Skip to content

Operations by Collection

An operation is a request against a specific endpoint within the CrowdStrike API. Each operation combines an HTTP method with an API endpoint and has a unique Operation ID. No two operations share the same method/endpoint combination.

Every operation within every service collection has a unique, case-sensitive string identifier. Operation IDs are used throughout the CrowdStrike SDKs to reference specific API calls — as method names, function parameters, and endpoint identifiers across all supported languages. They also serve as the primary way to locate operation details within this documentation.

The tables below list all available operations grouped by their service collection. Each Operation ID links to the full operation details including parameters, request body schema, and code examples.

Operation IDDescription
admission_control_get_policiesGet admission control policies.
admission_control_create_policyCreate an admission control policy.
admission_control_update_policyUpdate an admission control policy.
admission_control_delete_policiesDelete an admission control policy.
admission_control_add_host_groupsAdd one or more host groups to an admission control policy.
admission_control_remove_host_groupsRemove one or more host groups from an admission control policy.
admission_control_update_policy_precedenceUpdate admission control policy precedence.
admission_control_add_rule_group_custom_ruleAdd one or more custom Rego rules to a rule group in an admission control policy.
admission_control_remove_rule_group_custom_ruleDelete one or more custom Rego rules from all rule groups in an admission control policy.
admission_control_set_rule_group_precedenceChange precedence of rule groups within an admission control policy.
admission_control_replace_rule_group_selectorsReplace labels and/or namespaces of a rule group within an admission control policy.
admission_control_create_rule_groupsCreate one or more rule groups and add them to an existing admission control policy.
admission_control_update_rule_groupsUpdate a rule group.
admission_control_delete_rule_groupsDelete rule groups.
admission_control_query_policiesSearch admission control policies.
Operation IDDescription
PostAggregatesAlertsV1Retrieve aggregates for alerts across all CIDs.
PostAggregatesAlertsV2Retrieve aggregates for alerts across all CIDs.
PostCombinedAlertsV1Retrieves all Alerts that match a particular FQL filter. This API is intended for retrieval of large amounts of Alerts(>10k) using a pagination based on a after token.
PatchEntitiesAlertsV2Perform actions on alerts identified by alert ID(s) in request.
PatchEntitiesAlertsV3Perform actions on alerts identified by alert ID(s) in request.
PostEntitiesAlertsV1Retrieve all alerts given their IDs.
PostEntitiesAlertsV2Retrieve all alerts given their IDs.
GetQueriesAlertsV1Search for alert IDs that match a given query.
GetQueriesAlertsV2Search for alert IDs that match a given query.
Operation IDDescription
GetCombinedPluginConfigsQueries for config resources and returns details
ExecuteCommandProxyExecute a command and proxy the response directly.
ExecuteCommandExecute a command.
Operation IDDescription
ExecuteFunctionDataCountA selected list of queryLanguage count queries.
ExecuteFunctionsCountA selected list of queryLanguage count queries.
ExecuteFunctionDataQueryCountA selected list of queryLanguage count queries.
ExecuteFunctionsQueryCountA selected list of queryLanguage count queries.
ExecuteFunctionDataA selected list of queryLanguage queries.
ExecuteFunctionsOvertimeA selected list of queryLanguage overtime queries.
ExecuteFunctionsA selected list of queryLanguage services queries.
ExecuteFunctionDataQueryA selected list of queryLanguage queries.
ExecuteFunctionsQueryOvertimeA selected list of queryLanguage overtime queries.
ExecuteFunctionsQueryA selected list of queryLanguage services queries.
getServiceArtifactsRetrieve service artifacts.
UpsertBusinessApplicationsCreate or Update Business Applications
GetCloudSecurityIntegrationStateGet Cloud Security integration state.
SetCloudSecurityIntegrationStateSet Cloud Security integration state.
GetExecutorNodesGet all the relay nodes
UpdateExecutorNodeUpdate an existing relay node
CreateExecutorNodeCreate a new relay node
GetExecutorNodesMetadataGet metadata about all executor nodes.
DeleteExecutorNodeDelete a relay node
RetrieveRelayInstancesRetrieve the relay instances in CSV format.
GetIntegrationTasksGet all the integration tasks
CreateIntegrationTaskCreate new integration task.
GetIntegrationTasksMetadataGet metadata about all integration tasks.
GetIntegrationTasksV2Get all the integration tasks.
UpdateIntegrationTaskUpdate an existing integration task by its ID
DeleteIntegrationTaskDelete an existing integration task by its ID
RunIntegrationTaskRun an integration task by its ID
RunIntegrationTaskAdminRun an integration task by its ID with admin scope.
RunIntegrationTaskV2Run an integration task by its ID
GetIntegrationTypesGet all the integration types
GetIntegrationsGet a list of all the integrations
CreateIntegrationCreate a new integration
GetIntegrationsV2Get a list of all the integrations.
UpdateIntegrationUpdate an existing integration by its ID
DeleteIntegrationDelete an existing integration by its ID
ExecuteQueryExecute a query. The syntax used is identical to that of the query page.
ServiceNowGetDeploymentsRetrieve ServiceNow deployments
ServiceNowGetServicesRetrieve ServiceNow services.
GetServicesCountGet the total amount of existing services
GetServiceViolationTypesGet the different types of violation
GetTagsGet all the tags
UpsertTagsCreate new or update existing tag. You can update unique tags table or regular tags table
DeleteTagsRemove existing tags
DeleteGroup
GetGroupHierarchyGet group hierarchy
GetGroupV2Get group details
GetGroupsV2
GetIntegrationTasksAdminGet all the integration tasks, requires admin scope
GetUsersV2List users
PostGroupV2Create group
UpdateDefaultGroupUpdate default group
UpdateGroupUpdate group
Operation IDDescription
AggregateHuntingGuidesAggregate Hunting Guides
AggregateIntelligenceQueriesAggregate intelligence queries.
GetArchiveExportCreates an Archive Export.
GetHuntingGuidesRetrieves a list of Hunting Guides
GetIntelligenceQueriesRetrieves a list of Intelligence queries.
SearchHuntingGuidesSearch for Hunting Guides that match the provided conditions
SearchIntelligenceQueriesSearch intelligence queries that match the provided conditions.
Operation IDDescription
aggregates_file_details_post_v1Get file details aggregates as specified via json in the request body.
combined_file_details_get_v1Query file details
entities_files_upload_post_v1Upload file for case
entities_file_details_patch_v1Update file details
entities_file_details_get_v1Get file details by id
entities_files_bulk_download_post_v1Download multiple existing file from case as a ZIP
entities_files_download_get_v1Download existing file from case
entities_files_delete_v1Delete file details by id
queries_file_details_get_v1Query for ids of file details
entities_get_rtr_file_metadata_post_v1Get metadata for a file via RTR without retrieving it.
entities_retrieve_rtr_file_post_v1Retrieve a file from host using RTR and add it to a case.
entities_retrieve_rtr_recent_file_post_v1Retrieve a recently fetched RTR file and add it to a case.
aggregates_notification_groups_post_v1Get notification groups aggregations
aggregates_notification_groups_post_v2Get notification groups aggregations
aggregates_slas_post_v1Get SLA aggregations
aggregates_templates_post_v1Get templates aggregations
aggregates_access_tags_post_v1Get access tag aggregates.
entities_access_tags_get_v1Get access tags.
entities_notification_groups_get_v1Get notification groups by ID
entities_notification_groups_post_v1Create notification group
entities_notification_groups_patch_v1Update notification group
entities_notification_groups_delete_v1Delete notification groups by ID
entities_notification_groups_get_v2Get notification groups by ID
entities_notification_groups_post_v2Create notification group
entities_notification_groups_patch_v2Update notification group
entities_notification_groups_delete_v2Delete notification groups by ID
entities_fields_get_v1Get fields by ID
entities_slas_get_v1Get SLAs by ID
entities_slas_post_v1Create SLA
entities_slas_patch_v1Update SLA
entities_slas_delete_v1Delete SLAs
entities_template_snapshots_get_v1Get template snapshots
entities_templates_export_get_v1Export templates to files in a zip archive
entities_templates_import_post_v1Import a template from a file
entities_templates_get_v1Get templates by ID
entities_templates_post_v1Create template
entities_templates_patch_v1Update template
entities_templates_delete_v1Delete templates
queries_access_tags_get_v1Query access tags.
queries_fields_get_v1Query fields
queries_notification_groups_get_v1Query notification groups
queries_notification_groups_get_v2Query notification groups
queries_slas_get_v1Query SLAs
queries_template_snapshots_get_v1Query template snapshots
queries_templates_get_v1Query templates
entities_alert_evidence_post_v1Adds the given list of alert evidence to the specified case.
entities_case_tags_post_v1Adds the given list of tags to the specified case.
entities_case_tags_delete_v1Removes the specified tags from the specified case.
entities_cases_put_v2Creates the given Case
entities_cases_post_v2Retrieves all Cases given their IDs.
entities_cases_patch_v2Updates given fields on the specified case.
entities_event_evidence_post_v1Adds the given list of event evidence to the specified case.
queries_cases_get_v1Retrieves all Cases IDs that match a given query.
Operation IDDescription
cb_exclusions_get_v1Find all exclusion IDs matching the query with filter.
cb_exclusions_create_v1Create new Certificate Based Exclusions.
cb_exclusions_delete_v1Delete the exclusions by id.
cb_exclusions_update_v1Updates existing Certificate Based Exclusions.
certificates_get_v1Retrieves certificate signing information for a file.
cb_exclusions_query_v1Search for cert-based exclusions.
Operation IDDescription
cloud_registration_aws_create_accountCreates a new account in our system for a customer.
cloud_registration_aws_delete_accountDeletes an existing AWS account or organization in our system.
cloud_registration_aws_get_accountsRetrieve existing AWS accounts by account IDs.
cloud_registration_aws_query_accountsRetrieve existing AWS accounts by account IDs.
cloud_registration_aws_trigger_health_checkTrigger health check scan for AWS accounts.
cloud_registration_aws_update_accountPatches a existing account in our system for a customer.
cloud_registration_aws_validate_accountsValidates the AWS account registration status, and discover organization child accounts if organization is specified.
Operation IDDescription
cloud_registration_azure_create_registrationCreate an Azure registration for a tenant.
cloud_registration_azure_delete_legacy_subscriptionDelete existing legacy Azure subscriptions.
cloud_registration_azure_delete_registrationDeletes existing Azure registrations.
cloud_registration_azure_download_scriptRetrieve script to create resources.
cloud_registration_azure_get_registrationRetrieve existing Azure registration for a tenant.
cloud_registration_azure_trigger_health_checkTrigger health check scan for Azure registrations.
cloud_registration_azure_update_registrationUpdate an existing Azure registration for a tenant.
cloud_registration_azure_validate_registrationValidate an Azure registration by checking service principal, role assignments and deployment stack (if the deployment method is Bicep)
download_azure_scriptDownload Azure deployment script (Terraform or Bicep).
Operation IDDescription
QueryAWSAccountsSearch for provisioned AWS Accounts by providing a FQL filter and paging details. Returns a set of AWS accounts which match the filter criteria
GetAWSSettingsRetrieve a set of Global Settings which are applicable to all provisioned AWS accounts
GetAWSAccountsRetrieve a set of AWS Accounts by specifying their IDs
ProvisionAWSAccountsProvision AWS Accounts by specifying details about the accounts to provision
DeleteAWSAccountsDelete a set of AWS Accounts by specifying their IDs
UpdateAWSAccountsUpdate AWS Accounts by specifying the ID of the account and details to update
CreateOrUpdateAWSSettingsCreate or update Global Settings which are applicable to all provisioned AWS accounts
VerifyAWSAccountAccessPerforms an Access Verification check on the specified AWS Account IDs
QueryAWSAccountsForIDsSearch for provisioned AWS Accounts by providing a FQL filter and paging details. Returns a set of AWS account IDs which match the filter criteria
Operation IDDescription
cloud_registration_gcp_get_entitiesRetrieve all GCP entities (organizations, folders, projects) grouped by type with support for FQL filtering, sorting, and pagination.
cloud_registration_gcp_trigger_health_checkTrigger health check scan for GCP registrations
cloud_registration_gcp_get_registrationRetrieve a Google Cloud Registration.
cloud_registration_gcp_put_registrationCreates/Updates a Google Cloud Registration.
cloud_registration_gcp_create_registrationCreate a Google Cloud Registration.
cloud_registration_gcp_update_registrationUpdate a Google Cloud Registration.
cloud_registration_gcp_delete_registrationDeletes a Google Cloud Registration and returns the deleted registration in the response body.
Operation IDDescription
cloud_registration_gcp_get_entitiesRetrieve all GCP entities (organizations, folders, projects) grouped by type with support for FQL filtering, sorting, and pagination.
cloud_registration_gcp_trigger_health_checkTrigger health check scan for GCP registrations
cloud_registration_gcp_get_registrationRetrieve a Google Cloud Registration.
cloud_registration_gcp_put_registrationCreates/Updates a Google Cloud Registration.
cloud_registration_gcp_create_registrationCreate a Google Cloud Registration.
cloud_registration_gcp_delete_registrationDeletes a Google Cloud Registration and returns the deleted registration in the response body.
cloud_registration_gcp_update_registrationUpdate a Google Cloud Registration.
