ThreatGraph
The ThreatGraph service collection provides operations for exploring threat intelligence relationships. Retrieve edges and vertex summaries for threat entities, look up indicators observed on devices in your environment, and explore available edge types.
| Language | Last Update |
|---|---|
| Python | v1.6.5 |
| PowerShell | v2.2.9 |
| Go | v0.22.0 |
| TypeScript | v0.6.0 |
| Rust | v0.7.1 |
| Ruby | v1.4.0 |
This service collection has code examples posted to the repository.
Table of Contents
Section titled “Table of Contents”| Operation | Description |
|---|---|
combined_edges_getget_edges | Retrieve edges for a given vertex id. |
combined_ran_on_getget_ran_on | Look up instances of indicators such as hashes, domain names, and ip addresses that have been seen on devices in your environment. |
combined_summary_getget_summary | Retrieve summary for a given vertex ID |
entities_vertices_getget_vertices_v1 | Retrieve metadata for a given vertex ID. |
entities_vertices_getv2get_vertices | Retrieve metadata for a given vertex ID |
queries_edgetypes_getget_edge_types | Show all available edge types |
combined_edges_get
Section titled “combined_edges_get”Retrieve edges for a given vertex id.
Method GET
Route /threatgraph/combined/edges/v1
Scope Threatgraph: READ
PEP 8
get_edgesParameters
Section titled “Parameters”ids query · string
Vertex ID to get details for. Only one value is supported
limit query · integer
How many edges to return in a single request [1-100]
offset query · string
The offset to use to retrieve the next page of results
edge_type query · string
The type of edges that you would like to retrieve
Available values (284)
accessed_ad_computer | accessed_adfs_application | accessed_azure_application |
accessed_by_kerberos_ticket | accessed_by_process | accessed_by_session |
accessed_classified_file | accessed_okta_application | accessed_ping_fed_application |
accessed_service_account | accessed_web | agent_process |
agent_to_self_diagnostic | ai_agent_used_by | ai_runs_on |
allowed_by_process | allowed_firewall_rule | app_uninstalled_from_host |
assigned_ipv4_address | assigned_ipv6_address | assigned_to_sensor |
associated_by_ad_computer | associated_by_ad_group | associated_by_ad_user |
associated_by_aggregate_indicator | associated_by_app | associated_by_azure_ad_user |
associated_by_azure_app | associated_by_certificate | associated_by_control_graph |
associated_by_domain | associated_by_host | associated_by_host_name |
associated_by_idp_session | associated_by_incident | associated_by_indicator |
associated_by_ip | associated_by_ip4 | associated_by_ip6 |
associated_by_okta_user | associated_by_service_ticket | associated_control_graph |
associated_firewall_rule | associated_idp_indicator | associated_incident |
associated_indicator | associated_k8s_cluster | associated_k8s_sensor |
associated_mobile_forensics_report | associated_mobile_indicator | associated_module |
associated_primary_module | associated_quarantined_file | associated_quarantined_module |
associated_root_process | associated_to_ad_computer | associated_to_sensor |
associated_user_session | associated_vmware_cluster | associated_vmware_sensor |
associated_with_process | associated_with_sensor | attributed_by_process |
attributed_from_domain | attributed_from_module | attributed_on |
attributed_on_domain | attributed_on_module | attributed_to |
attributed_to_actor | authenticated_from_incident | authenticated_host |
blocked_by_app | blocked_by_process | blocked_by_sensor |
blocked_dns | blocked_ip4 | blocked_ip6 |
blocked_module | bundled_in_app | bundles_module |
cert_is_presented_by | cert_presented | child_process |
child_session | classified_file_accessed_by | closed_ip4_socket |
closed_ip6_socket | command_line_parent_process | connected_from_app |
connected_from_host | connected_from_process | connected_ip4 |
connected_ip6 | connected_mcp | connected_on_customer |
connected_on_sensor | connected_to_accessory | connected_to_wifi_ap |
connection_killed_by_app | connection_killed_by_process | containerized_app |
containerized_by_sensor | control_graph | created_by_incident |
created_by_process | created_by_user | created_quarantined_file |
created_service | customer_agent_has_user | customer_has_sensor |
customer_ioc | customer_sensor_to_sensor | customer_user_to_sensor_user |
deleted_by_process | deleted_rule | denied_by_firewall_rule |
denied_by_process | denied_firewall_rule | detected_module |
detection | device | disconnect_from_wifi_ap |
disconnected_from_accessory | disconnected_from_host | dns |
dns_request | duplicated_by_app | duplicates_app |
established_on_ad_computer | established_on_host_name | established_on_ip4 |
established_on_ip6 | established_on_sensor | established_session |
established_user_session | executed_app | executed_by_process |
executed_macro_script | executed_script | extracted_file |
failed_to_authenticate_ad_user | failed_to_authenticate_to_ad_computer | failed_to_authenticate_to_adfs_app |
failed_to_authenticate_to_azure_app | failed_to_authenticate_to_okta_app | failed_to_authenticate_to_ping_app |
failed_to_authenticate_to_service_account | generated_by_renewing | generated_by_session |
generated_dce_rpc_epm_request_against_dc | generated_dce_rpc_request_against_dc | generated_failed_authentication_to_ad_computer |
