Network Scan Scans
Operations for the Network Scan Scans service collection.
| Language | Last Update |
|---|---|
| Python | v1.6.5 |
| PowerShell | |
| Go | v0.22.0 |
| TypeScript | v0.6.0 |
| Rust | v0.7.1 |
| Ruby | v1.4.0 |
Table of Contents
Section titled “Table of Contents”| Operation | Description |
|---|---|
aggregate-scansMixin0aggregate_scans | Returns “scans” aggregations |
create-scanscreate_scans | Create “scans” using provided specifications |
delete-scansdelete_scans | Delete “scans” by their IDs |
get-scansget_scans | Get “scans” by their IDs |
query-scansMixin0query_scans | Get “scans IDs” by filter |
update-scansupdate_scans | Update “scans” using provided specifications |
aggregate-scansMixin0
Section titled “aggregate-scansMixin0”Returns “scans” aggregations
Method POST
Route /netscan/aggregates/scans/GET/v1
Scope Network scanning: READ
PEP 8
aggregate_scansParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
date_ranges body · array
Array of date range specifications for date-based aggregations.
exclude body · string
Fields to exclude from the aggregation.
extended_bounds body · object
field body · string
The field to aggregate on.
filter body · string
FQL query to filter the data before aggregating.
filters_spec body · object
from body · integer
Starting index for the aggregation.
include body · string
Fields to include in the aggregation.
interval body · string
Time interval for date histogram aggregations (e.g., day, week, month)
max_doc_count body · integer
Maximum document count for bucket inclusion.
min_doc_count body · integer
Minimum document count for bucket inclusion.
missing body · string
The value to use for documents missing the aggregation field.
name body · string
The name of the aggregation query.
percents body · array
q body · string
Full-text search query.
ranges body · array
Numeric range specifications for range aggregations.
size body · integer
The maximum number of results to return per aggregate.
sort body · string
The field to sort aggregate results on.
sub_aggregates body · array
Nested sub-aggregation specifications.
time_zone body · string
The time zone to use for date aggregations.
type body · string
The type of aggregate query to perform.
Code Examples
from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
date_ranges = [ { "from": "string", "to": "string" }]
ranges = [ { "From": "integer", "To": "integer" }]
sub_aggregates = [ {}]
response = falcon.aggregate_scans(date_ranges=date_ranges, exclude="string", field="string", filter="string", from=integer, include="string", interval="string", max_doc_count=integer, min_doc_count=integer, missing="string", name="string", q="string", ranges=ranges, size=integer, sort="string", sub_aggregates=sub_aggregates, time_zone="string", type="string")print(response)from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
date_ranges = [ { "from": "string", "to": "string" }]
ranges = [ { "From": "integer", "To": "integer" }]
sub_aggregates = [ {}]
response = falcon.aggregate_scansMixin0(date_ranges=date_ranges, exclude="string", field="string", filter="string", from=integer, include="string", interval="string", max_doc_count=integer, min_doc_count=integer, missing="string", name="string", q="string", ranges=ranges, size=integer, sort="string", sub_aggregates=sub_aggregates, time_zone="string", type="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = [ { "date_ranges": [ { "from": "string", "to": "string" } ], "exclude": "string", "extended_bounds": { "max": "string", "min": "string" }, "field": "string", "filter": "string", "filters_spec": { "filters": {}, "other_bucket": boolean, "other_bucket_key": "string" }, "from": integer, "include": "string", "interval": "string", "max_doc_count": integer, "min_doc_count": integer, "missing": "string", "name": "string", "percents": ["string"], "q": "string", "ranges": [ { "from": integer, "to": integer } ], "size": integer, "sort": "string", "sub_aggregates": [ { "date_ranges": ["string"], "exclude": "string", "extended_bounds": {}, "field": "string", "filter": "string", "filters_spec": {}, "from": integer, "include": "string", "interval": "string", "max_doc_count": integer, "min_doc_count": integer, "missing": "string", "name": "string", "percents": ["string"], "q": "string", "ranges": ["string"], "size": integer, "sort": "string", "sub_aggregates": ["string"], "time_zone": "string", "type": "string" } ], "time_zone": "string", "type": "string" }]