Operation IDDescription
cloud_security_registration_oci_get_accountRetrieve a list of OCI tenancies with support for FQL filtering, sorting, and pagination
cloud_security_registration_oci_rotate_keyRefresh key for the OCI Tenancy
cloud_security_registration_oci_validate_tenancyValidate the OCI account in CSPM for a provided CID. For internal clients only.
cloud_security_registration_oci_create_accountCreate OCI tenancy account in CSPM
cloud_security_registration_oci_delete_accountDelete an existing OCI tenancy in CSPM.
cloud_security_registration_oci_update_accountUpdate an existing OCI account.
cloud_security_registration_oci_download_scriptRetrieve script to create resources in tenancy OCID
Operation IDDescription
GetRuleInputSchemaGet rule input schema for given resource type.
ReplaceControlRulesAssign rules to a compliance control (full replace).
GetComplianceControlsGet compliance controls by ID.
CreateComplianceControlCreate a new custom compliance control.
UpdateComplianceControlUpdate a custom compliance control.
DeleteComplianceControlDelete custom compliance controls.
QueryComplianceControlsQuery for compliance controls by various parameters.
GetRuleGet a rule by id.
RenameSectionComplianceFrameworkRename a section in a custom compliance framework.
GetComplianceFrameworksGet compliance frameworks by ID.
CreateComplianceFrameworkCreate a new custom compliance framework.
UpdateComplianceFrameworkUpdate a custom compliance framework.
DeleteComplianceFrameworkDelete a custom compliance framework and all associated controls and rule assignments.
GetEnrichedAssetGet enriched assets that combine a primary resource with all its related resources.
GetEvaluationResultGet evaluation results based on the provided rule.
GetRuleOverrideGet a rule override by ID.
CreateRuleOverrideCreate a new rule override.
UpdateRuleOverrideUpdate a rule override.
DeleteRuleOverrideDelete a rule override.
CreateRuleMixin0Create a new rule.
UpdateRuleUpdate a rule.
DeleteRuleMixin0Delete a rule.
QueryComplianceFrameworksQuery for compliance frameworks by various parameters.
QueryRuleQuery for rules by various parameters.
GetSuppressionRulesGet Suppression Rules by ID.
CreateSuppressionRuleCreate a new suppression rule.
UpdateSuppressionRuleUpdate a suppression rule.
DeleteSuppressionRulesDelete Suppression Rules by ID.
QuerySuppressionRulesQuery suppression rules with filtering, sorting and pagination.
Operation IDDescription
combined_cloud_risksGet cloud risks with full details based on filters and sort criteria.
ListCloudGroupsExternalQuery Cloud Groups and return entities with full details.
ListCloudGroupsByIDExternalRetrieve Cloud Groups by their UUIDs.
CreateCloudGroupExternalCreate a new Cloud Group with specified properties and selectors.
UpdateCloudGroupExternalUpdate an existing Cloud Group’s properties.
DeleteCloudGroupsExternalDelete Cloud Groups in batch by their UUIDs.
ListCloudGroupIDsExternalQuery Cloud Groups and return only their IDs.
Operation IDDescription
cloud_security_assets_combined_application_findingsGet findings for an application resource with pagination.
cloud_security_assets_combined_compliance_by_accountGet combined compliance by account.
cloud_security_assets_entities_getGets raw resources based on the provided IDs param. Maximum of 100 resources can be requested with this method. Use POST method with same path if more are required.
cloud_security_assets_queriesQuery cloud security assets.
Operation IDDescription
cloud_compliance_framework_posture_summariesGet sections and requirements with scores for benchmarks.
cloud_compliance_rule_posture_summariesGet compliance score and counts for rules.
Operation IDDescription
cspm_evaluations_combined_iom_by_ruleReturn IOMs grouped by rule.
cspm_evaluations_iom_entitiesGets IOMs based on the provided IDs
cspm_evaluations_iom_queriesGets a list of IOM IDs for the given parameters, filters and sort criteria.
Operation IDDescription
cloud_security_timeline_risks_enrichedReturns the enriched asset timeline. Rate limited to 500 requests per minute per CID. Exceeding this limit returns HTTP 429 (Too Many Requests).
Operation IDDescription
CombinedDetectionsSearch IaC Detections using a query in Falcon Query Language.
ReadDeploymentsCombinedSearch for snapshot jobs identified by the provided filter.
RegisterCspmSnapshotAccountRegister customer cloud account for snapshot scanning.
ReadDeploymentsEntitiesRetrieve snapshot jobs identified by the provided IDs.
CreateDeploymentEntityLaunch a snapshot scan for a given cloud asset.
GetCredentialsIACGets the registry credentials (external endpoint).
GetScanReportRetrieve the scan report for an instance.
GetCredentialsMixin0Gets the registry credentials.
Operation IDDescription
getCombinedAssessmentsQuerySearch for assessments in your environment by providing an FQL filter and paging details. Returns a set of HostFinding entities which match the filter criteria
getRuleDetailsGet rules details for provided one or more rule IDs
Operation IDDescription
getEvaluationLogicMixin0Get details on evaluation logic items by providing one or more finding IDs.
Operation IDDescription
ReadContainerAlertsCountBySeverityGet Container Alert counts by severity.
ReadContainerAlertsCountSearch Container Alerts by the provided search criteria.
SearchAndReadContainerAlertsSearch Container Alerts by the provided search criteria.
Operation IDDescription
GetRuntimeDetectionsCombinedV2Retrieve image assessment detections identified by the provided filter criteria.
ReadDetectionsCountBySeverityAggregate counts of detections by severity.
ReadDetectionsCountByTypeAggregate counts of detections by detection type.
ReadDetectionsCountAggregate count of detections.
ReadCombinedDetectionsRetrieve image assessment detections identified by the provided filter criteria.
ReadDetectionsRetrieve image assessment detection entities identified by the provided filter criteria.
SearchDetectionsRetrieve image assessment detection entities identified by the provided filter criteria.
Operation IDDescription
extAggregateClusterAssessmentsGet the assessments for each cluster.
extAggregateImageAssessmentsGet the assessments for each image.
extAggregateRulesAssessmentsGet the assessments for each rule.
extAggregateFailedContainersByRulesPathGet the containers grouped into rules on which they failed.
extAggregateFailedContainersCountBySeverityGet the failed containers count grouped into severity levels.
extAggregateFailedImagesByRulesPathGet the images grouped into rules on which they failed.
extAggregateFailedImagesCountBySeverityGet the failed images count grouped into severity levels.
extAggregateFailedRulesByClustersGet the failed rules for each cluster grouped into severity levels.
extAggregateFailedRulesByImagesGet images with failed rules, rule count grouped by severity for each image.
extAggregateFailedRulesCountBySeverityGet the failed rules count grouped into severity levels.
extAggregateRulesByStatusGet the rules grouped by their statuses.
Operation IDDescription
AggregateImageAssessmentHistoryImage assessment history
AggregateImageCountByBaseOSAggregate count of images grouped by Base OS distribution
AggregateImageCountByStateAggregate count of images grouped by state
AggregateImageCountAggregate count of images
CombinedBaseImagesRetrieve base images identified by the provided filter criteria
GetCombinedImagesGet image assessment results by providing an FQL filter and paging details
CombinedImageByVulnerabilityCountRetrieve top x images with the most vulnerabilities
CombinedImageDetailRetrieve image entities identified by the provided filter criteria
ReadCombinedImagesExportRetrieve images with an option to expand aggregated vulnerabilities/detections
CombinedImageIssuesSummaryRetrieve image issues summary such as Image detections, Runtime detections, Policies, vulnerabilities
CombinedImageVulnerabilitySummaryaggregates information about vulnerabilities for an image
CreateBaseImagesEntitiesCreates base images using the provided details
DeleteBaseImagesDelete base images by base image UUID
Operation IDDescription
ReadPackagesByImageCountRetrieves the N most frequently used packages across images.
ReadPackagesCountByZeroDayRetrieve packages count affected by zero day vulnerabilities.
ReadPackagesByFixableVulnCountRetrieve top x app packages with the most fixable vulnerabilities.
ReadPackagesByVulnCountRetrieve top x packages with the most vulnerabilities.
ReadPackagesCombinedExportRetrieve packages identified by the provided filter criteria for the purpose of export.
ReadPackagesCombinedRetrieve packages identified by the provided filter criteria.
ReadPackagesCombinedV2Retrieve packages identified by the provided filter criteria.
Operation IDDescription
ReadVulnerabilityCountByActivelyExploitedAggregate count of vulnerabilities grouped by actively exploited
ReadVulnerabilityCountByCPSRatingAggregate count of vulnerabilities grouped by csp_rating
ReadVulnerabilityCountByCVSSScoreAggregate count of vulnerabilities grouped by cvss score
ReadVulnerabilityCountBySeverityAggregate count of vulnerabilities grouped by severity
ReadVulnerabilityCountAggregate count of vulnerabilities
ReadVulnerabilitiesByImageCountRetrieve top x vulnerabilities with the most impacted images
ReadVulnerabilitiesPublicationDateRetrieve top x vulnerabilities with the most recent publication date
ReadCombinedVulnerabilitiesDetailsRetrieve vulnerability details related to an image
ReadCombinedVulnerabilitiesInfoRetrieve vulnerability and package related info for this customer
ReadCombinedVulnerabilitiesRetrieve vulnerability and aggregate data filtered by the provided FQL
Operation IDDescription
queryCombinedContentUpdatePolicyMembersSearch for members of a Content Update Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria.
queryCombinedContentUpdatePoliciesSearch for Content Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Content Update Policies which match the filter criteria.
performContentUpdatePoliciesActionPerform the specified action on the Content Update Policies specified in the request.
setContentUpdatePoliciesPrecedenceSets the precedence of Content Update Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies when updating precedence.
getContentUpdatePoliciesRetrieve a set of Content Update Policies by specifying their IDs.
createContentUpdatePoliciesCreate Content Update Policies by specifying details about the policy to create.
deleteContentUpdatePoliciesDelete a set of Content Update Policies by specifying their IDs.
updateContentUpdatePoliciesUpdate Content Update Policies by specifying the ID of the policy and details to update.
queryContentUpdatePolicyMembersSearch for members of a Content Update Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria.
queryPinnableContentVersionsSearch for content versions available for pinning given the category.
queryContentUpdatePoliciesSearch for Content Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Content Update Policy IDs which match the filter criteria.
Operation IDDescription
aggregates_rule_versions_post_v1Get rules aggregates as specified via json in the request body.
combined_rules_get_v1Find all rules matching the query and filter.
combined_rules_get_v2Find all rules matching the query and filter.
entities_latest_rules_get_v1Retrieve latest rule versions by rule IDs.
entities_rule_versions_export_post_v1Export rule versions.
entities_rule_versions_import_post_v1Import rule versions.
entities_rule_versions_publish_patch_v1Publish existing rule version.
entities_rule_versions_delete_v1Delete versions by IDs.
entities_rules_get_v1Retrieve rules by IDs.
entities_rules_post_v1Create a correlation rule.
entities_rules_delete_v1Delete rules by IDs.
entities_rules_patch_v1Update a correlation rule.
entities_rules_get_v2Retrieve rule versions by IDs.
queries_rules_get_v1Find all rule IDs matching the query and filter.
queries_rules_get_v2Find all rule version IDs matching the query and filter.
queries_templates_get_v1Mixin0Search rule template IDs matching the filter.
entities_templates_rules_post_v1Create rule from template.
entities_templates_get_v1Mixin0Retrieve rule templates by IDs.
Operation IDDescription
entities_rules_ownership_put_v1Change the owner of an existing Correlation Rule
Operation IDDescription
GetCSPMAwsAccountReturns information about the current status of an AWS account.
CreateCSPMAwsAccountCreates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
DeleteCSPMAwsAccountDeletes an existing AWS account or organization in our system.
PatchCSPMAwsAccountPatches a existing account in our system for a customer.
GetCSPMAwsConsoleSetupURLsReturn a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetCSPMAwsAccountScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetCSPMAzureAccountReturn information about Azure account registration
CreateCSPMAzureAccountCreates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
DeleteCSPMAzureAccountDeletes an Azure subscription from the system.
UpdateCSPMAzureAccountClientIDUpdate an Azure service account in our system by with the user-created client_id created with the public key we’ve provided
UpdateCSPMAzureTenantDefaultSubscriptionIDUpdate an Azure default subscription_id in our system for given tenant_id
AzureDownloadCertificateReturns JSON object(s) that contain the base64 encoded certificate for a service principal.
AzureRefreshCertificateRefresh certificate and returns JSON object(s) that contain the base64 encoded certificate for a service principal.
GetCSPMAzureUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment
GetBehaviorDetectionsRetrieve a list of detected behaviors.
GetConfigurationDetectionsRetrieve a list of active misconfigurations.
GetConfigurationDetectionEntitiesGet misconfigurations based on the ID - including custom policy detections in addition to default policy detections.
GetConfigurationDetectionIDsV2Get a list of active misconfiguration ids - including custom policy detections in addition to default policy detections.
GetCSPMPolicyGiven a policy ID, returns detailed policy information.
GetCSPMPoliciesDetailsGiven an array of policy IDs, returns detailed policies information.
GetCSPMPolicySettingsReturns information about current policy settings.
UpdateCSPMPolicySettingsUpdates a policy setting - can be used to override policy severity or to disable a policy entirely.