generated_failed_authentication_to_adfs_app | generated_failed_authentication_to_azure_app | generated_failed_authentication_to_okta_app |
generated_failed_authentication_to_ping_app | generated_failed_authentication_to_service_account | generated_ldap_search_against_dc |
generated_service_ticket | had_code_injected_by_process | has_app_installed |
has_attributed_process | has_attribution | has_firmware |
implicated_by_incident | implicated_sensor | indexed |
initiated_by_ad_computer | initiated_by_azure_ad_user | initiated_by_okta_user |
initiated_by_user | initiated_session | injected_code_into_process |
injected_thread | injected_thread_from_process | installed_app |
installed_by_app | installed_on_host | invalid_firewall_rule |
invalid_from_process | invalidated_by_process | invalidated_firewall_rule |
invokes_model | involved_ad_computer | involved_service_account |
ip4_socket_closed_by_app | ip4_socket_closed_by_process | ip4_socket_opened_by_process |
ip6_socket_closed_by_app | ip6_socket_closed_by_process | ip6_socket_opened_by_process |
ipv4 | ipv4_close | ipv4_listen |
ipv6 | ipv6_close | ipv6_listen |
killed_ip4_connection | killed_ip6_connection | known_by_md5 |
known_by_sha256 | linking_event | loaded_by_process |
loaded_module | loaded_skill | macro_executed_by_process |
mcp_tool_call | member_of_full_command_line | module |
module_written | mounted_on_host | mounted_to_host |
network_close_ip4 | network_close_ip6 | network_connect_ip4 |
network_connect_ip6 | network_listen_ip4 | network_listen_ip6 |
opened_ip4_socket | opened_ip6_socket | parent_of_command_line |
parent_process | parented_by_process | participating_process |
performed_psexec_against_dc | presented_by_cloud | primary_module |
primary_module_of_process | process_ai_agent | protected_by_shield |
quarantined_file | queried_by_process | queried_by_sensor |
queried_dns | queried_on_customer | queried_on_sensor |
received_from_cloud | registered_by_incident | registered_scheduledtask |
renewed_to_generate | reports_aggregate_indicator | resolved_from_domain |
resolved_to_ip4 | resolved_to_ip6 | rooted_control_graph |
rule_set_by_process | script | self_diagnostic_to_agent |
session_on_sensor | session_process | set_by_process |
set_firewall_rule | set_rule | shell_io_redirect |
shield_activated_on_host | submitted_prompt | tool_spawned_process |
trigger_process | triggered_by_control_graph | triggered_by_process |
triggered_control_graph | triggered_custom_ioa | triggered_detection |
triggered_indicator | triggered_mobile_indicator | triggered_xdr |
triggering_domain | triggering_network | uncontainerized_app |
uncontainerized_by_sensor | uninstalled_app | unmounted_from_host |
unmounted_on_host | used_tool | user |
user_session | uses_ai_agent | witnessed_by_sensor |
witnessed_process | wmicreated_by_incident | wmicreated_process |
written_by_process | wrote_module |
direction query · string
The direction of edges that you would like to retrieve.
scope query · string
Scope of the request
Available values (2)
device | customer |
nano query · boolean
Return nano-precision entity timestamps
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_edges(direction="string", edge_type="string", ids=id_list, limit=integer, nano=boolean, offset="string", scope="string")print(response)from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.combined_edges_get(direction="string", edge_type="string", ids=id_list, limit=integer, nano=boolean, offset="string", scope="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("combined_edges_get", ids="string", limit=integer, offset="string", edge_type="string", direction="string", scope="string", nano=boolean)print(response)Get-FalconThreatGraphEdge -Id "string" ` -EdgeType "string" ` -Limit integer ` -Offset "string"package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/threatgraph")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
limit := int64(0) offset := "string" direction := "string" scope := "string" nano := boolean
response, err := client.Threatgraph.CombinedEdgesGet( &threatgraph.CombinedEdgesGetParams{ Ids: "string", Limit: &limit, Offset: &offset, EdgeType: "string", Direction: &direction, Scope: &scope, Nano: &nano, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.threatgraph.combinedEdgesGet( "string", // ids "string", // edgeType integer, // limit "string", // offset "string", // direction "string", // scope boolean // nano);
console.log(response);use rusty_falcon::apis::threatgraph_api::combined_edges_get;use rusty_falcon::easy::client::FalconHandle;
#[tokio::main]async fn main() { let falcon = FalconHandle::from_env().await.expect("Could not authenticate");
let response = combined_edges_get( &falcon.cfg, // configuration "string", // ids "string", // edge_type Some(integer), // limit Some("string"), // offset Some("string"), // direction Some("string"), // scope Some(boolean), // nano ).await.expect("API call failed");
println!("{:?}", response);}require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::Threatgraph.new
response = api.combined_edges_get('string', 'string')
puts responseResponses
{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}combined_ran_on_get
Section titled “combined_ran_on_get”Look up instances of indicators such as hashes, domain names, and ip addresses that have been seen on devices in your environment.
