Network Scan Detections
Operations for the Network Scan Detections service collection.
| Language | Last Update |
|---|---|
| Python | v1.6.6 |
| PowerShell | |
| Go | |
| TypeScript | |
| Rust | |
| Ruby |
Table of Contents
Section titled “Table of Contents”| Operation | Description |
|---|---|
aggregate-detectionsaggregate_netscan_detections | Returns “detections” aggregations |
combined-detectionsget_combined_netscan_detections | Get “detections” by filter |
get-detectionsget_netscan_detections | Get “detections” by their IDs |
query-detectionsquery_netscan_detections | Get “detections IDs” by filter |
aggregate-detections
Section titled “aggregate-detections”Returns “detections” aggregations
Method POST
Route /netscan/aggregates/detections/GET/v1
Scope Network scanning: READ
PEP 8
aggregate_netscan_detectionsParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
date_ranges body · array
The date_ranges value.
exclude body · string
The exclude value.
extended_bounds body · object
The extended_bounds value.
field body · string
The field value.
filter body · string
The filter value.
filters_spec body · object
The filters_spec value.
from body · integer
The from value.
include body · string
The include value.
interval body · string
The interval value.
max_doc_count body · integer
The max_doc_count value.
min_doc_count body · integer
The min_doc_count value.
missing body · string
The missing value.
name body · string
The name value.
percents body · array
The percents value.
q body · string
The q value.
ranges body · array
The ranges value.
size body · integer
The size value.
sort body · string
The sort value.
sub_aggregates body · array
The sub_aggregates value.
time_zone body · string
The time_zone value.
type body · string
The type value.
Code Examples
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
date_ranges = [ { "from": "string", "to": "string" }]
extended_bounds = { "max": "string", "min": "string"}
filters_spec = { "filters": "string", "other_bucket": True, "other_bucket_key": "string"}
ranges = [ { "From": 0.0, "To": 0.0 }]
response = falcon.aggregate_netscan_detections(date_ranges=date_ranges, exclude="string", extended_bounds=extended_bounds, field="string", filter="string", filters_spec=filters_spec, from=integer, include="string", interval="string", max_doc_count=integer, min_doc_count=integer, missing="string", name="string", percents=["string"], q="string", ranges=ranges, size=integer, sort="string", sub_aggregates=["string"], time_zone="string", type="string")print(response)from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
date_ranges = [ { "from": "string", "to": "string" }]
extended_bounds = { "max": "string", "min": "string"}
filters_spec = { "filters": "string", "other_bucket": True, "other_bucket_key": "string"}
ranges = [ { "From": 0.0, "To": 0.0 }]
response = falcon.aggregate_detections(date_ranges=date_ranges, exclude="string", extended_bounds=extended_bounds, field="string", filter="string", filters_spec=filters_spec, from=integer, include="string", interval="string", max_doc_count=integer, min_doc_count=integer, missing="string", name="string", percents=["string"], q="string", ranges=ranges, size=integer, sort="string", sub_aggregates=["string"], time_zone="string", type="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = [ { "date_ranges": [ { "from": "string", "to": "string" } ], "exclude": "string", "extended_bounds": { "max": "string", "min": "string" }, "field": "string", "filter": "string", "filters_spec": { "filters": {}, "other_bucket": boolean, "other_bucket_key": "string" }, "from": integer, "include": "string", "interval": "string", "max_doc_count": integer, "min_doc_count": integer, "missing": "string", "name": "string", "percents": ["string"], "q": "string", "ranges": [ { "from": integer, "to": integer } ], "size": integer, "sort": "string", "sub_aggregates": [ { "date_ranges": ["string"], "exclude": "string", "extended_bounds": {}, "field": "string", "filter": "string", "filters_spec": {}, "from": integer, "include": "string", "interval": "string", "max_doc_count": integer, "min_doc_count": integer, "missing": "string", "name": "string", "percents": ["string"], "q": "string", "ranges": ["string"], "size": integer, "sort": "string", "sub_aggregates": ["string"], "time_zone": "string", "type": "string" } ], "time_zone": "string", "type": "string" }]
response = falcon.command("aggregate_detections", body=body_payload)print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Responses
[ { "buckets": [], "doc_count_error_upper_bound": 0, "hits": {}, "name": "string", "sum_other_doc_count": 0 }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}combined-detections
Section titled “combined-detections”Get “detections” by filter
Method GET
Route /netscan/combined/detections/v1
Scope Network scanning: READ
PEP 8
get_combined_netscan_detectionsParameters
Section titled “Parameters”offset query · integer
An offset used with the
limit parameter to manage pagination of results. On your first request, don’t provide an offset. On subsequent requests, add previous offset with the previous limit to continue from that place in the resultslimit query · integer
The number of “detections” to return in this response (Min: 1, Max: 100, Default: 100)
sort query · string
Sort “detections” by their properties. A single sort field is allowed
filter query · string
Search for “detections” by providing an FQL filter
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.get_combined_netscan_detections(offset=integer, limit=integer, sort="string", filter="string")print(response)from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.combined_detections(offset=integer, limit=integer, sort="string", filter="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("combined_detections", offset=integer, limit=integer, sort="string", filter="string")print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Responses
[ { "default_tcp_ports": [], "default_udp_ports": [], "id": "string", "name": "string", "script_id": "string", "services": [], "supported_credentials_protocols": [], "types": [] }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}get-detections
Section titled “get-detections”Get “detections” by their IDs
Method GET
Route /netscan/entities/detections/v1
Scope Network scanning: READ
PEP 8
get_netscan_detectionsParameters
Section titled “Parameters”ids query · string or list of strings
IDs of “detections” to be retrieved (Min: 1, Max: 100)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_netscan_detections(ids=id_list)print(response)from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_detections(ids=id_list)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("get_detections", ids=id_list)print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Responses
[ { "default_tcp_ports": [], "default_udp_ports": [], "id": "string", "name": "string", "script_id": "string", "services": [], "supported_credentials_protocols": [], "types": [] }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}query-detections
Section titled “query-detections”Get “detections IDs” by filter
Method GET
Route /netscan/queries/detections/v1
Scope Network scanning: READ
PEP 8
query_netscan_detectionsParameters
Section titled “Parameters”offset query · integer
An offset used with the
limit parameter to manage pagination of results. On your first request, don’t provide an offset. On subsequent requests, add previous offset with the previous limit to continue from that place in the resultslimit query · integer
The number of “detections IDs” to return in this response (Min: 1, Max: 100, Default: 100)
sort query · string
Sort “detections” by their properties. A single sort field is allowed
filter query · string
Search for “detections” by providing an FQL filter
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.query_netscan_detections(offset=integer, limit=integer, sort="string", filter="string")print(response)from falconpy import NetworkScanDetections
falcon = NetworkScanDetections(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.query_detections(offset=integer, limit=integer, sort="string", filter="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("query_detections", offset=integer, limit=integer, sort="string", filter="string")print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Responses
[ "string"]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}