GetCSPMScanScheduleReturns scan schedule configuration for one or more cloud platforms.
UpdateCSPMScanScheduleUpdates scan schedule configuration for one or more cloud platforms.
GetCSPMAzureManagementGroupReturn information about Azure management group registration
DeleteCSPMAzureManagementGroupDeletes Azure management groups from the system.
CreateCSPMAzureManagementGroupCreates a new management group in our system for a customer.
CreateCSPMGCPAccountCreates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
DeleteCSPMGCPAccountDeletes a GCP account from the system.
UpdateCSPMGCPAccountPatches a existing account in our system for a customer.
ConnectCSPMGCPAccountCreates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id
GetCSPMGCPServiceAccountsExtReturns the service account id and client email for external clients.
UpdateCSPMGCPServiceAccountsExtUpdates an existing GCP service account.
GetCSPMGCPUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment
GetCSPMGCPValidateAccountsExtRun a synchronous health check.
ValidateCSPMGCPServiceAccountExtValidates credentials for a service account
GetCSPMCGPAccountReturns information about the current status of an GCP account.
UpdateCSPMAzureAccountPatches a existing account in our system for a customer.
getCloudEventIDsGet list of related cloud event LogScale IDs for a given IOA
Operation IDDescription
get_patternsGet pattern severities by ID.
get_platformsMixin0Get platforms by ID.
get_rule_groupsMixin0Get rule groups by ID.
create_rule_groupMixin0Create a rule group for a platform with a name and an optional description. Returns the rule group.
delete_rule_groupsMixin0Delete rule groups by ID.
update_rule_groupMixin0Update a rule group. The following properties can be modified: name, description, enabled.
get_rule_typesGet rule types by ID.
get_rules_getGet rules by ID and optionally version in the following format: ID[:version].
get_rulesMixin0Get rules by ID and optionally version in the following format: ID[:version]. The max number of IDs is constrained by URL size.
create_ruleCreate a rule within a rule group. Returns the rule.
delete_rulesDelete rules from a rule group by ID.
update_rulesUpdate rules within a rule group. Return the updated rules.
update_rules_v2Update name, description, enabled or field_values for individual rules within a rule group.
validateValidates field values and checks for matches if a test string is provided.
query_patternsGet all pattern severity IDs.
query_platformsMixin0Get all platform IDs.
query_rule_groups_fullFind all rule groups matching the query with optional filter.
query_rule_groupsMixin0Finds all rule group IDs matching the query with optional filter.
query_rule_typesGet all rule type IDs.
query_rulesMixin0Finds all rule IDs matching the query with optional filter.
Operation IDDescription
ListCollectionsList available collection names in alphabetical order.
DescribeCollectionsFetch metadata about one or more existing collections.
DescribeCollectionFetch metadata about an existing collection.
ListObjectsList the object keys in the specified collection in alphabetical order.
SearchObjectsSearch for objects that match the specified filter criteria (returns metadata, not actual objects).
GetObjectGet the bytes for the specified object.
PutObjectPut the specified new object at the given key or overwrite an existing object at the given key.
DeleteObjectDelete the specified object.
GetObjectMetadataGet the metadata for the specified object.
ListSchemasGet the list of schemas for the requested collection in reverse version order (latest first).
GetSchemaGet the bytes of the specified schema of the requested collection.
GetSchemaMetadataGet the metadata for the specified schema of the requested collection.
ListObjectsByVersionList the object keys in the specified collection in alphabetical order.
SearchObjectsByVersionSearch for objects that match the specified filter criteria (returns metadata, not actual objects).
GetVersionedObjectGet the bytes for the specified object.
PutObjectByVersionPut the specified new object at the given key or overwrite an existing object at the given key.
DeleteVersionedObjectDelete the specified versioned object.
GetVersionedObjectMetadataGet the metadata for the specified object.
Operation IDDescription
GetD4CAwsAccountReturns information about the current status of an AWS account.
CreateD4CAwsAccountCreates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
DeleteD4CAwsAccountDeletes an existing AWS account or organization in our system.
GetD4CAwsConsoleSetupURLsReturn a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
GetD4CAWSAccountScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
GetDiscoverCloudAzureAccountReturn information about Azure account registration.
CreateDiscoverCloudAzureAccountCreates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
UpdateDiscoverCloudAzureAccountClientIDUpdate an Azure service account in our system by with the user-created client_id created with the public key we’ve provided.
GetDiscoverCloudAzureUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment.
GetDiscoverCloudAzureUserScriptsReturn a script for customer to run in their cloud environment to grant us access to their Azure environment.
DiscoverCloudAzureDownloadCertificateReturns JSON object(s) that contain the base64 encoded certificate for a service principal.
GetDiscoverCloudAzureTenantIDsReturn all available Azure tenant IDs.
GetHorizonD4CScriptsReturns static install scripts for Horizon.
DeleteD4CGCPAccountDeletes a GCP account from the system.
ConnectD4CGCPAccountCreates a new GCP account with newly-uploaded service account or connects with existing service account.
GetD4CGCPServiceAccountsExtReturns the service account id and client email for external clients.
UpdateD4CGCPServiceAccountsExtUpdates an existing GCP service account.
GetD4CGCPUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment.
CreateD4CGCPAccountCreates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
GetCSPMGCPUserScriptsAttachmentReturn a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment.
GetD4CCGPAccountReturns information about the current status of an GCP account.
GetD4CGCPUserScriptsReturn a script for customer to run in their cloud environment to grant us access to their GCP environment.
Operation IDDescription
entities_classification_get_v2Gets the classifications that match the provided ids
entities_classification_post_v2Create classifications
entities_classification_patch_v2Update classifications
entities_classification_delete_v2Deletes classifications that match the provided ids
entities_cloud_application_getGet a particular cloud-application
entities_cloud_application_createPersist the given cloud application for the provided entity instance
entities_cloud_application_patchUpdate a cloud application.
entities_cloud_application_deleteDelete cloud application.
entities_content_pattern_getGet a particular content-pattern(s).
entities_content_pattern_createPersist the given content pattern for the provided entity instance.
entities_content_pattern_patchUpdate a content pattern.
entities_content_pattern_deleteDelete content pattern.
entities_policy_precedence_post_v1Update Policy Precedence.
entities_enterprise_account_getGet a particular enterprise-account(s).
entities_enterprise_account_createPersist the given enterprise account for the provided entity instance.
entities_enterprise_account_patchUpdate a enterprise account.
entities_enterprise_account_deleteDelete enterprise account.
entities_file_type_getGet a particular file-type.
entities_sensitivity_label_get_v2Get sensitivity label matching the IDs (V2).
entities_sensitivity_label_create_v2Create new sensitivity label (V2).
entities_sensitivity_label_delete_v2Delete sensitivity labels matching the IDs (V2).
entities_local_application_group_getGet particular local application groups.
entities_local_application_group_createPersist the given local application group for the provided entity instance.
entities_local_application_group_patchUpdate a local application group.
entities_local_application_group_deleteSoft Delete local application. The application won’t be visible anymore, but will still be in the database.
entities_local_application_getGet a particular local application.
entities_local_application_createPersist the given local application for the provided entity instance.
entities_local_application_patchUpdate a local application.
entities_local_application_deleteSoft Delete local application. The application wont be visible anymore, but will still be in the database.
entities_policy_get_v2Get policies that match the provided ids.
entities_policy_post_v2Create policies.
entities_policy_patch_v2Update policies.
entities_policy_delete_v2Delete policies that match the provided ids.
entities_web_location_get_v2Get web-location entities matching the provided ID(s).
entities_web_location_create_v2Persist the given web-locations.
entities_web_location_patch_v2Update a web-location.
entities_web_location_delete_v2Delete web-location.
queries_classification_get_v2Search for classifications that match the provided criteria.
queries_cloud_application_get_v2Get all cloud-application IDs matching the query with filter.
queries_content_pattern_get_v2Get all content-pattern IDs matching the query with filter.
queries_enterprise_account_get_v2Get all enterprise-account IDs matching the query with filter.
queries_file_type_get_v2Get all file-type IDs matching the query with filter.
queries_sensitivity_label_get_v2Get all sensitivity label IDs matching the query with filter.
queries_local_application_group_getGet all local application group IDs matching the query with filter.
queries_local_application_getGet all local-application IDs matching the query with filter.
queries_policy_get_v2Search for policies that match the provided criteria.
queries_web_location_get_v2Get web-location IDs matching the query with filter.
Operation IDDescription
GetDeliverySettingsGet Delivery Settings.
PostDeliverySettingsCreate Delivery Settings.
Operation IDDescription
CombinedReleaseNotesV1Queries for releases resources and returns details.
CombinedReleasesV1Mixin0Queries for releases resources and returns details.
GetDeploymentsExternalV1Get deployment resources by IDs.
GetEntityIDsByQueryPOSTReturns the release notes for the IDs in the request.
GetEntityIDsByQueryPOSTV2Get entity IDs by query (v2).
QueryReleaseNotesV1Queries for release-notes resources and returns IDs.
Operation IDDescription
GetAggregateDetectsGet detect aggregates as specified via json in request body.
UpdateDetectsByIdsV2Modify the state, assignee, and visibility of detections.
GetDetectSummariesView information about detections.
QueryDetectsSearch for detection IDs that match a given query.
Operation IDDescription
entities_states_v1Retrieve the host content state for a number of ids between 1 and 100.
queries_states_v1Query for the content state of the host.
Operation IDDescription
queryCombinedDeviceControlPolicyMembersSearch for members of a Device Control Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria.
queryCombinedDeviceControlPoliciesSearch for Device Control Policies in your environment by providing a FQL filter and paging details. Returns a set of Device Control Policies which match the filter criteria.
getDefaultDeviceControlPoliciesRetrieve the configuration for the Default Device Control Policy.
updateDefaultDeviceControlPoliciesUpdate the configuration for the Default Device Control Policy.
performDeviceControlPoliciesActionPerform the specified action on the Device Control Policies specified in the request.
getDefaultDeviceControlSettingsGet default device control settings (USB and Bluetooth).
updateDefaultDeviceControlSettingsUpdate the configuration for Default Device Control Settings.
setDeviceControlPoliciesPrecedenceSets the precedence of Device Control Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence.
getDeviceControlPoliciesRetrieve a set of Device Control Policies by specifying their IDs.
getDeviceControlPoliciesV2Get device control policies for the given filter criteria. Supports USB and Bluetooth.
createDeviceControlPoliciesCreate Device Control Policies by specifying details about the policy to create.
postDeviceControlPoliciesV2Create Device Control Policies by specifying details about the policy to create.
deleteDeviceControlPoliciesDelete a set of Device Control Policies by specifying their IDs.
patchDeviceControlPoliciesClassesV1Update device control policy’s classes (USB and Bluetooth).
updateDeviceControlPoliciesUpdate Device Control Policies by specifying the ID of the policy and details to update.
patchDeviceControlPoliciesV2Update Device Control Policies by specifying the ID of the policy and details to update.
queryDeviceControlPolicyMembersSearch for members of a Device Control Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria.
queryDeviceControlPoliciesSearch for Device Control Policies in your environment by providing a FQL filter and paging details. Returns a set of Device Control Policy IDs which match the filter criteria.
Operation IDDescription
combined_applicationsSearch for applications in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns details on applications which match the filter criteria.
combined_hostsSearch for assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns details on assets which match the filter criteria.
get_accountsGet details on accounts by providing one or more IDs.
get_applicationsGet details on applications by providing one or more IDs.
get_hostsGet details on assets by providing one or more IDs.
get_iot_hostsGet details on IoT assets by providing one or more IDs.
get_loginsGet details on logins by providing one or more IDs.
query_accountsSearch for accounts in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_applicationsSearch for applications in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of application IDs which match the filter criteria.
query_hostsSearch for assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_iot_hostsSearch for IoT assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_iot_hostsV2Search for IoT assets in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
query_loginsSearch for logins in your environment by providing a FQL (Falcon Query Language) filter and paging details. Returns a set of asset IDs which match the filter criteria.
Operation IDDescription
DownloadFileGets pre-signed URL for the file.
EnumerateFileEnumerates a list of files available for CID.
FetchFilesDownloadInfoGet files info and pre-signed download URLs
FetchFilesDownloadInfoV2Get cloud security tools info and pre-signed download URLs
Operation IDDescription
GetDriftIndicatorsValuesByDateReturns the count of Drift Indicators by the date. by default it’s for 7 days.
ReadDriftIndicatorsCountReturns the total count of Drift indicators over a time period
SearchAndReadDriftIndicatorEntitiesRetrieve Drift Indicators by the provided search criteria
ReadDriftIndicatorEntitiesRetrieve Drift Indicator entities identified by the provided IDs
SearchDriftIndicatorsRetrieve all drift indicators that match the given query
Operation IDDescription
refreshActiveStreamSessionRefresh an active event stream. Use the URL shown in a listAvailableStreamsOAuth2 response.
listAvailableStreamsOAuth2Discover all event streams in your environment
Operation IDDescription
aggregate_external_assetsReturns external assets aggregates.
combined_ecosystem_subsidiariesRetrieves a list of ecosystem subsidiaries with their detailed information.
blob_download_external_assetsDownload the entire contents of the blob. The relative link to this endpoint is returned in the GET /entities/external-assets/v1 request.
blob_preview_external_assetsDownload a preview of the blob. The relative link to this endpoint is returned in the GET /entities/external-assets/v1 request.
get_ecosystem_subsidiariesRetrieves detailed information about ecosystem subsidiaries by ID.
post_external_assets_inventory_v1Add external assets for external asset scanning.
get_external_assetsGet details on external assets by providing one or more IDs.
delete_external_assetsDelete multiple external assets.
patch_external_assetsUpdate the details of external assets.
query_ecosystem_subsidiariesRetrieves a list of IDs for ecosystem subsidiaries.
query_external_assetsGet a list of external asset IDs that match the provided filter conditions. Use these IDs with the /entities/external-assets/v1 endpoints
query_external_assets_v2Query external assets (v2).
