Skip to content

Operations by Collection

An operation is a request against a specific endpoint within the CrowdStrike API. Each operation combines an HTTP method with an API endpoint and has a unique Operation ID. No two operations share the same method/endpoint combination.

Every operation within every service collection has a unique, case-sensitive string identifier. Operation IDs are used throughout the CrowdStrike SDKs to reference specific API calls — as method names, function parameters, and endpoint identifiers across all supported languages. They also serve as the primary way to locate operation details within this documentation.

The tables below list all available operations grouped by their service collection. Each Operation ID links to the full operation details including parameters, request body schema, and code examples.

Operation IDDescription
ListAccessScopesExternalList Access Scopes By ID
QueryAccessScopesExternalQuery Access Scopes and returns IDs
Operation IDDescription
admission-control-add-host-groupsAdd one or more host groups to an admission control policy.
admission-control-add-rule-group-custom-ruleAdd one or more custom Rego rules to a rule group in an admission control policy.
admission-control-create-policyCreate an admission control policy.
admission-control-create-rule-groupsCreate one or more rule groups and add them to an existing admission control policy.
admission-control-delete-policiesDelete an admission control policy.
admission-control-delete-rule-groupsDelete rule groups.
admission-control-get-policiesGet admission control policies.
admission-control-query-policiesSearch admission control policies.
admission-control-remove-host-groupsRemove one or more host groups from an admission control policy.
admission-control-remove-rule-group-custom-ruleDelete one or more custom Rego rules from all rule groups in an admission control policy.
admission-control-replace-rule-group-selectorsReplace labels and/or namespaces of a rule group within an admission control policy.
admission-control-set-rule-group-precedenceChange precedence of rule groups within an admission control policy.
admission-control-update-policyUpdate an admission control policy.
admission-control-update-policy-precedenceUpdate admission control policy precedence.
admission-control-update-rule-groupsUpdate a rule group.
Operation IDDescription
EntitiesAgentTemplatesV1Retrieve agent template entities for the provided IDs
QueriesAgentTemplatesV1Query agent template IDs with pagination
Operation IDDescription
GetAgentVersionsV1Retrieve agent version entities for the provided ids.
QueryAgentVersionsV1Query agent versions based on the provided filters.
Operation IDDescription
GetQueriesAlertsV1Deprecated: please use version v2 of this endpoint.
GetQueriesAlertsV2Retrieves all Alerts ids that match a given query.
PatchEntitiesAlertsV1Perform actions on detections identified by detection ID(s) in request.
PatchEntitiesAlertsV2Deprecated: Please use version v3 of this endpoint.
PatchEntitiesAlertsV3Perform actions on Alerts identified by composite ID(s) in request.
PostAggregatesAlertsV1Deprecated: Please use version v2 of this endpoint.
PostAggregatesAlertsV2Retrieves aggregate values for Alerts across all CIDs.
PostCombinedAlertsV1Retrieves all Alerts that match a particular FQL filter.
PostEntitiesAlertsV1Deprecated: please use version v2 of this endpoint.
PostEntitiesAlertsV2Retrieves all Alerts given their composite ids.
Operation IDDescription
CreateAPIClientCreate new API Client.
DeleteAPIClientsDelete existing API Client(s) based on API Client ID(s) provided as request parameter(s) ‘ids’.
GetAccessibleScopesGet all available scopes for customer.
GetAllAPIClientIdsForCustomerGet All API client ID(s) for customer.
GetAPIClientsGet API Client(s) based on API Client ID(s) provided as request parameter(s) ‘ids’.
ResetAPIClientSecretReset existing API Client(s)‘s secret based on API Client ID(s) provided as request parameter(s) ‘ids’.
UpdateAPIClientUpdate existing API Client based on API Client ID provided as request parameter ‘ids’.
Operation IDDescription
ExecuteCommandExecute a command.
ExecuteCommandProxyExecute a command and proxy the response directly.
GetCombinedPluginConfigsQueries for config resources and returns details
Operation IDDescription
CreateExecutorNodeCreate a new relay node
CreateIntegrationCreate a new integration
CreateIntegrationTaskCreate new integration task.
DeleteExecutorNodeDelete a relay node
DeleteGroup
DeleteIntegrationDelete an existing integration by its ID
DeleteIntegrationTaskDelete an existing integration task by its ID
DeleteTagsRemove existing tags
ExecuteFunctionDataA selected list of queryLanguage queries. request & response are in MSA format
ExecuteFunctionDataCountA selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionDataQueryA selected list of queryLanguage queries. request & response are in MSA format
ExecuteFunctionDataQueryCountA selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionsA selected list of queryLanguage services queries. request & response are in MSA format
ExecuteFunctionsCountA selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionsOvertimeA selected list of queryLanguage overtime queries. request & response are in MSA format
ExecuteFunctionsQueryA selected list of queryLanguage services queries. request & response are in MSA format
ExecuteFunctionsQueryCountA selected list of queryLanguage count queries. request & response are in MSA format
ExecuteFunctionsQueryOvertimeA selected list of queryLanguage overtime queries. request & response are in MSA format
ExecuteQueryExecute a query.
GetCloudSecurityIntegrationStateGet Cloud Security integration state
GetExecutorNodesGet all the relay nodes
GetExecutorNodesMetadataGet metadata about all executor nodes
GetGroupHierarchyGet group hierarchy
GetGroupsV2
GetGroupV2Get group details
GetIntegrationsGet a list of all the integrations
GetIntegrationsV2Get a list of all the integrations
GetIntegrationTasksGet all the integration tasks
GetIntegrationTasksAdminGet all the integration tasks, requires admin scope
GetIntegrationTasksMetadataGet metadata about all integration tasks
GetIntegrationTasksV2Get all the integration tasks
GetIntegrationTypesGet all the integration types
getServiceArtifacts
GetServicesCountGet the total amount of existing services
GetServiceViolationTypesGet the different types of violation
GetTagsGet all the tags
GetUsersV2List users
PostGroupV2Create group
RetrieveRelayInstancesRetrieve the relay instances in CSV format
RunIntegrationTaskRun an integration task by its ID
RunIntegrationTaskAdminRun an integration task by its ID - for admin scope
RunIntegrationTaskV2Run an integration task by its ID
ServiceNowGetDeployments
ServiceNowGetServices
SetCloudSecurityIntegrationStateSet Cloud Security integration state
UpdateDefaultGroupUpdate default group
UpdateExecutorNodeUpdate an existing relay node
UpdateGroupUpdate group
UpdateIntegrationUpdate an existing integration by its ID
UpdateIntegrationTaskUpdate an existing integration task by its ID
UpsertBusinessApplicationsCreate or Update Business Applications
UpsertTagsCreate new or update existing tag.
Operation IDDescription
AggregateHuntingGuidesAggregate Hunting Guides
AggregateIntelligenceQueriesAggregate intelligence queries
GetArchiveExportCreates an Archive Export
GetHuntingGuidesRetrieves a list of Hunting Guides
GetIntelligenceQueriesRetrieves the details of a list of Intelligence queries IDs
SearchHuntingGuidesSearch for Hunting Guides that match the provided conditions
SearchIntelligenceQueriesSearch for a list of intelligence queries IDs that match the provided conditions
Operation IDDescription
aggregates.access-tags.post.v1Get access tag aggregates
aggregates.file-details.post.v1Get file details aggregates as specified via json in the request body.
aggregates.notification-groups.post.v1Get notification groups aggregations
aggregates.notification-groups.post.v2Get notification groups aggregations
aggregates.slas.post.v1Get SLA aggregations
aggregates.templates.post.v1Get templates aggregations
combined.file-details.get.v1Query file details
entities.access-tags.get.v1Get access tags
entities.alert-evidence.post.v1Adds the given list of alert evidence to the specified case.
entities.case-tags.delete.v1Removes the specified tags from the specified case.
entities.case-tags.post.v1Adds the given list of tags to the specified case.
entities.cases.patch.v2Updates given fields on the specified case.
entities.cases.post.v2Retrieves all Cases given their IDs.
entities.cases.put.v2Creates the given Case
entities.event-evidence.post.v1Adds the given list of event evidence to the specified case.
entities.fields.get.v1Get fields by ID
entities.file-details.get.v1Get file details by id
entities.file-details.patch.v1Update file details
entities.files.delete.v1Delete file details by id
entities.files_bulk-download.post.v1Download multiple existing file from case as a ZIP
entities.files_download.get.v1Download existing file from case
entities.files_download.post.v1Download existing files from case
entities.files_upload.post.v1Upload file for case
entities.get-rtr-file-metadata.post.v1gets metadata for a file via RTR without retrieving it
entities.merge.post.v1Merges a source case into a destination case.
entities.notification-groups.delete.v1Delete notification groups by ID
entities.notification-groups.delete.v2Delete notification groups by ID
entities.notification-groups.get.v1Get notification groups by ID
entities.notification-groups.get.v2Get notification groups by ID
entities.notification-groups.patch.v1Update notification group
entities.notification-groups.patch.v2Update notification group
entities.notification-groups.post.v1Create notification group
entities.notification-groups.post.v2Create notification group
entities.retrieve-rtr-file.post.v1retrieves a file from host using RTR and adds it to a case
entities.retrieve-rtr-recent-file.post.v1RetrieveRecentRTRFile retrieves a recently fetched RTR file and adds it to a case
entities.slas.delete.v1Delete SLAs
entities.slas.get.v1Get SLAs by ID
entities.slas.patch.v1Update SLA
entities.slas.post.v1Create SLA
entities.template-snapshots.get.v1Get template snapshots
entities.templates.delete.v1Delete templates
entities.templates.get.v1Get templates by ID
entities.templates.patch.v1Update template
entities.templates.post.v1Create template
entities.templates_export.get.v1Export templates to files in a zip archive
entities.templates_import.post.v1Import a template from a file
queries.access-tags.get.v1Query access tags
queries.cases.get.v1Retrieves all Cases IDs that match a given query.
queries.fields.get.v1Query fields
queries.file-details.get.v1Query for ids of file details
queries.notification-groups.get.v1Query notification groups
queries.notification-groups.get.v2Query notification groups
queries.slas.get.v1Query SLAs
queries.template-snapshots.get.v1Query template snapshots
queries.templates.get.v1Query templates
Operation IDDescription
cb-exclusions.create.v1Create new Certificate Based Exclusions.
cb-exclusions.delete.v1Delete the exclusions by id
cb-exclusions.get.v1Find all exclusion IDs matching the query with filter
cb-exclusions.query.v1Search for cert-based exclusions.
cb-exclusions.update.v1Updates existing Certificate Based Exclusions
certificates.get.v1Retrieves certificate signing information for a file
Operation IDDescription
cloud-registration-aws-create-accountCreates a new account in our system for a customer.
cloud-registration-aws-delete-accountDeletes an existing AWS account or organization in our system.
cloud-registration-aws-get-accountsRetrieve existing AWS accounts by account IDs or organization IDs
cloud-registration-aws-query-accountsRetrieve existing AWS accounts by account IDs
cloud-registration-aws-trigger-health-checkTrigger health check scan for AWS accounts
cloud-registration-aws-update-accountPatches a existing account in our system for a customer.
cloud-registration-aws-validate-accountsValidates the AWS account registration status, and discover organization child accounts if organization is specified
Operation IDDescription
cloud-registration-azure-create-registrationCreate an Azure registration for a tenant.
cloud-registration-azure-create-suppressionsCreate new issue suppression rules
cloud-registration-azure-delete-legacy-subscriptionDelete existing legacy Azure subscriptions.
cloud-registration-azure-delete-registrationDeletes existing Azure registrations.
cloud-registration-azure-delete-suppressionsRemove/revoke suppression rules
cloud-registration-azure-download-scriptRetrieve script to create resources
cloud-registration-azure-get-issue-suppression-values-by-fieldRetrieve distinct filterable values for issue suppression fields
cloud-registration-azure-get-issue-values-by-fieldRetrieve distinct filterable values for issue fields
cloud-registration-azure-get-issuesRetrieve issues for Azure registrations
cloud-registration-azure-get-registrationRetrieve existing Azure registration for a tenant.
cloud-registration-azure-get-scriptDownload Azure deployment script (Terraform or Bicep)
cloud-registration-azure-get-script-versionsRetrieve all available script versions with filtering and sorting
cloud-registration-azure-get-suppressionsRetrieve existing suppression rules with filtering
cloud-registration-azure-trigger-health-checkTrigger health check scan for Azure registrations
cloud-registration-azure-update-registrationUpdate an existing Azure registration for a tenant.
cloud-registration-azure-update-suppressionsUpdate existing suppression rules
cloud-registration-azure-validate-registrationValidate an Azure registration by checking service principal, role assignments and deployment stack (if the deployment method is Bicep)
Operation IDDescription
CreateOrUpdateAWSSettingsCreate or update Global Settings which are applicable to all provisioned AWS accounts
DeleteAWSAccountsDelete a set of AWS Accounts by specifying their IDs
GetAWSAccountsRetrieve a set of AWS Accounts by specifying their IDs
GetAWSSettingsRetrieve a set of Global Settings which are applicable to all provisioned AWS accounts
ProvisionAWSAccountsProvision AWS Accounts by specifying details about the accounts to provision
QueryAWSAccountsSearch for provisioned AWS Accounts by providing an FQL filter and paging details.
QueryAWSAccountsForIDsSearch for provisioned AWS Accounts by providing an FQL filter and paging details.
