-CreatePut-FilesV2Real Time Response Admin
Upload a new put-file to use for the RTR put command.
RTR-CreateScriptsReal Time Response Admin
Upload a new custom-script to use for the RTR runscript command.
RTR-CreateScriptsV2Real Time Response Admin
Upload a new custom-script to use for the RTR runscript command.
RTR-DeleteFileReal Time Response
Delete a RTR session file.
RTR-DeleteFileV2Real Time Response
Delete a RTR session file.
RTR-DeletePut-FilesReal Time Response Admin
Delete a put-file based on the ID given.
RTR-DeleteQueuedSessionReal Time Response
Delete a queued session command
RTR-DeleteScriptsReal Time Response Admin
Delete a custom-script based on the ID given.
RTR-DeleteSessionReal Time Response
Delete a session.
RTR-ExecuteActiveResponderCommandReal Time Response
Execute an active responder command on a single host.
RTR-ExecuteAdminCommandReal Time Response Admin
Execute a RTR administrator command on a single host.
RTR-ExecuteCommandReal Time Response
Execute a command on a single host.
RTR-GetExtractedFileContentsReal Time Response
Get RTR extracted file contents for specified session and sha256.
RTR-GetFalconScriptsReal Time Response Admin
Get Falcon scripts with metadata and content of script
RTR-GetPut-FilesReal Time Response Admin
Get put-files based on the ID’s given.
RTR-GetPut-FilesV2Real Time Response Admin
Get put-files based on the ID’s given.
RTR-GetPutFileContentsReal Time Response Admin
Get RTR put file contents for a given file ID
RTR-GetScriptsReal Time Response Admin
Get custom-scripts based on the ID’s given.
RTR-GetScriptsV2Real Time Response Admin
Get custom-scripts based on the ID’s given.
RTR-InitSessionReal Time Response
Initialize a new session with the RTR cloud.
RTR-ListAllSessionsReal Time Response
Get a list of session_ids.
RTR-ListFalconScriptsReal Time Response Admin
Get a list of Falcon script IDs available to the user to run
RTR-ListFilesReal Time Response
Get a list of files for the specified RTR session.
RTR-ListFilesV2Real Time Response
Get a list of files for the specified RTR session.
RTR-ListPut-FilesReal Time Response Admin
Get a list of put-file ID’s that are available to the user for the put command.
RTR-ListQueuedSessionsReal Time Response
Get queued session metadata by session ID.
RTR-ListScriptsReal Time Response Admin
Get a list of custom-script ID’s that are available to the user for the runscript command.
RTR-ListSessionsReal Time Response
Get session metadata by session id.
RTR-PulseSessionReal Time Response
Refresh a session timeout on a single host.
RTR-UpdateScriptsReal Time Response Admin
Upload a new scripts to replace an existing one.
RTR-UpdateScriptsV2Real Time Response Admin
Upload a new scripts to replace an existing one.
RTRAuditSessionsReal Time Response Audit
Get all the RTR sessions created for a customer in a specified duration
RunIntegrationTaskASPM
Run an integration task by its ID
RunIntegrationTaskAdminASPM
Run an integration task by its ID - for admin scope
RunIntegrationTaskV2ASPM
Run an integration task by its ID
scans-reportODS (On Demand Scan)
Launch a scans report creation job
ScanSamplesQuick Scan
Submit a volume of files for ml scanning.
schedule-scanODS (On Demand Scan)
Create ODS scan and start or schedule scan for the given scan request.
scheduled-reports.getScheduled Reports
Retrieve scheduled reports for the provided report IDs.
scheduled-reports.launchScheduled Reports
Launch scheduled reports executions for the provided report IDs.
scheduled-reports.queryScheduled Reports
Find all report IDs matching the query with filter
SearchAndReadContainerAlertsContainer Alerts
Search Container Alerts by the provided search criteria
SearchAndReadDriftIndicatorEntitiesDrift Indicators
Retrieve Drift Indicators by the provided search criteria
SearchAndReadKubernetesIomEntitiesKubernetes Protection
Retrieves a list of Kubernetes IOMs identified by the provided search criteria.
