Skip to content

Network Scan Detections

Operations for the Network Scan Detections service collection.

LanguageLast Update
Pythonv1.6.6
PowerShell
Go
TypeScript
Rust
Ruby

OperationDescription
aggregate-detections
aggregate_netscan_detections
Returns “detections” aggregations
combined-detections
get_combined_netscan_detections
Get “detections” by filter
get-detections
get_netscan_detections
Get “detections” by their IDs
query-detections
query_netscan_detections
Get “detections IDs” by filter

Returns “detections” aggregations

Method POST
Route /netscan/aggregates/detections/GET/v1
Scope Network scanning: READ
PEP 8 aggregate_netscan_detections
body body · dictionary
Full body payload as JSON formatted dictionary.
date_ranges body · array
The date_ranges value.
exclude body · string
The exclude value.
extended_bounds body · object
The extended_bounds value.
field body · string
The field value.
filter body · string
The filter value.
filters_spec body · object
The filters_spec value.
from body · integer
The from value.
include body · string
The include value.
interval body · string
The interval value.
max_doc_count body · integer
The max_doc_count value.
min_doc_count body · integer
The min_doc_count value.
missing body · string
The missing value.
name body · string
The name value.
percents body · array
The percents value.
q body · string
The q value.
ranges body · array
The ranges value.
size body · integer
The size value.
sort body · string
The sort value.
sub_aggregates body · array
The sub_aggregates value.
time_zone body · string
The time_zone value.
type body · string
The type value.
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
date_ranges = [
{
"from": "string",
"to": "string"
}
]
extended_bounds = {
"max": "string",
"min": "string"
}
filters_spec = {
"filters": "string",
"other_bucket": True,
"other_bucket_key": "string"
}
ranges = [
{
"From": 0.0,
"To": 0.0
}
]
response = falcon.aggregate_netscan_detections(date_ranges=date_ranges,
exclude="string",
extended_bounds=extended_bounds,
field="string",
filter="string",
filters_spec=filters_spec,
from=integer,
include="string",
interval="string",
max_doc_count=integer,
min_doc_count=integer,
missing="string",
name="string",
percents=["string"],
q="string",
ranges=ranges,
size=integer,
sort="string",
sub_aggregates=["string"],
time_zone="string",
type="string")
print(response)
[
{
"buckets": [],
"doc_count_error_upper_bound": 0,
"hits": {},
"name": "string",
"sum_other_doc_count": 0
}
]


Get “detections” by filter

Method GET
Route /netscan/combined/detections/v1
Scope Network scanning: READ
PEP 8 get_combined_netscan_detections
offset query · integer
An offset used with the limit parameter to manage pagination of results. On your first request, don’t provide an offset. On subsequent requests, add previous offset with the previous limit to continue from that place in the results
limit query · integer
The number of “detections” to return in this response (Min: 1, Max: 100, Default: 100)
sort query · string
Sort “detections” by their properties. A single sort field is allowed
filter query · string
Search for “detections” by providing an FQL filter
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.get_combined_netscan_detections(offset=integer,
limit=integer,
sort="string",
filter="string")
print(response)
[
{
"default_tcp_ports": [],
"default_udp_ports": [],
"id": "string",
"name": "string",
"script_id": "string",
"services": [],
"supported_credentials_protocols": [],
"types": []
}
]


Get “detections” by their IDs

Method GET
Route /netscan/entities/detections/v1
Scope Network scanning: READ
PEP 8 get_netscan_detections
ids query · string or list of strings
IDs of “detections” to be retrieved (Min: 1, Max: 100)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_netscan_detections(ids=id_list)
print(response)
[
{
"default_tcp_ports": [],
"default_udp_ports": [],
"id": "string",
"name": "string",
"script_id": "string",
"services": [],
"supported_credentials_protocols": [],
"types": []
}
]


Get “detections IDs” by filter

Method GET
Route /netscan/queries/detections/v1
Scope Network scanning: READ
PEP 8 query_netscan_detections
offset query · integer
An offset used with the limit parameter to manage pagination of results. On your first request, don’t provide an offset. On subsequent requests, add previous offset with the previous limit to continue from that place in the results
limit query · integer
The number of “detections IDs” to return in this response (Min: 1, Max: 100, Default: 100)
sort query · string
Sort “detections” by their properties. A single sort field is allowed
filter query · string
Search for “detections” by providing an FQL filter
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_netscan_detections(offset=integer,
limit=integer,
sort="string",
filter="string")
print(response)
[
"string"
]