UpdateAWSAccountsUpdate AWS Accounts by specifying the ID of the account and details to update
VerifyAWSAccountAccessPerforms an Access Verification check on the specified AWS Account IDs
Operation IDDescription
cloud-registration-gcp-create-registrationCreate a Google Cloud Registration.
cloud-registration-gcp-delete-registrationDeletes a Google Cloud Registration and returns the deleted registration in the response body.
cloud-registration-gcp-get-entitiesRetrieve all GCP entities (organizations, folders, projects) grouped by type with support for FQL filtering, sorting, and pagination.
cloud-registration-gcp-get-registrationRetrieve a Google Cloud Registration.
cloud-registration-gcp-post-terraform-scriptGenerate Google Cloud Terraform deployment scripts (zip files)
cloud-registration-gcp-put-registrationCreates/Updates a Google Cloud Registration.
cloud-registration-gcp-trigger-health-checkTrigger health check scan for GCP registrations
cloud-registration-gcp-update-registrationUpdate a Google Cloud Registration.
Operation IDDescription
cloud-security-registration-oci-create-accountCreate OCI tenancy account in CSPM
cloud-security-registration-oci-delete-accountDelete an existing OCI tenancy in CSPM.
cloud-security-registration-oci-download-scriptRetrieve script to create resources in tenancy OCID
cloud-security-registration-oci-get-accountRetrieve a list of OCI tenancies with support for FQL filtering, sorting, and pagination
cloud-security-registration-oci-rotate-keyRefresh key for the OCI Tenancy
cloud-security-registration-oci-update-accountPatch an existing OCI account in our system for a customer.
cloud-security-registration-oci-validate-tenancyValidate the OCI account in CSPM for a provided CID.
Operation IDDescription
CloneComplianceFrameworkClone an existing compliance framework to create a custom copy
CreateComplianceControlCreate a new custom compliance control
CreateComplianceFrameworkCreate a new custom compliance framework
CreateRuleMixin0Create a new rule
CreateRuleOverrideCreate a new rule override
CreateSuppressionRuleCreate a new suppression rule
DeleteComplianceControlDelete custom compliance controls
DeleteComplianceFrameworkDelete a custom compliance framework and all associated controls and rule assignments
DeleteRuleMixin0Delete a rule
DeleteRuleOverrideDelete a rule override
DeleteSuppressionRulesDelete Suppression Rules by ID
GetComplianceControlsGet compliance controls by ID
GetComplianceFrameworksGet compliance frameworks by ID
GetEnrichedAssetGets enriched assets that combine a primary resource with all its related resources
GetEvaluationResultGets evaluation results based on the provided rule
GetRuleGet a rule by id
GetRuleInputSchemaGet rule input schema for given resource type
GetRuleOverrideGet a rule override
GetSuppressionRulesGet Suppression Rules by ID
QueryComplianceControlsQuery for compliance controls by various parameters
QueryComplianceFrameworksQuery for compliance frameworks by various parameters
QueryRuleQuery for rules by various parameters
QuerySuppressionRulesQuery suppression rules with filtering, sorting and pagination
RenameSectionComplianceFrameworkRename a section in a custom compliance framework
ReplaceControlRulesAssign rules to a compliance control (full replace)
UpdateComplianceControlUpdate a custom compliance control
UpdateComplianceFrameworkUpdate a custom compliance framework
UpdateRuleUpdate a rule
UpdateRuleOverrideUpdate a rule override
UpdateSuppressionRuleUpdate a suppression rule
Operation IDDescription
combined-cloud-risksGets cloud risks with full details based on filters and sort criteria
CreateCloudGroupExternalCreate a Cloud Group.
DeleteCloudGroupsExternalDelete Cloud Groups in batch
ListCloudGroupIDsExternalQuery Cloud Groups and returns IDs
ListCloudGroupsByIDExternalList Cloud Groups By ID
ListCloudGroupsExternalQuery Cloud Groups and returns entities
UpdateCloudGroupExternalUpdate Cloud Group
Operation IDDescription
cloud-security-assets-combined-application-findingsGet findings for an application resource with pagination
cloud-security-assets-combined-compliance-by-accountGets combined compliance data aggregated by account and region.
cloud-security-assets-entities-getGets raw resources based on the provided IDs param.
cloud-security-assets-entities-postGets raw resources based on IDs in the request body.
cloud-security-assets-queriesGets a list of resource IDs for the given parameters, filters and sort criteria
Operation IDDescription
cloud-compliance-framework-posture-summariesGet sections and requirements with scores for benchmarks.
cloud-compliance-rule-posture-summariesGet compliance score and counts for rules.
Operation IDDescription
cspm-evaluations-combined-iom-by-rulereturns ioms grouped by rule
cspm-evaluations-iom-entitiesGets IOMs based on the provided IDs
cspm-evaluations-iom-entities-postGets IOMs based on IDs in the request body.
cspm-evaluations-iom-queriesGets a list of IOM IDs for the given parameters, filters and sort criteria.
Operation IDDescription
cloud-registration-cross-provider-get-account-aggregatesReturns cross-provider account aggregates by status
Operation IDDescription
cloud-security-timeline-risks-enrichedReturns the enriched asset timeline.
Operation IDDescription
CombinedDetectionsSearch IaC Detections using a query in Falcon Query Language
CreateDeploymentEntityLaunch a snapshot scan for a given cloud asset
GetCredentialsIACGets the registry credentials (external endpoint)
GetCredentialsMixin0Gets the registry credentials
GetScanReportretrieve the scan report for an instance
ReadDeploymentsCombinedRetrieve snapshot jobs identified by the provided IDs
ReadDeploymentsEntitiesRetrieve snapshot jobs identified by the provided IDs
RegisterCspmSnapshotAccountRegister customer cloud account for snapshot scanning
Operation IDDescription
getCombinedAssessmentsQuerySearch for assessments in your environment by providing an FQL filter and paging details.
getRuleDetailsGet rules details for provided one or more rule IDs
Operation IDDescription
getEvaluationLogicMixin0Get details on evaluation logic items by providing one or more finding IDs.
Operation IDDescription
ReadContainerAlertsCountSearch Container Alerts by the provided search criteria
ReadContainerAlertsCountBySeverityGet Container Alerts counts by severity
SearchAndReadContainerAlertsSearch Container Alerts by the provided search criteria
Operation IDDescription
GetRuntimeDetectionsCombinedV2Retrieve container runtime detections by the provided search criteria
ReadCombinedDetectionsRetrieve image assessment detections identified by the provided filter criteria
ReadDetectionsRetrieve image assessment detection entities identified by the provided filter criteria
ReadDetectionsCountAggregate count of detections
ReadDetectionsCountBySeverityAggregate counts of detections by severity
ReadDetectionsCountByTypeAggregate counts of detections by detection type
SearchDetectionsRetrieve image assessment detection entities identified by the provided filter criteria
Operation IDDescription
extAggregateClusterAssessmentsget the assessments for each cluster
extAggregateFailedContainersByRulesPathget the containers grouped into rules on which they failed
extAggregateFailedContainersCountBySeverityget the failed containers count grouped into severity levels
extAggregateFailedImagesByRulesPathget the images grouped into rules on which they failed
extAggregateFailedImagesCountBySeverityget the failed images count grouped into severity levels
extAggregateFailedRulesByClustersget the failed rules for each cluster grouped into severity levels
extAggregateFailedRulesByImagesget images with failed rules, rule count grouped by severity for each image
extAggregateFailedRulesCountBySeverityget the failed rules count grouped into severity levels
extAggregateImageAssessmentsget the assessments for each image
extAggregateRulesAssessmentsget the assessments for each rule
extAggregateRulesByStatusget the rules grouped by their statuses
Operation IDDescription
AggregateImageAssessmentHistoryImage assessment history
AggregateImageCountAggregate count of images
AggregateImageCountByBaseOSAggregate count of images grouped by Base OS distribution
AggregateImageCountByStateAggregate count of images grouped by state
CombinedBaseImagesRetrieves a list of base images for the provided filter.
CombinedImageByVulnerabilityCountRetrieve top x images with the most vulnerabilities
CombinedImageDetailRetrieve image entities identified by the provided filter criteria
CombinedImageIssuesSummaryRetrieve image issues summary such as Image detections, Runtime detections, Policies, vulnerabilities
CombinedImageVulnerabilitySummaryaggregates information about vulnerabilities for an image
CreateBaseImagesEntitiesCreates base images using the provided details
DeleteBaseImagesDelete base images by base image uuid
GetCombinedImagesGet image assessment results by providing an FQL filter and paging details
ReadCombinedImagesExportRetrieves a paginated list of images, with an option to expand aggregated vulnerabilities/detections.
Operation IDDescription
ReadPackagesByFixableVulnCountRetrieve top x app packages with the most fixable vulnerabilities
ReadPackagesByImageCountRetrieves the N most frequently used packages across images
ReadPackagesByVulnCountRetrieve top x packages with the most vulnerabilities
ReadPackagesCombinedRetrieve packages identified by the provided filter criteria
ReadPackagesCombinedExportRetrieves a paginated list of packages identified by the provided filter criteria,used for export.Maximum page size: 100.
ReadPackagesCombinedV2Retrieve packages identified by the provided filter criteria
ReadPackagesCountByZeroDayRetrieve packages count affected by zero day vulnerabilities
Operation IDDescription
ReadCombinedVulnerabilitiesRetrieves a paginated list of vulnerabilities filtered by the provided FQL.
ReadCombinedVulnerabilitiesDetailsRetrieve vulnerability details related to an image
ReadCombinedVulnerabilitiesInfoRetrieve vulnerability and package related info for this customer
ReadVulnerabilitiesByImageCountRetrieve top x vulnerabilities with the most impacted images
ReadVulnerabilitiesPublicationDateRetrieve top x vulnerabilities with the most recent publication date
ReadVulnerabilityCountAggregate count of vulnerabilities
ReadVulnerabilityCountByActivelyExploitedAggregate count of vulnerabilities grouped by actively exploited
ReadVulnerabilityCountByCPSRatingAggregate count of vulnerabilities grouped by csp_rating
ReadVulnerabilityCountByCVSSScoreAggregate count of vulnerabilities grouped by CVSS score
ReadVulnerabilityCountBySeverityAggregate count of vulnerabilities grouped by severity
Operation IDDescription
createContentUpdatePoliciesCreate Content Update Policies by specifying details about the policy to create
deleteContentUpdatePoliciesDelete a set of Content Update Policies by specifying their IDs
getContentUpdatePoliciesRetrieve a set of Content Update Policies by specifying their IDs
performContentUpdatePoliciesActionPerform the specified action on the Content Update Policies specified in the request
queryCombinedContentUpdatePoliciesSearch for Content Update Policies in your environment by providing an FQL filter and paging details.
queryCombinedContentUpdatePolicyMembersSearch for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
queryContentUpdatePoliciesSearch for Content Update Policies in your environment by providing an FQL filter and paging details.
queryContentUpdatePolicyMembersSearch for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
queryPinnableContentVersionsSearch for content versions available for pinning given the category.
setContentUpdatePoliciesPrecedenceSets the precedence of Content Update Policies based on the order of IDs specified in the request.
updateContentUpdatePoliciesUpdate Content Update Policies by specifying the ID of the policy and details to update
Operation IDDescription
aggregates.rule-versions.post.v1Get rules aggregates as specified via json in the request body.
combined.rules.get.v1Find all rules matching the query and filter.
combined.rules.get.v2Find all rules matching the query and filter.
entities.latest-rules.get.v1Retrieve latest rule versions by rule IDs
entities.rule-versions.delete.v1Delete versions by IDs
entities.rule-versions_export.post.v1Export rule versions
entities.rule-versions_import.post.v1Import rule versions
entities.rule-versions_publish.patch.v1Publish existing rule version
entities.rules.delete.v1Delete rules by IDs
entities.rules.get.v1Retrieve rules by IDs
entities.rules.get.v2Retrieve rule versions by IDs
entities.rules.patch.v1Update rules
entities.rules.post.v1Create rule
entities.templates.get.v1Mixin0Retrieve rule templates by IDs
entities.templates_rules.post.v1Create rule from template
queries.rules.get.v1Find all rule IDs matching the query and filter.
queries.rules.get.v2Find all rule version IDs matching the query and filter.
queries.templates.get.v1Mixin0Search rule template IDs matching the filter.
Operation IDDescription
entities.rules_ownership.put.v1Change the owner of an existing Correlation Rule
entities.rules_ownership.put.v2Bulk change the owner of existing Correlation Rules
Operation IDDescription
AzureRefreshCertificateRefresh certificate and returns JSON object(s) that contain the base64 encoded certificate for a service principal.
ConnectCSPMGCPAccountCreates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id
CreateCSPMAwsAccountCreates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
CreateCSPMAzureAccountCreates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
CreateCSPMAzureManagementGroupCreates a new management group in our system for a customer.
CreateCSPMGCPAccountCreates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
DeleteCSPMAwsAccountDeletes an existing AWS account or organization in our system.
DeleteCSPMAzureAccountDeletes an Azure subscription from the system.
DeleteCSPMAzureManagementGroupDeletes Azure management groups from the system.
DeleteCSPMGCPAccountDeletes a GCP account from the system.
DiscoverCloudAzureDownloadCertificateReturns JSON object(s) that contain the base64 encoded certificate for a service principal.