response = falcon.command("aggregate_scansMixin0", body=body_payload)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/network_scan_scans" "github.com/crowdstrike/gofalcon/falcon/models")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
from := "string" to := "string" exclude := "string" field := "string" filter := "string" from := integer include := "string" interval := "string" max_doc_count := integer min_doc_count := integer missing := "string" name := "string" q := "string" From := integer To := integer size := integer sort := "string" time_zone := "string" typeVar := "string"
response, err := client.NetworkScanScans.AggregateScansMixin0( &network_scan_scans.AggregateScansMixin0Params{ Body: []*models.MsaAggregateQueryRequest{ { DateRanges: []interface{}{ { From: &from, To: &to, }, }, Exclude: &exclude, ExtendedBounds: &struct{}{}, Field: &field, Filter: &filter, FiltersSpec: &struct{}{}, From: &from, Include: &include, Interval: &interval, MaxDocCount: &max_doc_count, MinDocCount: &min_doc_count, Missing: &missing, Name: &name, Percents: []interface{}{}, Q: &q, Ranges: []interface{}{ { From: &From, To: &To, }, }, Size: &size, Sort: &sort, SubAggregates: []interface{}{ { DateRanges: []interface{}{ { From: &from, To: &to, }, }, Exclude: &exclude, ExtendedBounds: &struct{}{}, Field: &field, Filter: &filter, FiltersSpec: &struct{}{}, From: &from, Include: &include, Interval: &interval, MaxDocCount: &max_doc_count, MinDocCount: &min_doc_count, Missing: &missing, Name: &name, Percents: []interface{}{}, Q: &q, Ranges: []interface{}{ { From: &From, To: &To, }, }, Size: &size, Sort: &sort, SubAggregates: []interface{}{ { DateRanges: []interface{}{}, Exclude: &exclude, ExtendedBounds: &struct{}{}, Field: &field, Filter: &filter, FiltersSpec: &struct{}{}, From: &from, Include: &include, Interval: &interval, MaxDocCount: &max_doc_count, MinDocCount: &min_doc_count, Missing: &missing, Name: &name, Percents: []interface{}{}, Q: &q, Ranges: []interface{}{}, Size: &size, Sort: &sort, SubAggregates: []interface{}{}, TimeZone: &time_zone, Type: &typeVar, }, }, TimeZone: &time_zone, Type: &typeVar, }, }, TimeZone: &time_zone, Type: &typeVar, }, }, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.networkScanScans.aggregateScansMixin0( [{ dateRanges: [{ from: "string", to: "string" }], exclude: "string", extendedBounds: { max: "string", min: "string" }, field: "string", filter: "string", filtersSpec: { filters: {}, otherBucket: boolean, otherBucketKey: "string" }, from: integer, include: "string", interval: "string", maxDocCount: integer, minDocCount: integer, missing: "string", name: "string", percents: [], q: "string", ranges: [{ From: integer, To: integer }], size: integer, sort: "string", subAggregates: [{ dateRanges: [{ from: "string", to: "string" }], exclude: "string", extendedBounds: { max: "string", min: "string" }, field: "string", filter: "string", filtersSpec: { filters: {}, otherBucket: boolean, otherBucketKey: "string" }, from: integer, include: "string", interval: "string", maxDocCount: integer, minDocCount: integer, missing: "string", name: "string", percents: [], q: "string", ranges: [{ From: integer, To: integer }], size: integer, sort: "string", subAggregates: [{ dateRanges: [], exclude: "string", extendedBounds: {}, field: "string", filter: "string", filtersSpec: {}, from: integer, include: "string", interval: "string", maxDocCount: integer, minDocCount: integer, missing: "string", name: "string", percents: [], q: "string", ranges: [], size: integer, sort: "string", subAggregates: [], timeZone: "string", type: "string" }], timeZone: "string", type: "string" }], timeZone: "string", type: "string"}] // body);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::NetworkScanScans.new