Method GET
Route /threatgraph/combined/ran-on/v1
Scope Threatgraph: READ
PEP 8
get_ran_onParameters
Section titled “Parameters”value query · string
The value of the indicator to search by.
type query · string
The type of indicator that you would like to retrieve
Available values (6)
domain | ipv4 | ipv6 |
md5 | sha1 | sha256 |
limit query · integer
How many edges to return in a single request [1-100]
offset query · string
The offset to use to retrieve the next page of results
nano query · boolean
Return nano-precision entity timestamps
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.get_ran_on(limit=integer, nano=boolean, offset="string", type="string", value="string")print(response)from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.combined_ran_on_get(limit=integer, nano=boolean, offset="string", type="string", value="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("combined_ran_on_get", value="string", type="string", limit=integer, offset="string", nano=boolean)print(response)Get-FalconThreatGraphIndicator -Type "string" ` -Value "string" ` -Limit integer ` -Offset "string"package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/threatgraph")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
limit := int64(0) offset := "string" nano := boolean
response, err := client.Threatgraph.CombinedRanOnGet( &threatgraph.CombinedRanOnGetParams{ Value: "string", Type: "string", Limit: &limit, Offset: &offset, Nano: &nano, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.threatgraph.combinedRanOnGet( "string", // value "string", // type integer, // limit "string", // offset boolean // nano);
console.log(response);use rusty_falcon::apis::threatgraph_api::combined_ran_on_get;use rusty_falcon::easy::client::FalconHandle;
#[tokio::main]async fn main() { let falcon = FalconHandle::from_env().await.expect("Could not authenticate");
let response = combined_ran_on_get( &falcon.cfg, // configuration "string", // value Some(integer), // limit Some("string"), // offset Some(boolean), // nano ).await.expect("API call failed");
println!("{:?}", response);}require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::Threatgraph.new
response = api.combined_ran_on_get('string', 'string')
puts responseResponses
{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}combined_summary_get
Section titled “combined_summary_get”Retrieve summary for a given vertex ID
Method GET
Route /threatgraph/combined/{vertex-type}/summary/v1
Scope Threatgraph: READ
PEP 8
get_summaryParameters
Section titled “Parameters”vertex-type path · string
Type of vertex to get properties for
Available values (114)
accessory | accessories | actor |
ad_computer | ad-computers | adfs_application |
adfs-applications | ad_group | ad-groups |
aggregate_indicator | aggregate-indicators | ai_agent |
ai-agents | sensor | devices |
ai_model | ai-models | ai_prompt |
ai-prompts | ai_session | ai-sessions |
ai_skill | ai-skills | ai_tool |
ai-tools | mobile_app | mobile-apps |
azure_application | azure-applications | azure_ad_user |
azure-ad-users | containerized_app | containerized-apps |
certificate | certificates | command_line |
command-lines | control_graph | control-graphs |
detection | detections | domain |
domains | extracted_file | extracted-files |
fdp_classified_files | fdp-classified-files | firmware |
firmwares | mobile_fs_volume | mobile-fs-volumes |
firewall | firewalls | firewall_rule_match |
firewall_rule_matches | host_name | host-names |
detection_index | detection-indices | idp_indicator |
idp-indicators | idp_session | idp-sessions |
incident | incidents | indicator |
indicators | custom_ioa | custom_ioas |
ipv4 | ipv6 | k8s_cluster |
k8s_clusters | legacy_detection | legacy-detections |
mcp_server | mcp-servers | mobile_os_forensics_report |
mobile_os_forensics_reports | mobile_indicator | mobile-indicators |
module | modules | macro_script |
macro_scripts | okta_application | okta-applications |
okta_user | okta-users | process |
processes | ping_fed_application | ping-fed-applications |
quarantined_file | quarantined-files | script |
scripts | shield | shields |
sensor_self_diagnostic | sensor-self-diagnostics | kerberos_ticket |
kerberos-tickets | user_id | users |
user_session | user-sessions | vmware_cluster |
vmware_clusters | web_access | wifi_access_point |
wifi-access-points | xdr | any-vertex |
ids query · string or list of strings
Vertex ID to get details for
scope query · string
Scope of the request
Available values (2)
device | customer |
nano query · boolean
Return nano-precision entity timestamps
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
vertex_type body · string
Type of vertex to get properties for. Allowed values:
Available values (321)
accessories | accessory | actor |
ad-computers | ad-groups | ad_computer |
ad_group | adfs-applications | adfs_application |
aggregate-indicators | aggregate_indicator | ai-agents |
ai-models | ai-prompts | ai-sessions |
ai-skills | ai-tools | ai_agent |
ai_model | ai_prompt | ai_session |
ai_skill | ai_tool | any-vertex |
azure-ad-users | azure-applications | azure_ad_user |
azure_application | certificate | certificates |
command-lines | command_line | containerized-apps |
containerized_app | control-graphs | control_graph |
custom_ioa | custom_ioas | detection |
detection-indices | detection_index | detections |
devices | domain | domains |
extracted-files | extracted_file | fdp-classified-files |
fdp_classified_files | firewall | firewall_rule_match |
firewall_rule_matches | firewalls | firmware |
firmwares | host-names | host_name |
idp-indicators | idp-sessions | idp_indicator |
idp_session | incident | incidents |
indicator | indicators | ipv4 |
ipv6 | k8s_cluster | k8s_clusters |