GetBehaviorDetectionsGet list of detected behaviors
getCloudEventIDsDeprecated: use cdrapi entities/event-details/v1 ‘logscale_related_events_query’ instead.
GetConfigurationDetectionEntitiesGet misconfigurations based on the ID - including custom policy detections in addition to default policy detections.
GetConfigurationDetectionIDsV2Get list of active misconfiguration ids - including custom policy detections in addition to default policy detections.
GetConfigurationDetectionsGet list of active misconfigurations.
GetCSPMAwsAccountReturns information about the current status of an AWS account.
GetCSPMAwsAccountScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetCSPMAwsConsoleSetupURLsReturn a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetCSPMAzureAccountReturn information about Azure account registration
GetCSPMAzureManagementGroupReturn information about Azure management group registration
GetCSPMAzureUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment
GetCSPMGCPAccountReturns information about the current status of an GCP account.
GetCSPMGCPServiceAccountsExtReturns the service account id and client email for external clients.
GetCSPMGCPUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment
GetCSPMGCPValidateAccountsExtRun a synchronous health check.
GetCSPMPoliciesDetailsGiven an array of policy IDs, returns detailed policies information.
GetCSPMPolicyGiven a policy ID, returns detailed policy information.
GetCSPMPolicySettingsReturns information about current policy settings.
GetCSPMScanScheduleReturns scan schedule configuration for one or more cloud platforms.
GetIOAEventsFor CSPM IOA events, gets list of IOA events.
GetIOAUsersFor CSPM IOA users, gets list of IOA users.
PatchCSPMAwsAccountPatches a existing account in our system for a customer.
UpdateCSPMAzureAccountPatches a existing account in our system for a customer.
UpdateCSPMAzureAccountClientIDUpdate an Azure service account in our system by with the user-created client_id created with the public key we’ve provided
UpdateCSPMAzureTenantDefaultSubscriptionIDUpdate an Azure default subscription_id in our system for given tenant_id
UpdateCSPMGCPAccountPatches a existing account in our system for a customer.
UpdateCSPMGCPServiceAccountsExtPatches the service account key for external clients.
UpdateCSPMPolicySettingsUpdates a policy setting - can be used to override policy severity or to disable a policy entirely.
UpdateCSPMScanScheduleUpdates scan schedule configuration for one or more cloud platforms.
ValidateCSPMGCPServiceAccountExtValidates credentials for a service account
Operation IDDescription
create-ruleCreate a rule within a rule group.
create-rule-groupMixin0Create a rule group for a platform with a name and an optional description.
delete-rule-groupsMixin0Delete rule groups by ID.
delete-rulesDelete rules from a rule group by ID.
get-patternsGet pattern severities by ID.
get-platformsMixin0Get platforms by ID.
get-rule-groupsMixin0Get rule groups by ID.
get-rule-typesGet rule types by ID.
get-rules-getGet rules by ID and optionally with cid and/or version in the following format: [cid:]ID[:version].
get-rulesMixin0Get rules by ID and optionally with cid and/or version in the following format: [cid:]ID[:version].
query-patternsGet all pattern severity IDs.
query-platformsMixin0Get all platform IDs.
query-rule-groups-fullFind all rule groups matching the query with optional filter.
query-rule-groupsMixin0Finds all rule group IDs matching the query with optional filter.
query-rule-typesGet all rule type IDs.
query-rulesMixin0Finds all rule IDs matching the query with optional filter.
update-rule-groupMixin0Update a rule group.
update-rulesUpdate rules within a rule group.
update-rules-v2Update name, description, enabled or field_values for individual rules within a rule group.
validateValidates field values and checks for matches if a test string is provided.
Operation IDDescription
DeleteObjectDelete the specified object
DeleteVersionedObjectDelete the specified versioned object
DescribeCollectionFetch metadata about an existing collection
DescribeCollectionsFetch metadata about one or more existing collections
GetObjectGet the bytes for the specified object
GetObjectMetadataGet the metadata for the specified object
GetSchemaGet the bytes of the specified schema of the requested collection
GetSchemaMetadataGet the metadata for the specified schema of the requested collection
GetVersionedObjectGet the bytes for the specified object
GetVersionedObjectMetadataGet the metadata for the specified object
ListCollectionsList available collection names in alphabetical order
ListObjectsList the object keys in the specified collection in alphabetical order
ListObjectsByVersionList the object keys in the specified collection in alphabetical order
ListSchemasGet the list of schemas for the requested collection in reverse version order (latest first)
PutObjectPut the specified new object at the given key or overwrite an existing object at the given key
PutObjectByVersionPut the specified new object at the given key or overwrite an existing object at the given key
SearchObjectsSearch for objects that match the specified filter criteria (returns metadata, not actual objects)
SearchObjectsByVersionSearch for objects that match the specified filter criteria (returns metadata, not actual objects)
Operation IDDescription
ConnectD4CGCPAccountCreates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id
CreateD4CAwsAccountCreates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
CreateD4CGCPAccountCreates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
CreateDiscoverCloudAzureAccountCreates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
DeleteD4CAwsAccountDeletes an existing AWS account or organization in our system.
DeleteD4CGCPAccountDeletes a GCP account from the system.
GetD4CAwsAccountReturns information about the current status of an AWS account.
GetD4CAWSAccountScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetD4CAwsConsoleSetupURLsReturn a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetD4CCGPAccountReturns information about the current status of an GCP account.
GetD4CGCPServiceAccountsExtReturns the service account id and client email for external clients.
GetD4CGCPUserScriptsReturn a script for customer to run in their cloud environment to grant us access to their GCP environment
GetD4CGCPUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment
GetDiscoverCloudAzureAccountReturn information about Azure account registration
GetDiscoverCloudAzureTenantIDsReturn available tenant ids for discover for cloud
GetDiscoverCloudAzureUserScriptsReturn a script for customer to run in their cloud environment to grant us access to their Azure environment
GetDiscoverCloudAzureUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment
GetHorizonD4CScriptsReturns static install scripts for Horizon.
UpdateD4CGCPServiceAccountsExtPatches the service account key for external clients.
UpdateDiscoverCloudAzureAccountClientIDUpdate an Azure service account in our system by with the user-created client_id created with the public key we’ve provided
Operation IDDescription
entities.classification.delete.v2Deletes classifications that match the provided ids
entities.classification.get.v2Gets the classifications that match the provided ids
entities.classification.patch.v2Update classifications
entities.classification.post.v2Create classifications
entities.cloud-application.createPersist the given cloud application for the provided entity instance
entities.cloud-application.deleteDelete cloud application
entities.cloud-application.getGet a particular cloud-application
entities.cloud-application.patchUpdate a cloud application
entities.content-pattern.createPersist the given content pattern for the provided entity instance
entities.content-pattern.deleteDelete content pattern
entities.content-pattern.getGet a particular content-pattern(s)
entities.content-pattern.patchUpdate a content pattern
entities.enterprise-account.createPersist the given enterprise account for the provided entity instance
entities.enterprise-account.deleteDelete enterprise account
entities.enterprise-account.getGet a particular enterprise-account(s)
entities.enterprise-account.patchUpdate a enterprise account
entities.file-type.getGet a particular file-type
entities.local-application-group.createPersist the given local application group for the provided entity instance
entities.local-application-group.deleteSoft Delete local application.
entities.local-application-group.getGet specific local application groups
entities.local-application-group.patchUpdate a local application group
entities.local-application.createPersist the given local application for the provided entity instance
entities.local-application.deleteSoft Delete local application.
entities.local-application.getGet a particular local application
entities.local-application.patchUpdate a local application
entities.policy.delete.v2Deletes policies that match the provided ids
entities.policy.get.v2Gets policies that match the provided ids
entities.policy.patch.v2Update policies
entities.policy.post.v2Create policies
entities.policy.precedence.post.v1Update Policy Precedence
entities.sensitivity-label.create-v2Create new sensitivity label (V2)
entities.sensitivity-label.delete-v2Delete sensitivity labels matching the IDs (V2)
entities.sensitivity-label.get-v2Get sensitivity label matching the IDs (V2)
entities.web-location-group.createCreate a web location group
entities.web-location-group.deleteSoft delete web location groups
entities.web-location-group.getGet specific web location groups
entities.web-location-group.patchUpdate a web location group
entities.web-location.create-v2Persist the given web-locations
entities.web-location.delete-v2Delete web-location
entities.web-location.get-v2Get web-location entities matching the provided ID(s)
entities.web-location.patch-v2Update a web-location
queries.classification.get.v2Search for classifications that match the provided criteria
queries.cloud-application.get-v2Get all cloud-application IDs matching the query with filter
queries.content-pattern.get-v2Get all content-pattern IDs matching the query with filter
queries.enterprise-account.get-v2Get all enterprise-account IDs matching the query with filter
queries.file-type.get-v2Get all file-type IDs matching the query with filter
queries.local-application-group.getGet all local application group IDs matching the query with filter
queries.local-application.getGet all local-application IDs matching the query with filter
queries.policy.get.v2Search for policies that match the provided criteria
queries.sensitivity-label.get-v2Get all sensitivity label IDs matching the query with filter
queries.web-location-group.getGet all web location group IDs matching the query with filter
queries.web-location.get-v2Get web-location IDs matching the query with filter
Operation IDDescription
GetDeliverySettingsGet Delivery Settings
PostDeliverySettingsCreate Delivery Settings
Operation IDDescription
CombinedReleaseNotesV1Queries for release-notes resources and returns details
CombinedReleasesV1Mixin0Queries for releases resources and returns details
GetDeploymentsExternalV1Get deployment resources by ids
GetEntityIDsByQueryPOSTreturns the release notes for the IDs in the request
GetEntityIDsByQueryPOSTV2returns the release notes for the IDs in the request with EA and GA dates in ISO 8601 format
QueryReleaseNotesV1Queries for release-notes resources and returns ids
Operation IDDescription
GetAggregateDetectsDeprecated: This endpoint will be decommissioned on September 30, 2025.
GetDetectSummariesDeprecated: This endpoint will be decommissioned on September 30, 2025.
QueryDetectsDeprecated: This endpoint will be decommissioned on September 30, 2025.
UpdateDetectsByIdsV2Deprecated: This endpoint will be decommissioned on September 30, 2025.
Operation IDDescription
entities.states.v1Retrieve the host content state for a number of ids between 1 and 100.
queries.states.v1Query for the content state of the host.
Operation IDDescription
createDeviceControlPoliciesCreate Device Control Policies by specifying details about the policy to create
deleteDeviceControlPoliciesDelete a set of Device Control Policies by specifying their IDs
getDefaultDeviceControlPoliciesRetrieve the configuration for a Default Device Control Policy
getDefaultDeviceControlSettingsGet default device control settings (USB and Bluetooth)
getDeviceControlPoliciesRetrieve a set of Device Control Policies by specifying their IDs
getDeviceControlPoliciesV2Get device control policies for the given filter criteria.
patchDeviceControlPoliciesClassesV1Update device control policy’s classes (USB and Bluetooth)
patchDeviceControlPoliciesV2Update device control policy base (USB and Bluetooth)
performDeviceControlPoliciesActionPerform the specified action on the Device Control Policies specified in the request
postDeviceControlPoliciesV2Create/clone a device control policy (USB and Bluetooth)
queryCombinedDeviceControlPoliciesSearch for Device Control Policies in your environment by providing an FQL filter and paging details.
queryCombinedDeviceControlPolicyMembersSearch for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
queryDeviceControlPoliciesSearch for Device Control Policies in your environment by providing an FQL filter and paging details.
queryDeviceControlPolicyMembersSearch for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
setDeviceControlPoliciesPrecedenceSets the precedence of Device Control Policies based on the order of IDs specified in the request.
updateDefaultDeviceControlPoliciesUpdate the configuration for a Default Device Control Policy
updateDefaultDeviceControlSettingsUpdate the configuration for Default Device Control Settings
updateDeviceControlPoliciesUpdate Device Control Policies by specifying the ID of the policy and details to update
Operation IDDescription
combined-applicationsSearch for applications in your environment by providing an FQL filter and paging details.
combined-hostsSearch for assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
get-accountsGet details on accounts by providing one or more IDs.
get-applicationsGet details on applications by providing one or more IDs.
get-hostsGet details on assets by providing one or more IDs.
get-iot-hostsGet details on IoT assets by providing one or more IDs.
get-loginsGet details on logins by providing one or more IDs.
query-accountsSearch for accounts in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-applicationsSearch for applications in your environment by providing an FQL filter and paging details. returns a set of application IDs which match the filter criteria.
query-hostsSearch for assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-iot-hostsSearch for IoT assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-iot-hostsV2Search for IoT assets in your environment by providing an FQL (Falcon Query Language) filter and paging details.
query-loginsSearch for logins in your environment by providing an FQL (Falcon Query Language) filter and paging details.
Operation IDDescription
DownloadFileGets pre-signed URL for the file
EnumerateFileEnumerates a list of files available for CID
FetchFilesDownloadInfoGet files info and pre-signed download URLs
FetchFilesDownloadInfoV2Get cloud security tools info and pre-signed download URLs
Operation IDDescription
GetDriftIndicatorsValuesByDateReturns the count of Drift Indicators by the date. by default it’s for 7 days.