SearchAndReadUnidentifiedContainersUnidentified Containers
Search Unidentified Containers by the provided search criteria
SearchDetectionsContainer Detections
Retrieve image assessment detection entities identified by the provided filter criteria
SearchDriftIndicatorsDrift Indicators
Retrieve all drift indicators that match the given query
SearchHuntingGuidesCAO Hunting
Search for Hunting Guides that match the provided conditions
SearchIndicatorsIntelligence Indicator Graph
Search indicators based on FQL filter.
SearchIntelligenceQueriesCAO Hunting
Search for a list of intelligence queries IDs that match the provided conditions
SearchKubernetesIomsKubernetes Protection
Search Kubernetes IOMs by the provided search criteria. this endpoint returns a list of Kubernetes IOM UUIDs matching the query
SearchObjectsCustom Storage
Search for objects that match the specified filter criteria (returns metadata, not actual objects)
SearchObjectsByVersionCustom Storage
Search for objects that match the specified filter criteria (returns metadata, not actual objects)
ServiceNowGetDeploymentsASPM
ServiceNowGetServicesASPM
SetCloudSecurityIntegrationStateASPM
Set Cloud Security integration state
setContentUpdatePoliciesPrecedenceContent Update Policies
Sets the precedence of Content Update Policies based on the order of IDs specified in the request.
setDeviceControlPoliciesPrecedenceDevice Control Policies
Sets the precedence of Device Control Policies based on the order of IDs specified in the request.
setFirewallPoliciesPrecedenceFirewall Policies
Sets the precedence of Firewall Policies based on the order of IDs specified in the request.
setPreventionPoliciesPrecedencePrevention Policies
Sets the precedence of Prevention Policies based on the order of IDs specified in the request.
setRTResponsePoliciesPrecedenceResponse Policies
Sets the precedence of Response Policies based on the order of IDs specified in the request.
setSensorUpdatePoliciesPrecedenceSensor Update Policy
Sets the precedence of Sensor Update Policies based on the order of IDs specified in the request.
severity.query.v1IOC
Query Severities.
signalChangesExternalFileVantage
Initiates workflows for the provided change ids
ss-ioa-exclusions.aggregates.v2IOA Exclusions
Get Self Service IOA Exclusion aggregates as specified via json in the request body.
ss-ioa-exclusions.create.v2IOA Exclusions
Create new Self Service IOA Exclusions.
ss-ioa-exclusions.delete.v2IOA Exclusions
Delete the Self Service IOA Exclusions rule by id.
ss-ioa-exclusions.get-reports.v2IOA Exclusions
Create a report of Self Service IOA Exclusions scoped by the given filters
ss-ioa-exclusions.get.v2IOA Exclusions
Get the Self Service IOA Exclusions rules by id.
ss-ioa-exclusions.matched-rule.v2IOA Exclusions
Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent
ss-ioa-exclusions.new-rules.v2IOA Exclusions
Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent.
ss-ioa-exclusions.search.v2IOA Exclusions
Search for Self Service IOA Exclusions.
ss-ioa-exclusions.update.v2IOA Exclusions
Update the Self Service IOA Exclusions rule by id.
startActionsFileVantage
Initiates the specified action on the provided change ids
StartSearchV1NGSIEM
Initiate search
StopSearchV1NGSIEM
Stop search
SubmitFalconx Sandbox
Submit an uploaded file or a URL for sandbox analysis.
TestParserFromTemplateNGSIEM
Test Parser from LogScale YAML Template in NGSIEM
tokens-createInstallation Tokens
Creates a token.
tokens-deleteInstallation Tokens
Deletes a token immediately.
tokens-queryInstallation Tokens
Search for tokens by providing an FQL filter and paging details.
tokens-readInstallation Tokens
Gets the details of one or more tokens by id.
tokens-updateInstallation Tokens
Updates one or more tokens.
