Skip to content

AIDR

Operations for the AIDR service collection. Also available in FalconPy as Guardian.

LanguageLast Update
Pythonv1.6.6
PowerShell
Go
TypeScript
Rust
Ruby

OperationDescription
aggregateAgentSessionsV1
aggregate_aidr_agent_sessions
Aggregate agent-session counts by product
aggregateAgentsV1
aggregate_aidr_agents
Aggregate agent counts by product
aggregateDetectionsV1
aggregate_aidr_detections
Max detection severity per agent and product
aggregateSkillsV1
aggregate_aidr_skills
Aggregate skill usage counts by name
aggregateSkillUsageV1
aggregate_aidr_skill_usage
Aggregate skill invocation counts by name (LogScale)
aggregateToolsV1
aggregate_aidr_tools
Aggregate tool usage counts by name
aggregateToolUsageV1
aggregate_aidr_tool_usage
Aggregate tool invocation counts by name (LogScale)
entitiesAgentInstallationsV1
get_aidr_agent_installations
Get AI agent installation details by IDs
entitiesAgentOSUsersV1
get_aidr_agent_os_users
Get an OS user by aid + username
entitiesAgentSessionsV1
get_aidr_agent_sessions
Get AI agent session details by IDs
entitiesAgentsV1
get_aidr_agents
Get AI agent details by IDs
entitiesClassifiedFileAccessV1
get_aidr_classified_file_access
Get FDP classified file access for a process
entitiesExecutionsV1
get_aidr_executions
Get AI agent execution detail by session ID
entitiesFileEventsV1
get_aidr_file_events
Get file write activity from AI session processes
entitiesModelNamesV1
get_aidr_model_names
Get AI model name details by IDs
entitiesNetworkEventsV1
get_aidr_network_events
Get outbound network connections from AI session processes
entitiesProcessTreeV1
get_aidr_process_tree
Get spawned process tree for an AI session
entitiesSessionActivityV1
get_aidr_session_activity
Get ThreatGraph session activity (tools, models, processes)
entitiesSkillsV1
get_aidr_skills
Get AI skill frontmatter details by IDs
entitiesToolsV1
get_aidr_tools
Get AI tool details by IDs
queryAgentInstallationsV1
query_aidr_agent_installations
List AI agent installations
queryAgentOSUsersV1
query_aidr_agent_os_users
List OS users that ran AI agents
queryAgentSessionsV1
query_aidr_agent_sessions
List AI agent sessions
queryAgentsV1
query_aidr_agents
List AI agent instances
queryDetectionsV1
query_aidr_detections
List detections involving AI agent processes
queryExecutionsV1
query_aidr_executions
List AI agent process executions
queryMcpServerNamesV1
query_aidr_mcp_server_names
List MCP server names
queryModelNamesV1
query_aidr_model_names
List AI model names
queryPromptsV1
query_aidr_prompts
List AI prompt records
querySkillsV1
query_aidr_skills
List AI skill frontmatters
querySkillUsageV1
query_aidr_skill_usage
List AI skill invocations (LogScale, session-scoped)
queryToolsV1
query_aidr_tools
List AI tools
queryToolUsageV1
query_aidr_tool_usage
List AI tool invocations (LogScale, session-scoped)

Aggregate agent-session counts by product

Method GET
Route /aidr/aggregates/agent-sessions/v1
Scope Aidr Events: READ
PEP 8 aggregate_aidr_agent_sessions
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
product query · string
Filter by AI product name (e.g., CLAUDE_CODE, CURSOR)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.aggregate_aidr_agent_sessions(limit=integer,
offset=integer,
time_range="string",
product="string")
print(response)
[
{
"Product": {},
"ProductName": "string",
"count": {}
}
]


Aggregate agent counts by product

Method GET
Route /aidr/aggregates/agents/v1
Scope Aidr Events: READ
PEP 8 aggregate_aidr_agents
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.aggregate_aidr_agents(limit=integer,
offset=integer,
time_range="string")
print(response)
[
{
"AgentProduct": {},
"AgentProductName": "string",
"count": {}
}
]