ReadDriftIndicatorEntitiesRetrieve Drift Indicator entities identified by the provided IDs
ReadDriftIndicatorsCountReturns the total count of Drift indicators over a time period
SearchAndReadDriftIndicatorEntitiesRetrieve Drift Indicators by the provided search criteria
SearchDriftIndicatorsRetrieve all drift indicators that match the given query
Operation IDDescription
listAvailableStreamsOAuth2Discover all event streams in your environment
refreshActiveStreamSessionRefresh an active event stream.
Operation IDDescription
aggregate-external-assetsReturns external assets aggregates.
blob-download-external-assetsDownload the entire contents of the blob.
blob-preview-external-assetsDownload a preview of the blob.
combined-ecosystem-subsidiariesRetrieves a list of ecosystem subsidiaries with their detailed information.
delete-external-assetsDelete multiple external assets.
get-ecosystem-subsidiariesRetrieves detailed information about ecosystem subsidiaries by ID.
get-external-assetsGet details on external assets by providing one or more IDs.
patch-external-assetsUpdate the details of external assets.
post-external-assets-inventory-v1Add external assets for external asset scanning.
query-ecosystem-subsidiariesRetrieves a list of IDs for ecosystem subsidiaries.
query-external-assetsGet a list of external asset IDs that match the provided filter conditions.
query-external-assets-v2Get a list of external asset IDs that match the provided filter conditions.
Operation IDDescription
ReadRequestBodyretrieve a large request body, such as a file, that has spilled into object storage
Operation IDDescription
AggregateAlertsRetrieve aggregate epp alerts values based on the matched filter
AggregateAllowListRetrieve aggregate allowlist ticket values based on the matched filter
AggregateBlockListRetrieve aggregate blocklist ticket values based on the matched filter
AggregateDeviceCountCollectionRetrieve aggregate host/devices count based on the matched filter
AggregateEscalationsRetrieve aggregate escalation ticket values based on the matched filter
AggregatePreventionPolicyRetrieve prevention policies aggregate values based on the matched filter
AggregateRemediationsRetrieve aggregate remediation ticket values based on the matched filter
AggregateSensorUpdatePolicyRetrieve sensor update policies aggregate values
AggregateSupportIssuesRetrieve aggregate support issue ticket values based on the matched filter
AggregateTotalDeviceCountsRetrieve aggregate total host/devices based on the matched filter
GetDeviceCountCollectionQueriesByFilterRetrieve device count collection Ids that match the provided FQL filter, criteria with scrolling enabled
QueryAlertIdsByFilterRetrieve Alerts Ids for epp that match the provided FQL filter criteria with scrolling enabled
QueryAlertIdsByFilterV2Retrieve Alerts Ids for epp, idp and ngsiem that match the provided FQL filter criteria with scrolling enabled
QueryAllowListFilterRetrieve allowlist tickets that match the provided filter criteria with scrolling enabled
QueryBlockListFilterRetrieve block listtickets that match the provided filter criteria with scrolling enabled
QueryEscalationsFilterRetrieve escalation tickets that match the provided filter criteria with scrolling enabled
QueryRemediationsFilterRetrieve remediation tickets that match the provided filter criteria with scrolling enabled
Operation IDDescription
CreateRegistryEntitiesCreate a registry entity using the provided details
DeleteImageDetailsDelete Images by ids.
DeleteRegistryEntitiesDelete the registry entity identified by the entity UUID
DownloadExportFileDownload an export file
GetCredentialsGets the registry credentials
GetImageAssessmentReportRetrieves the Assessment report for the Image ID provided.
GetReportByReferenceGet image assessment scan report by image reference (v2)
GetReportByScanIDGet image assessment scan report by scan UUID (v2)
HeadImageScanInventoryGet headers for POST request for image scan inventory
ImageMatchesPolicyAfter an image scan, use this operation to see if any images match a policy.
LaunchExportJobLaunch an export job of a Container Security resource.
PolicyChecksCheck image prevention policies
PostImageScanInventoryPost image scan inventory
QueryExportJobsQuery export jobs entities
ReadExportJobsRead export jobs entities
ReadImageVulnerabilitiesRetrieve known vulnerabilities for the provided image
ReadRegistryEntitiesRetrieves a list of registry entities identified by the customer id.
ReadRegistryEntitiesByUUIDRetrieves a list of registry entities by the provided UUIDs.
UpdateRegistryEntitiesUpdate the registry entity, as identified by the entity UUID, using the provided details
Operation IDDescription
DeleteThirdPartyPasskeyRegistryDeletes third party passkey registries
GetThirdPartyPasskeyRegistryFetches third party passkey registries
QueryThirdPartyPasskeyRegistryQuery third party passkey registries
UpdateThirdPartyPasskeyRegistryUpdates third party passkey registries
Operation IDDescription
DeleteReportDelete report based on the report ID.
DeleteSampleV2Removes a sample, including file, meta and submissions from the collection
GetArtifactsDownload IOC packs, PCAP files, memory dumps, and other analysis artifacts.
GetMemoryDumpGet memory dump content, as binary
GetMemoryDumpExtractedStringsGet extracted strings from a memory dump
GetMemoryDumpHexDumpGet hex view of a memory dump
GetReportsGet a full sandbox report.
GetSampleV2Retrieves the file associated with the given ID (SHA256)
GetSubmissionsCheck the status of a sandbox analysis.
GetSummaryReportsGet a short summary version of a sandbox report.
QueryReportsFind sandbox reports by providing an FQL filter and paging details.
QuerySampleV1Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200
QuerySubmissionsFind submission IDs for uploaded files by providing an FQL filter and paging details.
SubmitSubmit an uploaded file or a URL for sandbox analysis.
UploadSampleV2Upload a file for sandbox analysis.
Operation IDDescription
fdrschema.combined.event.getFetch combined schema
fdrschema.entities.event.getFetch event schema by ID
fdrschema.entities.field.getFetch field schema by ID
fdrschema.queries.event.getGet list of event IDs given a particular query.
fdrschema.queries.field.getGet list of field IDs given a particular query.
Operation IDDescription
DeleteFederatedConnectionsConfigDelete configuration for a federated connection
PatchFederatedConnectionsConfigUpdate configuration for a federated connection
PostFederatedConnectionsConfigCreate configuration for a federated connection
Operation IDDescription
createPoliciesCreates a new policy of the specified type.
createRuleGroupsCreates a new rule group of the specified type.
createRulesCreates a new rule configuration within the specified rule group.
createScheduledExclusionsCreates a new scheduled exclusion configuration for the provided policy id.
deletePoliciesDeletes 1 or more policies.
deleteRuleGroupsDeletes 1 or more rule groups
deleteRulesDeletes 1 or more rules from the specified rule group.
deleteScheduledExclusionsDeletes 1 or more scheduled exclusions from the provided policy id.
getActionsMixin0Retrieves the processing results for 1 or more actions.
getChangesRetrieve information on changes
getContentsRetrieves the content captured for the provided change id
getPoliciesRetrieves the configuration for 1 or more policies.
getRuleGroupsRetrieves the rule group details for 1 or more rule groups.
getRulesRetrieves the configuration for 1 or more rules.
getScheduledExclusionsRetrieves the configuration of 1 or more scheduled exclusions from the provided policy id.
highVolumeQueryChangesReturns 1 or more change ids
queryActionsMixin0Returns one or more action ids
queryChangesReturns 1 or more change ids
queryPoliciesRetrieve the ids of all policies that are assigned the provided policy type.
queryRuleGroupsRetrieve the ids of all rule groups that are of the provided rule group type.
queryScheduledExclusionsRetrieve the ids of all scheduled exclusions contained within the provided policy id.
signalChangesExternalInitiates workflows for the provided change ids
startActionsInitiates the specified action on the provided change ids
updatePoliciesUpdates the general information of the provided policy.
updatePolicyHostGroupsManage host groups assigned to a policy.
updatePolicyPrecedenceUpdates the policy precedence for all policies of a specific type.
updatePolicyRuleGroupsManage the rule groups assigned to the policy or set the rule group precedence for all rule groups within the policy.
updateRuleGroupPrecedenceUpdates the rule precedence for all rules in the identified rule group.
updateRuleGroupsUpdates the provided rule group.
updateRulesUpdates the provided rule configuration within the specified rule group.
updateScheduledExclusionsUpdates the provided scheduled exclusion configuration within the provided policy.
Operation IDDescription
aggregate-eventsAggregate events for customer
aggregate-policy-rulesAggregate rules within a policy for customer
aggregate-rule-groupsAggregate rule groups for customer
aggregate-rulesAggregate rules for customer
create-network-locationsCreate new network locations provided, and return the ID.
create-rule-groupCreate new rule group on a platform for a customer with a name and description, and return the ID
create-rule-group-validationValidates the request of creating a new rule group on a platform for a customer with a name and description
delete-network-locationsDelete network location entities by ID.
delete-rule-groupsDelete rule group entities by ID
get-eventsGet events entities by ID and optionally version
get-firewall-fieldsGet the firewall field specifications by ID
get-network-locationsGet a summary of network locations entities by ID
get-network-locations-detailsGet network locations entities by ID
get-platformsGet platforms by ID, e.g., windows or mac or droid
get-policy-containersGet policy container entities by policy ID
get-rule-groupsGet rule group entities by ID.
get-rulesGet rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string)
query-eventsFind all event IDs matching the query with filter
query-firewall-fieldsGet the firewall field specification IDs for the provided platform
query-network-locationsGet a list of network location IDs
query-platformsGet the list of platform names
query-policy-rulesFind all firewall rule IDs matching the query with filter, and return them in precedence order
query-rule-groupsFind all rule group IDs matching the query with filter
query-rulesFind all rule IDs matching the query with filter
update-network-locationsUpdates the network locations provided, and return the ID.
update-network-locations-metadataUpdates the network locations metadata such as polling_intervals for the cid
update-network-locations-precedenceUpdates the network locations precedence according to the list of ids provided.
update-policy-containerUpdate an identified policy container, including local logging functionality.
update-policy-container-v1Update an identified policy container.
update-rule-groupUpdate name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
update-rule-group-validationValidates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
upsert-network-locationsUpdates the network locations provided, and return the ID.
validate-filepath-patternValidates that the test pattern matches the executable filepath glob pattern.
Operation IDDescription
createFirewallPoliciesCreate Firewall Policies by specifying details about the policy to create
deleteFirewallPoliciesDelete a set of Firewall Policies by specifying their IDs
getFirewallPoliciesRetrieve a set of Firewall Policies by specifying their IDs
performFirewallPoliciesActionPerform the specified action on the Firewall Policies specified in the request
queryCombinedFirewallPoliciesSearch for Firewall Policies in your environment by providing an FQL filter and paging details.
queryCombinedFirewallPolicyMembersSearch for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
queryFirewallPoliciesSearch for Firewall Policies in your environment by providing an FQL filter and paging details.
queryFirewallPolicyMembersSearch for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
setFirewallPoliciesPrecedenceSets the precedence of Firewall Policies based on the order of IDs specified in the request.
updateFirewallPoliciesUpdate Firewall Policies by specifying the ID of the policy and details to update
Operation IDDescription
CreateSavedSearchesDynamicExecuteV1Execute a dynamic saved search
CreateSavedSearchesExecuteV1Execute a saved search
CreateSavedSearchesIngestV1Populate a saved search
GetSavedSearchesExecuteV1Get the results of a saved search
GetSavedSearchesJobResultsDownloadV1Get the results of a saved search as a file
IngestDataAsyncV1Asynchronously ingest data into the application repository
IngestDataV1Synchronously ingest data into the application repository
ListReposV1Lists available repositories
ListViewV1List available views
Operation IDDescription
CreateFileV1Creates a lookup file within a foundry app
UpdateFileV1Updates a lookup file within a Foundry app
Operation IDDescription
createHostGroupsCreate Host Groups by specifying details about the group to create
deleteHostGroupsDelete a set of Host Groups by specifying their IDs
getHostGroupsRetrieve a set of Host Groups by specifying their IDs
performGroupActionPerform the specified action on the Host Groups specified in the request
queryCombinedGroupMembersSearch for members of a Host Group in your environment by providing an FQL filter and paging details.
queryCombinedHostGroupsSearch for Host Groups in your environment by providing an FQL filter and paging details.
queryGroupMembersSearch for members of a Host Group in your environment by providing an FQL filter and paging details.
queryHostGroupsSearch for Host Groups in your environment by providing an FQL filter and paging details.
updateHostGroupsUpdate Host Groups by specifying the ID of the group and details to update
Operation IDDescription
CreateMigrationV1Create a device migration job.
GetHostMigrationIDsV1Query host migration IDs.
GetHostMigrationsV1Get host migration details.
GetMigrationDestinationsV1Get destinations for a migration.
GetMigrationIDsV1Query migration jobs.
GetMigrationsV1Get migration job details.
HostMigrationAggregatesV1Get host migration aggregates as specified via json in request body.
HostMigrationsActionsV1Perform an action on host migrations.
MigrationAggregatesV1Get migration aggregates as specified via json in request body.
MigrationsActionsV1Perform an action on a migration job.
Operation IDDescription
CombinedDevicesByFilterSearch for hosts in your environment by platform, hostname, IP, and other criteria.
CombinedHiddenDevicesByFilterSearch for hidden hosts in your environment by platform, hostname, IP, and other criteria.
DevicesActionsDeleteV1Permanently delete hosts from the system.
entities.perform_actionPerforms the specified action on the provided group IDs.
GetDeviceDetailsGet details on one or more hosts by providing host IDs in a POST body.
GetDeviceDetailsV1Get details on one or more hosts by providing agent IDs (AID).