kerberos-tickets | kerberos_ticket | legacy-detections |
legacy_detection | macro_script | macro_scripts |
mcp-servers | mcp_server | mobile-apps |
mobile-fs-volumes | mobile-indicators | mobile_app |
mobile_fs_volume | mobile_indicator | mobile_os_forensics_report |
mobile_os_forensics_reports | module | modules |
okta-applications | okta-users | okta_application |
okta_user | ping-fed-applications | ping_fed_application |
process | processes | quarantined-files |
quarantined_file | script | scripts |
sensor | sensor-self-diagnostics | sensor_self_diagnostic |
shield | shields | user-sessions |
user_id | user_session | users |
vmware_cluster | vmware_clusters | web_access |
wifi-access-points | wifi_access_point | xdr |
actor | ad-computers | ad-groups |
ad_computer | ad_group | adfs-applications |
adfs_application | aggregate-indicators | aggregate_indicator |
ai-agents | ai-models | ai-prompts |
ai-sessions | ai-skills | ai-tools |
ai_agent | ai_model | ai_prompt |
ai_session | ai_skill | ai_tool |
any-vertex | azure-ad-users | azure-applications |
azure_ad_user | azure_application | certificate |
certificates | command-lines | command_line |
containerized-apps | containerized_app | control-graphs |
control_graph | custom_ioa | custom_ioas |
detection | detection-indices | detection_index |
detections | devices | domain |
domains | extracted-files | extracted_file |
firewall | firewall_rule_match | firewall_rule_matches |
firewalls | firmware | firmwares |
host-names | host_name | idp-indicators |
idp-sessions | idp_indicator | idp_session |
incident | incidents | indicator |
indicators | ipv4 | ipv6 |
k8s_cluster | k8s_clusters | kerberos-tickets |
kerberos_ticket | legacy-detections | legacy_detection |
macro_script | macro_scripts | mcp-servers |
mcp_server | mobile-apps | mobile-fs-volumes |
mobile-indicators | mobile_app | mobile_fs_volume |
mobile_indicator | mobile_os_forensics_report | mobile_os_forensics_reports |
module | modules | okta-applications |
okta-users | okta_application | okta_user |
ping-fed-applications | ping_fed_application | process |
processes | quarantined-files | quarantined_file |
script | scripts | sensor |
sensor-self-diagnostics | sensor_self_diagnostic | shield |
shields | user-sessions | user_id |
user_session | users | vmware_cluster |
vmware_clusters | web_access | wifi-access-points |
wifi_access_point | xdr | ad-computers |
indicator | ad-groups | indicators |
ad_computer | ipv4 | ad_group |
ipv6 | adfs-applications | k8s_cluster |
adfs_application | k8s_clusters | aggregate-indicators |
kerberos-tickets | aggregate_indicator | kerberos_ticket |
any-vertex | legacy-detections | azure-ad-users |
legacy_detection | azure-applications | macro_script |
azure_ad_user | macro_scripts | azure_application |
mobile-apps | certificate | mobile-fs-volumes |
certificates | mobile-indicators | command-lines |
mobile_app | command_line | mobile_fs_volume |
containerized-apps | mobile_indicator | containerized_app |
mobile_os_forensics_report | control-graphs | mobile_os_forensics_reports |
control_graph | module | customer |
modules | customers | okta-applications |
detection | okta-users | detection-indices |
okta_application | detection_index | okta_user |
detections | ping-fed-applications | devices |
ping_fed_application | direct | process |
directs | processes | domain |
quarantined-files | domains | quarantined_file |
extracted-files | script | extracted_file |
scripts | firewall | sensor |
firewall_rule_match | sensor-self-diagnostics | firewall_rule_matches |
sensor_self_diagnostic | firewalls | tag |
firmware | tags | firmwares |
user-sessions | host-names | user_id |
host_name | user_session | hunting-leads |
users | hunting_lead | wifi-access-points |
idp-indicators | wifi_access_point | idp-sessions |
xdr | idp_indicator | shield |
shields | custom_ioa | custom_ioas |
Code Examples
from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_summary(ids=id_list, scope="string", nano=boolean, vertex_type="string")print(response)from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.combined_summary_get(ids=id_list, scope="string", nano=boolean, vertex_type="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("combined_summary_get", vertex_type="string", ids=id_list, scope="string", nano=boolean)print(response)Get-FalconThreatGraphVertex -Id @("ID1", "ID2") -IncludeEdge $booleanpackage main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/threatgraph")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
scope := "string" nano := boolean
response, err := client.Threatgraph.CombinedSummaryGet( &threatgraph.CombinedSummaryGetParams{ VertexType: "string", Ids: []string{"ID1", "ID2", "ID3"}, Scope: &scope, Nano: &nano, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.threatgraph.combinedSummaryGet( "string", // vertexType ["ID1", "ID2", "ID3"], // ids "string", // scope boolean // nano);
console.log(response);use rusty_falcon::apis::threatgraph_api::combined_summary_get;use rusty_falcon::easy::client::FalconHandle;
#[tokio::main]async fn main() { let falcon = FalconHandle::from_env().await.expect("Could not authenticate");
let response = combined_summary_get( &falcon.cfg, // configuration "string", // vertex_type vec!["string".to_string()], // ids Some("string"), // scope Some(boolean), // nano ).await.expect("API call failed");
println!("{:?}", response);}require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::Threatgraph.new
response = api.combined_summary_get('string', ['ID1', 'ID2', 'ID3'])
puts responseResponses
{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}entities_vertices_get
Section titled “entities_vertices_get”Retrieve metadata for a given vertex ID.