body = [Falcon::MsaAggregateQueryRequest.new( date_ranges: [{ from: 'string', to: 'string' }], exclude: 'string', extended_bounds: { max: 'string', min: 'string' }, field: 'string', filter: 'string', filters_spec: { filters: {}, other_bucket: boolean, other_bucket_key: 'string' }, from: integer, include: 'string', interval: 'string', max_doc_count: integer, min_doc_count: integer, missing: 'string', name: 'string', percents: [], q: 'string', ranges: [{ From: integer, To: integer }], size: integer, sort: 'string', sub_aggregates: [{ date_ranges: [{ from: 'string', to: 'string' }], exclude: 'string', extended_bounds: { max: 'string', min: 'string' }, field: 'string', filter: 'string', filters_spec: { filters: {}, other_bucket: boolean, other_bucket_key: 'string' }, from: integer, include: 'string', interval: 'string', max_doc_count: integer, min_doc_count: integer, missing: 'string', name: 'string', percents: [], q: 'string', ranges: [{ From: integer, To: integer }], size: integer, sort: 'string', sub_aggregates: [{ date_ranges: [], exclude: 'string', extended_bounds: {}, field: 'string', filter: 'string', filters_spec: {}, from: integer, include: 'string', interval: 'string', max_doc_count: integer, min_doc_count: integer, missing: 'string', name: 'string', percents: [], q: 'string', ranges: [], size: integer, sort: 'string', sub_aggregates: [], time_zone: 'string', type: 'string' }], time_zone: 'string', type: 'string' }], time_zone: 'string', type: 'string')]
response = api.aggregate_scans_mixin0(body)
puts responseResponses
[ { "buckets": [], "doc_count_error_upper_bound": 0, "hits": {}, "name": "string", "sum_other_doc_count": 0 }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}create-scans
Section titled “create-scans”Create “scans” using provided specifications
Method POST
Route /netscan/entities/scans/v1
Scope Network scanning: WRITE
PEP 8
create_scansParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
block_windows body · object
Block Windows configuration attached to the scan
credentialed body · boolean
Indicates if the scan is credentialed
credentials body · object
The credentials for this scan
description body · string
Description of the scan
fragile_device_detection body · boolean
Indicates if the scan includes fragile-device detection
name body · string
Name of the scan
scheduling body · object
Scheduling configuration attached to the scan
target_asset body · object
The target asset for this scan
target_asset_filter body · object
The target asset filter for this scan
target_external_ip body · object
The target external IP for this scan
target_ip body · object
The target IP for this scan
target_type body · string
The type of the target for this scan
Available values (5)
ip | asset | asset_filter |
asset_vuln | external_ip |
template_id body · string
Template identifier for the scan
Code Examples
from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.create_scans(block_windows={}, credentialed=boolean, credentials={}, description="string", fragile_device_detection=boolean, name="string", scheduling={}, target_asset={}, target_asset_filter={}, target_external_ip={}, target_ip={}, target_type="string", template_id="string")print(response)from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.create_scans(block_windows={}, credentialed=boolean, credentials={}, description="string", fragile_device_detection=boolean, name="string", scheduling={}, target_asset={}, target_asset_filter={}, target_external_ip={}, target_ip={}, target_type="string", template_id="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = [ { "block_windows": { "intervals": ["string"], "timezone": "string" }, "credentialed": boolean, "credentials": { "auto_authorize_scanners": boolean, "ids": ["string"] }, "description": "string", "fragile_device_detection": boolean, "name": "string", "scheduling": { "days_of_month": ["string"], "days_of_week": ["string"], "end_date": "string", "frequency": "string", "occurrence": "string", "start_date": "string", "start_time": "string", "timeout_seconds": integer, "timezone": "string" }, "target_asset": { "ids": ["string"] }, "target_asset_filter": { "fql_filter": "string" }, "target_external_ip": { "ip_specs": ["string"] }, "target_ip": { "ip_specs": ["string"], "zone_id": "string" }, "target_type": "string", "template_id": "string" }]
response = falcon.command("create_scans", body=body_payload)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/network_scan_scans" "github.com/crowdstrike/gofalcon/falcon/models")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
credentialed := boolean description := "string" fragile_device_detection := boolean name := "string" target_type := "string" template_id := "string"