Max detection severity per agent and product

Method GET
Route /aidr/aggregates/detections/v1
Scope Aidr Events: READ
PEP 8 aggregate_aidr_detections
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
agent_id query · string
Filter by agent ID (see endpoint notes: some use the 64-hex AIAgent.Id, detections use the 32-hex SensorId)
product query · string
Filter by AI product name (e.g., CLAUDE_CODE, CURSOR)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.aggregate_aidr_detections(limit=integer,
offset=integer,
time_range="string",
agent_id="string",
product="string")
print(response)
[
{
"AgentId": "string",
"AgenticProductTag": {},
"maxDetectionScore": {}
}
]


Aggregate skill usage counts by name

Method GET
Route /aidr/aggregates/skills/v1
Scope Aidr Events: READ
PEP 8 aggregate_aidr_skills
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
name_filter query · string
Filter by name pattern (supports wildcards via like)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.aggregate_aidr_skills(limit=integer,
offset=integer,
time_range="string",
name_filter="string")
print(response)
[
{
"SkillName": "string",
"count": {}
}
]


Aggregate skill invocation counts by name (LogScale)

Method GET
Route /aidr/aggregates/skill-usage/v1
Scope Aidr Events: READ
PEP 8 aggregate_aidr_skill_usage
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 2h, 24h). Max 7d; defaults to 2h if omitted (LogScale-backed)
session_id query · string
Filter by AgenticSessionId
aid query · string
Filter by sensor ID (aid) — identifies a host, not a single agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.aggregate_aidr_skill_usage(limit=integer,
offset=integer,
time_range="string",
session_id="string",
aid="string")
print(response)
[
{
"AgenticSkill": "string",
"count": {}
}
]


Aggregate tool usage counts by name

Method GET
Route /aidr/aggregates/tools/v1
Scope Aidr Events: READ
PEP 8 aggregate_aidr_tools
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
sensor_id query · string
Filter by sensor ID (32-hex aid / AIAgent.SensorId)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.aggregate_aidr_tools(limit=integer,
offset=integer,
time_range="string",
sensor_id="string")
print(response)
[
{
"Name": "string",
"count": {}
}
]


Aggregate tool invocation counts by name (LogScale)

Method GET
Route /aidr/aggregates/tool-usage/v1
Scope Aidr Events: READ
PEP 8 aggregate_aidr_tool_usage
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 2h, 24h). Max 7d; defaults to 2h if omitted (LogScale-backed)
session_id query · string
Filter by AgenticSessionId
aid query · string
Filter by sensor ID (aid) — identifies a host, not a single agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.aggregate_aidr_tool_usage(limit=integer,
offset=integer,
time_range="string",
session_id="string",
aid="string")
print(response)
[
{
"AgenticToolName": "string",
"count": {}
}
]


Get AI agent installation details by IDs

Method GET
Route /aidr/entities/agent-installations/v1
Scope Aidr Events: READ
PEP 8 get_aidr_agent_installations
ids query · string or list of strings
One or more installation IDs (repeatable). Use the Id value from GET /aidr/queries/agent-installations/v1.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_agent_installations(ids=id_list)
print(response)
[
{
"AgentDeclarationPath": "string",
"AgentName": "string",
"AgentProduct": "string",
"AgentProductName": "string",
"AgentVersion": "string",
"BinaryPath": "string",
"FileSha256": "string",
"FirstSeen": "string",
"Hostname": "string",
"Id": "string",
"InstallSource": "string",
"LastExecutionTime": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"SensorId": "string",
"SpiffeId": "string"
}
]


Get an OS user by aid + username

Method GET
Route /aidr/entities/agent-os-users/v1
Scope Aidr Events: READ
PEP 8 get_aidr_agent_os_users
aid query · string
The OS user’s sensor ID (aid). Required — AIAgentOSUser is keyed on Aid + Username.
username query · string
The OS username. Required — AIAgentOSUser is keyed on Aid + Username.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.get_aidr_agent_os_users(aid="string", username="string")
print(response)
[
{
"Aid": "string",
"FirstSeen": "string",
"LastSeen": "string",
"ObjectSid": "string",
"Username": "string"
}
]