Operation IDDescription
ReadRequestBodyRetrieve a large request body, such as a file, that has spilled into object storage.
Operation IDDescription
AggregateAlertsRetrieve aggregate alerts values based on the matched filter
AggregateAllowListRetrieve aggregate allowlist ticket values based on the matched filter
AggregateBlockListRetrieve aggregate blocklist ticket values based on the matched filter
AggregateDeviceCountCollectionRetrieve aggregate host/devices count based on the matched filter
AggregateEscalationsRetrieve aggregate escalation ticket values based on the matched filter
AggregateFCIncidentsRetrieve aggregate incident values based on the matched filter
AggregateRemediationsRetrieve aggregate remediation ticket values based on the matched filter
AggregatePreventionPolicyRetrieve aggregate prevention policy values based on the matched filter
AggregateSensorUpdatePolicyRetrieve aggregate sensor update policy values based on the matched filter
AggregateSupportIssuesRetrieve aggregate support issue values based on the matched filter
AggregateTotalDeviceCountsRetrieve aggregate total host/devices based on the matched filter
QueryAlertIdsByFilterRetrieve Alert IDs that match the provided FQL filter criteria with scrolling enabled
QueryAlertIdsByFilterV2Retrieve Alert IDs that match the provided FQL filter criteria with scrolling enabled
QueryAllowListFilterRetrieve allowlist tickets that match the provided filter criteria with scrolling enabled
QueryBlockListFilterRetrieve block listtickets that match the provided filter criteria with scrolling enabled
GetDeviceCountCollectionQueriesByFilterRetrieve device count collection Ids that match the provided FQL filter, criteria with scrolling enabled
QueryEscalationsFilterRetrieve escalation tickets that match the provided filter criteria with scrolling enabled
QueryIncidentIdsByFilterRetrieve incidents that match the provided filter criteria with scrolling enabled
QueryRemediationsFilterRetrieve remediation tickets that match the provided filter criteria with scrolling enabled
Operation IDDescription
DownloadExportFileDownload an export file.
ReadExportJobsRead export jobs entities.
LaunchExportJobLaunch an export job of a Container Security resource. Maximum of 1 job in progress per resource.
QueryExportJobsQuery export jobs entities.
PolicyChecksPerform policy checks against container configurations.
GetReportByReferenceRetrieve a report by its reference.
GetReportByScanIDRetrieve a report by scan ID.
GetCombinedImagesRetrieve registry entities identified by the customer ID.
GetCredentialsGets the registry credentials.
GetImageAssessmentReportRetrieve an assessment report for an image by specifying repository and tag.
HeadImageScanInventoryGet headers for POST request for image scan inventory.
DeleteImageDetailsDelete image details from the CrowdStrike registry.
ImageMatchesPolicyCheck if an image matches a policy by specifying repository and tag.
PostImageScanInventoryPost image scan inventory.
ReadImageVulnerabilitiesRetrieve an assessment report for an image by specifying repository and tag.
ReadRegistryEntitiesRetrieve registry entities associated with the client ID.
ReadRegistryEntitiesByUUIDRetrieve registry entities associated with a specific UUID.
DeleteRegistryEntitiesDelete registry entities by UUID.
CreateRegistryEntitiesCreate registry entities using the provided detail.
UpdateRegistryEntitiesUpdate the registry entity, as identified by the entity UUID, using the provided details.
Operation IDDescription
GetArtifactsDownload IOC packs, PCAP files, and other analysis artifacts.
GetMemoryDumpExtractedStringsGet extracted strings from a memory dump.
GetMemoryDumpHexDumpGet the hex view of a memory dump.
GetMemoryDumpGet memory dump content, as a binary.
GetSummaryReportsGet a short summary version of a sandbox report.
GetReportsGet a full sandbox report.
DeleteReportDelete report based on the report ID. Operation can be checked for success by polling for the report ID on the report-summaries endpoint.
GetSubmissionsCheck the status of a sandbox analysis. Time required for analysis varies but is usually less than 15 minutes.
SubmitSubmit an uploaded file or a URL for sandbox analysis. Time required for analysis varies but is usually less than 15 minutes.
QueryReportsFind sandbox reports by providing a FQL filter and paging details. Returns a set of report IDs that match your criteria.
QuerySubmissionsFind submission IDs for uploaded files by providing a FQL filter and paging details. Returns a set of submission IDs that match your criteria.
GetSampleV2Retrieves the file associated with the given ID (SHA256)
UploadSampleV2Upload a file for sandbox analysis. After uploading, use /falconx/entities/submissions/v1 to start analyzing the file.
DeleteSampleV2Removes a sample, including file, meta and submissions from the collection
QuerySampleV1Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200
Operation IDDescription
fdrschema_combined_event_getFetches the combined schema.
fdrschema_entities_event_getFetch event schema by ID.
fdrschema_queries_event_getGet list of event IDs given a particular query.
fdrschema_entities_field_getFetch field schema by ID.
fdrschema_queries_field_getGet list of field IDs given a particular query.
Operation IDDescription
post_federated_connections_configCreate configuration for a federated connection
delete_federated_connections_configDelete configuration for a federated connection
patch_federated_connections_configUpdate configuration for a federated connection
Operation IDDescription
getActionsMixin0Retrieves the processing results for one or more actions.
startActionsInitiates the specified action on the provided change IDs.
getContentsRetrieves the content captured for the provided change ID.
getChangesRetrieve information on changes.
updatePolicyHostGroupsManage host groups assigned to a policy.
updatePolicyPrecedenceUpdates the policy precedence for all policies of a specific type.
updatePolicyRuleGroupsManage the rule groups assigned to the policy or set the rule group precedence for all rule groups within the policy.
getPoliciesRetrieves the configuration for 1 or more policies.
createPoliciesCreates a new policy of the specified type. New policies are always added at the end of the precedence list for the provided policy type.
deletePoliciesDeletes 1 or more policies.
updatePoliciesUpdates the general information of the provided policy.
getScheduledExclusionsRetrieves the configuration of 1 or more scheduled exclusions from the provided policy id.
createScheduledExclusionsCreates a new scheduled exclusion configuration for the provided policy id.
deleteScheduledExclusionsDeletes 1 or more scheduled exclusions from the provided policy id.
updateScheduledExclusionsUpdates the provided scheduled exclusion configuration within the provided policy.
updateRuleGroupPrecedenceUpdates the rule precedence for all rules in the identified rule group.
getRulesRetrieves the configuration for 1 or more rules.
createRulesCreates a new rule configuration within the specified rule group.
deleteRulesDeletes 1 or more rules from the specified rule group.
updateRulesUpdates the provided rule configuration within the specified rule group.
getRuleGroupsRetrieves the rule group details for 1 or more rule groups.
createRuleGroupsCreates a new rule group of the specified type.
deleteRuleGroupsDeletes 1 or more rule groups.
updateRuleGroupsUpdates the provided rule group.
signalChangesExternalInitiates workflows for the provided change IDs.
queryActionsMixin0Returns one or more action IDs.
queryChangesReturns 1 or more change ids.
highVolumeQueryChangesReturns 1 or more change ids.
queryPoliciesRetrieve the ids of all policies that are assigned the provided policy type.
queryScheduledExclusionsRetrieve the ids of all scheduled exclusions contained within the provided policy id.
queryRuleGroupsRetrieve the ids of all rule groups that are of the provided rule group type.
Operation IDDescription
aggregate_eventsAggregate events for customer
aggregate_policy_rulesAggregate rules within a policy for customer
aggregate_rule_groupsAggregate rule groups for customer
aggregate_rulesAggregate rules for customer
get_eventsGet events entities by ID and optionally version
get_firewall_fieldsGet the firewall field specifications by ID
get_network_locations_detailsGet network locations entities by ID
update_network_locations_metadataUpdates the network locations metadata such as polling_intervals for the cid
update_network_locations_precedenceUpdates the network locations precedence according to the list of ids provided.
get_network_locationsGet a summary of network locations entities by ID
upsert_network_locationsUpdates the network locations provided, and return the ID.
create_network_locationsCreate new network locations provided, and return the ID.
delete_network_locationsDelete network location entities by ID.
update_network_locationsUpdates the network locations provided, and return the ID.
get_platformsGet platforms by ID, e.g., windows or mac or droid
get_policy_containersGet policy container entities by policy ID
update_policy_container_v1Update an identified policy container
update_policy_containerUpdate an identified policy container
get_rule_groupsGet rule group entities by ID. These groups do not contain their rule entites, just the rule IDs in precedence order.
create_rule_groupCreate new rule group on a platform for a customer with a name and description, and return the ID
delete_rule_groupsDelete rule group entities by ID
update_rule_groupUpdate name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
create_rule_group_validationValidates the request of creating a new rule group on a platform for a customer with a name and description
update_rule_group_validationValidates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules
get_rulesGet rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string)
validate_filepath_patternValidates that the test pattern matches the executable filepath glob pattern.
query_eventsFind all event IDs matching the query with filter
query_firewall_fieldsGet the firewall field specification IDs for the provided platform
query_network_locationsGet a list of network location IDs
query_platformsGet the list of platform names
query_policy_rulesFind all firewall rule IDs matching the query with filter, and return them in precedence order
query_rule_groupsFind all rule group IDs matching the query with filter
query_rulesFind all rule IDs matching the query with filter
Operation IDDescription
queryCombinedFirewallPolicyMembersSearch for members of a Firewall Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedFirewallPoliciesSearch for Firewall Policies in your environment by providing a FQL filter and paging details. Returns a set of Firewall Policies which match the filter criteria
performFirewallPoliciesActionPerform the specified action on the Firewall Policies specified in the request
setFirewallPoliciesPrecedenceSets the precedence of Firewall Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence
getFirewallPoliciesRetrieve a set of Firewall Policies by specifying their IDs
createFirewallPoliciesCreate Firewall Policies by specifying details about the policy to create
deleteFirewallPoliciesDelete a set of Firewall Policies by specifying their IDs
updateFirewallPoliciesUpdate Firewall Policies by specifying the ID of the policy and details to update
queryFirewallPolicyMembersSearch for members of a Firewall Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
queryFirewallPoliciesSearch for Firewall Policies in your environment by providing a FQL filter and paging details. Returns a set of Firewall Policy IDs which match the filter criteria
Operation IDDescription
ListReposV1Lists available repositories and views
IngestDataAsyncV1Ingest data into the application repository asynchronously
IngestDataV1Ingest data into the application repository
CreateFileV1Creates a lookup file.
UpdateFileV1Updates a lookup file.
CreateSavedSearchesDynamicExecuteV1Execute a dynamic saved search
GetSavedSearchesExecuteV1Get the results of a saved search
CreateSavedSearchesExecuteV1Execute a saved search
CreateSavedSearchesIngestV1Populate a saved search
GetSavedSearchesJobResultsDownloadV1Get the results of a saved search as a file
ListViewV1List views
Operation IDDescription
queryCombinedGroupMembersSearch for members of a Host Group in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedHostGroupsSearch for Host Groups in your environment by providing a FQL filter and paging details. Returns a set of Host Groups which match the filter criteria
performGroupActionPerform the specified action on the Host Groups specified in the request
getHostGroupsRetrieve a set of Host Groups by specifying their IDs
createHostGroupsCreate Host Groups by specifying details about the group to create
deleteHostGroupsDelete a set of Host Groups by specifying their IDs
updateHostGroupsUpdate Host Groups by specifying the ID of the group and details to update
queryGroupMembersSearch for members of a Host Group in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
queryHostGroupsSearch for Host Groups in your environment by providing a FQL filter and paging details. Returns a set of Host Group IDs which match the filter criteria
Operation IDDescription
HostMigrationAggregatesV1Get host migration aggregates as specified via json in request body.
MigrationAggregatesV1Get migration aggregates as specified via json in request body.
HostMigrationsActionsV1Perform an action on host migrations.
GetHostMigrationsV1Get host migration details.
GetMigrationDestinationsV1Get destinations for a migration.
MigrationsActionsV1Perform an action on a migration job.
GetMigrationsV1Get migration job details.
CreateMigrationV1Create a device migration job.
GetHostMigrationIDsV1Query host migration IDs.
GetMigrationIDsV1Query migration jobs.
Operation IDDescription
CombinedDevicesByFilterSearch for hosts. Returns full device records.
CombinedHiddenDevicesByFilterSearch for hidden hosts. Returns full device records.
GetOnlineState_V1Get online status for one or more hosts.
PerformActionV2Contain, lift containment, delete, or restore a host.
PostDeviceDetailsV2Get details on one or more hosts by AID.