response, err := client.NetworkScanScans.CreateScans( &network_scan_scans.CreateScansParams{ Body: []*models.DomainScanCreateRequest{ { BlockWindows: &struct{}{}, Credentialed: &credentialed, Credentials: &struct{}{}, Description: &description, FragileDeviceDetection: &fragile_device_detection, Name: &name, Scheduling: &struct{}{}, TargetAsset: &struct{}{}, TargetAssetFilter: &struct{}{}, TargetExternalIp: &struct{}{}, TargetIp: &struct{}{}, TargetType: &target_type, TemplateID: &template_id, }, }, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.networkScanScans.createScans( [{ blockWindows: { intervals: [{ endTime: "string", startTime: "string" }], timezone: "string" }, credentialed: boolean, credentials: { autoAuthorizeScanners: boolean, ids: [] }, description: "string", fragileDeviceDetection: boolean, name: "string", scheduling: { daysOfMonth: [], daysOfWeek: [], endDate: "string", frequency: "string", occurrence: "string", startDate: "string", startTime: "string", timeoutSeconds: integer, timezone: "string" }, targetAsset: { ids: [] }, targetAssetFilter: { fqlFilter: "string" }, targetExternalIp: { ipSpecs: [] }, targetIp: { ipSpecs: [], zoneId: "string" }, targetType: "string", templateId: "string"}] // body);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::NetworkScanScans.new
body = [Falcon::DomainScanCreateRequest.new( block_windows: { intervals: [{ end_time: 'string', start_time: 'string' }], timezone: 'string' }, credentialed: boolean, credentials: { auto_authorize_scanners: boolean, ids: [] }, description: 'string', fragile_device_detection: boolean, name: 'string', scheduling: { days_of_month: [], days_of_week: [], end_date: 'string', frequency: 'string', occurrence: 'string', start_date: 'string', start_time: 'string', timeout_seconds: integer, timezone: 'string' }, target_asset: { ids: [] }, target_asset_filter: { fql_filter: 'string' }, target_external_ip: { ip_specs: [] }, target_ip: { ip_specs: [], zone_id: 'string' }, target_type: 'string', template_id: 'string')]
response = api.create_scans(body)
puts responseResponses
[ { "block_windows": {}, "cid": "string", "created_by": "string", "created_timestamp": "string", "credentialed": false, "credentials": {}, "description": "string", "fragile_device_detection": false, "frequency": "string", "id": "string", "last_run_timestamp": "string", "last_scan_status": "string", "name": "string", "next_run_timestamp": "string", "scheduling": {}, "target_asset": {}, "target_asset_filter": {}, "target_external_ip": {}, "target_ip": {}, "target_type": "string", "template_id": "string", "type": "string", "updated_by": "string", "updated_timestamp": "string" }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}delete-scans
Section titled “delete-scans”Delete “scans” by their IDs
Method DELETE
Route /netscan/entities/scans/v1
Scope Network scanning: WRITE
PEP 8
delete_scansParameters
Section titled “Parameters”ids query · string or list of strings
IDs of “scans” to be deleted (Min: 1, Max: 100)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.delete_scans(ids=id_list)print(response)from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.delete_scans(ids=id_list)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("delete_scans", ids=id_list)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/network_scan_scans")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.NetworkScanScans.DeleteScans( &network_scan_scans.DeleteScansParams{ Ids: []string{"ID1", "ID2", "ID3"}, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.networkScanScans.deleteScans(["ID1", "ID2", "ID3"]); // ids
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::NetworkScanScans.new
response = api.delete_scans(['ID1', 'ID2', 'ID3'])
puts responseResponses
[ "string"]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}get-scans
Section titled “get-scans”Get “scans” by their IDs
Method GET
Route /netscan/entities/scans/v1
Scope Network scanning: READ
PEP 8
get_scansParameters
Section titled “Parameters”ids query · string or list of strings
IDs of “scans” to be retrieved (Min: 1, Max: 100)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_scans(ids=id_list)print(response)from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_scans(ids=id_list)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("get_scans", ids=id_list)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/network_scan_scans")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.NetworkScanScans.GetScans( &network_scan_scans.GetScansParams{ Ids: []string{"ID1", "ID2", "ID3"}, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.networkScanScans.getScans(["ID1", "ID2", "ID3"]); // ids
console.log(response);use rusty_falcon::apis::quick_scan_api::get_scans;use rusty_falcon::easy::client::FalconHandle;