Get AI agent session details by IDs

Method GET
Route /aidr/entities/agent-sessions/v1
Scope Aidr Events: READ
PEP 8 get_aidr_agent_sessions
ids query · string or list of strings
One or more session IDs (repeatable: ids=A&ids=B). Use the Id value from GET /aidr/queries/agent-sessions/v1. This is the AIAgentSession entity key, not a ThreatGraph vertex key.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_agent_sessions(ids=id_list)
print(response)
[
{
"Cim": {},
"FirstSeen": "string",
"Id": "string",
"LastSeen": "string",
"Name": "string",
"Product": "string",
"ProductName": "string"
}
]


Get AI agent details by IDs

Method GET
Route /aidr/entities/agents/v1
Scope Aidr Events: READ
PEP 8 get_aidr_agents
ids query · string or list of strings
One or more AIAgent IDs (repeatable: ids=A&ids=B). This is the 64-hex content hash from the Id field of GET /aidr/queries/agents/v1 — NOT the 32-hex SensorId.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_agents(ids=id_list)
print(response)
[
{
"AgentIds": [],
"AgentName": "string",
"AgentProduct": "string",
"AgentProductName": "string",
"CreatedTime": "string",
"FirstSeen": "string",
"Hostname": "string",
"Id": "string",
"LastExecutionTime": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"SensorId": "string",
"SpiffeId": "string",
"UpdatedTime": "string"
}
]


Get FDP classified file access for a process

Method GET
Route /aidr/entities/classified-file-access/v1
Scope Aidr Events: READ
PEP 8 get_aidr_classified_file_access
id query · string
A process vertex ID of the form pid:{aid}:{process_id}. Obtain it from a process node in GET /aidr/entities/process-tree/v1 or /aidr/entities/session-activity/v1 (the process __id). A session ID is NOT accepted here — this endpoint does not resolve it.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_classified_file_access(id=id_list)
print(response)
[
{
"classified_file_accesses": [],
"command_line": "string",
"image_file_name": "string",
"process_id": "string"
}
]


Get AI agent execution detail by session ID

Method GET
Route /aidr/entities/executions/v1
Scope Aidr Events: READ
PEP 8 get_aidr_executions
id query · string
A session ID (AgenticSessionId from GET /aidr/queries/executions/v1 or /aidr/queries/agent-sessions/v1). Returns the process invocation(s) for that session; add context_process_id to narrow to a single execution.
context_process_id query · string
Narrow an execution to a single process invocation (ContextProcessId from GET /aidr/queries/executions/v1)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.get_aidr_executions(id="string", context_process_id="string")
print(response)
[
{
"AgenticInputTokens": {},
"AgenticModel": "string",
"AgenticOutputTokens": {},
"AgenticSessionId": "string",
"AgenticWorkingDirectory": "string",
"ContextProcessId": "string",
"ProcessTags": [],
"aid": "string",
"timestamp": "string"
}
]


Get file write activity from AI session processes

Method GET
Route /aidr/entities/file-events/v1
Scope Aidr Events: READ
PEP 8 get_aidr_file_events
id query · string
A session ID. Accepts either the AgenticSessionId from GET /aidr/queries/executions/v1 (resolved automatically) or a ThreatGraph vertex key aisess:{aid}:{session_id}. This is session-scoped — pass a session ID, not a process ID.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_file_events(id=id_list)
print(response)
[
{
"SessionProcessPid": [],
"__id": "string"
}
]


Get AI model name details by IDs

Method GET
Route /aidr/entities/model-names/v1
Scope Aidr Events: READ
PEP 8 get_aidr_model_names
ids query · string or list of strings
One or more AIModelName IDs (repeatable). Use the Id value from GET /aidr/queries/model-names/v1.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_model_names(ids=id_list)
print(response)
[
{
"Cim": {},
"FirstSeen": "string",
"Id": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"LastUsedTime": "string"
}
]