GetDeviceDetailsV2Get details on one or more hosts by providing host IDs as a query parameter.
GetOnlineState.V1Get the online status for one or more hosts by specifying each host’s unique ID.
PerformActionV2Take various actions on the hosts in your environment.
PostDeviceDetailsV2Get details on one or more hosts by providing host IDs in a POST body.
QueryDeviceLoginHistoryRetrieve details about recent login sessions for a set of devices.
QueryDeviceLoginHistoryV2Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline.
QueryDevicesByFilterSearch for hosts in your environment by platform, hostname, IP, and other criteria.
QueryDevicesByFilterScrollSearch for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit)
QueryGetNetworkAddressHistoryV1Retrieve history of IP and MAC addresses of devices.
QueryHiddenDevicesRetrieve hidden hosts that match the provided filter criteria.
UpdateDeviceTagsAppend or remove one or more Falcon Grouping Tags on one or more hosts.
Operation IDDescription
api_preempt_proxy_post_graphqlIdentity Protection GraphQL API.
delete_policy_rulesDelete policy rules
delete_policy_rulesDelete policy rules
get_policy_rulesGet policy rules
get_policy_rulesGet policy rules
get_policy_rules_queryQuery policy rule IDs
get_policy_rules_queryQuery policy rule IDs
GetSensorAggregatesGet sensor aggregates as specified via json in request body.
GetSensorDetailsGet details on one or more sensors by providing device IDs in a POST body.
post_policy_rulesCreate policy rule
post_policy_rulesCreate policy rule
QuerySensorsByFilterSearch for sensors in your environment by hostname, IP, and other criteria.
Operation IDDescription
CreatePoliciesCreate Image Assessment policies
CreatePolicyGroupsCreate Image Assessment Policy Group entities
DeletePolicyDelete Image Assessment Policy by policy UUID
DeletePolicyGroupDelete Image Assessment Policy Group entities
ReadPoliciesGet all Image Assessment policies
ReadPolicyExclusionsRetrieve Image Assessment Policy Exclusion entities
ReadPolicyGroupsRetrieve Image Assessment Policy Group entities
UpdatePoliciesUpdate Image Assessment Policy entities
UpdatePolicyExclusionsUpdate Image Assessment Policy Exclusion entities
UpdatePolicyGroupsUpdate Image Assessment Policy Group entities
UpdatePolicyPrecedenceUpdate Image Assessment Policy precedence
Operation IDDescription
audit-events-querySearch for audit events by providing an FQL filter and paging details.
audit-events-readGets the details of one or more audit events by id.
customer-settings-readCheck current installation token settings.
customer-settings-updateUpdate installation token settings.
tokens-createCreates a token.
tokens-deleteDeletes a token immediately.
tokens-querySearch for tokens by providing an FQL filter and paging details.
tokens-readGets the details of one or more tokens by id.
tokens-updateUpdates one or more tokens.
Operation IDDescription
cao_incidents_aggregates_v1Perform statistical aggregations over incident data.
cao_incidents_entities_v1Retrieve full details for one or more adversary incidents by their IDs.
cao_incidents_queries_v1Search for adversary incidents using FQL criteria and return a paginated list of matching incident IDs.
GetIntelActorEntitiesRetrieve specific actors using their actor IDs.
GetIntelIndicatorEntitiesRetrieve specific indicators using their indicator IDs.
GetIntelReportEntitiesRetrieve specific reports using their report IDs.
GetIntelReportPDFReturn a Report PDF attachment
GetIntelRuleEntitiesRetrieve details for rule sets for the specified ids.
GetIntelRuleFileDownload earlier rule sets.
GetLatestIntelRuleFileDownload the latest rule set.
GetMalwareEntitiesGet malware entities for specified ids.
GetMalwareMitreReportExport Mitre ATT&CK information for a given malware family.
GetMitreReportExport Mitre ATT&CK information for a given actor.
GetVulnerabilitiesGet vulnerabilities
PostMitreAttacksRetrieves report and observable IDs associated with the given actor and attacks
QueryIntelActorEntitiesGet info about actors that match provided FQL filters.
QueryIntelActorIdsGet actor IDs that match provided FQL filters.
QueryIntelIndicatorEntitiesGet info about indicators that match provided FQL filters.
QueryIntelIndicatorIdsGet indicators IDs that match provided FQL filters.
QueryIntelReportEntitiesGet info about reports that match provided FQL filters.
QueryIntelReportIdsGet report IDs that match provided FQL filters.
QueryIntelRuleIdsSearch for rule IDs that match provided filter criteria.
QueryMalwareGet malware family names that match provided FQL filters.
QueryMalwareEntitiesGet malware entities that match provided FQL filters.
QueryMitreAttacksGets MITRE tactics and techniques for the given actor, returning concatenation of id and tactic and technique ids, example: fancy-bear_TA0011_T1071
QueryMitreAttacksForMalwareGets MITRE tactics and techniques for the given malware
QueryVulnerabilitiesGet vulnerabilities IDs
Operation IDDescription
DownloadFeedArchiveDownloads the content as a zip archive for a given feed item ID
ListFeedTypesLists the accessible feed types for a given customer
QueryFeedArchivesQueries the accessible feed types for a customer.
Operation IDDescription
LookupIndicatorsGet indicators based on their value.
SearchIndicatorsSearch indicators based on FQL filter.
Operation IDDescription
createIOAExclusionsV1Create the IOA exclusions
deleteIOAExclusionsV1Delete the IOA exclusions by id
getIOAExclusionsV1Get a set of IOA Exclusions by specifying their IDs
queryIOAExclusionsV1Search for IOA exclusions.
ss-ioa-exclusions.aggregates.v2Get Self Service IOA Exclusion aggregates as specified via json in the request body.
ss-ioa-exclusions.create.v2Create new Self Service IOA Exclusions.
ss-ioa-exclusions.delete.v2Delete the Self Service IOA Exclusions rule by id.
ss-ioa-exclusions.get-reports.v2Create a report of Self Service IOA Exclusions scoped by the given filters
ss-ioa-exclusions.get.v2Get the Self Service IOA Exclusions rules by id.
ss-ioa-exclusions.matched-rule.v2Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent
ss-ioa-exclusions.new-rules.v2Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent.
ss-ioa-exclusions.search.v2Search for Self Service IOA Exclusions.
ss-ioa-exclusions.update.v2Update the Self Service IOA Exclusions rule by id.
updateIOAExclusionsV1Update the IOA exclusions
Operation IDDescription
action.get.v1Get Actions by ids.
action.query.v1Query Actions.
GetIndicatorsReportLaunch an indicators report creation job
indicator.aggregate.v1Get Indicators aggregates as specified via json in the request body.
indicator.combined.v1Get Combined for Indicators.
indicator.create.v1Create Indicators.
indicator.delete.v1Delete Indicators by ids.
indicator.get.device_count.v1Get the number of devices the indicator has run on
indicator.get.devices_ran_on.v1Get the IDs of devices the indicator has run on
indicator.get.processes_ran_on.v1Get the number of processes the indicator has run on
indicator.get.v1Get Indicators by ids.
indicator.sdmf-query.v1Executes an SDMF data frame query against IOC indicators
indicator.search.v1Search for Indicators.
indicator.update.v1Update Indicators.
ioc_type.query.v1Query IOC Types.
platform.query.v1Query Platforms.
severity.query.v1Query Severities.
Operation IDDescription
CreateIOCCreate a new IOC. *** Deprecated - Use the new IOC Management endpoint (POST /iocs/entities/indicators/v1). ***
DeleteIOCDelete an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (DELETE /iocs/entities/indicators/v1). ***
DevicesCountNumber of hosts in your customer account that have observed a given custom IOC
DevicesRanOnFind hosts that have observed a given custom IOC.
entities.processesFor the provided ProcessID retrieve the process details
GetIOCGet an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (GET /iocs/entities/indicators/v1). ***
ProcessesRanOnSearch for processes associated with a custom IOC
QueryIOCsSearch the custom IOCs in your customer account. *** Deprecated - Use the new IOC Management endpoint (GET /iocs/queries/indicators/v1). ***
UpdateIOCUpdate an IOC by providing a type and value. *** Deprecated - Use the new IOC Management endpoint (PATCH /iocs/entities/indicators/v1). ***
Operation IDDescription
ITAutomationCancelTaskExecutionCancel a task execution specified in the request
ITAutomationCombinedScheduledTasksReturns full details of scheduled tasks matching the filter query parameter.
ITAutomationCreatePolicyCreates a new policy of the specified type.
ITAutomationCreateScheduledTaskCreates a scheduled task from the given request
ITAutomationCreateTaskCreates a task with details from the given request.
ITAutomationCreateTaskGroupCreates a task group from the given request
ITAutomationCreateUserGroupCreates a user group from the given request
ITAutomationDeletePolicyDeletes 1 or more policies.
ITAutomationDeleteScheduledTasksDelete one or more scheduled tasks by providing the scheduled tasks IDs
ITAutomationDeleteTaskDeletes tasks for each provided ID
ITAutomationDeleteTaskGroupsDelete one or more task groups by providing the task group IDs
ITAutomationDeleteUserGroupDeletes user groups for each provided ids
ITAutomationGetAssociatedTasksRetrieve tasks associated with the provided file id
ITAutomationGetExecutionResultsGet the task execution results from an async search.
ITAutomationGetExecutionResultsSearchStatusGet the status of an async task execution results.
ITAutomationGetPoliciesRetrieves the configuration for 1 or more policies.
ITAutomationGetScheduledTasksReturns scheduled tasks for each provided id
ITAutomationGetTaskExecutionGet the task execution for the provided task execution IDs
ITAutomationGetTaskExecutionHostStatusGet the status of host executions by providing the execution IDs
ITAutomationGetTaskExecutionsByQueryReturns the list of task executions (and their details) matching the filter query parameter.
ITAutomationGetTaskGroupsReturns task groups for each provided id
ITAutomationGetTaskGroupsByQueryReturns full details of task groups matching the filter query parameter.
ITAutomationGetTasksReturns tasks for each provided ID
ITAutomationGetTasksByQueryReturns full details of tasks matching the filter query parameter.
ITAutomationGetUserGroupReturns user groups for each provided id
ITAutomationQueryPoliciesReturns the list of policy ids matching the filter query parameter.
ITAutomationRerunTaskExecutionRerun the task execution specified in the request
ITAutomationRunLiveQueryStarts a new task execution from the provided query data in the request and returns the initiated task executions
ITAutomationSearchScheduledTasksReturns the list of scheduled task IDs matching the filter query parameter
ITAutomationSearchTaskExecutionsReturns the list of task execution IDs matching the filter query parameter.
ITAutomationSearchTaskGroupsReturns the list of task group ids matching the filter query parameter
ITAutomationSearchTasksReturns the list of task IDs matching the filter query parameter.
ITAutomationSearchUserGroupReturns the list of user group ids matching the filter query parameter.
ITAutomationStartExecutionResultsSearchStarts an async task execution results search.
ITAutomationStartTaskExecutionStarts a new task execution from an existing task provided in the request and returns the initiated task executions
ITAutomationUpdatePoliciesUpdates a new policy of the specified type.
ITAutomationUpdatePoliciesPrecedenceUpdates the policy precedence for all policies of a specific platform.
ITAutomationUpdatePolicyHostGroupsManage host groups assigned to a policy.
ITAutomationUpdateScheduledTaskUpdate an existing scheduled task with the supplied info
ITAutomationUpdateTaskUpdate a task with details from the given request.
ITAutomationUpdateTaskGroupUpdate a task group for a given id
ITAutomationUpdateUserGroupUpdate a user group for a given id
Operation IDDescription
CombinedKnowledgeBaseAuditEventsV1Get knowledge base audit events with full event details and pagination.
EntitiesKnowledgeBaseAuditEventsV1Retrieve knowledge base audit event entities by their IDs.
QueriesKnowledgeBaseAuditEventsV1Query knowledge base audit event IDs with pagination and filtering.
Operation IDDescription
EntitiesKnowledgeBaseFilesCreateV1Upload a file to a knowledge base.
EntitiesKnowledgeBaseFilesDeleteV1Delete document from knowledge base.
EntitiesKnowledgeBaseFilesDownloadV1Download knowledge base file entities for the provided id.
EntitiesKnowledgeBaseFilesUpdateV1Update an existing file in a knowledge base.
EntitiesKnowledgeBaseFilesV1Retrieve knowledge base file entities for the provided id.
QueriesKnowledgeBaseFilesV1Query knowledge base files based on the provided filters.
Operation IDDescription
CombinedKnowledgeBasesV1Search for knowledge bases with filtering and return full entity details in a single response.
EntitiesKnowledgeBasesCreateV1Create or update a knowledge base.
EntitiesKnowledgeBasesUpdateV1Update an existing knowledge base.
EntitiesKnowledgeBasesV1Retrieve knowledge base entities for the provided id.
QueriesKnowledgeBasesV1Query knowledge bases based on the provided filters.
Operation IDDescription
AggregateAssessmentsGroupedByClustersV2Returns cluster details along with aggregated assessment results organized by cluster, including pass/fail assessment counts for various asset types.
AggregateAssessmentsGroupedByRulesV2Returns rule details along with aggregated assessment results organized by compliance rule, including pass/fail assessment counts.
AggregateComplianceByAssetTypeProvides aggregated compliance assessment metrics and rule status information, organized by asset type.