#[tokio::main]async fn main() { let falcon = FalconHandle::from_env().await.expect("Could not authenticate");
let response = get_scans( &falcon.cfg, // configuration vec!["string".to_string()], // ids ).await.expect("API call failed");
println!("{:?}", response);}require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::NetworkScanScans.new
response = api.get_scans(['ID1', 'ID2', 'ID3'])
puts responseResponses
[ { "block_windows": {}, "cid": "string", "created_by": "string", "created_timestamp": "string", "credentialed": false, "credentials": {}, "description": "string", "fragile_device_detection": false, "frequency": "string", "id": "string", "last_run_timestamp": "string", "last_scan_status": "string", "name": "string", "next_run_timestamp": "string", "scheduling": {}, "target_asset": {}, "target_asset_filter": {}, "target_external_ip": {}, "target_ip": {}, "target_type": "string", "template_id": "string", "type": "string", "updated_by": "string", "updated_timestamp": "string" }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}query-scansMixin0
Section titled “query-scansMixin0”Get “scans IDs” by filter
Method GET
Route /netscan/queries/scans/v1
Scope Network scanning: READ
PEP 8
query_scansParameters
Section titled “Parameters”offset query · integer
An offset used with the
limit parameter to manage pagination of results. On your first request, don’t provide an offset. On subsequent requests, add previous offset with the previous limit to continue from that place in the resultslimit query · integer
The number of “scans IDs” to return in this response (Min: 1, Max: 100, Default: 100)
sort query · string
Sort “scans” by their properties. A single sort field is allowed
filter query · string
Search for “scans” by providing an FQL filter
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.query_scans(offset=integer, limit=integer, sort="string", filter="string")print(response)from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.query_scansMixin0(offset=integer, limit=integer, sort="string", filter="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("query_scansMixin0", offset=integer, limit=integer, sort="string", filter="string")print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/network_scan_scans")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
offset := int64(0) limit := int64(0) sort := "string" filter := "string"
response, err := client.NetworkScanScans.QueryScansMixin0( &network_scan_scans.QueryScansMixin0Params{ Offset: &offset, Limit: &limit, Sort: &sort, Filter: &filter, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.networkScanScans.queryScansMixin0( integer, // offset integer, // limit "string", // sort "string" // filter);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::NetworkScanScans.new
response = api.query_scans_mixin0(offset: integer, limit: integer, sort: 'string', filter: 'string')
puts responseResponses
[ "string"]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}update-scans
Section titled “update-scans”Update “scans” using provided specifications
Method PATCH
Route /netscan/entities/scans/v1
Scope Network scanning: WRITE
PEP 8
update_scansParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
block_windows body · object
Block Windows configuration attached to the scan
credentialed body · boolean
Indicates if the scan is credentialed
credentials body · object
The credentials for this scan
description body · string
Description of the scan
fragile_device_detection body · boolean
Indicates if the scan includes fragile device detection
id body · string
ID of the scan
name body · string
Name of the scan
scheduling body · object
Scheduling configuration attached to the scan
target_asset body · object
The target asset associated with this scan
target_asset_filter body · object
The target asset filter associated with this scan
target_external_ip body · object
The target external IP associated with this scan
target_ip body · object
The target IP associated with this scan
target_type body · string
The type of the target scan
Available values (5)
ip | asset | asset_filter |
asset_vuln | external_ip |
template_id body · string
Template ID of the scan
Code Examples
from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.update_scans(block_windows={}, credentialed=boolean, credentials={}, description="string", fragile_device_detection=boolean, id="string", name="string", scheduling={}, target_asset={}, target_asset_filter={}, target_external_ip={}, target_ip={}, target_type="string", template_id="string")print(response)from falconpy import NetworkScanScans