Get outbound network connections from AI session processes

Method GET
Route /aidr/entities/network-events/v1
Scope Aidr Events: READ
PEP 8 get_aidr_network_events
id query · string
A session ID. Accepts either the AgenticSessionId from GET /aidr/queries/executions/v1 (resolved automatically) or a ThreatGraph vertex key aisess:{aid}:{session_id}. This is session-scoped — pass a session ID, not a process ID.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_network_events(id=id_list)
print(response)
[
{
"SessionProcessPid": [],
"__id": "string"
}
]


Get spawned process tree for an AI session

Method GET
Route /aidr/entities/process-tree/v1
Scope Aidr Events: READ
PEP 8 get_aidr_process_tree
id query · string
A session ID. Accepts either the AgenticSessionId from GET /aidr/queries/executions/v1 (resolved automatically) or a ThreatGraph vertex key aisess:{aid}:{session_id}. This is session-scoped — pass a session ID, not a process ID.
depth query · integer
Process tree depth (1=direct spawns, 2=grandchildren, 3=max). Default 2
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.get_aidr_process_tree(id="string", depth=integer)
print(response)
[
{
"SessionProcessPid": [],
"__id": "string"
}
]


Get ThreatGraph session activity (tools, models, processes)

Method GET
Route /aidr/entities/session-activity/v1
Scope Aidr Events: READ
PEP 8 get_aidr_session_activity
ids query · string or list of strings
One or more session IDs (repeatable). Accepts either the AgenticSessionId from GET /aidr/queries/executions/v1 (resolved to a graph vertex automatically) or a ThreatGraph vertex key aisess:{aid}:{session_id} (aid = the session’s aid; the sess- prefix is stripped).
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_session_activity(ids=id_list)
print(response)
[
{
"AgenticProduct": "string",
"AgenticSessionId": "string",
"ChildSessionAisess": [],
"ConnectedMcpMcpsrv": [],
"DisplayName": "string",
"InvokesModelAimod": [],
"LoadedSkillAiskill": [],
"SessionProcessPid": [],
"SessionRunByAiagent": [],
"UsedToolAitool": [],
"__id": "string",
"__typename": "string"
}
]


Get AI skill frontmatter details by IDs

Method GET
Route /aidr/entities/skills/v1
Scope Aidr Events: READ
PEP 8 get_aidr_skills
ids query · string or list of strings
One or more skill frontmatter IDs (repeatable). Use the Id value from GET /aidr/queries/skills/v1.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_skills(ids=id_list)
print(response)
[
{
"CreatedTime": "string",
"FirstSeen": "string",
"Id": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"SkillDescription": "string",
"SkillDirectoryHash": "string",
"SkillName": "string",
"UpdatedTime": "string"
}
]


Get AI tool details by IDs

Method GET
Route /aidr/entities/tools/v1
Scope Aidr Events: READ
PEP 8 get_aidr_tools
ids query · string or list of strings
One or more AITool IDs (repeatable: ids=A&ids=B). Use the Id value from GET /aidr/queries/tools/v1.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_aidr_tools(ids=id_list)
print(response)
[
{
"Cim": {},
"FirstSeen": "string",
"Id": "string",
"LastSeen": "string",
"Name": "string",
"SensorId": "string"
}
]


List AI agent installations

Method GET
Route /aidr/queries/agent-installations/v1
Scope Aidr Events: READ
PEP 8 query_aidr_agent_installations
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
sensor_id query · string
Filter by sensor ID (32-hex aid / AIAgent.SensorId)
product query · string
Filter by AI product name (e.g., CLAUDE_CODE, CURSOR)
hostname query · string
Filter by hostname of the device running the agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_agent_installations(limit=integer,
offset=integer,
time_range="string",
sensor_id="string",
product="string",
hostname="string")
print(response)
[
{
"AgentDeclarationPath": "string",
"AgentName": "string",
"AgentProduct": "string",
"AgentProductName": "string",
"AgentVersion": "string",
"BinaryPath": "string",
"FileSha256": "string",
"FirstSeen": "string",
"Hostname": "string",
"Id": "string",
"InstallSource": "string",
"LastExecutionTime": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"SensorId": "string",
"SpiffeId": "string"
}
]