AggregateComplianceByClusterTypeProvides aggregated compliance assessment metrics and rule status information, organized by Kubernetes cluster type.
AggregateComplianceByFrameworkProvides aggregated compliance assessment metrics and rule status information, organized by compliance framework.
AggregateFailedRulesByClustersV3Retrieves the most non-compliant clusters, ranked in descending order based on the number of failed compliance rules across severity levels (critical, high, medium, and low).
AggregateTopFailedImagesRetrieves the most non-compliant container images, ranked in descending order based on the number of failed assessments across severity levels (critical, high, medium, and low).
CombinedImagesFindingsReturns detailed compliance assessment results for container images, providing the information needed to identify compliance violations.
CombinedNodesFindingsReturns detailed compliance assessment results for kubernetes nodes, providing the information needed to identify compliance violations.
getRulesMetadataByIDRetrieve detailed compliance rule information including descriptions, remediation steps, and audit procedures by specifying rule identifiers.
Operation IDDescription
CreateAWSAccountCreates a new AWS account in our system for a customer and generates the installation script
CreateAzureSubscriptionCreates a new Azure Subscription in our system
DeleteAWSAccountsMixin0Delete AWS accounts.
DeleteAzureSubscriptionDeletes a new Azure Subscription in our system
FindContainersByContainerRunTimeVersionRetrieve containers by container_runtime_version
FindContainersCountAffectedByZeroDayVulnerabilitiesRetrieve containers count affected by zero day vulnerabilities
GetAWSAccountsMixin0Provides a list of AWS accounts.
GetAzureInstallScriptProvides the script to run for a given tenant id and subscription IDs
GetAzureTenantConfigGets the Azure tenant Config
GetAzureTenantIDsProvides all the azure subscriptions and tenants
GetClustersProvides the clusters acknowledged by the Kubernetes Protection service
GetCombinedCloudClustersReturns a combined list of provisioned cloud accounts and known kubernetes clusters
GetHelmValuesYamlProvides a sample Helm values.yaml file for a customer to install alongside the agent Helm chart
GetLocationsProvides the cloud locations acknowledged by the Kubernetes Protection service
GetStaticScriptsGets static bash scripts that are used during registration
GroupContainersByManagedGroup the containers by Managed
ListAzureAccountsProvides the azure subscriptions registered to Kubernetes Protection
PatchAzureServicePrincipalAdds the client ID for the given tenant ID to our system
PostAggregatesPodsGet aggregate query result for pods
PostSearchKubernetesIOMEntitiesSearch for Kubernetes IOMs with filtering options.Pagination is supported via Elasticsearch’s search_after search param and point in time.
ReadClusterCombinedRetrieve kubernetes clusters identified by the provided filter criteria
ReadClusterCombinedV2Retrieve Kubernetes cluster data
ReadClusterCountRetrieve cluster counts
ReadClusterEnrichmentRetrieve cluster enrichment data
ReadClustersByDateRangeCountRetrieve clusters by date range counts
ReadClustersByKubernetesVersionCountBucket clusters by kubernetes version
ReadClustersByStatusCountBucket clusters by status
ReadContainerCombinedRetrieves a paginated list of containers identified by the provided filter criteria.
ReadContainerCountRetrieve container counts
ReadContainerCountByRegistryRetrieves a list with the top container image registries.
ReadContainerEnrichmentRetrieve container enrichment data
ReadContainerImageDetectionsCountByDateRetrieve count of image assessment detections on running containers over a period of time
ReadContainerImagesByMostUsedBucket container by image-digest
ReadContainerImagesByStateRetrieve count of image states running on containers
ReadContainersByDateRangeCountRetrieve containers by date range counts
ReadContainersSensorCoverageBucket containers by agent type and calculate sensor coverage
ReadContainerVulnerabilitiesBySeverityCountRetrieve container vulnerabilities by severity counts
ReadDeploymentCombinedRetrieve kubernetes deployments identified by the provided filter criteria
ReadDeploymentCountRetrieve deployment counts
ReadDeploymentEnrichmentRetrieve deployment enrichment data
ReadDeploymentsByDateRangeCountRetrieve deployments by date range counts
ReadDistinctContainerImageCountRetrieve count of distinct images running on containers
ReadKubernetesIomByDateRangeReturns the count of Kubernetes IOMs by the date. by default it’s for 7 days.
ReadKubernetesIomCountReturns the total count of Kubernetes IOMs over the past seven days
ReadKubernetesIomEntitiesRetrieve Kubernetes IOM entities identified by the provided IDs
ReadNamespaceCountRetrieve namespace counts
ReadNamespacesByDateRangeCountRetrieve namespaces by date range counts
ReadNodeCombinedRetrieve kubernetes nodes identified by the provided filter criteria
ReadNodeCountRetrieve node counts
ReadNodeEnrichmentRetrieve node enrichment data
ReadNodesByCloudCountBucket nodes by cloud providers
ReadNodesByContainerEngineVersionCountBucket nodes by their container engine version
ReadNodesByDateRangeCountRetrieve nodes by date range counts
ReadPodCombinedRetrieve kubernetes pods identified by the provided filter criteria
ReadPodCountRetrieve pod counts
ReadPodEnrichmentRetrieve pod enrichment data
ReadPodsByDateRangeCountRetrieve pods by date range counts
ReadRunningContainerImagesRetrieve images on running containers
ReadVulnerableContainerImageCountRetrieve count of vulnerable images running on containers
RegenerateAPIKeyRegenerate API key for docker registry integrations
SearchAndReadKubernetesIomEntitiesRetrieves a list of Kubernetes IOMs identified by the provided search criteria.
SearchKubernetesIomsSearch Kubernetes IOMs by the provided search criteria. this endpoint returns a list of Kubernetes IOM UUIDs matching the query
TriggerScanTriggers a dry run or a full scan of a customer’s kubernetes footprint
UpdateAWSAccountUpdates the AWS account per the query parameters provided
Operation IDDescription
GetMalQueryDownloadV1Download a file indexed by MalQuery.
GetMalQueryEntitiesSamplesFetchV1Fetch a zip archive with password ‘infected’ containing the samples.
GetMalQueryMetadataV1Retrieve indexed files metadata by their hash
GetMalQueryQuotasV1Get information about search and download quotas in your environment
GetMalQueryRequestV1Check the status and results of an asynchronous request, such as hunt or exact-search.
PostMalQueryEntitiesSamplesMultidownloadV1Schedule samples for download.
PostMalQueryExactSearchV1Search Falcon MalQuery for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity.
PostMalQueryFuzzySearchV1Search Falcon MalQuery quickly, but with more potential for false positives.
PostMalQueryHuntV1Schedule a YARA-based search for execution.
Operation IDDescription
AggregateCasesRetrieve aggregate case values based on the matched filter
CaseAddActivityAdd an activity to case.
CaseAddAttachmentUpload an attachment for the case.
CaseDownloadAttachmentretrieves an attachment for the case, given the attachment id
CreateCaseV2create a new case
GetCaseActivityByIdsRetrieve activities for given id’s
GetCaseEntitiesByIDsRetrieve message center cases
QueryActivityByCaseIDRetrieve activities id’s for a case
QueryCasesIdsByFilterRetrieve case id’s that match the provided filter criteria
UpdateCaseupdate an existing case
Operation IDDescription
createMLExclusionsV1Create the ML exclusions
deleteMLExclusionsV1Delete the ML exclusions by id
exclusions.aggregates.v2Get exclusion aggregates as specified via json in request body.
exclusions.create.v2Create the exclusions, with ancestor fields.
exclusions.delete.v2Delete the exclusions by id, with ancestor fields.
exclusions.get-all.v2Get all exclusions.
exclusions.get-reports.v2Create a report of ML exclusions scoped by the given filters
exclusions.get.v2Get the exclusions by id, with ancestor fields.
exclusions.perform-action.v2Actions used to manipulate the content of exclusions, with ancestor fields.
exclusions.sdmf-query.v1Executes an SDMF data frame query against exclusion entities
exclusions.search.v2Search for exclusions, with ancestor fields.
exclusions.update.v2Update the exclusions by id, with ancestor fields.
getMLExclusionsV1Get a set of ML Exclusions by specifying their IDs
queryMLExclusionsV1Search for ML exclusions.
updateMLExclusionsV1Update the ML exclusions
Operation IDDescription
RequestDeviceEnrollmentV3Trigger on-boarding process for a mobile device
RequestDeviceEnrollmentV4Trigger on-boarding process for a mobile device
Operation IDDescription
EntitiesModelsV1Get Model Entities by IDs
QueriesModelsV1Query models based on the provided filters.
Operation IDDescription
addCIDGroupMembersAdd new CID group member.
addRoleCreate a link between user group and CID group, with zero or more additional roles.
addUserGroupMembersAdd new user group member.
createCIDGroupsCreate new CID groups.
createUserGroupsCreate new user groups.
deleteCIDGroupMembersV1Deprecated : Please use DELETE /entities/cid-group-members/v2.
deleteCIDGroupMembersV2Delete CID group members.
deleteCIDGroupsDelete CID groups by ID.
deletedRolesDelete links or additional roles between user groups and CID groups.
deleteUserGroupMembersDelete user group members entry.
deleteUserGroupsDelete user groups by ID.
getChildrenGet link to child customer by child CID(s)
getChildrenV2Get link to child customer by child CID(s)
getCIDGroupByIdV1Deprecated : Please use GET /mssp/entities/cid-groups/v2.
getCIDGroupByIdV2Get CID Groups by ID.
getCIDGroupMembersByV1Deprecated : Please use GET /mssp/entities/cid-group-members/v2.
getCIDGroupMembersByV2Get CID group members by CID Group ID.
getRolesByIDGet link between user group and CID group by ID.
getUserGroupMembersByIDV1Deprecated : Please use GET /mssp/entities/user-group-members/v2.
getUserGroupMembersByIDV2Get user group members by user group ID.
getUserGroupsByIDV1Deprecated : Please use GET /entities/user-groups/v2.
getUserGroupsByIDV2Get user groups by ID.
queryChildrenQuery for customers linked as children
queryCIDGroupMembersQuery a CID groups members by associated CID.
queryCIDGroupsQuery CID groups.
queryRolesQuery links between user groups and CID groups.
queryUserGroupMembersQuery user group member by user UUID.
queryUserGroupsQuery user groups.
updateCIDGroupsUpdate existing CID groups.
updateUserGroupsUpdate existing user group(s).
Operation IDDescription
get-global-configsGet “global-configs” for the CID
update-global-configsUpdate “global-configs” using provided specifications
Operation IDDescription
aggregate-networksReturns “networks” aggregations
create-networksCreate “networks” using provided specifications
delete-networksDelete “networks” by their IDs
get-networksGet “networks” by their IDs
query-networksGet “networks IDs” by filter
update-networksUpdate “networks” using provided specifications
Operation IDDescription
get-scan-run-reportsDownloads scan run report in CSV format
Operation IDDescription
aggregate-scan-runsReturns “scan-runs” aggregations
create-scan-runsCreate “scan-runs” using provided specifications
get-scan-runsGet “scan-runs” by their IDs
query-scan-runsGet “scan-runs IDs” by filter
update-scan-runsUpdate “scan-runs” using provided specifications
Operation IDDescription
aggregate-scannersReturns “scanners” aggregations
get-scannersGet “scanners” by their IDs
query-scannersGet “scanners IDs” by filter
update-scannersUpdate “scanners” using provided specifications
Operation IDDescription
aggregate-scansMixin0Returns “scans” aggregations
create-scansCreate “scans” using provided specifications
delete-scansDelete “scans” by their IDs
get-scansGet “scans” by their IDs
query-scansMixin0Get “scans IDs” by filter
update-scansUpdate “scans” using provided specifications
Operation IDDescription
create-templatesCreate “templates” using provided specifications
delete-templatesDelete “templates” by their IDs
get-template-configsGet details on the network scan template configurations
get-templatesGet “templates” by their IDs
query-templatesGet “templates IDs” by filter
update-templatesUpdate “templates” using provided specifications
Operation IDDescription
aggregate-zonesReturns “zones” aggregations
combined-zonesGet “zones” by filter
create-zonesCreate “zones” using provided specifications
delete-zonesDelete “zones” by their IDs
get-zonesGet “zones” by their IDs
query-zonesGet “zones IDs” by filter
update-zonesUpdate “zones” using provided specifications
Operation IDDescription
addDashboardLabelsAdd multiple labels to a single dashboard
addFileLabelsAdd multiple labels to a single file
addSavedQueryLabelsAdd multiple labels to a saved query
bulkAddDashboardLabelsAdd labels to multiple dashboards (max 100 items, non-transactional)
bulkAddLookupFileLabelsAdd labels to multiple lookup files (max 100 items, non-transactional)
bulkAddSavedQueryLabelsAdd labels to multiple saved queries (max 100 items, non-transactional)
BulkCreateDashboardsFromTemplateCreate Multiple Dashboards from YAML Templates.
BulkCreateLookupFilesCreate Multiple Lookup Files.
BulkCreateSavedQueriesFromTemplateCreate Multiple Saved Queries from LogScale YAML Templates.
BulkGetLookupFilesRetrieve Multiple Lookup Files by Filenames in NGSIEM.
