CrowdStrike Falcon - Get Detections by Incident
Deprecated. Use the `CrowdStrike Falcon - Get Detections by Case` playbook instead.
- Pack
- CrowdStrikeFalcon
- Tasks
- 6
Inputs
- IncidentID — The ID of the CrowdStrike incident.
Outputs
- CrowdStrike.Detection.Behavior — CrowdStrike Detection Details
- CrowdStrike.FoundDetections — Indicates whether detections were found.
Commands used
- cs-falcon-get-detections-for-incident
- cs-falcon-search-detection