List OS users that ran AI agents

Method GET
Route /aidr/queries/agent-os-users/v1
Scope Aidr Events: READ
PEP 8 query_aidr_agent_os_users
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
object_sid query · string
Filter by the OS user’s ObjectSid (AD security identifier)
aid query · string
Filter by sensor ID (aid) — identifies a host, not a single agent
username query · string
Filter by OS username
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_agent_os_users(limit=integer,
offset=integer,
time_range="string",
object_sid="string",
aid="string",
username="string")
print(response)
[
{
"Aid": "string",
"FirstSeen": "string",
"LastSeen": "string",
"ObjectSid": "string",
"Username": "string"
}
]


List AI agent sessions

Method GET
Route /aidr/queries/agent-sessions/v1
Scope Aidr Events: READ
PEP 8 query_aidr_agent_sessions
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
product query · string
Filter by AI product name (e.g., CLAUDE_CODE, CURSOR)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_agent_sessions(limit=integer,
offset=integer,
time_range="string",
product="string")
print(response)
[
{
"Cim": {},
"FirstSeen": "string",
"Id": "string",
"LastSeen": "string",
"Name": "string",
"Product": "string",
"ProductName": "string"
}
]


List AI agent instances

Method GET
Route /aidr/queries/agents/v1
Scope Aidr Events: READ
PEP 8 query_aidr_agents
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
product query · string
Filter by AI product name (e.g., CLAUDE_CODE, CURSOR)
hostname query · string
Filter by hostname of the device running the agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_agents(limit=integer,
offset=integer,
time_range="string",
product="string",
hostname="string")
print(response)
[
{
"AgentIds": [],
"AgentName": "string",
"AgentProduct": "string",
"AgentProductName": "string",
"CreatedTime": "string",
"FirstSeen": "string",
"Hostname": "string",
"Id": "string",
"LastExecutionTime": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"SensorId": "string",
"SpiffeId": "string",
"UpdatedTime": "string"
}
]


List detections involving AI agent processes

Method GET
Route /aidr/queries/detections/v1
Scope Aidr Events: READ
PEP 8 query_aidr_detections
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
agent_id query · string
Filter by agent ID (see endpoint notes: some use the 64-hex AIAgent.Id, detections use the 32-hex SensorId)
product query · string
Filter by AI product name (e.g., CLAUDE_CODE, CURSOR)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_detections(limit=integer,
offset=integer,
time_range="string",
agent_id="string",
product="string")
print(response)
[
{
"AgentId": "string",
"AgenticProductTag": "string",
"AgenticProductTagName": "string",
"AssignedToName": "string",
"CompositeId": "string",
"CreatedTimestamp": "string",
"DataDomains": "string",
"HasAgenticProcess": false,
"Name": "string",
"Product": "string",
"RiskScore": 0,
"Severity": 0,
"SeverityName": "string",
"Sha256": "string",
"SourceHosts": "string",
"SourceProducts": "string",
"Status": "string",
"Tactic": "string",
"Technique": "string",
"Timestamp": "string",
"UserNames": "string"
}
]


List AI agent process executions

Method GET
Route /aidr/queries/executions/v1
Scope Aidr Events: READ
PEP 8 query_aidr_executions
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 2h, 24h). Max 7d; defaults to 2h if omitted (LogScale-backed)
session_id query · string
Filter by AgenticSessionId
aid query · string
Filter by sensor ID (aid) — identifies a host, not a single agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_executions(limit=integer,
offset=integer,
time_range="string",
session_id="string",
aid="string")
print(response)
[
{
"AgenticInputTokens": {},
"AgenticModel": "string",
"AgenticOutputTokens": {},
"AgenticSessionId": "string",
"AgenticWorkingDirectory": "string",
"ContextProcessId": "string",
"ProcessTags": [],
"aid": "string",
"timestamp": "string"
}
]


List MCP server names

Method GET
Route /aidr/queries/mcp-server-names/v1
Scope Aidr Events: READ
PEP 8 query_aidr_mcp_server_names
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_mcp_server_names(limit=integer,
offset=integer,
time_range="string")
print(response)
[
{
"Cim": {},
"FirstSeen": "string",
"Id": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"LastUsedTime": "string"
}
]