TriggerScanKubernetes Protection
Triggers a dry run or a full scan of a customer’s kubernetes footprint
update-global-configsNetwork Scan Global Configs
Update “global-configs” using provided specifications
update-network-locationsFirewall Management
Updates the network locations provided, and return the ID.
update-network-locations-metadataFirewall Management
Updates the network locations metadata such as polling_intervals for the cid
update-network-locations-precedenceFirewall Management
Updates the network locations precedence according to the list of ids provided.
update-networksNetwork Scan Networks
Update “networks” using provided specifications
update-policy-containerFirewall Management
Update an identified policy container, including local logging functionality.
update-policy-container-v1Firewall Management
Update an identified policy container.
update-rule-groupFirewall Management
Update name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
update-rule-group-validationFirewall Management
Validates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
update-rule-groupMixin0Custom IOA
Update a rule group.
update-rulesCustom IOA
Update rules within a rule group.
update-rules-v2Custom IOA
Update name, description, enabled or field_values for individual rules within a rule group.
update-scan-runsNetwork Scan Scan Runs
Update “scan-runs” using provided specifications
update-scannersNetwork Scan Scanners
Update “scanners” using provided specifications
update-scansNetwork Scan Scans
Update “scans” using provided specifications
update-templatesNetwork Scan Templates
Update “templates” using provided specifications
update-zonesNetwork Scan Zones
Update “zones” using provided specifications
UpdateActionV1Recon
Update an action for a monitoring rule.
UpdateAPIClientAPI Clients
Update existing API Client based on API Client ID provided as request parameter ‘ids’.
UpdateAWSAccountKubernetes Protection
Updates the AWS account per the query parameters provided
UpdateAWSAccountsCloud Connect AWS
Update AWS Accounts by specifying the ID of the account and details to update
UpdateCaseMessage Center
update an existing case
updateCIDGroupsMSSP (Flight Control)
Update existing CID groups.
UpdateCloudGroupExternalCloud Security
Update Cloud Group
UpdateComplianceControlCloud Policies
Update a custom compliance control
UpdateComplianceFrameworkCloud Policies
Update a custom compliance framework
updateContentUpdatePoliciesContent Update Policies
Update Content Update Policies by specifying the ID of the policy and details to update
UpdateCSPMAzureAccountCSPM Registration
Patches a existing account in our system for a customer.
UpdateCSPMAzureAccountClientIDCSPM Registration
Update an Azure service account in our system by with the user-created client_id created with the public key we’ve provided
UpdateCSPMAzureTenantDefaultSubscriptionIDCSPM Registration
Update an Azure default subscription_id in our system for given tenant_id
UpdateCSPMGCPAccountCSPM Registration
Patches a existing account in our system for a customer.
UpdateCSPMGCPServiceAccountsExtCSPM Registration
Patches the service account key for external clients.
UpdateCSPMPolicySettingsCSPM Registration
Updates a policy setting - can be used to override policy severity or to disable a policy entirely.
UpdateCSPMScanScheduleCSPM Registration
Updates scan schedule configuration for one or more cloud platforms.
UpdateD4CGCPServiceAccountsExtD4C Registration
Patches the service account key for external clients.
UpdateDashboardFromTemplateNGSIEM
Update Dashboard from LogScale YAML Template in NGSIEM.
updateDashboardLabelsNGSIEM
Replace all labels on a single dashboard
updateDefaultDeviceControlPoliciesDevice Control Policies
Update the configuration for a Default Device Control Policy
updateDefaultDeviceControlSettingsDevice Control Policies
Update the configuration for Default Device Control Settings
UpdateDefaultGroupASPM
Update default group
UpdateDetectsByIdsV2Detects
Deprecated: This endpoint will be decommissioned on September 30, 2025.
updateDeviceControlPoliciesDevice Control Policies
Update Device Control Policies by specifying the ID of the policy and details to update
UpdateDeviceTagsHosts
Append or remove one or more Falcon Grouping Tags on one or more hosts.
