FalconHost
Deprecated. Use the CrowdStrike Falcon integration instead.
- Category
- Endpoint
- Pack
- CrowdStrikeHost
Configuration parameters
- url — Server URL (e.g. https://192.168.0.1) (required)
- id — API ID (required)
- key — API Key (required)
- useproxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
Commands (17)
- cs-delete-ioc — Deletes an indicator that you are monitoring
- cs-detection-details — Deprecated. Use the cs-falcon-search-detection command from the CrowdStrike Falcon integration instead.
- cs-detection-search — Deprecated. Use the cs-falcon-search-detection command from the CrowdStrike Falcon integration instead.
- cs-device-count-ioc — Returns the number of devices on which an IOC ran, according to type and value of an IOC
- cs-device-details — Get details for one or more devices, according to device ID
- cs-device-ran-on — Returns a list of device IDs on which an indicator ran
- cs-device-search — Search for devices in your environment by platform, host name, IP, or various other parameters
- cs-get-ioc — Get the full definition of one or more indicators that you are watching
- cs-process-details — Retrieves the details of a process, according to process ID, that is running or that previously ran.
- cs-processes-ran-on — Returns the process ID of the indicator if it ran on given device recently
- cs-resolve-detection — Deprecated. Use the cs-falcon-resolve-detection command from the CrowdStrike Falcon integration instead.
- cs-search-iocs — Returns a list of your uploaded IOCs that match the search criteria
- cs-threatgraph-detections — Gets the child process Threat Graph Detections.
- cs-threatgraph-processes — Gets the summary of Threat Graph Processes.
- cs-threatgraph-summary — Gets the details of a threat graph summary.
- cs-update-ioc — Updates one or more of the uploaded indicators
- cs-upload-ioc — Uploads one or more indicators for CrowdStrike to monitor