QueryDeviceLoginHistoryV2Retrieve recent login sessions for devices.
QueryDevicesByFilterScrollSearch for hosts with continuous pagination.
QueryGetNetworkAddressHistoryV1Retrieve IP and MAC address history.
QueryHiddenDevicesRetrieve hidden hosts matching filter criteria.
UpdateDeviceTagsAppend or remove Falcon Grouping Tags.
Operation IDDescription
GetSensorAggregatesGet sensor aggregates as specified via json in request body.
GetSensorDetailsGet details on one or more sensors by providing device IDs in a POST body. Supports up to a maximum of 5000 IDs.
QuerySensorsByFilterSearch for sensors in your environment by hostname, IP, and other criteria.
api_preempt_proxy_post_graphqlIdentity Protection GraphQL API. Allows to retrieve entities, timeline activities, identity-based incidents and security assessment. Allows to perform actions on entities and identity-based incidents.
get_policy_rulesGet policy rules.
post_policy_rulesCreate policy rules.
delete_policy_rulesDelete policy rules.
get_policy_rules_queryQuery policy rule IDs.
Operation IDDescription
ReadPoliciesGet all Image Assessment policies
CreatePoliciesCreate Image Assessment policies
DeletePolicyDelete Image Assessment Policy by policy UUID
UpdatePoliciesUpdate Image Assessment Policy entities
ReadPolicyExclusionsRetrieve Image Assessment Policy Exclusion entities
UpdatePolicyExclusionsUpdate Image Assessment Policy Exclusion entities
ReadPolicyGroupsRetrieve Image Assessment Policy Group entities
CreatePolicyGroupsCreate Image Assessment Policy Group entities
DeletePolicyGroupDelete Image Assessment Policy Group entities
UpdatePolicyGroupsUpdate Image Assessment Policy Group entities
UpdatePolicyPrecedenceUpdate Image Assessment Policy precedence
Operation IDDescription
audit_events_readGets the details of one or more audit events by id.
customer_settings_readCheck current installation token settings.
customer_settings_updateUpdate installation token settings.
tokens_readGets the details of one or more tokens by id.
tokens_createCreates a token.
tokens_deleteDeletes a token immediately. To revoke a token, use tokens_update instead.
tokens_updateUpdates one or more tokens. Use this endpoint to edit labels, change expiration, revoke, or restore.
audit_events_querySearch for audit events by providing a FQL filter and paging details.
tokens_querySearch for tokens by providing a FQL filter and paging details.
Operation IDDescription
QueryIntelActorEntitiesGet info about actors that match provided FQL filters.
QueryIntelIndicatorEntitiesGet info about indicators that match provided FQL filters.
QueryMalwareEntitiesGet malware entities that match provided FQL filters.
QueryIntelReportEntitiesGet info about reports that match provided FQL filters.
GetMalwareMitreReportExport Mitre ATT&CK information for a given malware family.
GetIntelActorEntitiesRetrieve specific actors using their actor IDs.
GetIntelIndicatorEntitiesRetrieve specific indicators using their indicator IDs.
GetMalwareEntitiesGet malware entities for specified IDs.
GetMitreReportExport Mitre ATT&CK information for a given actor.
PostMitreAttacksRetrieves report and observable IDs associated with the given actor and attacks.
GetIntelReportPDFReturn a Report PDF attachment
GetIntelReportEntitiesRetrieve specific reports using their report IDs.
GetIntelRuleFileDownload earlier rule sets.
GetLatestIntelRuleFileDownload the latest rule set.
GetIntelRuleEntitiesRetrieve details for rule sets for the specified ids.
GetVulnerabilitiesGet vulnerabilities
QueryIntelActorIdsGet actor IDs that match provided FQL filters.
QueryIntelIndicatorIdsGet indicators IDs that match provided FQL filters.
QueryMalwareGet malware family names that match provided FQL filters.
QueryMitreAttacksForMalwareGets MITRE tactics and techniques for the given malware.
QueryMitreAttacksGets MITRE tactics and techniques for the given actor.
QueryIntelReportIdsGet report IDs that match provided FQL filters.
QueryIntelRuleIdsSearch for rule IDs that match provided filter criteria.
QueryVulnerabilitiesGet vulnerabilities IDs
Operation IDDescription
DownloadFeedArchiveDownload feed file contents as a zip archive.
ListFeedTypesList the accessible feeds for a given customer.
QueryFeedArchivesQuery the accessible feeds for a customer.
Operation IDDescription
LookupIndicatorsGet indicators based on their value.
SearchIndicatorsSearch indicators based on FQL filter.
Operation IDDescription
getIOAExclusionsV1Get a set of IOA Exclusions by specifying their IDs.
createIOAExclusionsV1Create the IOA exclusions.
deleteIOAExclusionsV1Delete the IOA exclusions by ID.
updateIOAExclusionsV1Update the IOA exclusions.
queryIOAExclusionsV1Search for IOA exclusions.
ss_ioa_exclusions_aggregates_v2Get Self Service IOA Exclusion aggregates as specified via json in the request body.
ss_ioa_exclusions_get_reports_v2Create a report of Self Service IOA Exclusions scoped by the given filters.
ss_ioa_exclusions_get_v2Get the Self Service IOA Exclusions rules by id.
ss_ioa_exclusions_create_v2Create new Self Service IOA Exclusions.
ss_ioa_exclusions_update_v2Update the Self Service IOA Exclusions rule by id.
ss_ioa_exclusions_delete_v2Delete the Self Service IOA Exclusions rule by id.
ss_ioa_exclusions_matched_rule_v2Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent.
ss_ioa_exclusions_new_rules_v2Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent.
ss_ioa_exclusions_search_v2Search for Self Service IOA Exclusions.
Operation IDDescription
indicator_aggregate_v1Get Indicators aggregates as specified via json in the request body.
indicator_combined_v1Get Combined for Indicators.
action_get_v1Get Actions by ids.
GetIndicatorsReportLaunch an indicators report creation job
indicator_get_v1Get Indicators by ids.
indicator_create_v1Create Indicators.
indicator_delete_v1Delete Indicators by ids.
indicator_update_v1Update Indicators.
action_query_v1Query Actions.
indicator_search_v1Search for Indicators.
ioc_type_query_v1Query IOC Types.
platform_query_v1Query Platforms.
severity_query_v1Query Severities.
DevicesCountNumber of hosts in your customer account that have observed a given custom IOC
indicator_get_device_count_v1Number of hosts in your customer account that have observed a given custom IOC
DevicesRanOnFind hosts that have observed a given custom IOC. For details about those hosts, use GET /devices/entities/devices/v1
indicator_get_devices_ran_on_v1Find hosts that have observed a given custom IOC. For details about those hosts, use GET /devices/entities/devices/v1
ProcessesRanOnSearch for processes associated with a custom IOC (Deprecated)
indicator_get_processes_ran_on_v1Search for processes associated with a custom IOC
entities_processesFor the provided ProcessID retrieve the process details
Operation IDDescription
DevicesCountNumber of hosts in your customer account that have observed a given custom IOC.
GetIOCThis operation has been superseded by the IOC.indicator_get_v1 operation and is no longer used.
CreateIOCThis operation has been superseded by the IOC.indicator_create_v1 operation and is no longer used.
DeleteIOCThis operation has been superseded by the IOC.indicator_delete_v1 operation and is no longer used.
UpdateIOCThis operation has been superseded by the IOC.indicator_update_v1 operation and is no longer used.
DevicesRanOnFind hosts that have observed a given custom IOC. For details about those hosts, use GET /devices/entities/devices/v1.
QueryIOCsThis operation has been superseded by the IOC.indicator_search_v1 operation and is no longer used.
ProcessesRanOnSearch for processes associated with a custom IOC.
entities_processesFor the provided ProcessID retrieve the process details.
Operation IDDescription
ITAutomationGetAssociatedTasksRetrieve tasks associated with the provided file ID
ITAutomationCombinedScheduledTasksReturns full details of scheduled tasks matching the filter query parameter
ITAutomationRunLiveQueryStart a new task execution from the provided query data in the request and return the initiated task executions
ITAutomationGetTaskExecutionsByQueryRetrieve task executions by query
ITAutomationGetTaskGroupsByQueryRetrieve task groups by query
ITAutomationGetTasksByQueryRetrieve tasks by query
ITAutomationGetPoliciesRetrieve policies
ITAutomationCreatePolicyCreate a new policy of the specified type
ITAutomationUpdatePoliciesUpdate a new policy of the specified type
ITAutomationDeletePolicyDelete a policy
ITAutomationUpdatePolicyHostGroupsUpdate policy host groups
ITAutomationUpdatePoliciesPrecedenceUpdate policies precedence
ITAutomationGetScheduledTasksRetrieve scheduled tasks
ITAutomationCreateScheduledTaskCreate a scheduled task from the given request
ITAutomationUpdateScheduledTaskUpdate an existing scheduled task with the supplied info
ITAutomationDeleteScheduledTasksDelete scheduled tasks
ITAutomationCancelTaskExecutionCancel a task execution
ITAutomationGetTaskExecutionHostStatusRetrieve task execution host status
ITAutomationRerunTaskExecutionRerun the task execution specified in the request
ITAutomationGetExecutionResultsSearchStatusRetrieve execution results search status
ITAutomationStartExecutionResultsSearchStart an asynchronous task execution results search
ITAutomationGetExecutionResultsRetrieve execution results
ITAutomationGetTaskExecutionRetrieve a task execution
ITAutomationStartTaskExecutionStart a new task execution from an existing task provided in the request and returns the initiated task executions
ITAutomationGetTaskGroupsRetrieve task groups
ITAutomationCreateTaskGroupCreate a task group
ITAutomationUpdateTaskGroupUpdate a task group for a given ID
ITAutomationDeleteTaskGroupsDelete task groups
ITAutomationGetTasksRetrieve tasks
ITAutomationCreateTaskCreate a task with details from the given request
ITAutomationUpdateTaskUpdate a task with details from the given request
ITAutomationDeleteTaskDelete a task
ITAutomationQueryPoliciesQuery policies
ITAutomationSearchScheduledTasksSearch scheduled tasks
ITAutomationSearchTaskExecutionsSearch task executions
ITAutomationSearchTaskGroupsSearch task groups
ITAutomationSearchTasksSearch tasks
ITAutomationGetUserGroupReturns user groups for each provided id
ITAutomationCreateUserGroupCreates a user group from the given request
ITAutomationUpdateUserGroupUpdate a user group for a given id
ITAutomationDeleteUserGroupDeletes user groups for each provided ids
ITAutomationSearchUserGroupReturns the list of user group ids matching the filter query parameter. It can be used together with the entities endpoint to retrieve full information on user groups
Operation IDDescription
aggregates_knowledge_base_audit_events_v1Aggregate knowledge base audit events based on the provided msa criteria.
combined_knowledge_base_audit_events_v1Get knowledge base audit events with full event details and pagination.
entities_knowledge_base_audit_events_v1Retrieve knowledge base audit event entities by their IDs.
queries_knowledge_base_audit_events_v1Query knowledge base audit event IDs with pagination and filtering.
Operation IDDescription
entities_knowledge_base_files_download_v1Download knowledge base file entities for the provided id.
entities_knowledge_base_files_v1Retrieve knowledge base file entities for the provided id.
entities_knowledge_base_files_update_v1Update an existing file in a knowledge base. Supports updating file content and optionally its description.
entities_knowledge_base_files_create_v1Upload a file to a knowledge base.
entities_knowledge_base_files_delete_v1Delete document from knowledge base.
queries_knowledge_base_files_v1Query knowledge base files based on the provided filters.
Operation IDDescription
aggregates_knowledge_bases_v1Aggregate knowledge bases based on the provided msa criteria.
entities_knowledge_bases_v1Retrieve knowledge base entities for the provided id.
entities_knowledge_bases_create_v1Create or update a knowledge base. For deletion, provide knowledge base with IsDeleted=true.
entities_knowledge_bases_update_v1Update an existing knowledge base.
queries_knowledge_bases_v1Query knowledge bases based on the provided filters.
Operation IDDescription
AggregateAssessmentsGroupedByClustersV2Returns cluster details along with aggregated assessment results organized by cluster, including pass/fail assessment counts for various asset types.
AggregateComplianceByAssetTypeProvides aggregated compliance assessment metrics and rule status information, organized by asset type.
AggregateComplianceByClusterTypeProvides aggregated compliance assessment metrics and rule status information, organized by Kubernetes cluster type.
AggregateComplianceByFrameworkProvides aggregated compliance assessment metrics and rule status information, organized by compliance framework.
AggregateFailedRulesByClustersV3Retrieves the most non-compliant clusters, ranked in descending order based on the number of failed compliance rules across severity levels (critical, high, medium, and low).
AggregateAssessmentsGroupedByRulesV2Returns rule details along with aggregated assessment results organized by compliance rule, including pass/fail assessment counts.
AggregateTopFailedImagesRetrieves the most non-compliant container images, ranked in descending order based on the number of failed assessments across severity levels (critical, high, medium, and low).
CombinedImagesFindingsReturns detailed compliance assessment results for container images, providing the information needed to identify compliance violations.
CombinedNodesFindingsReturns detailed compliance assessment results for kubernetes nodes, providing the information needed to identify compliance violations.
getRulesMetadataByIDRetrieve detailed compliance rule information by ID. Includes descriptions, remediation steps, and audit procedures by specifying rule identifiers.