UpdateDiscoverCloudAzureAccountClientIDD4C Registration
Update an Azure service account in our system by with the user-created client_id created with the public key we’ve provided
UpdateExecutorNodeASPM
Update an existing relay node
updateFileLabelsNGSIEM
Replace all labels on a single file
UpdateFileV1Foundry Lookup Files
Updates a lookup file within a Foundry app
updateFirewallPoliciesFirewall Policies
Update Firewall Policies by specifying the ID of the policy and details to update
UpdateGroupASPM
Update group
UpdateGroupV1Mixin0Profile Groups
Update profile group metadata (name, description)
updateHostGroupsHost Group
Update Host Groups by specifying the ID of the group and details to update
UpdateIntegrationASPM
Update an existing integration by its ID
UpdateIntegrationTaskASPM
Update an existing integration task by its ID
updateIOAExclusionsV1IOA Exclusions
Update the IOA exclusions
UpdateIOCIOCs
Update an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (PATCH /iocs/entities/indicators/v1). ***
UpdateLookupFileNGSIEM
Update an entire Lookup File in NGSIEM
UpdateLookupFileEntriesNGSIEM
Update entries in an existing Lookup File in NGSIEM
updateMLExclusionsV1ML Exclusions
Update the ML exclusions
UpdateNotificationsV1Recon
Update notification status or assignee.
UpdateParserNGSIEM
Update Parser in NGSIEM.
UpdateParserAutoUpdatePolicyNGSIEM
Updates a parser auto update policy - ‘on’ enables auto-updates, ‘off’ disables them
UpdateParserExtensionNGSIEM
Update an existing Parser extension in NGSIEM.
UpdateParserFromTemplateNGSIEM
Update Parser in NGSIEM from YAML Template.
updatePoliciesFileVantage
Updates the general information of the provided policy.
UpdatePoliciesImage Assessment Policies
Update Image Assessment Policy entities
UpdatePolicyExclusionsImage Assessment Policies
Update Image Assessment Policy Exclusion entities
UpdatePolicyGroupsImage Assessment Policies
Update Image Assessment Policy Group entities
updatePolicyHostGroupsFileVantage
Manage host groups assigned to a policy.
updatePolicyPrecedenceFileVantage
Updates the policy precedence for all policies of a specific type.
UpdatePolicyPrecedenceImage Assessment Policies
Update Image Assessment Policy precedence
updatePolicyRuleGroupsFileVantage
Manage the rule groups assigned to the policy or set the rule group precedence for all rule groups within the policy.
updatePreventionPoliciesPrevention Policies
Update Prevention Policies by specifying the ID of the policy and details to update
UpdateQfByQueryQuarantine
Apply quarantine file actions by query.
UpdateQuarantinedDetectsByIdsQuarantine
Apply action by quarantine file ids
UpdateRegistryEntitiesFalcon Container
Update the registry entity, as identified by the entity UUID, using the provided details
updateRTResponsePoliciesResponse Policies
Update Response Policies by specifying the ID of the policy and details to update
UpdateRuleCloud Policies
Update a rule
updateRuleGroupPrecedenceFileVantage
Updates the rule precedence for all rules in the identified rule group.
updateRuleGroupsFileVantage
Updates the provided rule group.
UpdateRuleOverrideCloud Policies
Update a rule override
updateRulesFileVantage
Updates the provided rule configuration within the specified rule group.
UpdateRulesV1Recon
Update monitoring rules.