falcon = NetworkScanScans(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.update_scans(block_windows={}, credentialed=boolean, credentials={}, description="string", fragile_device_detection=boolean, id="string", name="string", scheduling={}, target_asset={}, target_asset_filter={}, target_external_ip={}, target_ip={}, target_type="string", template_id="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = [ { "block_windows": { "intervals": ["string"], "timezone": "string" }, "credentialed": boolean, "credentials": { "auto_authorize_scanners": boolean, "ids": ["string"] }, "description": "string", "fragile_device_detection": boolean, "id": "string", "name": "string", "scheduling": { "days_of_month": ["string"], "days_of_week": ["string"], "end_date": "string", "frequency": "string", "occurrence": "string", "start_date": "string", "start_time": "string", "timeout_seconds": integer, "timezone": "string" }, "target_asset": { "ids": ["string"] }, "target_asset_filter": { "fql_filter": "string" }, "target_external_ip": { "ip_specs": ["string"] }, "target_ip": { "ip_specs": ["string"], "zone_id": "string" }, "target_type": "string", "template_id": "string" }]
response = falcon.command("update_scans", body=body_payload)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/network_scan_scans" "github.com/crowdstrike/gofalcon/falcon/models")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
credentialed := boolean description := "string" fragile_device_detection := boolean id := "string" name := "string" target_type := "string" template_id := "string"
response, err := client.NetworkScanScans.UpdateScans( &network_scan_scans.UpdateScansParams{ Body: []*models.DomainScanUpdateRequest{ { BlockWindows: &struct{}{}, Credentialed: &credentialed, Credentials: &struct{}{}, Description: &description, FragileDeviceDetection: &fragile_device_detection, ID: &id, Name: &name, Scheduling: &struct{}{}, TargetAsset: &struct{}{}, TargetAssetFilter: &struct{}{}, TargetExternalIp: &struct{}{}, TargetIp: &struct{}{}, TargetType: &target_type, TemplateID: &template_id, }, }, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.networkScanScans.updateScans( [{ blockWindows: { intervals: [{ endTime: "string", startTime: "string" }], timezone: "string" }, credentialed: boolean, credentials: { autoAuthorizeScanners: boolean, ids: [] }, description: "string", fragileDeviceDetection: boolean, id: "string", name: "string", scheduling: { daysOfMonth: [], daysOfWeek: [], endDate: "string", frequency: "string", occurrence: "string", startDate: "string", startTime: "string", timeoutSeconds: integer, timezone: "string" }, targetAsset: { ids: [] }, targetAssetFilter: { fqlFilter: "string" }, targetExternalIp: { ipSpecs: [] }, targetIp: { ipSpecs: [], zoneId: "string" }, targetType: "string", templateId: "string"}] // body);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::NetworkScanScans.new
body = [Falcon::DomainScanUpdateRequest.new( block_windows: { intervals: [{ end_time: 'string', start_time: 'string' }], timezone: 'string' }, credentialed: boolean, credentials: { auto_authorize_scanners: boolean, ids: [] }, description: 'string', fragile_device_detection: boolean, id: 'string', name: 'string', scheduling: { days_of_month: [], days_of_week: [], end_date: 'string', frequency: 'string', occurrence: 'string', start_date: 'string', start_time: 'string', timeout_seconds: integer, timezone: 'string' }, target_asset: { ids: [] }, target_asset_filter: { fql_filter: 'string' }, target_external_ip: { ip_specs: [] }, target_ip: { ip_specs: [], zone_id: 'string' }, target_type: 'string', template_id: 'string')]
response = api.update_scans(body)
puts responseResponses
[ { "block_windows": {}, "cid": "string", "created_by": "string", "created_timestamp": "string", "credentialed": false, "credentials": {}, "description": "string", "fragile_device_detection": false, "frequency": "string", "id": "string", "last_run_timestamp": "string", "last_scan_status": "string", "name": "string", "next_run_timestamp": "string", "scheduling": {}, "target_asset": {}, "target_asset_filter": {}, "target_external_ip": {}, "target_ip": {}, "target_type": "string", "template_id": "string", "type": "string", "updated_by": "string", "updated_timestamp": "string" }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}