BulkInstallParsersInstalls multiple CrowdStrike-managed out-of-the-box (OOTB) parsers into the customer’s repository in a single operation.
bulkRemoveDashboardLabelsRemove labels from multiple dashboards (max 100 items, non-transactional)
bulkRemoveLookupFileLabelsRemove labels from multiple lookup files (max 100 items, non-transactional)
bulkRemoveSavedQueryLabelsRemove labels from multiple saved queries (max 100 items, non-transactional)
bulkUpdateDashboardLabelsReplace all labels on multiple dashboards (max 100 items, non-transactional)
BulkUpdateDashboardsFromTemplateUpdate Multiple Dashboards from YAML Templates.
bulkUpdateLookupFileLabelsReplace all labels on multiple lookup files (max 100 items, non-transactional)
BulkUpdateLookupFilesUpdate Multiple Lookup Files.
BulkUpdateSavedQueriesFromTemplateUpdate Multiple Saved Queries from LogScale YAML Templates.
bulkUpdateSavedQueryLabelsReplace all labels on multiple saved queries (max 100 items, non-transactional)
CloneParserClone an existing parser with a new name
CreateDashboardFromTemplateCreate Dashboard from LogScale YAML Template in NGSIEM
CreateLookupFileCreate Lookup File in NGSIEM
CreateParserCreate Parser in NGSIEM.
CreateParserExtensionCreate a Parser extension in NGSIEM for the provided base parser.
CreateParserFromTemplateCreate Parser from LogScale YAML Template in NGSIEM
CreateSavedQueryCreate Saved Query from LogScale YAML Template in NGSIEM
DeleteDashboardDelete Dashboard in NGSIEM
DeleteLookupFileDelete Lookup File in NGSIEM
DeleteParserDelete Parser in NGSIEM
DeleteSavedQueryDelete Saved Query in NGSIEM
ExternalCreateConnectorConfigCreate a new configuration for a data connector
ExternalCreateDataConnectionCreate a new data connection
ExternalDeleteConnectorConfigsDelete data connection config
ExternalDeleteDataConnectionDelete a data connection
ExternalGetDataConnectionByIDGet data connection by ID
ExternalGetDataConnectionStatusGet data connection provisioning status
ExternalGetDataConnectionTokenGet Ingest token for data connection
ExternalListConnectorConfigsList configurations for a data connector
ExternalListDataConnectionsList and search data connections
ExternalListDataConnectorsList available data connectors
ExternalPatchConnectorConfigPatch configurations for a data connector
ExternalRegenerateDataConnectionTokenRegenerate Ingest token for data connection
ExternalUpdateDataConnectionUpdate a data connection
ExternalUpdateDataConnectionStatusUpdate data connection status
GetDashboardTemplateRetrieve Dashboard(s) in NGSIEM as LogScale YAML Template.
GetLookupFileRetrieve Lookup File in NGSIEM
GetLookupFromPackageV1Download lookup file in package from NGSIEM
GetLookupFromPackageWithNamespaceV1Download lookup file in namespaced package from NGSIEM
GetLookupV1Download lookup file from NGSIEM
GetParserRetrieve Parser in NGSIEM.
GetParserTemplateRetrieve Parser in NGSIEM as LogScale YAML Template
GetSavedQueryTemplateRetrieve Saved Quer(ies) in NGSIEM as LogScale YAML Template.
GetSearchStatusV1Get status of search
InstallParserInstalls a CrowdStrike-managed out-of-the-box (OOTB) parser into the customer’s repository.
ListDashboardsList Dashboards in NGSIEM with Pagination and Filtering.
ListLookupFilesList Lookup Files in NGSIEM with Pagination and Filtering.
ListParsersList Parsers in NGSIEM
ListSavedQueriesList Saved Queries in NGSIEM with Pagination and Filtering.
removeDashboardLabelsRemove multiple labels from a single dashboard
removeFileLabelsRemove multiple labels from a single file
removeSavedQueryLabelsRemove multiple labels from a saved query
StartSearchV1Initiate search
StopSearchV1Stop search
TestParserFromTemplateTest Parser from LogScale YAML Template in NGSIEM
UpdateDashboardFromTemplateUpdate Dashboard from LogScale YAML Template in NGSIEM.
updateDashboardLabelsReplace all labels on a single dashboard
updateFileLabelsReplace all labels on a single file
UpdateLookupFileUpdate an entire Lookup File in NGSIEM
UpdateLookupFileEntriesUpdate entries in an existing Lookup File in NGSIEM
UpdateParserUpdate Parser in NGSIEM.
UpdateParserAutoUpdatePolicyUpdates a parser auto update policy - ‘on’ enables auto-updates, ‘off’ disables them
UpdateParserExtensionUpdate an existing Parser extension in NGSIEM.
UpdateParserFromTemplateUpdate Parser in NGSIEM from YAML Template.
UpdateSavedQueryFromTemplateUpdate Saved Query from LogScale YAML Template in NGSIEM.
updateSavedQueryLabelsReplace all labels on a single saved query
UploadLookupV1Upload file to NGSIEM
Operation IDDescription
oauth2AccessTokenGenerate an OAuth2 access token
oauth2RevokeTokenRevoke a previously issued OAuth2 access token before the end of its standard 30-minute lifespan.
Operation IDDescription
aggregate-query-scan-host-metadataGet aggregates on ODS scan-hosts data.
aggregate-scansGet aggregates on ODS scan data.
aggregate-scheduled-scansGet aggregates on ODS scheduled-scan data.
cancel-scansCancel ODS scans for the given scan ids.
create-scanCreate ODS scan and start or schedule scan for the given scan request.
delete-scheduled-scansDelete ODS scheduled-scans for the given scheduled-scan ids.
get-malicious-files-by-idsGet malicious files by ids.
get-scan-host-metadata-by-idsGet scan hosts by ids.
get-scans-by-scan-idsGet Scans by IDs.
get-scans-by-scan-ids-v2Get Scans by IDs.
get-scheduled-scans-by-scan-idsGet ScheduledScans by IDs.
query-malicious-filesQuery malicious files.
query-scan-host-metadataQuery scan hosts.
query-scansQuery Scans.
query-scheduled-scansQuery ScheduledScans.
scans-reportLaunch a scans report creation job
schedule-scanCreate ODS scan and start or schedule scan for the given scan request.
Operation IDDescription
createPreventionPoliciesCreate Prevention Policies by specifying details about the policy to create
deletePreventionPoliciesDelete a set of Prevention Policies by specifying their IDs
getPreventionPoliciesRetrieve a set of Prevention Policies by specifying their IDs
performPreventionPoliciesActionPerform the specified action on the Prevention Policies specified in the request
queryCombinedPreventionPoliciesSearch for Prevention Policies in your environment by providing an FQL filter and paging details.
queryCombinedPreventionPolicyMembersSearch for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
queryPreventionPoliciesSearch for Prevention Policies in your environment by providing an FQL filter and paging details.
queryPreventionPolicyMembersSearch for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
setPreventionPoliciesPrecedenceSets the precedence of Prevention Policies based on the order of IDs specified in the request.
updatePreventionPoliciesUpdate Prevention Policies by specifying the ID of the policy and details to update
Operation IDDescription
CreateGroupV1Mixin0Create a new profile group
DeleteGroupsV1Delete profile groups by IDs
GetGroupsV1Mixin0Get profile groups by IDs with full details
GetGroupUsersV1Get a list of groups with users that belong to them
GetUserGroupsV1Get a list of users with the groups that they belong to
GroupActionsV1Mixin0Perform actions on profile groups (add/remove roles, user groups, FGA objects)
GroupUsersActionsV1Mixin0Add or remove users from profile groups
QueryGroupsV1Mixin0Query profile group IDs with FQL filtering, pagination, and sorting
UpdateGroupV1Mixin0Update profile group metadata (name, description)
Operation IDDescription
ActionUpdateCountReturns count of potentially affected quarantined files for each action.
GetAggregateFilesGet quarantine file aggregates as specified via json in request body.
GetQuarantineFilesGet quarantine file metadata for specified ids.
QueryQuarantineFilesGet quarantine file ids that match the provided filter criteria.
UpdateQfByQueryApply quarantine file actions by query.
UpdateQuarantinedDetectsByIdsApply action by quarantine file ids
Operation IDDescription
GetScansCheck the status of a volume scan.
GetScansAggregatesGet scans aggregations as specified via json in request body.
QuerySubmissionsMixin0Find IDs for submitted scans by providing an FQL filter and paging details.
ScanSamplesSubmit a volume of files for ml scanning.
Operation IDDescription
DeleteFileDeletes file by its sha256 identifier.
DeleteScanResultDeletes the result of an QuickScan Pro scan.
GetScanResultGets the result of an QuickScan Pro scan.
LaunchScanStarts scanning a file uploaded through ‘/quickscanpro/entities/files/v1’.
QueryScanResultsFQL query specifying the filter parameters
UploadFileMixin0Mixin94Uploads a file to be further analyzed with QuickScan Pro.
UploadFileQuickScanProUploads a file to be further analyzed with QuickScan Pro.
Operation IDDescription
BatchActiveResponderCmdBatch executes a RTR active-responder command across the hosts mapped to the given batch ID.
BatchCmdBatch executes a RTR read-only command across the hosts mapped to the given batch ID.
BatchGetCmdBatch executes get command across hosts to retrieve files.
BatchGetCmdStatusRetrieves the status of the specified batch get command.
BatchInitSessionsBatch initialize a RTR session on multiple hosts.
BatchRefreshSessionsBatch refresh a RTR session on multiple hosts.
RTR-AggregateSessionsGet aggregates on session data.
RTR-CheckActiveResponderCommandStatusGet status of an executed active-responder command on a single host.
RTR-CheckCommandStatusGet status of an executed command on a single host.
RTR-DeleteFileDelete a RTR session file.
RTR-DeleteFileV2Delete a RTR session file.
RTR-DeleteQueuedSessionDelete a queued session command
RTR-DeleteSessionDelete a session.
RTR-ExecuteActiveResponderCommandExecute an active responder command on a single host.
RTR-ExecuteCommandExecute a command on a single host.
RTR-GetExtractedFileContentsGet RTR extracted file contents for specified session and sha256.
RTR-InitSessionInitialize a new session with the RTR cloud.
RTR-ListAllSessionsGet a list of session_ids.
RTR-ListFilesGet a list of files for the specified RTR session.
RTR-ListFilesV2Get a list of files for the specified RTR session.
RTR-ListQueuedSessionsGet queued session metadata by session ID.
RTR-ListSessionsGet session metadata by session id.
RTR-PulseSessionRefresh a session timeout on a single host.
Operation IDDescription
BatchAdminCmdBatch executes a RTR administrator command across the hosts mapped to the given batch ID.
RTR-CheckAdminCommandStatusGet status of an executed RTR administrator command on a single host.
RTR-CreatePut-FilesUpload a new put-file to use for the RTR put command.
RTR-CreatePut-FilesV2Upload a new put-file to use for the RTR put command.
RTR-CreateScriptsUpload a new custom-script to use for the RTR runscript command.
RTR-CreateScriptsV2Upload a new custom-script to use for the RTR runscript command.
RTR-DeletePut-FilesDelete a put-file based on the ID given.
RTR-DeleteScriptsDelete a custom-script based on the ID given.
RTR-ExecuteAdminCommandExecute a RTR administrator command on a single host.
RTR-GetFalconScriptsGet Falcon scripts with metadata and content of script
RTR-GetPut-FilesGet put-files based on the ID’s given.
RTR-GetPut-FilesV2Get put-files based on the ID’s given.
RTR-GetPutFileContentsGet RTR put file contents for a given file ID
RTR-GetScriptsGet custom-scripts based on the ID’s given.
RTR-GetScriptsV2Get custom-scripts based on the ID’s given.
RTR-ListFalconScriptsGet a list of Falcon script IDs available to the user to run
RTR-ListPut-FilesGet a list of put-file ID’s that are available to the user for the put command.
RTR-ListScriptsGet a list of custom-script ID’s that are available to the user for the runscript command.
RTR-UpdateScriptsUpload a new scripts to replace an existing one.
RTR-UpdateScriptsV2Upload a new scripts to replace an existing one.
Operation IDDescription
RTRAuditSessionsGet all the RTR sessions created for a customer in a specified duration
Operation IDDescription
AggregateNotificationsExposedDataRecordsV1Get notification exposed data record aggregates as specified via JSON in request body.
AggregateNotificationsV1Get notification aggregates as specified via JSON in request body.
CreateActionsV1Create actions for a monitoring rule.
CreateExportJobsV1Launch asynchronous export job.
CreateRulesV1Create monitoring rules.
DeleteActionV1Delete an action from a monitoring rule based on the action ID.
DeleteExportJobsV1Delete export jobs (and their associated file(s)) based on their IDs.
DeleteNotificationsV1Delete notifications based on IDs.
DeleteRulesV1Delete monitoring rules.
GetActionsV1Get actions based on their IDs.
GetExportJobsV1Get the status of export jobs based on their IDs.
GetFileContentForExportJobsV1Download the file associated with a job ID.
GetNotificationsDetailedTranslatedV1Get detailed notifications based on their IDs.
GetNotificationsDetailedV1Get detailed notifications based on their IDs.
GetNotificationsExposedDataRecordsV1Get notifications exposed data records based on their IDs.
GetNotificationsTranslatedV1Get notifications based on their IDs.
GetNotificationsV1Get notifications based on their IDs.
GetRulesV1Get monitoring rules based on their IDs.
PreviewRuleV1Preview rules notification count and distribution.
QueryActionsV1Query actions based on provided criteria.
QueryNotificationsExposedDataRecordsV1Query notifications exposed data records based on provided criteria.