UpdateSavedQueryFromTemplateNGSIEM
Update Saved Query from LogScale YAML Template in NGSIEM.
updateSavedQueryLabelsNGSIEM
Replace all labels on a single saved query
updateScheduledExclusionsFileVantage
Updates the provided scheduled exclusion configuration within the provided policy.
updateSensorUpdatePoliciesSensor Update Policy
Update Sensor Update Policies by specifying the ID of the policy and details to update
updateSensorUpdatePoliciesV2Sensor Update Policy
Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection
updateSensorVisibilityExclusionsV1Sensor Visibility Exclusions
Update the sensor visibility exclusions
UpdateSuppressionRuleCloud Policies
Update a suppression rule
UpdateThirdPartyPasskeyRegistryFalcon ID
Updates third party passkey registries
UpdateUserUser Management
Deprecated : Please use PATCH /user-management/entities/users/v1.
updateUserGroupsMSSP (Flight Control)
Update existing user group(s).
updateUserV1User Management
Modify an existing user’s first or last name.
UploadFileMixin0Mixin94Quick Scan Pro
Uploads a file to be further analyzed with QuickScan Pro.
UploadFileQuickScanProQuick Scan Pro
Uploads a file to be further analyzed with QuickScan Pro.
UploadLookupV1NGSIEM
Upload file to NGSIEM
UploadSampleV2Falconx Sandbox
Upload a file for sandbox analysis.
UploadSampleV3Sample Uploads
Upload a file for further cloud analysis.
upsert-network-locationsFirewall Management
Updates the network locations provided, and return the ID.
UpsertBusinessApplicationsASPM
Create or Update Business Applications
UpsertTagsASPM
Create new or update existing tag.
userActionV1User Management
Apply actions to one or more User.
userRolesActionV1User Management
Grant or Revoke one or more role(s) to a user against a CID.
v1.child-executions.queryWorkflows
Search for child executions by providing a FQL filter and paging details.
validateCustom IOA
Validates field values and checks for matches if a test string is provided.
validate-filepath-patternFirewall Management
Validates that the test pattern matches the executable filepath glob pattern.
ValidateCSPMGCPServiceAccountExtCSPM Registration
Validates credentials for a service account
VerifyAWSAccountAccessCloud Connect AWS
Performs an Access Verification check on the specified AWS Account IDs
WorkflowActivitiesCombinedWorkflows
Search for activities by name.
WorkflowActivitiesContentCombinedWorkflows
Search for activities by name.
WorkflowDefinitionsActionWorkflows
Enable or disable a workflow definition, or stop all executions for a definition.
WorkflowDefinitionsCombinedWorkflows
Search workflow definitions based on the provided filter.
WorkflowDefinitionsDeleteWorkflows
Accepts a list of workflow definition IDs and deletes those definitions and all their associated versions.
WorkflowDefinitionsExportWorkflows
Exports a workflow definition for the given definition ID
WorkflowDefinitionsImportWorkflows
Imports a workflow definition based on the provided model
WorkflowDefinitionsUpdateWorkflows
Updates a workflow definition based on the provided model
WorkflowExecuteWorkflows
Executes an on-demand Workflow, the body is JSON used to trigger the execution, the response the execution ID(s)
WorkflowExecuteSingleNodeV1Workflows
Executes a single activity node, resulting in an execution where test_mode=true and single_node_execution=true, associated with a definition ID if provided
WorkflowExecutionResultsWorkflows
Get execution result of a given execution
WorkflowExecutionsActionWorkflows
Allows a user to resume/retry a failed workflow execution, or cancel/stop a currently running workflow execution
WorkflowExecutionsCombinedWorkflows
Search workflow executions based on the provided filter
WorkflowGetHumanInputV1Workflows
Gets one or more specific human inputs by their IDs.
WorkflowMockExecuteWorkflows
Executes a workflow definition with mocks
WorkflowSystemDefinitionsDeProvisionWorkflows
Deprovisions a system definition that was previously provisioned on the target CID
WorkflowSystemDefinitionsPromoteWorkflows
Promotes a version of a system definition for a customer.
WorkflowSystemDefinitionsProvisionWorkflows
Provisions a system definition onto the target CID by using the template and provided parameters
WorkflowTriggersCombinedWorkflows
Search for triggers by namespaced identifier, i.e.
WorkflowUpdateHumanInputV1Workflows
Provides an input in response to a human input action.