Operation IDDescription
ReadClustersByDateRangeCountRetrieve clusters by date range counts
ReadClustersByKubernetesVersionCountBucket clusters by kubernetes version
ReadClustersByStatusCountBucket clusters by status
ReadClusterCountRetrieve cluster counts
ReadContainersByDateRangeCountRetrieve containers by date range counts
ReadContainerCountByRegistryRetrieve top container image registries
FindContainersCountAffectedByZeroDayVulnerabilitiesRetrieve containers count affected by zero day vulnerabilities
ReadVulnerableContainerImageCountRetrieve count of vulnerable images running on containers
ReadContainerCountRetrieve container counts
FindContainersByContainerRunTimeVersionRetrieve containers by container_runtime_version
GroupContainersByManagedGroup the containers by Managed
ReadContainerImageDetectionsCountByDateRetrieve count of image assessment detections on running containers over a period of time
ReadContainerImagesByStateRetrieve count of image states running on containers
ReadContainersSensorCoverageBucket containers by agent type and calculate sensor coverage
ReadContainerVulnerabilitiesBySeverityCountRetrieve container vulnerabilities by severity counts
ReadDeploymentsByDateRangeCountRetrieve deployments by date range counts
ReadDeploymentCountRetrieve deployment counts
ReadClusterEnrichmentRetrieve cluster enrichment data
ReadContainerEnrichmentRetrieve container enrichment data
ReadDeploymentEnrichmentRetrieve deployment enrichment data
ReadNodeEnrichmentRetrieve node enrichment data
ReadPodEnrichmentRetrieve pod enrichment data
ReadDistinctContainerImageCountRetrieve count of distinct images running on containers
ReadContainerImagesByMostUsedBucket container by image-digest
ReadKubernetesIomByDateRangeReturns the count of Kubernetes IOMs by the date. by default it’s for 7 days.
ReadNamespacesByDateRangeCountRetrieve namespaces by date range counts
ReadNamespaceCountRetrieve namespace counts
ReadKubernetesIomCountReturns the total count of Kubernetes IOMs over the past seven days
ReadNodesByCloudCountBucket nodes by cloud providers
ReadNodesByContainerEngineVersionCountBucket nodes by their container engine version
ReadNodesByDateRangeCountRetrieve nodes by date range counts
ReadNodeCountRetrieve node counts
ReadPodsByDateRangeCountRetrieve pods by date range counts
ReadPodCountRetrieve pod counts
ReadClusterCombinedRetrieve kubernetes clusters identified by the provided filter criteria
ReadClusterCombinedV2Retrieve kubernetes clusters identified by the provided filter criteria
ReadRunningContainerImagesRetrieve images on running containers
ReadContainerCombinedRetrieve containers identified by the provided filter criteria
ReadDeploymentCombinedRetrieve kubernetes deployments identified by the provided filter criteria
SearchAndReadKubernetesIomEntitiesSearch Kubernetes IOM by the provided search criteria
ReadNodeCombinedRetrieve kubernetes nodes identified by the provided filter criteria
ReadPodCombinedRetrieve kubernetes pods identified by the provided filter criteria
ReadKubernetesIomEntitiesRetrieve Kubernetes IOM entities identified by the provided IDs
SearchKubernetesIomsSearch Kubernetes IOMs by the provided search criteria. this endpoint returns a list of Kubernetes IOM UUIDs matching the query
GetAWSAccountsProvides a list of AWS accounts.
CreateAWSAccountCreates a new AWS account in our system for a customer and generates the installation script
DeleteAWSAccountsMixin0Delete AWS accounts.
UpdateAWSAccountUpdates the AWS account per the query parameters provided
ListAzureAccountsProvides the azure subscriptions registered to Kubernetes Protection.
CreateAzureSubscriptionCreates a new Azure Subscription in our system
DeleteAzureSubscriptionDelete an Azure Subscription from the system.
GetLocationsProvides the cloud locations acknowledged by the Kubernetes Protection service
GetCombinedCloudClustersReturns a combined list of provisioned cloud accounts and known kubernetes clusters.
GetAzureTenantConfigReturns the Azure tenant config.
GetStaticScriptsGet static bash scripts that are used during registration.
GetAzureTenantIDsProvides all the azure subscriptions and tenants IDs.
GetAzureInstallScriptProvide the script to run for a given tenant id and subscription IDs.
GetHelmValuesYamlProvides a sample Helm values.yaml file for a customer to install alongside the agent Helm chart
RegenerateAPIKeyRegenerate API key for docker registry integrations.
GetClustersProvides the clusters acknowledged by the Kubernetes Protection service
TriggerScanTriggers a dry run or a full scan of a customer’s kubernetes footprint.
PostSearchKubernetesIOMEntitiesSearch Kubernetes IOM entities by filter criteria
PatchAzureServicePrincipalAdds the client ID for the given tenant ID to our system.
Operation IDDescription
GetMalQueryQuotasV1Get information about search and download quotas in your environment
PostMalQueryFuzzySearchV1Search Falcon MalQuery quickly, but with more potential for false positives. Search for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity.
GetMalQueryDownloadV1Download a file indexed by MalQuery. Specify the file using its SHA256. Only one file is supported at this time
GetMalQueryMetadataV1Retrieve indexed files metadata by their hash
GetMalQueryRequestV1Check the status and results of an asynchronous request, such as hunt or exact-search. Supports a single request id at this time.
GetMalQueryEntitiesSamplesFetchV1Fetch a zip archive with password ‘infected’ containing the samples. Call this once the /entities/samples-multidownload request has finished processing
PostMalQueryEntitiesSamplesMultidownloadV1Schedule samples for download. Use the result id with the /request endpoint to check if the download is ready after which you can call the /entities/samples-fetch to get the zip
PostMalQueryExactSearchV1Search Falcon MalQuery for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity. You can filter results on criteria such as file type, file size and first seen date. Returns a request id which can be used with the /request endpoint
PostMalQueryHuntV1Schedule a YARA-based search for execution. Returns a request id which can be used with the /request endpoint
Operation IDDescription
AggregateCasesRetrieve aggregate case values based on the matched filter
GetCaseActivityByIdsRetrieve activities for given id’s
CaseAddActivityAdd an activity to case. Only activities of type comment are allowed via API
CaseDownloadAttachmentretrieves an attachment for the case, given the attachment id
CaseAddAttachmentUpload an attachment for the case.
CreateCaseV2create a new case
GetCaseEntitiesByIDsRetrieve message center cases
QueryActivityByCaseIDRetrieve activities id’s for a case
QueryCasesIdsByFilterRetrieve case id’s that match the provided filter criteria
Operation IDDescription
getMLExclusionsV1Get a set of ML Exclusions by specifying their IDs.
createMLExclusionsV1Create the ML exclusions.
deleteMLExclusionsV1Delete the ML exclusions by ID.
updateMLExclusionsV1Update the ML exclusions.
queryMLExclusionsV1Search for ML exclusions.
exclusions_aggregates_v2Get exclusion aggregates as specified via json in request body.
exclusions_get_all_v2Get all exclusions.
exclusions_perform_action_v2Actions used to manipulate the content of exclusions, with ancestor fields.
exclusions_get_reports_v2Create a report of ML exclusions scoped by the given filters.
exclusions_get_v2Get the exclusions by id, with ancestor fields.
exclusions_create_v2Create the exclusions, with ancestor fields.
exclusions_update_v2Update the exclusions by id, with ancestor fields.
exclusions_delete_v2Delete the exclusions by id, with ancestor fields.
exclusions_search_v2Search for exclusions, with ancestor fields.
Operation IDDescription
RequestDeviceEnrollmentV3Trigger on-boarding process for a mobile device
RequestDeviceEnrollmentV4Trigger on-boarding process for a mobile device
Operation IDDescription
getChildrenV2Get link to child customer by child CID(s)
getChildrenGet link to child customer by child CID(s)
getCIDGroupMembersByGet CID group members by CID Group ID.
getCIDGroupMembersByV1Get CID Group members by CID Group IDs.
addCIDGroupMembersAdd new CID Group member.
deleteCIDGroupMembersDelete CID Group members entry.
getCIDGroupByIdGet CID Groups by ID.
getCIDGroupByIdV1Get CID Group(s) by ID(s).
createCIDGroupsCreate new CID Group(s). Maximum 500 CID Group(s) allowed.
deleteCIDGroupsDelete CID Group(s) by ID(s).
updateCIDGroupsUpdate existing CID Group(s). CID Group ID is expected for each CID Group definition provided in request body. CID Group member(s) remain unaffected.
getRolesByIDGet MSSP Role assignment(s). MSSP Role assignment is of the format: <user_group_id>.<cid_group_id>.
addRoleAssign new MSSP Role(s) between User Group and CID Group. It does not revoke existing role(s) between User Group and CID Group. User Group ID and CID Group ID have to be specified in request.
deletedRolesDelete MSSP Role assignment(s) between User Group and CID Group. User Group ID and CID Group ID have to be specified in request. Only specified roles are removed if specified in request payload, else association between User Group and CID Group is dissolved completely (if no roles specified).
getUserGroupMembersByIDGet User Group members by User Group ID(s).
getUserGroupMembersByIDV1Get User Group members by User Group ID(s).
addUserGroupMembersAdd new User Group member. Maximum 500 members allowed per User Group.
deleteUserGroupMembersDelete User Group members entry.
getUserGroupsByIDGet User Group by ID(s).
getUserGroupsByIDV1Get user groups by ID.
createUserGroupsCreate new User Group(s). Maximum 500 User Group(s) allowed per customer.
deleteUserGroupsDelete User Group(s) by ID(s).
updateUserGroupsUpdate existing User Group(s). User Group ID is expected for each User Group definition provided in request body. User Group member(s) remain unaffected.
getUserGroupsByIDV2Get user groups by ID.
queryChildrenQuery for customers linked as children
queryCIDGroupMembersQuery a CID Groups members by associated CID.
queryCIDGroupsQuery CID Groups.
queryRolesQuery links between user groups and CID groups. At least one of CID Group ID or User Group ID should also be provided. Role ID is optional.
queryUserGroupMembersQuery User Group member by User UUID.
queryUserGroupsQuery User Groups.
deleteCIDGroupMembersV1Deprecated: Please use deleteCIDGroupMembersV2.
Operation IDDescription
get_global_configsGet “global-configs” for the CID
update_global_configsUpdate “global-configs” using provided specifications
Operation IDDescription
aggregate_networksReturns “networks” aggregations
get_networksGet “networks” by their IDs
create_networksCreate “networks” using provided specifications
delete_networksDelete “networks” by their IDs
update_networksUpdate “networks” using provided specifications
query_networksGet “networks IDs” by filter
Operation IDDescription
get_scan_run_reportsDownloads scan run report in CSV format
Operation IDDescription
aggregate_scan_runsReturns “scan-runs” aggregations
get_scan_runsGet “scan-runs” by their IDs
create_scan_runsCreate “scan-runs” using provided specifications
update_scan_runsUpdate “scan-runs” using provided specifications
query_scan_runsGet “scan-runs IDs” by filter
Operation IDDescription
aggregate_scannersReturns “scanners” aggregations
get_scannersGet “scanners” by their IDs
update_scannersUpdate “scanners” using provided specifications
query_scannersGet “scanners IDs” by filter
Operation IDDescription
aggregate_scansMixin0Returns “scans” aggregations
get_scansGet “scans” by their IDs
create_scansCreate “scans” using provided specifications
delete_scansDelete “scans” by their IDs
update_scansUpdate “scans” using provided specifications
query_scansMixin0Get “scans IDs” by filter
Operation IDDescription
get_template_configsGet details on the network scan template configurations
get_templatesGet “templates” by their IDs
create_templatesCreate “templates” using provided specifications
delete_templatesDelete “templates” by their IDs
update_templatesUpdate “templates” using provided specifications
query_templatesGet “templates IDs” by filter
Operation IDDescription
aggregate_zonesReturns “zones” aggregations
combined_zonesGet “zones” by filter
get_zonesGet “zones” by their IDs
create_zonesCreate “zones” using provided specifications
delete_zonesDelete “zones” by their IDs
update_zonesUpdate “zones” using provided specifications
query_zonesGet “zones IDs” by filter
Operation IDDescription
UploadLookupV1Upload a lookup file to NGSIEM.
GetLookupV1Download lookup file from NGSIEM.
GetLookupFromPackageWithNamespaceV1Download lookup file in namespaced package from NGSIEM.
GetLookupFromPackageV1Download lookup file in package from NGSIEM.
StartSearchV1Initiate a NGSIEM search.
GetSearchStatusV1Get status of a NGSIEM search.
StopSearchV1Stop a NGSIEM search.
GetDashboardTemplateGet dashboard template by ID.
CreateDashboardFromTemplateCreate dashboard from template.
UpdateDashboardFromTemplateUpdate dashboard from template.
DeleteDashboardDelete dashboard.
GetLookupFileGet lookup file by ID.
CreateLookupFileCreate lookup file.
UpdateLookupFileUpdate lookup file.
DeleteLookupFileDelete lookup file.
GetParserTemplateGet parser template by ID.
CreateParserFromTemplateCreate Parser in NGSIEM from template.
GetParserGet parser by ID.
CreateParserCreate Parser in NGSIEM.