Method GET
Route /threatgraph/entities/{vertex-type}/v1
Scope Threatgraph: READ
PEP 8
get_vertices_v1Parameters
Section titled “Parameters”vertex-type path · string
Type of vertex to get properties for
Available values (114)
accessory | accessories | actor |
ad_computer | ad-computers | adfs_application |
adfs-applications | ad_group | ad-groups |
aggregate_indicator | aggregate-indicators | ai_agent |
ai-agents | sensor | devices |
ai_model | ai-models | ai_prompt |
ai-prompts | ai_session | ai-sessions |
ai_skill | ai-skills | ai_tool |
ai-tools | mobile_app | mobile-apps |
azure_application | azure-applications | azure_ad_user |
azure-ad-users | containerized_app | containerized-apps |
certificate | certificates | command_line |
command-lines | control_graph | control-graphs |
detection | detections | domain |
domains | extracted_file | extracted-files |
fdp_classified_files | fdp-classified-files | firmware |
firmwares | mobile_fs_volume | mobile-fs-volumes |
firewall | firewalls | firewall_rule_match |
firewall_rule_matches | host_name | host-names |
detection_index | detection-indices | idp_indicator |
idp-indicators | idp_session | idp-sessions |
incident | incidents | indicator |
indicators | custom_ioa | custom_ioas |
ipv4 | ipv6 | k8s_cluster |
k8s_clusters | legacy_detection | legacy-detections |
mcp_server | mcp-servers | mobile_os_forensics_report |
mobile_os_forensics_reports | mobile_indicator | mobile-indicators |
module | modules | macro_script |
macro_scripts | okta_application | okta-applications |
okta_user | okta-users | process |
processes | ping_fed_application | ping-fed-applications |
quarantined_file | quarantined-files | script |
scripts | shield | shields |
sensor_self_diagnostic | sensor-self-diagnostics | kerberos_ticket |
kerberos-tickets | user_id | users |
user_session | user-sessions | vmware_cluster |
vmware_clusters | web_access | wifi_access_point |
wifi-access-points | xdr | any-vertex |
ids query · string or list of strings
Vertex ID to get details for
scope query · string
Scope of the request
Available values (2)
device | customer |
nano query · boolean
Return nano-precision entity timestamps
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
vertex_type body · string
Type of vertex to get properties for. Allowed values:
Available values (321)
accessories | accessory | actor |
ad-computers | ad-groups | ad_computer |
ad_group | adfs-applications | adfs_application |
aggregate-indicators | aggregate_indicator | ai-agents |
ai-models | ai-prompts | ai-sessions |
ai-skills | ai-tools | ai_agent |
ai_model | ai_prompt | ai_session |
ai_skill | ai_tool | any-vertex |
azure-ad-users | azure-applications | azure_ad_user |
azure_application | certificate | certificates |
command-lines | command_line | containerized-apps |
containerized_app | control-graphs | control_graph |
custom_ioa | custom_ioas | detection |
detection-indices | detection_index | detections |
devices | domain | domains |
extracted-files | extracted_file | fdp-classified-files |
fdp_classified_files | firewall | firewall_rule_match |
firewall_rule_matches | firewalls | firmware |
firmwares | host-names | host_name |
idp-indicators | idp-sessions | idp_indicator |
idp_session | incident | incidents |
indicator | indicators | ipv4 |
ipv6 | k8s_cluster | k8s_clusters |
kerberos-tickets | kerberos_ticket | legacy-detections |
legacy_detection | macro_script | macro_scripts |
mcp-servers | mcp_server | mobile-apps |
mobile-fs-volumes | mobile-indicators | mobile_app |
mobile_fs_volume | mobile_indicator | mobile_os_forensics_report |
mobile_os_forensics_reports | module | modules |
okta-applications | okta-users | okta_application |
okta_user | ping-fed-applications | ping_fed_application |
process | processes | quarantined-files |
quarantined_file | script | scripts |
sensor | sensor-self-diagnostics | sensor_self_diagnostic |
shield | shields | user-sessions |
user_id | user_session | users |
vmware_cluster | vmware_clusters | web_access |
wifi-access-points | wifi_access_point | xdr |
actor | ad-computers | ad-groups |
ad_computer | ad_group | adfs-applications |
adfs_application | aggregate-indicators | aggregate_indicator |
ai-agents | ai-models | ai-prompts |
ai-sessions | ai-skills | ai-tools |
ai_agent | ai_model | ai_prompt |
ai_session | ai_skill | ai_tool |
any-vertex | azure-ad-users | azure-applications |
azure_ad_user | azure_application | certificate |
certificates | command-lines | command_line |
containerized-apps | containerized_app | control-graphs |
control_graph | custom_ioa | custom_ioas |
detection | detection-indices | detection_index |
detections | devices | domain |
domains | extracted-files | extracted_file |
firewall | firewall_rule_match | firewall_rule_matches |
firewalls | firmware | firmwares |
host-names | host_name | idp-indicators |
idp-sessions | idp_indicator | idp_session |
incident | incidents | indicator |