List AI model names

Method GET
Route /aidr/queries/model-names/v1
Scope Aidr Events: READ
PEP 8 query_aidr_model_names
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_model_names(limit=integer,
offset=integer,
time_range="string")
print(response)
[
{
"Cim": {},
"FirstSeen": "string",
"Id": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"LastUsedTime": "string"
}
]


List AI prompt records

Method GET
Route /aidr/queries/prompts/v1
Scope Aidr Events: READ
PEP 8 query_aidr_prompts
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 2h, 24h). Max 7d; defaults to 2h if omitted (LogScale-backed)
session_id query · string
Filter by AgenticSessionId
aid query · string
Filter by sensor ID (aid) — identifies a host, not a single agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_prompts(limit=integer,
offset=integer,
time_range="string",
session_id="string",
aid="string")
print(response)
[
{
"AgenticPrompt": "string",
"AgenticSessionId": "string",
"ProcessTags": [],
"aid": "string",
"timestamp": "string"
}
]


List AI skill frontmatters

Method GET
Route /aidr/queries/skills/v1
Scope Aidr Events: READ
PEP 8 query_aidr_skills
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
name_filter query · string
Filter by name pattern (supports wildcards via like)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_skills(limit=integer,
offset=integer,
time_range="string",
name_filter="string")
print(response)
[
{
"CreatedTime": "string",
"FirstSeen": "string",
"Id": "string",
"LastInventoryTime": "string",
"LastSeen": "string",
"SkillDescription": "string",
"SkillDirectoryHash": "string",
"SkillName": "string",
"UpdatedTime": "string"
}
]


List AI skill invocations (LogScale, session-scoped)

Method GET
Route /aidr/queries/skill-usage/v1
Scope Aidr Events: READ
PEP 8 query_aidr_skill_usage
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 2h, 24h). Max 7d; defaults to 2h if omitted (LogScale-backed)
name query · string
Filter skill invocations by skill name (matches AgenticSkill exactly)
session_id query · string
Filter by AgenticSessionId
aid query · string
Filter by sensor ID (aid) — identifies a host, not a single agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_skill_usage(limit=integer,
offset=integer,
time_range="string",
name="string",
session_id="string",
aid="string")
print(response)
[
{
"AgenticSessionId": "string",
"AgenticSkill": "string",
"AgenticToolUseId": "string",
"aid": "string"
}
]


List AI tools

Method GET
Route /aidr/queries/tools/v1
Scope Aidr Events: READ
PEP 8 query_aidr_tools
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 7d, 24h). Max 90d
sensor_id query · string
Filter by sensor ID (32-hex aid / AIAgent.SensorId)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_tools(limit=integer,
offset=integer,
time_range="string",
sensor_id="string")
print(response)
[
{
"Cim": {},
"FirstSeen": "string",
"Id": "string",
"LastSeen": "string",
"Name": "string",
"SensorId": "string"
}
]


List AI tool invocations (LogScale, session-scoped)

Method GET
Route /aidr/queries/tool-usage/v1
Scope Aidr Events: READ
PEP 8 query_aidr_tool_usage
limit query · integer
Maximum number of results to return (1-500, default 50)
offset query · integer
Pagination offset (0-1000)
time_range query · string
Lookback period (e.g., 2h, 24h). Max 7d; defaults to 2h if omitted (LogScale-backed)
tool_name query · string
Filter tool invocations by tool name (e.g., Bash, Read, Write, Edit)
session_id query · string
Filter by AgenticSessionId
aid query · string
Filter by sensor ID (aid) — identifies a host, not a single agent
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import AIDR
falcon = AIDR(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_aidr_tool_usage(limit=integer,
offset=integer,
time_range="string",
tool_name="string",
session_id="string",
aid="string")
print(response)
[
{
"AgenticDescription": "string",
"AgenticPath": "string",
"AgenticPattern": "string",
"AgenticQuery": "string",
"AgenticSessionId": "string",
"AgenticSkill": "string",
"AgenticTool": "string",
"AgenticToolName": "string",
"AgenticToolUseId": "string",
"CommandLine": "string",
"Url": "string",
"aid": "string"
}
]