UpdateParserUpdate parser.
DeleteParserDelete Parser in NGSIEM.
UpdateParserAutoUpdatePolicyUpdate a parser auto update policy.
InstallParserInstall a CrowdStrike-managed out-of-the-box (OOTB) parser.
BulkInstallParsersInstall multiple CrowdStrike-managed out-of-the-box (OOTB) parsers.
GetSavedQueryTemplateRetrieve Saved Query in NGSIEM as LogScale YAML Template by ID.
CreateSavedQueryCreate Saved Query from LogScale YAML Template in NGSIEM.
UpdateSavedQueryFromTemplateUpdate Saved Query from LogScale YAML Template in NGSIEM.
DeleteSavedQueryDelete Saved Query in NGSIEM.
ListDashboardsList dashboards.
ListLookupFilesList lookup files.
ListParsersList parsers.
ListSavedQueriesList saved queries.
UpdateLookupFileEntriesUpdate entries in an existing Lookup File in NGSIEM.
ExternalListDataConnectionsList and search data connections.
ExternalListDataConnectorsList available data connectors.
ExternalGetDataConnectionStatusGet data connection provisioning status.
ExternalUpdateDataConnectionStatusUpdate data connection status.
ExternalGetDataConnectionTokenGet Ingest token for data connection.
ExternalRegenerateDataConnectionTokenRegenerate Ingest token for data connection.
ExternalGetDataConnectionByIDGet data connection by ID.
ExternalCreateDataConnectionCreate a new data connection.
ExternalUpdateDataConnectionUpdate a data connection.
ExternalDeleteDataConnectionDelete a data connection.
ExternalListConnectorConfigsList configurations for a data connector.
ExternalCreateConnectorConfigCreate a new configuration for a data connector.
ExternalPatchConnectorConfigPatch configurations for a data connector.
ExternalDeleteConnectorConfigsDelete data connection config.
UpdateParserFromTemplateUpdate Parser in NGSIEM from YAML Template. Please note that name changes are not supported, but rather should be created as a new parser.
Operation IDDescription
oauth2RevokeTokenRevoke a previously issued OAuth2 access token before the end of its standard 30-minute lifespan.
oauth2AccessTokenGenerate an OAuth2 access token
Operation IDDescription
aggregate_query_scan_host_metadataGet aggregates on ODS scan-hosts data.
aggregate_scansGet aggregates on ODS scan data.
aggregate_scheduled_scansGet aggregates on ODS scheduled-scan data.
get_malicious_files_by_idsGet malicious files by ids.
cancel_scansCancel ODS scans for the given scan ids.
get_scan_host_metadata_by_idsGet scan hosts by ids.
get_scans_by_scan_ids_v1Get Scans by IDs.
get_scans_by_scan_ids_v2Get Scans by IDs.
create_scanCreate ODS scan and start or schedule scan for the given scan request.
get_scheduled_scans_by_scan_idsGet ScheduledScans by IDs.
schedule_scanCreate ODS scan and start or schedule scan for the given scan request.
delete_scheduled_scansDelete ODS scheduled-scans for the given scheduled-scan ids.
query_malicious_filesQuery malicious files.
query_scan_host_metadataQuery scan hosts.
query_scansQuery Scans.
query_scheduled_scansQuery ScheduledScans.
Operation IDDescription
AggregatesDetectionsGlobalCountsGet the total number of detections pushed across all customers.
AggregatesEventsCollectionsGet OverWatch detection event collection info by providing an aggregate query.
AggregatesEventsGet aggregate OverWatch detection event info by providing an aggregate query.
AggregatesIncidentsGlobalCountsGet the total number of incidents pushed across all customers.
AggregatesOWEventsGlobalCountsGet the total number of OverWatch events across all customers.
Operation IDDescription
queryCombinedPreventionPolicyMembersSearch for members of a Prevention Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedPreventionPoliciesSearch for Prevention Policies in your environment by providing a FQL filter and paging details. Returns a set of Prevention Policies which match the filter criteria
performPreventionPoliciesActionPerform the specified action on the Prevention Policies specified in the request
setPreventionPoliciesPrecedenceSets the precedence of Prevention Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence
getPreventionPoliciesRetrieve a set of Prevention Policies by specifying their IDs
createPreventionPoliciesCreate Prevention Policies by specifying details about the policy to create
deletePreventionPoliciesDelete a set of Prevention Policies by specifying their IDs
updatePreventionPoliciesUpdate Prevention Policies by specifying the ID of the policy and details to update
queryPreventionPolicyMembersSearch for members of a Prevention Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
queryPreventionPoliciesSearch for Prevention Policies in your environment by providing a FQL filter and paging details. Returns a set of Prevention Policy IDs which match the filter criteria
Operation IDDescription
ActionUpdateCountReturns count of potentially affected quarantined files for each action.
GetAggregateFilesGet quarantine file aggregates as specified via json in request body.
GetQuarantineFilesGet quarantine file metadata for specified ids.
UpdateQuarantinedDetectsByIdsApply action by quarantine file ids.
QueryQuarantineFilesGet quarantine file ids that match the provided filter criteria.
UpdateQfByQueryApply quarantine file actions by query.
Operation IDDescription
GetScansAggregatesGet scans aggregations as specified via json in request body.
GetScansCheck the status of a volume scan. Time required for analysis increases with the number of samples in a volume but usually it should take less than 1 minute
ScanSamplesSubmit a volume of files for ml scanning. Time required for analysis increases with the number of samples in a volume but usually it should take less than 1 minute
QuerySubmissionsMixin0Find IDs for submitted scans by providing a FQL filter and paging details. Returns a set of volume IDs that match your criteria.
Operation IDDescription
UploadFileQuickScanProUploads a file to be further analyzed with QuickScan Pro. The samples expire after 90 days.
DeleteFileDeletes file by its sha256 identifier.
GetScanResultGets the result of an QuickScan Pro scan.
LaunchScanStarts scanning a file uploaded through UploadFileQuickScanPro.
DeleteScanResultDeletes the result of an QuickScan Pro scan.
QueryScanResultsGets QuickScan Pro scan jobs for a given FQL filter.
Operation IDDescription
RTR_AggregateSessionsGet aggregates on session data.
BatchActiveResponderCmdBatch executes a RTR active-responder command across the hosts mapped to the given batch ID.
BatchCmdBatch executes a RTR read-only command across the hosts mapped to the given batch ID.
BatchGetCmdStatusRetrieves the status of the specified batch get command. Will return successful files when they are finished processing.
BatchGetCmdBatch executes get command across hosts to retrieve files. After this call is made BatchGetCmdStatus is used to query for the results.
BatchInitSessionsBatch initialize a RTR session on multiple hosts. Before any RTR commands can be used, an active session is needed on the host.
BatchRefreshSessionsBatch refresh a RTR session on multiple hosts. RTR sessions will expire after 5 minutes unless refreshed.
RTR_CheckActiveResponderCommandStatusGet status of an executed active-responder command on a single host.
RTR_ExecuteActiveResponderCommandExecute an active responder command on a single host.
RTR_CheckCommandStatusGet status of an executed command on a single host.
RTR_ExecuteCommandExecute a command on a single host.
RTR_GetExtractedFileContentsGet RTR extracted file contents for specified session and sha256.
RTR_ListFilesGet a list of files for the specified RTR session.
RTR_ListFilesV2Get a list of files for the specified RTR session. (Expanded output detail.)
RTR_DeleteFileDelete a RTR session file.
RTR_DeleteFileV2Delete a RTR session file. (Expanded output detail, use with RTR_ListFilesV2.)
RTR_ListQueuedSessionsGet queued session metadata by session ID.
RTR_DeleteQueuedSessionDelete a queued session command.
RTR_PulseSessionRefresh a session timeout on a single host.
RTR_ListSessionsGet session metadata by session id.
RTR_InitSessionInitialize a new session with the RTR cloud.
RTR_DeleteSessionDelete a session.
RTR_ListAllSessionsGet a list of session_ids.
Operation IDDescription
BatchAdminCmdBatch executes a RTR administrator command across the hosts mapped to the given batch ID.
RTR_CheckAdminCommandStatusGet status of an executed RTR administrator command on a single host.
RTR_ExecuteAdminCommandExecute a RTR administrator command on a single host.
RTR_GetFalconScriptsGet Falcon scripts with metadata and content of script
RTR_GetPut_FilesGet put-files based on the ID’s given. These are used for the RTR put command.
RTR_GetPut_FilesV2Get put-files based on the ID’s given. These are used for the RTR put command.
RTR_GetPutFileContentsGet the contents of a put-file based on the ID given.
RTR_CreatePut_FilesUpload a new put-file to use for the RTR put command.
RTR_CreatePut_FilesV2Upload a new put-file to use for the RTR put command.
RTR_DeletePut_FilesDelete a put-file based on the ID given. Can only delete one file at a time.
RTR_GetScriptsGet custom-scripts based on the ID’s given. These are used for the RTR runscript command.
RTR_GetScriptsV2Get custom-scripts based on the ID’s given. These are used for the RTR runscript command.
RTR_ListFalconScriptsGet a list of Falcon script IDs available to the user to run
RTR_CreateScriptsUpload a new custom-script to use for the RTR runscript command.
RTR_CreateScriptsV2Upload a new custom-script to use for the RTR runscript command.
RTR_DeleteScriptsDelete a custom-script based on the ID given. Can only delete one script at a time.
RTR_UpdateScriptsUpload a new scripts to replace an existing one.
RTR_UpdateScriptsV2Upload a new scripts to replace an existing one.
RTR_ListPut_FilesGet a list of put-file ID’s that are available to the user for the put command.
RTR_ListScriptsGet a list of custom-script ID’s that are available to the user for the runscript command.
Operation IDDescription
RTRAuditSessionsGet all the RTR sessions created for a customer in a specified duration
Operation IDDescription
AggregateNotificationsExposedDataRecordsV1Get notification exposed data record aggregates as specified via JSON in request body.
AggregateNotificationsV1Get notification aggregates as specified via JSON in request body.
PreviewRuleV1Preview rules notification count and distribution. This will return aggregations on: channel, count, site.
GetActionsV1Get actions based on their IDs. IDs can be retrieved using the QueryActionsV1 operation.
CreateActionsV1Create actions for a monitoring rule. Accepts a list of actions that will be attached to the monitoring rule.
DeleteActionV1Delete an action from a monitoring rule based on the action ID.
UpdateActionV1Update an action for a monitoring rule.
GetFileContentForExportJobsV1Download the file associated with a job ID.
GetExportJobsV1Get the status of export jobs based on their IDs. Export jobs can be launched by calling CreateExportJobsV1. When a job is complete, use the job ID to download the file(s) associated with it using GetFileContentForExportJobsV1.
CreateExportJobsV1Launch asynchronous export job. Use the job ID to poll the status of the job using GetExportJobsV1.
DeleteExportJobsV1Delete export jobs (and their associated file(s)) based on their IDs.
GetNotificationsDetailedTranslatedV1Get detailed notifications based on their IDs. These include the raw intelligence content that generated the match. This endpoint will return translated notification content. The only target language available is English. A single notification can be translated per request.
GetNotificationsDetailedV1Get detailed notifications based on their IDs. These include the raw intelligence content that generated the match.
GetNotificationsExposedDataRecordsV1Get notifications exposed data records based on their IDs. IDs can be retrieved using the QueryNotificationsExposedDataRecordsV1 operation. The associated notification can be fetched using the notifications operations.
GetNotificationsTranslatedV1Get notifications based on their IDs. IDs can be retrieved using the QueryNotificationsV1 operation. This endpoint will return translated notification content. The only target language available is English.
GetNotificationsV1Get notifications based on their IDs. IDs can be retrieved using the QueryNotificationsV1 operation.
DeleteNotificationsV1Delete notifications based on IDs. Notifications cannot be recovered after they are deleted.
UpdateNotificationsV1Update notification status or assignee. Accepts bulk requests.
GetRulesV1Get monitoring rules rules by provided IDs.
CreateRulesV1Create monitoring rules.
DeleteRulesV1Delete monitoring rules.
UpdateRulesV1Update monitoring rules.
QueryActionsV1Query actions based on provided criteria. Use the IDs from this response to get the action entities on GetActionsV1.
QueryNotificationsExposedDataRecordsV1Query notifications exposed data records based on provided criteria. Use the IDs from this response to get the notification entities on GetNotificationsExposedDataRecordsV1.
QueryNotificationsV1Query notifications based on provided criteria. Use the IDs from this response to get the notification entities on GetNotificationsV1 or GetNotificationsDetailedV1.
QueryRulesV1Query monitoring rules based on provided criteria. Use the IDs from this response to fetch the rules on GetRulesV1.
Operation IDDescription
report_executions_download_getGet report entity download
report_executions_retryRetry the execution of a report by ID.
report_executions_getRetrieve report details for the provided report IDs.
report_executions_queryFind all report execution IDs matching the query with filter
Operation IDDescription
queryCombinedRTResponsePolicyMembersSearch for members of a Response policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria
queryCombinedRTResponsePoliciesSearch for Response Policies in your environment by providing a FQL filter and paging details. Returns a set of Response Policies which match the filter criteria
performRTResponsePoliciesActionPerform the specified action on the Response Policies specified in the request
setRTResponsePoliciesPrecedenceSets the precedence of Response Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence
getRTResponsePoliciesRetrieve a set of Response Policies by specifying their IDs
createRTResponsePoliciesCreate Response Policies by specifying details about the policy to create
deleteRTResponsePoliciesDelete a set of Response Policies by specifying their IDs
updateRTResponsePoliciesUpdate Response Policies by specifying the ID of the policy and details to update
queryRTResponsePolicyMembersSearch for members of a Response policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria
queryRTResponsePoliciesSearch for Response Policies in your environment by providing a FQL filter with sort and/or paging details. This returns a set of Response Policy IDs that match the given criteria.