indicators | ipv4 | ipv6 |
k8s_cluster | k8s_clusters | kerberos-tickets |
kerberos_ticket | legacy-detections | legacy_detection |
macro_script | macro_scripts | mcp-servers |
mcp_server | mobile-apps | mobile-fs-volumes |
mobile-indicators | mobile_app | mobile_fs_volume |
mobile_indicator | mobile_os_forensics_report | mobile_os_forensics_reports |
module | modules | okta-applications |
okta-users | okta_application | okta_user |
ping-fed-applications | ping_fed_application | process |
processes | quarantined-files | quarantined_file |
script | scripts | sensor |
sensor-self-diagnostics | sensor_self_diagnostic | shield |
shields | user-sessions | user_id |
user_session | users | vmware_cluster |
vmware_clusters | web_access | wifi-access-points |
wifi_access_point | xdr | ad-computers |
indicator | ad-groups | indicators |
ad_computer | ipv4 | ad_group |
ipv6 | adfs-applications | k8s_cluster |
adfs_application | k8s_clusters | aggregate-indicators |
kerberos-tickets | aggregate_indicator | kerberos_ticket |
any-vertex | legacy-detections | azure-ad-users |
legacy_detection | azure-applications | macro_script |
azure_ad_user | macro_scripts | azure_application |
mobile-apps | certificate | mobile-fs-volumes |
certificates | mobile-indicators | command-lines |
mobile_app | command_line | mobile_fs_volume |
containerized-apps | mobile_indicator | containerized_app |
mobile_os_forensics_report | control-graphs | mobile_os_forensics_reports |
control_graph | module | customer |
modules | customers | okta-applications |
detection | okta-users | detection-indices |
okta_application | detection_index | okta_user |
detections | ping-fed-applications | devices |
ping_fed_application | direct | process |
directs | processes | domain |
quarantined-files | domains | quarantined_file |
extracted-files | script | extracted_file |
scripts | firewall | sensor |
firewall_rule_match | sensor-self-diagnostics | firewall_rule_matches |
sensor_self_diagnostic | firewalls | tag |
firmware | tags | firmwares |
user-sessions | host-names | user_id |
host_name | user_session | hunting-leads |
users | hunting_lead | wifi-access-points |
idp-indicators | wifi_access_point | idp-sessions |
xdr | idp_indicator | shield |
shields | custom_ioa | custom_ioas |
Code Examples
from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_vertices_v1(ids=id_list, scope="string", nano=boolean, vertex_type="string")print(response)from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.entities_vertices_get(ids=id_list, scope="string", nano=boolean, vertex_type="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("entities_vertices_get", vertex_type="string", ids=id_list, scope="string", nano=boolean)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/threatgraph")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
scope := "string" nano := boolean
response, err := client.Threatgraph.EntitiesVerticesGet( &threatgraph.EntitiesVerticesGetParams{ VertexType: "string", Ids: []string{"ID1", "ID2", "ID3"}, Scope: &scope, Nano: &nano, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.threatgraph.entitiesVerticesGet( "string", // vertexType ["ID1", "ID2", "ID3"], // ids "string", // scope boolean // nano);
console.log(response);use rusty_falcon::apis::threatgraph_api::entities_vertices_get;use rusty_falcon::easy::client::FalconHandle;
#[tokio::main]async fn main() { let falcon = FalconHandle::from_env().await.expect("Could not authenticate");
let response = entities_vertices_get( &falcon.cfg, // configuration "string", // vertex_type vec!["string".to_string()], // ids Some("string"), // scope Some(boolean), // nano ).await.expect("API call failed");
println!("{:?}", response);}require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::Threatgraph.new
response = api.entities_vertices_get('string', ['ID1', 'ID2', 'ID3'])
puts responseResponses
[ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}entities_vertices_getv2
Section titled “entities_vertices_getv2”Retrieve metadata for a given vertex ID
Method GET
Route /threatgraph/entities/{vertex-type}/v2
Scope Threatgraph: READ
PEP 8
get_verticesParameters
Section titled “Parameters”vertex-type path · string
Type of vertex to get properties for
Available values (114)
accessory | accessories | actor |
ad_computer | ad-computers | adfs_application |
adfs-applications | ad_group | ad-groups |
aggregate_indicator | aggregate-indicators | ai_agent |
ai-agents | sensor | devices |
ai_model | ai-models | ai_prompt |
ai-prompts | ai_session | ai-sessions |
ai_skill | ai-skills | ai_tool |
ai-tools | mobile_app | mobile-apps |
azure_application | azure-applications | azure_ad_user |
azure-ad-users | containerized_app | containerized-apps |
certificate | certificates | command_line |
command-lines | control_graph | control-graphs |
detection | detections | domain |
domains | extracted_file | extracted-files |