QueryNotificationsV1Query notifications based on provided criteria.
QueryRulesV1Query monitoring rules based on provided criteria.
UpdateActionV1Update an action for a monitoring rule.
UpdateNotificationsV1Update notification status or assignee.
UpdateRulesV1Update monitoring rules.
Operation IDDescription
report-executions-download.getGet report entity download
report-executions.getRetrieve report details for the provided report IDs.
report-executions.queryFind all report execution IDs matching the query with filter
report-executions.retryThis endpoint will be used to retry report executions
Operation IDDescription
createRTResponsePoliciesCreate Response Policies by specifying details about the policy to create
deleteRTResponsePoliciesDelete a set of Response Policies by specifying their IDs
getRTResponsePoliciesRetrieve a set of Response Policies by specifying their IDs
performRTResponsePoliciesActionPerform the specified action on the Response Policies specified in the request
queryCombinedRTResponsePoliciesSearch for Response Policies in your environment by providing an FQL filter and paging details.
queryCombinedRTResponsePolicyMembersSearch for members of a Response policy in your environment by providing an FQL filter and paging details.
queryRTResponsePoliciesSearch for Response Policies in your environment by providing an FQL filter with sort and/or paging details.
queryRTResponsePolicyMembersSearch for members of a Response policy in your environment by providing an FQL filter and paging details.
setRTResponsePoliciesPrecedenceSets the precedence of Response Policies based on the order of IDs specified in the request.
updateRTResponsePoliciesUpdate Response Policies by specifying the ID of the policy and details to update
Operation IDDescription
DismissAffectedEntityV3POST Dismiss Affected Entity
DismissSecurityCheckV3POST Dismiss Security Check by ID
GetActivityMonitorV3GET Activity Monitor
GetAlertsV3GET Alert by ID or GET Alerts
GetAppInventoryGET Applications Inventory
GetAppInventoryUsersGET Application Users
GetAssetInventoryV3GET Data Inventory
GetDeviceInventoryV3GET Device Inventory
GetIntegrationsV3GET Integrations
GetMetricsV3GET Metrics
GetSecurityCheckAffectedV3GET Security Check Affected
GetSecurityCheckComplianceV3GET Compliance
GetSecurityChecksV3GET Security Check by ID or GET List Security Checks
GetSupportedSaasV3GET Supported SaaS
GetSystemLogsV3GET System Logs
GetSystemUsersV3GET System Users
GetUserInventoryV3GET User Inventory
IntegrationBuilderEndTransactionV3POST Data Upload Transaction Completion
IntegrationBuilderGetStatusV3GET Status
IntegrationBuilderResetV3Reset
IntegrationBuilderUploadV3POST Upload
Operation IDDescription
ArchiveDeleteV1Delete an archive that was uploaded previously
ArchiveGetV1Retrieves the archives upload operation statuses.
ArchiveListV1Retrieves the archives files in chunks.
ArchiveUploadV1Uploads an archive and extracts files list from it.
ArchiveUploadV2Uploads an archive and extracts files list from it.
DeleteSampleV3Removes a sample, including file, meta and submissions from the collection
ExtractionCreateV1Extracts files from an uploaded archive and copies them to internal storage making it available for content analysis.
ExtractionGetV1Retrieves the files extraction operation statuses.
ExtractionListV1Retrieves the files extractions in chunks.
GetSampleV3Retrieves the file associated with the given ID (SHA256)
UploadSampleV3Upload a file for further cloud analysis.
Operation IDDescription
scheduled-reports.getRetrieve scheduled reports for the provided report IDs.
scheduled-reports.launchLaunch scheduled reports executions for the provided report IDs.
scheduled-reports.queryFind all report IDs matching the query with filter
Operation IDDescription
DownloadSensorInstallerByIdDownload sensor installer by SHA256 ID
DownloadSensorInstallerByIdV2Download sensor installer by SHA256 ID
DownloadSensorInstallerByIdV3Download sensor installer by SHA256 ID
GetCombinedSensorInstallersByQueryGet sensor installer details by provided query
GetCombinedSensorInstallersByQueryV2Get sensor installer details by provided query
GetCombinedSensorInstallersByQueryV3Get sensor installer details by provided query
GetSensorInstallersByQueryGet sensor installer IDs by provided query
GetSensorInstallersByQueryV2Get sensor installer IDs by provided query
GetSensorInstallersByQueryV3Get sensor installer IDs by provided query
GetSensorInstallersCCIDByQueryGet CCID to use with sensor installers
GetSensorInstallersEntitiesGet sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV2Get sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV3Get sensor installer details by provided SHA256 IDs
Operation IDDescription
createSensorUpdatePoliciesCreate Sensor Update Policies by specifying details about the policy to create
createSensorUpdatePoliciesV2Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection
deleteSensorUpdatePoliciesDelete a set of Sensor Update Policies by specifying their IDs
getSensorUpdatePoliciesRetrieve a set of Sensor Update Policies by specifying their IDs
getSensorUpdatePoliciesV2Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs
incrementUninstallTokenIncrements a bulk maintenance token.
performSensorUpdatePoliciesActionPerform the specified action on the Sensor Update Policies specified in the request
queryCombinedSensorUpdateBuildsRetrieve available builds for use with Sensor Update Policies
queryCombinedSensorUpdateKernelsRetrieve kernel compatibility info for Sensor Update Builds
queryCombinedSensorUpdatePoliciesSearch for Sensor Update Policies in your environment by providing an FQL filter and paging details.
queryCombinedSensorUpdatePoliciesV2Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details.
queryCombinedSensorUpdatePolicyMembersSearch for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
querySensorUpdateKernelsDistinctRetrieve kernel compatibility info for Sensor Update Builds
querySensorUpdatePoliciesSearch for Sensor Update Policies in your environment by providing an FQL filter and paging details.
querySensorUpdatePolicyMembersSearch for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
revealUninstallTokenReveals an uninstall token for a specific device.
setSensorUpdatePoliciesPrecedenceSets the precedence of Sensor Update Policies based on the order of IDs specified in the request.
updateSensorUpdatePoliciesUpdate Sensor Update Policies by specifying the ID of the policy and details to update
updateSensorUpdatePoliciesV2Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection
Operation IDDescription
GetSensorUsageHourlyFetches hourly average.
GetSensorUsageWeeklyFetches weekly average.
Operation IDDescription
createSVExclusionsV1Create the sensor visibility exclusions
deleteSensorVisibilityExclusionsV1Delete the sensor visibility exclusions by id
getSensorVisibilityExclusionsV1Get a set of Sensor Visibility Exclusions by specifying their IDs
querySensorVisibilityExclusionsV1Search for sensor visibility exclusions.
updateSensorVisibilityExclusionsV1Update the sensor visibility exclusions
Operation IDDescription
DownloadExportFileMixin0Download an export file
LaunchExportJobMixin0Launch an export job of a Lambda Security resource.
QueryExportJobsMixin0Query export jobs entities
ReadExportJobsMixin0Read export jobs entities
Operation IDDescription
GetCombinedVulnerabilitiesSARIFRetrieve all lambda vulnerabilities that match the given query and return in the SARIF format
Operation IDDescription
EntitiesSpansV1Retrieve spans for the provided ids.
QueriesSpansV1Query spans based on the provided filters.
Operation IDDescription
combinedQueryEvaluationLogicSearch for evaluation logic in your environment by providing a FQL filter and paging details.
combinedSupportedEvaluationExtPerforms a combined query and get operation for retrieving RiskSupportedEvaluation entities.
getEvaluationLogicGet details on evaluation logic items by providing one or more IDs.
queryEvaluationLogicSearch for evaluation logic in your environment by providing a FQL filter and paging details.
Operation IDDescription
combinedQueryVulnerabilitiesSearch for Vulnerabilities in your environment by providing an FQL filter and paging details.
getRemediationsGet details on remediations by providing one or more IDs
getRemediationsV2Get details on remediation by providing one or more IDs
getVulnerabilitiesGet details on vulnerabilities by providing one or more IDs
queryVulnerabilitiesSearch for Vulnerabilities in your environment by providing an FQL filter and paging details.
Operation IDDescription
combineVulnMetadataExtPerforms a combined query and get operation for retrieving Risk (vulnerability metadata) entities.
Operation IDDescription
GetEventsBodyGet event body for the provided event ID
GetEventsEntitiesGet events entities for specified ids.
GetRulesEntitiesGet rules entities for specified ids.
QueryEventsGet events ids that match the provided filter criteria.
QueryRulesGet rules ids that match the provided filter criteria.
Operation IDDescription
combined_edges_getRetrieve edges for a given vertex id.
combined_ran_on_getLook up instances of indicators such as hashes, domain names, and ip addresses that have been seen on devices in your environment.
combined_summary_getRetrieve summary for a given vertex ID
entities_vertices_getRetrieve metadata for a given vertex ID.
entities_vertices_getv2Retrieve metadata for a given vertex ID
queries_edgetypes_getShow all available edge types
Operation IDDescription
EntitiesToolsV1Retrieve tools entities for the provided id.
QueriesToolsV1Query tools based on the provided filters.
Operation IDDescription
ReadUnidentifiedContainersByDateRangeCountReturns the count of Unidentified Containers over the last 7 days
ReadUnidentifiedContainersCountReturns the total count of Unidentified Containers over a time period
SearchAndReadUnidentifiedContainersSearch Unidentified Containers by the provided search criteria
Operation IDDescription
aggregateUsersV1Get host aggregates as specified via json in request body.
combinedUserRolesV1Deprecated : Please use GET /user-management/combined/user-roles/v2.
CombinedUserRolesV2Get User Grant(s).
CreateUserDeprecated : Please use POST /user-management/entities/users/v1.
createUserV1Create a new user.
DeleteUserDeprecated : Please use DELETE /user-management/entities/users/v1.
deleteUserV1Delete a user permanently.
entitiesRolesGETV2Get info about a role
entitiesRolesV1Get info about a role
GetAvailableRoleIdsDeprecated : Please use GET /user-management/queries/roles/v1.
GetRolesDeprecated : Please use GET /user-management/entities/roles/v1.
GetUserRoleIdsDeprecated : Please use GET /user-management/combined/user-roles/v1.
GrantUserRoleIdsDeprecated : Please use POST /user-management/entities/user-role-actions/v1.
queriesRolesV1Show role IDs for all roles available in your customer account.
queryUserV1List user IDs for all users in your customer account.
RetrieveEmailsByCIDDeprecated : Please use POST /user-management/entities/users/GET/v1.
retrieveUserDeprecated : Please use POST /user-management/entities/users/GET/v1.
RetrieveUserDeprecated : Please use retrieveUsersGETV1.
retrieveUsersGETV1Get info about users including their name, UID and CID by providing user UUIDs
RetrieveUserUUIDDeprecated : Please use GET /user-management/queries/users/v1.
RetrieveUserUUIDsByCIDDeprecated : Please use GET /user-management/queries/users/v1.
RevokeUserRoleIdsDeprecated : Please use POST /user-management/entities/user-role-actions/v1.
UpdateUserDeprecated : Please use PATCH /user-management/entities/users/v1.
updateUserV1Modify an existing user’s first or last name.
userActionV1Apply actions to one or more User.
userRolesActionV1Grant or Revoke one or more role(s) to a user against a CID.
Operation IDDescription
v1.child-executions.querySearch for child executions by providing a FQL filter and paging details.
WorkflowActivitiesCombinedSearch for activities by name.
WorkflowActivitiesContentCombinedSearch for activities by name.
WorkflowDefinitionsActionEnable or disable a workflow definition, or stop all executions for a definition.
WorkflowDefinitionsCombinedSearch workflow definitions based on the provided filter.
WorkflowDefinitionsDeleteAccepts a list of workflow definition IDs and deletes those definitions and all their associated versions.
WorkflowDefinitionsExportExports a workflow definition for the given definition ID
WorkflowDefinitionsImportImports a workflow definition based on the provided model
WorkflowDefinitionsUpdateUpdates a workflow definition based on the provided model
WorkflowExecuteExecutes an on-demand Workflow, the body is JSON used to trigger the execution, the response the execution ID(s)
WorkflowExecuteSingleNodeV1Executes a single activity node, resulting in an execution where test_mode=true and single_node_execution=true, associated with a definition ID if provided
WorkflowExecutionResultsGet execution result of a given execution
WorkflowExecutionsActionAllows a user to resume/retry a failed workflow execution, or cancel/stop a currently running workflow execution
WorkflowExecutionsCombinedSearch workflow executions based on the provided filter
WorkflowGetHumanInputV1Gets one or more specific human inputs by their IDs.
WorkflowMockExecuteExecutes a workflow definition with mocks
WorkflowSystemDefinitionsDeProvisionDeprovisions a system definition that was previously provisioned on the target CID
WorkflowSystemDefinitionsPromotePromotes a version of a system definition for a customer.
WorkflowSystemDefinitionsProvisionProvisions a system definition onto the target CID by using the template and provided parameters
WorkflowTriggersCombinedSearch for triggers by namespaced identifier, i.e.
WorkflowUpdateHumanInputV1Provides an input in response to a human input action.
Operation IDDescription
getAssessmentsByScoreV1Get Zero Trust Assessment data for one or more hosts by providing a customer ID (CID) and a range of scores.
getAssessmentV1Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID) and a customer ID (CID).
getAuditV1Get the Zero Trust Assessment audit report for one customer ID (CID).