Operation IDDescription
DismissAffectedEntityV3Dismiss affected entity.
DismissSecurityCheckV3Dismiss security check.
GetActivityMonitorV3Get activity monitor.
GetAlertsV3Get alerts.
GetAppInventoryGet application inventory.
GetAppInventoryUsersGet application inventory users.
GetAssetInventoryV3Get asset inventory.
GetDeviceInventoryV3Get device inventory.
GetIntegrationsV3Get integrations.
GetMetricsV3Get metrics.
GetSecurityCheckAffectedV3Get affected resources for security checks.
GetSecurityCheckComplianceV3Get security check compliance.
GetSecurityChecksV3Get security checks.
GetSupportedSaasV3Get supported SaaS applications.
GetSystemLogsV3Get system logs.
GetSystemUsersV3Get system users.
GetUserInventoryV3Get user inventory.
IntegrationBuilderEndTransactionV3End integration builder transaction.
IntegrationBuilderGetStatusV3Get integration builder status.
IntegrationBuilderResetV3Reset integration builder.
IntegrationBuilderUploadV3Upload integration builder.
Operation IDDescription
ArchiveListV1Retrieves the archives files in chunks.
ArchiveGetV1Retrieves the archives upload operation statuses. Status done means that archive was processed successfully. Status error means that archive was not processed successfully.
ArchiveUploadV1Uploads an archive and extracts files list from it. Operation is asynchronous.
ArchiveDeleteV1Delete an archive that was uploaded previously.
ArchiveUploadV2Uploads an archive and extracts files list from it. Operation is asynchronous.
ExtractionListV1Retrieves the files extractions in chunks.
ExtractionGetV1Retrieves the files extraction operation statuses.
ExtractionCreateV1Extracts files from an uploaded archive and copies them to internal storage making it available for content analysis.
GetSampleV3Retrieves the file associated with the given ID (SHA256).
UploadSampleV3Upload a file for further cloud analysis. After uploading, call the specific analysis API endpoint.
DeleteSampleV3Removes a sample, including file, meta and submissions from the collection.
Operation IDDescription
scheduled_reports_launchLaunch scheduled report executions for the provided ID(s).
scheduled_reports_getRetrieve scheduled reports for the provided report IDs.
scheduled_reports_queryFind all report IDs matching the query with filter
Operation IDDescription
GetCombinedSensorInstallersByQueryGet sensor installer details by provided query
GetCombinedSensorInstallersByQueryV2Get sensor installer details by provided query
GetCombinedSensorInstallersByQueryV3Get sensor installer details by provided query
DownloadSensorInstallerByIdDownload sensor installer by SHA256 ID
DownloadSensorInstallerByIdV2Download sensor installer by SHA256 ID
DownloadSensorInstallerByIdV3Download sensor installer by SHA256 ID
GetSensorInstallersEntitiesGet sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV2Get sensor installer details by provided SHA256 IDs
GetSensorInstallersEntitiesV3Get sensor installer details by provided SHA256 IDs
GetSensorInstallersCCIDByQueryGet CCID to use with sensor installers
GetSensorInstallersByQueryGet sensor installer IDs by provided query
GetSensorInstallersByQueryV2Get sensor installer IDs by provided query
GetSensorInstallersByQueryV3Get sensor installer IDs by provided query
Operation IDDescription
revealUninstallTokenReveals an uninstall token for a specific device. To retrieve the bulk maintenance token pass the value ‘MAINTENANCE’ as the value for ‘device_id’.
incrementUninstallTokenIncrement a bulk maintenance token.
queryCombinedSensorUpdateBuildsRetrieve available builds for use with Sensor Update Policies.
queryCombinedSensorUpdateKernelsRetrieve kernel compatibility info for Sensor Update Builds.
queryCombinedSensorUpdatePolicyMembersSearch for members of a Sensor Update Policy in your environment by providing a FQL filter and paging details. Returns a set of host details which match the filter criteria.
queryCombinedSensorUpdatePoliciesSearch for Sensor Update Policies in your environment by providing a FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria.
queryCombinedSensorUpdatePoliciesV2Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing a FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria.
performSensorUpdatePoliciesActionPerform the specified action on the Sensor Update Policies specified in the request.
setSensorUpdatePoliciesPrecedenceSets the precedence of Sensor Update Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence.
getSensorUpdatePoliciesRetrieve a set of Sensor Update Policies by specifying their IDs.
createSensorUpdatePoliciesCreate Sensor Update Policies by specifying details about the policy to create.
deleteSensorUpdatePoliciesDelete a set of Sensor Update Policies by specifying their IDs.
updateSensorUpdatePoliciesUpdate Sensor Update Policies by specifying the ID of the policy and details to update.
getSensorUpdatePoliciesV2Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs.
createSensorUpdatePoliciesV2Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection.
updateSensorUpdatePoliciesV2Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection.
querySensorUpdateKernelsDistinctRetrieve kernel compatibility info for Sensor Update Builds.
querySensorUpdatePolicyMembersSearch for members of a Sensor Update Policy in your environment by providing a FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria.
querySensorUpdatePoliciesSearch for Sensor Update Policies in your environment by providing a FQL filter and paging details. Returns a set of Sensor Update Policy IDs which match the filter criteria.
Operation IDDescription
GetSensorUsageHourlyFetches hourly average. Each data point represents the average of how many unique AIDs were seen per hour for the previous 28 days.
GetSensorUsageWeeklyFetches weekly average. Each data point represents the average of how many unique AIDs were seen per week for the previous 28 days.
Operation IDDescription
getSensorVisibilityExclusionsV1Get a set of Sensor Visibility Exclusions by specifying their IDs.
createSVExclusionsV1Create a sensor visibility exclusion.
deleteSensorVisibilityExclusionsV1Delete the sensor visibility exclusions by ID.
updateSensorVisibilityExclusionsV1Update a sensor visibility exclusion.
querySensorVisibilityExclusionsV1Search for sensor visibility exclusions.
Operation IDDescription
ReadExportJobsMixin0Read export jobs entities.
QueryExportJobsMixin0Query export jobs entities.
DownloadExportFileMixin0Download an export file.
LaunchExportJobMixin0Launch an export job of a Lambda Security resource.
Operation IDDescription
GetCombinedVulnerabilitiesSARIFRetrieve all lambda vulnerabilities that match the given query and return in the SARIF format.
Operation IDDescription
combinedQueryEvaluationLogicSearch for evaluation logic in your environment by providing a FQL filter and paging details. Returns a set of evaluation logic entities which match the filter criteria.
combinedSupportedEvaluationExtPerform a combined query and get for RiskSupportedEvaluation entities.
getEvaluationLogicGet details on evaluation logic items by providing one or more IDs.
queryEvaluationLogicSearch for evaluation logic in your environment by providing a FQL filter and paging details. Returns a set of evaluation logic IDs which match the filter criteria.
Operation IDDescription
combinedQueryVulnerabilitiesSearch for Vulnerabilities in your environment by providing a FQL filter and paging details. Returns a set of Vulnerability entities which match the filter criteria.
getRemediationsV2Get details on remediation by providing one or more IDs.
getVulnerabilitiesGet details on vulnerabilities by providing one or more IDs.
queryVulnerabilitiesSearch for Vulnerabilities in your environment by providing a FQL filter and paging details. Returns a set of Vulnerability IDs which match the filter criteria.
getRemediationsGet details on remediations by providing one or more IDs.
Operation IDDescription
combineVulnMetadataExtPerform a combined query and get operation for retrieving Risk (vulnerability metadata) entities.
Operation IDDescription
GetEventsBodyGet event body for the provided event ID
GetEventsEntitiesGet events entities for specified ids.
QueryEventsGet events ids that match the provided filter criteria.
GetRulesEntitiesGet rules entities for specified ids.
QueryRulesGet rules ids that match the provided filter criteria.
Operation IDDescription
combined_edges_getRetrieve edges for a given vertex id. One edge type must be specified.
combined_ran_on_getLook up instances of indicators such as hashes, domain names, and ip addresses that have been seen on devices in your environment.
combined_summary_getRetrieve summary for a given vertex ID.
entities_vertices_getRetrieve metadata for a given vertex ID.
entities_vertices_getv2Retrieve metadata for a given vertex ID.
queries_edgetypes_getShow all available edge types.
Operation IDDescription
ReadUnidentifiedContainersByDateRangeCountReturns the count of Unidentified Containers over the last 7 days
ReadUnidentifiedContainersCountReturns the total count of Unidentified Containers over a time period
SearchAndReadUnidentifiedContainersSearch Unidentified Containers by the provided search criteria
Operation IDDescription
aggregateUsersV1Get user aggregates as specified via json in request body.
GetRolesGet info about a role.
combinedUserRolesV1Get user grant(s). This operation lists both direct as well as flight control grants between a User and a Customer.
CombinedUserRolesV2Get user grant(s). This operation lists both direct as well as flight control grants between a User and a Customer.
entitiesRolesV1Get info about a role, supports Flight Control.
entitiesRolesGETV2Get info about a role.
userActionV1Apply actions to one or more users.
userRolesActionV1Grant or Revoke one or more role(s) to a user against a CID.
GrantUserRoleIdsAssign one or more roles to a user.
RevokeUserRoleIdsRevoke one or more roles from a user
GetAvailableRoleIdsShow role IDs for all roles available in your customer account. For more information on each role, provide the role ID to GetRoles.
queriesRolesV1Show role IDs for all roles available in your customer account. Supports Flight Control.
queryUserV1List user IDs for all users in your customer account.
GetUserRoleIdsShow role IDs of roles assigned to a user. For more information on each role, provide the role ID to GetRoles.
RetrieveUserGet info about a user.
retrieveUsersGETV1Get info about users including their name, UID and CID by providing user UUIDs.
CreateUserCreate a new user. After creating a user, assign one or more roles with GrantUserRoleIds.
createUserV1Create a new user. After creating a user, assign one or more roles with userRolesActionV1. Supports Flight Control.
DeleteUserDelete a user permanently.
deleteUserV1Delete a user permanently. Supports Flight Control.
UpdateUserModify an existing user’s first or last name
updateUserV1Modify an existing user’s first or last name. Supports Flight Control.
RetrieveEmailsByCIDList the usernames (usually an email address) for all users in your customer account
RetrieveUserUUIDsByCIDList user IDs for all users in your customer account. For more information on each user, provide the user ID to RetrieveUser.
RetrieveUserUUIDGet a user’s ID by providing a username (usually an email address)
Operation IDDescription
WorkflowActivitiesCombinedSearch for activities by name. Returns all supported activities if no filter is specified.
WorkflowActivitiesContentCombinedSearch for activities by name. Returns all supported activities if no filter specified.
WorkflowExecuteExecutes an on-demand Workflow, the body is JSON used to trigger the execution, the response the execution ID(s)
WorkflowExecuteInternalExecutes an on-demand Workflow, the body is JSON used to trigger the execution, the response the execution ID(s)
WorkflowMockExecuteExecutes an on-demand Workflow with mocks
WorkflowExecutionsActionAllows a user to resume/retry a failed workflow execution.
WorkflowExecutionResultsGet execution result of a given execution
WorkflowSystemDefinitionsDeProvisionDeprovisions a system definition that was previously provisioned on the target CID
WorkflowSystemDefinitionsPromotePromote a version of a system definition
WorkflowSystemDefinitionsProvisionProvisions a system definition onto the target CID by using the template and provided parameters
WorkflowDefinitionsCombinedSearch workflow definitions based on the provided filter
WorkflowTriggersCombinedSearch for triggers by namespaced identifier, i.e. FalconAudit, Detection, or FalconAudit/Detection/Status. Returns all triggers if no filter is specified.
WorkflowExecutionsCombinedSearch workflow executions based on the provided filter
WorkflowDefinitionsExportExports a workflow definition for the given definition ID
WorkflowDefinitionsImportImports a workflow definition based on the provided model
WorkflowDefinitionsActionEnable or disable a workflow definition, or stop all executions for a definition.
WorkflowDefinitionsUpdateUpdates a workflow definition based on the provided model.
WorkflowGetHumanInputV1Gets one or more specific human inputs by their IDs.
WorkflowUpdateHumanInputV1Provides an input in response to a human input action. Depending on action configuration, one or more of Approve, Decline, and/or Escalate are permitted.
v1_child_executions_querySearch for child executions by providing a FQL filter and paging details.
Operation IDDescription
getAssessmentV1Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID) and a customer ID (CID).
getAuditV1Get the Zero Trust Assessment audit report for one customer ID (CID).
getAssessmentsByScoreV1Get Zero Trust Assessment data for one or more hosts by providing a customer ID (CID) and a range of scores.
getCombinedAssessmentsQuerySearch for assessments in your environment by providing an FQL filter and paging details. Returns a set of HostFinding entities which match the filter criteria