fdp_classified_files | fdp-classified-files | firmware |
firmwares | mobile_fs_volume | mobile-fs-volumes |
firewall | firewalls | firewall_rule_match |
firewall_rule_matches | host_name | host-names |
detection_index | detection-indices | idp_indicator |
idp-indicators | idp_session | idp-sessions |
incident | incidents | indicator |
indicators | custom_ioa | custom_ioas |
ipv4 | ipv6 | k8s_cluster |
k8s_clusters | legacy_detection | legacy-detections |
mcp_server | mcp-servers | mobile_os_forensics_report |
mobile_os_forensics_reports | mobile_indicator | mobile-indicators |
module | modules | macro_script |
macro_scripts | okta_application | okta-applications |
okta_user | okta-users | process |
processes | ping_fed_application | ping-fed-applications |
quarantined_file | quarantined-files | script |
scripts | shield | shields |
sensor_self_diagnostic | sensor-self-diagnostics | kerberos_ticket |
kerberos-tickets | user_id | users |
user_session | user-sessions | vmware_cluster |
vmware_clusters | web_access | wifi_access_point |
wifi-access-points | xdr | any-vertex |
ids query · string or list of strings
Vertex ID to get details for
scope query · string
Scope of the request
Available values (2)
device | customer |
nano query · boolean
Return nano-precision entity timestamps
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
vertex_type body · string
Type of vertex to get properties for. Allowed values:
Available values (321)
accessories | accessory | actor |
ad-computers | ad-groups | ad_computer |
ad_group | adfs-applications | adfs_application |
aggregate-indicators | aggregate_indicator | ai-agents |
ai-models | ai-prompts | ai-sessions |
ai-skills | ai-tools | ai_agent |
ai_model | ai_prompt | ai_session |
ai_skill | ai_tool | any-vertex |
azure-ad-users | azure-applications | azure_ad_user |
azure_application | certificate | certificates |
command-lines | command_line | containerized-apps |
containerized_app | control-graphs | control_graph |
custom_ioa | custom_ioas | detection |
detection-indices | detection_index | detections |
devices | domain | domains |
extracted-files | extracted_file | fdp-classified-files |
fdp_classified_files | firewall | firewall_rule_match |
firewall_rule_matches | firewalls | firmware |
firmwares | host-names | host_name |
idp-indicators | idp-sessions | idp_indicator |
idp_session | incident | incidents |
indicator | indicators | ipv4 |
ipv6 | k8s_cluster | k8s_clusters |
kerberos-tickets | kerberos_ticket | legacy-detections |
legacy_detection | macro_script | macro_scripts |
mcp-servers | mcp_server | mobile-apps |
mobile-fs-volumes | mobile-indicators | mobile_app |
mobile_fs_volume | mobile_indicator | mobile_os_forensics_report |
mobile_os_forensics_reports | module | modules |
okta-applications | okta-users | okta_application |
okta_user | ping-fed-applications | ping_fed_application |
process | processes | quarantined-files |
quarantined_file | script | scripts |
sensor | sensor-self-diagnostics | sensor_self_diagnostic |
shield | shields | user-sessions |
user_id | user_session | users |
vmware_cluster | vmware_clusters | web_access |
wifi-access-points | wifi_access_point | xdr |
actor | ad-computers | ad-groups |
ad_computer | ad_group | adfs-applications |
adfs_application | aggregate-indicators | aggregate_indicator |
ai-agents | ai-models | ai-prompts |
ai-sessions | ai-skills | ai-tools |
ai_agent | ai_model | ai_prompt |
ai_session | ai_skill | ai_tool |
any-vertex | azure-ad-users | azure-applications |
azure_ad_user | azure_application | certificate |
certificates | command-lines | command_line |
containerized-apps | containerized_app | control-graphs |
control_graph | custom_ioa | custom_ioas |
detection | detection-indices | detection_index |
detections | devices | domain |
domains | extracted-files | extracted_file |
firewall | firewall_rule_match | firewall_rule_matches |
firewalls | firmware | firmwares |
host-names | host_name | idp-indicators |
idp-sessions | idp_indicator | idp_session |
incident | incidents | indicator |
indicators | ipv4 | ipv6 |
k8s_cluster | k8s_clusters | kerberos-tickets |
kerberos_ticket | legacy-detections | legacy_detection |
macro_script | macro_scripts | mcp-servers |
mcp_server | mobile-apps | mobile-fs-volumes |
mobile-indicators | mobile_app | mobile_fs_volume |
mobile_indicator | mobile_os_forensics_report | mobile_os_forensics_reports |
module | modules | okta-applications |
okta-users | okta_application | okta_user |
ping-fed-applications | ping_fed_application | process |
processes | quarantined-files | quarantined_file |
script | scripts | sensor |
sensor-self-diagnostics | sensor_self_diagnostic | shield |
shields | user-sessions | user_id |
user_session | users | vmware_cluster |
vmware_clusters | web_access | wifi-access-points |
wifi_access_point | xdr | ad-computers |
indicator | ad-groups | indicators |
ad_computer | ipv4 | ad_group |
ipv6 | adfs-applications | k8s_cluster |
adfs_application | k8s_clusters | aggregate-indicators |
kerberos-tickets | aggregate_indicator | kerberos_ticket |
any-vertex | legacy-detections | azure-ad-users |
legacy_detection | azure-applications | macro_script |
azure_ad_user | macro_scripts | azure_application |
mobile-apps | certificate | mobile-fs-volumes |
certificates | mobile-indicators | command-lines |
mobile_app | command_line | mobile_fs_volume |
containerized-apps | mobile_indicator | containerized_app |
mobile_os_forensics_report | control-graphs | mobile_os_forensics_reports |
control_graph | module | customer |
modules | customers | okta-applications |
detection | okta-users | detection-indices |
okta_application | detection_index | okta_user |
detections | ping-fed-applications | devices |
ping_fed_application | direct | process |
directs | processes | domain |
quarantined-files | domains | quarantined_file |
extracted-files | script | extracted_file |
scripts | firewall | sensor |
firewall_rule_match | sensor-self-diagnostics | firewall_rule_matches |
sensor_self_diagnostic | firewalls | tag |
firmware | tags | firmwares |
user-sessions | host-names | user_id |
host_name | user_session | hunting-leads |
users | hunting_lead | wifi-access-points |
idp-indicators | wifi_access_point | idp-sessions |
xdr | idp_indicator | shield |
shields | custom_ioa | custom_ioas |
Code Examples
from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_vertices(ids=id_list, scope="string", nano=boolean, vertex_type="string")print(response)from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.entities_vertices_getv2(ids=id_list, scope="string", nano=boolean, vertex_type="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("entities_vertices_getv2", vertex_type="string", ids=id_list, scope="string", nano=boolean)print(response)Get-FalconThreatGraphVertex -Id @("ID1", "ID2")package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/threatgraph")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
scope := "string" nano := boolean
response, err := client.Threatgraph.EntitiesVerticesGetv2( &threatgraph.EntitiesVerticesGetv2Params{ VertexType: "string", Ids: []string{"ID1", "ID2", "ID3"}, Scope: &scope, Nano: &nano, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.threatgraph.entitiesVerticesGetv2( "string", // vertexType ["ID1", "ID2", "ID3"], // ids "string", // scope boolean // nano);
console.log(response);use rusty_falcon::apis::threatgraph_api::entities_vertices_getv2;use rusty_falcon::easy::client::FalconHandle;
#[tokio::main]async fn main() { let falcon = FalconHandle::from_env().await.expect("Could not authenticate");
let response = entities_vertices_getv2( &falcon.cfg, // configuration "string", // vertex_type vec!["string".to_string()], // ids Some("string"), // scope Some(boolean), // nano ).await.expect("API call failed");
println!("{:?}", response);}require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::Threatgraph.new
response = api.entities_vertices_getv2('string', ['ID1', 'ID2', 'ID3'])
puts responseResponses
[ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "next_page": "string", "offset": "string" }, "powered_by": "string", "query_time": 0.0, "trace_id": "string" }, "resources": [ { "customer_id": "string", "device_id": "string", "id": "string", "object_id": "string", "properties": {}, "scope": "string", "timestamp": "string", "vertex_type": "string" } ]}queries_edgetypes_get
Section titled “queries_edgetypes_get”Show all available edge types
Method GET
Route /threatgraph/queries/edge-types/v1
Scope Threatgraph: READ
PEP 8
get_edge_typesCode Examples
from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.get_edge_types()print(response)from falconpy import ThreatGraph
falcon = ThreatGraph(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.queries_edgetypes_get()print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("queries_edgetypes_get")print(response)Get-FalconThreatGraphEdgepackage main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/threatgraph")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.Threatgraph.QueriesEdgetypesGet( &threatgraph.QueriesEdgetypesGetParams{ Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: process.env.FALCON_CLOUD!, clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.threatgraph.queriesEdgetypesGet();
console.log(response);use rusty_falcon::apis::threatgraph_api::queries_edgetypes_get;use rusty_falcon::easy::client::FalconHandle;
#[tokio::main]async fn main() { let falcon = FalconHandle::from_env().await.expect("Could not authenticate");
let response = queries_edgetypes_get(&falcon.cfg).await.expect("API call failed"); // configuration
println!("{:?}", response);}require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::Threatgraph.new
response = api.queries_edgetypes_get
puts responseResponses
{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}